Dutton, she says she has some hope that the incoming Obama administration might overturn the Anti-Terrorism and Effective Death Penalty Act, or ANPA, a 1996 federal law which has made it much more difficult for Troy Anthony Davis and inmates like him to challenge their death sentences. The law restricted federal court review of judgments made by state courts and established shorter timelines for death row inmates to introduce new evidence. For FSRN, from Atlanta, I'm Andrew Stelzer. And you're listening to radio station WBAI New York, the time is 7 o'clock, time once again for Off the Hook. This is WBAI New York, the time is 7 o'clock, time once again for Off the Hook. And good evening to everybody, the program is Off the Hook, Emmanuel Goldstein here with you on this Wednesday evening. I don't know why so many people are here tonight, but we have a full house. Let's start over, look, not Kevin's over on the other side of the room. Hello. How you doing? It looks like Dot Rett there. Hello. Rob T. Firefly. Good evening. Red Hacked. Yep. And Voltaire, how you doing? Hey there. Jim, welcome again. Hello. Actually, I'm going to introduce you in a minute. Lexicon's over on the other side of the room. Say hi. Hello. And Mike, all the way over behind the microphone. Who's just waving. Yes. Well, he's going to move into where the microphone is now. And Bernie S. down there in Philadelphia. Greetings from Philadelphia. We've got a full house. We have a full house. And we have a special guest. Tiffany Redd joins us again. Hello. And you can feel free to move that microphone closer to you, so you don't have to lean over. And we have all kinds of things to discuss. First, I'd like to remind people here a little public service announcement for people that listen to the radio station and are local to the radio station. Come join us for the Holiday Book Fair. It's taking place from December 3rd. That's today. December 3rd through December 7th. That's a few days from now. Hours are 3 to 8 p.m. That's today, tomorrow, and Friday. In fact, you have an hour to get here. And Saturday and Sunday from 12 to 6 p.m. Holiday Book Fair. All kinds of cool books that you can pick up here at the radio station. Our address is 120 Wall Street. That's in New York, New York. And again, come on down up until 8 p.m. Take advantage of holiday books. Annual thing we do here at the radio station. Okay. We have all kinds of interesting, fun, enlightening news stories and analysis. And we'll be trying to take phone calls a little bit later on as well. Let's see. What's going on with the Pentagon? There's all kinds of mayhem as always. Apparently, Russian hackers have penetrated the Pentagon computer system in a cyber attack. It's an electronic attack that was so serious that Admiral Michael Mullen, he's the chairman of the Joint Chiefs of Staff, briefed President George W. Bush and Robert Gates. That's how serious it was. He briefed them. Defense officials told the Los Angeles Times that the attack struck computers within the U.S. Central Command, which oversees Iraq and Afghanistan, and involved malicious software known as malware that permeates a network. This one was significant. This one got our attention, said an official speaking anonymously because he was scared of the script kiddies that pulled it off. Officials did not disclose the extent of the damage and would not elaborate on the reasons for believing the assault originated in Russia. The Pentagon and other U.S. government departments face repeated cyber attacks, especially from Russia and China, either from individuals or indirectly from those countries' governments. So interesting. Also, they say here within the past 18 months, Russia has been accused of orchestrating major electronic attacks on neighbors Estonia and Georgia. But I seem to recall reporting here on this particular radio show that the attack in Estonia was actually the result of a bored college student in Estonia doing that, and it wasn't anything to do with Russia at all. Am I correct? No, that's the thing. But it was reported so frequently that Russia had done it that probably whoever was writing this story didn't have the time to do all the research and learn that Russia had nothing to do with it. So the story has become, basically the fictional part has become the truth now, the way it was reported at first because it was said so many times that even though the facts point to something else, we're just going to remember it the way it was reported the first time. I have no idea, obviously, who was responsible for whatever is being, I would say described, but they're not even describing. Alex Spilius in Washington. Alex Spilius in Washington wrote for the UK Telegraph, the newspaper. That's who wrote the article. He's responsible for saying that. I have no idea who's responsible for the acts described in this story. No, but he's responsible for accusing Russia of attacking Estonia. I'm just saying if it turns out it was someone else, we'll probably forget about it. Well, that's true too. But for now, just remember Russia has attacked Estonia. Russia has always attacked Estonia. Nothing else will ever be. That may actually be true. Yeah, I'm talking about in the cyber world. Voltaire. I think we should reinforce the fact that even these government people aren't claiming the Russian government per se. No, they're not. They're saying it comes from Russian-based computers which might actually be controlled someplace else because they're probably zombies. Yeah, maybe from China. Zombies. Okay, who wants to describe what zombies are for our listeners that might be really in a panic now that aren't familiar with these little terminology things? Well, what happens is when a dead computer bites another dead computer, it becomes a zombie. Oh, that's a vampire. Yeah, that's a vampire process. RedHack, I'm going to pick on you because you're listening to your iTunes thing. You just got an iPhone and you can't even stop playing with it during the show. Sellout. You're having fun with that, aren't you? Traitor. It's okay. I don't judge you. I just mock you. But tell us about zombies because I think you're the most qualified right now to talk about that. Like zombie PCs? Yeah, sure. Zombie PCs. Or zombies like the ones that exist in the Caribbean. Which do you think? Haiti, rather. There are zombies in Haiti? Yeah, yeah, yeah. Tell us about those. I'm curious. Really? No. I don't think Jim wants you. I have no idea what you're talking about. Well, the whole zombie thing actually originated from that part of the world in that there's actually, I think it's the poison of the puffer fish or something like that and it's used to actually make people like unwilling slaves. Jim's shaking his head and I believe him because he was on Jeopardy and not me. Let's talk about the other zombies because we don't have that much time. I'm sure we'll be fielding a lot of phone calls about this if we continue. So what's the question? The question is zombie computers, zombie PCs. What are they? Yeah, tell us what they are so that our listeners don't panic and think they're real zombies out there. Sure. They'd be machines that have been compromised in some way and usually they'd be part of a botnet. So the computer has been compromised by a virus or somebody installed some malware or something like that and an attacker would have control of it and usually how they're controlled is the PC will sign on to say an IRC channel or something where it will wait for commands. And so, I mean, yeah, your computer at home could be in a botnet for all you