Ethical Space Hackers + CryptoProgram + Juice Jacking Revisited.
TL;DRA cybersecurity team ethically hacked a European Space Agency satellite to expose GPS and image vulnerabilities. The episode also revisits FBI juice jacking warnings, finding no documented real-world attacks, and examines a crypto scam…
A chat episode about the world's first ethical satellite hacking exercise, a much deeper look at Juice Jacking and whether (and when) it's actually a thing, and a remarkable crypto themed money making opportunity that walked through our door.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: This episode, we're gonna boldly go somewhere hacked has never gone before.
Speaker 2: Where are we going, Jordan?
Speaker 1: Hacked is going to space. Oh. Hackers in space, Scott.
Speaker 2: It's, you know, this is it a utopian or dystopian? I'm I gotta ask.
Speaker 1: You've heard the show before. It's Star Hackers. It's cosmic cybercrime. No. They're not actually in space. These are hackers on Earth, but they are hacking stuff in space. We are talking about the cybersecurity team that hacked a European Space Agency satellite to prove, a, that satellites can be hacked, GPS coordinates manipulated, images sent back doctored, and, b, to figure out how to stop it. Makes sense. We're gonna loop back around and talk about a topic we touched on very briefly a couple episodes ago, juice jacking
Speaker 2: Okay.
Speaker 1: And ask an important follow-up question about that FBI warning against Juice Jacking that we read off in that episode, which is, has it ever actually happened? Oh. And then in the back half, we're gonna talk about a website that came across your path, Scott, with a really just incredible crypto themed money making opportunity. Not just an Internet story. You bumped into this one IRL.
Speaker 2: I'm not gonna say much right now because I wanted to be a part of this. I wanted I want people to experience this. You know, we talk about crypto
Speaker 3: Sure.
Speaker 2: Usually off handedly on this podcast, and we've never really Yeah. Taken a shot at it. It's not our attention. We do talk about, like, obviously, lots of the cyber crimes and other things that go on, the frauds that live in the crypto space. And, yeah, one came walking through my door the other day. So I think I I think I just got to embrace it and take the time to talk about it.
Speaker 1: I'm I'm looking forward to it. All that more in this episode of Hacked. How you doing, Scott?
Speaker 2: I'm good, Jordan. How are you?
Speaker 1: I'm doing good. I'm good. You really turned that one over in your head. You thought about it for a second.
Speaker 2: Well, you know, it's I'm a I'm not gonna lie. I feel like the brain's a little cloudy today. Sure. But, you know, we were chatting before the episode, and I feel like Jordan's in the same boat. So let's let's hope that we're maximizing our sharpness here. Maximizing my sharpness. Turning my brain on.
Speaker 1: I'm here to pour the last 5% of sharpness I have in me, into the microphone for the people. So, hopefully, we can do it.
Speaker 2: So where do we wanna start? Do we wanna start with Space Hackers, or do we wanna go juice jacking first? I feel like, you know, it's a tie back to previous episodes. I think we should kick it there.
Speaker 1: Why don't we why don't we start there? So for anyone that didn't hear it, couple episodes ago, right at the very, very end of the episode, I think the press release had gone live that day, so we decided to include it. We we touched on something called juice jacking. The FBI had put out this warning. For anyone that doesn't know or that wasn't listening to that, juice jacking is a cyber attack essentially where a person's device is compromised when they plug into a public charging station. There's a bunch of variations on it, but the basic idea is you you try and use a a publicly available port, and it compromises your phone or device.
Speaker 2: For the long time listeners, we did an episode on bad USB. Some of you will know what that is. Some of you isn't. But, essentially, it's a USB key that is used to compromise computer systems. It requires physical access. You insert the key into the computer, then does some things, you know, tries to compromise the computer. And I guess juice jacking is the same kind of idea. You know, the the little port on the bottom of your phone, you know, if you're lucky enough to have a USB c, unlike us Apple users who have, you know, FireWire. No. It's not FireWire.
Speaker 1: What is it? Lightning. Thunderbolt. Lightning.
Speaker 2: No. Lightning. That's what it is. Lightning. It's essentially a USB port still. It's not the same protocol and stuff, but essentially gives hardware access to the device. That's why they can pull an HDMI out of it, you know, feed insert into SD cards and things like that. Like, you can get dongles that come out of your phone because it's essentially a a bus access port just like a USB port would be. So juice tagging kinda makes sense. You know? We're living a world of bank card skimmers and, you know, tons of other hardware implementation level frauds and hacks. You know? Deuce jacking just seems like something that would be if they're not doing it, I would say that's a missed opportunity for bad people.
Speaker 1: A missed opportunity for bad people. Yeah. It sure does seem like it would be a thing. So last week, the FBI puts out I think it was the FBI Denver office puts out that warning, Then the FCC re ups and puts out the warning another time, and that kinda one two punch, everyone covers this. NPR suggests, quote, crime is becoming increasingly common potentially due to a rise in travel. WAPA says, quote, there's a substantial privacy risk due to juice jacking. CNN cautioned that connecting to a malicious charger could lead to immediate infection. There's a Fortune headline warning readers not to use these free charging stations lest their, bank accounts get depleted. These these announcements prompt a whole bunch of of media coverage about this thing. It, as you said, has been kind of floating around in the world for a little over a decade now. Term was coined originally, I think, by maybe not friend of the show, but someone we're both fond of, Brian Krebs, coined it back in 2011 when he saw a Oh, yeah. Actually a tech demo with a large hacking conference about this.
Speaker 2: I'd love to I'd love to meet Brian one of these days. You know, I feel like we talked about him enough. And if you don't know who he is, you should check out Krebs on security.com. His his blog, it's amazing. Something I've followed for literally
Speaker 1: I think we gotta start going to those conferences. I feel like all these stories, there's always like a there's a and then
Speaker 2: Participate in the world, Jordan? Participate in the community? Come on.
