and themselves despite the deep-seated societal hostility to blackness grounded in 400 years of white supremacy. This event will happen on Thursday March 17 at 7 p.m. at the Commons Cafe 388 Atlantic Avenue between Hoyt and Bond Streets in the Borum Hill section of Brooklyn. For more information go to independentwithay.org. That's independent.org. And you're listening to radio station WBAI New York. The time is just about 7 o'clock. It's time once again for a special expanded edition of Off the Hook. I cut the wall. I cut myself while shaving. Now I can't make a cough. We couldn't get much worse. But if they could, they would. Bum-diddly-bum for the best, expect the worst. I hope that's understood. Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! Bum-diddly-bum! And a very good evening to everybody. The program is Off the Hook. Manuel Goldstein here with you on this Tuesday, or I'm sorry, Wednesday evening joined tonight by Mike. Hi there. Rob T. Firefly. Good evening. And Kyle. Hello. Bernie S. Do we have Bernie S.? No? Wait, hold on. Hold on. We have to bring him up. Okay. Do we have Bernie S. now? Greetings from Philadelphia. There he is. Okay. Sorry. We had the wrong channel. Okay. Can you hear me from Philadelphia? Well, we can hear you over the phone. I don't know where you are. But yeah, Philadelphia sounds good. Okay. Good. We're here for about two hours tonight. Wow. Doing a special expanded edition. Guess what? The fundraiser is still going on. Yes, we still have one more week, I believe. I mean, it's good because we get to talk to people that we don't always talk to. More on that in a bit. Yes, yes. We do get to talk to, we have a special guest who's going to be joining us in just about a minute, I guess. But first, any updates from people? We haven't been on in two weeks, I believe. There's a lot going on, but let's get to our guest, maybe. Okay. Let's get to our guest. Well, our guest has to do with the actual fundraiser because it's part of something that we're offering tonight. But yeah, there's a cocktail party outside, too. So if we could just maybe close the door, that'd be nice. We have, as we said, another two-hour fundraising edition of the program as part of the winter fundraiser. And we'd like to offer things to our listeners that are of interest to the hacker community, to people interested in technology. And tonight we stumbled into something that I think is going to be truly amazing and interesting. There's this new book, it's not yet out, it's about to come out, called The Car Hacker's Handbook. It's a guide for the penetration hacker or penetration tester, I guess, and all about cars. We've talked about this many, many times. We've talked about how cars are basically computers these days and privy to all sorts of security issues and technological wizardry as well. But all kinds of risks, all kinds of things that we haven't really thought through. And hacking cars has become something of an interesting topic. I know, Kyle, you've been involved in things like this for years, and just basically the right of access to car technology. Something that any kind of technology, the powers that be, try to control it and keep hackers like us from actually accessing the hardware and the software. And cars are turning into that, where you can't just take your car to a mechanic anymore. You have to take it to somebody who's licensed to look at it and to read the software and do all sorts of other things. And it's increasingly software as well. It's increasingly a code that is a problem, not just mechanics. Yeah, and those dealerships or manufacturers limit the access to the tools which can interface with the computer systems. And that in and of itself makes it pretty difficult for the average mechanic, who themselves would be setting up to do all kinds of different repairs, preparing what kinds of tools they're going to use and how they're going to maybe repair or operate on a specific system on a vehicle. When they don't have access to the software, they can't really prepare themselves to work on the vehicle. And with a book like this, you get sort of, I think, a sense of how to set up your work to get around some of that stuff, because we don't have access to the right kinds of tools. So this is becoming something that's important. And in fact, we reported on some changes in the interpretation of the DMCA rule about working on vehicles and also agricultural equipment. But the computer systems that run these things have, as you said, been off limits and very difficult from a legal standpoint. And this interpretation is allowing a year for manufacturers and dealers and so on to prepare for this. But after a year, the interpretation of the DMCA will allow for a lot more tinkering and building onto these platforms. So hopefully it's going to be this is sort of just the emergence of it. And this book is not out yet. It's really kind of an emerging and exciting field. Well, let's bring out our guest. The Car Hackers Handbook was written by Craig Smith. Craig Smith is on an airplane right now. Hopefully he's not trying to hack that. But we have the, I guess, chief guy behind No Storage Press, which publishes this book and has been on our radio program before. Bill Pollack, welcome to Off the Hook. Thanks. I'm wondering why Craig isn't in a car. Yeah, you know, you'd think. Maybe he knows too much about cars. Planes are safer. Tell me, what drew you to this subject matter? So first, I should say, Craig's the expert here, but I was his editor on it. And that means in No Storage Press, I worked through every single line of the book. And as Craig can tell you, he probably wanted to, hopefully not, but may have wanted to strangle me at one point or two. Any good editor gets that. Yes, I know. Yeah, it's happened many times. I haven't been strangled yet, but I've heard that on multiple titles. I have the scars. You probably understand. But anyway, the result is excellent. So I actually was at, I don't know, some car. I can't remember. It was probably 2 o'clock in the morning. I was talking to a friend of mine saying I really wanted to do a book about car hacking because I like, there are, Kyle was talking about like, I guess, OBD-II stuff. So first off, you can get pretty cheap OBD-II readers. And the Android market or Google Play has, I think it's called Torque Pro. I was just looking at it while you were talking. You can actually use that to connect with your OBD-II reader and get a bunch of data and actually look at torque curves and stuff. Yeah, Bill, OBD-II, what is that? Oh, it's the, I don't remember what it stands for, but basically it's like OBD-I, I guess, came first. And it's basically the connector, like in my Acura, mine's a 99 Acura. So anyway, it's like in the back of the ashtray. There are these connectors that I think are usually internal to the car. You plug in there and you can read the codes from the engine control unit and other computer systems in the car. There might be a dozen systems in the car. So that's what the mechanics are reading. And it used to be like you'd buy an OBD-II scanner. You'll get the codes, and then you have to basically interpret the codes using a book or something like that. But now, I mean, like some manual, right, or just go online and find the codes and then try to zero in on what systems have issues. But now with like Torque Pro, if you just look in the Google Play market for OBD-II or just OBD, you'll pull up different tools that will connect to these cheap scanners. They're like maybe $20. Wow. And then you can actually – sorry. Bill, I'm sorry to interrupt. This is Bernie. No, go ahead. OBD-II stands for Onboard Diagnostics. Thank you. That's right, yes. And it's been around – my old Volvo had OBD-I, and my newer Volvo has OBD-II. For like $20, you can actually see the data stream. Not just the data stream, but you can see all the codes that your car is reporting live. Yeah, you can actually pull it live. I don't remember exactly what I paid. But if you look around, I bought this thing. I gave it to a friend of mine because I'm not going to – I'm just not going to use it. And by the way, my 66 Volvo does not have OBD-anything. That's probably the safest vehicle. It doesn't have anything. And it also doesn't have doors that lock, which is another separate issue. Well, can I just read the first paragraph of the description of the Car Hacker's Handbook? Because I think this is what will make it interesting to most of the people listening now. Modern cars are more computerized than ever. Infotainment and navigation systems, Wi-Fi, automatic software updates, other innovations aim to make driving more convenient. But vehicle technologies haven't kept pace with today's more hostile security environment, leaving millions vulnerable to attack. Now, Bill, is that just fear-mongering here or what are we talking about? Yeah, so you asked me a question which I didn't respond to like a good politician. So basically the thing that was the most eye-opening thing to me, this is kind of like editing the – we did this book on VoIP hacking, and it's basically like the fundamental problem with VoIP is everything is sent in the clear. So every attack is kind of the same, and it hasn't really changed. Vehicles, my assessment of vehicles, having gone through every line of this book, basically cars are like networks from the 1990s on four wheels that weigh 5,000 pounds and travel 80 miles an hour. These networks are completely exposed. There's a section in here, for example, which talks about – and this is just a piece of it, right? It's like cryptographic algorithms that are broken that are sold by automotive manufacturers because basically you've got a bunch of engineers and someone designed it into some chip, and they've got all the data, and they just keep making this thing, and they're known to be broken. But that's just one piece of it. So now we've got, for example, vehicles where you've got tire pressure sensor monitors that connect wirelessly with the engine control unit, and that's the way into a car. We were developing – and this is not like – this isn't like theory. This is all real. It's like attacking any kind of wireless network. Vehicle-to-vehicle communication systems are being developed. So basically the idea is – it's pretty interesting. It's also kind of terrifying that cars are sending out – they're capturing beacons from roadside obstacles or whatever, and they're communicating with that, which is sending information to the driver. But anything that's going into the car is a way in. This is like one of the things with Bluetooth. Bluetooth didn't go right into the heart of the CPU. It doesn't have – unless you turn on protection. I don't know enough about Bluetooth security. But basically, like, if you don't lock the door or build blocks there, it just goes right through. And cars are old engineering. So Bernie's Volvo, like, they were not – engineers were not thinking about this stuff as far as what I gather. It just was not a consideration. And you can see it in the way engineers think. There was a great talk at this past Chaos Communication Congress called Dieselgate, where they talk about the whole VW thing and, you know, how VW basically beat the mission controls. This is the way that automotive engineers think. They're not tasked with securing a system. They're tasked with, like, you must achieve this thing. We want, you know, remote door locks. We want remote engine start. No one's talking to them. And I've heard this from people who work for some high-profile car manufacturers. They don't want to put the money amongst them at the security. They don't want to hear it. It doesn't fit into the equation. So what you get are these kinds of systems that are built one on top of another, often proprietary systems, but you can find white papers about them. You can also find tools online. I'll have to find the name of the tool. There's one suite of tools that Craig talks about, which is, like, a free set of tools. I think it may be through Open Garages, which is basically the group to do car hacking. And it's pretty amazing. So basically you can set up, like, an ECU test bench. You pull an engine control unit out of a junkyard. Let's say you wanted to figure out how to attack Bernie's car. So you go and find the same Volvo model. Volvo is very good about making the same model over and over for years. And you go and find an ECU unit, and you set it up in a test bench. And then you connect up to it, and you can read things like RPM, and then you can figure out what's controlling the RPM sensor. So if that RPM sensor is controlled by some particular packet, like some packet going through the network, you can then work with that packet. I'm no expert on this topic. But basically, like, if you can figure out what's controlling it, you can control that packet to get, say, for example, open the doors. And you can replay packets. So the classic replay attack is you capture the things. And this is like cracking software, right? Like people, early people cracking software, they weren't necessarily reverse engineering things. They would just cut out the piece of code generation and then push it out there. Here's my key gem. And basically it's the code. I don't know how it works. Just run this thing. It'll make codes for you. So a replay attack is like, I'm not going to make the thing. I'm just going to capture the signal and send it back. So if it's a wireless attack, it's a replay attack. You capture the signal. You send it back, which is why – and there are some expensive tools to do this, and there are some cheap ones. But you can capture signals. You can target things to make the doors open or start the engine. And it's like – and it's not – this isn't like, yeah, sure, it can't happen. We know these are high-profile attacks that have happened, like Charlie Miller and, I guess, Chris Valsack's attacks, among others. And the thing is that when these attacks happen, they can take down hundreds of thousands of vehicles around the world. At the same time? It depends on what the attack is. If it's something – let's