At 11 p.m., Sugar in My Bowl presents bandleader, composer, alto and soprano saxophonist, flutist, imbira, sanza, and lukembi player TK Blue. Join us as we discuss TK Blue's most recent release, Amour, and upcoming club dates. That's Sunday, July 23rd at 11 p.m., right here on WBAI New York, 99.5 FM, and WBAI.org on the web. And you're listening to radio station WBAI New York. The time is 8 o'clock on a Wednesday night. You know what that means. It's time for Off The Hook. But if they could, they would. Bondedly bond for the best, expect the worst. I hope that's understood. Bondedly bond. Bondedly bond. Bondedly bond. And a very good evening to everybody. The program is Off The Hook. Emanuel Goldstein here with you, joined tonight by Rob T. Firefly. Good evening. Kyle. Hi, everyone. I'm here. Alex. Hello, hello. Voltaire. Hello. And hopefully you, our listeners, because we need you tonight. Tonight is the first part. This might actually be our only appearance on the summer fundraiser. Sometimes they put something else on for the second week. But this is an important part of our fundraising efforts. We do this every summer. And we have a special phone number set up for you. Where is it? Oh, there it is. So many phone numbers up on the wall. 516-620-3602 is the telephone number to call to pledge your support to WBAI. And as you know, we have been making valiant efforts to catch up on all our premiums. We are caught up up until the spring drive, which we are busy getting packages sent out to people. We heard from a listener who volunteered to come forward and sacrifice their grab bag, their hacker grab bag. So if you're one of the people waiting for a grab bag from our last fundraiser, and you heard our appeal last week for somebody to step forward because we don't have enough of them, and we're going to substitute something else. Well, we have somebody. We have a volunteer. And we want to thank that person for writing in. But we anticipate no such problems this week. This time, because we have one premium that we are offering. And Rob, actually, this is, again, something that you're stepping forward with to exhibit your incredible talents as not only a hacker, but a hacker painter. And you've come up with something completely different this time. You want to tell us what it is? I have. In the past, and to success, which I very much appreciate, I've done some sets of paintings for the station that are kind of relevant to the things we talk about. I did a set of historic and notable computers. I did a set of historic and notable telephones. I did a set of portraits of people from hacker history. And this new set, which has not yet begun, so there's nothing you can look at yet, but this new set is going to be historic and notable forms of data storage. We don't think a lot about data storage, I don't think, generally, unless we work with it a lot. We don't think about it nearly enough. No, but we have all kinds of things just that surround us all the time that hold little bits and pieces of data that we need. And that's everything from SD cards and actual physical disks to things like flash chips and more historical things like five and a quarter inch floppy disks, punch cards. There's a very interesting set of 19th century punch cards, which I'm looking forward to doing. And just things that over the years people have saw fit to trust with their information. Okay, so basically what you do is every time somebody calls in to pledge, and again that number is 516-620-3602, the amount we're asking for is a paltry $50. Yes, indeed. $50. Which, you know, I don't think you're offering it for enough, actually, because if you go to an art gallery, you will see paintings that you put to shame, to be honest. And I know because, you know, we've hung up your paintings in various places and people come and they comment on them. And sometimes they want to buy them and we don't sell them at any price. But here you can buy them for a measly $50 and you will get a unique painting, one that is made only for you. And it will be of some kind of data storage device, as Rob mentioned, a punch card, I guess that is a storage device. Yeah, a punch card can be a storage device. Lots of other things can be storage device. Whatever you get, you'll also get a little placard that you can mount with it that explains what it is that you've got a painting of. How about a Winchester 10 megabyte hard drive from way back in the 1980s or something? That's a possibility. There's definitely going to be bits and pieces from all across data storage history. So it won't just be modern data storage. Not at all. It can be old data storage. I like to pick notable milestones and bits and pieces from across history. Yes, it is just for a pledge of $50, which I should add, I do have something of an art career going, and that's significantly less than I would charge for a comparable painting that I were just selling to somebody or being commissioned for. But it's the donation I make because it's something that I believe is very important, this station, and it needs your support. And I'm going to get that support by donating what I can because you donate what you can. 516-620-3602. Be the first on your block to get one of Roptie Firefly's classic paintings, this time of a data storage device. You won't know which one you're going to get, but what you do get is going to be the only one of its kind. So imagine if Vincent van Gogh had this offer when he did a show here a while back. How much that would be worth now if you had a one of a kind? I'm not saying necessarily that Roptie Firefly will go down that same road, but it's quite possible that this will be something of immense value down the road. But in any event, it's going to be a really, really cool painting to have in your home, in your office. Hey, why not both? There's no limit, right? Somebody can pledge for a couple of these. You can get as many as you want. There are a limited amount available. I notice, Alex, you're squirming. What's going on? I am. This is really fantastic. I'm pledging for at least one of these tonight. I'm tempted to take all of them. I notice you have your credit card out and everything and a pencil. I'm just wondering about the logistics of how I go about... Well, don't make the phone call from here because it'll go out over the radio and then your credit card information. I don't want to give my credit card out over the radio. I trust our listeners to be responsible and honest. You can also pledge online. Give to WBAI.org. Give the number to WBAI.org and look up historic data storage painting and you'll be able to get it that way. Historic data storage painting. Okay, that's the classification. But it's always best to talk to a human, I think. Yes, and if you talk to a human, ask for the