These commentaries are produced by Noelle Hanrahan for Prison Radio. You've been listening to Free Speech Radio News. Our newscast is supported by Pacifica Radio, community radio affiliate stations, and listener supporters. We podcast at www.fsrn.org. That's F-S-R-N dot O-R-G. You can email us your feedback, questions, and story ideas to comments at F-S-R-N dot O-R-G. From KPFA in Berkeley, I'm Anitra Grisales. And you're listening to radio station WBAI, where the time is just about 7 o'clock. Actually, it's 7.01. Time for another exciting edition of Off The Hook. It's good fun when you know. Off The Hook. And very good fun when you know. And a very good evening to everybody. I figured we'd let the theme play all the way through this time for once. Emmanuel here with Off The Hook, joined tonight by Mike. Hello. And over on, well, not really on the other side of the room is not Kevin. Hello. Welcome. You haven't been with us for a while. Last week. Don't you have class now? I did. Did you quit? No. No, not in a sense. The teacher kind of quit. He is on the other side of the room. It's just a very small room. Yeah. Yeah, that's true. We're in a different studio tonight. And also, I should bring in Bernie S. from Philadelphia. Are you there? Yes, I am here from Philadelphia. Okay, great. So, everything works, which is a good thing. But, yeah, we needed to give up the other studio because of a pressing need for another programmer, which is not a problem. But we just have to sort of find the new buttons and figure out where everything is and where everything is not. I've already messed one thing up. Jones, if you're listening to this, I didn't record the first minute of the show. What will we do? I don't know. We have to patch it together. In fact, if you listen to the archives, you're probably going to notice a difference with the show up until this point where I mentioned that or where I started talking shortly before that. But we are recording it now. How are our levels? Levels look good. Levels look good, yeah. Let me hit the mic. Yeah, they seem fine. Okay, we're not too amateurish tonight. And also I should point out that we just found out while we are in, in fact, delay, we're in delay, we don't have access to the delay button. So that means that we can't take phone calls because if something bad were to happen, the only way for us to save ourselves from a $325,000 fine from the FCC would be to run through three different studios to get to the button in the main studio. That's just the way it is right now. So we are in delay, but we have no control over it. Does that make any sense? To me, maybe. I'm not sure about our audience. I'm thoroughly confused. Okay. Well, that's good, I guess. Bernie, how are you doing down there? Good. It's tough living in a censored society. It really is. You know, I mean, I know our listeners can handle things that go out of the air by accident, which does happen occasionally, but it shouldn't be that big a deal. But it is, unfortunately, and we have to take it very seriously. Anyway, let's launch into various topics for tonight. First one being a late-breaking story, which is kind of disturbing, I guess. A man has been killed when his phone exploded. I feel like the National Enquirer here. Haven't we done this one already? No, this is a new one. This happened in Seoul, South Korea. An exploding mobile phone battery apparently killed a South Korean man in the first such known case in this gadget-obsessed country, according to the Associated Press. Gadget-obsessed. The man, identified only by his family name, which there's no point in us even saying, was found dead at his workplace in a quarry Wednesday morning, and his mobile phone battery was melted in his shirt pocket. Yeah, we presume that the cell phone battery exploded, the police official said, only on the condition that we never find out who he is, who the police official was. The police are being anonymous now? Yeah, isn't that something, that the police are being anonymous? What do they care? It's not like they did anything wrong, as far as we know. Maybe they're not supposed to talk to the press. Unless it was not really a cell phone at all, but some sort of bugging device. Well, the phone was made by South Korea's LG Electronics, LG, of course, standing for Life's Good, not in this case, though. It's the world's fifth biggest handset maker. LG Electronics confirmed its product was involved in the accident, but said such a battery explosion and death was virtually impossible. Virtually is not good enough, apparently, for this guy. I guess. A person with only one known name. We're not going to say on the air. Manuel? Yes, go ahead, Bernie. Typically, this happens with the third-party aftermarket cell phone batteries, the ones not made by the cell phone manufacturer. These are like off-brand rechargeable batteries that are typically made with substandard chemical formulations and so forth, which make them more likely to have bad chemical reactions inside, and then the pressure builds up and they explode. In previous cases where exploding cell phone batteries were analyzed, they were found not to be the original equipment manufacturer batteries, but like third-party knockoffs. So if you're worried about this, make sure that the battery in your phone is not a counterfeit battery. A lot of times they have a hologram on them that says Motorola or whatever manufacturer the phone is to indicate that it's a genuine OEM battery and not some third-party knockoff that is more likely to explode. It seems like kind of a scare tactic to get people to only buy approved products. It might explode and kill you otherwise. These stories could be planted by the cell phone companies, cell phone manufacturers, to get people to buy the batteries, but I don't know if that's too plausible. Are you suggesting that this one named person, individual, whose name we're not reading over the air, actually does not really exist, and perhaps even the police official who claims, who demands anonymity also may not even exist? Well, we don't seem to have a lot of hard facts on this. Well, we know the guy worked in a quarry, so that sort of narrows it down a little bit. Yeah, okay. I don't know why they'd include that detail. It does remind me of this kind of interesting paper I read this week about de-anonymization of datasets. So our listeners might know that Netflix had this competition to see who could improve their recommendations algorithm, and what they did was they released 500,000 movie ratings, and they didn't say who rated them, but they said user ID number 17 rated this movie a four and that movie a three. And what's interesting is that this paper was able to figure out who a lot of these users were using other publicly accessible data. So maybe we could figure out who this guy is as well. How were they able to figure out who the people were just based on what movies they liked? They're very talented. It's a very thorough paper. It turns out that you only need about six movie ratings to uniquely identify a person. So if you can