And that wraps up today's program. The newscast was produced by Katherine Komp. Headlines editor was Jess Burns. Washington, D.C. editor was Matt Laszlo. Our technical production team at KPFA in Berkeley is Rose Katopci and Scott Pham. You can visit us online at fsrn.org. You can send questions, comments, or news tips to comments at fsrn.org. Thanks for listening. In New York, I'm Dorian Marina. And at 7 o'clock, you're listening to WBAI New York. It's time once again for Off the Hook. I hope that's understood. One, two, three, go! Off the Hook And good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you on this Wednesday evening. I'm joined tonight by Mike. Hi. Dot Rett. Hey. Rob T. Firefly. Good evening. Gus. Well, hi. Jim. Hello. Bernie S. Down in Philadelphia. Greetings from Philadelphia. And special guest tonight, Tiffany Rad. Hello. Along with Rick Moy. Hello. And we have all kinds of fun things to talk about tonight. Actually, I want to start by playing something kind of cool in the background. And I'll explain what this is all about. Is that it? Yeah. I wasn't aware there was... You know what? That's not it. I'm sorry. I'm playing the wrong thing. No, that is it. That is it. Okay, I'm sorry. I just wasn't aware there was percussion there. Okay, what you're hearing is a Tesla coil playing music. And we might actually be talking to the guy behind this, who will be at the Maker Faire this weekend in Queens. And I saw something like this at the CCC Congress in Berlin last winter. But this is a lot better, a lot louder. It's hard to describe without showing you the video. The music is kind of cool. But you have a video right there. And I'm looking at it. I see there's a bunch of tubes hooked up, sort of like a pipe organ style. And there's a Tesla coil. It looks kind of like lightning in reverse. And somehow that's playing music. And it's just one of the many kinds of things that you'll see this weekend. Is someone controlling it, or does it just go by itself? I think someone's controlling it, but not right there. They're not standing there. I think it's dangerous. Yes, Bernie, go ahead. Is the spark, is the plasma itself being modulated? Is the sound coming from the lightning bolt? Or is it coming from something else? That's my understanding, that it is coming from the lightning bolt. And when I saw it in Germany, it was coming from there, except it was much lower. Wow. Cool. And something is making those drums beat. I don't know what it is exactly. I think it's triggers. It looks like it's maybe a bolt acts as a trigger for one particular instrument's electronic pulse. Yes, the Tesla coil is doing it all somehow. The cool thing is it looks like it's reaching out and hitting them, which is pretty freaky. Yes, it really is. So, yes, I thought that would be kind of cool. A lot cooler if we had the guy there to talk to, but so far, no luck reaching him. But, again, the Maker Faire happening this weekend in Queens, and just go to makerfaire.com, I believe is the website. Spell faire with an E. The old World's Fair grounds in Queens. It's going to be quite an interesting weekend with all sorts of strange projects and activities going on. And a bunch of us might even be there too, wandering around, doing all kinds of fun things. Should be interesting. Now, speaking of interesting projects, I got involved in one that sort of spun out of control in the last couple of days. I don't know how many of you have noticed. I think just about everybody has noticed the new Google feature, Google Instant, where basically you have answers given to you before you finish typing. It's kind of cool. Actually, I was trying to describe it to people weeks before because for some reason it was working in my area before it was working anyplace else. And I was just basically telling people, Google, it's instant text reading my mind. I wasn't able to even phrase a sentence out of it. And everybody just thought I was crazy and ignored it. And then all of a sudden it happened and everybody was talking about it. Okay, fine. Here we are in the world of Google Instant where your thoughts are completed for you. But what we've discovered is that there are many words that Google will not complete for you that they consider to be objectionable in one form or another. What happens when you type a particular word, it just simply doesn't give you any suggestions at all. And what we've been doing over the last few days with the help of many, many people who have sent us email is just kind of figuring out what some of those words are. And some of them are kind of unpredictable. Who's got the list? All right, does anybody have any favorites that they found? Gus, you've got some? Remember, there are certain words you can't say over the radio. Right, we can't say those either. And those are, I think, seven words. They have hundreds of words here. Yes. And phrases and weird things like that. Let's see. What I like is that this list includes capital letters within the word to let you know at what point the censorship kicks in. So it's like you start to type a word and it'll be okay. And then all of a sudden you hit a certain letter, like Arian, for example, is on the front page. I'm going to stop you right there because I don't think it's the right use of the word censorship because you're not really being censored. You do get the results if you hit return. This is true. And you're not being prohibited from saying something or speaking out. But it is filtering, and it's a good demonstration of how results can be tailored to your particular audience and how you might not ever see something that exists. And one good example of this, if you go to Google and you type the word murder, right, M-U-R-D-E-R, you'll see underneath, you'll see all kinds of suggestions, not one of which has anything to do with the actual act of murder. They're all band names and nice things like that. If you hit return, all of a sudden you get different results. So it's very interesting to see how this actually plays out. Now, one in particular that I can think of, the word teen, T-E-E-N, not allowed. You won't get any responses for that because apparently most responses in Google's opinion are not for family viewing or whatever it is that they're... But it'll start to suggest up to T-E-E. It's just when you hit N that it changes because it could be looking for a golf tee, for example. But teens are somehow... I can't imagine that, like, maybe not Disney, but some youth-oriented media company will stand for that for long because it's sort of like, I don't know, odd. The word lesbian, blocked. I mean, that's unbelievable to me that that would actually be the case. And bisexual but not gay, do I remember? Right, bisexual is blocked. Yeah, and it's up to, let's see, what is it, bisexual, after you hit bisexual for that. So if you want to see the list and maybe contribute to it yourself, we've been getting all manner of contributions from people all around the world with every imaginable offensive, potentially offensive word or description of some kind of sexual or excretory activity that might be flagged in one way or another, just simply go to www.2600.com slash Google