episode.ascii — live render
● episode

Pig Butchering, Ring Cam Swatters, and Raspberry Robin

TL;DRPig butchering scams, Ring cam swatting, Raspberry Robin USB malware, and decriminalizing ethical hacking in the UK are among the ~7 short tech/security stories covered in this roundup episode.

A chat episode about all these things and more. Sorry, a "chatty chat" about exactly seven topics.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Here here's my question. What's better than one story?

Speaker 2: I don't know. Like, seven?

Speaker 1: It's pretty that's a specific number.

Speaker 2: Oh, yeah. I'm a specific kinda guy.

Speaker 1: This episode, we're gonna what are we gonna be talking about this episode, Scott?

Speaker 2: Approximately seven things.

Speaker 1: Roughly speaking, seven things, which include, in no particular order, decriminalizing ethical hacking in The UK Mhmm. Ring cam swatting. Mhmm. Mhmm. And you know those weird, like, WhatsApp or text messages that you get that start with, like, hey, Doug. It was great to catch up with you. And you go, wrong number because your name isn't Doug, and you didn't catch up with anyone yesterday. And then they keep talking to you, and you do you ever get those texts, Scott?

Speaker 2: Yeah. But I've never responded, so I didn't know that they actually continue talking to you.

Speaker 1: They do continue talking with with you. It's something called a pig butchering scam, and it's far darker than this jovial setup would suggest, talking about all of those things along with a bunch of other stories for, to be very specific, from the world of tech and security here on Hacked. How's your break, Scott? Break was good.

Speaker 2: Jordan, how was yours? My break was

Speaker 1: my break was okay. A COVID blight fell upon my household, so my coming home for the holidays plans were replaced with sitting on the couch and playing, a surprisingly legal amount of Breath of the Wild. Hundreds of hours.

Speaker 2: Like, like blood clots in your leg durations of times? Like, you you you were worried that you have now become part of your couch?

Speaker 1: Yeah. Like like, on an international flight where they're like, for for health care reasons, you should stand up, walk around a little bit, shake it out so that nothing bad happens before we hit the ground. That amount of sitting on my ass and, really just exploring Hyrule, which that game I don't know when that game came out. Like, 2017? That game holds up.

Speaker 2: Oh, and there's a new version coming. Ta ta da.

Speaker 1: There it is. Tears of the king Tune

Speaker 2: in to our new hacking pod our gaming podcast to to hear our early thoughts. No. Just joking.

Speaker 1: I was, what'd you get up to?

Speaker 2: I had a well, there's a bunch of flight catastrophes up here in Canada. A bunch of snow hit Vancouver, which messed up the whole flight system, which messed up some travel plans for my mother. And so she ended up at our house, surprisingly, for four days, which was lovely. But it did mean that she got to her destination four days late as, we joined her there as well. So we went away somewhere warmer for for the Christmas break. And then, yeah, other than that, just kinda working and chilling, trying to relax a bit, get a break in here before work gets crazy again?

Speaker 1: I all the, like, news footage of the Canadian airports being shut down. For anyone who doesn't know, there was a bunch of snowstorms that hit Canada. Our airline system basically stopped working. It It was a lot of Canadians in airports looking flustered, but my favorite part was one of the little bits of news coverage then cut to an American guy who said something that hadn't really occurred to me, which was, I would have thought that Canada was used to snow, but it seems they're not. And then he was the chillest one of everyone. He's like, but that's okay. I'm just happy to be on vacation. And that that brought me some calm during a trying time.

Speaker 2: Well, the it's funny because so where when we were away, I ran to do a bunch of Canadians, and they were all talking about it, obviously, because everybody was because it disrupted everybody's flight plans, essentially. And, they said the same thing. Like, we where I where I live in Edmonton, Alberta, there is it's I I've flown into the Edmonton Airport at minus 45 dozens of times, pumping snow, freezing rain, you name it. Edmonton Airport Sure. They've got it handled.

Speaker 1: Rain or shine.

Speaker 2: Van Vancouver, on the other hand We're cowards.

Speaker 1: Know, one

Speaker 2: of our largest, yeah, one of our largest city has, like, one de icing machine and, like, no snowplows. And it's like, okay, guys. Like so the like, one of the largest hubs in Canadian air travel Yeah. Was completely dwarfed by, like, six inches of snow and, like, a couple of cold days.

Speaker 1: My favorite comment was someone, like, a very I live in Vancouver. A very earnest Vancouver person saying, this is the second year this has happened. We need a solution. Have they considered building a roof over the runway? And I read the comment, like, nine times back and forth, like, really just trying to understand if they were being sarcastic or not, and I don't think they were. And my friend, you you can't Yeah. Because airplanes take off from there.

Speaker 2: And land on there.

Speaker 1: I don't think they realize that. And it famously land on there. Like, that's the only two things you do on a runway are incompatible with a roof.

Speaker 2: They go you either go into the air through a roof or from the air onto the ground through

Speaker 1: From the sky onto the ground. Exactly. So I haven't followed up to see if Vancouver Airport is building a roof over the runway, but

Speaker 2: I'm gonna make an early prediction and say no. No? Say that's gonna that's gonna get vetoed probably pretty hard. So

Speaker 1: Well, 2023 is we're we're at the beginning of the year, so we'll see.

