Got questions about your computer? Mm-hmm. Want to know about the latest electronics? Yeah. Are you confused by high-definition TV? A little. Well, tune into WBAI every Wednesday at 8 p.m. for The Personal Computer Show. Yeah? Yeah, that's every Wednesday on WBAI 99.5 FM. Oh. So why don't you tell a friend? Well, okay. And tell your boss. Well... Hey, call your mom! Learn all about The Personal Computer Show every Wednesday at 8 p.m. on WBAI 99.5 FM. Oh, okay. And you are listening to WBAI New York 99.5 FM. The time is just about 7 o'clock. Time for another exciting edition of Off The Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a call. We couldn't get much worse, but if they could, they would. Bum-diddly-bum for the best, expect the worst. I hope that's understood. Bum-diddly-bum! And a very good evening to you. The show is Off The Hook. Rob T. Firefly here with you. I'm joined in the studio by Mike. Hi. redhacked.red. Hello. Gus is here. Oh, hi. And Jim. Hello. And on the phone, I believe we have Bernie S. in Philadelphia. Yes, greetings from Philadelphia. And we've got Emanuel in Parts Unknown. Yeah, I'm in a town called Rockwall, Texas, that literally I just pulled over the interstate because that's where I happen to be at this hour, and I just discovered they have free Wi-Fi. I'm kind of just surfing the net right now. Excellent. They don't have payphones, though, from what I hear. What's that? I'm sorry, I'm miles away. What? I thought you were on this radio program, but you said they don't have payphones in that town. Hang on, let me just close my Facebook page. Oh, gosh. Yes, no, it is a nice day, you're right. It's kind of hot, though. But boy, I'll tell you, it's Texas. So what are you doing in Texas? Good question. In fact, a few people have asked me that. Basically, I had the situation where a friend moved to Arizona and left his car in New York. He's rather absent-minded. And he said to me, Emanuel, would you be kind enough to drive my car from New York to Arizona? And, you know, I do that kind of thing. I enjoy doing that kind of thing. So I decided, yeah, why not, I'll do that. I basically started off very late Sunday night. Actually, I made it. I started about midnight on Sunday and made it all the way to Champaign, Illinois in one shot. It was about 18 hours of driving. And the funny thing is, I'm driving a car with no license plates. It just has a temporary piece of paper on the back window. But it's a really kind of interesting way of dealing with law enforcement when you realize you're riding down the street and you have no license plates at all. And usually you get pulled over for one reason or another, but this is pretty much waving a red flag in front of them. It's interesting to see how they react. Inside of ten minutes on Long Island I was pulled over. That's the only time, though. I figured I'd be pulled over every half hour like clockwork on the way out here, but nobody seems to really care. Emanuel? Yes? Is this a state temporary license piece of paper in the window, or is this just something somebody hand scribbled? And you said there in Rockwell there's free Wi-Fi. Is that municipal Wi-Fi that the local government provided, or is this just some individual's Wi-Fi or some company like Starbucks? Any other questions? That's it. Okay. Well, let me tackle your first question at the beginning. No, this is not like a Timothy McVeigh type of car here. It's like they scribbled something random on a piece of paper and expect that to be a license. It's a state-issued license. The thing is it only lasts 30 days, and this is what happens when you have a car that's not registered in any particular state. Actually, New York is very difficult to get this. Arizona was very easy, so it's actually an Arizona piece of paper that expires at the end of the month. And I've already forgotten your second question. I'm sorry. The Wi-Fi. Oh, yes. The Wi-Fi. It comes from the Rockwell Public, so I imagine it's the municipality doing this. That's great. I had to agree to a few things. I'm not proud of it, but I had to agree to these things before I could start surfing, but I did, and here I am. I'm not connected through the web now, but I'm basically able to connect almost anything. But you had to sign over your firstborn child to the Patriot Act or something like that? I don't want to go into what it is they made me say, but I just want to see, first of all, if 2600 is blocked. And, yeah, it is blocked. The website page is currently unavailable. Your organization has chosen to limit viewing of this site due to the rating of its content and, in parentheses, computer hacking. If you feel that you have received this page in error, please contact and please, listeners, please contact these people. Rockwell County IT, phone number 972-204-6250. Once again, Rockwell County IT, 972-204-6250. But before you call them, though, there's some folks a little bit closer to home. I was actually in a New York City public school a little while ago, and 2600 is blocked there, too, for more or less the same reasons. So if you feel like calling the New York City public school district. There's probably some blacklist that's just shared either among these tools or. . . Well, Gus, do you have a specific phone number for those people? I don't offhand, but we can. . . If any callers out there want to do a little bit of research on that, but just find the New York Board of Ed's site. Mike has an idea. I'm looking at a web page right now that says that 2600 is not appropriate content for the city of Rockwell, and they have a phone number for people to call if they feel that that is not proper, that is not correct. And I can give the phone number again if that's what you want. It's 972-204-6250. And just ask why they block something like this. First of all, the only thing really that's on our web page are the radio shows that we do here. There's really no computer-hacking content other than news stories. The computer-hacking content is in a magazine. I don't know if the magazine is blocked in here, but the website doesn't make any sense. We've talked about this before, how these censorware things work. And what it is is private companies that build the lists, and the governments or other private entities just buy them and the software to run them. And there's really no effective redress available because the censorship is outsourced and the government doesn't do it itself. And there's probably no vetting or no openness to the process of how they decide whether they're censored or not. There's absolutely none, and it's done by computer mostly because there's no way any company could amass enough staff to go through the whole web and decide what isn't offensive. And these algorithms are buggy. In this particular case, though, they give a phone number, 972-204-6250. I've never seen that before. Call early, call often. Also, the name of the software, it's called St. Bernard iPrism. I don't know what that's all about, but that's the software that's running here. A large dog is going to bring you a cask of booze if you use their site, I guess. It might have something to do with that eye on top of a pyramid that's on the back of the dollar bill. Don't say that on BAI. Don't say that. No, people will believe you. Is that iPrism, P-R-I-S-O-N, or prism, P-R-I-S-M? Zing! You honestly think that a company is going to be called iPrism? It's iPrism, as in something colorful and magical. Okay. And very limited in