Blacklist. That's what we're calling it, the Google Blacklist, because that's really what it is. And bad words. I think they've even described them as bad words. While we're on the air, I'm hoping somebody will look up the word poodle, which may seem like an odd word to have on there. I can do that right now. Please do. Roxy Firefly has some commentary, and I'll go and look this up. Just to note why, this was a word that was on Scientology's. . . Wait, poodle? Poodle, yeah. Like the dog? Like the dog. It was on Scientology's Net Nanny list back in the day when that got released, and that was one of those ones that really stuck out in my mind. Like, why are they blocking that? Well, I looked up hacker already. Hacker is not blocked, because believe me, if it was blocked, we'd be in court by now, I'm sure. I'm up to the second O in poodle, and so you know that poo is okay. Well, you know, I'm not sure how seriously they take this, and I've made it up to the E. . . Are you getting live results? Yeah, I see poodle rescue as a suggestion. Actually, you know what, wait a minute. Don't you want to be on the first page of the actual showing the results? Do we somehow have an old version of Google that doesn't do what it's supposed to do? Go for some results and get the first page. No, no, it's not doing what Google is supposed to do, where you basically type a word and it shows you the results. It's not doing that. It's like I've gone back several weeks here. The BAI computer is the only computer I know that doesn't have this, but I thought it was something Google did, not something local. Are you using a normal web browser? Because I know that some web browsers it won't do that feature with. As normal as we can get? Well, let's see what I'm using. I've already come across that. We use only Soviet web browsers, WBAI. We're using Firefox 3.6.10. Do you have JavaScript enabled? You know, I don't know, and I don't have authorization to do such a thing. Do you have to have JavaScript enabled? I suspect so. Yeah, that's definitely HTML5. But still, yeah, use JavaScript. Okay. Well, we can't do that then. I'm sorry. Someone else is going to have to check your poodle. Any other favorite words before we move on? Because we have all kinds of other things. I just think, you know, rather than call this censorship, I think it's a better way to put it is perhaps where Google decides to be less helpful. Yeah, so I'm not going to tell you about this. If you want to find out more, hit return. It's a great way, though, to find out really secret words that nobody uses. There really are all kinds. I don't have it right in front of me right now. But, Rob, you have it in front of you. Anything stand out that's not too risque to say over the air? Rob, you're still on the list of things that are blocked. Do you want to go a couple pages down? Yeah. Where's the list of things that aren't blocked? Because I found those. Well, the things that aren't blocked aren't that. I mean, most things aren't blocked. But the things that are blocked are kind of fascinating as well. Bernie, do you want us to look at anything for you? No, I was just thinking that this could be used if poodle was indeed blocked. That's one of the words that has political overtones because Tony Blair was described as a poodle, as in George W. Bush's lapdog, widely in the U.K. So, you know, this could be used to sort of tailor people's thought processes in a way, I think. Mm-hmm. Well, it does make you sort of hesitant. And when you get that blank screen, you realize, I've typed a bad word. I've typed something that could be misinterpreted or misread or something. The phrase, girl on, when you type the end, it'll block you, which, you know, I don't know what that could possibly be. Oh, yeah. I'm sure we can— You know, the funny thing is, is like literally within the first day or so, I already started noticing that certain words wouldn't complete. I wasn't actually cataloging it. It didn't occur to me back then. But automatically, it just became a natural thought that, yeah, they don't want to complete these words because they're— Sex is not blocked. Sexy is. Yeah. Can't say sexy. How about yif? I don't know what that is. But, you know, that rings a bell that might be there. We've been seeing all kinds of entries. And, you know, there are a lot of sick minds out there. People have been sending us a list of hundreds of words. And how do they know all these words? But they just rattle them off. And maybe they have access somehow to the master list. Mike? No? Okay. Now, Google is not the only company involved in things like this. T-Mobile is being accused of censoring text messages. Now, again, I'm not sure if this is a proper use of the word censor. It might be. A mobile marketing company claimed on Friday it would go out of business unless a federal judge orders T-Mobile to stop blocking its text messaging service, the first case testing whether wireless providers can block text messages they don't like. Easy Texting claims T-Mobile blocked the company from sending text messages for all of its clients after learning that LegalMarijuanaDispensary.com, an Easy Texting client, was using its service to send texts about legal medical marijuana dispensaries in California. T-Mobile subjectively did not approve of one of the thousands of lawful businesses and nonprofits served by Easy Texting, according to the New York federal lawsuit. The suit against T-Mobile, which controls about 15% of the U.S. mobile market, comes as the company just announced it was raising its texting prices, which is obscene in and of itself when you consider how cheap texting is for the phone companies. The case comes amid a fierce debate surrounding net neutrality with net giant Google claiming that wireless carriers should not be bound by the same rules as wireless carriers, and even the New York-based texting service acknowledges that the case raises novel issues. At the very least, Easy Texting has raised serious questions about the legal ability of a wireless service provider to block its customers from exchanging text messages with Easy Texting's customers. Now, I'm a little confused by this because I'm not sure if this is a case of a company sending messages to somebody who already has expressed a desire to get the messages or if they're spamming and sending messages to everybody. And I get a lot of spam messages which really annoy me, and I think they should all be blocked, so I'm not really sure where this fits in. I'm a little confused with how the whole texting thing happens. But if they're blocking these particular types of messages from this company, would they be blocking messages about legal marijuana from one person to another? That's definitely a concern. Mike? I suspect this is some kind of spam company that wants to get good press by claiming they're being censored, but maybe I'm wrong. Yeah, well, I hopefully have something to back that up other than just accusing these people. The name of this company, Mobile Marketing? I don't trust any of those people. Easy texting or mobile marketing? Well, I think there was some discussion on Slashdot that it could be a marketing company that you