WEBVTT - Ransomware and WannaCry

0:00:04.200 --> 0:00:07.240
<v Speaker 1>Get in text with technology with tech Stuff from how

0:00:07.280 --> 0:00:14.000
<v Speaker 1>stuff works dot com. Hey there, and welcome to tech Stuff.

0:00:14.040 --> 0:00:17.840
<v Speaker 1>I'm your host, senior writer John in Strickland right for

0:00:17.960 --> 0:00:20.720
<v Speaker 1>how stuff works dot com. It's a groovy website. You've

0:00:20.760 --> 0:00:23.280
<v Speaker 1>never been there. You should go check it out. You've

0:00:23.320 --> 0:00:25.360
<v Speaker 1>been listening to tech stuff all this time and didn't

0:00:25.440 --> 0:00:29.760
<v Speaker 1>know there was website. Work on your listening skills. I

0:00:29.840 --> 0:00:32.360
<v Speaker 1>love you how stuff works dot Com. Check it out.

0:00:32.400 --> 0:00:34.479
<v Speaker 1>So today I thought take a look at a tech

0:00:34.560 --> 0:00:37.120
<v Speaker 1>story that happened not too long ago as the recording

0:00:37.120 --> 0:00:41.159
<v Speaker 1>of this podcast. I'm recording it on ma It is

0:00:41.200 --> 0:00:43.960
<v Speaker 1>publishing much later than that, but not too long ago

0:00:44.000 --> 0:00:48.640
<v Speaker 1>from today. A virus emerge that really caused a lot

0:00:48.680 --> 0:00:52.600
<v Speaker 1>of headaches, particularly in the UK and a lot of

0:00:52.640 --> 0:00:54.600
<v Speaker 1>other countries. Not so much in the United States, but

0:00:54.720 --> 0:00:58.200
<v Speaker 1>a lot of other ones. And it's called Wanna Cry.

0:00:58.640 --> 0:01:02.360
<v Speaker 1>It's the Wanna Cry ran somewhere virus. It really became

0:01:02.400 --> 0:01:06.200
<v Speaker 1>big news starting on May twelve, sen That's where when

0:01:06.200 --> 0:01:08.760
<v Speaker 1>it went viral for the first time and spread the

0:01:08.840 --> 0:01:12.880
<v Speaker 1>thousands of machines. Uh. The account goes anywhere between two

0:01:13.000 --> 0:01:16.959
<v Speaker 1>hundred thousand and four hundred thousand computers, depending upon what

0:01:17.040 --> 0:01:21.280
<v Speaker 1>authority you're looking at. I want to cry was exploiting

0:01:21.280 --> 0:01:26.080
<v Speaker 1>a vulnerability in a protocol used by the Windows operating system.

0:01:26.120 --> 0:01:28.360
<v Speaker 1>But I'll explain all of that a little bit later. First,

0:01:28.440 --> 0:01:33.080
<v Speaker 1>let's talk about what ransomware is and where it came from. So,

0:01:34.120 --> 0:01:39.400
<v Speaker 1>to put it simply, ransomware is a subset of malware,

0:01:39.640 --> 0:01:44.600
<v Speaker 1>and malware stands for malicious software. Um. You might also

0:01:44.640 --> 0:01:47.919
<v Speaker 1>hear it described as a computer virus. That's largely because

0:01:47.920 --> 0:01:50.800
<v Speaker 1>in the early days of personal computers there are really

0:01:50.800 --> 0:01:53.880
<v Speaker 1>only two major types of malware, and those were viruses

0:01:53.960 --> 0:01:57.800
<v Speaker 1>and worms. Uh, and so we've often used computer viruses

0:01:57.880 --> 0:02:00.480
<v Speaker 1>shorthand for malware. But there are a lot and lots

0:02:00.520 --> 0:02:03.120
<v Speaker 1>of different kinds of malware out there, and so using

0:02:03.120 --> 0:02:05.600
<v Speaker 1>a term like virus is not as specific as most

0:02:05.600 --> 0:02:08.600
<v Speaker 1>people would prefer. But what the heck is a virus

0:02:08.600 --> 0:02:10.160
<v Speaker 1>and what the heck is a worm? Well, a virus

0:02:10.200 --> 0:02:13.000
<v Speaker 1>is some malicious code that a programmer designs that inserts

0:02:13.000 --> 0:02:16.280
<v Speaker 1>itself into another program. They're typically part of some sort

0:02:16.280 --> 0:02:19.520
<v Speaker 1>of executable file, so e x E in the Windows

0:02:19.520 --> 0:02:23.120
<v Speaker 1>operating System world or DOSS. Even the virus does not

0:02:23.280 --> 0:02:27.160
<v Speaker 1>activate until the computer runs the respective file. So you

0:02:27.200 --> 0:02:29.680
<v Speaker 1>can have a computer that has a virus on it,

0:02:29.800 --> 0:02:32.680
<v Speaker 1>but the virus is inactive. It is dormant because you

0:02:32.760 --> 0:02:35.600
<v Speaker 1>have not yet run that file, and as long as

0:02:35.600 --> 0:02:38.880
<v Speaker 1>you don't run that file, the virus will remain dormant.

0:02:38.919 --> 0:02:41.919
<v Speaker 1>It will be inert. But once you run the file,

0:02:42.000 --> 0:02:44.960
<v Speaker 1>it activates the virus and it ends up replicating itself.

0:02:45.880 --> 0:02:48.920
<v Speaker 1>Sometimes it will use other programs to spread itself to

0:02:49.160 --> 0:02:53.440
<v Speaker 1>other machines. In the old days, before you had networked computers,

0:02:53.600 --> 0:02:56.080
<v Speaker 1>it would essentially replicate itself over and over again in

0:02:56.200 --> 0:03:00.480
<v Speaker 1>order to overwrite everything on the computer and essentially jam

0:03:00.520 --> 0:03:04.320
<v Speaker 1>everything up. You couldn't end up saving anything to the computer.

0:03:04.639 --> 0:03:09.160
<v Speaker 1>Everything would be overwritten by this virus, essentially rendered your

0:03:09.160 --> 0:03:15.040
<v Speaker 1>computer useless. Uh. It's pretty nasty stuff. The worm, on

0:03:15.080 --> 0:03:17.760
<v Speaker 1>the other hand, is a self propagating piece of code

0:03:17.800 --> 0:03:20.800
<v Speaker 1>that does not rely on another file, and typically the

0:03:20.880 --> 0:03:25.200
<v Speaker 1>programmer depends upon some sort of trick like social engineering

0:03:25.280 --> 0:03:28.440
<v Speaker 1>to get people to execute the worm and start that

0:03:28.560 --> 0:03:32.120
<v Speaker 1>self propagation process. Now, both viruses and worms are part

0:03:32.160 --> 0:03:35.080
<v Speaker 1>of a larger classification of malware, and ransomware is a

0:03:35.120 --> 0:03:40.200
<v Speaker 1>specific type of malware that as the name suggests holds

0:03:40.200 --> 0:03:44.200
<v Speaker 1>a victim's computer for ransom. It doesn't break into their

0:03:44.240 --> 0:03:46.360
<v Speaker 1>house and steal it and then put a gun to

0:03:46.440 --> 0:03:49.520
<v Speaker 1>the monitor and say pay up or it gets it.

0:03:50.000 --> 0:03:52.440
<v Speaker 1>Otherwise you would just need a particular set of skills

0:03:52.960 --> 0:03:55.200
<v Speaker 1>to go after those folks, as we learned in the

0:03:55.240 --> 0:04:00.240
<v Speaker 1>documentary Taken. Typically, malware that as ransomware will do one

0:04:00.240 --> 0:04:04.560
<v Speaker 1>of two things. The most common version on desktop machines

0:04:04.600 --> 0:04:08.880
<v Speaker 1>and laptops is that it will encrypt the victims computer,

0:04:09.480 --> 0:04:12.160
<v Speaker 1>so that means it will encode your computer so that

0:04:12.200 --> 0:04:15.280
<v Speaker 1>none of your files will be readable or even you know,

0:04:15.320 --> 0:04:17.120
<v Speaker 1>you won't even be able to locate them because they're

0:04:17.160 --> 0:04:22.920
<v Speaker 1>all renamed. Under this nonsense encryption approach, that can end

0:04:23.000 --> 0:04:25.760
<v Speaker 1>up causing your computer to be useless or at least

0:04:26.000 --> 0:04:30.000
<v Speaker 1>give make it your information inaccessible. The goal is to

0:04:30.080 --> 0:04:32.839
<v Speaker 1>get the victim to fork over some cash and in return,

0:04:33.200 --> 0:04:36.320
<v Speaker 1>the hackers will decrypt the computer. They'll give whatever the

0:04:36.360 --> 0:04:41.880
<v Speaker 1>password is or the methodology to decrypt all the information

0:04:41.880 --> 0:04:43.720
<v Speaker 1>and turn it back to the way it was before

0:04:43.880 --> 0:04:50.120
<v Speaker 1>it was attacked. Now, uh, there's the second variant of

0:04:50.240 --> 0:04:54.640
<v Speaker 1>ransomware that doesn't encrypt a computer. Instead, what it does

0:04:54.760 --> 0:04:57.919
<v Speaker 1>is locks people out of a device. This is the

0:04:58.120 --> 0:05:02.440
<v Speaker 1>locker version of in somewhere. It's most frequently seen in

0:05:02.560 --> 0:05:07.000
<v Speaker 1>Android based devices, so mostly mobile sets like handsets, tablets,

0:05:07.040 --> 0:05:10.960
<v Speaker 1>that kind of thing. And essentially hackers full of victim

0:05:11.000 --> 0:05:14.600
<v Speaker 1>into downloading and installing a malicious app, and then the

0:05:14.920 --> 0:05:17.839
<v Speaker 1>app will then activate this software that locks the victim

0:05:17.920 --> 0:05:21.040
<v Speaker 1>off from accessing their device. They won't be able to

0:05:21.080 --> 0:05:24.520
<v Speaker 1>use it, essentially bricks it until you are to pay

0:05:24.600 --> 0:05:26.640
<v Speaker 1>up a ransom. You might get like a little screen

0:05:27.200 --> 0:05:30.160
<v Speaker 1>that demons that shows you, you know, until you pay

0:05:30.560 --> 0:05:35.279
<v Speaker 1>x amount to why you won't have access to this device.

0:05:35.920 --> 0:05:37.719
<v Speaker 1>So you are told that you have to pay the

0:05:37.720 --> 0:05:39.680
<v Speaker 1>hackers in order to regain access to your device. And

0:05:39.640 --> 0:05:43.440
<v Speaker 1>in either case, ransomware is not pretty. Now. This is

0:05:43.839 --> 0:05:48.279
<v Speaker 1>similar to, but distinct from, another scheme that some hackers

0:05:48.320 --> 0:05:52.599
<v Speaker 1>employ over the last few years, which is blackmail. Hacker

0:05:52.640 --> 0:05:57.240
<v Speaker 1>groups like rex Mundy have targeted large corporations with a

0:05:57.279 --> 0:06:01.440
<v Speaker 1>goal of infiltrating their systems and dealing as much data

0:06:01.520 --> 0:06:06.480
<v Speaker 1>as possible, including customer data. That's one of the big targets.

0:06:06.520 --> 0:06:10.839
<v Speaker 1>So having that customer data is a very powerful tool.

0:06:11.120 --> 0:06:14.720
<v Speaker 1>Companies do not want their customers to lose confidence in them.

0:06:15.160 --> 0:06:17.760
<v Speaker 1>So if a hacker group is able to get hold

0:06:17.800 --> 0:06:20.360
<v Speaker 1>of a huge amount of customer information from a company

0:06:20.640 --> 0:06:23.000
<v Speaker 1>and then say, hey, if you don't pay up, we're

0:06:23.000 --> 0:06:26.760
<v Speaker 1>going to release this information or we're gonna sell it off. Uh,

0:06:26.839 --> 0:06:29.960
<v Speaker 1>it's bad news and it's very hard to recover as

0:06:29.960 --> 0:06:33.440
<v Speaker 1>a company if you've suffered that kind of data breach.

0:06:34.400 --> 0:06:37.839
<v Speaker 1>So it's similar to blackmail, but not exactly the same

0:06:37.880 --> 0:06:40.960
<v Speaker 1>because with ransomware, the hackers might not even be interested

0:06:41.040 --> 0:06:44.280
<v Speaker 1>at all in what's on the computer systems they target.