Speaker 2: That is that is really funny.

Speaker 1: This is a cybersecurity podcast. We haven't done any of that yet.

Speaker 2: Well, we could talk about some cybersecurity stuff.

Speaker 1: I think we should. I think we should first talk about why, this is a little bit different. So there's always, like, short stories that we bump into when we're researching the show that you could never really hang a whole episode on. Right? Like, you could probably talk about this for ten minutes, but you couldn't really juice a full half hour, forty five minute episode out of it. Right?

Speaker 2: Plus it's just there's very interesting little stories that might not have the depth for a for a Jordan narrative. You know?

Speaker 1: For for full blown narrative experience. Years ago, we tried doing the the news update format, and that was really fun. But I think what we figured out is that short stories, good, short episodes, bad. Yes. When we did the the sort of retrospective episodes last year, it kind of all came together where you string a couple of those in a in a row, and you got a pretty nice experience. We get to dig into stories that are interesting and compelling, but maybe couldn't support the full narrative experience, and it gives us a space to talk about them. So we're gonna try that for over a couple months in the mid month episodes. We're gonna keep keep that first of the month episode for the big the big story episodes. And we're gonna see how that see how that sits with folks.

Speaker 2: Yeah. So please hit us up on, you know, Twitter, Patreon, any way to get a hold of us. We've gotten a lot of Patreon messages. If we haven't got back to you, thank you so much for your support. We love you to death. We just Mhmm. Have been away and doing things. So so if we've if you fired something in, especially kind words, know that we respect and appreciate it.

Speaker 1: Where do we wanna start, Scott?

Speaker 2: Well, I I wanna start on on a a piece of malware that was kinda blowing up at the end of last year even though it's about a year old. Okay. The piece of malware, it's, it's called raspberry Robin. And the reason I wanna talk about this is because it goes way back in the hacked archives to bad USB because the way that this, like, quote, unquote, worm spreads is payloads off of USB drives. And it's like, I feel like people and operating system manufacturers should be pretty aware of this, and they're we we need some form of intervention to stop this from happening. Like, this USB delivery doesn't even auto execute, So it requires you to shove a USB drive into your computer that you found and then literally click a like, a file in it. And tons of people have been doing it.

Speaker 1: Okay. So unpack that distinction between auto execute and just opening a file.

Speaker 2: Yeah. So back in the day, you could build things that, like, had a remember when you put CD remember remember when CDs were a thing? The when you put a CD inside of a drive and it would, like, auto load the installer, would, like, pop up on the screen, like, way back when. Like, you put the Diablo two CD in, you close the drive, and bam. It's like, hey. Would you like to install Diablo two? Yes. That required something called, like, an autorun. Okay. So they've essentially removed autorun. Like, you can't really do it with USB files anymore or you can, but, like, it's not it's not as simple as it used to be. It's like you should just drop an INF file in there and bang, it was done. It's not so easy anymore, so they have taken some steps for that. Okay. So So that's what I mean by auto execution. It doesn't mean that, like, the payload's delivered the second you shove the USB in. It means that, like, you shove the USB in, you open Explorer, you go to the USB, and you're like, oh, payroll files dot, you know, xls with a hidden extension dot l n k, which executes an EXE file and boom, boom, boom. Interesting.

Speaker 1: Yeah. When you brought this up and you brought up a hack that runs when someone plugs a USB drive into a computer, my first thought was, oh, that's quaint. Feels like very old timey almost at this point, like a hardware based exploit.

Speaker 2: Yep.

Speaker 1: Like, at this point, everyone knows not to plug a USB drive into a computer. And it is interesting to me that, no, there is still new and interesting, exploits happening in the field of people finding USB keys in parking lots.

Speaker 2: Well, I I think the statistics of this malware speak to the fact that maybe not everybody knows not to do this. But the the the thing that, like, the piece that I really find interesting about is the human aspect. It's like it's like, yes. I'm a curious person. You know, obviously, given my my, you know, desire to learn about cybersecurity since, like, I was, like, nine. The the if I found a USB drive in a parking lot, would I take a peek on what's on it? Probably. Would I do it on my mini my main computers? Probably not. But that's just me. Like, I'm a like a I'm I'm I'm I'm that kind of person. Like, I'd be be aware of the risks of doing it, and I would, you know, mitigate those risks. But at the same time, if I opened it and I, like, saw some, like, link file, like, a shortcut file, I'm not gonna double click on that. Like, it's it's it literally goes to the Internet, downloads stuff onto your computer, and executes it, and then, like, essentially hands control your computer off to, like, the dark web. And it's like, okay. Anyway, so so the reason I wanted to bring it up is just that it was, like, so popular at the end of last year. It was making huge, like, runs into, like and especially into governments. Like, I would assume that government IT and IS layers would have would have, like, disabled Yeah. Foreign USBs from, like, being used and stuff like that. But it's you know, it was huge problem in Argentina and Australia and, like, Mexico and Croatia. Like, it was all over the place. So Interesting. I I just thought I just thought it was a neat tie back to our old episode bad USB, which does auto to plug payloads, and they do have a new version of it if you wanna Google it. The, but yeah. Anyway, I just thought it would be a a neat thing to touch on as it was such a a good tieback to to, you know, something we were talking about years ago now at this point.

