Pledging. I want to go in and answer your phone call, but you know what if the phone lines are busy Don't give up stay with us. I want to make a last call for this incredible material This is margaret prescott host of sojourner truth Help me to get the truth around teach the truth to the youth. Thank you for calling and pledging if I need to raise another $1,500 in the next few minutes, so help us out here. Keep calling us. This is your host margaret prescott prescott The number is 5 1 6 6 2 0 3 6 0 2 5 1 6 6 2 0 3 6 0 2 or go to give the number to Wbai.org And you are listening to radio station Wbai that's 99.5. If you're listening on a radiophonic device wbai.org if you're listening on a live stream And wherever you're listening, it's just about 8 p.m Eastern time time for off the hook The telephone keeps ringing so I ripped it off the wall I cut myself while shaving Now I can't make a call We couldn't get much worse But if they could they would Bum diddly bum for the best expect the worst I hope that's understood Bum diddly bum So So So Deferi Very good evening to you The program is off the hook Rob t firefly here with you and i'm joined in the studio by alex Howdy And by voltaire. Hey And uh on the phone we should have emmanuel and kyle you guys there It's on the phone rob, but uh, we barely have you if there's a little knob there You can turn so we can hear you louder. That would be so great Uh, let me try that. Uh, I push I turn the knob that says, uh, that says emmanuel. Did that work? You're a little better. But if you can have whatever knob is by your microphone up to the max I think that that's the best thing I believe I believe everything's in that position. So, uh, let's see We'll just have to let's make do with that. Uh, and yes, um, uh, kyle and I are out in on the west coast Actually, that's why we're not in the studio with you. Uh, we are in southern california where the temperature is baking hot Oh, no. No e i'm sorry. I have to correct you what? um, this is the the uh picturesque And scenic pacific northwest. Oh, wait a minute. Hold on a second. It's it's 95 degrees. It's smoggy What do you mean? It's the pacific northwest? No. No, it's um It's it's the forecast is actually calling for smoke today. Yeah, I saw that I thought I thought that was what los angeles had There was a guy running down the street saying it hasn't rained in 52 days, too Well, they're saying that um, seattle's the new la wow in More than more ways than one. But yeah, that's um That's true. We're in washington state Okay. Well, this is news to me folks. Uh, I thought I was somewhere else but um, uh, you guys are in new york That's what's important And um, and we have all kinds of fun things to talk about tonight. Do we have a special guest on the phone? We do. Uh, we are also joined on the telephone by uh noted security researcher. Sandy clark Hi, can you hear me? Hey sandy? How you doing sandy who is at the university of pennsylvania? She's uh, Uh, I believe infosec research scientist cyber security analyst. I'm sure many other things as well Yeah, i'm also short Well Uh, it's interesting. Um, we we um, we've been reading the story over the last couple of weeks about What happened at the recent hacker conference defcon? With um with voter machines. I'm just going to read an excerpt from usa today Where basically they said hackers five voting machines zero It took less than a day for attendees at the defcon hacking conference to find and exploit Vulnerabilities in five different voting machine types. The first ones were discovered within an hour And 30 minutes none of these vulnerabilities has ever been found before They're all new now. We all know usa today can exaggerate and get the story wrong Um, so how how accurate is that? Well, it's accurate that the first remote exploit was found within 90 minutes There were a couple of others that were um local that required access to the devices Um, they are similar to vulnerabilities that have been found before But several of them were new Wow, and and every machine got popped multiple times So there there was no machine that did not get hacked No machine that did not get hacked and and no machine that didn't did not find more than one vulnerability So can you give us an example of what a typical hack of one of these machines might have been? well These machines by the way the ones that we had with the exception of one which was a wind bolt That was running windows 98 and that's the only machine of all the machines that has been um excluded from from Future elections, but it was used in 2015 in virginia Um, so that's how recent they've been using. Um windows 98 on Every one of the devices had the absolute latest firmware and software upgrades that were available to them But they are running windows ce they are running old versions of linux they are we're running a um 2007 version of open ssl And because this is proprietary software proprietary firmware. This is the latest versions that you can run. So basically most of the vulnerabilities at um The and the payloads that you have in your tool bag would probably work Um what across those platforms, uh, what were the kinds of uh vulnerabilities typical of what people found? hard-coded passwords open ports and and Able to get in to write whatever they wanted. They were able to to download the firmware they were able to upload whatever um including A group that um, rick rolled one of the devices, but you could basically Um put anything you wanted on custom. They also found that some of the machines contained old information including the results of one election the um with obama winning but mccain getting a lot of votes as well and On one machine and this was really quite um disturbing because it's violation of federal law We found the voter records of I think 650 000 voters And so, um, yeah, so that was pretty scary Hey sandy, can I ask you a question? Uh, you mentioned that a lot of these outdated operating systems Were required because of firmware. Could you explain that to us? I'm, sorry required because of firmware. Yeah, I thought you mentioned something that there was a contingency between Firmware and outdated os's like microsoft xp or old versions of linux running No, i'm, sorry that I must have missed what I meant was that they were running the proprietary firmware and proprietary um uh proprietary software such that What we had on them was the latest and we have no other way to upgrade them because it has to be given to us by the manufacturers I see. So this outdated