did sign up for it, but then once you have responded to one, they start sending you things that are unrelated and they don't respond. There are some sort of speculations as to what was going on there. Yeah, I'd like to learn more about how these short codes work. For instance, they give examples here. A church could send a schedule to a cell phone user who texted the word church to say 313-131 and someone else might send the word party to get party supplies or something like that. I'd like to know more about how you get that particular thing. Maybe the day can come where somebody texts WBAI and all of a sudden, there's a $50 bill on their phone charge and it gets donated to us, except we probably wouldn't get only a small percentage. The control of these, they're called short codes, which are numbers that are less than 10 digits that you can send an SMS to. The control of who gets those short codes is actually very tightly held by the carriers. They can say, you are a company with a marketing plan that is not worthy of one of these five-digit codes, you can't have one. They'll say to another company, okay, you can have one, but it's going to cost you lots and lots of money, so you might have to split it up with several other people in order to be able to afford it. I think that's an interesting case of non-neutral communications where the carriers choose who can and can't have these codes. Very interesting. Who decides which carrier gets which code? The carriers have sort of an alliance. It used to be that you would only get the code with one carrier at a time and that made it sort of difficult to get the same code on every carrier, so they have sort of an alliance that's run by the carriers that doles these things out. I've opened up Internet Explorer and guess what? It works on Internet Explorer. I can now see results. So, Gus, you want me to look up Poodle for you? I'm going to do that right now. Okay, I'm up to the second O and typing the E now. Yep. And it looks like it's there. I'm seeing pictures of Poodles. Yes. Okay, so they're not in league with Scientology. That's nice. Okay, well, did you really think Google was in league with Scientology? You never know. We would have known by now if that was the case. I thought they gave up on the whole Don't Be Evil thing. So, you know, I figured if they were like, ah, you know, you're in for the lamb, you're in for the ewe or whatever. I don't think they've officially given up on that. I don't think so. That's actually an interesting point that Gus just made about, you know, giving up on this whole Don't Be Evil thing. Have you guys seen their transparency report where they show the list of how many requests for censorship or data governments have given them from around the world? Yeah, this story just came out, actually, and I thought it was interesting that Google was releasing it. According to them, Internet freedom is declining. A search company this week released a new online tool to highlight specific instances of government censorship of the Internet in countries from Germany to Turkey and Australia to Thailand. It's called Google Transparency. It's an online report that shows Internet censorship around the world is increasing over time and not always in the countries you'd expect. The threat to Internet freedom has actually been growing over the past few years, a spokesperson said, noting that the United States generally bucks that trend by supporting open online communication. Now, Thailand, for example, asked Google to remove YouTube videos that showed the Thai king with feet near his head. His feet near his head or is he an acrobat? I don't understand. I think it's culturally insulting. Okay, what are feet doing near his head anyways? Was he lying on the ground or was somebody doing a high kick? It could have been a shoop job. I mean, somebody could have floor shopped it. Yeah, I suppose that's possible. But it's YouTube. Put them in post, you know. Yeah. Criminal offense. Well, I know they're sensitive to that kind of thing, but really blocking all of YouTube because of that. Okay, well, yeah, national law in Thailand bans such offensive representations. And Google agreed not to show such videos within Thailand, although they're still available elsewhere in the world. Now, Germany bans neo-Nazi content. Oh, interesting fact. On the Google blacklist, the word neo-Nazi is banned, but not KKK, not Nazi, not fascist, just neo-Nazi. Only the old Nazis are okay. Just saying. If there are neo-Nazis out there concerned about their civil rights, you've got an issue now. Yeah. Anyway, Germany bans neo-Nazi content. Google has agreed to remove such sites from its Google search engine, Google.de, that is. Turkey, meanwhile, blocks YouTube because the company refused to take down all potentially offensive videos about the Turkish political hero Ataturk. Ataturk. The founder of modern Turkey. Atta boy, something. That's probably an insult saying it like that, but it's a way to remember it anyway. Australia. Sorry, go ahead. He's Ataturk. He's the guy that wouldn't let Turks wear fez caps because he thought that that made him look silly. So, Ataturk. Well, that would make anyone look silly. Yeah, it's good to look silly occasionally. Now you've anchored Moroccans. Why can't a country just specialize in looking silly? I think it would make everybody feel better. Now, Australia is considering a law that would block some websites in an effort to prevent the trafficking of child porn. So, everyone has their own reasons. Everyone has their own sensitive issues. And, of course, there's China. We all know about that. So, yeah, according to Google, the freedom is going down. I guess it's kind of a little bit ironic seeing what we're focusing on right now. Although, again, I want to stress that what this is is simply, I guess, guidance so that people don't see nasty words showing up on their search when they might not mean that. Although, if you type, you know, two girls, one cup, I imagine you're looking for something along those lines. And, yes, that is block two, as is one cup, two girls, and a kind of mixture of that. And if you don't know what I'm talking about, be happy that you don't. Don't look it up, please. It can't be unseen. If you do look it up, you have to hit return to get the results. Tiffany, yes. In some ways, this discussion is not particularly new. A while ago, eBay went through this with different items that in France, for instance, they weren't allowed to sell Nazi items online. France wanted to block people coming from IP addresses that were in France from purchasing this as well in the U.S. That's actually, that considering eBay does sell, it has a category for spells and incantations, as I just found out from Regretzi the other day. So you can have a spell to, I think there's something about past life regression. So there, and at the bottom, you do have to put in a thing that says, this is for entertainment purposes only. But, I mean, it's just sort of interesting, like what gets blocked and what doesn't. Yeah, definitely. And now I've angered all the Wiccans out there. What do you have against spells? All right, we have all kinds of other