say, for example, you've got a vehicle that connects to OnStar. And let's say that OnStar is communicating with that whole suite of vehicles. Or let's say it's Ford. I mean, this is just me talking, right? But let's say you've got Ford Sync. And now the next wave is, you know, Tesla is going to start this. Of course, you dial – the car connects to a central server, which updates your firmware. It connects with the car. Let's say you attack that server. Somehow you man-in-the-middle it. And then you're sending – you understand how that server works. I think Tesla actually has got very, very strong security built in. They also have an amazing CSO and some great people on the team. So I think they're very, very impressive. But for some of the more traditional car manufacturers, they go out and they buy the system. They don't check the strength of the security system. But now this satellite is communicating with all the cars. So someone goes in and man-in-the-middles the satellite, right? I mean, anything is possible given enough money. And then whatever it is that man-in-the-middling it, as in, like, I am the satellite you want to talk to, not that satellite, then pushes a signal out to all those vehicles and shuts them down. And they're going 80 miles an hour and the engines turn off. Because they determine that, oh, in order to do this, this is the control code we need to send. So we craft this thing and we send it to all the vehicles that are connected to that satellite. And maybe it's not all around the world because the satellite is only in a certain position. But whatever is the range of the satellite, you can shut down the vehicle. I mean, it's totally practical. So, Bill, this book sounds like it's great not only for people who have cars and want to know more about them and get into them, but also people like me who hate cars and want to destroy them. I like cars. I really like old cars. I also like new cars. I like all kinds of cars. But this is not a book. There's a section on performance tuning. So the first people wonder, like, oh, I can get more power out of my car. I say to those people, go to someone who does a chip monitor for $400, like I have a Volvo 850-96, and you can chip it for like $450. You'll take it from 200 horsepower to, I think, 275. Just do that because someone's already figured it out. That's actually one of the best deals around. The Turbo 850s are pretty amazing because they basically were underclocked, essentially, for American Roads. But what I think – I mean, it's really interesting. If you work on cars and you understand that there are computers there and you want to understand what's going on inside, it's really going to take you deep inside what's going on inside that automobile network. And the key thing, I would say – and again, I'm not Craig, but my read on it is the CAN bus, which I'm somewhat going to try to remember the – but anyway, it's the core network that runs in the car. And lots of things connect to the CAN bus. There's a lot of information traveling down some central path without security. And it's collected from different sources. So it might go to the infotainment unit, which is getting increasingly complex. It goes to the engine control unit, which is controlling throttle control or braking or sending information, processing stuff for the car. And those units have gotten much more complex. It's taking readings from the tire pressure monitoring sensor. It might – these cars have started to connect to the Internet. There's all this stuff coming in. It's like imagine that that's your house and you don't have a firewall. That's what I see in the vehicle. And everything is controlled. And you've got a house that's – everything is controlled wirelessly. Everything goes on. It's really striking, though. For those of us who have been paying attention to technology for the past couple of decades, we've seen so many things that were just appliances, simple appliances, become so much more complex. Our telephones are now computers. Our televisions are computers. Our refrigerators are computers. And our cars, which have long been this thing that just gas goes in one end, smoke comes out the other end, and it takes you places. It's basically a very complex computer itself. So this book sounds like a real eye-opener for not only people who are already technical experts and want to learn how to tweak things, but for people who really haven't thought much before about what goes on behind the scenes and under the hood when they turn the key and start it up. I guess we should mention how people can get this book. I know we haven't been doing that. It's The Car Hacker's Handbook, a guide for the penetration tester. Fascinating stuff. We can talk for hours about this, and we just might. You can call 212-209-2950. Is that still the number? Yeah, it's still the number. I haven't been here in a while. Okay, 212-209-2950, pledge of $55. We'll get you a copy of this book. We only have limited numbers. So if you're interested in this kind of thing, and I think you should be. I think what Bill is talking about is something that affects all of us. Even if you're not technically inclined, even if you're not a hacker, it's good to know what it is your car is capable of doing or what it is that your car is vulnerable to. You might not think about these things. You might not realize that, hey, somebody can change these settings, or I can change these settings, or the manufacturer is not telling me the truth, or this is what my vehicle is capable of. All of that and more is what you will learn. If you're somebody who does like to fiddle around with the hardware that you own, then this book will really be invaluable in showing you some of the things that you can do. 212-209-2950 is the phone number. Yeah, this is definitely a great way to catch up with the state of the art. Something Bill pointed out that is true is that you have these generations of vehicles slowly becoming a little bit more complex, having a bit more in the way of sensors and computers. What that is is tracking various parallels, a lot of what we've seen with other forms of technology where you've got more and more data accruing and that is being captured or recorded on up to some of these systems being connected wirelessly and so on as Bill was indicating. This will thrust you right into the driver's seat, so to speak, of the huge amount of information and, as he said, free tools and different techniques. I really want to go through and see this. I've only seen a review and a description and what Bill has said, but I would love to see this because I think it does a great job of organizing the different topics and will help you organize your work if you're pursuing some of these systems. Maybe you own a vehicle yourself and so on. This is a great way to get caught up on some of the latest and most interesting systems in most of, actually, the 256 million cars on the road today. That's a lot of cars, so spreading this information around. And it is indeed the latest. This book, if I'm not mistaken, comes out this month, actually, doesn't it? Well, I'm holding a copy in my hand. This is an early copy, but, yeah, the book business is like a giant freighter. Everything takes a long time to move, but yes, sort of. Well, it's worth the wait many times, and I think this is one of the examples of it. Tell us something about No Storage. You've been around for ages and publishing all kinds of interesting material. I have to retire, you're right. I probably should retire, but I probably will not until I die. So we've been around since 1994. One book that I think Bernie always has found intriguing is Hacking the Cable Modem, which is kind of like this is sort of like the next wave. Anyway, what I try to do is basically make books that make people smarter. So one story I like to tell is when I was at Hope probably in 2000, I remember, and we brought out Hacking the Art of Exploitation by John Erickson, and no one was buying our book because they were all buying books that would be like, go to this website and run this attack and whatever. And I stood there, and I was really annoyed because I have no filter, and I just basically said to people, like, if you want to learn something, read this. If not, go over there and buy that. I said that for a day. By the end of the conference, it was all sold out because basically people opened it up, they saw code, and they put it down. Because a lot of people in the hacking community aren't necessarily comfortable with code, and you don't have to be a programmer to do something useful with code, you just need to be able to read it and find patterns and stuff, which is what a lot of people do, especially a lot of reversers. So what I've tried to do over the years, especially in the hacking community, is not only build books. I like to think about hand-crafting them in many ways, like find books that are interesting, that make people smarter, that cover topics that some people won't touch, but that I think are important to cover, important to address. Because something like this, for example, when I was at Shmucon Hacker Conference in D.C., a guy came up to me who had a booth there, and he goes, I want to buy that book. It wasn't released. I said, well, it's not released. I said, well, I work with the White House, and there are 10,000 people in D.C. that need this right now because this is what everyone's talking about. And I sold them an early sample. I didn't give it to them. I should have probably sold it at the price of military hardware for $3,000. But I sold it for $20. But it's fine. It's fair. But anyway, I think one thing is this is a huge attack service, and for people who are looking to get into hacking and looking for opportunities, there's going to be a lot of interest in this topic because it's terrifying to many people. Because everyone goes out and buys these fancy cars where everything's plugged in. It's terrifying to governments. It's a really unprotected giant attack service, and it needs to be addressed. So this is the kind of thing that I think is the kind of thing that we need to do more of. There aren't that many opportunities to do this. And the other thing is that I won't bring out a book unless I think we can do something great, and I really think this is great. It's a wake-up call for many people throughout government. It's a wake-up call for the auto industry. One thing I've also seen is when we do something, it gets noticed and people can't do it. They have to pay attention. It's like it's suddenly very real. And we've got an awful lot of coverage in news media, and you can't just ignore it anymore. It's something real. And there's something about books coming from a publisher that just makes it like someone walks into an office. It's like, you know, we've been talking about this, and look at this. And imagine someone, like, thumps the book down to the table. It's like, pay attention. You can't ignore it anymore, and I think that's kind of the magic of books. We also not only publish in this area, we're doing a bunch of program books for kids, and I think we basically lead that whole market. And I think that's really important because you've got these kids who are 10 years old, and we publish, for example, Python for Kids. We did Learn to Program in Minecraft. We've got the best-selling books on Scratch by far. We're working with the MIT Lifelong Kindergarten to do the Scratch Junior book, which is like a program book for 5- to 8-year-olds. We're trying to do stuff like figure out how to do interesting math books for kids because I look at kids. I watched my son growing up, and I remember, like, he had friends when he was, like, 10 or 11, and they were kind of interested in science and math, but they just didn't really do anything with it, and they kind of fell off. He's continued on with, like, a tremendous interest in math and science, but I think for any kid that wants to do that, I want to be there to have resources for them because one thing I can't stand is, like, when I see a kid, they're, like, they're frustrated, or they... I mean, I certainly felt like this when I was younger. They can't get the kind of information that they want. Books don't speak to them. I want to make something for them because I understand that level of frustration. I've met several kids, like, 10-year-old kids who've learned Python from Python for Kids. It came up to me in a play. Many girls, actually, 10-, 11-, 12-year-old girls, who learned to code, and we didn't make the book for boys or girls. We just tried to make a clear book, for example, that would help people to understand basic programming. And with everything we do, we try to make it accessible so anyone should be able to pick this up and understand it as much as possible. You know, if they're not an electrical engineer, I can't make them into one. Well, I can, but not with this book. Well, I'm thinking of a scenario where a kid gets this book and starts hacking the family car. Is that something that... It's not, like, very unlikely. It's not... This is not... These are not simple attacks. Mm-hmm. It's not, like... And it's not a book that's full of attacks. That's the thing. It's, like, there's one thing in the book that basically... Basically, you can... You know, where cars have, like, push-button codes on them, there's a whole... Just a sequence of numbers that you can press in. Apparently, you press in the sequence of numbers, and within 20 minutes, you can open any car door. Wow. I've done that once. You did that? Okay, well, there you go. Yeah, but it was probably just default. You know, I was messing around. But, yeah, some cars have those keypads on the side. I know the smart car that we have from Canada, which, by the way, Bill, that's a real nightmare, trying to get that fixed without the right codes. But there was a special... A sequence of things you had to do with the key fob and buttons on the dashboard. And when you did it correctly, your running lights would turn off, and you could bypass that, since, in Canada, running lights were required. But there are all kinds