match those six with six movies that they rated on IMDb or some other public source, then you can get all the other movie ratings that they might not want public. If you take six ratings, that is so unique. What's the scale? One to 10? One to 100? One to five. One to five? One to five. All right. So I rate six movies, was it? Ten movies? How many? Six. Six movies. Okay. I give one a two, one a four, one a five. You're saying that just that combination, that six-digit number, if you will, that is unique enough to make me stand out. It appears to be, yeah. Wow. There are some movies almost everyone can agree are really terrible and some that are really good. Well, it turns out that most people have seen at least some unusual movies. Obviously the big movies that millions and billions of people have seen, a lot of people have seen those and most people have some opinion on them. But if you look at the movies out of, say, the top 1,000, it's pretty unusual exactly which of those movies each individual has seen and what they thought about them. And this goes to show how easy it is to be tracked without realizing that you are being tracked. It's something simple. As innocuous as just saying on a scale of one to five whether you like a movie, having six of those. Well, first of all, what were they cross-referencing it to? Netflix has all this information publicly available? Who says what about what movie? No. Netflix released this anonymized data set and they were able to compare it to people's public IMDb ratings, ratings on IMDb. And they're assuming that the ratings are the same. Well, it turns out that there's some fudge factor, that if it's not all exactly the same, you can still pick the closest match and almost certainly be right. And, I mean, it's interesting because it raises other questions of how to anonymize data because Netflix, I think, honestly, didn't intend to tell anyone individual users' preferences. They said, all right, we'll take the names out and that will be fine. But it turns out not to be fine. So it has interesting implications for other large data sets. Well, interesting you should bring that up because an interesting story came out this week concerning a device known as TiVo, which many of us use. NBCUniversal has become the first major TV broadcaster to strike a deal with TiVo for the right to use their TV viewership research and interactive advertising products. Now, that agreement was announced earlier this week. It reflects rising demand in the TV industry for detailed audience viewing information. I'm not sure why there's a rising demand for detailed audience viewing information. I guess they just want it more than ever now. Information is power. I guess, but wasn't it always power? I don't know. NBC wants more and more power. They want their power to rise. They need their information to rise. Well, okay. Anyway, TiVo is a provider of digital video recorders. About a year ago, they started offering advertisers second-by-second ratings of programs and commercials based on the viewing habits of its subscribers as well as other services. Second-by-second ratings. Now, earlier this month, they added demographic data about the viewers themselves such as age, income, marital status, and ethnicity. First of all, I'm curious. How are they getting this information? I have two TiVos, and neither one of them has asked me anything about my ethnicity or my age or my income or anything like that. Well, they could easily know. How would they know? I'm assuming it's based off the information you registered with TiVo with. Well, that's not real information either. Whoops. It's not required by law that I tell TiVo the truth, is it? Is it? I mean, maybe you lie. I mean, it's another thing. Like, maybe you actually are unidentifiable in this particular data set. I've been told that many times. But most people probably tell the truth when they're asked these questions. And if TiVo were particularly evil, they could correlate the address with other publicly accessible sources of information and know even more about you. Mike, that's the thing. Everyone tells the truth when they're asked these questions. Why? Why do you all tell the truth? When companies ask you your name and age and address, why do you tell them the truth? Why do you give all this information out and make it so easy for them to track you? That's what I don't understand. And people go and they do it on Facebook and on MySpace and on LiveJournal. They give all their private information out, their real name, their real address, their real city, their real likes and dislikes, and the people they like and dislike, and all these intimate thoughts that, you know, in years past, you would keep locked up in a desk drawer somewhere. So I just don't get it. It seems like, yeah, privacy is more and more endangered today. But it seems like we're also giving more and more of it away voluntarily. Well, I went to a talk once called Privacy is Dead. And did you get over it? I tried. All right, continuing with this story then. With its research, TiVo is competing with industry giant Nielsen Media Research, which also offers commercial ratings and demographic data. Advertisers, media buyers, and TV networks have made many of their ad deals this year based on Nielsen ratings of TV commercials. You know, if I was a Nielsen person, I would never give a commercial a good rating at all because I hate commercials. I really do. So I don't know why people would give positive ratings to those kind of things. Companies like NBCUniversal are looking for additional products from sources such as TiVo, which can tap its set-top boxes to get data about the viewing patterns of its subscribers. Advertisers have been asking us to help them find new ways to make TV advertising more effective. This partnership gives us the data, the research, and the tools to try a bunch of new advertising formats and test their performance. NBCUniversal will also use the agreement to sell advertisers TiVo products such as interactive tags, which means that... This is great. The tag means a company's name can still be seen even if the viewer is zapping through an ad. So viewers can also click on the tag for more information. It'll be just like having one of those awful websites where the pop-up boxes show up. And another TiVo service allows viewers watching promotions of NBCUniversal shows to click on the promotion and immediately record the show. Actually, that's not such a bad thing because that's something that sometimes you want to do. And this is all starting on January 1st. I know, Mike, you have some questions or some concerns about privacy here, about being tracked. They say it's anonymous. TiVo says that they're not evil and that this information, this tracking information, does not correlate to someone's name, although it seems to not correlate to ethnicity and age and income. Well, if you are in a town with, you know, few people of your race and TiVo says that most people of your race like a certain program, it becomes very easy to correlate it to you. I mean, there's