That's right. And once again, that number is 212-209-2950. Off The Hook is here, and they're about to do their program. And I'll just give it to the guys over here. And once again, one more time for the number, 212-209-2950. This is WBAI New York 99.5 FM and WBAI.org on the web. Coming up next is Off The Hook. Now, now, now, now. Thank you, Reggie. And the time is a certain point after 7 p.m. You are listening to WBAI 99.5 FM New York, and it is time for another exciting edition of Off The Hook. The telephone keeps ringing So I ripped it off the wall I cut myself while shaving Now I can't make a call We couldn't get much worse But if they could, they would Fundidlybump are the best, expect the worst I hope that's understood Fundidlybump Fundidlybump And a very good evening to you. This program is indeed Off The Hook. Rob T. Firefly here with you. I'm joined in the studio by Mike. Hi there. And over the newfangled comrec system, I hope to have Emanuel Goldstein. Yes, can you hear me? I can hear you indeed. You sound very good. You sound like you're here in the studio. Yes, except I sound like I'm one second behind in my headphones. Okay, it's going to be very confusing for me. It also doesn't sound like I hear you, Rob. I hear Mike, but I don't hear Rob very well. I can hear it. Did you hear the problem, Rob? I did hear the problem, and Reggie's here now. He's hearing us a second behind. Oh, okay, there's a big button on the thing that says fix, and we pressed it. How do we sound now, Emanuel? Emanuel, can you hear us at all anymore? Well, Mike, I hear you, but the problem is I hear myself a full second later, which makes it awfully difficult for me to monitor myself. I'll give you an example of this. Is it still happening now? Something just happened. There's a lot less background noise. Does that help you at all, Emanuel? Apparently not very much. Maybe. Maybe. How's it sounding now? We seem to – this board has so many buttons, and there's like N buttons, and, of course, 2 to the N minus 1 configurations are wrong. So we are rapidly trying them all. Okay, so that may be it. All right, eventually we'll run out of buttons to press. How are we sounding now? Can you hear us at all, Emanuel? Again, Mike, I hear you. I don't hear Rob. He hears Mike, but not me. Okay, do you hear me now? Emanuel, do you hear me? Apparently you still don't hear Rob. This is very exciting. I hear you, Mike, saying that, but I don't hear – I might have heard Rob just now. Do you hear me now? Yes, I do. Wow, excellent. Okay, so you're hearing me now. Are you still hearing a delay? I don't even hear myself, which is good because I can hear myself out of my own head, so I don't have to hear myself through my headphones. So that works for me. All right, we should take a photograph of the board and remember this configuration for next time. I remembered it all, but it's all coming back to me. Okay, we seem to be – The problem is we couldn't test this out before because the program before us was live, so we couldn't test this out. So please bear with us, listeners, because we had to test this live on the air, but I think it works now, right? Yeah, it seems to be sorted out now, and everything's cool. So, Emmanuel, how are you doing out there? I'm just great. And where is out there? I'm here with Kyle. Hi, I'm here. Out there is Spain. Yeah, we're actually in Granada, which is in Spain, by the way. Granada, where they get the grenadine. And how's that place treating you? It's quite nice, actually. See, here's the thing. When you travel in foreign countries, you have to sort of adapt. We were going from Barcelona to Madrid, and we realized that the train ticket from Barcelona to Madrid was horribly expensive. But if we were to get a Spain pass, which enabled us to get four different passes, it was only slightly more expensive. So for the price of just a little bit more of a ticket from Barcelona to Madrid, we were able to get a ticket that took us to four different places. So we went to Madrid, and now we're down in Granada, and we still have two other places to go, and we're not exactly sure where those are yet. So you must have taken their fairly new high-speed trains that they have in Spain. Absolutely. Yeah, the trains are really, really fast. Five, six hours go by, and you're on the other side of the country, which is pretty amazing from the American perspective, where that would be several days. Yeah, it's incredible how every single country we've been in has really good high-speed rail, Spain being no exception to that. The AVE trains are the high-speed lines here, and they get you places very, very quickly. Barcelona to Madrid in about three hours. So they're like birds. Did we lose you, Emmanuel? It sounds like we might have lost them. This is terribly sad. But if indeed we have lost them, they know how to connect back up, and I'm sure they'll let us know when they're back. In the meantime, we've got an interesting show for you today. We're back to one hour, or a bit less than one. And yeah, there's a lot going on. First of all, I'll update you, dear listeners, on the pledge situation. We've gotten last week, or the week before last, we weren't on last week, we put out the call for people who pledged for premiums of hours on this show through WBAI in the past, no matter how long, and did not receive your premium. And we've been getting responses to that, which are eye-opening. We are reading them. We are hanging on to them. We are bringing them to the attention of the people whose attention needs to be brought to. So if you haven't done that yet, please do get in touch with us. Send us your name and address when you pledged. If your name and or your address has changed, send us the current one as well, so we can match things up to where they belong. This is not an easy process. It's not a fast one, sadly, but it's one that we're determined to get right. Do I hear you guys again? Emmanuel, are you there? We're back. We're back. Are we back? Hello? You seem back. Hello? Hello? Oh, no, that was awful. Wave