banjo throwing competition. Don't miss it. Tickets are reasonably priced and the venue is easily accessible by public transit. Visit BrooklynFolkFest.com for more information and for tickets. That's the Brooklyn Folk Festival coming up April 28th, 29th, and 30th. Hope to see you there. Hi, this is Donovan and you're tuned to WBAI, listener-supported, non-commercial radio in New York. And this is WBAI New York. The time is 8 o'clock on a Wednesday and that means it's time for Off the Hook. So I ripped it off the wall. I cut myself while shaving. Now I can't make a cough. We couldn't get much worse. But if they could, they would. Bum-diddly-bum for the best, expect the worst. I hope that's understood. Bum-diddly-bum! Bum-diddly-bum! And a very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you, joined tonight by Rob T. Firefly. Good evening. Kyle. Hey, how's it going? Alex. Comrade. And Voltaire. Hello. Oh, we got a packed house tonight. And we have a lot to talk about. It's a bit of mischief in the air. You notice that? Well, it's hot, but there's also mischief in the air. Sometimes one gets lost in the other. But, you know, last Friday, right after the 2600 meeting, had nothing to do with it. OK, I just want to make that clear from the outset. Somebody set off all the sirens in Dallas, all the tornado warning sirens. Somebody did that. How many, how many sirens are we talking? I mean, all of them, Kyle, all of them. Every single. As if you didn't know. Every last siren. Every last cotton-picking siren. That's a lot of sirens. In Dallas. Yeah, so according to the story that, well, there are many, many stories that came out about this. City officials don't know who triggered Dallas's outdoor warning sirens late Friday, but they do know how it was done. And it wasn't. They were saying the system was hacked. They were saying computer hackers. Every time something happens, it's computer hackers. But now they're kind of they're saying something a little bit different. Now they're saying, yeah, it was done by broadcasting a few tones via either radio or telephone signal. In other words, there wasn't a computer hack at all. It's a radio system, not a computer issue, said Dallas city manager T.C. Broadnax. The city's outdoor warning sirens had to be manually shut down. I don't even know what's involved in that. And then turned back on late Sunday with immediate fixes intended to prevent the type of incident that woke up and shook up much of the city on Friday night. Now, you know, I have some experience with this. I've never activated a siren, but not through lack of trying. Back in the day when the Shoreham nuclear power plant was a threat to all of us and it was it was 95 percent complete and everybody was trying to figure out ways to stop this thing from ever opening up. They had these sirens that were located in a 10 mile radius from the nuclear power plant out in Long Island. And we noticed that the sirens had little radio antennas on them, and we set out to figure out how to to activate those sirens, to find out through through various documents what the frequencies were that needed to be sent, what tones on what frequency. And we had a bunch of people that were really dedicated to doing this. Unfortunately, the plant got shut down before we ever got to that point. But the thing is, it is a good tactic. The sirens go off, especially sirens that nobody understands what they're for in the first place, which was the case in the Shoreham nuclear power plant. And, you know, it would have raised some questions as to, well, first of all, did you hear them? What did it get your attention? And then did you know what to do when you heard them? Things like that. What I see here in the Dallas situation is somebody outlining a system that is so horrendously flawed that all it takes is literally sending out a couple of tones onto a particular frequency. And all of a sudden, all of these all these sirens are triggered. I suspect it probably was something either either a radio receiver or something, a telephone line that's connected to all of the sirens. Easy to find out. Look at the sirens, see if there's an antenna or see if there's a phone line going to it. And then you have your answer. So the next question is what sequence of tones? If it's a radio frequency, you simply have to listen to the radio frequency, see what tones were sent. It's that simple. In many cases, it's that simple. Now, just looking online in the last 10 minutes or so, I'm seeing posts on a site called RadioReference.com talking about Genesee County. I'm not sure which Genesee County this is. We have one in New York, I believe, but I'm not sure if it's there or some other state. But basically, they're outlining various means that outdoor warning sirens can be activated. Direct local control, remote activation via fiber optic lines, telephone line control from a central point, radio control using a two-tone sequential format, radio control using a DTMF string, in other words, touch tones, radio control using FSK packet or satellite control. And I really kind of doubt satellite control. As far as actual frequencies, those of you with ham radios and scanners and things like that, I do know this might be Minnesota. Oakland County sirens are toned out at 155.265. Yeah, so if you tune to that frequency. Also, 154.980 megahertz, 155.265, you know, all kinds of things like that. It's very simple to find this out. The FCC is required to keep this information public. So with a little bit of research, a little bit of technical know-how, and a good sense of mischief, you too can make your local sirens go off if they're set up in such an insecure way. And I think, you know, yeah, it was a pain in the ass to be woken up and to have the whole city of Dallas not know what was going on. But if it never happens again like that, then it does meet the criteria for a public service. Well, what's interesting to me is if this was going to be a system whereby it could be triggered by a radio frequency by some kind of broadcast, then it's possible if the radio waves were not monitored, if nobody was monitoring for this, that that tone could be brute forced, that essentially you could just be broadcasting out tones until you get the right one and you activate every single alarm in Dallas. On the other hand, if, and as I understand the Dallas signaling system was, the packet or the tone that was sent to trigger the alarms was just out in the open, it wasn't encrypted, there was nothing about it. So if you knew what the frequency was in the past, you could be monitoring that frequency, record the tone, and then rebroadcast it. I think it would be that simple in order to activate the entire alarm system for the city of Dallas. It's ridiculously simple and you have to wonder about these legacy type systems that are from a bygone era, that people don't really understand how they work and nobody is accounting for them. Really, it's an infrastructure issue. Not only legacy systems, but new systems as well that nobody understands and that are horribly secured. This makes me