know if you're on broadband. Botnet. Okay. Well, might my computer, my personal computer be a zombie without me knowing it? Yeah. So how would I find out? How would I ever know? Find out if there's any malware on it. Okay. So you run some kind of malware scan and see if your computer has been infected. You can just install Linux on it. Yeah. You know, Linux is not the answer to every problem there is. I see so many people having difficulties booting up Ubuntu or something and not being able to get something to work. I remember actually years ago being at Linux World and there was a booth for a Linux virus scanner. They couldn't tell me what it did though. They installed a virus and then scanned it. All right. Let's get back to the Pentagon because they're always a source of entertainment. The Pentagon has banned, at least temporarily, the use of external computer flash drives because of a virus threat officials detected on defense department networks. While defense officials would not publicly confirm the ban, messages were sent to department employees informing them of the new restrictions. As part of the ban, the Pentagon was collecting any of the small flash drives that were purchased or provided by the department to workers according to one of the messages. That was somehow intercepted. Now workers are being told there is no guarantee they will ever get the devices back. It is not clear how long the ban will last. Pentagon spokesman Brian Whiteman, or Whitman rather, would provide no details on the virus, but he described it as a global virus that has been the subject of public alerts. This is not solely a department problem. This is not solely a government problem, he said, with increasing panic in his voice. The Pentagon has acknowledged that its vast computer network is scanned or probed by outsiders millions of times each day. Now, are they counting web hits when they say that, I wonder? I doubt it. They're probably counting port scans. Okay, well, millions? Millions of times each day? Could be. I mean, if someone was, well... I mean, I can only do it a thousand times myself, but I guess... I mean, if I had to guess... Do you think there's a thousand people doing it also? If I had to guess, they're probably just checking either packets coming into their network on the router level, or maybe they have like a... What are they called now? Like a black hole? I don't remember the term now. Basically just a machine that shouldn't be getting packets, or an IP that shouldn't be getting packets, but it is. Interesting. Well, Bernie, go ahead. I just said the word honeypot. Maybe that's what he was thinking of. Maybe they're not smart enough to set up honeypots at the Pentagon. I think they are, but for our listeners, again, describe the honeypot to us. Well, it's a server designed to look like a really important server with all kinds of important files that an attacker might want to have, but it's really a spoof of one server. It's simulation. And you set that up so it attracts all the attacks, as opposed to the servers that you really don't want to attack, and then you log all the information going to that one. So it's just sort of a diversion attempt. Okay. All right. Continuing on this subject, or on the subject of governmental things, we have some feedback to what we were talking about last week. We were talking about GOP.gov, the Republican Party. And Stephen writes in, saying, four points. Yes, every member of the House Republican Caucus is elected with all the caveats about the legitimacy of bourgeois democracy and the verifiability of voting in the U.S. So by the standards you read on the air, GOP.gov is legitimate. Does this make sense to everybody? That's legitimate? We disagree? Mike? I mean, what are we going to do about it if it's not legitimate? Well, we can just say it's illegitimate. It's hardly the worst thing the Republicans have ever done. Well, no, that's true. We just want to make sure that .gov is being used properly. That's all. We could file a complaint. We could file a complaint. We could do that. Number two, do the Democrats have such a site? The Democratic Caucus in the House is at www.dems.gov, D-E-M-S.gov. It took me ten seconds to find it. Well, thank you, Stephen. None of us could find it that quickly. In fact, none of us found it before you told us about it. So thanks for letting us know that. The domain name even looks like the Republican one. Okay, well, I looked at democrat.gov and democratic.gov and, I don't know, all the other initials I could think of, but didn't find it. Number three, to my knowledge, there is no single legislative or other elected body in the U.S. where the Green Party, Libertarian Party, etc. form a caucus. If they did, then for what it's worth, they too could have a .gov site. It might be more interesting if they did. And number four, are you kidding? Is this topic worth any airtime? With a huge range of communications and information technology issues, technical, policy, corporate, political, cultural, I'm somewhat disappointed that you went on and on and on and on about the .gov domain. Sort of ridiculously pointless topic, like the extra tone for cell phones to Switzerland, cell phone calls to Switzerland, or whatever story I'm listening to right now. Thanks for considering my comments, Stephen. Well, Stephen, yes, in fact, we do consider this worthy of airtime. It's kind of what we do on this particular radio program. In fact, just for you tonight, we introduce the new feature, .gov of the week. Yes, in this particular feature, we focus on a .gov site and beat it to death until you never want to hear about it again. And this particular time, we have the site, which I'm sure many people have not heard about yet, but you will. And you're encouraged to visit the site. Oh, that's so pleasant. Talking about GovGav, have you ever heard of GovGav? Have you ever heard of GovGav? What's so funny? Something funny? I missed a joke. GovGav, yes, your U.S. government blog. I'm not kidding. This actually exists. You can go out there and find these things. Let me read you the press release about this. A new general government web blog or blog has been launched by the U.S. General Services Administration, GSA, to further improve citizen access to official government information and services. Americans clearly love the idea and practice of blogging, said GSA Administrator Lurita Doan. The creation of GovGav is another step forward in improving public access to government information and services. This blog will be an invaluable resource in helping us keep citizens informed of the many opportunities and programs offered by the U.S. government. Now, available at GovGav.gov, the blog features daily posts from a GSA team of five managers, each drawing on his or her professional experience as a government informant. Oh, wait. I read that wrong because I've seen that so many times. As a government information expert to help spotlight U.S. government information and services of greatest use in Americans' daily lives. Some 57 million Americans are active through the blogosphere. Are you active in the blogosphere? No, there's five people working on this. They probably make, I don't know, at least 40 grand a year. So this website is costing the taxpayers at least a fifth of a million dollars a year. Yes, but Mike, what you fail to realize is that GovGav.gov is a use of the .gov domain, which is not all serious and poker-faced. It's a little bit more entertaining and friendly. So people who think the .gov domain is just all serious, now you have something else to