There will be a regular meeting of the WBAI local station board on Wednesday, September 11, 2013 at Al Juan for the Arts, located at 16 Beaver Street, 4th floor in Lower Manhattan. The public is invited. And you're listening to WBAI New York. It's 6.59 p.m., which means it's one minute to seven o'clock, one minute to off the hook. And you know what? We're just going to start a little bit early tonight. Maybe the machine won't, but we will. And a very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you, joined tonight by Mike. Hi there. Kyle. Hi. Who apparently is also not working. Okay, hang on. Let's try that again, Bernie. Are you there? Yes. Greetings from Pennsylvania. All the buttons are in the wrong position today. So we have a skeleton crew tonight, but that means that we can take more phone calls and talk to more people and talk more amongst ourselves because we have so much to talk about as far as what's been going on in the world of surveillance and hacking and whistleblowing and various things like that. Brazil. Brazil's rather mad at the United States this week because it turns out that there are new allegations from the Snowden documents that Washington spied on President Dilma Rousseff, complaining that their sovereignty may have been violated, suggesting that it could call off the planned state visit to the White House next month in a similar way to how Obama called off his visit to Putin this week. A Brazilian news program reported on Sunday that the U.S. National Security Agency spied on emails, phone calls, text messages of Rousseff and Mexican President Enrique Pena Nieto, a disclosure that could strain Washington's relations with Latin America's two biggest nations. Mexico asked the United States to investigate the allegations, saying there would be a serious violation of its sovereignty if proven true. And Brazil's government, which is already smarting from earlier reports that the NSA spied on the emails and phone calls of Brazilians, called in U.S. Ambassador Thomas Shannon and gave the U.S. government until the end of the week to provide a written explanation — no less than 300 words — of the new spying disclosures based on documents leaked by fugitive former NSA contractor Edward Snowden. That report comes to us from Reuters. Bernie, any thoughts? Well, I think I read another story that the government of Brazil... I've got to stop you right there, Bernie. You're all choppy. Are you away from a transmitter or something? I'm hearing choppiness, too. I thought the choppiness was at your end. Can you hear me now? Well, I hear you now, but you're definitely the choppy one. I'm very digitized and choppy, so should I call back? Well, unless you want to preserve this sound for the entire hour, yeah, let's call back, try it again. I don't think anybody wants this. No, I don't think anybody wants this. Bernie's going to call us back. Mike, what do you think about all this? I think it's kind of amazing. So the Mexican government's response is to demand an explanation from the United States because I'm sure they'll get a truthful one. I don't know exactly what else they should do. I wouldn't suggest they bomb the United States or anything like that, but I don't know that ask for an explanation, please kindly, sir. How else do you send a message except by bombing places? That's how you send messages. I saw it on TV. You should watch less TV. Yeah, I guess so. Kyle, your thoughts? I heard in some of the reporting about this, it was like sort of a proof of concept that basically it was an exercise in how powerful the NSA spying program was that they could get like personal communications of the president of like Brazil and Mexico and stuff like that, which was an interesting attribute of the story that it was almost for sport. We might have a less choppy Bernie. Let's see if that is true. Bernie, you there? Do I sound less choppy now? Much less choppy. Go ahead and give us your honest opinion on this story. Well, the Brazil thing, wasn't there also a move this week or at least an announcement by the government of Brazil that they were considering, and maybe you already talked about it while I was offline, that they were considering only having all official communication go through the state run media and maybe even offering state run ISP and even offering that to individuals if they wanted to not have supposedly U.S. surveillance? Yeah, there's two related stories. And the details, the Brazil story, I've only been able to find sources in Portuguese, which is a language I don't speak, so I'm not totally sure what's going on. But apparently they're talking about making their own email service and possibly offering it to all Brazilians who don't want to be spied on by the U.S. government. It remains to be seen if they have the technical capacity. Of course, if you're a Brazilian and you want to keep secrets from your own government, which many people might want to do, then this is not the way to go. But that'll be interesting. And then there's another similar story from India. Apparently India, they use Gmail a lot, even in the higher reaches of the government. And they've, I guess, been slowly coming to the realization that this is maybe not a good idea for things they want to keep secret from the U.S. government. Yeah, I tried to print that story in Chrome and it wouldn't print. Google doesn't want you to print stories about people switching away from Gmail. But I can try and read between the ads that they stuck in the middle of it. A senior official in the Ministry of Communication and Information Technology said the government plans to send a formal notification to nearly, and that's where it cut off. But Gmail data of Indian users resides in other countries. Half a million people, this story said. Half a million, okay. The servers are located outside. Currently we are looking to address this in the government domain where there are large numbers of, large amounts of critical data. That's according to a secretary in the Department of Electronics and Information Technology. So yeah, India is looking into asking all of its employees, all of its governmental employees to stop using Google's Gmail for official communication. I can't imagine why anybody would use a service like that, any kind of commercial web-based service where your mail is stored in the cloud and read by ad-based technology for official government business. Well, the reason that people use it is because it's free and works reasonably well. But the downsides, I would say, outweigh that. Yeah, official government business really shouldn't be thinking about what's free and what's, you know, what's, I don't know, it just doesn't seem to make very much sense to me. Kyle? There's like lots of free email programs that you could run yourself that are also easy to implement. And I think that's never been cooler with like some of the stuff coming to light. Anything you want to suggest as far as what people might be able to run on their own? Maybe kids