your arms the other way. We fell into some weird zone, and it was awful. It was terrible. Okay, are we back now? Can you hear us? You are back. You are no longer in another dimension. Welcome back. Newfangled technology. Oh, my God. Okay, yeah. So here we are. I think I heard something of what you were saying, Rob, about people being upset about premiums and things like that, right? Yes, indeed. Just updating people where we have been collecting the responses we've been getting to our call for missed premiums. If you didn't receive a premium, no matter how long ago, and you haven't gotten in touch with us recently, please do so. We are holding on to those. We are following up on them, and we are proceeding with the arduous process that it's taking to solve this. This episode today is a fundraiser. We are still doing a fundraiser. And if you go to givethenumeral2wbai.org, or if you call our famous pledge line at 212-209-2950, Off The Hook needs your support. Let them know you're supporting Off The Hook. We, unfortunately, don't have more premiums of our own to offer you, but WBAI has their own premiums, and you can look on the website or ask the operators what they've got for you for supporting Off The Hook. Your support is still vital, and if there's still going to be a station for us to solve our present problems at, we need your support. So don't hesitate. There's a reason why we don't have premiums for you, and that's because we don't want to enter anything new into the mix at this stage because there's been such a problem with getting the old premiums out. We don't want to make it any more difficult. We do believe the station should be supported, obviously, because we're on it, and we think that people who just want to keep Off The Hook on the air, keep WBAI on the air, should be calling 212-209-2950 or going to the website and supporting us that way. But we don't want to offer any new premiums because we're afraid that might not result in more complaints in the future. We're working on getting the previous ones fixed. And I know Bernie has more information on this. Bernie, is Bernie with us? Bernie is not with us. There was a question as to whether he'd be available or not, and we have not heard from him, nor is the special Bernie-only phone light blinking over here. So we're doing without him for the moment, though his presence is felt in spirit. All right. Well, if Bernie is listening or if we're able to reach him, then I know he has some more information on the premium situation. I just read something on the e-mail list. But we do encourage people to call 212-209-2950. Yes, there are premium issues. We do want to get them fixed. And the best way to do that is to support the station so that we are still here to talk about them in future weeks. Yes, indeed. So while we're asking for your support and hoping to earn your trust for the times we do this in the future, there's also a lot going on. We haven't been on for two weeks. A lot has happened in the worlds of our spheres of interest. One big one, one big story that's going on this week is the LulzSec hacker known as Sabu has been released after a quote-unquote extraordinary FBI cooperation. Authorities credit Hector Xavier Montsegur with helping them cripple Anonymous in lenient sentence of time served. Now, for those unfamiliar with the whole Sabu or LulzSec fiasco, either of you guys want to summarize that? Well, Sabu I know has been an essential part of the whole LulzSec movement over the past couple of years. But it turned out he was actually an informant for the feds for that entire time. It was a question as to whether or not he was being intimidated into doing this and just how severe his punishment should be by the feds for supposedly being part of LulzSec. It's a very weird story. I don't like to see anybody go to prison. I don't like to see anybody punished for things like this. I do have very bad feelings about anybody informing on others. So I'm very conflicted on this. You would not be alone in that. There's pretty much an outcry for this guy in certain circles. He doesn't seem to be hacker friend number one in the world right now. Monsegur, or Sabu as the celebrated hacker, was known with sentence to time served equivalent to the seven months he spent in prison last year plus one year supervised release in reward for having spent much of the past three years working as a federal informant. He had been facing a maximum sentence according to official guidelines of more than 26 years, but they seem very happy with him. Loretta Preska, the chief judge of the federal district court, repeatedly praised what she called Sabu's truly extraordinary cooperation. Apparently he provided, quote, sophisticated and complex assistance to the government, allowing them to pierce the secrecy surrounding LulzSec and successfully prosecute its members. Monsegur himself has said, I'm not the same person I was three years ago. I've come a long way and I've had to do a lot of thinking and soul searching. I'm wondering if we've heard the last about this guy. I mean, what's interesting, of course, is I have no way to validate whether this is true or not. But what some people are saying is that Sabu not only informed the police about crimes, if you will, that were to be committed, but actually instigated some of these things that may not have otherwise happened without his involvement. So that is a bit worrying. Indeed. There's a figure in all this known as Jeremy Hammond, who is currently in prison. And let's see, Sabu, or Monsegur, was seminal in nailing Jeremy Hammond, who at the time was the FBI's number one most wanted cyber criminal in the world, for his role in hacking into the private intelligence firm Stratfor. Now, Hammond was sentenced to 10 years last November for his role in the computer breach. What was not discussed during Monsegur's sentencing on Tuesday was that when he was convicted, Hammond claimed that Monsegur himself had directed much of his criminal activity, including attempts to break into the websites of