Hotline Hacked Vol. 8
TL;DRA caller reveals how weak default passwords (8 digits only) on a major Australian ISP's modems let him crack Wi-Fi anywhere using deauth attacks and Hashcat. A second caller describes spamming a Canadian grocery loyalty points system to…
Let's get festive with it. Calls concerning grocery point systems, Australian internet providers, and so much more. Want to share your story? Check out hotlinehacked.com.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession. Act of the b.
Speaker 2: Good day,
Speaker 3: guys. Just calling up from Australia. I wanted to say I really love your show. You're doing a fantastic job. It's been absolutely awesome listening to you guys tell all sorts of amazing stories over the past few years, so thank you for everything you've done. I was listening to a story from a a guy in Brisbane, which is a bit north of where I am in Sydney, And he was telling, you know, default credentials, story, the kind of standard stuff that you would hear, the standard kind of hack. And I thought, well, I wish I had a story to tell, but I don't like, I'm a pretty rubbish hacker. I don't really have any story I can tell, and this is probably the part where I should say that you should obfuscate my voice if you don't mind. So for the past three years or so, I've been getting free Internet anywhere in Australia. So I kinda stumbled upon this hack, and I I reckon it must be known in hacking communities in Australia, but I haven't I haven't heard anyone talk about it. So I'm sure I'm not the first to realize this, but it's this pretty cool thing that I found where there's this huge Internet provider here, probably the most popular one, and you can beat the name if you have to. It's, so when you sign up with a plan using this Internet provider, they ship you out a modem, and the modem has a default SSID, c network name, and a default password. Now the default network ID is Wi Fi dash and then four hexadecimal values, and the default password is always eight numbers. So it's not you know, there's no characters. There's no symbols. There's no uppercase, lowercase. It's just eight numbers every time. So I think, you know, originally, maybe three years ago, that was considered perhaps secure enough. But, what I found was you could capture a handshake either through just sniffing or through, deauth attack. Once you have that handshake, which you probably wanna stop the podcast and explain it because I'm sure you'll do a much better job than I will. Once you have that handshake, you can convert it to a format that, Hashcat will read. And Hashcat's this awesome program that uses a computer's GPU to compare hashed passwords with the hash that you've captured very, very quickly. So you can
Speaker 4: go through a million passwords in a couple
Speaker 3: of minutes. It's it's amazing stuff. So the the results is that anywhere you go in Australia, you'll you can do a Wi Fi scan and also yeah. Basically, open a Wi Fi scan and you'll see that there's Wi Fi dash four hexadecimal values in your vehicle. That's a default, SSID for I'm sure they're probably using a default password. Right? So, you can run capture the handshake from that SSID, run Hashcat, and in about two and a half minutes, you'll have free Internet anywhere in Australia. So, yeah, it's it's been awesome. It's been really, really good. And the funny thing is, like, I I thought I don't have a story, and then I thought, oh, this is this is something that's pretty good. Maybe this will fit the criteria. And I went to look up your number, and I passed, like, five legitimate methods to report this to the organizations I should be reporting this to. But instead, I'm telling you the story. So I hope you enjoy it, and, thanks again for everything you guys have done.
Speaker 5: Well, thank you for your kind words and taking the time to send us your story.
Speaker 6: As opposed to the five legitimate organizations that you could have reported it to along the way, you went straight to the source, hotlinehack.com. It it well, it's a call in show where you can share your strange tale of technology true hacker computer confession, including how you get free Internet. This reminds me of, like, a first episode we did or or maybe even before we ever recorded you just explaining, all the different machinations of free Internet you'd come up with over the years, Scott.
Speaker 5: Yes. We did talk about this. We have talked about this. But right now, I wanna talk about our sponsor, DeleteMe
Speaker 4: Yep.
Speaker 5: Who brings us Hotline Hacked. And without them, we wouldn't have these episodes coming out every month. So thank you. Delete me. We will talk about them a bit in the future, but right now, let's get back to the story. Yes. So we talked about this during the flipper zero thing because the flipper zero is especially good at d auth attacks and and sniffing a handshake. So you can literally get modules and things that attach to it for Wi Fi access. Sasquatch, I think, him and some of the other creators have these, like, beautiful big LED LED screen attachments that go into the GPIO pins that are specially built for mass d auth and recording handshakes to then put through hashcat and and and pull it out. So
Speaker 6: this
Speaker 5: is awesome. I I love that you've identified such an infrastructural issue in a massive ISP. And because they are so prevalent, you just have access wherever you wanna go.
Speaker 6: So for anyone that doesn't know, there's a couple different, like, ingredients to this little thing, the caller is cooked up. First one is a Wi Fi d auth attack for anyone that doesn't know kinda what what is that.
Speaker 5: Sure. So, essentially, you're sending d auth packets at the Wi Fi router, which is then causing essentially it to terminate connections with things. So you're essentially punting things off the Internet. So think about it like that. You're essentially just kicking kicking a device off of the Internet. So you spoof the MAC address of that device, and then you essentially tell the wireless access point that, like, you don't wanna be connected to it anymore. So it deauthorizes you. It just punts you. Interesting. And and then the real one tries to reconnect because it's just been punted, and that is the handshake that he's recording if that makes sense.
Speaker 6: Which he's recording is it the thing that he's recording is hashed, and so he's then using this hashcat tool in order to figure out what the password is based on that.
Speaker 5: Yeah. Yeah. Yeah. So, like, hashcat is just essentially a big, like, password brute force. So it just it's it's custom written to use, like, high performance GPU, like, your NVIDIA graphics cards and stuff to to be able to process faster data. So often, there'll be, like, a dictionary attack. Like, we talked about this in problems with passwords
Speaker 6: I remember this.
Speaker 5: Where it's, like, you have a hash by the time you, like, kind of parse the handshake, you you essentially get an encrypted version of the password, and then you can, like, essentially, like, brute force it with dictionaries or random, randomly generated, you know, hashes.
Speaker 6: And he's able to do this because as he mentioned, the password is always just eight numbers for this large Australian ISP and importantly no characters. So that makes it a lot easier for you to just brute force guess, because you're not it's it's a smaller set of things. It's just numbers you're working with here.
Speaker 5: Yeah. That that the dictionary file like I could write a Python script to generate actually sorry chat gpt could write a Python script to generate that dictionary.
Speaker 6: I don't write things anymore. Thank you very much. I have a robot that does that for me.