out there listening that just got a computer or something. Well, I mean, I'm not thinking of anything in particular. There's a lot of different software packages out there. But basically, start with a free operating system and build a server and then, you know, implement some kind of mail, whatever mail you want. Well, what's free operating system? Have I heard of a copy of Windows? Yes. That's what you recommend? No. You recommend any operating systems? I don't know. No, I don't want to recommend anything in particular. I mean, Linux, Unix. Well, maybe this is the problem. We need to recommend some things so people actually get some motivation and do something outside the Mac world and the Windows world. Mike, anything? I think, though, that it is a lot harder to do any of these things. And I do run my own mail server, but it's on a server I rent from someone who I don't trust. I don't know what the security advantage is here, but I mean, you know, not someone I actively distrust, but a corporation that operates in the United States and obeys the laws of the United States. I recommend FreeBSD. There. That didn't hurt. Everybody wants to recommend Linux or something like that. I'm not going to get into the Linux, BSD debate. It's very boring. It's all good. It's all good. But the thing is... But it is true to say that it is much harder to do than to just use Gmail. Yeah. I recommend Plan 9. Plan 9. Okay. Well, the thing is... Why are you laughing, Bernie? Oh, I have a Plan 9 t-shirt. I actually started playing with that operating system, I think, a few years ago at one of the Dutch hacker conferences. There was a tent there that had a Plan 9 tent. That's sort of a... It's a superset of Linux developed by the folks at AT&T Bell Labs. I've seen you wear that t-shirt, Bernie. Yeah. Can we keep our... With Glenda. Glenda, the Plan 9 buddy. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Whatever. Oh, my goodness. What is the Plan 9 bunny. But anyway, that's a good suggestion. I think there's a market opportunity here for some person or company to roll out a really reasonably secure mail server that's like an appliance. You can just co-locate it where you want or put it in your own premises and that is your mail server. I think that could be a market demand for something like that now. Yeah. I think a lot of people that are running like VPS and things like that, that they don't necessarily have control of, I think that an appliance or something that you can put somewhere wherever you choose or determine that kind of uplink it'll have, that's kind of worth investigating because of the problem of, yeah, you're paying a subscription, you're paying like $2.99 a month or whatever you pay for your VPS, which is great, but if something happens to it, if they want to just have a big copy of everything on it, unless you're really savvy at implementing encryption and stuff, you run into problems like that. I would encourage people to virtualize a bunch of different OSs and try and figure that out and choose one that they end up liking. So build a system and run a hypervisor and then install a myriad of OSs and the ones you get good at and you enjoy, maybe pick those to implement in machines that you build yourself. So write to us. Tell us, oth at 2600.com. Tell us what works for you and what you recommend. And remember, the operating system doesn't have to be something that you use for everything. You can run multiple operating systems. Sure, you can run Windows for some things, you can run Mac for other things if that works for you and if that's something that you find to be convenient, but you don't have to sacrifice your privacy at any stage if, say, you want to run a mail server and have it completely secure and there's no solution that works in one of those operating systems, you can run something else. Absolutely. OS diversity is a really cool thing for your mind. I mean, not being like cutting things off and saying, like, I'll never do this or I'll never touch that. It's the same thing with like programming languages or foreign languages or maybe even social groups, people you hang out with. You should have as much diversity as you can possibly handle and really kind of experiment and push your mind and you never know what's possible thereafter and you'd probably be in a better place. I wasn't planning on talking. Do you have something else, Mike? Well, I just want to give a couple of solutions that maybe you can do in less than 10 hours a week, which I think is what most people want from their email. There's a project called MailPile, which is still in development. Some Icelandic folks launched it at the, well, I don't know if the official launch, but they started talking about it at the OM conference this summer. So it's not quite ready to use, but the promise is that you'll be able to install this software and you won't have to trust your mail server. We'll see how that works out. It's not open to the entire public, but if you identify as an activist, there's a wonderful organization called RiseUp. Their website's riseup.net, of course, and they will host your email for you. If you use them, you should kick them some money if they need it, but they're really great people and I trust them. Okay. I wasn't planning on talking about operating systems really, certainly not to this degree, but getting back to the Brazil story, I wanted to ask you, Mike, if you think, we talked about this last week, the president of Brazil found that she's being spied upon by the United States, by the NSA. Similar episode in Mexico. Is this something that we should expect from the NSA? Because well, like you said, the NSA spies on governments. Yeah. I mean, it's their job. The president of Brazil may or may not have thought she was successfully evading the NSA, but if she didn't think the NSA was trying to listen to her phone calls, then she should get some advisors who will tell her they were. What I'm curious about, let's say there's another country, maybe Syria or Iran or a country like that. I just picked those two at random. We found that they were bugging phones of US government officials. Would we not be lobbing missiles at them just for doing that? I wouldn't be lobbing missiles at them. Okay. You know what I mean. Every week, we've got to say, yeah, we're not the US government. I know. We're saying we, the United States, okay? Of course, the US government has one set of standards for itself, another for its friends and another for its enemies. That's not new. I think we'd lob press releases at first. Okay. Well, we'd start that way, I guess. But yeah, the thing is, yeah, I'm not surprised by this, but that doesn't make it right. I don't think you're saying it's right. No. I don't think, I want to be clear. My position is a little nuanced. I don't think it's right for the US government to be spying on foreign leaders. But I think it is more wrong when they spy on people who are not the government. Okay. Yeah. I certainly agree with