things to focus on tonight, and we're going to have Tiffany tell us some of the things that she's been up to, which is always interesting to hear about. But first, let's look at some real crime stories that have been going on because we live in a dangerous world. NBA star Shaquille O'Neal has been sued for computer hacking. That's right. The NBA veteran faces allegations that he hacked into a computer and destroyed email evidence in an attempt to frame a former employee. Sean Darling, who worked as a personal IT guy for O'Neal from 2007 to 2009, a personal IT guy, wow. You're an NBA star. Why do you need a personal IT guy? I mean, do you even have time to check email? I don't get it. Maybe the IT guy checks email for him. And does the tweets for him. Personally. Oh, does the tweets. So you can't even be bothered to do your own tweets. You have to hire somebody to do that for you. Okay. Well, anyway, this person filed suit against the NBA star for, quote-unquote, intentional infliction of emotional distress, invasion of privacy, and civil RICO racketeering charges. On August 3rd in Miami-Dade County, he claims that O'Neal hacked into his voicemails and those belonging to an alleged mistress. Yeah. Basically, he alleges that O'Neal, along with his houseboy, Joe Caballero, houseboy, really? Disposed of Darling's computer in the lake behind O'Neal's house and gave him cash to buy another replacement iMac. Disposed of it? Don't iMacs float? Wow. There's an app for that. Yeah, the report says Darling has an extensive criminal record. This is the guy that's suing him. So I don't know. It's quite a tangled web that is being woven down there. Rob? I think all we can say about this is don't attack Shaq or you'll get a Shaq hack attack back. That's whack. How long have you been holding on to that for? Wow. Okay. Then there's the case of camera rage. This happened over in, I believe, in England. Is this in England? Yes, over in the UK. A man who objected to a CCTV camera keeping watch on his bedroom window from the house opposite has appeared before a judge charged with stealing the camera and throwing it in a river. A lot of things being thrown into water this week. What happened was the camera was installed in an empty house opposite Christian Lord's home in Carlisle, and he and his girlfriend didn't particularly like the 24-hour monitoring of their movements, so he broke in and removed it. He pled guilty to a charge of burglary and the theft of the 1,500-pound surveillance camera. What kind of camera? Wow. $1,000. What were they? Was it high-definition, surround sound, all kinds of things? Oh, man, I didn't parse that. I thought you meant 1,500 pounds as in that was how heavy it was. No, it wasn't that heavy. It might as well have been for that kind of money. I'm burning my brains. So anyway, there is no dispute that the CCTV looked out solely upon the property occupied by Mr. Lord and his girlfriend, said the prosecuting counsel. They say it was unclear who had installed the camera or why, and they believe that the landlords might have been responsible. But, yeah, over there, everyone is CCTV happy. Wait, don't you have to know whose camera got stolen before you can show that it was in fact stolen? You'd think that. I mean, yeah, they seem a little confused. They don't know who installed it, but yet they're charging him with theft, so obviously they have to know who it belongs to. Then the guy could just say, the owner gave it to me, and until you find the owner, you don't know differently. Maybe there was a lot of cussing and swearing while he was tearing the thing down and throwing it into the river, and that's sort of what got law enforcement involved. Tiffany? About 4,000 CCTV cameras, I think, just came live in New York City as well, if you heard about this. I heard something to that. How many? I think it was 4,000. That's the number that I remember hearing. And where are these things? All over. Really? Yeah. Wow. Is there an accomplishment for knocking them all out like there is in Portal? I mean, my take on that story was that guy was just like, he was going for the completest. He was trying to win the game. I have no idea what you're talking about. Sorry. Basically, I don't think you can just knock the cameras out. And I think just basically if you know where they are, that's probably a good thing, spreading knowledge. So Tiffany, we know they put in, how many, 4,000, but we don't know who put them in? Is that what you're saying? It's the city of New York, right? Yeah, New York City. Oh, gotcha. Okay, continuing with our crime watch. This is an interesting story. A former employee of a Baltimore drug abuse program was indicted on Thursday, actually two Thursdays ago, on charges that he hacked into office computers and caused a pornographic image to be displayed during a PowerPoint presentation his boss was giving to the board of directors. Walter Powell, and I give his address and everything, is charged with several counts of unauthorized access to computers and unauthorized possession of passcodes. He faces up to 48 years in state prison if convicted on all counts. When did we lose our sense of humor? Uploading porn to a PowerPoint presentation or to a slideshow or to a website, that's just the American way, isn't it? Bernie, do you think maybe this might be a little bit over the top? 48 years? I mean, I don't think he should have gotten a year over 46. Yeah, I mean, 48 is just too much. I mean, they made the statement, but really, what did this guy do? He uploaded the pornographic image into a PowerPoint presentation, and I'm just looking for exaggerated statements of what this wound up costing them. Basically, they say Powell became disgruntled in the weeks leading up to his departure. He used his home computer to gain access to the company's internal servers. He installed software to allow him to track the computer keystrokes of his colleagues. And over the course of 32 days, he accessed or attempted to access the network more than 100 times using the passwords of those employees. He then broke into a particular account, forwarded confidential emails to employees, and composed a fictitious email message sent out on a mass distribution list. Basically, 17 board members were present when the PowerPoint presentation, which was designed to highlight the accomplishments during what were then the CEO's first few months, when that got underway. He said the computer shut down and restarted projecting the image of a naked woman on two wall-mounted screens, one 64 inches wide, the other 32 inches. Why does that matter how big the picture was? But three of the board members are still hospitalized from shock, and yeah, no, I think they got over it. I really think they got over it, and I think they need to get over it. You know what? This is grounds for firing somebody. You fire somebody, they lose their job, that's it, case over. But not in this country. We have to have massive lawsuits and people going to prison for 48 years. And yet the people who continue to make their employees watch regular PowerPoint presentations go unpunished. Yeah, yeah. And I think the 48 years that they're talking about, if you