WEBVTT - Notorious Hackers

0:00:04.480 --> 0:00:12.440
<v Speaker 1>Welcome to Tech Stuff, a production from iHeartRadio. Hey thereon

0:00:12.600 --> 0:00:16.040
<v Speaker 1>Welcome to Tech Stuff. I'm your host, Jonathan Strickland. I'm

0:00:16.040 --> 0:00:19.599
<v Speaker 1>an executive producer with iHeart Podcasts and How the tech

0:00:19.640 --> 0:00:24.720
<v Speaker 1>are You? So I thought I would talk about hackers today,

0:00:25.280 --> 0:00:28.760
<v Speaker 1>and the word hacker these days is almost exclusively used

0:00:28.800 --> 0:00:33.159
<v Speaker 1>to describe people who, through one means or some other means,

0:00:33.240 --> 0:00:36.440
<v Speaker 1>find a way of infiltrating computer systems. But the term

0:00:36.520 --> 0:00:41.440
<v Speaker 1>hacker has a more broad definition. It really describes anyone

0:00:41.440 --> 0:00:45.839
<v Speaker 1>who's interested in taking stuff apart to learn how it works,

0:00:46.440 --> 0:00:50.000
<v Speaker 1>and maybe even putting it back together again so that

0:00:50.240 --> 0:00:53.640
<v Speaker 1>it does something it wasn't intended to do when it

0:00:53.720 --> 0:00:57.480
<v Speaker 1>was built originally. Now that thing might be a computer

0:00:58.000 --> 0:01:01.800
<v Speaker 1>or a mobile device, it might be a system. Hacking

0:01:02.200 --> 0:01:04.400
<v Speaker 1>can mean lots of different stuff. I mean, that's where

0:01:04.400 --> 0:01:07.520
<v Speaker 1>we get things like life hacks, which often end up

0:01:07.520 --> 0:01:10.040
<v Speaker 1>not being hacks at all. There's some life hacks out

0:01:10.080 --> 0:01:13.440
<v Speaker 1>there that I think we're just jokes that then were

0:01:13.520 --> 0:01:17.880
<v Speaker 1>spread sincerely by other people, because y'all, it doesn't make

0:01:17.920 --> 0:01:21.080
<v Speaker 1>any sense to just to take the top of a

0:01:21.080 --> 0:01:23.720
<v Speaker 1>squirt bottle off and invert it to turn it into

0:01:23.760 --> 0:01:26.520
<v Speaker 1>a funnel that that hole at the bottom is way

0:01:26.560 --> 0:01:28.920
<v Speaker 1>too small for that anyway, you know what I mean.

0:01:29.200 --> 0:01:33.280
<v Speaker 1>But sometimes people just want to figure out how something

0:01:33.319 --> 0:01:35.560
<v Speaker 1>works and taking it apart is the best way to

0:01:35.560 --> 0:01:37.160
<v Speaker 1>do it. Or maybe they want to figure out how

0:01:37.200 --> 0:01:40.920
<v Speaker 1>to manipulate whatever it is in order to unlock its

0:01:40.959 --> 0:01:45.319
<v Speaker 1>full potential. Like there are computers out there that have

0:01:45.560 --> 0:01:49.240
<v Speaker 1>certain clock speeds that's essentially how fast the processor is

0:01:49.280 --> 0:01:54.080
<v Speaker 1>able to complete operations per second, and often there are

0:01:54.280 --> 0:01:58.280
<v Speaker 1>limiters placed on the clock speed, and if you figure

0:01:58.320 --> 0:02:00.880
<v Speaker 1>out how to remove those limitters, you can make your

0:02:00.880 --> 0:02:05.480
<v Speaker 1>computer operate a lot faster. This has trade offs. It

0:02:05.760 --> 0:02:09.560
<v Speaker 1>usually means more power consumption and more heat generated and

0:02:09.600 --> 0:02:13.320
<v Speaker 1>potentially can actually damage your machine. But that's one example, right,

0:02:13.360 --> 0:02:17.560
<v Speaker 1>you can unlock the full potential of your computer something

0:02:17.560 --> 0:02:23.200
<v Speaker 1>that was intentionally restricted from operating at full capacity. Or

0:02:23.360 --> 0:02:25.760
<v Speaker 1>maybe you just want to figure out how to use

0:02:25.800 --> 0:02:29.440
<v Speaker 1>a paid service for free. The phone freakers of the

0:02:29.520 --> 0:02:32.440
<v Speaker 1>nineteen seventies fall into that category. These are folks who

0:02:32.440 --> 0:02:35.919
<v Speaker 1>found ways to manipulate the plain old telephone system or pots,

0:02:36.400 --> 0:02:38.520
<v Speaker 1>so that they could do stuff like make free long

0:02:38.560 --> 0:02:41.519
<v Speaker 1>distance phone calls. They did it with all sorts of

0:02:41.520 --> 0:02:46.960
<v Speaker 1>different ways, mostly by producing specific tones into a telephone

0:02:47.000 --> 0:02:49.839
<v Speaker 1>and then being able to make free phone calls. Good

0:02:49.840 --> 0:02:53.040
<v Speaker 1>old capt'n Crunch used to do that using a whistle

0:02:53.280 --> 0:02:56.640
<v Speaker 1>from a capt'n crunch box. But over time, the world

0:02:56.720 --> 0:02:59.000
<v Speaker 1>at large has started to use the word hacker to

0:02:59.080 --> 0:03:02.080
<v Speaker 1>mean someone attempt to gain a legal access to a

0:03:02.160 --> 0:03:05.919
<v Speaker 1>computer system, either in order to snoop around or create

0:03:05.960 --> 0:03:08.880
<v Speaker 1>a means to infiltrate the system whenever they want by

0:03:08.880 --> 0:03:12.760
<v Speaker 1>putting in a back door, or steal information from someone,

0:03:12.960 --> 0:03:15.960
<v Speaker 1>or inject malware into a system, or some combination of

0:03:16.000 --> 0:03:18.840
<v Speaker 1>all of these things. So today I thought we'd chat

0:03:18.880 --> 0:03:23.440
<v Speaker 1>about three notorious hackers. Actually that's not even true. Two

0:03:23.520 --> 0:03:27.880
<v Speaker 1>notorious hackers and one hacker conglomerate. So I decided to

0:03:27.960 --> 0:03:30.600
<v Speaker 1>raid a list that was created by Kasperski Labs. That's

0:03:30.639 --> 0:03:33.720
<v Speaker 1>a Russian computer security company that's had a pretty rough

0:03:33.760 --> 0:03:36.440
<v Speaker 1>go of it as of late due to being based

0:03:36.480 --> 0:03:39.520
<v Speaker 1>in Russia. Here in the United States, essentially they've been

0:03:39.880 --> 0:03:44.200
<v Speaker 1>banned from being used in various agencies and companies. But

0:03:44.480 --> 0:03:49.080
<v Speaker 1>Kaspersky has a very long history with cybersecurity, and I'm

0:03:49.120 --> 0:03:53.760
<v Speaker 1>going to start with number two on the Kaspersky list,

0:03:53.960 --> 0:03:56.440
<v Speaker 1>because it's not so much as a person as it

0:03:56.480 --> 0:03:59.560
<v Speaker 1>is a collective. This is that conglomeration I was talking

0:03:59.600 --> 0:04:03.160
<v Speaker 1>about now. It is not unusual for hackers to form

0:04:03.440 --> 0:04:07.280
<v Speaker 1>loose collectives. That happens a lot. Some hackers might belong

0:04:07.360 --> 0:04:12.040
<v Speaker 1>to more than one collective, and they might share resources

0:04:12.080 --> 0:04:17.039
<v Speaker 1>and motivations and goals. But one very very loose group,

0:04:17.480 --> 0:04:20.240
<v Speaker 1>and it's not just hackers, but hackers make up a

0:04:20.279 --> 0:04:22.960
<v Speaker 1>good number of them. It's a group that's caused headaches

0:04:23.000 --> 0:04:27.400
<v Speaker 1>for numerous targets for more than twenty years. Now. Is Anonymous,

0:04:27.800 --> 0:04:31.840
<v Speaker 1>as in that's what they're called big A Anonymous. I'm

0:04:31.880 --> 0:04:35.360
<v Speaker 1>not sure if the association is as strong as it

0:04:35.640 --> 0:04:39.920
<v Speaker 1>once was, like in the two thousand teens. But when

0:04:39.960 --> 0:04:42.200
<v Speaker 1>I think of Anonymous, the image that always comes to

0:04:42.240 --> 0:04:46.520
<v Speaker 1>my mind is a Guy Fawkes mask. That's really kind

0:04:46.560 --> 0:04:48.880
<v Speaker 1>of emerged in around two thousand and eight. Really, several

0:04:48.920 --> 0:04:53.320
<v Speaker 1>folks claiming to represent Anonymous have worn such masks, particularly

0:04:53.360 --> 0:04:55.360
<v Speaker 1>in the early days, like that became kind of a

0:04:55.400 --> 0:04:58.599
<v Speaker 1>symbol for the group. I don't know that it's as

0:04:58.800 --> 0:05:02.320
<v Speaker 1>strongly associated with them these days, honestly, but they grew

0:05:02.520 --> 0:05:07.000
<v Speaker 1>out of the online image based forum four Chan, which

0:05:07.560 --> 0:05:12.040
<v Speaker 1>has spawned many things terrible and otherwise over the years,

0:05:12.200 --> 0:05:15.520
<v Speaker 1>mostly terrible. If I'm being honest, A lot of terrible

0:05:15.520 --> 0:05:18.400
<v Speaker 1>stuff came out of four Chan. The origins of anonymous

0:05:18.440 --> 0:05:22.039
<v Speaker 1>were humble and juvenile. Some folks on four Chan would

0:05:22.120 --> 0:05:25.640
<v Speaker 1>meet in various virtual spaces in order to coordinate efforts

0:05:25.760 --> 0:05:30.520
<v Speaker 1>to torment various online communities through the age old practice

0:05:30.560 --> 0:05:35.200
<v Speaker 1>of trolling. So they were essentially just creating conflict online

0:05:35.440 --> 0:05:37.800
<v Speaker 1>for the lulls, and that was it, Like, that was

0:05:37.839 --> 0:05:42.400
<v Speaker 1>their goal, get some amusement by making other people really mad,

0:05:42.880 --> 0:05:46.120
<v Speaker 1>and they often like to aim at online communities that

0:05:46.160 --> 0:05:49.279
<v Speaker 1>were catering to kids. You know, some folks just like

0:05:49.320 --> 0:05:53.000
<v Speaker 1>to watch the world burn. Honestly, making people mad is

0:05:53.040 --> 0:05:56.760
<v Speaker 1>not hard to do, right, It's a pretty easy thing.

