Morning Drive and Afternoon Drive, you'll get local voices, non-corporate news, and WBAI, Arts and Labor Radio for the Tri-State, to the right of NPR on the dial, and to the left on Everything Else That Matters. And that was our moment of silence for Pete Seeger. It's 7 o'clock, you're listening to W... I'm not kidding. He really touched me. You're listening to WBAI New York, it's 7 o'clock, time for Off The Hook. I hope that's understood. Bundy, let's go! It's 7 o'clock, time for Off The Hook. And a very good evening to everybody. The program is Off The Hook. Emmanuel Goldstein here with you on this Wednesday evening, joined tonight by Rob T. Firefly. Good evening. Mike. And Bernie S. Greetings from Pennsylvania. Well, I don't want to go on too much of a rant here, but I was planning on being here so much more than just five seconds ago when I ran through the door, and yet that was the real reason why there was all that silence. Don't trust GPS, folks. Don't trust it, okay? I'm another victim of Google today because, for some reason, some idiot decided it would be a good idea to have an outdoor hockey game tonight at Yankee Stadium, and that's where everybody's going. I knew that, and this stupid app I have on my phone directed me right into the traffic. Even though I knew it was a bad idea, I followed like an idiot and wound up in traffic for about four hours. Is this the first time you've said on the air that you have a phone that can run apps? Well, I said it on the other radio show. They know about it. Maybe this audience doesn't, but yeah, I've railed against certain stupid things, whether they're smart or not. It's just you should never trust technology without actually really understanding what it's doing. I don't know what it's doing. It knew there was traffic. It even said, you'll be there in an hour and a half, but there's heavy traffic. Okay, so why take that route? Why not take the route where I can see and the radio is telling me that there's no traffic? No, take this one. There's a toll. You can pay the toll, too. Google loves for you to pay tolls, and then, okay, what happened? The timer just increased after a while. No apology, nothing. It sounds like, despite your previous admonition, you knew the technology was wrong. It's not even blind trust, and yet you followed it anyway. Well, I sort of wanted to see. Yeah, I have this weird desire sometimes to see things fail, so I wanted to say, okay, you know what? I'm going to trust you. Let's see what happens, and I did. I saw what happened, and it was almost a catastrophe. Then I couldn't find parking around here. It was, oh boy, it was something else. Daniel? Yes. The GPS you're using, was it displaying traffic information as well, or just the navigation info? It was displaying traffic info when I started. It was saying traffic is heavy here, traffic is light there, and basically, I don't have a lot of time to fiddle with it while I'm driving. One thing I noticed, which really kind of annoyed me, I was looking, because I couldn't figure out how to get it to speak out loud. It started speaking to me as soon as I got out of the car, announcing to everybody around me that my destination is on the left. That's great. Thank you. I feel like a real idiot now. That would have been helpful inside the car to tell me that. Instead, it forces you to look at the screen while you're driving, which is unsafe. Then at one point, there was this little tiny bit of notation that said resume. Apparently, I had touched it in a bad way, and it had aborted what it was doing, and I had to hit this little tiny button that said resume, because it thought that I wanted not to go where I was going anymore. I just want to note, you spent ... Go ahead, go ahead, Bernie. Emanuel, you just shouldn't have touched it in a bad way, and maybe it's getting even with you, but I just want you to know ... I was just moving it out of the way, actually. The traffic information you were getting, that is not GPS technology. That is terrestrial technology broadcast by local FM radio station on a data subcarrier. Bernie, ordinarily, I would cheerfully agree with you. This is not a data quibble with me about terminology. Okay. All right. I'm just saying, you said you have a problem with GPS technology. I will give you the ... This is not a GPS problem. Okay. Okay. Can we admit it's all Google's fault, at least? Can we agree on that? No. Google ... It says Google on it, for God's sake. Okay. If it says it on it, and it takes the credit for it, it should get the blame when it doesn't work. Okay. I thought you were talking about just a dedicated GPS thing. Well, it says ... I don't want to get into this, because we have other things to talk about tonight. Okay. That's why I'm flustered, because I just had to run in here. After leaving in so much time, I knew there was a stupid outdoor hockey game tonight. Whose idea was that? It's something like 15 degrees Fahrenheit outside, and they're going to make people sit and watch other people who are well-prepared to be outdoors play a game, and there's going to be some second thoughts about that, I think. You're supposed to do these things in the daytime, not at night. Okay. Anything that we want to share with people? We have some interesting things to get to in a little bit, which we'll be doing, but has there been any news developments that are on our minds? Quite a bit. Why don't you introduce one? Have you ever used this thing I haven't called TorMail? Yes. I heard it was completely compromised. Completely. People know maybe about the anonymity network Tor, which is a thing you can use to visit websites and make it hard for an eavesdropper to know which websites you visited, and for the website to make it hard to know who you are. There was a thing called TorMail, which is not run by the people who run Tor, but was designed to work with Tor, where you could allegedly send emails and no one would be able to read it except your intended recipient, which is pretty cool and a thing that a lot of people have a lot of reason to want. But apparently the FBI seized the entire database of TorMail. So if you were using this thing, then the FBI now has any message you sent through it. Why wasn't it encrypted? Yeah, I don't understand how that's even possible, because something like that is set up thinking that this could happen. So how could they possibly be so vulnerable that all the information could just wind up in enemy hands? I don't know the details of who ran this particular survey, but I think my assumption is that they saw a market for privacy conscious people. They wanted to somehow make money off those people, and they didn't really care about providing quality service. Okay. Now there's TorMail.org.net.com. Do you know which one it is, or are they all the same? I have no idea. I looked for that a little bit earlier, and I just saw it in many different incarnations. Well, it's gone now. Past records of it. This does demonstrate the importance of knowing the difference between something like