add up all the stuff, the keystroke logging programs, trying to access accounts, I don't think it's- Every key a year? Yeah. I don't think it's just for the pornographic images coming up during his boss's presentation, which from what I remember reading in another article, they didn't quite catch on who was the guy doing the presentation immediately, which must have been interesting to see. It's just, you know, in a movie, everybody would be laughing, so I don't understand why real life has to be that different. So the conclusion is that the PowerPoint presentation was so boring that even the person giving it wasn't paying attention to it? You know, maybe the woman in the picture should be suing as well because her image was used without her permission. And there's possible copyright infringement. Maybe there was music in the background that wasn't paid for as well. Who knows? We can go crazy with this. Final story here. London's Metropolitan Police said it might reopen an investigation into the alleged hacking of phones of top British politicians and celebrities by a tabloid newspaper. News of the World journalist and a private investigator were sentenced to prison in 2007 for hacking into voicemails of members of the Royal Family's staff. The private investigator also admitted hacking into model Elle McPherson's messages, among others. But the New York Times alleged in a detailed investigative piece that far from Royal reporter Clive Goodman and private investigator Glenn Mulcair being lone culprits, phone hacking was common practice at the newspaper. The allegation could have a direct effect on the British government because the editor of the paper at the time was Andy Coulson, who is now British Prime Minister David Cameron's top communications aide. Well, you couldn't have picked a better person to know what the weaknesses are in various systems. And hacking into a voicemail account, really? Is that a major crime or is that just an indication that your security needs beefing up? The Times Magazine ran an article on this fairly extensive a few weeks ago and the summary is if you're in Britain and anyone might ever write a newspaper story about you, like choose a password that's not 1234, please. Yeah, or not 1111 or 0000 or your name or the same digit that your phone number is, things like that. That's basic common sense from the 1980s that I thought we all learned. Well, apparently people in Britain, at least, and probably America too, didn't because they, you know, allegedly at least, got into all kinds of people's voicemail and, you know, endlessly. You know, I think if you're a public official and someone gets into your voicemail, your email, well, you know, that's your failure and people are kind of curious about these things. The Sarah Palin thing, for instance, the Sarah Palin email break-in, that turned out to be very beneficial to people finding out what she was really up to. Of course, the person who did that was found guilty of a crime. Didn't stop her. Didn't stop her either, that's true. Tiffany, so now you're here and you're here with Rick and I understand you guys have some fascinating project that you're working on. Let's fill in the listeners. Rick? Great, yeah. So the project grew out of some work that NSS Labs does where I work and NSS Labs is an independent security research firm and what we do is we take security products and test them to see if they're going to stop malware, phishing, and exploits because we often rely on those products to protect our data and one of the things that we found was when we're testing products, there are literally over 15,000 high and critical vulnerabilities in systems, operating systems, applications, et cetera, and as you're testing security products, you want to take the live attacks against those vulnerabilities so that you can understand whether or not you're really protected and if you're not, you can take steps to either accept that risk or do something to plug it and what we found was there really weren't enough of those exploits, those tools that we as security professionals use to evaluate the defenses that we have. When you look at penetration testing tools that are out there, there's very little content that's organized in one place that you can trust and rely on in order to do your security evaluations. So we had kind of a novel idea because the content's not lacking, it's out there and there are many individuals who are very smart and talented at coming up with this stuff but they were just dispersed throughout our communities and so we came up with the idea to really create something like the app store but for exploits and to give security researchers the ability to develop and sell their work on a marketplace so that other security practitioners could get access to them. And one thing particular about this that we're doing is we're working upon the Metasploit framework already so there are options. If you write an exploit you can either submit it to Metasploit so if you'd like to release it for free, there you go. And what we're doing is we're taking some code that perhaps isn't completed or if it's code that isn't quite operating as the author said it was perhaps backdoored. We're cleaning that up, we're making sure stuff isn't backdoored so we're adding a little bit extra to the exploits that we find and they're going to be running upon the Metasploit framework. Interesting. For the non-technical people in our audience, what's the significance of this as far as their security or the future of technology? Well, one of the questions is does anyone here do any pen testing? Is there anyone here? Okay. Penetration testing. Penetration testing is where your testing assistant authorized use to access the system and where do you get your tools? Without admitting to, of course, any friends. For the radio audience I should point out that .ret raised his hand. I don't know if he thought that could be seen on the radio but, yeah, I guess answer the question. Well, since you're talking about Metasploit I will say I have played with that. So you actually answered a question of mine which was going to be what form are you releasing this in? Do you just release reports, scripts that use it or would it plug into things like Metasploit or more than one option? It's going to plug into Metasploit and we're going to be releasing executables but what we're doing is trying to make it more affordable for people to buy clean tools knowing that it's not backdoored. If you want to start out in pen testing one thing that's difficult is getting a set of tools that you know is reliable and is clean and isn't going to be doing stuff that you didn't think it was going to do and then releasing that it could be a lot of liability for you. So we're taking some of the liability out of that. That's one of my jobs is I'm making sure that we're going to do the best we can to make sure it isn't backdoored and it's clean and reliable. So that's for the technical audience in terms of people who might be using this. What about for those of us who are just end users on the computer? What does this do for us? What it does for us for everyone else is we want more people