that. Bernie, any thoughts? Bernie? Did we lose Bernie? I think we lost Bernie. How about that? Can you hear me now? Yeah. What's going on with your phone? What's going on down there? Brenda's having trouble today, apparently. Apparently. Yeah. I agree with Mike on that. And it is, you know, our government, our defense department or, you know, really war department, their job really is to gain intelligence on everything that's going on to benefit US interests and protect us and all that stuff. But spying on individuals really did not involve national security for the most part, so I'm against it. Okay. All right. You'll find a lot of opposition to that in the hallowed halls of Congress and other places. And apparently another way that the NSA is spying and monitoring various bits of information, they hire outside companies to help it do its work. And apparently, looking at the black budget, we'll get into that in a second, the agency, their top hackers, yes, they have top hackers, they're funneling money to firms of dubious origin in exchange for computer malware that's then used to spy on foreign governments. This year alone, the NSA secretly spent more than $25 million to procure software vulnerabilities from private malware vendors. That's according to a wide ranging report on the NSA's offensive work by the Washington Post. The Post, which is Microsoft, already tell the government about gaps in their product security before issuing software updates, reportedly to give the NSA a chance to exploit those bugs first. But the NSA is also reaching into the web's shady air crevices to procure bugs the big software vendors don't even know about, vulnerabilities that are known as, anyone? I'm not going to say it. You're not going to say it? I don't want to say it. You, Kyle, do you want to say it? O-Days. Okay. Well, that's good. Zero days, but O-Days, either one. So they're actually going out there and buying them and then using them. So I just imagine there's all these people out there saying, oh boy, I've got all these zero day wares here and I can sell it to the NSA now and they could be my biggest customer. This is reality. This is actually apparently happening. I mean, almost certainly people we know have done this and told us about it and if they want my opinion, they should stop. Sold to the NSA. How do you even start that transaction? It's kind of like getting, well, on darknets, right? And I think you have to understand, I guess, that their mentality is that they want to get to these things first. And then if they can add them to like a collection that they've amassed, then they can use them in maybe distracting or actual like hacks or campaigns that have a bit more of a political bent so they can tap into their like, or look back at their vast library and then that becomes their quote arsenal. That and the brilliant hackers they apparently employ. Wow. Just gets stranger and stranger. Now speaking of that black budget, it's a $52.6 billion black budget for fiscal 2013. It's called a black budget because it's secret. I'm not quite sure why it's called a black budget for that reason, but we have not been able to analyze this for many, many years. And the only reason that we're able to analyze it now is because Edward Snowden leaked it. Yeah. It's one of the other bits of information that has been revealed. And basically what the government does, they've annually released its overall level of intelligence spending and they've been doing that since 2007, but they have not divulged how it uses the money or how it performs against the goals set by the president and Congress. It's an amazing amount of freedom they have. I just want to highlight what you just said. They would not even reveal the amount of money they were spending until 2007. That's how enshrined in secrecy this organization, these organizations have been. Couldn't we have just subtracted and see how much money is missing from all the other budgets? I'm not exactly clear, but people who tried to do that, they tried and they got estimates, but they weren't able to get the exact numbers. The allocation, excuse me, the allocation wasn't clear at all. It all basically was in the defense department had one budget and then there was the black budget that existed and where that stuff went when it was really tough to decipher. This bureaucratic and operational landscape has never been subject to public scrutiny until now. 178 page budget summary, and it's not that much. You can see it details the successes, failures, and objectives of the spy agencies that make up the U.S. intelligence community. Do you know how many spy agencies we have? More than... Like 15 or so? 16. 16, Bernie. Yes. 16. The one that was a secret I forgot about. 107,035 employees. Now I'd like to name all 16 if I could, but I can't. I don't even know. Some of them have classified names. Oh, then I definitely want to name them. I want to find out all 16 names. There's a link actually in this story, but I printed it on paper so it doesn't work. Did you try pressing on the paper? It doesn't work. I tried. Okay, I'll start. CIA. Uh-huh. DIA. DIA. Okay, you know about that. That's good. NSA. NSA. FBI? Are they considered... I don't think they're secret. Well, no. I didn't say secret. Spy agencies. Oh, just spy? FBI has a counterintelligence division. Maybe they're the one Bernie has forgotten about. They tried to recruit me once. It didn't work. Okay, FBI. I wasn't talking about them. Yeah, Secret Service. Secret Service. Right? Nice. Yeah, I think. That's five. They're not... None of these are intelligence agencies per se. Okay. Yeah, we're kind of stretching. They're not part of the intelligence community per se. Well, you know, if I could click on that link, maybe I could get all 16 of them. There's the National Geospatial Agency. Right. Wait a minute. What? Who are those people? They make secret maps. You're right. No, that's a good one. Okay. Go ahead, Bernie. Didn't that used to be geospatial? Didn't that used to be the National Reconnaissance Office, our spy satellite people? They can't hear you nod. You're saying the NRO went away, so I can't say that as one of them. Right. The National Reconnaissance Office, which maintained or built and operated our spy satellites for other government agencies, didn't they change their name to National Geospatial whatever? So their name's shifting. I don't know. They don't want us to know. But yeah. The CIA and NSA, which are the two biggest of the bunch, are just, I don't know, the tip of the iceberg, but just part of the iceberg. Well, let's look at some highlights here. And of course, people can track down on the internet the entire 178-page budget summary for the NSA, $52.6 billion just for one year. Spending by the CIA has surged past that of every other spy agency with $14.7 billion in requested funding for 2013. The figure vastly exceeds outside estimates and is nearly 50% above that of the National Security Agency, which conducts eavesdropping operations and