scope. Okay. Let's get to some, well, first of all, I just want to give a slight rant, but that wasn't my rant. My rant has to do with radio. First of all, I did something yesterday which was pretty traumatic, actually, what I wound up doing, because I realized my route took me through this particular part of the country, and I really just wanted to see it for myself. I'm talking about the city of Joplin, Missouri, that was hit by a horrendous tornado a couple weeks ago. And I went through there yesterday evening, and it was simply unimaginable. I can barely describe just the miles and miles of completely flattened landscape where once houses and buildings of various sorts stood. It was definitely a sobering experience, and I just kind of stood there for maybe an hour or so just looking at all the devastation and talking to some of the people. And it's incredible that so few people perished in that disaster. I imagine they're very well prepared for this type of a thing. It literally takes a matter of seconds for something like this to happen and for the incredible devastation to occur. I talked to one guy who lost his house. I was just looking down a random street, and this guy pulled up next to me and said, yeah, my house used to be right over there. Everybody that was there got out, though, and it's safe. No sign of bitterness or self-pity or anything like that, just the fury of nature, what it can do if you're not prepared and if you just turn around for a second, anything is possible. So that was really something to see. When I was driving through the city, though, I was hoping there would be a station like BAI there where people could just sort of talk about what they were going through, because imagine something like this in New York. Imagine the entire East Village being wiped away because that's about the extent of it as far as the landmass, maybe even more than that, of buildings that just disappeared. People want to talk about this. They want to share their heartache and get advice and talk about various things. Everywhere I looked, it was just playing the same music, the same commercials, the same nonsense that you hear on commercial radio all the time. I just figured the people of Joplin deserved a little better than that. Afterwards, I was driving into a state I'd never been to before, Arkansas, and there was this horrendous thunderstorm going on, I mean, really biblical proportion, lightning strikes on all sides of my car as I was driving down this road, and all kinds of thunder and hail and everything you could imagine. And I turn on a radio station that's actually local in the area, and I hear a weather forecast in between stupid music saying that there's a chance of showers tonight. While all this is going on around me, while monsoons of the century are taking place, this idiot on the radio is telling me that there's a chance of showers. And I realized this person probably isn't anywhere near this state and probably recorded this quote-unquote weather forecast eight hours ago and has no idea what he's even talking about or where he's talking to. And that is the state of radio. That is why community radio is such an important thing to have, because in times of trouble where there's all kinds of disasters and weather situations, you need that voice. You need to hear from people who are live in the studio telling you what's going on. That's what you turn to. And I realized as I was driving down this dark road in Arkansas, how would I ever know if there was some kind of emergency approaching? These radio stations have simply neglected their responsibilities to the public. That's my rant. We here might not always know what we're talking about, but we can not know locally and live. Exactly. Thank you, Rob. That's exactly it. It's good to know there's human beings there, and there always are at BAI. We try our best. All right, moving on. What's been going on in the news today? What's this about the Senate being hacked? What's LulzSec up to now? Our friends at LulzSec. What have they done now? They have done a whole bunch of things in the past week. Apart from they had released a bunch of internal info about the Senate.gov's hardware and what they've got going on. They have hit Sony. Of course, a couple of weeks ago they hit PBS. They have hit some games companies and things of that sort. It just seems to be completely and totally random. Hey, Rob, have you seen this website? It's very useful. HasSonyBeenHackedThisWeek.com What? HasSonyBeenHackedThisWeek.com The answer is apparently not yet. Not yet. The latest was on the 8th of this month, which was not much more than a week ago. That just flipped over today then. I guess it's worth keeping an eye on because Sony has been slapped around a lot lately. What was the final tally? Something like 13 or 14 different hacks. Something to that effect. LulzSec has been up to that. They've been disseminating internal information about all sorts of agencies. They have been basically doing so in a manner that's really confusing the mainstream media. That's, I think, one of the funnier parts about all this. Because there doesn't seem to be rhyme or reason behind these. They're just sort of going randomly. The media seem to be looking for a single, solitary reason they're doing what they're doing. Beyond for the lulz, which apparently isn't suitable for primetime news. I was talking to somebody at National Public Radio today, actually, about this very topic. It's hard to explain why this is a good thing. But I tried to bring up what used to happen back in the 1990s, when there were groups of hackers that would go around exposing corporations and basically showing the security holes. And a lot of times this resulted in all kinds of crackdowns against those very same hacker groups or other ones. But the effect was that the corporations were also exposed for having little or no security. And I think that's what's good about what's happening now, is that you don't know who's going to get hit next. But you do know when they do get hit, they're going to be shown for the fools they are, as far as not protecting their clients' privacy or their customers' privacy. And people get to realize just how vulnerable they actually are and how they really don't have any control over their own data. The enemy is not LulzSec. The enemy is incompetence within these corporations. I've got to say, actually, I think the most interesting thing that LulzSec appears to have done in the past little while is there's a defense contractor whose files they've cracked into, and they've pulled up some sort of interesting documents about the relationship between this company and the Defense Department and the activities that they've been asked to do as a part of it. And I haven't gotten a real chance to look closely into it. Bernie, did you get a chance to listen to that audio file they turned up at all? I did. I believe it was a company called Univalence. Right. Unvalence. Unvalence. Unvalence. I think Univalence would have been a better name, frankly, than Unvalence. But I think we talked about Univalence briefly last week on last week's show. If you go to LulzSec's website, which I don't have the—anybody who has the URL, they can give it out. LulzSecurity.com. And do go to the root directory, because their auto-loading sound is great for a little bit of enjoyment. I don't think a lot of our listeners know how to spell that, Rob. L-U-L-Z Security. S-E-C-U-R-I-T-Y.com. Got