Speaker 1: So so that's juice jacking. Right? This thing that makes total sense. There's these FBI releases, these this FCC announcement. Everyone covers it, and that was kind of the story. That's when we, you know, kinda skimmed past it, talked about it on the show a couple weeks ago. Then there was this secondary wave of coverage that I wanted to talk about here. An article by Brian Krebs and then a another article from Ars Technica. The Brian Krebs article, the headline was a little bit a little bit gentler. It says, why is juice jacking suddenly back in the news? Ars Technica's Dan Gooden went a little bit further. Fearmongering over Publix charging stations needs to stop. Here's why. And the thrust of these is that broadly speaking, most cybersecurity experts maintain that juice jacking is not a threat to the general public. Unless you are being targeted by a nation state actor, there are quote no known real world cases of juice jacking because modern iPhones and Android devices require users to acknowledge a warning before exchanging files with connected devices.
Speaker 2: Mhmm.
Speaker 1: Mike Grover, a researcher who court, like, essentially creates offensive hacking tools and conducts offensive hacking research for big companies, believes that the threat of juice jacking is exaggerated for the general public and is more relevant to targeted situations. There are extreme edge cases where keyboards or devices disguised as keyboards can enter malicious commands when connected to iPhones, but these attacks are limited and are pretty impractical for juice jacking. The big headline here is that for the past five years, no one has demonstrated a successful juice jacking attack on a device running a modern version of iOS or Android. Apple representatives, when contacted, were not aware of any attacks in the wild, and no security experts or documented cases of juice jacking occurring in the wild have been found.
Speaker 2: That's fascinating.
Speaker 1: I found it very fascinating. And then I thought about it. I I I plugged in, one of my partner's lightning cables that I never used, and my phone, as Android phones do, popped up with a little thing saying, hey. Would you like to allow data transfer using this cable and device?
Speaker 2: And?
Speaker 1: Well, I clicked no. And it seems like that's what most people would do.
Speaker 2: K. I'm gonna counterpoint that because I've done this at least five times
Speaker 1: where
Speaker 2: I'll jump into a rental car. I'll throw in a USB cable. Sure. Sure. And, you know, it instantly kicks up and says, hey. Do you trust this card? Do you wanna transfer your phone contacts to it or whatever whatever piles of data? And, usually, I'm in the progress of opening, like, Google Maps, and then that pop up pops up right above the icon I'm about to hit, and I hit the trust button. I've spent time looking for how to undo that trust connection.
Speaker 1: Right. Right. Right.
Speaker 2: Use usually, what happens the second I hit that trust button is I rip the cable out of the bottom of the phone because I don't want all of my 2,800 contacts on my phone to be uploaded to some random rental car in Austin.
Speaker 1: Yeah. Sure.
Speaker 2: So it it's it's I don't I don't think the pop up is is by any means, a security step to prevent anything. You know? Like, how many times you jump on an airplane, you throw your phone into the USB port to charge it, and bang, you get get a do you trust this computer pop up? It's like, absolutely not. I do I trust this? I want the free energy. I don't want I don't wanna communicate with it.
Speaker 1: Mhmm.
Speaker 2: That is fascinating that there's actually no reputable known attacks of with this factor. That's crazy. I would have thought given how many people and the the extents that that people go to steal my credit card
Speaker 1: You'd think they'd want your data.
Speaker 2: Yeah. Be it custom molding, new plastic inserts to go over top of the gas pumps at my local like, the I can't imagine, you know, that that people aren't haven't tried this. It, so Besides proof of concepts.
Speaker 1: Proof of concept is a really good place to start here. So like I mentioned, Brian Krebs, term first kinda coined it, Defcon conference in 2011. It was this researchers demonstrating this proof of concept. The the the idea of compromising, you know, fake wall chargers sort of started to evolve over the years. There was MacTans, which is a really, really popular one. But the the big a lot of the reporting that happened about this, in 2019, the Los Angeles District Attorney's Office published an alert warning people about this scam. People loading malware onto charging stations or on cables left at stations to infect unsuspecting users' devices. TechCrunch reporter Zach Whitaker, started digging into this. He contacted the d DA's office and asked them, hey. Do you have any, like, instances of this happening in your jurisdiction that you can point to? And they couldn't. Followed up saying, hey. Can you, as the district attorney here, point to any jurisdictions in The US where this has happened, and they couldn't provide any. So it's not to say that there aren't any happening. It's that there's a lot of announcements going out about how this is a very significant threat without a lot of documented case studies. It's not to say, however, that, charging stations and cables can't be used to compromise devices. It's just worth looking into how they can be used to realize that, it's a pretty, high budget operation. So Linus Tech Tips just did a, like a little dropped a little video about something called the o m g cable. Mhmm. It's a regular looking USB c lightning type cable. It's a lot like the bad USB rubber ducky from that episode from years ago that you mentioned, Scott. And it's a cable with a little microcontroller used to emulate an input device like a keyboard and a mouse. Even has a little Wi Fi, emitter inside of it so that it can create its own little network to talk to other networks. Really interesting product. Costs $200 for one of these cables. Requires a moderately high technical sophistication to even use. This isn't to say that someone couldn't use this against the general public. It's that it's much better for, like, a targeted attack, and there are much easier ways to hack the average person. Everything we talk about in the show is that you just you lie
Speaker 2: to them. The ultimate hack. The lie.
Speaker 1: You don't need to buy $200 The ultimate hack is you just lie to them. Mike Grover, the security researcher who created this product, says that, he wants to live in a world that is so secure from that kind of social engineering and lying based hack that the only way to get the average person is to need to use a 200 cable. This just isn't where you would start for most people. I found that very interesting.
