Therefore, I urge listeners to support this station, because the dog hole, and make no mistake about it, is out to get it. Trust me. So do the right thing, and donate now at give2wbai.org. That's give2wbai.org. And don't be surprised if you find yourself yearning for the good old days of Tricky Dick Nixon. Yes. Okay. How do you follow up that? Wow. First Reagan, now Nixon. It's 8 o'clock. You're listening to WBAI in New York, and if it's Wednesday, that means it's time for Off The Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving. Now I can't make a call. We couldn't get much worse, but if they could, they would, Von Diddley Bonk for the best, expect the worst. I hope that's understood. Von Diddley Bonk. And a very good evening to everybody. The program is Off The Hook. Emanuel Goldstein here with you, joined tonight by Rob T. Firefly. Good evening. Kyle. Yes, that's true. And Bernie S. down somewhere. Greetings from Philadelphia, Emanuel. And our special guest, Kevin Mitnick. Hey, how's everybody doing? You know, I didn't expect to see you in person today, but welcome. Welcome to our new studios in Brooklyn. Yeah, this is awesome. I was supposed to actually fly out to Los Angeles tonight, but I delayed my flight, so I got the opportunity to be here. So it's awesome. And Kevin has a new book out, and this is exciting news, especially for BAI listeners, because we're offering it tonight as a special limited edition premium. We'll get into details on that in just a moment. The book is called The Art of Invisibility. Is that correct? Exactly. So myself and Rob Vermossi worked on this for the last year, and what inspired me to do the book was really the revelations of Edward Snowden, because we all knew, right, at least people that were involved in 2600, that the government's monitoring us. We knew this, right? Technically. It was a technical reality. Right. We weren't sure. We didn't have the evidence. And then when Snowden came out, we go, OK, it all makes sense. But we didn't know to what degree their capabilities were. So I was thinking, wow, what about other issues where schools spy on students, employers on employees, identity thieves on people like you and I? Average folks don't even know what VPN is or how to use a password manager. What is VPN? Well, I have to represent the average folks. It's a new type of brownie. No, but that's funny, because when I was on the Rachel Ray show earlier today, and, you know, it's a bunch of housewives and that sort of thing, one of the, I think the co-host said BPN. Oh, no, VPN. Anyway, what I wanted to do was actually give the tools to people on the street, the everyday people, not security people or people involved in technology like us, because we know this stuff, but more for people that don't know. So that's kind of what inspired me to write this book. So it's for the everyday person. It's not for the security professional. They should know these things. That's true. That's true. And they don't have time to read books anyway. But if you're interested in the things that we talk about here on Off the Hook, I can't imagine a better book to plunge into. Actually, I've got a copy right here, The Art of Invisibility. This is how solid it is. It's a heavy book. It's got a lot of really, I'm going to read some of the chapters. 300 pages. 300 pages. 300 chapters, I think, kind of tell the story. Time to disappear. Exactly. That's what it's all about, right? Because we want to disappear. Getting off the grid. Yeah. If Big Brother is everywhere. Your password can be cracked. Who else is reading your email? Wiretapping 101. Well, you're kind of an expert on that, aren't you? Yeah. I had some involvement in that in the past, so I could speak to it a little bit. If you don't encrypt, you're unequipped. You know where that comes from, right? No. Where does that come from? If it doesn't fit, you have to acquit. Oh, boy. Yes. The old O.J. Simpson trial. How about that? Exactly. Exactly. So I thought it was clever. Yes. Well, I don't think he's going to sue you for that. Now you see me, now you don't. Every mouse click you make, I'll be watching you. The police. Every breath you take. Right. Exactly. That's good. That's good. Yes. Believe everything. Trust nothing. That's pretty much true. Yes. You can run, but not hide. It's very difficult. You ran. You hid. Right. And how I got caught back in 1995 is I got pretty complacent. What I did at the time is I used cell phones, but back in those days, you didn't have data over cell, right? That didn't exist. So I was able to modify a U.S. robotics modem to actually connect to a PTRE25 Nova telephone. Those are almost like brick phones, and actually do 300 and 1200 baud. So I was able to dial up to the internet, if you want to call it that at the time, through ISPs like Netcom. And I used to just call different dial-up numbers, or what they called POPs, in different cities to make it more difficult to track the origination of the call. And I would even get switch access, hack into whatever phone company I wanted to, and monitor that POP to see if any technicians ever did a command to do a line trace, essentially. So anyway, I got complacent. I stopped looking at the switch and that sort of thing. Because I was using a fixed location in Raleigh, it's not too difficult if you use a fixed location to do radio direction finding. And what they were able to do, for those that don't know, there was a guy that became involved in the case, a guy named Satomo Shimomura. And he became involved because myself and this guy living in Israel at the time, Jonathan, hacked into his system because we thought he had the Okie 900 source code. And my hobby at the time was hacking into companies that develop cell phones to get the source code. Jonathan, he had the three letters, right? Yeah, J-S-Z. J-S-Z, I