I'm Linda Perry for WBAI News asking you to speak out on behalf of WBAI by becoming a listener member. The phone number to call is 516-620-3602 or going to your smartphone and putting in 41444, text WBAI. Many thanks. And you're listening to radio station WBAI in New York. The time is 801 and that means once again it's time for another exciting edition of Off the Hook. I'm Linda Perry for WBAI News asking you to speak out on behalf of WBAI. And a very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you, joined tonight by Rob T. Firefly. Good evening. Alex. Hello everybody. And Kyle. I'm here. Well, thanks again to all our listeners for their tremendous support over the past couple of weeks. And this is the last week. This is the last week of the summer fundraiser that we will be asking for your calls, your support to 516-620-3602 or to give to WBAI.org. It doesn't mean you don't. You have to stop giving. No, and I'm not finished giving out the ways you can give. I'm sorry. Texting to 41444, which a number of us have already done. It feels really good. You know, gone are the days where you come tearing down to the station cash in hand to say, hey, I want to donate to the place. You don't have to do that anymore. Phone calls, text messages, emails. That's the way of the 21st century. And we are on in the 21st century. We've been on since the year 1960 with this amazing place, this amazing radio station. Yes, we've migrated from one building to another throughout many boroughs in this fair city. And currently we're in Brooklyn. And you know, I think this is the best place. It's really awesome because we have a lot of really cool people here. It's a great neighborhood. Great confluence of interested and active people. It's just vocal. You could just sit here and just watch all those people go by and be inspired by it. So it's really a healthy atmosphere. And it's an atmosphere that you, the listener, have made possible. Because were it not for you, we wouldn't be here. We wouldn't be broadcasting. Something else would be at 99.5 FM. What do you think that might be? It could be a country station. It could be, oh, I don't know. Do we have enough top 40 stations? Or, you know, the Smooth Rock. Is that a thing? How about an NPR? Well, NPR has six stations in the area. Even that might be enough for them. No, I don't think that's enough. No? Seven? Okay. Who knows? Seven's more of a, it's like a lucky number. There is no end. You might hear people in the media say, radio is dead. Broadcast media is dead. It's not. If it were, then all these stations will be given over to community groups that exist and are completely clogging up the FM band as it is. But nobody's giving up their radio stations. Nobody's giving up the broadcast facilities because there is still magic in broadcasting. And that's why we do this. Because we are drawn to radio. You know, podcasting is great. We are also a podcast because we broadcast on the internet as well. But we also feel an affinity for the traditional radio studio where we talk into microphones, where there are people here live, where there is a signal broadcasting. In this case, off the top of the Empire State Building. And you may have heard, in fact, there have been some mainstream media pieces about this, about the problems we've been having with the Empire State Building. Basically, being charged a huge amount of money. Something like, was it four times the going rate? Is that the number? Yeah, the market rate being blown way out of proportion. And what is owed, I guess, is also being rated at something way over the reasonable rate that we think is kind of, I don't know, what we owe in reality. But it's been blown way out of proportion. Imagine this scenario where, you know, the World Trade Center has just been destroyed by an act of terrorism. And there's no place else to go except for the Empire State Building. Who then says, yeah, you know what, you guys can have the space for the next 20 years, but you're going to pay this amount this year, this amount next year. And basically, this ascending scale of prices that you don't really have a choice about at the time. And then when 15 years go by, you realize, wow, that is a lot of money that we were forced into agreeing to. And there are other facilities now that didn't exist before that do now that charge a quarter of that. And that's what other stations who weren't back into a corner are able to pay. We are the station in New York City least able to pay that kind of money, which is simply insane. So we are, you know, in our tradition, we are fighting back against injustice and saying this is not fair and it's hurting this place. And I know that at first the Empire State Building was not willing to even talk about this. And I think thanks to listener pressure and some coverage in the mainstream media as well as alternative media, they're starting to look at alternatives. And that is important. That is vitally important because without this place, without this broadcast tower, without this radio station, we lose our voice literally. There is no way we can broadcast and reach people. And the magic of radio as opposed to podcasts, which is also magical in a totally different way. Radio, you know, it gets people by surprise in your car, when you're driving, when you're just tuning the FM dial. It's something you might hear without expecting to tune in. You know, on a podcast you're generally looking for what it is you listen for. And here you find it. And we've heard from so many listeners over the years about how they stumbled upon our program. And that is really, that I think is one of the most important things about radio, is that way of just reaching random people of all ages, backgrounds, income levels, you name it. And that's why we need your support. 516-620-3602. And it's not just listening to the radio station. I mean, I've heard from multiple people who stumbled upon this program, started listening to it, and through that discovered the hacker scene in general. And they've ended up going to their 2,600 meetings, going to Hope, and basically becoming full and contributing members of the hacker community, through stumbling upon us here. A lot of stumbling going on in the radio world, but it's good stumbling, because when you stumble, you find something generally interesting. Now, to build on a couple of things that you're saying, Emmanuel, you know, we talk about the power of radio, we talk about WBAI, and being something worth fighting for. And remember, it wasn't too long ago. Actually, it was a while ago, but it does feel like yesterday, when the Pacifica National Board was being threatened to be taken over by corporate interests. And people literally sat down in the hallways of WBAI and got arrested, while we were on the air. I remember that. Back in 2000. And since we keep all our shows online, you can hear that yourself. That was pretty amazing. Was that 2001? I think it was 2000. I think it was 2000. 