0:06:44.600 --> 0:06:49.240
<v Speaker 1>They don't care if there's customer information or if it's

0:06:49.400 --> 0:06:53.120
<v Speaker 1>internal systems that that doesn't matter. What they want to

0:06:53.200 --> 0:06:57.160
<v Speaker 1>do is affect as many critical computers as they possibly

0:06:57.200 --> 0:07:01.000
<v Speaker 1>can with ransomware, because if it's a critical device, if

0:07:01.000 --> 0:07:04.280
<v Speaker 1>it's something that's very important for the operations of a

0:07:04.400 --> 0:07:08.799
<v Speaker 1>larger organization or company, then that puts a huge amount

0:07:08.800 --> 0:07:11.239
<v Speaker 1>of pressure on the company to pay up the ransom

0:07:11.360 --> 0:07:16.000
<v Speaker 1>so they can get access to that critical hardware. Again, um,

0:07:16.040 --> 0:07:19.080
<v Speaker 1>that's the whole point of ransomware. They don't they don't

0:07:19.120 --> 0:07:21.000
<v Speaker 1>care if it's you know, what the nature of the

0:07:21.040 --> 0:07:24.080
<v Speaker 1>stuff is, as long as it's important because they're not

0:07:24.240 --> 0:07:27.440
<v Speaker 1>after the data itself there after money. They just want

0:07:27.440 --> 0:07:29.480
<v Speaker 1>to lock down those computers as much as they can

0:07:30.360 --> 0:07:32.920
<v Speaker 1>and then convince people to pay them so that they

0:07:32.920 --> 0:07:37.400
<v Speaker 1>can unlock them. Now, the first recorded instance of ransomware

0:07:38.000 --> 0:07:41.520
<v Speaker 1>was called the AIDS trojan and it was designed by

0:07:41.640 --> 0:07:46.280
<v Speaker 1>Joseph L. Pop p O p P. That particular attack

0:07:46.320 --> 0:07:49.080
<v Speaker 1>falls under the category of the trojan horse, which is

0:07:49.360 --> 0:07:52.679
<v Speaker 1>of course named after the legendary gift to the city

0:07:52.680 --> 0:07:56.920
<v Speaker 1>of Troy that secretly housed invading soldiers that were from Greece.

0:07:57.680 --> 0:08:02.040
<v Speaker 1>A trojan horse is malware that that looks like a

0:08:02.080 --> 0:08:05.320
<v Speaker 1>regular program. It fools someone into thinking they're using some

0:08:05.720 --> 0:08:09.600
<v Speaker 1>benign piece of software, but in reality they're essentially handing

0:08:09.600 --> 0:08:11.920
<v Speaker 1>over some critical part of their computer systems to the

0:08:11.920 --> 0:08:14.360
<v Speaker 1>whims of a hacker. So a lot of trojan horse

0:08:14.400 --> 0:08:18.679
<v Speaker 1>programs these days are programs that look like they're innocent.

0:08:19.040 --> 0:08:21.520
<v Speaker 1>You run them, and then it allows a hacker to

0:08:21.560 --> 0:08:25.360
<v Speaker 1>get a back end, like a back door entry into

0:08:25.440 --> 0:08:29.640
<v Speaker 1>your computer, usually administrative level control, and from there they

0:08:29.640 --> 0:08:31.960
<v Speaker 1>can do lots of different things. They can lock you

0:08:32.000 --> 0:08:34.640
<v Speaker 1>out of a system, They can allow you to continue

0:08:34.760 --> 0:08:37.040
<v Speaker 1>using a system so that you don't know that they're

0:08:37.040 --> 0:08:39.920
<v Speaker 1>even there. They can spy on what you're doing. They

0:08:39.920 --> 0:08:43.000
<v Speaker 1>can even redirect your computer to send traffic to a

0:08:43.160 --> 0:08:46.600
<v Speaker 1>target machine as part of the distributed denial of service attacks.

0:08:46.679 --> 0:08:50.720
<v Speaker 1>So this is a very common ploy that hackers will

0:08:50.800 --> 0:08:54.840
<v Speaker 1>use in order to build bot nets or computer armies. Now,

0:08:55.240 --> 0:09:00.160
<v Speaker 1>the AIDS trojan virus predates the World Wide Web, so

0:09:00.800 --> 0:09:04.120
<v Speaker 1>this was not a virus that was spread over email.

0:09:04.160 --> 0:09:08.960
<v Speaker 1>It wasn't spread over a compromised website. It was distributed

0:09:09.040 --> 0:09:14.200
<v Speaker 1>actually on floppy disks, good old floppy disks, and they

0:09:14.200 --> 0:09:18.480
<v Speaker 1>were sent over the postal service. Most of the recipients

0:09:18.559 --> 0:09:22.360
<v Speaker 1>were from other parts of the world, not the United States.

0:09:22.400 --> 0:09:24.800
<v Speaker 1>Here in the US, we really didn't have an issue

0:09:24.800 --> 0:09:29.240
<v Speaker 1>with the AIDS trojan virus directly. These were the targeted

0:09:29.280 --> 0:09:32.400
<v Speaker 1>systems were mostly in other places in the world, like Europe,

0:09:32.400 --> 0:09:36.719
<v Speaker 1>in Africa, in uh Asia, that kind of thing. So

0:09:38.120 --> 0:09:44.280
<v Speaker 1>the target for this attack happened to be companies and

0:09:44.360 --> 0:09:49.040
<v Speaker 1>agencies that were either in education or healthcare, and they

0:09:49.040 --> 0:09:53.480
<v Speaker 1>were concerned with educating people about the AIDS virus. The

0:09:53.559 --> 0:09:57.000
<v Speaker 1>disc was posing as educational software that was to teach

0:09:57.040 --> 0:10:00.520
<v Speaker 1>you about the AIDS virus. So it's pretty insidious that

0:10:00.600 --> 0:10:03.800
<v Speaker 1>it was. It took on this form. The software on

0:10:03.840 --> 0:10:07.160
<v Speaker 1>the disc included an actual survey that would tell the

0:10:07.200 --> 0:10:09.920
<v Speaker 1>taker what their odds were of contracting the AIDS virus

0:10:09.960 --> 0:10:13.440
<v Speaker 1>based off their responses. So, for example, it might ask

0:10:13.600 --> 0:10:17.240
<v Speaker 1>if you take intrivinous drugs and if so, do you

0:10:17.280 --> 0:10:20.560
<v Speaker 1>share needles? That sort of thing, and as you would

0:10:20.600 --> 0:10:22.880
<v Speaker 1>answer it, it would give you the odds of you

0:10:23.080 --> 0:10:25.960
<v Speaker 1>contracting the AIDS fires. So on the surface, it seemed

0:10:26.000 --> 0:10:30.480
<v Speaker 1>like actual educational software. What you didn't realize as you

0:10:30.600 --> 0:10:33.160
<v Speaker 1>ran this software on your computer is that in the

0:10:33.200 --> 0:10:37.240
<v Speaker 1>background code was running so that it would infect the computer,

0:10:37.360 --> 0:10:40.800
<v Speaker 1>and after a predetermined number of reboots to the system,

0:10:40.880 --> 0:10:44.160
<v Speaker 1>the software would encrypt all of your files. So, in

0:10:44.160 --> 0:10:47.240
<v Speaker 1>other words, it would set up as kind of a

0:10:47.280 --> 0:10:51.200
<v Speaker 1>doomsday clock, except instead of time, it was in reboots.

0:10:51.520 --> 0:10:53.600
<v Speaker 1>So every time you shut down your system and turned

0:10:53.640 --> 0:10:57.400
<v Speaker 1>it on, you were one step closer to activating this worm,

0:10:57.720 --> 0:11:00.720
<v Speaker 1>and eventually you would hit that threshold old and the

0:11:00.760 --> 0:11:02.840
<v Speaker 1>next time you turned on your computer, all of your

0:11:03.000 --> 0:11:08.360
<v Speaker 1>files would get encrypted by this by this malware. The

0:11:08.400 --> 0:11:11.000
<v Speaker 1>only thing you would see when you would reboot that

0:11:11.120 --> 0:11:15.160
<v Speaker 1>system that last time would be a message that says

0:11:15.320 --> 0:11:17.960
<v Speaker 1>turn on a printer. So essentially you'd have to have

0:11:18.000 --> 0:11:21.520
<v Speaker 1>a printer connected to the affected computer and when you

0:11:21.559 --> 0:11:23.760
<v Speaker 1>turned it on, it would send a print command to

0:11:23.880 --> 0:11:26.120
<v Speaker 1>the printer and print on a sheet of paper with

0:11:26.200 --> 0:11:30.760
<v Speaker 1>the instructions to pay the ransom, which is kind of interesting,

0:11:30.800 --> 0:11:35.000
<v Speaker 1>a little primitive, but obviously you didn't have bitcoin or

0:11:35.000 --> 0:11:38.800
<v Speaker 1>anything like that back in those days, so the ransom

0:11:38.840 --> 0:11:43.040
<v Speaker 1>note would print out once the computer was activated or

0:11:43.120 --> 0:11:46.680
<v Speaker 1>connected to an activated printer. The note directed victims to

0:11:46.760 --> 0:11:50.559
<v Speaker 1>send one eighty nine dollars to a post office box

0:11:50.640 --> 0:11:55.840
<v Speaker 1>located in Panama. After doing so, uh Pop, who of

0:11:55.880 --> 0:11:59.920
<v Speaker 1>course was not identifying himself as the perpetrator, promised that

0:12:00.040 --> 0:12:03.120
<v Speaker 1>he would send the decryption program to unlock the contents

0:12:03.160 --> 0:12:06.280
<v Speaker 1>of the victim's computers. In the UK, where the virus

0:12:06.320 --> 0:12:09.720
<v Speaker 1>was first reported, some medical institutions began to delete data

0:12:09.840 --> 0:12:12.160
<v Speaker 1>rather than pay the ransom. They were worried that their

0:12:12.200 --> 0:12:15.440
<v Speaker 1>systems have been totally compromised and that a hacker had

0:12:15.559 --> 0:12:18.200
<v Speaker 1>access to all of that data, so as a result,

0:12:18.760 --> 0:12:22.199
<v Speaker 1>they started the leading stuff, and in fact other parts

0:12:22.200 --> 0:12:26.080
<v Speaker 1>of the world were following a similar strategy. The Independent

0:12:26.480 --> 0:12:29.960
<v Speaker 1>reported that there was one organization in Italy that lost

0:12:30.160 --> 0:12:33.880
<v Speaker 1>a decade's worth of AIDS research as a result of this,

0:12:34.000 --> 0:12:37.760
<v Speaker 1>because there was a panic that uh, the compromised data

0:12:37.800 --> 0:12:41.760
<v Speaker 1>could be otherwise changed or altered, UH, which I guess

0:12:41.800 --> 0:12:44.840
<v Speaker 1>is repetitive or redundant, but at any rate that they

0:12:44.880 --> 0:12:48.040
<v Speaker 1>were worried that this vulnerability was worse than what they

0:12:48.080 --> 0:12:52.360
<v Speaker 1>were already seeing. So there were people who who lost

0:12:52.480 --> 0:12:55.200
<v Speaker 1>years and years of work as a result of this

0:12:55.520 --> 0:12:59.160
<v Speaker 1>ransomware attack. Now I mentioned earlier, we know who made

0:12:59.160 --> 0:13:03.040
<v Speaker 1>this virus. So knowing who made it, what exactly happened?

0:13:03.040 --> 0:13:05.760
<v Speaker 1>How did this story unfold? It's a bit strange, to

0:13:05.760 --> 0:13:07.920
<v Speaker 1>be honest. So let's give you some background on the

0:13:07.960 --> 0:13:10.360
<v Speaker 1>man who had programmed the virus in the first place.

0:13:10.920 --> 0:13:15.800
<v Speaker 1>Joseph L. Pop had graduated with a PhD from Harvard University,

0:13:15.840 --> 0:13:19.480
<v Speaker 1>and he was in the field of evolutionary biologies, not

0:13:19.600 --> 0:13:22.520
<v Speaker 1>in the field that you would immediately associate with someone

0:13:22.559 --> 0:13:28.360
<v Speaker 1>who's programming the world's first ransomware virus. UH. He was

0:13:28.760 --> 0:13:33.319
<v Speaker 1>actually not an enemy to AIDS research. That was his field.

0:13:33.640 --> 0:13:38.080
<v Speaker 1>He was consulting with the World Health Organization in the

0:13:38.160 --> 0:13:41.600
<v Speaker 1>area of AIDS research over in Kenya, so why would

0:13:41.640 --> 0:13:44.840
<v Speaker 1>he design a computer program that locked away computers used

0:13:44.880 --> 0:13:47.080
<v Speaker 1>by people who were trying to research AIDS and provide

0:13:47.160 --> 0:13:51.440
<v Speaker 1>education for at risk populations. Well, that depends upon whose

0:13:51.559 --> 0:13:55.520
<v Speaker 1>story you believe. So story number one came from Pop's lawyer,

0:13:55.600 --> 0:13:59.520
<v Speaker 1>who said that Pop's plan was to shake things up.

