Artwork for 05: We're all screwed...

05: We're all screwed...

59 min

Dynamic advertising can change episode lengths. Timestamps are approximate.

Summary

This episode covers problems with Facebook privacy settings and practical ways to protect computers, accounts, and personal information. The hosts also discuss multimedia eBooks, collaborative show notes, reading across devices, and science fiction novels.

  • The hosts describe Facebook posts appearing with unexpected privacy settings.
  • They discuss interactive eBooks, penetration testing, and online learning.
  • Jason DeFillippo explains how malware can capture credentials and enlist computers in bot networks.
  • They recommend software updates, distinct passwords, password managers, and secure browsing.
  • They caution that location and vacation posts can reveal routines or when a home is empty.
  • They advise keeping passwords out of visible notes and desktop files, and keeping a debit card PIN separate from the card.
  • They describe using Mammoth to collaborate on show notes and praise the Kindle app’s reading progress sync.
  • They recommend Cyberstorm, Daemon, and Freedom™.

Key moments

  1. Facebook privacy settings

    The hosts describe Facebook posts appearing as public or visible only to their authors despite their chosen settings.

  2. Multimedia books and online learning

    They discuss interactive eBooks, penetration testing, a proposed online safety book, and accreditation for online learning.

  3. Malware and bot networks

    Jason explains how malware can compromise computers, capture credentials, and make infected machines part of bot networks.

  4. Protecting accounts and personal information

    The hosts discuss passwords, workplace monitoring, secure browsing, and geolocation sharing.

  5. Location sharing and privacy

    They warn that location and vacation posts can reveal routines and absences from home.

  6. Everyday password practices

    They advise against leaving passwords in visible notes or desktop files and recommend keeping a debit card PIN separate from the card.

  7. Collaborating with Mammoth

    The hosts describe using Mammoth’s shared boards to prepare show notes.

  8. Ebooks and science fiction

    They discuss Kindle reading across devices, their preferences for physical books, and the novels Cyberstorm, Daemon, and Freedom™.

Full transcript

143 lines · machine transcribed
  1. Welcome to Grumpy Old Geeks, a weekly podcast where two old internet vets talk about technology, the internet, where it's going to shit and what we do to fix it. I'm Jason. And I'm Brian.

  2. You can find us on Facebook at facebook.com slash grumpy old geeks, on Twitter at GOG podcast, or on the web at grumpy old geeks.com. Or you can email us at podcast at grumpy old geeks.com. And now you can also subscribe to us on iTunes. Just search for Grumpy Old Geeks.

  3. Number five is alive. I should have known that was coming. Yeah. I love my 80s movies. So, guess what Facebook did? More updates and more changes. More updates and more changes. Guess what I noticed last night? Privacy settings change. Yeah. All my posts for about the past week have gone to public. Yeah. Facebook plays this game where they pretend that that doesn't actually happen.

  4. I've been screaming about it for about two years now. I've noticed every single time that I've gotten an update on, say, the Facebook mobile device, all my settings are reverted and changed again. So, are you complaining about free software that you didn't pay for? I'm not complaining about it because I didn't pay for it. But it is, given the privacy flaps that have happened with them and their commitment to our privacy and making sure that we understand everything, it seems a little suspect. Yeah.

  5. They can't actually dial that in and make sure that things don't change. Yeah. Yeah. It was, uh, it was really, really surprising to see that because I know for a fact, and I went into my privacy settings and it all says friends only. Right. Friends only, friends only. But when I post, they go straight to public. Yeah. There's, there's some funky stuff going on. Um, for a long time for the first few updates, um, that I noticed it happening to me. It was really distressing. Uh, for whatever reason,

  6. for the last two weeks for me, every time that there's been an update, it's actually gone in the reverse and it's, it switched for me to only me. So I'll do an update and like, I'm kind of good with my updates and I'm used to getting comments and, and, and things. And you know, an hour or two later, no comments. And I look at it online and it's set to only me. Well, yeah, I've had that, I've had that happen to quite a bit. And, uh, yeah, it's just all over the place. So how can,

  7. if they can't be consistent, you know, that's, that's kind of troubling, but I mean, you shouldn't be posting anything on there, but I mean, that you really don't want anybody to see. But I mean, if that's the way, like, you know, you think of, um, battered wife who ran away from her husband and is talking to her family on there while she tries to get, you know, get help. That's, that's something that happened. Yeah. Yeah. And well, they also, well, nobody was ever able to conclusively prove this or not, but there was that issue briefly when they first rolled out the

  8. timeline that apparently private messages were being listed in the timeline archives as well, which is if you're sending a message and the, and they did try to push this as a, as an email system that is just supposed to be to one person, you do not want that showing up in your timeline feed. Yeah. No doubt. Yeah. Uh, again, free service. Yeah. So, you know, if we were paying 15 bucks a month, they probably wouldn't do that kind of stuff, but they can get away with it now

  9. because Hey, it's free caveat emptor. Yeah. And I'm sure it's not, uh, I don't know if it's intentional or not. I have a feeling that the wobbly privacy settings on updates might be somewhat intentional, but, uh, the rest of it could just be glitches and it's a big confusing, hard system.

  10. Well, yeah. I mean, it's got one of the most complicated systems ever built. So yeah, by far. So this is probably what can you do? Yeah. It comes down to what can you do? I can't complain. It's free. Go to app.net, go to app.net and pay. And, uh, then only have two or three other people on there that you actually know instead of the 400 or so that I keep in touch with. Well, you're so personable, uh, only online. So I went back up to San Francisco last weekend. Yes. My old stomping

  11. ground. Uh, good trip. It was a great trip. You know, I kind of missed that startup energy up there. There was, uh, it was just, it's just a really good vibe. It might help because it was the one weekend that the weather was absolutely perfect. The one out of the three weekends you get every year because it's miserable the rest of the time. We had San Fran, uh, weather here. It was not that great this weekend. Um, that's good. I took the LA weather with me. See, I've never actually spent time up

  12. there. I I've gone up for, for work trips. I've, I've been up there to, you know, hang out with Apple and stuff like that. But, um, I, I never experienced that startup energy or that whole San Fran tech scene. So yeah, I've never even been, I'd lived up there for five, six years, I think off and on, and I've still haven't gone to Apple. It's a, it's nice. They know what they're doing over there.

  13. Yeah. Yeah. And now they'll have a spaceship that you can go visit. Really? Have you seen that you haven't seen the new building design? No, I have not. It looks like a giant spaceship. Awesome. That's great. I'm actually going to be going over to Apple here in, in LA on Friday. So I've got a meeting. They've got some office over on sunset. So I'm going to check that out. I wonder if it's a designed or if it's just a cubicle space, they took over and shove some Apple people into. We'll see.