Tor, which is decentralized. It's a protocol that anybody can help the network run. Anybody can run their own node on it. It's completely not under the control of any one entity. And something like TorMail, which is one entity trying to provide one service, because anytime something is in one central location, that one location is a vulnerability. And if that one location is within the United States, then yeah, chances are it's going to be under the purview of things like the FBI. The location was not in the United States. It wasn't. But that didn't help. Huh. Where were they? But the FBI sees something that was not in the United States. They can do that. Okay. There's a thing, we've talked about it a little bit on the show in the past, called the Mutual Law Assistance Treaty, MLAT. Maybe the people in the know, I'm sure they call it something else, and one was used in this case. Hmm. Okay. Just so we can clarify, it's not Tor, like Robert was saying, Tor is not completely compromised or anything horrible like that. But I imagine a lot of people are going to get confused and assume that it is. Yeah. It's sort of like the Wikipedia WikiLeaks thing, where some people might see Wiki and think they're the same entity or the same thing, and they're not. They're very, very different. All right. Now, what's this about NSA looking into Angry Birds now to get personal information? They seem to be reaching quite a bit, but first of all, okay, this is another thing on a smartphone that I have not yet delved into, and I don't intend to. But everybody's playing this stupid game called Angry Birds, and how in God's name does your personal information wind up in that particular app? Advertising networks. Okay. So they don't ... The NSA did not piggyback on you actually flinging the things at the other things. I guess it's the birds that get flung. They don't care about that, but they care about the data that the advertising networks, which we've said on the past, are out to get your privacy, and they're good at getting your privacy violated. So the NSA wanted to just take a shortcut and get that information straight from the ad networks. Well, according to this story that was put out in conjunction with New York Times and The Guardian, when a smartphone user opens Angry Birds, the popular game application, and starts slinging birds at churtling green pigs, spy agencies have ... I'm almost on the side of the spy agencies now. Spy agencies have plotted how to lurk in the background to snatch data revealing the player's location, age, sex, and other personal information, and that's according to secret British intelligence documents. I imagine these were leaked by Snowden. So yet something else that we have learned. Maybe the authorities realized that the bad guys in the game are pigs, and they got offended? I wonder if they keep track of how good you are too. We could use somebody like you with your flinging ability. It's a Last Starfighter scheme. I think they don't. I think they're much more interested, as I said, in the ad networks. I'm kind of curious, actually. A lot of this data, I don't know how the ad networks get it. How do they know if you're married or not? Do you have to tell Angry Birds in order to play? People seem to want to tell everything to everybody, and it's probably a link to social networking and all sorts of places where you reveal all this information. It's not that hard to find. That's right. They probably get it from Facebook. Wouldn't be surprised. This kind of shocked me, and I use the word shocked relatively rarely, but apparently this is common practice in the corporate world. I did not know about this. If you leave a job, oftentimes what happens is the telephone that you have, which is your phone, by the way, not the company phone, your phone, is somehow completely wiped of all data, ostensibly to protect the corporation that you are now leaving or have just been fired from, but it also winds up wiping all of your personal information. I can include photographs, I can include voicemail messages, I can include everything that is on your phone, and this is something that apparently people are accepting that, yes, this can happen. First of all, using your own phone for company business, I don't see how it becomes the company's phone where they can do something like this, and second, how do they even get the ability to do this? Who gives that to them? I imagine the employee probably does in some ill-fated signature. Generally, so there's this device management technology as the framework this falls under where the company, your employer might say, in order to use your phone to access the company network you have to agree to install this security software, and if you're a normal person you might not know what that means, but it's entirely possible that one of the features of the security software is exactly what you described. Bernie, any thoughts on this? Has your phone ever been wiped by an ex-employer? No, I've not let employers have access to my phone's innards before, but the general term for all this is called bring your own device, where companies that used to provide cell phones to mobile phones, smartphones, to their employees to use for company stuff, and but more recently they've been, typically they're more secure phones like BlackBerrys, but then more recently people wanted iPhones or whatever, so companies just said, well just bring your own device instead, you can use that, we just have to install our software on it, and there's probably some click contracting you agree to that for any reason the employer can just wipe everything off your phone, and that's what this person here whose phone was wiped by his immediately recent employer, and he didn't realize he'd signed this, but he said he probably did, and they just wiped out all his family pictures and everything right off his phone and brought it back to factory condition while he was having lunch, so that would be very troubling to me. First of all, I have always tried to not keep my only copy of anything on my phone, because my phone's always subject to getting lost or broken or something while I'm out in the world, and I don't want to lose anything actually important due to that, but the idea that my employer would want to, wouldn't that sort of access to my phone, I think it would sort of tint my willingness to sign up with that employee to be employed, but if it's part of a mound of paperwork that people are just signing when they start a job that they don't really read, I could see how this could insidiously sort of get in there as something that's accepted. Being somewhat new to the smart world culture, I'm curious, what is the actual process for wiping a phone, what do you do, do you go online, do you call customer service, do you just shake it really hard, what do you do? You have to have access to some sort of administrator software on the phone, so the company when you're hired might say, install this software to get access to your corporate email, and you'll probably