to be able to get into pen testing and make it affordable and making sure that your tools are good and if you would like to write your own exploits that's something that we will what we're offering is a marketplace more so than being the sellers directly. Yeah, I think in terms of my mom or my sisters they're not really going to be using this but they'll be benefactors of the proliferation of these tools to security professionals. So one of the things we find out is that the security products that consumers buy folks are either completely jaded and say, oh, I'm not going to buy it. I don't trust it. It doesn't work. Or they say, oh, I've got this thing. I picked it up at the store. It says total protection, complete protection. I'm good. I'm protected. And nothing could be further from the truth. So by getting these exploits out into the hands of other professionals we're adding transparency into the marketplace so that security professionals can test them and know how effective is product A versus product B. Are there settings that I can change to increase my security? And the vendors themselves are truly struggling to keep up with the amount of malware and exploits that are put out there. So they'll also be able to be customers of these tools and do more testing on their products before they release them so that they're higher quality and have greater coverage. So you'll be going to, say, Norton and Symantec and all them and they'll be coming to you saying, okay, show us what the latest, you know, worm or Trojan is or something like this and help us get it into our products so that we can protect and not help us get into the product but help get protections against those into our product, right? Something like that? Something like that. I mean, those types of organizations have substantial resources. So they see a lot of the attacks that are out there. And to be specific, we're really trying to focus on the low-hanging fruit, which isn't always the latest zero days. There are exploits or vulnerabilities in software that have been out for many years. So the idea is to allow them a more automated and efficient manner to test their products. And right now, that's really not very standardized when you compare, say, other industries like the legal profession or the medical profession or automobile safety. Computer safety is more of a random event in some cases. So we're trying to help advance the state of the art. What do you think the biggest security concern is for the average computer user these days? Downloading things from the web? Programs they install? Bad words? Well, probably not bad words. Not yet. Most of us are pretty hardened. We're at only the case with our computers. Well, there's three different types of things that you can be vulnerable to, either phishing attacks where you give up information, socially engineered malware, which you knowingly, unwittingly install, and then exploits, which are really attacks against your technology. And they can happen silently in the background simply by visiting a website. And it used to be that you'd say, hey, don't go to the dodgy porn sites because that's where you get infected. These seedy sites of the web are the dangerous ones. Well, nowadays, we've seen these exploits hosted on all sorts of popular sites, New York Times, MLB.com, many popular sites. It's very difficult to maintain the security of websites as we know. You're saying I go to the New York Times website and create a news story and somehow be infected with something. It's very possible. It happened last year, actually. When did that happen? Someone uploaded something? How did they get it there to start with? Well, so that particular incident, web properties utilize ad servers that are third party where they simply allow another network to display or deliver an image or another iframe of web content to the end user. So in some cases, the malicious code is not always hosted on the main site. It could be delivered through ad networks. It's called malvertising. In other cases, it's fairly easy to do a SQL injection attack and take control of a web server and then put what you want on there. So there's tons of ways to get... Do you recommend people running ad blocking software to at least eliminate that threat? I certainly try to. And annoyance as well. Rob? I think it's worth explaining maybe for people who aren't familiar with it just what the scene is like and what it is you're changing. So not counting what you're doing, say I wanted to get into pen testing right now, which I don't because I've seen pen testing. But say I wanted to get into it right now and what's available to me? How would I get hold of any tools to do it? Well, there's really... Metasploit is the major open source project that's out there. It's created by H.D. Moore out of Austin, Texas. And he created it several years ago. And it's a modular system by which you can write exploits and payloads and do different things to hide them called evasions. There are other commercial tools that are out there. But by and large, Metasploit's the most widely distributed framework. And of course, you'd probably want to find someone to give you some pointers. Go to the website and learn. Are we talking about going to Russian forums too a lot of the time? Not to throw it all on Russia, but, you know, I mean, it's happening. If you are a pen tester, I know that there are some that I know that are just starting out. It's kind of like your little black book. I do know people who have had to purchase pen testing tools in Russia and China. And these are also people that when they go on contract for even government projects, they bring these tools with them to work. Some of these tools, if you look at some of the code, it's messy, not as efficient, but it's also some of it's backdoored. And if you don't really know what you're looking for when you step through the code, there can be some surprises in there. So right now, if you are starting out and you can't afford some of the more expensive professional tools, you might collect your own. And that's what we're trying to create a little bit of insulation. We'll go through that stuff. And that's the way that we're setting up the store is that we will take, we're going to have buyers and sellers. If people are selling us code, we're going to have a bit of a vetting process. We're going to know, we'd like to know who they are, who's creating the code, some names, other information that'll help us figure out where the code's coming from. And same with the buyers of the code. But we, let's just say that when we get code in, we're really analyzing the tool instead of who's the buyer, who's the seller. It's the tool we want to make sure is clean. So I'm sure a lot of people who are in pen testing or want to get in pen testing are like, oh, this is great. This is fantastic. But where would they go in order to find this marketplace? So the marketplace is called Exploit Hub, and they can go to exploithub.com and sign up to get onto the mailing list. We anticipate launching it next month in October in a closed beta to folks we know, try to work out some of the kinks and then broader after that. Oh, that's fantastic. Tiffany, you were saying that you're going to be vetting the sellers, hopefully. What is that going to entail for them? I'm sort of wondering, because I'm always interested in how we know whether anything's reliable online. So what kind of criteria are you looking at? We are going to be doing an authentication check just so that, well, we're going to, Rick can explain a little bit more of how the financials are going to be handled with the accounts. But pretty much the seller sets up how much they'd like to sell that exploit for what amount. And then we need to make sure that bank account, how it works, the money's going to go to where they say they want it to go. But we're not doing a full criminal background check. We don't really think that's important. Really, it's the tool we are looking at, not the person who's selling it to us. Let me just give out the phone number. 