proprietary firmware Is the latest they offer I see interesting and this seems to to dovetail a lot with With some of the security problems that were the root cause of things like the wanna cry and wanna crypt ransomware event Would that be right? In a way, um some of the the upgrades that would have prevented Um, what cry could have been installed if um, if the people had installed it, but there are other problems with Medical i'm thinking particularly of the hospitals that were brought down many of anytime you change a device that has FDA certification you have to jump through a lot of other hoops in order to get it recertified So there's a lot of pushback against ever updating any of that So it's a different problem Sandy I had a question concerning how you guys were able to acquire these voting machines in the first place because we've been trying To do this for years And it seems like this is uh, exactly what what we needed to do was was actually get our hands on these things and not be restricted Well, where do you get anything right ebay? That's amazing and they're they were running they're running windows 98 out of the box now for those unfamiliar with windows 98 it came out in 98, which was about 17 years ago now or um something to that effect, uh Oh 19 years. Oh, so so it's old enough to vote itself in In some states, maybe maybe that's why it's there but um so we've seen this so often in um, just sort of the internet of things exploits and all sorts of things that come about where um, things aren't easy to upgrade things are uh, artificially limited and Um, so it's not just a matter of manufacturer responsibility of uh, keeping these things upgraded and keeping the latest exploits, uh, you know uh, uh quelled, uh quelled but uh it's actually impossible for somebody to to uh conduct good security practices with Something as important as an electronic voting machine and it's even worse than that because we when we think about the voting we're thinking about the voting machines that a voter or a poll worker has access to Maybe three days a year But there are also back-end systems That the ballots are designed on that the votes are tabulated on and the final tally and results are kept that the voter registration databases are on and frequently these also obsolete Computers are are running and connected to a network and available year-round Uh That's somewhat terrifying I have to say um, you know one of the The issues that keeps coming up here in particular on this show is in the wake of the 2016 election, there was an effort to Try to have some sort of forensic analysis of voting machines in various districts But that was stalled in federal court because of this chicken and the egg problem Where a judge wouldn't necessarily order a forensic examination of a voting machine unless there was evidence of tampering And how would you have evidence of tampering if you didn't have a forensic examination? So sandy given what you've seen at defcon and given what you know If a forensic examination was in fact ordered. How likely do you think it was that tampering would have been found? Well, I think that depends on the sophistication of the attacker, right? Because we know from our tamper evidence village at defcon that it's Equally easy to get through all of the basic protections that would provide evidence of tampering such as um stickers over the ports It just takes a little bit of alcohol and a syringe to remove that And then the sticker still works so you can replace it and there's a number of other ways that you could do that um that that you could um Remove stickers as well. Um alcohol is just Yes um If the attacker was sufficiently sophisticated Then any evidence that they had of tampering they could also cover up or remove uh, for example if they were going to Change the votes in in an election if the election was close enough, they could just flip the votes because the Paper trails are either not used um don't exist or What is printed out on the printer is whatever the software tells it to print out Anyone who who had malicious access to the the device itself could change what was printed out on the printed receipt as well And that would cover up any sort of evidence that they were there If they had access to the back-end database systems, they could alter an election for you Uh sandy you mentioned that um, these machines are mostly proprietary And there's recently an editorial by jane worldly in the new york times I have to uh cut you off there. Apparently we accidentally lost sandy So i'll uh, i'll try and get her back. But in in the meantime, uh, emmanuel and kyle Uh, why don't you uh, tell us a little bit about your travels? Well, um, I kind of want to bore the listeners with our with our uh travel especially I don't know what state i'm in But I do have a letter from one of our listeners on this subject that I think is is kind of appropriate So while we're trying to reach sandy again, uh, let's hear from bob in minneapolis Her rights, uh while I agree there is disturbing trend in using insecure technologies in elections in the usa as well as worldwide Uh, there has always been fraud with elections. One could argue that paper ballots are technology as well Paper is one of the most important technological advancements Ever and without paper, we would not have 2600 along with many other things Uh, there was plenty of fraud in the paper ballot days The problem is only partially related to technology and related more to people and process rob briefly mentioned process and paper ballots But in the era of paper ballots, there was still fraud because of people uh through bribes Breaking and entering to tampa with ballots, etc I fully admit that the problem is complex and an important one as our representative democracy relies on it But I believe that technology when implemented correctly can be an essential part of the solution Thanks, bob in minneapolis for that uh that opinion and I have to say You know, uh technology most definitely and we see this all the time We see this as kind of a theme of our program week after week. Uh, yes, it can be the um, uh, the essential part of the solution When implemented correctly and we see constantly it's not being implemented correctly There are mistakes being made left and right and when it's implemented incorrectly Uh, it can cause devastating confusion, uh compromising of a sort that was never possible before uh, it really um It depends on how competent the people are who install this What their true motivations