say, okay, I'm a new hire, I'm not going to make waves, and then depending on how the software works, probably they do something with computers, that's my guess. And I guess I would know if you deleted it pretty quickly. If you deleted it, yeah, you might be able to get one step ahead of the company and delete the software before they use it to wipe your phone, but you'll lose access to anything that that software provided, so you don't want to do that while you're still employed. It seems to me this is a lawsuit waiting to happen, where somebody wipes out someone's personal information because they worked for a particular company and they basically invade their privacy on their own device and completely wipe it. I cannot believe that's real, I can't believe that that actually happens, maybe people can write into us and tell us some stories, oth at 2600.com. Hey, last week we talked about the guy that was reported to have hacked into healthcare.gov, and we expressed, I guess, somewhat of a bit of doubt as to what might actually have taken place. We got a lot of mail. Boy, we got a lot of mail. Here's a piece of mail from Nancy, sounded like you didn't know who David Kennedy was, I assume you mean the one who works for TrustedSec.com. I've met the guy a couple of times, heard him speak at conferences several times as well. I find it hard to believe a successful person with his own business would try to break into a government website without being asked to test the security of it by the government. Of course, since he went on Fox News, then I'm willing to admit that my judgment may be an error. I may be mistakenly assuming high intelligence equates to common sense. Thanks, Nancy, for that. We basically got a lot of pieces of email, similar types of consternation, I think. What we decided to do is we have David Kennedy on the phone with us now. He's speaking to us from Norway. David, are you with us? I'm with you. Thank you for having me. Appreciate it. Absolutely. Well, I've got to say, you've got a lot of people out there sticking up for you and saying that we got it wrong last week. I have to say, we were reporting the story based on what we were reading in the media. I'm sure you know that the media doesn't always get all the facts right. Keeping in mind we only have 45 minutes, is there maybe a brief list of things that the media got wrong about the story you'd like to outline? Sure. Just to kind of equate how this all started, when the Healthcare.gov infrastructure got released, it obviously had a rocky start of being able to stay up and issues with being able to register people. What I do, I'm a pen tester, do a lot of source code analysis, web application security, stuff like that. When you look at a large company, when they build applications, the first thing they do is availability of the system and making sure people can register so they can make money. Security is usually an afterthought after that. When they were having all these issues, I just started looking around the site itself. Not any type of attacks whatsoever, no inserting of input values, nothing like that. Really just looking at a lot of Google analysis, just kind of browsing the site as a normal user would. We started to find a lot of things that are symptomatic of a much larger problem. I've never said that the website is hackable. I've said that the kind of analogy I used was, and this is what I did when I testified in front of Congress, was instead of me being a security person, let's just say I was a mechanic, and a car drives past me and the engine is making clanking sounds and there's blue smoke popping up everywhere and there's oil leaking, there's probably a problem with the engine. When you look at programming all the time, you look at the source code, you look at everything else, you start to see a lot of things that are symptomatic of a much larger problem. That was the whole conversation. There's a lot of sites that make up what we call healthcare.gov. There's a lot of supporting infrastructure, a lot of things out there. This is all public knowledge and everything else out there. Most specifically, I think the one that got the most attention was the 70,000 accounts. Just to clear that up- Within four minutes, you got access to 70,000 accounts in four minutes, according to Fox News. Right. I don't know if you saw the blog post I did to try to keep that under wraps, and I actually sent emails to the different media outlets to show that, but basically there's another website, and I won't get into the details because it's still there, but there's another website you can Google for, and it's supposed to be an open site. It's a different authentication from the healthcare.gov, different user population, everything else, and it's an open site for folks to be able to register and log into. They post the profiles on Google, so if you Google the site, their profiles are on there. If you go to the profiles, which are open and are supposed to be open, it shows information about that profile, which again, it's supposed to be open on those sites. Literally there's around 70,000 or so of those, probably on error, exposed email addresses and things like that. Additionally, this is just one of the smaller problems, but just last week, people were, since you can register for the site, you can actually create basically your own healthcare.gov webpage that you can serve malware off of. I think the Nigerian prince made it up there, Justin Bieber, good people. Oh, nice. Wow. Yeah. Well, David, when you say 70,000 profiles on healthcare.gov, what exactly is a profile? The way the profile works is it's a way of ... You can basically customize your own page. It's a sub-site. It's not actually on healthcare.gov. It's a sub-site, so something.healthcare.gov. Inside of there, you can create your own profile. You can communicate with other people. It's kind of like a social media type interaction thing. It's all hosted with the healthcare.gov umbrella. That's what the conversation was about, was when you have something open like this under the umbrella of the healthcare.gov infrastructure, it's going to be problematic because people are going to abuse that and abuse the information on there. I'm trying to understand. I'm trying to understand. If you register for healthcare.gov, why would you want to talk to other people through healthcare.gov other than the health insurance company that you wind up using? Well, this is like a ... It's a site that's used for communication between people. Developers can go and talk to them about hooking into the healthcare.gov infrastructure. It's basically kind of like a place to communicate back and forth with. I don't know the whole specifics of what it was developed with. It was done by a third party that wasn't through CGI and was basically hooked into the healthcare.gov infrastructure. If, say, your cousin in Scranton or something puts together a profile, signs up on healthcare.gov, are you saying that that information that they put in there is now on Google and