2000 into 2001. That whole period was pretty hectic. And the NYPD was over at 110 Wall Street, when we were still in Manhattan. And the NYPD was making their announcements in the hallway, that they were going to arrest everybody who didn't leave the station. And they had no idea. Except me, because I was on the air. You were on the air, but I had your cell phone connected. We sent you into the thick of it to report back on the radio. And literally, I held the phone up to the NYPD officer, and he broadcast out that message. And hundreds of people were outside the station in no time. Yeah, people started migrating over to help stay at the station. It was an incredible experience. And then back on Long Island, when I lived on Long Island at the time, there was organizing at the Cinema Arts Center over in Huntington with Vic Skolnick and Charlotte Skolnick. I think Vic actually has passed away now. God bless him. But it was an incredible experience to see so many people come out and literally fight for WBAI. And that's what we're engaged in now. I mean, this is an existential struggle here. We're always struggling to survive. 516-620-3602 to give us a lifeline. What that mode, the ability to be found, as it were, on the radio dial, that in conjunction with the independent support we get from our listeners, really gives us the ability to have complete independence and autonomy, and tell these unique stories and talk about issues that you really can't find on a lot of other frequencies or even podcasts and other forms of media. So that is what we mean when we say magic of radio and the community radio model. And that means you don't have commercials. You don't have people telling you things based on some kind of guidelines or management telling them that this is something, some perspective we need to cover. Politically, there's all kinds of attitudes and perspectives here. And that's what makes this place so interesting to people that do find it. Well said, yes. Now, on the subject of supporting the radio station, Rob has been kind enough to donate paintings that he is making himself. The latest, what's the series called, the latest one? They're called Historic Data Storage paintings. And what's a historic data storage example? Well, one example that people might have seen me paint this past Sunday because I live-streamed it. I was going to get to that. It was a three and a half inch floppy disk, the delightful old hard plastic ones. And this particular disk was America Online version 2.5, which I still have hanging around for some reason. Maybe I'll sign up one of these days. But yeah, it'll be things like that. Various ways in which we stored data over the years. I've had all kinds of great suggestions from people of sort of data storage things they'd like to see me paint. In addition to the various kinds of disks and floppies and things we've had over the years, there have been, someone suggested a human brain. That's something that stores data, a book. I think it was someone on the show who suggested a human brain. Yeah, and I have my eyes on the punch cards from the Jacquard loom in the 19th century, which was a programmable loom. Wait, what? 19th century? Yep, it was a loom that you would weave fabric on and it was mechanized and there were punch cards that you could basically program this loom to do certain patterns. In the 19th century? Yep, it was seen as a precursor to the punch cards that later went into machines. Wow. Computers, rather. How are you going to paint that? Do you have to see one? I'd have to see one. I don't have any around, but there's plenty of source material out there. I suppose that's similar to the the paper tape they would use in player pianos, you know, where it's actuating something based on what it's reading in a punched tape or card. Yeah, there are all kinds of real neat and exciting things and some unexpected things in the history of the ways we've held information for later use and I look forward to painting a bunch of them. Now, you can get one of these paintings from Rob T. Firefly by calling 516-620-3602. What is the pledge amount? The pledge amount is $50, which I should mention is considerably less than I would just charge for a painting if I were selling one in my regular art career, but I've donated these to the station and I want them to get into the hands of supporters. So, for a pledge of just $50 or more to 516-620-3602 or give to WBAI.org and ask for the historic data storage painting. We've also got a couple of other things. Well, let me just focus on this for a second because I just wanted to ask, can someone pledge for more than one of these? That's somebody that, somebody in the street randomly asked me that before and I just wanted, I didn't know what to tell them. Yeah, absolutely. You're allowed to pledge for as many as you want of the ones that are remaining. Right now, there are not many left. There are six left. Okay, so these have been going steadily. They have. They've been going pretty steadily over the past couple of weeks. I'm really grateful to that and really grateful for that and to the listeners who have gotten hold of ones already. And yes, 516-620-3602 will get you a 5 by 7 inch acrylic on canvas. Original painting, not a print or a copy of any kind. You will get the thing that I have painted. You'll get a random one and you'll also get a placard explaining what it is the painting portrays. And when they call, they need to ask for what specifically? For the historic data storage painting. The historic data storage painting. And look for that also online if you go to give2wbai.org. Now, if you text to 41444, that's just a straight donation. You can make a monthly, annual, can you make a daily donation? I don't know if that exists. But you can you can basically specify an amount that does not hurt you to donate to WBAI to keep us going. And I'm not sure if you're asked there, but if you are asked what your favorite radio show is, we can't tell you to say Off the Hook, but we can just tell you that you're listening to Off the Hook right now, obviously. So keep that in mind. Now there are other things. First of all, before you get to the other things, you mentioned that you were basically live tweeting. What was it you were doing? I was live-streaming it over YouTube. Just live-streaming the painting session. Literally watching you paint. Yeah, people were watching me paint. The camera was zoomed in on the painting. And while I was doing this, I was chatting with the people in the room with me about what I was painting. And just that led to all sorts of interesting conversations. Picasso never did this. Picasso, I guess... Van Gogh never did this. Van Gogh, he was, I think, a bit preoccupied. You're doing this. You're showing people you painting live on the internet. Yeah. Wow. And it's something you can keep an eye on our Twitter, Hacker Radio Show. Or you could go there if you want to see the recording of the last time I did this. It's been retweeted by us at Hacker Radio Show. So if you missed it, you can still see it. If you missed it, you can still check out the recording. And you can also skip ahead if you want to just hurry up and see what the heck comes next. But yeah, it was fun. It