Speaker 5: Yeah. Exactly. So so ChatGPT could write build you a script that would generate a dictionary file of just one of those combinations per line, and it would generate that in in moments. And then you'd just be able to use that as the as the dictionary for the the brute force. If you knew it was eight digits, that's an easy easy easy win.
Speaker 6: And I guess because it's standardized, you do. I like how this started with I'm a pretty rubbish hacker and then proceeded to explain something that doesn't strike me as rubbish at all. It's like I think you cracked this thing wide open their collar.
Speaker 5: I just I just think it's like this is this is like how do I say this? It's like a it's like a functional hack.
Speaker 2: Yeah.
Speaker 5: It's like this person is saving like, I don't know what your Internet bill is, but my Internet bill is like
Speaker 3: Yeah. Yeah.
Speaker 5: $131,400 dollars a year for my home Internet. This person's saved, like, $5,000 by just being, like, these are all over my neighborhood. Or if you're living in
Speaker 2: an
Speaker 5: apartment or condo building, you go to a cafe. Like, if they are such a prevalent ISP, the they'd be everywhere. It would take you a few moments to to, like, run your dias script, like, read the read the, the handshake, parse it, brute force it, and then boom, you're in online.
Speaker 6: Yeah. I guess I I was thinking of this. I wasn't thinking of them as being able to do this at home. I was thinking of it as, like, oh, you're on the go and you wanna connect to something? Here you go. But I guess you could just, like, live by the sword, die by the sword, and just use this hacked Internet all the time.
Speaker 5: Well, if if, like, when I'm in our office and I run, like, a Wi Fi scanner to see what's available, there's literally I did it yesterday. There are 360 wireless networks within range of
Speaker 2: Right.
Speaker 5: Of my desk. So it's like and a boatload of them are one of our prevalent ISPs, and I can see that. So it's like if I knew how to get into any of those, I just pick the one that has the highest, you know, connection value, and I'd brute force it and jump on it.
Speaker 6: When I was a teenager and I first got my own computer, not the, like, family computer sitting on the desk, but I I got a laptop, and it had Wi Fi. But our house did not have Wi Fi because why would we need Wi Fi? We have one computer and it's plugged into the wall. There's a good year and a half where I was just connecting to a password free Wi Fi connection for my neighbors, which I haven't thought about in a really long time. Significantly less technically sophisticated than this.
Speaker 5: Well, when Wi Fi came out, it was like the wild west. Like Yeah. They got it got installed every it like, it wasn't just that you had free access to people's Wi Fi. It was that all the Wi Fi routers, nobody ever changed them from default admin passwords. So you could literally download, like, a a Reddit like, it would be a Reddit post at this point. Right. But, like, back then, it was, like, something that we could share in, like, a BBS or a news group or something. And it would just be every model of wireless and network router, it's admin credentials by default. And you you say you could literally just war drive around a neighborhood.
Speaker 6: War drive?
Speaker 5: Yeah. Connect connect to, connect to, I got every house's wireless network, log in to their router, change permissions, do whatever you wanted, and then just go to their neighbors and do the same thing. It was it was literally the wild west.
Speaker 6: I we've managed to make, like, a 115 of these things, and I've never heard the term war driving. And it is literally what you're describing, the act of searching for Wi Fi wireless networks as well as cell towers, usually from a moving vehicle. The thing that popped into my head was in Mad Max Fury Road where they have
Speaker 5: the
Speaker 6: cars with the guys on the poles. That's
Speaker 5: pretty much the same thing. Well, I
Speaker 6: I bet it was.
Speaker 5: Same thing.
Speaker 6: Yeah. You have like a pole pole.
Speaker 5: Bunch of teenage nerds sitting in, like, a beat up old car driving around with laptops on their on their on their on their laps.
Speaker 6: Yeah. There's a war boy shredding on the electric guitar as you try and, like, connect to Wi Fi networks you shouldn't have.
Speaker 5: Yeah. No. I think there was more like a Wu Tang CD in the, the the, like, you know, aftermarket CD player. The, It was pretty good. I think you have heard the term war drive. I'm pretty sure talking Sasquatch and I talked about war driving because that's essentially what they've built now for the flipper zeros.
Speaker 6: Got it.
Speaker 5: It's like these these, like, massive antenna arrays with screens, and, like, they're all set up to do, like, the MAC address cloning and the thing and all the rest of it. So it's like they're pretty much built for these things.
Speaker 6: There was a comment on that episode because it got a bit more technical where someone said, like, I understood two thirds of this, and I had a really fun time. And I also understood about two thirds of it and had a really, really fun time. So that might have been what was going on there. It was also apparently in War Games with, with Matthew Broderick.
Speaker 5: So, yeah,
Speaker 6: there's some lore here that I need to my I need to brief myself on.
Speaker 5: Oh, I might have to give you a book list for Christmas. Maybe I'll just Amazon you some stuff, like, some old school hacking books.
Speaker 6: I could probably just, like do a little book club. That's that's fun. Little twenty twenty five book club.
Speaker 5: Oh, you know what we should do is we should do, like, the hacked archive. We should buy hacked. Archive and set up, like, find all of the old zines because it used to be that, like, the hacking subculture, like like, there was a few key zines for, like, like, freaking and, like, 2600. And, like, you used to buy these little tiny, you know, 18 page, you know, loose leaf paper with a staple through it. Talking zines, man. Yeah. Yeah. You'd buy the chapters for, like, three dollars because it was the only place that brought it in from wherever it was from. And we should find all of those, scan them in, and, like, archive them because, like, that's that's, like, history for, like, you know, my subculture, I guess.
Speaker 6: So some someone must have done it. If not, then we should get on it. So the other thing I like about this call, and it maybe transitions us into the next call, is the holiday season episode. We wanna give things back to, you know, we we wanna give some gifts under the tree. So so far, our Australian listeners have a nice little present for how to get free WiFi.
Speaker 5: Mhmm.
Speaker 6: This next one is for our Canadian listeners.
Speaker 3: Oh.
Speaker 4: Jordan, Scott, feel free to ask me to rerecord this. I don't think I need to, mask my voice, but I'll just go ahead and start telling the story. So so I think when I use Canadian, see my friend is interesting for the wild. Correction.
Speaker 5: We're both Canadian.
Speaker 6: We're both Canadian. And now we're gonna sing the full national anthem in its entirety in a three two.
