From 2pm to 3pm, we'll be bringing a show to WBAI 99.5FM titled On Air With The Blacks. We'll feature the latest in pop culture news, music interests, and issues facing the LGBTQ community of color and beyond. God help the WBAI audience. You have no idea what you're in for. Until then, live the hype life. Wow, we missed that, didn't we? Well, you can go to the archives and hear it there, WBAI.org. You're listening to WBAI in New York. The time is 8 o'clock. Time once again for Off The Hook. But if they could, they would. Bondedly bond for the best, expect the worst. I hope that's understood. Bondedly bond! And a very, very good evening to everybody. The program is Off The Hook. Emmanuel Goldstein here with you. Joined tonight by Rob T. Firefly. Good evening. Alex. Good evening. Kyle. Yo, what's up? And Voltaire. Hey. Well, here we are again on another Wednesday evening, talking about high technology and hacking incidents and cyber threats and all sorts of things like that. Taking your phone calls a little bit later on. Boy, did we get a good response to our discussion last week about something you might not think is hacker-related, mass transit. But it is. It is, because there's all kinds of technology at work there. And we're always trying to figure out how to make things work more efficiently, what the vulnerabilities are, and just comparing automated systems of one sort or another, because they are kind of fascinating. Let's look at a couple of letters. And we'll get into some other stories in a little bit as well. In regards to the transit pass talk on the previous show, someone made a comment about the MTA cards being prone to damage and slow from having to read and write to the magnetic stripe. And when I was in New York City this past June, I experienced just that. I'd loaded $20 on my MTA card, MetroCard, that is. But it later got a very slight crease and no longer read. And after spending a good 10 minutes trying to work out the crease, it finally started to read again. So I can see how these are susceptible to easy damage. I much prefer the DC transit pass, as it can withstand a lot more. Thank you, Dave, for that letter. And our email address, of course, oth at 2600.com. Philip writes, I've been an on-and-off listener to Off the Hook for many years, at least since the late 1990s. I live in Winnipeg, Canada. In your last episode, you guys were discussing transit smart card systems. Recently, I visited the UK in July, made extensive use of a visitor Oyster card while I was in London. I found the system quite easy to use and straightforward. I also used the trams in Manchester and Nottingham and many of the double-decker buses while in the UK. This trip was my first ever leaving North America. I'm a bit of a transit geek and rail fan, so I'm always fascinated to hear about the differences in the transit infrastructure in different places. I really enjoy your radio show and look forward to hearing it on my podcast client each week. And folks, if you have a podcast client that does not carry our radio show, please let us know what it is so we can make sure that we're covered on all bases. If you have any ideas of better ways to distribute Off the Hook, we'd love to hear it. Anyway, continuing with this letter. My own city, Winnipeg, introduced a smart card system too just last year. Ours is called a... Nobody here knows, right? It's called a Pego card. Yeah, a Pego card. It's similar to London's Oyster card, an RFID-based non-contact card. And it's used here to ride the newly introduced BRT system and regular bus services. And, you know, I find that in so many cities, there's a really cool name. What is it? It's the Orkder card in Seattle. I still can't pronounce that. Yeah. And it's the Jazzy Pass in New Orleans. What's it going to be in New York? Because eventually they're going to introduce a contactless RFID-based card for all your mass transit needs. And it's going to have to have a cool name. We can maybe decide it now because there's probably people working right now in offices designing the system. And they have yet to come up with a cool name. And that's what we're here for. Go ahead, Volterra. Maybe. Lazio has been fighting with Cuomo to get funding for MTA. So maybe there's a compromise thing called the Cuomo card. Really? Really? You think that's what it's going to be called? The Cuomo card? I could go even worse. Like with something Apple-related. You know, like Big Apple. That whole… Apple card? Cliché. Yeah. Or a rat-related card. Oh, yeah. Because that's what we want to advertise. Our New York City's rats. Pizza rat card. I told you. Cliché. Uh-huh. Okay. I don't know. Well, I think we all pretty much agree that the Oyster card is better than what we have now, and it's kind of the gold standard of transit passes. But we received an email from our friend Karamune in Tokyo, who believes differently, and I'm gonna read that letter. Thanks for such a fascinating discussion of transit systems last week, you're very welcome. I know some of you have been to Japan, but your listeners may like to know that the fare card system here is the best in the world, and I don't say that lightly. There's one system for the whole of Japan, as far as the passengers are concerned. Two cards are available, the Suica, I'm not sure if I'm pronouncing that right, S-U-I-C-A, and PASMO, but they're identical from the passenger's point of view. Suica stands for Super Urban Intelligent Card, I don't know what the A is for, but okay, that's what it's called, the Suica card, it's already intimidating me. PASMO is named after the system it replaced, PASNET. The cards use Sony's Felica RFID system. The cards are powered by the reader, work from about 10 centimeters away, four inches or so. Unlike many systems outside Japan, Felica uses mutual authentication to help prevent scammers setting up fake card readers. The cards contain an 8-bit RISC CPU combining EEPROM, RAM, ROM, RF capability, et cetera. The reader communicates in the 13.56 megahertz range at 212 kilobits a second, that is, using Manchester