remember. Right, right, right. So I'm not mentioning his last name because I don't know if he's still, I think, a little bit paranoid. But in any event, even though the statute of limitations has run, so we compromised his machine. He actually, it was a bait machine. So he had TCP dump running to probably look for new types of attacks or zero days that would exploit his system so he can capture them, essentially, and kind of profile attacks. So it didn't take him long to catch on that we were in his system. And then I became suspect number one, largely due to John Markoff, right, the New York Times reporter. I became suspect number one every time something went wrong. Anything got broken into? Any computer, any place. Must be Kevin. Yes. Must be Kevin. I saw that happen constantly. Right. So then Shimomura went on a vigilante mission. But what he did, he was able to help the government find me because he was a smart guy. And he said, let's not look, let's not try to trace Kevin back because they should try to trace the calls back. But I had full controls of the switching systems at the phone company. So I was able to manipulate that. I could make it look like it was coming from anybody. So I used to like giving them red herrings. But he had a smart idea. He says, let's not try to trace a call back. Let's just do what they call a terminating number search, which is basically looking for numbers dialed. Right. And they would just put in all the numbers for the netcom pops around the US. And they found, wow, there's a cell phone number in Raleigh, North Carolina, dialing that. And I would change the number daily. But what they were able to do is work out, these numbers were calling it over the last few days. But it was always coming from the same cell tower. Right. So then they were smart. And they would just monitor that cell tower for any data calls. Because if it was a data call, it's suspicious. Because don't forget, nobody was using data back in those days at a dollar a minute. Right. It wasn't a feature that was widely available. No, no, no, no. In fact, there was no such thing at the time. It really makes you realize how much we take for granted setting up like a travel router in a hotel, like just to get online and get data. This is crazy. You're rebuilding it. It's so easy. There's even Wi-Fi's that go like, you know, you have 4G LTE. It's like, oh, my God, I wish I had this back in the day. It's so easy. Yeah. No, but this is stuff you were really building out of just what was at hand. Yeah. So actually, it was actually taking a US old robotics modem and repurposing it and setting it up. So we're using the audio jack on the actual device. Right. So I was able to communicate at low speeds. And eventually, I got complacent. I was using the same fixed location all the time. And eventually, the government, you know, Shimomura, you know, helped the FBI. They actually did radio direction finding, found the apartment. They showed my picture to the rental leasing office. And they didn't recognize me because I was really good at changing my appearance. How would you do that? Oh, I had very long hair. I had a mustache. I would change my weight. I'd change the type of clothes I wear. I'd change my gait, how I walked, everything. You changed how you walked? Yeah, by putting like a pebble in my shoe at first. That's good. That's good. Yeah. I wouldn't think of that. That's really good. Well, I actually read materials on this. It wasn't something I just thought of, actually. So I don't remember. I mean, as a kid, I used to go to this book store called The Survival Bookstore in Los Angeles. And what it was was all the underground books by Paladine Press, if you remember, by Eden Press. So as a 13-year-old, I realized, oh, I can disappear. I can get new identities and this sort of thing. So people will think that I got caught that way. But actually, what really happened is I was actually working out at the gym that night, came home. It was Valentine's Day, 1995. And I just had this really bad gut feeling that something bad was going to happen. I don't know why. It was just like this overwhelming bad gut feeling. So I actually open up my door, go out, and I go over to the balcony, which looks over the parking lot. And I actually look back and forth over the parking lot, and I chalk it up to paranoia. I walk back inside. Ten minutes later, FBI, open up. So it's because I looked out because it was suspicious. Some guy walks out, looks around like something's wrong, goes back in the apartment at 1.30 in the morning. That's how I was caught. Really? OK. I hadn't heard that. So if you hadn't walked out, they would have had to knock on a lot of doors, or would they have just given up? Well, they had a Triggerfish unit device with them, which is kind of the predecessor to the Stingray. And over time, they would have obviously nailed me. But if I got wind, which they did make mistakes because when I went to log into the well and other systems, I'd compromise. I realized all the credentials were changed. So I knew something was up, and I could have possibly escaped at the time. And I would have if I could have. How long were you on the run for? About three years. That's simply incredible. And you went from all different... So you were in Seattle at one point? Yeah, I was in Seattle. I was in Denver working for a law firm. It was kind of funny because all the partners at the law firm were like retired judges. And here I was, a federal fugitive. And they'd call me because their computer wasn't working. So it'd be kind of funny. So I'm sure when they found out later, they were like, oh my God. Wow. Fox in the henhouse. Fascinating. Well, this book is the third in a trilogy. The first two, The Art of Intrusion and The Art of Deception. How is this book different from those two? It's totally different. The