  14. I'll report back. And this is for, cause you guys do iBooks. Yeah. We've been doing a lot of their, well, eBooks, their eBooks. Yes. They're very particular in the iBook store. Because the iBook was a failed product that they had. Remember the iBook, it was one of their cheaper laptops that did not do well. Oh, so they do not like that word. And even though the eBooks are in the iBook store, we cannot call them iBooks. And it's a source of endless confusion and press releases and emails that go out often. Yeah. I was just confused.

  15. Yeah. Yeah. It's quite confusing, but it's actually, it's a really great product. I'm not just pimping it because we're doing a bunch of them, but it's pretty damn cool. And I'm really surprised that I haven't seen an Android version or that Kindle hasn't rolled out something similar. So it's just, it's the ability to do a lot of multimedia within text and, and it's great. It takes, it takes books to the whole next level. And I'm really hoping that people get on board with it. I mean, I, I salivate at the mouth about thinking about like doing Stephen King's gunslinger series with this format and, and putting

  16. all the illustrations in and doing video and audio. And it's really cool. Yeah. So you showed me, uh, one of the books that you did for Coldplay. Yes. And it was very cool. Yeah. It's, it's a cool thing. It's a, it's a, it's, I'm really hoping consumers get behind it and Apple really promotes it more because it's great. It's, and it's a lot of fun to work with. And it's actually been exciting, uh, for, for both me and my business partner, Wendy, uh, to do these things, because as we were talking last week

  17. a little bit about how kind of boring building websites has become and it's kind of, everything's kind of the same and you don't really get to push boundaries. And this has been a blast for us. We're learning something completely new and doing really cool stuff with it. That's really cool. Yeah. Yeah. It's, it's cool that you guys have like a new avenue to, to kind of move into last, uh, last fall, I thought about doing a, uh, kind of a sideways career change and I wanted to, uh,

  18. become what's called a pen tester, basically a penetration tester to break into companies. They, that getting paid to break into companies, I should say. And, uh, so I did a lot of research on, um, security and stuff like that and all the tools that they use and read the books on it.

  19. So that was kind of an interesting, uh, foray into that, but it's a growing field and, and you get to dabble in the black arts, but use them for good. Yeah. Yeah. It's, uh, it just, after doing all the research, it didn't seem like something I wanted to do longterm because a lot of it is, uh, very kind of mundane and tedious and you know, and at the end of the day, what do you have? You have basically a report that you had to a client that says you're screwed here, here, here, and here. Right. You know?

  20. Well, I mean, you could also make that your own like full-time thing though, because then it's like, and here's how I can fix them. So hire me to fix them too. Yeah. So I mean, it's an interesting thing. Get them on the front half and the back half. Exactly. Exactly. You're getting them front and back. So, and that is going to be our major topic today. Is it not? Yeah. Yeah. Because you got all excited. I did. Cause in going, going into all the research, I was thinking, oh, well I can,

  21. I can marry my two passions of writing and computers and write a book. Right. And I was going to write a book that was basically geared for parents to teach their children how to stay safe online. Don't take pictures of your privates. Yeah. No sexting. It did never end well.

  22. And through all that research, I just, I got too busy and haven't finished the project, but I got started on it. So I want to kind of share some of the things that I learned going through a lot of this deep dark hole of how people break into other people's systems. Right. And I'm going to save the conclusions for later, but it's very interesting. And I want to circle back though with a little

  23. followup from last week. I had a couple of very interesting conversations about our, our e-learning topic. Oh, good. Um, my friend who is a PhD doctor, um, has the complete opposite opinion that you should ever get any kind of, uh, accreditation for work or learning that you do on the internet. Okay.

  24. And his main top, his main point is most of the actual learning wasn't in the lectures. It was working with people that you go to school with to figure out the problems doing the actual homework and, you know, working on it. Yeah. I get that argument. I totally get that argument. It makes a lot of sense, but I guess my assumption would be that this is somebody that's already socially able and, uh, and able to, you know, it's not somebody that just sits at home and can't talk to

  25. anybody or interact with anybody. Um, I get it. Yeah. I, that's a really good argument that I have a hard time saying anything about. I mean, it totally makes sense for, especially for, you know, your first level degree. But I think that that point goes out the window, say, if you've already got your, your, um, bachelor's degree and you just want to get a master's or something like that on the side after you've, you've already had that experience. You've been in probably in the workforce. So I'm thinking more

  26. continuing education. Okay. So, but I get it. I totally get that. That's a, that's a really valid point for, for, especially for kids just coming out of high school. And we all know that our education system is so fucked. Oh, I cussed. Sorry. Explicit. Um, our education system is so fucked already now that anybody coming out of high school, unless they're a complete self-starter, doesn't have a great education and doesn't have a lot of experience interacting with other people, working with groups. They're just basically getting out because they're 18 and the story.

  27. So, yeah, I mean, that's a lot of it. I mean, I look at my brother, he came out of the current high school system and went straight into college and he graduates in a couple of weeks. Right. I'm going to get my plane tickets. Shit. Um, I was the plane reminding you. Oh yeah. The plane, the, uh, God, where was I? Oh, but he's, he came out, you know, a physicist. Yeah. So there, I think if you're motivated, you can, you can make school work for you, but I don't know how

  28. motivated kids are nowadays. Yeah. I mean, that was really kind of my point, even when we were talking about it and maybe I didn't make it clear enough, but that's definitely for like highly motivated self starters who have their shit together. Yeah. And yeah. Cause I don't think you're going to go through that process home alone, going through this stuff unless you're motivated. Exactly. You never would, you, you would never get it done. You would never pass the test.

  29. You would never get the accreditation anyways. It would not happen unless you're one of those kinds of people. And I see that as a good thing. Separates the wheat from the chaff. Yeah, indeed. So I think that's, uh, about it for segment one. Yes. That's the, that's a bit of our first segment. I'll go ahead and plug the beer right now. Uh, today's beer is Firestone Union Jack IPA and I got a big thumbs up from Jason. Oh my God. This stuff is so good. It is so tasty. It's so tasty. I want

  30. another one. Well, let's go get one. All right. Our sponsor this week is Burner. Burner is an app for your iPhone or Android device that gives you disposable phone numbers for calling or texting on the down low. Keep your real number private and communicate incognito. So let's say you're at a conference. There are two hard and fast rules of conferences and that's ABC and DTA. ABC is always be charging. So your phone or laptop doesn't die from lack of juice. DTA is don't trust anyone because

  31. who the hell knows who all these people really are. You may want to do an off the record hookup with Glenda from accounting or recruit an employee from another company to join your team. Either way, you never want to use your own number. So get a Burner. Burner gives you completely disposable phone numbers with just a few clicks. When you're done with your covert ops, just burn it. Go to BurnerApp.com and after you download the app, enter the code GRUMPY to get three free credits. Offer good to the first 50 special agents who aren't afraid to help save the world. So get on it today.