was my first time trying something like that. And I got a good response. And I've been told I need to do it more. So I will be. Well, not in the sense that you need more practice. In the sense that this is entertaining. Do it again. Yeah, in the sense that the people who saw it have enjoyed it. Good, good. And what is your website so people can see examples of just how amazing your paintings are? You can see that on robvincent.net. You could also take a look at my art portfolio at robtfirefly.tumblr.com. Okay, great. Well, thanks again for this donation to us. Again, the phone number 516-620-3602 or the website, give to the numeral 2, wbai.org. And look for the historic paintings there. Now, we have other things as well. We do. We have some things that we found in the back of a disused cabinet and under some stairs behind it. You know, I could get into the whole thing. But these are a lot of time exploring. Yeah, these are some bundles that we have actually left over from previous fundraisers. We had some extra books from from past books. So we have a book called Teach Your Kids to Code, which is a very good book that basically does what it says on the tin. It's coding lessons, not just for children, but for interested adults as well. And it's bundled together with a book called Beautiful Lego, which goes into how you can construct all sorts of interesting and fascinating artwork with with Lego and depictions of famous monuments and things like that. It's really pretty. If you have a bright kid who is into technology, this is the perfect gift, I think. Absolutely. And you can get the bundle of both of these books while supplies last for a pledge of $75. And then take your kid to Maker Faire, which is coming next month. Absolutely. And yeah, you won't have any problems from them anymore. They'll behave. They'll be good. They'll be just building things left and right. It's a pretty awesome thing to see kids turned on to technology like this. Mm-hmm. And this bundle, if you go to give2wbai.org or call 516-620-3602, it's called Beautiful Lego and Teach Your Kids to Code. That's the name of the package. And as of right now, there's only four of these packages left. Okay, so best hurry, or you might have some angry children around you who said, Mommy or Daddy, why didn't you get this for me when you had the chance? 516-620-3602. Well, just ask, why are you slow? Yeah. You know, kids are impatient. They want things right now. Yeah. And the books will come soon, too. We're getting them out a lot faster than we have in the past. The books are actually right here at the station already. Yes. They can go out. They can go right out. The paintings, I'm still painting, so that'll be some more time. But paint has to dry. Yes. You don't want smudged painting showing up in the mail. You want it to dry enough where it can survive the United States Postal Service. Don't get me started on them. I've got some bones to pick with the Post Office. I thought they were your best pals. All right, so anything else that we have, or is that pretty much it? We have one more thing. One more thing. Which is a book by a friend of the show, John Baktle, called Hack This. And it's 24 incredible hackerspace projects from the DIY movement. And it's just all these different sort of hackerspace type projects you can do. Very, very well illustrated. Very well laid out. It's a very good book. I have a copy myself. And you can get that for a pledge of $40. It's called Hack This. If you call 516-620-3602, or go to give2wbai.org, you can get all the info on this. And if you wish to pledge for it. So if you call 516-620-3602 and say Hack This, they will immediately call up that book and ask you for $40. That is what should happen, yeah. Okay, that sounds reasonable to me. But while those supplies last, we've only got a couple left. Okay, well I think we've pretty much laid it out for everybody. You know why it's important to support this place. What we are offering you as our thanks. How you can actually make those contributions. Mm-hmm, yes. And now we're gonna move on. We are going to move on. What has been hacked this week? What hasn't been hacked this week? My goodness. Okay, well I'm glad you asked it that way, because that gives me a lead-in to a story I haven't actually read yet, because I just saw it when I was coming in here. And I was driving at the same time, so it was kind of dangerous to actually... Hot-off-the-news aggregator. Hackers are now targeting car washes. Wait, why? Yeah, this is a story from the New York Post, so you're gonna have to humor me a little bit, as I read directly from their pages. So filter the sensation a little? Yeah, a little bit. So, but it is a car wash. I see a picture of a car in a car wash. Okay. I'm not sure why anybody would... Is this an unattended one? It's a British license plate, or a EU license plate. Oh, you're right. I don't know what that's all about. Something as mundane as getting your car washed could now become a dangerous ordeal. Yes, chew on that for a while. Let's have some fear sink in. It already is a dangerous ordeal. Why is adding computers to everything just... It just adds danger to everything. Computers are fine. It's when the hackers get involved. That's when the danger comes, because hackers are evil. Oh, right. Okay. But what about good hackers? Well, you know, that's the struggle we've been in now for a long, long time. Where basically, hackers are, no offense Rob, painted with a broad brush, and everybody is seen as a threat. Because you have to have a bad guy. Yeah, and it's easy to say these kids are the bad guys, or these people who are into technology. They're the, you know, the Mr. Robot people. They're bad, and they're out to destroy society, and cause all kinds of panic and mischief. So, what is really going on with this car wash? How... Oh, I have no idea. I just read the first sentence. So, let's learn together. A group of security researchers have exposed the vulnerabilities in automatic car washes, and proved... I can't even imagine what that is. And proved just how easy it can be for hackers to target an internet connected, drive-through car wash, and damage vehicles. Okay, a couple of things. Now, first of all, why, why is an automatic car wash connected to the internet? I mean, I'm sure there's some reason. I'm sure there's some, something that's made more convenient for whoever is running it. But really, do you need that? Do you have to be connected to the internet? What, what is, what does the internet give you, when all you're doing is spraying water onto a car, and soap, and, and, and, and drying it in the end, hopefully? I'm gonna guess... How does the internet help any of that? I'm gonna guess this is purely to make management of that, of said car wash, a, a waking dream for whomever is responsible for managing that car wash. You know, the fluid levels, and sensors, and, and all of that just seamlessly gets sent to some person who's on a beach somewhere, and then when they find out, they get back on the cruise ship and go fix it. So, basically, this is for, for people running car