very happy. As an old phone freak from the 1990s when we used to play all sorts of tones into the telephone to make it do all sorts of cool stuff, I love that somewhere there's a piece of vital infrastructure that's so incredibly outdated that we can dust off those old skills and put them to work again. Oh yeah, and they're everywhere. They're all over the place. All kinds of old equipment is still set up. I just want to read one more quote from this website. The tones activate a special radio receiver that is tied in with a siren timer and motor control. Usually the smaller areas in Michigan will have a common set of tones that will activate all the sirens for the three to five minutes steady signal, which is used to alert the public for a tornado warning. Then each fire department has a separate set of tones for each siren that can be used for the local fire signal, which is something that we hear all over the place. Volunteer firemen are called by sirens. So yeah, these things can be very simply triggered. Maybe nobody took the time to figure out exactly how to do it. They can also be relatively easily secured so that not everybody can do it. Go ahead, Voltaire. I actually feel like even though this system didn't turn out so well, I feel like in general radio control systems are more safe than any software, like something using a computer. As we saw in the recent with the Iranians penetrating Westchester dams and the same thing in Ukraine, it's important that it's not connected to the Internet. There's no reason to. There's no reason to connect it to the Internet. I mean, yeah, it's more convenient, I suppose. But we've had these things before without them being connected to the Internet. It just adds a whole other level of vulnerability, and it's really not smart. The problem with Internet software connected ones is you're always tempted to make it with government contracts, get it as cheap as possible, and it's cheaper when you're able to have a remote IT admin. So you're always going to have Internet connected ones. Yeah. Go ahead, Al. Well, I think you bring up an interesting point, Voltaire, in that it is some sort of security feature that would require actual physical presence in Dallas in order to activate all of these as opposed to doing something remotely from a network. So in that sense, I guess it is somewhat smart, but having the ability to simply broadcast that tone without any method of authentication or handshaking whatsoever is totally crazy. Yeah, absolutely. I'd like to ask, actually, Kyle, you and I were in Amsterdam once. I think it was the first Monday of the month, and they always test their air rate sirens at noon on that one day of the month. I'm not sure. I might have the day wrong, but I'm sure they have it right. I'm sure they have a system that's secure. Not everybody can simply access and send some tones over and have every air rate siren in the country going off, and they know what air rates mean over there, too. So that could cause a real panic, but I think we could learn something from that particular system. Well, there's all kinds of reasons, I think, in the U.S., but we tend to kind of keep things that do work the way they are instead of completely redeploying something as varied as an array of sirens like this. But from the story, it worked great. It wasn't the technology. It wasn't the way it was designed or set up that broke. It was that people were informed about how it is supposed to work, either, as you said, from a test or from just, as Alex implied, it certainly could be possible, as is possible with a lot of things, that you could just punch different tones on the frequency once you've found that frequency. But, yeah, it's, I guess, a good reason to maybe re-evaluate, if you've got one of these systems deployed in such a way, perhaps another layer or another feature to make it just somewhat less trivial for someone to approach at that frequency and initiate. Do you think they'll ever find the person who did it? My guess is that this may have been some sort of insider who may have had access to the documentation. So that's where I would look first. I would look to see if there are any disgruntled employees, look to see if anybody recently left. Is it important to find the person? Is it important to track them down or maybe just to learn a lesson from this? I think, in this particular instance, we're going to make an example out of this person if they find him because this could be considered some sort of critical alert warning system, you know, about emergency alerts. That's completely insecure and now it will be secure because of this. Totally agree. But people will make the argument that he didn't have to make it this public, that he could have simply blown the whistle and contacted somebody in government and said this is an insecure system rather than wake up the entire city of Dallas, which I don't mind. I have no problem with that whatsoever. I feel like people in Dallas got a taste of what we have in New York constantly, which is jackhammering, waking people up around midnight, and I'm perfectly happy with that level of suffering. When I read that story, I had a little bit of schadenfreude. When I read it, I said absolutely. People in Dallas finally understand what it's like to live on my block. Go ahead, Kyle. I was going to say that the tornado sirens probably are more of a wail than the ones Emmanuel and I heard in the Netherlands, but it kind of depends on the type because some of them can be more like an industrial buzzer and others more like a traditional siren, and it depends on the purpose, the reason it's installed and what people are using it for. But it's important that we have the system in the first place so that it does work when we need to alert people. By the way, just to put this in perspective, we're saying they woke everybody up in the middle of the night. They went off at 11.40 p.m., so that's the middle of the night in Dallas. That woke everybody up in Dallas. It is. Yeah, that's something like that. People go to bed around 9 p.m. there. The other really interesting bit about this, and I think we touched on it briefly before, is the mischaracterization of what happened initially. Somebody had referred to this as a, quote, hack, unquote, and then everybody presumed that there was some kind of network-based attack that caused this to happen possibly from a remote actor, a state like Russia may have been involved in this. This actually reminds me of an old story, and I believe that I told this story at a Hope maybe 17 years ago or something like that, whereby long before I was a lawyer and I was a young teenage kid, we, meaning some colleagues and I, and actually some people with whom we do a lot of work these days, had figured out a way by hacking into a PBX system, a PBX, a private branch exchange, the external link into an internal phone system for a major department store that has since gone out of business. We were scanning around trying to find a modem, a carrier. We got a dial tone. We realized it was a PBX. We couldn't figure out