coding. Specific enough for you guys? In 2009, over 41 million cards were in use, I guess there are far more in use now. The cards can be used on just about every train, bus, monorail, tram, and taxi in Japan, except for the Shinkansen bullet trains, and you can use them at convenience stores, kiosks, many shops, and of course, many vending machines. Japan's famous vending machines sell loads of things, including hot and cold drinks, ice cream, umbrellas, books, hot snacks, candy, potato chips, cookies, and batteries, et cetera, et cetera. The cards require a 500 yen deposit, that's about $4.60. To get this back, you need to return the card, and that's something I still don't understand about London, because I got the deposit back, but I got to keep the card as well, so I'm not sure what the deposit was for. It doesn't make much sense. No, it doesn't. The card can hold a total of 20,000 yen, that's $184. You can, of course, change your card, or I'm sorry, charge your card from your cell phone using systems such as Apple Pay. The cards just seem to work really well, and if there's ever a problem, you just tell the staff and they fix it immediately, and the staff are friendly and very helpful. In comparison, London's Oyster card is a disgrace. That's right. It's a disgrace. Can you imagine what the Metro card is? As a Brit, I'm deeply ashamed of it. The system is infamous for overcharging. The transport for London staff are rude, incompetent, and unhelpful. Hey, it's London. I mean, that's what I expect. And the staff are often absent or hiding. Wow. Well, you know, it's simply amazing to see all these different perspectives. Thanks, Karamun, for your perspective here. I look forward to testing out that system. I look forward to a system like that coming to the States, coming to New York. I mean, using a card for everything, using it for cabs, using it for convenience stores and vending machines, it can collect quite a bit of information about you and your habits, I would imagine, and this intelligent card might get more intelligent than you would like it to be. But still, you know, remembering back the days of tokens in the subway system, it is a lot more convenient. It is, and I think, you know, we're venturing towards that, and especially over in London as well, where they have these contactless credit cards that can be used, or rather connected to an Oyster card account that will allow you to just waive the credit card contactlessly over the turnstile and open that up. And then, of course, you can go and use that in a pub, and you can use that in a restaurant, and you can use that to buy provalactives, whatever you want, and it's all connected to you. So I think we're already moving in that direction quite rapidly. Seems so, and it seems people are embracing this. So if that's going to be the way that things are done, then we just need to learn how it works and how it can be manipulated. Yeah, especially if it advances and becomes something that's used for, like, single-payer health care or something, that there's a lot more information floating around. You know, imagine going to all your different doctors with one card that whatever the government, big government pays for, and whatever utopia that is. Yeah, yeah. Kind of like loyalty cards, you know, in supermarkets that everybody seems to use these days. In fact, the other day, we were in a store. Do you remember this? We were in a store, and you were being interrogated for your loyalty card. And the thing is, you kept giving out different phone numbers that were associated with you, and none of them were matching. So basically, you were giving the clerk all your phone numbers and not getting anything out of it. And the thing that really got me is that even if you had given her the right one, you don't get anything. You don't get a discount. A lot of these loyalty programs, I don't know what the purpose of it is. They just know how to target you better, and they certainly know your habits better. But if someone could enlighten me on what the appeal is for loyalty programs that you don't even get a discount for, I'd love to know. Well, I'll tell you, Dwayne Reed is notorious for having, I think, the worst loyalty program ever. I mean, I don't think I've ever gotten a cent back from them. So why do you have it? I don't use my real phone number on it. I mean, maybe we should give—should I give people a great tip about these loyalty programs this evening? Yeah, go ahead. Something that seems to always work. No matter where you are, what store, there's always some joker who has registered a loyalty card program with the telephone number 202-456-1414. That's right. The White House. 202-456-1414. Seems to always work. Of course it does. But if you give that number out audibly to a clerk and there's somebody like me standing behind you online, we're going to know exactly what you're up to. No question. Yeah. And they'll know that you're the president. A similar effort had been advanced with whatever your local area code is, plus 867-5309. I'm not going to even say that out loud because that's going to just evoke all kinds of reactions. But it basically does say, what if everybody uses the same loyalty card? What kind of deals do you get then? And what kind of habits does it—you're buying a massive amount of groceries every single day. Oh, no question. But think about it from this perspective as well. Well, maybe I shouldn't ask you this. This is sort of a personal question, Emanuel, but do you have life insurance? You don't want to answer that. I don't even understand life insurance. I really don't. Well, the underwriting for life insurance is extremely extensive, and they request access to your medical records, to your patient history, to any kind of hospital visit, the medications you have. They contact your pharmacies. They'll contact Duane Reade. As the underwriting process becomes more connected with the ordinary data that we leave behind us on a day-to-day basis, perhaps people are going to be looking at things like our loyalty card programs. Wouldn't