washes that have fired all the employees, and yeah, are somewhere else, and couldn't care less about the business they're running. Correct. That's, okay. They can't check the fluids themselves when they're there, because they're not there. Right. Maybe, maybe if you need more fluids, you download them from the cloud. Oh, that's good. Now, wait, wait, my, my whole problem with this is, why, I mean, don't hackers have better things to do than mess with people's wash and wax? Hackers, in case you're not keeping up with it, Kyle, are basically intent upon causing all kinds of mayhem and destruction wherever they go. Doesn't matter, doesn't matter what the target is. Whatever the target is, it's in danger because of the hackers. Oh, I see. I can repeat myself over and over again. I've watched enough Trump press conferences to know how to do this, all right? The hackers are, are, are the evil force, and they have to be reined in. They have to be controlled. Wow, this is easy, actually. I can, I can, I can dig this. You slip right into that. Technology is a real blessing to all of us, and it's a shame, really, that a few misguided people out there, with clearly not enough to do, are ruining it for everybody else. We could be so far ahead. We could be doing all kinds of amazing things with this high technology of ours. Instead, we have to look over our shoulders and worry about the criminal element and how it's going to make everything come crashing down. I mean, I'm just, I need a drink. Really, I, I wonder, what is it in the car wash that can actually hurt your car? I mean, aren't these things designed in the first place to not hurt your car? What if you put a sorbic acid into the car wash instead of detergent? What about that, Alex? Have you thought about that? Yeah, maybe you could mix up the fluids. With the internet, this is possible now. You can do that. I think you're probably right about that. That sounds like terrorism. Now, it's funny, because the parameters, I guess, of how far in a brush or some kind of scrubber maybe goes, then it's, it's pressing against and ruining paint or something. We're talking about a car wash, not a, not a proctology exam or something. Well, that's next, Alex. That's next. Yeah, hackers can hack your proctology. I got a proctology story coming after this one. I can't wait. That will definitely keep you awake at night. For some people, their car is a very personal space, and, but the other thing is, you have, like, there's no, like, mechanical stops. You know, usually these things are designed in a certain way, and perhaps for a different size cars, it needs to be able to be variable to a degree, and it uses some kind of sensing that can then be put out of parameter or specification. I've never ever looked at the insides of how car washes work these days, and I'm sure there's a variety of generations and models. Well, we've all strolled through a car wash at one point, or not, not the wet part, but, you know, they let you walk past and watch your car. You get the idea. You know, it's a bunch of brushes hitting the car, and, and, and no one's really sitting there, you know, no scientists are sitting there figuring things out. I don't know what it is that can be adjusted. It's either working or it's not working, right? Yeah, this has to be a specific type versus, you know, all the other types of car washes there are, right? I mean, is this a new thing that, that they're so connected? We're only two paragraphs into this New York Post story. We could spend an entire day just reading the New York Post on these airways and dissecting every sentence. It truly is. Let's continue. Using an old pickup truck to test their theory, the research team hacked an internet-enabled PDQ laser wash system, one of the most commonly used systems in the country, and this is according to Motherboard, so it's probably true. Okay, I believe them. All right, PDQ laser wash system. Okay, so that sounds like a sensor of some sort, a very specific type of car wash, as, as I theorized, so. Their findings showed an attacker could easily manipulate bay doors to trap or strike vehicles in the car wash. Okay, so we're talking about closing the door. Closing the door is something that a hacker can now do, and yeah. Okay, so what's the defense against that? This is beginning to sound like the most climatic scene from 2001, right? I mean, yeah. Open the pod bay doors. He wouldn't open the door. Yeah. No, Hal wouldn't open the door. That's right. Well, he wouldn't open the door. Right. So, you know, well, I don't know. Maybe there's an analog there. Maybe not. This whole thing is fascinating, though. I mean, my, my son is incredibly fascinated with car washes. Your son is two. Four. Four. Okay, well, still. Time flies. Okay, that's kind of scary. Not scary, but also kind of, like, you know, it's, it's also inspirational. Absolutely. Yeah, definitely. I want to stay on his good side. Yes. I'm afraid. Okay, hackers could also potentially control the mechanical arms inside the car wash, releasing powerful streams of water at the vehicle's doors to prevent passengers from leaving. Couldn't anybody who works there also do the same thing? And as long as there are people working there, can't they prevent this from happening? You could do that with a hose. Yeah. Or prevent somebody from getting out of the door. Is this the worst security vulnerability? Like, is this the worst thing we have to worry about right now? I mean, really? I don't care if somebody gets trapped in their car in a stupid car wash. You see, Kyle, your problem is that you don't panic at the appropriate times. This is a story from the New York Post telling you when to panic and you refusing to do it. How can they possibly sell newspapers? This is silly. Why was there a team of researchers doing anything? I mean, tell me they just got a free car wash out of this. I'm not sure. That's all I'm interested in knowing. It's a group of security researchers. Maybe by the end of the story, we'll find out who they are. Good for them. Yeah. Well, what else are you gonna do with an old pickup? In big quotations, like security research. Really? This is what your skills are being used for? Well, you know, maybe they were just on their lunch break. Is this like piecemeal, like side work or something? It's probably every aspect of life they go and say, hey, this could happen if a hacker did this. So brave of them. Yeah. God love them. You sound sarcastic, but I know you're not because that's just how the radio makes you sound. No, it's true. I'm standing on my chair now and I have my hand on my heart because this is patriotism at work. Well, we are in the middle of this article. Let's continue now. The team even sent instantaneous commands to open and close one bay door to strike the vehicle repeatedly, proving how a hacker could trap drivers as they try to escape the car wash. It's gonna be bloodshed and mayhem inside the car wash. They'll call it Car Wash 2, the sequel. The waxing begins. I don't know. Something really scary. I'm not ever going to a car wash again. I'm not gonna drive