it. Great. If you go there, you can actually hear an intercepted conference call that the LulzSec crew apparently recorded of this company whose job is to do electronic surveillance for government agencies. And you can really hear what they're up to. It's kind of interesting. And they were really exposed. And I think one of the allegations was that this contractor was contracted to take over part of—was it Libya's IT infrastructure? Yeah. Yes, indeed. Interesting stuff. It's very on topic, too. It's reminiscent of what WikiLeaks was doing last year as far as always being there with a story that's topical, whether it's about Libya or the Defense Department or Sony. There's one particular story about Citigroup. Now, is LulzSec behind the Citigroup hack as well? I don't know if they were. It's not clear that they were. Let's blame them. Let's blame them for everything, because everyone else is going anyway. They seem the type to take credit for what they do. This quote from a listener, Mike sent this in to us, basically about the Citigroup hack. Once inside, they leapfrogged between the accounts of different city customers by inserting various account numbers into a string of text located in the browser's address bar. All they had to do was take the account number and just insert it, and they got all the information about the customer that way. That's the level of security we're talking about. Going back to the story about the fellow, this guy named Kareem who runs UnValence, the reason they got into his stuff, and they got into his own email, because he was using the same username and password for all his stuff, which being the guy in charge of a computer security company, breaking basically rule one of keeping your stuff secure, this is the funny part of it. You can rage and blame LulzSec for daring to do this, but these people are doing the equivalent of leaving your front door open and expecting not to get robbed. Yeah, okay, but Rob, I'm going to take you up on that, because I've made that analogy many times. I hate the house analogy, I really do. And when you make the house analogy, people are going to say, well, I want to be able to leave my door unlocked, I have the right to do that, and lots of people do leave their doors unlocked. How dare you intrude into their homes and just invade their privacy like that? Don't they have the right to shoot you with their shotgun now? Okay, well, then to clarify the analogy a little more, it's like leaving your door unlocked with a big neon sign in front with an arrow pointing to the doorway saying, I left a million dollars in here and I'm not home. Yeah, I think it's more like, you know, it's not you so much leaving your door unlocked, it's somebody else giving you the lock that's broken. Ah, that's a very good point. You remember my old golf course analogy where basically you're wandering onto the premises of a golf course where the company that runs the golf course has left information about all their customers on the front lawn in an unlocked file cabinet? I think that's a lot better analogy than walking into someone's personal domain. I want to go to that golf course, that sounds like fun. I don't usually like golf. You should go to one of these websites and I'm sure you can find all kinds of things. But, you know, what hackers are not interested in, and I'm interested in going into people's personal computers. You won't find hackers logging into your PC or your Mac. Hackers will get blamed for everything that goes wrong with your computer, and that's really the result of spam and malware and things like that made by all kinds of quote-unquote cyber criminals, not hackers. Hackers are interested in bigger things than that, things that involve a lot of people, involve cover-ups and scandals and all sorts of things. And another thing LulzSec had just started doing over the past day or two was they had posted a phone number to their Twitter inviting their readers to send in suggestions of who to attack next. And this phone number was posted and apparently very quickly started getting tens, hundreds of calls per second. And they took this number now that's ringing constantly and they've decided to start redirecting it to random people. So basically the target of their choice is now receiving constant phone calls and basically having a denial-of-service attack done on their phone line. A bunch of targets, including FBI. Yeah, it's been the FBI I think more than once already. So caller beware if you're interested in that because you don't know where your phone call is going to be connected. You know, what used to be a fun prank back, again in the 90s, we're going back in time here. You used to be able to call, do you know what a pager is? Does anybody know what a pager is? Yes. Yeah, they're great. Yeah, they're amazing. You used to be able to call up a phone number and access somebody's pager. You type in some numbers on your touch-tone phone, hit the pound sign. It would beep three times. And some of the companies would allow you to enter another, say, four or five-digit string, which would either be another person's pager number or that same person. So you could make one phone call and loop around and page different people with someone's phone number. And if somebody really annoyed you, you could page maybe 100 people on a single phone call with somebody's phone number followed by 911, meaning it's urgent. And if you do that at 4 o'clock in the morning, not only will that person get 100 phone calls at 4 o'clock in the morning, but they're going to get 100 phone calls from very annoyed people who have just gotten woken up saying this is something important. So it's all a matter of fun that you're opening up by doing that. Of course, that's not possible anymore. There's other ways to annoy people. It's still possible. Sorry. Is it still possible? Absolutely. Pagers are still very reliable and still used by a lot of government agencies and people in the medical industry. I had one until recently. I'm thinking about getting it back again. It's much less susceptible to infrastructure downage like cell phones are. Well, the only people that you can annoy there are people who know that, not average people, unfortunately. But speaking of phone numbers, I made a discovery over the past week working on a project. I was going through some old off-the-hook summations, and I discovered back in the late 90s we had a voicemail number at the radio station that we gave out over the air and probably forgot about. We gave it out to one or two shows, and not only did we forget about the voicemail number, we forgot the password and everything. And just on a lark, I decided to call to see what the number is now. Well, guess what? If you call 212-209-2967, you'll still hear our greeting from 12, 13 years ago. And unfortunately, we have no way of getting into that mailbox, so I have no idea how to retrieve the messages. And I don't know if anybody at the station does either. We have to ask and see if maybe we can get that reset. But I was just blown away that that's been sitting there the whole time. Can we try it now? Sure, go ahead. Oh, that was... I know we didn't. 212-209... Turn it up. Is that it? That's it, but the audio is really low. Yeah, I've got it pegged here, so it's really low. It wasn't that low when I called it. How strange. Maybe it doesn't like to be called from itself. I'll hang up on it. What's also amazing is that it's not full. You can still leave