of little hidden things like that in modern cars, which I think would be kind of cool. I don't know that this will reveal those. I mean, that's not really... This is very focused, I would say, on low-level stuff, understanding the system, but serious attacks. Those kind of Easter egg things. It's like your dishwasher has a problem. You wave the magic wand, and codes come up, and it's serviceable, and you push some button, and the thing's fixed. It's not that so much. It's more like, this is how the thing is built. This is how the communication... So this is great for people looking for network attacks, people looking for new exploits. There's a lot of people that are always looking for exploits. And my strong belief is that I want to teach people how systems work, because they can find new exploits, and they can make better systems. I don't want to give people collections of attacks. That just makes people more annoying. And people, you can get that on the Internet. But I want people to walk away, with all the books we publish, with a real understanding of the system. Because when you understand the system, you're ahead of everyone else. You're ahead of all the people that are waiting for something. It's like people who are waiting for Microsoft to hand them the answer to using some Microsoft tool, versus people who are building their own tools, or working with Linux, because I'm a Linux fan. I can actually do this stuff themselves, or in two minutes, solve their own problems. This is really about understanding this as a system. Just as you would understand TCPIP, and when you understand how networks work, you find attacks. And early attacks, like in the 90s, it was easy for people to find attacks, because nothing was protected. I mean, it was like the Internet was new, and it was like a candy store. Now things have gotten much more complicated. But vehicles, at least based on my read of vehicle infrastructure, hasn't changed. It's the same system. So, you know, Bernie's OBD-1, whatever. I mean, these all had computers, and they had no security. And they've been in vehicles for years. And now, by making things more accessible, you don't have to pop open the hood to get into the car. You can connect to the tire pressure monitoring system. And that's the thing, too, with a book like this, is it's not just about cracking open a book and finding some exploits so you can do some devilish things, but it's about cracking open the book and finding exploits and the ways they happen described to you to open your eyes to what can go on, what can happen, how to protect yourself against such things, or even just to realize that, yes, this sort of thing is going on behind the scenes of this popular device that everyone owns. Yeah, and let's not discount that. That's really important, the empowerment of understanding the system such that you can repair it. I don't want to lose that in the conversation at all because that's a really important thing. So many devices, consumer electronics, I mean, I'm sure all you guys would back me up, that they're much more disposable. There's not a lot of ability to physically repair things, especially when they're software or they're then sort of obscured or made hard to work with, either because you don't have the tools necessarily. But this is really critical stuff for people that maybe hobby with their car or just maybe have a problem or an annoyance, like the lights you were talking about, Emmanuel. It just gives them that much more of an edge, as Bill was saying, than your kind of average consumer who might end up waiting and waiting and waiting and waiting at the dealer to get in for an appointment and all of that sort of rigmarole and so on. I just want to add that. It's always, as I understand it, I'm not a car person myself, but I've known many car people and people who are heavily into car culture, and for decades you've always seen people in their garages always tweaking this and twisting that and trying to get some more out of this or at least fix something themselves. And that's something that you need to now know, things like you'll find in this book, because it involves computers, it involves electronics, it involves components like this. It's not all just pipes and wires anymore. 212-209-2950. Get your copy of The Car Hacker's Handbook for a pledge to WBAI of $55. You'll learn so much about what's going on in your automobile, in other people's automobiles, the potential. You'll probably come up with all kinds of ideas for things that you hadn't thought possible before. Bill, do you think this book and books like it will sort of serve as a wake-up call to the automotive industry to fix their stuff? Yes, I absolutely do. I mean, I still look at the guy's face for MITRE. It's like, you know, we need this. And I got the same thing at DEF CON, too. I mean, we had just early samples. Book publishing is not the same business as it was 20 years ago, but a book can still have significant impact because it makes things very real. And I think this is, it's not just like, oh, there's something published online. Lots of people in high positions in government are still very, books are very influential. People that, you know, people are still learning through textbooks. When you give someone a physical thing, it makes a difference. And if someone can walk in with this physical thing and say, hey, this is what we were afraid of, dunk, here's this thing, I think this will make an absolute, I think it makes a significant difference because it's very real. It's very, you know, you hand someone a printout for something online, it's not real to them. You hand them a magazine or you hand them a book and it's like, it's a real thing now. Yeah, I hear that. Believe me, websites can be taken down. Things that are online disappear. You know, try looking for something that, you know, was around even 10 years ago. It's really, really hard to find sometimes. Most times, I would say. A book like this, it's permanent. You know, somebody will find this in their garage 20 years from now and still be captivated by it. That's the nature of publishing, the good nature of publishing. There's a lot of crap out there too, absolutely, but I don't think the stuff that you put out qualifies in any sense as that. It's always been fascinating material and stuff that hackers really take an interest in. And I don't think this will be any exception. In fact, I think this is the first of many such books that will be coming out on this particular subject. I imagine you'll probably have a series of these things. Especially this year. Yeah. Yeah, I don't know. Well, only if Craig wants to write another one. But we will have to see. I mean, the thing for me is, like, I want the best people doing stuff so I can make it great. And the way we work with everything, so we have two levels of editorial. So we have about five editors who are essentially developmental editors, and I do that level work. So I'm probably working on 10 projects right now, and we read every line, like, in-house. It's not done overseas. We like people who actually know what they're talking about and work with the authors to craft that thing. Once that's done, it goes to copy it. So that first step is significant, because I don't know anything. We only publish 30 books a year, but we have a very high profile as a company because they're almost all successful. And the only way to do that is to actually work on them. You can't just throw them out there. I'm not in the business of content generation. Like, there are companies that are starting up now that are like, we make books based on data science. That just seems like an oxymoron to me. I make books that our readers want. I go to shows so I can understand what's important to people and try to mirror that in the kind of things that we produce. One thing that our readers want is relevant information. Don't fill with fluff. Find people who know what they're talking about. Make sure I can read it. So we do that. And that's why we're like, I mean, sure, maybe I could do 10 books, but I won't, unless I can find 10 amazing authors who are writing on something interesting. And we do know a bunch of some serious car hackers now. I would do other books on the topic, but I don't really know what I would do. I'm really happy with where this book ended up, and I don't actually know what I would do as an extension of this unless Craig wanted to do something. Craig's an amazing author. He's really phenomenal. Can you tell us a little bit about Craig? Like, what makes him the guy to write this book? He's an extremely well-respected trainer, like, really well-respected in the industry, extremely well-connected. He knows everyone, and there's, as you might imagine, some people fly under the radar in this community. His group, Open Garages, has been really central to disseminating information about car hacking and working on tools and stuff. He is, in my experience with him, which is mostly through email, I did see him yesterday, but he knows, like, everything about this, and it's actually really fascinating to watch the interplay between Craig and his technical reviewer, Eric, because Eric would be like, oh, there's this thing. Like, a lot of this is just simply not known, or someone picked this up from this auto manufacturer, and Craig would have been able to say, you know, you're right, it's that, but I was just over at this company talking to them about this thing, and, you know, this is actually the way it works, and here's this white paper. So they're digging through a lot of primary sources and trying to explain it. And some things, normally, we like everything explained in our books. Whenever there's a new term introduced, we like it to be explained. In some cases, we just don't know enough about the technology. Like, Craig knows it exists, but he's not necessarily sure, you know, where it came from or what it's going to turn into. It's maybe a proposed standard, and maybe it's been sitting on the books for years, but we're not sure where it's going to go. So that was a little bit frustrating to me, only because I couldn't answer all the questions. I couldn't find answers to all the questions that I had. But, I mean, I'm sure there are some other people out there who know as much as Craig does, but I can't imagine that there's more than a handful. Well, the thing is, Bill, you're going to hear from those people, and any questions that you have, any new technologies that are emerging, you're going to get follow-ups. You're going to get all kinds of other things. That's why I say I think this will be the first in the series. I think there are all kinds of people throughout the world that have something to contribute to this particular subject matter, and you guys will be at the forefront of all that. I'd absolutely do that. And the thing is that, you know, we'll always do it right. That's the way my business is built. If I don't like the way a book is progressing, I just pull it out of production. I spent last spring rewriting three books that I thought weren't ready, and my chief editor did the same. And we ended up with, we published Automate the Boy Stuff with Python, which is selling, like, it's selling better than any Python book that anyone has seen in years. It's an amazing book. We published Python Playground, which is, like, really interesting Python. I'm not a programmer, but I've edited many very successful programming titles, but I don't write any code because I have nothing I want to write. I like reading code. I think it's interesting. I like solving problems. So this is some very complex stuff with, like, you do a firework simulation, you create auto-stereograms, all done in Python. Really interesting, lots of math, and I'm not afraid of that. And I believe that within the hacking community, and hackers of all kinds, people like to think, and I want people to think, I don't want to publish boring stuff because I have to edit it. I don't do books on end-to-end. And this particular book, the Car Hackers Handbook, was something that, I mean, you're not an auto mechanic, I assume. I have tools. Uh-huh. Okay. All right. But this is something... I don't really know how to use them. It piqued your interest, though. I mean, I think you were the first guinea pig as far as when something like this is put forth. You found it interesting as somebody in the hacker community, and I think that means that a lot of other people will also find it interesting. Yeah, no, I like it. I mean, I've taken apart engines, like tops of engines and stuff. I like to get into cars, but my thing is always like, I know kind of what's going on in there, but I don't know enough. I know enough to be dangerous and wreck my vehicle. And one caveat about this is, you can totally destroy your engine with this book. Oh, really? Okay, well, that's handy. Tell us how that would go about. Well, I mean, if you do things wrong, I mean, that engine control unit is just a computer. So if you go and you push the RPM into some crazy zone, I mean, you could just like, you'll leave one section. It's pretty funny. It's like, make sure when you do this that the car is someplace where it can't move. It's on blocks. And I mean, these attacks can be dangerous to your vehicle and to your person, because if you like, let's say you do something. So part of vehicle attacks is based on using things like Wireshark. You capture packets from the network running on the vehicle, just like you would on any network. And then you see what the packets do. So once you identify those packets, you can do things with the packets. But once you figure out what's controlling the RPM, you can then control the RPM. But if you're sitting in a computer, you're kind of divorced from the thing, and then next thing you know, it's like, what does this button do? And you push this thing, and now whoop, you just blew the engine. I'm sure that's totally possible. I don't think it's not going to happen in five minutes, but that ECU has tremendous control over your vehicle. And you've also got what? Electric steering. Don't we have like