are? Uh how the software is written in the first place Uh, so yeah, there's great potential uh for good and for evil and with that I hope we have sandy back. Absolutely. I'm back Welcome back sandy. Uh sandy. I was just reading a letter, uh from a listener who was talking about Fraud that existed back in the paper ballot days And um, I imagine that is a concern as well, of course back then um The most fraud you could really uh accomplish would be limited to one particular machine or as many people As uh, you could threaten with bodily harm or whatever Uh, whereas today, uh with the kinds of compromising we're seeing Electronically, um and tell me if this is an exaggeration entire elections could be swayed could be manipulated Oh, no, I think you're absolutely right because it's a matter of scale, right? and A paper ballot attack while there are ways to even counterfeit ballots. We found one in when we did our analysis um it's It really doesn't scale and the way to use the technology that we have To help us at least to do our elections now it would be to use paper ballots with optical scanners Because then even though it's possible to compromise optical scanners just as much as you can compromise any other computing device You can always go back to the paper ballot if you need to do a recount Okay Walter wouldn't one of the problems of optical scanners be that it only triggers a recount where they look at the paper ballots if there's a close enough margin of error and if so, basically anybody that's hacked the machines can make it so that there's Like a wide enough margin that there's not a uh, it doesn't trigger a recount And I I think that candidates, um, if they question election can also pay for a recount Uh Recounts are triggered in if an election is is really close If they think that there's a problem or if a candidate wants to pay for it Yeah, I think that's the difference between like an automatic recount maybe and then when it is contested to me That's that's a that's a human problem more than it is a computer problem. We're saying that it's triggered Uh by a particular percentage, but we could change those rules We could make it so that every election gets counted twice. Why not? We we Computers can do these things we count them twice and the numbers should be exactly the same if if if they're not Then maybe best two out of three or something But if you're using a purely digital, uh device and you're not using a paper ballot being counted by by a digital device Then then the purely digital device will just report the same number twice. Anyway, how do you tell? That's true Well the the way around that would be to have a manual recount of the actual paper ballots, right? So so we have to have a paper ballot Yeah, and this whole idea that we have electronic voting machines in so many districts that are critical districts and without Any paper ballot associated whatsoever just strikes me as completely nuts these days knowing what we know about voting systems Knowing what we know about the certification process and their susceptibility to compromise The fact that we have these Electronic voting machines with no paper records to me You know and this was an argument that was made in some of the complaints filed by jill stein Almost seems like an equal protection under the law or equal rights violation to those voters in those particular districts Because they're at a higher risk of having their right to the franchise completely compromised Well, you have to understand too how This came about it was Rushed very very fast after the 2000 election because of all the problems with the chad the hanging chads and the dimple chads and and the whatever and and supposedly they were unable to to count the votes in florida because of how bad the ballots were And so the government funded this Which meant and and and the government rarely Gives a funded mandate where they they will pay for states to buy a whole bunch of stuff And in this case, they had to buy electronic voting machines And if they didn't use the money by a certain period of time the money would be taken away from them At the same time we had the american with disabilities um lobbying for these because A device that can You can plug a headphone into and it can tell you. Um, what the various Candidates are and where they're located Allows people with visual problems to be able to vote in secret They don't have to bring a friend with them to read the ballot or something like that And so those Lobbyists for the electronic machines and lobbyists for the american with disabilities Really pushed this movement forward and it happened very very fast And so no one even had a chance to develop a secure machine and and most of the voting machines were developed and sold by people who make atms like d bolt And they have completely other problems, I mean they were able to claim, you know, well we can keep your money safe So like, you know, of course we can keep your voting safe, but it's not the same problem at all You can't operationally. Yeah, the entirety of the workforce is it's a different mentality as far as securing it And and the trust inherent in that And who has access to it? Yeah, the chain of chain of custody and so on Exactly most of voting machines sit in a closet or in a warehouse Yeah, I think the thing with like atms is you have a different state, um that model than voting machines like where's atms You'd be battling petty criminals. Whereas voting machines you have to face down nation states, which is a lot harder On that on that subject. There's actually a story. Uh just came out in the washington post Uh kenyan president uhura kenyatta took what appeared to be an unassailable lead today In his bid for re-election even as his opponent called the results fraudulent Uh, 93 percent of the votes have been counted kenyatta led uh leads with about 54 percent far ahead of opposition leader Rayla Odinga at about 45 percent. Odinga is calling the result of yesterday's election a complete fraud Outlining an elaborate hacking scheme that he said significantly manipulated the outcome According to Odinga a hacker used the login information of a top election official chris zondo Who was mysteriously killed last month to enter the country's electoral database You know, it just seems uh sandy that with every election that's happening from this point on There is going to be some kind of accusation of of uh, the the whole um process being hacked Uh, how on earth do we ever recover from this? That is the question that