Environmentalists know many hurdles remain to weaning the nation off of fossil fuels. They had hoped the BP disaster would have been the turning point. It wasn't. But they're not giving up hope yet. Matt Laszlo, FSRN, Washington. And that's the program for today. The newscast was produced by Catherine Comp. Thanks for listening. In San Francisco, I'm Danny Wood. And this is radio station WBAI New York. The time is 7 o'clock. And once again, for Off the Hook. And good evening to everybody. The program is Off the Hook. Emanuel Goldstein here with you, joined tonight by Mike, Voltaire, Jim, and Bernie S. down in Philadelphia. Greetings in Philadelphia. Small showing tonight. Yeah. What's up with that? Where is everybody? This is... Really? This is everybody? Last week, we had 50 people in the studio, and now we have, like, four. Maybe... Well, I don't know what's wrong with us, but maybe they're all outside playing hooky because the weather's so nice. I guess. Although, you know, I like playing in the snow myself. But regardless... That's why you're here. Yeah. I suppose. Well, we'll try and get through it the best we can. And we do have some interesting things to talk about, as we always do. Some startling revelations have taken place in the last day or so. But, you know, nothing is more important than welcoming a new area code. And that's what we get to do this week. As of Saturday. As of Saturday, here in New York City, we have a brand new area code of 929. Yeah. Wow. What a nightmare that would have been back in the Rotary days. 212 was always the best area code in the country, because it didn't take very long to dial the thing. Now, it doesn't matter with all the touchstones everybody uses. But 929 is the new code for people who can't get codes in, I guess, the other area codes. It's going to be assigned to people in the Bronx, Brooklyn, Queens, Staten Island, but not Manhattan. Those people who request a new service or line and can't get phone numbers in 718, 917, 646, or 347. And I think we have a test number. Mike, you found this test number, did you not? Yeah, I even called it. And it's pretty exciting, isn't it? Oh, yeah. All right. We're going to call a test number to prove that the 929 area code works. Bernie, any area codes down in Philadelphia? For a good 10 years down here. But we'll probably do for another one. I hate these splits, though. It's really confusing. I used to be able to remember almost all of them. Yeah, the whole thing is really stupid, the way they implemented this. I don't want to go on my usual tangent about how we should have had four-digit area codes, because we could have kept the 212 for the whole region then, and everybody would know where they're calling from. It doesn't really matter anymore, because people are carrying phones with weird area codes from different parts of the country, and nobody really knows where anybody is anymore. Which I guess is some good to that. Maybe people don't want to be identified by their geographical location. And with cell phones, you don't really have a geographical location anymore. But we'll get into the locations of cell phones in just a minute. Here's a test. We're going to get a dial tone here, and call this test number to prove that the 929 area code exists. You have reached the new 929 NPA test line in the Kingsbridge Central Office. You have reached the new 929 NPA test line in the Kingsbridge Central Office. Oh, where's it going? Due to a high calling volume, all of our circuits are busy. Please try again later. Thank you. This is a recording. Wow. I love it. Our BAI listeners... Due to a high calling volume, all of our circuits are busy. Please try again later. Thank you. This is a recording. I know that guy. That guy, he sells bagels down... No, I know him. I definitely know that guy. That voice. Can't mistake it. You know him too, right, Jim? Yeah, absolutely. Sounds like every New Yorker. Sounds like every New Yorker, right? I don't know about that. Look, we're coming through on the phone somehow. All right. I'm going to... All right. That hung up on us. That was a test number. And that tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That hung up on us. That was a test number. And that tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That hung up on us. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That hung up on us. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That hung up on us. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That hung up on us. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That hung up on us. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. It answered last time I tried it. Yeah. This is the danger of calling things live on the air. Oh. The 9X Style Business Center for Long Island is presently closed. The hours of operation are Monday to Friday from 9 to 5, excluding holidays. If there is an emergency, please call Repair Service by dialing 516-890-6611. So, this seems to pre-empt that. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. That tells us where the 929 area code seems to be going through one particular central office. I'm going to... All right. So, it does predate the 516-631 area code split and also predates 9X being taken over by Bell Atlantic and then by Verizon, so, wow. They just leave these things lying around. Okay. We have a caller ID test, and this is a good one. Thank you for calling the Bell Atlantic call block test line. Your telephone number is not blocked from appearing on our caller ID equipment. If you believe your blocking feature is not working properly, please call Bell Atlantic Repair Service, whose number appears in the customer guide pages of your phone directory. Yeah. So, here we have Bell... Now, here's the interesting thing. Can we do star 67 from these lines? Let's find out. Oops. I hit the wrong number. Hold on. Okay. I've blocked the caller ID now. I'm going to call that same number and see if the Bell Atlantic caller ID test works. Thank you for calling the Bell Atlantic call block test line. Your phone number is not blocked from appearing on our caller ID equipment. If you believe your blocking feature is not working properly, please call Bell Atlantic Repair Service, whose number appears in the customer guide pages of your phone directory. Now, here's the interesting thing. Can we do star 67 from these lines? Let's find out. Can we do star 67 from these lines? Now, here's the interesting thing. Can we do star 67 from these lines? Can we do star 67 from these lines? Can we do star 67 from these lines? Can we do star 67 from these lines? Thank you for calling