people can look that up? Not on healthcare.gov. You'd have to register for a different site. Okay. This is actually ... It's been in the news. There was a thing that happened last week where they were hosting on a malware. The website was data.healthcare.gov. That's what came out in the news articles for all of this. That's when they were serving up the malware from the website. They basically closed all registration, so you can't even log into it now. Basically, they're serving up malware, things like that. As soon as you register for that site, again, independent authentication, as soon as you register for that site, all that information is public. Okay. There's not any disclosure or anything like that. The person who put the information in there didn't necessarily want that information to be public. Is that the point? Well, there's nothing there that says that your information is going to be posted, i.e. your email address, your first name, last name, anything else that you post up there. It's all pretty much just open to the public. It gets indexed via Google and everything else. There's no disclosure of that when you register for the site. To me personally, grabbing 70,000 or so ... 70,000 is just a number that was one of the profiles that was on the page. It could go up to 100,000, 200,000, I'm not sure. It's a lot of information that you can grab about individuals registering for the site to use for other things. Having a fully-fledged website hosted on data.healthcare.gov makes it much more believable. Hey, David. A lot of people ... 2600 used to have a forum where people could log in and talk about the conference that we help run. One of the features of that forum was that you could create a profile and you could put your bio and I don't know what else was there. It was public data. We never had 70,000 users, but it seems fairly similar here. You create public data and it's available publicly. Is there a difference? In the forums that you used, were you exposing email addresses and things like that? I don't know. I don't think we were. I'd like to know if we were. I'm not aware of doing that. We definitely weren't. And also, people who were signing up on our forum knew that they were signing up on a forum and filling out a public profile so they could choose what they did or didn't put up there based on that. And I've registered on healthcare.gov several times now. Well, because I was testing it in different areas, different states, and different names, things like that. But I would be rather appalled if I knew that the information I put in there is able to be seen by other people because it was never said to me that that would be the case. But it's a different website. Okay. The thing is, I went in through that website. That was the portal that I went in through. If I got transferred someplace else because of the state I happen to be in, I still consider it part of healthcare.gov. I'm sure that there are people out there who are confused and registered for this other website intending to see healthcare. But it's not... My understanding, and tell me if I'm wrong, is that this website where the data was exposed is not part at all of the get some healthcare thing. Correct. Yes. Different. But well, that's a whole other topic too. So this is one of about 20 other things as well, like extensions and things like that that were vulnerable through Google, stuff like that. I mean, again, more systemic problems, I guess, as a whole. But yes, it's a completely separate infrastructure. So when you log in and you register for the healthcare.gov website, it's a completely independent website of the other one. Okay. But you can get to the other one through that. Is that right? Absolutely. Well, David, let me ask you, what exactly is the problem here with these website developers? How do they make things that cause such problems? Well, what happened from this, and this is from the very get-go, is you look at the government process. And the government process is typically it's go to the lowest bidder. And you have an X amount of time, finite time to get it. And then you bid on X, and it ends up turning out to be Y, which you have 3,000 people kind of putting their feelers in. And it becomes a completely different infrastructure you had before. And so you have that, and then you have companies that have to staff up for it. So you go from, let's just say, 20 developers to 500 developers overnight. There's no real way to build a solid SDLC with security built into it. So it's really a larger problem. It's not healthcare.gov specifically in any way, shape, or form. It's federal and statewide. And it has to do with how we do our entire procurement process in the government. And the check mark for everybody in the industry right now on the government side is FSMA. And FSMA blows. It sucks. Okay. Tell us something about what that is. The Federal Information Security Management Act of 2002. Basically it's an act that basically requires information security to be kind of embedded into the government. And what FSMA is, they have to attest to what's called 800-53, and it basically just gives guidelines to how you should run security. So it's more of like a, I guess something comparable to it would be something like a HIPAA-type thing, but for information security. So more of like an overall high-level governance structure around information security. So it's a check box, and that's what it's become in the industry. And they have to adhere to NIST guidelines, which is the 800 series, and it becomes basically a check mark of how you comply to security. And for folks that have been in the security industry a long time, compliance definitely doesn't equal a secure environment. It requires frequent testing and understanding and building security into your software lifecycle and how you build your applications versus anything else. And that wasn't done. Interesting. Hey, Dave. Go ahead, Bernie. Yeah. Dave. Hi. This is Bernie in Philadelphia. I just wanted to ask, there's a common conception or misconception due to maybe some bad reporting in the mass media, news media outlets, that you caused... You caused it to release. You accessed personal identifiable information from a site or either healthcare.gov or a site connected with it, but that's not really what happened, is it? Not at all, no. In fact, if there was anything that I'd accidentally accessed with personal identification, I'd probably call law enforcement right away and then swear to God that I didn't try to do it on purpose. Yeah. Good luck with that. Well, yeah. No. The intent wasn't to do any type of attacks whatsoever in the system or extract any information or access anything in an unauthorized fashion. It was literally just, hey, from a tertiary view, can I make an assessment on this? And I can't say that whole thing sucks and everything behind it is horrible, but again, looking for web apps a long time, there's certain things that you see, like SPF records that aren't done, SSL certificates, basic stuff that a