Ticketmaster’s Billions in Barcodes Stolen + AI Misinformation Botnet + Breaking AT&T news
TL;DRShiny Hunters claimed to have stolen 193M Ticketmaster barcodes worth ~$23B and demanded $8M ransom. Simultaneously, researcher Conduition reverse-engineered Ticketmaster's Safetix rotating barcode security, rendering it ineffective.
We got a lot of messages about the Ticketmaster hack that went down since our last episode. We dive into all the weird angles of that evolving story, a strange real time news update about the AT&T hack, and spend a surprising amount of time hyping a Canadian movie about Blackberry.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: At any given time Ticketmaster is in possession of a few billion dollars in barcodes. These barcodes represent tickets to shows and concerts.
Speaker 2: We
Speaker 1: are not going to get into the question of whether Ticketmaster is a bad company using its near monopolistic market share to bully musicians, venues, and fans in what seems like an active effort to drive down the quality of live entertainment around the world.
Speaker 2: Are you sure we're not gonna get into that? Because it sounds like we just got into that.
Speaker 1: Scott, I'm tell we're not getting into it. Okay. Okay. Okay. The point is that the billions of dollars of tickets they sell every year are sitting on a server somewhere, which represents a massive target for an enterprising hacker or potentially hackers to go after. Which I bring up because about a month ago, the hacker group Shiny Hunters starts posting that they have breached Ticketmaster. And a few days ago, they released more information on breach forums about what they stole. They are claiming, amongst a bunch of other pretty sensitive user data, 193,000,000 barcodes with an estimated value of, and I want to get this right, $22,695,713,141 US. Woah. Big big number. And I would think someone in practice would struggle to move $22,000,000,000 in stolen concert tickets. But not having $22,000,000,000 worth of your commodity leaked to the public has got to be worth something to Ticketmaster. So Shiny Hunters then claims on the form that they are trying to charge a ransom. Initially 1,000,000, eventually eight once they realize the value of the data. Ticketmaster has claimed that even if they did leak, they have a security system that prevents people from using stolen barcodes. A system that they call Safetix. You've probably seen it. The barcodes have this sort of moving line over them. They're refreshing certain information dynamically. Most people have used Safetecks before. So, pretty interesting story on its own. Then, in a weird coincidence, a few days later, I see a post by an anonymous security researcher named Conduition on Hacker News that is blown up. And it turns out that right as Ticketmaster is in the middle of this giant data breach stolen ticket data scandal, another story is unfolding that concerns this researcher who claims to have cracked the Safetix system, Reproducing the dynamically refreshing tickets that Ticketmaster claims makes these leaks moot. So the story right now goes, someone steals billions in tickets from Ticketmaster, but don't worry Ticketmaster has safetix, But, oh, no. Someone just cracked safe ticks. It's a fascinating story, and I think we gotta talk about it.
Speaker 2: I'm in. I'm in.
Speaker 1: We got lots to get to, man, on this episode of Hacked. Atonal sounds. How are we doing, Scott?
Speaker 2: I think we're both a little off, but I think all in all, we're okay. How are you doing? I think we're
Speaker 1: I'm doing pretty good. I'm doing pretty good. I'm recording in, in my bedroom because I have a house guest, and I have a headache. So I'm I'm happy to be here. Am I at my best? No. But I'm but I'm happy to be here.
Speaker 2: I I strive to be anywhere close to your not best. The, yeah, we're at the tail end of a, like, a five day heat wave, and I think everybody's kind of slowly losing it a bit.
Speaker 1: Yep.
Speaker 2: But, thankfully, I think it's cracked. I think the Mhmm.
Speaker 1: I've forgotten what it's like to be comfortable.
Speaker 2: I, not gonna lie, have since the the day that this all kind of set in, like what it was at Sunday of last week when it started to get really hot, like
Speaker 1: Mhmm.
Speaker 2: I've had my AC pinned and I've refused to let my house warm up because I know that I don't think the AC can sufficiently bring the temperature back down. So, like, normally my thermostat's all eco y, but for this heat wave, I've kept it pinned. And I feel bad for my air conditioning unit and my, like, home circulating fans and stuff because they've just been working for, like, two hundred straight hours, which is or, like, one hundred and fifty straight hours. So I feel bad for them. You know? A lot a lot of empathy for the moving parts in my furnace.
Speaker 1: Those little motors. When when I found out that we were gonna have the the house guest I mentioned, staying with us during this in that room, I I was like, I'm he might die. Like, I I'm really genuinely worried about putting him in there, and so far has hasn't died. So it's going okay.
Speaker 2: Good stuff. You haven't killed somebody. Awesome. The, yeah, the it has been it's been hot. It's been enjoyable, though. I found myself biking a number of times in the heat. And as long as you stay well hydrated, it seems to be okay. I think my body is getting a bit used to the heat, which is nice. So feels like summer. You know? Feels like summer.
Speaker 1: You know who I particularly want to stay hydrated? Who? Our our our new patrons on Patreon.
Speaker 2: Oh, yeah. Of course. I hope they're I hope they're surviving well in this heat wave if they if they happen to be in it.
Speaker 1: It's true. I particularly just wanna know that Reza Mousavi is well hydrated and thriving. You know, thank you for your support. It means a lot to us.
Speaker 2: I've I've got concerns for big Mike is a sasquatch because sasquatches are quite hairy, so he's probably very warm. So I'm hope I'm hoping he's found himself a nice mountain pond to lie in.
Speaker 1: This probably betrays a lack of knowledge of, basic biology, but I think about how, like, dogs can pant it out. Can sasquatches pant? I guess they're more like a Yeah. I don't know. But but I I hope he's doing well.
Speaker 2: This could start a lifelong discovery in the physiological components of a Sasquatch and what makes up a Sasquatch.