all kinds of stuff like that. And furthermore, like, I can conceive of no way that this could benefit anyone except the advertisers. I mean, our friend, Junce, disagrees. He wrote to us that if his preferences help to shape the future of television programming, then he's all for it. But I'm not convinced that this data will somehow lead to an increase in television programming quality. I think it will just lead to somehow them charging more for advertisements. Well, I mean, do you think that if you ask the majority of people in this country what the best TV programs are on the air, do you think you'll get a better answer or a worse answer than what people are assuming are the better programs on TV today? You know, I have faith in people, but I don't have that much faith in the American public as a whole as far as taste goes. I think we just wind up with a whole bunch of reality shows and infomercials. Well, they're very cheap to produce, and apparently people watch them religiously that advertisers know that it's a good buy. Mm-hmm. Well, what are some ways we can mess with their heads and give bad information out and make it so that this kind of study is kind of worthless? I don't think there's enough of us. Like, I think, you know, if 10% of the TV views in public somehow manages to provide bad data, then the other 90% is still valuable data. Mm-hmm. So I don't know. They can't tell the difference between a bad 10 and a good 90. It doesn't matter. You know, if you have data that's 90% good, you have data that's 90% good. Hey, Manuel. Yes, Bernie. This is sort of a paradigm shift compared to the old rating systems like Nielsen and so forth used to use where one family or one person who was viewing or listening habits really counted for, like, 10,000 people in the population. So I got a call from Nielsen Research once for their... Actually, no, it was Arbitron, for their radio station survey. I got a call from Arbitron about 15 years ago, maybe even a little... Yeah, about 15 years ago. And I delighted in telling them that when they asked me what radio stations I listened to, I delighted in telling them that I enjoyed listening to Radio Havana, Cuba and Radio Moscow. Oh, boy. I also said the BBC and Radio Doja Bella and things like that, but I don't know whether that was just discarded as bad data, but I'd like to think that skewed the result somehow. I think it also resulted in the Patriot Act. Thanks, Bernie. Oh, well. Okay, well, that's... It's all propaganda. There are ways. Yeah, there are ways to mess with them and give out slightly wrong names. Like, for instance, if you fill out... If you have to fill out a form of any sort, you don't have to spell your name exactly right. Spell it a little bit off or add a different middle initial or something like that or put sweet number whatever at the end of your address. All of that will help you see who's sending your name to whom and who you can trust and who you can't trust. Sometimes their data entry people do that for you. Uh-huh. Spell your name wrong. Oh, that's true as well. That is definitely true. But particularly if you're entering it yourself online or something, then there is no data entry person. Speaking of TiVo, TiVo is now finally coming to Canada. That's right. Canada now is going to be getting TiVo. I believe it's not going to be quite the same as in the States, but this is the first time. They have digital recorders for the various cable and satellite companies up there, but TiVo's move into Canada represents a natural important progression for our business as we continue to make sustained progress across international markets. You can guess who said that. That was one of the spokespeople for TiVo saying that. All right, so exciting news, and I'm sure Canadians will now be happy to have their viewing habits tracked perhaps. Sold to the CBC, maybe. Maybe, yes. Okay, Mike, you found this story, which I thought was very interesting, about some charities that were having difficulty with their ISPs and how hackers are the ones who are getting blamed for their email addresses and passwords being bandied about. Do you have any more details on this? Yeah, apparently thousands of donors to 92 charities that use online database software and services from Convio Incorporated. These email addresses and passwords got taken by people who weren't supposed to have them. Convio is one of these big companies that provides online services to non-profits. There's a number of them, and I've always found them to be kind of sleazy whenever I've met them in the past. You meet them in alleys or something? No, I meet them in conferences where they're trying to give me things in order to buy their very expensive services. Okay, it's expensive, but it's geared towards non-profits. Why would non-profits go to something A, sleazy, and B, expensive? Well, a lot of non-profits don't have in-house technical staff who can implement it in a more cost-effective way. And if they go to something that's not geared towards non-profits, it's even more expensive? Well, there's certain needs that non-profits have in common. The need for donor tracking and stuff like that is a sort of niche that a lot of companies like to fill, or some companies fill. Yes, Bernie? Mike, I had a question. Does this company, do they generally charge like a... How do they charge these non-profits? Is it like a cut of the proceeds that they collect from the donors? Or is it just a flat rate or a combination? I mean, I don't know this particular company's pricing model, but in general it can be any of those. If they're doing online donation processing, then they'd probably take a cut. If they're just tracking, it could be by the size of the database or a flat monthly fee or whatever they can get away with. What were some of the non-profits that were using this company? I think the Red Cross was one of those, wasn't it? I don't know about the Red Cross, but CARE, the large charity, the American Museum of Natural History, was part of it. FreePress.net was one of them. So what exactly happened? The 62 non-profit groups, they say that information about their donors might have been compromised. In what way? Were they just out there on the web or something, on a website? Was that information even given out? I mean, it's not clear. Even in this article, this article is in the Times, and the first paragraph it says 92 charities and the fourth paragraph it says 62, so I don't even know how many people are affected by this, but apparently they got the usernames and passwords, and most people probably have the same password on other services, especially for these non-profits that they may interact with only once a year. So that someone could impersonate them on another website, and the article is careful to warn us that there's no evidence that this data has been used to breach anyone's privacy yet. I mean, that evidence, you wouldn't see that evidence, not immediately anyway. Individuals would see it, and you'd have to contact every single individual person to find out if there was any evidence that