the four-digit code in order to get into this PBX until one day my now colleague had said to me, try the first four letters of that store's name. And we did that, and it let us right in. And because he had worked at that store, we knew all of the internal codes for the phone system. So this was a, quote, insider threat, unquote, is what happened. So we could be anywhere. We were sitting on the shores of Morocco and dial 516-467, blah, blah, blah, blah, hit the four-digit code, and then once we got into the internal system, dial 71, and it would transfer our call over to the store's PA system. And we had complete control. This is a 16-year-old with complete control over a store's PA system. So we wreaked havoc all over the place. And at this point, they had no clue that there was any external link into their internal phone system. So what this store started to do was they thought it was somebody in the store picking up the phone. They stopped trying to catch shoplifters, and they trained all of the security cameras onto the phones in the store. And they were going to catch that culprit who was picking up the phone and making these crazy pages. And we did, you know, we read the entire first page of A Clockwork Orange over the loudspeaker. We played ministry. We did all kinds of horrible things. We used to put things on sale. We had to close the store early. They only realized that they could terminate us by making a page over us. So you would have, you know, 3 or 4 seconds before somebody, you know, shut off your rant of expletives or something like that. But it's the same thing. People don't understand how it happened. They mischaracterize it as a physical security event. And here, they're mischaracterizing it as a network event when it actually was a physical event. So we've gone full circle here. That's really the point of that story. I'm shocked at your actions in the past and how you caused this multi-billion dollar story to go out of business. Oh, that's not an admission. I never said I was involved. Oh, okay. All right. Yeah, perhaps. I'm also curious how this works. Like if, say, this person who may or may not be found was broadcasting on a certain frequency, does one siren have to receive that signal? And then does that trip the entire system of sirens? Or is it about the broadcast radius of the initiator of that signal, that false signal? Because that would then say like, okay, we can figure out where this transmission was from, if it was even recorded. That kind of thing. That is the information I think would be detailed in finding the perpetrator if that was really. I suspect if it was a radio signal that every siren has a receiver and received that signal. If it's strong enough. Yeah. Because Texas is big, right? There's only Dallas. Oh, it's just Dallas. Yeah, so it's not that hard to get a repeater and simply broadcast tones on that frequency. Sure, you could do that. Or a phone line too, although that's more expensive to have a phone line running to every single siren. And it's also more prone to failure. Whereas over the air is likely to keep broadcasting even during a power failure. So, you know, if the person was smart, I don't think they're traceable. I don't think so. Unless they start bragging about it in bars, and sometimes that does happen. Yeah, I guess even in a city it's close enough if they're broadcasting at all to set the whole system off. Now, we have a couple other things to focus on. A couple of the technological things. But first, before we move on to that, I just wanted to tell the folks at Hectory Voltaire maybe you can help with this. Through our social networking Twitter account, we will be taking questions. Are we taking questions online? Is that how it works? Questions and comments. Questions and comments. This is in addition to the phone line. We have a phone line. But with the phone line, we're going to be taking phone calls a little bit later on. We're going to ask people who have not called before to call us. All right? And we'll give them the phone number too. Don't call now because if you call now, it's just going to ring and it's going to time out and you'll get frustrated. The phone number is 347-335-0818. That's our phone number. And we ask that if you've called before, let someone else have a chance because there are a lot of listeners. We hear it all the time. I try to call. I never get through because other people are always calling. And sometimes the same person is calling more than once. So let's hear from some of our newer callers as well. And we'll take those phone calls a little bit later on. But now, via our Twitter account, which is what again? Hacker Radio Show. Hacker Radio Show. Wow. That's because Off the Hook was taken by a seafood place. It's true. It's still pretty descriptive. Yeah. But okay, Hacker Radio Show is our Twitter account. Now, how can people ask questions there? Go to Twitter.com slash Hacker Radio Show. Say Twitter.clown. Is that what you said? Dot com. Dot com. Okay. I'm not sure if dot clown is a new TLD yet. Wow. Okay. Well, let's hope not. Twitter.com slash Hacker Radio Show. And how do they ask us questions? You have to sign up for Twitter and then click the compose and it should automatically have the at sign on it. Okay. And they can direct message us too? Or are they tweeting publicly? No, I think it has to be public. Has to be public. Dot sign Hacker Radio Show and say whatever you want to say to us. Okay. And you have a device there that will automatically read this and you will forward us the questions and then hopefully we will have the answers. Yes. Okay. And unlike the phone call and you can say one of the seven dirty words. Yeah, but we can't. Yes. We can't. We're not going to repeat it. No, we're not going to repeat it. You're welcome to use those. Yeah, if that makes you feel better somehow and I know a lot of people do feel the need to use those words when talking to us. It might help them get their point across. Might. I think we should start taking questions and comments by fax. You know where the fax machine is here? Because I don't. I think it's right under your desk. Right over there. You've never seen it. Don't give me ideas, Alex. All right, all right. We're going to get to faxing later. Okay, yeah, I'm sure we will. I will drag a fax machine in here. I will. You will? I'll make that happen. I don't want to see it. Burger King, if I can say, Burger King has put itself into the news recently because United and Pepsi have been hogging the headlines. So Burger King decided to hijack the Google Assistant. And what they did was, they put out this 15-second ad. You might have seen it. It features somebody in a Burger King uniform leaning into the camera before saying, Okay, Google, what is the Whopper Burger? And what that does, it doesn't play porn or anything like that, which has happened before for other requests. But basically, anyone who has a Google Home device near their television set, that weirdly phrased request prompted the speaker to begin reading the Wikipedia entry for the Whopper. It's a