Speaker 1: This is this is where we spin off our new show Cryptids, where we we just ask very granular hypothetical questions about, the Loch Ness Monster. And you know who I think will be there supporting us? Benno Overleason. Thank you so much for your support.
Speaker 2: Absolutely. And Golden Techie three eighty. We really appreciate your support.
Speaker 1: Just as much as we appreciate it. From Luke Schneider. Thank you so much.
Speaker 2: And Lord v. Appreciate
Speaker 1: you. Last but not least, Adam Piccard. Thank you so much for your support. If you wanna support the show via Patreon, go on over to hackedpodcast.com. It redirects there. You can jump on into our Discord and share cool stuff you made in the share cool stuff you made channel. It's, it's a lot of fun, and it means a lot to us.
Speaker 2: Totally. Thanks to all our patrons. We love you so much. We do. Ticketmaster. Ticketmaster.
Speaker 1: I wanna talk about it. I think that's been the big story since we last spoke. I've been seeing it all over the place. Bruno over on Twitter, Michael in the Discord of several people shared with us this story. Because there's actually, like, three or four stories here all starting to get woven together in a weird blurry mess. It's pretty early in this story. There's a lot of, competing tales of what has occurred here. So big old asterisk over this thing, but I think we got to start there.
Speaker 2: The yeah. I I think so too that when I saw the original information coming out about the League of the Barcodes, I was like, oh, yeah. Of course. Like, barcodes are nothing but a series of numbers. Of course, someone's gonna have, you know, hacked into a database, grabbed the records, and pumped them out of the dark web somewhere. I'm shocked that it hadn't happened before, honestly.
Speaker 1: Mhmm.
Speaker 2: And then it's funny because I didn't actually know about the reverse engineering of the of the of the algorithm until right as we started this recording. But the first thing that jumped into my mind when I saw the leak was with such a large dataset, somebody could surely reverse engineer the algorithm. So here we are.
Speaker 1: Here we are. Yeah. It I I think a few people have started to observe the serendipity of an independent security researcher cracking safe ticks right at the same time as Ticketmaster has is experiencing one of the largest breaches they've ever experienced, potentially multiple. We'll get to it. But I I I definitely found it fascinating. I was getting these leaks about this story, and then I was over on Hacker News, and I saw that post, and I thought, what are what are the odds? And given how people feel about Ticketmaster, pretty good, I I think is maybe what I'm learning.
Speaker 2: I think, you know, I don't I don't know about all this hate for Ticketmaster, but it sounds like there's a lot of it. There is. I'm just joking.
Speaker 1: I'm a I'm a big Ticketmaster stan. Big Live Nation guy.
Speaker 2: Yeah. Be huge. I got a Ticketmaster t shirt. You know, I'm on their merch store cop and their stuff there. I'm Got
Speaker 1: that tattoo. Master. Sadly
Speaker 2: sadly, I think we're all patrons of Ticketmaster. We are. We wanna be or not.
Speaker 1: That's the problem.
Speaker 2: Yeah. Crazy, crazy, crazy story. That number, the 22,000,000,000 number really shocked me. I didn't think it would be nearly that much, but I guess that just is a representation of how much of our, you know, creative, like, revenue that goes to artists now comes from events.
Speaker 1: It's true.
Speaker 2: Like, I I don't I used to go to a boatload of concerts when I was younger, and I don't as much anymore. And usually when I do these days, the tickets are really expensive. And I'm always, like, kind of shocked at how much a ticket cost these days. But I guess that's the cost of online streaming platforms and our music royalties going away with record sales disappearing and things like that. So
Speaker 1: It is probably the last one of the last meaningful, revenue sources for artists, and it's not great when it has been captured to the degree that it has. But regardless, so in May Regardless. Regardless. We'll get back to that. In May, this hacker group called Shiny Hunters infiltrates Ticketmaster.
Speaker 2: I think we've talked
Speaker 1: about them before. Shiny Hunters is a black hat criminal hacker group. They started showing up around 2020. They were behind the AT and T hack in 2021, the Microsoft hack in 2020, Wattpad, Mashable, a bunch of stuff you've probably heard of. They're named Shiny Hunters after Shiny Pokemon, which requires no explaining as far as I'm concerned. So so they hacked Ticketmaster, part of Live Nation. And recently, they went on to announce a little bit more information about the extent of the breaches, Do this big post on breach forums under the title Ticketmaster event barcodes, Taylor Swift part one of 65,000. So, July 4, which is when I got into the story, they dropped this follow-up post unpacking more about what they stole in this breach and the negotiation they claimed they have had with Ticketmaster. Like I said, big old grain of salt with all of this. They're claiming to have stolen 440,000 tickets for Taylor Swift's Eros tour, which this is an aside. In the post, they say, quote, she will be performing in front of Congress, alongside performing in her tour, sort of speaking to the severity and impact of this breach. The numbers here are pretty wild. Total barcode stolen, 193,000,000 with their napkin math indicating, the better part of $23,000,000,000 US in value. According to Shiny Hunters, they initially accepted a rushed sort of $1,000,000 offer from Live Nation to keep the breach under wraps. Live Nation has denied this. They say that realizing the true value of the data they have, they increase their demands up to 8,000,000. Their rationale behind this is that they when they figured out what was in here, the potential cost of all of this to LiveDataion in their minds went up, and I think that that's pretty valid. Totally. Yeah. It's not a good situation with Ticketmaster right now. I think a lot of people have gotten the, hey. We lost some of your information emails yesterday. I was talking to someone. We're looking at 980,000,000 sales orders, 1,200,000,000 party lookup records, 440,000,000 unique email addresses, 400,000,000 encrypted credit card details with partial personal information. And Shiny Hunters is claiming that this breach is one of the largest publicly disclosed non scrape breaches of customer, you know, personal information ever. There's another actor in this, a person, a character on Breachforms named Spider Hunter. It's unclear whether they're part of it. They're the same hacker who, back in June, leaked a million Ticketmaster user records. If they're part of Shiny Hunters, it's unclear why there are two separate ransom demands. Theirs was 2,000,000, Shiny Hunters is eight's. It's all pretty messy. But if you if you get to a high enough level and you look at the worst case scenario here, it's the Ticketmaster was breached by two different groups and is being currently held ransom by two separate parties.