0:05:56.880 --> 0:06:00.000
<v Speaker 1>I guess the thrill was having, you know, this big

0:06:00.200 --> 0:06:04.080
<v Speaker 1>impact on someone's mentality, and that that was the thrill.

0:06:04.560 --> 0:06:06.240
<v Speaker 1>But I would argue you should just raise the bar

0:06:06.320 --> 0:06:09.479
<v Speaker 1>a little bit, like, yeah, you can make people angry,

0:06:09.520 --> 0:06:11.680
<v Speaker 1>but that's not very hard to do for most folks,

0:06:11.920 --> 0:06:15.200
<v Speaker 1>So why not set yourself a really challenging goal, like

0:06:15.279 --> 0:06:19.000
<v Speaker 1>make people happy. That's a lot harder to do. Anyway,

0:06:19.279 --> 0:06:22.320
<v Speaker 1>from about two thousand and three to two thousand and seven,

0:06:22.400 --> 0:06:24.880
<v Speaker 1>Anonymous wasn't really much more than just a bunch of

0:06:24.920 --> 0:06:29.360
<v Speaker 1>folks trying to get their kicks by ticking off other people. However,

0:06:29.800 --> 0:06:33.760
<v Speaker 1>starting in two thousand and seven, the group began to evolve,

0:06:34.080 --> 0:06:38.480
<v Speaker 1>partly due to a misapprehension the media had about the

0:06:38.680 --> 0:06:43.679
<v Speaker 1>very loose association of trolls. So media reports were starting

0:06:43.720 --> 0:06:46.919
<v Speaker 1>to suggest that Anonymous was far more organized than what

0:06:47.000 --> 0:06:51.080
<v Speaker 1>it was, and far more motivated, and most importantly, way

0:06:51.080 --> 0:06:56.680
<v Speaker 1>more capable of causing harm than the group actually was.

0:06:57.120 --> 0:07:00.720
<v Speaker 1>This included footage that would have like stock images of

0:07:00.920 --> 0:07:04.920
<v Speaker 1>cars exploding and stuff, implying that Anonymous was capable of

0:07:05.160 --> 0:07:08.960
<v Speaker 1>real world violence. And this is kind of like if

0:07:09.640 --> 0:07:12.480
<v Speaker 1>a reporter saw a bunch of kids playing cops and

0:07:12.560 --> 0:07:16.840
<v Speaker 1>robbers and then did a feature about how this dangerous

0:07:16.960 --> 0:07:20.000
<v Speaker 1>gang was taking over the city. It was a lot

0:07:20.000 --> 0:07:23.720
<v Speaker 1>of exaggeration. The pranksters at Anonymous found this to be

0:07:23.840 --> 0:07:27.520
<v Speaker 1>pretty darn amusing, and also it was stroking their egos right, Like,

0:07:27.800 --> 0:07:32.000
<v Speaker 1>if you are mostly a low level troublemaker, but you're

0:07:32.040 --> 0:07:35.440
<v Speaker 1>being portrayed as like some sort of mastermind, that's really

0:07:35.480 --> 0:07:39.040
<v Speaker 1>gonna stroke your ego. In another case, the Canadian Security

0:07:39.080 --> 0:07:42.200
<v Speaker 1>Intelligence Service reached out to one member of the group,

0:07:42.240 --> 0:07:45.240
<v Speaker 1>a guy named Aubrey Cottle, and they thought Coddle could

0:07:45.240 --> 0:07:50.880
<v Speaker 1>help disrupt online terrorist organizations, essentially infiltrate and then disrupt

0:07:51.160 --> 0:07:54.640
<v Speaker 1>these terrorist cells online. And Cottle was like, I don't

0:07:54.640 --> 0:07:57.000
<v Speaker 1>know where they got the idea that I could do this.

0:07:57.400 --> 0:08:02.360
<v Speaker 1>I mean, I'm just stirring up, you know, mess. We'll

0:08:02.360 --> 0:08:05.160
<v Speaker 1>say this is a family friendly show, after all, will

0:08:05.160 --> 0:08:08.680
<v Speaker 1>stir stuff up online. I'm not really here to break

0:08:08.760 --> 0:08:12.040
<v Speaker 1>up terrorist cells. But having folks think you're a much

0:08:12.080 --> 0:08:14.560
<v Speaker 1>bigger deal than you are can be kind of fun.

0:08:14.840 --> 0:08:17.880
<v Speaker 1>And it got some folks thinking about actually using their

0:08:17.960 --> 0:08:21.200
<v Speaker 1>perceived power to do something more than just riling folks

0:08:21.280 --> 0:08:23.600
<v Speaker 1>up on the Internet, so it kind of became a

0:08:23.640 --> 0:08:29.720
<v Speaker 1>bit of a self fulfilling prophecy. This grew into Project Chenology,

0:08:30.280 --> 0:08:34.360
<v Speaker 1>in which the group targeted the Church of Scientology. So

0:08:34.800 --> 0:08:38.160
<v Speaker 1>Church of Scientology, that's a whole topic that is beyond

0:08:38.280 --> 0:08:41.800
<v Speaker 1>the scope of tech stuff, but has a long history

0:08:42.000 --> 0:08:47.920
<v Speaker 1>of some really manipulative and oppressive policies that pull people

0:08:47.960 --> 0:08:52.800
<v Speaker 1>into the church, keep them there, and exploit them extensively.

0:08:53.400 --> 0:08:56.760
<v Speaker 1>So this is the time when the Guy Fawkes masks

0:08:56.880 --> 0:08:59.679
<v Speaker 1>started showing up. If you don't know who Guy Fawkes was,

0:09:00.400 --> 0:09:05.960
<v Speaker 1>he was one of several terrorists really in the seventeenth

0:09:05.960 --> 0:09:10.880
<v Speaker 1>century who planned to blow up Parliament and potentially assassinate

0:09:11.000 --> 0:09:15.680
<v Speaker 1>the King of England. But their plot was uncovered and

0:09:16.200 --> 0:09:20.280
<v Speaker 1>the members of the plot were put to death, including

0:09:20.520 --> 0:09:23.040
<v Speaker 1>Guy Fawx himself, who was not the leader of the group,

0:09:23.120 --> 0:09:26.160
<v Speaker 1>but was a member of it and has largely been

0:09:26.200 --> 0:09:30.839
<v Speaker 1>associated with that and then was appropriated by Alan Moore

0:09:31.000 --> 0:09:34.400
<v Speaker 1>in his v for Vendetta graphic novel, and so he's

0:09:34.400 --> 0:09:38.880
<v Speaker 1>sort of become a symbol of anti authoritarian practices, like

0:09:38.960 --> 0:09:43.000
<v Speaker 1>it's like a vigilante sort of thing. So members would

0:09:43.000 --> 0:09:46.040
<v Speaker 1>be wearing Guy Fawkes masks and show up in videos

0:09:46.280 --> 0:09:48.640
<v Speaker 1>and speak out against the church. Usually they would have

0:09:48.679 --> 0:09:52.040
<v Speaker 1>their voice distorted in the video as well. Members also

0:09:52.080 --> 0:09:54.640
<v Speaker 1>got access to web pages that belonged to the Church

0:09:54.640 --> 0:09:59.080
<v Speaker 1>of Scientology. They were able to get administrator access to

0:09:59.120 --> 0:10:02.360
<v Speaker 1>these pages and then defaced the web pages. They also

0:10:02.480 --> 0:10:05.840
<v Speaker 1>launched d DOS attacks on the organization, and they organized

0:10:05.920 --> 0:10:10.760
<v Speaker 1>in person protests outside of Scientology properties. Now in case

0:10:10.760 --> 0:10:13.720
<v Speaker 1>you're not familiar with the term d DOS, that stands

0:10:13.720 --> 0:10:17.640
<v Speaker 1>for distributed denial of service. Now, essentially a d DOS

0:10:17.679 --> 0:10:21.559
<v Speaker 1>attack is all about overwhelming a target. So typically we're

0:10:21.559 --> 0:10:25.240
<v Speaker 1>talking about a web server, so machines are programmed to

0:10:25.360 --> 0:10:29.400
<v Speaker 1>follow specific routines. The way web servers work is that

0:10:29.720 --> 0:10:33.720
<v Speaker 1>they receive requests from clients. A client is just someone

0:10:33.720 --> 0:10:37.960
<v Speaker 1>else's computer tech technically computer browser, and the server responds

0:10:38.000 --> 0:10:40.960
<v Speaker 1>by sending data to the client. So, if you want

0:10:40.960 --> 0:10:43.400
<v Speaker 1>to visit a web page and you type the URL

0:10:43.400 --> 0:10:46.160
<v Speaker 1>in your browser bar, your browser, which is the client

0:10:46.200 --> 0:10:49.040
<v Speaker 1>in this case, sends a request out over the internet.