clever way of getting viewers' attention, but it's also a really quick way of getting on viewers' nerves. And there's a sampling of various reactions that do, in fact, use some of the words that we can't say. But here's what happened. Google Assistant basically shut it down. Yeah, Google shut this down. And now, if that ad airs on your television set, you will simply see the light go on, and then the light will turn off. Now, from this article in Ars Technica, Google's shutdown of the feature is interesting. The ad will still wake up a Google Home. The OK Google phrase will light up the device. The little lights on top will spin while it waits for the query to make a round trip to Google's servers. Google Home will no longer dutifully recite the burger's ingredient list, though. Apparently, Google has made changes so that Burger King's specific recording of the phrase will no longer trigger a voice response. Instead, the Google Home just quietly goes back to sleep without any response to the query. And having a live person, though, if you're next to your Google Home device, you can still say, OK, Google, what is the Whopper burger? and get a full voice response. Android phones, a little more secure because they recognize your voice, apparently, so it's only going to respond to you. But I found this interesting. I've noticed the same thing on Alexa, that when something plays on television where somebody is saying something to Alexa, it'll light up, but it won't respond. So I think this programming of a certain frequency of voice from a television commercial or something like that is not that uncommon. I think it's being done on a regular basis. Rob? What's fascinating about this, I mean, we covered a story a while back where a news story talking about somebody using an Alexa unit to buy a dollhouse caused everyone who was tuned to that station and had an Alexa unit to themselves get a dollhouse bought for them, or at least the attempt made. And what's really an evil genius level move on Burger King's part about this is that when you ask Google things, it tweaks your Google Ads algorithms and such. So they're not only making you listen to your gadget read you the Wikipedia article for the Whopper, but it's also throwing Burger King into your Google Ad history, which then tweaks your Google Ad algorithms across the board, I believe. So they're really insinuating themselves in your online experience further than they knew, at least until it was shut down. And what's also interesting is this, you know, okay, Google gets their information from Wikipedia, and there was evidence that a PR person for working for Burger King themselves edited the Wikipedia article to be snazzier sounding and more PR sounding for when this went live. It's since been reverted. But there's really multiple levels of evil going on here, and it's kind of impressive. It's interesting. They say with this ad airing nationally, Burger King is opening the door for an editing war. It risks having a malicious editor make the Google Home say something inappropriate when explaining the Whopper. So these are 21st century problems here. But, you know, to basically prove the theory that this is something that has to be done on a case-by-case basis, I imagine anyone who has a Google Home device near the radio right now is going berserk because we're probably triggering it over and over again. In fact, if I say something like, okay, Google, initiate self-destruct, oh, I messed it up, I'm sorry. Okay, Google, initiate self-destruct sequence. Yeah, hopefully that works. And I don't know what will happen. What's the most annoying thing you can say to, okay, Google? Anybody know? Or Alexa? It depends on what it's activating or how it's configured, what it's connected to. Exactly. Yeah, it's entirely circumstantial. So it really depends. But yeah, open blinds, turn off this, turn on that. And yeah, I think that over and over again eventually would activate some things. Alexa, can you hear me? Now, if your Alexa answered yes, then we know that we can trigger it until somebody at Amazon turns that particular phrase off. Yeah, so if we were to say something like, Alexa, play Never Gonna Give You Up. Oh, boy. Yeah, there's all kinds of annoying things you can do. Okay, Google, count down from 1,000. That'll keep you busy for a while. Yes, Voltaire? Do you think the Dallas tornado was caused by somebody saying, okay, Google, initiate Dallas tornado warning system? No, I don't think these two technologies are interrelated yet. But the thinking behind them, I believe, is. Kyle? Has anyone checked to see if you say, okay, Google, what is a Big Mac, if that works? Because then you realize they're getting a monopoly on voice-activated descriptions of burgers, the other chain, with their sandwich. So by doing a dumb marketing thing, Burger King kind of self-selected themselves out of being described on these devices. And one other thing I want to say is, remember that these are the quirks of them advertising this stuff to you. Yeah, they need to sell it. You need to be a subscriber of this technology. Question that a little, you know? Yeah, and this whole Internet of Things business that we're being subjected to. You said a story a couple of weeks ago. Dishwashers have a directory traversal bug. Utterly predictable vulnerability advisory on the full disclosure mailing list details CVE-2017-7240, which basically, it's a built-in web server that's used to remotely control the glassware cleaning machine from a browser. The corresponding embedded web server, PST10 web server, typically listens to port 80 and is prone to a directory traversal attack. Therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aid in subsequent attacks. That's according to this particular notice. Directory traversal attacks let people access directories and data they really shouldn't be able to reach as a sensitive configuration files for your dishwasher and similar stuff. This information can be exploited to potentially seize control of the at-risk system. In other words, you can gain a foothold to potentially hijack the machine, infect it with malware. And because the company that makes these things is an appliance company and not an IT company, they don't really have a process for fixing security bugs. So the researcher who noticed this particular vulnerability contacted them, never got a response. I contacted them back in 2016. So the message in this particular story, which was on the register, appliance makers, stop trying to connect stuff to networks, you're no good at it. And why does a dishwasher have to be on the internet? Seriously. Give me one good reason, Alex. So you can infect it with ransomware. Yeah, that's the only reason. That's the only reason. It's not a good reason, no. This type of vulnerability is ridiculous that it still exists today. Way back, I would say, in 2012, 2013, when IP-enabled video cameras were first being promulgated widely around the United States and people were using them, they were very often compromised because it was very similar. They're essentially