Speaker 2: Yeah. That's bad news.
Speaker 1: It's not great news. No.
Speaker 2: I'm in the background here trying to find a good, database size calculator to estimate approximately how much data these people had to exfil.
Speaker 1: Oh my god.
Speaker 2: Because 980,000,000 records is a massive piece of data.
Speaker 1: You make a good point.
Speaker 2: Like The
Speaker 1: hackers have been like, can you mail us a hard drive?
Speaker 2: Like, could you imagine trying to open an Excel spreadsheet that was 980,000,000 lines long? Oh my god.
Speaker 1: It'd be like your air conditioner.
Speaker 2: It'd just be brutal. Oh, yeah. Exactly. Like that, it would have taken them like granted Ticketmaster will have large pieces of pipe and and massive data centers, but to x fill that much data, like, that's a huge amount of data. Like, we're in in the like I don't like, I'm trying to find a calculator here because I don't even wanna estimate how many how big this is. But
Speaker 1: It's not small.
Speaker 2: No. It's not small. That's the that's the point.
Speaker 1: So Ticketmaster writes a comment to Hackreeds who did a great job breaking this story saying, quote, Ticketmaster's safe ticks tech technology, that is a mouthful, protects tickets by automatically refreshing technology. Safe ticks technology by automatically refreshing a new and unique barcode every few seconds so it cannot be stolen or copied. This is just one of many fraud preventions we're implementing to keep tickets safe and unassailable. So we read this story. Bruno sends it to us. Michael sends it to us. Great story. Go over to Hacker News, and we bump into this post by Conduition. Conduition is an anonymous cipher freak specializing in the cryptography, scrupulous smart contracts, and he writes this big, long, very in the weeds, breakdown called Reverse Engineering Ticketmaster's Rotating Barcodes in brackets, Safetix overview. It's It's essentially a case study of how to reverse engineer these tickets. Conduition kind of tells a story of buying some tickets from Ticketmaster, which issued them via, you know, this mobile entry system called Safetix with these rotating barcodes instead of printable PDF tickets. This rubs them the wrong way. They found the experience bad. They don't like having to purchase, to download an app that could potentially be compromising their security in order to use a ticket. They find it, biased against people that aren't good with technology, but do wanna see live music, which is honestly pretty reasonable. Mhmm. So Conduition embarks on a project to crack safetix.
Speaker 2: I don't think it took him long. No. I read through his his synopsis. He made some early discoveries like the animated barcode sweepy line thing that goes over and over and over. Your your barcode is is actually just a CSS animation.
Speaker 1: That's my favorite part.
Speaker 2: Essentially, an HTML page. Yeah. Yeah. So it's like and and the other thing is too is that once you load your ticket, it saves it locally. So pretty much getting the source HTML for your ticket data will pretty much show you what's going on or, like, would be a good chunk of where to start. So Mhmm.
Speaker 1: So,
Speaker 2: yeah, he makes some makes some really great early discoveries and yeah. Ticketmaster.
Speaker 1: Yeah. Like you said, there's a couple different things going on here. First off, as you said, there's these refreshing blue lines that go over the barcode, which I think, he refers to basically as security theater. As you said, it's just a CSS animation that doesn't inherently enhance the security whatsoever.
Speaker 2: But I do love, like, the the moniker security theater. I feel like a lot of security is security theater.
Speaker 1: Completely.
Speaker 2: I I've never heard that used, and I'm gonna start using that now.
Speaker 1: I I think he has a great understanding of this Safetick system. Uh-huh. And what it really is, like, there is definitely a security element to this. They are trying to make it more difficult to using something called a time based one one time password, which is similar to the things used in two factor authentication to cycle through the numbers that generate the barcodes. He rapidly figures out how to fake that. But to be honest, a lot of this is just due to the fact that Ticketmaster, it's pretty remarkable coincidence that these tickets can only be bought and sold inside of Ticketmaster's app, effectively giving Ticketmaster complete control over the secondary market of tickets. Yep. There's arguments for why this could be considered good because it helps eliminate scalping, except no, it doesn't, and the prices on those tickets go insane. So it's really, hard not to see it that way.
Speaker 2: I'm gonna jump in and say that there is a valid Yeah. Point for this that's not just to eliminate scalping because, obviously, scalping still exists. It just occurs in the Ticketmaster platform so that they get 25% or whatever their cut is of the scalp. The I think the big thing here is, like, back when back when digital tickets came out, and there was no safe ticks, you would send somebody money and they would send you a screenshot of the ticket.
Speaker 1: Yes.
Speaker 2: And you didn't know if they sent that screenshot to, like, 33 other people. So if you got to the venue a little bit later and went to scan in and they told you that your ticket was already used, then you just got scammed. And I think that's the positive for this is that they were trying to eliminate end user scamming so that they could enforce their own scamming. No. Wait. A legend scam.
Speaker 1: Completely. The ticket resale ecosystem is just, like, a nightmare, and that persists to this day. I think the unfortunate thing about those scams is that, apparently, I was digging around in some Reddits of people who work in theaters. They say the number of people that show up to a concert with duplicates of the same QR code, Ticketmaster, non Ticketmaster is like, that happens a lot, I guess. People walking up not knowing that their tickets were a scam and finding out while they're staring at the ticket clerk is a pretty common experience, and it it one that thoughtful programming and good security could potentially help address.