some of that be protected by HIPAA laws and stuff? Not unless you consent to give it to them. It absolutely is protected. It's a great question. But if you give consent to them to access that data, then they have lawfully accessed it. And that's how they get around it. They have to sign a myriad of consent forms in order for them to contact all of your doctors and get this information. But what if they tied that with your purchasing history at Duane Reade, and they saw you going in there at 3 o'clock in the morning and buying three pints of Ben and Jerry's? Do you think that you'd be more at risk for a heart attack if they saw that happening more frequently? So I think there are really nefarious and unusual ways to use this data. So they may not know that you're suffering from one ailment or the other, but they know that you're treating something with a whole lot of whatever type of embarrassing medicine you can think of. Absolutely. Yeah. And they might infer you're not well because of that. It seems to me like a social network of some sort where you basically, you want to buy something that your health insurance isn't going to like if they find out about it, join our social network, and we'll buy it for you under this particular card, and then we'll just bill you separately for that. It seems like that kind of thing is probably already being developed. Or you could just use cash. What a concept. Yeah. You could just use cash. You could just use cash. Do they still accept that? Some places, yeah. Wow. Well, in any event, I wouldn't have stood a chance, because you were standing beside me with this loyalty card thing. And suffice to say, in my defense, I was just merely being cheap and spouting off numbers I thought might work that were like old members of whatever store. We could have still been there now, because that conversation just was not ending. Yeah. She was giving me out different phone numbers, and she didn't care how many you were going to give out. Then she asked, do you want to join the program if you're not part of the program already? I hesitated. I almost started. And then I realized, oh, no, she's just going to give me a bunch of paperwork. Then it was harassment. Eighteen people behind you online. I was like, I don't want this. I don't need this. This is not how I want to spend my life. And Alex, to answer your question, I think death insurance is a lot better. All the programs on TV now with the dead come back to life. Wouldn't it be nice to have a policy where you know someone's going to stay dead, and if they don't, you get compensation? That's actually a very good point. I am remembering some stories, I think, that relate to loyalty programs as well. I don't remember the specifics of them, but I do remember reading some stories about people going in and buying pregnancy tests or buying diapers or buying things in preparation for a pregnancy, and then that data being used to market to them via email direct marketing that may have been tied to, let's say, a family member's email address, which then outed the fact that somebody had bought pregnancy-related materials, or I believe another individual actually seemed to have been informed via email marketing that they were pregnant before they even realized it themselves. If you go into a hardware store and you buy an axe and a plastic bag and some gloves, that sets off an alarm someplace, or will it in the future, where someone says, hey, you know, that person probably is up to something that might be bad, now we should do something? That's true. That's where cash comes in handy. It's also nice to mess with the system a little bit and try and confuse it if you have a lot of time on your hands. We don't have a lot of time on our hands, so I want to get through this last letter on mass transit. I think it's the last one. You mentioned on the show last week the MTA is ignoring the barcodes in their new app and only looking for the date and time on the screen. We're talking about the app for the LIRR and I think Metro North as well. I showed up, Metro North conducted the barcode when he asked for my e-ticket and he told me they weren't checking the barcodes at this time. My guess is they want to get their riders and staff used to using the app first before phasing in the barcodes, or maybe the QR code scanners are still back-ordered. Signed Colin. Colin, thank you for that letter. That's an interesting point. You know, all you need is an app that has the date going back and forth and three colors and you're in. Free MTA rides for you on commuter lines. I'm pretty sure the handsets that they're using have the barcode capability there, like in mechanical form. It just isn't actually on or a part of their workflow. So if they suspect something, they will ask to see that barcode, maybe? I mean, unless there's something that is, you know, unless it's not active at all. But if it does work, they do, I believe, have the hardware to use it. But I don't know if, like you guys, like was said in the letter, I don't know, it may not be active for some reason. I know a lot of train conductors listen to this show. So maybe one of you could write into OTH at 2600.com and give us some information on how it all works. I'd love to know. And different systems, too, because different cities use it in different ways. There are national rail networks and buses and things like that. And it's just kind of fun to see us all stumbling into the digital age here with different apps and programs. Do they get custom phone covers instead of punches? Yeah, that's the thing. That's the old system. LIRR conductors, if you look at your ticket when it's punched, every single one of them has a unique pattern. If you have the star, that's like you're the king of conductors. But lots of them just have random patterns, it seems. And there are people that go around collecting these. Yeah, it's an interesting part of that. Is Randy working this train? I want his punch on my ticket. That's why I don't really approve of the app. I don't want them punching fancy holes in my