0:14:00.080 --> 0:14:04.440
<v Speaker 1>He wanted to change the the whole model of how

0:14:04.720 --> 0:14:08.679
<v Speaker 1>AIDS research was going about. He thought it was two regimented,

0:14:08.720 --> 0:14:11.520
<v Speaker 1>he thought it was off base. According to the lawyer,

0:14:12.280 --> 0:14:15.200
<v Speaker 1>uh and that Pop's plan was to use the ransom

0:14:15.280 --> 0:14:18.199
<v Speaker 1>money that he would get from people paying this d

0:14:18.720 --> 0:14:23.840
<v Speaker 1>dollars a pop to fund alternative AIDS education programs. So

0:14:24.160 --> 0:14:26.680
<v Speaker 1>you could argue that if this is actually the case,

0:14:27.080 --> 0:14:30.200
<v Speaker 1>this was a protest against the establishment and their approach

0:14:30.200 --> 0:14:32.080
<v Speaker 1>to AIDS research. So you would think of Pop as

0:14:32.120 --> 0:14:37.040
<v Speaker 1>some sort of crypto activist or crypto anarchist. But the

0:14:37.120 --> 0:14:40.320
<v Speaker 1>judge in the case actually disagreed with this and said

0:14:40.360 --> 0:14:43.480
<v Speaker 1>that Pop just wasn't even fit to stand trial, and

0:14:43.520 --> 0:14:47.640
<v Speaker 1>this was because his behavior had become something pretty strange

0:14:47.640 --> 0:14:51.440
<v Speaker 1>and erratic. He was the reason he was caught in

0:14:51.480 --> 0:14:54.120
<v Speaker 1>the first place. I mean, he could have just gotten

0:14:54.120 --> 0:14:56.160
<v Speaker 1>away from Europe and and no one would have ever

0:14:56.200 --> 0:14:59.000
<v Speaker 1>known it was him. The reason he was caught was

0:14:59.040 --> 0:15:03.200
<v Speaker 1>that he was in an airport in Amsterdam and he

0:15:03.240 --> 0:15:08.120
<v Speaker 1>wrote the sentence doctor Pop has been poisoned, which I

0:15:08.160 --> 0:15:11.480
<v Speaker 1>think would make a great title for an album, but

0:15:11.560 --> 0:15:16.920
<v Speaker 1>he wrote it on another passenger suitcase. It's pretty strange already.

0:15:16.960 --> 0:15:21.600
<v Speaker 1>Apparently he had been um acting somewhat unusually as the

0:15:21.680 --> 0:15:24.360
<v Speaker 1>stress was getting to him about trying to get out

0:15:24.360 --> 0:15:29.800
<v Speaker 1>of Europe while this story about the AIDS trojan virus

0:15:29.960 --> 0:15:33.440
<v Speaker 1>was making headlines over there, so he was feeling a

0:15:33.440 --> 0:15:36.680
<v Speaker 1>lot of pressure, and according to some stories, at least

0:15:36.720 --> 0:15:39.880
<v Speaker 1>he cracked well. The authorities saw that he was writing

0:15:39.880 --> 0:15:43.000
<v Speaker 1>stuff on other people's suitcases and took him aside for questioning,

0:15:43.000 --> 0:15:45.800
<v Speaker 1>and they searched his baggage, and when they did, they

0:15:45.840 --> 0:15:49.360
<v Speaker 1>found evidence that he was the one behind manufacturing and

0:15:49.400 --> 0:15:53.960
<v Speaker 1>distributing all those discs that had the malware on them. So,

0:15:54.000 --> 0:15:56.800
<v Speaker 1>while he was waiting for trial in the UK, his

0:15:56.880 --> 0:16:01.840
<v Speaker 1>behavior grew increasingly strange, and eventually Judge Jeffrey Rivlin dismissed

0:16:01.840 --> 0:16:04.920
<v Speaker 1>the case because he said that Pop was unfit to

0:16:05.040 --> 0:16:10.240
<v Speaker 1>stand trial. Pop was released and essentially got off scott free.

0:16:10.320 --> 0:16:14.680
<v Speaker 1>He eventually would open up a butterfly conservatory in upstate

0:16:14.680 --> 0:16:17.720
<v Speaker 1>New York. So you can go see Joseph L. Pop's

0:16:17.760 --> 0:16:22.800
<v Speaker 1>butterfly Conservatory and see the the conservatory built by a

0:16:22.800 --> 0:16:25.920
<v Speaker 1>guy who built the first ransomware in the world, which

0:16:25.920 --> 0:16:29.360
<v Speaker 1>is a little unusual. There is another theory about what

0:16:30.160 --> 0:16:34.200
<v Speaker 1>pops motivations were that have nothing to do with crypto

0:16:34.320 --> 0:16:41.720
<v Speaker 1>anarchist tendencies or erratic behavior. It's not nearly as grand

0:16:41.720 --> 0:16:43.720
<v Speaker 1>an act as all that, it's not as strange as

0:16:43.760 --> 0:16:46.280
<v Speaker 1>all that. The theory states that Pop was actually just

0:16:46.360 --> 0:16:50.120
<v Speaker 1>seeking revenge. He had been passed over for a position

0:16:50.280 --> 0:16:53.600
<v Speaker 1>with the World Health Organization, so some theories say he

0:16:53.640 --> 0:16:55.960
<v Speaker 1>got very upset that he wasn't picked for this job,

0:16:56.440 --> 0:16:59.280
<v Speaker 1>and as a result, he designed and then unleashed the

0:16:59.400 --> 0:17:04.480
<v Speaker 1>software targeting organizations that he felt he should have been

0:17:05.400 --> 0:17:07.960
<v Speaker 1>taking a larger role in, but because he got passed over,

0:17:08.320 --> 0:17:10.800
<v Speaker 1>he didn't have that opportunity. And he even had a

0:17:10.800 --> 0:17:13.840
<v Speaker 1>digital diary that contained evidence that he had been planning

0:17:14.000 --> 0:17:15.960
<v Speaker 1>this attack for more than a year and a half,

0:17:16.640 --> 0:17:19.600
<v Speaker 1>so it was a premeditated act, not something that was

0:17:19.680 --> 0:17:24.840
<v Speaker 1>done spontaneously, at least according to that digital diary. Ah. So,

0:17:25.800 --> 0:17:27.200
<v Speaker 1>there are some people who say that he was just

0:17:27.359 --> 0:17:30.119
<v Speaker 1>bitter about not getting that job, and that was the

0:17:30.119 --> 0:17:33.280
<v Speaker 1>motivation he had for building the first ransomware. But whatever

0:17:33.280 --> 0:17:35.920
<v Speaker 1>the reason, he didn't serve any time for his crime.

0:17:36.080 --> 0:17:39.560
<v Speaker 1>And his encryption scheme was relatively simple to reverse. It

0:17:39.600 --> 0:17:45.359
<v Speaker 1>was symmetric encryption, and it wasn't particularly robust, so after

0:17:45.480 --> 0:17:48.480
<v Speaker 1>some time, experts were able to figure out how to

0:17:48.560 --> 0:17:52.879
<v Speaker 1>reverse engineer it, essentially using brute force to decrypt the

0:17:53.320 --> 0:17:58.760
<v Speaker 1>affected computers. So uh, it really wasn't as bad as

0:17:58.800 --> 0:18:02.040
<v Speaker 1>it could have been, or as it later would turn

0:18:02.160 --> 0:18:06.240
<v Speaker 1>to be, as future ransomware hackers would create more robust

0:18:06.480 --> 0:18:14.240
<v Speaker 1>means of of putting your data off limits. So one

0:18:14.280 --> 0:18:20.560
<v Speaker 1>thing that Pop also set into motion was this tendency

0:18:20.680 --> 0:18:25.360
<v Speaker 1>for hackers who have developed ransomware to target healthcare organizations,

0:18:25.600 --> 0:18:29.960
<v Speaker 1>whether it's hospitals or organizations that are related to healthcare,

0:18:30.640 --> 0:18:33.600
<v Speaker 1>that's a prime target for ransomware. And the reason is

0:18:34.000 --> 0:18:39.080
<v Speaker 1>the information inside those computers is critical, literally critical to

0:18:39.119 --> 0:18:43.640
<v Speaker 1>the lives of human beings. So by targeting these very

0:18:43.720 --> 0:18:48.440
<v Speaker 1>critical systems that have a high sense of of urgency

0:18:48.520 --> 0:18:53.480
<v Speaker 1>about the data that they contain, the hackers are maximizing

0:18:53.520 --> 0:18:58.000
<v Speaker 1>the chance that people will give in and pay their demands.

0:18:58.040 --> 0:19:02.280
<v Speaker 1>So two different trends that he started. He started the

0:19:02.359 --> 0:19:06.360
<v Speaker 1>ransomware trend and he started the targeting healthcare trend, both

0:19:06.440 --> 0:19:11.120
<v Speaker 1>of which are pretty odious, I would say, But yeah,

0:19:11.160 --> 0:19:13.640
<v Speaker 1>the more valuable and urgent the information is, the more

0:19:13.720 --> 0:19:16.880
<v Speaker 1>likely you are to pay up when something gets locked away.

0:19:17.600 --> 0:19:23.240
<v Speaker 1>Now we'll talk more about early ransomware in just a minute,

0:19:23.280 --> 0:19:26.280
<v Speaker 1>but before we jump into that, let's take a quick

0:19:26.320 --> 0:19:38.200
<v Speaker 1>break to thank our sponsor. So early ransomware attackers would

0:19:38.720 --> 0:19:42.040
<v Speaker 1>originally they were building their own encryption codes to convert

0:19:42.119 --> 0:19:45.679
<v Speaker 1>files into seemingly meaningless gibberish. So what's going on with

0:19:45.760 --> 0:19:47.880
<v Speaker 1>encryption in the first place? What does that actually mean?

0:19:48.240 --> 0:19:50.119
<v Speaker 1>I used the term a lot. You've probably heard it

0:19:50.160 --> 0:19:52.480
<v Speaker 1>a lot, and some of you are probably very familiar

0:19:52.840 --> 0:19:55.560
<v Speaker 1>with the whole concept of encryption. But in case you

0:19:55.600 --> 0:19:58.560
<v Speaker 1>are not, and you're wondering, what does that even mean?

0:19:59.040 --> 0:20:01.680
<v Speaker 1>I mean, I get that it turning my files into

0:20:01.680 --> 0:20:04.840
<v Speaker 1>stuff that I can't read, but what is actually happening?

0:20:05.080 --> 0:20:08.840
<v Speaker 1>I thought I would give a very very basic explanation

0:20:08.840 --> 0:20:12.119
<v Speaker 1>of what encryption is. Now, keep in mind, this is

0:20:12.160 --> 0:20:16.720
<v Speaker 1>at its most basic level encryption involves using a key

0:20:16.840 --> 0:20:19.760
<v Speaker 1>to encode data in a way that makes it meaningless

0:20:19.800 --> 0:20:24.480
<v Speaker 1>to an outside observer who does not also possess that key.

0:20:24.480 --> 0:20:27.679
<v Speaker 1>So this is just making codes essentially, It's what it

0:20:27.680 --> 0:20:30.280
<v Speaker 1>boils down to. It's just using a very advanced algorithm

0:20:30.280 --> 0:20:33.280
<v Speaker 1>in order to do it, and using a huge number

0:20:33.400 --> 0:20:37.280
<v Speaker 1>of potential of variations on that so that you make

0:20:37.280 --> 0:20:41.640
<v Speaker 1>it very very difficult for people to reverse engineer the

0:20:41.640 --> 0:20:46.560
<v Speaker 1>strategy you use to encrypt the information, thus making it safe. Uh,

0:20:46.600 --> 0:20:49.360
<v Speaker 1>if you use a very simple set of rules, then

0:20:49.400 --> 0:20:52.280
<v Speaker 1>obviously your data isn't that safe. All it takes is

0:20:52.400 --> 0:20:55.320
<v Speaker 1>someone to notice what the rules are and then they

0:20:55.320 --> 0:20:59.400
<v Speaker 1>can reverse it that way. So if you've ever used

0:20:59.400 --> 0:21:03.720
<v Speaker 1>a substitut tuition cipher, you're you've experimented with an extremely

0:21:03.760 --> 0:21:06.600
<v Speaker 1>simple version of encryption. So you might decide with a

0:21:06.600 --> 0:21:09.159
<v Speaker 1>buddy that you're going to shift all the meaning of

0:21:09.280 --> 0:21:12.880
<v Speaker 1>letters one over from their actual place on the alphabet,

0:21:13.280 --> 0:21:15.800
<v Speaker 1>so that when you write your to a message encode

0:21:15.960 --> 0:21:19.080
<v Speaker 1>to your buddy, a B is an A, and a

0:21:19.200 --> 0:21:21.400
<v Speaker 1>C is a B, and so on and so forth.