0:10:49.040 --> 0:10:52.720
<v Speaker 1>This request eventually routes to the appropriate web server, which

0:10:52.760 --> 0:10:55.800
<v Speaker 1>then responds to the request and sends back a web

0:10:55.840 --> 0:10:58.040
<v Speaker 1>page so that you can view it in your browser. Well,

0:10:58.040 --> 0:10:59.880
<v Speaker 1>in order for this to work, the server can't just

0:11:00.120 --> 0:11:03.720
<v Speaker 1>ignore incoming requests. You know. Imagine you're on your browser

0:11:03.800 --> 0:11:06.080
<v Speaker 1>but you type in a URL for a web page

0:11:06.120 --> 0:11:08.960
<v Speaker 1>and nothing happens, or maybe you get an error message

0:11:09.000 --> 0:11:12.440
<v Speaker 1>because the server has decided to deny your request for

0:11:12.520 --> 0:11:15.520
<v Speaker 1>whatever reason. In most cases, the server is more or

0:11:15.600 --> 0:11:19.800
<v Speaker 1>less compelled to answer every single request. Well, you can

0:11:19.840 --> 0:11:22.640
<v Speaker 1>flip that and turn it into an attack because if

0:11:22.679 --> 0:11:26.040
<v Speaker 1>you send countless waves or requests to a web server,

0:11:26.520 --> 0:11:29.400
<v Speaker 1>then you can overwhelm that web server so it can't

0:11:29.400 --> 0:11:32.600
<v Speaker 1>do anything useful. Like other people who are just legitimately

0:11:32.640 --> 0:11:35.600
<v Speaker 1>trying to access the server get timed out or denied

0:11:35.880 --> 0:11:40.319
<v Speaker 1>because it's too busy responding to all these ridiculous requests

0:11:40.360 --> 0:11:43.600
<v Speaker 1>that are flooding in. That's a denial of service attack. Now,

0:11:43.760 --> 0:11:48.160
<v Speaker 1>what makes a distributed denial service attack is when hackers

0:11:48.679 --> 0:11:53.120
<v Speaker 1>compromise other machines. Some hackers might compromise machines in order

0:11:53.120 --> 0:11:56.000
<v Speaker 1>to access data on the affected devices, but others are

0:11:56.000 --> 0:11:58.240
<v Speaker 1>just happy to siphon away a little bit of computing

0:11:58.280 --> 0:12:02.679
<v Speaker 1>power and some connectivity, and they turned these affected computers

0:12:02.720 --> 0:12:06.000
<v Speaker 1>into bots. And then you get an army of these bots,

0:12:06.040 --> 0:12:09.400
<v Speaker 1>and you direct the army to send countless messages to

0:12:09.760 --> 0:12:14.079
<v Speaker 1>your target web server, and the hacker meanwhile remains shielded

0:12:14.160 --> 0:12:16.760
<v Speaker 1>because they're not the ones sending the messages to the

0:12:16.800 --> 0:12:19.640
<v Speaker 1>target server. Their army of bots is doing it. That

0:12:19.880 --> 0:12:23.040
<v Speaker 1>is a distributed denial of service attack. So Anonymous made

0:12:23.240 --> 0:12:26.560
<v Speaker 1>liberal use of that tactic, particularly in the early days,

0:12:26.559 --> 0:12:29.400
<v Speaker 1>but then throughout its history they've held de dos attacks

0:12:29.440 --> 0:12:33.000
<v Speaker 1>against different targets, and from that point forward, Anonymous became

0:12:33.040 --> 0:12:37.120
<v Speaker 1>more associated with hactivism than with trolling, though a lot

0:12:37.120 --> 0:12:40.720
<v Speaker 1>of the activist activity borrowed liberally from the trolling days,

0:12:40.760 --> 0:12:43.000
<v Speaker 1>and once in a while they would just engage in

0:12:43.000 --> 0:12:46.200
<v Speaker 1>trolling as well. The group has targeted numerous individuals and

0:12:46.360 --> 0:12:51.080
<v Speaker 1>organizations for lots of different reasons. Generally speaking, Anonymous tends

0:12:51.120 --> 0:12:56.120
<v Speaker 1>to follow a slightly leftist approach with very strong libertarian principles. Now,

0:12:56.160 --> 0:12:59.800
<v Speaker 1>not all of their targets have been large organized bastions

0:12:59.840 --> 0:13:04.840
<v Speaker 1>of authoritarianism. For example, McKay hatch wasn't exactly an institution.

0:13:05.000 --> 0:13:07.080
<v Speaker 1>McKay hatch was a kid who was running a website

0:13:07.120 --> 0:13:10.679
<v Speaker 1>called The No Cussing Club, and members of Anonymous doxed

0:13:10.720 --> 0:13:13.320
<v Speaker 1>him and launched a campaign of harassment. So I guess

0:13:13.320 --> 0:13:16.600
<v Speaker 1>their love of cussing was just too damn strong. But

0:13:16.760 --> 0:13:21.640
<v Speaker 1>other targets were definitely more high profile. Anonymous was generally

0:13:21.679 --> 0:13:24.400
<v Speaker 1>speaking on the side of wiki leaks and carried out

0:13:24.440 --> 0:13:27.680
<v Speaker 1>a few attacks on various government servers around the world

0:13:27.800 --> 0:13:31.880
<v Speaker 1>in protest of the persecution of people like whistleblower Chelsea Manning,

0:13:31.960 --> 0:13:35.720
<v Speaker 1>for example. Many members of Anonymous have supported social causes

0:13:35.840 --> 0:13:39.240
<v Speaker 1>like Occupy Wall Street and Black Lives Matter movement, but

0:13:39.320 --> 0:13:43.280
<v Speaker 1>the group is not formally organized, and generally anyone can

0:13:43.320 --> 0:13:46.040
<v Speaker 1>take action in the name of Anonymous, but the rest

0:13:46.040 --> 0:13:49.240
<v Speaker 1>of the group might distance themselves from those kinds of people.

0:13:49.440 --> 0:13:52.120
<v Speaker 1>For example, in the early days of anonymous activism, a

0:13:52.160 --> 0:13:55.760
<v Speaker 1>group claiming to be anonymous got access to the web

0:13:55.800 --> 0:14:01.319
<v Speaker 1>page for the SOHH or Support Online Hip Hop news website.

0:14:01.400 --> 0:14:04.440
<v Speaker 1>The hackers deface the website, and they included the use

0:14:04.480 --> 0:14:07.680
<v Speaker 1>of stuff like racial slurs and stereotypes, which is pretty

0:14:07.760 --> 0:14:11.400
<v Speaker 1>darn tacky. The attackers claim to be anonymous, though the

0:14:11.440 --> 0:14:13.480
<v Speaker 1>group as a whole, as far as I can tell,

0:14:13.559 --> 0:14:16.920
<v Speaker 1>made no such claim. And in other cases you might

0:14:17.000 --> 0:14:21.040
<v Speaker 1>have a member who convinces a subset of Anonymous the

0:14:21.120 --> 0:14:24.480
<v Speaker 1>anonymous community to work together towards some goal, and they

0:14:24.480 --> 0:14:27.360
<v Speaker 1>can create a little splinter group or spinoff group. It's

0:14:27.440 --> 0:14:31.440
<v Speaker 1>very loosey goosey. The hacking skills and anonymous also run

0:14:31.480 --> 0:14:35.680
<v Speaker 1>the spectrum. There are undoubtedly some accomplished hackers among the group,

0:14:36.040 --> 0:14:38.920
<v Speaker 1>while others fall more into the realm of script kitties.

0:14:38.960 --> 0:14:41.400
<v Speaker 1>These are folks who have downloaded tools that do most

0:14:41.440 --> 0:14:44.120
<v Speaker 1>of the work for them. But because membership is fluid

0:14:44.360 --> 0:14:48.520
<v Speaker 1>and you know Anonymous, I can't really give more specifics

0:14:48.560 --> 0:14:51.760
<v Speaker 1>than that. I can talk a bit more about Anonymous

0:14:51.760 --> 0:14:54.080
<v Speaker 1>before we move on to our next hacker. But before

0:14:54.120 --> 0:14:56.400
<v Speaker 1>we do that, let's take a quick break to thank

0:14:56.440 --> 0:15:07.920
<v Speaker 1>our sponsors. So we're back. I've got a little bit

0:15:07.920 --> 0:15:10.360
<v Speaker 1>more to say about Anonymous before we move on. Some

0:15:10.520 --> 0:15:13.880
<v Speaker 1>high profile operations that are at least suspected to be

0:15:13.920 --> 0:15:16.880
<v Speaker 1>the work of Anonymous, because again, the loose organization of

0:15:16.920 --> 0:15:19.680
<v Speaker 1>the group means that some operations could be the work

0:15:19.760 --> 0:15:22.680
<v Speaker 1>of a subset or a splinter group of the overall

0:15:22.720 --> 0:15:26.240
<v Speaker 1>group and not reflective of the group as a whole.

0:15:26.400 --> 0:15:30.520
<v Speaker 1>Because of its loose association, it's really hard to attribute

0:15:30.560 --> 0:15:33.880
<v Speaker 1>anything to the overall group, Like even something that might

0:15:33.960 --> 0:15:36.960
<v Speaker 1>have the support of most members of Anonymous might not

0:15:37.120 --> 0:15:41.880
<v Speaker 1>have total support. So the nature of Anonymous itself makes

0:15:41.920 --> 0:15:48.040
<v Speaker 1>it difficult to use any definitive phrases. But Operation Darknet

0:15:48.600 --> 0:15:52.640
<v Speaker 1>was one that Anonymous engaged in. Anonymous went after sites

0:15:52.640 --> 0:15:56.280
<v Speaker 1>that hosted child pornography. They infiltrated some of those sites.