Speaker 4: There was, a large grocer, that had a point program. I think they still do. And, you could submit online, complaints of missing points, and these points would equate to $10, increments. So, originally, and I think the most wrong thing, for lack of a better term, was you could spam the, site overnight with, like, let's say, script or whatever. It didn't have any, image thing or whatever, to you know, for a human. So it was pretty
Speaker 5: A CAPTCHA. He's talking about CAPTCHA. Didn't have a CAPTCHA to make sure you weren't submitting multiple posts.
Speaker 6: So you're just spamming this thing like I lost I didn't get points for my brownies. I didn't get points for my rotisserie chicken I bought yesterday. I didn't get points for my Sunny d. Gimme gimme gimme.
Speaker 5: Sunny d. Do you not drink Sunny d, do you?
Speaker 6: I am a man in my mid thirties. I would die if I drink Sunny d.
Speaker 4: And you could wake up with, you know, $500, of value worth of points that you could spend. And you could go spend them online or you could go to the store and use them. So, you know, I would go and order something online just to my place. Wouldn't even care. And so, like, socks and, you know, groceries, but you can only get so many groceries because they'll go bad. And and then, and the reason what you'd see in your email would be, like, a whole bunch of rejected ones, but every once in a while, you'd get someone like Judy just, like, approved, and it would be, like, a $50 grab. So maybe, like, out of, like, 50, maybe one would go and that if one that one was $50 and you get $50. You know, I tried various different amounts, I think.
Speaker 5: So, really, what you're doing is you're writing a script to submit claims, hoping that there's someone lazy enough that they've written a script to approve claims on the other side.
Speaker 6: And this fucking slacker Judy over here has just proven these things left, right, and center. I see your hustle.
Speaker 5: I I respect it. Yeah.
Speaker 2: I think
Speaker 4: it was actually 49, 100 points or whatever. Yeah. Though that would be the max I'd ever get, but I had better luck with doing 20 or something. But just submitting request and then eventually, you know, you submit enough request, all they get denied, and then you build up an account with this much. Well, that that worked for a while. And then, eventually, it implemented some sort of thing where, like, the human they they either put the humans on humans on the system or or automated it. So, everything was rejected, and a human had to, like, take a better look at it, and they couldn't just do pass. But the thing is what they changed it to was if it was under or if it was $10, and you had spent $10 on that, loyalty account, then they would automatically give it to you. No questions asked every time a 100% of the time. And then anything over, they would send it to a human to review, and it would get always rejected. Whereas before, it would sometimes go through. So that that's the two different kind of phases of this, and then that first phase didn't last that long. I mean, that was actually better, with the, you know, getting an account worth $500, overnight. But then it it limited to, like, the most you could get on one account was $10. So, like, I mean, most people, I think, would have stopped there, but
Speaker 6: Panami. Panami. Not this guy.
Speaker 4: Me having lots of free time on my hands. I, figured out that, you know, you how you can create, you know, multiple accounts, the same thing. There's no, image thing to make multiple accounts. And it would also, you know, allow you to do the the Gmail thing where you go plus zero one, plus zero two, plus zero three on your loyalty account name to be able to use the same, Gmail account. Not that that's a huge plus, but it just makes it easier for, making multiple accounts. And then, so the the thing is with the so you could normally just do the $10, and, you know, so you have to spend $10 on the account, and then you would get $10 for free, so it'd be, like, 50% off. And there's little stipulations where, like, you couldn't put it towards tax. So, like, if if you were buying something that had tax on it in Canada, I think it's a, like, if it's a certain type of food, then there's no tax on it. So then you try and, like, find combinations of, like, okay. I'm gonna buy bananas. I'm gonna buy whatever, and it's gonna total up to, like, $10 on 1¢, then you'd pay 1¢. So as long as it's over $10, you would get $10 taken off, not including tax. And I think, I I guess I'll tell you. So the tax could be, like, 50¢ in the in the province I was in at the time. I no longer live in Canada. And
Speaker 5: I know what province you live in based on how much tax you're paying.
Speaker 4: And so, most people would solve it there, 50% off. But what you could also do then to take it a step further was you could create, you know, another account, and and there was a way of linking the two accounts together. So you could spend the $10 on the new account from the old account that claimed the $10 of missing points.
Speaker 5: So you're making an account. Mhmm. You're probably spending 10 initial dollars. You're then getting a refund on the points for the $10 or $10 worth of points refunds.
Speaker 4: Exactly.
Speaker 5: Then you're moving those to a new account and then spending them and then making a claim and then moving it to a new account and doing this over and over, I imagine, is where we're about to get to.
Speaker 4: It would it would allow you to to site start cycling these accounts because it it bypass the rule of you have to spend $10 of new money on an account to be able to claim $10 of free points, that you could spend as $10 at the store. So so it allowed you to chain these accounts together.
Speaker 5: So, really, he found the actual unlimited money glitch.
Speaker 6: Yeah. It it seems like a well, we'll get to this at the end, but I think exactly that. He there was a a $10 criteria for this that basically minimized the discount he was getting to just to just that, a 50% discount, and he found a way to chain these accounts together to get around that, that So
Speaker 5: as long as you only want money in $10 lots, you could probably get as many as you were willing to create, an actual unlimited money glitch.
Speaker 6: For Canadian groceries.
Speaker 5: It's not bank fraud, but it's loyalty fraud.
Speaker 4: Then you just make another new account. You'd link it to the, account that you had just claimed the $10 on, spend it on the new account, then the new account would look like you had spent $10 on it. You'd break the connection, spend the money, spend the free $10, claim the $10 of free. So I I would just do this. I would I I wasn't working at the time, and, and I had lost a vehicle because I was
Speaker 5: Tell me how much money you stole.
Speaker 6: I wasn't working at the time. Yeah. You were.
Speaker 4: I had a company vehicle or whatever. And, so I only had a bicycle, so I'd bicycle to these, these stores. And they there'd be multiple places in Canada where you could spend these these points. And, I would just go ahead and I made a rule where I could only, spend $210 at a time, per store every two hours because I thought if if I if any more than that, it would just
Speaker 5: This was a job. This man biked around the city going to what I'm assuming is Shoppers Drug Mart at this point.
Speaker 6: Developing theories about which one of our many fine Canadian food monopolies he was doing this to. But, yeah, this is a basically a full time job.
Speaker 5: And he was spending $20 every two hours at each location. This is a job. This may
Speaker 6: It's so ambitious. It's so ambitious and so constrained at the same time. Yeah.