foreign governments. Hammond says Monsegur had supplied him with lists of foreign countries vulnerable to attack, including Brazil, Iran, and Turkey. Hammond went so far as to suggest that the FBI had been using him to launch cyber attacks around the world, with Monsegur acting as the coordinator. And it sounds like we might have lost the guys again. Emmanuel, are you there? It seems like this newfangled thing is... Even we didn't press any buttons, just to be clear. It's not the fault on this end. You can't see, but I'm actually sitting on the room opposite the buttons, as far away as I can. I'm leaning forward to the mic. Oh, I think I hear them again. Hello? Hello. Are you there? I am indeed, and so are the rest of us, and so are our listeners. Can you hear me? Yes, I can hear you as well. Good. How was the other dimension this time? It was pretty good, actually. It's better than sounding like you're coming from a phone overseas, I'll say that, but it's also, it's got its kinks. Well, that's what we do. We confront the kinks and do our best to work them out. Moving on to other stuff that's going on. We spoke a lot two weeks ago about the FCC situation and the net neutrality battle, in which things have not been going well. There's a website that our mysterious correspondent Joonce pointed us toward, called stoptheslowlane.com. What's on this site is not only a brief description of what's going on in the whole sphere of the FCC, but also a widget or GIFs or things of that sort that you can embed on your own website, which simulate a really slowly loading website as if it were put in the slow lane, which the death of net neutrality is very likely to introduce to the Internet. It only happens once for every visitor to your site. If you'd like to get hold of that widget, it's stoptheslowlane.com, which is a project of the organization Fight for the Future, which has also been doing other FCC-related protests and projects and things at fightforthefuture.org. I think it was since we last spoke that the FCC released its report. Yeah, it was the day after, I think. Which is a bit hard to parse and hard to know exactly what is in it. They are definitely, apparently, considering net neutrality, as those of us who care about the issue define it, but they don't appear to be favoring it. So I would highly encourage everyone not only to visit this website, but to go directly to the FCC and send them your comments. Some of the technical, legal mumbo-jumbo can be a bit overwhelming, but if the Internet providers are classed as what's known as a title-two common carrier, which is an utter nonsense phrase as far as I'm concerned, then they will be required to carry your bits the same that they carry Netflix's bits or Google's bits or anyone else's bits. I think that's a very important principle, so if you agree, then use that magical phrasing in your comments to the FCC. Indeed. On that note, I'm going to leave you two guys for a moment while I try and get a special guest of ours on the phone. So I will be quiet for a bit, so you guys, take it away. Can you still hear us? We can. Okay, well, we've had some interesting experiences technological-wise here in Europe while we've been traveling. This is the first time I've ever actually had a phone that has unlimited data, and that's been very interesting because I've been able to do things such as tethering through my phone while riding on a train with no other Internet access and being able to use a computer to connect online and check email and things like that. But there have been all kinds of issues as well, such as 4G here in Spain not actually connecting to any websites and variously disconnecting at certain points. It's great in certain ways, but it's also kind of inconvenient in others. Especially when you're using stuff that really heavily relies on data, like mapping and navigation stuff. Sometimes you would be in an area where perhaps they don't support the services that require those speeds, so you'd have your GSM go from a high-speed standard like 4G down to something like 2G, and it makes it really impossible to follow. And often what we found is it completely fails or it hangs, and you have to back out completely or maybe even restart your device, which makes it really inconvenient if you're maybe landing somewhere late night or trying to find someplace that you're completely unfamiliar with. You can really be stranded if you set yourself up to rely on these services. So we've really noticed that it's great to have global 4G services like that and all these fancy data things, but often when you get out into the world and want to use them, the places you're arriving in aren't quite ready. Maybe they've only got a couple of the newer antenna schemes and a lot of the legacy antennas still in use, and those ones that can support the services you're demanding in C2 are really not ready and saturated themselves with locals and people that are also using the high-speed services. So it's not exactly what you sign up for when you're buying it maybe from your local provider. Once you get out into the world, it can be underwhelming to say the least. Excellent. Now, Emmanuel, you had mentioned a couple of weeks ago about AVG quarantining all the things on your computer, and we have someone on the line now who is a bit knowledgeable about this sort of thing. Eric, are you there? Yeah, I'm here. Okay. Welcome, Eric, to the program. Eric is one of our speakers at our upcoming Hacker Conference, HopeX, which is at x.hope.net. And Eric, could you describe what your talk is about? Yeah. So I'm mostly talking about signature-based technology. So antivirus is one of those things. Forensic tools is another thing. Intrusion detection, which is my favorite, is another thing I'll be talking about. And it's mostly about pranking or trolling those tools itself based on their really dumb signatures. I would be talking about a different vendor for the AV side of it, but there are funny things you can do with the way that they quarantine. Being that it's an