has long been considered the giant of the community. I guess I should clarify. So if we say that the budget is $52.6 billion, that's not for the NSA, that's for, I guess, all of the spy agencies. Correct? I mean, I think it's a reasonable question to ask what we're getting for our money. Isn't this the agency, the CIA, isn't that what our good friend Robert Steele derides and just absolutely tears apart the most with just saying how wasteful and abusive and corrupt it is and inefficient and not intelligent? He has said that on occasion, yes. And if you want to see some of those occasions, go to our YouTube channel, Channel 2600, and look for Robert Steele, and you'll see a bunch of talks by him discussing this way in the past, too, before a lot of the things we know now came to light. Anyway, continuing with some highlights here. The CIA and the NSA have begun aggressive new efforts to hack into foreign computers, computer networks, to steal information and sabotage enemy systems, embracing what the budget refers to as offensive cyber operations. That's what we just referred to before. Long before Edward Snowden's leaks, the U.S. intelligence community worried about anomalous behavior by employees and contractors with access to classified material. The NSA planned to ward off a potential insider compromise of sensitive information by reinvestigating at least 4,000 people this year who hold high-level security clearance. Oh, that would be a pain. Yeah. Well, unfortunately, Snowden got there first. U.S. intelligence officials take an active interest in friends as well as foes. Pakistan is described in detail as an intractable target, and counterintelligence operations are strategically focused against the priority targets of China, Russia, Iran, Cuba, and Israel. Yeah, Israel. The latter is a U.S. ally but has a history of espionage attempts against the United States. Surprise, surprise. In words, deeds, and dollars, intelligence agencies remain fixed on terrorism as the gravest threat to national security, which is listed among five mission objectives. Counterterrorism programs employ one in four members of the intelligence workforce and account for one-third of the intelligence program's spending. And finally, the governments of Iran, China, and Russia are difficult to penetrate, but North Korea's may actually be rather simple. There are five critical gaps in U.S. intelligence about Pyongyang's nuclear and missile programs, and analysts know... Actually, I got that backwards. I tried the hardest to get into. The analysts know virtually nothing about the intentions of North Korean leader Kim Jong-un. So that's some revealing information. Do you think we're less safe for people knowing about it now? I can't... I mean, I would just like to know what we're getting for our money. They seem to have caught, like, what, five terrorists a decade? Like, for $52 billion a year, that's not a very good rate of return. No, certainly not. Okay, so moving on. We have a suggestion from some people who have written in to us about, well, people who are concerned about Google and about having your searches saved or referenced or just kept in a computer someplace. There is another search engine that says, no PRISM, no surveillance, no government backdoors. You have our word on it. The Washington Post and, well, actually, they go into a story now about PRISM, what that's all about. So we've talked about PRISM enough, I think, but this particular search engine is known as Startpage. Now they say, Startpage has always been very outspoken when it comes to protecting people's privacy and civil liberties, so it won't surprise you that we are a strong opponent of overreaching unaccountable spy programs like PRISM. In the past, even government surveillance programs that were begun with good intentions have become tools for abuse, for example, tracking civil rights and anti-war protesters. Programs like PRISM undermine our privacy, disrupt faith in governments, and are a danger to the free internet. Startpage and its sister search engine, IsQuick, have in their 14-year history never provided a single byte of user data to the U.S. government or any other government or agency. Not under PRISM, not under any other program in the U.S., not under any program anywhere in the world. They say they're different because they do not store any user data. We make this perfectly clear to everyone, including any governmental agencies. We do not record the IP addresses of our users. We don't use tracking cookies. So there is literally no data about you on our servers to access. Since we don't even know who our customers are, we can't share anything with Big Brother. In fact, we've never gotten even a single request from a governmental authority to supply user data in the 14 years we've been in business. Maybe they don't know about them. Startpage uses encryption, which is HTTPS by default. Encryption prevents snooping. Your searches are encrypted, so others can't, quote-unquote, tap the internet connection to snoop what you're searching for. The combination of not storing data together with using strong encryption for the connections is key in protecting your privacy. Our company is based in the Netherlands. U.S. jurisdiction does not apply to us, at least not directly. Any request or demand from any government, including the U.S., to deliver user data will be thoroughly checked by our lawyers, and we will not comply unless the law, which actually applies to us, would undeniably require it from us. And even in that hypothetical situation, we refer to our first point. We don't even have any user data to give. We will never cooperate with voluntary spying programs like PRISM. And finally, Startpage cannot be forced to start spying. Given the strong protection of the right to privacy in Europe, European governments cannot just start forcing service providers like us to implement a blanket spying program on their users. And if that ever changed, we would fight this to the end. And their slogan, privacy, it's not just our policy, it's our mission. Startpage.com. What do you guys think about this? Mike? I didn't know we read press releases on the air. Well, when it's something like this, we do, yeah, because it's of interest, and I think our listeners would be sort of baffled. I mean, if you don't have any users, then you probably don't get so many requests for user data, would be the first thing to point out. You really think the governments would get it right away, that, I mean, you know, they could read Twitter themselves, yet they request tweets from Twitter is because they can't figure out how to do that. So you're not dealing with the most intelligent people in the world. No, I mean, but, you know, usually the government, at least for smaller companies, they request data about a specific user. And if you don't, if the government has no targets who are a user of this service, then the service won't get any requests, not because of anything nice they did, just because