0:15:56.320 --> 0:16:01.400
<v Speaker 1>They skimmed user information and published user information online, essentially

0:16:01.440 --> 0:16:05.280
<v Speaker 1>revealing people who were frequently going to these child pornography sites,

0:16:05.320 --> 0:16:07.840
<v Speaker 1>and they called for law enforcement to take action against

0:16:07.880 --> 0:16:10.880
<v Speaker 1>the pornographers. So that was one of those cases where

0:16:10.920 --> 0:16:15.000
<v Speaker 1>Anonymous said it was taking up action to defend the

0:16:15.080 --> 0:16:19.600
<v Speaker 1>defenseless and to call for justice against people who were

0:16:19.840 --> 0:16:25.600
<v Speaker 1>committing really terrible acts against vulnerable folks, in this case children.

0:16:25.960 --> 0:16:30.600
<v Speaker 1>In twenty twelve, Operation Russia targeted several high profile Russian

0:16:30.600 --> 0:16:33.640
<v Speaker 1>officials and exposed a scheme in which these officials were

0:16:33.640 --> 0:16:37.400
<v Speaker 1>apparently paying bloggers to promote pro Kremlin and more to

0:16:37.440 --> 0:16:43.120
<v Speaker 1>the point, pro putin propaganda. Operation Bahrain was actually not

0:16:43.280 --> 0:16:48.200
<v Speaker 1>targeting Bahrain directly, but Formula one. So why do that? Well,

0:16:48.280 --> 0:16:51.480
<v Speaker 1>at the time, the Arab Spring was in full bloom.

0:16:51.640 --> 0:16:56.240
<v Speaker 1>That was a series of protests and movements throughout the

0:16:56.280 --> 0:17:00.000
<v Speaker 1>Arab world in which citizens were protesting against various authorities,

0:17:00.440 --> 0:17:05.199
<v Speaker 1>government officials and regimes and agencies, and Formula one was

0:17:05.240 --> 0:17:09.440
<v Speaker 1>preparing for the twenty twelve Bahrain Grand Prix in cooperation

0:17:09.640 --> 0:17:13.000
<v Speaker 1>with the government, and Anonymous was siting with the anti

0:17:13.040 --> 0:17:17.560
<v Speaker 1>government protesters and viewed Formula one as participating in sportswashing,

0:17:17.760 --> 0:17:21.600
<v Speaker 1>that is, using a sporting event to spread government propaganda.

0:17:22.040 --> 0:17:25.600
<v Speaker 1>During the operation, Anonymous carried out DIDOS attacks against Formula

0:17:25.640 --> 0:17:29.280
<v Speaker 1>one and leaked information gathered during a data breach on

0:17:29.359 --> 0:17:33.399
<v Speaker 1>Formula one systems. In more recent years, Anonymous members have

0:17:33.480 --> 0:17:38.320
<v Speaker 1>participated in operations against Israel in protests for that country's

0:17:38.320 --> 0:17:42.879
<v Speaker 1>ongoing conflict with Palestinians, as well as an operation targeting

0:17:42.960 --> 0:17:46.960
<v Speaker 1>Russia for its ongoing war against Ukraine. And it's been

0:17:47.000 --> 0:17:50.640
<v Speaker 1>more than twenty years since a group of Internet trolls

0:17:50.760 --> 0:17:54.120
<v Speaker 1>started just causing grief online, and the group is still

0:17:54.160 --> 0:17:58.080
<v Speaker 1>active today, possibly because it is so hard to define.

0:17:58.160 --> 0:18:00.560
<v Speaker 1>I don't know that you could call it the same group.

0:18:00.640 --> 0:18:03.000
<v Speaker 1>In fact, I don't know how many people who were

0:18:03.080 --> 0:18:06.320
<v Speaker 1>part of Anonymous in the earliest days are still active

0:18:06.320 --> 0:18:09.520
<v Speaker 1>in the community today. I do think if we're going

0:18:09.600 --> 0:18:12.800
<v Speaker 1>to talk about Anonymous, one place to start is just

0:18:12.880 --> 0:18:17.960
<v Speaker 1>the group's own slogan. We are Anonymous, we are legion.

0:18:18.520 --> 0:18:24.880
<v Speaker 1>We do not forgive, we do not forget, expect us. Okay,

0:18:25.040 --> 0:18:29.560
<v Speaker 1>with that cheerful message, let's swap on over to a

0:18:29.600 --> 0:18:33.480
<v Speaker 1>different hacker, someone who was very much identified, someone who

0:18:33.520 --> 0:18:37.320
<v Speaker 1>was responsible both for committing several high profile, high impact

0:18:37.480 --> 0:18:40.520
<v Speaker 1>acts of theft and wirefraud as well as a guy

0:18:40.640 --> 0:18:45.320
<v Speaker 1>who helped take down other hackers. His name is Albert Gonzalez,

0:18:45.520 --> 0:18:49.000
<v Speaker 1>and he sometimes went by handles that included soup Nazi

0:18:49.480 --> 0:18:54.000
<v Speaker 1>as a Seinfeld reference or Kumba Johnny So. Gonzalez was

0:18:54.000 --> 0:18:57.040
<v Speaker 1>born in nineteen eighty one in Cuba and brought up

0:18:57.080 --> 0:18:59.719
<v Speaker 1>in the United States, and he was interested in computers

0:19:00.000 --> 0:19:03.160
<v Speaker 1>at a young age. According to a piece written by

0:19:03.280 --> 0:19:06.240
<v Speaker 1>James Verini in The New York Times magazine back in

0:19:06.400 --> 0:19:11.080
<v Speaker 1>twenty ten, an early hint that the young Albert Gonzalez

0:19:11.240 --> 0:19:13.760
<v Speaker 1>was a potential thorn in the side of the law

0:19:14.040 --> 0:19:16.840
<v Speaker 1>came in the nineteen nineties when it was discovered that

0:19:16.920 --> 0:19:20.320
<v Speaker 1>he had penetrated NASA's computer systems when he was just

0:19:20.600 --> 0:19:24.440
<v Speaker 1>fourteen years old. The FBI paid him a little visit

0:19:24.480 --> 0:19:28.560
<v Speaker 1>at school about that. Apparently he had developed a rather

0:19:28.800 --> 0:19:33.040
<v Speaker 1>distinct disdain for authority, and meanwhile, he and some friends

0:19:33.040 --> 0:19:37.680
<v Speaker 1>were fascinated with learning how various systems worked. Now he

0:19:37.760 --> 0:19:42.119
<v Speaker 1>was more interested in systems than in programming. He liked

0:19:42.200 --> 0:19:46.320
<v Speaker 1>learning how networks worked, and not just computer networks, but

0:19:46.400 --> 0:19:50.359
<v Speaker 1>like networks of people. He would probe at these different systems,

0:19:50.480 --> 0:19:52.520
<v Speaker 1>and often it didn't take very long for him to

0:19:52.560 --> 0:19:56.080
<v Speaker 1>find a vulnerability. So back in the early days of

0:19:56.119 --> 0:19:59.679
<v Speaker 1>the Internet, security protocols were very much a work in

0:19:59.760 --> 0:20:02.879
<v Speaker 1>pro and not everyone was on the same page. A

0:20:02.960 --> 0:20:08.199
<v Speaker 1>lot of people and companies had incredibly lacks security practices,

0:20:08.560 --> 0:20:11.200
<v Speaker 1>and you could think of that as just being a

0:20:12.560 --> 0:20:16.240
<v Speaker 1>common feature in the Internet, kind of like how the

0:20:16.240 --> 0:20:19.359
<v Speaker 1>web pages at that time almost all had the obligatory

0:20:19.520 --> 0:20:24.280
<v Speaker 1>under construction graphic posted somewhere on their web page. Now, Gonzales,

0:20:24.320 --> 0:20:27.480
<v Speaker 1>like I said, he wasn't really a coder a programmer.

0:20:27.560 --> 0:20:32.240
<v Speaker 1>He would rely on other hackers for building code instead.

0:20:32.480 --> 0:20:35.920
<v Speaker 1>He was just really good at understanding how systems worked

0:20:35.920 --> 0:20:39.320
<v Speaker 1>and then navigating through those systems and finding the valuable

0:20:39.359 --> 0:20:43.880
<v Speaker 1>information stored within them. He was also really adept at

0:20:43.920 --> 0:20:47.200
<v Speaker 1>social engineering. He was great at manipulating people to get

0:20:47.240 --> 0:20:50.400
<v Speaker 1>what he needed, whether that was a login password or

0:20:50.560 --> 0:20:54.199
<v Speaker 1>information about Wi Fi networks or whatever. He also was

0:20:54.280 --> 0:20:59.080
<v Speaker 1>reportedly a pretty serious drug user. Typically he relied on

0:20:59.160 --> 0:21:02.960
<v Speaker 1>stimulants like cocaine when he was pulling long hours while

0:21:02.960 --> 0:21:07.560
<v Speaker 1>infiltrating systems, and that would become a pretty big issue

0:21:07.560 --> 0:21:11.200
<v Speaker 1>for him. Among his go to activities would be sniffing

0:21:11.200 --> 0:21:15.360
<v Speaker 1>out credit card numbers either by finding a database belonging

0:21:15.440 --> 0:21:18.560
<v Speaker 1>to say, a business like a retailer, and then just

0:21:18.640 --> 0:21:21.359
<v Speaker 1>siphoning off numbers that were stored in there, because not

0:21:21.480 --> 0:21:24.840
<v Speaker 1>everyone stored their numbers and encrypted formats, which meant if

0:21:24.920 --> 0:21:27.480
<v Speaker 1>you had access to the database, you had access to numbers.