normal pen test would find in a very early stage. And there was other things that a lot of other people were very vocal about. I know Ben Simo found that you can bypass the forgot password stuff and get access to other people's accounts. And there's other ones where individuals will log in and you see other people's information. So broken authorization and access control. So these things are much larger, of a much larger problem around how they developed it. You don't have to go and attack the site. There's no reason to. You can see it from an outside view. And so everything was done, again, from a normal browser. No interceptor proxies, no having to manipulate traffic, nothing like that. Basically just Google and Chrome. And no input validations, no trying to test for SQL injection or things like that. That to me would be violating a lot of ethics and trying to find vulnerabilities in the site. It's literally just trying to see what you can see from a normal person's perspective. But do you think for those people that wouldn't have a problem violating those ethics, that they would find quite a bit of vulnerabilities? Well, that's the thing. I mean, you have to look at this and say, is it hacked or has it already been hacked? And I guess the question is, we don't really know because there's no breach disclosure laws for the federal government. You know, HIPAA, there's no PHI data, period, on healthcare.gov. But HIPAA only goes down to the state level, even though it's a federal mandate. And there's no breach disclosure laws, even though 49 states have that. Federally, if a breach happens, they don't have to report it. But on a positive note, I do want to say that I testified twice in front of Congress. The second time was a pretty horrible experience. I probably will never do it again. Politics aren't for me. I'm kind of a security guy. But what it did do is it brought a lot of awareness, I think, to needing change and needing to do something different. And HHS did reach out to me, and we've been working with them, and I feel very confident that they're doing the right things to fix it and make sure that security is on the forefront, which is a really positive thing. I just hope that it takes hold, not just with healthcare.gov and not just with the medical side of it, not the medical side, but just the small flavor that HHS has, but really federal-wide, because we really have a problem, I think, with how we actually defend our systems. I'm curious about the horrible experience in front of Congress. Was it a bunch of congressmen just trying to get sound bites and make you look bad? Yeah, pretty much. The first time around was real positive. I think everybody was really interested to know about it, and the second time around was really just trying to, I think, kind of keep me quiet so that I didn't talk about it anymore. And instead of talking about the issues and talking about the security, it became more about politics. I stay out of politics completely. I'm not a Republican or Democrat. I don't like any of them, period. So when it came to what I was trying to say, I was really keeping it just on the lines of security, and that's it. No other agenda, really just security. And obviously, you can't do that in that type of environment. It becomes very politicized very fast. And so it turned to where they're trying to hit me on technicalities where I didn't solve the paperwork properly so they wouldn't hear my testimony, but then it was approved and it wasn't. And it just turned into this really craziness thing, which, like I said, it happens, I guess, and I'm glad I got to do it. But I'll stick to what I know best, which is security. And that's always the danger with this stuff, isn't it? Where whenever security and politics meet, you get this sort of atmosphere where they're not trying to find out the actual facts. They're trying to get soundbites out of you to support what they want to say. And I think the security community, by and large, is very familiar and very tired of that sort of state of events. Because it's a very sort of political thing to try and change the facts to fit your views rather than try and get the actual facts and then do something about them. I totally agree. Apart from the way the politicians responded, how has the response been in the general public, in the media? Well, I mean, I think, you know, in general, it's been pretty good. I mean, I try to balance myself on which news organizations I go into. So just for everybody out there, I did CNBC, CNN, Bloomberg, Huffington Post, and a few other ones that kind of kind of spanned out of it. But, you know, I think, you know, overall, aside from the over sensationalizing that happened from the $170,000 mark, it was pretty accurate and received pretty well. And, you know, the whole goal of this wasn't to really target HealthCycle because that's not the problem. The problem is the federal government side and moving to more, you know, stringent rules on how people do security. And I don't know if I was able to accomplish that or not. Well, it definitely got the conversation going. So I think that's definitely an accomplishment. Yeah. And I hope it does. I hope it keeps going. And I hope the federal government changes. I just don't know if I have enough oomph in me personally alone to do it. And there's a lot of folks that helped me, you know, when I knew this was going to be kind of a rough one going into it. And so, you know, I sent my findings to some folks that I know, you know, in the industry. So Ed Skoudis and, you know, Kevin Johnson, who focused on web applications, and a few other folks. And they said, hey, here's my stuff. What do you think? You know, if you were to say, you know, just looking at this from a, you know, web app perspective and you saw these issues here, what would you think? And, you know, they all pretty much came back to the same thing, that there's some issues there that definitely need to be looked at. And I just hope that it kind of broadens over to the federal government. Now we're mentioning the federal government here, and obviously there are all kinds of websites run not only by federal government, state governments, local governments, and corporations, in addition to regular people. How prevalent do you think the kinds of problems you uncovered on this site are on all those other sites? I think probably it's significantly worse all across the board. I think the states are even more horrendous than the federal, but I think it's pretty bad all around. And the thing is, you know, there's sites that you can look at that, you know, monitor, you know, like torrents and things like that, looking for, you know, like compromised accounts. And, you know, you have the Pwnlist and stuff like that, where, you know, they look for accounts. And you see, you know, .gov sites getting tagged all the time, and big ones that you would, you know, know if you heard the names and, you know, saw public information. And, you know, we never hear about it. We never hear about the mass