automatic process, there is something that I came up with that I call a tumor, but it's a way you can make not malware grow inside the quarantine folder. And it is vendor-specific, but it's something kind of funny. But in general, it's all about, I wouldn't call it attacks, but just kind of funny things you can do with security signature-based tools and a little bit more analog stuff as well. So I can go into more detail about specifics if you'd like. Do you have any questions? Yes, please. Okay. Well, I will. So metaphor kind of, and I think I mentioned this in the program guide, but it's one that was actually inspirational, and I heard even more than a decade ago on this very program. But it was talked, this was a little bit after the Patriot Act with the marked books and all that. So one idea is evasion. So don't go to the library and check out books that are marked as suspicious. And I don't think that's a good solution. That's kind of self-censorship. So one of the solutions that was discussed was to encourage everybody to check out these marked books because then you make their signature useless by saturating it. And I would argue that the signature itself is dumb. You're trying to track criminals by profiling them, and it's not really accurate. Now we've got a bunch of false positives we're introducing to this. The spirit of what I'm doing with all the technology tools, it's not actual attacks that I want to do. It's kind of an art. So you give the security system what it's looking for by the letter of the law, but without giving it what the system's owners intend to find, which is the spirit of the law. So it's false positives, which is why the talk itself is going to be called This is the X you're looking for. The tools looking for something, we provide it just that, but not an actual attack. So as far as AV goes, we feed it false positives or do the tumor thing. File carving forensic tools, we give it just the headers and footers, but not actual content, so then it builds up a hard drive. Intrusion detection systems, that's one thing I've been working on a lot, and there's a variety of ways you can give it a pile of needles in the needle stack. Also, Pirate Eye is one thing that I'll talk about briefly. And it was, again, inspired by this program listening to the whole Google Glass story a while back, maybe a few months ago. So that's another interesting thing I'll go into. And loosely related, I'll talk about grocery loyalty cards and how to mess up their data a little bit, something I've done before. Oh, yeah, that sounds awesome. Yeah, it is awesome. But, yeah, and just to kind of wrap up with my specifics, on the other hand, with the watchers, right, so we often hear from people saying that they don't care that they're being watched, they have nothing to hide. And I usually like to respond or follow up with, okay, let me follow you into the shower or the toilet or your bedroom when you're doing other stuff, you know. So I don't think that's a good point. So, again, instead of the whole evasion side of it, we know they're watching. It feels like we kind of are losing that battle. I still fight for privacy and advocate taking measures for it, but it feels like we're up against a black box. And even if legislatively we feel that we have privacy and there's transparency, I still feel like there's a black box and we don't know for sure. So this talk isn't really about privacy. It's about knowing that they're watching, just assuming they're watching, and just making it annoying to the watchers. So, you know, clog the tubes with Goatsee or make a very large needle stack and saturate them or twist the signatures around on them like the tumor concept. And one last thing for the talk, there will be some handouts, or not really prizes, but things I want to give away. So there will be physical objects I'll be handing out. There's going to be proof of concepts and everything like that too. Code I'll be releasing. And that's kind of the gist of it. Well, Eric, let me ask you something. Have you talked at HOPE conferences before? Yeah, so two years ago I gave the explosive steganography talk. Yes, indeed. That's right. Yeah, I know you guys mentioned that one on the program a few times. It's kind of shocking me. It's kind of cool. But that was a very exciting talk. I really like the way that that talk went. Can you talk a little bit about what that was about? Yeah, so there's even some overlap. I talked about some of the AV stuff, some forensic stuff, but in a completely different angle. It was about hiding information in halos, I guess you could call it, that people wouldn't normally want to touch and with encryption as well. So AV was a big part of it. But it was just like malware false positives, which I'm going to kind of go in a different direction with this talk. Forensic tools, it was a hard drive exploder. If you used like Scalpel or Foremost on a hard drive, it would fill up like with a 2 megabyte payload, it would fill up the hard drive by hundreds of terabytes. And one thing I'm not going into would be archive bombs, which I kind of made my own wheel for that. But, again, it's something that people wouldn't normally want to touch, but there's also a secret message in there. So to call it steganography was kind of not a very accurate title, but I really wouldn't know what to call something like that. But it's not actually a bomb, just for any listeners who might be confused. Right, I had actually mentioned that right at the beginning of the talk, and I was talking to some other people around the area before I went up there to talk about it. I was like, yeah, I'm doing explosive steganography. And people were like, oh, explosive, you probably don't want to talk about that. You could get arrested. I'm like, no, no, no, wait, wait, this is software. This is kind of funny. I seem to remember, though, that when you said it wasn't a bomb, the audience still stayed where they were and were interested in what you were talking about. There was no mass exodus of hopeful blowers