the Bell Atlantic call block test line. Your telephone number is blocked from appearing on our caller ID equipment. If you believe your blocking feature is not working properly, please call Bell Atlantic Repair Service, whose number appears in the customer guide pages of your phone directory. Okay, so this thing actually works. It doesn't give out the phone number. It tells you if your phone number is blocked or not, which is an antiquated system back in the days when this was first introduced. It was called call ID back then. So those numbers still exist. They're still out there. They're still operational. And I wonder when they're going to find them, if they ever actually disconnect them. This listener also, unfortunately this listener didn't sign their name, so we can't credit them. But this is what's known as the Verizon lady on speed. Yeah, I could not make this up if I tried. We're sorry, since you did not select a carrier, this call cannot be completed as dialed. You may designate a carrier to handle this type of call by calling that company or your Verizon business office during regular business hours. To place this call in an emergency, just dial zero. We're sorry, since you did not select a carrier, this call cannot be completed as dialed. You may designate a carrier to handle this type of call by calling that company or your Verizon business office during regular business hours. To place this call in an emergency, just dial zero. Yeah, and that's the present day communication system of Verizon. That's how that company operates. How about an old school recording of a phone call not going through? And this does not come from Verizon or any of the local companies. We're sorry, you have reached a number that has been disconnected or is no longer in service. If you feel you have reached this recording in error, please check the number and try your call again. Yeah, that was a recording that I think we all were familiar with back in the 90s. I don't think they have that recording anymore. And what that recording tells me, if you feel you have reached this recording in error, please check the number and dial again. Which if you dial the number that you thought you were dialing, you're in an endless loop then. You're just continuously dialing because you check it and dial again. So I never understood that recording. But that was something that was part of many of our childhoods growing up to recordings like that. And the final number we're going to call is a special tone. Hopefully somebody can tell us what tone this is. It's actually a series of tones. I think that's it. Yes, that's it. Bernie, any thoughts on that? Well, it could be trying to handshake with a modem on our side and trying different types of modem protocols and tones. So it'd be interesting to try to call that number with one of those old modems, one of those V.everything modems that would do all the known protocols and see if it handshakes. And then see what it accesses. All right. Well, that's a project, I guess. Again, we're not going to give out the phone numbers, but people might be able to glean what the phone number is by what we dialed. And thanks for listening, for sending us interesting phone numbers. We like calling things like that over the air and experimenting. That's what the whole hacker world has always been about. But on to news, because we have some very interesting news that is still sort of coming in. This is a new article that appeared last week about snooping, snooping on cell phones. Now, cell phone users, according to Computer World, say they want more privacy and app makers are listening, but they're not listening to user requests. They're literally listening to the sounds in your office, kitchen, living room, and bedroom. A new class of smartphone app has emerged that uses the microphone built into your phone as a covert listening device, a bug in common speak. But according to app makers, it's not a bug, it's a feature. The apps use ambient sounds to figure out what you're paying attention to. It's the next best thing to reading your mind. The issue was brought to the world's attention recently on a podcast called This Week in Tech with Leo Laporte, and he and his panel shocked listeners by unmasking three popular apps that activate your phone's microphone to collect sound patterns from inside your home, meeting, office, or wherever you are. The apps are Color, Shopkick, and IntoNow, all of which activate the microphone's and user's iPhone or Android devices in order to gather contextual information that provides some benefit to the user. Color uses your iPhone's or Android phone's microphone to detect when people are in the same room. The data on ambient noise is combined with color and lighting information from the camera to figure out who's inside, who's outside, who's in one room, and who's in another. So the app can auto-generate spontaneous temporary social networks of people who are sharing the same experience. Shopkick works on both iPhone and Android devices. One feature of the app is to reward users for simply walking into participating stores, which include Target, Best Buy, Macy's, American Eagle Outfitters, Sports Authority, Crate and Barrel, and many others. Users don't have to press any button. Shopkick listens through your cell phone for inaudible sounds generated in the stores by a special device. And IntoNow is an iOS app that allows social networking during TV shows. The app listens with your iPhone or iPad to identify what you're watching on TV. The company claims 2.6 million broadcast airings in its database. A similar app created for fans of the TV show Grey's Anatomy uses your iPad's microphone to identify exactly where you are in the show so it can display content relevant to specific scenes. Wow. Do you guys have any idea about applications like this? These things aren't necessarily a bad thing as long as they alert the users what they're doing. But the example with Color was one where nobody actually knew that it was spying on users until this podcast. I imagine people have to opt into this sort of a thing. It's not something that's... No, they're not even alerted to it. They're not alerted. As soon as you install the application, it... Okay, but you have to install the application. Yeah. You know what the application does when you install it. Does it auto-install? No, but yes. Well, it doesn't auto-install, but it doesn't say that it's using its microphone. It's recording your sound and sending it back to its server. What else is it for then if it doesn't do that? No. With Color, nobody suspected that it would use sound