compromise, unless somehow, you know, the PHI data that's stored in there, you know, gets sent out to the world. Then all of a sudden they have to kind of play, you know, makeup on it. So I think that's a big problem. And I think all of our information is just basically being scraped by everybody right now. And there's nothing we can really do about it. Well, what would you say to people that are going to register through a site like healthcare.gov? Should they not do that? Should they be careful in what they say? Well, I mean, you know, my stance before was stay away from it. You know, just because, you know, the issues in the rocky start, and I know that they're working to fix them. But, you know, I literally, you know, I've been working, you know, having some discussions with HHS, and I really believe that they're really focusing on doing things right. So, you know, I would say that, you know, hey, you know, take a look at it, you know, weigh your risks on it, and go and do it if you have to do it. And, you know, just know that, you know, it's going to be, I mean, if you look at where our information is stored in the federal government, it's pretty much everywhere. So, you know, putting it in healthcare.gov right now is not going to make a big difference in the event that something did happen. But I would say, you know, at this point, you know, with what they're doing and from what I'm hearing, I would say that, you know, it's getting much better. Interesting. Can you give us an example of perhaps somebody or a news organization or just any entity really that got the story as wrong as you could possibly get it, or just is jumping to all kinds of conclusions that are completely crazy? Yeah. I think the initial ones spawned off of...I can't remember if it was the Washington Times or the Washington Post. It was one of those. And literally... We read the Washington Times. That's the one we had. Yeah. So that was the one. That was the one that got it completely off. And I actually sent them an email on the day that it came out, and basically explaining that this thing's, you know, completely, you know, messed up. And they actually posted another story clarifying the situation. So that was really cool. And they responded really fast to it. So there's another article that they wrote to kind of clarify. I wish they would have put, you know, hey, this story's been kind of, you know, inaccurate. So here's the new post to it, but they didn't put that on there. But, you know, I think that was the one that kind of started the catalyst of everybody else. Uh-huh. And I imagine it's been pretty difficult having to deal with all that. Yeah. I mean, you know, the last thing you want to see is your name saying, heck, heck, you know, a government website. That's not something that I want to be associated with, nor did I ever do. So you know, setting the record straight was really important to me. And, you know, I mean, obviously, you guys, you know, saw the article and, you know, made some judgments on that, too. And that's not what I want to have happen. You know, the whole intent wasn't to do anything bad or malicious, and it wasn't anything, like, in that capacity. Right. But it got kind of blown out of proportion pretty quickly. And, you know, it seems like it's died down, and things have been fixed quite a bit, and the stories came out in the right direction, and it's just a matter of getting the right information out there. I'll tell you, I'm not a, you know, huge understanding of the media or politics. I'm sure you're probably much more acclimated than I am, Emmanuel, but, you know, the whole thing is, you know, it's crazy just how one thing just spawns into a whole bunch of other things. You're like, where the hell did this come from? Uh-huh. You know? Yeah. I agree with that. That's for sure. Hey, just to set the record straight, you haven't fled to Norway, right? You're just there. Right? It's not like it snowed in a second or anything like that, right? No. All right. Good. I have not. I'm doing some customer work out here. I actually have a very, you know, successful business doing information security consulting work, and, you know, I contribute to the open source community and all that good stuff and do all the right stuff. So, no, I'll be back shortly, and thank gosh, because my wife and three kids are missing me, so. Oh, good, good. You know, we've heard nothing but good things from the many people who listen to the show who knew more about you than we did. David, we hope that we can see you at our conference in July, if you're around in New York City. It would be great to share some of this information. I'd love to. I have to warn you, I hug everybody, so if you're not a hugger or a friend, I can get along. Well, there's a lot of that that goes around, but anything else that you want to tell us? Websites? Any kind of points of information? I mean, the trustedsec.com blog post, there's one there on the healthcare.gov security update. It kind of outlines the history of everything that happened. You know, that's a good one, and, you know, I think that's really it for me. And, you know, on the techie side, I write the social engineering toolkit and a bunch of other open source frameworks for exploitation on the White Hat side, so check them out. They're free. If you could just say a little more slowly the name of your website so people can find it. Oh, sorry. I talk fast. Website.com. Thanks. Someone also wrote in and said that you started a convention. Is that true? I did. I started a conference called DerbyCon with a few other folks, and, you know, for me, I kind of grew up early on, like, I think it was DEFCON 9 or 10, and I remember, you know, kind of sitting out there. Was it Alexis Park? Okay. Yeah, I remember those. And sitting out there and just kind of, you know, everybody was open and talking to people and it was really friendly and family-feeling, and I saw, you know, the SMU group for the first time, and it was kind of like, you know, the CDC was there and all the kind of people that, you know, I admired and kind of thought were the most amazing people in the world. And DerbyCon was kind of founded off of that family feel, and it was insane. The first year we opened it, we had over 1,000 people, and last year, we broke over 2,000. So it's a really great conference family-feel type of thing. And where is DerbyCon? It's in Louisville, Kentucky. I see. You hear the way he said Louisville? Are you from Kentucky? I'm not. I'm not. But I fell in love with the downtown area there. It's such a tight-knit ecosystem where you're basically partying with all your hack buddies. Well, the thing is, you said Louisville the way people from Louisville say it. So that's why I thought maybe you were a native. So when is the next DerbyCon? It's always the last weekend in September. So I think it's the 26th, 27th, and 28th of September. Okay. Well, there's not much that'll get me to Kentucky, but that could be one of the things. We'd love to have you. All right, David. Thank