up of things. Have you run into any trouble, I guess, as a result of this resource? You keep setting off the criminal detection systems. Do they think you're a criminal, or you don't know? Well, so that's the beauty. Like I said, it's in part setting these things off. So, okay, an intrusion detection system, it's supposed to detect intrusions. I'm not really intruding. I'm just matching the signatures. So, I mean, I'm sure that you can make some kind of argument of how it could possibly be illegal, but I don't really know of why it would be at this point, at least. Antivirus, I mean, false positives. It's not actual malware, right? The forensic tool thing, that could be maybe worse. I think, I mean, I didn't really go into the detail of how I go about that, but you could imagine certain ways you can try to overload that algorithm a little bit. But that, I also, the only way that that could possibly, I don't know, I think annoying the FBI, that's probably a bad idea, but I don't think you're even doing anything necessarily illegal with that either. If any of that makes any sense. I don't know that that would stop them, but could you maybe explain what an intrusion detection system is? Some of our audience might not be familiar. I would compare it to antivirus, but for a network, not a hard drive. So, you're looking for certain kind of patterns in the network traffic as opposed to patterns or behaviors on an actual computer or host. So, it's something that network operators would use? Yeah. Very interesting. Well, I think we're going to move on to some more stories. There's a lot going on. But, Eric, thank you very much for joining us. Thanks for having me. And your talk will be at HopeX. What's the title? This is the X you're looking for. Excellent. And how can people find more information on your talk? Do you have a website? I have xlogix at Twitter. xlogix at Twitter. Okay. Thank you very much for joining us, Eric. Thanks for having me. And I will see you at the conference. I will see you, too. And let me just point out, this is one of about 100 talks that we'll be having at HopeX taking place July 18th through 20th at the Hotel Pennsylvania here in New York City. Yes, indeed. Will all of them have X in the title or just this one? If they don't, maybe we should insert Xs where we can. Let's see if we can get away with that. But, yeah, we had a great response to our call for talks. We've since, I believe, closed that. Though, if at this late hour you've just now come up with something that's really tremendously cool and that you think we should take a look at, I believe you can still send it in to us, speakers at hope.net. Let me just say, Rob, with every passing day, it has to be all the more awesome for us to actually consider it this far past the deadline. So if you have an idea, it's got to be really good at this point. But there's still all kinds of stuff. If you want to be a vendor at Hope, get in touch with vendors at hope.net. If you want to volunteer at Hope, volunteer at hope.net, I believe, is the address. And all sorts of stuff going on. And, of course, all the information for that is at x.hope.net. Moving on to some other stuff that's been going on. We've been told about something that's happening tonight on television. What's that? It's like a computer, except there are less buttons to push, and it's less fun. But tonight, NBC Nightly News, which is apparently still a thing, is going to broadcast an exclusive interview with Edward Snowden himself. Nightly News anchor Brian Williams will be talking to Snowden on the interview broadcast tonight at 10 p.m. Eastern. Check your local times for whenever it's going on by you in other time zones. It will possibly be available on the internet on NBC Nightly News' own site as well. Interesting stuff. Is it NBC Nightly News if it's on at 10 p.m.? One would think. One would think. Well, it's NBC Nightly News, but it's on at 10 p.m., according to what I have here. Wow. According to my sources, which I am holding in my hand. So I thought this had already been released because we've seen excerpts from it already. They've shown bits of it, but they haven't shown the whole thing, I believe, is what's going on. So they're going to show the whole thing, and that's going to happen tonight. A lot of stuff going on around him. There are other ways Snowden is in the news. A story from Reuters said that Snowden has said he would have much to tell the Germans about what's going on in their country. Former U.S. intelligence contractor Edward Snowden told a German magazine that he has new information to share with a German parliamentary inquiry investigating U.S. surveillance, and that he believes all Germans' rights were violated. German lawmakers on a committee investigating the spying decided earlier this month that they wanted to question Snowden, and they didn't agree on whether he should be invited to testify in person or remotely. Snowden, of course, is in Russia, and it does not look likely that he will leave there. And it sounds like you guys were lost for a second, but now you're found again already. Just for a second. We're back. Welcome back. Welcome back. So this is an interesting story, the German situation. There are clearly some members of the German parliament who want very much to bring Edward Snowden to Germany and offer him asylum there, but it seems that the leading political party, the Angela Merkel's party, is not so interested. So there's a lot of negotiations going on, but unfortunately it doesn't look like Snowden will be receiving asylum in Germany, at least in the immediate future. Yeah, the argument brought up by the opposition was that Snowden can only express himself freely if he is in Germany. Snowden's German lawyer, not surprisingly, has ruled this out, saying it could jeopardize his stay in Russia, or indeed in the free world, I think. Yeah, so we'll definitely be keeping an eye on that. Other stuff going on. Got some listener emails that are pretty interesting. Matthew writes in, Greetings, gentlemen. Last