We're all wondering about right now, and I don't have an easy answer for you I think the only way to do this is to use paper ballots and scan them optically Um, at least that would give the results quick enough to satisfy the news uh sources and things like that, but There's no other way. There's no other way that we can get have any guarantees. Is that done? Uh, I know canada has a very simple system where basically people just mark things on a piece of paper and they get counted Um, is that the kind of model you're looking at? That's exactly the model i'm looking at Um, but we have the world's like most complicated ballots, right? they're 13 pages long and they're full of all of these other little things because you'll vote for president of the united states and your dog catcher in the same election and the complexity Makes things so much worse But the only way that we can have any sort of confidence In the result of our election is if we have paper ballots that we can go back to Anything that's not entirely digital I don't think anyone's going to trust anymore Absolutely, um, so sandy you were uh, you were at the defcon conference, uh, Which recently happened in las vegas and you and some other folks had a whole voting village set up Uh there could you uh, tell us a little bit about how that came about? It was fantastic um It took us a while to find a number of machines and we weren't sure what we were going to get so When we were setting everything up, we were very unsure whether anyone would find it interesting at all We thought people would come and look around and say oh voting machines meh and go back and do something fun like car hacking and instead We couldn't even set up a full election. We didn't have The equipment that would you would design a ballot on we didn't have any of the tallying we didn't even have some of the the um Things that we needed to actually erase and reset a machine from scratch We just had These boxes that we picked up off off of ebay and from a couple of other options And set them up got everything up and running the best we could and then people just Came and went to work and it was just The reason I love the hacker community. It was just phenomenal um and We had people coming in All hours and staying for a while and coming back with with oh, I think i've got another idea so I was I wish it could have been there because it was just great Well, this certainly won't be the last time this happens in fact, we hope that uh, you're at the circle of hope next july Um helping us to do something something similar Um, i'm curious though. Has anyone in the uh in the voting machine industry or even politicians? Uh reacted in any way to what you guys did Oh, didn't you know? We had two um congressmen come and visit During defcon. Oh my and they actually they actually did a podcast um Also, i'm sorry i've forgotten their names But it was one was a democrat and one was a republican But they were both absolutely united in the need to fix voting and And they were actually very pleased with what they saw and then they came and spoke to everybody So so I was I was Surprised and really pleased at the positive response. We got we got from from um our representatives As for the vendors We get you get the response you always get from vendors, right? Yes In fact a few years ago, uh, we had gone to a demonstration uptown of new voting machines and we asked the vendors Hey, you want a bunch of hackers to um, uh to look at your machines and tell you how secure they are They never got back to us Um what I would like to see in the future I'd like to see those new machines the ones that are being implemented, uh throughout the country um Have them give those to us. Let us test those And uh and and report back if if they are secure, they should have nothing to be afraid of precisely When we did our study back in 2007, we were one of a very small group of people that had The luxury the good fortune to be able to to get our hands on these machines and even then the vendors fought for quite a while, uh Um to to try and control what we would be allowed to tell the public they wanted um final say on On what they could remove from our report and we wouldn't we didn't agree to actually um sign the ndas and look at anything until we had um control over Everything that we we could say so we Our compromise was that we would keep the actual proof of concepts In a private appendix, but that the public would learn of every single vulnerability we found and We were the second group. There was another group We did I I was part of the ohio ever study that was led by the secretary of state of ohio at the time Uh jennifer burner her name was and there was a previous study that had been done in california The california top to bottom state and those were pretty much the only two studies that have been done On machines that are used in the u.s So maybe 30 people had had a chance to look at these machines and because of of defcon now thousands of people have had a look at these machines and every voting machine needs to have thousands tens of thousands hundreds of thousands of of people who understand security Getting a chance to pour over them. They should be all open source hardware open source firmware and open source software What kinds of uh criteria did you guys have for hacking? Was it basically anything goes? I mean where people bring in uh, you know band saws and heavy equipment or did you see any uh, anything that Maybe made you take have a pause that maybe it might be a bit much Uh We only asked that they keep one of each device whole so that anyone who came after them would have a chance to try something but At least one of everything got taken apart at some point Nobody actually brought in a spectrum analyzer or an arc welding latch man, so um, maybe next time Wow sandy what you've done. I think what you guys all have done is is a tremendous service to um, To the entire public not only in this country but worldwide because these are exactly the things that we need to know And it's that it's that hacker ideology of uh of opening it up and and full disclosure Uh that um, that is is the honest truth and you have to wonder Uh about anyone who doesn't want that to be known So I think what you guys did as far as revealing all of that and and trying to get as much information as possible Uh really did a lot of good Well, but it wasn't us it was the whole hacker community right it was everyone who showed up and they could mess with something um That's that's the only