you so much for speaking with us. And keep doing what you do and stay safe because there's a lot of people out there that don't get it, obviously. Thank you very much for having me. I appreciate it. And keep doing what you folks do. It's totally an honor to be on here, seriously. All right. Well, enjoy Norway. It's great this time of year. It's much warmer than where I'm from in Ohio. That's probably true. All right, David. Thank you. Good night. Thanks, David. And that was David Kennedy, security analyst, a guy at the heart of a big story, I think, involving healthcare.gov. And I guess, you know, it shows you how many things there are to pay attention to and to check out and test. I mean, nobody thought to actually do those kinds of penetration. I don't know if it's even technically a penetration test, but just basically look at what's available, what information is out there, and look at the response that it got. It's pretty incredible. Yeah. It really demonstrates the value of that sort of thing. If you have the knowledge of something being vulnerable, you want to let the people responsible. You want to let the people know about it. But at the same time, you don't want that misconstrued as you being the person who broke the site open and are doing shady things, like can happen with nth generation news stories that are written for sensational headlines. So we do try and keep the record straight here, and we're glad we had the opportunity to do so. All right. We're going to take some phone calls, 212-209-2900. That's our telephone number. And our email address is oth at 2600.com if people want to write to us. And express their views, their wishes, their demands, whatever. Here's a letter from our friend Leo. In last week's show, you guys were talking about Google Glass. Somebody mentioned that it's basically wearing a camera on your forehead. The thing is, that's not quite accurate. It's more like wearing a smartphone on your forehead. That's much better, isn't it? Actually, a pretty crappy smartphone, as Google decided to put a tiny battery pack into it, but I digress. An unrooted Google Glass can only record up to 15 minutes of video at a time. And the biggest reason for that is, like I said above, the battery life sucks. But Google Glass isn't really meant for recording. It's supposed to be an augmented reality type of device. So that's why the camera is there. That way, the device should know where to do overlays and things like that. But it's too weak for that. I don't honestly understand the whole controversy around it. It seems that people are most bothered not by the fact that it has a camera, but by the fact that you can actually see the camera and know that there's a possibility that you might be recorded. It's like people are complaining not about potential surveillance, but rather the fact that the possible surveillance is overt. Google Glass costs $1,500. A pair of glasses with an HD camera cost only a few hundred dollars max, and those are top-of-the-line surveillance items. If somebody bought a Google Glass device to record people covertly, then they wasted their money. And also, Google Glass won't be such a good idea for Hope X, in my opinion. Why? Because if you're nearsighted, then you either won't be able to see the screen or you'll have to squint really, really hard. They now have prescription lenses, but that's just the Google Glass attached to a pair of glasses. The guy that got questioned by the feds must be somebody connected to Google, as the new prescription Google Glass only was announced earlier in January. So thanks, Leo, for that bit of information. But you know, the thing about it is, yeah, it can only hold 15 minutes. The battery life sucks. That's all going to improve. We all know this. The other thing, I really want to know about the HD cameras. For a couple hundred bucks, you can put on glasses. I didn't know it was that cheap. So you are afraid of this technology until you own it? No, I want to play with it. Yeah, and then you'll be okay with it? I'll be playing with it. I play with all kinds of things I'm not okay with, but I do want to know how they work. Yes, Bernie? I was just going to say, these little cameras are getting better and better. I bought one in Beijing about a couple, three years ago. And it's about the size of my thumb. You could clip it onto your clothes, and it's fairly unobtrusive. And the video quality was amazing, and you could record a couple of hours. We had the spy pens that we had as premiums here on WBAI, so yeah, I'm aware of that. I just didn't know that it was such good quality, it was easy to put on glasses, and yes, it's a valid point that Google Glass is overt. It's basically advertising what you're doing, whereas other people could be ... And that's why I made the point last week that we're going to have contact lenses that do this kind of thing before too long. How do you fight that? How do you fight things like this when you can't see it? It's very hard to fight what you can't see. It's also very hard to fight the advancement of technology and the ability to do things like hide a camera on your person. Is it the advancement of technology, Rob? Is it? I don't know. I think part of the thing we need to do as a culture is create social mores around these things and the Google Glass is one of the most visible, both that you can actually see it when it's on someone's face and that we're talking about it a lot, opportunities for us to have that conversation. I don't think it's reasonable to say, there was this thing 10 years ago that some people bought that could do some of the same things and no one talked about it then, so this new thing must be okay now. I think it's important for us to figure out what is okay, what we're okay with. Yeah, but even if we're not okay with it, how would you stop it? How can you possibly stop something that's so tiny that no one can even detect it? You cannot hang out with people who would do that sort of thing. But how do you know those are the people? There's no way to know. Yes, Bernie? Spray paint. What, on people's faces? This is not the kind of culture I want to live in. You can have little tiny spray paint containers, like people carry around little mace sprayers, but it just has black paint, like undercoating spray. If you see a little camera, you can just spray it on the lens. Yeah, but the point is, you won't see the little camera because it's so little that you can't see it, and it's hidden. Some of them are hidden inside, I've seen a couple hidden inside, the lens is hidden in a button that you could have on your shirt or coat or jacket, and you just see buttonholes. You can't really see the lens. It's very hard to see. Yeah, I used to think that having a camera hidden in a lamp was a big deal, but apparently that's nothing these days. You can hide them anywhere, and just assume you're being recorded at all times. Is that what we want to live in? A society where we assume we're being recorded at all times? It's worse than anything Orwellian, I