Speaker 2: I I I can't see a world where this cat and mouse game doesn't continue, though. Like, I think there's just so much money, especially, like, when you look at something like the eras tour. Like the Sure. Such a such a massive broad scale global tour. Tickets were in crazy demand. I'm sure both of us know people that flew to foreign cities to go to go see the tour literally just like, yeah, literally the, you know, when people are committing 4 or $5,000 to a vacation essentially to go to this concert, you know, picking up a set of tickets on the secondary market for a thousand bucks a pop is not, you know, outrageous when you're looking at the fact that you're investing so much in it already. So it's it's I think that the game is nowhere near over and I think that it's gonna be an this would be an interesting through line for the remainder of the hacked seasons to talk about what Ticketmaster is doing and and other ticket providers are doing to stop people from defrauding, you know, the the the end users on the secondary market. And it's like they've kind of gone the Apple motif where it's like we control our app store, we control what goes on our phone, and Ticketmaster is like, we control the secondary market. Like, we're not denying that it exists, but the only way that we can make it somewhat safe is to control it. So I can kinda see the corporate side of it, but at the same time, it does take that monopoly narrative and kind of blow it up even a bit more.
Speaker 1: Yeah. Especially considering the, part of justice cases for whether or not they're operating monopoly that they're currently engaged in. The timing of this couldn't have been worse for them as a company.
Speaker 2: Which for which furthers the Apple motif
Speaker 1: For sure.
Speaker 2: Because Apple is dealing with the same thing.
Speaker 1: Completely. They, it does bring up just how much of the economic value in the live entertainment space is just literally represented by numbers on a server somewhere belonging to a company. Conduition unpacks. These are something called Spreadsheet. TF four one seven barcodes encoding UTF eight texts with this CSS animation sweeping on top of it. And quite quick it's it it is a fascinating read, even for a layperson like myself. I recommend everyone check it out. Mhmm. But he was relatively quickly able to to work it out. The conclusion of their posts, I just wanna read it because I found it fascinating. And it it think it speaks to part of the motivation Condoition had in taking on this project and part of how people feel about, the company. Language note for the quote I'm about to read. I think we can all agree, fuck Ticketmaster. I hope their sleazy product managers and business majors read this and throw a tantrum. I hope their devs read this and feel embarrassed. It's rare that I feel genuine malice towards other developers, but to those who design the system, I say shame. Shame on you for abusing your talent to exclude the technology technologically disadvantaged. Shame on you for letting the market team dress this dark pattern as a safety measure. And, shame on you for supporting a company with cruel business practices, which is then linked to the lawsuit we mentioned, over whether or not Live Nation was threatening to withhold shows from major venues that don't use Ticketmaster as their only service, ticket provider. The last line of this I quite liked. Software developers are the wizards and shamans of the modern age. We ought to use our powers with the austerity and integrity such power implies. You're using them to exclude people from entertainment events. Have fun refactoring your ticket verification system. It's it's so technically sophisticated and so petty.
Speaker 2: You love it, don't you? This speaks to you. This
Speaker 1: I do. Yeah, it really does. It just it scratches something.
Speaker 2: If I know Jordan well enough, this is right right in your wheelhouse, which is definitely why we're leaning in with this story. The, the barcodes in the text, the they're just two different standards. UTF is Unicode. One of the main Unicode standards, the database is used to encode text so that if you have multinational text or cross language text, it knows how to encode it and and de encode it. So and then the PDF four one seven barcode format is just a stacked vertical style barcode rather than the traditional one, which would have been on the old school, Ticketmaster tickets, like just the lines that you see in the
Speaker 1: Got it.
Speaker 2: UPC codes. This one's kind of a more modern representation of it, but, essentially, it's the exact same thing. This holds a bit more data. So, Got it.
Speaker 1: There's also the time sensitive element to it that I don't totally understand involving refreshing them, but Condo Sheen seems to have been able to figure that out too.
Speaker 2: Yes. You know,
Speaker 1: getting in sync with whatever that clock system that they're using is.
Speaker 2: So RSA created a, a version of this for two factor authentication, I don't even know, in the nineties, maybe, the little secure ID tags. I I think it was the late nineties. I'd have to double check. Right. Which made We've
Speaker 1: talked about these before.
Speaker 2: Yeah. Which made them famous, you know, and it was like this little dongle that you wore on your key chain. It had, like, an a rotating number every sixty seconds on it. And that was your time generated one time password. So the this is essentially doing the same process. So it's using a twenty five year old security process, give or take. I'm not exactly sure on the dates, but it has to have a clock sync and then the shared secret, which is the, like, the salt in the hash to generate the the barcode or the one time password. So pretty now I would say, like, when it came out in the nineties, it was revolutionary, and I'd say now is very, you know, de facto security standard. It's better than nothing. I don't know. It's you can't say that they didn't they're not trying. Let's just say that.
Speaker 1: I don't doubt for a second that Ticketmaster earnestly doesn't want people to be able to fake these tickets because it undermines the secondary market that they control.
Speaker 2: Like Well, it also underlines them. Yeah. Like the like like, if you can imagine, if we could go back thirty years, like, still to this day when I run into mostly bureaucratic processes, they're mostly governmental that require, like, such low barriers to entry, like a piece of paper that they'd photocopied and they hand you a copy of it. And you're like, well, I can go take this home and photocopy it myself. And then I can give one of these out to everybody. And we've all just bypassed some bureaucratic headache. And it's like thirty years ago, you could have done that with tickets. Like, it was barely anything. The the barrier to entry was the ticket stock. It's like our cash paper. You know, it's like Sure. It's like making money is comes down to, like, can you get the right paper?
Speaker 1: Yeah. A printer.
Speaker 2: It's like that's
Speaker 1: Yeah.
Speaker 2: Sure. The barrier to yeah. Exactly.