Art of Deception was a lot about social engineering attacks. And I had to fictionalize it because at the time the government, there was an agreement that I couldn't tell my story for seven years after I was released from custody in 2000. So I was approached by a publisher, John Wiley and Sons, because they wanted a book on social engineering and how companies could prevent it. So what we did is we took real attacks that I've done over the years and just fictionalized everything. So it's like change the names to protect the innocent. Except me, I wasn't innocent. So in any event, that book was released. It became like a bestseller, at least for in the information security space. And then I was approached to do a more technical book. And I don't like doing super technical stuff because what happens, you decrease the audience. And you don't sell books, right? And the whole purpose is to get the message out to as many people as possible. So then we wrote The Art of Intrusion, which was really interviewing other attackers and getting their really cool stories and vetting them to whatever degree we could. That was Ghost in the Wires. No, that was Art of Intrusion. Oh, Art of Intrusion. Other people's stories. Art of Deception, Art of Intrusion, and then- We haven't gotten to Ghost in the Wires yet. I'm sorry, I'm getting ahead. Yeah, so this book, the coolest story in that book was the first story about these guys that hacked Vegas video machines. And so that was the coolest story. And then time passed. I was finally able to write Ghost in the Wires, which was my memoir. For seven years. For seven years. Okay, so that was about your specific- That was my story, which became a New York Times bestseller. And that was a great book. That was a really great book. Yeah, it was kind of like when I was reading it, I go, this is cool. And then I'm thinking, wow, I can't believe I did all that crap. Right? That's what I was thinking. I go, wow, now that I put it all together, maybe I was lucky. I only got five years. What gets me is they make a stupid movie like Takedown, right? And Ghost in the Wires, that's the movie. That's the story right there. I have a guy working on the script. He's a TV guy in Los Angeles. Adapting it so that it can be a screenplay. But the thing is, it's like a project that is more on the back burner because he already has contracts to do other TV shows. So those are first priority because that's money, right? And contract. So he's also working on my script. It was supposed to be done this year. I mean, 2016. So I'm just being patient. And I really believe in this guy because he's a really great writer. I'll just tell you who it is because I put on Twitter a guy named Jeff East and he does White Collar and Graceland. So if you ever watch those shows. And so I'm just being patient. And, you know, when he gets it done, he gets it done. And then hopefully a production studio will like the script and they'll agree to make the movie. But who knows? Hollywood's a funny thing. So, you know, I'm not keeping my hopes up. And just to keep it clear, this movie, we won't have to go out and protest? Hopefully not. Okay. Don't forget, unfortunately, you give up your rights when you sell your movie rights or your book rights. Basically, now the studio owns them. But since I'm working with the writer, I'm telling the story, I really believe it will be, you know, in a truthful fashion. It will be the truth rather than trying to fill in the blanks with falsities because you don't know the real story. Well, there's certainly no shortage of new studios and methods, maybe a streaming service or something that actually produces it. But as long as the stories get out there, I think that's important. You're not stuck with one mode. But definitely letting it develop slowly is the right way to do it. Right. The techniques that were like in this book that I used, you know, back in 1995, a lot of them were not available. We didn't have Tor, for example. It would have been a lot harder to track my location. Right. So I didn't write the book to, you know, to so people could evade the law and escape. That wasn't the purpose of it. It was really how about journalists and dissidents and privacy activists that really have a need to protect their privacy. Then I get into a more of an advanced section in the back of the book, which really the secret to me is separating your initial connection to the Internet from your true identity. The first connection, because you get all these VPN providers. Oh, we don't log. You know, we don't keep connection logs. You know, that's all bull. Okay. They all do. Right. They have to. Yeah. So. Just got to watch your language on the radio here. Oh, I forget. I had to hit the button. So, yes, we're safe. Yeah. Definitely. That last statement about this isn't right was a huge breath of fresh air. Otherwise, you know, it might have been far harder, but I wanted to also touch on what Emanuel said, that prior to 1995, when both Kevin and I were apprehended by federal agents separately, the entire community really had not gotten its feet wet in the activism area. area and uh... i am really glad that being around the beginning of when that was happening being the center of it is kevin was uh... and now we take it for granted that hackers activists it's almost one in the payment in a lot of ways so um... i'd i'd really want to thank the listeners to this station who have been listening all that time since the mid nineties and before and and watching this community develop the hacker community develop on w b a i answer twenty six hundred and to the conferences uh... into a really a social justice community and that's what this radio station w b a act is really all about a social justice and how to be really well-informed about what's going on in this world and in in in