phone. No, no. Maybe I didn't explain it right. That's not what they... Okay, we'll talk after the show. Here's one more letter, not having to do with this kind of thing, but having to do with travel in general from Maryland. I heard your fascinating report of your train trip around the United States, what Kyle and I were doing over the past few weeks. I'd like to do what you did. I've never traveled around the US and don't really drive enough to have a car or a feeling that I would like to drive that much, totally understand that. I'd like to go by train like you did. Can you tell me how you did that? Well, we simply got on an Amtrak train and it started going. Short answer is look at some of the routes and start thinking about your trip. Be flexible. If you have to call and talk to somebody, they'll book it. But I mean, I don't want to be a travel agency here, but yeah, all the normal travel planning stuff. But just to do it by rail, you'd plan slower. Yeah. The thing is, we're going to sound like a travel agency because there's only one national rail system in the country and that's Amtrak. It's hard not to, but this is true. If you want to explore the American system, that's basically what you have to explore. But there are some things that are changing. For instance, we've talked on the other radio show about the new Houston-Dallas high-speed rail line that's being built by private interest that will change the time it takes to get from Houston to Dallas from nine hours to 90 minutes. It's all being done without any taxpayer money and supposedly they're going to start construction next year. This is an example of something that could really happen. Trains going 210 miles an hour. This is what we need to see. But the more you use rail, the more that industry, I think, will prosper and the more you are a part of that, the more you'll be versed in it as a form of travel and it becomes something that more people do by choosing that. It's a big deal and we need to see more of it. The people we talk to on the train invariably love the train more than anything else. They don't want to fly. Flying is uncomfortable and crowded and hectic and stressful and the train is just not like that at all. Okay, so in answer to this question, yeah, how do you do that? You basically go and check their website, find a place you want to go to. What kind of a ticket did you buy is the next question. Okay, there's many different ways you can do this and on Amtrak they have the coach section which is usually in the back of the train, although sometimes the train's reverse direction and the back becomes the front, but that happens everywhere. And if you don't mind riding for a day or two in regular seats, it can be very cheap to go across the country this way. If however you decide you want to get a room, there's different options for that as well. There's a really, really tiny room called a roomette, then there's just a plain tiny room called a room, and then there's an okay room called a family room. And they all cost different amounts and they're quite expensive actually, unless you use what are known as points, which you can get through their credit card system. And if you just charge a lot of money onto the card, over time you'll find you have enough to take rides all over the place and get rooms. And nothing beats that, where you can actually sleep on a train and wake up. And when you consider, you get accommodation, you get all your meals included in that price, so if you do the calculations and see how much you would have spent staying someplace and going out three times a day to get food, maybe it'll start being more economical. What was your itinerary? Our itinerary was random. Basically we started in Seattle, decided we wanted to go to the Bay Area, booked a train down there, then L.A., then from L.A. to New Orleans, then New Orleans to Chicago, then Chicago to New York. But that was interesting because we decided to go through D.C., so we picked a train that routed through D.C., which you can do as well. Yeah, yeah. It was the on-the-limb itinerary. Yes. How long did it take? It took a couple of days. The longest stretch was a couple of days. And for instance, if you were to go from New York to Los Angeles by train, you would probably go New York to Chicago, switch trains there, and usually you have about eight hours to walk around Chicago, which is awesome to be able to do that. Go back in on a different train, and that's another two days to get to the West Coast. So it's three days total to do that, two different trains. And the other final question was where did you stay? Well, we stayed on the train. That's what you do if you travel that way. Yeah, and that's depending on the class of service. You can also find accommodations very close to the train station, and that's a great rule of thumb just in general when you're traveling. Oftentimes the grittiest places, the cheapest places are near train stations, and they're always interesting to stay in, always interesting to learn about. But it's a neat system, and that's what we're kind of about is learning different systems and being well-versed in them. And what this payment, the RFID conversation with regard to ticketing and stuff and the It's all part of, I think, new forms of technology becoming affordable and becoming standardized within these systems, and we're all about learning how that stuff works, learning how it's implemented, how and where it goes wrong when it's implemented. And there's a lot of really exciting stuff. I know it's kind of slow in general, but just with regard to the system here in New York and also nationwide, the more people use it, the more it becomes a priority. And even if you don't, it's still something that Americans are working on and care about. Is anyone here checking the Twitter feed to see if anyone can come up with a better idea than Tesla card? We have the Hudson card. What do we have? Hudson card. Not bad. Hudson card. Okay. What about the Trump card? Okay, Alex, can you wait for us outside? No, sir. We'll be done in a