Speaker 2: I just wanna I just wanna back up a step. You caught my interest when you you mentioned some of the stats. Mhmm.
Speaker 1: A
Speaker 2: lot of conversation about communicating with district attorneys and other American things. Sure. Have you thought about the option that maybe this attack vector is being used in other foreign countries of which I will not name, but we can all assume we know which ones we're talking about.
Speaker 1: Yeah. Sure. Definitely.
Speaker 2: And they're and they're worried that that attack vector will be brought into, another global power that they're not currently, you know, in love with. Operating in? Yeah. Sure. Sure. Yeah. So the that would that would be where my mind goes is is if anyone's doing this in any kind of massive scale, like, you hear Mhmm. About, you know, eastern superpowers and how they how they love good insights into their their citizen base and population.
Speaker 1: Mhmm.
Speaker 2: I could see I could see this being something that's actively going on and, like, say, you were to take a a lovely trip to, you know, beautiful Saint Petersburg and plug your phone in somewhere. Mhmm. You know, it's just it's probably a better habit to develop to, like, understand that when you plug Yes. It's not the power cable in your laptop. You know? Back in the day when you had, like that's just straight, you know, DC voltage coming into your laptop. There's no way to really hack your computer through a DC input feed that goes into a power. Mhmm. Where when you plug in the base of your phone, you're essentially USB c powering it and giving access to whatever you're plugging into to your phone.
Speaker 1: Yeah.
Speaker 2: Or tablet or whatever or a USB c powered computer. And that changes the changes the risk profile plugging into things. Now it'd be interesting if we saw the rise of of phones that had a separate power port.
Speaker 1: Oh, interesting.
Speaker 2: Or maybe just the room removal of a bus port altogether because that could be a thing as we go more and more wireless.
Speaker 1: Until you switch over to the the, data transfer port because you need to connect to your rental car in Austin.
Speaker 2: Hey. Apple CarPlay wireless is coming. Ours here.
Speaker 1: Sick. I think there's so the really skeptical, read here, and I don't think I necessarily prescribe to this, is that this was, this every couple years, we get a little fear mongering press release. And I don't quite think it's that.
Speaker 2: Yeah.
Speaker 1: What I think it is and so a few years ago, the only way you could brute force your way into one of these devices was using something called a gray key. It's a, like, a a device marketed to law enforcement that you can plug a phone into, and after several hours, it can crack a password and it costs $30,000. An o m g cable doesn't have quite that capacity as a different use case, but you can do some pretty similar stuff now for $200. Mhmm. Now, $200 is still prohibitively expensive to buy a ton of these things and pepper them around the world at every, like, public charging station. But 30,000 down to 200, tech tends to get cheaper. Mhmm. So I think that just sort of having this out there in the world is, like, it it's almost, let's get in front of this and start communicating this idea that, you know, don't trust your hardware, before these cables cost $10, before they get so cheap that you can just have them out in the world and see what happens. Because just because we're not there yet does not mean we're not going to get there.
Speaker 2: Yeah. It's a it's a it's a viable attack vector. Obviously, the FBI feels the same. Whether it's being used a lot or not, it still doesn't reduce the risk of it. So I think I think ingraining in people a sense of security when it comes to, wow, you know, everything in my life is on this tiny little computer that I carry around and is completely vulnerable to being stolen and or, you know, broken into if I do the wrong thing. Like, not setting a passcode on your phone, which is insane. The yeah. Yeah. I I I if it's if it's not a thing, I think the more that people ignore it, the more it'll become a thing.
Speaker 1: Yeah. So
Speaker 2: I think it's it's it's probably a healthy thing to communicate
Speaker 1: about. I think it can be both true that it is not yet as big of a thing as, some of these warnings might suggest, but yet it is almost notably going to become more of a thing. I think those are probably both, at least somewhat term. Yeah. Yeah. But is it a thing in space, Scott? This is the question.
Speaker 2: Something in space into a charging port on Earth?
Speaker 1: Like a satellite? No. I I don't know that you can. I
Speaker 2: don't know.
Speaker 3: I don't know.
Speaker 1: I don't know the juice jack
Speaker 2: is is gonna be a thing.
Speaker 1: It's very expensive to get the cable up there.
Speaker 2: Goes from $200 for a cable to many, many, many million. And Yeah. The deployment of it's very, very bad.
Speaker 1: Well and as we learned about a week ago, there are much easier ways to compromise, stuff in space.
Speaker 2: Let's hear it. Let's hear it.
Speaker 1: So about a week and a half ago, cybersecurity researchers from the large French defense firm Thales, did a demonstration at the European Space Agency's CISAT conference in Paris. It's their big, like, space defense conference. And in this, they did a demonstration in which they successfully seized control of a satellite in a demonstration that has been described as the world's first ethical satellite hacking exercise. Importantly, not the first time a satellite has been hacked, just the first time it was done ethically as an exercise. So this demonstration targeted a European Space Agency's OPSAT satellite. This isn't cyber security related, but I thought it was cool. It was a nano satellite, which I guess are the size of about a shoe box. This little shoe box size thing that contained a quote experimental computer 10 times more powerful than any currently operating on a European Space Agency spacecraft. And I think, from what I was able to assess, the whole purpose of this little shoebox sized OPSAT satellite, nanosatellite, was as a security research, like, machine.
Speaker 2: Sure.
Speaker 1: It was sent up so that they could test live remote testing mission control systems and stuff like that.
Speaker 2: It's like a honeypot. They built themselves a honeypot to test it.
Speaker 1: For them to test themselves. Yeah. They they needed a bull's eye, so they they made their own. So in the demonstration, the company said its ethical hackers exploited the satellite's, quote, standard access rights to gain control of its application environment. It, quote, made it possible to compromise the data sent back to Earth, in particular, by modifying the images captured by the satellite's camera to achieve other objectives such as masking selected geographic areas in the satellite imagery while concealing their activities to avoid detection. They basically got in the middle of the data transmission to and from this little experimental satellite, and they were able to doctor images it was sending back and then conceal their activities.