historic data storage painting. That's what we're calling it. We can get a human. That's rare these days, too. Even that's a treat. This is really fantastic. I've got a lot of extra space on our wall in our conference room. And in fact, you mentioned that you really do have quite a repertoire as an artist these days. And actually, as Voltaire can attest to, we recently picked up for our office, our law firm's office in the conference room, a painting, a mixed-media painting made from 1981 by an artist by the name of Carla Andre, who became fairly well-known, I guess. My wife found this, actually, at Housing Works. And it's beautiful. It actually is somewhat relevant to what you have proposed as a pledge tonight, which is it's made from painting, oil painting, and some old punch cards. And they're kind of strewn around the painting. It's made from punch cards? Old punch cards in the painting. And then next to the punch cards are boards. You know, sort of boards that looked really modern back in the 80s, but look so anachronistic today. So I could see this is going to go really, really well. If anybody, I mean, I imagine a lot of our listeners work in technology, this is going to be really cool for your office. I mean, this sort of demonstrates the type of person you are. It indicates that you support public radio, that you listen to off-the-hook, that you are a fan of art. And to be really quite honest, for $50 to get something originally made by Rob T. Firefly, this is a steal. But Alex, you've left out the most important part. What is that? Supporting the radio station. I think I did say that. Oh, did you mention that? I'm sorry. I think I did. There were so many things, I lost track. But yeah, that is the most important thing, keeping this radio station on the air. You think so? Broadcasting from that big old Empire State Building, as long as we're able to. And basically just saying, I'm a proud listener to off-the-hook, and I put my money where my mouth is. I think the fact that you can get this kind of deal on WBAI is reason enough to support the station to keep these kind of deals going on. I mean, I'm frankly possibly tempted to snag them all, but I really don't think it would be fair. What, all 15 of them? Yeah. That's the number we have. We could do that. We've got a lot of space on our wall. Wow. Okay, well, 516-620-3602, you better call fast. You better do it. Absolutely. Because they could disappear. Now, Rob, how big are these paintings, and what are they composed out of? These are acrylic paintings. They're painted with acrylics on a five-by-seven stretch canvas, so five-inch-by-seven-inch, which maybe if you've got a large wall, maybe you want more than one. And also, I should direct listeners, if you're curious, if you haven't seen my work before, you can go to robvincent.net, and right on the front page there, there's a link to where you can look at the pass sets that I've given away on this station, plus other work I've done, and get a taste for what sorts of things that might happen with this new one. All right. Again, 516-620-3602. Ask for the Historic Data Storage painting for a pledge of $50. Get as many as you want. And if for some reason you don't like paintings or you don't like art, you can still pledge. And there's all kinds of other premiums that are being offered here at the radio station. You can just ask or give a look around the website, give2wbai.org. But I think this is the one to pledge for this hour. Yeah, how we thank you isn't necessarily as important. It's really the gesture you're making to this community. And we have a variety of things to send to you, and this is one of them, but it doesn't really compare to the commitment that is to WBAI. I just want to mention the two other ways you can just give to WBAI.org and also the short code. Oh, yeah. You can SMS donations. Let's see if I'm doing this right. It's just WBAI and you text that to 41444. So you can text 41444 and just simply input the letters WBAI. And you'll probably be texted back and you'll have to incur whatever message or data fee. I might do that right now because I'm curious what happens. I also want one of these damn paintings. I didn't mean that, Rob. They're great paintings, but I really want one of them. And we already have paintings of yours hanging up, but they call for more. They really do. What's the one we have hanging, Kyle? We have a police call box. That's right, the British one, right? Yeah. Wow, that's pretty cool. Again, the number is 516-620-3602. Ask for the historic paintings and historic data storage painting for a pledge of $50 and I think you'll be pleased with that. I'm going to try texting that number just a little bit. Yeah, see what it says back. It'll probably prompt you for the amount that you're going to pledge and then give you some sort of verification and maybe a transaction number of some sort. Check it out, though. If you just want to SMS, it's WBAI to 41444. Another thing we are keen to remind you of is the WBAI Buddy Program, which is another way you can basically sponsor the station, but it's continuous. So you're basically committing to, say, five bucks or 99.5 cents. Whatever it is, you're basically paying you can sign up and basically every month of the year, just like your water bill or internet or other costs, it'll be deducted and... Sorry, that's my phone. Clearly you've just donated. No, I didn't actually. I was about to. It knows I'm going to do it. Regardless, the Buddy Program is something that goes on all year and basically has you donating throughout the year, and that is a way for us to guarantee that certain costs and revenue will be there for the station to pay for transmitter fees and other incidentals that are required for this year. Fair transmitter fees, not ones that are 100 times the market value or whatever. That's right. It's not an open tab for the Empire State Building. We handle that and by you giving us that money that allows us to do that behind the scenes and we don't have to appeal all the time. This is a special time of the year and we're asking you, we're asking our listeners, please give us a call or text 41444 WBAI. I am doing that right now. I texted WBAI to 41444 and my phone is now asking me if I really want to do that. This may result in charges. It's not going to result in charges. It's just a simple text message. Your phone probably is detecting that it's a short code and not a phone number. I've sent the message and I have received the message in return saying, thanks for your pledge to Pacifica. Complete your gift here and a link. My data plan is horrible and here it is finally. You have the ability to pledge $25, $50, $100, $25, there's all kinds of possibilities. One time weekly, monthly, quarterly. You simply enter your first name, last