couple of hours. That's actually got a little ring to it, but no. It's just horrible. If some people have their way. All right. In other news. You have another one? We have the bed bug card. Really? Okay. Really, folks? That's the best you can do? For the city that never sleeps, the awake card. Awake card? That's not bad. What about the asylum card? The insomnia card. For the asylum cities? Wow. We're so jaded here, aren't we? Wow. Okay. Latin American social media giant, Taringa. How many of us have an account on Taringa? No? Nobody? No. What is that? They were hacked. They were hacked big time. Another day, another data breach. This time, Taringa, and I think I'm pronouncing it right, a Reddit-like social network website for Latin American users has suffered a massive data breach in which 28 million accounts of registered users have been stolen. Now, this was revealed when Leakbase, which is a data breach notification website, got their hands on the Taringa database. And upon scanning, it was concluded that in total, 28,722,877 records were taken from the site, which includes usernames, email addresses, and their passwords hashed with MD5 algorithm cracking, of which is considered a piece of cake. Now, according to Taringa's on-site statistics, they have 28,512,139 registered users. So somehow, they have more hacked accounts than they have accounts. So they got something like a whopping 101% of the records from this. I don't understand how that happened. That's better than Wells Fargo. This is not good news for them. No, it definitely is not. They confirmed the data breach, a security notice. The website said the incident took place on August 1st. We suffered an external attack that compromised the security of our databases and the code of Taringa. In a conversation with Hacker News, which is what we're reading from here, Leakbase claimed they have already cracked 26,939,351 of the stolen passwords, out of which 15 million are unique. This is where it gets really interesting. Well, first of all, it's one of the biggest data breaches taking place this year. If you're keeping track, in May, restaurant search engine Giant Zomato—am I pronouncing that right? I don't think I've ever said it before. They suffered a massive breach where 17 million accounts were stolen and sold on the dark web. Last week, a security researcher discovered a combo list containing 711 million email and passwords used by cybercriminals to spread dangerous banking trojans. And of course, the advice with Taringa, if you have an account, change your damn password. A lot of people were using really silly passwords here, and Hacker News did a bit of a study on this. 160,860 users used the password 1-2-3-4-5-6-7-8-9. We learned nothing. But only 90,000 used 1-2-3-4-5-6. So less people used that password than used the longer one. Taringa, the name of the actual social media company, that was used 49,681 times. I guess, you know, folks, go through all your Facebook friends and see how many of them use the password Facebook. Why not? Let's see what happens. What about Taringa 1-2-3-4-5-6? You know, I'm looking up that one right now, and I don't see it. You'd be safe. You'd be safe on that system. Okay, and then one more digit, 1-2-3-4-5-6-7-8-9-0. Only 22,000 people used that one, whereas 6-0, 17,000 used that. It's just incredible to me. What were the other passwords? 1-2-3-4-5. And then your first name, Alejandro, A-L-E-J-A-N-D-R-O, I'm sure I'm not pronouncing it right. Alejandro. Alejandro, okay. Alejandro. And then you've got a bunch of other Spanish names, Barcelona, 10,183 people used Barcelona. 8,000 people used Metallica. River Plate. I would not guess River Plate was a common password, but 7,624 people used that. And then, of course, you have the people who used 9-8-7-6-5-4-3-2-1. But that's only 7,000 people, as opposed to the 160,000 who used it going the right way. It's a little thing like that. America, 6,711 people used that. Carolina. I don't know why Carolina is there. 6,052. And then you have Cordy, 5,888. Real Madrid, 5,183. Pokimane, 5,037. Yeah, there are others, but that pretty much gives the general idea. But speaking of Real Madrid, their Twitter account got hacked. I don't know if you've heard about this. Oh, no. Yeah, Lionel Messi will not be playing for Real Madrid. Apparently, the hacker group R-Mine was behind the stunt, which went viral on their feed just days after Barcelona's account was taken over by hackers. R-Mine, which announced Paris Saint-Germain's Angel de Maria had joined the club as a hoax, the group was at it again, this time on the Champions League winner's account. They basically had a video of Messi scoring for Barcelona against Real Madrid. They had a post on Real's Twitter that said, Benvingo Messi, welcome, welcome. And well, the implication was pretty obvious. The group has hacked a series of high-profile accounts over the past 12 months, then followed up with a series of tweets claiming responsibility, saying internet security is a four-letter word and we prove that. The post went viral with over 27,000 retweets in the first 45 minutes of it being up. I assume that the hacked tweet is what went viral. But you know, I see nothing wrong with that. I see nothing wrong with this kind of a thing. It's educational. It shows you that there is no security to speak of on these particular accounts. And it's basically tweeting something that gets a reaction, but in the end, what harm is caused? I'm sure there are people calling for their heads and calling for them to be imprisoned, but this is exactly the kind of thing that we need, people waking us up. Well, I agree with that. And you know, you go back to this major social media breach that you just mentioned. What was the name of the site? Taringa? Taringa. Taringa. And breaches like that, where millions and millions of account data have been compromised, you know, will naturally lead to compromises in social media like this as well. Because if you can identify who's in charge of one particular account through any kind of recon or OSINT, and