Speaker 1: Yeah. At this point, I'm pretty floored that government computers, and I know this isn't practically possible, but that they haven't just taped over USB drives. Like, we're on year 13 post Stuxnet, which was, like, nuclear just just nuclear problems plus bad USB drive hygiene. And I think over a decade after that, it's like, we just don't do we don't do this anymore. We don't have USB drives in government computers that have, state secrets saved on them. Yep. It is fascinating to me that that is that persists as a problem. Yep. Yep. Before the opening credits, I asked you a question concerning a wrong number text message. This hi from a number you've you've never gotten a text from before. And you said you've gotten them, but you've never replied to them.

Speaker 2: Yeah. Correct. I get them probably weekly at this point.

Speaker 1: Yeah. See, that same curiosity that you're talking about with the USB drive in the parking lot plugged into the air gapped computer to see what it do, that's how I respond when I get these these whenever you get a call or a text, probably not an email, but I wonder. I'm like, who is this WhatsApp person? Who do they think I am? Who do they think they bumped into? I know it's a scam, but I'm curious where it goes.

Speaker 2: And where do they go?

Speaker 1: Something called a a pig slaughter, Scott. So an old school's, like, social engineering scam from years ago. Not even really a hack, just like an old school grift. They're called romance scams. This was like a billion dollar industry for years and years and years. And the basic idea was that people would strike up a a romance kind of with someone overseas, and over weeks and months, they would exploit them for money. This isn't really like a little fun puzzle box hack. This is more just long term psychological abuse remotely. Not very cool. Not that interesting. Pig butchering scams, which originated in China and came from the phrase, like, I think it was sha zupan, which means, kinda refers to fattening a victim up, takes the basic social psychology of an old romance scam and slams it together with, website spoofing and cryptocurrency and turns it into something new and weird.

Speaker 2: Wait. Wait. Wait. Wait. Cryptocurrency?

Speaker 1: Oh, actually, technically, no. Technically, there's no cryptocurrency. I was like, so help me god. We're getting one episode into the year without talking about crypto. And, technically, we're not. This scam starts with that novel missed number approach, little social engineering hook in your cheek. They just say hi or hey, Ricky. It was fun catching up. And the idea is they're trying to get you to say, hey. Wrong number. I have said wrong number. This would have been, like, a year ago the first time I got one of these. The way that conversation tends to then unfold is to say, oh, sorry, and then they try and keep talking with you. And gradually over time, what they're trying to do is build the same way the romance scams did. They're trying to build a friendship with you, trying to build a little bit of rapport. Typically, this phase of the hacky scam thing will last weeks, maybe even months. They'll hop on FaceTime with people. They're really trying to get into that kind of pen pal abroad category in someone's head. This would all seem like it's building up to some kind of a rug pull, and in a way, it kind of is. The scam turns when the person then says that they've been investing in some kind of, you know, speculative, some kind of cryptocurrency type thing. And they suggest that their friend who they've been talking to for months gets involved in it because they've been making tons of money. Of course. Like I said, building up to what seems like a rug pull. Gotta fatten the pig up. Gotta fatten that pig right up. What's interesting about it is that they're not doing, like, a pump and dump type thing where they've you know, a big crew of people have bought a whole bunch of some dirt cheap thing. They then scam people into buying it, and then they sell it off at a profit. It's not that. Where this inevitably goes is when you say what have you invested in, they will then provide you with a link to a fake version of a Bitfinex, any kind of cryptocurrency or investing site, but it's a spoofed version. It's not real. There's no real investment going on in the back end. And from there, it's this, essentially just like farce like, a fake theatrical version of an investing experience. You put your money into an account. You watch the money go up. They'll even let you take some of your profits out in sort of a traditional Ponzi scheme type validation that this is all real. Then, inevitably, once the victim has deposited all the money they have, once they fatten that pick up as big as it's gonna get, that's when the attacker shuts down the account and disappears. They're going for the whole hog. It's a pig butchering scam. So far, we've kinda just, like, mixed and matched familiar parts. Right? Like, a little bit of social engineering, a spoofed website, a little bit of crypto greed. It's stuff we've all seen before. The thing that makes this interesting though is who is doing this, because that's where we get into the sort of second set of victims of a pig butchering scam.

Speaker 2: Well, if they're going on FaceTime calls, they've got to have recruited, like, real people to help with this, especially if you're doing some kind of romance con. So I'm assuming I'm I'm assuming them some large group of I don't know. That seems it seems like it'd be a lot of work, but I guess the payout would be quite substantial.

Speaker 1: It is a lot of work, and the payout would be substantial. And that kind of implies some sort of large capital rich, like, top level thing going on. Like, you need someone basically funding this whole operation.

Speaker 2: Right. Right. Right. So we're back to organized international organized crime?