recordings. Now, on Android, it tells you when you install the application a list of things that it is allowed to do. It would tell you that at some point, this application might access the microphone. But even in that case, it won't tell you that the application will leave the microphone on all the time whenever the application's open. Even with these finer-grain permission models, there's still a threat because you get this long screen of permissions that probably most people don't even read, and it doesn't tell you what specifically it's going to do with these permissions. Amazing. And then today, we just saw this story. Two researchers have discovered that their iPhones have been tracking their whereabouts since they upgraded to iOS 4. While hidden, the data is unencrypted. If you have an iPhone running iOS 4 or a 3G-equipped iPad, Apple is and has been tracking your every move. That's according to Pete Worden and Alistair Allen at O'Reilly Radar. They recently figured this out. Worden is a former Apple employee. Allen is a senior research fellow at the University of Exeter in England. Check into Foursquare, and you'll expect a timestamp to be attached to a longitude and latitude record of your locale. The difference here, of course, is that there's no obvious opting in. It appears Apple does tell users in the fine print of its iTunes terms and conditions. I assume people read every single word of that. Apple has just been going about noting the whereabouts of each device approximately 100 times a day. That's according to Allen and Worden. We're not sure why Apple is gathering this data, but it's clearly intentional as the database is being restored across backups and even device migrations. What makes this issue worse is that the file is unencrypted and unprotected, and it's on any machine you're synced with with your iOS device. It can also be easily accessed on the device itself if it falls into the wrong hands. Anybody with access to this file knows where you've been over the last year since iOS 4 was released. Wow. This is unreal. Now, again, this file is not encrypted. It's simply there lying around. It's hidden, but it's there, and if you know where to look, then you can access it. It seems like something just built for law enforcement. What other purpose could this possibly serve? It's unclear. That's the thing. It's unclear what purpose it could serve. Apple could be using it for some sort of development. They might have just been writing it in some debug mode, and then they forgot to turn it off when they shipped the final product. The problem is that there's absolutely no way to know what this file is for or what gets done with it, and that's the real threat. Well, somebody needs to fess up over at Apple and explain what this file was created for. Even if they give an answer, will you believe them? Well, at least they're acknowledging it. Have there been any kind of acknowledgment whatsoever from Apple? The other thing that bugs me about this, how long have these devices been around for, and it took us this long to discover this? Well, they said about a year. Apparently, it's a new feature with the new version of the operating system. This wasn't in the very first iPhones and iPads. This is iOS 4, which they said was released about a year ago. Okay. Still, it's taking a year to find something like this. I mean, we're not constantly looking for these programs, apparently, but I think this proves why we should. Bernie, go ahead. I was going to say, law enforcement wants to copy the contents of your cell phone when you're entering the country or even in the state of Michigan now. Apparently, the Michigan State Police are driving around with these cell phone forensics devices in their cruisers, and if they stop you, without even arresting you, just asking you to hand over your cell phone and sucking all the information out of it, at least copying all the information out of it, and if they're aware of this file, they could easily see where you have been if they were investigating you for some reason. Now, I know the ACLU is complaining that this is an unconstitutional search, but it would not surprise me if at least federal law enforcement agencies, if not state law enforcement agencies, are already aware of this location file on Apple iPhones, so I'm a little suspicious of it, and I don't like it. This development in Michigan, now, the device that you refer to where cops are searching phones, I just assumed they were taking phones and simply handling them themselves and figuring out who you called and text messages and things like that, but it's something a bit more sophisticated than that? Well, they basically back up everything. There's a variety of products on the market available to law enforcement officers that you can just connect to cell phones, and it will back up as much as it can, not just who you call, but your text messages, anything else, pictures you've taken, messages you've received, and apparently location information, if that's on your iPhone. The law is not clear on this yet. I think it's pretty clear that it's an unconstitutional search, but the ACLU thinks it's worth challenging. The device itself is called the Universal Forensic Extraction Device. It sounds like something out of a science fiction show. It's made by Israeli-based Cellbrite, that's C-E-L-L-B-R-I-T-E, and they claim that it can copy all the content in a cell phone, including contacts, text messages, call history and pictures within a few minutes. Even deleted texts and other data can be restored by UFED. That's the acronym here, U-F-E-D, UFED 2.0. They say it works with 3,000 cell phone models, which represents 95% of the handset market. You know what, guys? We may think, if we're foolish, that we are protecting our data by putting passwords on our phones. No, you're not. You're not protecting anything. The only question I have, the picture I see here of the UFED Physical Pro has a device physically connected to the phone, but I wonder if a wireless version of this might be out there. Like a Bluetooth thing, that would be really interesting. Most phones are programmed not to give up as much information by wireless as they are by wire, for obvious reasons, but it doesn't mean that there are not either undocumented features or just plain old bugs that would allow at least some of this information to be extracted wirelessly. Bluetooth is a poor choice because it's very, very slow. You'd have to stand right next to the policeman for three hours for him to get all your data, but yeah, sure. Anything's possible. I mean, can any of us be surprised if