messages on it. It's not completely full after 15, 13 years. It will be in an hour. WBAI got a new phone system at some point recently, and they must have ported over the greetings, but maybe not the messages. Apparently not. That's something. Hey, can I read a letter from another listener? Yes, please. All right. Last week you briefly mentioned and praised LulzSec's recent exploits. A bit too briefly. For example, you didn't mention that 2600 itself was a target of LulzSec attacks. What's up with that? Also, for whose benefit was the release of all Sony usernames and passwords? And is it true that they singled out elderly people to have their personal data released? This is what the story at the Daily Tech said. Is it true? It's true. For a while reading that story, it looked like the word elderly was meant to refer to the veteran hackers at 2600, though reading further showed that did not be the case. So my next question, who is this guy at the Daily Tech that wrote the story? He seems to have a bit of a right-wing slant to his post, apparently. Has or has some connection to Adrian Lamo. And then finally, what is LulzSec trying to accomplish here? I feel that their actions are going to result in a big crackdown on Internet freedom. Nobody would like that more than people in power. No one has to wonder who is behind LulzSec. Please tell us which hackers, in your opinion, might be working for the government. Thanks, Richard. Well, Richard, first of all, to say that 2600 was attacked by LulzSec is not really accurate. There was a bit of a squabble on IRC. I think, Rob, you phrased it rather well on the mailing list as far as what IRC really is in relation to reality. Yeah, I basically said something to the effect of we've learned over the years not to confuse the IRC drama with real life. Yeah, so it was basically an argument between a LulzSec person and somebody on a 2600 channel. And it was quickly quelled. It had nothing to do with us or the organization as a whole. And as far as releasing elderly records, I'm not sure how you would do that. How would you target only elderly users of a system? Particularly the ones on the Sony network, which I don't know about. And the funny thing about that was that this was a piece on Daily Tech, a site called Daily Tech. It was an editorial posted June 5th by someone called Jason Mick. And the big headline was, you know, elderly users compromised and this and that. And the page is full of stock photos of sad-looking old people with their faces in their hands. And it was only updated at the end of it with a note to the effect that the victims of this attack were not specifically elderly. Which would be funny because if they got usernames and passwords, it's kind of hard to tell somebody's age from just those. Unless they're calling themselves like Matlock23Skidoo or something. But even so, that didn't cause them to change the headline. And it didn't cause them to remove the sad old stock photo people. So it makes a nice headline that they can quietly correct at the end of it. Well, is there any kind of advantage to releasing that information as this listener asks? I don't know. It goes back to are they trying to make some kind of point with this or what? But I think the elderly angle is another example of the mainstream media really sort of grasping at straws trying to find some kind of narrative, some kind of reasoning behind this. Well, let's not just call it the mainstream media. Let's just say any medium, anybody trying to make a name for themselves. It would appear that way. I mean, it brings to mind last week when we had the one in four hackers could be a NARC story that was running everywhere. And basically the headline in The Guardian was that there was an army of hackers working for the government, which is completely ridiculous. And not what we said at all. I guess the media just likes to make things as shocking as possible. And this story that the listener is writing about is no exception. What do you think of his theory that this is going to result in a crackdown and exactly what the people that are anti-hacker want more than anything else? Maybe even casting suspicion as to just who WellSec is or are they working for somebody? Well, I think it's worth keeping in mind that one of the things WellSec is exposing is how much the government is starting to actually go into trying to do things in the cyberspace. It's apparently part of their campaign in Libya. So, I mean, it's not like we should just go, you know, suspecting everybody around us or anything like that. But I do think it's sort of, you know, this is all clarifying to what extent this is a multi-sided, you know, effort by various factions who are all going cyber. Now to follow what Gus is saying, obviously what they're doing is they're showing, in my opinion anyway, and I agree with her, that they're showing that the government is already taking actions that, you know, oppose freedom on the Internet. But they probably, people generally don't like when that's being exposed, so they might try cracking down on organizations such as WellSec. But my personal opinion, I don't necessarily think they need to be actually some conspiracy run by the government. There have been plenty of honest people that have done this sort of thing for years since, you know, the hacking community is very young. This seems a bit like a throwback to things we used to see more in the 90s but kind of stopped after the government clamped down a bit. Yeah, and Voltaire is here. Hello. Crackdowns are stuff that activists have had to worry about since, like, forever. Like, we've always had to worry about this stuff since, like, the 60s. But I don't think we should fear crackdowns as reason for us to stop our activities, otherwise the government is already won. Did you hear any of that, Emmanuel? Well, he sounds like he's off mic, but I can hear him, yes. I do agree that that's no reason to stop doing what you're doing is fear of crackdowns. Otherwise, nothing would ever be accomplished anywhere because people would constantly be afraid of the what-ifs. Yeah, the whole point of activism in many cases is that it is, according to whatever regime you're trying to reform in some way, is that it is probably legally questionable. And thinking that, you know, you don't want to do something because you're scared of a crackdown, the whole point is you're trying to reverse that very negative situation. That's assuming that this is activism in the first place. It could just be people just having a bit of a lark. But either way, it doesn't warrant everybody losing freedoms. And freedoms should be something that we're aware of and we defend. And I think that's, by paying attention to these stories, that's what we wind up doing. I think, actually, going back to who this is, I think I've been sort of surprised by a lot of the coverage of how broad Anonymous also seems to be. Like, you know, the crackdown in Spain that just happened and various other places, it surprised me. So I'm sort of finding myself wondering who are the folks involved in this stuff? Because if you're involved with activist groups, you sort of know, oh, yeah, well, these people are affiliated with that particular organization, and these ones think that way, and these ones are anarchists, and these ones aren't. And, you know, so I'm sort of left feeling like I don't know that much about who these people are. Well, they were anonymous. That's why you don't know