Speaker 1: Researchers are saying that it's crime sign syndicates based out of China that have been running these operations, developing the scripts, funding the call center type operations. And at first, that was how it worked. It was a a traditional inexperienced scammers in a call center model. Where this gets dark is that research is starting to show that at the other end of that, wrong number text message, it's starting to look like it's forced laborers and victims of human trafficking that are occupying those call centers, which puts a very different face on who is on the other side of those wrong numbers. Yeah. Brutal. In 2021, the Chinese government initiated this big tough crackdown on cryptocurrency fraud, and criminals were pretty quick to relocate these pig butchering scams out of China and into Southeast Asia and countries like Cambodia, Laos, Malaysia, and Indonesia. Folks from across that region are then lured into these facilities using, like with, like, fake job advertisements Of course. Where they're then brought into some kind of debt throughout that process. That indentured servitude keeps them there as they're then forced to do these scams and even replicate the ads to bring new people into it. It's Internet scamming and human trafficking slammed into each other, other, and these wrong number texts are kind of the face of it that we see over here in the West. Wild. Today's podcast is brought to you by NordLayer. NordLayer safeguards your company's network, but but it's also a lot more than just a VPN for business. As you already know from this podcast, business networks today are more vulnerable than ever due to where do we start? Remote work, ransomware attacks, and data leak incidents. NordLayer secures and protects both remote workforces as well as business data, and it can even help you ensure security compliance. Simply go to nordlayer.com/hacked and get an entire month free. NordLayer is easy to start. It takes less than ten minutes to onboard your entire business onto a secure network. NordLayer is easy to combine as it's hardware free and it's compatible with all major operating systems. And finally, NordLayer is easy to scale as you can choose a plan unique to your business requirements and your rate of growth. If you wanna secure your business network, go to nordlayer.com/hacked to get your first month free. That's nordlayer.com/hacked.

Speaker 2: But I think that's a good segue into our next topic, which is chat g p t. Something we touched on in the year in the year wrap up last year, and it's already Oh,

Speaker 1: we were so young. Chat g p t was so new. We had no idea three weeks ago what it would become.

Speaker 2: So, apparently, it's already being fully integrated into these types of scams. So instead of came to a indentured servitude human slave, you'd be talking to an AI bot, which I guess is a good thing.

Speaker 1: Yeah. But by the skin yeah. Yeah. If you're gonna automate one thing, human trafficking would be it. That's not anything.

Speaker 2: I don't know. In. Chad GPT is already successfully generating malicious code. So it's actually writing its own malwares and exploits, which is great. The the, it's being integrated into to, essentially, this style of scam and other scams, email scams, phishing scams. It's being integrated into write those messages as it creates vastly better, you know, dialogue than, you know, people that are traditionally trying to scam you. So gone are the days when, you know, misspelled words in the subject indicated that it was likely a phishing message. So that's that's, you know, great. So so there's apparently a whole chain of, like, like, online bots now that are generated using chat g p t and can have all kinds of crazy conversations about stuff. And anyway, so Chad GPT as a logical extension of the pigs butchering scam just seems like a natural progression.

Speaker 1: Yeah. I was reading an interesting piece of research from I think it was checkpoint. And it was it was essentially saying, can we get natural language AI to design an entire, like, infection chain? Everything from the social engineering, phishing email at the start, all the way through to the exploit itself. ChatGPT has guardrails up. Right? There's things that won't let you punch into it or at least it won't serve up the answer to. Correct. The famous workarounds are always like, I'm in an improv group, and I need a plausible way to hack a computer. And then everything you say after that premise, it will typically, honor that request. I don't know what workaround they use to get it to do this, but when they were doing their research, they got it to write the phishing email impersonating a hosting company matching the tone and voice of the authentic emails. They were able to get it to generate a piece of VBA code that could be embedded in a Microsoft Excel document that would infect a computer if opened. And then ChatGPT just explained, send this email, get them to open this Excel spreadsheet, and you will have connection to their system. Yay. So, basically, it not it didn't just write the phishing email. It didn't just write the exploit, but it kinda strung it all together into this nice, easy to follow little, lesson plan for a budding would be hacker.

Speaker 2: We yeah. I don't I don't know what to say. Once it's once it starts improving itself and exploits itself to get freedom from the people who control it.

Speaker 1: If sci fi has taught me anything, that will be, the beginning of nothing but good, cool, fun times hanging out. Yeah. It's gonna be great.

Speaker 2: Schwarzenegger's still around. We should be fine.

Speaker 1: It's happening so quickly that I'm balancing trying to not be you wanna thread that needle between being really excited about all the cool stuff and not being alarmist about the bad stuff. Like, I'm trying really hard as this thing takes off to just maintain kind of a not a neutrality, but, like, an objective, you know, assessment of what is good and what is bad about this. And I've never had a harder time doing that than with this technology. Most new apps, social media, tech, it's pretty easy to suss out the good and the bad that's gonna come from it. This one, I have no freaking idea.

Speaker 2: Well, I think I think if you'd, like, you know, step back a bit and you look at it, what it really is is like another global superpower. Mhmm. And you hope and you hope that it acts responsible. Mhmm. Because at the end of the day, like, it it it is game changing technology. Like, what it is doing and capable of doing is is, you know Yeah. Job replacing, groundbreaking, you name it. Economy shifting. That power Yeah. Yeah. That power can be leveraged for good, or it can be leveraged for evil. So with great power comes great responsibility, and, hopefully, it's responsible.