they don't want anything. Remember Indymedia, when their servers were seized, they kept no logs either. And it was basically a phishing expedition by the government, as I recall, to get information wherever they could. They could do the same thing here, except they won't get anything. I mean, so, and the other thing I would say is that there's certainly an advantage to doing business with companies who are not based in the United States. But there's two caveats. The first is that the NSA has made it very clear they have no qualms about spying on any data that's outside of the United States. So if you are a U.S. resident and you are communicating with a server in the Netherlands, the NSA will try and spy on it, whether or not they succeed is one thing. But point B is that I don't trust the Dutch government either, and there are specific reasons for not trusting the Dutch government in particular, but there's also like no reason to trust really any government. But do you see anything in here that says trust the Dutch government? I see something that doesn't trust any government. They say that they don't get requests from the, what was the line? They cannot be compelled to spy upon their users because the EU law says so. And well, the Dutch government in particular is working very hard to change that law, so. Okay, Bernie, any thoughts? Well, I think Mike is right, that whenever you are operating under the sphere of any government, that government could well be pressured by the U.S. government to compel the company to turn over information. Or just because these people are confident they've never turned anything over to the NSA or to the Dutch government doesn't mean that their servers aren't being spied on surreptitiously. So you really have to operate your own mail server, or this is about a search engine company though, but still, is there any safe place on the planet? Why doesn't North Korea get into this business? I think we're, well, I don't really know how many users they have. I can't speak to that. And I think we're being just a little bit harsh on them, basically. I don't really get the point Mike was making, but I do know that it's from what it sounds like that they're dumping user data. So I mean, that sounds like a good thing. I don't know the details of it. But I will say that you do have a point, and Bernie as well, that if you are communicating with people, servers, outside the U.S., you're basically, it's almost like you're drawing extra attention to yourself. And then one other couple things I'd like to say, basically, I tried it out, and one of the things I guess that would supposedly protect you if you were communicating with a server outside the U.S. is HTTPS. And there's a couple settings. You can choose to not have HTTPS, and you can choose to use it. And I tried it with HTTPS, and it's a little slow if you have average American broadband, or you haven't assessed your broadband situation and done something whiz-bang with it. But you can also use Google with HTTPS. Right. Right. So in this case, they're, I don't know, it just felt a little slow, and the aesthetic probably needs some updating. If you've been on Bing or Yahoo or Google for many, many years, you might be a little jarred by the way it looks, because it is a lot different. It's weird trying something else. And for me, that was kind of an exercise in patience. But it works. It works really well. And they've got some interesting defaults, like for parental controls and stuff like that. Yeah. There seemed to be a default to basically keep a lot of information from crossing your eyes, unless you set it so that you see everything. You have to play with it a little bit. But these are, I mean, the grander point, I think, is that it's worth trying other kinds of services out there instead of doing everything in your digital life through one service provider. All right, well, I'm sure our listeners will try this out and let us know if it's any good or if it's something they can poke holes in. And we'll see if they actually keep the promises that they're claiming to make. I do have one additional thing that you reminded me of, that there's a thing that people should get. It's called HTTPS Everywhere. It's a plugin for Firefox. And what it does is, anytime you're visiting a website like Google or any of thousands of others that supports secure encrypted transmission of data, but does not always do it by default, this plugin will go in and use it on that website. So it's not a solution for the entire web. You have to be visiting sites that support it. But at least you can't accidentally visit a site that supports SSL without SSL. So make sure your browser employs that if the site makes it available. Yeah. And it works automatically. And it's put out by the EFF. Nice. I trust it. I'd like to hear the EFF's opinion on this as well. That would be kind of interesting. Maybe we'll have somebody on who can talk about this. Emmanuel? Yes, go ahead, Bernie. Wasn't there some suspicion or maybe some evidence that NSA had compromised the encryption certificates used by a lot of companies online that people rely upon for their HTTPS connections? I hear suspicions all the time, but I'm not sure how much evidence there actually was about that. But yeah, certainly something to study if there is any evidence of it. Well, okay. Just be careful who you trust. Who do you trust? Always. Always. Yeah. Isn't the certificate authority system based on buying certificates and stuff? I don't really know how that works. Does anybody know how to kind of explain that? Is there a way they could buy it, like they're buying these exploits or something, and then reverse engineer it somehow? Yeah, so people who don't know how certificate authorities work, I don't know that I can explain it quickly, but when you operate a website, you know, 2600.com, if you want to have www.2600.com and you want to have HTTPS so it's encrypted, you have to pay money to a company called a certificate authority who will verify to some degree of trust that you, in fact, own that website so that the certificate you use is marked valid. Now which certificate authorities are trusted by your browser is quite a scary list. If you open up, you can do it. It's hidden in the advanced settings of the browser. What certificate authorities are trusted? You'll see there's like 100 of them, most of which are companies you never heard of. There's big US companies like Verisign, which I don't trust, but almost every large website uses them. And then there's like weird small entities in small countries, the telecoms operator of 50 countries, and there's no reason to trust all of them. So the model is definitely broken, there are people working to replace it, but for now it has to be better than nothing. Better than nothing. Yes, better than nothing. Moving on here, some happy news. A powerful Delta IV heavy rocket launched a Classified Reconnaissance Satellite into space from Vandenberg Air Force Base in California last