way we're going to be secure Is is there is there any um any site you would recommend where people can remain updated on on this? I would go to eff and They they pretty much and I think aclu And probably um the center for democracy and technology cvt Are good sites that that always have the latest information of what's going on And many of the people who had a chance to work on both the california and the ohio studies. Um Publish or or tweet with um with those Um hashtags so so if you're watching or following any of that you'll hear whatever's latest going on there Um Excellent and uh sandy where can uh folks who are interested find more of your work online Most of my work is on my site at u-pen uh Center exceeds i'll send it to you Okay, so if they go to upen.edu and uh search for sandy clark, would they find I tweet as sa3 nder Excellent Well sandy, I will let you uh get back to your life, but thank you so much for joining us Well, thank you for asking me Absolutely Cheers Good night. Bye Okay, um that that was that was really cool um So i'm emmanuel and kyle I don't know if you guys uh want to hang out as well or uh, or get back to what you're doing over on the left Coast but well, uh, seeing as how i'm not in the state. I thought I was in I need to do some uh, some uh, Adjusting but uh, I know you guys have a lot to talk about with some other um, uh fallout from from that conference And uh and the hacker world as well as I understand, uh, you need to be raising some funds for this What we're now told is really the final week of the summer fundraiser Uh, so I think it would be best if we if we sent it back to the studio for that and uh, Encourage people to write to us oth at 2600.com with any feedback or questions or things like that And um, we'll join you again next week. We don't know where we're going to be I'm sure i'll get it wrong wherever that happens to be Okay. Well emmanuel and kyle, uh, good luck with uh with your travels over the next week Uh, thank you very much for joining us tonight Thank you. Good night Okay Well, um after all that, uh, we do have to uh raise a little fund So we're gonna go through this quickly, uh, we know we've we've heard from uh, some listeners out there who uh, kind of Kind of get uh, kind of get a bit. Um fed up with all the fundraising we have to do But the fact is we have to do it because it's the only thing that keeps these lights on in here It's the only thing that keeps these radio waves coming to you from the top of the expensive state the empire state building and uh It's it's the only way that uh that we can keep doing what we do here at off the hook and here at wbai so I will give you the pledge line, which is 516-620-3602 Or the uh website which is give to wbai.org And we have a few things that uh that we're offering in in um in return for your support this week We have a few left of the historic data storage painting by I can't read this name here. Oh, it's me Rob vincent aka rob t firefly of wbai is off the hook. I am as you may know, um an artist in my other life and um as part of my uh as part of my Art pursuits i'm doing a set of paintings acrylic paint on canvas five by seven inches of historical data storage paintings historical data storage devices from all over technologies history from all over human history Basically, um various ways and means that people have stored data And there's some stuff from the computer age. There's some stuff from the pre-computer age. It's going to be interesting. I'm going to Be uh live streaming the painting of some more of these I did that with one of them and it went over well So keep an eye on our twitter at hacker radio show for a word on when that happens again um, but for a for a contribution of Fifty dollars or more you can get one of these historic historic data storage paintings and uh There's there's a very limited amount left just a few left And after that the set will be complete and locked and loaded And i've already got a great deal to paint and just a few more left and yeah, so Uh, we've totally appreciated all your uh, all your support over the last a few weeks And the response to this has been pretty mind-blowing for for me personally and for us here um, so yeah, I won't go over this too, uh Too too much because we also have some other stuff. Um, we have some uh Some things from the hope conference. We've been talking about conferences and the things that happen at them and we have uh, once again a series of flash drives or with video files or dvds um your choice of the hope conference keynote addresses Um as well as some other popular featured talks from all 11 From all 11 of the hackers on planet earth conferences that have happened Um people like edward snowden steve wasniak cory doctorow kevin mitnick jello biafra cartoonist aaron mcgruder, uh Who else rich? Uh, i've said richard stallman. I have not said richard stallman richard stallman you guys that's right And remember a long time ago siva varianathan Yes, and you've you've pronounced that better than I ever could try that again Siva varianathan, I remember that specifically because he was at nyu at the time and and I think I was partly responsible for getting him Uh into the keynote position and I had to learn that name quite a while Quite regularly excellent. So you're in charge of pronouncing that for the rest of the show varianathan well done and uh, you can you can get all these uh, all these great talks on a set of Either dvd discs or a flash drive containing video files totally drm free um for a pledge of 75 or more Um, ask ask for the hope conference keynote series flash drive or the hope conference keynote series dvds um When you call 516-620-3602 or search for those items when you go to give2wbai.org Um, this is the final week of this fundraiser and it's a critical week because Basically the the amount of support that we get here at off the hook. Um directly Affects us here at off the hook and our ability to keep doing what we do on the station and it affects directly What what how how much we can do at the station in general just with wbai's continued existence In this bizarre and wonderful experiment that started in 1960. It's been going on for 57 years now Just based on what we're doing now, which is asking you the listeners for your help and your generosity and for you to Basically come out and say that yes, this is worth supporting. This is worth continuing to happen um, so 516-620-3602 or give2wbai.org and uh, yeah, if if you're not into any of these premiums, uh, or if you