Speaker 2: So they man in the middle data communication to a satellite?
Speaker 1: The man in the middle data communication with a satellite.
Speaker 2: I gotta like, this this when when I read this, I gotta assume you know, we're not talking about seventies satellites. You know, we're not talking about satellites that, you know, probably have less power than the the USB chip inside of that that cable we were just talking about. Mhmm. The when I when I you said they were doctoring photos. That's always a weird thing for me because my mind always jumps to, like, Photoshop.
Speaker 1: You know? Sure.
Speaker 2: Like, oh, they're just they're how are they gonna get in the middle of a data transmission, open Photoshop, edit a photo, and then resend it? So I wonder if it's not something like it's running UNIX, and it has, you know, a command line image tool, and they were able to modify the image files prior to sending using, you know, ImageMagick or something along those lines in the command line, that would make more sense more sense to me. At least that that was me Sure. Justifying how they did this because it seems pretty insane to be like, oh, yeah. I'm just gonna connect connect to the satellite Yeah.
Speaker 1: Sure.
Speaker 2: Edit some photos.
Speaker 1: Crack crack open creative cloud. Yeah. Totally. My guess would be that oh, lord. I don't know. But, I mean, the these photograph they're only taking photographs of one thing. Right? They're pointing that thing back at Earth and taking photos of down, essentially. Mhmm. And I'm assuming that they're largely stitched together images based on GPS status. So I wonder if by doctoring images, it's more to do with, you know, if you're looking at this GPS coordinate, don't bake it into the images you're sending back. Like, if it's more of, like, a direction for the camera than a doctoring of the image the camera produces.
Speaker 2: Yeah. Yeah. So that's that's where my mind went to. Like, obviously, too, if they're stitching
Speaker 1: Yeah.
Speaker 2: They probably have some form of image tool on the satellite that's executing, you know, a script to do something to these images, be it stitch them, be it, you know, increase the contrast and brightness, you know, whatever whatever the process for for the the pre Yeah. The preprocess of these images is. I wonder if they just interfered with that thing, but it's just a I I thought that that point alone jumped out at me the most being like, They're doctoring images in the transmission. That seemed seemed like the hardest thing. You know, when we talk about building a computer, putting it in a box, and then sending it to space, that computer still having security vulnerabilities isn't overly surprising. You know? It's still a computer at the end of the day. There still has to be inbound and outbound communication from it. To me, it makes sense that you can hack a satellite, just like you can hack a a car or a phone or a computer or anything else.
Speaker 1: Well, the the timing of it is pretty interesting too. So the exercise happened on April 27, and that's almost right before this very big news story concerning a release of a big old batch of highly classified US intelligence documents. I'm not sure if you followed this story, but it was a 21 year old IT worker who allegedly leaked a giant batch of documents on Discord. Not sure if you followed that one.
Speaker 2: I didn't. Didn't see that one.
Speaker 1: Very interesting story. We'll probably talk about it at some point in in greater detail because I think it warrants it. But inside of that giant data dump, there were warnings that the Chinese government is developing very similar safe abilities, capabilities as this demonstration to seize control of satellites. It's the leak suggested some stuff about the methods that folks in China have been exploring. Attackers mimicking the operator signals potentially enabling them to, quote, seize control of a satellite, rendering it ineffective to support communications, weapons, or intelligence surveillance, and reconnaissance systems. So it's a very interestingly timed experiment that lines up with some real world techniques in this document dump that happened again on Discord.
Speaker 2: At Discord.
Speaker 1: Beyond that document leak on Discord, we'll wrap up here is, you know, are there other case studies? Has this actually happened in the real world? World? One is a tech demo. One is sort of alleged tactics. Last year, a researcher from Belgium successfully infiltrated a SpaceX Starlink terminal using a custom designed mod ship. They were able to introduce their own unique code into the Starlink satellite. A separate group of researchers from the University of Texas was also able to gain control over STARLINK satellites. Those were both kind of more experiments. If we keep drilling, though, there are some very real world possible implications beyond demonstrations. Early last year as the Ukrainian invasion commenced, satellite Internet users across Europe started reporting significant service outages. And a piece in Bloomberg described how Russian hackers successfully breached several mainstream satellite Internet companies and were probably responsible for these outages. So while this is still largely a tech demo, still largely a speculative thing in document dumps, there are real world applications for hacking satellites as we become more reliant on satellites.
Speaker 2: Yeah. Absolutely. Especially with the the things going on in the world these days. The amount we're relying on them for, you know, battlefield communication, GPS usage, You know? Their satellites have just become so ingrained in us, not even just Internet connectivity, which is in its own right.
Speaker 1: Like, if
Speaker 2: you've been following the Ukraine conflict, obviously, Starlink has had a big presence in that. The it's interesting that they took control of the satellite and were introducing code and other malicious things via changing something on the the ground level, like something, you know, on in not in the satellite, but they changed the chip in the, like, the local access terminal, which which tells me that they put the control mechanisms here and not up there, which makes it much easier to bypass because you have you can touch it here. Or if you put it up there, it's a lot harder to get up there and change the chip. It's fascinating. I think we're gonna see more and more of this stuff, which is sad, but the the reality is is I think we've GPSs are everywhere. And I remember, you know, twenty years ago, you had to buy an individual GPS unit. Now it's like our watches have it, our phones have it, our cars have it, our you name it. We're all GPS ed up. We've willingly committed to being tracked.
Speaker 1: That's why I'm going to live in a canyon.