night's show was presented well in Emanuel's physical absence from the studio. Thank you very much. I was particularly interested in the contact info provided by your guest, but failed to get a correct URL. Kindly let me know what URL she sought to direct listeners to. Matthew, the guest we had on the last time, of course, was Sandra from the Open Internet Tools Project. She gave out the website Open Internet Tools Project, which is openitp.org. That's openitp for openinternettoolsproject.org. Also, Techno Activism Third Mondays. That's T-A numeral three and the letter M dot net. That's for a monthly series of events happening all over the place. There might be one by you. Of course, the, let's see. Here we go. We actually got some feedback. This is a bit fun. We got some feedback on Twitter on our show two weeks ago from Edwin, who writes, which is who we are on Twitter. I don't know. Do we have that technology? It might involve soldering some more stuff to this board, and I think Reggie would get mad at me. What if you just press all the buttons? None of those buttons can make Bernie S sound bad? I don't know. I think we'll have to depend on Bernie himself for that. But, yeah, no. This ComReq system, I think, has been a resounding success. You sound good today. Bernie sounded good two weeks ago. Who might sound good in the future? We don't know. Well, he doesn't sound very good today, does he? No, he has messaged me to inform me that he is occupied and not available this evening, but for a very good cause. A very good cause. I'm curious, is the microphone quality good? You're not picking up any interference or anything? We're picking up a little bit of, I think, room tone from where you are, but it's not unpleasant. We can hear everything. Okay, good, yeah. So be careful. We are a little bit cramped, but yeah, yeah, yeah. We hear you when you're sleeping. We know when you're awake. We control the horizontal. I think they're both awake. I mean, and have been the entire time that we've been on the ComReqs. Or do you have some other system for knowing who's awake and asleep? Not yet. Not that I'm willing to tell you guys about, though don't rule anything out knowing me. Morgan writes to us, I'm listening to KFJC this morning, the usual 9 a.m. show of TV and movie themes, soundtracks, and various audio goodies, when I heard a Conelrad 640-1240 civil defense spot, which reminded me of you guys. Of course, those were the emergency broadcast things we were talking about a couple of years ago. A couple of weeks ago. Time is an illusion. We often talk about emergency broadcast systems, but this one was just a couple of weeks ago. Yes, but it's from a great many years ago. As it turns out, Morgan writes, you can find a bunch of Conelrad stuff on the YouTubes. Like this one for Conelrad 640-1240 emergency broadcast system. He sends us the link to a video, which is entitled Conelrad, which is spelled C-O-N-E-L-R-A-D, civil defense TV spot, which is very interesting. There are a host of other videos. It's on the YouTube username Conelrad6401240. Now, Conelrad, there was a pair of frequencies involved with that, and I can't remember what they were. I don't think there's any way to find out. I don't know. I can't depend on such information dropping into my lap from parts unknown. Oh, wait, there it is. Okay, yes, it was 640 and 1240. You mean like the YouTube name you just read? Just like the YouTube. There might be something there. There might be some connection. This is very, very strange. One more listener email, then I want to try and get our next guest on the line. John writes in, what do you guys think of VPNs? Have you ever used them? I've been using iPredator.se, and I've also used MulVAD.net. They don't log either. They're pretty cheap, and the speeds are great too. I download a lot of torrents and share them, including your show. Thank you very much for that. Are there any other good VPNs that you know of that don't log? Thanks. Of course, the big problem with answering this question is how do we know who does and doesn't log? Anyone can say they don't log and yet still log, which has happened in the past and will probably happen again in the future. Do you guys want to explain for a bit what VPNs are about? Will I get our next guest on the line? VPN is a technology that encrypts your data traffic and sends it to some other computer somewhere, and that computer is then responsible for sending it onto the regular internet. It is hard for the people you're communicating with to know where you are. There are other uses for VPNs, which people use them to connect to their company's network when they're outside the company, but I think we're talking about the sort of public kind here. You were saying, Kyle? Just to elaborate a little bit, it's a port among the many ports in TCP, IP protocol, and it allows you to virtually present yourself on a network as though you are local. It'll simulate LAN speeds given your bandwidth, but it'll simulate as though you are on a switch locally, but it does it in an encrypted fashion and over long distances. It's not quite like other technologies that are a bit slower like the older FTP and secure FTP and things like that. It actually acts as though it is connected directly, but it's over a long distance and creates a session that is encrypted, and it does it over a specific port, and it has some attributes that are similar to proxying and some features that are similar as well. As far as the privacy implications of this software, it's okay. It can make it a little bit harder to find out who you are, but even if the provider is telling the truth and not generally keeping logs, they can be required by law to keep logs in certain circumstances, or it can be possible for a third party to sort of correlate what you're doing with what they're seeing. So for a sort of strong anonymity where you really don't want anyone to find out what's going on, I would recommend you use the software called Tor, T-O-R, that we've mentioned on this program before. They