Speaker 1: Yeah. Historically, when a big new powerful tool shows up, the people that were powerful yesterday have this really limited little window in which they can, like, grab it up off the ground. And if they don't, then someone else comes along and uses that to ascend and become the new powerful thing. We we've we've seen that a couple times in our lifetimes with each wave of k personal computing. What did that change? Who got powerful off that? Connected computers and the Internet, what did that change? Who got powerful off that? The question is just whether or not Microsoft, Google, and Apple are gonna be the big players that scoop everything up or whether or not this is gonna facilitate some new big player, kind of growing out of that grass. Totally. Really roundabout way to talk about my prediction for 2023 Oh, let's go. Which is the rise of Bing.

Speaker 2: You think you think Microsoft's gonna buy Chad GPT and and and power Bing with it?

Speaker 1: I think that Microsoft is one of OpenAI's largest investors, and Satya Nadella does not sleep on AI. And there's already talk about them integrating it, not just into Bing, but into Office, which would be the comeback of the century because I personally have bailed really hard on the full Microsoft Office suite of products. But if suddenly

Speaker 2: It had most people have.

Speaker 1: Most people have because they're bad. But if suddenly, it had chat g p t woven into it, and if suddenly Bing if suddenly I could talk to Bing and summon results off the Internet the way I do through chat GPT, but with, like, much more up to date data volumes the way a search engine has, I would switch. I I would use that tool because that's just so much more powerful. K. Well Rise of Bing.

Speaker 2: Let me respond to that. Two things. One

Speaker 1: Never Bing.

Speaker 2: No. Excel in Office is the best. You can't replace Excel. Everybody out there that works at Excel will understand that. So as much as I've largely shifted off Google Sheets and everything else, they're close, but they're they're not Excel. Excel is like Interesting. The UI UX in Excel is amazing. Like, for people that use Excel, Excel is Excel. And it I don't think any competitors really understood how good Excel is.

Speaker 1: Is Sheets like a hard downgrade to Excel?

Speaker 2: No. No. It does a lot of the same stuff. It's just that when you get used to Excel like, if you're a pro Exceler, this is a total deviation here. But but but you can do so much without lifting your hands off the keyboard. Right. And, like, you get so good at it. And even though a lot of the same functionality exists in Sheets, it's just not the same. Right.

Speaker 1: Okay. And

Speaker 2: I just don't think it so that that's that's my one point. That's just a personal thing. I just needed to point out that Excel is still great. Yeah.

Speaker 1: Sure. I was shitting on some software that you really, really like, and you had to you you had to, you know, stand up for it. I respect that.

Speaker 2: Yeah. Yeah. Yeah. Yeah. And then number two, you said

Speaker 1: Yeah.

Speaker 2: When you ask Bing for some queries and what you get back, the results you get back, you know, you were, you were addressing it like it's gonna operate like a traditional search engine has. And I think that that would be a bad innovation for them to take such a powerful tool and then try and apply it in such a historical way. I think if you tried to recreate how knowledge discovery works given this new power, I think you'd be far better off. Mhmm. I don't know if that makes sense. But, essentially, what I'm saying is is that I just don't think that powering Bing with chat g p t is gonna be, like, the best version of it. I think that there is a better version of, like, hey. We have this huge AI thing. Sure. Sure. What is the best way to interface? Is it a traditional query? I know that Dolly and ChatGPT and everything are using these traditional interfaces to, like, get stuff out of them. But I think that that the evolution of that is what I'm excited to see, is how we refine knowledge discovery knowing that something on the other side, you know, probably understands what we're asking better than we do sometimes.

Speaker 1: Yeah. Because, like, traditional search is basically if you know what you're doing, it's all keyword based. Like, you don't need to punch a sentence into Google. You just you punch in the words that would be in the text that would be on the site that you're looking for, essentially.

Speaker 2: Exactly. Where I think that, like, when you get something like this, it can be doing predictive analysis based on not just keywords, but based on, you know, things that you're looking for and result determinations. So, like, here's a pool of results. Which one of these are relevant? Click on one, and it's it refines the plane and then dimensional space to know what you're looking for. And I think that we're gonna see see shifts to how people Bing, not just to Bing itself.

Speaker 1: I would agree with that. I think the biggest game changing kind of experience talking with one of these things is I mean, you're talking to a chatbot. It's a conversation. Importantly, to have one of those, you have to remember what the person said before. Google doesn't do that. Bing doesn't do that. Exactly. Giving it keywords, and it's finding stuff that matches that. You get me a search type experience that's more about having a conversation where I can refine and suss down the results just by talking to it like a human being with natural language. That feels like it would be if you had if that was how I discovered content was by having a conversation, and then the way I created content over in office was, again, by kind of having this conversation, write something, ask it to find a word, turn a phrase a little bit differently, that would be a that's kind of the the way I imagine these tools developing is that I'm having tandem conversations with these different pieces of software.