web servers connected to a camera and web servers that would run Apache. And Apache ran on Linux. And most, well, a lot of these IP-enabled cameras, the default logins were never changed or they were hard-coded with certain credentials that were easily identifiable or recognizable or findable. And at that point, once you root this IP-enabled video camera that's running Apache, it's also running on top of a Linux system. And then on your network, you've got a rooted Linux box, which is not a really good thing to have in terms of your information security posture. Now, other machines on your network are now vulnerable because of this. Absolutely. There's a way in through your damn dishwasher. And there's a way to do lots of bad things with a rooted Linux box. Wow. Rob, go ahead. There's a common expression in the InfoSec community, there's no such thing as the Internet of Things. There's other people's computers in your house. So, Voltaire. Yes, I'd like to preempt any listener that wants help removing viruses from their dishwashers. Yeah. Yeah, after our show, the personal dishwasher show is on. You should direct those questions there. Contact the personal dishwashing people. Wow. You know, I don't think I could have guessed that we were going to get down this road 20 years ago. It's that app space on the phone that the distraction device must have an alert, must have a way to contact you, and these servers as a part of the device's design allow it to interact with the app. Unfortunately, a whole lot of other things, and of course their app may not get a lot of the attention it needs as far as development, and that creates a potent concoction for these scenarios. Some people saw this sort of thing coming 40 years ago. There's an old movie called The Demon Seed based on a Dean Kuntz novel, and it's about a woman in the future whose everything in her house is controlled by an intelligent computer, and it doesn't go well for her. Highly recommend it. Walter, do we have questions yet? How many hackers did it take to screw in the light bulb? Okay, that's not the kind of question I think we're looking for. Questions for the show, questions for us in particular. Anybody have anything to say? Hacker Radio Show is our Twitter account, and we'll be taking phone calls in just a moment, too. We'll give out the phone number again in case you missed it. Nothing? Nothing appropriate to read. Oh, really? So that's how it's going to be. All right, all right, fine. We can play this game, too. Well, okay, speaking of social media, this has been a little bit abuzz in social media. The new issue, which we talked about last week, which is out and causing a stir thanks to the bounty for the Donald Trump tax returns and a list of White House phone numbers, but also a list of the inner circle of the Trump administration, uncovered something a bit strange that maybe our listeners can investigate further. But apparently, according to the New York State Board of Elections, a particular Jared Kushner identifies as female. Yeah, look it up. It appears on page 22 of the spring issue of 2600 Magazine. And if you look, you will see that there is a field that is either M or F under every person that is listed there. And in this particular case, it's F. Just very interesting. I don't understand how that could have happened or why that happened, but that is how he is registered. He is registered as female with New York State Board of Elections. So you mean she? I'm sorry. Yes, you're right. I don't know what to say now. But if we get some clarification, that would be nice, you know. I don't know how you make an error like that if it is an error. But that is a fact. You heard it here first on Off the Hook. So I don't say we don't bring you breaking news. Okay, now we also have a story concerning Twitter being threatened by the Trump administration. And Twitter has turned around and sued right back, basically suing the Trump administration after Trump tried to compel the social media site to reveal the identity of an account that had been tweeting criticism of the president. This was the alt agency Twitter account. I can't remember which agency this one was. CIS. CIS, that's right. Yeah, it was Customs. Customs and Immigration Services. That's right, yes. Okay. Under Homeland Security. So there were all these accounts that are tweeting basic forms of criticism of the Trump administration. Often these individuals controlling those accounts had been or were in some way affiliated with the previous administrations or in that agency prior to the current administration coming in. So the Trump administration really took an interest in this particular account and demanded that Twitter hand over what information specifically? Alex, do you know? Well, it's rather interesting as a matter of fact because this particular account was highly critical of immigration policies, highly critical of all different types of things that were coming out of the Trump administration and it was stated that this was a current federal employee as well that was associated with the particular account. And what was requested was a lot of identifying information from Twitter about this particular user who was behind the alt CIS account, namely IP addresses, home phone numbers, the address associated with this particular account, the email address that was associated with it, all different types of very technologically focused data designed to unmask, as the word is bandied about these days, the identity of the individual behind the account. And what's rather curious about this is that the summons was issued by a special agent in charge, I believe, of a CIS office in Miramax, Florida, or Miramar, Florida, and it was faxed to Twitter. I told you we were going to get back to faxes later on and here we are. Wow, okay. It was faxed over to Twitter. People don't realize that for lots of big corporations, legal process, summonses, subpoenas, and things like that are often very times served via fax and they will accept it via facsimile. In fact, we just did this this week for a couple of subpoenas. So it was faxed over there and it was under the authority of a particular statute that has to do with CIS. It was 19 U.S.C. Section 1509 and this has to do with CIS's authority to cause importers of goods to produce certain records that relate to the importation of goods, ostensibly to determine if the right taxes were paid, if the right duties were levied, if there are penalties that should be associated with the failure to pay duties or fines, and it's all about these particular records that importers by statute actually have to retain because they're importers. So what's really clear just on the face of it is that this person who is behind the alt-CIS account had nothing to do with the importation of goods into the United States. It's totally crazy. It's beyond the pal nuts that somebody would issue a summons from a federal agency to an organization like Twitter and request documents that could unmask the identity of an individual merely for criticizing the policies of the government. Especially