anymore. How about that? Because if they can do this, what else can they do? What else can they control? It's better to hand wash your car anyway. That's true. Until they take over your prosthetic hands and then, you know, you start punching yourself in the face. I didn't think about that. Yeah, you didn't, did you? Okay, continuing here. Security researchers. Here we go. Here we go. You can write some letters now. Billy Rios of White Scope Security and Jonathan Butts of QED Secure Solutions plan to discuss their findings this week at a conference in Las Vegas. Well, I guess this story came out last week then because it's probably something that was actually August 1st. That was yesterday. So DEF CON's over. Black Hat's over. So I don't know what conference they're gonna be discussing it at, unless this is an old story. It's like Z-Sides or something. Z-Sides. Okay, that's a good one, actually. I don't know. Anyway, so this story in the post says they're going to be discussing. Maybe they already did. But interesting. The name of the car wash is PDQ Laser Wash System. The name of the security was QED Secure Solutions. I just think they kind of, the symmetry there. We believe this to be the first exploit of a connected device that causes a device to physically attack someone, Rios said to Motherboard. Well, yeah, that's, you know, that's true. If you put somebody exactly in that spot and issue a command, you could say that you're being attacked by a robotic arm or by a door or by anything, if somebody happens to be right there at the time. It doesn't mean that the car wash has gone berserk and is attacking people. While not all PDQ Laser Wash Systems are online, the researchers found more than 150 systems that were connected to the Internet nationwide. They explained a hacker could simply choose the IP address for the car wash they wish to target and then launch an attack script. Well, that actually sounds a little bit more interesting to me because, I mean, you could wreak some serious mayhem across the country. Yeah, but it's more because they left it in this position. It's not just a hacker that can do that, anybody can do that. Sure. It doesn't take any skill to launch an attack. No, not especially if you can script it. It takes a certain amount of ignorance to leave it in a position where somebody can do something so obviously wrong. Yeah, it sounds like maybe someone that managed it didn't understand the risk and the installer maybe didn't make them aware of how it was configured or never configured it to to be safer than it is. But it just seems, yeah, carelessness I think is somewhere in here as far as the configuration for however many hundred or so. And the manufacturers should be helping a little bit as far as making that intuitive for people to purchase their systems because I'm sure these things are not exactly cheap. I mean, how much does a car wash cost? You know, I haven't washed my car in a long time, so I don't know. No, no, no, to buy a car wash. Oh, to buy a car wash. Like a 2017, you know, big, you know, does it come like a transformer just, you know, unfurls itself and... I think the only way you can buy a car wash is to buy one that went out of business and then restart it. Yeah, but like say you're upgrading the equipment and you're moving in the new hardware for this smart car wash, how much does that cost? Yeah, these are questions that we're not prepared to answer right now. Yeah, so the manufacturers should be helping the people that are paying them to install this new fancy, you know, whiz-bang laser car wash, you know, to say, hey, maybe this shouldn't be like, you know, on a public IP, you know, with big, you know, welcome signs and everything. But Kyle, what I just thought of... What did you think of? What if the manufacturers, the people that are supposed to be helping these individuals that run the car washes, what if they're part of the International Hacker Consortium? That group of people I was referring to before that are intent upon causing mayhem and destruction, but they actually control all the car washes from within already, and they're simply forcing these people to install software and put them all in the cloud so that basically mayhem ensues. They'll sign up for premium car wash protection. It's like an add-on, right? You know, we're getting in too deep here, and it's scary. I think you are onto something, though, and I think something interesting that comes out of this article, too, is when we inject technology into various things where it just doesn't necessarily belong, there are a lot of huge liability issues that, let's say, ordinary car wash owners wouldn't think of. I mean, if they can be subject to an attack on the Internet, on their systems, I mean, now do car wash owners need to think about cyber liability insurance? Right, but the thing is, Alex, the thing is that, okay, you say on the Internet, the same thing could happen not on the Internet if somebody hits a button. You know, it's the same exact thing. The only difference is that they've given control to people that aren't even there to press those buttons. Well, that's exactly true. And why do you need to do that? It's cool. It's cool that you can control things from far away, but do you need to do that? You absolutely do not. Yeah. Absolutely do not, and that's why I think when we inject this technology to places where it shouldn't be, I mean, things like voting booths. Do we really need to have electronic voting booths without any kind of paper records? We're going to talk about that, too. Oh, we are. I'm foreshadowing. Well, just to, I guess, sum it up, I think the idea of being able to read, you know, status and that kind of stuff, that's one thing, but making it so easy or so flimsy such that, yeah, it maybe does that, but it's also vulnerable to a host of other things that the right people could exploit, that seems like careless design. Well, absolutely. If you're building that in. These stories are out, you know, these people, the car wash owners or PDQ technology should be placed on notice that there is a vulnerability, and we should expect this to be patched, because if it isn't, and they willfully turn a blind eye to it, then they're going to be looking down the barrel of some kind of lawsuit. Yeah. It's not going to be good for them. But it also could be that those sensors could report to something, and then that reports to something that doesn't have any more control than just reading from something that's offline through a different protocol that's just sending, you know, statistics about whatever, suds and wax and all that, but like, it doesn't need to be able to control robotic arms, like, you don't necessarily need the parameters for those to be anywhere near something that's a server. If you need those vital statistics on detergent and wax and all that, which must be the most fun job in the world, yeah, okay, that information can be sent to you, and you can pour over that, but yeah, as Kyle said, there's no reason to have robotic arms be controlled by people outside. See, the thing is, I think this