It is no longer able to bring in essential needs such as flour and rice, etc. Israel says the closure of Gaza's crossings will remain in place until Hamas's rocket fire from Gaza into Israel stops. For Free Speech Radio News, I am Rami Al-Mirari in Sadr in Gaza. And that will do it for today's newscast. In Los Angeles, I'm Aura Bogado. And you're listening to 99.5 FM, WBAI, New York. Time is 7pm, time for Off The Hook. We couldn't get much worse, but if they could, they would. Bondedly bound for the best, expect the worst. I hope that's understood. Bondedly bound. And good evening, everyone. The program is Off The Hook. This is Red Hacked here in the studio. I'm joined by Mike. Hi there. Rob T. Firefly. Good evening. Not Kevin. Hello. Voltaire. Salutations. And I believe we have Emmanuel on the line. Hello? Yes. Actually, I didn't think of a clever word to say to indicate that I'm here. But I guess instead I'll just be clever by saying that I'm somewhere else. I'm not in this country anymore. I am down in South America, in Brazil. I believe I mentioned this last week, in Sao Paulo right now, having just attended the YSTS 2.0 conference. I think we also have on the telephone Bernie S. Greetings from Pennsylvania. I'm not in Philadelphia, but I'm still in Pennsylvania. So tell us about the conference, Emmanuel. Well, actually, I'm going to do better than that. I'm going to hand you to one of the coordinators of the conference, and he'll be able to tell you all about that as well. But before I do that, I'd like to see if anybody's there. First of all, everybody get away from your computer and don't log on to anything like Google or ChaCha or Wikipedia, anything like that, okay? I want for people in the studio to guess what the time difference is between New York and Sao Paulo right now. Two hours. All right. I'm guessing it's the same, or maybe one hour. One hour. Okay. All right. How about other people in the studio? Three hours. All right, keep going. Five hours? Well, they only say that it's two or subtracted two, whichever. We are on the same side of the Atlantic Ocean. You realize that? Yeah. I'm going to go with minus one hour. I'll spill the beans. It is three hours. We are three hours. Wait a minute. Three hours in which direction? Are you ahead? We should be ahead. Yeah. Yeah, we are ahead. It's kind of confusing because they're on Daylight Savings Time now and we're not on Daylight Savings Time. And there's a period of time where they are on Daylight Savings Time or actually they're not on Daylight Savings Time and we are still on Daylight. There's a period of time where we're both on Daylight Savings Time, is what I'm trying to say, and then there's a period of time when we're not and they are, et cetera. So the time difference changes, I think, three different times a year. I've noticed a real shortage of daylight here in New York. Maybe it's a mistake we're making by not saving it. I'm not sure how that works exactly, but it is almost summer down here. It's actually late spring, although you wouldn't guess it by walking around. It's been raining just about every day and it hasn't been that hot, so I'm actually pretty happy with that. But here's something interesting. When I first got here, I brought two phones with me, as I usually do. I had my CDMA phone, which I subscribed to Verizon, and I had my GSM phone, which I subscribed to T-Mobile. Now, the CDMA phone is using a different company down here. I haven't dared to use it because I'm afraid of what it might cost. But the CDMA phone, as just about all of them do, displays the time as it gets it from the tower and the time was right. The time was, in fact, three hours ahead of New York time. However, the GSM phone was two hours ahead of New York time and I couldn't figure out where my phone thought it was because I don't know of any place nearby that's two hours. And even if you take into account the changing of the clock, I don't think that would have made any sense either. And then a few hours after I arrived, it just reverted to the proper time. So if anybody has any theories as to what exactly was going on with my GSM phone, I'd sure like to hear about them. I think it was frightened. Maybe so. What I'd like to do now is hand the phone over to Luis Eduardo, who is the coordinator of the YSTS 2.0 conference. YSTS stands for You Shot the Sheriff, and I guess maybe the first question I'm going to ask Luis to answer is why that name. And you guys feel free to jump in with any questions of your own. Here's Luis. How's it going, guys? How are you? Greetings. Good, how are you? So, yeah, You Shot the Sheriff. Why You Shot the Sheriff? Me and two other guys, William and Nelson down here in Brazil, we do actually a security podcast called I Shot the Sheriff because of the song. So last year we came up with the idea of doing a conference and bringing people together to pretty much have a different type of conference, a conference that has different types, all different types of talks, possible talks, politics and the hacker community and technical stuff and get in a more interactive way. So instead of I Shot the Sheriff, we turned that into for the conference, You Shot the Sheriff, so the attendees would have a better participation on the conference. That's why. What are some of the things you have at this conference? So it's a one-day conference. The way that we do it is on a different venue from last year. The venue is always a bar or a club or something like that. It's an open bar type of conference from 1 o'clock on, so to get people more relaxed and being free to ask questions and be a little bit more relaxed. Some of the types of talks that we had, like some guy talked about the different uses or misuses of the term hacker, for example. So it was more like a political, like on the political side. We had Hikari who runs TorCon talking about FPGAs and rainbow tables. We got Emmanuel talking about the three decades of hacking, so much covering the book, and another guy talking code boot attacks. So it's a pretty good mix of everything. So we try to bring everybody together to talk about everything about security and try to merge everything or bring everybody under the same roof at least once a year. About how many people are at this conference, and are they all from Brazil? Obviously Emmanuel's not from Brazil, but what other countries are represented and how many people are there? We had about the same number of people that we got last year that were about 80 people total. That's as much as the venues that we got could handle. And