name, mobile number, email address, and credit card number. It's that simple. You can do it all by your phone. This is really easy. I'm not going to fill in right now but it's 41444. Simply text WBAI. It's a new high-tech method of pledging. That's the way it works now. It may change in the future. We're trying these things. This is part of keeping the station going with a variety of options out there. We hope you'll choose one of them. How do we get such a cool number, 41444? It's such a good number. It's a good short code. I don't know. Thanks for that. No problem. Anytime. Let me ask you a question about that particular link. You text 41444. You text WBAI to that. Then you get a link. From a drop-down in that link, you can specify that you want the artwork. I haven't done that part yet but I imagine that's part of it as well. You do have an imagination. Let's hope you're right about that. I'm not going to fill it out right now because I'll be all distracted. I'll pledge at least. I'm not sure if it links to the premiums or if there's another page that comes up after you do that. I can tell you that after the show. I'm going to be doing it right now. It puts it all right there and it allows you to quickly make this transaction. It's a new way to do it but definitely a worthwhile and fairly easy-to-use way to contribute. This is a big part of keeping the station going. 516-620-3602 the phone number. Talk to a human. Or you could go to give2wbai.org whether live or later on. Search for the Historic Data Storage painting. If there are any left, you can grab one that way. Of course, if you're not into paintings, you can still donate any amount. You can even go onto the give2wbai.org site and look for some other premiums that WBAI themselves have for you and see if you can donate in the name of your favorite show, which we hope is off the hook. It's one of my favorites. If you do that, go to give2wbai.org or call 516-620-3602. You'll be doing the only thing that keeps the lights on around here all year round. Not just when we're doing this fundraising sort of thing. It's the only thing that keeps us going. Donations. It's the generosity of its listeners and the people basically stepping up and saying, this is important. I believe I want to be part of supporting it. And calling 516-620-3602 or going to give2wbai.org. You know, literally what you say is accurate because we are in a studio. The lights are on. And the only reason the lights are on is because we paid Con Edison. And the only reason we were able to pay Con Edison is because people like you have called in over the years to pledge whatever they can afford. And that money goes directly to paying all the bills that we have to pay. So yes, literally, it's because of people calling in that have kept the lights on, that keep this place going. That is... We don't have commercials. We don't have sponsors. We don't have underwriting even. Many, many non-commercial radio stations, including all of National Public Radio, have underwriting all the time. We don't even do that. It's all listener-supported. So that's why your call is that important. That's why it's more important for a station like this than for one of those corporate non-commercial stations that is really, really good at fundraising. We're here live. We're individuals. We're in that room where we have to pay to keep the lights on. The other important part of that is every little bit of it counts. The smaller, especially the smaller little bits of contributions that people can put together and afford, it really does matter. It adds up because if there's less people giving larger amounts, there's just less overall. But if you have a lot of people giving a variety of amounts, it really does add up. We really, really appreciate every little bit of it. Whatever you can possibly budget, please, this is a worthwhile institution and cause. With everything that we talk about on this radio show, whether it's politics or historic things going on in the world, we try to add a technical slant to it one way or another. We're doing that here as well because this whole text message to 41444, putting the phrase or the letters WBAI in your text message to start the process of donating in that manner, that's new to us. That's new to a lot of people, I'm sure. I'd like to know more about it. I'd love to get one for $2,600. Imagine if people could text $2,600. I don't know what they would do at that point. Maybe subscribe or maybe you could buy hope tickets that way. Who knows? But I don't know enough about it. I admittedly do not know anything about short codes or how to get them or who's in charge of them. We've thought about it over the years. We've contemplated this. We haven't really pursued it. We may though, but it's actually, this is a little bit different because it's sending you a link and traditionally short codes are a way to add a cost to a phone bill. Yeah, you could do it that way too. So you wouldn't then be entering your credit card information. This didn't work exactly that way. It's great that it works this way. That's why I said we're trying it out. I'm sure if something comes along that's more like that, the station will take advantage of that. But the technology's been around for quite a while and it's good that places like WBAI are embracing it and also it gives us ideas for, like you said, handling hope tickets. That would be a great way to do it. Yeah, we're open to all sorts of suggestions as far as new ways of using technology. And that's what we're all about here at Off the Hook. Well, we've pledged already. We've actually just taken two of the paintings. So there's two less that are available. When you say we, are you a collective? My law firm. We're going to hang up in our office. It's going to be in the conference room. That's amazing. Okay. Absolutely. Why not, right? Well, this is also a good test of the technology that we have here in the computer screen that tells us how long it takes for a pledge to show up. Because I think it takes longer than I would expect. Here's a logistical point. I'm claiming these paintings because I just pledged. However, if you use the 41444 text and you go through the steps that we discussed with the link, you don't necessarily have the option to specify what it is you're pledging for. You just pledge. So, how should our listeners then specify if they are using 41444 that they want the paintings? How would you expect me to know the answer to that since I've never even used this before now? I don't know. I guess... I hate it when people ask me questions about things I just learned about. I don't know. I've never done this before. If you want to fill out the full form... I did. But if I... on the 41444? Yes, I did. And were you asked a question at the end? No. So, well, then