Speaker 2: I like this story. Tinder is now requesting, video verification. If you're not sure what that is, it's that you have to essentially shoot a small video. You've you've probably seen some form of video verification at some point in your life. Some sites require for access, other things like that. If you haven't, I'm sure you'll see it more in the future. Essentially, you upload a small video of you confirming that you are who you are. Obviously, usually, you put something in the video to confirm that that is the reason for the video. And it essentially is a a two factor authentication and and identity confirmation so that they can prove that you are who you are and that you're willingly participating in the in the application usage. So for Tinder, that would be you can't make fake profiles because, obviously, you know, with the amount of fraud and stuff going on in the world, they don't want a bunch of people with with fake Tinder accounts trying to defraud people. Completely get it. I think we're gonna see more and more of this style of verification just as the world is being overrun by bots and fake users. But at the same time, I'll say that we're hitting the a different turning point where the bots and fake users are now actually capable of generating their own AI videos, and that's only gonna get better and better. So this type of verification is probably gonna get worse and worse.
Speaker 1: Yeah. So I don't I'm I'm not on Tinder, but like a lot of platforms, they're sort of like a forking in verification. Tinder also uses a blue check mark system. Mhmm. And it's kinda just verification. People can set a preference to, I only want to be swiping and chatting with people that have this verified blue check mark, which is Tinder seal of approval that you are not catfishing someone. And it used to be that you just had to take a photo of yourself using the selfie camera in the app, and now they want you to film a video. So my question on, like, the technical hardware side is, is the app forcing you to use a selfie camera any kind of a defense against an AI based spoof? Does that help prevent against that, or is there a way I'm not aware of of getting around that to feed in an AI generated video into that front selfie camera signal?
Speaker 2: You know? If there's a will, there's a way. Sure. I don't know of the screen, dog. I don't I don't yeah. Exactly. I don't know of anything outside my head, but if if there's a will, there's a way. You know? Right. Putting in in intercepting communication and faking it is something that we deal with constantly. The the the one of the things that I found most interesting about this, and I wanna I wanna flip this now, is something that I've been thinking about a decent amount because it's relevant, you know, both to the show, also to, you know, hobbies as well as careers is, you know, we talked about video game cheaters. And there's this huge huge issue in free to play games. You know, you got your Apex Legends. Your you you can rattle off the list of of free to play games that have massive cheating problems. And it all comes down to the fact that they chase the cheaters and ban them in in such with such haste, but they can just create new accounts. So most cheaters have hundreds of accounts. They don't have one account. When they lose that account, they don't, you know it's not over for them. They just jump to another account. Stop. Keep ruining people's games. And so I was actually thinking about this last weekend. And I think that that blue check mark system needs to move to free to play games because and if you're a game dev, if you work for any of the major studios, this one's free. Take it and run with it. DM us and say thanks. You know, if you create an account, you play some of these free to play games, lots of people buy the battle passes. They buy the the seasonal subscriptions. They spend money on these games. And, like, we've talked about that before. I see that largely as a tipping culture as, like, thanks for making this great thing that I enjoy consuming. Have some money. At the same time, every time I have a bad cheating experience, it makes me wanna play the game less and less. But I like the game. I want game studios to implement essentially a security bond where maybe I pay $20, and it goes into a a trust. And as long as my account never gets banned for cheating, I can get that $20 back. But it buys me the right to have a quote unquote, blue check mark. And then when I match make, I can choose to only match make against people that have the blue check mark. Right. So, essentially, there can be, you know, the public lobbies that are just full of chaos and cheaters running rampant. And then there can be the blue check mark lobbies, which are people who are, like, I'm serious about playing this game. And I understand that there will be financial, retaliation if I get caught cheating. And it's like, I think I would happily pay on a free to play game that I play with some regularity, I would happily pay $20.30 dollars just to have that just to be a part of a lobby and to be a part of games that have a way lower likelihood of having cheaters in them. What do you think of that, Jordan?
Speaker 1: Yeah. I was gonna ask I I like it. I was gonna ask if you need the financial penalty to have a verified blue check mark system, but I do like that the, you don't get your money back cudgel element of it. I think that that would Yeah. It's not here in Canada, I don't know if it's like it in The States, but you have to put a a coin into the shopping cart before you can take it. Mhmm. And if you wanna get your coin back, you gotta put the shopping cart back where you found it. There's a little bit of that psychology at work.
Speaker 2: But that's the thing. Because, like, the issue with free to play is that, like, you get an account banned, you just create a new one.
Speaker 1: Make a new one.
Speaker 2: There's automatic generators that just make hundreds of accounts. You can buy full accounts from the cheating companies. So the funny thing is is that these cheaters are paying tens, hundreds, thousands of dollars to cheat providers to ruin the game for other people. And those other people, I think, would happily pay or at least secure the ability to play without those cheaters. It's it's a the interesting thing, like, you know, you buy whatever digital currency is in these free to play games. It's like, just hold some of it in, like, a bond, and, you know, you can withdraw it and lose the blue check mark at any time. I don't know. I I just thought it would was a way to still allow people to enter the ecosystem of playing the game, but then the people that really enjoy the game can essentially remove or reduce the risk of of cheater interactions in their in their in their play.
Speaker 1: Because
Speaker 2: it's it's honestly one of those things that's just ruining free to play games at this point. And, like, EA's got monstrous lawsuits against companies, Activision too. They're trying to put a put a stop to it, but with the global cheap development community and how many how much money there is to be made in fulfilling that demand, it's it's it's I don't know. It's interesting. You know? Short of short of the government making it illegal like they did in Korea
Speaker 1: Mhmm.
Speaker 2: I don't I don't know I don't know I don't know what other retribution there is. So making it a a bit of a financial thing. If you wanna pay $20 to cheat for 10 games and then get your account banned and lose the $20, you're only gonna do that so many times.