most of the people are from Brazil. I want to say everybody, but this year just David, Hikari, and Emmanuel that flew down from the U.S. Well, it sounds like a good time. Are you going to do it again next year? It was fun. You guys can ask Emmanuel later, but, yeah, it was fun. And he was here last year too, so he may be able to give a better view, like an outside view of how it was compared to last year. Are you going to do it again next year? Hopefully, yes. The plan is to do the third edition next year, yes. Anything else our listeners should know about this conference or might want to know even if they shouldn't? Yeah, keep an eye out. We're going to do a little bit of advertisement for next year. It's not going to be like a two-day lead time or a two-month lead time, but we're going to give a better heads-up for people who want to come down. Last year we had more people from abroad. Felix from Germany was here. Nick Farr, a lot of people know, was here. And so hopefully next year we're going to get more people to come down to Brazil and have more fun and hopefully do a two-day conference instead of a one-day gig. Do you have a website we could check out? Yeah, the website is ysts.org. As in you shot the sheriff.org. Yes, exactly. And will the audio and video be available? Yeah, we have the videos on the archives. If you go to the website, you're going to see everything in Portuguese, but there's an English link there. If you click there and you go to archives, we got all the videos from last year on Google Video. And as soon as time permits, once we decompress from the whole craziness that is horrendous, we're going to be posting the videos from this year's talks as well. Great. Are just the audio files available for people that want to walk around and listen to them on their MP3 players? No, but that's something that we could actually do. We could get audio files also. Really good idea. Thanks. Great. Okay, so again for our listeners, if you're interested in looking at that, that's at ysts.org. Anyone else have any questions? So what else is going on down there in Brazil? At this point in time, what else is going on? Not much. Pretty much everybody seems to be ready for Christmas. We have Christmas lights all over the place already, and shopping malls, everybody going crazy with Christmas and Santa Claus. I don't know. We don't have Thanksgiving here, so I guess we want to be less on that and start selling stuff. I guess that's the idea. Sounds very cool. I know it's probably a bit soon to be asking, but any ideas for floating around for next year? For what? I'm sorry? For next year's con? You mean like time frame or when we're going to be doing it? Possibly, or just any ideas you have in mind for things to maybe, for different things to do or some other things. Well, yeah, as I said, we're going to try to do a two-day thing instead of a one-day thing, but like the topics or whomever we're going to do again, this was the first year we actually had a couple of papers. And again, anything security goes. If you think it'd be like a smaller hope slash CCC type of thing, different than other conferences that are more focused on only just technical stuff. Is this a mixed language conference or is it all in Portuguese or all in English? It is a mixed language conference. Most of the people here actually they understand English. Usually we speak slowly. But yeah, we're going to try to get translation as well because this year and last year we didn't have and some of the guys that came from abroad they said, well, that was really cool, but I didn't understand anything that people said. Although some of the speakers and we requested that and some of them actually did it, they had slides in English. So that was pretty cool. Makes it easier to follow, although you're not understanding anything. At least we got here. Makes it a little bit better. Would you say there's a strong hacker presence in Brazil or Latin America as a whole? There is. Yeah, in Brazil there's a lot of activity actually down here. It's quite interesting the way the security community is. It's not set up, but how it grew here. And it's in a maturing phase as far as I see. One of the reasons that, one of the motivations that I had last year to put this together is to try, now of course we're always going to get the differences between all kinds of levels of people, right? The management people and all the underground people of course. It's pretty normal for them to kind of dislike each other, but at the same point it's sometimes they fear whatever they don't know or they hate something they really don't understand. So at least the idea is to make sure that you understand what's happening. But yeah, there's a strong presence across the board, I want to say. From the underground community all the way up to the management folks, CSOs and that stuff. Actually some people that are actually up there understand what they're saying. So what led to the beginning of this? I know you said you have a podcast. Did it all come from that? Yeah, one day we were, I was actually down here because I actually live in California. So I was down here with one of the other organizers and we were doing the podcast for a few months already. I think about, I want to say eight months. Now on December it's going to be two years that we've been doing that. And people really like whatever we do just because we don't have any strong opinions about anything and no one can really fully understand everything that goes on. So we really make fun of each other and just try to make things easy and just open people's minds to see okay, this might be cool or this might be totally bogus or just talk about stuff that happened in the past week in the security community. And people kind of like, everybody kind of liked what we did. So I said well, why not keep, do a conference, a smaller one and keep the same format and that seemed to have worked out. This year people really liked what we did. Sounds good. Where can we check out your podcast? Podcast is, the website is, well it's going to be in Portuguese so if you want to practice your Portuguese it's going to be the website and it's spelled and as in navy, a-o-d-o-d dot com dot v-r. Which is a joke with iPod. Instead of iPod, that means notepad in Portuguese. So as somebody who's lived in both the United States and Brazil, what do you say that, I'm sure you're aware that at least in the United States there's a lot of data breaches in terms of personal data and social security numbers being leaked. Would you say