that's a way of pledging without getting a premium, I would imagine. I guess so, maybe. So, there was no drop down for the... There was no drop down for the premium there, but... by name. Yes, that's right. Yeah, it's just a pledging amount. So, I guess... Was there a way to leave a comment? No. Okay. There's no way to leave a comment. All right. So, if you want a premium, don't do it that way, is what we're learning. But a lot of people don't want premiums. A lot of people just want to pledge. And this is a great way to just pledge without having to interact with any of us. Or human beings. And if, say, you know, you're out somewhere, you can do this anytime with your phone. From anywhere. Absolutely. I think I'm just going to have to send Rob a note and remind him that... Why don't you pass him a note now? He's three feet away from you. I don't know. Voltaire, go ahead. If we were one of the corporate NPR stations, we'd be talking about how it only costs... It's only the cost of one coffee a day to pledge for our premium. But since we're Hacker Show, I think we should do this in terms of club mates. So, you get a... Okay. You get a 12-pack of club mates for $48 in the US. So, for about the cost of one fortnight of club mates for one club mate a day, you can get one of these paintings. Yeah. That's cool. Okay. I guess that works. That's the language people speak. Alright. 516-620-3602. Use the club mate equation. Yeah. So, if you're up to two mates a day, cut down. Go back down to one and divert those funds to the station. I mean, it's simple. Yes. Yes. It's really simple. It's a good club mate day. I don't want it to sound like we're advertising, but it's so hot and it's the kind of weather where you just need to get some energy and sit back and listen to the radio. Yeah. Indeed. Indeed. I'm sure plenty of people are enjoying themselves as we speak. Yes. Okay. So, let's get into some news of things that are happening in the world of technology because that's what we do here. But again, 516-620-3602. Please keep those calls coming in. This is an interesting case and Alex, I think you'd find it kind of interesting as well. It has to do with a pacemaker. And the first particular use of this in the courts. What is believed to be the first case of its kind to use data from a beating heart as evidence? A Butler County, which I believe is Ohio. Is that Ohio? Ohio. You know, this comes from journalnews.com. They don't say the name of the state anywhere. They just say Butler County. You're supposed to know where that is and the story is dateline Middletown. Yeah, okay. That really makes it stand out too, guys. Come on, you know. You have the whole internet reading your story. At least tell us where you are. Okay, so a Butler County judge ruled Tuesday that evidence from a pacemaker used to get a Middletown man indicted for arson can be presented at trial. Ross Compton was indicted in January on felony charges of aggravated arson and insurance fraud for allegedly starting a fire in September at his Cordonigal house. Middletown detectives said Compton gave statements that were inconsistent with evidence collected at the scene. Now, he has an artificial heart implant that uses an external pump. He told police he was asleep when the fire started. When he woke up and saw the fire, he told police he packed some belongings in a suitcase and bags, broke out the glass of his bedroom window with a cane, and threw the bags and suitcase outside before taking them to his house. Is that what people do when there's a fire? They pack a suitcase? I don't know. I just always thought just jumping out the window would be the first thing you do. Police then obtained a search warrant for all the electronic data stored in Compton's cardiac pacing device. The data taken from his pacemaker included his heart rate, pacer demand, and cardiac rhythms before, during, and after the fire. Now, a cardiologist determined it's highly improbable Mr. Compton would have been able to collect, pack, and remove the number of items from his house, exit his bedroom window, and carry numerous large and heavy items to the front of his residence during the short period of time he has indicated due to his medical conditions. You know, I'm kind of seeing through the guy's story just based on the whole packing a suitcase thing right there. I don't know if he needed the pacemaker data. But defense attorney Glenn Rossi argued that the pacemaker evidence should be thrown out because the search was an invasion of Compton's constitutional rights and unreasonable seizure of his private information. It's fundamentally unfair to say to a person the functioning of your body and the record of it related to illness that you have is something that the government should then be able to take and use to incriminate a person. Well, to that I would say, you know, we better get used to it. I'm not in favor of this, but as technology moves forward and as we have more cyborg type pieces within us, you better believe the government and every law enforcement agency imaginable is going to want access to that information, just like with EasyPass, just like with anything that is invented. And if you say there's no precedent for this, Alex, tell me if this is a good precedent. Fingerprints. Well, fingerprints are one example, but there's several others as well. This actually can be somehow or somewhat related to our pledge drive in that perhaps Rob could paint a picture of a pacemaker as a data storage device because it is storing data about this particular other man's activities. Now, the reason why they lost this particular argument in Butler County, Ohio, I think, is because the defense didn't really have a very, very strong argument. It's somewhat jarring and disquieting to think that data from a pacemaker can be used against somebody and forcing data from one's body to be used against one. It almost seems like you're being compelled to testify against yourself. Isn't a lie detector test similar too? Well, yeah. Lie detector tests are generally inadmissible as evidence. Anyhow, the polygraphs, that actually comes from a precedent from the court for which I clerked, the U.S. Court of Appeals for the Armed Forces. They were overturned by the Supreme Court in that particular case. But here, think about this. Our data is stored in our bodies for lots of different things that we do. Our activities, if we had smoked marijuana last night, perhaps, then that's going to be in our bloodstream or our urine or drug usage is stored in our hair. And all of this stuff, even if you're just driving your car along the west side highway, you get pulled over and a cop thinks that you may have had a whiff of alcohol on your breath, he can then compel you to breathe into a breathalyzer. And that's taking data from