Speaker 1: Well, it's funny that you bring that up because there's one final little stinger on this story before we go to break. Technically, Ticketmaster does offer some situations in which paper tickets are allowed. Resale the resale market is, you know, all safe ticks, but if you purchase directly from them, you I think you can actually get, printable paper tickets. The last beat in this story, a few days later after Ticketmaster posted this, no, we have Safetix system. Don't worry about any of this. We do have Safetix. Safetix solves all of it. Condo issue writes that unrelated document explaining how it is also vulnerable and kind of popping off against the company. Shiny Hunters, the original hackers, reads all of that and then does another post. And it concerns the fact that while you can't print the barcodes for digitally delivered tickets, they do sell those paper tickets. Their post goes, quote, we just shared a four step tutorial explaining how to make your own real tickets using the leaked information. A YouTube video, Ticketmaster's Ticketfest artwork guidelines, and then a link to Ticketmaster site explaining the, specific printing guidelines for their tickets. Quote, our response to Ticketmaster's claims is Ticketmaster's lies to the public and says barcodes cannot be used. The ticket database we have includes both online and physical ticket types. And then they add another just to sort of drive this point home. They just drop 30,000 of the barcodes along with this tutorial. So at this point, it sounds as though negotiation is broken down just so people can try it at home, which is, again, a level of pettiness. I I'm not even really sure whose side I'm on right now. The shiny hunters, you know, say what you will, but the drama of it all is certainly very, very compelling to me. And the thing that's unfortunate is that probably some people with real tickets are gonna have a very bad time at a concert when there are conflicts and duplicates floating out there in the world.
Speaker 2: Yeah.
Speaker 1: I'm hoping that Ticketmaster is being very, very upfront in reissuing any of those barcodes that were stolen, getting in contact with the actual proper owners of them. I hope they're, putting in the effort that this warrants because right now they have a lot of people going after them, and it would suck if the people that are inadvertently victimized are people that just wanted to go see a exciting concert from their favorite artist.
Speaker 2: If there's anything you can trust, it's that a company will be looking to limit its liabilities. And I think I think that the class action lawsuit that would be flying their way
Speaker 1: Yep.
Speaker 2: If they weren't taking it seriously, without weighing the cost of making people work harder to make sure that it gets resolved. So I'm I'm I'm confident in one thing, and it's that. The I can see Yeah. Especially when it comes to things like the Taylor Swift era's tour, which people have notoriously been flying around the world to go make sure they see and it's like imagine getting to Rome and going to the concert. The the only one that you could find tickets for showing up at the gate and being told that somebody's already entered under your ticket ID. Imagine that lawsuit and all of the travel logistics stuff that you would be including. Imagine if that happened to thousands and tens of thousands of people. It would be, you know, hundreds of millions of dollars lawsuit. So
Speaker 1: I would sooner get into a fight with the Department of Justice than Taylor Swift.
Speaker 2: Seriously.
Speaker 1: There's no one I don't I I wanna be in a fight with less than Taylor Swift and Swift. It's just not you're gonna lose.
Speaker 2: It's not
Speaker 1: a good idea.
Speaker 2: Yeah. And just, like, this is just a touchback and has nothing to do with the cybersecurity thing. But did you do you see the, like was it Amazon or Apple TV special about the Eris tour where they recorded one of the performances and released it?
Speaker 1: I haven't watched it.
Speaker 2: No. No. But you But
Speaker 1: I I I saw the ads. I saw the big banner. Yeah. There was, like, a movie about the tour.
Speaker 2: Yeah. Well, it's kinda it's like a live recording of a single performance, I believe. And last I heard Okay. And I'm not sure if this is confirmed, but the licensing rights alone for that single show were in the 9 figures. So it's like
Speaker 1: Get it. Get it, Taylor.
Speaker 2: At the bag. Like, you just have to do you you just have to do the concert that you were gonna do already, and a bunch of people set up really expensive camera gear, and you get a $100,000,000 licensing fee. Like, good for you.
Speaker 1: Yeah. Nothing but respect.
Speaker 2: Speaking of all alternative alternative income for, creative artists, looks like if you're at the top of that pyramid, the the revenue is not so bad. So
Speaker 1: Yeah. Things are going okay for Taylor Swift, but I wouldn't use her as a bellwether for the health of the arts and entertainment industry.
Speaker 2: Yeah. Yeah. If if Taylor's having a rough week, then you can just trust that there's, you know, a a few 100,000,000 other artists that are having terrible ones. Yeah. Crazy.
Speaker 1: Yeah. It's a wild one. Speaking of entertainers trying to get that bag, I think we take it over to the advertising oasis. Is that what we named it? I feel like that's what we named it.
Speaker 2: Yeah. I like Advertising oasis. It's like it's like got a peaceful energy. I think
Speaker 1: that's what it was.
Speaker 2: Peaceful energy. It's like it's like a day at the spa, but it's helping us pay for
Speaker 1: this podcast.
Speaker 2: Yeah. Commerce. But spa is not commerce. Come on.
Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started. You can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 3: Host unforgettable backyard barbecues with savings from Whole Foods Market. Get the good times going with made in house chicken or pork sausages and ready to cook kebabs for hassle free flavor. Grab tasty flatbreads and their new balsamic chicken salad in the prepared foods department. Keep things fresh with organic red cherries, strawberries, and peaches at their peak, and stock up on bug sprays and sun care must haves. Make your summer sizzle at Whole Foods Market.
Speaker 4: Still waiting in line?
Speaker 1: Again?
Speaker 4: That's time you will never get back. Save time and money with stamps.com. Over 4,000,000 businesses have skipped the line with stamps.com. Join them to save up to 90% off carrier rates from your computer or phone right now. Print postage for certified mail, registered mail, and packages in seconds. Then schedule a pickup right from your home or office. For a limited time, go to stamps.com and use code podcast for a free welcome gift. Taxes and fees apply.
Speaker 2: So speaking of the AT and T hack in 2021, which you'd reference when talking about shiny hunters
Speaker 1: Mhmm.