that this is better or worse in Brazil? Which one of those? Like theft of personal information and things like that electronically. Like because of corporate negligence, I guess, mostly. Keeping this type of data where? Sorry, I missed the whole thing. When you hear about banks losing all their customers' information and compromising social security numbers and the like and credit card numbers, does this happen a lot in Brazil as well? It does, actually it does. And it's not only, it's kind of an interesting question because especially here in Sao Paulo, they have to try to avoid tax corruption, I want to say. They're requiring people to kind of force the vendor or whatever store, retail stores, to give out the invoice or something similar to that. And in order to do that, they ask you for your social security number, the Brazilian social security number once. So you show up, you pay, they're like, do you want that? You say yes. So they're like in front of everybody, what's your social security number? So it's kind of like lame. But they also print that out on checkbooks so there's no point. Can that number be used in the same way that it is in the U.S.? Is it used to identify you to things like banks and credit cards? Unfortunately, yes. Yes, that can be used to identify yourself, yes, in the bad way as well. All right. That's interesting. Yes, so it could be. So in our case in the U.S., you don't have that much information while all you have is your address, but that can always change. But at least you might have your SSN on your checkbook because if you lose it or something like that, that's bad. But again, soliciting that in front of everybody in a retail store, that's not good either. But is there a large-scale theft of things like that or is it more small-scale, like if one person loses something or says it out loud? Are there breaches, technical breaches also? Well, yes. So this is the usability type of problem. But, yes, you have the other problems as well, not only of people like insider people working and getting this type of information from banks or from public places and putting on CDs and selling on the street for $10, well, not $10, but this would be more than that. It would be like, I don't know how much that would be actually. But, yes, this is the kind of stuff that you can actually find and buy on the black market, and that's pretty bad. And, of course, people also hack into systems and can get that kind of information. Or sometimes what happened was on the news not too long ago, what they were selling was actually not personal data but credentials to get into databases that you could get access to any personal data. So you've been involved in the hacker communities in Brazil and in the United States. What would you say is the way that in the United States the hacker community has a certain image that people on the street would think about, whether it's demonized or whether it's over-glamorized in Hollywood. Would you say that the hacker community in Brazil has a similar issue going on? From a motivation standpoint, yes. I want to say that, yes, they might get motivated for the same reasons or just for the wrong reasons sometimes, just what they've seen in movies and things like that. But on the other hand, what happens is information technology is just another tool to do bad things. So if you look back when people, like a few years ago, when people were after keyloggers and talking about Internet banking and things like that. Actually, as long as I remember, Brazil started with Internet banking before the U.S. around 1995, 1996. I don't recall seeing anything in the U.S. like that, but I could be wrong. So when people were talking about keyloggers, some banks, they had a virtual keypad, and I think that Brazil was the first one to have that. So people actually, instead of doing keyloggers, they created the malware that would actually take screenshots. So every time you click your mouse, it would say, yeah, you click this and this and this, and you figure out the password. So they're always changing that arm-wrestling kind of thing, technology and trying to find ways around it. But here, just because there's so much money, depends who pays for the things. So in the U.S., people, the user, they might not be that worried about getting identity fraud or something like that, because the bank pretty much is insured. In Brazil, the legality, it's kind of easy, because, let's say, if you go to an ATM, not talking about Internet banking now, but real banking, if you go to an ATM machine and you get robbed inside it, inside the premises of an ATM machine, the bank is responsible for that. But if you get hijacked and they take you there and they make you take the money out, and once you leave, they take your money, then it's not the bank's fault anymore. So they try to translate that to Internet banking. So they say, well, if it was something, if your Windows or whatever OS you're running, it's not batched, and you get hacked, and you're infected by something that is going to cause fraud later, they try to say that, well, it's the user's fault. Like, they do as much as they can to say, yes, the user's fault, it's not our fault, we're not going to pay. So they don't have any motivation to go after the criminals at all? They just say it's your fault and too bad? Yeah, because it's cheaper, right? It's the same thing. How much money are they going to invest to protect the user? They try, and actually, for the past few years, they've been increasing a lot. Some of the banks, they offer for free RSA tokens and things like that. Even for ATM machines, it's painful sometimes. Like my mom, she has her ATM card, she knows her PIN number, and then she has a poor man's RSA card that has like 50 passwords on it. So when you go to the ATM machine, it says, what's your PIN number? After you put the PIN number, it says, type password number 42, and then you go on your card, and you see password 42 is blah, blah, blah, and then you type that on the machine. For us geeks, that would be okay, but for some people, that is not okay. And then coming back to the Internet fraud, what happens is people send, of course, spam, saying, hey, this is your bank, go here, and by the way, type all 50 passwords. And talking to people here, actually, some people that don't understand, they were there typing all 50 passwords on this website just because they thought it was a bank. Like something, type all 50 passwords to verify or to activate your card. It's lame, but it works. That's very interesting, actually. I