your body. Your body's ratting you out again. Your body's ratting you out. Our data is stored in our bodies for all different types of things that we can do. So this is really no different. And I think the prosecution won because the analogies are frankly pretty cogent when you compare it to fingerprints, when you compare it to breath, when you compare it to semen, when you compare it to saliva. If you are charged with a crime, these things can be compelled. They can be forced out of your body, essentially. So, yeah, this really is no different. It's a case that a lot of people were tracking. It's going to have a lot of implications. I imagine there will be an appeal on this particular issue as well. But it raises a lot of really important privacy issues as to what kind of data is being stored in these particular types of pacemakers, whether it could ever be accessed by another person, whether that data should be encrypted, whether it should be overwritten after a certain period of time. I mean, people are going to have to think about whether or not a pacemaker can then be used against any one of the patients in which it's stored. Well, I think a better question we should be asking is, of the manufacturers of these artificial devices, such as pacemakers or even artificial limbs, what kind of logging, what kind of recording are you going to have in these devices, and what is something that we accept and we don't accept? I mean, think about it. If you have artificial limbs, they could put little cameras in them if they wanted to. They could record all the motion and activity that those artificial limbs are engaged in and have a different record of where you were at a certain time. GPS could be in there. Is that acceptable to us? If it's not, then we speak out against that now because if it's put into the product, I guarantee law enforcement will get access to it at some point. And especially so if, for instance, if this data in the pacemaker wasn't just stored in the pacemaker but was transmitted to the manufacturer of the pacemaker for error-related services, you know, for debugging, things like that. If this data is floating away in the ether somehow, it could very easily be snatched up by utilizing a third-party doctrine under Smith v. Maryland. This would be a record in possession of a third party that would then be subject to the subpoena power of law enforcement and could be really easily grabbed. You wouldn't need to access the pacemaker or the data from the pacemaker. Pacemakers have been in the news quite a lot over the last six or seven months or so. There was another case called, well, it had to do with a research firm called Muddy Waters. And they had determined that a pacemaker device could be subject to an attack by sending a whole bunch of malformed packets to this pacemaker device that would drain the battery. The pacemaker device communicated with something in the house, essentially. It was communicating back and forth to determine battery levels when you needed to go in for service. But if you sent a whole bunch of malformed packets to this particular device, it could actually drain the battery of the pacemaker and supposedly cause patient death. What this company, Muddy Waters, did was they I'm sorry, Muddy Waters was a research firm. I think it was called MedSec was the research firm that found this vulnerability. They then contracted with a research sort of hedge fund type stock shorting company called Muddy Waters. And instead of disclosing the vulnerability to St. Jude's Medical who developed the pacemaker, they engaged in negotiations with Muddy Waters to short the stock. And when they disclosed the vulnerability, the stock of St. Jude's fell dramatically. They shorted the stock and they all made tons of money. To my knowledge, I don't think the SEC has come out against them for disclosure like this. This is really the definition of outside information, not inside information. MedSec was not under contract or under any kind of NDA with St. Jude's. They found this vulnerability themselves. But it's a clear case of market manipulation based on a disclosure of a vulnerability that could affect life and death situations. So of course, the stock was shorted. This is a big problem we have now. And I anticipate that we're going to see more and more instances of market manipulation based on security vulnerabilities. And that's a whole other aspect to all of this. That's the financial cheating part of it. Not even addressing the privacy implications, which are really going to be affecting us. Absolutely. And a lot of people, including myself, would argue with you that this isn't really financial cheating. They mined this information and found it themselves and they should have the right to do with it as they please. They're playing by the rules, yes. They're using the system. But as we've seen in recent months, knowing how to use the system doesn't make you the best person in the world. That's true. Wow. Okay, well that's something to be aware of and to worry about I suppose. And of course, Russian hackers everywhere are figuring out how to get access to these devices. If you read the news and you panic easily, that's the biggest threat. In actuality, it's not just Russian hackers. Yes, it is Russian hackers, but it's hackers everywhere and it's not just hackers, it's people that have an agenda. And there was a story actually that came out recently about the devil's ivy vulnerability and how that affects millions, millions of Internet of Things devices. Basically, dozens of vendors tend to run the same third party code across an array of products and what that means is a single bug can impact a startling number of varied devices. One security company's researchers recently found that a vulnerability in a single Internet connected security camera can expose a flaw that leaves hundreds, actually thousands of different models, different models of devices at risk. This is from a story that just came out recently in Wired. Now, yesterday the Internet of Things focused security firm known as Senrio revealed a hackable flaw it's calling devil's ivy. It's a vulnerability in a piece of code called G-Soap. Widely used in physical security products potentially allowing far away attackers who could be in Russia, it's possible, to fully disable or take over thousands of models of Internet connected devices from security cameras to sensors to access card readers and let's not forget baby monitors. Definitely baby monitors are in there. In all, the small company behind G-Soap known as Genivia, who can keep track of these names? It's amazing. It says that at least 34 companies use the code in their IoT products and while Genivia has already released a patch for the problem, it's so widespread and patching is so spotty in