  32. All right. So we're going to talk about something that, uh, Jason is beyond incredibly passionate about. We actually both are. This is a, it's a, it's a big deal these days and it's becoming a big deal more and more. Um, basically all of our information is out there now and security is a big deal and Jason is very passionate. So I'm basically just going to walk away from the mic and probably go have a beer or two or maybe chime in with stupid comments, but go for it, Jason.

  33. Take it over. I would like you to stick around for the comments. So basically when you're talking security nowadays, internet security, computer security, um, we're talking about a couple different layers of security. First, you've got your personal computer, which is where you start with. Right. That's, that's your gateway to the internet. Which used to be where all of our information is. Right. We used to keep things locally on your own personal computer. On your floppy

  34. drives in the locked cabinet. Not even that long ago, the cloud is, is relatively new. Now we're not entirely sure where our information is a lot of the time. So yeah. And that goes to the second part, which is your personal private information that's out on the net, like your banking information and your auto loans, your mortgage, everything is stored on a server somewhere.

  35. Yes. And you need to protect that stuff as well. Let me chime in really quickly, uh, on this one. I told you I chime in a lot. I am sick of all you companies that use the identification number for everything as our social security number. You all need to fucking stop that. There's no way in hell I should ever be giving my social security number over the phone to anyone as an ID number, especially the phone company.

  36. Exactly. Yeah. Because I have to go to an app. When I go upgrade my phone to an Apple store, it's little kids asking me for my social. And I'm like, no way. Because you're going to take my credit card in about two minutes and then you've got my social and then, you know, you got everything game over. So then you've got your, uh, security around your correspondence. You've got your email, you've got your IMs, you've got your sex messages, sex messages. Yes. And, uh, and after that you get

  37. into like the granular security about your, um, public interactions, which is like your social media, media, your Facebooking, your Twittering, even if you have private accounts on, on these things, as we've already talked about, not always private. Private isn't private. No. I mean, that, so that's pretty much like the 10 foot, 10,000 foot level view, you know, like just the overview of everything. Right. So, uh, I just kind of want to start at the top on your

  38. computer, you know, PCs and, and to some extent, max, um, you've got viruses, exploits, malware that get on your machine through a myriad of, of ways. Right. You know, bad emails, bad websites, thumb drives, bad PDFs. Clicking on that email from that Nigerian guy. Oh, he just, he just wants you to send him, send him a check. So he's not getting into your computer.

  39. Or opening up that zip file from supposedly the 19 year old hottie chick. Oh, Oh, Kornikova. Yeah. And a Kornikova one. Yeah. Yeah. And this is a zip file in the email, and then you open it up and run the program. Yeah. Yeah. And you, and you know, we've been telling people for ages to not open attachments and all that stuff. But so, but that is your, that is your main, since that's your main way onto the internet and all your data is stored there, you need to protect

  40. it. And you can, everybody should at least have a very basic level of security on their machine. Get your antivirus up to date. If you're on a PC. Right. You know, on the Mac, I don't run antivirus because there aren't very many, well, A, there aren't very many Mac viruses. There are, um, that is starting to change. It is starting to change. I mean, they still, and the reason for that obviously is because back in the day, everybody had PCs. There weren't that many Macs. Macs were

  41. the domain of the super user, the designers, et cetera. The vast majority of machines out there, especially in the workforce were PCs, but that is starting to change. And we are starting to see more and more Mac viruses. Yeah. And, and when you look at the, when you look at the PC though, it's a, it's a fundamentally different architecture. Oh yeah. It's way easier to exploit a PC than a Mac.

  42. Yeah. I mean, all you needed back in the day was a copy of visual basic and you could write it all the viruses that you ever wanted to. Um, and in the Mac back then was just so terrible and OS anything up until 10, once it got to 10, then you're looking at the BSD kernel and everything is, you know, with a UNIX underpinning, which is, you know, had open source. So everybody knows how to hack that shit. Yeah. But it's also had years of security professionals looking at the source, you know? So it's, it's, it's a little, uh, a little bit hardened. I'll tell you a second

  43. about how do you, how, how these people get in. But, um, yeah. And you know, we, a lot of the security guys always tell people, Oh, you can open things if they come from a trusted source, somebody, you know, but half the viruses, what they do is they go in. First thing they do is grab your address book, start sending out, you know, they, they basically try and propagate themselves to everybody that, you know, so they send you, um, you send them the payloads,

  44. once or twice a week, I get emails from people that still have Hotmail emails for whatever reason. And that seems to be the most popular hack. It's just everybody in their address book gets an email. Well, I think, I think that's a, if you look at somebody that has a Hotmail account, they're not tech savvy. So they're not going to be keeping up with the patches, keeping up with the updates, keeping their, their OS up to date, you know, they're, you know, basically Luddites to begin with because they're still on Hotmail. Um, yeah. And the same thing, the clicking links.

  45. And even if you get a link that looks legit and you do the rollover and it shows you where it's actually going to go, because you know, you can hide the true destination of a link, even that might not be the final destination. It can do several layers of redirects to get you to somewhere else, you know? And that's, I mean, that's if, if these virus guys aren't doing that, then they're idiots because that's the best way to get, get around that stuff. Um, and I gotta say browsers

  46. are getting better as our email clients. They're starting to incorporate. I use, uh, Mozilla's, which is, I can't even remember. Firebird. Yeah. Really? I actually do use it. And it does a very good job of, of sniffing out those links and giving you a warning. So, you know, it's as you're probably going to get to, it's cat and mouse all the time chasing. And, uh, then those guys get smarter than they get smarter than they get smarter. Yeah. But I, I've been really impressed with, uh, Chrome and

  47. Safari as far as, um, warning people that they're going to a site that is possibly a fishing site. Yeah. Yes. That that's actually been pretty good. Uh, they've done a really good job on that. Um, it's hit and miss. I've, I've dealt with like, I re yes, I really want to go to this link and make it really hard because somebody's reported it as being whatever. So yeah, you know, it's hit and miss, but it's getting there. Yeah. And, and this whole thing is a numbers game. So yeah, it's like

  48. if they, they send out so many of these things in the bots propagate themselves and everything is, it's you're going to get hit at some point, especially if you have a PC. Yes. I mean, uh, my roommate's parents computer was running really slow. So they brought in this, this, you know, local expert to come and fix it. And he counted 107 viruses on that machine.