some kind of surreptitious wireless way of handshaking with your phone was developed and only in the hands of law enforcement, and maybe one day those two guys will discover another program on iPhones and Android phones that is actually transmitting more information than you ever agreed to have transmitted? It's possible, but it's also important to remember that if the police want this data, they have a very easy way to get it, which is that they just call up the cell phone carriers and say, hey, give me all the data. Yeah, but they can't get deleted pictures, and I don't think they can get all the text messages. Text messages, for sure. Well, deleted text messages. Yeah, because the cell carrier doesn't know if you deleted it or not. Can't get a contact list. That's not storage. That is true. Although, a lot of people synchronize their contact list with providers like Google. Can't get your desktop picture, you know, for whatever it is that you choose to have there. That's true. If you have something untoward as your desktop picture, they might have to actually look at your phone to see it. All sorts of little pieces that draw a big picture as to who you are and what you're doing, and that's what they're always into. Wow. So yeah, that's kind of shocking. Not surprising, but shocking. I don't know if that's even possible, but yeah. And then we had the story this week about the kind of dramatic move that was sure to send shockwaves through the surging internet poker world. U.S. officials have shut down and seized domain names for the three largest U.S. online poker companies. That happened on Friday. The indictment unsealed Friday alleges industry leaders, poker stars, full-tilt poker, and absolute poker, continued to operate their businesses inside the U.S. in the face of new laws barring internet poker and largely by deceiving financial institutions. And what that meant was that a bunch of internet domains, five I believe in total, were seized. And you have that nice little page up there now saying that the page now belongs to the government or something. Wait, were these U.S. companies? They were operating in the U.S. So I'm not sure if they were U.S. companies or if they just were operating websites there. The people that ran them were Americans, but all their operations were out of the country. That raises some really interesting issues, how the U.S. government can seize the domain name of a company that is doing something that may be illegal in the United States, but legal in the country where it's operated out of. Was the domain name actually operating outside the country? That I'm not sure. Bernie, do you know anything more about this? I don't know where it was operating, but it disturbs me that the U.S. government is seizing domain names of people and companies before they have been convicted of committing any crime, before the operators of the websites have been convicted of any crime. It's sort of almost like prior restraint in a way. It's like if I was charged with something and they seized my domain name that was well-known, I couldn't put up my side of the story on my domain name because effectively the government controlled my domain name. Well, we could parallel this to in the real world if, say, you were running a gambling shop in real life. You would be raided and perhaps they'd post some kind of notice on your door saying this facility has been closed, and I guess you could stand outside with a megaphone and tell the world your side of the story. But other than that, do you see any real difference? Well, it just seems really heavy-handed. I mean, they could effectively shut down the operations without seizing the domain name itself, but they're taking an easy way out and just seizing the domain name. It seems very heavy-handed and ham-handed of the U.S. government to be approaching things in this way. It's scary because you don't know what other domain names are they going to seize before anyone is convicted of a crime. I think it's a power being abused and asking for even more abuse in the future. I want to disagree with you just very slightly, Bernie. I don't think it's very heavy-handed at all because I think it's actually almost totally ineffective because it's very easy for these people, which are outside the United States and those in the United States who have not yet been convicted of a crime, to just buy a new domain name, possibly with a non-U.S. provider, and resume their operations. In fact, there's a Firefox extension, which I wish I had brought the name of, that will automatically, when you go to a seized website, redirect you to the new website of the operator, so you need not worry if you have this extension. I imagine the online poker-playing community, many of whom don't play with real money, are I guess trade information as to what the new domain names are of these companies. In a way, it doesn't effectively put these companies out of business, but for the casual visitor it can be shocking to see that this place looks like it's shut down. Why exactly is internet poker illegal? I understand the dangers, but all I see whenever I turn on TV late at night are poker shows these days, and it seems like it's being pushed everywhere with casinos and state gambling and things like that. It's only when the government does it that it's okay, and not anybody else. Is that the message? It's when the government's not getting their cut of the action. All right, so that's what this is all about. The federal government has the power to regulate interstate commerce, and so the internet poker falls into that. I still don't see how they can prevent people from accessing websites in other countries, other than what they're doing now, but there are websites in other countries that would not be able to be touched by the feds, and I guess they would just go after the people for accessing the websites in the first place? Because the .com domain is, the registrar that does that is U.S.-based, so they can pressure them. Well, not all the registrars are U.S.-based. But the .com one is. Is that really true? There's no foreign registrar that registers .com addresses? Well, it's complicated, because there's the entity that runs the .com, which you can't do business with, but there's the registrars that do do business with them, and I don't know which level the U.S. government intervenes. It's certainly safer, if you're concerned about the U.S. government, to transact with foreigners. Does anybody else think it's unfair that the U.S. government has got .com, and .gov, and .org, and everybody else has to use a two-letter country code beyond that, like .ru, and .cn, and every single country in the world? We get the default, .com, and .gov. Well, I think the .com is pretty international now, but the .gov is a little suspicious. Yeah, well, I mean, as we just said, .com seems to have the final say-so by U.S.