anything about who they are. Well, that question, though, probably does work better for the Anonymous, the folks called Anonymous over LulzSec. I mean, it seems that LulzSec is some coherent body, whereas Anonymous, anyone who wants to call themselves Anonymous are part of Anonymous. Well, I mean, you don't know how many people they are. You don't know where they are. There's very little that you know about them. So unlike some of the groups of the 1990s that had specific handles, specific people, and you sort of knew where they were, it's a lot more mysterious here, and I think it has to be for them to be able to remain in existence. I'm sorry. Go ahead, Bernie. Oh, yeah, I think one of LulzSec's also more recent exploits was of a U.S. Senate staffer. And headlines around the world were saying LulzSec hacked the U.S. Senate. It wasn't a terribly significant hack from an informational standpoint. It was just one workstation, I think, at the U.S. Senate age or something. But I think it's going to bring a lot of attention on LulzSec by federal law enforcement. So we're going to see how that works out. Yes, absolutely. And wasn't there something involving the IMF as well? Oh, yeah, the World Bank. Yes, the IMF. It's been a busy week, hasn't it? It really has. Yeah, what happened with the IMF was that apparently they're still in sort of trying to find their direction after their managing director last month was arrested. They were hit by what computer experts call a large and sophisticated cyber attack whose dimensions are still unknown. And apparently whatever this was, it was enough for them to— Now, the IMF offices— I'm sorry, but you sounded like Captain Picard on that. Make it so. But the IMF has offices in downtown Washington across the street from the World Bank, and this caused them to sever the electronic connections between themselves across the street over which they could share information because apparently it's just a case of shut down everything because we don't know what's compromised now. They couldn't find another electronic way to get data across the street. Yeah, I think it's really amazing if the IMF, which every time I hear IMF I think about Mr. Phelps and the Impossible Mission Force, but it's pretty much the same thing. Yeah. If the International Monetary Fund, who needs to communicate with the World Bank across the street from them, has to shut down their connection because they're worried about it being a compromise, and they can't figure out any way to establish a temporary connection across the street, I think that explains why their security is so bad. I think their next move is to shut down the plumbing as well. They should get a laser, really. It just keeps getting more and more interesting. Hey, Bernie, I understand that you had an incident with an air conditioner this last week. What was that all about? Fill me in on this. Somebody ordered an air conditioner in your name? Oh, yeah, yeah, that's right. Yeah, it's bizarre. Speaking of IT security, I got three e-mails from HomeDepot.com. I ordered a refrigerator from them last year, but that's the last time I had any business with them. But just a few days ago I got three e-mails, one acknowledging my order for an air conditioner, and then a few minutes later the order pickup barcode where I could print that out and go pick up my air conditioner at the Neptune, New Jersey store, which is a couple hours from me. And then a few minutes later, a third e-mail thanking me for picking up my air conditioner in Neptune, New Jersey. Amazing. Now, I've accessed your e-mail account now, and there's an interesting disclaimer at the bottom. Do you want to read that? Do you have that in front of you, or would you like me to? Yeah, please read it. It was pretty funny. This is a disclaimer that was in Bernie's e-mail that was sent to him. It says, The Home Depot disclaims all responsibility and liability for the accuracy and content of this attachment and for any damages or losses arising from any inaccuracies, errors, viruses, e.g., worms, Trojan horses, etc., or other items of a destructive nature which may be contained in this attachment and shall not be liable for direct, indirect, consequential, or special damages in connection with this e-mail message or its attachment. What in God's name is that all about? And they sent me these e-mails, unsolicited, obviously. I called TheHomeDepot.com, their online department, their order department. They couldn't find any record of the order at all, and at first I thought it was phishing spam, but they weren't asking me for any information. So then I called the Neptune, New Jersey store, and I spoke with a woman named Debbie at the service desk, who said, Yes, Mr. Cummings, I just gave you your air conditioner half an hour ago. Oh, boy. I don't think so, because I'm two hours away in Philadelphia, and I haven't been in Neptune, New Jersey for a very long time, like a year. Bernie, do you know how long you've been charged for this? I said, Did you ask them to show a photo ID like the store pick-up barcode certificate says? She said, Oh, no, I didn't ask them for a photo ID. So we have all kinds of security problems at TheHomeDepot.com with their ordering system, with their failing to ask for a photo ID. Apparently none of my credit cards was charged, though, so they may be confusing my e-mail address with another person. It's very bizarre. I'm trying to get to the bottom of it, and they're not talking. Well, the amazing thing is, as far as I'm concerned, even more interesting than the air conditioner is just that disclaimer at the end of the e-mail. And is this really their boilerplate disclaimer saying that they're not responsible if they send you a Trojan horse or a worm or something in the e-mail that they send to you? Is this really what companies are going to be saying from now on? I forwarded it to TheHomeDepot.com people in their order department, and they verified that it was a legitimate e-mail that I received. So, yep, that's what they're saying. And I guess everybody else is going to say, Well, it's not our fault if we send you a virus. Bernie, are you sure that a credit card hasn't been added to your account? Because it seems to me that that might have been – I've had people sign me up for their Target.com orders where I could have totally gone in and changed the mailing address to send it to someplace else or whatever like that. But it was just sort of like they somehow got the password sent to my account and things like that. So is that something that happened to you? Well, I haven't done another credit check of mine lately, but it's a good idea for me to do so. What's interesting is, though, if they got another credit card in my name, why would they use my e-mail at my – I'm not saying in your name, though. I'm just saying that they maybe used your e-mail address but added another credit card. How would anyone benefit from that? It wouldn't make any sense. Well, the one issue is why would they take control of Bernie's e-mail account or whatever just to use their own mode of payment? They have to be stealing something else. What would be the benefit of this? No, no, no. That's not what I'm saying. I'm not saying this person is a thief. I'm saying they're stupid. I'm saying they've just signed him up without knowing it wasn't their e-mail address because that happens all the time. Bernie, it sounds like you need to place an order with thehomedepot.com and ask them to