0:21:21.400 --> 0:21:25.919
<v Speaker 1>That's a very simple one shift substitution cipher. When you

0:21:26.000 --> 0:21:29.159
<v Speaker 1>receive a message, you use that key, which in this

0:21:29.200 --> 0:21:32.680
<v Speaker 1>case is just that very simple rule to decode the message,

0:21:32.720 --> 0:21:34.479
<v Speaker 1>and then you read it, and then later that night

0:21:34.520 --> 0:21:37.439
<v Speaker 1>you'll probably TP someone's home, because that's the kind of

0:21:37.440 --> 0:21:39.200
<v Speaker 1>thing we allows the kids used to do before there

0:21:39.240 --> 0:21:44.119
<v Speaker 1>was an Internet and Nintendo switches and whatnot. Obviously, computers

0:21:44.119 --> 0:21:47.520
<v Speaker 1>are using much more robust encryption techniques than a simple

0:21:47.560 --> 0:21:50.399
<v Speaker 1>substitution cipher. The goal is to create a method of

0:21:50.480 --> 0:21:53.080
<v Speaker 1>encryption that is so sophisticated that it would take someone

0:21:53.600 --> 0:21:57.480
<v Speaker 1>years or even decades before they could decrypt the information

0:21:57.600 --> 0:22:00.800
<v Speaker 1>without the use of a key in others, to use

0:22:00.880 --> 0:22:05.800
<v Speaker 1>brute force. Brute force is essentially when you just tele computer,

0:22:06.400 --> 0:22:09.480
<v Speaker 1>I want you to work through every variation of this

0:22:10.000 --> 0:22:14.640
<v Speaker 1>particular approach until you find the one that works. And

0:22:14.920 --> 0:22:19.000
<v Speaker 1>the more approaches there are, the longer that will take

0:22:19.040 --> 0:22:23.600
<v Speaker 1>a computer to accomplish. So your goal is to make

0:22:23.760 --> 0:22:28.119
<v Speaker 1>the encryption process difficult enough so that a computer doesn't

0:22:28.160 --> 0:22:31.080
<v Speaker 1>have any hope of solving it by brute force in

0:22:31.160 --> 0:22:35.320
<v Speaker 1>any reasonable amount of time. The earliest forms of computer

0:22:35.400 --> 0:22:38.199
<v Speaker 1>encryption used a fifty six bit key. Now remember a

0:22:38.240 --> 0:22:41.280
<v Speaker 1>bit is a single unit of information. It is either

0:22:41.400 --> 0:22:44.760
<v Speaker 1>a zero or a one. So if you have fifty

0:22:44.800 --> 0:22:49.600
<v Speaker 1>six bits, how many different combinations will that get you.

0:22:50.160 --> 0:22:55.240
<v Speaker 1>The answer is it's around seventy quadrillion possible combinations. That

0:22:55.280 --> 0:22:58.200
<v Speaker 1>sounds like a lot, seventy quadrillion, but as it turns out,

0:22:58.359 --> 0:23:03.720
<v Speaker 1>modern computers can brute for us that fairly quickly, quickly

0:23:03.760 --> 0:23:07.040
<v Speaker 1>being a relative term. But it's not impossible to use

0:23:07.080 --> 0:23:09.720
<v Speaker 1>brute force and break that kind of encryption, so it's

0:23:09.800 --> 0:23:13.680
<v Speaker 1>not safe. So today you would use a much higher

0:23:14.320 --> 0:23:17.960
<v Speaker 1>uh bit for your encryption, like two fifty six bit encryption,

0:23:18.359 --> 0:23:26.560
<v Speaker 1>which gives you way more potential combinations, exponentially more combinations.

0:23:26.960 --> 0:23:30.600
<v Speaker 1>So to decrypt without brute force, if you're not going

0:23:30.640 --> 0:23:34.000
<v Speaker 1>to try and just force all those different variations through,

0:23:34.520 --> 0:23:37.560
<v Speaker 1>you need that key. The key is like a secret

0:23:37.640 --> 0:23:40.919
<v Speaker 1>dacoder ring. So if you get hit with ransomware, what

0:23:40.960 --> 0:23:44.480
<v Speaker 1>the hackers are actually offering you is the decryption key.

0:23:44.560 --> 0:23:47.679
<v Speaker 1>In exchange for money you pay them, they give you

0:23:47.720 --> 0:23:50.760
<v Speaker 1>the secret super secret dacoder rings, so you can decode

0:23:50.760 --> 0:23:53.040
<v Speaker 1>all that stuff that's on your computer and you can

0:23:53.119 --> 0:23:56.720
<v Speaker 1>use it again. These days, the money is typically demanded

0:23:56.720 --> 0:24:00.080
<v Speaker 1>in the form of digital currency like bitcoin, or in

0:24:00.240 --> 0:24:05.119
<v Speaker 1>prepaid cards like money Pack, which, by the way, and

0:24:05.200 --> 0:24:08.639
<v Speaker 1>one of the stories I was reading was misspelled with

0:24:08.680 --> 0:24:12.480
<v Speaker 1>a typo calling it monkey pack, and I wish it

0:24:12.600 --> 0:24:16.960
<v Speaker 1>was monkey Pack, but monkey Pack is a brand of backpacks.

0:24:17.000 --> 0:24:21.040
<v Speaker 1>It is not a method of cash transfer, unless you

0:24:21.080 --> 0:24:23.399
<v Speaker 1>were to stuff a monkey pack filled with money and

0:24:23.400 --> 0:24:26.120
<v Speaker 1>then hand it to someone, then technically it is cash transfer.

0:24:26.480 --> 0:24:29.280
<v Speaker 1>But I'm pretty sure that the the author of the

0:24:29.359 --> 0:24:37.200
<v Speaker 1>article meant money Pack. More's the pity. So using Bitcoin

0:24:37.359 --> 0:24:42.320
<v Speaker 1>or these prepaid options it allows hackers to maintain their anonymity,

0:24:42.520 --> 0:24:45.200
<v Speaker 1>as opposed to giving you an address, like a physical

0:24:45.240 --> 0:24:48.160
<v Speaker 1>address to send money to, which you know you could

0:24:48.160 --> 0:24:50.639
<v Speaker 1>just hand over to authorities who would then stake it

0:24:50.680 --> 0:24:53.320
<v Speaker 1>out and try and catch the people who are responsible.

0:24:53.840 --> 0:24:56.160
<v Speaker 1>Using the digital approach, it's a lot harder to do that.

0:24:57.000 --> 0:25:01.200
<v Speaker 1>Since ransomware has become a more popular method to attack computers,

0:25:01.200 --> 0:25:03.600
<v Speaker 1>and it really took off once the World Wide Web

0:25:03.680 --> 0:25:06.960
<v Speaker 1>matured and upon the launch of the smartphone industry as well.

0:25:07.560 --> 0:25:12.320
<v Speaker 1>The Internet Crime Complaint Center or I SEE three says

0:25:12.400 --> 0:25:15.680
<v Speaker 1>that between two thousand five and two thousand sixteen they

0:25:15.680 --> 0:25:20.200
<v Speaker 1>received reports of more than seven thousand, six hundred ransomware attacks,

0:25:20.320 --> 0:25:23.640
<v Speaker 1>and by comparison, the i C three says it received

0:25:23.680 --> 0:25:27.800
<v Speaker 1>more than six thousand reports of data breaches, so ransomware

0:25:27.840 --> 0:25:32.040
<v Speaker 1>actually outnumbers data breaches the information you tend to see

0:25:32.080 --> 0:25:35.000
<v Speaker 1>in the US, at least, you see these big stories

0:25:35.040 --> 0:25:38.760
<v Speaker 1>about companies that had their systems compromised and people stole

0:25:38.800 --> 0:25:41.320
<v Speaker 1>a lot of information. That's a data breach. The big

0:25:41.400 --> 0:25:43.679
<v Speaker 1>Sony data breach from a few years ago is a

0:25:43.720 --> 0:25:47.040
<v Speaker 1>great example. Um not that it's great, but it serves

0:25:47.080 --> 0:25:51.760
<v Speaker 1>as a great example. Ransomware actually happens way more frequently

0:25:51.880 --> 0:25:54.879
<v Speaker 1>than those big data breaches because again, you don't have

0:25:54.960 --> 0:25:58.600
<v Speaker 1>to care about what information is in the system. You

0:25:58.720 --> 0:26:01.679
<v Speaker 1>just want to make it unreachable. So all you have

0:26:01.760 --> 0:26:06.840
<v Speaker 1>to do is fool someone into executing some malicious code,

0:26:07.560 --> 0:26:10.640
<v Speaker 1>and depending upon the nature of the malware, you might

0:26:10.640 --> 0:26:13.320
<v Speaker 1>be able to infect an entire system just through one

0:26:13.359 --> 0:26:16.520
<v Speaker 1>point of entry. You don't have to try and navigate

0:26:16.920 --> 0:26:21.040
<v Speaker 1>a complex and potentially very secure system of computers in

0:26:21.119 --> 0:26:24.960
<v Speaker 1>order to look for specific information, because again you don't

0:26:25.000 --> 0:26:27.320
<v Speaker 1>care what the information is, You just want them to

0:26:27.359 --> 0:26:32.960
<v Speaker 1>have no access to it. Now, in the mid two thousands,

0:26:33.160 --> 0:26:35.919
<v Speaker 1>there are a lot of different types of malware in

0:26:35.960 --> 0:26:42.680
<v Speaker 1>the ransomware category that debuted that included stuff like gp code, Archivas, Crotton,

0:26:42.960 --> 0:26:47.679
<v Speaker 1>cry Zip, may Archive, and troj Dot ransom dot A

0:26:48.480 --> 0:26:51.320
<v Speaker 1>and these were using tougher algorithms that were harder to crack.

0:26:51.720 --> 0:26:54.480
<v Speaker 1>Arcives was one of the first, and it used our

0:26:54.640 --> 0:26:58.440
<v Speaker 1>essay encryption and demanded that users visit specific websites to

0:26:58.520 --> 0:27:01.840
<v Speaker 1>make purchases and are to buy a password to remove

0:27:01.840 --> 0:27:04.720
<v Speaker 1>the lock on their files. So you would get a

0:27:04.760 --> 0:27:07.720
<v Speaker 1>message saying you need to go to this pharmacy's website

0:27:07.960 --> 0:27:11.040
<v Speaker 1>and you need to buy x amount of drugs from

0:27:11.040 --> 0:27:14.280
<v Speaker 1>this pharmacy, and after you do, we'll give you the password.

0:27:15.400 --> 0:27:19.680
<v Speaker 1>Pretty aggressive marketing scheme for that pharmacy, if you were

0:27:19.680 --> 0:27:23.160
<v Speaker 1>to ask me. Obviously it was a front for these hackers,

0:27:24.359 --> 0:27:28.560
<v Speaker 1>but pretty nasty stuff. And more and more frequently hackers

0:27:28.600 --> 0:27:31.320
<v Speaker 1>began to use off the shelf solutions as time went on.

0:27:31.520 --> 0:27:34.359
<v Speaker 1>Rather than build their own encryption codes, they began to

0:27:34.480 --> 0:27:37.399
<v Speaker 1>use stuff that a couple of people had developed and

0:27:37.440 --> 0:27:40.199
<v Speaker 1>then had released out into the wild for others to

0:27:40.320 --> 0:27:45.840
<v Speaker 1>use at their own discretion. So this did two things.

0:27:45.960 --> 0:27:50.119
<v Speaker 1>It increased the sophistication of the encryption algorithms that the

0:27:50.200 --> 0:27:54.480
<v Speaker 1>hackers were using, and it lowered the barrier to entrgue

0:27:54.720 --> 0:27:57.800
<v Speaker 1>for hackers to the point where if you are willing

0:27:57.840 --> 0:28:01.800
<v Speaker 1>to pay the money, you and get very simple hacker

0:28:02.000 --> 0:28:06.879
<v Speaker 1>tool kits that are easy to run. Like they are

0:28:06.920 --> 0:28:09.320
<v Speaker 1>they are made to be user friendly for the hacker

0:28:10.200 --> 0:28:12.680
<v Speaker 1>UM and you don't have to know how they work.