Wednesday. The launch took place in the clearest skies at 11.03 a.m. pacific time. Everything appeared to be going to plan up to the point at which the second stage of the rocket ignited six minutes into the flight. At that point, TV coverage was ended at the request of the US National Reconnaissance Office, NRO, which will operate the satellite. So apparently, Bernie, they're still called that. Called what? National Reconnaissance Office? Yes. Yes. Didn't you say they changed their name or something? Well, apparently there was some overlap and responsibility between National Geospatial and maybe it's a spinoff of the NRO, the National Geospatial Spies, whatever they are. But yeah, we don't know what this spy satellite does, do we? I guess secrecy again. Our government spent like probably a billion dollars for this to launch this, develop and build and launch this satellite. And what are they doing with it? Well, according to this report from Computer World, no details on the satellite have been released except that it will be operated by the NRO. The office is charged with providing innovative overhead intelligence systems for national security. In other words, spy satellites. And that's one of the clues to the satellite likely being the newest member of the NRO's keyhole spy satellite network. Other clues lie in the warnings sent out to mariners that detail three areas of the Pacific Ocean and to which the spent rocket stages fell back to Earth. So yeah, that's a clue there. Where was this launched from again? This was launched from Vandenberg Air Force Base over in California. OK, cool. Last Wednesday. So it's probably operational and spying on all kinds of things. And yeah, it's just the network just keeps getting more and more complete. Our listeners should know that spy satellites aren't just cameras anymore. There's some very powerful cameras that can allegedly read newsprint over your shoulder from a low Earth orbiting satellite like this one. But there's all kinds of other surveillance that satellites can do by monitoring radio transmissions, which is how cell phones and other communications technologies work. So there's a lot of types of electronic surveillance that can be accomplished from a spy satellite. So a lot of people are probably speculating about what this particular spy satellite is doing. Is this like optical beam splitting in the air? Could you take encrypted traffic, like encrypted radio signals, and intercept them and basically send them down to, say, a military base or someplace to process it, like Menwith Hill? Sure. That's basically how it works, right? Stuff like that. I mean, some of these satellites are incredibly sophisticated, even the unclassified ones we don't know about, that have the equivalent of an entire telephone company central office inside them. Also, large storage capacities, store and forward. The analysis is actually done on the ground, though. Like you said, they can store the stuff and then send it back down more efficiently by compressing it, that sort of thing. Who knows what they're sucking up and spitting down for analysis? It's anybody's guess. All right. I'm going to change gears here because I think we're picking on the NSA just a little bit too much and federal government. So actually, let's just move to a different federal government. We're going to talk about the Hemisphere Project. Have you heard about the Hemisphere Project? Yeah. It's a... What's that, Bernie? Is that the DEA thing? Well, it's a federal, local drug officials as well as a phone company. It's the same government, just a different part of it. Different part of it, yeah. Different part of it. It competes with itself. AT&T is involved in this as well, and they have an extremely close association together. What happens is the government pays AT&T to place its employees in drug fighting units around the country, and those employees sit alongside Drug Enforcement Administration agents, local detectives, supply them with phone data that goes back as far as 1987. 1987. This is incredible. And the Hemisphere Project covers every call that passes through an AT&T switch, not just those made by AT&T customers. Includes calls dating back 26 years. That's according to Hemisphere training slides bearing the logo of the White House Office of National Drug Control Policy. Some four billion call records are added to the database every day, the slides say. Technical specialists say a single call may generate more than one record. Unlike the NSA data, the Hemisphere data includes information on the locations of callers. And these slides were given to the New York Times by Drew Hendricks, who's a peace activist located in Hadlock, Washington. I think some drones are circling around there right now. But wow. I mean, how come this isn't front page news everywhere? It's on the front page of the Times. Yeah, everywhere though. That's the only place I saw it on the front page. This is huge. This is huge. 1986, 1987. I mean, wow. One of the crazy things about this story is that this is used for ordinary crime, drug crime, which is weird. But there are instructions given to the people that use the data, like don't mention the source of the data. We don't want news to leak out. And again, this is a program that requires no judicial oversight. The DEA can just request this data and get it, and it's insane. I don't know what to say. We've said the same thing about every one of these programs that gets revealed. It's insane. Okay, so that's the latest. That's the latest from the Hemisphere project. Emanuel, so what it means is most of the phone calls that have been made since 1987 in the United States, domestic telecommunications, most of them, the caller and the receiver of the call and the locations of the caller and the receiver are all being logged by your federal government under this project called Project Hemisphere. Is that right? They're being logged by AT&T, who gives the data to the federal government on request, which is probably a distinction without a difference. Have they requested all of it? They might have for all we know. Yeah, I mean, who knows? I find it hard to believe that the NSA doesn't have access to this data in one way or another, but that's not the story that was reported. And it's basically like good luck avoiding AT&T switches. This isn't something like a commercial relationship with the DEA that you might be able to avoid, say, by choosing a different provider in perhaps protests or something like that, because often smaller providers, maybe T-Mobile or Sprint or other companies, they have arrangements in certain areas maybe that AT&T is already sort of very entrenched in, and they'll say, all right, well, we want to broaden our coverage for our client base, wireless or otherwise, and they'll work out a business-to-business arrangement with AT&T and transit their data over AT&T's switches to get it to a more central point in the network. And in that sense, it's unavoidable that you'd be transiting, that