-based companies. It just doesn't seem as international as the Internet really should be. But regardless. All right, we have a special guest who's going to be joining us in just a moment, as soon as Mike reaches him on the telephone. But before we get into that, I just wanted to mention some updates with regards to—we were talking about MetroCards the last couple of days—the last couple of shows, that is. People have written in and shared information as to what exactly is going on when you have a card that expires. Turns out, Jim O'Grady wrote this story for transportationnation.org. He says, New Yorkers, have you ever lost a MetroCard for six months at the bottom—I'm sorry, for months. There's no six in there. Have you ever lost a MetroCard for months at the bottom of your purse or in between the couch cushions? Maybe you still have one that would be worth $10 if you hadn't let it expire. Add those to everyone else's lost or unused MetroCards over a year. The total comes to $52 million. Yeah. Practical terms. Riders absent-mindedness helps the New York City MTA. Say your cousin from Louisville leaves town with a pay-per-ride card with $8 on it. That's a service purchase that the New York City MTA needn't provide. But that money, all $52 million, could potentially be cashed in by riders. So it sits on the New York City MTA's books as a liability. Yeah. So, you know, they're depending on this money. They're depending on people not cashing in their MetroCards. And wow, how legitimate is that? Well, I mean, I'm not sure that this is a new problem with MetroCards. You could lose tokens or take them back to Louisville or whatever you want. Yeah, but you could always use them again later. You know, if you have a token, you could always bring it back to the city and throw it in one of the machines. I don't know if you lose it. I'm saying if you bring it back with you. I'm sorry. If you bring it back with you, you could... Or somebody could find it if you lose it. Here you have MetroCards that expire. They're no good anymore. You have to go through all kinds of hoops to get any kind of refund if they do expire. And plus you have tickets for the commuter lines that expire after two weeks. So there's all this money being paid for services that are never used. And it definitely strikes me as not being totally honest. It's a million dollars a week. Uh-huh. I mean, how do I get in on this? I'd like to be able to provide services and not ever actually have to give them to anybody. You know, there are ways to do it. Uh-huh. Okay. It's not very honest, I don't think. Okay. Joining us now on the phone from California is Aesthetics. Aesthetics, are you with us? Hey, yes, I sure am. Thanks for having me. Thanks. Thanks for being with us. Astute listeners and hope attendees might remember that Aesthetics was one of the key organizers of the AMD project that was a part of our whole badge system, which a lot of people really were impressed with. First of all, you want to tell us something about what those badges were all about? Yeah, sure. So just to give people some more context, they are location tracking and social networking devices. And that gets really interesting. But the whole purpose behind it was if you go to a conference, the whole point is you want to talk with people. And what we found was if you go to, say, Hackers on Planet Earth conference, often people kind of become not antisocial, but there's a certain degree of ice breaking that you have to do and it requires a bit of confidence. And not everyone has that. We wanted to create this as a project to sort of give people an opportunity to find out what common interests they have, things like that. So it's a great way for people to meet each other. Okay. And is that what happened at the conference? We had overwhelming success with it. We had a lot of people who they really enjoyed it. And overall, we had a lot of great reaction from it. The other element of it is the – so I've told you about the social networking. The other element of it is the location tracking. And this is kind of crazy. To give just an example, you come to the conference and you put on the badge, put the battery in it because it's an opt-in thing. And then suddenly the system can see where you are at all times. And that's kind of crazy because it gets into this whole, you know, the system tracking me that people know where I am and the good and the bad of that. Yeah. Well, at least in our case, people opted in, right? Nobody was being tracked without their permission. No, absolutely. And one of the key interesting things that I found is that at least at the last HOPE conference, we guaranteed populated badges as we called them for – When you say the last HOPE, you mean the next HOPE, right? Right. Right. Okay. Let's make sure because we're so confused by our own names. The last HOPE took place in 2008. The next HOPE took place in 2010. Right. We actually deployed both of them. True. But what we found is that we had two badges. One was the populated and the other was just a regular badge. And there were a lot of people who came to the conference to discover this project and they're like, I want to be tracked. And they actually got upset when we were out of populated badges. So people liked this so much they wanted to join and they even got upset when they couldn't. That's awesome. Aesthetics, how can this project be abused? All kinds of different ways. But the thing is, the way we're doing it is open source. So anybody who's interested in contributing can and we actually had a number of cases. For example, at the most recent conference, somebody changed their badge firmware so that they could spoof other people's badge IDs. So that's a fantastic way to abuse it right there. And maybe it messed with the system a little bit but it was lots of fun. So I could take my badge and modify it and pretend to be you so that there would be a dot moving around the map labeled Aesthetics but it would really be me. Yeah, not only can you do it, somebody did it. And it was kind of crazy, I give them mad props for it. But that's just within the conference setting. Other places where these things could be abused is, say somebody is using this to track their employees and make sure their employees are doing a good job. So one of the things we're looking at is all the social and privacy