the Internet of Things that it could persist unfixed in a large, large number of these devices. Now, they say we made this discovery in a single camera, but the code is used in a wide range of physical security products. Anyone who uses one of the devices is going to be affected in one way or another. The scope and scale of this thing is arguably as big as anything we've been concerned about with computer security in recent history. So, yeah, you know, it's cool to have all these neat little devices that connect to the Internet and tell you all sorts of statistics and you can control things, but every single one of them has a security risk. On the other hand, you know, this vulnerability is premised on the ability to send two gigabytes of data over to an individual device, which is a lot of bandwidth. So, the idea that the entire Internet is going to be massively affected by this, I think, is outlandish. Well, can you say that in five years? Probably. I could. I could say it. It may not be true, but I could definitely say it. Well, the thing is, whenever you say something is a large amount of bandwidth, that tends not to be the case a few years down the road. That's true. That's true. And if you think about, you know, on a local area network, it's pretty easy to send two gigabytes of data over to a device. Also, more importantly, I think, with this devil's ivy vulnerability, a lot of devices that are accessible on the Internet are going to be vulnerable to this. But a lot of devices that are internal on a network, they won't be discoverable by the hypothetical Russian hackers who have lots of bandwidth to spare and want to capitalize on this and listen to your baby monitors. But let's hypothesize that an attacker gains access to a certain segment of your network and finds one of these vulnerable security cameras on your network and then sends over two gigabytes of data, exploits this vulnerability, gains access to the security camera. These security cameras are generally just web servers. These web servers generally run on Apache. Apache runs on Linux. Then they've just compromised, essentially, a Linux box internally on your network. That's essentially game over. That's really, really bad. So the other issue we have with devil's ivy is that this could become an attack vector internally on people's networks and it probably requires a firmware upgrade in order to patch this particular vulnerability. People just ignore that. Large swaths of the population, when was the last time people upgraded the firmware on their router? It's true. Also, the design of your internal or home network, I think, is also really pivotal in this discussion because there are ways to design your network structurally such that Internet of Things type devices maybe are not on the same subnets as say a file server or other sort of critical stuff. That's something within a network that is your local IPs could be on a completely different numbering scale such that you have less opportunities for IP addresses for rogue machines to be taking advantage of and also they can't really talk across subnets that are obviously distinct or different within your LAN. Yeah, definitely. That's a possible solution. Very easy to just basically separate things in the way you design it but it's not the default. The default is rip open the box. Oh yay, it does this thing. I have the app on my phone. We're done. And then, you know, just keep adding devices onto your local network until you run out of IPs. You're basically making this bigger and bigger and ever expanding attack surface as Alex indicated. So many of these things that are compromised in this particular case seem to be devices related to security and that's stuff that people a lot of entities who would get these things put in do want accessible from outside. They do want to see what's going on on their security cameras while they're away. So that may interfere with how many layers of actual security you can put between one and the other on your network. Also firmware for your outside facing equipment like your router or other equipment access points specifically. You know, the stuff that people would be communicating to get into your network on but definitely routing systems and all of that I think is going to change or is supposed to change with some of the changes to the IP system that we have but some of that is slow going and you end up having a lot of mixed networks, a lot of networks with different generations of equipment with different capabilities. It's those ones you forget about. Those are the ones that get lost to time and then all of a sudden you realize it's been compromised and they're on your latest and greatest iteration of your network. It's the weak link and that's how they get in and get access. Rob? And now we're 20-25 years into the home computer revolution and still there are so many uncountable people out there who when Windows pops up a thing that says, hey, time to upgrade this, they just click out of it because they don't know what the heck to do about it. Now that we're dealing with an electronic environment involving stuff that also needs upgrading, involving appliances that need upgrading, how many people who own these things are actually going to put the effort into maintaining them like that? It's not only cases of things being on networks. Sometimes it's standalone devices. I read this article. This was in Forbes. How to hack someone off a Segway scooter in 20 seconds. I'm not making this up. Any hoverboard rider who isn't already concerned should be concerned about their physical well-being. Thanks to digital weaknesses in Segway's hands-free nine-bot mini pro scooter, that's not the kinds we have at Hope, so don't worry people who come to Hope. You won't be knocked off your Segway. They have more reason to worry though if they have one of those. The flaws made it possible to take almost complete control of the self-balancing vehicle and potentially knock off anyone aboard with some fairly basic hacks. Now, attacks could be carried out with just 20 seconds of continuous Bluetooth connection to a Segway hoverboard. That's according to IOactive researcher Thomas Kilbride. It may be sped up using other means. It's a little bit alarming. Not only would it be possible to kill the motor mid-drive, but it would be simple to steal a mini pro too, as seen in a demonstration video they released. In his previous concept hack, he started using the official nine-bot smartphone app that's used to control certain functions of the vehicle. That let him determine the location of nearby riders. For whatever reason, a now-removed feature in the app saw GPS locations of each scooter user made available to anyone in a given area. I don't know why you would need that. As Kilbride wrote in an