look at. Rob? Yeah, this is run by the GSA directly? Mm-hmm. Wow. I should point out that the GSA are also the ones who administer .gov domains. There you go. So it was them that decided that they themselves were worth a .gov domain for this. Redhacked. I like how the government is trying to jump into the 21st century now. Yeah, they're trying to jump into the 20th century. With blogging, but they couldn't bring the name with it. What, GovGav? You don't like GovGav.gov? It rolls off your tongue. Yeah. Then you can pick it up and say it again. Our daily post will cover a wide range of topics from what to do when an airline loses your luggage. Why do they put that in quotes? Who would ask a question like that? What to do when an airline loses your luggage? What does that have to do with the government? Didn't the airline lose your luggage at one point? Did you ask what to do when the airline loses my luggage? No, you didn't. If you knew about GovGav, maybe you could have done something about it. I actually didn't have my luggage. I'd given it to somebody else. Aren't you supposed to not do that? Yeah, I think so. I think it went through Canada. I don't know. It got lost somewhere. It wasn't with me, though. You can submit a recipe to the Library of Congress cookbook. I don't know why you'd ask it like that either. I didn't even know they had a cookbook. Readers can respond directly by leaving a comment. GovGav is a product of GSA's Office of Citizen Services and Communications, OCSC. We all know that. It will key off conversations. I don't know what that means. It will key off conversations in the blogosphere and draw on the resources in OCSC's family of websites, which is USA.gov, the official web portal of the U.S. government. Do you know that, USA.gov? Pueblo.GSA.gov, the public's trusted source of consumer information for more than 35 years. Actually, that's not true. That's a lie. How can Pueblo.GSA.gov be the public's trusted source of consumer information for more than 35 years when the Internet hasn't existed for that long? They were ahead of their time. Yeah, you see, they just phrased it badly. And ConsumerAction.gov, the federal site that helps with consumer problems. What we're focusing on today, this particular aspect of GovGav, is girl power. Yes, girl power is one of the government blogs that is run out there. You can get to it by typing blog.usa.gov slash roller. I don't know why you typed that. Slash GovGav slash entry slash girl underscore power. And I'm going to read one of the entries. This is from June 26, 2008 from Nancy. I'm sitting here eyeing the last couple thin mints left in the three boxes of Girl Scout cookies I bought for my 8-year-old friend, Alisa. Do you mind this government website I'm reading here? There's nothing to be laughing and tittering over. I know, three boxes? But hey, I was a Girl Scout back in the day, and I wanted to pass along to Alisa that sense of accomplishment I used to feel when people bought an armload of boxes for me. If you have a special girl in your life, here are some links to self-esteem building websites for girls from kids.gov and around the web. From the U.S. Department of Health and Human Services, girlshealth.gov features physical and mental health information for girls 10 to 16 years old to help them understand what they're physically and emotionally going through during this time of change in their lives. There's information on everything from the maturing process to getting in shape in a safe way to managing family relationships. Yes, not Kevin. How much were you paying for this again? I'm not paying. I just printed it out, all right? I didn't pay a damn thing for it. Being strong physically starts with building strong bones. The Powerful Bones, Powerful Girls campaign shows girls in a fun way why mom always says, drink your milk and go outside and play. Yes, Redhack. This is the strangest blog I've ever seen. Wait a minute. Wait a minute. It starts with somebody talking about their personal story about Girl Scout cookies and then suddenly drops into this boilerplate government-style speak. Well, you know, for kids 14 to 17. I can give you Nancy's email address. If you have trouble with her writing style, you can critique it personally. Girl Scout cookies, by the way, not healthy. Uh-huh. Yeah, the government shouldn't be recommending that we eat those. Anyway, girlpower.gov may have that old school website look, but it also has a variety of helpful resources for girls including activity books and sections on more serious issues like understanding eating disorders and coping with a parent's drinking problems. Hope with your own drinking problems. It just goes on and on. But, you know, we don't really have enough time to continuously go through this. Girlpower is at, as I said, blog.usa.gov, part of the GovGab program. They also used to have girlpower.gov, but if you go to girlpower.gov, it gives you this bad request, invalid host name error. But if you go to archives.org, you can see the old site that has various sections for grownups, for girls, research and news, all kinds of things like that. How long ago did that exist, girlpower.gov? You know, I'm not sure. It was this year. It was 2008. It was in February of this year. So I don't know if it's just simply a routing error or something like that or it was something more serious. Maybe they realized that girlpower.gov isn't exactly appropriate. Well, they do say at the bottom, they do say, Warning, children should advise their parent or guardian before sending information over the internet. And that's an important thing to realize. In any event, if you have information or a .gov site you'd like us to feature, just write to us, oth at 2600.com. I would be happy to focus on it. The .gov domain is filled with all kinds of surprises. You just have to go looking for it. Before today, I think I thought it was a lot more serious than it really is. It would be fun for the whole family. So again, oth at 2600.com, .gov of the week. Cyberbullying Case Oh, yeah. Okay, getting to the rest of the program now. Bernie, I believe you had a couple of stories about technology that you wanted to share with us. Yeah, there was the famous cyberbullying case was decided. Cyberbullying. Cyberbullying case. And then Tiffany is here also. She's going to lend her legal expertise because she's a lawyer. She's also going to talk about an interesting hardware software open source project she's working on. But the cyberbullying case is very disturbing for a lot of reasons. People who have probably been following the news knew that a woman named Laurie Drew was convicted of effectively using MySpace to upset a 13-year-old girl who stopped being friends with her daughter. And the girl was so upset after all her repeated harassment and goading that she committed suicide. She hung herself. She pretended that this woman pretended to be a boy and was rejecting her, making her feel awful. Is that the story? Yeah. This middle-aged woman impersonated a 16-year-old boy, won the girl's trust, and then sent her other messages. It said something to the effect that she was fat and worse things than that. And then someone sent this 13-year-old girl a message saying, the world would be a better place without you, that sort of thing. And then the girl hung herself. Wait. Did this Laurie person, is she the one who sent the message saying, the world would be a better place without you? No. It turns out it was one of her employees, an 18-year-old employee of hers who sent it. But apparently with Laurie's urging to send messages to