electric braking now or something? I don't know. All this stuff is electric. So it's controlled by an ender control unit. So you can destroy the thing. So what you do is, I think if someone actually wanted to do this, I would go to the junkyard, get an ender control unit from the car that you want to work on, and you set up a test bench. And you plug into it, and you get different readings. And you'll see on the ECU, like you'll make the RPMs go crazy, for example. And the thing to realize is that if it's connected to your car, the RPMs will probably go crazy. But it's connected to your engine. I mean, because that's also got output. You've got input that's controlling that sensor, but it's got some kind of output. It's actually going to do things to your car. But it's not like, this is not a book that anyone's going to just pick up and, like, you know, that afternoon just be doing crazy things to their vehicle. When you say you can do things, you're talking about the person that actually has physical access to the car. I'm picturing all kinds of tabloid reporters listening to this program now, freaking out, thinking that anybody, you know, from Malaysia can access the internet and hack your car. It's not like that, is it? I don't know the answer to that, because I don't know. I mean, again, I think like you've heard, I would say based on what I'm reading and what my understanding is of what automotive manufacturers are doing, I would definitely be concerned about some of these things when these vehicles are connected to the internet. Because from what I understand from speaking with Craig and reading the book, there isn't any security in the vehicles. They weren't designed for security. They were designed to meet engineering tasks, just as like, you know, VW designed their vehicles to meet emission standards that were known. And then when you go outside those standards, no one paid attention to that. So I don't, I mean, they're selling hardware today with broken cryptographic algorithms that are used to, you know, start a, do a remote start or open doors. And the thing is that they're known to be broken and they still sell these by, I imagine the hundreds of thousands. They're still selling stuff. So yeah, I would, I mean, I'm not, I mean, I'll still drive home. Well, first of all, my accurate doesn't have an internet connectivity and the radio is just all mechanical. So I'm not, I'm not concerned, but I'm definitely concerned when I think about things like, you know, I mean all these manufacturers are putting like, well, you've got like what like Apple, whatever, like in these cars. I don't know. I don't have a car like that. I don't have any of that stuff in my car, but all these electronics that have internet connectivity would definitely make me concerned. Now, some of the more classic attacks would involve, for example, firmware updates. So when you do map uploads and stuff, you can use that as a route in to the ECU, but you have to have physical access to the car, but some people could get it. My bigger concern is when, when you've got tire pressure monitoring, it's TPMS system, tire pressure monitoring system on each tire, each one has a unique code and it's connecting wirelessly with the ECU. That concerns me because that, as far as I know, there's no security happening there. So there's some idea, I think there's a handshake, but I can't imagine it's very strong security. So that's one thing that's definitely concerning to people. Go ahead, Bernie. I'm sorry. I'm sorry, Bill. I didn't mean to interrupt you. No, this is fine. Bill, I want to thank you because not only did you donate a bunch of copies of this hot off the press book or will be hot off the press later this month book, and it's not a cheap book either. This is a fairly pricey book that I encourage people to go out and buy it, but I'm sure it's well worth it. It's a huge fat Bible of great information. It's going to be eyeopening to anybody that uses a car or even travels in one, but you donated a bunch of copies of this book to this radio station so that we could raise some money to keep this station on the air. And we've been seeing you with No Starch Press at hacker conferences going back for years, both here and outside the United States. And you're just a great part of the hacker community. And you and 2600 are probably some, I mean, there's some other hacker publishers out there, but I've heard a lot of good things about you. I've seen people crowded around your table at Hope. You really put out some great books, and it's obvious from what you're saying here on the show that you really care that this content that gets out there is important and useful to folks. And anybody who has a car or travels in a car, which is probably just about anybody, ought to really look into this. Because even if you're not going to hack the car, it's good to know what you're riding in, like what the vulnerabilities are. I'm sure there's some of this stuff in this book that I wouldn't understand right off the bat, but I get the gist of it. I learn stuff from reading stuff I don't understand, and then it starts to sink in. So I encourage all of our listeners who ride in cars or drive cars themselves to support this radio station by calling 212-209-2950. And for a pledge of only $55, you'll get a great book that's well worth that, and you'll be supporting this radio station at the same time. So please, give us a call, 212-209-2950. Support the kind of publishing that goes on from No Starts Press. Support a radio station, WBAI, which is, frankly, how many other radio stations have interviewed you about this topic, Bill? None. Exactly. So this is why listeners like this show, because we give time to people that have interesting things to say about stuff that's going on. You're not going to hear on other radio stations, and that's the beauty of this listener-supported station. So please try to support this station if you're listening now. You must like the show or you wouldn't be listening. 212-209-2950. Get a great book. Learn about the vulnerabilities of the car you're driving or riding in. Support this radio station and support No Starts Press. It's all good causes. Again, 212-209-2950 is our phone number. Pledge of $55 gets you a copy of the brand-new Car Hackers Handbook, which you'll learn a ton of material about automobiles, what they're capable of, what the security vulnerabilities are all about. And it's the first step into the future, because this kind of thing is going to be around for decades to come. Absolutely. You can call 212-209-2950 and pledge $55 for the Car Hackers Handbook. You can also go to our website, give2wbai.org, and pledge for it online. We do have a limited amount of these to give out, so get on that while you can. If you're listening to this in the mysterious future, we may have some left, we may not. So give it a try, 212-209-2950 or give2wbai.org. Bill, we're going to be moving on on the top of the hour. We're on for an extra hour tonight, and I think we'll be talking about the whole Apple controversy maybe after that, and maybe taking some listener phone calls. But I wanted to ask you, in the time we have left, if there is anything in this book or anything that you'd like to share about the future prospect of automated driverless cars. I don't know. I've actually been in the Google driverless car, which is actually really interesting because it's collecting – what's interesting is that you can watch all the sensors and how it's processing data as it's driving. I think the driverless car basically embodies a lot of really good defensive driving skills. But I figure, depending on who makes those cars, if it's coming from Google, Google's got an amazing security team, and I imagine that those are going to be pretty well locked down because that's coming from a much more modern team than, say, Ford engineers, which isn't to say that there aren't great engineers at Ford. My concern is with anything connected like your smart TVs, like Nest thermostats and stuff, once we start to add network connectivity to these things, we have potential vulnerabilities. And if we don't have a good system or we don't triage it, then we've got a tech service. So I'm concerned about anything like that, anything that's connected with a driverless car. I imagine they're going to have vehicle-to-vehicle communication. They're going to want to talk to each other. But if they can talk to other cars, they can also talk to potential attackers. So I think you just extend – like if you – again, this goes back to kind of learning and understanding the system, then you can extend it to different types of attack services. And, Bill, earlier you were so skeptical about the possibility for future books on this topic. I think you're almost starting to spec one out right now. Yeah, no, I mean I have to just have the right person to do it. Like I won't – I mean I won't – I've missed whole waves of book opportunity because I couldn't find the right person to write it. Well, Bill, let's assume the right person is listening right now. How would they contact you to write the next book? They can write to me, Bill, at NoStarch.com. I have only one email address, which is why I'm about six months behind. That's pretty awesome. Yeah, I mean I'll check. I mean I try to – I don't know, I give up. I just want to press delete all and make it all go away, but I can't. Well, it seems like, you know, we keep going through the same thing over the years where things are tied into the network and there's no security because no one thought that security would be needed. And here we're seeing yet another example of this. We've heard rumors about airplanes as well. Are we ever going to learn? I don't know. I mean I think we have to – I think we have to change what our priorities are or at least add this into a priority. But we're – so much stuff is done behind closed doors by people who have been doing it the same way for 30 years, and the world is a different place. And I know from friends who have worked at automotive manufacturers, even forward-looking ones, that security is not a top concern because it hasn't been a top concern among consumers. So if consumers aren't saying, what did you do to protect my car? The automotive engineer is like, I need to cut costs here. Do this. Buy this thing for this manufacturer. Stick this thing in here. I don't care if it works. That's what our customers want. Well, Bill, isn't it in large part a lot about licensing these days? They kind of bypass really heavy security and in fact just sort of block people legally. That was my understanding, especially our friend Tiffany Rad who's done a lot of work with the right to repair. And that whole sort of era of dealerships preventing people from accessing – I think you alluded to the OBD-II system, but I have no indication that CAN bus isn't working the same way as far as dealer access and control without this kind of information, without a book like this. So it's really, really important and excellent timing given all of these interesting things that are computer-related. It is absolutely the case in point with Volkswagen here. We've got emissions that are absolutely illegal and sort of insufferable, like really not good for you whether you're around these kinds of cars or you own one. And for years it has been that you cannot actually look at the computer and modify it and use the techniques listed in this book. But now, especially in light of this scandal, but since last fall the interpretation by the Library of Congress has changed. So this is really an incredible, fantastic book. I can't wait to see it. And I really appreciate you speaking with us and sharing so much about this really amazing topic. Yeah, I love it. It's like the most interesting book I've worked on in years. It's an absolutely fascinating book. I couldn't wait for the chapters to come in. First, I love cars, but I love this kind of stuff. And I think it's a very important book for the world. And I don't mean to, and it's not hyperbole. It's like these cars are all over the world and everyone's sticking computers in them. And I think it's important to all of us who are on the roads, driving a car, walking down the street, that auto manufacturers pay attention to this. And I hope that this will be an eye-opener. I believe it was, again, based on that conversation with the guy from Meijer. People are paying attention and they're nervous. Yeah, if you're someone who breathes, too. Yeah, right. And I would encourage you to watch the deal gate thing from Chaos Congress. That will give people great insight into how automotive engineers think, how they have to think. Yeah, I'm going to have to go back and look for that one. I had absolutely no idea that they covered that at 32C3. Well, I sure hope the 11th Hope has a talk like that. And if you know someone who's interested in giving a talk like that or maybe Craig will be interested in doing that, we have a website, hope.net. The speaker section has all kinds of guidelines. Speakers at hope.net is our email address. But that's exactly the kind of thing that we do cover at the Hope Conferences. We have covered it before. So I imagine this summer in New York City we'll be talking about it. Yeah, you should have that. Car hacking quite a bit. Car hacking village. Car hacking village. Hey, I like that. I'm not sure how it would work, how we get the car inside. But we'll figure it out. Maybe we'll do it out on the street. That's a great idea. You'll figure it out. Well, we'll do it in the street, on 32nd Street or something like that. I hope that someone dies that, isn't it? Bill, how can people see all the other books that we talked about that you guys are publishing? Nostarch.com. Like Nostarch, please, without the word please. We always give, when people buy from us, we also have done this for years. We'll always give you coupons. If you don't have one, just write to us. We'll give you a coupon. And we also give, when you buy print books from us, we give you all the e-books free. And I've never used DRM. In fact, I was the first publisher in the country to come out against DMCA. The first one. And I stand by that. Well, I was the first publisher to get charged under the DMCA, so that's got to count for something. You're ahead of me. You win. I meant book publisher. I don't know about magazine. All I know is my business, the book side. Well, definitely kindred spirits, and a lot of what you say resonates in our publishing realm. Charge me. Go ahead. I'm waiting for the charges. I still don't have any charges. I'm sure they're coming. I'm sure someone's filling out forms right now. Bill, thanks so much for what you do on behalf of the entire HACC community and people who just are interested in learning. You've done such tremendous work, and I hope you do a lot more such work in the future. We have some interesting stuff in the hopper. And we're looking forward to seeing you at Hope this summer. And Bill Pollack from No Storage Press, thanks once more. Thanks again. Always fun. Always a pleasure. All right. Good night. And again, the book published by No Storage Press is our premium for tonight for a pledge of $55, 212-209-2950. You will learn so much about what cars can do and how cars can be manipulated and all sorts of things you probably never had any idea were possible. You will learn that and so much more, and you'll probably be fascinated from this point on. And, of course, if you know somebody that's interested in this kind of thing, let them know or give them this book as a gift. It's incredible. 