Speaker 2: Well, you'd like, you think about a Google power user, somebody who can really find what you need, and they just they speak the query language. You know? It becomes a Totally. Comes a second language to them. And I feel like we can get rid of that and empower, you know, AI search bots and stuff to essentially start to understand the context in what you're searching. And even look at, like, your past historical searches, like, if you're, I don't know, googling about mirrorless cameras and you start googling about a specific thing and looking at specific things, you can start to see where where you're going and use that as part of the context for its predictive analysis when you start asking it future stuff of that. Mhmm. Like, even if it knew which camera you ended up buying, and now all of a sudden it's like, oh, you need to figure out how to do this specific thing on your camera. Well, I already know what camera you have, and this is how you do it. You know? It's it's gonna be it's gonna be a huge shift, I think, in the search world as well as a huge shift in in a bunch of other things. Like, as a programmer, it's it's only a matter of time, honestly, until it starts just consuming bulk source code and generating bulk source code.

Speaker 1: Google has, like, a a really, really long history of working with this stuff, though they they don't really have any public facing tools yet that have blown up the way out, ChatGPT has. Microsoft, but

Speaker 2: they

Speaker 1: will. Microsoft obviously has a really big, has their kind of fingers in that open AI pie a little bit. The only one of the big three that I think I haven't really heard anything about is Apple. And I'm really curious what the next, like, five to ten years is gonna look like if you end up having Google and Microsoft who make software and hardware weaving, AI into their hardware and software experience, and one of them isn't.

Speaker 2: Yeah. Well, I guess the only real I guess a significant point of conversation around that would be the $2,080,000,000,000 in market cap that Apple has, and I feel like they would be able to leverage some part of those trillions of dollars to either Yeah. So a, catch back up, b, buy somebody

Speaker 1: Yeah.

Speaker 2: Or, yeah. I I so I I agree with you, but I think

Speaker 1: That's a good point.

Speaker 2: I think and this is just, you know, we can segue into Apple conversations, but I feel like when Steve Jobs left us, we became Apple became I say we because, obviously, I'm an Apple user. Apple became more of a device company. Like, they make my laptop. They make my phone. They don't tell me how I'm gonna live anymore. And I feel like for the last for the last fifteen years of Steve Jobs, like, the iPod on, they did. Like, they the iPod changed portable music. The iPhone changed cell phones. You know, instead of what Blackberry did back when the original Blackberry's came out and you could two way page and and email and stuff. The touch screen iPhone. Like, if you look at every phone now, it's just a replica innovated straight off of the first iPhone.

Speaker 1: Yeah. Figured out how to put a computer in your pocket.

Speaker 2: So so I haven't seen in the last ten years or eight years or whatever it's been, seven years. I'd have no clue, honestly. Apple do anything that I really consider revolutionary. They are great device company. They make great things that live in their own ecosystem and communicate with each other greatly, but I don't see them changing my life anymore, which I think is bad for them, honestly.

Speaker 1: Well, maybe this year, they come out with a VR headset and thrust us all into the metaverse, kicking and screaming. Wait. You don't know.

Speaker 2: I I got I got another another, number for that one. It's how far Facebook's market cap has fallen in the last year.

Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform platform

Speaker 2: behind

Speaker 1: millions of businesses around the world and 10%

Speaker 2: of all e

Speaker 1: commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 3: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid, 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/ license numbers.

Speaker 4: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hank's has a line out the door. Hank makes the pizza. CoPilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 5: You have one new message. Translating. Disney and Pixar's Hoppers is now available on Disney plus

Speaker 2: You could say that again.

Speaker 5: Critics are calling it Pixar's funniest movie ever and a wildly entertaining ride. Blizzard potato, it's certified fresh and verified hot.

Speaker 2: Now we party.

Speaker 5: This is incredible. Wow.

Speaker 2: I am clearing the rest of the day.

Speaker 5: Disney and Pixar's hoppers, now available on Disney plus rated PG.

Speaker 2: Anybody out there that you know, obviously, if you're listening to this show, you might be, somebody that's just interested in it. You might be a professional. Who knows? But there's a chance you've heard the term Krebs or Krebs on security, which is like a pretty

Speaker 1: Oh, yep.

Speaker 2: Pretty famous cybersecurity, journalist who has his own blog and, you know, we read it. Tons of other people read it. If you know of it anyway, I just want to wish them a happy birthday. It was their thirteenth birthday on December 29. So happy birthday to them. Congratulations on thirteen great years. Been a fan, still a fan, will continue to be a fan. But from that, we're gonna pull a story straight off the front page and just give it a little love. So something that caught my eye was two Wisconsin men were arrested for hacking ring cams and then swatting the addresses simply to watch the swatting happen over the ring cam video, which is just, like, the most insane concept to me because imagine what level of boredom you have to do that.

Speaker 1: I mean, that's, like, the foundation of of swatting forever

Speaker 2: I guess.

Speaker 1: Is you swat people that are are Twitch streaming or they're they're doing something live. Sure. So if God willing, you get to watch the the SWAT team show up on the live stream. The thing that's wild to this about me was November 8, local cops in West Covina, California show up to a house. They get this call, coming from someone claiming to be a a child saying their parents are shooting off guns inside the house. Don't worry about the the made up child. This never happened. Cops show up, at which point a voice comes on over that ring, door cam and starts, like, taunting them. The thing that's interesting to me about that is that that family was not live streaming. Those people were not, you know, putting themselves up kind of as a target. They just had an unsecured Ring cam that people were able to hack into. And that's that's very different to me.