think. I think they've given up, but the CCC in Germany used to sell paper bags you could wear over your head. Okay. So, now you don't know where you're going, and you're being recorded all the time. Well, I think there might be some cutouts for the eyes so you can see out. 212-209-2900. Yeah, we had a bunch of phone calls, and we talked all the way through them, and I know the timeout is very quick. So, if you call in, we will try to get to you as a call comes in. If you get hung up on, just call back. 212-209-2900. I believe next week the fundraiser begins, the winter fundraiser, so this might be the last chance for a little while to call in and voice your opinions or questions or things like that. I'm also reminded of a guy who came to one of the HOPE conferences, I think in the early 2000s, and he was wearing the novelty Groucho Marx glasses with the nose and the mustache to not want to be recognized. Yeah, and we all know who he is now. Yeah. Good evening. You're on Off The Hook. Yes, hello? Hi, speak up, please. Hi, my name is Matt. How are you doing? What's on your mind? Nothing, I just wanted to comment on the story that's being spoken on the radio. Go right ahead. You're on the radio right now, so go ahead. Oh, fantastic. What I was saying is, I don't necessarily, I'm not so afraid of it insofar as, nothing that I do on a daily basis is all that interesting and or worthy of record, and I think it's something from me and or anything else, if they try hard enough, they'll always have been able to. So this fear of ubiquity is, I think, a bit paranoid. I mean, what is everybody afraid of getting out there? What are we so afraid of being recorded? I'm not that scared of it, I don't think, I don't think it's Orwellian. You have no secrets at all? You have nothing that you wouldn't want us to know about? Of course there is, and I would be unhappy if somebody dug in my life to do it. I just don't think that that's all that realistic. The trouble with that argument is always that the, if you don't have anything to hide, then why are you worried sort of argument is, who decides what's worth hiding and who decides what's okay? You could say that what you do now is not notable, but what if one day one of your routine things that you do becomes something that people don't want to happen anymore, whoever makes the rules? I completely agree with that. What I guess I'm saying is that I don't think it lowers the bar of that kind of control or oppression all that much. I don't think it changes, it's not a game changer in people's ability to spy or control each other if that's what the powers be who have the amount of power to do such a thing decide to do. The way I always look at these situations, I try and put the power in an oppressive government, say Nazi Germany, or even present day, maybe in the streets of Ukraine right now. Not comparing the two obviously, but that kind of power, that kind of surveillance, being able to know and predict where somebody is or what they're going to be doing, what their habits are, it can be very, very empowering. If you happen to live in a regime where it's not much of a threat, great, but that's not a permanent situation by any means. I think that's true, but there's another argument to be said, which is that when it becomes so cheap and ubiquitous, the people that do the monitoring are just as vulnerable as being monitored. That's a very good point. But you see their reaction whenever you actually use it against them. If you record a cop, look at the reaction that you get. You'll get thrown in jail, you'll get all kinds of fictitious laws quoted at you. And same thing if you go to an intelligence agency and try to take a picture, you're going to get all kinds of resistance to that. So I say what's good for the goose is good for the gander, but it doesn't apply, unfortunately. I think that that's true, although you do see, I mean, in talking about these things, you do have the situation where police confessions and interviews with people are being recorded. And those kinds of practices, which when they do become universalized, and that transparency can make a big difference. That which is hidden is oftentimes very, very dangerous for society as well. I mean, false confessions, intimidation on the part of police, et cetera, et cetera, has been a big scourge in the justice system for decades. And the fact that cameras and transparency might at some point make that less likely is, I think, a huge boon. All right. Well, listen, thanks for the phone call. We're going to move on to some other calls. You too. Have a good day. And good evening. You are on Off The Hook. Uh-oh. Hello? Yes, go ahead. Hi. I'm calling. First, I want to preface this by saying just that I recently started listening to the show, and I really like what you guys are putting out there, and I wish it was available and more diverse. Well, thanks. Thank you very much. But there's one aspect of it that's been giving me, or the conspiracy theorist in me, a bit of pause, which is the truth of your nomenclature, or personage, as it were, if memory serves, from 1984, Daniel Goldstein was constructed by Big Brother as a fictitious leader to sort of bait to attract potential political subversives. Yes. You read to the end of the book. Not many people do that. And yes, that is true. It just means don't believe anybody. Don't trust anybody. I mean, obviously, trust people enough to stay sane, but assume that what you are being told, no matter what the source, may not be the entire truth or may not be true at all. Okay. Well, what kind of bearing did that have on your selection of that name? I mean, did that occur to you? Was that part of it? More or less, yeah. More or less. But basically, think for yourself. Okay. And don't believe any authority figure, and what you see in front of you is probably not really what's going on. Okay. Not even with you guys, I guess, to an extent. Well, we don't want people blindly agreeing with everything we say, obviously. Right. Okay. All right? All right. Thank you. I appreciate it. Thanks for your call. Keep listening. Yep. All right. Take care. Good calls tonight. 212-209-2900. Let's see if we can keep that going. Good evening. I think that it changes Emmanuel's opinion regarding cameras. I think that it changes people's behavior. I think that it is very destructive of freedom. I think that it makes people feel guarded, and I think it's very horrendous. I think that we need to start having some ethics about this. And they are everywhere. Mm-hmm. They are everywhere. There's 200 more that are being installed in Times Square now. They say it's temporary for the Super Bowl, but I don't think they are. I believe you. And I think there's a lot more than 200, too. Are there 200 vantage points of Times Square? I don't think so. Alright, that is something. OK, let me tell you something. If somebody, Joe hold on, gotta call Joe back. Okay, if somebody is threatening to throw you over a balcony, you don't have to have lunch with that person.