advisory that was recently released, each rider's location was published and publicly available, which makes weaponization of an exploit much easier for an attacker. You think? He then switched to a Bluetooth app called Nordic UART, which connects over Bluetooth to compatible devices. The scooter didn't require a password for access, allowing commands to be sent via the Nordic software. Again, the scooter did not require a password for access. Though the nine-bot application prompted a user to enter a PIN when launched, it was not checked at a lower level before allowing the user to connect. Yeah. That allowed Kilbride to change the PIN to 1-1-1-1-1-1. This didn't allow for complete control, but it locked the owner out. Think of the mentality here. When designing these things, when using these things, we're not thinking of the potential risks and security holes, and yeah, it can affect your home network, it can affect standalone devices, and it obviously can affect your computer and your phone. Security is something that you have to think about all the time. Voltaire. Given that you can hack Segways now, maybe we can combine the Segways and the Capture the Flag tournament. Well, again, I don't think you can hack the kind of Segways that we, I might be wrong. I don't think they use Bluetooth. We should purposely get hackable Segways then. Oh, okay, that sounds like a lot of fun. You can hack the Segway and then get the flag with it. Uh-huh, so you want someone out of control in a Segway that can't even stop the thing themselves. We're just happy to be part of our conference. I don't know if that's a good idea. We're just happy to get Segways that work at all. Let's just keep them going and doing what they're supposed to do, but I think proximity is a part of this. You'd have to be very nearby. You could probably get a custom and a longer range antenna, of course, to communicate on Bluetooth frequencies, but I think you'd have to be somewhat close to use this other software. What would be worse is if the phone was executing stuff that came in from remote locations over the internet because the phone itself was compromised and sending your temperatures in your house a crazy high and your Segway are falling off and your whole life's falling apart. Your laundry is not getting picked up or whatever else you have an app for. One thing I think Rob touched on is really, really important, and we've talked about this in so many other ways, but not as distinctly. It's happening with cars and really consumer electronics. The support, and we know this from OSs, the support has an end of life. The product design life cycle ends with OSs and they move on. They want you to get something else. We experience it with phones too, whether it's Blackberry perpetually going out of business or the latest Samsung not getting updates for longer than two years or whatever it is. These corporations pivot. They take a product and they move on. Apple does it. We've seen it all before. When you're buying something think about how you're going to repair it. This ties in with farm equipment and some of the right to repair stuff. When you're dealing with an electronic device are you able to solder it? Is it all SMD components? You're going to have to do reflow and all this crazy stuff basically rendering one short circuit the end of that device ever working at all. When you get into software it's even more obscure. Are you going to be able to deconstruct or decompile something that's running a microcontroller whether it communicates or not? The accessibility and the ability to modify or even understand how things are working, let alone support them yourself. If the company backs off that support how would you replace that? You can't. You're basically left in the lurch. It's increasingly something that I think we're all going to face. Who supports the things we like? If we like it, what keeps it going if the company's moved on or they've all been fired or something like that? Especially if it's something like a pacemaker or a car that's driving you around. Oh yeah, it's the old model. I stopped getting updates for the brakes years ago. These things are real problems we're going to be facing. It is about the developers and the companies standing by their original product designs and supporting them. How long are we going to expect them? We have to ask these questions as consumers. We also have to ask questions about do we want features like this? I saw a piece recently, I've seen many pieces actually about hacking cars. It's nice to have connectivity in your car but not at the expense of your safety. When you see that somebody can actually rolling down the windows, that's kind of cute, but when they can turn the car off while you're driving or put your blinkers on or do all kinds of things that could impact your safety very directly, you have to ask yourself, is this a good idea to have this potential? Yeah, just because you can put a hotspot in a car, does it mean every car should have a hotspot by default? Right, it's cool but is it the best idea? And you know, this is something, last weekend I decided to take a day away from everything, away from phones. How was that? Oh, it was amazing. It really was amazing. I saw you do it. I saw you walk away from all technology. I walked away and I kept walking. I didn't even look back. After a while, yeah, it's a bad idea to look back. After a while, it's just, you know, it'll get to you at some point. And I ask people all the time, are you able to do this? Can you walk away? Can you just walk away from your computer? Walk away from your phone? Definitely walk away from your phone because that's the thing that keeps pulling you back into everything. And can you just simply exist for 24 hours, obviously not during the work week because you have to do certain things then, but on a weekend, on a day off, can you simply commune with people, with nature, explore, drive a car that doesn't talk to you and connect to the internet all the time? It's getting harder and harder. It's getting harder and it's also getting hard to talk to people who appreciate this because, you know, five minutes without your phone, you start getting desperate. I'd like people to try this. I would like our listeners, as many as possible, to try a day without your phone, without a computer, a book, just exploration, hanging out with people and tell us how much fun it is, what you did, what you learned. Was it hard? Was it easy? These are important things because technology is great, but you really only appreciate technology when it's not something that you're constantly immersed in. The more you're immersed in anything, the less you appreciate it. So I think, you know, I keep my passion for technology by being away from it sometimes and then rediscovering