Speaker 4: Be greedy or something. I don't know. And, and I'm sure these people in the store, like, could recognize me. Okay. Why is this guy coming in and buying, like, a nightlight that's worth $10, you know, every every two hours or whatever? But I I would try and actually space it out so, like, it was a different
Speaker 5: So wait. He's he's sorry. I should do that. I'm not gonna say are you buying nightlights?
Speaker 2: He's just in
Speaker 6: it for the love of the game, Scott. I'm I'm honestly fully here for this. I think this is fantastic.
Speaker 5: For sure he was gonna be like, I was picking up groceries, you know, I was dropping stuff off at the food bank. Now, I'm buying night lights, just like spending the points, playing the game.
Speaker 6: Nothing conspicuous. You know, keep it under that that, that limit.
Speaker 4: Shift of the people there. But, I mean, if you're still doing it every day, I mean, at the same time, I don't think they really care care because they're making, you know, a little bit over minimum wage. I mean, they don't have time to even if they do report it, the guy above them probably doesn't care, and it just drops. So and then and, you know, you could send the codes to people too, for them to spend the $10 and then add a little kinda system where it would automate and okay. Now break the account. You know, make the next account, and you could all be automated. And then, I don't know if I should tell you the amount it got up to in a year, but one one year, it was just me personally. It was just under, wasn't too crazy. It was $99,960 Canadian, in one year, me personally, which means I did nine hundred and nine hundred and ninety six transactions, in a year.
Speaker 5: That's a lot of night lights. Let's do the rules. The, and just just for context, you should know that Canadians hate our grocery monopolies. Wow. As as given that Canada's population is so small, we actually are just ruled by oligarchies and monopolies. Oligopolies is actually the word I was going for there. And we have very few choices among self providers, Internet providers, grocery stores, etcetera. And we feel that pain pretty much constantly.
Speaker 6: Yeah. So this is a this is a real Robin Hood moment for us here north of the border. Some guy on a bicycle ripping around doing 996 transactions in a calendar year just to grift them out of a night later too. I am I am about this.
Speaker 4: Which I guess isn't that much. I mean, I I I didn't do it the full year, but it would there was a period of time in the months that, where I was, like, intent where I that's all I did. And I would just build up ridiculous amounts of, you know, toothbrushes and stuff because, eventually, you don't have anything to really buy anymore. And, like, when that when you're gonna give my dad, like, a bunch of tooth toothpick like, a lifetime supply of the tooth toothpick things. And, yeah, just to this day, I still have buckets full of, just random stuff, hygiene stuff primarily now, but, just soap and, like, a
Speaker 5: Your local homeless shelters will love to have that stuff. So if you have buckets of it and you find no use for it, please donate it because they're always calling for hygiene products at shelters.
Speaker 6: You might be able to do a little bit of wealth redistribution here if you play your cards right and just get the system auto shipping the hygiene products directly to the charitable organization. And you you might be on to something here, Fred.
Speaker 4: Times supply of soap and Dove soap. And just yeah. It was it was a good good go, and I I think you could probably still do it to this day. At the end, I think what what I where I stopped well, I moved away from Canada, but, also, they there was some interaction with, like, the I was using a, a specific VPN provider, and I think they were banning if I left the $10 on like, if I left the two accounts connected and I left the $10 on there for too long, they would put the accounts into a read only mode or a a collect only mode and not a not a spend mode, and then it would be and then it couldn't link new accounts to it. So if I left them for too long, there was a human going in there and and, you know, messing with the account, and then they have to start, like, a new chain of $10. And, eventually, it just became too tiresome to try and do that. But it it still did work, even even when I tried it a little bit ago when I went back to Canada once. And and I think they were doing it through, like, knowing the VPN IP. IP. I don't think they're having, like, hardware identification stuff, but I think it was through the IP. So, I mean, it could still work to this day. Anyway, I could rerecord this if, if needed. I kinda just went with it. Thanks. Love the podcast.
Speaker 5: We will chop it up and take out some of the longer parts, but thank you for calling in. This is
Speaker 4: Thank you.
Speaker 5: We will I think we should obfuscate a voice on this one as well.
Speaker 6: Yeah. We'll do a little something something to it.
Speaker 5: There's somebody in an in like, in a security and risk mitigation department that knows who you are. So if they listen to this podcast, they're like, that's the guy. Like, you know, the the the movie scene where it's like the detectives are hunting something. There's somebody out there who's like, oh, man. We he got away.
Speaker 6: The night fox, we've been calling him. We have a cork board with yarn and thumbtacks and, security photos up on the wall for the last decade. I really appreciate that this caller cooked this up when they were in Canada at Biking Around age, left Canada, and then when they came back to Canada, they like cracked it open just to see if it would work. And they're like, bye gum. It still it still goes. That $10 limit still seems to be there.
Speaker 5: Oh, man. This is I feel I don't know. I feel like the loyalty programs are probably they're probably much better now that they're all, like, major systems.
Speaker 4: Yeah.
Speaker 5: But I bet I bet in early days of loyalty rollouts and loyalty apps and stuff, like, I bet there were they were rife with security flaws, I bet.
Speaker 6: Oh, yeah. They've all basically converged, to our earlier point. And this isn't a show about issues with Canadian markets, but they've all basically converged around being three of these rewards programs. There's Loblaws PC Optimum, there's SobeSeen Plus, and then there's Metro, which is like the French Canadian one. And they're basically, every grocery store you're apt to find up here in Canada is now one of these three systems. So I would guess when, you know, these were all different grocery stores, you could just game the living crap out of these things. But by now, PC Optimum Points is basically a small country's economy. Like, it's like it's it's it's a third of our food infrastructure here up in Canada, so it's probably pretty locked down now. But I I could see there being, like, a little bit of a a little bit of a gap where at a certain price point at less than $10, sure, auto approve it once. And then you do this daisy chain thing that this caller figured out of, reconnecting these accounts. It's pretty clever.
Speaker 5: Well, then yeah. It is very clever. Like, this is to me, this is like this is the gamesmanship and the puzzle solving that makes cybersecurity speak to certain types of people. And this is definitely one of those types of people where he's just like, I figured out a system. Like, I figured, like, they they built something. I figured out a way to game it, and I'm gaming it. And I feel the payoff is of it is enough that I will fill pails full of toothpicks because that is my trophy for, like, figuring out the game. Totally.