is a worthy thing these guys did to point this out, because they're basically saying, this is stupid to have it set up this way. I think we can do without the sensationalism pointing the finger at hackers. I don't know how much of that is them, how much of that is the New York Post, but it's typical of the way the media covers this. Yeah, and that was kind of my point, is that, yeah, it may be online, but is this really an alluring target? I think people who are really interested in exploiting vulnerabilities, and who could take advantage of this, are really busy doing other things than messing with people's car. Yes, exactly. It is fun, though, to think of, oh, I didn't know this could be targeted as well, this, you know, someone could set this up poorly, and this is the risk that we face, so it's important to talk about this. Let's finish up the story. Although some software-based safety mechanisms can prevent car wash attacks from occurring, car wash attacks, they used to mean something completely different when I grew up. It's basically being attacked in the parking lot of a car wash. The researchers were able to disable most of these systems. If you're relying purely on software as safety, it's not going to work if there's an exploit in play. That's according to one of the researchers. The only thing that's going to work in this scenario is hardware safety mechanisms. A spokesperson from PDQ said the company is working to increase security measures and fix problems within its system, which is exactly what you'd expect them to say. Yeah, they're going to put Nerf on the pod bay door, apparently. That's what's... It's not a bad idea. I could think of all kinds of other things that could cause harm and danger, but I'm not going to share that right now. But yes, Alex, you mentioned voting machines, and we're also mentioning hacker conferences in Vegas, and DEF CON happened this last week. They did something which sounds really, really cool. Something that we want to do at Hope. We've wanted to do at Hope, and we couldn't quite get it together to do this. It wasn't easy. What they did was something I don't think we even thought of. They bought a bunch of old voting machines off of eBay. Maybe they weren't for sale when we were trying this a few years ago, or maybe they were just phenomenally expensive, or maybe they just were hopelessly outdated. But basically, this is a good thing to try and figure out. Basically, what happened was they bought these voting machines of different sorts, and I think they got 30 of them, computer-powered ballot boxes that had been used in American elections. They were set up in a simulated National White House race, and hackers got to work physically breaking the gear open to find out what was hidden inside. We issued a challenge, this was many years ago, to Diebold. I remember we called them to find out how to pronounce it, and I forget what they said on the phone. Is it Diebold? Let's say it's Diebold. We contacted Diebold because we went to some kind of a demonstration. I think it was in Upper Manhattan or in the Bronx or someplace, and they were showing off machines. A bunch of companies were, and we asked them then, okay, you know, this is a good machine. Would you mind if a bunch of hackers tested it at a conference coming up? Never heard from them again. We tried to contact them several times. Would not take us up on the offer. And to me, that tells me that they're not that enamored with their own security, and they're a little afraid of what could happen. So that kind of gave us the answer we were looking for in the first place. But anyway, in this particular case, they managed to get 30 of these ballot boxes, and hackers got to basically physically break the gear open, find out what was inside, and in less than 90 minutes, the first cracks in the system's defenses started appearing, revealing an embarrassingly low level of security. And then, one got hacked wirelessly. Without question, our voting systems are weak and susceptible. This is according to Jake Braun. He's the one who sold DEF CON founder Jeff Moss on the idea earlier this year. Thanks to the contributions of the hacker community today, we've uncovered even more about exactly how. The scary thing is, we also know that our foreign adversaries, including Russia, North Korea, Iran, possess the capabilities to hack them too, in the process undermining principles of democracy and threatening our national security. But you know, I go further. I say, you know, even our friends can do this. Anybody can do it. It's not just the ones you're most afraid of. It's not just the ones that, you know, you hate the most. The fact is, anybody can do this. People inside the country, candidates themselves, companies, foreign adversaries, foreign friends. The system is not secure. That's what needs to be proven. We don't have to point the finger at a particular culprit. It's just possible for this to happen, period. I entirely agree with that. And you know, in one sense, I think it's really great what they did over there. But on the other hand, you know, it's sort of an obvious conclusion here, because I think we've known for many, many years, based on primarily academic research into the security of voting booth systems, that these things are eminently hackable. And this is something that was talked about ad nauseum in the lead-up to the November 2016 election. And then, of course, in the aftermath of the November 2016 election, when we were talking about, in a legal sense, whether or not there should be some sort of forensic examination of these voting systems to determine whether or not they were tampered with. And we ran into this chicken and egg problem in all the places where Jill Stein had filed her lawsuits, where judges said, well, if you don't have any evidence of tampering, we're not going to order a forensic examination of any of these particular voting systems, even though we know that they are so eminently hackable and so incredibly vulnerable to simple attacks. Can I just say, Alex, in response to that, would it not be a public service for hackers everywhere, or for people everywhere, to simply tamper as much as possible? That way there always is evidence of tampering, no matter where they look, and they would have to yield to this. I think it would be, frankly, a great idea, because, you know, without evidence of tampering, you can't have a forensic examination. Without a forensic examination, you can't have evidence of tampering. So if it was so obviously and blatantly tampered with, then perhaps a recount or some kind of examination would have been ordered. But we didn't have that. And you have this strange system whereby the security and the simple interoperability of these voting systems are certified by these bodies that are also funded by the voting machine manufacturers themselves. So there's a circle of self-interest that is circulating around this particular industry that is producing really bad machines. Bad machines that we didn't know about. This kind of is where I would say that perhaps a more helpful thing, I