this woman, to this girl who stopped being friends with her daughter. Real salt of the earth here. It is. All right. So what's disturbing about this? Other than these people, these real gems of society, what's disturbing about this story? This is all the soap opera stuff. But what's really disturbing about this case is the United States federal government decided this was worthy of a federal case and decided to prosecute this woman under the Computer Fraud and Abuse Act, which is the Title 18, Section 1030, which is the same law that was used to prosecute many hackers, including Kevin Mitnick, FiberOptic, and a lot of other of our friends, basically with a theory that violating the terms of service of some online service provider constitutes unauthorized access to that service and is therefore a federal offense. Now this has implications to all of us because not one of us has used some online service without violating one of their terms of service because these agreements are so long and nobody reads them. Hold on a second. You're saying we all have violated the rules somewhere? I mean, I don't know. Where could I possibly have violated the rules? Well, for instance, Google. If you read its terms of service, you can't use any Google services unless you're at least 18 years of age. I don't know if you're of age yet, Emmanuel. Wait a minute. When you go to Google, when do you agree to anything when you go to Google? You agree to it by using the service. You don't, but it's one of their terms of service. In some of their service you have to click to agree to your terms of service, but somewhere in Google's policy it says you can't use their services without being an adult because they want to avoid the whole issues where kids could access pornography and that sort of thing. Tiffany, weigh in on this. Just about any website you access on the internet is going to have some type of you agree to these terms to be able to access this information. One of the really big problems with this case is also anonymity online. I know a lot of people, including myself, who have set up accounts that may not have been in my legally given name, and now that's going to be – it could be construed to be illegal. Even Bruce Schneier, for instance, did some stuff where he – let's just say he made boarding passes that he used to go through airports, and he – well, I guess that would be a Computer Fraud and Abuse Act. Wait, he made fake boarding passes? Yeah, yeah. He and an author – I like the way you said that. Yeah, they made fake boarding passes. I think one of them actually was listed Osama bin Laden. Oh, no, he did not. Yeah, actually, it has been done. He walked through the airport as Osama bin Laden. I cannot unofficially say someone did this in Boston over Thanksgiving weekend flying into BWI as well. This Thanksgiving? Yes. Well, okay. That could be a Computer Fraud and Abuse Act. The next time someone does this, can they tell us so we can at least watch and see what happens when somebody reads it? The funny thing is nothing happens. They read it and nothing happens. Obviously, they didn't read it. That's one of Bruce Schneier's points. If they read it, I think something might have happened. Well, according to the article Bruce Schneier did, they looked at it. I mean people have gone through with all kinds of other items that – flags from Afghanistan, all kinds of other patriot items, and they don't get stopped or questioned. It's just like, yeah, sure, go ahead. Well, I don't think anybody knows what a flag from Afghanistan would look like who works for the TSA. But they even had – someone had a shirt that they went through that said Osama bin Laden, picture of him, no problem getting through TSA. And why shouldn't they? I'm sorry, what's wrong with the T-shirt? Yeah, T-shirt is one thing. I mean they probably think that there's some kind of like target on his head or something like that so they're a good patriot. But to have an ID that says Osama bin Laden, I just think that would like raise a flag even in the most dim-witted employee's head. I can tell you sometimes it does not. Wow. Yeah. Well, I could say Bruce Schneier, when they got online to print out the boarding pass, if he used a name that wasn't his own, under a case like this, it could be construed as a violation of the CFAA. Yeah. Okay. So how much trouble is Bruce in now, especially now that you've norked him out on the air? Well, let's go back to websites though. So, okay. I mean I can understand things like MySpace and I guess Facebook and things like that. Yeah, you agree to something at some point. But a search engine? You just go to the search engine and you start using it. Are we saying that kids aren't supposed to be using Google? Is that the gist of this? Well, it could be the gist of that. That's what's concerning about this case. But in a way what was good is that this has been reduced from a felony to a misdemeanor. And so there is a possibility that Ms. Drew is just going to get parole for this case. But it was a very big problem that the Computer Fraud and Abuse Act was not intended for this type of crime. And actually in Missouri they said they couldn't find a crime. So in California, I believe it was Beverly Hills, California, decided that the courts there would take jurisdiction because that's where MySpace servers are. So there's a very active prosecutor who feels like he has a personal stake in prosecuting this case fully because he said it could be anyone's child online. But other articles I've read have suggested that he's up for election. Oh, of course. Yeah. I've got Google's Terms of Service here or part of Google's Terms of Service. And this is what it says. You may not use . . . Google's products, software, services, and websites, more dots, and may not accept the terms if, more dots, you are not of legal age to form a binding contract with Google. So, yeah, that's interesting. But it's just that you never really get the chance to even agree to that if you start using the site right away. There is an argument that Terms of Services, which generally aren't read by anybody, aren't properly enforceable. And the fact that they're using these Terms of Services as a legal basis to prosecute somebody is kind of interesting. Well, it sounds like they're trying to enforce it now in some way. But it's kind of sort of like a contract, and both parties need to be fully aware of all the terms. That's why I think that this case could have been handled differently. This could have been contract straight across the board instead of bringing in Computer Fraud and Abuse Act, which the felonies for that, if the jury had found her guilty of those felonies instead of misdemeanors, is pretty severe. I mean, the fact of the matter is that when she signed up for the service, I don't think that they should have used the Computer Fraud and Abuse Act, but if she agreed to it, and I think in MySpace's case, you actively agreed to it, whether or not she read it, because I think the defense was trying to say, well, she didn't read it, so it doesn't apply to her. That's like, okay, if I signed a contract, if I signed all of my possessions over to you, and I didn't read it first, that's my fault for signing it. So if you're agreeing to it and not reading it and then claiming that it's not your fault because you didn't read it, that you violated it, that doesn't really stand out. Well, that's an argument that goes both ways, but the fact of the matter is they do still argue that for contracts, and this should have been a contract issue. Yeah, yeah. No, I