212-209-2900 is our phone number. We have Tiffany Rad, Rick Moy here with us, talking about their exciting new project. Rob. Now, there have been a couple of write-ups of what you're doing so far. I think it was Forbes magazine that labeled you digital arms dealers. That's right. Would you say that's apt? Well, there's something to be said for catchy titles to sell magazines. Yeah. I have a question. Go ahead, Bernie. You guys said that you were going to be vetting the buyers and the sellers. Doesn't this put a big liability on ExploitHub for, say, someone who socially engineers ExploitHub to circumvent your vetting process, purchases malware tools, and then uses them to victimize people who then turn around and sue you guys for providing the malware to the perpetrator? Yep, that's right. That is possible. We do anticipate that there are liability concerns, and we've been spending quite a bit of time discussing how we can manage some of that. Nothing is ever liability-free. We're managing it. But what we are going to be doing is the information that we're collecting about the seller, like I said, we're not going to look into the criminal background but what they're selling. And for the buyer, we want to make sure that they are who they say they are and the account that they give us from which they're paying, that we're going to take their names. And if that particular exploit is used for malpurposes, there's going to be a paper trail. This isn't anonymous. We won't take anonymous submissions. We won't sell to people anonymously. Will it be watermarked? I was going to say, it's worth noting that what we're talking about are non-zero days. So for those of you technical folks out there, that means that these exploits exist against vulnerabilities that have been out there for many years and in many cases, and there are remediations available for them, whether it's patches or security products. So the whole intent here is to provide testing tools so that folks can understand what their own liability and risk is. Okay, we're about to take some phone calls. 202-209-2900. Just one question. How do you think if this kind of thing existed, say, 10, 15 years ago, do you think it would have changed a lot in the hacker world, for instance? Well, I think it may have. I think it's still something that is going to change the hacker world in the sense that we are attempting to legitimize a trade of tools and tools that are really can be used the same as lockpicking tools, for instance. Way back when, it was illegal to possess lockpicking tools. Still is. In some states, it is. Not in most of them, which is good, because the laws have changed. This is just a tool. And while, to answer the liability question, the O days, which are the zero days, those types of exploits, those carry the heaviest liability. And while we're not in the market of dealing with the O days, what we will do is we can help negotiate a responsible disclosure. If people have them and they're kind of afraid to what do we do with the O days, we can help, especially I can help with that, is helping do the disclosure. But we're not going to go full. I mean, you don't need us if you're going to go full disclosure. Full disclosure means you don't give the vendor any type of notice. You just kind of use the exploit, and it's out in the wild. Whereas responsible disclosure, sometimes vendors would like between 30 days, and some of them, like, well, six months to a year is a lot of time for something that's, you know, very high-risk vulnerability. That's a little bit, some people say that's a little bit too much time to give the vendor, but we'll help. A little bit, yeah. Yeah, we'll help negotiate with that if you have something you'd like to talk to us about with an O day. All right. Website again? Exploithub.com. Okay. 212-209-2900. Let's take some phone calls, and please stay on subject, and no speeches and various other things like that, and please turn your radio down. And good evening. You're on off the hook. Hi. You just said stay on subject. I wanted to ask you about something else. Uh-huh. Make it quick. All right. Have you heard about this worm called Stuxnet? I just read about some developments about it that I thought were really interesting. Okay, I'm seeing some nods, so you guys have heard about this? Yeah, can you give a little bit of details about it? I've heard about it, but... It came out, I think, a couple months ago, and it made headlines because it was known to attack industrial control systems, like SCADA, and a security researcher just came out with an analysis about a week ago that was that originally it was thought to steal data, like it was meant to steal intellectual property, but he found that it actually fingerprints the control system, looking for a very specific one, and then inserts sabotage commands. Sounds like something from the movie Hackers. It really does. That level of sophistication. The rumor is that the government of Israel may have created it to destroy the reactor in Iran. It's kind of cool. Well, they have their airplanes for that. I don't know if they need this kind of sophistication, but you guys heard anything about this? I've heard about it, and these are the worms that are, I think, very interesting, ones that aren't just sent out to do massive damage, like the new email type of viruses or worms that are around. Not new, but they're back again. But this one particularly, if it is targeting particular companies' technologies, it is very interesting. When you look through the code and you find where it's phoning home, those that are created for particular people and companies are very interesting and pretty threatening. Okay, let's take another phone call. 212-209-2900. And good evening. You're on off the hook. Hello. I will try and keep everything very short, but on the topic of musical test coils, there was a plan for something that I came across called a plasma tweeter, which is the high-frequency type of speaker that basically just makes noise through an ionized gas. On the topic of the Google Instant, if you pause for a moment, if you stick that result into your Google Web History, it'll even tell you how long you paused for. Wait, whoa. Hold on a second. I've entered so many foul words in the last couple of days. Are