want to donate a A lower amount or a different amount or a random amount or what have you any amount helps, um, just uh, just let the person on the phone or Select the uh the item on the menu that says you're donating in the name of your favorite show Which we hope is off the hook Um, it's certainly among my favorites You can also text you can text the letters wbai to the shortcode 41444 and you'll get a text back with uh with the With the next step to process a donation and that way does not get you our special premiums, but that way um does get you other things you can uh, you can um, Support support the station just with any amount you can give whether it's a few dollars or whether it's a big pile of dollars or uh or anything So yes, give2wbai.org 516-620-3602 Or uh text 41444 Well, I'll i'll be the first to say I can't wait to get My two happy little historic data storage devices that are going to be painted by our very own rob t firefly I think they that's a fantastic deal. Everybody should consider it Uh, if they haven't already we've been on the air fundraising, I guess this is our fourth week right now and um, Please don't make us do this any longer We we try and limit how much of this we do it is a reality of what we're doing here because Frankly it's expensive to run a radio station in um, a frighteningly major media market like new york city and uh, yeah, I mean we we could uh, we could we could basically uh Just stop paying for all this just let it go But if that happened, we would not ever get anything like this back Not here not in new york city not in the middle of the fm dial Um, this this is just like it's a complete fluke that this place even happened in the first place So, um the fact that uh, the fact that it's on such a such tenterhooks such a such a tenuous grip on its continued existence um, really Really means something because if we lost this we would not be getting it back um, and and there's so much important stuff that goes on at the station so many important things to talk about which You know, maybe is a good segue What do you think ralph? I think that's a very good segue. Yeah, fantastic Uh, one of the really important things that happened last week to get back to the the meat and potatoes of our show here Uh, and thank everybody for their support. By the way, if you are calling in and pledging once again, 516-620-3602 Malware tech also known in his by his real name as marcus hutchins was arrested last week in las vegas After the defcon and blackhat conferences He is best known as the guy who stopped the wanna cry Wanna crypt ransomware attack by registering a domain name that he found when he was analyzing the malware This turned out to be a sort of sinkhole it was a kill switch for the domain name and it stopped the worldwide spread of this particular ransomware attack that we had tangentially referenced in our earlier discussion with sandy clark This was a ransomware attack that was affecting places like the national health service in the uk And just spreading all around the world causing mayhem So he was hailed as basically a hero of the information security community And a guy who didn't really want a lot of the praise He seemed very demure about it and was very casual and and came off looking I think incredibly classy in my opinion I think we should say he was he had been anonymous before this time or pseudonymous like running the blog and so but some Tabloid journalist in the uk after he stopped it like basically doxxed him That that's exactly right. Yeah, he didn't want his name out there, but At any event last week. He was arrested by federal authorities while in mccarran airport in las vegas Attempting to leave the country and head back to the uk and he was arrested on an indictment that had actually been I believe the indictment came down on 11 july So that's something interesting right there this indictment came well before he well actually shortly before he entered the country Which raises a lot of questions here? um, namely What did the uk government know about this if anything at the time? and Was marcus hutchins being surveilled while he was over at defcon who were the people with whom he was consorting? I'm sure everybody and all of his associations are probably a little worried here Part of the the big problem with what happened with malware tech is that there's a tremendous fallout from this in the information security community and this divide in my opinion frankly is intolerable it's also unnecessary and it's also really destructive because After the snowden revelations in 2013 There was a big divide between I would say the private sector the government and the information security community because nobody had any trust of each Other and here we are in another situation just a few years later after that divide has slightly been healed Where we now have somebody who is a security researcher? arrested on what is Arguably a rather flimsy indictment Alleging he violated the wiretapping app alleging various things about the computer fraud and abuse act and this sort of rift is going to cause a dearth of information sharing between the private sector and the government again just at the time when it's incredibly critical that we have such Collaboration happening for all the very reasons that sandy clark had mentioned with respect to voting machines earlier in our program Yeah, a lot of researchers have actually gone on record and saying that they're not Stopping sharing information. So it's this repercussions have already started Yeah, I think that's that's exactly right and you know, we have the indictment here and everybody talks about the indictment, you know Rob, what do you think? Do you think we should read it into the record? We've got a couple of minutes. It would probably take about four or five minutes if I read it quickly What do you think? I think uh, I think um, yeah, let's let's do this. Okay, let's give it a shot I'm going to read really really quickly and when I say redacted that means that this is the name of the unindicted co-conspirator That is missing from this particular indictment Okay indictment case 17-cr124 Count one the grand jury charges at times material to this indictment defendants defendant redacted use the online aliases redacted Defendant marcus hutchins was a citizen resident of the united kingdom hutchins used various online aliases including malware tech Relevant terms a protected computer Was a computer in or affecting interstate commerce commerce or communications including a