  49. That's impressive over the years, you know, cause they, they bought it. They never did anything to it cause they didn't know. They just know, know how to go look at their financial information and check their emails. Yeah. Okay. Yeah. That's the scariest thing. I mean, I think about my parents because they obviously are not particularly tech savvy and they're running computers and all that sort of stuff, but they basically go in and check their financials and they check their retirement and they

  50. check their medical stuff. I mean, this is important information. You do not want to have people getting access to. And that's all these, these, the older generation is doing on their computers and they have no security whatsoever. Yeah. And no idea. Yeah. And one, I mean, all it takes is one, you know, one virus gets in, then they have basically full control of your machine. It's what we, you know, they, in the business, we call it root admin, super user, which means they own it and they

  51. can do whatever they want. They can put in key loggers to basically log everything that you type. So you type in the URL for your bank or you, or you type in, you go, one of my favorites is people, they, all these people go to Google, they type in the name of the bank and hit, I'm feeling lucky and it just takes them to their bank. So you've just typed the name of your bank, easy enough to go backtrace, get the URL. Then you type your username and your password. Those three, those three keys are

  52. all you need, you know, and boom, there's your bank. So, oh, I'm just going to be a guy who sets up an automatic bill pay with no email notification that just siphons out money every month to something that looks legit. And hopefully they won't catch it. And they probably won't if they're that dumb anyways.

  53. Yeah. And the other thing is what they do when they get, get ahold of these machines, they put in headless clients that let them basically become part of a bot network. And bot networks are usually used for sending huge amounts of spam, running, uh, distributed denial of service attacks to take down other websites. And in any, there's a ton of different things that they can do, but those are like the, the main ones. Right. So once these hackers have all these machines, then what they do is they have

  54. their own private message boards where they rent out, they're like, we have this many CPUs. Okay. We've got a, how many do you need a 10,000 machine attack, a hundred thousand machine attack? Right. This is how much the hourly rate is for time on our network. And that's where they make a lot more money. I think probably than doing the bank accounts, but that's amazing that they actually charge for it. That's fascinating. Uh, the black hearts get really weird. Do me a favor really quick though, because I've had a lot of friends ask me and I've had to explain it. A lot of people

  55. don't really understand what it is. Explain what a DOS is. Um, well, there's a DOS is just a denial of service. That's, I mean the denial of service attack. Yeah. The distributed denial of service attack is basically when there are so many computers hitting the same website at the same time, it overloads the capacity of the company to deliver their website, thus knocking down the entire system.

  56. Right. And it comes through a bunch of different, you know, there's a bunch of different means that they can do it. There's, um, what's called a SYN AC attack where like when you pass a, when you're doing packet exchanges because all the information on the internet goes in little packets and it gets reassembled, it gets reassembled based on, you know, the numerical order once it gets to the target machine and all that. But you can send, um, a SYN packet and the computer is supposed to send an AC packet and there's ways to get around it. So you just got way too technical. I was going for the easy

  57. one. Okay. Okay. So I'll just say it here. Basically what happens is they get a whole bunch of fucking computers to attack one system at one time to knock it off. That's what it is. Yeah. And since there are so many systems they can't filter because like if it's just one system sending a bunch of traffic to it, that's easy to filter out and say, okay, this IP is, yeah, this IP is done. Knock them out with a DDOS. It is distributed. So coming from everywhere.

  58. You go rent a hundred thousand computers in New Zealand and computers in India and computers in Kansas and computers in Wyoming. It's yeah. Yeah. All these computers infected are sold as a block. Yeah. So, so, and then all they do is they just send a command to their, the command and control software sends it to the remote host and then the remote host just does what it does, what it's

  59. supposed to do. So, I mean, it's, it's a tough, it's a tough thing to try and get around if you don't know how your computer works. And if you're not savvy enough to watch your router, if the light, if you're sitting in the living room, your computer is just by itself and you look at the little blinky lights and they're going crazy, something's up, you know? And so, yeah, on the, on the PC, keep your antivirus up to date, keep your system up to date on the Mac. I use a little program called little

  60. snitch. I have that on my Mac as well. It's one of the first things I learned on my Mac. Yeah. Cause it tells you every program that tries to access the internet, what port they're using, where they're trying to go. And you can say yes or no. We can say you, yes, we're now, but not forever or allow this program forever. And it can be a pain sometimes, but it can be annoying, but at least I know, you know? Yeah. It's a, it's definitely one of those

  61. awesome tools. If you have a Mac worth getting and it's, it's cheap. It's probably like 20 bucks. It'll be in the show notes. Um, so yeah, on your PC, do you run antivirus? Yes, I do. You do. You keep it up to date? Yes, I do. Patch your system all the time? All the time. All right. Good man.

  62. Although that's bitten me in the ass a couple of times. Thanks a lot, Microsoft. No offense, but you've put out some crap patches that have screwed me for a couple of days because I do it religiously immediately all the time. Yeah. So, and I always have. Yeah. Um, and another tip for people who aren't super savvy, turn your computer off at night or when you're not at home, don't leave it running all the time. Yeah. I mean, if you don't know what you're doing and you don't have any systems on there, don't listen to that crap about it takes

  63. more energy to, to boot it up and shut it down than just leaving it on all night. Just turn it off because you have no idea what's happening on your system while you're sleeping. Yeah. And it also just helps to, um, reduce the impact on the rest of the world. You know, if everybody turned their damn computer off at night, A yeah, it would save power and B there would be less hack attacks at those different times. Yeah. If you're not using your system,

  64. shut it down. Yeah. Okay. Okay. Real quick. Uh, get rid of Java, flash and Adobe Acrobat, but there's still so many crappy flight sites out there done in flash. What are you going to do, Jason? Pretend, pretend your home machine is an iPad. Get rid of them. Java. Uh, yeah, Java 100% get rid of some people can't get rid of flash, but I do agree with the recommendation. I haven't gotten read it off, uh, off my system, but I know what I'm doing. Yeah. Yeah. And, and

  65. update it like, don't ignore the little thing that says update always updated all the time. Yeah. And Adobe Acrobat, I mean, these are just the three main targets that a lot of, a lot of these guys use because they're so buggy and they, they say they, uh, trade, uh, zero day exploits all the time on these things. And it's basically a zero day exploit for people that don't know. Nail this one because this is another one that I've tossed around and everybody's like, what? Yeah. These are, these are

  66. holes in the programs that the companies have either not found out about yet or not patched yet. So basically they're, but they're known they're out there. Like people know about these things. The companies have just not either found out themselves. Yeah. Well, that's the whole point. Cause somebody has to know about it or it doesn't exist. If tree falls in the woods. Well, I'm saying it's like generally known by the bad guys. Like it's out there. Yeah. And, and PDFs, most of the browsers

  67. nowadays have PDF built into them, you know? So I wouldn't, I wouldn't do that. So private information, your bank accounts, your sensitive information, the stuff we talked about, let's get off the PC now. Yeah. Um, passwords. Hmm. Passwords. I literally ran across somebody the other day that had, and Google allows this lowercase a one, two, three, four, five, six, seven, eight as their Gmail

  68. password. Right. Well, that's not good. It's ridiculous. And they probably use that on all of their other sites. Yeah. Never use the same password for more than one site. That is something I am guilty of and have been trying to fix and been slowly taking care of that.