you can then identify that account in a past data breach, and then decrypt something that has been in sort of, you know, hashed in a way that is, you know, not particularly strong, you know, then it becomes easy to compromise that particular account. And you go through these passwords, and those passwords are very easy to identify if something is just hashed without being salted as well. When you hash and salt something, that's when you're adding some sort of randomized data to the hash as well, so that you can't go through an entire password file and identify it. Can you give us an example of salting a hash? What would that be like? Well, there's one way to do it in Amsterdam, but that's, you know, separate from what we're talking about here. But it's essentially just adding a little bit of randomized data to a particular hash so that it couldn't be identified across data breaches. Using your password, for instance. Give us an example. You mean QWERTY? Yeah, yeah. No, go on. Go on QWERTY. That would be on your, yeah. Real Madrid is one of them. Yeah, Hotmail account there. Yep. All right. My favorite plate is the River Plate. So, you know, giving out a lot, actually, there. But this is a huge issue for Turinga, too. We deal with these kinds of things all the time. I would love it if a listener could send us a data breach notification letter from Turinga if they live in the United States. Because any company that has a breach like this, that has customers in the United States and they satisfy the definition of personal information under any state data breach notification statute, which is generally a username, a name, address, email address, plus a password, you know, or some kind of account identification, then they're supposed to notify that particular person that their account has been compromised and give them instructions about what they should do in order to remediate the risk. And in some cases, you also have to notify state attorneys general. This becomes a huge problem for many companies. We deal with it all the time. But when you're dealing with 29 million users, this is something that could be really crippling. And once those databases end up on the dark web, they can be searched. And if those hashes aren't salted, they are very easily searchable for one user's password across sites. Well, I think what we're also learning from this, or what we've learned, I think a lot of people are learning this, because this is pretty common knowledge. If you use the password 123456789 on Turinga, you might be using the password 123456789 on Facebook or on something else. And if somebody is able to get your password information tied to that account, then they're able to say, OK, I'm going to try it on other accounts, too. Now, maybe you use different passwords for all different systems that you use. It's a smart thing to do. It's not smart, however, to keep a file on the system that gets compromised that says passwords and is a list of all the passwords. Some people do that. It's not an easy problem to fix for people who aren't technically minded. How do you keep everything secure? It's something that, you know, some people use password managers. Then the password managers get hacked, and all your passwords are out there. There are many tricks. We've published some of them in 2600 as far as ways of having passwords that are easy for you to remember, but hard for other people to guess, such as the first letter of a sentence of a paragraph that you memorize. That's one thing that you could possibly try. But there are many, many others. The thing is, nothing should be treated as rock solid and completely secure. And every time this happens, it's a learning experience. Now, all the news stories, of course, say hackers are out there in the dark web selling all this. You know what? There are people doing that. Yes, there are people doing that. That's not what hackers do. Hackers figure out the security vulnerabilities, and they tell you how it works, and they write about it. And that's what the hacking world has always been about. Criminals, of course, will take advantage of what hackers tell them. And yes, a hacker can be a criminal as well. You can do two things at once. But this is something that people do who are up to no good. And hackers do not have the cornerstone on that market. All right. Instagram. Yes, Instagram also got hacked. Only six million accounts. You remember when that used to be a lot? Now we're talking, you know, Yahoo had, what, a billion accounts hacked? It's just ridiculous. Why don't we just assume everything is hacked? Because it just seems like it is. Every week we read another story. And of course, last week, Selena Gomez's Instagram account was taken over by hackers who posted to the feed explicit photographs of Justin Bieber. The same ones that we were forced to endure a year or two ago. Yeah. And it's just publicity for all these famous people who don't do anything. All right. It's like how many times we're going to hear about Game of Thrones, HBO, if they're going to release the episodes or not. It's publicity for them. It's publicity for all these, quote unquote, stars. And basically, you can protect yourself in many ways by having two-factor authentication, by having good passwords, by changing them occasionally. Yeah. Try out some of the stuff. A lot of operating systems and software come with a form of password management. They're not all the best. Like you said, it's not worth putting all of your trust in one or the other, but definitely try it out. Or like two-factor, if you can just, it's a matter of turning it on in whatever web service you use, play with it. See how it works for you. And also, I advise against keeping such personal information on these devices and these accounts where you can actually be hurt by its imminent release. Unless you have physical access to a machine that you know you control, you're vulnerable to somebody else's mistake. Somebody else could have some kind of a hole that they are responsible for, for a massive system and millions of people