use the same billing information on your last order. I've got to say, somewhat related to what Gus is saying, I have a Gmail account. I'm not going to give it out on the radio, but basically everybody with my last name and first initial, I guess I just did give it out, thinks that Gmail account belongs to them. And I get all kinds of e-mail with all sorts of private information, sales confirmations, airline tickets. God knows what these people trust to send to this account that is not theirs. I don't know why they keep giving it out, but I feel like putting up some kind of website and just publishing it all because hey, it's all getting sent to me anyway and you guys aren't protecting your own information very well. I've actually been doing that. I've actually been collecting this information and sort of debating whether or not to publish it. But the thing that got me is I got signed up for a school's e-mail list in Sacramento, and the school said unless you actually physically come into our office, you cannot unsubscribe from this list. So I was getting all kinds of information about when class trips were and when to pick up your child. So this is not exactly security we're talking here. And if I have to walk to Sacramento to get it off it, it's just not helpful. It's only a few thousand miles. Surely you could do it. Hey, this was the week that the Sarah Palin e-mails were released. I assume we've all been busy reading these. I've read one or two. We were discussing a mail before the show, this story, and we couldn't come up with anything interesting to say about it. One of my friends had one, and it was a guy who wrote to Sarah Palin to be like, I just think you're really wonderful, and you're a great role model for my daughter, and I really want you to run for vice president because I just think you're an amazing person. And I actually tracked down the guy's online handle and found that he was also a really big Mac devotee. He's a big Mac user. And he just has these really weird ways of sort of like almost sexual ways of talking about the Macintosh. So I think I sort of determined that if you're going to be writing to Sarah Palin and telling her how much you love her, you're probably nuts. Well, apart from that, I really want to talk about how these e-mails are being disseminated. Now the government is releasing these e-mails, but not electronically. They're in the form of 24,000 pages of paper printed out and put in boxes. And to get a copy, journalistic organizations have to apparently go to Alaska and pick this up. I'm not sure about that, Rob. I have a bunch of PDFs right here. No, I do too. Because what happened there is that other agencies have been getting hold of the paper copies and then scanning them in. Right. Wired, I think, has been doing it. Wired has been doing it. I think the AP, somebody else has been doing that. A quick way to digitize 24,000 pieces of paper is to have a sheet feed scanner, and that will do it pretty quickly. Yeah, and such things exist. But the quote here is that the state said that it was not practical to provide electronic versions of the e-mails. So apparently it was far more practical than just pressing forward on something to just print it all up into 24,000 pages and put it in big heavy boxes that you have to go get. This is the government of the state of Alaska we're talking about here, Rob. I mean, how surprised are you really? I find it interesting that the way it's being spun by the right-wing media, and they are spinning this really incredibly. The Washington Times, which is a bastion of right-wing media, the headline reads, the Sarah Palin e-mail mania backfires on the media as 13,000 e-mails of the former governor of Alaska, Sarah Palin, were released on Friday. The liberal mainstream media scurried down to general Alaska to collect 24,000 pages of what they thought could be a damning story. Dozens of major news publications released the 24,000 pages online to find something to smear the possible 2012 Republican contender, but their search came out dry. Instead what they found was a hard-at-work governor leading the great state of Alaska. I don't know if they've read all 13,000 e-mails to really reach that conclusion, but I do know inside these e-mails is her e-mail address at Yahoo. I'm not sure, was that public information before? The e-mail address at Yahoo came out during the campaign, I think in 2008. Somebody had broken into her Yahoo e-mail account and posted what they found, and in there found government business being conducted over her personal e-mail. So apparently what we're getting here are the e-mails on the government address, but there was any number of things that we'll never know about, apparently, that were conducted over Yahoo. That's not really true, because what I was reading, everything is sent to somebody at .gov, Alaska, whatever, Alaska's .gov address, but always when it's Sarah Palin it's to a Yahoo address, which I found to be hilarious. She didn't use the .gov domain for some reason, but these e-mails are both from and to that particular Yahoo address, which was the first time I'd actually seen the full address, so I thought that was interesting in and of itself. Maybe they just found the term Yahoo more descriptive. Yeah, my understanding was that they actually gave access to the Yahoo account, and then they just decided what was official business and what wasn't, and we just have to trust them. Well, we don't have to trust them, because the e-mails were all leaked several years ago. That's true. Yeah, and somebody wound up going to prison for that, I believe. Yes, indeed. All right, well, that's another example of how hacking can be a good thing as far as releasing information the public really does deserve to know about, government business on a private system. Yeah, I think they really need to know about that. Here's something else, though, just continuing the theme of The Washington Times being a really conservative paper. There's a story about the White House cutting access to federal websites, and let's listen to this first paragraph. Under the Obama administration's campaign to promote transparency, the White House announced today it intends to eliminate the public's access to half of the federal government's websites within the next year. I mean, that's true, that's what's happening, but that's not a news story. That's not how you write a news story. That's an opinion piece, and that's really an incredible way of saying it. But, yeah, it's a massacre of .gov websites. We'd better get back on track with our .gov of the week. Yeah, we may be missing out. A reporter named Dino had written in to let us know about one particular one that was apparently brought up by Vice President Biden as an example of the waste that's quote-unquote going on, and it's deserttortoise.gov, and it's a website all about the desert tortoise. Wait, wait, but there's no music. There's no music. Yeah, we can't do an official .gov of the week. We can't do an official .gov of the week, but we're doing a listener email, so it's legal. Can we do this? Can we do a massive copying of all the .gov sites out there that will have them for the future? Actually, that's something that Jason Scott's archiving team would probably be, because they have sites that they watch regularly to see if things are being taken down. They have a fire drill thing for things that they think might be taken down so they can practice backing things up. So I