under a statute such as this does not at all pertain to any of their activities online or off. So is there a theory as to who is behind this? Who is behind the particular account? Yeah. No, behind the demand for more information if it's coming from some account that has no business asking in the first place. Oh, well, the summons was drafted by a special agent in charge, and it was sent over to Twitter, and then in response Twitter had filed suit in the U.S. District Court in San Francisco seeking declaratory judgment and an injunction. And essentially what that means is that they're asking the court to declare this as unconstitutional, as ultra-vera, as outside of their normal authority, and enjoin them from trying to enforce this particular summons because it is so crazy and out there. And what's rather interesting is that this was a non- and this is something that is not widely reported, I guess, but this was a non-lawyer who issued this summons. As far as I can tell, the special agent in charge who drafted this, I don't know if he has a law degree, if he's a member of any bar, but there were a lot of errors that went into this particular summons. It was littered with errors. It was probably never really read through, and if it was read through, that's even worse. And we'll get to these errors in a second. Okay, yeah, I'm curious what they are. It was a non-lawyer who drafted this, and nobody really came to the defense of this particular agency action and this particular summons, and I think that's because it is so legally indefensible that no lawyer would put his name on an argument trying to defend this crazy action. There is an obligation in federal court not to file frivolous arguments with a court, and I don't think there's no way to make an argument that's not frivolous. I guess the other way of saying that is it would have to be a frivolous argument if you're going to defend this, right? So nobody came to the defense of this particular argument. Now, some of the errors that were found in this particular summons were, I believe it was faxed, again getting back to faxes, on March 14th, and it called for the production of records on March 13th. So the day before it was sent... I've run into that tactic before. You have, I bet you have. You have to bend time to see to their demands. Well, yeah, I mean, Twitter is an interesting organization. They probably haven't perfected time travel yet, though we don't know. That could be being held as a trade secret. But that was one error. Obviously, it was an error to use this particular authority under the U.S. Code to try to obtain these particular records. And then there was this other rather interesting wrinkle to it as well, where if the person whose records were being summoned by CIS wanted to tell Twitter not to comply with this particular summons, then they too had to tell Twitter not to comply also by March 13th, the day before, in order for that to be effective. And then they had to do this in writing, and it also had to be faxed over to the special agent in charge who issued the summons. So this completely idiotic procedural mechanism is included in this summons that would, if you utilized it, unmask the identity of the person behind the account by virtue of you saying you don't want them to comply. So none of it makes sense whatsoever. This is a totally bizarre action, but the complaint that was filed in U.S. District Court in San Francisco, I encourage everybody to read it because reading legal complaints is not really a lot of fun, but this one, it seems like the lawyers who were behind it had a really great time destroying this argument on constitutional basis. And this was dated, what date did it actually come out? Was it April 1st? I don't know. Are you thinking there's some kind of joke component to this? Well, I'm wondering now. Yeah, it could be. It's possible. I'm not sure. I don't think so. This is totally nuts, but the complaint in this, you don't generally see screenshots of tweets in complaints, and they really had a lot of fun with this because one particular paragraph, and I'll read you the actual quote from the paragraph. They're talking about the importance of speech and the importance of anonymity and how Twitter allows you to be anonymous and to publish under an anonymous name. And essentially this is a historical act that we have enshrined in our history of the United States. For instance, they even make mention of the fact, and I didn't realize this, or I didn't remember it until recently, but the Federalist Papers by Madison, Hamilton, and John Jay were published under a pseudonym. Is that precursor to Twitter? Yeah. Well, yeah, something like that. Founding fathers knew what they were talking about. Absolutely. They saw this coming. Absolutely. They published under Publius. There's some other people in the room that probably know a little bit about publishing under pseudonyms. I'm not going to stare at them or anything. Okay, yes. In any event, they had a lot of fun with this particular complaint. At paragraph 27, and this even goes back to a lot of the other stuff that we've been talking about for weeks, they write that some accounts, speaking of all of the other alt government accounts, some accounts appear to equate the simple act of broadcasting facts as an expression of dissent. And then they have a screenshot of global warming statistics with respect to El Nino and that the simple statement of a fact about global warming coming from one of these alt accounts is protected political speech. And it's anonymous speech. And because it's political speech and anonymous speech, it should be doubly protected. And then at that point, the government has to have a really compelling interest to unmask the identity of the speaker in the absence of some kind of civil offense or criminal activity. So we're not talking about here, and this is really important to note, that we're not talking about a situation where somebody is discussing classified information. They're talking about what's happening in federal agencies. These are the people that are best situated to let us know if there's fraud, if there's waste, if there's abuse, if there's totally nutso things happening in the Trump administration. Their voices are more important than ever. And the fact that nobody came to their defense gives me some hope that at least the Trump administration's lawyers have a semblance of duty left in them. The thing that fascinates me about this is in response to the Trump administration, there have been a slew of Twitter accounts and other social media things that claim to be people in various federal agencies, people in various government jobs who are tweeting all disgruntled about what's going on there. I could write in my Twitter bio that I'm the guy who cleans the gunk out of the White House chicken soup machine, but are these people at any extra legal risk because they're claiming to be government employees? They could be because I think they could be targeted, they could be unmasked, they could suffer some form of retaliation in