do a lot more tricks, but it does make the connection slower, and so maybe it's not as good for downloading torrents. For off-the-hook torrents, of course, there's no need for privacy at all because it's completely legal, and so you can just download that. That's fine. Yes, you have our permission. Okay, moving on, I would like to introduce our next special guest. It's another Hope speaker, Sandy Clark, also known as Mouse, and she is a veteran of hacker conferences. I think she might have been at every single one I've ever been to, no matter where. And Sandy's got some interesting stuff to talk about. Sandy, are you with us? I am. Excellent, excellent. Would you like to start off, please, by just explaining what your talk at HopeX is going to be about? I'd love to. Josh Marpett and I are going to be speaking on the CSI effect and the damage that it does to hackers. Lately, we've been collecting a lot of information, several months worth of policy and law and forensics and investigations and things that are going on, and they all have to do with hackers in some way or another. They all involve some form of legal or illegal uses of computers or networks. And the people who are ultimately responsible for making the judgment and the decisions and for putting new laws into place do not understand how these things work and either the pros or the cons of the technology. And so Josh and I are going to talk both about the courtroom and forensics and things you need to be aware of and what you need to be able to explain, but also the policy ramifications of this, since the laws are going to be made by people who don't even use email. Right. Now, you call this the CSI effect. Now, CSI is, as our listeners may know, a popular television show, which is known among people in sort of the security industries and investigative industries and things for being really, really funny for certain reasons. Could you tell us a bit about why you call this the CSI effect? For two reasons. First, since about 2009, lawyers, law enforcement officers, and people involved on juries and in courts have noticed that CSI is having an effect based on the ways that people who are sitting on juries respond. And they might understand that something needs DNA, but they might not understand how the DNA test actually works. And it's changing the way that lawyers are having to present cases. It's changing the way that criminal investigators are having to collect data because certain forms have noticed that things like no one licks their envelope shut anymore. They tape them. Gloves are being used more frequently. Bleach is being used more frequently. So definitely this TV show has had an effect on both criminals and juries. And we've noticed the same thing, but the funny aspects of CSI that you refer to, the classic one is when they thought that they were being hacked and two people start pounding on a keyboard at the same time. It seems like we have some telephones, maybe in Spain, that we're hearing here in New York. No, that's not us. I don't know where that's coming from. Oh, so we have random noises. That's always exciting. Random phone noises are okay. That's more exciting actually than just random background noise. So CSI and other pop culture phenomena have this habit of presenting very sort of Hollywood fictionalized versions of how things like investigative tools actually work. And it's magic and it's easy and it's fast. I just hacked the White House. So then when you have the result of people in real life thinking that's how things work, it can mess up the process of like juries or other sort of aspects of the justice system. Exactly. Or perhaps take away from some of the actual invasions of our privacy and surveillance that are going on that we've spoken to, like electronic stuff, the real stuff that's everyday and serious. It keeps people buying bleach maybe, but I could definitely see the implications. It sort of takes away from the stuff that they ought to be maybe concerned about as a society. Exactly. I've even come across this in my own work. Well, that's why the twofold aspect of this talk, because it's not just concerned with courtrooms and juries, but people who are making legal policy. And if they think that something works one way but it doesn't or they don't understand the collection of data and the fact that if it never goes away, this can result in retroactive criminalization, something that wasn't illegal when you did it, but they have the data and it becomes illegal 10 years later, and now they can go back and find out who did it. Right. And there's the classic example of like Ted Stevens, the late Alaskan senator, and his series of tubes metaphor when describing the Internet, which was kind of a great example of the people in charge of regulating something not knowing quite how it actually works in reality, which can be dangerous. It can be a very dangerous thing. And I think it also affects, well, privacy in particular, because things like the ubiquitous license plate collecting cameras that are all over the place now, but you and I or anyone can go out and buy a subscription to one of the license plate collecting data services or to any of the data services. Anyone can buy a fairly inexpensive subscription to this. And suddenly you have all the information you need to stalk somebody. Right. And, of course, we've spoken a little bit in the past about the dangers of private industry gaining more and more of the control over things like a license plate database or car sensors along the highway or things like that, because you can never be quite sure what's being done with the information, and the regulation isn't as strong. And think about it now with smart cars and self-driving cars and the ability to remotely shut down a car. Right. There was a big news story today and yesterday, I think, about Google working on its own car that drives itself, and they're testing that. It looks cute. It looks like a little square thing, but I don't think I want Google, knowing how their business model