0:21:27.720 --> 0:21:30.199
<v Speaker 1>He also made friends with other hackers who specialized in

0:21:30.240 --> 0:21:34.720
<v Speaker 1>building programs specifically to skim credit card numbers, one of

0:21:34.760 --> 0:21:38.400
<v Speaker 1>those being Stephen Watt, who was sometimes known by handles

0:21:38.480 --> 0:21:42.920
<v Speaker 1>like Jim Jones or sometimes the Unix Terrorist. And as

0:21:42.960 --> 0:21:46.040
<v Speaker 1>a young adult, Gonzales joined a group of like minded

0:21:46.080 --> 0:21:50.960
<v Speaker 1>hackers that would call themselves the Shadow Crew, and it

0:21:51.000 --> 0:21:53.480
<v Speaker 1>was kind of like a forum for hackers, but not

0:21:53.720 --> 0:21:56.320
<v Speaker 1>just that, it was also a trading place. At Shadow Crew,

0:21:56.359 --> 0:22:00.280
<v Speaker 1>people could buy and sell information like stolen credit card

0:22:00.359 --> 0:22:04.680
<v Speaker 1>or debit card numbers, and they also could find tutorials

0:22:04.720 --> 0:22:07.960
<v Speaker 1>about how to carry out various criminal activities and how

0:22:07.960 --> 0:22:11.719
<v Speaker 1>to do things like how to get blank cards and

0:22:11.760 --> 0:22:16.239
<v Speaker 1>then emboss them and print magnetic strips on them and

0:22:16.320 --> 0:22:21.080
<v Speaker 1>imprint the stolen card information you had onto card blanks

0:22:21.359 --> 0:22:24.239
<v Speaker 1>so that you could then take those cards to like

0:22:24.320 --> 0:22:28.280
<v Speaker 1>an ATM and potentially withdraw tons of cash in the process.

0:22:28.600 --> 0:22:31.760
<v Speaker 1>In fact, that's actually what Gonzales was doing when he

0:22:31.880 --> 0:22:35.280
<v Speaker 1>first got caught. Shadow crew had built up an enormous

0:22:35.400 --> 0:22:38.879
<v Speaker 1>database of stolen card numbers, and Gonzales had made a

0:22:38.920 --> 0:22:41.440
<v Speaker 1>bunch of fake cards, and he set out to hit

0:22:41.480 --> 0:22:45.520
<v Speaker 1>some ATMs in North Manhattan in New York City. By chance,

0:22:45.960 --> 0:22:50.640
<v Speaker 1>there was this plain clothes NYPD detective who just spotted

0:22:50.680 --> 0:22:55.440
<v Speaker 1>Gonzales and thought Gonzales looked an awful lot shady. Gonzalez

0:22:55.560 --> 0:22:58.400
<v Speaker 1>was wearing a woman's wig at the time and a

0:22:58.520 --> 0:23:01.800
<v Speaker 1>fake nose ring, and the detective was actually on the

0:23:01.800 --> 0:23:04.560
<v Speaker 1>lookout for a totally different kind of criminal because there

0:23:04.560 --> 0:23:06.960
<v Speaker 1>had been some car thieves who had been hitting some

0:23:07.000 --> 0:23:11.480
<v Speaker 1>neighborhoods in Upper Manhattan, and so this detective started following

0:23:11.520 --> 0:23:14.159
<v Speaker 1>Gonzalez thinking that maybe he found one of the people

0:23:14.440 --> 0:23:17.040
<v Speaker 1>who had been boosting cars in the area. But it

0:23:17.080 --> 0:23:21.760
<v Speaker 1>wasn't cars that Gonzalez had boosted. It was card numbers,

0:23:21.880 --> 0:23:25.960
<v Speaker 1>not cars. So the detective follows Gonzalez, sees Gonzalez go

0:23:26.040 --> 0:23:29.200
<v Speaker 1>up to an ATM notices that Gonzalez is very likely

0:23:29.240 --> 0:23:31.760
<v Speaker 1>in disguise, like he's wearing like a hoodie and everything,

0:23:31.800 --> 0:23:33.760
<v Speaker 1>but also, like I said, a wig and a nose ring,

0:23:34.160 --> 0:23:38.320
<v Speaker 1>and Gonzalez starts using cards to access an ATM and

0:23:38.359 --> 0:23:41.080
<v Speaker 1>withdraw cash, and then just switch to a different card

0:23:41.160 --> 0:23:45.240
<v Speaker 1>and withdraw more cash. So the detective figured that Gonzalez

0:23:45.320 --> 0:23:48.959
<v Speaker 1>wasn't stealing automobiles, but he was definitely doing something that

0:23:49.000 --> 0:23:53.840
<v Speaker 1>was questionable. And so Gonzales got picked up by the police,

0:23:54.200 --> 0:23:56.960
<v Speaker 1>not because the cybersecurity team figured out who he was,

0:23:57.080 --> 0:23:59.320
<v Speaker 1>but because someone in the real world spotted him and

0:23:59.359 --> 0:24:04.160
<v Speaker 1>suspected that something was pinky. So Gonzalez ended up turning

0:24:04.320 --> 0:24:08.200
<v Speaker 1>informant on the Shadow Crew. This was largely to protect

0:24:08.280 --> 0:24:10.600
<v Speaker 1>himself so he wouldn't have to go to prison, and

0:24:10.880 --> 0:24:15.400
<v Speaker 1>he thought, well, I can end up helping the law

0:24:15.440 --> 0:24:20.320
<v Speaker 1>enforcement identify and catch other hackers. Now, Gonzales didn't necessarily

0:24:20.359 --> 0:24:22.560
<v Speaker 1>know who everyone was in Shadow Crew. In fact, he

0:24:22.600 --> 0:24:24.600
<v Speaker 1>didn't know who most of them were. The whole point

0:24:24.920 --> 0:24:28.400
<v Speaker 1>of the hacker culture was to create these personas that

0:24:28.800 --> 0:24:31.520
<v Speaker 1>while you know it was connected to you, you couldn't

0:24:31.600 --> 0:24:35.560
<v Speaker 1>trace it back to a person easily. However, Gonzales had

0:24:35.560 --> 0:24:37.840
<v Speaker 1>built up a lot of trust in the community, so

0:24:38.480 --> 0:24:42.200
<v Speaker 1>he ended up helping the Secret Service identify various high

0:24:42.280 --> 0:24:45.000
<v Speaker 1>level members of Shadow crew. But even while he was

0:24:45.080 --> 0:24:49.680
<v Speaker 1>working with the authorities to put away his fellow hackers,

0:24:50.040 --> 0:24:53.439
<v Speaker 1>he also kept up his own criminal activities. In fact,

0:24:53.960 --> 0:24:58.560
<v Speaker 1>he really stepped it up. He targeted large retail organizations

0:24:58.960 --> 0:25:01.359
<v Speaker 1>and so one of the things he started to do

0:25:01.560 --> 0:25:06.159
<v Speaker 1>was tap into these businesses through their own Wi Fi networks.

0:25:06.240 --> 0:25:08.680
<v Speaker 1>He and his colleagues would engage in a practice called

0:25:08.880 --> 0:25:13.400
<v Speaker 1>war driving. So war driving just involves driving around, typically

0:25:13.480 --> 0:25:16.720
<v Speaker 1>with like a laptop, and you're searching for Wi Fi networks,

0:25:17.080 --> 0:25:19.400
<v Speaker 1>and once you find a Wi Fi network, the next

0:25:19.400 --> 0:25:21.680
<v Speaker 1>step is to prod the network and see if there's

0:25:21.680 --> 0:25:25.720
<v Speaker 1>any vulnerabilities you can exploit. Now, that doesn't necessarily involve

0:25:25.840 --> 0:25:28.840
<v Speaker 1>any high tech stuff like it can, but it doesn't

0:25:28.880 --> 0:25:31.479
<v Speaker 1>have to. Sometimes all it takes is just a working

0:25:31.520 --> 0:25:35.480
<v Speaker 1>knowledge of generic login and password credentials, you know Wi Fi.

0:25:35.760 --> 0:25:38.359
<v Speaker 1>Especially at the time when Gonzalez was doing this in

0:25:38.400 --> 0:25:41.919
<v Speaker 1>the mid two thousands, it was fairly new and not

0:25:42.000 --> 0:25:44.440
<v Speaker 1>everyone actually took the trouble to, you know, do things

0:25:44.440 --> 0:25:47.800
<v Speaker 1>like change the default settings on their Wi Fi networks,

0:25:47.960 --> 0:25:51.000
<v Speaker 1>which meant that it was trivial to infiltrate those systems.

0:25:51.040 --> 0:25:53.280
<v Speaker 1>You might as well not use any security at all.