something weird happened to them. But what I found interesting about the article, which appeared in the New York Times on the 27th, the very first word is hackers, and the first sentence reads, hackers obtained access last month to the email addresses and passwords of thousands of donors to 92 charities that use online database software and services from Convio Inc. So right away, hackers, they're the ones behind this. It doesn't matter that there was no security or somebody made a very bad mistake. Hackers are the only people out there that are interested in getting access to this information. Is that what you read out of this? It's what it says. I mean, it's pretty clear that hackers are the first word of both the title and the body of the article. Well, it says hackers cracked charities' addresses and passwords. Is that how this allegedly took place? It's what it says. I mean, it's interesting because, assuming that they got enough addresses, there's 92 charities, probably some are bigger than others, but this is thousands, if not hundreds of thousands of people. If they steal money from a dozen or a few dozen of them, these people are never going to connect it to the charity. I mean, I don't know how many donors the American Museum of Natural History has, but it's got to be a lot. Ah, interesting. And most of them, probably only occasional donors who wouldn't think of it. Well, the American Red Cross says up to 278,000 email addresses have been compromised. I'm not even sure what that means. How do you compromise an email address? They got the password to email addresses by donating to the Red Cross? I have to assume it's the same password to the actual email. For instance, Gmail or Hotmail or something like that. But then it says, passwords were also at risk in 1,351 instances. So they're differentiating email addresses from passwords. So how is an email address at risk if you don't know the password? This makes no sense to me at all. Anyway, they say, we're lucky this just involved email addresses and a few passwords and not any personal identification or personal numbers. So I guess what they mean, if I can try and read into this, what they mean is simply by listing the email addresses of donors, they consider that to be compromised. So private information, I suppose, getting out. I imagine it'd be more than just their email address. Well, even, I mean, even a lot of people might consider it a loss of privacy to know that they are affiliated with these nonprofits. I mean, depending on exactly which groups, some people may not want their employers to know who they give money to. Or who's, not even with money, but who they are ideologically aligned with to receive a newsletter. So, you know. I would just like to know how this was done. I mean, what exactly are they saying? Because obviously, what would you need to crack to get a list of people's email addresses in a particular system? It sounds like something was just left lying around. We've seen this countless times where companies put databases on their websites someplace and someone just figures out the URL to it. That's not really cracking into a system. It's not really doing a hacker-type thing. It's maybe being a little bit clever in figuring something out. But you certainly can't blame the person who finds it. It's the person who leaves it out there for the whole world to see. Yeah, I mean, and if it were just one nonprofit, you could assume that the, you know, IT director of that nonprofit or whoever had a bad password or something. But the fact that there's 92 of them seems to indicate that there's some flaw in the software package. Okay, well, I guess that's the story of lost data of the week, which seems to happen almost every time we're on the air. Last week, it was England with all those people, millions of people with all their information out there. And now people donate to charities. Nobody's safe. It's another reason why you should use fake information, not when you're donating things. Obviously, you want to really give money, but you don't have to use the same email address. You don't have to use the correct spelling of your name or even an address unless they need to mail you something. In fact, sometimes it's better to make a donation and give them a fake address so that they don't pester you forever when you stop making donations. I've had that happen a few times. Okay. In Ottawa, they are calling for more surveillance cameras or the police chief is anywhere. I don't know how the rest of the city feels about that. But more surveillance cameras should be keeping an eye on citizens in Ottawa's downtown core, says Chief Vern White. He said this on Tuesday. I'm not suggesting that the police have a police-owned state where we maintain security and surveillance over our citizens. I'm telling you that I believe it would assist the police in criminal investigations and may assist citizens who make complaints against police, possibly. It's so great that they're looking out for us. Well, they're just trying to fool us into saying, yeah, we need cameras so that we can catch you guys doing something bad. You know, like the guy who got tasered. I think we all saw the video of the guy getting out of his car and getting tasered by the hysterical cop for not doing something exactly the way he wanted him to do it. No, I can't say I saw that video. It's been everywhere. I saw the one where the, in the college, the kid getting tasered. Oh, that too. There's so many taser cases, it's ridiculous. But this one was a guy who got pulled over by a cop and you see him getting out of the car and basically the cop is yelling at him the whole time and the guy just says, what's the matter with you and turns around and walks back to his car and at that point he gets, he's shot in the back with a taser and his wife jumps out of the passenger side all hysterical and he screams at her to get back in the car and apparently she was at risk of being tasered too for not following his commands. Yeah, you know, and it was all captured on camera, the camera of the police car. The police cars have little cameras and apparently the cop didn't get to this one and erase it in time. So this has been all over the place. Well, it's interesting we're talking about tasers in Canada as I just happened to stumble upon a fact of that 18 people were killed last year in Canada with tasers. Yeah, and I think between 150 and 300 over the past few years in the United States. So this is a big problem and tasers are obviously being used a whole lot but that's not really what the story is about. It's just sort of a side show. We talked about this last night on Off the Wall. But yeah, cameras I guess can be good for uncovering police misconduct of which there certainly is quite a lot as well as other things but it's also something you change the whole way you live your life when you realize that you're always on camera and I don't know how many of us are we on camera now? I don't see a camera in here but look around. Those of you listening now are you on camera somehow? You might