  69. Get up. There are password management packages out there. Yep. There's LastPass and there's one password. One password I am running on the Mac. Yeah. I run it on everything. It's on my iPad, my iPhone and my, my multiple Macs. Yeah. Um, and it syncs with Dropbox. So your passwords are always, even if I'm out, I can pull up my iPhone and log into anything I need to log into, but it will generate massively long, complicated strings because it's a math problem for the crackers. So let me throw

  70. a solution that, that I had found a while ago that, that I want your opinion on. And this is obviously for people that are considerably less tech savvy that would never run any of this. Um, there was an idea that you would throw out, um, basically the first couple letters. You use the first letter of a phrase that you would totally remember. And then a set of numbers right after that, that you would totally remember. And then you end with your initials and uppercase that way you're covering

  71. everything. How long, how long is the password? Well, you have to come up with a big long phrase, like every good boy does fine all the time or something like that. Some, something you would remember. So you use the first letter of everything. You use a set of numbers that you would remember kid's birthday, something like that. And then your own initials or somebody else's initials in uppercase at the end. It's that's pretty good for a password. If you're going to be super lazy and not do everything, right? It's all right, but it has to be at least 14 characters,

  72. right? You know, you need something. So you need a longer phrase. Yeah. But everybody could come up with a pretty long phrase that they would remember themselves. But you still don't want to use it on every site. That's, that's where you don't want to use it on every site. Right. And I mean, do you read the XKCD comic? Yeah. There, he has, he has a great comic. We'll link it in the show notes at grumpy old geeks.com about, excuse me, beer again, um, using a multi-phrase approach.

  73. So you do have a very long phrase and the math to basically crack that is once you get, like I said, once you get past that certain, certain limit on computing power nowadays, and you get past the rainbow tables they've got for all the currently cracked passwords and MD fives and all that stuff, then it becomes, you know, a computing problem and it's easier to remember. So if you can pick a phrase for each website, right, go with that and make it long. But I, I am just, you're going to forget,

  74. you're going to have to deal with it. Just get a password manager. They're cheap, best investment I ever made. And never, like I said, never use it on the same site more than once, because if you get cracked once, if they steal the database, the user database, they've got your email address, they've got your username. Most people use the same username on every site.

  75. Yeah. You know, so, boom, you're in, you know, that's why, that's why, and nowadays you get, I, Harmonix was hacked the other day and I, my rock band account, because I was a rock band player for a very long time. Yeah. Oh, boy. Um, so they were rock band night for grumpy old geeks.

  76. Oh, I'm in. Uh, so they, they, they just reset everybody's passwords. And I'm like, from a company perspective, that's just bad PR. But, um, so yeah, never, what was it? Oh, the email address thing too. Yes. So most people use the same email address on every site.

  77. Yes. As do I. Yeah. Is your, um, email run through Gmail? No. Okay. Well, scratch that. Sorry. Yeah. There's a, there's a really cool, I'll tell you about the cool hack. I shadowed her point. No, I'll tell you about the cool hack about Gmail. So if you've got a Gmail address. Yes. You can take whatever the name is. So like, say mine's Jason at, uh, my custom domain that I use because I use Google, Google accounts. If you do your name plus in a phrase,

  78. it treats that as it'll be a unique email for the service that you're using. Right. But it won't be your actual email address. So I, I have, uh, several layers of aliasing and craziness going on. Yeah.

  79. But it's just an easy way to just say, okay, for my, so for Twitter. So my name dash Facebook. No, no, no, no, no, no. So say for your Twitter account, you go, you, you pick a word that is not in, not the actual service you're using. Cause it like J plus Twitter would be, or Jason plus Twitter would be okay. So I know that's easy to figure out. Yeah. So it's like Jason plus I hate this fucking service. Yeah. That works. Okay. So, but it's easy to, it's not easy to guess. So if they do

  80. get your email address that you're using on the alias side for the different services, they can't go use your email address as a login token. Right. Okay. That makes sense. And on the email side. So I know some people have a problem with Google, but me personally, I run everything through Google apps.

  81. You know who has the biggest problem with Google? Who? Yahoo. Oh, sorry. Tech joke. Actually, I think Facebook nowadays, all the talent, all the talents leaving Google to go to Facebook. All right. I'm going to stop derailing you. Go. So I've come up with a system basically to abstract all of my email correspondence from the actual account that is ever that the public ever sees. Okay. So it's a, it's a very long and complicated

  82. process. It'll take you about half an hour to set up, cost you five bucks a month if you're going to use the paid Google apps because they took away the free version because they weren't obviously making enough money. Yeah. So that's going to be on the website when this goes live. It'll be in the show notes and it'll be on the homepage of grumpy old geeks.com. You can check it out if you, if you really seriously want to keep your email private and not have it hackable by somebody who breaks a database for a

  83. a website that you signed up for three years ago and they've left the company, the company's dead. The website's still there. The database is still there. None of the security patches have been made for three years and then all your data is just sitting there. Okay. Let me ask you. Yeah. We all know if, if we're working for our company and we have a company email address, they have entire full access to all of that. Correct? 100%. What if you're checking your email that

  84. you've created with this system from a work computer through the, a work internet connection? Is this still secure or is that fucked at that point? Well, if there's a couple, a couple of things there, a, you shouldn't do it. Okay. Period. Yeah. If you're going to be, if you're going to be at work, checking your personal email or checking anything personal, do not use the company network. Do not use the company computers. So we trust Verizon and use our phone? Yeah. Okay. That's all. I think

  85. that's fine. Okay. Uh, just make sure that your phone isn't using the in-house Wi-Fi because I've seen people get busted for that. Right. Um, I don't connect to why. No, I know, I know people that have been security have come and escorted people out of the building because they were stupid enough to not turn their Wi-Fi off and start sending seditious emails. Um, so don't do that. Okay. Um, and there is a case to be made that if you're connecting to a, like a web mail service that

  86. it's over HTTPS and they can't actually like see the traffic, what they're probably can do though, is just screen share what you're doing and see exactly what you're doing and read whatever's on your screen. Right. Same with I am, you know, all that stuff there. There's so many security packages for corporations out there to let them spy on their employees that it's just not safe to do. Don't do it. Don't do it. And in, in the eyes of the law, you're the one at fault because you're on their time.

  87. They're paying you on their equipment on their wireless network. Exactly. Yeah. To not do company work. It's, it's, it is a, you know, determination offense. Right. But a lot of places are kind of lax nowadays, you know, Oh, it's my lunch break. I just wanted to check my Facebook. You know, I find that most companies just seem to block certain addresses and then they monitor for the amount of data that seems to be, they want to know that you're not like downloading porn all day long.