this speech show particular from a technical standpoint how what's going on and how to protect yourself so this book to kevin is offering up who i thank you for donating them is a is a great way to learn more about i don't know if there's any more copies left but even if they're not a copies but please call the station right now five six eric at five one six six two zero three six zero two and pledge whatever you can to support the station this community of people who really care what's going on in canton can advise you from a technical standpoint how to protect yourself again five one six six two zero three six zero two if you're ready to do it online it's give to w b a i dot org and um... thanks for your support that's what keeps this whole community going you know it's it's interesting bernie uh... it that we just yesterday released volume fourteen of the hacker digest what that is is a compilation of an entire year and five fourteen was nineteen ninety seven that's when we really started talking about kevin bitnick's case uh... and virtually every issue and i i remember going through uh... the letters letters to the editor and we received a fair number of letters that said why are you supporting this guy you shouldn't be doing this is just talk to be talking about technology uh... and there were there were some vocal critics saying that we should not be involved in issues of social justice and we get that to this day you know we're talking about all kinds of horrors are coming in with the new administration and and we get mail from people saying you should not be involved in this at all similar to the way people in hollywood uh... get get uh... uh... demands from people to only do their job and not participate in that conversation it's all related is all the part of the same conversation and you can learn so much by by sharing your expertise and and and just basically uh... putting your own unique perspective onto the whole thing yeah it's not it's not it's not comfortable for us to just be frivolous and uh... and be into the latest gadget uh... for the sake of it these things matter these things have an impact on society and uh... uh... had we not had this uh... this history to tell the world that hackers aren't going to accept judgment uh... lightly uh... we we wouldn't we wouldn't be able to have the conversations we we can have about uh... hacking as a positive thing a positive force for people they're making things that are innovating uh... in in uh... the educational environment and and elsewhere places that really need uh... uh... that to encourage and and uh... have that enthusiasm for technology as we're uh... creating uh... people who will be contributing to society in the future they've got to have these tools they have to have an understanding of this stuff and not just sort of passively accept what uh... authorities say to them or what uh... an application is forcing them to do based on someone else's uh... choices for them and uh... yeah that's that's part of what we we try to get out uh... through the magazine and uh... and it's it's grown and evolved and it incorporates all of these different things uh... as uh... as an initiative for a really really large community and and a diverse one at that yeah i've always felt the uh... the activists in the hacker worlds are are very very naturally intertwined i was never an activist who decided to become a hacker i was i was a hacker who used a hacker outlook who uh... was interested in seeing how things are seeing how things work seeing how things could be improved how they could be subverted what have you and this knowledge led me to things that uh... that awaken the activist spark in me and basically uh... brought me down that road so it's uh... it's it's really flip sides of the same coin i think okay an update all the books are gone so uh... if you do call in uh... don't ask for that because you'll be disappointed but you can still get the eleventh hope one hundred dvd collection you can still get the eleventh hope uh... flash drive collection as long as those uh... don't get depleted five one six six two zero three six zero two or you can as as a listener just did simply donate as a twenty five dollar donation thank you very much for that it all adds up at all keeps this radio station going hey kevin well i i said we're going to talk about cloud bleed a little bit uh... and and we're talking about the cloud how people uh... stick all their private information in there and while uh... i guess the reckoning finally happened where all these passwords were were revealed uh... and um... and people's private information guess what it's uh... it's in other people's hands now are you surprised no not really i mean uh... you know the guy who actually discover this uh... uh... so if i'm pronouncing his right name armand armandy uh... he's with the google zero project so this guy is extremely brilliant what is the google zero uh... it's basically a project by google where they have all these security uh... you know very bright minds brilliant minds and information security they find bugs okay and they report them to get them fixed and uh... they make things better right so it's like kind of like google's ethical hacking squad so to speak so the guy that uh... what's his name uh... george holtz was on there once on uh... and he got ian beer and really really some bright bright minds in this so uh... i guess uh... from what i read from what i recall from uh... tavis's blog he was working on a different problem and realized he was getting these chunks of uninitialized memory getting returned to him so he started investigating and realized that there was a bug in the proxy uh... that cloudfare was using that would allow you to dump memory from the proxy right and essentially that's where you could see just you know raw