0:28:13.080 --> 0:28:15.560
<v Speaker 1>You just have to use them. It's like using any

0:28:15.600 --> 0:28:18.040
<v Speaker 1>other program on a computer. You don't have to know

0:28:18.080 --> 0:28:20.800
<v Speaker 1>how it works in order for it to work. And

0:28:20.880 --> 0:28:23.640
<v Speaker 1>that makes it much more dangerous because it suddenly makes

0:28:23.760 --> 0:28:27.760
<v Speaker 1>ransomware a more viable option for a larger group of

0:28:27.760 --> 0:28:31.760
<v Speaker 1>people and thus put more computers at risk. It's a

0:28:31.840 --> 0:28:40.680
<v Speaker 1>pretty ugly cycle. So you also saw websites began to

0:28:41.600 --> 0:28:47.719
<v Speaker 1>get compromised and that became an issue too. UM and

0:28:47.760 --> 0:28:51.880
<v Speaker 1>you also started to see malware that would copy notifications

0:28:51.920 --> 0:28:55.880
<v Speaker 1>from trusted sources to fool people into installing malicious software.

0:28:56.240 --> 0:28:59.200
<v Speaker 1>So you've probably encountered something like this in the past.

0:28:59.400 --> 0:29:03.120
<v Speaker 1>You may have gone to a website that was not secure,

0:29:03.200 --> 0:29:06.360
<v Speaker 1>it was maybe a compromised website, and you might get

0:29:06.360 --> 0:29:08.640
<v Speaker 1>a pop up window that says, hey, you need to

0:29:08.760 --> 0:29:12.600
<v Speaker 1>update your flash, so that you can watch this content,

0:29:12.800 --> 0:29:16.600
<v Speaker 1>or you might get a notification saying, hey, the FBI

0:29:16.720 --> 0:29:18.920
<v Speaker 1>is looking at you right now, so you need to

0:29:18.960 --> 0:29:22.600
<v Speaker 1>follow this this link. But in in general, these are

0:29:22.640 --> 0:29:26.520
<v Speaker 1>not legitimate things. These are actually phishing attempts to try

0:29:26.600 --> 0:29:28.880
<v Speaker 1>and get you to click on stuff to download and

0:29:28.880 --> 0:29:32.400
<v Speaker 1>install the malware so that you compromise your own computer.

0:29:33.400 --> 0:29:36.640
<v Speaker 1>So don't do that, and don't go to that website anymore.

0:29:36.760 --> 0:29:39.920
<v Speaker 1>It's been compromised. It is not a nice place for

0:29:39.920 --> 0:29:43.640
<v Speaker 1>you to go visit. Go outside, get some fresh air,

0:29:44.720 --> 0:29:47.400
<v Speaker 1>or if it's on your phone, turn your phone off.

0:29:48.320 --> 0:29:52.840
<v Speaker 1>You know, just be careful. Over time, the demands from

0:29:52.840 --> 0:29:55.840
<v Speaker 1>hackers have increased as well as the sophistication of the

0:29:55.880 --> 0:29:59.120
<v Speaker 1>hacking program. In the mid two thousand's, the typical demand

0:29:59.240 --> 0:30:03.560
<v Speaker 1>for payment is hovering somewhere around three hundred dollars, typically

0:30:03.600 --> 0:30:06.400
<v Speaker 1>between two hundred and four hundred bucks. And this is

0:30:06.400 --> 0:30:08.600
<v Speaker 1>where the economies of scale come into place. A three

0:30:08.640 --> 0:30:12.560
<v Speaker 1>hundred dollars in the grand scheme of things is not

0:30:12.760 --> 0:30:17.800
<v Speaker 1>that much money. Now, it's not cheap. Three dollars is significant.

0:30:17.840 --> 0:30:20.360
<v Speaker 1>I mean, I'm not gonna just drop three hundred bucks

0:30:20.400 --> 0:30:22.520
<v Speaker 1>and walk away without a care. In the world. That's

0:30:22.920 --> 0:30:25.880
<v Speaker 1>it's a significant amount of money, but it's not an

0:30:26.080 --> 0:30:28.560
<v Speaker 1>enormous ransom. It's not like the sort of stuff you

0:30:28.600 --> 0:30:31.880
<v Speaker 1>see in movies where a character gets kidnapped and then

0:30:32.280 --> 0:30:36.640
<v Speaker 1>the the kidnappers demand a million dollars in ransom money.

0:30:36.800 --> 0:30:39.960
<v Speaker 1>It's three hundred bucks. However, you also have to remember

0:30:40.160 --> 0:30:44.400
<v Speaker 1>that ransomware typically if it's being really successful, is infecting

0:30:44.960 --> 0:30:49.400
<v Speaker 1>hundreds or thousands of computers at three hundred bucks of pop.

0:30:49.480 --> 0:30:53.520
<v Speaker 1>Assuming that people are playing ball, that ends up adding

0:30:53.600 --> 0:30:58.640
<v Speaker 1>up pretty quickly, so it ends up being uh an

0:30:58.680 --> 0:31:01.719
<v Speaker 1>effective way to extort people out of money. Today, the

0:31:01.760 --> 0:31:05.400
<v Speaker 1>price is closer to five dollars on average, so it's

0:31:05.400 --> 0:31:08.120
<v Speaker 1>gone up. It's no longer around three hundreds, around five.

0:31:09.040 --> 0:31:12.840
<v Speaker 1>And again, just through sheer number alone, you can see

0:31:12.880 --> 0:31:15.520
<v Speaker 1>the potential for hackers to make lots of money using

0:31:15.560 --> 0:31:20.680
<v Speaker 1>this methodology. And also a lot of the software today

0:31:21.080 --> 0:31:23.959
<v Speaker 1>comes along with a deadline, so it's not just that

0:31:24.000 --> 0:31:27.160
<v Speaker 1>your information is locked away, but that you have a

0:31:27.200 --> 0:31:31.800
<v Speaker 1>limited amount of time before UH something worse happens to you.

0:31:31.840 --> 0:31:33.960
<v Speaker 1>So you've gotta like pay up before the end of

0:31:33.960 --> 0:31:38.640
<v Speaker 1>the month, or we'll start deleting your information. We'll start

0:31:38.640 --> 0:31:40.760
<v Speaker 1>deleting your files so that not only are they not

0:31:40.840 --> 0:31:44.240
<v Speaker 1>accessible to you now, you'll never be able to access

0:31:44.280 --> 0:31:49.080
<v Speaker 1>them again because we're gonna completely delete and overwrite them.

0:31:49.160 --> 0:31:52.200
<v Speaker 1>So it becomes that kind of level of extortion. You know,

0:31:53.000 --> 0:31:56.120
<v Speaker 1>you've got a nice, uh database, only it sure would

0:31:56.160 --> 0:31:58.280
<v Speaker 1>be a shame as someone out though encrypted it and

0:31:58.280 --> 0:32:03.000
<v Speaker 1>then stead deleting it piece by peace. That's the sort

0:32:03.000 --> 0:32:06.760
<v Speaker 1>of message that the hackers are sending. So it's definitely

0:32:06.800 --> 0:32:16.800
<v Speaker 1>gotten more sophisticated, more expensive, and more um malicious over time. However,

0:32:16.880 --> 0:32:20.240
<v Speaker 1>ransomware does tend to change very quickly. You don't tend

0:32:20.280 --> 0:32:24.600
<v Speaker 1>to see one type of ransomware dominate for longer than

0:32:24.680 --> 0:32:28.280
<v Speaker 1>say a year or so. Kaspersky Labs, which is a

0:32:29.040 --> 0:32:33.520
<v Speaker 1>computer security company, reported that the most prominent ransomware between

0:32:33.560 --> 0:32:36.160
<v Speaker 1>two thousand and fourteen and two thousand fifteen was a

0:32:36.200 --> 0:32:39.760
<v Speaker 1>program called crypto Wall, which accounted for more than half

0:32:39.800 --> 0:32:42.840
<v Speaker 1>of all the ransomware examples found in the wild. Something

0:32:42.880 --> 0:32:45.600
<v Speaker 1>like fifty eight percent of all ransomware was crypto Wall

0:32:45.800 --> 0:32:49.080
<v Speaker 1>or some variation of crypto Wall, and according to the FBI,

0:32:49.200 --> 0:32:52.720
<v Speaker 1>the hackers behind crypto Wall made eighteen million dollars from

0:32:52.720 --> 0:32:56.160
<v Speaker 1>their victims, and crypto Wall was one of the earliest

0:32:56.160 --> 0:32:59.320
<v Speaker 1>types of ransomware to spread over compromised websites, and earlier

0:32:59.400 --> 0:33:05.200
<v Speaker 1>ransomwarely relied on other methodology too for distribution, but crypto

0:33:05.240 --> 0:33:10.960
<v Speaker 1>wall went through compromise websites and email attachments and affected

0:33:10.960 --> 0:33:14.080
<v Speaker 1>a lot of targeted computers. It used a two hundred

0:33:14.120 --> 0:33:17.760
<v Speaker 1>fifty six bit key to encrypt specific types of files,

0:33:17.760 --> 0:33:20.680
<v Speaker 1>so it would look for files that had uh specific

0:33:20.680 --> 0:33:24.800
<v Speaker 1>extensions like a dot d C file, a dot A

0:33:24.880 --> 0:33:27.600
<v Speaker 1>document file. It would look for those sorts of files

0:33:27.680 --> 0:33:30.800
<v Speaker 1>and encrypt them using this two d fifty six bit key.

0:33:30.920 --> 0:33:33.760
<v Speaker 1>Then it would use a two thousand, forty eight bit

0:33:34.000 --> 0:33:36.800
<v Speaker 1>r s A key to encrypt the two fifties six

0:33:36.880 --> 0:33:40.960
<v Speaker 1>bit key. This double encryption made it much more difficult

0:33:41.000 --> 0:33:44.520
<v Speaker 1>for you to figure out how to reverse the process.

0:33:44.560 --> 0:33:47.120
<v Speaker 1>But the following year saw crypto wall reduced to just

0:33:47.320 --> 0:33:50.760
<v Speaker 1>five point one of all ransomware, so it went from

0:33:50.760 --> 0:33:53.480
<v Speaker 1>fifty eight percent to five point to one percent in

0:33:53.520 --> 0:33:56.800
<v Speaker 1>the span of one year. The new heavy hitter was

0:33:56.840 --> 0:34:00.000
<v Speaker 1>a piece of software called Tesla crypt, and the hackers

0:34:00.040 --> 0:34:03.600
<v Speaker 1>behind that malware frequently demanded their ransoms in Bitcoin and

0:34:03.680 --> 0:34:09.000
<v Speaker 1>other forms of digital payment. Ransomware attackers continued to aim

0:34:09.000 --> 0:34:11.799
<v Speaker 1>at the healthcare industry for the reasons I mentioned earlier.

0:34:12.080 --> 0:34:15.359
<v Speaker 1>Hospitals have been affected by various types of ransomware UH.