  88. Yeah. Yeah. I mean, the last place I was at, it was, you know, it was a big ad agency and they blocked Vimeo because, and, and YouTube, because I would, the, I was friends with the IT guy and he would show me the, the, basically the screen they were looking at had the person's computer name, had what they were doing. So it would say YouTube, YouTube, YouTube, YouTube, YouTube.

  89. Yeah. And at four o'clock every day, the entire company's internet would die. Right. Because end of the day, might as well go watch some cats, you know, dogs. Yeah. So everybody out there that thinks that your company isn't monitoring you and spying on you with what you're doing at work, they are, they see what's happening. You just haven't caused a problem yet.

  90. Yeah. And they read all your emails. They read all of your emails, every single one, because also, and I don't want to take a dig on geeks like us, but, uh, the people that get into this stuff and work in, in these departments, uh, we've known quite a few, they're a bit weird and they don't have a big social life and they do like to kind of read your emails and hope that you're sending pictures of yourself and your naughty bits. See, I haven't run across that many people like

  91. that. I've ran across quite a few. Okay. Like I said, the last place I was at, the guy, the guys up there were really cool. Yeah. I mean, there's a lot of great people. Don't let me besmirch the occupation in general, but there are some freaky ones out there and they're seeing everything. They're seeing everything that goes by, everything that you do. Yeah. And since we were an ad agency that was primarily inside the movie industry and we would get audited every year from the MPAA, the MPAA comes into these companies now nowadays and they do audits and they

  92. have sent the FBI into these companies for, for scripts that have gotten leaked. Yeah. Um, so they're very careful on a lot of different fronts. Like you can't send attachments, but you can open up Dropbox and share it and share it that way. So although I do find it interesting that they blocked Vimeo and, and, and that was just bandwidth. It was bandwidth because it's screwed up.

  93. As an advertising agency, you'd want to look at other ads. Yeah. You'd want to look at the things that are out there. Yeah. And then a lot of it was actually corporate research. Like we built Facebook games, so we had to be on Facebook all day, you know, so it's, I don't, it's a blurry world. Yeah. And I, I feel bad for those guys cause it's a, I mean, it's a tough road to hoe with them. Yeah. And that's kind of one of the reasons I was getting into the penetration testing side because I saw how many holes there were for somebody who knows what they're doing. Like, so an intern comes in who is tech savvy,

  94. cause they're going to be smarter nowadays than all of the other people working at the company who's, you had grew up with, you know, IBM and in their mouth like me, uh, you tend to know more than the IT guys. Cause the IT guys just want to make, they want to make everybody's computer work. They're not really concerned about, you know, all the security stuff out there. Yeah. They're just keeping things running. They're making sure you're connected to the printer. Yeah. Oh yeah. Get emails found down

  95. today. This printer's down. Oh, good. Back up. You know? And there are some scary things out there, like checking the pen testing stuff. There's a little box you can get that you can basically just, if you, if you're sneaking into the agency on some other pretext, you plug the ethernet, you basically plug it between the ethernet port and the wall. And it just, you capture everything that happens. And it just, it does port scans for everything on the network,

  96. saves it all to a, uh, uh, just like in onboard memory. Right. And battery operated. Then you either can remote into it from the outside and get into the network that way or pick it up next time. That's amazing. There are so many crazy tools out there. And these guys have built tools that I think are just perfect for criminals. Like there's this thing called Metasploit and, uh, the social engineering toolkit. These things are made for penetration testers to go test the integrity

  97. of a company's security. But if you're not, if you're not a penetration tester and you're just a dick. Yeah. If you've, yeah, if you've got no morals. Yeah. The same tools get you into everything. Yeah. Yeah. And I found, uh, tools that will run SQL exploit attacks against any website and give you a report. I deal with those all the time. Well, I'll teach you how to write some code to get you around the SQL exploit stuff because I spent a lot of time working on my, working on my, uh, uh, attack, uh,

  98. profiles for all of my websites. Well, we're running out of time for this segment and there's so much more we should talk about. No, we do, we do have another topic that we just have to get into real quick. Okay. The social media side of stuff, your personal information, you know, so we'll, we'll, we'll keep this tight. Whenever you're on a social network, always use HTTPS, not HTTP. There are settings in most of the big social network sites now that let you enable that by default. So whenever like your Gmail, Facebook, Twitter that say only let me browse the site securely, make sure that's

  99. checked. Yes. A hundred percent. Yeah. If you don't, you're a moron. Yeah. And we run into, I ran into this with people in the industry that know this stuff and still don't do it. Right. I just, I have to toggle it because I have to test both sides of it, but for the most part, everybody should have that turned on and these sites should just require it.

  100. Honestly, it's like a bank. Yeah. If you're not going in via HTTPS and you're at a coffee shop, you can't get in. Yeah. You know, but I'm saying if you're at a coffee shop, you're going via like unsecured network, your password has just been given to everybody in that coffee shop. Yep.

  101. I can sniff that wifi and run packet analysis on the whole nine yards. You're done. Um, turn off geolocation by default for everything that you do, like your Instagram, the photo map stuff, turn that off, turn off geolocation on Facebook, Twitter, because it's, it's, it's a real time point of where you're at at a given time. And anybody that's savvy can go back and reassemble those points and find out your daily routine. Yeah.

  102. And you know what, you're not, we all do fall into routines. Yeah. So that's no surprise. I, you know, you keep checking into the gym at 11 o'clock every single day, your house is empty, your house is empty. And at some point you probably put your address up on Facebook. Yeah. I can find anything about you, you know, so make it harder for them to, uh, get your information. I'm sorry, somebody just went by yodeling outside. Um, well, you haven't experienced the wonders of my alley yet, which is a constant topic on my Facebook. It sounds like the first time that's happened.

  103. It sounds like that. Well, you know, we get some, uh, some happy homeless and some happy, uh, you know, people just walking down the aisle. Okay. Let's wrap this puppy up. Okay. Okay. If you're going on vacation, don't talk about your vacation until you get back. Don't post pictures of your vacation while you're on vacation. Don't post pictures of you podcasting while you're podcasting, just what my friend, you and I keep our, our, well, as much as we can, we keep Facebook pretty secure

  104. for us. So for us, it's not that big of a deal, but if you don't really know what your privacy settings are, but again, like we said, Facebook fucks up. Yeah. So you don't always know how things are going. And my Instagram is public, but I know that there are roommates at the house. Yeah. You know, there's, when I'm somewhere else, there's somebody at the house and we have a giant Doberman and guns. So that's enough of that. But my friend Mac posted, he was at the Grand Canyon.

  105. Voila. What, what happened? Neighbor sees that he's on vacation, sneaks into his backyard, stashes a duffel bag of a hundred with $175,000 worth of pot to pick up later. And it just happened to be that, oh, the direct TV guy was coming that day. And they were like trying to, you know, run some cable and stuff and came across it in his backyard. And he's like, well, shit, I'm in a bad movie plot. Now what am I going to do? And he called the cops and they came and took it away. He's got a great blog post about it. We'll put it on, we'll put it in the show notes.