agree with that. I'm just saying that her defense was silly. Well, she was also saying that it was the 18-year-old employee who was the one who set up the account, I believe, and she clicked on whatever just to get through to set up the account, but she did deny that she knew anything about terms of service agreement. Okay. All this aside, I mean, it's silly the way it's being prosecuted. Should she be prosecuted for something, for making this happen or helping to make this happen, or is this just an example of people taking the net too seriously again? Yeah. In Missouri, they said, we can't find any crime that's been committed. I know the parents of Megan were probably really distraught over this. Maybe just something as simple as harassment, but to bring in Computer Fraud and Abuse Act, that's really extreme. It makes a lot of contracts that we either agree to click to or don't online the force of criminal law potentially. Yeah. Look at some of these terms. This is match.com. You must be at least 18 years of age and single or separated from your spouse to register as a member of match.com or use the website. So that means if you're married and you're using this to maybe cheat on your wife or husband, then you actually are in more trouble than that because you're breaking the law because you're agreeing to something. Well, perhaps the reason that they use the Computer Fraud and Abuse Act was because in this case, the harassment didn't actually occur in California, right? Because you said they were prosecuting in California. So all they had to go by was what happens on the servers if they'd been able to do it in Missouri under some normal – while relating to the actual – I mean, whether or not it's a crime on the books, it should be because, I mean, it's terrible that this person would do this to another person. But I think the reason they probably went with the computer attack is because of the fact that crime, if there is one, didn't occur in California. I think – and we talked about this in my class at the University of Maine, the Computer Science Department, that we talked about this last February, I believe, when it first became very public, and no one believed the CFAA would actually stick. I'm surprised in a way that it has, but I have heard throughout the community, the legal community, that perhaps they're trying to broaden the way the CFAA is used. And that's a little bit disturbing because this is not what – I mean, I think most people would agree this is not what the law was intended to do. You will not provide inaccurate, misleading, or false information to eHarmony or to any other user. If information provided to eHarmony or any other user subsequently becomes inaccurate, misleading, or false, you will promptly notify eHarmony of such change. How many of you have done that? I don't use that, but – I don't think that gets you out of it. Wow. Okay. Yes, go ahead, Bernie. I just want to say that I want to reiterate the disturbing part of this decision is that it makes the most minor violation of an online term of service prosecutable in federal court as a felony. And it's statistically accurate to say that people who use online services at some point have violated – most of them have violated some term of service somewhere inadvertently. And that literally makes most people who have used any online service prosecutable under federal law for committing a federal misdemeanor or a felony under United States Code Title 18, Section 1030. Now, I'm not saying the federal government is going to go after millions and millions of people, but the fact is that if it sets this precedent where everybody could be prosecuted for this, and it basically allows the government to almost round up anybody they want to. Yes, a selective prosecution. So we're saying basically the intention – I mean, generally, the intention of terms of service, I feel, is to protect the company rather than go after the user, right? So the company doesn't want their users to do certain things, and if they do do that, then the company is safe because, oh, well, that's not what we intended it for. But in this case, they're turning the user's violation into a crime is the problem we're having, right? Yeah. Rob. So how much do you see this opening the floodgates? I mean, can I go out tomorrow and insert a little terms of service on a website I run saying, you know, if you're reading this site, then you have to send me $5 million and a jet plane and then sue those readers of mine who don't? Ah, you read my mind. I wasn't going to tell anybody, but I was going to set this up. Oh, boy. Actually, the email that Bernie sent me, Chris, I'm going to pronounce his name wrong, but it's Sohoigan, I believe at Berkman, at Harvard Berkman Center, he was saying in his email that, yeah, how about you put something up like that in terms of service agreement that if the RIAA exceeds their authorized access to your servers, well, then they could be held responsible for computer fraud abuse act violations. You ever get one of those emails where it says redistribution of this email is prohibited? And a lot of times it's sent to you in error. You get mail from somebody else and they send it to you saying, you are forbidden from, and I always send it all over the place because if someone sends me email, I can do whatever I want with it. It's not nice to send it to other people. No, I won't be their best friend if I do that, but I've got every right to do that. I'm sorry. I just feel like I do lexicon. If there's a stop sign in a grocery store parking lot that the grocery store put there and you run that stop sign, can you get arrested for that? We're veering into all kinds of different territory here. It seems like a similar territory. Well, I don't know. It depends if the grocery store is actually registered with the Department of Motor Vehicles. Since when does anyone get arrested for running any stop sign? If it's in a private, especially if it's in a private lot. I think Martin Luther King did, and that's sort of selective prosecution. It's exactly how they get you in whatever way they wish. Hey, Manuel. Yes, go ahead, Bernie. I just wanted to read to the listeners the actual wording of the part of Title 18, Section 1030, which is federal law that was used to criminally prosecute this woman. It's only one sentence. It's pretty brief. It says, whoever intentionally accesses a computer without authorization or exceeds authorized access and thereby obtains information from any protected computer, if the conduct involved is in interstate or foreign communication, shall be punished as provided in subsection C of this section. So basically it says if you do anything with some communication service that wasn't explicitly authorized ahead of time, then you're guilty of committing this federal crime. Wow. I'm sure it does seem like a blank check for the authorities. Now, what happens in terms of service agreements are, obviously this could become a federal crime to break. So what happens if somebody under the age of 13 says they are 13 to get on a website like MySpace? You want to charge them as an adult? Is that what you're getting at? No, no. The point is that they're too young to make a contract, but they've broken a federal law. I made plenty of contracts when I was a kid. This is so weird. And what happens when you introduce other countries where the rules are different? We seem to think that the United States runs everything and we can just make these terms and agreements and the rest of the world is going to respect them, and I don't think they