computer located outside the united states that is used in a manner That affects interstate or foreign commerce or communications of the united states Malware, it's interesting to see how these things are defined By the way was a term used to describe malicious computer code installed on protected computers without authorization that allowed unauthorized access to the protected computer Kronos was the name of a particular type of malware that recorded and exfiltrated user credentials and personal identifying information from protected computers Kronos malware was commonly referred to as a quote banking trojan Encrypting was a term used to describe computer code used to conceal the existence of malware from antivirus software the conspiracy Between in or around july 2014 and july 2015 in the state and eastern district of wisconsin and elsewhere redacted and marcus hutchins aka malware tech knowingly conspired and agreed with each other to commit an offense against the united states namely to knowingly cause the transmission of a program Information code and command as a result of such conduct intentionally And as a result of such conduct intentionally caused damage without authorization to ten or more protected computers during a one-year period in violation Of title 18 united states code sections 10 30 a 5 a c 4 b 1 and c 4 a 1 6 manner and means of conspiracy the manner and means sought to accomplish the object and purpose Of the conspiracy included advertising the availability of kronos malware on internet forums selling kronos malware receiving and distributing the proceeds obtaining Obtained from selling the kronos malware and acts done in furtherance of the conspiracy concealed and hidden and caused to be concealed and hidden overt acts and furtherance of the conspiracy and furtherance of the conspiracy and to accomplish the act and purpose of the conspiracy the following Overt acts among others were committed and were caused to be committed Defendant marcus hutchins created the kronos malware on or about july 13th 2014 a video showing the functionality of the kronos banking trojan was posted to a publicly available website Defendant redacted used the video to demonstrate how kronos worked. Let me just interject something here There's a lot of redaction coming in these next paragraphs and that's mostly about the criminal conduct In around august 2014 on an internet forum defendant redacted offered to sell the kronos banking trojan for three thousand dollars In around february 2015 defendants defendants marcus hutchins and redacted Updated the kronos malware on or about april 29th 2015 defendant redacted using the name redacted Advertised the availability of the kronos malware on the alpha bay market forum on or about june 11th defendant Redacted sold a version of the kronos malware in exchange for approximately two thousand dollars in digital currency on or about july 17 2015 defendant redacted offered Crypting services for kronos all in violation of title 18 united states code section 371 count 2 the grand jury further charges Between in or around july 2014 and august 2014 in the state in the eastern district of wisconsin and elsewhere Redacted and marcus hutchins aka malware tech knowingly disseminated by electronic means and advertisement of any electronic mechanical Or other device knowing and having reason to know the design of such device renders it primarily useful for the purpose of the surreptitious Interception of electronic communications and knowing the content of the advertisement and having reason to know that such advertisement Will be transported in interstate and foreign commerce in violation of title 18 united states code section 25 1 2 1 c 1 and 2 Count 3 the grand jury further charges that honor about june 11th 2015 in the state in the eastern district of wisconsin and elsewhere Redacted and marcus hutchins aka malware tech intentionally sent electronic mechanical or other Devices or other device in interstate foreign commerce knowingly and having reason to know the design of such device renders They're primarily useful for the purpose of the surreptitious interception of electronic communications in violation of title 18 united states code sections 25 1 2 sub paragraphs 1 a and 2 Count and counts 4 and 5 And 6 are all very similar I don't think it's worth reading the entirety of those into the record since we we only have about 10 minutes left here But you get the gist of it and the gist of this indictment primarily has to do with this unnamed Uh co-conspirator here Um, we can't say unnamed and unindicted because he's he's in the indictment. He's just redacted So this brings up a lot of issues too. I mean who the hell is this guy? Uh, and for me, I wonder if he's cooperating with the government at this particular time and perhaps that's the reason why his name is redacted That that seems to be uh, that seems to be a solid theory I mean the fact that this is an indictment it is indicting both of them Um, but uh, but they're withholding the name of one of them for some reason in the published version Um, yeah, they they want to they want to cover this, uh, this person, um, whoever he or she may be um And yeah, if this is if this is such a such a high profile case and such a big deal a big enough deal to Follow, uh, follow hutchins around a hacker conference and then nab him as he's trying to go home um Yeah, that that seems like it seems pretty heavy and it seems like a strange way for the powers that be to go about it I I think that's absolutely right and there's there's a lot of questions that remain unanswered from this particular indictment, you know Namely, what is really the the government's theory of the case here? We don't know a lot of facts You know a lot of what they're alleging rests on this july 11th 2015 act of the sale of this particular malware the alleged sale of chronos supposedly, you know on the other hand there were posts all over twitter about malware tech posting I think in I I actually don't remember the year maybe full tear. Do you remember the year where he posted a twitter message? where he was looking for particular snippets of the chronos malware Yeah, you don't remember that okay, sorry to put you on the spot there but um In any event, there's a lot of indications that he was actually that malware tech marcus hutchins was actually looking for this particular code Which you know, maybe exactly the type of thing you would want to have on the record if you actually did in fact create the code I mean, that's