212-209-2950. Ask for the Car Hackers Handbook, and a pledge of $55 will get you that. It's really interesting. I mean, as people who listen to this program know, I'm not really into cars at all. But just to know what kinds of things are possible, what's coming, what's going to be possible, what is now possible that we should make impossible, a book like this really shows the way. As we've said, if it's from Nostalgia Press, we know it's a good book even though it's not out yet, so we haven't read it. 212-209-2950. Call and get your copy or go to give2wbai.org. Just as we said, a limited number of copies available, so act now. While supplies last. I wasn't going to put it that way, but we can. But it's true. 212-209-2950. Really fascinating material, and I can't wait to learn more about this myself because there are things that I'd like to be able to do in cars that I drive. For instance, a little thing like this. I'd like to change the Fahrenheit to Celsius in a digital thermometer. I'd like to change the 12-hour clock to a 24-hour clock. I know it's possible. The dealer says, no, we can't do it. It's not allowed. But I'll sell you a tool that's $800 that'll let you do it. They haven't made that offer yet, but I think they just don't have the imagination. Oh, no, no, I'm an aftermarket guy. Yeah, you've got to talk to the dealer about that. Uh-huh, uh-huh. All right, we're at the end of our first hour, but we're on for two hours tonight. Yes, lucky listeners. Here at WBAI New York, the Personal Computer Show is not on. We're going to take a little break. We'll be back in just a moment, and we'll be talking about the Apple controversy and maybe taking some phone calls in just a little bit. You know what else has been pissing me off lately? Google. You guys know Google? A couple of people have heard of it. Most of you guys are like, Google? What's Google? Google it and find out. Friends, the only way to learn anything anymore is to Google it. And that was fine at first, because things were simple. It was like Google was my friend, right? I'd be like, hey, Google, what do you know about this? And Google would be like, well, Ben, here's what I've got for you. Things were simple then. Google was my friend. But somewhere along the line, things changed, and Google turned into that annoying friend that would let you finish a story because it'd keep interrupting you, trying to guess the ending before you can get to it. Right now I sit down, I type the letter P, and Google is like, Pacific Ocean? Is it Pacific Ocean? Is it? Is it pacifiers? Is it pack rats? Is it peanuts? Is it piss bags? What is it? I need to know what it is right now. Tell me what it is right now. I can't wait anymore. I end up learning about stuff that I'm not interested in because Google is so suggestive. I typed in take flight. Three hours later, I'm an accidental ornithologist having inadvertently studied birds for the better part of an afternoon. Now I'm Googling binoculars, planning a family bird watching trip. I was trying to book a flight to Cleveland. Thanks a lot, Google. What am I supposed to do with all this bird knowledge? Oh yes, the words of Ben Bailey on Google here on WBAI. Off the hook, we're here for another hour and we'll be taking phone calls in just a little bit, but I just want to reiterate what we did in the last hour. We were talking about car hacking and offering an incredible book that you can pledge for. Pledge of $55, 212-209-2950. Learn all about car hacking, how you can hack your car, how other people can hack your car, what cars are capable of, what silliness has been programmed into them and lack of security and all sorts of things like that. How to make it better or how to make it worse. Mm-hmm, yeah. We've been talking about this for a while. It's something that is going to keep coming up and I'm sure there are going to be all sorts of scandals and chaos in the future and people will refer back to this book and to the conversations we've had. So now's the opportunity to get this book and be ahead of those conversations, 212-209-2950. Your pledge of $55 or more if you want can get you the Car Hackers Handbook and we want to again thank Bill who we just spoke to for an hour for donating these books. Your $55 go to the radio station. They go to keep us on the air. They go to keep all the other programs on the station on the air. As Bill said, no other radio station in the country will interview him about this topic. We will and we can't do it without your support. 212-209-2950 or go to givetowbai.org. But you know what other radio stations will do and TV stations and networks and all sorts of things? They will cover stories like this but they'll get it wrong and they'll talk about all sorts of fear-mongering aspects to it all and that leaves people uneducated and ignorant and that's exactly what you will not be if you read this book and hopefully if you listen to this radio show. 212-209-2950 Pledge for the Car Hacking Book and learn a ton. Emmanuel, you know why one of the big reasons that a lot of the other radio stations and news sources will get it wrong when they talk about things like car safety and car vulnerabilities because they are beholden to say a company that sells a car and that advertises the car on their network and that pays them a lot of money and that would not like it if they said bad things about their brand of car. We don't do that here at WBAI, do we? No, there are no car commercials on WBAI Airwaves. No car commercials, no commercials for anything else actually because we don't take money from interests like that in order to advertise their stuff. What we do do to stay on the air is we ask you, the listener, for your support. This is the only thing that has kept us on the air for decades and it's the only thing that can continue to keep us on the air and keep us free to say what we want about what we want and to do it in the way that we've done for so long. So call 212-209-2950 or go to give2wbai.org and you can pledge $55 for the Car Hackers Handbook. You can pledge for something else. You can pledge any amount you wish and show your support and help us keep doing what we do. Yes, we are a strictly community radio formatted entity here in the middle of the FM dial. I would say it's the middle. It's close to the middle. It's about as middle as you can get. One way or the other, but suffice to say, that's where we are and this is not just about giving pledges and getting items in return. This is really a concrete contribution to this institution coming at you over the radio or online. There's a lot of changes, a lot of exciting things going on here, but we need your support to keep that active and to maintain a lot of the technical and organizational things that keep this place thriving. You can be a part of that. So please, if you're interested in this, if this book is interesting to you, if maybe you just feel like giving a little bit of support because you enjoy off the hook or have for some time, now's the time that you can give a little bit back for whatever you've gotten out of our program and support more of that into the future here at WBAI. Bernie, any words from you down there in Philadelphia? Well, this project that Bill Pollack's been working on at No Starch Press has enthused me enough to go out and buy a copy. I can't pledge with him on the show, but if not, I'll buy the book directly from No Starch Press. I don't know. Do we have any idea if all the copies that were donated have been pledged for yet? I cannot say for sure. I don't have online access to that bit of information yet, but we'll find out. Yeah, we don't have a telly. Bernie, if you want to pledge while you're on the air, you can go to give2wbai.org and do it that way. Yeah, that's one way to do it. But although, I don't know if we like distracted radioing, so maybe don't. I think actually a few of us in this room were so interested by the book that we were a little bit nervous about not getting copies ourselves. So phones were passed around, and I think if it runs out, it might be because of us. So you better hurry up and give a call. But you can still pledge. You can pledge any amount. I can actually get all the codes out of my car for about a $20 ODB2 Bluetooth device. I can look on an Android phone, which my blackberry will run Android apps. This is an amazing opportunity for you to imagine you're spending tens of thousands of dollars or tens of thousands of dollars for a car, and you're basically buying a bunch of computers in a moving platform, and you have no access to any of the computers. It's ridiculous. It shouldn't be that way. You should be able to control or at least know what's going on with these computers that you just paid a lot of money for, whether it's a new or used car. So one last effort on this. Please call 212-209-2950. Support the radio station. For $55, we'll send you a great gift. It was given to us by No Starch Press. But this is a very current topic. It's fresh, hot off the press, and you'll definitely be hearing more about it. Do we have some more stories to cover today? Yeah, we sure do, but I just wanted to say if for some reason you're not interested in this, you can still call and pledge. There are all kinds of other pledge levels, all kinds of other premiums, and you can become a WBAI buddy. Just call 212-209-2950. Ask for more information on that, and believe me, every little bit counts. Every little bit keeps this station going, and we're able to have conversations like this where we talk about new technology and things that are not being covered in the mass media. All right, so one thing that is being covered quite a bit in the mass media, but I'm not so sure they're getting it right either, is the whole Apple story. Now, I wasn't here the last couple of weeks, and admittedly, I have not been extremely focused on the story, but I think I have a basic idea of what it's all about. But does anybody feel confident enough to kind of give, without injecting your opinion into it, what it is that Apple is facing with this whole give us access to somebody's phone controversy? Mike? Yeah, so we talked about this last time we were in the air a bit, but Apple produces a very popular line of cell phones, our audience may know, and you can lock the cell phone so you can't turn it on without entering a password. And apparently, you can configure these phones so that if you enter the wrong password 10 times, the phone wipes itself and you can't get into it ever again at all because the data's gone. One of these phones was owned by the man in California who shot a bunch of his coworkers, and the phone is owned by his employer, the county government, and the FBI claims they would really like to get into this phone because they claim there's some investigative need for that. Am I doing a good job of not injecting my opinion? Yeah, so far you're doing good. And it's a tough case for them. Just add my opinion. So they claim they really want to be in this phone, and what they would like, and they don't want to just guess passwords because if this feature is enabled and they guess the wrong thing 10 times, then the phone will be wiped and they won't be able to get in anymore. So what they would like Apple to do is not what Apple has already done because Apple's already done that, which is provide a copy of all the backups of the phone that they have and just everything that Apple actually has in its possession has already apparently been provided. But the government would like Apple to go a step beyond. They would like Apple to create a special version of the software that runs on the phone so that the FBI can try as many passwords as it wants without the phone being wiped. They want to be able to try them as quickly as the hardware will allow. Normally if you have a device and you guess the wrong password enough times, it will slow down the rate at which you can guess so that you can't just guess all the passwords. But the FBI would like to be able to guess all the passwords and they would like Apple to write this software for them. They would like Apple to install it on this device for them. And the other thing the FBI wants is they don't even want to type in all the passwords. They want to be able to enter the passwords in. Remotely from a computer or something. Okay. That's a pretty good summation I think. Now if I understand correctly, if you were to hand me your iPhone right now. I have a different phone which operates more or less the same way. I got you to say what kind of phone you don't have. Yeah. No one in here has an iPhone. I'll say the name of my phone if you think it's interesting