would bet that they're probably on top of that, right? Yes, GeoCities and Google Video are one thing. These are heavy hitters. This is .gov. You think that text files is going to want to mess with them? Jason Scott more than text files behind this now. Mike, do you remember what the name of the new group is? It's an archiving group. Archive.org. No, it's not Archive.org. It's Archive Team or something. Yeah, there's the Archive Team, and Jason Scott now works for the Internet Archive, sometimes called Archive.org, which also archives the Internet, among other things. So I'm sure that someone's making a copy, but it's worth finding out who. We should secretly put Jason on to talk about it. If anybody knows of efforts to preserve this content, which is fast disappearing, please email us. I do know that the Internet Archive, which archives the entire web, or at least tries to, has often had a special focus on archiving U.S. government websites, so maybe they'll make an even more special focus on these websites. I'm hoping the U.S. government announces in advance which .gov websites it's going to take down so people can see them before they take all that information down. I think the likelihood of that happening is slim to none. Yeah, but Bernie, if you were a government and you wanted people not to see something, would you tell them what they're not going to see before you took it away? I know that apparently one site that's been quietly deleted without any warning as part of this effort was fiddlinforesters.gov, which was about foresters who play the fiddle. What? So this valuable information has disappeared into the ether. Does this have anything to do with national security or what? That seems a little bizarre. No, that's not to be confused with diddlingforesters.gov. Moving along, we have this whole Facebook thing going on with facial recognition. Now, apparently this is something that Google was going to get involved in, but they decided it was too hot, and they want to let Facebook take the heat for it. Basically, it involves using pictures that are already on Facebook and running some kind of algorithm to identify based on previous identifications. If you're identified once on Facebook, if you showed up in the background of someone else's picture, Facebook will be able to somehow tell that that's you. That's how I understand it. It's pretty scary, I think. So this technology already exists in a couple of commercial products. I know, for example, that Apple's iPhoto does this for your own thing. Basically, what it does is you go and you start tagging people saying, this is so-and-so, this is so-and-so, and then based on people you've already identified, it goes and basically tries to find other matches, and then you say yes or no. So Facebook's basically taking this kind of facial recognition technology, and in their case, because people love to tag other people in photos, they already have that identifying information, and so then they can try to find other matches. And, of course, as usual, it's opt-out, not opt-in, so it's on by default that you can be identified in other people's photos automatically. Here's my question. If you're not a member of Facebook and someone tags you and says, this is this person, what do you do then? I don't know what you do if you're tagged in a photo, but I know as someone who's not a member of Facebook, there is a forum thread that I somehow got subscribed to with my email address. Somebody else did it for me, apparently. And I get emails whenever someone posts to it, and the unsubscribed links do nothing because, of course, I'm not a member of Facebook, and so I can't be unsubscribed from things, apparently. So I don't know how that's working or why it's working. In terms of – I mean, I'm making a guess here, but I assume that if someone's just tagging you and putting your name, it probably doesn't collect that kind of information because it's not being tied to a specific account or bit of information. It's just kind of a text string tag. So I would assume that you would have to have an actual account for this to kick in, but I'm guessing. I have to join Facebook to get Facebook to stop sending me messages about things I'm not on on Facebook. But RedHack, how hard would it be for somebody to make an account for someone who didn't join Facebook, use their face, use their information, and then the person who really is that person is going to have a hard time disconnecting that account, and all pictures will naturally be mapped to that person. Sure. I could see that. I don't know. I don't know what the solution to that is, right? I don't know what kind of harassment that is. It's definitely harassment. There's got to be a word for it. Well, it would violate their terms of service. I guess. Well, that's sure to stop them. Shall we take some phone calls? We could, but no one's calling. The number, if people want to call, is 212-209-2900. Can I just say I was at the Texarkana Institute of Technology today, which is a hacker space that's in Texarkana, Texas. It's right on the border of Arkansas and Texas. It was really kind of cool seeing what people are doing there, how you can just start a space in one of these small cities and hackers will come. Basically, I dropped off a whole case of Club Mate for them, and everybody's really, really happy there. It's inspiring to go through these particular states and see what hackers are up to. Did they come to the HOPE Conference? They did. They've had a great table at the HOPE Conference before. Some good stuff. Yes, very much so. Yeah, this country is full of surprises. Wherever you go, you'll find interesting people. Some of our interesting people are calling us right now. Hello, you're on the air. Hey, guys. What's on your mind? I want to talk about a smart card. They're talking about a smart card in a new system in Iraq. What do you know about that? Countrywide for… For Iraqis? I'm sorry? For Iraqis or for foreigners? What we're looking at, is it for Iraqis only, or will it be for more than just Iraqis, or will each country have a smart card, or will there eventually be one smart card and one big brother and one big jail? That's a smart card, not a smart car. No, not the car, the card. Card. I know personally that all the U.S. forces over there have smart cards that they use to buy products and services at their government canteen, and that some local merchants are accepting those cards and have some sort of debit system. But you may be talking about something else, which may be a U.S.