think you're safe but really there could be something outside that can see you or maybe you're driving and there are cameras on the road or maybe you're a babysitter and the people that you're babysitting for put a little camera in the lamp or something. Everyone's always, we've got spy mania where we're watching each other constantly. I don't know if I'm on camera right now but I have a sneaking suspicion my voice is being recorded. That's hopefully true. We'll see about that later. But yeah, it's something obviously they're trying to push out here in New York City more and more surveillance. They want to build the ring of steel here downtown to hopefully make things safer. I can't believe you said that with a straight face. The ring of steel that they're going to build. Well listen, we say Freedom Tower now without laughing. Who says? It seems really absurd. Well I mean basically they say things enough times. U.S. Department of Homeland Security. We say that and we don't burst into laughter every time we say it anymore because it's become reality. There are kids who are being born right now who don't know what life was like before such ridiculous things as Patriot Act and U.S. Department of Homeland Security and Ring of Steel and Freedom Tower. These are words that will become ingrained in our psyches and we won't be able to shake it. So yeah, I'm not laughing when I say this anymore. I still laugh every time I hear someone order Freedom Fries. I don't hear that very often. I don't hang out with those kind of people. I think most people who do that too are joking maybe. But anyway, so they want to bring this into Manhattan like they have in London where you can't take half a step without being on a new camera in London. It's insane. And apparently that's what Bloomberg's idea for New York is to actually make New York as much of a surveillance state as London. What I find odd about that, if you look at the statistics of violent crime for this year, actually for murders for this year, do you know how many people have been killed in this city by people they didn't already have some kind of relationship with? Just random violence that involved death. How many people? Not a lot. 35. 35 for a city of how many million people? It's incredible. Six million? Eight million? Yeah, something like that. So I think that's safer than just walking through a mall. And I dare say even if you put cameras everywhere, it probably wouldn't have affected such a low number. And when I was in London, when I was talking to people in London and reading newspapers over there, I was hearing reports that yes, crimes weren't committed in front of the cameras. They moved their victim to the forest and killed him there when it wasn't on camera. So it just is resulting in spreading out of the crime a little bit more. But the cameras are still there. You're still being recorded for everything you do. And keep in mind, it's not just for violent crimes or for illegal things. It's for being in a neighborhood you're not supposed to be in. It's for hanging out with people you're not supposed to be hanging out with, being associated with a group of individuals. And that can be used against you at some point. Maybe not today. Maybe not tomorrow. But at some point, a government could come along that could completely profile all sorts of people based on their interest and their association. So these are scary tools we're putting in place. And we should think twice about them. That's my message to Ottawa. Anyway, the cameras, according to a criminal lawyer, who I don't know why he's in this story, but criminal lawyer Mark Urtel said that they reduce people's privacy and civil liberties. That's probably why he's in the article because they knew he was going to say that. Thank you, Captain Obvious. I'm not quite sure what else he said to merit being in this article here. I think that's pretty much it. But Carleton professor Josh Greenberg, who is conducting a publicly funded study of CCTV cameras, closed circuit television, said researchers watching surveillance camera operators consistently found that they focus their cameras more on some types of people than others, such as young black or aboriginal men. What a surprise. I'm shocked. The studies also found that camera operators often use their systems to ogle women and girls and compare their sexual attributes. Ogle? Yes. What's ogle? Ogle, you know, I don't hang out with many oglers or oglers, so I don't really know how to pronounce it. I'm proud of that. Anyway, many in the crowd. What crowd? Where'd the crowd come from? Apparently a crowd gathered once this story started to be written. Many in the crowd said they didn't care about privacy concerns and the cameras would make them feel safer. And that, my friends, that is it right there. Those of you who don't care. That's why this is happening. People who don't care and say, yeah, go ahead. Put in more cameras. I'll feel safer. These people are beyond not caring. They actively want the cameras. They will feel safer with them and they want to feel safer. Mm-hmm. But they're fooling themselves. Well. That's valuable. One woman said the streets of Ottawa downtown are not like they were in the 1950s. There wasn't crack and all the other stuff that seriously affects our downtown neighborhoods and makes us feel unsafe. How does a camera prevent crack? I don't understand how that's even possible. Crack detecting cameras? You can do crack in your own home away from the camera. Yeah. So I understand it. Another woman in the now unruly crowd said cameras made her feel less safe. I'm not going to feel more secure than my daughters and I are on tape. I'm not going to feel more secure that my daughters and I are on tape. Where somebody is watching me when I have no idea what's being done with the tape that's being made. I have no idea about what could be done in the future in terms of creating a record about my movements in public space. And that's something. It's public space. It's one thing to have cameras in office buildings where it's private property and they want to know who's where. But we're talking about people walking down public streets, in parks, things like that. Years ago, this would have created a lot more outrage than it's creating now because of the fear factor. Sad, isn't it? Okay. What else should we be afraid of? Cell phone. Cell phone tracking. Federal officials are routinely asking courts to order cell phone companies to furnish real-time tracking data so they can pinpoint the whereabouts of drug traffickers, fugitives, and other criminal suspects. That's according to judges and industry lawyers. Wait, wait, wait. Note to fugitives. Turn your cell phone off. Well, is that even enough? Just turning it off? I think so. Bernie? Well, it's not enough, but it would be enough if the federal officials were routinely asking them, maybe, with at least some probable cause because in many of these cases, judges have granted these requests without requiring the government to demonstrate that there's any probable cause to believe that a crime