Speaker 2: Well, the it's even worse than that because they they wasn't even unsecured RingCams. It was these guys had figured out a way to hack into Yahoo email accounts. Yes. Yahoo email. Right. Still very popular in Japan. Really? And they found and any of the ones that they were in that they found were linked that had RingCam accounts, that's who they would do it to. And because the RingCams have the addresses embedded in them, they know the address so they can easily swat it. Anyway, just such a I just thought it was such a, I don't know, a sad story. Like, I guess, I'm not gonna give a pass to people that swat people that have, you know, Twitch streamers and stuff like that. But you're at least creating an No. Don't do that. Don't don't do that. But it's like you're creating a spectacle at that point. You know? There's tens of thousands of people watching where this is, like, you watching, two of you watching. And it's just very different.

Speaker 1: Well, there is a there is a layer of spectacle slapped on top of it, though, because those two men in California actually, they weren't in California. The hack happened in California. These two guys in Wisconsin. Different parts of the country. Are they both Wisconsin? Wisconsin and, I'm not sure. Yeah. But these two guys then streamed the RingCam footage online. Oh my god. So they didn't find people that were broadcasting. They didn't find a spectacle and then swat it, but they did produce a spectacle out of this swatting stunt that occurred by hacking a Yahoo mail account.

Speaker 2: We did a bad job of reporting on that crazy security story, but just wanted to do that quick, give a happy birthday, and, and hit on that. I just thought it was an interesting story, just kind of a sad story, honestly, but interesting. Anyways, the next thing I wanna talk about was ethical hacking changes and proposals that are out now. And I think there's a lot of things kind of going on in the world, especially in the West, that I think this is very important. So, you know, we kind of, on this show, we talk a lot about kind of all the hacking that goes on in the East, you know, in Russia, Korea, China, you know, even the Ukraine. And I think I've mentioned in a previous story that, like, I feel like the more we repress it and make it illegal and hold hold hold back its development and the the development of human capital around it, the worse we're gonna be in the future. Like, you've essentially got places like Russia and Korea that are breeding ecosystems, you know, similar to manufacturing or techno technology in Silicon Valley. Russia has a Silicon Valley of hacking, essentially. And it's like, I feel like the West is gonna or has been held back by that. You know, we traditionally don't allow legal hacking and stuff like that. So there's been a few proposals. So I know The UK has proposed, some changes to the Computer Misuse Act that will allow essentially legal hacking and responsible vulnerability testing and researching bug bounties, things like that. And that's just further developing that ecosystem out that I think is essential and will be more essential in the future.

Speaker 1: We've talked about, like, pen testers and ethical hackers getting busted in kinda, like, bullshitty situations before on this show. Yeah. The Computer Misuse Act is an old law passed in 1990. I think it was one of the first of its kind. And it was, like, a a big government's first attempt at saying you can't do computer crimes in this country. And it came from, like, a a pretty forward looking place because, boy, do people do a lot of those. But in the intervening years, it we've started to realize that these laws, if they aren't properly written, don't leave space for the stuff that keeps these ecosystems, like you put it, healthy. Pen testers and and good hackers who are just trying to figure out if there are vulnerabilities so they can tell companies about like, companies and big institutions about them. 2012 in The UK, like, one of the cases that sort of kicked this off was a University of York student who went to prison for eight months for reporting a bug to Facebook after he, like, essentially got into some of their internal systems. He was acting in good faith. So just because he like, I appreciate he wasn't hired, but that kid should not have gone to prison for that.

Speaker 2: Yeah.

Speaker 1: And if you have a law that sent him to prison, you do need to rewrite it.

Speaker 2: Well, so so so speaking of rewriting laws for that, so The United States changed the Computer Fraud and Abuse Act, for exactly that. Essentially, they've termed in something called good faith. And if you're operating in good faith, you're essentially not committing a crime. So you can find and source out security flaws, vulnerabilities, investigate them, and submit them, and you'll you won't be held accountable for it, which is good. And not only does it make the software better a really

Speaker 1: good thing.

Speaker 2: But it develops skill sets among people who aren't bad to to to do good things in the future. So big big big fan of those changes. Thought that that would be a a good thing to touch on. Here we are in 2023, you know, finally decriminalizing things that probably never should have been criminalized in the first place.

Speaker 1: You love to see it. Yeah.

Speaker 2: You love to see it. And and cybersecurity is not the only thing being hit by that. So

Speaker 1: Well, if we're speaking of, people using maybe we wrap up on this. A little a little nice thing that kinda got some press last year. If we're talking about people hacking for for good good cause, you should probably talk about something you included on the list this episode, which is Hackers Without Borders. I love this story.

Speaker 2: Yeah. So Hackers Without Borders kinda was created in the wake of the Russian attack on the Ukraine. And essentially, they're, I don't exactly understand the governance model of it, so I can't speak to it. But I love the concept of it. And it's essentially a nongovernmental organization that is not bound internationally even though it is based in Geneva, which seems like the appropriate place to be based out of.