the workplace as well. I think it's a dangerous position for them to be in. The Intercept actually published, I don't know, maybe a month ago or so, a really interesting article, and maybe we can tweet this out later, about how to anonymously set up a Twitter account. That's what I was going to ask because the things that you made reference to before, phone numbers, email addresses, physical addresses, why does anybody need to give that information to Twitter? Now I know it's required now that you have a phone. You can't get a Twitter account unless you have a phone number. Is that correct? I think so. All right. So Google Voice, you have a phone number that forwards to a different phone number. That way you get their particular text message when you need to get it, and your anonymity is preserved. Mailing address, you simply do not have to give them your mailing address, you don't have to give them your real name. There are so many things you don't have to do that people assume they have to do so that your identity will be protected, even if something like this succeeds. And this did not succeed. In fact, we should point out, the Trump administration on Friday said it would withdraw the demand that the social media company Twitter unmask an account critical of the president. So I guess they got the message, but they still tried to do this. Well, there's two other sides of this as well. And one is that, and this gives me great heart, that Twitter isn't just willy-nilly complying with legal process demands as they get them. They're actually reading these things. And that's really, really important to us as users. And if you're going to rely on Twitter to operate an alt account as a federal employee, you need to know that you've got somebody in your corner that is not going to just kowtow to any form of legal process. So I think that's great, okay? This is like real kudos to Twitter for doing this and for hiring Wilmer Hale and Seth Waxman. Well, can you imagine what would happen to them if they didn't do this? Absolutely. If they allowed their users to be prosecuted and identified just out of intimidation, they would become worthless overnight. Well, there's an interesting sort of contradiction as well because you have these social media outlets that capitalize on our personal information, our browsing habits, our tweets. They monetize all that data. They suck it away from us, yet they are protective of our anonymity because it protects their business model. So there's two sides to that coin as well. Now, on the other hand, the person who issued this particular summons either had no idea what his actual authority was under the law as a special agent in charge of a Florida office of Customs and Immigration Services, which is terrifying to say the least, or they were trying to pull a fast one on a social media outlet and unmask the identity of this particular federal employee. In this current administration, does either scenario shock you? Not at all. Yeah, this is par for the course. No? Hey, we promised we'd take phone calls and we're going to keep that promise. And again, please, if you have not called before, we want to hear from you. 347-335-0818. We love the people who have called in already, but we want to hear from more people. We only have one phone line. 347-335-0818. Volter, any more social media questions that we might be able to actually read? What is our favorite hacker hat color? That's what people want to know, our favorite hacker hat color. Well, you're wearing green at the moment. I think our least favorite is red. But my hat says UConn on it. It has nothing to do with hacking. I got it in the UConn. So it's not a hacker hat. I guess because I'm wearing it, does that make it a hacker hat? Maybe that's the secret word that activates the Dallas tornado warning system, is hacker hat. Let's take a phone call. Good evening. You're on off the hook. Go ahead. Speak up. Hi. G'day. It's Nathan in Australia. Oh, my God. Nathan in Australia. Wow. I feel like we've already met you through a Chris Lilley program or something. Yeah. At your first Friday of the month a couple of years ago at the city group center there. We did meet you. I remember, actually. We made the same comment. Okay. How about that? So you're actually in Australia now? Yeah, in Australia, sitting at my desk at work. It's school holidays here, and so I'm listening to the show on my phone and thought I'd call in via Skype. You know, I got to say, you sound better than most people who call locally right now, and you're in Australia. That's amazing. Oh, that's nice. That's nice to hear. You sound nice, too. Well, thank you. Any questions or comments that you'd like to convey to us? I love the idea of having a more interactive show like you're doing tonight, like with somebody following tweets and so on like that. That's probably my comment. You know, hearing good balance between having stories and commentary from your team and having comments from listeners, I think is a great idea. Thank you. Thank you. Hopefully we can do that more in the future. Any other comments? Are you coming back to the States anytime soon? Oh, I'd love to. I always end up there just before the HOPE conference, and so I've never been to it yet. So hopefully at some stage I'll get to come to that. But, yeah, no, I just thought I'd ring and just say good day because I thought it would be a nice opportunity. Well, Nathan, thank you so much for calling, and you've actually reminded me of something that I wanted to mention about the HOPE conference. Voltaire, you had a question? No? Okay. So thank you for calling, and we'll open up the phone line for somebody else. Good night. See you. Bye. Good day, I guess. It's tomorrow over there. But, yes, we have the next HOPE conference coming up in 2018. We're actually finalizing it now, if you can believe that. But one thing we don't have yet is a name. So we would like to ask our listeners to help us find a name. It's the 12th conference. Now, we're not going to name it something lame like the 12th HOPE or HOPE No. 12 or HOPE 12 or something like that. No, we don't do that. But we want to have something that is kind of imaginative. It can have the word dozen in it maybe because it is going to be the dozenth conference, or it can have some kind of a phrase. Remember Beyond HOPE in 1997? That was a conference that used the word HOPE in a different way. HOPE, of course, stands for Hackers on Planet Earth. So if you have a suggestion or idea, email us, OTH at 2600.com. And if you select the winning entry, we will say thank you directly to you when you come to the conference. Yeah. Good evening. You're on off the hook. Go ahead. Hello? Hi, where are you calling from? Hey, I'm calling from LeBron. You sound like you're calling from so far away, and the guy from Australia sounded like he was next door. That's amazing. I'm driving right now. Let me just pull over because I've got a question. I've been trying to present you guys for like the last two weeks. All right, pull over. Let's be safe. Pull over and ask the question