implications of these badges. Interesting. Now, you guys are planning something for the Chaos Camp taking place in August in Germany, right? Yeah, we're looking at setting the badges up again. And we actually have a brand new kind of badge that we're working on. It's this totally new design and has USB and everything, which is really cool because the way it works is there's USB directly on the badge. If you go to openamd.org, you can take a look at it. But you can actually plug your badge directly into your computer. And that allows people to more easily work on the firmware. And it's Arduino based, which means that people who already know how the Arduino works or are learning things about it, they can go in and hack on the firmware themselves. So we're just trying to make it more open and more accessible to the general community. For those listeners who might not know what Arduino is, do you want to give a very brief explanation? Yeah, sure. Anybody who has, let's see, there's a bunch of cool hardware projects going around. For example, I think MakerBot is using this. And other things, if anybody reads Make Magazine, there's all kinds of little instructables. But it's a very easy to use microcontroller, which allows you to write your own little programs and do all kinds of hardware hacking. So if you want to do a little DIY homebrew project, then usually Arduino is the interface that you would be using for it. So by learning this, you get access to a whole bunch of other stuff. And it's really easy to use. Go ahead, Barney. I just want to also point out to our listeners who might not be familiar, that AMD is an acronym for Attendee Metadata. The conference attendees, it shares metadata of where they are and information about the attendees. But it has nothing to do with a company, AMD, who makes microprocessor chips. Oh, great. I agree. Yeah, hopefully they don't think so either. Now, Aesthetics, can you tell us something about the history, how this developed, who was instrumental in putting this all together over the years? Sure. So from what I recall, originally this stems out of the CCC, the Chaos Communications Congress, over in Germany, in Berlin every December. Miloš Marijak and his wife, Brita, from OpenBeacon, were the ones who originally created this project called Sputnik. And a bunch of people went over there for one of the congresses, and they thought, wow, this is an amazing project. We have to bring this back to Hope. And so, I want to say early 2008, we were looking about trying to figure out how can we integrate it. But we were also thinking, well, we have to add something of our own to it, which is where the whole Attendee Metadata part of it, so the social networking part of it, comes into play. And from there, we've just improved upon it. We have brought more community people into it, and we've actually built kind of a team around it. It's a lot of fun. All right. So now you've got what's known as a Kickstarter program going for the CCC project? Yeah, what we're doing is we have everything covered, but we want to give back to the community, so we're allowing people to go on and get badges, and we've created a Kickstarter to do that. And if you go to openamd.org forward slash Kickstarter, you can check it out. For our listeners who might not know what Kickstarter is all about, you want to fill them in? Sure. Yeah. So Kickstarter is kind of crowdsourced funding. It's a new phenomenon, which basically you set a goal, and people can come and they can pledge money towards a project. And so a lot of indie artists use this for putting out a new album and whatnot, and we decided, hey, why don't we try doing pre-sales over this and see how it goes? And it's really interesting, because it's no risk for the people involved, because if the project doesn't meet its goal by the deadline, which in our case is going to be May 1st, then the money just doesn't happen. And anybody who pledged, they just, you know, they're scot-free. On the other hand, people can get all kinds of cool stuff out of it. So really, it's a great way to use the community to bring people together and fund projects. It's also a great way to support the project, even if you can't personally be there yourself. And also for the people who can't afford to support it more than other people, to kick in whatever they feel is good for them. So May 1st is your deadline. Are you optimistic that you're going to reach your goal by then? Well, we're doing what we can. We've put out a bunch of stuff. We have an article up on Hackaday, and we just posted something on the Hackerspaces.org blog with lots of information. So really, it's up to everyone out there. All right. So if you are able to pull this off, it means that every attendee at the CCC camp will have one of these, or people who choose to have them? Right. So people who pledge on the Kickstarter, they're guaranteed a badge. And people who come to the conference, we will be selling them for whatever. We will have a limited supply, so you kind of have to get it early, because there's not going to be one for everyone. I want to make the distinction, this is not the official camp badge. This is an independent project that we're running. But it's lots of fun, and the camp has given us good lessons. And also, the whole idea of a camp, it's a huge space. Being able to watch people as they explore throughout the acres and acres of land, I assume that most, if not all, the land will be covered. That itself is going to be fascinating. Yeah. It's going to be an interesting challenge. The two areas, there are different types of what are called villages, and then there are talk silos and other things. And we're going to be focusing mostly on the villages and the silos, because there's a bunch of other things. If we tried to cover, say, all the parking area, that would be insane and ridiculous. But there's a whole bunch of different things that we're looking at. We're also setting up, say, protective things for in case there's bad weather. We want to make sure that people's badges will be protected, and the hardware as well. So a lot of different things to take into account. Definitely a challenge. So people who aren't going to go to the camp, which is a shame for them, they can still go on the Kickstarter and get a badge and play with it and track themselves around their house maybe? Sure, absolutely. Yeah, absolutely. We are going to send badges to people who have pledged but can't make it after the camp. And another way that people can get involved, we have a lot of stuff going on right now in terms of software development. We're still