works, I don't think I want them in control of my vehicle. It has no steering wheel, and it has no user-accessible brakes. People are really bad at driving, though. I don't know if this computer is better than people or not, but it certainly seems feasible to me. It's intentionally designed to look cute, and it only has an emergency button. It has no actual controls. It's meant to be disarming. I was reading a bit about this, but you're absolutely right, Rob. It's crazy. Yeah, they don't even put a little robot guy in front to cheerfully tell you where you're going. It's a bit upsetting. I'm more worried about someone being able to shut it down. Yeah. Without my knowledge. Knowing how much the average person's desktop computer gets attacked and compromised and whatnot, do you want to open up that same vulnerability on everyone's car? Exactly. And does that cascade? It certainly could be a targeted attack, but what happens if we get vehicle to vehicle and vehicle to infrastructure? Then the whole thing cascades. So these things need to be thought out very carefully. This is the perfect talk for Hope, because Hope has a lot of people who are concerned with getting active and getting involved. What we need are more people to go down and brief the congressional staffers, more people to spend time talking to people who make policy and explaining this sort of thing. Also, it has always been a goal at Hope to spread the knowledge of how things work to those interested. That's what we try to do with all our talks. Now, you've spoken at Hope before, haven't you? I have, many times. I gave a talk on breaking law enforcement wiretapping hardware, and I've talked about e-voting systems. Let's see. Recently, I think the most recent talk I gave was on lessons learned from history. Your talks never fail to be interesting and fascinating, and you can certainly pack a room. You're kind. I learn a lot more from speaking. You can catch Sandy's talk if you come to HopeX, x.hope.net. Sandy, do you have a web link or similar to give out to people who would like more information on what you're doing? Seclab.upenn.edu. Hold on. Let me make sure I've actually got this right. Maybe if you just Google mouse, you'll come right up. Try this one. Seclab.cis.upenn.edu. Seclab.cis.upenn, and that would be with two Ns, .edu, correct? Correct. And I assume Seclab is S-E-C-L-A-B. It is. All right, excellent. Well, Sandy, thank you very much for joining us. Thank you for asking me. Excellent, and we will see you at the conference. Yep. It's always tragic organizing these things. There's no way to see all these talks in one visit to a conference. Yeah, thankfully. Absolutely. We do get recordings of everything, and we release those later on. But, yeah, one of the saddest things about even going to the conference is that you can't see all the things at once. Even as an attendee, you have to pick which ones you're going to go see. But, you know, that's part of the fun of it, and it's part of the experience. And if you miss anything you want to see, you'll be able to get hold of it afterward. Thank you a lot, Sandy, for joining us. And I remember vividly her talk on wiretapping. It's fascinating. And all of those can be found at Channel 2600, the YouTube site. We've got all of the recordings, and we look forward to seeing people at HOPEx. Yes, indeed, and that's youtube.com slash channel 2600, 2-6-0-0. Support off the hook. Give the numeral to WBAI.org or call 212-209-2950. This show is the only premium we can offer you. WBAI has some other premiums. But we cannot do this without your support, whether you're listening live, whether you're listening afterward, whether you're listening in the past. Somehow support us. Keep us alive. Keep us on the air. Keep the station going. Particularly if you've invented a time machine, there must be some way to leverage that for profit. Share some with us. If you've invented a time machine, you can go back in time, submit a talk to HOPEx about it, and get in ahead of everyone else. That's smart. This is a good plan. Now that we've thoroughly confused the audience. And I think I've confused myself as well. But, yeah, we will always enjoy your emails. Send us your emails. OTH at 2600.com. Hey, can I just step in for a sec? I've been on the other side of the room working on actual speaker submissions over the past hour or so, because I've been doing that for the last few weeks. And, boy, we have a lot of really, really good talks. Sandy's is just one of them. But I just want to remind people that hopex.net, or x.hope.net, I'm sorry, is the web address to check for all kinds of updates on the upcoming HOPE Conference. And, please, spread the word. We have amazing things coming up. There will be updates coming over the next few weeks. And we'll, of course, be back next week at this time with more fun stuff on Off The Hook. Indeed we will. Thank you for listening. Thank you for your emails. And I'd like to thank our guests, Sandy and Eric, our HOPEx speakers. For Off The Hook, this is Rob T. Firefly. Have a very good night. Stay tuned for the next show. Good night. Bye. I'm lost in a mountain dream La-da-da-da-da-da-da-da-da-da-da- We soldiered on, we ate it all Toothpaste and soap, deceit and balls But times were tough and big that day Looked more attractive every day I swear to God I didn't know what made the suit They said it was a mountain ghost Lost and confused, I sensed more of a poultry flavor as I ate But didn't think much of it until a toenail caught in my throat Da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da I swear to God, I swear to God Da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da-da Fatty, you'll be no great loss to science for the secret service Fatty, you tasted great Although I cry myself to sleep every night I think of you I also start to salivate I swear to God I just didn't realize It seemed more grisly somehow when he was alive I swear to God I never thought he'd taste so fine I have a second but the rescue plays the part La-la-la-la-la-la-la-la