0:25:53.320 --> 0:25:56.320
<v Speaker 1>If you're not changing things like the default password, right,

0:25:56.440 --> 0:25:58.720
<v Speaker 1>because then all you have to do is know which

0:25:58.800 --> 0:26:01.919
<v Speaker 1>companies use default words, you know which default passwords, and

0:26:02.000 --> 0:26:04.200
<v Speaker 1>just go through and start using those until you get

0:26:04.240 --> 0:26:06.919
<v Speaker 1>into the system. And that was a large part of

0:26:06.960 --> 0:26:09.919
<v Speaker 1>what Gonzales in his group was doing. So even in

0:26:10.040 --> 0:26:13.960
<v Speaker 1>cases where someone did think to make this change, where

0:26:14.000 --> 0:26:16.240
<v Speaker 1>they did go so far as to change the defaults,

0:26:16.440 --> 0:26:19.320
<v Speaker 1>sometimes just a little social engineering could go a long

0:26:19.359 --> 0:26:21.399
<v Speaker 1>way toward getting you what you wanted. You know, you

0:26:21.440 --> 0:26:24.600
<v Speaker 1>trick someone into sharing log in credentials and you're in

0:26:24.640 --> 0:26:27.199
<v Speaker 1>the game. You just tell them, oh, I'm here to

0:26:27.880 --> 0:26:31.639
<v Speaker 1>improve your internet connection, to speed things up or whatever,

0:26:32.040 --> 0:26:35.280
<v Speaker 1>or to fix a problem. And you get login information

0:26:35.359 --> 0:26:37.800
<v Speaker 1>from someone, a lot of people will just hand it

0:26:37.840 --> 0:26:40.240
<v Speaker 1>over because they're like, well, that's outside of my expertise,

0:26:40.560 --> 0:26:43.119
<v Speaker 1>I don't know what I'm doing. Sure, this person seems

0:26:43.119 --> 0:26:44.879
<v Speaker 1>like they're on the up and up. Here's my log

0:26:44.920 --> 0:26:47.399
<v Speaker 1>in information. And then you snoop around long enough in

0:26:47.440 --> 0:26:49.520
<v Speaker 1>a system, you might find a way to access higher

0:26:49.600 --> 0:26:52.840
<v Speaker 1>level files. Right, you might be able to get administrator

0:26:52.920 --> 0:26:57.000
<v Speaker 1>level access to a system. That's kind of what Gonzales

0:26:57.080 --> 0:26:59.840
<v Speaker 1>was really good at doing. And that's where the profit is,

0:27:00.160 --> 0:27:04.959
<v Speaker 1>because that's where you're able to access the most sensitive information.

0:27:05.320 --> 0:27:09.640
<v Speaker 1>So Gonzales breached numerous databases that had pretty poor security

0:27:09.680 --> 0:27:12.800
<v Speaker 1>controls but lots of customer data, and so he got

0:27:12.840 --> 0:27:16.280
<v Speaker 1>access to even more credit and debit cards through major

0:27:16.359 --> 0:27:22.440
<v Speaker 1>retailers and consumer facing companies like TJ Max, OfficeMax, Barnes

0:27:22.480 --> 0:27:25.800
<v Speaker 1>and Noble Dave and Busters and lots more. He also

0:27:25.920 --> 0:27:29.200
<v Speaker 1>double crossed a few hackers in his community at this time.

0:27:29.400 --> 0:27:32.280
<v Speaker 1>In that New York Times magazine article, it's revealed that

0:27:32.480 --> 0:27:36.160
<v Speaker 1>while he was working with the Secret Service, Gonzales secretly

0:27:36.200 --> 0:27:40.040
<v Speaker 1>sold a junk database of stolen credentials. Those credentials were

0:27:40.080 --> 0:27:42.880
<v Speaker 1>no longer really active and so they weren't really useful.

0:27:43.320 --> 0:27:45.760
<v Speaker 1>It was just junk. But he sold this database to

0:27:45.800 --> 0:27:49.520
<v Speaker 1>a hacker because he knew that hacker was also under

0:27:49.960 --> 0:27:52.520
<v Speaker 1>the scrutiny of the Secret Service and they were closing

0:27:52.560 --> 0:27:56.320
<v Speaker 1>in on the hacker. So he makes money from this hacker.

0:27:56.520 --> 0:27:59.000
<v Speaker 1>The hacker gets caught and it looks like the hacker

0:27:59.119 --> 0:28:01.960
<v Speaker 1>is the one who actually stole the database of credentials

0:28:02.000 --> 0:28:05.560
<v Speaker 1>in the first place, so Gonzalez is able to offload

0:28:05.760 --> 0:28:11.639
<v Speaker 1>a worthless database of information onto someone who then takes

0:28:11.840 --> 0:28:14.439
<v Speaker 1>the fall for having stolen it in the first place.

0:28:14.720 --> 0:28:17.800
<v Speaker 1>By two thousand and seven, gonzalez Is working relationship with

0:28:17.840 --> 0:28:21.040
<v Speaker 1>the Secret Service was kind of falling apart, but he

0:28:21.160 --> 0:28:25.040
<v Speaker 1>was still really just getting started, and he had graduated

0:28:25.080 --> 0:28:30.440
<v Speaker 1>to SEQL injection attacks SQL. So essentially, a sequel injection

0:28:30.600 --> 0:28:34.880
<v Speaker 1>uses commands written in structured query language and it exploits

0:28:34.920 --> 0:28:37.280
<v Speaker 1>a vulnerability. It doesn't just work on its own. There

0:28:37.280 --> 0:28:41.800
<v Speaker 1>has to be a poorly designed system, and such systems

0:28:41.840 --> 0:28:45.600
<v Speaker 1>will sometimes accept commands that are in SQL without even

0:28:45.640 --> 0:28:49.280
<v Speaker 1>the formal logging in process. It's like you bypassed the

0:28:49.760 --> 0:28:53.000
<v Speaker 1>bit where the bouncer has to ask for your ID,

0:28:53.280 --> 0:28:55.680
<v Speaker 1>like you found a different way in, and it doesn't

0:28:55.680 --> 0:28:57.880
<v Speaker 1>give you full access to the building, but because you

0:28:57.960 --> 0:29:01.120
<v Speaker 1>happen to have like this one, you then can get

0:29:01.160 --> 0:29:05.400
<v Speaker 1>access to other stuff. That's essentially what sequel injection does.

0:29:05.720 --> 0:29:09.440
<v Speaker 1>It gives commands, and if the system is not hardened

0:29:09.480 --> 0:29:13.640
<v Speaker 1>against such attacks, the system's programmed to respond to those commands.

0:29:13.920 --> 0:29:17.920
<v Speaker 1>So this is one way that hackers would create backdoor

0:29:18.080 --> 0:29:21.120
<v Speaker 1>entry points into systems where they could come and go

0:29:21.200 --> 0:29:24.440
<v Speaker 1>as they pleased. So that's what Gonzales and his colleagues

0:29:24.440 --> 0:29:28.200
<v Speaker 1>were doing. Now, ultimately, he began to breach point of

0:29:28.440 --> 0:29:32.920
<v Speaker 1>sale machines like where cards were actually getting swiped. I

0:29:32.960 --> 0:29:36.880
<v Speaker 1>remember when this happened because news about how major retailers,

0:29:36.920 --> 0:29:39.280
<v Speaker 1>the big one being TJ Max as I recall, but

0:29:39.480 --> 0:29:41.840
<v Speaker 1>it was lots of them, not just TJ Max, but

0:29:41.960 --> 0:29:44.640
<v Speaker 1>all these different companies were starting to report these security

0:29:44.640 --> 0:29:47.920
<v Speaker 1>breaches in which someone had somehow managed to access credit

0:29:47.960 --> 0:29:51.200
<v Speaker 1>card numbers, sometimes credit card scanners right at the point

0:29:51.240 --> 0:29:54.280
<v Speaker 1>of sale and just grabbing numbers in real time. That's

0:29:54.280 --> 0:29:58.800
<v Speaker 1>someone was Gonzales and his crew. Okay, I've got more

0:29:58.800 --> 0:30:02.760
<v Speaker 1>to say about gonz and wrapping up his story. Plus

0:30:02.800 --> 0:30:05.320
<v Speaker 1>we have another hacker to talk about, but first let's

0:30:05.360 --> 0:30:18.160
<v Speaker 1>take another quick break. So we're back now. While Gonzalez

0:30:18.240 --> 0:30:21.680
<v Speaker 1>had a history of using stolen credit card and debit

0:30:21.720 --> 0:30:26.200
<v Speaker 1>card numbers personally, the really big money was in selling

0:30:26.320 --> 0:30:30.240
<v Speaker 1>databases filled with just hundreds of thousands of credit card

0:30:30.320 --> 0:30:34.560
<v Speaker 1>numbers to other people. And he had really accumulated tens

0:30:34.720 --> 0:30:39.000
<v Speaker 1>of millions of card numbers over his various exploits, and

0:30:39.040 --> 0:30:41.000
<v Speaker 1>he would sell them to people all over the world.

0:30:41.360 --> 0:30:44.200
<v Speaker 1>But one of his big buyers was a guy located

0:30:44.480 --> 0:30:49.040
<v Speaker 1>in Ukraine, and Gonzales felt comfortable working with this guy

0:30:49.240 --> 0:30:52.360
<v Speaker 1>because the extradition laws in Ukraine at the time weren't

0:30:52.480 --> 0:30:57.080
<v Speaker 1>very scary, so if his contact was picked up, then

0:30:57.120 --> 0:31:00.160
<v Speaker 1>he would probably just kind of get off without too

0:31:00.200 --> 0:31:03.360
<v Speaker 1>much trouble. He certainly wouldn't get extradited to the United States,

0:31:03.400 --> 0:31:07.000
<v Speaker 1>and Gonzalez himself would remain insulated, so he felt that

0:31:07.040 --> 0:31:10.600
<v Speaker 1>there was a lower risk working with criminals in Ukraine.