0:34:15.480 --> 0:34:19.960
<v Speaker 1>Some of them include Los Angeles Hollywood Presbyterian Medical Center,

0:34:20.640 --> 0:34:24.880
<v Speaker 1>the Los Angeles County Department of Health Services, Ottawa Hospital,

0:34:25.600 --> 0:34:28.719
<v Speaker 1>Kentucky Methodist Hospital, and lots and lots of others. A

0:34:28.760 --> 0:34:32.000
<v Speaker 1>ton of them are in California. In fact, in some cases,

0:34:32.440 --> 0:34:35.200
<v Speaker 1>hospitals paid the ransom in order to regain control and

0:34:35.320 --> 0:34:38.439
<v Speaker 1>access of their systems, but in other cases, savvy tech

0:34:38.480 --> 0:34:43.000
<v Speaker 1>professionals were helping to quarantine affected computers to disconnect them

0:34:43.000 --> 0:34:45.920
<v Speaker 1>from the network so that they wouldn't spread the malware

0:34:46.080 --> 0:34:50.120
<v Speaker 1>further into the system. And then they worked to UH

0:34:50.160 --> 0:34:55.720
<v Speaker 1>to reboot the systems using old backups, so essentially going

0:34:55.760 --> 0:34:59.799
<v Speaker 1>to the backup files and you know, you lose some

0:35:00.000 --> 0:35:03.080
<v Speaker 1>stuff because chances are you generated some data since the

0:35:03.200 --> 0:35:06.560
<v Speaker 1>last backup, but it meant that they got back these

0:35:06.640 --> 0:35:09.440
<v Speaker 1>systems UH and didn't have to pay the ransom in

0:35:09.480 --> 0:35:13.640
<v Speaker 1>several cases. Now, sometimes hackers have a real flair for

0:35:13.680 --> 0:35:18.640
<v Speaker 1>the dramatic UH. There's the team that's behind the Jigsaw ransomware,

0:35:19.880 --> 0:35:23.560
<v Speaker 1>Jigsaw taking its name from the villain in the Saw

0:35:23.880 --> 0:35:27.600
<v Speaker 1>series of films. The malware not only locked the victim's computer,

0:35:28.080 --> 0:35:31.120
<v Speaker 1>but displayed an image of the puppet that was used

0:35:31.160 --> 0:35:35.560
<v Speaker 1>by Jigsaw, Billy, the puppet from the Saw series, And

0:35:35.600 --> 0:35:38.839
<v Speaker 1>there was a message there that would state that rather

0:35:38.880 --> 0:35:42.759
<v Speaker 1>than just a regular deadline, Jigsaw would delete files as

0:35:42.800 --> 0:35:45.520
<v Speaker 1>time passed, like every hour that passed would mean more

0:35:45.560 --> 0:35:49.640
<v Speaker 1>files deleted. So the longer you waited, the more information

0:35:49.640 --> 0:35:52.440
<v Speaker 1>you would lose. That gave that sense of urgency to

0:35:52.560 --> 0:35:57.280
<v Speaker 1>pay off the hackers. H And also if you turned

0:35:57.360 --> 0:36:01.320
<v Speaker 1>off your computer, it was even worse really, because the

0:36:01.360 --> 0:36:04.479
<v Speaker 1>next time you booted your computer, one thousand files would

0:36:04.520 --> 0:36:07.360
<v Speaker 1>be deleted from your computer. It was an incentive to

0:36:07.560 --> 0:36:11.560
<v Speaker 1>not turn your system off, um, because once you turn

0:36:11.600 --> 0:36:14.040
<v Speaker 1>it on again, you would lose a thousand times what

0:36:14.160 --> 0:36:18.800
<v Speaker 1>you would lose every hour. It's pretty evil. By fourteen,

0:36:19.280 --> 0:36:23.000
<v Speaker 1>hackers were designing locker based ransomware for Android systems, and

0:36:23.040 --> 0:36:26.840
<v Speaker 1>one of those was Saiping, which used fake Adobe Flash

0:36:26.960 --> 0:36:30.160
<v Speaker 1>update messages to commence users to install the malware that

0:36:30.200 --> 0:36:33.160
<v Speaker 1>would lock you out of your Android device until you

0:36:33.239 --> 0:36:37.000
<v Speaker 1>paid a two D dollar ransom using money packs. Those

0:36:37.000 --> 0:36:40.359
<v Speaker 1>are those prepaid charge cards. So what happened is when

0:36:40.360 --> 0:36:43.160
<v Speaker 1>you try to activate your phone, instead of getting the

0:36:43.320 --> 0:36:46.239
<v Speaker 1>screen to unlock your phone, you've got a message saying

0:36:46.280 --> 0:36:48.680
<v Speaker 1>you had to pay this amount of money uh in

0:36:48.800 --> 0:36:54.480
<v Speaker 1>money packs to this particular account or you would not

0:36:54.640 --> 0:36:58.400
<v Speaker 1>get access to your phone again. A similar piece of

0:36:58.520 --> 0:37:03.239
<v Speaker 1>ransomware was called Coal or ko l e R or

0:37:03.320 --> 0:37:06.279
<v Speaker 1>Color if you prefer, which claimed that the holder of

0:37:06.320 --> 0:37:09.600
<v Speaker 1>the phone was being investigated by law enforcement and then

0:37:09.640 --> 0:37:12.440
<v Speaker 1>they were being fined as a result. So this is

0:37:12.440 --> 0:37:15.440
<v Speaker 1>playing on people's fear, right Like if you send them

0:37:15.480 --> 0:37:18.600
<v Speaker 1>a message saying, hey, you're in trouble and unless you

0:37:19.000 --> 0:37:22.360
<v Speaker 1>follow this link, you're gonna go to jail, that gives

0:37:22.360 --> 0:37:25.279
<v Speaker 1>people a big incentive to try and figure out what's

0:37:25.320 --> 0:37:26.879
<v Speaker 1>going on. A lot of people are going to click

0:37:26.920 --> 0:37:30.960
<v Speaker 1>that link, not thinking that, hey, the FBI probably doesn't

0:37:30.960 --> 0:37:33.680
<v Speaker 1>reach out through websites to let you know that you're

0:37:33.719 --> 0:37:36.840
<v Speaker 1>in trouble. They probably come door to door for that

0:37:36.920 --> 0:37:40.040
<v Speaker 1>kind of thing. But uh, it's the sort of thing

0:37:40.040 --> 0:37:42.759
<v Speaker 1>that's meant to instill panic. And when we panic, we

0:37:42.840 --> 0:37:45.839
<v Speaker 1>make bad decisions. We make very quick decisions. We don't

0:37:46.200 --> 0:37:49.320
<v Speaker 1>think we don't use critical thinking. So that's the whole

0:37:50.360 --> 0:37:56.279
<v Speaker 1>method of attack in this type of ransomware. So this

0:37:56.320 --> 0:37:58.839
<v Speaker 1>one also added a nasty additional kick. It was a

0:37:58.880 --> 0:38:01.120
<v Speaker 1>locker worm type of all where that would then send

0:38:01.160 --> 0:38:04.360
<v Speaker 1>messages to anyone in the context list of a compromised device.

0:38:04.880 --> 0:38:07.279
<v Speaker 1>So if you got me with that, if you send

0:38:07.320 --> 0:38:10.120
<v Speaker 1>me a message saying, hey, we're the FBI and your

0:38:10.160 --> 0:38:12.960
<v Speaker 1>totes in trouble brow and I fell for it and

0:38:13.000 --> 0:38:16.080
<v Speaker 1>I clicked on it, then it would the malware would

0:38:16.080 --> 0:38:17.880
<v Speaker 1>not only lock me on my phone, it would go

0:38:18.000 --> 0:38:20.400
<v Speaker 1>through my contact list and send a message out to

0:38:20.560 --> 0:38:24.680
<v Speaker 1>everyone in my contact list with a similar message in

0:38:24.719 --> 0:38:28.000
<v Speaker 1>the hopes of catching even more people. So this way

0:38:28.040 --> 0:38:31.040
<v Speaker 1>you allow the virus to propagate across the network. All

0:38:31.040 --> 0:38:32.680
<v Speaker 1>you have to do is in fact a couple of

0:38:33.160 --> 0:38:35.960
<v Speaker 1>well connected people, and chances are you're going to see

0:38:36.000 --> 0:38:39.320
<v Speaker 1>a lot more infected devices as a resultant that becomes

0:38:39.320 --> 0:38:42.719
<v Speaker 1>like a ripple effect that keeps moving out from the source. Uh,

0:38:43.440 --> 0:38:46.480
<v Speaker 1>people who are savvy to it will ignore it, but

0:38:47.320 --> 0:38:51.240
<v Speaker 1>that doesn't help all the people who don't ignore it.

0:38:51.239 --> 0:38:55.000
<v Speaker 1>It's pretty nasty stuff though. By two thousand fifteen, enterprising

0:38:55.000 --> 0:38:58.799
<v Speaker 1>programmers began to create ransomware as a service or are

0:38:58.960 --> 0:39:01.480
<v Speaker 1>a a s now. These were the people who had

0:39:01.480 --> 0:39:04.879
<v Speaker 1>designed the tools that other folks would actually use. So

0:39:05.120 --> 0:39:09.160
<v Speaker 1>you might have programmers who have no desire to actually

0:39:09.280 --> 0:39:12.680
<v Speaker 1>use ransomware themselves. They're not directly going to put it

0:39:12.719 --> 0:39:16.200
<v Speaker 1>to use. Instead, they'll sell it to hackers who do

0:39:16.320 --> 0:39:18.799
<v Speaker 1>want to use it, but who don't have the ability

0:39:18.880 --> 0:39:23.880
<v Speaker 1>to program or design these algorithms or these types of malware,

0:39:24.880 --> 0:39:26.920
<v Speaker 1>and so you'd sell it for like a thousand to

0:39:26.960 --> 0:39:29.239
<v Speaker 1>three thousand dollars. There's a lot of money, but when

0:39:29.280 --> 0:39:32.239
<v Speaker 1>you factor into the account the fact that you can

0:39:32.280 --> 0:39:35.480
<v Speaker 1>demand five h bucks per locked computer, and if you're

0:39:35.520 --> 0:39:39.040
<v Speaker 1>hitting thousands of them, three thousand dollars is nothing. A

0:39:39.040 --> 0:39:44.040
<v Speaker 1>lot of these ransomware as a service providers also demand

0:39:44.120 --> 0:39:49.320
<v Speaker 1>a certain percentage of the profits, like ten, but still

0:39:49.400 --> 0:39:54.600
<v Speaker 1>you're still talking huge amounts of money, So it doesn't

0:39:54.600 --> 0:39:57.200
<v Speaker 1>take very many victims to play ball before you recapture

0:39:57.239 --> 0:40:01.279
<v Speaker 1>your costs, and it makes ransomware even more prevalent. One

0:40:01.400 --> 0:40:03.960
<v Speaker 1>ransomware attack that made headlines in the United States happened

0:40:04.000 --> 0:40:08.920
<v Speaker 1>on November That was the Friday following the US holiday

0:40:08.960 --> 0:40:12.360
<v Speaker 1>of Thanksgiving, which is also known as Black Friday. For

0:40:12.440 --> 0:40:15.319
<v Speaker 1>those who don't know what Black Friday is, that's a day.

0:40:15.320 --> 0:40:17.239
<v Speaker 1>It's called that because a lot of stores will open

0:40:17.320 --> 0:40:20.560
<v Speaker 1>up with special sales and it's all in an effort

0:40:20.600 --> 0:40:24.080
<v Speaker 1>to sell enough stuff to make an overall profit for

0:40:24.200 --> 0:40:26.400
<v Speaker 1>the end of the year, to go in the black.

0:40:26.800 --> 0:40:28.680
<v Speaker 1>As they say, if you're in the red, that means

0:40:28.680 --> 0:40:30.520
<v Speaker 1>that you're operating at a loss. If you're in the black,

0:40:30.560 --> 0:40:33.680
<v Speaker 1>you're operating at a profit. That's why it's called Black Friday. Well,

0:40:33.800 --> 0:40:36.040
<v Speaker 1>that's a very popular day for people to go out shopping,

0:40:36.080 --> 0:40:38.640
<v Speaker 1>and it means it's also a popular day to to

0:40:39.040 --> 0:40:44.279
<v Speaker 1>just get outside and travel. So the hackers had targeted

0:40:44.560 --> 0:40:48.920
<v Speaker 1>San Francisco's municipal transportation system also known as MUNI, M

0:40:49.000 --> 0:40:52.440
<v Speaker 1>You and I, and on that day they were able

0:40:52.480 --> 0:40:55.560
<v Speaker 1>to infect the ticketing and bus management system for MUNI

0:40:55.680 --> 0:40:59.560
<v Speaker 1>with a ransomware attack. They demanded one hundred bitcoin for

0:40:59.719 --> 0:41:05.520
<v Speaker 1>the antidote for the the key to decode everything uh

0:41:05.600 --> 0:41:08.760
<v Speaker 1>and at that time a hundred bitcoin was worth about

0:41:08.800 --> 0:41:13.560
<v Speaker 1>seventy three thousand dollars. But instead of paying the ransom,

0:41:13.719 --> 0:41:17.319
<v Speaker 1>MUNI decided to offer free rides to passengers while they

0:41:17.320 --> 0:41:20.439
<v Speaker 1>worked on a solution. So for two days you could

0:41:20.520 --> 0:41:23.239
<v Speaker 1>ride Muni absolutely free. You didn't have to have a

0:41:23.280 --> 0:41:26.319
<v Speaker 1>ticket or anything. You could just get on um. But

0:41:26.440 --> 0:41:29.480
<v Speaker 1>then once they were able to reboot the system and

0:41:29.520 --> 0:41:34.120
<v Speaker 1>restore from backup the it was back to normal operations.