Speaker 6: It was like you can imagine a person who the first stage of this plan prior to the $10 limit was it was a law of large numbers thing. It was like, I'm gonna do these big big claims. And the vast majority, but I think the number they said was one out of 50 of them might ever get through. But that's all you really need because you script it, you run it automated overnight, and you come back the next morning and you see, oh, boom, one of them went through. Which means to your earlier point, Scott, that there was probably some security person working for this large, grocery chain who was very well aware of this, like Mhmm. Fraudulent claims. And so they they shifted the numbers a little bit, and then this caller didn't buckle. When that shift took place, it was like, now it's a $10 limit. It's like, okay. Yeah. And now it's a $10 limit. You have to spend $10. It's like The the
Speaker 5: the game is adapting. The other
Speaker 6: the other side is Exactly.
Speaker 5: The other side is is is playing. Yeah. Exactly.
Speaker 6: Yeah. Exactly. Like, the their side of the chessboard is moving. You're just like, okay. Fine. I'll string the accounts together.
Speaker 5: Like, the thing that surprises me is that, like, they would have known they would have had a photo of him. You know? Like, they would have known, like, the he went into this drug drugstore, grocery store, whatever, because the points are spendable everywhere, even at gas stations in Canada Yep. Due to the oligopoly above us. But the, the they would have known. They would have pulled security footage. Like, if they were blocking his individual VPN IP, like, they would have gone to the lengths to be like, okay. Like, we've we saw that he made a 20 nightlight purchase on Thursday, January 9 at this location. Like, let's pull the security footage and and pull a photo of this person. And then they probably would have distributed that photo in the area, which was even more surprising if they didn't. So the fact that he played for so long and accumulated such a high point value on the on the
Speaker 6: leaderboard. Points.
Speaker 5: The, yeah. Wild. I would have thought for sure that they would have stepped in harder and stopped it. And and the fact that years later when he came back for a holiday or something or see family or, you know, whatever the the point was, still worked is wild.
Speaker 6: Yeah. I mean, he speculated, I think, correctly that the staff I have I have a a good friend who works for a large grocery chain, and I can attest.
Speaker 5: They don't care.
Speaker 6: That guy's face could have been printed 10 feet tall with wanted above and below it. Big dollar signs next to it, and they they just just couldn't give less of a shit. The other thing I like was, that he pivoted towards toothpicks and toothbrushes, a lot of dental hygiene stuff, but like non disposable products because I think the quote was groceries, you can only buy so many of them before they go bad, which is like I remember being an age where if there was fresh food in my fridge, it was definitely gonna go bad before I would have a chance to eat it. I would I would simply throw up that the average Canadian spends about $16,000 on groceries in a year, and his annual gains were about 9,000. So you could totally eat $9,000 worth of groceries from a grocery store, but that really wasn't the tenor of this game.
Speaker 5: The Yeah. Yeah. I agree. I agree. The thing that made me think of a Shoppers Drug Mart, and this is just totally an aside for any Canadians listing, is when he mentioned that the points are spendable in a lot of places. Right. Because I know the PC Optimum points are both grocery, drug stores, gasoline, like they're kind of accrued and spent all over the place. So that's when I thought, okay, this is probably probably is the PC shoppers drug market programs.
Speaker 6: Yeah. You could a real Canadian superstore sells PS fives. I'll just say that. True. I'll just I'll just lob that up in the air. You can you can buy a Nintendo switch at the real Canadian superstore or a Shoppers Drug Mart, I think, at this point.
Speaker 5: So Full full disclosure, I bought an Xbox Series x when they they could not be found anywhere from Shoppers Drug Mart.
Speaker 6: That's the pro tip up here is if you're trying to get, like, some really, hard to find electronics, there's always, like, three of them under a bunch of Culligan jugs of water in some of these grocery stores.
Speaker 5: It's the
Speaker 6: weirdest thing. They're like the new iPhone. Yeah. I think
Speaker 4: we got a couple on the back.
Speaker 6: They're like sure. There's a lineup around the block everywhere else, but rock on. Great call. Thank you for sharing it with us. If you're ever back up in Canada again, please keep trying this and let us know if it works. You can share that call as can anyone at hotlandhack.com. We wanna hear your strange tale of technology. You can call into the phone number. You can submit audio via an email. You can send it as text. If you asked us to, we'll we'll futz with your voice as needed. We love to hear your tales. But the only thing we love more than that, Scott. Do you know what it is?
Speaker 4: Oh. I think you do.
Speaker 5: I I do. I do. I think you do. It's our sponsor. Delete me. Delete me.
Speaker 6: Scott, do you ever wonder how much of your personal data is out there on the Internet for anybody to see?
Speaker 5: No. Because I know it's too much. You do? I do. And and one of the things so this is an anecdote. So my mom recently got scammed. I told Jordan this. Yeah.
Speaker 6: This sucks. Somebody called Amazon,
Speaker 5: you know, quote, unquote Amazon. Yeah. Yeah. Yeah. Yeah. Yeah. My mom got taken, who is one of the most viciously cynical when it comes to her personal security people I've ever met, which is the shocker in this. And I would bet money that they had personal information on her that make her feel more comfortable about it and they probably ended up getting that information via the data broker hack or something like that because these were true professionals they had full blown sites and things set up to clone and obfuscate and do everything to make it seem like they were hyper legitimate. And, yeah, it would not surprise me if that they had personal information that they had either purchased or stolen from a data broking site to help help with their goal.
Speaker 6: Yeah. Which was to do something real shitty. I'm sorry that happened. No worries. Their goal being to use your name, your contact info, your Social Security number, your home address, info about your family, and to take that stuff and sell it on the Internet for money, which is why anyone on the web can buy those private d private details. That can all lead to identity theft, phishing attempts as we saw here, harassment, spam calls, and you can protect your privacy with, friend of the show and sponsor, Paula UnHacked. Delete me.
Speaker 5: You know, just given current events and stuff, you know, I'm hyper aware of safety, security, and it's easier than ever to just find information on people online and that's something that I think needs to go down and away. So all this data is just hanging out, but it has real world impacts and real world consequences to people as you know, we've now seen in the story that I told. So that's why, you know, I recommend you use DeleteMe. Join deleteme.com/hacked, code word hacked, to check out. It's a subscription service that removes your personal information from hundreds of these data brokers. They send you regular personalized privacy reports showing what info they found, where they found it, what they got removed. So it's not just a one time service that you run once and walk away from. It's kinda constantly a service that's running in the background. So Yeah. I recommend it.