0:31:10.680 --> 0:31:13.200
<v Speaker 1>But then this contact took a little trip to Turkey

0:31:13.240 --> 0:31:15.840
<v Speaker 1>and got snatched up by authorities and things went south

0:31:15.880 --> 0:31:18.480
<v Speaker 1>in a hurry, so ultimately that did not work out

0:31:18.480 --> 0:31:22.120
<v Speaker 1>so well for Albert Gonzalez. Law enforcement was looking into

0:31:22.160 --> 0:31:25.200
<v Speaker 1>the various data breaches, and through tracking down people on

0:31:25.320 --> 0:31:29.520
<v Speaker 1>the outskirts of this crime, they were slowly circling in

0:31:29.760 --> 0:31:34.000
<v Speaker 1>on Albert Gonzalez himself. That also included some tailtale signs

0:31:34.040 --> 0:31:37.840
<v Speaker 1>at Dave and Busters, which played another part in kind

0:31:37.880 --> 0:31:42.320
<v Speaker 1>of narrowing down the search. See the program that Gonzalez's

0:31:42.800 --> 0:31:45.560
<v Speaker 1>crew was using to skim credit card numbers at the

0:31:45.640 --> 0:31:50.160
<v Speaker 1>daven Buster's locations had a limitation. It would not reset

0:31:50.600 --> 0:31:53.480
<v Speaker 1>if the computer systems had been shut down. And then

0:31:53.520 --> 0:31:56.320
<v Speaker 1>turned back on. So if the computer systems reset, the

0:31:56.480 --> 0:32:00.560
<v Speaker 1>skimming program did not reset with those comput systems that

0:32:00.640 --> 0:32:03.960
<v Speaker 1>needed to be reinitiated. So that meant that the hackers

0:32:04.000 --> 0:32:06.959
<v Speaker 1>would have to revisit Dave and Busters on a fairly

0:32:07.000 --> 0:32:09.920
<v Speaker 1>frequent basis. And then eventually David Busters starts to figure

0:32:09.920 --> 0:32:13.640
<v Speaker 1>out that these frequent customers are also shady customers and

0:32:13.720 --> 0:32:18.960
<v Speaker 1>suspicions raise. The investigation culminated in a May seventh, two

0:32:19.000 --> 0:32:23.160
<v Speaker 1>thousand and eight, raid on a hotel room near Miami Beach, Florida.

0:32:23.240 --> 0:32:28.840
<v Speaker 1>So Miami was Gonzales' hometown. He moved there after he

0:32:28.880 --> 0:32:32.400
<v Speaker 1>worked with the Secret Service back in the earlier two

0:32:32.400 --> 0:32:37.640
<v Speaker 1>thousands and was helping them unveil and unmask and capture

0:32:37.720 --> 0:32:40.520
<v Speaker 1>various hackers. He moved to Miami and that's where he

0:32:40.760 --> 0:32:45.120
<v Speaker 1>operated for much of the mid to late two thousands.

0:32:45.120 --> 0:32:50.760
<v Speaker 1>Really and law enforcement arrested Gonzales in this raid, and

0:32:51.160 --> 0:32:55.240
<v Speaker 1>Gonzales eventually led authorities to dig up a barrel containing

0:32:55.280 --> 0:32:58.040
<v Speaker 1>more than a million dollars in cash that was buried

0:32:58.040 --> 0:33:02.000
<v Speaker 1>in his parents' backyard. Whether or not that was the

0:33:02.600 --> 0:33:05.400
<v Speaker 1>majority of his money or all of it, who knows.

0:33:05.840 --> 0:33:09.040
<v Speaker 1>Maybe it was just a bit to throw a bone

0:33:09.080 --> 0:33:12.760
<v Speaker 1>to the authorities and keep the rest secretly locked away.

0:33:13.240 --> 0:33:16.360
<v Speaker 1>But Gonzalez pled guilty to all the charges that were

0:33:16.400 --> 0:33:19.640
<v Speaker 1>filed against him. He was sentenced to two concurrent twenty

0:33:19.720 --> 0:33:22.520
<v Speaker 1>year prison sentences, meaning he was serving out both of

0:33:22.560 --> 0:33:26.120
<v Speaker 1>them at the same time. His buddy, Stephen Watt aka

0:33:26.600 --> 0:33:30.480
<v Speaker 1>Jim Jones, would get two years in prison and a

0:33:30.560 --> 0:33:33.360
<v Speaker 1>quarter of a million dollars in fines for having coded

0:33:33.520 --> 0:33:36.920
<v Speaker 1>the sniffer programs that Gonzalez was relying upon, though Wats

0:33:36.960 --> 0:33:40.720
<v Speaker 1>himself argued that he didn't know what Gonzalez was really

0:33:40.760 --> 0:33:43.200
<v Speaker 1>doing with the stuff he had built. I don't fully

0:33:43.680 --> 0:33:46.480
<v Speaker 1>know if that's believable, but he did say that he

0:33:46.840 --> 0:33:50.120
<v Speaker 1>definitely didn't agree with some of the targets that Gonzales

0:33:50.160 --> 0:33:52.600
<v Speaker 1>wanted to go after that Watt just felt that that

0:33:52.720 --> 0:33:57.520
<v Speaker 1>was not really appropriate. Another hacker named Damon Patrick Towey,

0:33:57.840 --> 0:34:00.479
<v Speaker 1>who did a lot of Gonzales' leg work, got hit

0:34:00.520 --> 0:34:03.600
<v Speaker 1>with a five year prison sentence, now equated to multiple articles.

0:34:03.680 --> 0:34:07.160
<v Speaker 1>Gonzales would be in prison till eligible for parole, which

0:34:07.160 --> 0:34:10.759
<v Speaker 1>wouldn't be until twenty twenty five, but apparently he was

0:34:10.800 --> 0:34:13.720
<v Speaker 1>released last year on September nineteenth according to the Bureau

0:34:13.800 --> 0:34:16.400
<v Speaker 1>of Prisons. If you do a research of him on

0:34:16.480 --> 0:34:18.720
<v Speaker 1>the Bureau of Prisons, it says he is no longer

0:34:18.760 --> 0:34:21.880
<v Speaker 1>in custody. Oddly enough, I couldn't find any articles about

0:34:21.920 --> 0:34:25.080
<v Speaker 1>his release. But if someone is in prison long enough,

0:34:25.120 --> 0:34:27.239
<v Speaker 1>I figure the folks who covered their crimes will have

0:34:27.320 --> 0:34:29.960
<v Speaker 1>moved on. So it's quite possible that no one just

0:34:30.200 --> 0:34:33.799
<v Speaker 1>noticed that he was released from prison. Assuming he's on

0:34:33.840 --> 0:34:36.520
<v Speaker 1>the outside now, the question is will he stay on

0:34:36.680 --> 0:34:43.040
<v Speaker 1>the straight and narrow or return to his system exploiting ways. Now,

0:34:43.120 --> 0:34:46.440
<v Speaker 1>our final hacker that we're covering in this episode is

0:34:46.480 --> 0:34:50.160
<v Speaker 1>a tragic story and it's also connected to Albert Gonzales,

0:34:50.560 --> 0:34:55.520
<v Speaker 1>so this guy has a relation to that story. It's

0:34:55.560 --> 0:34:59.320
<v Speaker 1>the story of Jonathan James. He was born in nineteen

0:34:59.360 --> 0:35:01.360
<v Speaker 1>eighty three, so he was just a couple of years

0:35:01.400 --> 0:35:04.800
<v Speaker 1>younger than Gonzales. His father was a computer systems analyst,

0:35:04.840 --> 0:35:08.160
<v Speaker 1>and young Jonathan James developed a keen interest in computers

0:35:08.200 --> 0:35:11.839
<v Speaker 1>as well, so keen that years later, when Jonathan James

0:35:11.880 --> 0:35:15.920
<v Speaker 1>would get picked up by authorities for breaching secure systems,

0:35:15.960 --> 0:35:18.960
<v Speaker 1>his father would claim, quote, I've been in computers for

0:35:19.040 --> 0:35:22.040
<v Speaker 1>twenty years, and I can't do what he was doing

0:35:22.360 --> 0:35:25.920
<v Speaker 1>end quote. Now, what he was doing was mainly snooping around.

0:35:26.200 --> 0:35:29.640
<v Speaker 1>He was using computers and the young Internet to explore

0:35:29.719 --> 0:35:33.400
<v Speaker 1>different computer systems, and like Gonzales, that included some systems

0:35:33.400 --> 0:35:37.480
<v Speaker 1>that he absolutely positively was not supposed to be able

0:35:37.520 --> 0:35:41.879
<v Speaker 1>to access. In nineteen ninety nine, Jonathan James allegedly infiltrated

0:35:41.880 --> 0:35:45.400
<v Speaker 1>more than a dozen computers belonging to the National Aeronautics

0:35:45.400 --> 0:35:49.440
<v Speaker 1>and Space Administration good old NASA, again just like Gonzales

0:35:49.440 --> 0:35:52.520
<v Speaker 1>had done when he was fourteen years old. The computers

0:35:52.520 --> 0:35:56.880
<v Speaker 1>were located at NASA's Marshall Space Flight Center in Alabama,

0:35:57.080 --> 0:36:00.000
<v Speaker 1>and the intrusion, once detected, prompted the agency to show

0:36:00.200 --> 0:36:02.520
<v Speaker 1>down some of those computers for the better part of

0:36:02.560 --> 0:36:06.360
<v Speaker 1>a month. James would later be accused of having stolen data,

0:36:06.400 --> 0:36:09.880
<v Speaker 1>including highly sensitive information about the International Space Station, and

0:36:09.960 --> 0:36:14.120
<v Speaker 1>that he had downloaded software from NASA during his unauthorized

0:36:14.280 --> 0:36:18.040
<v Speaker 1>tour of their computer systems, and authorities would later estimate

0:36:18.080 --> 0:36:21.160
<v Speaker 1>that his activities had cost the agency around forty thousand

0:36:21.280 --> 0:36:25.080
<v Speaker 1>bucks in various ways, from having to replace compromise systems

0:36:25.120 --> 0:36:28.560
<v Speaker 1>to paying folks to fix vulnerabilities though one could argue

0:36:28.560 --> 0:36:30.680
<v Speaker 1>that in that case, at least James had kind of

0:36:30.719 --> 0:36:34.319
<v Speaker 1>done NASA a service because James didn't have darker motivations

0:36:34.360 --> 0:36:37.480
<v Speaker 1>against the agency. And one could argue that if someone's

0:36:37.520 --> 0:36:40.000
<v Speaker 1>going to bust into your computer systems and reveal that

0:36:40.040 --> 0:36:42.680
<v Speaker 1>there's a big security vulnerability, you would rather it be

0:36:42.719 --> 0:36:45.799
<v Speaker 1>a sixteen year old kid than an actual terrorist. But

0:36:46.160 --> 0:36:49.560
<v Speaker 1>that's not to say that Jonathan James was a naive, innocent,

0:36:49.880 --> 0:36:54.160
<v Speaker 1>curious boy. He certainly was curious, that was definitely true.