-financed government ID system, national ID system for Iraqis. Some countries do have smart cards as national ID cards. Estonia is particularly notable as an early adopter of this. But I would think that Iraq has higher infrastructure priorities to worry about than smart cards. There's talk of them revaluing their dinar currency, which apparently was devalued when the Bushis and the this guys and that guys wanted to go in and raid their oil structure country. So now that that's over, we want to be friends and steal their oil from inside, now that we've got ourselves in there. But supposedly revaluation of the currency, which is interesting. That's an Iraqi dinar, and I gave the 2700 guys a heads-up about it. Those 2700 guys, they always are beating us. They're 100 ahead of us. It's terrible. I don't know the whole deal, and I don't act like I know it. I don't even know the whole deal of the Suffolk County Board of Elections either. I figured I'd call and talk about this new smart card set up over there, mentioning it as if it's a prototype for countries to change into and the world. Okay, well, we have to move on, but thank you very much for your phone call. I just had a quick comment about the smart card thing. Actually, I have a passport from another country that has a biometric identity chip and can store all this stuff on it. But because I got it in New York, where they didn't have the machine to write the information to it, it just has a blank chip in it. Could you write things on it? I haven't tried. I don't actually know what kind of— I assume it's some sort of read-write RFID thing. It would be really cool if you could be like, he has green skin, and then see how they react when they scan your passport. Yeah, I don't know how well locked down it is, to be honest. But all I know is I have a blank one. There is one thing to remember as far as all these new technological innovations. They always test them either on prisoners or on countries that we invade first, before they roll them out to the American public. So that's something to keep in mind. All right, let's take another listener phone call. You're on the air. Yeah, hi. Hi. Am I on the air yet? Yes, you are right now. Okay, I'm sorry. Do you guys have any comments on the current beginnings of a cyber war between Vietnam and China over some islands off the coast of Vietnam? I don't know anything about it. Does anyone else? I know they're having words about it. I didn't know it was going to be a cyber war. I thought it was going to be a good old-fashioned war. Well, every war is a cyber war nowadays. Apparently. It's the in thing. But if anyone has any info on that, send it to us, oth at 2600.com. How do you fight a cyber war over some islands? It's an interesting question. Maybe our next caller has some insight. Maybe it's in Second Life. Is that? Hello? Hello. I'm actually just calling from the protest of the WikiLeaks brand jury investigation in Boston. It just ended. Tell us more about it. We had a turnout of about 100 people. We had some awesome speakers, people from all over, and we're really hoping to get the word out, though. It's ironic what is happening. Forty years after the Pentagon Papers were released, it's effectively the same situation with people from Boston being called and subpoenaed and forced to testify and then refusing to testify. We announced that David Howes refused to testify to many cheers throughout the crowd. Do you have a site where people can go for information on further protests? Yes. We formed an organization called Civic Council. That's Council with C-O-U-N-S-E-L. That is a group that's dedicated to supporting the people subpoenaed, spreading open government and transparency ideals in the United States, educating the public about WikiLeaks, Bradley Manning, and all of that. You can go to CivicCouncil.org. That's Civic Council with C-O-U-N-S-E-L. CivicCouncil.org, and that's Council with an E-L. Hey, I have a question about that grand jury. Were anyone in the protest able to identify people walking out of the grand jury? It's a federal felony to leak information from the proceedings of a federal grand jury. But it would be wonderful if someone on that grand jury leaked information about the WikiLeaks grand jury to WikiLeaks or some other organization, preferably not the New York Times, who is trying to pretend they're WikiLeaks. Well, we've been in Boston, so we haven't. Although I know that David was hoping to gather information on what happened, take note to release that. Yes, so I think he made a statement about that earlier today. So that's probably the best place to get information. That should be hitting the media in the next few days. All right, we'll definitely be reporting this story in the weeks ahead because this is of interest to our listeners. Thank you very much. I think we can maybe fit one more quick phone call in. We'll try it. Hello, you're on the air. Oh, a dial tone. That was quick. Let's try this caller. Hello? Yes, hi. On the city breaking security issue, CityCard, I received a letter from CityCard stating that unauthorized access to your city account. They send this mail to everyone, or is it just to – you think it's just to these people that the information was compromised? I know that. I'm a Citibank customer, and I didn't get one, so I don't know. I'll second that. But it's not necessarily that you were targeted as an individual, but I guess they didn't send it to all their customers. Typically, these big companies send letters to people who they think the account may have been compromised. Did the letter promise you one year of free credit monitoring or something like that? Yes, exactly. Yes. Okay. That costs city money to offer, so it's likely that they really believe that your information was compromised because they're not going to offer that free credit monitoring for a year to everybody because they have to pay like $10 or something to some company to provide you with that. Frankly, they should offer it to you for life because you don't know how long that information – I think they get a deal on that because they give away so many of those things that the company that offers them must be raking it in from the people who forget to cancel after the end of the year. Right. Yes. Okay. So I should take this seriously and activate my new number. Okay. They send me a new card. Great. Well, best of luck with that. Thank you. On that note, we're just about out of time, so we have to call it a night. Get in touch. Send us an email, oth at 2600.com. Thank you for listening for Off the Hook. This is Rob T. Firefly. Have a good night. Dog gone female, riding a freight train. Yes, I am female. A dangerous female, so watch out. Off the Hook Do you ever feel angry? Are you paralyzed by your anger? Do you feel yourself with butterflies in your stomach a lot? Do you get headaches? Are you really frustrated? Do you ever get to the point where you're going to blow up and you're afraid that if you blow up, you're going to blow away all your friends and all your coworkers? Chances are, all of this behavior is a symptom of the Fast Patch. You're not expressing your anger. We can assertively express our anger if we handle our anger assertively. We complain and complain and complain. I'm angry. So what do we do? I want praise. I want to go home. I want sex. I want a cookie. I want praise. I want to go home. I want sex. I want a cookie. The Fast Patch Am I really sorry? Did I really do something bad? Why am I apologizing? I don't think I'm always wrong. Do you? Do people push your button? Are they telling you that you're too fat, too aggressive, not nice enough, or just hard to get along with? Are they telling you that people who grew up in Connecticut are stupid? Do they tell you that you're weak? Are you simply the person who gets the sand kicked in their face? Negative, negative, negative. Now you're angry. And now you have something to say. I want praise. I want to go home. I want sex. I want a cookie. I want praise. I want to go home. I want sex. I want a cookie. I want praise. I want sex. I want a cookie. I want to go home. I want sex. I want a cookie. I want praise. I want to go home. I want sex. I want a cookie. I want a raise. I want to go home. I want sex. I want a cookie. I want what she wants. I want to go home. I want sex. I want a raise. I want to go home. I, well, I want mostly that. But, anyway.