don't know if a system like that could take off in this country when people seem to have the same four-digit PIN on everything in their life, and they wouldn't be into looking up password number 42. Yeah. Yeah, I've seen that. Visibility is where they say, well, this is a way for you to be safe. Yeah. Define safe. I've seen that in use in Europe for banking, but only Internet banking, not for ATMs. So, you know, it makes sense because you could be accessing it from any machine as opposed to the machine they control, but I think it would be maybe a little overkill for ATMs, I don't know. I don't know. Yeah. The other thing they do here as well is integration with cell phones as well. So when you go to an Internet banking website, assuming you're in the right place, they ask you to register your cell phone. So for some transactions, actually, you have to send you an SMS, and you have to verify whatever they say to buy SMS. But again, the same way they have different ways to protect, you have other possible attack factors. Right. Just go. All right. Well, thanks, Luis. Will we see you in Berlin this December? Hopefully, yeah. Hopefully. Everybody's talking about going to CCC, so it's not my arm twist, I guess. All right. I have some Club Monte there. All right. Well, thanks a lot, and sounds like it was a good conference. Okay. Hope to see you guys here next year. All right. Thank you. Take care, guys. Bye. Bye. All right. That's Luis Eduardo. We were just talking to the coordinator of the conference here in Sao Paulo, Brazil. Actually, I just wanted to ask Luis one or two other things concerning well, I think it's great to talk to people down here and see the interest level that people have towards the hacker history, the hacker world. And the one thing, though, that most of them have not done is travel to the United States to become part of something like HOPE. And Luis, by the way, is one of our coordinators at the HOPE conferences. I'd like to ask Luis, is there anything that he thinks you can do to get people to come to the U.S. and take part in the hacker community there? Well, number one is get a visa. Sometimes getting a visa is a problem. So... And it actually became a problem for people from the U.S. to come to Brazil as well because of reciprocity. But I think what a real example is, a few years ago, I tried to get my parents to go visit me where I live, and they... And I was living there for a few years already, and they simply got turned down because the person who was processing their visas simply didn't understand that, that they are retired, they have no tax return forms or actually the tax return because they're exempt of that, and that was seen as a bad thing. So if a person that has worked all their lives or if people who have worked all their lives and stuff like that cannot make it to the U.S., imagine somebody that is starting as a security professional or a hacker or just wants to go there to join a conference or other conferences, and they're going to say, what are you going to be doing there? Like, if you say, I want to go to Disney World, it was already really hard. You say, yeah, I'm a hacker. I want to go to a hacker conference to network and meet cool people and learn cool stuff. That's going to be even harder. I don't know, maybe creating a special visa type would be a good idea, you know, meet one or something like that. Okay, thanks, Luis. Actually, I also want to remind people we have CCC coming up in Germany in Berlin in December of this year. Go to ccc.de for information on that hacker conference coming up. But we have something exciting to announce for next year. I believe the phrase this time is HAR. Yeah, HAR. I heard something about that. Hacking at random. What do you know? Do you have something with you? I have it here, if you don't. It's another conference in the Netherlands, I guess, hot on the tails of last year's CCC camp, and four years ago is What The Hack. And it's HAR 2009. So, looks interesting. And HAR, of course, stands for hacking at random. Of course. And this is scheduled to take place August 13th through 16th of 2009. And it's taking place... Does anybody want to try to pronounce this town? Or are you going to leave it to me? I think it's your job. Yeah, you can do it. All right. Vleerhouten. Hey, I think that came out all right. I think people are better. Vleerhouten, Netherlands is where that's going to be taking place. For more information, go to HAR, H-A-R 2009 dot O-R-G, and you'll find out everything there is to know right now. It's about an hour and a half from Amsterdam by train because, of course, you can take a train to tiny little towns in Holland. And it looks like they've got a program committee set up, and the planning is starting. And planning is starting. And we even have more exciting news than that. It turns out there's going to be a hacker camp right... Well, I want to say right here. Right there in the United States, where you guys are, next year as well. This will be taking place in Washington State, I believe, sometime during the month of May. It's going to be called Tour Camp, and it's organized by the same folks who bring you TourCon in Seattle and San Diego. And we'll have more information on that with specific dates and details and ways of getting involved as we get them. But that's exciting news to think that it's actually going to happen in the United States, a hacker camp. I never thought I'd be able to say that, but it's actually being organized, and it looks like it's going to be really cool. I talked to the coordinator while we were both down here in Sao Paulo, and the planning is really proceeding nicely. And this could be on par with the European hacker camps. For anyone who's never been to one of these camps, I really highly recommend them. There's something unique for sure. It's really different when you kind of take it outside. I don't know how to describe it, but it's really nice. So if you can't make it to the Netherlands... Nice phrase there, take it outside. But yeah, I guess that does add something to the whole hacker world when you do that. Yeah. Okay, we have all kinds of other bits of information that have been sent to us by our listeners that we've uncovered ourselves. One thing, I'd like to just mention this because we were talking about this last week, the .gov.gov site, which is, I guess, so the clearinghouse information on .gov sites. Our friend RiskTaker writes in to say the website at .gov.gov, which, by the way, those of you who wanted to get there, you spell out the first .gov, P-O-T-G-O-V, and then it's actually a period G-O-V once they get there. That website mentioned by one of your callers is inaccessible from my German IP address. However, from my U.S. shell account, it works fine. So it would seem that not only do you have to be a government agency to obtain a .gov domain, but you also have to be using a U.S. IP. And I tried that from down here in Brazil, and it does not work down here as well. So I guess you have to be in the United States or using a U.S. IP in order to reach that site. Have any of you guys visited the .gov site? That's really boring. Apparently it costs $150. In addition to being a government agency, you have to pay $150 to get one of these domains. Go ahead, Bernie. I'm sorry. There was some controversy amongst us as to how certain .gov domain names can legally exist. For instance, last week I mentioned rnc.gov. It was mistaken. It's actually gop.gov, which is a common abbreviation for Grand Old Party, meaning the Republican Party. gop.gov is a domain name with not a government agency, yet it has blatant political information on there about the Republican Party and putting down other parties. We're kind of puzzled as to how this domain name can legally exist. Change.gov exists, and he's not president yet. True. But if you look at the protocols for registering a .gov domain name, I can't find any way either of these organizations can qualify for one. But I guess it's who you know. Change.gov, by the way, spammed me today. I had sent a week or two ago. They have a form where you can send your suggestions, your policy suggestions to the president-elect, so I did that, and I didn't get any substantive response to my email, somewhat unsurprisingly. But apparently now I'm on some mailing list where they tell me to go watch videos about things I don't care about. It's very strange. I don't know. I think it's a difference between someone spamming you and you emailing them and then sending you something back that you don't want. I did not opt in. I did not opt in to any Change.gov announcements mailing list, that's for sure. Were you given an opportunity to do that? Oh, you might have, just by sending the mail in the first place. I don't know. I haven't gotten any mail from them, I'll tell you that. If you want change, then you have to opt into our mailing list. You might be happy to know that they actually took down that form, but most people that were talking about that were kind of upset because they were like, you don't care about my concerns. Maybe they're just protecting them from their spam. I don't know. Well, I mean, I know they don't care about my concerns, but if they're going to pretend to, they could pretend more effectively. Yeah, and on .gov, I'm sorry. Interesting surveillance stuff that's going on in the news lately. Did you guys hear about this story? It was actually on the front page of the Times. This guy that was accused of murder, in fact was locked up for murder, has been released because of his MetroCard. That's right. His lawyer decided to take a look at his MetroCard and discovered that it backed up his alibi perfectly, saying that he had gotten on a train at one point, gotten on a bus at another point. If he had done all that, there's no way that he could have committed the murder. And the MetroCard is being hailed as a hero here. It saved a guy from going to prison. It's something incredible, and it's obvious that what we need is more surveillance of this sort, more ways that our whereabouts can be tracked at every moment so that when we don't commit murders, we can prove it. Now, was this a paper ride thing, or was it a credit card? Did he buy it with a credit card? Because I'd be curious. It was an unlimited ride. It wasn't when he bought it. It was when he used it, and it was an unlimited ride card, and it backed up. In fact, they have a PDF on the New York Times website. You can look at the printout. It's something you can't do for your own card. You can see his card and see everywhere he went, when it was used, and all the internal codes that the transit authority uses to track these things. Because I know that they track it to some degree in the fact that they can, if your card is stolen or if somebody buys unlimited ride cards with a credit card, they can shut it off. But I didn't know that they kept such extensive records. Well, apparently, this card was linked to him with the very simple means of getting his wallet that the police took when they arrested him, taking the MetroCard out, and noting the serial number. It didn't require anything too sophisticated on that end. Right, but for those unfamiliar with the MetroCard, it's a completely generic card of which several billion exist, and I'm not sure exactly how they could tie it to him in the sense that it was him that used it to take the rides that are on it. Well, one thing in the article, the headline and most of the paragraphs in the article were about the MetroCard, but sort of buried in this article, they did mention that one of the things he did that evening was go to a check-cashing place where they took his photograph when they cashed the check. So there seems to be a lot of evidence that he was doing what he said he was doing and not what the police said he was doing. And it should also be pointed out that he tried to tell the police to look at his MetroCard when he was arrested, and they did. They took it out of the wallet and looked at it, and then they put it back. I think what he meant was that, look at what was on the MetroCard, and they might actually find that it backed up his story. Now, the first thing I suspected when I read the story was, yeah, he could just plan all that in advance, hand it to somebody, and have them go and do all this and then give them back the wallet before he gets questioned. It's a lot of planning to do. But the thing, I think the icing on the cake is the fact that he went to that check-cashing place and his photo is right there. It's hard. Trust me, when you're committing a crime and you want something to work just exactly right, it's hard to get everything to line up perfectly like that. Almost never works. I'll keep that in mind. Yeah. Now, as far as tracking and surveillance and things like that, there's a piece on MSNBC earlier this week that basically talked about how paranoia, in all places, England, is on the rise. Irrational fears may be a lot more common than thought, according to surveys. Paranoia, once assumed to afflict only schizophrenics, is apparently a lot more common than previously thought. According