  106. Um, and just teach your kids to turn this stuff off. I've, I've had to do this with my friends, kids who were, you know, in the burgeoning celebrity business, they, you know, were trying to become celebrities and posting videos of songs and stuff. And it's like stalker target right there.

  107. Yeah. So make sure that if they're posting online, that there's no geolocation. Oh, domain privacy too. If you've got a domain, use the domain privacy, because if you sign up for a domain, it's tied to your house, you know, all that. Or be smart and have a PO box and have everything run through that.

  108. Yeah. Which is what I've done for my company. Yeah. So, and I can still find your address from your PO box. Yeah, probably you can, but yeah. Uh, there's going to be a bunch of resources in the show notes. We had to run through this stuff really quick. It's, you know, it's a deep, deep topic and nobody's actually safe period. Anybody can get anything, but you're going to, you're going to increase your chances of being safe. Exactly.

  109. Because you, you did, uh, before we started this and we were talking about it earlier before, uh, we even started the podcast, Jason was like, basically through all my research, you're, we're all fucked. Yeah. Yeah. 100%. So that was a nice and gloomy start, but, uh, it's just how it decreased the chances. Yeah. Decrease the chances. And you have a better chance of making it through without any of this crappy stuff happening to you. Think of it like wearing your seatbelt in your car. Right. You don't, you don't drive anywhere without your seatbelt

  110. anymore because if you do get hit, it's going to suck, you know? So you wear your seatbelt and if you do get hit, then you know, you minimize the damage. Yeah. So, so yeah, Jason, you delivered. Um, there's a lot more we can talk about, obviously for all of this stuff. If anybody wants to know about anything more in depth, we will definitely make that a segment and we'll talk about it even deeper. Yeah. Just let us know. Yeah. Write us a podcast at grumpy old geeks.com with any, anything you want to hit or leave us a note on our Facebook page. Yeah. Or the Twitter,

  111. but just make sure you're using HTTPS. Yeah. When you do that. Absolutely. Am I dreaming? No. Where am I? In bed. What am I doing? Talking to myself. Look, I must have a star on my door. Or better still. A door, a door, a door.

  112. Swing doors, huh? Okay, doors. Swing. Uh, one last security note, which probably wasn't even on Jason's radar because he doesn't even think people would be this stupid, but, uh, don't ever write your password down on a yellow post-it note and have it attached to your monitor. I've actually run across junior programmers that

  113. I've worked with that have done this before. And I have summarily taken it, torn it up in front of them, thrown it at their face and say, don't you ever do this again. Yes. My parents still have it on their monitor and I've had people over and had the geek squad over and I'm like, what are you doing?

  114. Well, they, they, they actually hire the geek squad. I changed. Well, it's either that or me. Geek squad. Exactly. At some point I'm like, I'm not driving down to Anaheim to do this again. Yeah. So there we go. Um, yeah, don't do that. Yeah. Don't do that. Please ever don't have your password written down. Don't have it in a text file that is called logins on your desktop or passwords on your desk. I know somebody that has an Excel doc that sits on his desktop and writes his

  115. passwords down. I sent him the link to one password the other day. So these are very basic rules of security because, uh, you know, Jason went super hardcore. So don't do any of that stuff. And don't keep your pin number in your wallet with your debit card. That is supremely stupid.

  116. I have that right now because I just got a new debit card and I can't remember the number yet. Right. Okay. So, you know, uh, we, we preach, but we also we're fallible. We're human. Things happen. Um, we'll get there. Okay. So Jason, so you got, uh, this week I want to talk about, uh, one quick thing.

  117. We've been doing the show notes, uh, collaboratively in Google docs up until now. Yes. It's been okay. But, uh, I found a new service this week called a mammoth and it's basically like a joint pin board type of thing where you just drag images and links and all this stuff. It's got a bookmarklet.

  118. So when you're on a site, you can just hit boom, add to a board type of thing, and then you can share it. And then it's a collaborative type of, you know, experience where we can both write on it and leave stuff. So this week and, and, and somewhat last week, yeah, we did, uh, the show notes on mammoth.

  119. By, by we, uh, mostly Jason, uh, I'm still coming up to terms with it. It's pretty cool. I just haven't caught on yet. Yeah. Um, so go, if you check it out, go to mammothhq.com. It's still on a private beta, but if you pimp them and, and basically repost the link to the board that you created and get five people to sign up, they'll let you in. Yeah. Or as I found with Brian, if you just share a board with

  120. somebody, they let that person in. Yes. Apparently have full access and it is pretty cool. I haven't had the time to really mess around with it too much. And again, the show was mostly you. So yeah, there was much need for me, but for the next one, I'm definitely going to play around with it. I've already installed all the things and yeah, it's, it's a groovy site. I think one of the coolest things they do though, is one of the default boards is a talk to mammoth board, right? It's basically a help desk inside of your system. Yeah. And they had a bug last week where I couldn't put numbers

  121. in the board title. So, you know, grumpy old geeks episode four was wouldn't, wouldn't work. Yeah. That didn't work. So I wrote, but I wrote the guys back and forth and they were super cool. They fixed the problem. Um, they've been taken, uh, so it is beta, you know, they're, they're working through it. Um, I want HTTPS access, obviously it's important to me and you know, and a couple other things and they're like totally, totally cool guys so far or girls. I don't know. So to keep with all of our themes so far, since we talked about security on it, how are they making money?

  122. Um, I think they're going to, they, they have to have a premium. I've got a charge for this in, in, in a beta that's this raw. Yeah. You can't do that. Yeah. No, no, it's too early, but it's a cool service and yeah. And if they, and that's why I'm, that's why I'm kind of excited to try them out because they do have a lot of things that I like. I like the bookmarklet because I'm, I'm out surfing, looking for stuff for the show and I just, it's a one click, you know, overlay type of thing. And I, so far I like it. I'm, I'm, I'm a fan. There are a few little bugs

  123. here and there, you know, the editor is a little wonky here and there, but like I said, open bait and free right now. Yeah. So try it out. And if these, if it works out and these guys go premium, I'll kick them coin. They're doing good stuff. Yeah. It's a good service. It's been pretty cool. Yeah. Yeah. So what you got, what have I got? Um, I was basically going to talk about how much I love the Kindle app. I don't, I love Kindle in general. I like Amazon. Amazon's a great

  124. service. It's been amazing. Uh, the Kindle by all reports is fantastic. My mom has one. I love the Kindle app, which I have on my iPad and it's great for buying books and reading. Um, but instead of that, I'm going to talk about a book I just finished last week. I wanted to talk about the Kindle app with you. Oh, well, let's talk Kindle app really. Yeah. We'll get to the book because I love the Kindle app. It's fucking ridiculous. I've owned three physical Kindles. I bought the first one

  125. the day it was announced. Yeah. I've also this cause I'm a, I'm a huge ebook nerd. I bought the, I had the rocket ebook back in the day. I've always wanted an ebook. I've been a huge cheerleader for ebooks since the early nineties. It took me a while to get into it. Oh, I'm not going to lie. It took the iPad for me to get into ebooks. Okay. Until then I bought books religiously. Right. Real hardcore. And you're a reader. You're a reader. Oh yeah. I'm a reader.