it and thinking about it when I'm not there. It's like most things in life. I think this is going to end up, I think this is something we learned sort of in the mid to late 90s about, like, phone etiquette. When you have cell phones everywhere, do you shout loudly about your domestic problems or whatever, or are you quietly able to talk about very detailed things because you're not as dynamic as whomever is having a domestic dispute over the phone? This etiquette took a while for people to really integrate into their behavior and it's the reason now you don't really have a lot of interruptions maybe during a presentation or a film because people instinctively silence their equipment and avert their eyes in preparation for something else. And I think it's really going to be about it's going to become important to have healthy behaviors not for other people but for your own mental health. We have so many things we can be paying attention to, so much information we can take in. It's going to be something we have to do for our own behavior to actually spend time on ourselves and get away from being constantly pulled in every direction. I would extend that to include television to include radio, yes I know, you wouldn't be able to listen to us to include those kinds of things and simply interact as a human being with other human beings. And they could be on their phone, I guess but you shouldn't use their phone to send messages to people or anything like that. I don't know, I think it's a great experiment. You know, you think about this whole idea of work life balance these days and it really is such a myth because of these devices. For many, many years I worked at a huge international law firm and the old guard of the equity partnership at the firm, you know, they made their bones when they were working in the 70s and the 80s and the 90s and everybody works really hard but when they were associates and they were going up through the ranks, if they left the office or they were out on the weekend having brunch with their wife or having dinner, nobody could call them, nobody could email them. The worst case scenario is you would go home and there would be a message on your answering machine, if you had one, to go back into the office. Now I felt like we were just constantly harassed by clients, by partners, by people, by administrators. There's just no way to get away from it in certain jobs, in certain responsibilities. Well it seems like most jobs now people are on call all the time. Absolutely. And expect it to answer no matter where they are or what time of day it is. And I'm all in favor of people turning off their phones and doing this sort of deep exhale but perhaps after they call 516-620-3602 to help pledge and keep the station on the air. Yes, call that number, pledge your support for WBAI and then take a break from technology. I think that's a good idea. Totally agree. Yeah. Kyle? It is possible to do what you said. I think you have to train people around you that you're not really going to be reachable or that it isn't a good time. You can stay connected and it obviously depends on what kind of job you're in. If you're a brain surgeon I think you should just do it. I think you should just do it and when people say, where were you? I was trying to reach you. Say, I took a day off. You know, let them deal with it at that point instead of all this hand-holding. Just basically say, I took time for myself and I can do that. Sorry, what are you talking about? I just got an important email. Yeah, exactly. You'll actually have real conversations with people. When I got back to it, when I got back to the internet and looked at my phone, I was more productive. I was able to communicate better. Nobody was really that upset. Nobody really missed me that much. It was actually and just the amount of clear-headedness I got just from being away for a little while was irreplaceable. I think I need to do that more. I think a lot of us need to do that more and rediscover what's around us. Voltaire? I think the right to disconnect when you're home from work is really important and that's been recognized by in France, labor unions have won the right to stop their bosses from emailing them after work. Yeah, but the right to disconnect sounds great, but not if you connect yourself and just do something else that's as connected as work. It's just a different flavor. I'm saying rediscover the world that's out there because there is so much more than just technology. And then technology will mean so much more when you go back to it. Well, God bless those over-unionized European economies. We have a lot to learn from them. Absolutely. Hey, let's talk about the paintings just for another minute so that we can get more people to call in. Thank you to those people who did call in. 516-620-3602. We're offering special paintings of data storage devices made by our own Rob T. Firefly. Rob, could you quickly describe them? They will be acrylic paintings on a 5x7 stretched canvas, each one one of a kind, not a print, not a copy. And you will get a picture of some historically notable data storage device and a placard that you can mount next to it that explains the device and its place in technological history. And if you call 516-620-3602 or go to give2wbai.org you can have a quick look and help us out. Help us keep doing what we do here at WBAI. Pledge of $50, 516-620-3602. You can also go to the website give2wbai.org and look for the historic data storage painting, I believe is the phrase. You can also text 41444 with WBAI. However, I believe you will not be able to get a premium if you do that, if you just want to pledge. Make sure you mention, though, that Off the Hook is your favorite show, assuming that it is. Again, the phone number, 516-620-3602. Thanks to everybody who has been calling in. Your support is what keeps us going and hopefully we will be back in the very near future with more amazing content about technology, hackers, the internet, that kind of thing. I'd like to give a quick shout out to the podcast Steal This Show at StealThisShow.com. On yesterday's episode, July 18th, 2017, Voltaire and I were the invited guests and we talked about a lot of this sort of thing. People all over the world that are interested in this. Every time we go to different places, we meet some of them. It's really good to bring those worlds together. Hey, you can write to us oth at 2600.com. Follow us, Hacker Radio Show on Twitter. And most importantly right now, you can call 516-620-3602 and pledge whatever you can afford to keep this radio station going here at WBAI. This is Emmanuel for Off the Hook. If we're not on next week, we'll certainly be on the week after that. Have yourselves an amazing time no matter what you wind up doing. Good night.