is taking place. It's really outrageous. There should be probable cause. The cellular telephone industry association, the lobbying arm for the cellular industry, has said that there's a lack of consistent legal standards for tracking a user's location and that's made it difficult for carriers to comply with these law enforcement agencies' demands. The guy who represents the CTIA has said that he's never seen such a request that was based on probable cause. Never. Never seen a request to track somebody by cell phone based on probable cause? Yes. Does that mean that there aren't very many guilty people around or that they just skip that step all the time? It means they're just skipping that step that should be required. And that's again, that's not even against the Justice Department standards that there should be probable cause and they're not doing it. So let's just use a hypothetical here. Let's say that they're out there, the federal government wants to track one of us and so they request from a cell phone company bits of information that allow them to keep, is it real-time monitoring we're talking about? It could be. Okay. It may or may not be. Monitoring of one sort or another of one of us in this room. Okay. So they do that. They don't have to show probable cause. They get that information. What happens after that? The carrier then provides that information. It can be done in real time. It depends. There's different services that the carriers provide. And all of them are really expensive. It's like thousands of dollars every time they do one of these. And it's like hundreds of dollars per ping. Wait. They charge the cops to spy? Oh. Huge amounts of money. A huge profit center for the wireless carriers. I didn't know that. Oh, yeah. Not just the wireless carriers but the wireline carriers also. Yeah, but you see, if Andy Sipowicz from NYPD Blue wants to get into an apartment where there's supposedly some foul play going on and he asks the landlord to let him into the apartment, the landlord doesn't say, okay, that's going to be 10 bucks. So at what point does the cell phone company get to say, we're going to charge you for this little bit of spying that you want us to undertake? It's just the way it's done. It's been done that way for decades where the phone companies just submit a bill. And then there's actually published rates for this stuff that I've seen for the various carriers. And it's really expensive stuff just to set it up it's so much. And then for every additional ping it's so much. So a typical tracking deal like this could result in, you know, could cost many thousands of dollars which, you know, guess whose pocket that comes out of? Well, it just seems to me that a phone company, a cellular phone company could actually have an incentive, a profit incentive here of spying on its customers. Maybe they could lower the rate of phone calls and make that really cheap so people are using them all the time and then sell the service of spying on those people who are using the phones all the time to law enforcement and that's where they make their real profit. Well, it also comes out of our pockets because there's thousands of dollars that are charged for every one of these, every one of these non-probable cause requests. Of course, yeah. It's all tax dollars that comes out of our pockets. And that's not even... We're paying for our own spying. Right, that's not even for the customers of the cell phone company. That's just something... We don't have a say in that, Bernie. That's just what happens. Yep. Wow, it's genius. Okay, but getting back to my hypothetical. Okay, so they go and they watch us move around. Let's say they watch NotKevin move around for a month or two, track his movements, see where he goes. And I imagine they also can see what he dials up and what he accesses on his phone as well. That's a different request. That's a different fee involved. That's a different request. Okay. They can tell where you are when you're like 30 feet, wherever you go. But then if they want pen register data, that's extra. That costs extra to get that information. And neither request are being submitted now by law enforcement agencies with probable cause, with an affidavit of probable cause. They're using some lower standard. Okay, so basically we're just watching NotKevin move around from his house to his school to wherever else he feels like going. Yes. I thought probable cause was just about the lowest standard out there. I mean, it's basically the cop saying, yeah, I think he did it and I have some reason. It's not a high burden of proof. And you're saying they can't even meet that? No. What they're using is they're citing specific and articulable facts showing reasonable grounds to believe the data are relevant to an ongoing criminal investigation, which is different than what's called Rule 41 of the Federal Rules of Criminal Procedure, which contains the probable cause standard, which is a higher standard. So this is like, as you point out, this is a really low standard. Basically, they can just pull this out of their ass. Oops, forgot the delay. Run down the hall, will you? We've got six seconds to make it. Okay. Okay, so continuing, though, with my hypothetical, we're watching NotKevin, or they're watching NotKevin go all over the place and do all kinds of dull, boring things, supposedly, nothing really incriminating, for however long they feel like. And then they decide, you know what? This is boring. We don't want to watch this guy anymore. Let's stop doing it. Okay? Yeah. What happens after that? Well, I'm sure they don't throw that data away. They store it for future reference, maybe. Does NotKevin ever get told that they're watching him, that they were watching him for the last few months? No. Okay, so that's something I'm kind of curious about. There's no requirement that the person who is a subject of the monitoring be told about it? Because way back when my phone calls were being pen-registered by the FBI, I got a little letter from New York Telephone saying, oh, by the way, this has been going on maybe a month or two ago. It was after the fact, but they did tell me they were required to. That was then. This is now. Say for some reason I did find out this was happening. Would you have to file a Freedom of Information Act to obtain this data? You could. Whether you're going to get an answer or not is a whole other story. Would NotKevin be legally allowed to stop using his phone and not be tracked, or is that illegal now, too? Actually, there are federal rules that we'll call enhancements. When they're sentencing somebody, they can add points of enhancements which increase your criminal score so you get more sentence, a longer sentence. So if you evaded being tracked, like thinking you could be followed by your cell phone data, if you stop using a cell phone, the prosecutor could actually say, and he used this, there's all these rules they have. One of them is if you took evasive action, and that would be considered evasive action. Wow. What times, what fantastic, marvelous times