one running theory, but we don't know a lot about the facts that are really underlying this We don't know who this person is, you know at this moment in time as of I believe it was Uh friday, um Yeah, I think it was friday that um malware tech was actually granted bail It was thirty thousand dollars bail and the conditions of his release at the moment are are pretty tough I mean, he's not allowed to leave the country had to surrender his passport. He's not allowed to use a computer um that Raises a lot of issues about the participation in his own defense, right? And uh it that went through on at 3 30 p.m On friday, which meant it didn't get brought back by the 4 p.m Deadline to get it done by the business day. So um hutchins had to spend the weekend in jail and was freed monday But that's that's exactly right. You're you're exactly right. Sorry about that Um, and then that caused I believe he's going to be heading over to milwaukee to wisconsin to be arraigned On 14 august which is this coming monday, so he hasn't pleaded guilty or not guilty to any of these crimes yet That's what the arraignment is for He will go in front of a federal district court judge on monday in milwaukee and they will read to him the charges There probably won't be much more Information coming out of that but uh in all likelihood he's going to plead not guilty all that being said according to uh, some of the reports that have covered the hearing last week While he was in custody after he was arrested, I believe it was last wednesday He spent about 24 hours in fbi custody during which he was interrogated without a lawyer um, he In my guess voluntarily spoke to the fbi Most people even uk citizens are generally aware of the miranda rights and according to the fbi He confessed to writing some of the code of cronos I really wonder however about whether that's a real confession because in the security community people write snippets of code all the time That could be maliciously used in Subsequent malware. So admitting to that hardly seems like a confession to me Yes, certainly. In fact, uh, somebody there's another old tweet of um, Malware tech where they he's he's uh was saying that Somebody he found an example of a piece of malware using an open source code He wrote um, and he but he basically saying like that's kind of Like how the industry works and it's very problematic that they'd be charging him for that And you and this has a major effect on on our community and hacker community on the information security community because of the chilling effect This is going to be having on on free speech I mean we saw how important it was at defcon to have this voting booth hacking village We've got the circle of hope coming up next year I mean how reticent and how reluctant are people going to be now to come to the united states when? They perform research and analytics like this. I mean how Worried are people going to be about there being some sort of sealed indictment out Somewhere, you know where they can be arrested when they're trying to leave the country or leave a particular conference I mean this is going to have a a major chilling effect on The freedom of association and and the general sharing of critical security vulnerability information So definitely the the infosec community is taking this as a as a stab to the heart which it rather is there's a story on the register.co.uk discussing the case and talking about how um hutchins was very widely respected in the in the security community and Experts all over the place basically are withdrawing their participation in the open community In response to what's happened to hutchins because you know, no one else You know others others are starting to feel to fear for their Liberty and safety and stuff if they continue to do their job, which is to research security Also the fact that the uh, fbi waited until after he was done in vegas and on his way out As opposed to like navigating on his way to defcon. It makes me feel like maybe they were on the information fishing exposition You know, it's it's really quite true. I mean, I we we just don't know right now and and I think it's it's very easy for us to simply dismiss the This indictment as really flimsy and but I I think we have to wait to see what the facts are when they pan out I don't want to pass judgment on this at all. I do think that there are some Sort of novel and very tenuous legal theories upon which it's based Uh, this is going to be an extremely interesting story really interesting litigation And we wish him the absolute best. We're here to support. Absolutely. We're going to be keeping a sharp eye on this We encourage you to as well Uh hutchins own site is malware tech.com. Uh, you can find his tweets at uh, malware tech blog Is his twitter screen name with the at sign in front of it as is traditional on that site? Fantastic Do we have one minute to share some some interesting stuff? There was just some news that came out about north korea We have a very short. Okay I would like to show share you guys with you guys some interesting stuff that we mine generally at my firm We do a lot of intelligence related to the domain namespace and I just wanted to share with you over the last 24 hours some of the domain names that were registered in the dot-com space Uh interestingly enough, uh, we we've got some very very curious data sources that we can get this from Uh north korea v usa.com north korea miniature nuke.com north korea miniature nuclear warhead.com The north korean war.com dprk north korea.com and weirdly enough North korea casino.com Although I think that was updated and created in april But um, one of those rings very close to our heart the north korean ward.com Uh was registered right here in brooklyn just a couple blocks away from the station as a matter of fact Uh, let's see what happens. Let's wish the world the best absolutely um and with that, uh, we've uh, We put the we put the cap on another week here at off the hook send us email oth at 2600.com follow us and ping us on twitter at hacker radio show and uh Continue to keep your eyes open continue to support what we do here on this program in the station give to wbai.org Or 516-620-3602 Or text wbai to 41444 Thanks again to our guest sandy clark Thanks to emmanuel and kyle for uh pitching in from across the country And thanks to you the listener who uh Who this is all for? for off the hook This is rob t firefly Have a very good week So So With somebody So So With somebody So Right on right on Join the jam Oh Hey