data whether it's uh... ssl or whatever and what he found was you know credentials you know for uh... many of uh... cloudfare's customers and that sort of thing so it was uh... it reminded me of heartbleed heartbleed was you know a very similar bug in open ssl and that allowed you to dump memory uh... a certain amount of memory and uh... and the same issue existed uh... with cloudbleed and uh... cloudfare fixed it but uh... who knows who took advantage of the bug for you know since it existed i don't think it existed for too long i think you know uh... i'd have to reread the blog i think it was like uh... for maybe under a year uh... well uh... kevin i want to thank you so much for uh... for being here and talking about all this and for continuing to do what you do you spend a good amount of time uh... going all around the world giving talks right? yeah pretty much so what i do these days is uh... i run a pen testing company and companies hire us globally to break in physically technically using social engineering testing wireless networks, SCADA, just the whole the whole thing and uh... why they do this is they want to look at you know are their security controls effective and if not how do we shore up our defenses and i'm always looking for really good uh... expert level senior people so you can always send the resume to info at mitnicksecurity.com uh... the other thing i do is i'm on the speaking circuit so i go to lots of different conferences and events and i speak about information security and uh... i work on special projects i'm i'm also uh... a partner of a company out of clearwater florida uh... called know before and through this company we offer simulated phishing attacks so what companies could do is phish their own employees so it becomes a teachable moment when they fall for the phish can you give us an example of how that would work yeah so basically we have a console with a lot of different phishing campaigns and uh... for those that don't know what a phish is it's basically like john podesta just recently got hacked he received an email purportedly from google and uh... uh... that basically said his account was accessed from an unauthorized IP address or something of that nature he sent it over to his IT guy and the IT guy said oh yeah that email's real he goes ahead and clicks on the link puts in his credentials and that sort of thing and that's how his emails were stolen eventually and handed over to wikileaks so these are like typical phishing attacks a fourteen-year-old could do them but a lot of companies are getting victimized with ransomware and the vector is social engineering using spear phishing for example uh... there's another type of phishing where you don't even try to get on their systems you basically just try to trick the CFO or their delegate into wiring millions of dollars it's called CFO fraud and people are gullible gullible enough to actually do it so uh... Stu Showerman and I back four and a half years ago decided hey how can we better train people at companies not to be so gullible so we have a training course but one of the most important things is the inoculation how do you inoculate people from being gullible when it comes to phishing attacks so then we actually let IT departments at companies actually do phishing campaigns against their own users when they fall for them right for the phishing it becomes a very teachable moment and then they can be trained and hopefully through this inoculation process they're going to become much smarter much trained so they can really catch any real phishing attacks that come in the future so I imagine you have a pretty high success rate at uh... at getting into these well a hundred percent when I'm doing security testing a hundred percent get it right through uh... when the vector when they allow us to use social engineering attacks when companies actually test for the first time because you know before they uh... sign up for the product they actually do you know they do a first phishing test you know just and that's not spear phishing that's simple stuff and there's about a thirty to thirty five percent click rate now that doesn't mean they're exploitable of course because you know in a phishing attack you have the exploit the con you have the con and then you have to exploit usually the software that resides on the desktop right or if they're foolish enough to you know click on a java applet then you got code execution immediately but anyway uh... it's amazing how many people will fall for phishing attacks I mean again you know John Podesta did you know and he's Hillary Clinton's campaign manager but this happens in businesses all the time and again what the criminal side is doing is actually deploying ransomware through this technique because that's how they're making money and they're making a ton of money so the ransomware basically encrypts all their files essentially right and they have to pay somebody usually in bitcoin to get it unencrypted and exactly and they actually walk you through how do you how do they make it very easy right how to western union they give you a little tutorial this is how bitcoin works just give us the the the money here and you'll get your files yeah get one you have one bitcoin number I think one bitcoins worth two grand now something like that well it's not that much I don't think but uh... just to quickly point out for any listeners who are unfamiliar but interested in searching out more info this is phishing spelled p h i s h i n g yeah not the kind you do with your grandfather hopefully not and when we use this vector right I've been doing I've been running this pen testing company since 2003 when I was finally off supervised release and whenever a client allows us to use a social engineering and scope of a pen test we've always get it we always get at