to British psychologist Daniel Freeman, nearly one in four Londoners regularly has paranoid thoughts. Emanuel, the three and four who don't always have, who don't constantly have paranoid thoughts, are none of them in the government there? Because there doesn't seem to be... I don't think they went that far. I'm not sure if they gave that specific information. But what they found out was more than 8,500 adults, they found that 21% of the people thought there had been times when others were acting against them. First of all, I don't think that's paranoid at all, because I think people are acting against us all the time. But then I'd probably just lump me into that 21%. Now, another survey of about 1,000 adults in New York found that nearly 11% thought other people were following or spying on them. The thing is, you pick a city like London where you have cameras every few feet and all sorts of surveillance going on constantly, how can people not be paranoid about being watched and followed all the time? This is what I don't understand. If only one-fifth of the people in the United Kingdom or in London think that there's this constant threat to their well-being, how do you explain the surveillance society? If 80% of the people feel safe, what are all these cameras for? Well, that's another way of looking at it, I suppose. Maybe the cameras make them feel safe. But the situation that they have over there, when they're constantly being spied upon and constantly being told that there's danger, of course people are going to feel vulnerable. Of course they're going to be upset and paranoid. That's just what they're being taught. Is this conspiracy theory paranoia, or is this just paranoia, mild paranoia? I think it's just paranoia. I don't think it's that, to be honest. But I guess what they're trying to make it sound like is that they're going to be wacky conspiracy theory type people, but actually it's a normal response to very stressful situations created by the authorities. I'd like to add something to this. One of my favorite quotes is from the character Dr. Johnny Fever, who said, when everyone's out to get you, paranoia is just good thinking. Dr. Johnny Fever said that, eh? Yes. He's a true hero of mine. All right. Well then, any other news in the news? Oh, there's plenty. There's plenty. Here's something that came out of Canada. This is kind of an interesting story that was forwarded to us. Canadian pilots are not happy these days about the increasing number of laser beams being pointed at their cockpits. That's right, Transport Canada statistics regarding the number of reported incidents of laser beams being pointed into the cockpits of airplanes have some pilots concerned that dangerous activity is becoming a growing trend. We don't want this to become a bigger hobby, a bigger stupid hobby. Serge Bilyeu, spokesman for the Air Canada Pilots Association, Transport Canada's latest Civil Aviation Daily Occurrence Reporting System reports. What a sentence that is. Transport Canada's latest Civil Aviation Daily Occurrence Reporting System reports show that 62 incidents of the bright lights being pointed at the cockpits have been reported so far in 2008. Six of those incidents occurred at Montreal Trudeau International Airport in just the last week. Other incidents have been reported in Winnipeg, Calgary, and Toronto. According to the reporting system, a total of 101 laser beam incidents have been reported since 1997. Basically, they're saying, or Bilyeu is saying, we want to put people on notice that this is dangerous, not funny, and you're potentially playing with the safety of people. Shining bright lights into the eyes of pilots can potentially be blinding, he says, and it's especially of concern since many of the reported incidents have taken place during landings. When we're doing takeoff or landing in an airplane, it's quite a busy time, and we want to be full up dealing with the task at hand. There's no time to get some Yahoo! flashing laser lights from the flight deck. It seems like common sense. They say, though, that this is probably the result of the powerful green light beams that are used by astronomers. They can travel several kilometers. They're used to point to stars. According to the president of the Montreal branch of the Royal Astronomical Society of Canada, Andrew Fizekas, they can cut through thick cardboard. You can light a match across the room just pointing this type of laser. Now, I'm not sure what he meant by that. You can't really light things with these lasers. Does anybody know what that means? Yes, you can. There are some, believe it or not, they're not legal for purchase in the United States, but there's some Chinese manufacturers who are making very high-power laser pointers that you can order from the United States. You can search online and find these pretty easily, and some of them are several hundred milliwatts, like 500 milliwatts, 600 milliwatts, which is enough to cut through, and a friend of mine that came to Philadelphia and visited me with one of these, and we were able to pop a balloon with one of these laser pointers and cut a plastic bag with it. You can also ignite the head of a match. So these things, if something like that were to hit your retina, you would be very seriously permanently impaired from a visual standpoint, or basically blinded. Now, I don't think the pilots are in danger of being permanently blinded by this, because the time the laser beam reaches the plane, the power has dissipated a lot, but it's still dangerous from a standpoint. It's like a camera flash effect. You're sort of dazed and blinded for a few seconds, and when someone's flying an airplane with a bunch of people on it, that's not a good thing. Especially when they're landing. Yeah. Basically, even if it doesn't cause permanent damage to the pilot's eye, it's equivalent to that guy who likes to sit in a lawn chair and have a bunch of balloons, bring them up into the sky. If he does that right in front of a 747 that's trying to land, it's not going to hurt someone's eyes, but it's certainly going to distract the pilot and cause a potential disastrous effect. So if you have a laser beam out there, be careful where you use it. Don't point it up at the sky. You must know that there's nobody else up there. All right. We got some mail from last week's show concerning... We were talking about virtual worlds and some of the insanity that's going on in virtual worlds. I think I had a little tirade about that myself. Well, basically, this writer, I tend to say I've noticed