Speaker 6: You sign up. You provide them with exactly what information you want taken down. They're experts take it from there. If you're interested in something like this, take control of your data. Keep your private life private. Sign up for DeleteMe. It's a special discount for listeners of Hotline Hacks. You can get 20% off your DeleteMe plan when you go joindeleteme.com/hacked and use promo code hacked to check out. So the only way to get 20% off is go to joindeleteme.com/hacked and enter code word hacked at checkout. Scott, one more time for the feedback.
Speaker 5: That's join deleteme.com/hacked, code hacked, sponsor of Hotline Hacked. Appreciate them.
Speaker 7: So the statute of limitations has expired, so I can speak freely. My name is Jeremy. I'm from Atlanta.
Speaker 5: What a great way to
Speaker 6: start a story. Way to start a story. I think in any setting too.
Speaker 5: The statute of limitations is over. I have no fears of being charged for this, and I'm happy to tell this story.
Speaker 6: You could start a TED talk that way. You could start, a wedding speech that way. It is a very provocative way to start a story.
Speaker 5: I I love the theory that you could start a wedding speech that way. That's a wedding speech I wanna hear.
Speaker 6: That would
Speaker 5: be amazing. To the mic and uses that as the opener to a wedding speech. Everybody would lean in.
Speaker 6: Now that the statute of limitations is over. Like the
Speaker 5: toast to the groom. You know, the statute of limitations is over. The the hall would go silent.
Speaker 6: Yeah. The groom just starts shaking his head quietly.
Speaker 5: I'm gonna bank that one. And listeners of of Hotline Hacked, you just gave them, like, amazing advice for any speeches they have to do in the future.
Speaker 6: Especially if it doesn't get resolved by the end of the talk. Like, if it's just a nice, like, story about how the bride and groom met, but you started with now that the statute of limitations has expired. That's good.
Speaker 7: Back in 2015, I was running around with the underbelly a little bit using a lot of methamphetamines, running with a scammy crowd. I got the idea to download a bunch of background check apps and see if I I was looking to see if I had a warrant, trying to find out if I needed to be worried. So I downloaded all the usuals, been verified, truth finders, etcetera. And I found one on the Android App Store called People Spy. The APK is still visible. However, the app hasn't worked since about 2018. So I download the app, and, of course, the first thing you do is do a background check on yourself. And I did it, and it was a little buggy. It kinda went in and out and looked up some other people and, didn't really think anything about it. One day, I was looking around in the file directory of my Android device, and in the slash folder, I see a random text file that's called people spy dot t x t. So I open it, and this was all the metadata that the app collects, you know, previous criminal history, address history, telephone number history, acquaintances, and then there was a section that said relatives. And I look, and I see my mother's name, and next to it is her Social Security number. This is a number that I know and could verify. So I looked my mom up. I found me as a relative, and there was my Social Security number exposed in plain text just in a metadata dump file from one of these background check apps. At that point, I realized that I had open access to everybody's Social Security number pretty much ever as long as they had a somewhat unique name. Findable. Easy. A 100% of the time, once I got sober and got my life together, I contacted the company that was the owner of it, just kinda making a, you know, moral disclosure. Hey. Your app was doing this. You may wanna check the servers and see make sure this doesn't happen again. They denied it, completely ignored me, and, I've left it alone since. Thanks a lot. Again, the app was called People Spy.
Speaker 6: I guess, first and foremost, kudos for for getting sober. Congratulations, caller. Yeah. And then for having the wherewithal after all of that was said and done to contact this app and let them know that there's a glaring security compromise in their shit.
Speaker 5: I feel I feel like Hotline Hacked is three quarters entertainment, one quarter moral growth. Like, that's like a lot a lot of these stories a lot of these stories, they're like, yeah, I did these things and it wasn't great. Like, this one wasn't obviously cyber, like, crime related, but, there there it seems like every every episode we have a story that has some more growth. So, yes, kudos to you for getting sober and and, getting your life on the rails. So kudos.
Speaker 6: Peoplespy.com. I I I dug this up after looking at this call. It doesn't currently seem to still exist. It's redirecting. I'm not sure if it's a new product or they sold the, they sold the email to someone else, but it redirects to email tracer dot com. You can find press releases about this, And it does get into, the sponsor of the show. And then something we've just talked about, especially during the national, public data breach that happened this year, that got a lot of people talking about these data brokers, is that the existence of these services that will sell you information gathered from a bunch of different sources indiscriminately is tricky because, you know, there's really no protection for what someone does with it afterwards, including building a webs building an app Mhmm. That stores information in plain text on the device locally that it probably shouldn't be
Speaker 2: Yeah.
Speaker 6: Which sounds like according to this caller is what occurred here.
Speaker 5: I feel like Yep. No matter how bad we mess up an ad read, that is a better advertisement for DeleteMe than anything we could have said. It's just like getting your information out of these data brokers because I guarantee, like, these apps are powered by it. They're buying, you know, wholesale lots of data, personal information about people, which is how they're how the app exists. So it's it's yeah. I yeah. I I have not a lot to say besides this is not surprising, and there are ways to combat it.
Speaker 6: Yeah. It seems like lazy something lazy occurred here. If this is how this went down, this is some sloppy, sloppy development that took place, I guess is what I'm trying to say.
Speaker 5: Yeah. But to me to me, it's not even just that. Like, it is it is sloppy in the sense that they've essentially given like, they clearly bought this information. Yeah. Right? Like, they have the the personal information, the sins, all the rest of this jazz or the socials, showing the Canadian in me there. The, they they have these from datasets that they purchased, and it's like the fact that they're exposing it is like if anything, it's them not charging enough for access for it. You know? Like, it's it's like you can still buy this information. It's just that, like, they shouldn't be giving it away for for free. He said, like and I'm saying that in, like, a kinda cynical way, but it's like like the that's not a feature of of People Spy. And it's like but they still have that information. Some other random person still bought it. Yeah. So it's not like it's super confidential.
Speaker 6: I think that's the thing that I wanna understand more about this. And I'm waiting for a story to function as an excuse to dig into it more, is is the legality of some of this stuff. Like if you can't confirm the provenance of a social insurance number that is inside of the database of a product that you are selling to other people, How's that legal? There should be a some kind of law that that's bumping up against. I'm not sure exactly which one, but I'm surprised that's a totally fair and legal thing to do. Yeah.
Speaker 5: I I know in Canada, we have a higher bar Right. Of rigorous protection for for personal information. I'm not sure about other countries. I'm not a like an IP lawyer or like a whatever lawyer would deal with this.