to our listeners. I don't know. Okay. The point is, if you had an iPhone and tell me if this is true of iPhones in general and you handed me your iPhone and I tried to guess your password 11 times, I'd wipe your entire phone? Well, after the first few tries there would be increasingly long delays. I understand they're on the order of hours. So it would take you quite a while to wipe an iPhone that way. So I could really annoy somebody just by borrowing their phone for a minute and trying to guess the password a few times. They wouldn't be able to even use it for a couple of hours? I don't know the details of the slowdown sequence but there is one. So I think, you know, the first delay is a slowdown. The first delay is short and then it goes to the order of minutes then to the order of hours before the phone gets wiped. Okay. And there is data that has already been backed up to the iCloud is what they call it. Yeah. Do you know how often that happens? This is one of the controversies in the case because apparently the regular backups stopped sometime before this shooting and what the San Bernardino County people, I don't know exactly which agency did, Sheriff or... I don't know if it's the law enforcement or the agency that the shooter worked for who owned the phone but anyway someone reset the backup password which apparently is a thing you can do on the computer so that no more backups could take place rather than just trying to bring the phone into somewhere with Wi-Fi and have a backup automatically take place which would maybe give the latest data without all these shenanigans. So wait, if they hadn't changed the password then the next backup would have taken place and they would have had all the information that they want now. That's not a certainty but it's a thing that seems likely. Okay, alright. Does anybody have any disagreements or problems with this scenario so far? Ethical, moral problems or... Well I mean there's all kinds of ethical problems with what happened obviously. Barney, does that drive what you understand? I think Mike did a pretty good summary of the situation and there's a lot of misinformation I think that's been inaccurate and incomplete information that's being reported on... We're going to get to all the misinformation. There's plenty of time for that. Kyle, do you have something? Well I mean it's accurate to my understanding. There was one thing that I heard that was brought up which I think is interesting. It was a question that was asked during a hearing about this by I believe a congressperson who inquired about the ability of the FBI to mirror the phone so that they can start over the 10 tries infinitely. And I think Apple responded in the affirmative that that was an alternative to breaking the system is them competently mirroring the existing installation and whatever data is there as a backup so that after 9 tries they can start over. So that's not really something you're hearing in the media about this because the FBI has this angle of wanting Apple to explicitly do this work for them when there are other techniques than breaking this particular system. And that's the huge thing about this case. It's not about finding out anything about this one person who used this phone because that person is dead and we don't really need to know any more than that to effectively close this case. But what they want is the ability to do this from now on to whatever phones they like. Well, they say no, it's just this one time. They say that but obviously if they do it once they'll be able to do it again. So, yes, Kyle. And what has been brought up in the media in the context of using that tool that they're hypothetically being forced to create is that it will then become a process, a tool that is used with some regularity thus opening it up to it being exploited as a routine process that is subverted somehow. So you set up that infrastructure for that. You have administrative people, people within whatever agency getting access and up to and including foreign actors. And one of the representatives of the hearing brought this up but like state actors or people in organized crime and so on can then use these tools if they're exfiltrated from whatever secure place they can be stored. And I think Apple was they really did articulate the defensive side of that because the government is basically like the reason customers create their passwords and stuff is because Apple can't guarantee that. And so the government's saying okay, break that and then we'll take care of all of that in a place that you yourself can't guarantee exists. There is no secure place to keep the tools for this just like there's no place for Apple to keep all of everyone's passwords for this. So it was a good argument. Okay. Well, that's interesting. I think we should get into that a little bit later as well as far as the hearing that took place. But based on all this based on what I'm hearing first of all I imagine if any of us knew what the password was we wouldn't have any trouble with the password being given to the authorities to look into this, right? I mean, if I said hey, the password's 2600 yeah, go ahead. Go crazy. How good friends are you with this guy? I don't know. I'm just saying if I knew there was a back door if I knew there was a way it's not a question of people saying oh, you have no right to look into this person that obviously was guilty of horrible things. And if Apple has the ability and this is where I think I might be ruffling some feathers here but I think this is this is a statement that I've come to based on what I've heard. If Apple has the ability to get access to this phone then I think they should give them access to that phone. Does anybody have a problem with that? I imagine you do. I mean, how do you define has the ability I guess would be the question. If they are able to sit in a room and either punch a few buttons or write a few words write a few bits of code then in my view if they have that ability they've already done it. Because it's not hard for them to accomplish this. They have access. And basically what we're doing right now is believing them when they say we haven't done this we don't want to do this. And I'm a little bit suspicious that all of this is a big Apple PR push. That they simply want to say we protect our users more than anything and we hold privacy to be completely something that we will never violate. But I think if they have the ability to do this then somewhere in a back room someplace they have already done it or they will do it when it suits them. And that's what worries me. But then if they have the ability to do this how does that ability to do this end up as say evidence you could present in court if it's not legal for them to do this? Well the thing is the authorities are finding ways to bypass those annoying little requirements and either get the evidence they want illegally or simply engage in some kind of operation based on illegally obtained evidence. I don't think that's really going to be something that people are going to waste much time soul searching about there. I think if we've all already got it in our heads that okay if you use say Gmail then Google as a company has the ability to if they're served the proper warrants to just let any investigators they want into your Gmail to flip through it and see what's in there. Well that's the thing. Okay that's a good example. Gmail will say we don't read our users email. Of course they do because they give you ads based on what's maybe computers are reading it maybe humans aren't actually looking at this but you know they have the ability to read your email. And if they say we don't do that great believe them. Believe Google if you want believe Apple if you want but you know they have the ability to do this. So that's why if it was something where I'm trying to think of a good analogy to this maybe PGP is the best one. If somebody went to the people that run PGP or GPG or whatever and say we want to read these messages the answer they're going to give you is we can't. It's not possible. We can't just crack the code because we designed the system so that we can't crack the code. Apple's not saying that. Apple's not saying we can't do this. They're saying we won't do this which means they can do this which to me means they have done this. No they're saying they can't do the they cannot break the password. They're being asked to create a tool that makes it easier to break the password which means they can create that tool like Mike was talking about the slowdown and the attempts being interrupted after nine or ten or whatever that was it wipes the data that's local to the phone. That's that process is what they're being asked to break. It's not necessarily the password itself. Right. I think they explained that the password itself creates the encryption key or is a part of the key generation in that whole part of the software. That means a clever Apple engineer someplace who does not agree with company policy and has the appropriate access can do this on their own. But they can't do it easily without the tool that eliminates the slowing down and the wiping feature. And I mean you can brute force things. There are tools out there that you can use to brute force things but without but it's a lot harder if that is not disabled. Well, I think somewhere they have access to the code that will slow that will bypass the slowing down when you guess an invalid password. I think that can be bypassed as well with the appropriate access. Right, but it's a custom version of the operating system that would then be generated and I think that was also an argument that was made that you are then signing a version of the operating system for the government. Right. There's no guarantee the government is going to be able to secure that copy of the operating system. But do you think it's possible that Apple and the higher echelons of Apple they have something like this designed so that they can whenever they feel like access certain devices. I don't think so. I don't think they're that shady but I do think it's physically possible. I mean, so look we know that Apple is working teams within Apple are working to make it harder and harder for them to be able to do this to their immense credit. As a feature. Yeah, the next version of the phone the specific requirements asked for here won't work anymore. What is truly frightening to me about this government request is that they are saying to Apple you must weaken the security of your own product. As we talked about in the first hour security of computer products is already way too weak for the government to mandate companies to design software that is weaker than they know how to make is a terrible precedent and one that I think we really ought to stop. Oh, I agree with that. Absolutely. And they are in fact requesting that even though they're saying that they're not requesting that. It's quite obvious that if they do manage to do this I mean Cyrus Vance has a whole room full of phones that he wants to get into right here in New York City. And I imagine every district attorney around the country has a similar story. So this is a very bad precedent. But what I'm trying to do is simply not believe a corporation at face value that they have not already done this that they don't have the ability and that we should just believe when they say we don't want to do this that they have not already done it. I will be happy when I hear them say it's not possible. It's not possible. And you're saying the next version of the phone might have that ability where it's not possible? I don't want to play iOS forensics expert on the air because I'm not one. But the claim is that it's even harder in the next version of the phone. They produced as part of their reply brief an estimate for how long it would take them to make this software. It was something on the order of a team of six engineers for a month which is you know if Apple has six engineers working for them they could get it. But it's not the kind of thing they would just do on a whim. Right it's not sorry it's not good for their bottom line. It's not their everyday business model. That's why I'm saying I don't think they care. I'm not saying I trust them not to do it. The engineer is not there. Like you're saying it isn't possible someone there has an interest or has done this just for proof of concept. But I don't think they care because it's not their bottom line is what they care about. Absolutely. Apple is not a governmental agency. Google is not a governmental agency. These are private businesses and ultimately they're there to make a buck. And the key to the security of any system lies largely in how it was designed. That depends on why it was designed. They're designing a system to provide a device to their users that will do what their users want. If the government is stepping in and saying they have to do that differently what's the process for that? How is that being overseen? How is that decision being made and forced allowed to happen? If you run your own little locksmith shop and the government walks in one day and says you have to give us a copy of every key you sell somebody that would be seen as overbearing. That would be seen as overreaching. But it's essentially what's happening at Apple. It would be seen that way if you found out about it. What if they did that and told the locksmith you can't tell anybody. Like one of these letters that they send out to people saying you can't tell anybody you got a letter. There could be companies in fact I'm sure there are companies where they are working with the government and they've been told don't tell anybody that you're working with the government. Now Apple is different because they're objecting to this loudly and that's admirable but again in the back of my mind I have all these doubts that well okay is that really what's going on? What is actually possible? And again you mentioned governments. There are governments all over the world. So what one government does another government will do something even worse. So once you start