will. Tiffany. That's one of the reasons that the state of Virginia has very strict cybercrime laws is because they claim that they're the internet capital of the United States, possibly even of the world, where all kinds of connections are coming in through, well, mostly AOL servers. So Virginia is taking it upon themselves to try to create jurisdiction for computer crimes, and that's why they made some laws that are pretty strict. Interesting. Okay, moving on. I wanted to read this story because I just think it's a fascinating story. It ran in the New York Times about a week or so ago, and the headline, it's just a great headline. Man held an email mix-up to get $25,000. New York City has agreed to pay just over $25,000 to a former private school employee who was arrested, interrogated, and held by the police for more than 30 hours on a harassment charge after a bizarre email mix-up last year. The man, William Halliwell, was working as a library assistant at the Riverdale Country School in the Bronx in April 2007 when he had an innocent exchange of email messages with his boss, the library director. But when the library director mistakenly sent the message meant for Mr. Halliwell to an email address that was similar to his but did not belong to him, the recipient of that address replied with a crude and abusive response. The blame fell on Mr. Halliwell, who has left the school. One line in the response said, I want your sweet body against my skin. New York Times I'm quoting here. Please do not laugh. The response also included a racist reference, a mention of using prostitutes, and a statement that the sender had bought a gun and had considered suicide. Soon, the police were questioning Mr. Halliwell, and he became the subject of local news articles, causing enormous embarrassment, he said, in a lawsuit filed in July in the Federal District Court in Manhattan. Mr. Halliwell of Dobbs Ferry said in the suit that the officers deliberately and maliciously ignored a mountain of evidence that proved that he did not send the offending message. Mr. Halliwell said he invited officers to review the messages in his computer. He said it was clear that his account did not contain messages with the address linked to the abusive sender. Mr. Halliwell's lawyer said this was a completely unnecessary nightmare for an innocent man. The harassment charge was later dropped. Connie Pankratz, a spokeswoman for the city's law department, said, to avoid protracted litigation, we thought an early resolution was in the best interest of the parties and the court. A spokeswoman for the school, which was not a defendant in the lawsuit, could not be reached by phone for comment, but Mr. Halliwell said he was happy that the case had been resolved, quote, because I know that people will know obviously that I didn't do this. He said he hoped that his suit would lead to better training for the police in how email technology works. And isn't that great for everybody? I just have one question, which is if you send a single email, you can be arrested for that? Like, that's what I don't understand, how the police came to be involved in the first place. Well, I don't know. There was that comment about pressing the skin against body. I mean, if someone who sent that email and, in fact, was a co-worker of this librarian should probably be fired, but does it rise to the level of a crime? Well, harassment. He was charged with harassment, I guess, which is what that woman might have been charged with if Sander had prevailed. Don't you need to, like, hang outside someone's apartment and, you know, wait for them outside to be harassing them? I think if you send someone an email over and over again. Yeah, but a single email, I don't see how that would be harassment. Maybe this person continued to send email or something like that. That might be part of the story we're not hearing. But, yeah, it does seem bizarre. But the whole thing is bizarre. That's what's weird about this. Tiffany? It could be sexual harassment that all you really need is one instance of that happening for someone to kind of raise the flag about it. Is that a crime, though? Isn't that usually a policy of a place, not something that you'd be charged with? Well, it depends on, I think, whoever the victim is, if they want to follow through with that. Well, what seems bizarre is that the victim, quote-unquote, victim knew the perpetrator, again in quotes, and a simple conversation could have probably settled this unless they really believed that this was possible of the other person. So, yeah, it's definitely bizarre. Now, Bernie, I believe you have something else for us? Yeah, Tiffany has traveled all the way down from Maine to New York City today to give a presentation at Pace University. Do you want to talk about that a bit, Tiffany? Sure, I'd love to do that. We created a car computer. It's an interface, actually, for OBD2, which is a port that is in your car that you can connect to your car computer because your car does a lot of stuff that I think most people who own cars don't know about. For instance, scan tools. You can go get a scan tool and it can read the air codes, but also... Wait, wait, what? Scan tools. Air codes? Air codes, like when air is E, like a mistake. Air codes? Yeah, air codes, yeah. So if your car has... That's what they call air codes? Yeah. All right. It actually, it'll output a number and then they can figure out what that number relates to for the check engine light. But this does a lot more than that. In fact, your car records information about your driving and we wanted to find out how much. Like a black box on an airplane, you mean? Yes, exactly. And at times, your car will record such as if you braked really hard before an accident, your car will know that. So in some states, police go up with this thing that just looks like a cell phone, hook it up, and they can take the air codes off your car. So it'll say, hey, there was a near, you know, an instance that the computer recorded. We don't know what that is. And also, just being able to access that information because it does, it is found to be relevant in court. Now, this is only for new cars, though. Old cars don't have this. In the past 10 years, yeah. Older than past 10 years, no. But if you have a car that you've purchased in the past 10 years, it has OBD2 in it. And what we're trying to do with this is we're leasing our software and hardware, open source, free software, so people can take this and develop it. And in fact, four years ago at Hope, Nothingface gave a presentation on Introduction to Automotive Networks. That was the title. And he talked generally about how this can be done. Well, he finally has done it. And we have a prototype we're working on. And I'm competing in a venture capital competition to try to get some VC money to get the prototype fully working because we anticipate having a touchscreen that you can control all kinds of things with your car. Can't you also tweak certain things like the firing times and stuff like that with the control? I think one of the things that we're not going to touch legally is going to be the airbags. I believe they're... Yeah, that's something that I don't think you can create a tool to turn those off unless you're an automotive manufacturer or a dealer and someone gets a letter stating that either they have a handicapped child that needs to sit in the front seat and you can have that switch put in your car to turn it off. That's computer control? That's not mechanical? It's computer control. Interesting. So what if the computer breaks? Well, if