Speaker 2: Breaking that AT and T has been hacked again. Apparently, hackers have stolen all of the 2022 call and text data for nearly their entire cell network. So here's here's the big catch on is they didn't take the content of the data, which is great, but they literally just got the interconnections. So, like, this person called this person at this time. This person texted this person at this time. But this this information literally came out today as we're recording on Friday the twelfth. So As we're recording this. We're recording. And it's funny because you you made reference to the 2021 hack, and I was reading these stories this morning. And I was like, oh, AT and T got hacked again. The because, yeah, the 2021 hack, I think, was something like 7,600,000 users were impacted by. And this one, it looks like their entire network was impacted by which is kind of wild. So there wasn't a lot of personal information apparently apparently it is just the connection logs, you know, so it is big. It is bad, but it could have been worse, I guess, is what we say these days with the amount of data data breaches going.
Speaker 1: Yeah. I'm glad the content of text messages isn't there. Content of calls feels like it would be trickier, but I could see there being a world in which, God forbid, somehow, a a text leak was to happen. And if it was to happen from AT and T in The States, that would be pretty catastrophic. You can read about it in a SEC filing, and AT and T also dropped a press release literally as we were recording this. Pretty wild.
Speaker 2: Yeah. If it was content, I feel like we would find ourselves in a world where people were I think that I think that we'd see a big rush to companies like signal and lots of encrypted messaging platforms because I just think that like, I feel like once that veil gets lifted, it'll be hard to get reestablished. Yeah. And it's like text messaging is is one of those like, text messaging was created as, like, a a side gimmick on the side of your phone.
Speaker 1: Mhmm. I don't
Speaker 2: know if you remember t nine texting and stuff like that, but, like, phones were phones for phone calls. And now nobody uses phones for phones, really. It's very rare. So the text message is the preferred, or I would say one of the more preferred ways to communicate among close individuals. And, yeah, I feel like if that if that wall ever comes down or that veil gets lifted, I feel like there'll be a big rush to more secured messaging platforms, things like that, which I don't think is a terrible option. But, you know, just an interesting tidbit that ties back to the Completely. Story. It's a literally happening as we speak.
Speaker 1: Yeah. I I think we're hopefully at the tail end of the transition from SMS to RCS. We've all been living in the shadow of still using this twenty year old unencrypted technology Uh-huh. Because, a couple of large technology companies can't, speak frankly, get their shit together and adopt, an encrypted standard that might threaten the color of some bubbles in a messaging app. But it sounds like we're finally going through that process. So hopefully, if one of these leaks ever happens again, we'll we'll know for certain that in an era of RCS, we don't need to worry about our text messages getting leaked.
Speaker 2: The in in looking back through time, like, the BlackBerry obviously brought us, you know, the smartphone largely.
Speaker 1: Yeah.
Speaker 2: But they also brought us BD Messenger, which when it existed was, I would say, a bigger marketing piece than the fact that, like, once other smartphones started to penetrate the market, people were married to their b b messenger list because they had, like, an instant encrypted messaging platform among like, I used to have a bunch of really powerful people on my b b messenger, and it's like, those are people whose contacts I've essentially lost forever and haven't communicated with since. Sure. And, like, that was a thing. And it's like, I can see I can see why the large technology companies are holding the strings and are fighting back against the migration, but I think they're doomed. I think that it's it's a
Speaker 1: Oh, totally. I think
Speaker 2: it's gonna be a mandatory change, and I'm It's only a matter of time. Yeah. I'm looking forward to it. It's not like it's it's not like you don't have the option to message with people on other technology platforms. It's just Nope. The messaging is worse, which is just worse for everybody. So it's like, what's the point? Like, you're not there's no real competitive technological advantage here. Like, just join the club.
Speaker 1: Did you, Blackberry was weirdly ahead of their time in so many different ways. Did you watch the Blackberry movie? Total tangent. Did you see it?
Speaker 2: Total Canadian tangent here. Yes. Of course. The miniseries. Yeah. It was great. Well done. I thought I thought they It was so good. I thought they wrapped it up. Like, this is we're in tangent land. I thought they wrapped it up a bit too fast for me. Like, they kinda went from, like they told the development of the of the plot and the storyline of the company, but then they brought it all down in, like, one episode. And I was like, feel like a lot of things probably happened in those moments. So it would have been to me to me, that was my only beef for it, but I thought it was very well done.
Speaker 1: Interesting.
Speaker 2: I think I think my
Speaker 1: I, I forgot that they rechopped it as a TV show because I watched it as a movie, so we started talking about episodes. I was like, wait a minute, but you're totally right. I think CBC, the Canadian broadcaster, chopped it up as a show. I Glenn Howerton as the like, that was so good.
Speaker 2: Anyway Always sunny in Philadelphia. Yeah. It was great. The
Speaker 1: Yeah. He was good.
Speaker 2: I didn't actually know it came out as a full length movie. I thought it only came out as a miniseries because it was, I think, four episodes. It makes more sense why it resolved so quickly hearing that it came from a movie format. But, because I think
Speaker 1: it was It worked better as a film also.
Speaker 2: Yeah.
Speaker 1: I I didn't find the wrap up quite so bad, but I can imagine that if the last forty minutes was an episode, it would seem as though everything was going great until the last episode, which is a weird arc for a thing.
Speaker 2: Yeah. Yeah. Why I think there's one scene in that entire movie slash miniseries that really stood out to me. That was like I don't know if you remember it, but they're Jay Baruchel. Baruchel. Right? Canadian actor. Guy that played
Speaker 1: one
Speaker 2: of the founders. Yeah. He's on stage, like, talking to the team about the iPhone coming out. And one of the senior techs gets a text message and you hear the iPhone noise and he pulls out his phone and mutes it. And he and he's like one of the lead devs for BlackBerry, but he pulls out his iPhone. And I just thought that that was such like a that's really good. Such a powerful scene of being like like he's up on stage being like, we're not in trouble. We're not in trouble. And then you hear the iPhone, like the original yeah. Exactly. You hear the original SMS noise come out of an iPhone in their in, like, their team, and it was like, oh. And, like, to me, that was like, whoever directed it, like, that scene, you nailed it. Like, that to me, like, I was like, yep. There it is. Like, that's the downfall of your company. Like, you just heard the noise of it.