working with a government there's no end to what it is they can control. So it's a very very dangerous precedent. But trying to look at it from the position of Apple a company that wants to make money I think it was a very good move for them to publish the letter they did that we read last week on the show decrying the government's request and talking about why they don't want to do it why they won't do it because that in itself was as you said a good PR move. That in itself is a move that will increase Apple shareholder value and that's what they're there to do. One thing that was brought up was this idea that their product is predicated on some level of trust with their consumers and that another important distinction in that is this international appeal the fact that this is a multinational company and that for them to create this for phones here would set a precedent internationally or create a product internally that is desirable and it's already the case that they work with government agencies from around the world I mean this whole case I think the first call they said in the hearing this week that their government relations response team received a call at like 2 in the morning on a Saturday and they were active on this like immediately after of course they're saying that in the hearing to appear diligent but I believe they correspond with a lot of things the distinction is that they relate and coordinate with the government where they have to e.g. subpoena but they I think are drawing a line here and that's a lot of what's being thrown around the media is this line being drawn and another distinction or reason that's a bit contentious is the way it looks I mean this is a terrorism case so it's sort of the language and the attitudes around it there's a lot of attempts I think around this that are making them out to be a bit not patriotic but that I think is myopic it's short sighted because other entities around the world will want more access if our government is given more tools or more access and if they can't get it legally they're going to try to find it they're labeling it terrorism I think just to get their way mass shootings all the time in the United States for some reason that one was considered terrorism and others are not considered terrorism I don't want to get into that because we'll just be talking for hours about that Bernie I know you wanted to get in on this yeah to answer your question that you asked a minute ago can Apple provide a means to bypass to brute force the phone so that the FBI can gain access to the content yes Apple has already admitted they can do this and they basically provided a price quote for this in response to the court order the court said that Apple could had to respond within so many days had to either comply or respond within 10 days and say within I think 5 days and explain if this was an undue burden and Apple provided a quote of basically how many engineers and how many person hours it would take to do this and that they said they would have to build a SCIF which I thought was really interesting you rarely hear about this in the public media a SCIF is an acronym for it's used by government by intelligence agencies SCIF is a secure compartmentalized information facility it's basically a vault where work can go on inside this vault and no information can pass out of the vault it's without authorization it's like secure against a tempest eavesdropping it's a secure facility CIA operates them NSA operates them all around the United States what's your panel that you can climb out of well it would be nice if there was such a thing but no these are really and they cost tens of millions of dollars to build a SCIF apparently they're really expensive and Apple has quoted like this would cost all this to do this so why would not the FBI just say go ahead alright we'll do this if you can do that no the FBI wants a tool in their possession that they can use quickly maybe covertly in a jiffy to brute force anybody's iPhone password instead of having to go through the process of going to Apple and say hey here's the phone go through all the stuff you gotta do in your SCIF to bypass the information and give us the information the FBI wants to be able to just go in at will and anybody's phone once they have this we know that's what the FBI wants but you're saying the FBI got a quote from Apple Apple said yeah we can do this why didn't the FBI just accept that and get that information and then push to get more because like I said the FBI wants Apple to provide them with a tool that they can use quickly and covertly that's not what they're saying they're saying they only want it for this one phone why didn't they just accept it for the one phone clearly the FBI is lying about it because once it's this one phone then it'll be another phone and then it'll just I know they're lying but they don't admit they're lying while they're still asking for the one thing they haven't gotten yet when has the FBI ever admitted to lying it's documented through it sounds like you're saying they are look the thing is if Apple said yes we can do this for you and the FBI wanted this I don't understand why they wouldn't just say okay give that to us we'll pay you for it and then after that's done move on to the next thing which I agree would be getting access to any phone they want anytime I think it's come down to basically a pissing match the FBI wants their software they want it now to access any phone they want they don't want I find a lot of parallels between this and the whole CALEA thing the Communications Act for Law Enforcement Assistance that was passed in late 94 news media agencies are saying all over that this would be an unprecedented step for a company to cripple their security to provide access to law enforcement no this has been going on for 22 years since CALEA has been the law of the land the FBI and other law enforcement agencies can directly access central office telephone switches and listen to phone calls and we know that they can do that we know those systems are not secure that's my problem with this this system is not secure and we need to admit that but Mike you said that Apple refused to do this the spec that Bernie is describing is an exhibit in the brief opposing the government here it's not like Apple said this is how much it will cost please give us the money it's because they're claiming undue burden actually conscription I forget which right that is but anyway there's like labor involved and Apple's arguing that they're being conscripted into creating this tool and so if they can say look this is going to take this many engineers it's basically saying this involves labor that's the part I don't understand why would they say it takes this many engineers this is what it would take and then say we're not going to do that why not just say we're not going to do that or we can't do that why give them the particulars as to what it would take because they were trying to use that as an item in their defense saying look how much work and how much money it would take us in order to exceed your demands and this is an undue burden to place on a company so they're trying to present it in that way but they're also saying we can't technologically do this we can feasibly do this if you throw the money the resources at it but we still don't want to do this yeah you see I think that was their mistake is saying that saying that and admitting that it could be done I mean is your claim that Apple's lawyers are incompetent or that they're dishonest and they want to lose this case? I don't know about their lawyers I don't know about their level of competency what I get from all this is that technically it's possible to do what the FBI wants to do therefore that technology is not secure and should not be used. We should have something where users have the ability to lock out whoever they want to lock out and Apple can't do a damn thing about it and by extension neither can the FBI. We don't have that right now. Yeah that characterization is accurate in that and I also think the whole iCloud backing up which some people might say is obvious but that's the one thing in this that is just totally normalized that like oh yeah iCloud is just straight up on the FBI's desktop or something whoever yeah they have something from like an hour beforehand but that's not enough they want all of it I know yeah but it is that and the work of creating this tool being I lost my train of thought it's not hard to do in situations like this but here's something to consider all this talk from the authorities about how they need all this access they have to have this information keep in mind you just go back a couple of decades and people didn't have cell phones they didn't keep all this information there you had to run an investigation based on what you had in front of you pen registers, phone taps, things like that it wasn't all there laid out for you so for those people that say we are being victimized by technology, encryption is the enemy it's a bunch of nonsense because the amount of information that you do get through social media and through these devices that contain everything and nine times out of ten you are able to get the access that you want because the person isn't clever enough to select the password in the first place you have it a lot easier now for investigative work so don't buy that argument what I was going to say is that they can we can say with confidence that they can break the nine attempt feature on the passwords of iOS devices right? that's what they have to the government is asking them to create as a tool and Apple is saying we don't want to do this but we can, it'll take six engineers but it's not that they're saying we can break the encryption, we're saying we can break the nine attempts and the wiping so that you can continue to try to break the password through brute force but they're equivalent, right? substantially all people have a four digit pin if you don't have limits you can try 10,000 pins in an hour, it's not if the FBI gives me one guess I think I might be able to get it I have a suspicion but how many guesses have they used, does anybody know? and the other question I had well go ahead well and that goes back to the technique that was brought up that involves mirroring the device which Apple said is potentially possible that was my other point is it possible to simply copy the phone to another phone and then you have 10 more guesses kind of like running it in a virtual machine essentially having a clone of the OS and I think Apple responded saying that it's dependent on the state of the RAM of the state of the phone and so on if we could figure this out we'd help figure out how you can get into that particular phone but not for the entire customer base of Apple go ahead Bernie on our last broadcast I brought up that very point that Apple could very likely clone this phone in its current state and make 100 copies of it so that the FBI could use its agents to sit at tables and like manually try every possible pin after they go through 9 tries on one phone and they go to the next one but what FBI wants is not only software tools that will allow them to enter more than 10 pins without it wiping the phone but they want to be able to have no delay between these brute force attempts so as Mike said you could have a computer try all the possible pin codes in probably less than an hour and go through that so that's the nature of brute force attempts so there's a lot of disingenuousness going on here I think both from FBI and Apple frankly and this is nothing new the FBI has been trying to do this with systems for decades and they're just trying it again. Yeah I totally agree with you Bernie there is some mistakes I think on both sides and subterfuge of sorts and one thing that was I think kind of speaks to your point that was brought up is that they admitted that the one representative I think who was sort of opposing Apple who was on the second hearing that I watched was questioned and basically asked about NSA techniques what kinds of things would NSA do and basically got this guy to acknowledge that the NSA said yeah we actually do have ways but we can't really help you because if we show you these techniques then they'll become known Good point yes Hey we should involve our listeners in this discussion I'm sure we might have some other opinions to share. Our phone number our RNA phone number is 718-780-8888 that's 718 780-8888 8 I should also point out though that we are in the dying breath of a fundraiser and we have I believe we still have copies of the car hacking book for pledges of $55 if you're interested in learning about how cars are hacked, how they could be hacked all kinds of things I'm sure the auto industry does not want you to know about. Give a call to 212-209-2950 pledge $55 for that and you'll become extremely educated. You'll frighten your neighbors. 