safely. Yeah. It's about work for FedEx, right? Okay. Just give me one second. Let me get out the truck because I'm in the truck. Hold on one second. You're driving a FedEx truck right now. Hello? Wow. Yes, you're a FedEx driver, and you're calling us right now from a FedEx truck. FedEx just put some surveillance cameras in the trucks, right? Okay. To watch the driver, I guess, outside and to watch the driver. I'm calling. Is there any way you can fight that or alter that view? It seems like it's an invasion of privacy. So we did get your mail, so thanks for writing us. Oh, okay, okay. You did get through to us, and I'm glad you called tonight. Thanks for asking your question. I've been trying to reach you guys. I love your show. I was trying to get to Live of Hope, but I didn't have a PayPal account. I wanted to volunteer for the Hope. I didn't have a PayPal account. Well, you don't need a PayPal account to volunteer. I was trying to get cash and pay, and they said, no, you can't do it. That's what the young lady was telling me. Well, we can address all those issues, but let's address your FedEx. Kyle, do you have an answer for me? Could you just describe what exactly it is that was installed as far as you're aware? And as far as techniques to avoid, it depends on exactly how the system is designed and what exactly you're trying to obscure. Maybe you want to change the appearance or not appear at all without turning it off. If you could describe what it looks like, what the system actually is. It's a pinhole-type camera with, I think it has, looking on the inside and outside, I think it's the same way as a dual camera. One looks outside the truck and one looks inside at the driver. I have two, I think it says, two sensors or two lenses or something like that. I can take a picture and maybe send it. It sounds like it has something for night vision so it can sense the light level and adjust automatically. I don't know what the pictures look like. I went online. I went onto the site to see. But of course, the company is going to make it glorified in their favor. Oh, of course. My next question was, how was it introduced? Was it a safety thing, like, oh, we had recent things with drivers being… Oh, we're going to protect you just in case somebody cuts you off. No, no, that's not the case, no. Yeah, well, it's going to be a tough battle because you're an employee of theirs and they can set the rules, and a number of truck companies are doing this. In fact, I'm looking at a website right now called TruckingTruth.com, which is really pretty awesome. And they talk about trucking cameras, in-cab cameras that both face the road and the driver. They're basically recording in a loop, recording all the previous footage until an incident occurs. And some of these companies are Arnold, Belevance, Boyd Brothers, Carroll Farmer. I don't see FedEx listed here, but I'm sure they'll be added in the next update. They're on board. Yeah. They're on board because I'm not stressed, but I'm like, well, this is another stress that you're on the road that you've got to worry about. If I'm doing the right things, I can't get on the phone. But then they'll call me for a call. You don't want me to be on the phone, but then you'll call me and ask me things while the camera's rolling. It's like a double-edged sword. So I know I have to either find a new occupation or something. But for the moment, I don't want it in my face. It's making me uptight. Well, you know, here's what I suggest. I suggest that you basically get those thoughts together. Write it up in a couple of paragraphs why this kind of surveillance is bad for you and send it to us. We'll print it. We'll print it in the magazine, and maybe these people will see it and realize, hey, this isn't a good idea to do this. This is causing stress. This is causing issues that we didn't consider. Because, you know, I guarantee if they're just listening now, they're going to say, well, what's he trying to hide? But if you basically put it together in a few paragraphs and make the argument, it might have some resonance. You know, they know what the pressure is that they put on you and how you're going to feel about being invaded like this. But, yeah, I'll send you an email. I'll type it up and send you an email. But I just want to know if there's any way I can fight that, you know? There's always a way. And getting your voice out is the first way. Voltaire, go ahead. One more thing. As far as your meetings, because I know you have a meeting in New York, in Manhattan. I think it was on 3rd Avenue? 3rd Avenue and 51st Street, right? 53rd Street, I'm sorry. Yes. Is it always going to be there or, like, you know? Well, for now it is. For now, they're remodeling the Citigroup building, and we're half a block away, so it's a pretty good location. Because, right, at that time, I'm like, I'm working. I'm listening to you, but I'm working at that time. But I really want to get involved. Well, we're there generally until about 8 or 9 o'clock, so I don't know if you're working that late. Yeah, I'm here from 4 in the afternoon to 4 in the morning. Oh, boy. That's going to be tough. Yeah. But, you know, we'll have plenty of word on the next HOPE conference, which hopefully we'll figure out a way that you can make it there. And it should be fairly simple. Voltaire, you had a point? I wanted to ask the listener, are you unionized? Yes. Did you hear the question? I know you're not, but I love the way you talk. Okay. Did you hear the question from Voltaire? Are you unionized? Well, anyway, I don't want to give you too much of your time. That's all right. Okay. I'm going to assume that was a no. Kyle, go ahead. Yeah. That's an important attribute of this. The short answer is there are many ways you can deal with this, officially and unofficially. I would also suggest to watch how it's maintained. When things are added on to equipment, sometimes there are processes and things that have to be done. And by watching that and getting an understanding, you can get a little bit more insight about how it works. And as Voltaire implied, talk to your managers. If you feel this is impacting your ability to do your job, then you have an argument. You have an argument because you said clearly stresses on the job are already there. This is just an additional one. And if it affects the performance of your job, it's probably affecting other people. Absolutely. And with that, we are out of time. Reminder, write to us if you have ideas for what the next help conference should be called, oth at 2600.com. Also write to us if you have any feedback or thoughts or suggestions for the show in general. Our social media account on Twitter, Hacker Radio Show. Tweet to that. Ask us questions. Give your commentary. And tune in again next week at this very same time. Well, actually, we'll be leaving at this very same time. But one hour earlier, we'll be arriving, and you can listen to another action-packed edition of Off the Hook. For now, this is Emanuel for Off the Hook. Stay tuned for the Personal Computer Show here on WBAI. Good night.