Speaker 6: Maybe this is a an interview we should try and put together in the new year. And if you happen to know someone in your life that might be this kind of expert is I I'd like to hunt someone down that can explain to me as, like, way the court system in The States regards these kinds of incidents where it's like you have a private company and some of these companies are not large companies. It's like a dude spins it up and they go buy a bunch of data from a bunch of sketchy sources and then resell it in a vaguely slick legal looking package. I'm like, I just wanna understand that from a legal perspective.
Speaker 5: Here's the thing. So I've reached out to two of those people in the last year.
Speaker 6: Shit.
Speaker 5: One specifically to talk about the, Canadian online protections out because and that pile of thing. And I actually reached out to the EFF, old supporter of the show, Electronic Frontier Foundation, because if anybody is gonna know the answers to that stuff in The States, it will be somebody that works there that's a lawyer. We'll try
Speaker 6: and get them on in 2025.
Speaker 5: So if you work at the EFF or the Canadian Civil Liberties Association, please reach out get at hack podcast dot com.
Speaker 6: Take it across the finish line.
Speaker 5: Should we take a little little break to the ad oasis?
Speaker 6: Oh, man. It's cold this time of year. It's wet. It's snowy. I could chill on a beach for for a minute or two. Let's do it. Let's get over there. Let's go.
Speaker 2: What's up, guys? My name is Jay Pod, and I wanted to share kind of a fun story from my high school days in the late nineties. It's kinda like a little early slice of hacking. Not really hacking. Just a kid being a kid with maybe too much access and not enough oversight.
Speaker 5: Hell yeah, brother. Yeah. Hell yeah. What do you do here?
Speaker 2: I went to a a magnet school. Anyways, we got computers earlier than most schools, which is kind of a big deal back then. And I've I've grown up around tech. Like, my older brothers, they're really into it. I remember we had, like, a Commodore 64, and my brother's got all kinds of PCs growing up. I really wasn't into it, but I was just, like, exposed to it early on. So, anyways, fast forward to high school. One of the first programs they introduced to us was something called the EBS program or electronic book system. And, basically, in our class, we had to read books, and then every week, we took a quiz. And it was, like, a DOS based program or something like that. But, anyways, each week, we were required to complete a quiz as part of our grade. This computer basically managed the tests for the teacher. But the problem was no no one at the school had any real training or knew how to use it, especially our teacher. So every week, she, like, kinda struggled to log in and set up the quizzes and get the class organized. So naturally, I get it was kinda straightforward to me. So I kinda, I guess, was a tech savvy kid at the time. So I volunteered to help.
Speaker 5: Just a classic social engineering and the teacher's pet going on here, I think.
Speaker 6: Why, missus Tomlinson? I know how the computer works.
Speaker 2: And without any hesitation, my teacher just handed me over her credentials and let me do everything. And here's the thing. Her her login credentials weren't just limited to the EBS program. I quickly realized that, they gave me full unrestricted access to the school's entire computer network and not just from the school network. I I was able to remotely log in. There are no firewalls, no multifactor authentication, no real oversight, just basically a login name and a password. So at first, I didn't really think much of it. I was kinda focused on getting the EBS work for the class, you know, try to help everyone out, make the teacher's life a little easier. But then curiosity kind of got the best of me, and I started poking around in the software and discovered something that's kinda hilarious in retrospect. All the data, the questions, the answers were kinda basically stored in unencrypted text files right on the machine. Literally no encryption, no file permissions, nothing. It was like, they assume no one would ever look into it. So being a teenager and not wanting to spend my evenings reading books, I downloaded the EBS software on my home computer. And with a simple text editor, I had access to all the answers for every quiz in the program. The first thing I did, of course, was test it out. I went to class, took the quiz, and got a perfect score. It was it was pretty easy. And then it didn't take long before I realized I could share this discovery with my friends.
Speaker 5: Bad decision. Bad decision. I feel like every one of these stories begins with, like, I figured it out. I could I could cruise my way to college and then it's like, but then I wanted to help my friends out and then we got busted and then we got thrown out of school.
Speaker 6: Yeah. There are no secrets that time does not reveal. The more people you let in on something, the the quicker it's gonna get it's gonna get found out.
Speaker 2: They gave me the name of the book they were supposed to read that week, and I just handed them the answers. I printed it up on my mom's printer, brought them to school. No one bought anything of it. So we aced every quiz for the rest of the year. And to this day, I don't think the teachers ever figured out what was happening. They just
Speaker 5: Prove me wrong. Yeah.
Speaker 6: Prove me wrong. Sometimes crime pays.
Speaker 5: You must have been hanging out with the smart kids because I feel like the if a teacher sees a student go from a a a 60% average to a 100% on every test, it would be like a shocker. But if there were already, like, eight kids and then they just kept getting a's, it's okay.
Speaker 6: I wonder finish the call. I have a theory. Okay.
Speaker 2: They thought the software was working, and we're all doing really good. But, I I I probably gave every kid in my class a printout at least once a week. You know?
Speaker 5: So this caller's audio file act like, not accidentally. And we have a five I think it was a five minute limit. It shouldn't be a five minute limit.
Speaker 6: No. There there's there. I don't think there is. Or maybe there is. Yeah. We don't seem to have a second call.
Speaker 5: Disconnected at five minutes, so we don't have the rest of his story. So we'll just tease it that apparently he got access to the overall network and into, some of the gray data and other pieces of information that he probably shouldn't have. We don't know the rest of the story. So if you wanna call in and finish this, this can be a cliffhanger ending.
Speaker 6: For the year.
Speaker 5: Oh, I love it. For the year.
Speaker 6: Like an old network drama. So here's my theory. K.
Speaker 5: Let's hear it.
Speaker 6: And and this this kinda gets back to what you said of the conspicuousness of, like, wow. This kid starts getting nineties and a hundreds on all these quizzes. Oh, shit. All of this kid's friends have started really acing all of the quizzes too. You know, a teacher, you don't have to be tech literate to be shrewd and smart and observant. So So I'm wondering here's what I'm thinking has maybe occurred here. I'm a teacher. I'm not the most tech savvy teacher maybe ever. It's early days computers. I don't need to be. I give a student some login credentials to to get their help figuring out how a thing works. They're good at computers, maybe they can help me figure it out. It's a learning opportunity for the kid. That kid started getting a 100% on every quiz, and the quizzes are stored on the computer, and all of their friends are getting 100%. So I have two choices. I can either untangle this massive, security breach that I have engineered by giving the login credentials to a teenager, or I can consider the fact that the school year is pretty short. And next year, this kid's gonna be someone else's problem. And so maybe they just get a 100% on, like, ninth grade algebra or book reports or whatever the heck it was. It's English class in junior high or high school. It's like, you know what? You got you got you got the a. Get the heck out of my hair, and now I've learned a valuable lesson. Do not share login credentials with the students. That's my theory.