working on all the firmware, and we're putting a bunch of new visual features together. So to give people an idea of the visuals, if you've been to any of the HOPE conferences, for example, you may have seen a screen that showed what we call kind of the marauder's map. You have a map of the conference, and then you have little dots moving around, which is actually you. And that's pretty cool. And what we're looking at is ways that we can make really, really cool visuals, do data mining and things like that. Because what we have is locations of where people are, as well as all their interests that they've gone to the website and filled out a profile and whatnot. And we want to figure out really fun, creative ways that we can explore on visuals and data mining stuff. So if you're interested in getting involved, again, go to openamd.org. And if you're interested in participating in the camp, ccc.de has information. If you go to events.ccc.de, you'll find some, it's rather vague info at this time, but it's getting more and more specific. There's a call to papers. I think that closes on May 1st. So if you are interested in presenting something, definitely look into that. There's also a very well thought out call for a space program. So if you're interested in a space program, definitely check it out. Space program. Okay, fine. Yeah, it gives you an idea of where minds get to in situations like this. So yeah, it's going to be fun. It's going to be a blast. I think as many of us as can possibly get over there, we'll definitely try to do that this August. So Aesthetics, one more time, give out the URL for people to contribute. It's www.openamd, as in attendemetadata.org. And we're looking for volunteers as well as if anybody's interested in sponsoring, that's fantastic too. So. All right, great. Well, best of luck and thanks for all the efforts you put in. Cool. Well, thanks for having me. All right. And we'll be in touch as this project develops over the months ahead. It's always something exciting happening. We're going to take some phone calls, 212-209-2900, like to hear what our listeners are up to. A couple of interesting things going on in the world, which I think people need to know about. This involving the Ministry of Defense over there in England, a story from the Daily Star newspaper over there. The bungling Ministry of Defense workers have laid bare Britain's nuclear submarine secrets to our enemies. It's a bit historical sentence, but maybe it's true. A classified government report into the sub's vulnerabilities has been published online with key parts blacked out to prevent sensitive material getting into the wrong hands. Fair enough. But a massive blunder has meant anyone with basic computer knowledge could reverse the censorship and read every word of the previously restricted report. It reveals how easy it would be to cause a Fukushima-style reactor meltdown in a sub and details the capabilities of U.S. vessels. Wow. So, Mike, what kind of technique did they use to do this? I haven't looked at this document in particular, but generally the problem is that people make a PDF and then they put black bars using the PDF tools on top of the images or the text or whatever, but you can usually just copy and paste. It doesn't require the advanced technical skill that this paper says you need. The underlying thing, as we've said before in this program, that if you are an evil agency and you wish to release a document but not all of it, the NSA is your friend because it has published a guide called Redacting with Confidence. And I guess the people in the UK didn't read it. Well, computer security expert in this story, Graham Cluley, said the MOD had committed a schoolboy error. The senior technology consultant said it's a staggeringly stupid thing to do. Anyone with even an elementary knowledge of computing would know how to read it. I can only assume they gave it to a junior member of staff to deal with. If this document is like this, who knows what else is. It's very sloppy security. Dot Ret, welcome. Hello. What's... You have something to say on this? Yeah. I was just going to say that, you know, I think that it could have been given to a senior member of the staff. A lot of the people in governments don't really know how these technologies even seem to work. It's black. No one can read it now. Yeah. You think that. But I don't know. People just read some security manuals. It's not that hard to figure out that you're not really blacking anything out by doing this. And that's another reason why I think it might... It could just be senior level staff. They don't read anything. They just, you know... I think everybody's guilty of not reading enough. Yeah, that's true. And one more story. Then we'll take some phone calls. And this comes from a site called techdirt.com. Here's a follow-up to a story posted a few months ago about college student Evan Emery, who put together an admittedly sophomoric video on YouTube that made it look like he was singing a sexually explicit song to elementary school kids. It's not hard to figure out how somebody could do that. You film somebody singing, you film reaction of kids, and you film someone singing again. It's called editing. And it makes it seem like someone's doing something they're not, in case anybody didn't know how that was possible. So he didn't actually sing that song to the kids. He sang perfectly reasonable children's songs to the kids, and only later filmed the explicit song in an otherwise empty classroom, and then, for fun, edited the two together. While this does seem childish, it's hardly unique. In fact, the very same thing is quite frequently done on various TV shows and in movies. Yet in this case, the guy was arrested and is facing 20 years in prison for manufacturing child sexual abusive material. Now, actually, what has happened was he's been sentenced to 60 days in jail, three years probation, and now he must remain 500 feet away from minors. At least he doesn't have to put his name on the sex offenders registry. But imagine this. The parents of the children are still angry. A news report from the courtroom shows a father complaining that the sentence isn't enough, how his daughter is traumatized by the whole thing. But that leads to the obvious question of how she even heard the song in the first place. She wasn't present. Everyone is acting as if he actually sang the song to these kids, when he did not. Emery's own lawyer calls the plea deal fitting, but honestly, it seems silly. Yes, the video he put together was childish and stupid, but does that really deserve jail time? Anybody