  126. How many books do you read a year? At least two a week. Two a week? Yeah. You kick my ass. I, I always, I have a 52 book goal a year. It's that's my read book a week. I've slowed down recently just because life takes over. Well, audible.com has changed that for me. So now I can, I can read in bed at night on a physical book or a Kindle app book or unless it's a technical book, but then I use when I'm out

  127. walking the dog jump, juicing up my Fitbit numbers. I'll listen to an audio book. Yeah. I don't do the audio books. I do podcasts for that stuff, but Amazon owns audible and yeah. Yeah. And now good reads. Good reads. So yeah, I'm with you 100%. It's so easy. It's amazing. Yeah. Uh, devices sync with each other on where you're at. So if I'm stuck at the DMV and I just have my iPhone with me and I launched

  128. the Kindle app, it takes me to the exact page that I left off last night on my iPad. Yeah. Yeah. Unbelievable. And it syncs with your physical Kindle too. So if you've got the wife, I've got a wifi version. My original was a 3g, right? My mom's still got that and it still works. She can buy a book in the car wherever she's at. Right. Um, which is amazing for the price that it's still, the radio still works and the cellular signal still works. I'm like, talk about a loss leader on that one. But yeah,

  129. I don't, I don't use my physical Kindles anymore. I haven't bought a physical book in ages. Yeah. It's been a long time. The, uh, I pick up like first editions of things that I really love physically now, or if a new book came out, like by one of my favorite authors, I'll immediately read it on my Kindle app and then I'll go buy the physical book just because I want to have it because it's my favorite author, but I'm done with buying physical books for the most part. And they're selling more

  130. eBooks than physical books now for good reason. It's so convenient. So amazing. And it's a beautiful experience. Yeah. Besides technical books, the last physical book I bought was the four hour chef because well, it's besides being three inches thick, there's so, there's so many images in it that it may, it doesn't really translate that well to ebook format. See, I picked that up on, on the Kindle app and I have been having trouble with it. Yeah. That's what I just dropped the coin and bought the, you know, bought the physical book because it is a much better experience. But if you

  131. would have done an iBook or an ebook, as we've talked about before with the Apple stuff, that would translate really well. And that would make a great Apple ebook product. Here's the problem with that. The four hour chef is the first book from the Amazon publishing company.

  132. So therefore, yes, I can see the problems that would come into play. Yeah. So what Amazon needs to do is adopt the same format and juice their Kindle fires so they can read the same format. Oh, I agree completely. I've been waiting for that. So I'm waiting for anybody to kind of replicate what Apple's done with their, with their eBooks. Yeah. So, okay. So tell me about the book you were talking about. So yeah, very specifically the book that I just finished last week. And this is before Jason

  133. told me he wanted to only talk about security for this week's podcast was a book called Cyberstorm by Matthew Mather. And, um, you know, it's, it's talking exactly about the stuff that we talked about. This is an entire book talking about how it's such a mistake to connect everything to the internet without understanding security. And it's about how realistically our power grids, a lot of the things that run our daily lives are connected to the internet and they're open for

  134. the kind of exploitation that we've just been talking about and how they're going to easily be shut down. And this is a fiction book that basically explores what would happen if somebody made an attack on us and systems started to cascade fail and how we'd basically back in the dark ages in about 10 minutes. Yeah. Yeah. And it's actually written by a guy who is apparently, according to the bio right here, a leading member of the world's cybersecurity community. We didn't

  135. really get to backcheck that before, but it's a good book. Um, not, you know, he's not an amazing, he's not Tim or, you know, Kurt Vonnegut or anybody like that, but it was good. It was interesting. And he definitely had his facts, right? He knew what he was talking about when he was talking about the computer stuff. Yeah. So he was, he was an infosec. Yeah. It was a really good book.

  136. I enjoyed it a lot. So I highly recommend it. Okay. And as a counterpoint to that, I just want to throw out a book since we were talking about Kindle, I'm going to make this quick. Uh, the first two books from author Daniel Suarez, who was an IT professional for most of his career. And then he came out with two of the most amazing books. The first one's called demon and that's spelled like a Unix demon, D A E M O N. Yes. The good spelling. Yes. And the second one is freedom

  137. downtime. Those two books together comprise one of the best stories I've honestly read since, uh, uh, Neil Stevenson, snow crash. Oh, that's snow crash. Snow crash. I, I, I've got chills again, man. I'm thinking snow crash. Well, I've got a, I've got a week, I've got a week until I need another book. And those two are going to be downloaded for my trip to Hawaii. So, uh, I will report back on those by episode, I'd say seven. Okay. And, and for the listeners,

  138. I highly recommend the audible.com versions because the, the reading is exquisitely done. Um, I have listened to a few audible books and, and they're always very well done. No, they're not. Some of them are just butt ass. Well, the good books that I've, and, and the trick, the trick to getting around a bad reader on audible is just to go to X. I still can't do that. Any, any book can be fixed by going to X chipmunks. You get used to it. I've, I've got on the, on the new

  139. downcast app, they've gone to three X. I've, I tried to listen to something the other night at three X because I only had 20 minutes and it was an hour podcast. I'm like, I can do it. Just makes me think about Christmas and the chipmunks Christmas out. It really fucks with your sleep though, man. Cause you, you start dreaming in three X. Oh, it's bad. Oh, dear. Oh, did we swear again? Oh, oh, sorry guy that didn't realize that we were explicit. Yeah.

  140. Somebody, somebody gave us a bad review because we said poopy words. He liked the show, but he didn't like a poopy words. Fuck it. Yeah. Bitches. Okay. Last one to kill a bad guy buys the beer.

  141. We're driving to Florida. This January bear knuckle fighting championship takes over the ocean. The inaugural bruise cruise sales from Miami to the Bahamas aboard the Norwegian jewel. Three straight days with pool deck, bear knuckle fights in the Caribbean, massive parties, beach events, DJs, cigars, tequila tastings, and nonstop action. The lineup reveals coming soon.

  142. Cabins are disappearing fast and the prices won't stay this low. Reserve your spot with just $200 down at BKFSEA.com. At QVC, shopping is more than just checking out. It's discovering something new every day. Start with today's special value. Then explore exciting finds across the brands and

  143. categories you love. From beauty and fashion to home, culinary, and outdoor living. Shop now at QVC.com.

Now playing: 05: We're all screwed...