0:41:34.520 --> 0:41:37.640
<v Speaker 1>So it was only a temporary downtime for Muni. It

0:41:37.680 --> 0:41:40.239
<v Speaker 1>was very you know, it was still damaging because that's

0:41:40.239 --> 0:41:44.920
<v Speaker 1>two days without any revenue, but it showed that the

0:41:44.960 --> 0:41:47.520
<v Speaker 1>city of San Francisco and Muni in particular, was not

0:41:47.640 --> 0:41:51.480
<v Speaker 1>willing to play ball by the hackers standards. Now, there

0:41:51.520 --> 0:41:54.320
<v Speaker 1>are dozens of other variations that have appeared over the years,

0:41:54.320 --> 0:41:57.279
<v Speaker 1>but I think it's a good time too now look

0:41:57.360 --> 0:42:00.160
<v Speaker 1>over at the want to Cry virus, because that is

0:42:00.280 --> 0:42:03.120
<v Speaker 1>the most recent version of ransomware as of the recording

0:42:03.120 --> 0:42:05.640
<v Speaker 1>of this episode, and I'm gonna jump right into that

0:42:05.760 --> 0:42:08.839
<v Speaker 1>topic right as when we take another break to thank

0:42:08.880 --> 0:42:21.840
<v Speaker 1>our sponsors. One of Cry is an aggressive, coordinated ransomware attack,

0:42:21.920 --> 0:42:26.399
<v Speaker 1>one of the biggest ransomware attacks in history, and it's

0:42:26.400 --> 0:42:29.960
<v Speaker 1>affected hundreds of thousands of computers, many of which are

0:42:30.040 --> 0:42:33.279
<v Speaker 1>part of the health care industry. Its main method of

0:42:33.320 --> 0:42:36.640
<v Speaker 1>compromising a machine is to exploit vulnerabilities that are in

0:42:36.680 --> 0:42:41.160
<v Speaker 1>an old build of the Service Message Block Protocol, which

0:42:41.239 --> 0:42:45.320
<v Speaker 1>is part of a larger block of protocols that Windows

0:42:45.320 --> 0:42:49.560
<v Speaker 1>machines used for file sharing. Specifically, the virus could attack

0:42:49.600 --> 0:42:54.280
<v Speaker 1>computers that had inbound SMB communications on ports one, nine

0:42:54.520 --> 0:42:57.000
<v Speaker 1>or four forty five, and then there were some later

0:42:57.120 --> 0:42:59.680
<v Speaker 1>variants that aimed at different ports, but the initial one

0:42:59.800 --> 0:43:03.239
<v Speaker 1>was looking at those two. All you have to do

0:43:03.960 --> 0:43:06.840
<v Speaker 1>to protect yourself against this, by the way, is updating

0:43:06.880 --> 0:43:10.239
<v Speaker 1>your computer to the latest Microsoft security patch. It removes

0:43:10.280 --> 0:43:15.839
<v Speaker 1>the vulnerability. Now, once the computer is infected, the malware

0:43:16.160 --> 0:43:19.680
<v Speaker 1>could sort of put out feelers across the local network.

0:43:19.800 --> 0:43:24.040
<v Speaker 1>So if this infected machine is on a local network

0:43:24.120 --> 0:43:27.720
<v Speaker 1>with other machines, it could then use that to send

0:43:27.719 --> 0:43:30.800
<v Speaker 1>the malware to the other devices on that local network,

0:43:30.840 --> 0:43:33.200
<v Speaker 1>so it could spread really fast. All it takes is

0:43:33.200 --> 0:43:36.480
<v Speaker 1>that one compromise device on a system to have it

0:43:36.600 --> 0:43:39.839
<v Speaker 1>spread throughout the entire system, and it made it particularly

0:43:39.960 --> 0:43:42.799
<v Speaker 1>dangerous for these interconnected devices that weren't up to date

0:43:42.840 --> 0:43:47.080
<v Speaker 1>on security patches. Now. Before it made its debut, Want

0:43:47.080 --> 0:43:49.600
<v Speaker 1>to Cry was published as part of a large group

0:43:49.640 --> 0:43:53.840
<v Speaker 1>of documents stolen from the n ess A by a

0:43:53.880 --> 0:43:56.960
<v Speaker 1>group of hackers. So among those documents was a list

0:43:57.000 --> 0:44:02.000
<v Speaker 1>of twenty three hacking tools that targeted indoors vulnerabilities. One

0:44:02.040 --> 0:44:05.560
<v Speaker 1>of those hacking tools was codenamed Eternal Blue, and that

0:44:05.719 --> 0:44:09.520
<v Speaker 1>is what would become Wanna Cry. So Wanna Cry started

0:44:09.520 --> 0:44:13.960
<v Speaker 1>off as an n S a identified and targeted vulnerability

0:44:14.160 --> 0:44:18.399
<v Speaker 1>in Windows operating systems. This raises some tricky questions about

0:44:18.440 --> 0:44:22.120
<v Speaker 1>intelligence agencies and how they intersect with computer vulnerabilities that

0:44:22.280 --> 0:44:25.160
<v Speaker 1>I will get to in just a moment. But nearly

0:44:25.200 --> 0:44:27.600
<v Speaker 1>a month went by without want to Cry becoming a

0:44:27.640 --> 0:44:30.640
<v Speaker 1>public menace. So it was released by this group of

0:44:30.640 --> 0:44:34.480
<v Speaker 1>hackers into the wild. Anyone who went to tour and

0:44:34.520 --> 0:44:38.760
<v Speaker 1>went to this particular site could or really file sharing

0:44:38.760 --> 0:44:42.839
<v Speaker 1>area could get hold of these documents. But for about

0:44:42.880 --> 0:44:46.040
<v Speaker 1>a month nothing really happened. Then on May twelve, two

0:44:46.040 --> 0:44:49.560
<v Speaker 1>thousand seventeen, at eight forty two a m. London time,

0:44:50.280 --> 0:44:52.239
<v Speaker 1>and I love how precise we can be with this,

0:44:52.840 --> 0:44:57.720
<v Speaker 1>the virus was unleashed and the first attacked attack lasted

0:44:57.760 --> 0:45:00.600
<v Speaker 1>for most of the day and it compromised hundreds of

0:45:00.600 --> 0:45:04.160
<v Speaker 1>thousands of machines. But it wasn't as bad as it

0:45:04.200 --> 0:45:07.320
<v Speaker 1>could have been because it got sidelined when a British

0:45:07.400 --> 0:45:11.560
<v Speaker 1>cybersecurity analyst found a u r L embedded in the

0:45:11.680 --> 0:45:15.479
<v Speaker 1>Wanna cry virus attack. That led them to a kill

0:45:15.560 --> 0:45:18.480
<v Speaker 1>switch for the virus. So this was something that the

0:45:18.520 --> 0:45:22.759
<v Speaker 1>hackers had built into the system, or really you could

0:45:22.840 --> 0:45:25.200
<v Speaker 1>argue the n S a built into the system so

0:45:25.239 --> 0:45:29.719
<v Speaker 1>that you could shut it off remotely. So they did.

0:45:29.920 --> 0:45:32.640
<v Speaker 1>They flipped the kill switch and it stopped the spread

0:45:32.719 --> 0:45:34.759
<v Speaker 1>of the virus right there, So it could have been

0:45:34.880 --> 0:45:37.640
<v Speaker 1>much worse than it was if it had left been

0:45:37.719 --> 0:45:41.680
<v Speaker 1>left unchecked. The hacking group that was responsible was called

0:45:41.680 --> 0:45:44.880
<v Speaker 1>the Shadow Brokers Um. They sent out a message on

0:45:44.960 --> 0:45:47.800
<v Speaker 1>May sixteenth claiming to have many more exploits for sale

0:45:47.840 --> 0:45:51.319
<v Speaker 1>if hackers wanted to subscribe to their services. So they

0:45:51.320 --> 0:45:54.120
<v Speaker 1>were saying, hey, you see how much mess we made

0:45:54.120 --> 0:45:56.080
<v Speaker 1>with want to cry? We have a whole lot more.

0:45:56.200 --> 0:46:00.480
<v Speaker 1>Just become a subscriber and then we'll share our tools

0:46:00.520 --> 0:46:04.520
<v Speaker 1>with you. Meanwhile, affected computers were causing huge headaches for

0:46:04.600 --> 0:46:07.680
<v Speaker 1>thousands of people in the UK. Several hospitals sent out

0:46:07.680 --> 0:46:12.040
<v Speaker 1>messages that some appointments and operations would be postponed while

0:46:12.360 --> 0:46:15.919
<v Speaker 1>they were working on fixing these compromise systems. They said,

0:46:15.920 --> 0:46:18.680
<v Speaker 1>it just wasn't safe. It was putting people's health at

0:46:18.800 --> 0:46:24.160
<v Speaker 1>risk to try and maintain appointments and operations without having

0:46:24.160 --> 0:46:28.239
<v Speaker 1>those computer systems in place. Experts were work working really

0:46:28.239 --> 0:46:30.960
<v Speaker 1>hard to restore systems from backups, but that's a pretty

0:46:30.960 --> 0:46:34.280
<v Speaker 1>slow process, and just the sheer number of affected computers

0:46:34.320 --> 0:46:38.719
<v Speaker 1>across multiple companies and multiple countries meant that there was

0:46:38.760 --> 0:46:42.600
<v Speaker 1>no coordinated effort. Right Like, you had all these individual

0:46:42.640 --> 0:46:46.359
<v Speaker 1>little islands that were affected by this virus, and each

0:46:46.400 --> 0:46:49.400
<v Speaker 1>one had to respond to it in its own way,

0:46:49.400 --> 0:46:53.080
<v Speaker 1>in its own time, So there was no coordinated, major

0:46:53.120 --> 0:46:56.480
<v Speaker 1>effort to overturn the virus. It was just pockets of

0:46:56.480 --> 0:47:00.000
<v Speaker 1>that throughout the world. The same was true for others

0:47:00.000 --> 0:47:04.480
<v Speaker 1>systems all over the world. In all, fifty countries were

0:47:04.480 --> 0:47:07.800
<v Speaker 1>affected by the Wanna cry virus. That being said, according

0:47:07.840 --> 0:47:10.759
<v Speaker 1>to zd net, despite the fact that the virus was

0:47:10.800 --> 0:47:15.520
<v Speaker 1>pretty widespread, only zero point one percent of the victims

0:47:15.560 --> 0:47:19.600
<v Speaker 1>have opted to pay the ransom. As of the zd

0:47:19.719 --> 0:47:22.600
<v Speaker 1>net report, the hackers had raised about a hundred eight

0:47:22.719 --> 0:47:26.440
<v Speaker 1>thousand dollars total, which, considering the size of the attack

0:47:26.480 --> 0:47:29.440
<v Speaker 1>and the number of systems that were compromised. Is actually

0:47:29.480 --> 0:47:32.640
<v Speaker 1>a pretty small amount of money. Hundred eight thousand dollars.

0:47:32.960 --> 0:47:34.960
<v Speaker 1>It's a lot of money to me, But if you're

0:47:35.000 --> 0:47:38.600
<v Speaker 1>talking about the payoff for a massive attack on that scale,

0:47:39.120 --> 0:47:41.400
<v Speaker 1>it's a fraction of what those hackers were hoping for.

0:47:41.560 --> 0:47:45.200
<v Speaker 1>I'm sure of that. Uh. Now here are some takeaways

0:47:45.640 --> 0:47:50.400
<v Speaker 1>from the Wanna Cry experience that I think are really important. First,

0:47:50.440 --> 0:47:52.680
<v Speaker 1>let's talk about the n s A. And I'm gonna

0:47:52.719 --> 0:47:55.880
<v Speaker 1>try and maintain my composure because I have very strong

0:47:55.960 --> 0:47:59.239
<v Speaker 1>feelings about this particular issue. So this is my own

0:47:59.239 --> 0:48:01.640
<v Speaker 1>personal opinion in This is not the opinion of how

0:48:01.680 --> 0:48:05.279
<v Speaker 1>stuff works. It's just Jonathan Strickland's opinion. I find it

0:48:05.440 --> 0:48:11.000
<v Speaker 1>unconscionable that an intelligence agency would identify and design an

0:48:11.040 --> 0:48:15.960
<v Speaker 1>exploit for a vulnerability in software rather than informing the

0:48:16.040 --> 0:48:20.280
<v Speaker 1>respective parties about the vulnerability. So, in other words, instead

0:48:20.280 --> 0:48:24.040
<v Speaker 1>of going to Microsoft and saying, hey, we we discovered

0:48:24.080 --> 0:48:26.759
<v Speaker 1>this vulnerability that's in your software. You should patch it

0:48:26.880 --> 0:48:29.160
<v Speaker 1>or else someone else might create an exploit for it,

0:48:29.400 --> 0:48:33.280
<v Speaker 1>they said, hey, there's a vulnerability in Windows. Let's create

0:48:33.320 --> 0:48:36.200
<v Speaker 1>our own exploit for it that we might end up

0:48:36.320 --> 0:48:40.040
<v Speaker 1>using for intelligence purposes. In the future. Never mind the

0:48:40.080 --> 0:48:45.200
<v Speaker 1>fact that this puts everyone at risk, as is evidenced

0:48:45.200 --> 0:48:47.440
<v Speaker 1>by the fact that the want to Cry virus is

0:48:47.440 --> 0:48:53.760
<v Speaker 1>an actual thing. So the company Microsoft had no knowledge

0:48:53.880 --> 0:48:57.239
<v Speaker 1>of this vulnerability. They weren't aware that it existed. It

0:48:57.320 --> 0:48:59.800
<v Speaker 1>wasn't until the shadow brokers published those n s A

0:49:00.000 --> 0:49:02.359
<v Speaker 1>hacking tools that Microsoft found out about it, and then

0:49:02.360 --> 0:49:06.360
<v Speaker 1>they got to work creating a security patch to cover

0:49:07.000 --> 0:49:09.680
<v Speaker 1>and change that exploit so that it wouldn't work anymore.