least find one user inside an organization that gives us complete access to the network so they can say don't use social engineering but doesn't that's not realistic because the average person out there who is a social engineer isn't going to say oh they don't want me to yeah I'm not going to use that I'm not going to violate that rule right but you know the second you know attack vector that's a that works very well today is exploiting web applications that are internet facing that have bugs because companies develop them not using SDLC which is the secure development lifecycle or they buy them from vendors who don't do the same but with social engineering I mean the real work comes in in the information reconnaissance is actually researching the company researching the target trying to get a domain that they would trust from a customer supplier or vendor so once you figure out the trust model that somebody is likely going to fall for actually executing the attack is a simple part the hard part and how do you you can build a target list quite easily you can go to LinkedIn you can put in a company name and you can search for people's positions like network engineer system administrator database administrator and you can quickly work out who has privileges inside the company right but that's not to say that's the best way to get your foot in the door the best way is to target people that are not technically astute right sales and marketing for example so you you get some sales guy because and you're sending a PO which is a PDF file which has been booby-trapped so once the guy opens it you get control of his machine and then once you get your foot in the door of the network then you use technical exploitation to get admin rights on that person's box and then move yourself through the network for example when we get on a Windows network active directory network we always get domain admin always because we use a tool called responder I'm not going to go through with how the responder works because we don't have that much time but you could google it right and basically we're able to capture hashes across the wire and I have a couple of very fast GPU password crackers I get like 900 billion NTLM hashes a second which is the how Windows hashes passwords using NTLM and they'll NTLM v2 900 billion 900 billion a second so if I take it a nine character password I could just crack it in a few hours no matter if it's uppercase lowercase symbols letters doesn't matter right so if you're running active directory and you're not deploying the proper security controls and you this game over right the adversary is gonna get in they're gonna get domain admin and they're gonna get access to everything so when somebody gets the treatment from you as far as the pen testing and they realize how vulnerable they they are and then you tell them the the steps to take are they secure at that point not necessarily because a lot of companies don't take all the steps because it takes time it's expensive in some cases but as you know it's basically maturing their security program so as we test stuff find bugs they fix maybe some or all of the bugs they hire us again six months a year later to do the test again we find the ones they didn't fix we find new ones and it's this constant cycle of trying to mitigate the risk right but it's not just hand in the pen test and everything is you know everything is fine not at all because everything changes every day they're installing new applications there are new people that are joining the company there's always new things to exploit that's right that's that's that's so true Kevin how would somebody contact you if they if they want their company to be subjected to your scrutiny they can go to Mitnick security.com that's M like Mary I T N I C K security.com and that's my that's our company website and I imagine if if they want to get you to speak someplace with the same yeah same way same site you know so through that site we do the services of you know penetration testing and speaking and speak I'm represented by an agent so it goes right to the agent so any any interesting gigs coming up when's the next one next one's in Florida I don't know who the client is but I know it's in Miami then right after that I go to Santiago Chile oh wow speaking for Intel which is their big energy company out there I just did several speaking events for VMware in Orlando which went really well and when I'm doing these events it's not just getting up on stage and talking and showing a PowerPoint presentation I actually show the latest exploits you know the ones that that work when we're doing pen testing so it becomes like a magic show and how I originally gotten into hacking was through my love of magic awesome that's another story for another day Kevin so good to see you again and we look forward to to doing this again in the future having you at a hope conference and all the best yeah absolutely I love being here it's a great to see everybody again and I want to thank all the 2600 supporters for for everything that they've done for me and especially you Eric and I hope to see everybody around again at the next hope conference and don't forget there are 2600 meetings this Friday coming up all around the world do you know we have about a hundred and fifty meetings I just counted them I didn't realize how many we had that's a lot of meetings so a whole lot of meetings but there's there's one here in New York coming up 5 p.m. Friday at the new location right Rob the atrium the atrium on 3rd Avenue by 53rd Street half a block from the Citigroup building we'll be back again I'm not sure we're on next week because next week I think there's some special programming we'll let you know via the website and Twitter account hacker radio show we will see you when we see you have a good night