are compromised as a result through no fault of their own. We keep posting all of our private information and vulnerabilities and things like that onto these systems, and then we're surprised when they get released. If you don't do that in the first place, and just assume at some point these systems will get hacked, it'll be a learning experience more than it'll be torture. One can hope. There's still this prevailing mentality that, oh, I'll put my stuff in Google services or in Instagram or whatever, and it'll be safe because it's a big organization and it's a big company and whatever. But then we're constantly told about these leaks when they happen to famous people, when they happen to celebrities. But when you look at these leaks of it happening to a celebrity, if you take that to inform you that these systems aren't even protecting their high-value clients or customers or users or whatever, then how are you going to trust it with your junk? Yeah, it's all a learning experience. So every time we tell you about some platform that's been hacked and all these millions of accounts exposed, we can learn from that. We can say, yeah, this is the effect of that particular system being compromised, and how do I protect myself in case the account I use gets compromised as well? And how seriously will I take that when it happens? Okay, our phone number is 347-335-0818. If anybody has any comments or information they'd like to share with us, again, 347-335-0818. We'd like to hear from our listeners. And again, our Twitter account, Hacker Radio Show. If you have any comments you'd like to compress into 140 characters, feel free. And of course, you can also write to us, oth at 2600.com. I think I've covered just about every base there. We have a phone call coming in, so let me punch up the right buttons here and press this one and say, you're on the air. Go ahead. First off topic, is Emanuel Goldstein your handle, and is it from 1984? Well, I'm going to say yes to simplify things, yes. I only learned that recently when I actually listened to the bloody thing on BAI. I never knew that. That's one of the best jokes of my life. Well, it's not a joke. My name is not a joke. My name was carefully selected. But do you know how long I've been listening to your show and thinking that was actually your name? Well, what's wrong with that? As far as I'm concerned, it is actually my name because it represents my feelings and the perspective I come from. And I think we should all get a chance to use our names. That's why my online name is Anonymous. There you go. See? Now I know something about you. That makes sense. The two best jokes of my life included Al Franken doing the Al Franken Decade. I thought he was a political conservative when I saw him do that, and it was not until he ran for office that I realized he was a political liberal. So that was a long joke. And it wasn't the longest one, but it was the best of all, was when I first tuned in to Saturday Night Live, and they were doing the Bass-O-Matic. And I watched it. I didn't have any prep. I just switched it, and there it is. Are you tired of the same old vegetable drink? And I'm watching him do this, and I'm going, that's disgusting. Who the hell would buy this thing? And I didn't know it was a gag until I saw it fade to the audience instead of a cut. And then I knew, okay, it was a skit, and it was part of the show. You know, half of those SNL skits would work much better if you couldn't hear the audience underneath them at the beginning. People would think they were real commercials. I remember one. I don't know if it was SNL or Second City. It was, there was a device called Mr. Coffee. They had a device called Mr. Tea. And basically, it was pouring hot water into a teacup, but you had to buy a device to do that. That one doesn't get enough credit. Okay. You'll cut me off. I've got a million things I've been writing down as the show went. The Rockaway was an exit you put another token in. Oh, is that how it worked? Yeah, when you were going into the city, you only paid once. Okay. No, no, no. I'm sorry. When you went into the city, you paid twice. You put in two tokens. So, okay, you would get off the train at Broad Channel and then get on again? No, no, no. When you got off the train at any of the stations down there at Rockaway, you only had to put in one token. Okay. You had to put a token in to get out. At the Rockaway stations. There was another turnstile. I see. Okay. So, if you went from one Rockaway station to another? Yes. There's a question about that I can't answer. Okay. Well... That question I can't answer. That immediately occurred to me. I would love to time travel and see just how that worked. Rob, you had something? I have a question for you, caller. Now that you've heard 1984, what did you think of it? Okay. Like Aldous Huxley in Brave New World, he's got his economics all wrong, so his society isn't possible. Like the Heisenberg compensators, doesn't work. I think the description of getting a crap beat out of you and then talking sounds realistic. I think there's a lot in there that does work and that we might think is improbable. We see more of it every day. We see newspeak every day. Oh, yeah. For sure. I see on Fox News, I see words like, you know, North Korea being called no-co, and things like that. What are these people thinking? And it's becoming more and more reality. Well, you know, if only the people... This is one thing... One of the things, in spite of the bad behaviors in the American federal government, to which I object, one thing I will say positive is we, the British, and our Jewish friends have a sense of humor that nobody else in the world seems to have. So if only they had a better sense of humor in these other places. Well, I think they do. I think we might not understand their sense of humor as they might not understand our sense of humor. I suppose, but when I find out what their humor is like and get it translated, it seems less involved. Well, let's use Canada as an example. A lot of people spend time trying to