here think it does? Or... Go ahead, Voltaire. I think it's more than just silly. It's downright scary, the precedent that it sets. Absolutely. What would happen if somebody else did the edit? What would happen if somebody else edited the pieces together to make it seem like he was singing something to school kids? Would they then be guilty of this kind of material? Or would he be guilty? Or would people reading it be guilty? Mike? I mean, as you said, as the article said, this is a very standard technique used by all kinds of media productions. If you want to have footage of a murder in a school, but you don't want to actually expose small children to a murder, then you edit it together, and it's a good way to do it. I don't really get why this is any different. And that would basically mean any film director would be guilty of murder, maybe? If they filmed what appeared to be a murder? Not any film director, but many film directors. Or just something inappropriate for kids? If they edited something together, it made it seem like they were witnessing something? What I found really disturbing about this is that what we're talking about here is these laws are supposed to protect people from being harmed. How are these children being traumatized by something they were never exposed to? This sounds almost like a thought crime. You know, someone thought of singing an explicit song in front of children. That's horrible. How dare you put that in our minds? I love the outraged parents. The outraged parents for kids who weren't even there when it happened. Even if he actually did sing the song in front of children, then Diane, it still would have been upsetting that he's getting jail time. That's a criminal offense. That opens up a whole other kettle of fish, then. I'm sure people would have something to say about whether that kind of thing is appropriate or not, and what kind of penalty, if any, should exist if something like that did happen. Before we go to the phones, I just want to make sure that our listeners are aware of the news in the Bradley Manning case. He is being moved, apparently, from Quantico, Virginia, where he's been held for many months and been basically tortured. He's being moved to Fort Leavenworth in Kansas. There's some hope that his treatment will improve, but of course, there's no guarantees of that. Why can't he be tortured in Kansas? I know many people are tortured in Kansas. Just being in Kansas is torture enough for some of us. You said that. I didn't say that. I just made an allusion to it. You made me say it. The fact of the matter remains that it's possible that this is some sort of face-saving move where they can say, the treatment in Quantico was fine. We're just moving him to some people who won't torture him just because. But it's also possible that the torture will start up again in Kansas. Hopefully, good news, but certainly not there yet. Kansas is also pretty far away from major cities like New York and Washington, where people might be able to have easier access for demonstrations, things like that. I'm not sure how many people would demonstrate in Kansas. I know one group of people that would demonstrate in Kansas, but somehow, I don't think they are going to come out on his side. Quantico is right outside Washington, D.C., so relatively easy access for people to get to. Okay, very quickly, then we're going to take some phone calls. Yeah, I'm worried that besides this just being a face-saving move, this is actually done specifically for that point, so that way less people can get there to protest, so there's just less visibility of this whole issue. They might be hoping people will just forget. All right, 212-209-2900 is our phone number. If your name is Rebel, do not call that number. Call any other number but not that one. If we pick up the phone and it's Rebel, we will not be happy. 212-209-2900. Good evening. You're on off the hook. Go ahead. Oh, hi. Hi. I'm surprised that you guys didn't talk about this Android app that some researchers came out with a couple months ago that did exactly the same thing you were talking about. It listened using the microphone for ambient noise, except it did the exact evil thing you would expect. It listened for people saying numbers. It calculated what the numbers were and sent them back to a central server. Numbers? Yes. There's a YouTube video. They call it Sound Comber, like combing your hair. Okay. They demonstrate, literally the guy has the app on his phone and he says his credit card number and it shows up on his computer a few feet away. Oh, wow. They did not release the code. These are researchers. They're not evil people, but really it's only a matter of time. No, that's true. The latest, what was it? Phishing scheme from your phone? You just speak numbers into it and it gets transmitted to some faraway place where evil people are doing credit card fraud and all kinds of other things? Wow. They made a research paper and they explained it. They kept the permissions that the app asked for down to really a bare minimum, so it's very difficult to tell that it's doing anything at all. All right. Well, thanks for that. Let's take one other phone call. We don't have very much time. Good evening. You're on Off the Hook. Yes. I'm Tom from the Bronx here. Hi, Tom. I'd like to say that there's so much paranoia floating around. In the Bronx, in Co-op City, there's a movie theater that they have a bunch of Maxwell Smarts and Smartines running around trying to figure out who's from the Mideast. I've been approached a dozen times at least when I'm going over to the movies. I gave up going to those movies. Uh-huh. And they'll come over to you with something like a Mideast voice, like a town or something. They want to see if you respond to it. All right. Well, Tom, we're out of time, but I would just suggest don't talk to anybody. No, no, I didn't. All right. I didn't talk to anybody. What I mean to say is they're sick. Uh-huh. And they got the Burger King doing it next door, too. Well, we've known that for quite some time, but thanks for that information. Whenever they start these government programs, it always starts in the Burger King. That's something to remember. And now, our feature presentation. That's our show for tonight. We'll be back next week. Good night, everybody. OTH at 2600.com is our email address. See you next week. Doug, you sucker. No luck to watch what people say. These songs lead you away. Get those dummies to dinner. Just play that sound. Let's give it that new thing. Oh, yeah, yeah. Yeah, that's what I say, funky music from these guys that are off the hook.