212-209-2950 Keep us on the air. Pledge whatever you can afford Alright we have a whole bunch of people calling in. I'm sure we have all sorts of ideas here Good evening. You're on Off the Hook. Go ahead Hello. I watched that entire hearing on c-span.org It's still there for anybody to watch The smartest congressman was a fellow from California named Darrell. I'm not sure if it's Esau or Isai however he says his name. He seemed to be on Apple's side but he was the one asking about the and all that and did FBI request a source code from Apple so that they can create their own bypass to the system Apparently that didn't happen yet He also asked did you ever hear of a shredder company that was asked to provide a way to reassemble the shredding. He was one of the smartest That is the parallel I was looking for That was a That was a great exchange and he had him on the ropes there. Yes he did Now he was one of the smartest people there. One of the dumbest was a woman named DelBene and she mentioned the scenario that was on the CSI cyber where somebody remotely hacked a printer and set it on fire I mean just so stupid and she really she brought that into the hearing as if it were possible and she really believed it. This is where the government gets their ideas from CSI cyber. Think about it. Exactly 100% correct but anyway I urge everybody to watch that. It's on cspan.org and they're probably running it on cspan again He was the fellow from California was one of the smartest there were a couple other people who were pretty good there was a woman a former Google analyst seemed to be on Apple's side also her name is Susan Landau and she's a professor now and she said her take is that the FBI should be concentrating on their surveillance and not asking people to crack things so she was another good person. Now the lawyer for Apple his name is Bruce Sewell S-E-W-E-L-L they only had one lawyer there he couldn't handle all that by himself when I think of the team of lawyers that OJ had I mean Apple could certainly afford better than that I don't know why they just stuck that one guy there and let him out there to hang because they're asking him about well you want you want Congress to fix everything well what's your proposal and he had none so that kind of put him in the corner and it goes on and on and on you know what happened I can't go through all of them but I had posted some of my things that I some of the things that I thought were important on the internet in any event everybody should watch the c-span.org Thanks very much for that pointer and after this show is over folks, not before then go to c-span.org and watch that hearing I mean I think the fantasy about the exploding printer while fantasy only goes to the point that we need to improve the security of all these devices and government orders to weaken the security which is already too weak is precisely not what we need. Well I think the first step in that is to make sure that it's clear that that is what they are asking for that they are asking to weaken security not simply to get access to one particular phone and that's something they have not really been forthcoming with but those of us who have any understanding of the technology knows that's exactly what it's going to lead to. Now we were talking about Apple having support from various entities this is interesting there was a panel of cryptographic luminaries at the RSA conference and guess who did not support Apple? The co-inventor of the RSA algorithm Adi Shamir Mr. S. Yes in my opinion he said Apple goofed it is the case of a single phone it can set precedence but if you look at the issue it falls on the side of helping the FBI in this case. My advice is they should have complied this time and waited for a better test case. What do you guys think of that? I think this is turning out to be a better test case than imagined let's be clear that you know Apple's move here has to be you know not to play at all because if they they don't want to be in the business of deciding on a case by case basis and it's you know one of the points Apple made in its brief and I really hate that I'm agreeing with such a large corporation which does so much else wrong but on this I think they're pretty right and they point out that this case is being litigated in the press before it is being litigated in the courts or simultaneously at the very least if the FBI seriously thought that there was any even minuscule chance of the data on this phone leading to another co-conspirator they would not make such a public deal about this. They would not want to tip that person off but the shooter in this case destroyed all his personal phones this is the work phone it seems to be fairly clear that there just aren't any co-conspirators to be found the government is using this as a test case because they can call it terrorism and they hope that that will get them whatever they want and then they can go use it in more ordinary cases in the so called war on drugs and stuff like that Well I'm not sure how we can say for sure there's no other co-conspirators there could be we don't know We can't say for sure but it seems fairly clear at this point that the likelihood is quite small Alright well I don't know enough about the case to say one way or the other but I do know that this would set a bad precedent if it were something that was just accepted and I also don't know was the FBI the one that went public with this or was it Apple that went public with this because maybe the FBI did want to keep this quiet If the FBI wanted to keep it quiet they would file the motions under seal They can keep it quiet and they didn't the director of the FBI wrote blog posts about it and all this stuff In a manual? Yes If this was really about national security which it clearly isn't because the suspects are dead at this point The FBI as Mike pointed out they could have gone to the FISC the Foreign Intelligence Surveillance Court. They could have gone secretly to this court and Apple would not have been able to gotten an order and Apple would not have been able to say anything about it. They could have got a national security letter from the FBI saying you can't talk about it and you have to comply with this order and you know who knows how often that happens with other companies behind closed doors. Well that's precisely the point I was making before is that it could happen and we would not know about it Hey maybe it's already happened and they just didn't tell the FBI about it. Who knows but if they can do it secretly that means it's pretty much done because they will do it secretly at some point Alright let's take another phone call 718-780-8888 and good evening you're on off the hook. Go ahead Turn down your radio please Oh yeah sorry Here let me turn it. Yeah what's on your mind? Yeah Yeah okay I'm on Go ahead I'm on the radio. Yes you're on the radio but not for much longer Okay well what I wanted to say is that the memes on big countries with huge militaries that say we want this and you're going to give it to us and they comply. The government is like the mafia on steroids if they want that information if they want Apple to comply they just say well you got $100 billion offshore we're going to tap into that and Apple would dance to any tune the government wanted so this to me is just a kabuki dance. They're just trying to look good. Apple's trying to look like it's serving its customers but they've probably either already given that information off or they're doing some kind of dance where they're saying there's information that they got and they can't actually go after those people or leads or actually go after and catch somebody unless they say they got that information off the phone they probably already have it So you think this is more like a market test to see how it plays with their customer base Yeah I heard that Apple was saying yeah we'll get you stuff and then when it became public then they started going oh no we're not going to do that Yeah that's kind of the impression I got too that had it not gotten so public wouldn't have looked at it in that particular way and said how can we make our image as good as possible and protect our customers. How is it playing though with the populace overall my impression is that a lot of people seem to think that Apple should be just giving the FBI whatever it wants but then you know what a lot of people are voting for these days. Yeah but do a lot of people realize that 70% of the intelligence community is private now and there's a lot of jerk offs you know that are actually watching private information right now laughing about people's nude photos that they're catching online that they're sneaking into. These guys are just regular hacks men they're not hackers but regular people that have access to all kinds of information that's just so they showed us and it's out of control there's no privacy there there's not even a government regulation behind it you just have these companies and they're just it's like a wild west out there so get their information over to them good luck there's some guy out there that you teed off you got his girlfriend and he's gonna say oh now I can get even with you 20 years ago and he can start screwing up your life let me tell you something this is bad news. Alright well thanks so much thanks for that call and we're gonna try and take another phone call any comments on what we heard so far? I mean I think again it just goes to the point we need more security rather than less yeah well who's arguing for less security? The FBI? That's it. And their powerful allies alright 718 780-8888 good evening you're on off the hook go ahead can you advise me how to get an anti-virus for android tablet you're listening to the wrong show the personal computer show will be on next week at this time alright good evening you're on off the hook go ahead yeah speak up okay what I'd like to say is apart from listening to CNN and Daryl Issa who can we contact to vent our frustrations where something would get done that's the question of the ages isn't it who will listen? Bernie any ideas on this? by the way let me add in another bullet point if I may it was reported the day after the attack by these two terrorists that Apple changed their security plan or system on some level this was reported by Alex Jones maybe you guys can give an update to this or an answer to this well yeah you saved us some time but yeah we can look into that Bernie any idea on who I can contact? I kept hearing I kept hearing touch tones in between his questions what was his question? who will listen? how can you contact somebody that might actually do something about this and take our concerns seriously? well obviously Apple already if Apple already is on our side pretty much or vice versa you would have to contact some of the government all I can suggest is you write to your legislators whether they really care or not I don't know your U.S. Senators your Congress people write to them because you know I think really they care more about keeping their jobs than they do about this security issue frankly and if they diss too many of their constituents they know that the gravy trains over and they're not going to be able to play in the sandbox anymore. I think locally Hakeem Jeffries was participating in this he's a Congress person for Brooklyn here somebody who might know about it somebody that might actually listen thanks for that phone call we can probably take another one or two 718-780-8888 but does anyone here have anything to add? I mean in addition to the good advice that Kyle and Bernie gave you can always follow the EFF for action alerts and stuff like that. And the ACLU too in fact they filed an amicus brief today I believe defending Apple. They say the stakes of the fight between Apple and the FBI could not be higher for digital security and privacy if the government has its way then it will have one party to turn American tech companies against their customers and in the process undercut decades of advances in our security and privacy. So yeah we need more security that prevents them from doing things like this not less and I think maybe this is a tactic on their behalf to ensure that we don't move any further in the direction that we want to go in more so than it is an attempt to get access to this one particular phone I think they're scared of losing control. They're scared of losing access to this particular aspect of our private lives. I mean it goes beyond our private lives these phones as I was reading I wish I could remember who wrote in an article today argued pretty convincingly these devices have become literally an extension of our minds which and government has never had access before to our minds and that is you know something that I wish to prevent them from having. Yeah it's the importance of this stuff is critical and like that came up in the hearing it was mentioned that these things are phones are becoming a platform for authentication they're becoming wallets they're becoming full of accounts and access to various parts of our life and platforms and so it's a huge hugely important issue to protect these things. Nice going guys we had a bunch of calls and they all went out into Neverland. They're still ringing but we can't get to them. Folks that called in. Anyone that calls in in the next 30 seconds we'll get you on. 718-780-8888 and if you have a phone ringing now we don't know where you are because that's the way our system is set up it just transfers someplace and we can't get to it anymore. You can write to us OTH at 2600.com oh they're back okay let's see if we can get one of these. Good evening you're on Off the Hook make it quick. Hi what's on your mind? Turn your phone down turn your radio down. Yes Please go ahead Yes my concern is that you know unless us as the people you know do something about it and all get together and put a stop to it it's never gonna stop I mean all these choices that we make you know we could talk about it and everybody could keep talking about it but nobody actually groups together and makes a difference. Well I don't know if that's true I think a lot of people do group together but we have to be louder and we have to maintain a sustained attack on this kind of a thing and educate people let them know why this is important and why it's something that benefits them. Hey we're out of time I know Rob you have something to remind the folks about. Yep speaking of grouping together 2600 meetings happening all over the world 2600.com slash meetings find one near you or start one near you www.2600.com slash meetings write to us mth at 2600.com We'll be back next week I believe WBAI New York Good night Give me crack anal sex take the only tree that's left stuff it up the hole in your culture Give me a back door burning wall give me a star in St. Paul I've seen the future brother it is murder slide slide slide all direction nothing you can't measure anymore the blizzard the blizzard of the world cross the threshold it's overturned the order of the soul when they say repent repent I wonder what they meant when they said repent repent I wonder what they meant when they said repent repent I wonder I'm a bad man. International Working Women's Day at WBAI will broadcast...