understand Canadian humor. Can you think of Greg Ferguson described the two groups you can rip into in comedy? Nazis and Canadians. Well, I mean, if you ever watch the Red Green show, it's something that, you know, you can spend a lifetime trying to figure out why is that funny? Why are people so, you know, amused by that? And you might not ever figure it out, but it's real. It's a real thing to them. Absolutely. Well, my viewpoint is subject then to correction. So far, it's been my impression that we over here have a better sense of humor, a more sophisticated, well, especially the British, have a more sophisticated sense of humor, more involved. Yeah, but that's because it's our sense of humor and we're laughing at it. All right. Okay. Okay. I'll, you know, I'm claiming that I went and looked at the other stuff. The German sense of humor is really interesting. It's a very dry sense of humor and I can appreciate that, but I don't always understand it. Yeah, yeah, yeah. I got that part. And the point is, when I looked at the other ones, it was, I could measure it quantitatively, not necessarily enjoying it or understanding it, but I can measure it quantitatively. There are, you know, four levels to this joke and only two levels to that joke, that kind of thing. Okay. Look, you've told me to go correct, go check my viewpoint. So I will. All right. Let me see. Tokens are inconvenient. Are you kidding? They're like cash. Yeah. It's just, they seem so antiquated now in 2017. I know when, back in 94, when the MetroCard was being introduced, we thought the token would last forever. And now it's just, it's so antiquated and such a part of history. They guaranteed there was always a clerk there. You could always get information. And especially with the GPS crowd walking into walls with their heads down on their cell phones, they need it. Excuse me. I can't figure out if I've arrived at my destination because my GPS didn't tell me. Well, look in front of you, so ask the clerk. No argument there. There should be a clerk at every single station. I agree with that. And not having them has proven to be a big mistake in many ways. Rob. I can speak to that, though, from the other standpoint, the organizational standpoint, because I was in the arcade business for years and a token-based system is so much more expensive and complex to maintain and to operate than a magnetic card-based system or an RFID-based system. If it's functioning correctly, though. Are you hearing that story from the card manufacturers? Yeah, that's a big lobby, the card manufacturers out there. Any other points? Because you want to open up the front. I hated London. My band did three gigs in London recently. It was absolutely horrible. Yes, I agree it was a disgrace, but not in the way that that fellow suggested. It's a threat. They're tracking you. If you screw up, they fine you because you didn't have enough money in the blasted card. You're inside the system. You can't buy more money. You're trapped. They fine you. There's a hack for that, by the way. Always make sure you have a small amount of money that's impossible to spend, like an amount that cannot be spent. And then if it's got an amount of money, it just puts a negative balance on the card. Wow, interesting. That's a hack. If you allow the balance to go to zero, they screw you. We did something like that in London. To avoid, to be able to get out of a system. There you go. But yeah, definitely. It sounds like the old Charlie situation in Boston where he got trapped. Well, it's a fictional character, but the song Charlie on the MTA was... Really? Yeah, he was just riding around all the time. His wife would bring him a sandwich once a day. Those guys on the New York City subway give him a dollar when they come around begging. Oh, no, no, no, no. This was based on Boston system where you had to pay to get out and he didn't have the nickel to get out. And thus, they've named their day passer as the Charlie card, right? Yes. Yeah, that's after the song. Listen, sir, it's been a delight talking to you. Send us your music. We'd like to hear what kind of things you play. They did that in Boston. How come you don't like the rat card? I mean, that's up to you. It's just, maybe it'll grow on me. I don't know. We'll have to see. I got some other interesting stuff for you guys. I guess I got to call back, right? Yeah, call back another time. But thanks so much for calling. Let's see if we can fit in one more phone call at 347-335-0818. Yeah. Always great to hear from our listeners. I think that was a fascinating call. I love the fact that he used the phrase, tough bananas. You know, you don't hear that often enough. I hear that every day. I bet you do. Yeah. You definitely do. On that subject, though, you know, he talked about 1984. I listened to most of that on WBAI as well. It was really harrowing. Weren't you on that? You were on that yourself. Yeah, I read the CNN op-ed that I wrote on 1984. It was really harrowing. Yeah. Would it be the sound that you like? Or should I do it over until I get it right? You say everything I know is wrong So do me a favor and play along for a minute As the rest of the year is turned Don't be alarmed if you smell something burning upstairs It's a little beefy Rollin' around in a boxcar, fingers together Maybe it wouldn't be hard to explain If I only had a brain Somewhere on a higher mental plane I might learn to come in from the brain If I had a clue Would I still be here with you? Gee whiz, if I only had a brain Who's that? Oh, my little friend Cupid Wearin' a shirt that says I'm with Stupid Always nearby wherever I go He's lookin' out for me, don't you know? Mr. Excitement, never in a rush Johnny on the spot with an arrow in his butt Ouch, I guess your love is true Now, if I could only get a clue Somewhere on a higher mental plane I might learn to come in from the brain If I had a clue Would I still be here with you? Gee whiz, if I only had a brain If I had a clue Would I still be here with you? Gee whiz, if I only had a brain Gee whiz, if I only had a brain