Speaker 1: We talked about this in the, in the GDC episode. But as games are moving kind of away from in app purchases and more towards taxing user generated content, identity verification feels like it, if not being necessary for that to work, certainly has a benefit to know who you are buying and selling stuff to. Mhmm. And know that you're taking part in an economy where everyone has a little blue check mark. Yeah. Sure. I see the appeal of that.
Speaker 2: Yeah. And and, like, I see the appeal of making a free to play game. Obviously, you can introduce it to a large audience with no barriers of entry. Great.
Speaker 1: Mhmm.
Speaker 2: I would say I don't know how many people then convert into being people that spend money on the game, but given the revenue numbers that you see in some of the quarterly reports coming out of major studios, I think it's pretty good. Yeah. So it's like if I'm at the point that I'm spending money on cosmetics in many instances in these games, you're not most game companies get roasted when they have pay to win stuff. But when it comes down strictly to cosmetics and other things, like, that's where, again, I see that, like, tipping culture. You're like, oh, yeah. I love this game. Here's $12. Yeah.
Speaker 1: Toss a couple bucks in the in the hat. Yeah. Sure.
Speaker 2: But at the same time, it's like once you truly start to enjoy a game, if your experiences just get worse and worse and robbed from you by people cheating for whatever, you know, mental health reasons they do that, the the there's gotta be there's gotta be a way there's gotta be a way around it. And it's like, if it's not a financial disincentive, like, they've tried hardware banning, there's spoofers for that. They try so many different things.
Speaker 1: Mhmm.
Speaker 2: And none of them have really worked. So it's like, if they can just get to the point where it is a financial penalty, no. I'm okay with that, especially for established games that have huge player bases like Call of Duty, Apex, League of Legends, things like that. So I I just think it's I don't know. I think it's a it's it's it's something that as a society, we need to be moving more to the video selfie, you know, kind of verification, but maybe it needs to be financial.
Speaker 1: Yeah. For the nine seconds when a video selfie is still, unspoofable, it would, it would solve the problem. But but money's but money's evergreen. It'll always people never wanna lose that.
Speaker 2: Exactly.
Speaker 1: And if they wanna make money, maybe they should look into a little no. I'm not even gonna say that. Some call a crypto program. Oh my
Speaker 2: god. We'll get back to that later.
Speaker 1: We'll get back to that later.
Speaker 2: We'll get back to that after the break.
Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 4: When you need to build up your team to handle the growing chaos at work, use Indeed sponsor jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.
Speaker 3: Sierra has all the best active and outdoor brands you need. From athletic stuff, like a full court pickup game, swish, to athletic stuff, like a half mile stroll. Get those steps in. And for morning hikes up the mountain trail, good pace to nighttime ghost stories from the camping chair. What a twist. Whatever level of active, Sierra loves it all. Head to Sierra or sierra.com for the brands you want at the prices that let you do it all. From athletic to athletic ish, Sierra's got it.
Speaker 5: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid, 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/ license numbers.
Speaker 1: So, Scott, I I've been trying to get rich quick lately. Do you know of anything that could help me out with that?
Speaker 2: Jordan.
Speaker 1: Do I?
Speaker 2: K. Story time.
Speaker 1: Story time. Take me through it. So Yeah.
Speaker 2: We had a birthday the other week, couple weeks back, and one of my wife's friends popped back into town for the birthday. You know, came over, hung out, walked through the front door of my house. Mhmm. And this isn't something we normally cover on the show, not something that I normally wanna cover on the show. But, then proceeded to try in a in a bit of an MLM model, tell us about how they were making so much money on the Internet with crypto. Not just investing in crypto and the regular ways of crypto, but a little system by the name of Crypto Program. So I'm not sure if you're familiar with it. I certainly wasn't. But it's essentially an MLM style investment. I don't wanna the intent here isn't to slander that they might be the most brilliant people in the world and have figured out how to make money out of thin air because let me tell you about the returns on this program in a second. But I will say that there have been a number of notices coming out from securities commissions and administrators saying, you know, hold up, watch out, and maybe don't get invested in this. Notably, the province next to ours, the BC Securities Commission, which I will add is where my friend lives who is currently invested in this.
Speaker 1: So
Speaker 2: they came out, and essentially flagged a notice and said, hey. You know, watch out for this. We exercise or we urge you all to exercise caution when dealing with this firm. They don't have any registration. They have a lot of bold claims and nothing to back it up. You know, please be put on notice. But let's let's just let's just dive into this. You know, there's lots of information. Once once he's once they told me the name of it, I I I went I just googled it and just, you know, found a pretty incredible little article by behindmlm,uh,.com. It seems to be this site that tears apart kind of multilevel marketing schemes and how they work. And this program actually has an MLM model. There are referral commissions. So you get additional returns on the people that you directly bring in and then the people that they bring in. So it has that upward
Speaker 1: Sort of triangular form factor.
Speaker 2: Precisely. Precisely. It seems very multilevel and very marketing. But let's let's just let's just talk about this because it blew my mind. So this company promises on a $550 investment, USD.
Speaker 1: And am I gonna make? Tell me.
Speaker 2: I invested in either gonna be? USD coin or Tether. So the two kinda USD related coins. I wouldn't say that they're, you know, exactly pinched to the US dollars. We've seen some variances occur, but coins that are essentially supposed to represent the value of 1 US dollar. They guarantee a return of 25% per month
Speaker 1: Oh my gosh. Per month, Jordan. Per month? Oh, wow.
Speaker 2: And then you get an for people under you in the tiers
Speaker 1: Triangular shape. Sure.
Speaker 2: The person directly underneath you, for the first month that they're in, you get an additional four and a half percent on anything that they put in. So that's 29 and a half percent. You get an additional 2.8% of what they put in for the months after the first month, but the first month, you get a bonus, so you get four and a half percent. People underneath them, you get a consistent 1.14% return. So that means if you bring enough people into this, you would essentially be getting, like, 29% a month, which is insane returns. Seems seems high. If you've done anything in finance, 29% guaranteed monthly returns is insane.