mean, this adds to, you know, maybe already documented stuff about these different systems. And it is, of course, interesting that they had so many different types and so on. But it would have been really cool to see also maybe or what we need now that we've established this yet again, that voting machines are terrible, computerized that is, that perhaps we need to see 30 hacker designed voting machines in the future to be evaluated instead of these companies that are kind of stuck in this self-interested loop of bad stuff, right? There's a lot of profit there. And there's definitely a market for secure voting machines going forward. You know, one of the scary things about this too is that the voting systems that we have in places where voting is considered to be more secure, it is more secure because there's some sort of paper record or some kind of paper ballot. But if the tallying system itself has been monkeyed with, then there's only going to be some sort of recount or recalibration of the paper ballots on the basis of, let's say, a really low margin of victory for one candidate over another. So if something is monkeyed with and there isn't, well, to such an extent that there isn't a very slim margin of victory, then we would never know. And the paper ballots that we have as a backup system to ensure the integrity of our election are completely meaningless. Yeah. And I think it's also worth pointing out that in a normal voting election cycle and in a voting polling station, you have protocols, procedures, and monitors there. I'm going to venture to say that this was pretty much a free-for-all on all 30 of these. Oh yes, absolutely. But what I think would be an even more interesting test, obviously, you know, a presidential election, there's all kinds of attention being pointed at various things. But if you target a particular small election that uses the same machines, because they do use the same machines for big elections and small elections, you basically pick a small area that's off the map. And you quietly gather, I don't know, 50, 100 hackers and say, this is the one. We're going to learn everything we can about this particular machine. And this school board election or local town council election, we're going to target this one and prove once and for all how easy it is or just how it can be done, how an election can be thrown into chaos. Because, you know, it'll be thrown into chaos. They'll probably have to have another election, but you'll have proven the point without causing a scandal that you might wind up paying more than anybody else does and maybe not taken seriously. In this particular case, you can say, yeah, it's obvious that 10,000 people don't live in this town, only 1,000 people do, and yet we had that many votes. Things like that will be easier in an isolated type of scenario. So I'm thinking that might be the best way to target, you know, you pick a machine that you know has vulnerabilities and you target it and you prove it once and for all. Now, here are some of the machines that they were able to get into at the DEF CON demonstration. A WinVote system used in previous county elections was, it appears, hacked via Wi-Fi. The MS03026 vulnerability in WinXP allowing InfoSec academic Karsten Schurman to access the machine from his laptop using RDP. Another system could be potentially cracked remotely via OpenSSL bug CVE-2011-4109, it is claimed. So all kinds of fun was had, and I think, you know, we may have learned quite a bit. Now, according to this article in the register, we're told the WinVote machine was not fully secured and that the intrusion would have been detected and logged, so don't panic too much. And not all the attack equipment is used in today's elections. However, it does reveal the damage that can potentially be done if computer ballot box makers and local election officials are not on top of physical and remote security, especially with a growing interest from Russia and other states. So this is where you got to inject panic. It's kind of like, you know, what the Post does with hackers, the mainstream media does with Russia. It's like, imagine if Russia did this and everyone else is imagine if hackers did this. The point is, bad security is bad security. It doesn't matter who does it. That's what you have to focus your attention on. I mean, it's something really scary. Back in, I think it was maybe September or October, I debated the executive director of the Board of Elections for New York City about whether or not New York's elections could, in fact, be hacked. And in doing the research in preparation for that particular debate, I looked into the archives of the city and specifically at the RFPs, the responses to RFPs for secure voting systems. And some of these were totally ridiculous. Some of them had proposals to wirelessly transmit the results of an election, you know, from one area to another. So from one voting precinct to some kind of centralized place where all the votes would be tallied. I mean, the idea that you are wirelessly transmitting ballots, votes, you know, that are, you know, our right to enfranchisement is totally scary to think that that's flying through the airwaves. I mean, and these were very serious proposals from serious companies that cost gigantic amounts of money in order to implement. But we didn't have that here in New York, but it was a really fascinating read scouring through those old records. Yeah, well, it goes to show, if you're clueless, the harm is almost immeasurable. And it's a wonder, just comparing this to sort of the old way of doing things when everything was on paper ballots, paper tapes, what have you, from the pre-electronic voting machines. And there was such a chain of custody with those things. The election workers, you know, they had access to certain things and then they got dropped into a box that only one election worker would have. And he would basically do the spy movie thing, handcuff it to his wrist and take it from one place to another, where somebody else with the key to that could get to it. And there was just all these measures of security. And when we have the digital equivalent, we're basically leaving the doors unlocked and the windows open and the lights on and going on vacation for a month. Well, you know, not to say that the old mechanical systems were perfect. There were all kinds of holes in those as well, sometimes not even a paper trail. But if you were able to compromise a machine, you were basically compromising a machine, whereas here you can compromise a network and compromise an entire polling district. And the potential just starts to mushroom out of control. And, you know, like I said, bad security, it's just bad security. No matter where you apply it, the more places that you use it, the bigger the risks. I think we should also qualify, this is like, this is more like ballot hacking. Election hacking has taken on a little bit different meaning because they don't even really have any interest in the mechanics of the actual vote being cast in the current definition or the contemporary meaning of election