a few comments that have emerged on the show that indicate somewhat of a misunderstanding as to modern cyber culture in various areas. For a group of people who basically literally help create that culture, I think it's quite interesting that you are now throwing your hands in the air in bemusement at these crazy kids. The first comments I noticed were about the Internet Movement Anonymous and their protest against the church of Scientology. There's a lot of misinformation and misunderstanding going on about this quote-unquote group. I would hope that you look into it further as it is quite an interesting phenomenon that could not have occurred as readily without modern technology and Internet. I'm not kidding. I believe we have looked into this quite thoroughly, have we not? Very thoroughly. We actually had them at our conference. Yeah, at our conference. I think maybe this writer did not listen to the earlier shows where we talked about this. We know they're not a group. We know what these individual people stand for and about the fight against Scientology and the fact that it is significant. Would you say it's a significant thing? I would say it's quite significant as they've shut down many of the churches throughout the world, so they're obviously doing something. Yeah. Secondly, though, there is this issue about virtual property and how ludicrous some of you think it to be, particularly Emmanuel. Again, I just find it interesting that these ideas are so readily dismissed when the concept of virtual environments are so central to the hacker mindset. Although at first, paying for clothing in Second Life or something like it may seem ridiculous, the psychological impact that it has on the individual is no different to buying clothes in real life. It is about the creation of identity and place within a community slash society. It is very clear that those who spend a lot of time within virtual environments feel this need to create identity just as strongly as anybody in the real world. Therefore, their transactions are incredibly similar in nature. Sure, there is an issue of tangibility of the items being bought, but remember that for the most part these are microtransactions. You aren't spending $100 on a shirt, but rather 10 cents or something like that. Customizability is important to people. Identity is important to people to the extent that they will spend $10 to $20 or more to get it. Now, regarding the gifts on Facebook, paid gifts are pretty much dead in the water now since there are literally dozens of free applications that do the same thing. But the concept of it is indeed an interesting one. Why would you pay for something like an icon and by pay we're talking about only a dollar or so because you want to show the person that you mean it. It isn't just a flippant online interaction. You put your money where your mouth is, so to speak. Also, take note that many of these are done for charity, so there's a secondary reason there, too. I realize this email is way too long to be used for the program. Ha! You're mistaken there, too. But thank you for taking the time to read through it regardless, and I hope that some of the issues can be raised at some point in the future. Are you losing touch with the future? For so long you were at the forefront of technology. I'd hate to see it turn into a back-in-my-day situation. Signed, Dear Lucis from London. Now, I know, Rob, you had some very interesting comments on this whole tangibility issue and how much things cost in the virtual world. Anything you'd like to reflect upon here? I did, I did. You guys know I can get rather long-winded about this subject, but condensing it for the time we have left. Using Second Life as the example, as it is the quote-unquote economy that's going on in there for things like virtual items, virtual clothing, and also virtual land, I have a big problem with the way that it's been implemented. Basically, it's DRM-based, it's not user-friendly, and it's not quite honest with what it's doing technically, since anything you can buy is basically an image file and some 3D mapping data that is downloaded to your computer every time you use it. Basically, what I think we're seeing with companies like Linden Lab, who run Second Life, and Blizzard, who runs World of Warcraft and other things, reminds me a lot of companies like America Online and CompuServe back in, say, the early 90s, where you had these closed systems popping up all over the place, which each on their own could be interesting, but it's just very contained and it's very controlled by those that are operating them. And my attention has been diverted from things like Second Life to there is one project called Open Simulator, which is an open-source implementation of Second Life that anybody can run and anybody can start up a server and connect it to others, and the ultimate goal is to create sort of an open protocol with which you can freely create what you want, you can express what you want, you can have all the individuality you like without paying one company for the privilege. And I think that's where the future of such things lies. I don't think we're losing touch with the future. I think we're just taking the first baby steps into such a future. Well, you know, what's interesting is that what this writer says, that, yeah, there's no harm here because either microtransactions, 10 cents each, a few pennies, but that's not where it stops. There are so many more examples that go well into the realm of absurdity. I'm not in this world myself, and I do think it is a bit crazy, but aren't there people paying huge amounts of money for virtual property in places like Second Life? There are. There are people who now make livings with stuff like that. There's one very prominent person in China who has basically become the Second Life equivalent of a land baron, just buying up and renting out because people will actually rent this land to each other, buying and renting out land that all exists in this one company's servers. And basically, if things were opened up enough to where anybody could freely create, then there would be no market. Right now, what's called a market is just something completely artificially maintained and influenced by the company that's running it. And on top of that, the fact that they control the whole thing means that it doesn't develop very quickly. I haven't seen much change in the software in ages. I don't use it regularly, but it's not very good software to begin with. Yeah, and I've dabbled in the whole land-owning thing and