Speaker 1: Yeah. Crunch those numbers for me, Scott.
Speaker 2: I pulled up I pulled up my trusty, you know, HP 12 c. If you don't know what it is, great calculator. You should get one. Reverse post notation. If you're a math nerd, does a little finance, the HP 12 c, just Google it. The thing's beautiful. It's the nicest calculator in the world. And I ran some quick calcs. If you put $10
Speaker 1: in Some forensics accounting.
Speaker 2: If you put if you put $10,000 in at 25% monthly returns
Speaker 1: I'm gonna be so fucking rich.
Speaker 2: Twelve months in, you have a $145,000. Sick. Twenty four months, you have $2,120,000.
Speaker 1: Double down. What happens in three?
Speaker 2: I didn't run the three. I will in a sec if you want me to. I I just I just wanna talk about this from a corporate perspective because if you can guarantee 25 up to 29% guaranteed returns, that means that you essentially have figured out the matrix and you know how to make money out of thin air. So it's like the the the question then becomes and I don't wanna talk about the fact that this is crypto or this is anything. This isn't an unregulated space, which, you know, should fire up a million red flags. But if you know how to print money out of thin air, why do you need to seek investment? Why are you giving this money to other people? Because you've got to assume that the crypto program people also need to make money off of your investment. So let's say that they they split they split the difference with you. So they give you half and they keep half, which it would be if you know how to make money out of thin air, it seems like a pretty pretty low return for the company. Is there essentially
Speaker 1: people that sell money? Thing to do if you can print money to give half of it away. But If
Speaker 2: you've figured out a system where you can get 50% guaranteed returns on investment, Well, I don't I don't see why you would ever like, the credibility test for me is is if you know how to do that, why are you making it public? If you actually know how to do that, you don't need other people's money. There's no reason to share this. You can make more money than you've ever thought possible. At 50 per at 50% returns I did some quick numbers. Say you took $50,000 in friends and family money. Twelve months, 6,500,000. Twelve. Twenty four months, $842,000,000. So if you know if if you know how to make returns on that level, how? Why have you turned this in your into a multilevel investment opportunity?
Speaker 1: Sure.
Speaker 2: It it it it it blows my mind that things like this exist. Like, people don't give it. I'm not gonna say people think it's legit. I'm gonna say people don't give it enough critical analysis. Sure.
Speaker 1: I'm not gonna assume that the numbers on this site are real because I'm not going to assume that anything on the site is real because my gut is that this is not real. But if you were, to go over to the site and you shouldn't, don't. I'm gonna read it for you. Quote, the best way to grow your crypto. You're gonna see a big old video with a very AI human being taking you through this. There are no names on this site. There are no real human being faces explaining any of this. Behind MLM did some very nice reporting and figured out who is behind this. I'm not going to say their name for legal reasons. But the site would suggest that there are 11,000 registered users with 10,000 registered wallets. And the product they're basically trying to hawk here. Step one, you create an account. Step two, you add a cryptocurrency wallet. Step three, you use it to buy this package. It is unclear what is in the package. It's not crypto. It's something, I think. I I don't I don't know what you're buying, but then step four, you get a 25% monthly return. So it's literally like the step three, question mark, step four profit meme. They put that on a real website and put an AI face next to it, and they want you to give them hundreds of dollars.
Speaker 2: Well, here is here is the here is the question mark. Here's what they state. This is directly off their website. When you a package, we use the funds to buy goods and services at one price and then offer them at another price. So they're essentially doing
Speaker 1: There should be a name for that process.
Speaker 2: They're essentially doing goods and service arbitrage. This one's called online
Speaker 1: Oh, they are.
Speaker 2: Yeah. This one is called online affiliate marketing, sending paid and organic traffic to purchase services when the opportunity presents itself. Oh my god. Means there's it's it's insane to me. It's insane. Either these people have figured out the matrix and are giving it away to people just out of the goodness of their hearts. Because I'll tell you what, Jordan, if I knew how to make 50% legal, 50% monthly returns
Speaker 1: I'll see you on your island, Scott. Like You'd
Speaker 2: only yeah. Yeah. Literally. Like, I would I would leverage and sell everything I own, do it for twelve months, and never nobody in the descendancy tree of my life would ever have to work again.
Speaker 1: Yeah. I mean, so the way these typically work how do I put this? The way certain triangle sheet scheme like, shaped, business plans tend to work is everyone buying into this system, is putting money into a pot. And as long as the pot is bigger than people trying to take money out, the pot keeps getting bigger. Inevitably, there's only so many people on the planet who will fall for a grift. And at a certain point, more people start trying to take their money out than are putting the money in, and the whole thing collapses. Historically, that's what this looks like. You can tether on the, like, I'll pay you, you'll give me a cut of yours, kinda you work under me and my funnel element to it. If you can't keep getting people into it, it collapses.
Speaker 2: I'm going to just simply read off the Merriam Webster definition for Ponzi scheme. Has nothing to do with this company. Not implying it. Unrelated and of state
Speaker 1: It's completely unrelated. Fact.
Speaker 2: Yeah. An investment swindle in which early investors are paid off with money put in by the latter ones to encourage more and bigger risk taking. Famous Ponzi scheme, Bernie Madoff, lasted for decades. The ability to bring people in, give them guaranteed returns, show them on paper that they're making returns. And then when the odd person cashes out, you just pay it from the pool of money given to you by other people. As long as you can keep growing the pool, if people wanna cash out, they can, which actually means that some people, Ponzi schemes, probably actually made out good and got insane returns. And I I think
Speaker 1: Mhmm.