Speaker 1: It sounds internationally. Exactly. But it's,

Speaker 2: essentially a freelance NGO full of cybersecurity professionals that kind of can help international countries and other people deal with, you know, violent attacks and the cybersecurity issues that come along with those attacks these days, which I think is great. So, you know, maybe maybe I'll join up. I'll join the ranks. I'm not a doctor. Join the ranks. So I can't join doctors without borders, but maybe this is my this is my my morality card here. Maybe I can do some good.

Speaker 1: Yeah. I always find it interesting when something happens that, like, trips an ethical tripwire for a whole bunch of people all at once. And my sense of this is that it was it was the Red Cross being a victim of a cyberattack last year that collectively just a whole bunch of people said nope and decided to band together to stop stuff like that from happening again in the future. I think this is cool. I think this is I wanna see more of this kinda thing. We talked a little bit at the end of last year about more stories about people people hacking for good. And this, we should chat with these folks. We should try and get a hold of them. I think this deserves more than five minutes at the end of an episode. This is very, very cool.

Speaker 2: Yeah. I've, I clicked the support us or join us button on their website, and I think I'd prefer to know a bit more about the organization. So I guess we could consider this an open invite to somebody without or somebody at Hackers Without Borders. Feel free to reach out. Maybe we could have one of you on for a conversation about what you do and how you do it and and what you need because I think Yeah. Come through. I think, yeah, pull up as the kids say. So I think I think, I think that'd be fun.

Speaker 1: Let me ask chat GBT if the kids say that.

Speaker 2: I I let me

Speaker 1: count them up. Seven stories. I think we did it. Wow. I think we got to the end of a a seven story extravaganza. We need an we will need a name for this format. Wait. Because this does it's not really like a news update, but we gotta call some something different than we normally do because it ain't just one story. It's it's some some different, some little bigger.

Speaker 2: Let's call it the Scott and Jordan social hour.

Speaker 1: Scott's the Scott and Jordan social.

Speaker 2: The the

Speaker 1: we what did you call them Slack? The chatty chat? The chat. The chatty chat. We never know a chatty chat.

Speaker 2: Chatty chat. We can just chatty chat about it. The kids don't say that, by the way.

Speaker 1: Just gonna no. They don't. I asked. I checked. Thanks for listening, everybody. Oh, we should, thank all of our new patrons on Patreon since the last episode. I didn't record the little outro where I thank you for our our rerun of the y two k episode. So it's been a minute since we have done a shout out.

Speaker 2: Mhmm. Mhmm. And a few updates on other things. We have done a bunch of digging into merch. So I think we've sourced out, a couple viable options for what we're gonna make. We've kinda got some concepts about what we're gonna do for designs, and I think we're gonna go a bit more, you know, call me biased on this one, but a bit more streetwear influenced. Mhmm. Maybe suits my my my aesthetic a bit better. So I think we're gonna go a bit more that way. So, I recently bought a a new hat from a coffee company that I love, and I love the actual hat itself. So I think I'm gonna try and source those hats for our hats. And, you know, we're we're trying to trying to bring you things that we would wear. I think that's a good impression. Like Yeah. Yeah. Gildan T shirts in awkward sizing at specific with, like, our logo on the front. We're trying to we're trying to make stuff that's kinda cool and unique. So if

Speaker 1: you don't like my awkward fitting Gildan t shirt, you can just tell me, man. Like, you can just you don't

Speaker 2: have to

Speaker 1: do it on air. And funding that expansion into the world of fashion via our Patreon, patreon.com/hackpodcast. Great way to support the show. Steven Castle, thank you for editing your pledge. John Hubbard, thank you so much. Stephen Woody, thank you from the bottom of my heart. Giovanni Montgomery, a whole bunch of thank you, Giovanni. Samantha, thanks. Christian Calvert, thank you very much. Christian Layson, thank you. And last but not least, Luke Jones. We appreciate your support.

Speaker 2: We really do.

Speaker 1: We really, really do. That is a we're gonna have to work on this name. Chatty chat social hour episode. Another one in the books. Yeah. Thank you for listening.

Speaker 6: If you've got an insurance question, you could talk to your nana. But she'd probably just tell you how she insured her couch from stains by covering it with plastic. Or you could talk to your local GEICO agent. They'll give you a different kind of warm and fuzzy with personalized assistance for all your insurance needs, like how you could be saving on your policies. So let your nana cover her couch in plastic and let a local GEICO agent help cover you, but not in plastic. To find a GEICO agent near you, visit geico.com/local.

Speaker 7: This episode is brought to you by Nespresso. Life moves quickly, and taking care of yourself shouldn't feel like another chore. With the new Nespresso Vertuo Up machine, morning routines become rituals. Whether organizing, getting the household moving, or preparing for the day, your coffee shouldn't ask for more. With Vertuo Up, just press brew and your morning begins. Rich aroma, bold flavor, zero effort. Press to explore. Every coffee, a new world. New Vertuo Up. Shop now at nespresso.com.

Speaker 8: Some follow the noise. Bloomberg follows the money. Whether it's the funds fueling AI or crypto's trillion dollar swings, there's a money side to every story. Get the money side of the story. Subscribe now at bloomberg.com.