Speaker 5: I I think if that was the theory, the teacher would maybe request to have their credentials changed mid season once you once they realize what's going on. So here's my theories. One, smart kid, obviously, maybe surrounded by other smart kids. They were already getting nineties and the hundreds.
Speaker 4: Sure.
Speaker 5: Now they just don't have to work for them. They just literally get them. And it sounds like maybe in the future, they just get them by editing the grades. But we don't know. Cliffhanger.
Speaker 4: Cliffhanger.
Speaker 5: The so that that's my theory one. Theory two is that, what was the previous caller's reference for the lazy employee, Judy?
Speaker 6: Yeah. I think it was Judy. Judith. Judy.
Speaker 5: Maybe this is a Judy. Maybe the teacher was a Judy and was just saying, I didn't even look at the grades. The computer's auto checking them. She doesn't even need to review them. She's like, I've got artificial intelligence now. I'm in auto drive. The the the computer and this kid coordinate my class and all of the testing now, and I don't even need to look at it. I'm gonna be like I guess this was probably before you'd be staring at your phone, but maybe they were reading, like, Martha Stewart magazine. Classic Judy move. Classic
Speaker 6: Judy move. Yeah. Judy might just not give a shit.
Speaker 5: Yeah.
Speaker 6: That's always and that's that almost that theory almost loops back around to my original theory, which is that the teacher cared less about untangling this than they did about catching the kid. And it's just like, Jude the thing I know about Judy is Judy doesn't give a fuck. And she just, like, let it ride as she had done in her previous job working in the, a customer support, department of a large Canadian grocer. She didn't give a shit there. She approved all of those claims, and she doesn't give a shit now if that kid gets 10 out of 10 on every quiz.
Speaker 3: Mhmm. Mhmm.
Speaker 5: Yeah. Alright. Good theory. Good theory and a cliffhanger ending. Hopefully, they call back in with the rest of the story. Please do so if you hear this. Jordan, I think, was their name. Not just your name. Also your name.
Speaker 6: Not just my name. It's my name too.
Speaker 4: And it could
Speaker 6: be yours. No. I can't. But you could get your call on hotlinehack.com if you if you if you want. You can't have my name, but you can do that. Share your strange gel tech? I think true hack.
Speaker 5: Is this the last last episode of the year? I
Speaker 6: think it might be. I think we got, a rerun coming up Early January? On, like, on, like, New Year New Year's Day kinda thing. I think we'll we'll drop a a hacked classic for everyone to to to enjoy. But I think in terms of original content, this is this is a wrap on 2024.
Speaker 5: Yeah. Thanks thanks for being here with us, everybody. Thanks to definitely thanks to all the participants in Hotline Hacks taking time out of your life to to be a part of the show. We really appreciate that. We know it's it's not just asking for you to listen, but it's also asking for you to contribute as part of the show. And and big thank you to all of you.
Speaker 6: It's true. Thanks to all our sponsors. Thanks to everyone that shared a story. And thank you for listening. Yeah. We really enjoy making this bad boy. We got a lot of really fun schemes patched for 2025, so we we hope you'll stick around and,
Speaker 5: happy to
Speaker 6: be here with us. Thanks for
Speaker 5: the Discord gang. Thanks to the patrons. Thanks to the people that reach out. I don't know if you saw it, but, Patrick Bjornfoot? I'm hope I'm I'm probably masking that, but it looks like Bjornfoot to me, is part of the sinus infection gang. And he sent me a recommendation for what looks like a World War two, like, mass produced gas mask, like a emergency gas mask. But, apparently, these things are very common in cross country skiing. So so instead of your face freezing up and and having cold, dry air constantly burning your sinuses and your lungs, you put these masks on and they remoisturize the air with the moisture from your breath, which kinda makes sense. A little bit of a strong look for me just to wear out and about on the random Wednesday and March.
Speaker 6: I don't know about that. I think you could. I think you'd bring a an intense post apocalyptic energy that we could all enjoy right now.
Speaker 5: So the, Thank
Speaker 6: you for thank you for your email. Same to, Tobias. Emailing him with some some fun game references from Moscow. We really appreciate it. If you just wanna send us a message, not for hotline, get it hackedpodcast.com, is a is a great way to get a hold of us. Submit a story. Also a great way to get a hold of us. We're here. We're around.
Speaker 5: We are. We try to be. Try to be.
Speaker 6: We try.
Speaker 5: And, yeah. Hit us up on the socials. Hack podcast on most things. I don't think we're very active on really any of them. People do tweet us, and we do get back to them. I recently put a ChatTPT prompt on there to generate a Python script to download all of the episodes of our podcast as m p threes. Somebody asked how to do it, and I was like, just ask ChatTPT, and it will do it for you. Yeah. I think that's it.
Speaker 6: I think that's it. To everyone who listened, thank you so much. Happy New Year's. We'll catch you in the next one.
Speaker 5: Ciao.
Speaker 2: Hey, everyone. It's Olivia Culpo, and I can't wait to tell you all about Abercrombie's new summer collection. All their new dresses and colorful swim feel perfect for a Euro summer, and Abercrombie has a new 100% linen collection. It's the perfect mix of looking put together and elevated with the lightness and comfort of linen. Shop Abercrombie this summer in the app, online, and in stores.
Speaker 8: You're great at protecting your data, but lots of places could still expose you to identity theft.
Speaker 5: I thought it was safe.
Speaker 8: If that happens, LifeLock gives you a US based restoration agent who will stick by your side from start to finish. Phone calls, filing documentation, preparing insurance claims, your agent handles it all. In fact, we're so confident restoration is guaranteed. Pour your money back. Isn't it nice to have someone like that on your side? Save up to 30% your first year at lifelock.com/podcast. Terms apply.
Speaker 5: There's a new way to sweet greet. Meet wraps, handheld, hearty, and made for life on the move. With bold chef crafted flavors, fresh ingredients, and over 40 grams of protein, they're built to satisfy without slowing you down. Try wraps today in the app or at order.sweetgreen.com, available at all participating locations.