you could avoid their network, unavoidable to not transit their network. One of the capabilities of the system that they are so very proud of is that even if you throw out your cell phone and get a new one, they can somehow, and they're not really clear on how they do it, but they must analyze your movement patterns or something, figure out your new number and provide that data to the DEA as well. It's really stuff that the Stasi really wishes it had this. They had to actually follow people around to know where they went. Well, I mean, that's the whole point right there. We say the Stasi, we say, you know, all kinds of horrible governments of the past and secret police and all that, as if it's something that's not coming back, and it always comes back. There always will be evil in the future, even if we don't believe there's evil right now in the present. We are making tools that will always be around and will just be improved upon, and just think of how those tools could be used in those hands without safeguards. All right. We're going to take phone calls, 212-650-5782. So much to talk about. We have so much more we can't get to because we only have an hour, but we'd like to hear your opinions on what we've reported so far. Again, you can also write to us here at OffTheHook, oth at 2600.com. You're listening to WBAI New York, and let's read one bit of email that we did get. This is in response to another listener who wrote to us last week, the letter from Angelo. This is from Anne. Contrary to Angelo's annoyance at your insightful political comment, I am so grateful for your focused discussion on the important information emerging from Manning's and Snowden's bravery. I never had any interest or understanding of technology until I started listening to your program. You guys say what few others on the air dare to voice. I also don't loathe technology talk anymore. Thank you so much. Thank you, Anne, for those amazing words and the inspiration. That's a really nice letter. Isn't that nice? It's interesting. That came to our website, WBAI.org. People can submit comments there as well, or again, write to us, oth at 2600.com. Here's something from Bob in Queens. This is kind of a public service that I think we're going to release to the public because that's what we do as well. We tell people about potential privacy risks. Maybe this isn't a privacy. Maybe this is something that's normal these days. I don't know. I looked at it, and I was like, holy cow, this actually works. But Bob says, the other night we had a power outage, so I used my smartphone to go to the Con Ed webpage to report it. I went to the page. I entered my home phone number, and I entered Queens as my borough, 718 number and Queens as the borough. Lo and behold, they promptly displayed my street address without any other verification of any sort. So all you have to do is go to https://apps1.coned.com, and that should be all caps, reportoutage.asp. Or you can just basically look for the page that says report an outage for Con Ed. All you have to do is enter someone's phone number and get the borough right. You have five guesses to get the borough right, and you'll get their address. Did you just call the slash a backslash? Did I say backslash? I'm sorry. No backslashes in that. Yeah, I was using a Windows machine before. There's no backslashes in that. It's all slashes. Yeah. Although, you know, how hard would it be to make the backslash work like a forward slash? Maybe it does. That'd be cool. I've never tried it. I've never tried it myself. But yeah, it's true. You put someone's phone number in. Now, you might ask, okay, why is that a big deal? If you know their phone number, you probably know their address. Not really. If you're curious who owns a certain phone number, this is a great way to find out. It's called customer name and address. CNA is something we used to use as hackers way back in the day where basically we'd enter a phone number and a computer or a human, if we had the right codes, would tell us who it belonged to, the address. This isn't giving you a name, but it is giving you an address, and you can figure it out from there. Just go by the address and see what name is on the mailbox or whatever. You might have to think, okay, how can I abuse this? The point is it can be abused. Unlisted numbers are in there. Cellphone numbers are in there if they are affiliated with the account. Another thing you can do on this webpage, you can enter an account number. Now, okay, you have to have someone's account number. Account numbers aren't that different. If you have one account number, you can probably figure out other formats or the numbering schemes and get different addresses that way. You let us know. Is this a big deal? OTH at 2600.com. All right. Let's take some phone calls. Again, the phone number, 212-650-5782. And the call that was just there dropped off, but as soon as I turn this up, I know I'm going to hear that horrible noise. Bernie, are you there? Not you. I'm here. All right. You're not a horrible noise, but there is that other line next to you that when it rings, we hear the horrible noise. And right now, it's not ringing. Wow. How about that? 212-650-5782. I know what will make it ring. If I... Okay. If I come up with a suggestion, that'll make it ring. All right. Let's see who's out there. Good evening. You're on Off The Hook. Hey there. How are you doing? Okay. I've got a call for you. You've got to speak up because otherwise, you'll get horrible feedback. Okay. Last night, I was... I did a name check on myself and I found out some outfit on the web called Radaris, I believe it is. Excuse me. They listed my prior addresses, prior telephone numbers. And they said, we do not delete any information unless we get a court order. And I'm like, I don't care. That's my information. And I don't want it up on the internet. Do they really have... Do you know who these people are? And do they have the right to do this? I know they're not the only ones. If you enter somebody's name into Google or wherever, you will get all kinds of sites like this coming back and saying that they have information. And they will sell that information to other people. They'll give you a little taste of it, but they will sell other bits of information as well. And I think it's very shady. It's very shady what it is they're doing. I mean, I'd like to get the information on the person who owns the company and put his information up on the internet and see how he likes it. I'm sure it's already up there, but you could publicize it some more and say, this is the person behind it or this is one of the people behind it. Do a who is on the site, you know, go to, just type who is into a search engine and that site and you'll get the ownership information. You should anyway. What was the name of that website? Startpage? Is it the other one? The one we were talking about before is startpage.com. Is that it? Yeah. Yeah. Startpage.com. Try that out. Let us know how that