0:49:10.560 --> 0:49:12.680
<v Speaker 1>And then they made the security patch available, so if

0:49:12.680 --> 0:49:15.680
<v Speaker 1>you installed it, you were fine. Your security patch was

0:49:15.760 --> 0:49:19.320
<v Speaker 1>up to date. Then the at least the initial attack

0:49:19.360 --> 0:49:23.239
<v Speaker 1>of want to Cry wouldn't affect you because the vulnerability

0:49:23.280 --> 0:49:28.239
<v Speaker 1>had been patched up. So I say shame on the

0:49:28.360 --> 0:49:30.799
<v Speaker 1>n s A for identifying and then building a tool

0:49:30.840 --> 0:49:34.319
<v Speaker 1>to exploit such a vulnerability for their own purposes. As

0:49:34.360 --> 0:49:36.600
<v Speaker 1>we've seen this particular case, it can result in someone

0:49:36.680 --> 0:49:39.200
<v Speaker 1>else getting those same tools and using them to cause

0:49:39.239 --> 0:49:42.040
<v Speaker 1>a great deal of trouble. But it was also possible

0:49:42.680 --> 0:49:45.280
<v Speaker 1>that just by sitting on this information and not sharing

0:49:45.280 --> 0:49:48.000
<v Speaker 1>it with Microsoft, the n s A could have given

0:49:48.000 --> 0:49:51.640
<v Speaker 1>other parties the chance to discover that same weakness and

0:49:51.719 --> 0:49:54.839
<v Speaker 1>develop their own exploits for it, which would have been

0:49:54.840 --> 0:49:58.120
<v Speaker 1>even worse because Microsoft wouldn't have known about until after

0:49:58.160 --> 0:50:03.040
<v Speaker 1>people had been actively affected by that exploit. So, in

0:50:03.040 --> 0:50:05.480
<v Speaker 1>other words, even if the NSA had never had their

0:50:05.480 --> 0:50:08.640
<v Speaker 1>hacking tools stolen, let's say that the hackers never were

0:50:08.680 --> 0:50:11.560
<v Speaker 1>able to get hold of eternal Blue and turn it

0:50:11.560 --> 0:50:14.880
<v Speaker 1>into want to cry. Even if that had never happened,

0:50:15.120 --> 0:50:19.920
<v Speaker 1>someone still might have discovered that Microsoft vulnerability and exploited it. Meanwhile,

0:50:19.920 --> 0:50:21.920
<v Speaker 1>the n s A had known about it the whole time.

0:50:22.200 --> 0:50:25.840
<v Speaker 1>I really maintain that it was their responsibility to share

0:50:25.840 --> 0:50:30.480
<v Speaker 1>that information with Microsoft considering the potential for destruction. And

0:50:31.080 --> 0:50:34.879
<v Speaker 1>I find it really troubling that an intelligence agency can

0:50:34.920 --> 0:50:37.960
<v Speaker 1>act in such a way that puts hundreds of thousands

0:50:37.960 --> 0:50:40.640
<v Speaker 1>of computers and people, because we're talking about the health

0:50:40.680 --> 0:50:44.759
<v Speaker 1>care industry at risk. I don't know that any intelligence

0:50:44.840 --> 0:50:48.879
<v Speaker 1>is worth that. Again, that's my own personal opinion. So

0:50:49.760 --> 0:50:53.800
<v Speaker 1>that's the Jonathan bias to be perfectly blunt. But another

0:50:53.840 --> 0:50:57.600
<v Speaker 1>takeaway is that in order to practice good security, you

0:50:57.640 --> 0:51:01.360
<v Speaker 1>need to make sure your operating system is patched and current.

0:51:02.000 --> 0:51:05.000
<v Speaker 1>Now I'm just as guilty as other people at putting

0:51:05.040 --> 0:51:07.640
<v Speaker 1>off installing updates if you ever get that message like

0:51:07.680 --> 0:51:11.120
<v Speaker 1>you need to install some updates, chances are you've gotten

0:51:11.120 --> 0:51:14.080
<v Speaker 1>on the computer to do something specific and you don't

0:51:14.120 --> 0:51:17.120
<v Speaker 1>really want to put that off by installing updates. You

0:51:17.120 --> 0:51:19.200
<v Speaker 1>want to get to whatever it is you need to do,

0:51:19.880 --> 0:51:22.040
<v Speaker 1>and so you might just put it off, and you

0:51:22.120 --> 0:51:25.279
<v Speaker 1>might keep putting it off until your computer forces you

0:51:25.320 --> 0:51:29.400
<v Speaker 1>to do it. But really the better plan is to

0:51:29.400 --> 0:51:32.719
<v Speaker 1>go ahead and install those security patches when you get them,

0:51:32.760 --> 0:51:34.880
<v Speaker 1>so that you can make sure that your computer is

0:51:34.920 --> 0:51:37.160
<v Speaker 1>not vulnerable to these sort of attacks. Plus, you know

0:51:37.200 --> 0:51:39.279
<v Speaker 1>what often means that your system is just running more

0:51:39.320 --> 0:51:44.960
<v Speaker 1>effectively if it's patched properly. So just be sure you're

0:51:45.080 --> 0:51:49.920
<v Speaker 1>installing legitimate updates to your system, not falling for some

0:51:50.040 --> 0:51:53.000
<v Speaker 1>fishing scam. Typically you can do it because if it's

0:51:53.080 --> 0:51:56.719
<v Speaker 1>the system itself that's prompting you to update, and you're

0:51:56.760 --> 0:52:00.320
<v Speaker 1>not in any browser or anything, you're probably pretty safe.

0:52:00.320 --> 0:52:02.759
<v Speaker 1>You're either pretty safe for your computer is already compromised,

0:52:02.760 --> 0:52:07.160
<v Speaker 1>in which case you know it's too late anyway. And finally,

0:52:07.480 --> 0:52:10.560
<v Speaker 1>back up your data. Use some sort of system to

0:52:10.640 --> 0:52:14.160
<v Speaker 1>back everything up, whether it's an external drive a cloud

0:52:14.200 --> 0:52:18.480
<v Speaker 1>based system, back up your information that way. If worst

0:52:18.520 --> 0:52:23.240
<v Speaker 1>comes to worst, if you cannot retrieve your information because

0:52:23.239 --> 0:52:27.240
<v Speaker 1>of a ransomware attack, you can bite the bullet, wipe

0:52:27.280 --> 0:52:31.560
<v Speaker 1>your system, install the operating system again, go to your backups,

0:52:31.600 --> 0:52:35.040
<v Speaker 1>and restore from your backups. Now, that probably means that

0:52:35.080 --> 0:52:38.160
<v Speaker 1>you're gonna lose some stuff, because chances are you've generated

0:52:38.200 --> 0:52:41.120
<v Speaker 1>some data since the last time you did a backup.

0:52:41.560 --> 0:52:45.239
<v Speaker 1>Unless you're doing backups very frequently, that's always going to

0:52:45.280 --> 0:52:48.400
<v Speaker 1>be the case. But it's better to lose some data

0:52:48.600 --> 0:52:52.200
<v Speaker 1>rather than lose everything or be forced to pay into

0:52:52.680 --> 0:52:57.320
<v Speaker 1>a ransomware attack, because every time someone pays the hackers,

0:52:58.120 --> 0:53:01.120
<v Speaker 1>you are sending the message this is a way you

0:53:01.160 --> 0:53:04.479
<v Speaker 1>can make money, and you're inspiring other people to take

0:53:04.560 --> 0:53:08.360
<v Speaker 1>the same pathway as the hackers did, whether they're designing

0:53:08.400 --> 0:53:11.640
<v Speaker 1>their own or using and off the shelf ransomware as

0:53:11.640 --> 0:53:18.520
<v Speaker 1>a service approach. So don't negotiate with the hackers. Instead,

0:53:19.440 --> 0:53:24.480
<v Speaker 1>use backups, patch your security, have up to date antivirus software,

0:53:24.560 --> 0:53:29.400
<v Speaker 1>running practice, good web browsing and email hygiene so that

0:53:29.480 --> 0:53:34.320
<v Speaker 1>you're not inviting these sort of attacks into your life.

0:53:34.960 --> 0:53:38.000
<v Speaker 1>And if you do that, you really minimize the chance

0:53:38.040 --> 0:53:41.280
<v Speaker 1>that you will fall victim to this kind of attack.

0:53:42.200 --> 0:53:45.040
<v Speaker 1>It no, no system is ever going to be perfect,

0:53:45.160 --> 0:53:47.360
<v Speaker 1>no system is ever going to be full proof, but

0:53:47.480 --> 0:53:52.520
<v Speaker 1>you reduce those odds drastically, and if you are backing

0:53:52.600 --> 0:53:56.840
<v Speaker 1>up your information, then you can at least you know again,

0:53:56.880 --> 0:54:01.320
<v Speaker 1>wipe your machine and start over again without worrying about

0:54:01.560 --> 0:54:06.560
<v Speaker 1>enabling some hackers into and inspiring future generations of hackers

0:54:06.719 --> 0:54:09.920
<v Speaker 1>to do the same thing further down the line. And

0:54:09.960 --> 0:54:12.759
<v Speaker 1>that's it. That's all I have to say about ransomware

0:54:12.760 --> 0:54:14.719
<v Speaker 1>and want to cry for this episode. I might end

0:54:14.800 --> 0:54:16.759
<v Speaker 1>up having to do another one in the future. The

0:54:16.800 --> 0:54:19.160
<v Speaker 1>story is still playing out as I record this episode,

0:54:19.160 --> 0:54:21.880
<v Speaker 1>so who knows. But if you guys have any suggestions

0:54:21.920 --> 0:54:24.440
<v Speaker 1>for future episodes of tech Stuff, whether it's a topic

0:54:24.440 --> 0:54:26.440
<v Speaker 1>you want me to cover, or someone you would like

0:54:26.480 --> 0:54:29.000
<v Speaker 1>me to interview, or perhaps a guest host you would

0:54:29.040 --> 0:54:31.880
<v Speaker 1>love to see on the show, send me a message.

0:54:32.200 --> 0:54:35.879
<v Speaker 1>The email address for the show is text stuff at

0:54:36.160 --> 0:54:39.160
<v Speaker 1>how stuff works dot com, where you can drop me

0:54:39.280 --> 0:54:41.799
<v Speaker 1>a line on Twitter or Facebook. The handle for the

0:54:41.800 --> 0:54:44.200
<v Speaker 1>show at both of those is text Stuff hs W.

0:54:44.760 --> 0:54:49.880
<v Speaker 1>And finally, you can watch this show stream live on Twitch.

0:54:50.239 --> 0:54:54.000
<v Speaker 1>I record I live stream all my recordings. You get

0:54:54.000 --> 0:54:58.280
<v Speaker 1>to see me make mistakes chat with folks in between segments.

0:54:58.640 --> 0:55:00.160
<v Speaker 1>So if you want to be part of that, want

0:55:00.160 --> 0:55:03.080
<v Speaker 1>to be part of the community, go to twitch dot

0:55:03.160 --> 0:55:06.319
<v Speaker 1>tv slash tech stuff. You'll be able to see the

0:55:06.320 --> 0:55:09.200
<v Speaker 1>show page and the schedule. And I would love for

0:55:09.239 --> 0:55:12.200
<v Speaker 1>you to join me someday in one of these podcast dreams.

0:55:12.200 --> 0:55:14.520
<v Speaker 1>I have a lot of fun chatting with everyone there

0:55:14.920 --> 0:55:18.200
<v Speaker 1>and just kind of geeking out over technology. So join me,

0:55:18.239 --> 0:55:22.280
<v Speaker 1>won't you, And I'll talk to you guys again really

0:55:22.320 --> 0:55:30.680
<v Speaker 1>soon for more on this and thousands of other topics

0:55:30.719 --> 0:55:41.640
<v Speaker 1>because it how staff works dot com