the computer breaks in your car, that's happened to me. I had a Land Rover. They're notorious for computer errors. So then does the airbag not fire? Well, one of the problems we were worried about was that off-roading, that hitting really hard bumps that the airbag would go off when we really didn't want it to. So I don't know if you'd consider that like a broken computer. Hitting a rough bump makes the airbag go off? I meant if something went wrong with the computer and you, you know, hit something, right? It's not mechanically triggered? It has to be triggered by the computer? I believe that there is... I'm not exactly sure. I'm working on that piece of an accelerometer or something like that when the car stops. But there is an electronic signal that's sent for the computer to say, you know, time to release that. Now, okay. So you basically tie into the car's system somehow. How do you do that? How do you actually read this? Where do you read it from? There's a plug that's usually underneath the steering wheel in your car that if you take your car in for emissions inspections in most states, they'll pull that out and hook it up to a machine. In Maine, we don't. Well, where I live, your lights and horn kind of have to work. There are other things. But where we live, we've never had it hooked up. In Virginia, that's how they did it. And the computer ran the inspections. But that's where that is. And we didn't use, we used brute force methods for the protocol, like send out commands and also reverse engineering. So we did it without having to crack any of the encryption. And there is some for certain parts of the computer there. Nice. Interesting. Let me just grab the phone number for people to call in with questions or comments. 212-209-2900. We have about 10 minutes left to take phone calls, so we'd like to hear from people. But Tiffany, how can people learn more about the project that you're involved with? We are going to be working with this with Maine's Hackerspace. We hope to get some people to be able to write code, release it. It's going to be released under GPL version 2. And we are going to set up a wiki. But right now, Maine's Hackerspace is a good place that you can go to check this out. We're going to be having updates on how we're building the rest of the car computer. You say Maine's Hackerspace? So there's a Hackerspace in Maine? Right now, it's virtual. And we're meeting sometime around the same time as the 2600 meeting at the Maine Mall. What city? Portland, Maine at the Maine Mall at the 2600 meeting. We talk about getting together and creating the Hackerspace. And there's a meeting coming up this Friday. That's right. Okay, so where is that again? In Portland, Maine? It's at the Maine Mall. There's one mall in Maine. It's the Maine Mall. The Maine, Maine Mall. Okay. Not Kevin. Can you say what parts of the car are encrypted? I'm sorry? Which parts of the car are encrypted? I think there are some parts that control the anti-lock brakes. And I think that's one of the ones that is encrypted. There's encryption in my car? So they encrypt the anti-lock brakes, but the airbags are unencrypted? I don't know for sure about the airbags, but I do know it's illegal to touch, to mess with that, to create a tool that acts as that. But it's not illegal to theorize about how it works. Yeah. And to experiment and things like that. Rob? So how close are we to an open source car that can talk to us and jump over things and help us fight crime? Ask Richard Stallman. I'm sure he's working on that. Right now, we have an advanced scan tool. We can get all the stuff from the scan tool and output it. But to be able to actually change the firing of your engine, the oxygen sensors, things like that, we need a little bit more funding. And that's one of the reasons I'm going to Pace, is to try to get some interested in putting up some money for Angel and some money. Are there commercial products that do this already? What's interesting is no, they're not. That's why we're hitting a very cool market right now, is that there aren't. Scan tools are just about it. What I'm curious to know is, about this black box feature in the car computers, what do all these car companies have to say about this in their terms of service agreements? Oh boy. There we go. Actually, you don't own the software that is in your car. That's right. You have a license to it when you buy it. So the DMCA has gotten into our cars now. We thought a lot about the DMCA when we were designing some of the software for this. It is a problem. It's a stifling innovation. That's my opinion. Amazing. Voltaire, then we're going to take a phone call. 212-209-2900. Is there a big difference between the types of cars by individual manufacturers and different manufacturers? Yeah, there are a few different standards, and we'll be able to cover them all. It's just a little bit. We're going to tweak the code a little bit for each one of them, but there are about three different standards. Is this going on in Europe as well or just in the States? As far as I know, it's just in the States. Okay. And probably Canada too. Yeah. All right. Let's take a phone call. Good evening. You're on Off The Hook. Hey, Greg from Manhattan. How are you doing? How are you doing? What's on your mind? Question for your guest. What makes their product any different from any of the commercially available scan tools on the market already? The scan tools just address, usually in very basic graphical function, which air codes are triggered by the car and how to clear them. You can clear them as well. This is different in that it does a lot of other features. You can do more to control your car instead of just reading what your car is telling you. Okay. There's a couple of products on the market already that do that. For example, for Volkswagen Audi group cars, the Vagcom, for Porsche, Mercedes-Benz, you have the Shark Tuner. There's a few of them out there already that, I mean, if you want, you can fit them with your Acer laptop like I do. And tune your car while you're sitting in the driver's seat. Are they open source? I'm sorry? Are they open source? No, they're not. Well, that's the difference. Well, it's one of the differences. What's the advantage of an open source as opposed to, you know, one of the already available products? Good question. Yeah. The product that we have now, we will sell a commercial version of it. It's still going to be open source, software, and hardware. But the commercially comparable tool costs about between $5,000 to $10,000. Mostly dealerships have these. And we want to also create features that are open source so people can write their own stuff to control their own cars that way. The scan tools that are out now, the ones that are like, I think the most expensive one I've seen is about like $300, $400. Again, it just handles a lot with error codes. The ones the dealers have, those are the ones that are really expensive. And we'd like to make this more available for people who like to tweak their cars and at Hope we got a lot of feedback from people who do augmentation to cars. Well, I mean, this would help me out because with my smart car, which is a Canadian registered car, nobody in the States knows how to read the codes. All the dealers, even the people who sell smart cars can't read because this is a different one. This is a Canadian one with a diesel engine. So I have to drive it to Canada to get a major service because no one here wants to pay all the money to buy the software that will read the codes. It's pretty expensive. Yeah. So we'd