we live in. I just can't get used to it. Okay, so, and the way to be safe, the way to be safe, is turning off your cell phone enough? Is it still sending out a ping or something, or do you have to take the battery out? What's the wise thing to do if you think you're being tracked? Well, the absolute surest way to ensure your phone is not being pinged or tracked is to remove the battery. I mean, if there are, your phone could be hacked, sometimes remotely, by law enforcement agencies through the cellular carriers or PCS carriers, to make it look like it's, you know, it's operating normally, and it could actually be transmitting audio from your phone or whatever. I mean, there's all kinds of things you can do to be absolutely sure, and when your phone is in your, when your battery is in your phone and you're not using it, it's still communicating with a network more or less constantly and can be pinged very easily. So, if you really want to be sure, you can either take the battery out or put it in, you know what also works? You can keep it in, you can keep the battery in, you can put it in a couple of those anti-static bags. I thought you were going to say tinfoil, but okay. Tinfoil will work too, but those sort of silvery-looking bags that they package circuit boards in, if you ever bought a, like an adapter card for your computer and there was like this grayish envelope that is sort of silvery, you could put it, and two layers of that will attenuate the signal enough. You can actually see the phone through the transparent thing, but it blocks the signal. Of course, it won't receive any calls, but you can still punch buttons and like retrieve information from it. Amazing. Speaking of, go ahead, Mike. I was just going to say, you could use a cell phone jammer. Yeah, I guess you could. How about that? Speaking of not Kevin's movements over the last week and why the authorities might be interested in tracking him, you went to the demonstration to save the Hotel Pennsylvania. Yes, I did. I think you're the only person in the room that made it over there because it was the day after Thanksgiving on Black Friday. What was it like? What happened? It was actually a lot of fun. I was expecting it to be very subtle, but everyone there was very enthusiastic and was just really getting into handing out the flyers and explaining the situation to passersby. We got a lot of compliments from hotel workers and even Amtrak workers who seemed to be staying at the hotel. Well, it is right across the street from Penn Station, so it's not that surprising. The reaction from just regular people coming up out of Penn Station or walking down the street, did they know about the hotel being in danger? It seemed like most people did not know about it, but once we explained, gave them the brief explanation of what's going on, they really got into it. For those who don't know, Hotel Pennsylvania is where we have our conferences, the HOPE conference that takes place every couple of years. In fact, the next one is going to be in July of 2008. They announced plans. Vornado, the company that owns that entire part of town apparently, announced plans to tear down the hotel and replace it with a huge office complex that will look like another version of Times Square, according to the artist rendering that we got a glimpse of. What we've gotten involved in since then is this campaign to just preserve the hotel in any way possible by landmarking it, by just getting all kinds of public support, by putting pressure on Merrill Lynch not to abandon downtown and go uptown and fill this new building. The response has been simply unbelievable. Community Board 5 voted for landmark status, and the process just continues. We have all sorts of people involved now. There's a website, www.savethehotel.org, that has all sorts of information on it. There's an online forum at talk.hope.net that you can get involved in and post all sorts of information, ideas, feedback, that kind of thing. We have an email address, hotelat2600.com. That's hotelat2600.com for people to send any pictures or correspondence, memories, stories, opinions about the hotel that we can then use and distribute and send out to other people. This is a movement that's really starting to grow, and not just in the New York area because people from outside the New York area are the ones who stay in a place like this. They come to the Hope Conferences or they come to other conferences, and it's just a piece of history that we're afraid might be lost, and obviously, from our own perspective, if we lose this piece of history, we don't have a home as far as the Hope Conferences go. So it's good to see people get involved, and I guess there'll be more demonstrations in the future? In fact, there will be. Okay, so we'll be announcing that here on this radio station and at hope.net as well. Okay, let's take a look at some of the email that we get, our email address. God, I've been throwing a lot of URLs and email addresses around in the last two minutes, but our email address, oth at 2600.com, for those people who want to write to Off The Hook and give their feedback, opinions, whatever. Send us hate mail. We don't get enough. Hate mail, yeah. Hate mail is very important to us. It gets us through the day, and lately, everybody's been friendly, and what kind of world is that? I mean, don't get me wrong. We appreciate the friendly people, too, but we could use some hate mail. Yeah, friendly people are fine, but we know there's a lot of people out there that can't stand us, and come on, folks. Don't hold back. Okay, Dear Off The Hook, great show. You see, this is the problem. Great show. I look forward to it every week. I hear that all the time. We sound really horrible, don't we? Please tell me the artist of the exit music at the end of last week's show. You played some ambient music, and I loved it. Signed, James. James, you were talking about last week, and that was probably Moby. We've been playing Moby a lot lately. We won't be playing Moby tonight. We'll be playing somebody else. I hope Moby's not offended. No, but if somebody writes in and asks what we played, we usually announce it the week afterwards. That's just the way it works. Here's something interesting. This person wrote in, having discovered something, or gotten something in the mail, Chase, is it called Chase Manhattan anymore, or just Chase? It's JPMorgan Chase, isn't it? Yeah, I can't keep up. Okay, Chase now allows you to get basic information about your accounts with them through text messaging. Yeah, by sending a text command to their Chase mobile system from your phone, you can be sent a reply message with your balance, next payment, due date, or recent transaction history. This sounds like it has all kinds of potential for abuse and misuse, considering that text messages are not encrypted when sent over the internet, and that text messages can be sent from all kinds of non-cell phone devices. How could Chase authenticate the user's identity correctly over this non-secure medium? They don't address these security issues