works. By the way, can I mention one last thing? Please. There are two buildings in Manhattan that supposedly, you know, run by the phone company. One at the foot of Manhattan. You know, these two gigantic windowless buildings. One is on 57th Street. And the other is on Pearl Street? Right. And these are windowless buildings with gigantic stairs in the front because supposedly they are bomb-proof, flood-proof and supposedly they've been, you know, NSA places for years. I mean, this is not news. We've got two of them in New York City. One of our favorite ones is at 30 Thomas Street. It's a Brutalist building and it's featured in the Hacker Calendar? Yeah. Brutalist architecture. You got to check the 2012 Hacker Calendar, which is last year's. We had this amazing picture of this building that looks like it's straight out of the film Brazil or 1984 or something like that. No windows. It probably goes as far down on the ground as it does above ground. And it's just, it's really scary. There are buildings like this all over the place. The phone company built buildings to withstand all kinds of things. And of course, government agencies took a keen interest in that as well. So by all means, Explore, report to us when you find something like that. Thanks so much for that call. We're going to try and take another one, 212-650-5782. Let's see who this is. Good evening. You're on Off The Hook. Hi. Hi. Speak up, please. Yeah. Turn on your radio. I just wanted to mute my radio. Yes, please do that. Hopefully it's next to you. Yes, it is. What's on your mind? Hi. Well, I'm calling because, honestly, I've been following you for over 20 years. I mean, not, you know, literally. Oh, yeah. I hope not. Going to 2600 meetings 20 years ago. And I've met Bernie, I've met you, and I've listened to this show for almost 20 years too. And I have a question that you, having been in the scene even longer than I am, might be able to shed some light on. I'm really curious about it. And that is, what happened to the promise of the ubiquity of encrypted email? I remember when PGP came out in, like, 92, and everybody was really excited about this. And back then, it was sort of like a solution without a problem. A lot of, even though, obviously, people who are in the know knew that the government was using surveillance back then. But now we have so many different instances of news reports, so many, you know, no more speculation, no more conspiracy theories in the back alleys of the Internet. So many things that blatantly show the government is collecting anything and everything in perpetuity. And yet, it's like, I was using PGP 20 years ago, and I'm not using PGP nowadays. I can't get my friends to use any sort of encrypted email solution, and I don't see any sort of encrypted email solution gaining any sort of traction as far as market share or popularity, whatever. Yeah, I agree. And I think there are two reasons. One is that people aren't, even after all this, convinced of the importance of it. And two, we've really let people down as far as coming up with something that's easy to use and cross-platform and all that. There are all sorts of problems with the programs that come out. We can do it, and it will work if we do it. But there has to be a unified effort. Well, I really want to ask you before I get disconnected, if I do, that PGP, as we know, hasn't been secure for a long time, which was absorbed by McAfee and all that as an email client. Do you at least know of what is a gold standard for encryption that doesn't have a backdoor that you can use in this day and age to encrypt voice communication, voice over the internet and email or anything? Are you asking us for an answer on that? Yes, I am. I don't know if any of us have one. I mean, so GNU PG, the GNU Privacy Guard is fine for email. I don't have a recommendation for voice. The thing that we've learned, though, is that this encryption only does so much because what the NSA in particular and some of these other agencies are most interested in is not so much what you say, but who you say it to, who you communicate with. And unfortunately, none of these programs do anything about that problem. So I hope that the technology gets better and provides some solutions here. But you're right that we haven't got anything complete. I agree. It's an interesting question and it is sort of difficult and not ubiquitous enough. And basically, I think that people that do understand how to encrypt stuff like email especially, you should teach other people, like really evangelize and don't tell people how easy it is. Actually get them to use it. It will protect you and it will protect other people, people you care about. And I think, yeah, going forward that it's definitely going to become something that we all need to embrace a lot more. I'd like to actually ask for help in that field myself. At 2600, we've over the years had various PGP keys out there. And we're trying to get rid of them because we don't... It was ages ago, but people keep sending us things in ancient encryption schemes for keys that we no longer have and we can't get them to stop. And if those keys didn't exist out there, then people wouldn't send messages. And I've asked lots of people. No one seems to know how to just wipe them all out. You have to sort of prove something. And it's very hard to prove that when you no longer have the password yourself. It's difficult. I mean, the answer is you can't if you don't have the keys. Exactly. Because if you could, then anyone else could, and that would be a problem. Yeah. So there needs to be some... Because this happens a lot. I'm not the only person. We're not the only people. We occasionally move on and forget passwords or don't use them for several years. So there has to be something in place that can prevent that from happening. That's our biggest problem is people sending us things that we can't decrypt. So if you see any PGP keys out there for us, don't use them because we don't have a current one. And every time we put a current one in place, people use the wrong one. So we needed something a little bit easier, I think, to use. So one thing that's more proactive that you can do is when you create a new key, you can set the expiration date. So if you say this is only good for a year, and then if you're still using that key in a year, you can sort of extend the expiration date so you don't necessarily have to create a new one. But that doesn't help for old keys that don't have an expiration date. No, it certainly doesn't. Okay, listen, we're out of time. I want to remind folks that we have the 2600 meetings coming up this Friday in various places. Go to www.2600.com slash meetings to see if there's one near you. And if there isn't, maybe you can start one. And it's a great place to talk about things like this. Meanwhile, write to us, oth at 2600.com. Stay tuned for the Personal Computer Show here on WBAI. This is Emmanuel for Off The Hook. Have a good night. Alrighty then. Wow! That was something.