you saying there's a record of that someplace? It should be in your Google Web History if you have that enabled, which maybe you don't. Oh, good Lord. It'll record how long you paused for. Where does one see this? It's the Google Web History. It's the Google Web History. I'm not sure which link along the top browser it is. Is this something I'm storing locally, or is it something that Google is storing? It's something that Google is storing, helpfully for you, for your benefit, for your man. Okay. Well, again, where do I see this? It's one of those links at the top, like Calendar and things like that. Okay. And the last, if hopefully it's not too off-topic, but the Haystack program, which was recently revealed, is basically worthless, although before it was lauded as breaking Internet censorship in Iran. No one could get a copy of it to evaluate it. Would an individual program like this benefit from penetration testing through this Metasploit-based product? I think Jacob Applebaum, actually, did look through it and just exposed the vulnerabilities in Haystack in the past couple of weeks. I think it's been done. Okay. But I'm sure there are many other products that have similar claims. Yeah. That's probably how Jake did it. All right. Thanks for your call. .Ret. Manuel, if you're worried about your records being stored, it does also depend on if you have an account or not. If you have an account, there will be a setting in your Google account settings to enable or disable your history for that sort of thing. And if you're not, well, then there's not really much you can do. I believe they'll just anonymously record based on your IP. I want to see. I want to see where it says how long I paused for. I want to see that. I've never heard of that before. Well, I've never seen that before, since I'm sure most of us haven't, because when we last checked the settings, this wasn't a feature. Wow. All right. 212-209-2900. Let's take another phone call. Good evening. You're on off the hook. Speak up. Okay. You got to speak up. All right. Nobody's there. Let's take another phone call. Good evening. You're on off the hook. Speak up, please. Okay. There's something wrong with the phone here. The lights are turning green. I don't know. Bernie, are you still there? I'm still here. Okay. Something. Okay. I'm going to try these ones over here. Good evening. You're on off the hook. All right. Basically, I don't know what's happening. Mike, why don't you take a look at this phone here? Every time I press a button, it turns green. I think someone else is picking up the phone somewhere else in the studio. Do you want to just press a button? Okay. That worked. Okay. Good evening. You're on off the hook. Go ahead. Hello. Hello. Yeah. I had a Monroe virus. Go Monroe. I don't know about that. Do you want to try another one? Try another one. Okay. Good evening. You're on off the hook. Hey. It's Pack Rat. How are you doing? What's on your mind? Yeah. Script. And Twitter. Did you hear about that? Australia, Australian kid, Melbourne, put the JavaScript into a Twitter. It found a vulnerability that apparently went completely crazy. And where is he in prison now? He's actually not in prison yet. This just happened today. Oh. Okay. So where can I tune in and watch the car chase? I would assume Yahoo News. Okay. I hadn't heard about any of this. So Rob, do you know something about this? Yeah. I heard about it early today. Basically, there was a string of JavaScript that someone could tweet that whenever someone moused over the link, it would automatically execute this code and retweet the tweet for you in your own account. I know where you heard about this. You heard about this from one of the guys on Mystery Science Theater 3000. He tweeted about this to me. I just think it's really funny that's what we found out about this. Pretty much everyone was tweeting about it early this morning. Everyone was tweeting about it. Yeah. Everyone was freaking out about it and Twitter patched it and it's now been gone. And I missed the whole thing. You missed the whole thing. Bernie, go ahead. I didn't say anything. Oh, I thought you did. Nope. Oh, I'm sorry. You're still on the phone. So any other thoughts from you? The kid was actually commenting about how he hasn't told his parents about it yet and he is afraid of what the legal repercussions are going to be. Wow. Okay. Well, that's something to think about. I think he lost his allowance for the rest of the week. At least. At least. Thanks for that call. Let's see if we can squeeze in one more. See what's happening there? See, it turns green. I'm not crazy. When I push it, it turns green. When you push it, it turns red. What's wrong with this phone here? That's really bizarre. Okay. See, it works fine. That works for you. All right. From now on, you push the buttons. Good evening. You're on off the hook. Yes. I wanted to talk about the HTCP crack and Intel's threat to Sue. Anybody who uses a device that uses it. Anybody here prepared to engage in this conversation? Do you want to summarize it for us briefly? I'm going to take that as a no. Let's move on. What happened is there's this protocol that HD devices like televisions and Blu-ray players can use to make sure that no one can get at the unencrypted content as it goes from one device to the next. The sort of master key, which is the key that is used to make the keys inside the devices, got out. Now, anyone can make their own HD device and it will appear to be secure. All right. Let's see if we can squeeze in one more phone call in the time we have left. Push the button, Mike. Good evening. You're on off the hook. Hi. Thanks for taking my call. No problem. I'm wondering. This is a very jujude question. Why is it that we never hear of the arrest and prosecution of people who create these viruses that raise so much havoc in our lives? Well, I have heard of people being prosecuted for this kind of thing in the past, but should writing a virus be something that people get punished for? In the United States, it's really when the tool is, it's the execution, the use of a tool that, for most things, unless it's a, I don't want to get into discussion about gun law, but for most of the things that are just tools, lockpicking tools, that's the best example. If you are leaving the scene of a crime, those can be used against you as burglary tools. But the same with code. If it's not released with malicious intent, if you just create it, you write the code. That particularly is not, it's not until it accesses a non-authorized computer that becomes something that's criminal. All right. Tiffany Redd, Rick Moyer. I want to thank you both for stopping in and sharing this. It's fascinating. I'm sure we're going to hear more about this again on the website one more time. ExploitHub.com. Okay. And a bunch of us will be at Maker Faire in Queens over the weekend, so be sure to stop by. Go to MakerFaire.com for more information on that. And if you want to find some bad words, help us find bad words for the Google Blacklist, go to 2600.com slash Google Blacklist. It's a lot of fun for the whole family. See you next week. Bye-bye. Computer love by the Zap Band. Hahaha.