content creation. I'm actually kind of active in some of the free content groups that exist within Second Life, which are neat ideas and everything, but at the end of the day, it is all contained in this one computer in, I think, California. Well, I have a question about this. Yes. If I was to go to this land baron's space in cyberspace, in the virtual world, whatever, and I was to destroy his entire property, raze it to the ground, burn it, whatever it takes in the virtual world, and it wasn't able to come back, and I just somehow broke in and was able to do this, would I be prosecuted in the virtual world or the real world? The funny thing about that issue is that when you own, quote-unquote, property in Second Life, you control what can happen on it. You control if other people can bring items onto it, if other people can execute code in their scripting language that they have for the behavior of these virtual items. So nothing can happen on your land that you don't want to. You can't go onto somebody's land and destroy it. They can just limit what you're able to do and kick you off, basically. How about if I hack into the machine that it's all hosted onto and erase everything? What happens then? That would be interesting. But you do realize that people spend their money on all kinds of silly things that aren't virtual. I mean, I'm not exactly convinced that buying a pixel t-shirt is any worse than buying some useless tchotchke that physically exists but serves no purpose. I'm not really harmed by this virtual economy. Well, you're not harmed. The people that are throwing money away literally because they're completely obsessed with this, it's the equivalent of throwing away money on lottery tickets, except you don't even get the ticket here. You're spending money literally on nothing. In this day and age where the economy is really going down the crapper, I think we need to inject some common sense into the equation and realize that, yeah, it's fun to play games and things like that, but let's not inject real life into this any more than it has to be. I mean, there was a case just this last week where these people are getting divorced now because somebody was caught cheating in the virtual world with another avatar. I thought there was a murder. I mean, how crazy is this going to get? There's going to be murders going on in the virtual world and people are going to go to real prisons. There was a virtual murder involved, I thought. Didn't she cheat? That was another case. Oh, that was a different case. Yeah. Oh, my. Yeah, somebody signed in as somebody else and quote-unquote killed their avatar in, I think it was a Japanese game. I'm not sure. They didn't get charged for murder. They got charged for hacking that. That's good. What was in the case we were talking about last week about a woman who was divorcing her real life husband because she caught him, or she caught his avatar in a virtual world having sex with another avatar of apparently a woman, but nobody knows for sure. Go ahead, Bernie. Well, Luis has a local perspective on this. I'd just like to make sure he gets this in quickly before we go off tonight. Hang on. Luis? No, what happened here in Brazil probably a year ago was totally the opposite. Some guy got kidnapped because he had lots of points and he was bragging to all his friends and stuff like that. He had whatever virtual money they get on Second Life. So they kidnapped him, and in order to return him, he had to give away whatever he had. That's all. The thing about the Second Life money is it's freely exchangeable for actual money, so that's where the heavy issues are brought into play. They physically kidnapped him for his virtual assets. Yeah, it was a real kidnapping. A real kidnapping for virtual information. That's brilliant. I don't think I can make the argument anymore how I'm saying this. Wait a minute, though. But as soon as the guy is not kidnapped anymore, can't he just call the content provider and say they stole my virtual assets? I don't understand. And they just shut it off? It doesn't make any sense. Anyway. I was wondering if the case we were discussing last week where there was virtual adultery going on, whether they'll end up having a virtual divorce and whether he'll have to pay her virtual alimony. I think this has gone on long enough. Luis told me, by the way, that he didn't choose to pursue reversing it out of fear of the real-life consequences. I guess that makes sense. Do we have any more time? We're pretty much out of time. I don't think we have time for phone calls, if that's what you're asking. Oh, let's do that. Next week we'll certainly take phone calls. Our email address, as always, is oth at 2600.com. We love hearing from our listeners, whether it's criticism, critique, whatever. I guess maybe we should close off with some bit of information. Bernie, you dug up the Secret Service codenames for the Obama family? Oh, I did. Do you want me to read them? I have them here. Maybe they're more fun to read than the classified information. It's widely known that Renegade is Barack Obama's codename. And let's see if I can remember the other ones. Does anyone else have them in front of them? Yeah, right here. Michelle Obama is Renaissance. Malia, am I pronouncing that right? Malia is Radiance. And Sasha, anyone want to guess what Sasha Obama's codename is? Ren and Stimpy. No. I'm going to guess it starts with an R. Has to start with an R. Starts with an R. And it's the key to a major film. No? No. The answer is Rosebud. I thought you were going to say Red Rum. That would be a good one, though, wouldn't it? It's interesting that the information comes to you across international borders from Brazil and hopefully didn't flag too many secrets. All right. Well, I think that's it for us then tonight. And we'll be back again next week, same time, same place. So good night. Good night from Brazil. Good night. Hello? Hello, Floyd. Hello, baby. Why did you wait so long to call? Hello, baby. Why did you wait so long to call? Well, I've been so sick and worried Ever since you left last fall Please, please tell me Why did you stay away so long? You know I've been so lonesome Staying here all alone Staying here all alone Well, I'm just so sick and worried Baby, please come back home Baby, please come back home Won't you call again tomorrow As for operator 210 It's worth fifty million dollars To hear that sweet, sweet voice again And don't worry about the charges You know I'll take care of it on this end You're so sweet, Floyd. I'll call you tomorrow. Bye. Bye.