like to release this so that if people want to write stuff like for this, they can, as long as they release their code too. One of the benefits to it being open source is the fact that with these commercial ones, you're pretty much limited to what the provider of the software or hardware wants you to do or has given you the ability to do. And with open source, it kind of lets other people who maybe have other ideas or interests take a look at it. And, you know, a lot of the legwork then has been done in terms of communicating with it and they can do some more stuff. So there's room for innovation. Exactly. And it's not just limited lockdown-like commercial. Let's take another phone call. Good evening. You're on off the hook. Oh, well, you blew it. Let's go over here. Good evening. You're on off the hook. Hello. That's my voice. What's on your mind? Yeah, I'm on the OBD2 systems. Yes, go ahead. The older ones were OBD1, OBD2, and now you have CAN now. She's working on a system for CAN or for OBD2-O. Because CAN is now called OBD2, but I think they're calling it OBD2-N. Wow, our listeners are informed on this. Yeah, that is. That's great. It is going to also be with CAN. So we are addressing that in the development for this tool. All right. And then you were saying, on my particular car, I drive a 97 Grand Prix, which is OBD2. The anti-lock systems and airbags have their own computer systems, so the main computer on the car does not control it. Well, what we're going to do is, it is possible to control that, but we're going to make sure that there's access control to that so that if there is an average consumer who isn't quite as enlightened as you are, you sound like, about cars, that they can't really mess with some very serious safety stuff. I see. Well, that would be great. I mean, what kind of interface are you going to have? Are you going to have... You were saying something about a touchscreen? We're going to have a touchscreen that can be mounted on the dashboard, but also for a different kind of product, a little bit of a more consumer market. You can take a cell phone with a GPS in it, it has to have an accelerometer as well, and you can create a governor for your car, such as if your 16-year-old is driving, you can find out the GPS coordinates of where it is and how fast that car is going, and you can be text messaged when that car, the location of where it is and how fast it's going. Can you actually make it so your 16-year-old can't go more than 25 miles an hour? Yeah. Actually, GM cars, I read in 2010, well, this is if GM stays around, they're going to have special keys that you... a particular key that you can give to someone who you don't want to drive over 55 miles per hour. Uh-huh. That the chip in it is read by the car and it can say, hey, this key can't go faster. You could make an application that will make something happen if you go less than 50 miles an hour, like the movie Speed, and it'll be sort of fun, you know? That's like the Segways. The Segways have been a hope the past two conferences. They have three different keys, and the speed is then limited by which key you use to start it. Until we get Barry the key to look at it and make his own key. Well, I think they're like Java buttons, or they're these, like, small... Yeah, they are. They are electronic buttons of sorts. Shall we take one more phone call? See if we can squeeze one in. And good evening. You're on Off the Hook. Hello. Hi, what's on your mind? Yeah, I need contracts for your cell phones, and, like, they're trying to get you to have a two-year contract. Right. You know, or to upgrade, or to keep your, you know, and all these things. I just want, you know, you basically just want a regular phone, you know, where we can make calls. I don't really want all that fancy stuff. Yeah, they try to railroad you into accepting them for two years and giving you a heavy penalty if you discontinue them beforehand. There's a way around that. What's the way around that, Bernie? You can buy a used phone, like on eBay, that was on the carrier that you want to use. You just have to make sure that that phone you're buying has met all of its agreements as far as the subsidy that the carrier provides when they sell you the phone at a discount. Oh, if you own your own phone, you don't have to sign any contract with them. You can use it on a month-to-month basis with all the carriers here. All right. Okay. All right. It just seems like, you know, you just want a regular phone. You don't want to always write and they're calling you now. Yeah, I just want a phone that you can use as a phone, not as a camera, not as a way of life, just a phone. That would be very nice. Two things. Usually you can, by paying full price for the phone, you don't have to sign a contract. Or again, like Bernie said, you can buy a used phone. Second thing is, there's actually ways to get out of contracts with the phone company. One of the ways is that the contract, with the contract, you agree to it unless they change some term of the contract or some pricing that affects you negatively, impacts you negatively. And actually, there are some fees on there that they put, you know, federal so-and-so fee, but it's not actually a price set by the government. It's a fee and they're passing it on to you. So they set the cost. And by arguing with them that their change, usually it changes every couple of months, has negatively impacted you, whether it goes up or down, they can't say what negatively impacts you. You can usually actually argue your way out of the contract. Another way is to say you're dead. That usually gets you out of the contract too. Well, yeah. It's harder to prove. Well, you have somebody else call. Okay. That's pretty much going to do it for us here tonight. I want to thank Tiffany for coming in. Again, give us the information for people to track your project. We go to, actually through my website is tiffanyrad.com and we're going to have a link to Maine's Hackerspace. And please go there and check out OpenAuto and write some features for us and we'd love to share that with everyone. Okay. Remember, everybody, 2600 meetings are this Friday. We'll see you there and have a good week. Write to us, oth at 2600.com. See you next week. Good night. Do do do do. Do do do do. Do do do. Do do. I just telephone upstairs when I'm troubled. Never need to drop a nickel in at all. Do do. And the boss is there awaiting. I'm not exaggerating. And he's sitting, waiting for my call. Do do. I just telephone upstairs when I'm troubled. Troubled. With just a little rocket ship below. Do do. And the boss's phone is ringing. My weary heart stops singing. And suddenly I hear him say hello. Do do. It's a long ways to heaven. Heaven. But I'm sure to get there by night. For if I can't see the road ahead of me, I'll dial the operator in the sky. I just telephone upstairs when I'm troubled. Never waste my time worrying at all. Do do. When I don't know where I'm going, he's got his way of knowing. And he's sitting, waiting for my call. Do do. Well if you say I'm weary and I'm lonely, he will tell you what to do and how to start. Oh yes. I have the strangest feeling. Feeling like a mountain bent and lifted from my heart. Well some people pray for money and for riches. But they don't know just how poor some rich folks are. And I have found a friend who gives me consolation. Yes. And I really found my lucky star. Yes. I just telephone upstairs when I'm troubled. And he's sitting, waiting for my call. And he's sitting, waiting for my call. Oh yes. And he's sitting, waiting for my...