Speaker 1: Yeah. So It's in c. My favorite I thought you were gonna bring up the scene where, Glenn Howarden's character is is screaming at some people. And I won't say the context as a spoiler, but, Waterloo, Ontario is where Blackberry was based, and he, it's Glenn Howerton screaming, I'm from Waterloo where the vampires hang out, which is just like, that was stuck in my head for hours after watching that movie. I'm like, what is going on in Waterloo? I gotta go there. I'm from Waterloo where the vampires hang out with, like, a Canadian accent shouted horse. It was such a I I really like that movie.
Speaker 2: He did he did such a great job playing, playing that role. I thought I I don't know. I thought the casting, like, for essentially a Canadian film
Speaker 1: really good.
Speaker 2: Like, to bring in a bunch of, like, like, top tier acting talent to run the leads. I thought they did a great job. So if you haven't seen it, I don't even remember exactly what it's called, but let's look it up. I highly recommend I think
Speaker 1: it was called Blackberry.
Speaker 2: It's just called Blackberry. If if if you're old like me and you had a Blackberry, you should go watch this movie because it's it's good. It's fun. It's like an interesting narrative on it, so highly recommended. I think it's on Amazon as well as it looks like it's for rent on both YouTube and Google, and it's on Crave. So there you go. If you have any of those things,
Speaker 1: There you go.
Speaker 2: Do yourself a favor. Go spend an hour or two watch this. Any You should
Speaker 1: still have the advertising oasis sound design firing in the background of this whole part. I wanna talk about a AI powered Russian bot farm.
Speaker 2: Talk away.
Speaker 1: Are you down?
Speaker 2: Yeah. Of course.
Speaker 1: K. I'm basically an
Speaker 2: AI tool to write me my responses fast enough that
Speaker 1: You prob you probably could, and you you wouldn't be alone. So the FBI announces they took down this, a thousand, you know, account botnet powered by AI. So, announcing the take down of this bot farm that's using large language models to power about a thousand fake accounts on x and Twitter spreading disinformation, coercion sentiments. You know, AI powered botnets spreading state sponsored propaganda is kind of novel, but it's made up of relatively familiar parts.
Speaker 2: Don't we just call that Twitter now? Just like It's
Speaker 1: really bad. I don't go on there very often, but it's just bots.
Speaker 2: It's the yeah. It's interesting. I'm not sure I'm not sure how they're gonna compensate for it, but there are a lot of and you can like, I've gotten well like, you know how there's, like, teachers that know how to read between the lines of what is a chat generated essay? It's like I can now when I'm on when I do dip my toe into the observing pool of x.com, I can immediately see It's always in the comments and the responses. So, like, something will get posted and, like, then there will be a bunch of, like, weird account names that have, like, this perfectly structured response.
Speaker 1: And I'm
Speaker 2: like, oh, that's a bot. Like, that's a bot. Like, that's a bot. Like, they almost have to look for, like, whose grammar is too good. And then, like, auto moderate all of those things because everybody else on x is just, like, screaming, you know, political and social positions in, like, broken English. And then there's like this well structured, like, thing being like, well, I think Russia deserved to invade Ukraine because Ukraine has and it's like and you're like, okay, that's a bot. So am I am I shocked at who's behind this botnet?
Speaker 1: If it uses a semicolon, that's probably not.
Speaker 2: Am I if I'm am I surprised that Russia was behind this? Then no, if there's something more deeper, then maybe. But if it's just a Russia state sponsored thing, that does not surprise me whatsoever.
Speaker 1: No. That part alone isn't necessarily surprising. Are you familiar with rt?
Speaker 2: Rt.com, like the like the Russian telecom, the news thing? Yeah. Russian Today
Speaker 1: Russia Today oversee a seg sorry. One sec.
Speaker 2: All good. There there's the noise from BlackBerry. There's the noise from the BlackBerry movie. You still use
Speaker 1: I still use that. Yeah. RT, Russia Today, Rosalia, Segovia is a Russian state controlled international news television, you know, network. It's funded by the Russian government. This botnet was not created by a company inside of Russia or, like, a a, you know, state sponsored hacking group. This botnet was allegedly created by RT, by the, deputy editor in chief back in 2022, funded and approved by the FSB, which is the successor to the KGB. So this botnet on Twitter was produced by a large news network.
Speaker 2: I wish I could act more shocked to that, but I feel
Speaker 1: That attracts to you.
Speaker 2: That attracts to me. The and maybe it's because I spend so much time on x listening to people shout about media biasing. I I don't spend a lot of time on x, but when I am on x, I see those sentiments perpetuated constantly.
Speaker 1: Sure.
Speaker 2: And, like, we all know this. Like, Canada has the CBC and there's a large faction of Canada that believes that they're essentially just the, propaganda arm of the current government. So like like a bunch of Canadians believe that. So for the CBC version in Russia to be a propaganda arm of the KGB, that doesn't surprise me, sadly.
Speaker 1: But them them running an LLM powered botnet on Twitter, Maybe it's just like the word cloud is so strange, but I guess it it does sort of track. It's what you'd expect. They're using American sounding names and fake accounts set in locations across The States. User accounts like Ricardo Abbott from Minneapolis posting a video of Putin justifying what they're doing in Ukraine. Sue Williamson posting a video of Putin, talking about a new world order. It's all the content you'd expect but from these, you know, faux American accounts produced by a newsroom. The, you know, this, you know, giant botnet, they they put they this botnet was mentioned in a cybersecurity advisory by the FBI, The Netherlands intelligence officers, Canadian cybersecurity authority. Just sort of talking about how they use these LLMs to create these social media personas en masse to generate text messages and images and to sort of just mirror the disinformation, that other bot personas were, you know, creating to sort of develop a bit of a sense of a consensus on the platform on a case by case, topic by topic basis. Yeah. Yeah. I found it fascinating. I guess it isn't really that surprising. It's the the kind of thing where as you say it out loud, you're like, yeah. It is it is a very familiar ingredients, but I I was intrigued by that.