Speaker 2: Having spoken to my friend that he knows people and is a person who has made out somewhat good from this. But at some point, in a completely unregulated investment with no oversight, you anyway, I'm not gonna say anything. I'm just gonna say you should just Google it because if I knew how to make 50% and our monthly returns
Speaker 1: Maybe we'll, try you have no idea what I would do with it. Let's, let's let's maybe put a pin in it with, what behind MLM wrote about this. Sure. Is it puts it nicely. The business model fails the Ponzi logic test. Anyone capable of legitimately generating 25 a month on a consistent basis isn't giving you access for free. In fact, they probably wouldn't be giving you access at all because 25% a month with even a modest starting capital soon turns into a fortune.
Speaker 2: That's exactly my thought process when they were explaining it to me. I was like, there's no way that that people are just like, yeah. Why wouldn't why not? Why wouldn't I just give this to you?
Speaker 1: They go on to say, I'm I'm quoting behind mlm.com again. Just quoting them. While I can't speak for every promoter, neither crypto program or the name of the person they have, looked into as being behind this, neither of those are registered with the SEC. This means, at a minimum, Crypto Program is committing securities fraud. Seemingly well aware that they are operating illegally, they offer up this disclaimer, arguing that they are exempt from The US Securities Act of 1933. They do not cite a reason why. Quote, disclaimers like this are meaningless. You can't just claim to be exempt from securities law and carry on breaking the law. Yep.
Speaker 2: Right through my door.
Speaker 1: Yeah. Wow. This is walked right through your door.
Speaker 2: It's funny. You know, we we make the offhanded comment about crypto here and there and about how it's an unregulated space and the risks and the thievery and the Sure. Sure. And you name it. And then this one just, you know Yeah. Hopped into my life. I felt like I had to talk about it. It's it was just such a fascinating
Speaker 4: fascinating
Speaker 2: challenge to society to to to look at it and go, this seems like a great idea versus this is clearly something that I should be scared of.
Speaker 1: Mhmm.
Speaker 2: And the intro the the human nature is fascinating where some people see it as the opportunity that they've been waiting for, and other people see it as, you know, a risk, a massive risk.
Speaker 1: You see story after story after story of people getting rich by investing in stuff, and then you see story after story about people getting rich investing in crypto, and then a crypto investment thing comes along and says, this is that'll now all that, this is gonna happen to you. It's very compelling. And just like OneCoin, what we have here isn't even really this isn't a crypto scam. There's a lot of bad faith crypto projects, big rug pulls. That happens all the time. This isn't even that. This is, allegedly just a Ponzi scheme that you buy into with crypto. They haven't created a new coin or token or thing. They're just using that stuff
Speaker 2: I
Speaker 1: to do a good old
Speaker 2: fashioned Ponzi scheme. Proclamation. I'm just here to talk about
Speaker 1: Allegedly. Allegedly. Allegedly. Allegedly.
Speaker 2: Yeah. Anyway, I think that's I think that's it. That's all I wanted to talk about. So, you know, solving video game cheating, watching out for potentially risky crypto investment structures on the Internet. Hackers. Safe hackers.
Speaker 1: Mhmm.
Speaker 2: Juice jacking, whether it exists or not and whether it will exist or not, and whether it exists or not in other countries. Getting for Tinder.
Speaker 1: And getting verified on Tinder, and whether or not AI will make all that, irrelevant. You know what? Let's end here. Just on the subject of AI generated videos, which are relevant to Tinder and relevant to a cryptoprogram.me, Did you follow the fake Drake story?
Speaker 2: Oh, yeah. Absolutely. Heck, yeah. We're talking about the music generated one?
Speaker 1: Yeah. The music generated fake Drake.
Speaker 2: Yeah. Love it.
Speaker 1: I think we're gonna talk about this in the future. The new one that just dropped, the other day was a Frank Ocean one. But what was interesting here wasn't that it went viral on the Internet. It's that someone used that technology on a leaked music form where people sell leaked prelaunch music to one another. They created fake Frank Ocean music, went on one of these forums where people buy early access to leaked tracks, sold the fake tracks to those, underground music collectors, and made off with, like, $13,000.
Speaker 2: Wow. Yeah. I I I wonder when Frank Ocean's gonna radio only to hear his new hit single that he didn't and I know nothing about it.
Speaker 1: Not before Grimes does. Not before Grimes does because she just put her voice out for anyone to use.
Speaker 2: Did she?
Speaker 1: Yeah. She did. It's actually pretty cool. I don't know why I brought this up right as we're outroing an episode. It seems like a whole thing we should talk about. Maybe we'll talk about this on the next Chatty Chat episode of Hacked.
Speaker 2: Take care, everybody.
Speaker 1: Thanks for listening.
Speaker 6: Athletic brewing company crafts award winning non alcoholic beers for those who wanna be part of every round. With over 185 flavor awards, they're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company fit for all times.
Speaker 7: The right window treatments change everything. Your sleep, your privacy, the way every room looks and feels. At blinds.com, we've spent thirty years making it surprisingly simple to get exactly what your home needs. We've covered over 25,000,000 windows and have 50,005 star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real design professionals, free samples, zero pressure. Right now, get up to 45% off-site wide, plus get a free professional measure at blinds dot com. Rules and restrictions apply.
Speaker 8: From lashes for days with the viral liquid lash extensions mascara to awakening your eyes with lift and color from the brilliant eye brightener, Thrive Cosmetics is the go to when you want to amplify your everyday look. Plus, every product is 100 vegan, cruelty free, and made with clean skin loving ingredients that work with your skin. And for every product purchased, Thrive Cosmetics donates to help communities thrive. So every time you use your favorite Thrive Cosmetics product, you're helping communities you care about too. Amplify your everyday. Go to thrivecosmetics.com/shine26 for an exclusive offer of 20% off your first order. That's thrive cosmetics, causemetics.com/shine20six.