at all on their website, from the intro over there. At Chase, we use a variety of technologies to help ensure that our products and services remain secure. From the frequently asked questions, is Chase mobile secure? Yes. At Chase, we're dedicated to protecting your personal information, and we use a variety of technologies to help ensure our products and services remain secure. It's a variety of technologies I really want to know more about. So they seem to be saying, just trust us, but aren't they setting themselves up for major abuse of their systems? I'd love to hear what you guys have to say about this on the show sometime. Of course, you can just go to the chase.com site, but thanks, Scott, for writing in. I believe, Bernie, you've been in communication with Scott and got him to actually sign up for this service and test it out, right? Yeah. He said, actually, it seemed pretty interesting that there's no, it doesn't allow you to change any account information or do any account transfers, but it does let you see your balance and that sort of thing. He's, I mean, Scott is further experimenting with it, and we threw some suggestions at him, try this, try that. So I can't try it myself because I don't have a Chase account. So throwing some ideas at him, and we'll follow up on that. Well, Scott tells us that initially, the signup involves Chase sending an eight-digit activation code to his phone. He then entered that on their website, and that was it. They sent the confirmation text message plus two more text messages that just listed all the possible commands. And let's just go over those commands real quickly. B-A-L to get your available balance. B-A-L, nickname, get available balances for your nicknamed accounts. History, H-I-S-T, nickname. See a history of transactions for your nicknamed accounts. Due nickname, D-U-E. Check the payment due date for a nicknamed credit card. Do any of your credit card accounts have nicknames? Am I out of it for not having nicknames for my credit card accounts? I don't even know what this means. Why would you give a nickname to a credit card account? Get with the program, man. Is it like a pet or something? Okay. Nick, see a list of your account nicknames. I got to try that one. Maybe my accounts have nicknames I don't know about. Help, get additional service information. Command, see a list of available commands. And stop. That's the best one. Stop, unsubscribe from Chase Mobile. Never bother me again. Scott says, so far I'm impressed with the system's speed. If I send B-A-L for my account balance or a HIST, H-I-S-T, for five latest transactions, I receive a response text message in six to eight seconds. Having tried this out, I can see that it's way faster and more convenient even than logging into their web system. If all you need is your account balance, recent transactions, or payment due date, it's great. Of course, you have to be okay with all that information being sent to you in clear text through their SMS gateway. The system cannot be used to apply any changes to your accounts, like transferring funds, opening and closing accounts. It's essentially read-only. And also, at no point in my testing, as Bernie was hoping, did it send my account number via text. So apparently, it's secure on that level at least. I tried to test spoofing my from text number, but I'm not sure how to do that. The number for Chase's system is an SMS short code of 24273, and I'll just bet that spells Chase. Does it? Could. Yeah, no one has a phone in front of them, but it probably does. I do. Yeah, it does. It does. Yep, yep. Okay, I've got it memorized. And I wasn't able to figure out a way to send a text to a short code without using an actual phone. So if anyone has any ideas on how to spoof a cell phone number and send to an SMS short code, then we might have a vulnerability here. This is something I'm actually not sure about. Is it possible to spoof messages to these short codes? If you use some of the email gateways, it may be possible to spoof messages to an actual cell phone, but I'm not sure of a way to spoof messages to these short codes. Maybe one of our listeners knows. Not Kevin, aren't you known in some circles as the spoofing king? No, not that I know of, but... Caller ID, ANI, you know how to spoof all these things, don't you? I'm not going to answer that question. Well, this is a good way to answer these questions. The thing is, is it possible? Is it possible to do this kind of spoofing? Honestly, I have no idea, but it's very likely. I'm just going to put that out there. Okay. Now, if anyone out there knows how to do this kind of spoofing so that you can full chase Chase Manhattan, JPMorgan Chase, Time Warner Chase, whatever they're called this week, please send us email and tell us how it works and we'll try it out. We'll try to take the system down. That's not as negative as we're making it sound, but a system should be tested for its strengths and weaknesses. OTH at 2600.com. That's our email address, so please send us mail. I'm actually generally worried about this system as Chase is also the bank that seemed to have thrown out 40,000 records of their customers last year in their trash bags. Yeah. Yeah, isn't that something? So you sort of have to test them out. You sort of have to test their security. Well, it looks like we're just about out of time, and as we said at the beginning of the show, we couldn't take phone calls this week because we're in a different studio. We're in Studio 3 down the hall, and we don't have access to the delay button. We're on delay, but we can't press the button in case somebody said something bad. We couldn't bleep them out without being in a different room at the same time, so that's just the way it goes, but next week. Next week is a different story, and please feel free to give us a call then. We're going to leave now, and we believe the Personal Computer Show is going to come at you from a different studio. I saw them poking their heads in, so they're somewhere. Well, I think they're curious as to what we're doing in here instead of in the room we're supposed to be in. In fact, I'm assuming, I'm going on a big assumption here that this whole hour we're actually on the air. We're not just talking to ourselves in this little tiny room down the hall. I have evidence of that. Okay, well, it wouldn't be the first time. There's so many shows that we've done that nobody has ever heard, but that's going to do it for us tonight. I want to thank everybody for presumably listening, and I just had to figure out why... Ah, yes. There we go. I pressed the wrong button. We'll be back again next week with a normal show, supposedly. Again, the email address oth at 2600.com for your feedback, letters, praise, and, of course, hate mail. Always welcome. It's a manual for Mike, not Kevin and Bernie. Have yourselves a good night, and we'll be in touch. Stay tuned for the Personal Computer Show. Good night. electronic music plays electronic music plays electronic music plays electronic music plays electronic music plays electronic music plays