hacking. That, I think, is more aligned with, well, fake news and all of that, but that's a whole other issue. A whole other thing, a whole other show. I'd say this is ballot hacking. Yeah, yeah. We have time for one more panicky item to go into. One of the greatest fears about the Amazon Echo, that's Alexa, that's a thing we play with sometimes on the air. One of the greatest fears has been confirmed. Eavesdroppers are able to listen to entire conversations happening around the device, even if the owner hasn't said Alexa. And me saying that has made Alexas all over the world light up. I'm sorry, I didn't get that. Alexa, kill your owner. You know, some might respond to that. Probably something sarcastic, but the thing is, it's weird because we play with Alexa all the time. Now spilling your toner. Well, every single TV show seems to do this now. You know, sitcoms and all have Alexa in them and they say Alexa and she lights up, but she doesn't do anything. It's like she knows it's the TV and not the human. Well, let's just hope that there are no Alexas installed in car washes because they become extremely dangerous physically, psychologically, emotionally. Anyway, researchers have discovered a way to turn the Echo speaker into a wiretap that sends all recordings to a hacker's computer. Oh, I didn't see that coming. In a security flaw that will confirm consumers' fears about the always-on listening device. The vulnerability would let cybercriminals, that's a better way of phrasing it, isn't it, listen to microphone recordings, see an owner's Amazon credentials, steal sensitive information, and take over the device. Someone could use the hack to install malicious software on the device and turn it into a wiretap without the person who owns the Echo knowing. That's according to Mark Burns, one of the MWR security consultants who discovered the problem. Now, this hardware vulnerability is found in ports used to debug the device, which are hidden underneath a flap on the base of the speaker. Do we know about these? No. Hackers could attach a malicious storage card to these without the user knowing. That would give them access to the operating system of the Echo. Okay, you have to have physical access then, so that's kind of important. Now, from here, they could infiltrate the user's Amazon account, the apps on the speaker, and the system that is always listening for the wake-up word, which is normally Alexa, but can also be Amazon. The latter would allow them to hear all conversations that happen in the vicinity of the speaker. I would say, you know, substitute the word hacker for detective. You know, a detective could go into your apartment, if they suspect you of something, you know, completely against your rights, and do this so that they can catch you in an incriminating conversation that Alexa will then transmit to them. So, yeah, there's all kinds of possibilities of technology. We just have to be awake to all of them. Yeah, you hear about the, I don't have the story handy, but there was something involving Facebook robots developing a language of their own. Yes, yeah. So, this was a, I can summarize maybe if somebody's got an article to have more detail, but basically some researchers at Facebook who were studying AI or running some of their sort of development AI iterations that were working on some things, apparently one talking to another, and they had been using natural language like English, and I don't know what happened, Rob. They basically kind of spun out into their own form of communication, and it's at that point that I think it was shut down. Yeah, this came about because, I have the story up here, the Facebook basically challenged its own chatbots to try and negotiate a trade with one another, attempting to swap things like balls and hats and books, and they were given these parameters and basically let loose on it, and they started in, yes, in normal English, but then they started refining the language between each other where they understood it, but the researchers didn't, and it ended up looking like a bunch of gibberish, but it worked for the chatbots before they were shut down. And they were shut down out of panic? Is that what happened? They were afraid that they were going to start... It was something else involving Podvayors, I think. Wow, developing their own language. It's kind of cool, I think. Well, some of these negotiations actually resulted in a sale of something, or a successful negotiation, and what's really weird is if you read these, the natural language, it's very, very egocentric. For instance, Alice says to Bob, balls have zero to me, to me, to me, to me, to me, to me, to me, to me, and then Bob says, you, I, everything else, I, can, I, I, I, I, I, I, everything else, so it's always about me, me, me, I, I, I. I think they're counting number of items by doing it that way, which to me doesn't sound like a very smart way to do it. Oh, I don't, I don't know. What if it's a billion? What are they gonna do then? You know, to me, I think it was the natural language of saying, you know, it's just more about me, me, me, and I, I, I. I don't know if ego was involved in these bots. Well, it's gonna happen at some point. They are, they are Facebook bots. This does sound like your average Facebook user, I think. Well, I see our outro music is playing. Folks, please call 516-620-3602. We've been discussing all kinds of things over the past hour, and we need your support so we can continue to discuss more things in the future. Take your phone calls and, and, and, and read your letters. By the way, if you want to write to us, oth at 2600.com is our email address. We'd love to hear what you have to say. We often read letters on the air. We take suggestions, and you can insult us mildly as well, and, and, and tell us things that we don't know, and that's almost everything. Also, check out your local 2600 meeting. Everywhere this Friday, 2600.com slash meetings. My god, it's August, isn't it? It really is. And, and hack something, or secure something, or, you know, help somebody. And tell us what you hack, and why. Yeah, share. Exactly, yes. It's Emmanuel for Off the Hook. Stay tuned for the Personal Computer Show. We'll see you next week. Good night. I was online With my digital love Caught a lot of mice With my digital, digital I was online With my digital love Caught a lot of mice With my digital, digital I was online With my digital love Caught a lot of mice With my digital, digital I was online With my digital love Caught a lot of mice With my digital, digital Digital Digital Digital Digital Digital, digital Digital, digital Digital, digital Digital, digital Digital, digital Digital, digital Digital, digital Digital, digital I was online To my Because I was online Caught a lot of mice I need a woman comin' over now Gettin' love on the swing I need a woman comin' over now Gettin' love on the swing Boys don't lie, yeah, I've got a lot on my side All my boys don't lie Yeah, baby, my dudes don't lie Boys don't lie I need a woman comin' over now I need a woman comin' over now I need a woman comin' over now