Speaker 2: I don't know what you'd call this, you know, clusterfuck that is development and fact finding and developing of ideas and ideologies, it makes total sense that you'd want a multi prong attack and it doesn't sadly doesn't surprise me. And I don't know. I think I would spend more of my time focusing on who's to blame. Like Russia's obviously just trying to do what's best for Russia's interests. Like, should we be holding X and Facebook and any of the other social networks more accountable to not like, at what point are we just gonna start banning all traffic from Russia? And again, you know, to cite back to a story recently about North Koreans being our IT people, will that even work? Like, how where where are we gonna where where are we gonna intervene here? So it's like, how can we put a stop to this? And when will truth come back? And does truth even exist as a concept anymore? What even is truth?
Speaker 1: What even is truth? Truth exists that Russia is running probably a ton of large LLM powered botnets to tell stories and spread information abroad is not surprising. That a large media institution would actually be behind it is, like, kind of novel to me. The fact the thing that feels like it's shifting is the normalization of it, and this is maybe in where the story ends. And it has to do with the fact that RT I'm not gonna say they haven't denied it, but it their response was pretty fascinating to me. And it wasn't saying, no, this didn't happen. No. We had nothing to do with this. So Bloomberg broke the story. Again, on the topic of botnet farming, RT's response to Bloomberg who wrote the story was, quote, farming is a beloved pastime for millions of Russians, which, like, I I am really not on their side on this one. That's a pretty funny thing to say when someone's accused you of running a state sponsored, LLM powered botnet.
Speaker 2: Oh, that's amazing.
Speaker 1: It's quite the response.
Speaker 2: Yeah. That's whoever the head of that PR department is deserves a raise or deserves whatever empower the the government of Russia can give them. Aside from the great, quote, it's like this stuff, this stuff works, you know, social manipulation works marketing like we work in marketing, like we know that this works like it. It's like we read these stories here about it being used for social and political manipulation, but it's like we haven't seen in our ad marketing careers the service offering that these like, I I'm I'm what I'm trying to get to is that I'm shocked that there's there's not one of these for, like, rent or, like, you can buy media time and have your own bot farm promote your your product, social cause, whatever we're marketing because it's like this stuff works. And it's like they know it works, and they've been tuning it. Like, Russia, China, Korea, North Korea have been doing things like this for, I would say, the better part of a decade. And it's they're tuning it. They're getting better at it. We had now have large language models, which make it more effective. They don't have to use as much, you know, human capacity. They can use more chip capacity. It yeah. It it makes sense
Speaker 1: Mhmm.
Speaker 2: If your goal is to change the perspective on something. So, yeah, it's it doesn't shock me. I'm interested to see when this stuff starts to impart into our world of, like, hey. You wanna promote your social cause? Like, we can really mess up social media around, you know, a geographical area for, like, the state sponsored, you know, social political manipulation tool to a marketing tool unless these social networks can get ahead of it in some way.
Speaker 1: Yeah. Like you said, I would assume that probably is already happening on mass the day that, the BBC or CBC or CNN started talking about how they're doing it with quippy little lines and press blasts. That's gonna be
Speaker 2: Oh, yeah.
Speaker 1: That's gonna be an interesting day because it kind of happened here, in the place where you would maybe think it would happen, because as they said, farming is a beloved pastime for millions of Russians.
Speaker 2: And with that note, we're gonna sign off.
Speaker 1: On that note, we got Ticketmaster. We got, AT and T, you know, hack stolen records. We got AI powered Russian bot farms. It was a fun one. Beat the heat, Scott. Stay cool out there. Stay hydrated
Speaker 2: by firm. You too. And if anybody's looking to jump into a nice summer visor, be sure to check out store.hackpodcast.com. If you've got any interesting tales and stories of cybercrime hacks, technology manipulation, anything fun and exciting that you wanna share with the group, hotlinehack.com. Is there anything else that we need to hit before we sign off?
Speaker 1: I think that's everything.
Speaker 2: Thanks again, all.
Speaker 1: Think, I think thanks for making it to the end, and we'll we'll catch you in the next one. Take care.
Speaker 5: If you've got an insurance question, you could talk to your nana. But she'd probably just tell you how she insured her couch from stains by covering it with plastic. Or you could talk to your local GEICO agent. They'll give you a different kind of warm and fuzzy with personalized assistance for all your insurance needs, like how you could be saving on your policies. So let your nana cover her couch in plastic and let a local GEICO agent help cover you, but not in plastic. To find a GEICO agent near you, visit geico.com/local.
Speaker 6: You're great at protecting your data, but lots of places could still expose you to identity theft.
Speaker 7: I thought it was safe.
Speaker 6: If that happens, LifeLock gives you a US based restoration agent who will stick by your side from start to finish. Phone calls, filing documentation, preparing insurance claims, your agent handles it all. In fact, we're so confident restoration is guaranteed. Pour your money back. Isn't it nice to have someone like that on your side? Save up to 30% your first year at lifelock.com/podcast. Terms apply.
Speaker 7: Tired of your car insurance rate going up even with a clean driving record? You're not alone. That's why there's Jerry, your proactive insurance assistant. Jerry compares rates side by side from over 50 top insurers and helps you switch with ease. Jerry even tracks market rates and alerts you when it's best to shop. No spam calls. No hidden fees. Drivers who save with Jerry could save over $1,300 a year. Switch with confidence. Download the Jerry app or visit jerry.ai/libsyn today. That's jerry.ai/libsyn.