0:36:54.440 --> 0:36:57.880
<v Speaker 1>But he really enjoyed the challenge of hacking into supposedly

0:36:57.960 --> 0:37:01.560
<v Speaker 1>secure systems, and he would claim that his motivation to

0:37:01.640 --> 0:37:03.520
<v Speaker 1>do this was mostly just to see if he could

0:37:03.560 --> 0:37:06.399
<v Speaker 1>do it, and also to brag about this to other

0:37:06.480 --> 0:37:08.960
<v Speaker 1>hackers so that he could get some, you know, kind

0:37:09.000 --> 0:37:12.800
<v Speaker 1>of clout in the hacker community. In the hacker community,

0:37:12.840 --> 0:37:15.800
<v Speaker 1>he took on the handle Comrade, with the O and

0:37:15.880 --> 0:37:19.480
<v Speaker 1>comrade being a zero instead of the letter O. That

0:37:19.560 --> 0:37:22.520
<v Speaker 1>might have been a little brash considering some of his targets,

0:37:22.600 --> 0:37:27.520
<v Speaker 1>Like to use a term that has its connections to Russia,

0:37:28.000 --> 0:37:30.440
<v Speaker 1>might have been a little brash because one of his

0:37:30.480 --> 0:37:34.400
<v Speaker 1>targets was the defense threat Reduction Agency, which itself is

0:37:34.480 --> 0:37:36.920
<v Speaker 1>part of the US Department of Defense. So this is

0:37:37.000 --> 0:37:39.880
<v Speaker 1>still in the summer of nineteen ninety nine, when James

0:37:39.920 --> 0:37:43.120
<v Speaker 1>was just sixteen years old. The agency in this case

0:37:43.200 --> 0:37:46.360
<v Speaker 1>was responsible for monitoring potential threats to the United States,

0:37:46.400 --> 0:37:51.360
<v Speaker 1>including stuff like nuclear or biologic weaponry, so this is

0:37:51.719 --> 0:37:56.360
<v Speaker 1>definitely highly classified information we're talking about. James uncovered a

0:37:56.360 --> 0:37:59.200
<v Speaker 1>ton of information while he was poking around. He intercepted

0:37:59.280 --> 0:38:03.200
<v Speaker 1>thousands of messages between different agency members and gained access

0:38:03.239 --> 0:38:06.640
<v Speaker 1>to nearly twenty different log in credentials. While he was

0:38:06.680 --> 0:38:10.360
<v Speaker 1>doing all this, the agency noticed that someone was snooping around, however,

0:38:10.520 --> 0:38:13.319
<v Speaker 1>and over the course of the next few months, law

0:38:13.360 --> 0:38:16.560
<v Speaker 1>enforcement was able to trace those intrusions back to Jonathan

0:38:16.680 --> 0:38:20.480
<v Speaker 1>James's home. Now, according to his dad, Jonathan's identity was

0:38:20.520 --> 0:38:25.600
<v Speaker 1>discovered largely through the cooperation with ISPs, so Internet service

0:38:25.640 --> 0:38:29.800
<v Speaker 1>providers worked with law enforcement to trace back the traffic

0:38:30.120 --> 0:38:33.320
<v Speaker 1>that was coming from Jonathan James's home and leading into

0:38:33.640 --> 0:38:36.840
<v Speaker 1>the Department of Defense. James was brought up on charges

0:38:36.960 --> 0:38:39.880
<v Speaker 1>as a juvenile, and he pled guilty to those charges.

0:38:40.000 --> 0:38:43.000
<v Speaker 1>If he had been an adult when he carried out

0:38:43.040 --> 0:38:46.240
<v Speaker 1>these hacking activities probably would have faced some pretty serious

0:38:46.360 --> 0:38:48.960
<v Speaker 1>jail time and some fines, but as it stood, he

0:38:49.040 --> 0:38:52.440
<v Speaker 1>was sentenced to six months of detention in a juvenile facility.

0:38:52.640 --> 0:38:54.920
<v Speaker 1>The Justice Department said he was the first juvenile to

0:38:54.960 --> 0:38:59.319
<v Speaker 1>actually serve time for hacking now. Unfortunately for James, the

0:38:59.400 --> 0:39:02.840
<v Speaker 1>consequence of his actions followed him well after his release

0:39:02.880 --> 0:39:06.799
<v Speaker 1>from juvenile detention. He found it difficult to secure employment.

0:39:07.000 --> 0:39:10.720
<v Speaker 1>While some hackers have leveraged their experiences into a job

0:39:10.840 --> 0:39:13.800
<v Speaker 1>in cybersecurity, James found it hard to do the same.

0:39:14.040 --> 0:39:16.800
<v Speaker 1>He also was still in touch with some other hackers,

0:39:17.000 --> 0:39:19.760
<v Speaker 1>and while he was determined to avoid a legal activity,

0:39:19.960 --> 0:39:24.359
<v Speaker 1>his circles included folks that were connected to Gonzalez, and

0:39:24.480 --> 0:39:29.360
<v Speaker 1>Gonzales showed far less concern about the legality of his actions.

0:39:29.600 --> 0:39:33.040
<v Speaker 1>So when Albert Gonzalez's crew started stealing thousands of credit

0:39:33.080 --> 0:39:36.280
<v Speaker 1>card numbers from around a dozen major companies, the Secret

0:39:36.320 --> 0:39:40.879
<v Speaker 1>Service decided to look in on James. They found references

0:39:40.920 --> 0:39:48.000
<v Speaker 1>to a j. J in those in those those hacker communications,

0:39:48.280 --> 0:39:52.000
<v Speaker 1>and Jonathan James couldn't that be JJ. As it turns out,

0:39:52.080 --> 0:39:56.759
<v Speaker 1>JJ may have meant Jim Jones aka Stephen Watt, who

0:39:56.800 --> 0:40:01.680
<v Speaker 1>was one of Gonzalez's colleagues, and the Secret Service was

0:40:01.719 --> 0:40:04.319
<v Speaker 1>looking at James. I mean, James had proven himself to

0:40:04.320 --> 0:40:08.600
<v Speaker 1>be an adept hacker, far capable of gaining access to

0:40:09.160 --> 0:40:12.240
<v Speaker 1>what were supposed to be secure systems. But Jonathan James

0:40:12.280 --> 0:40:17.440
<v Speaker 1>was already battling depression due to his struggles of getting

0:40:17.480 --> 0:40:22.359
<v Speaker 1>a stable life post detention, and the suspicion directed at

0:40:22.440 --> 0:40:26.520
<v Speaker 1>him probably exacerbated things. Not to say that it caused

0:40:26.680 --> 0:40:30.440
<v Speaker 1>what would follow to happen, but that it certainly was

0:40:30.600 --> 0:40:33.719
<v Speaker 1>another element on top of a lot of other stresses

0:40:33.760 --> 0:40:36.920
<v Speaker 1>that were already leading to some serious depression. Because on

0:40:37.000 --> 0:40:40.399
<v Speaker 1>May eighteenth, two thousand and eight, just eleven days after

0:40:40.480 --> 0:40:46.160
<v Speaker 1>authorities had brought Albert Gonzales into custody, Jonathan James committed suicide.

0:40:46.680 --> 0:40:49.080
<v Speaker 1>He left behind a note that claimed he had no

0:40:49.120 --> 0:40:52.600
<v Speaker 1>connection with the recent attacks against TJX and the other

0:40:52.680 --> 0:40:56.360
<v Speaker 1>companies that Gonzales had targeted, but he also had quote

0:40:56.719 --> 0:41:00.520
<v Speaker 1>no faith in the justice system end quote. Further, he

0:41:00.600 --> 0:41:03.759
<v Speaker 1>tragically revealed that he felt he had no control over

0:41:03.840 --> 0:41:07.120
<v Speaker 1>his own life and only by taking his life could

0:41:07.120 --> 0:41:12.040
<v Speaker 1>he regain control, which is an incredibly tragic ending. And

0:41:12.239 --> 0:41:14.759
<v Speaker 1>just a note here because I do think this is important.

0:41:15.120 --> 0:41:18.200
<v Speaker 1>If you are ever in a place where you're having

0:41:18.280 --> 0:41:22.359
<v Speaker 1>suicidal thoughts, please reach out to a crisis hotline. There

0:41:22.400 --> 0:41:25.080
<v Speaker 1>are many such lifelines around the world. Here in the

0:41:25.160 --> 0:41:28.640
<v Speaker 1>United States, the national lifeline is nine to eight eight,

0:41:29.120 --> 0:41:32.719
<v Speaker 1>and talking to someone can be a huge help. But

0:41:32.840 --> 0:41:36.759
<v Speaker 1>that's it for this episode about famous hackers. There are

0:41:36.760 --> 0:41:39.719
<v Speaker 1>lots more, and I'll probably do more episodes where I'll

0:41:39.719 --> 0:41:42.239
<v Speaker 1>talk about some others. You know, I didn't even mention

0:41:42.320 --> 0:41:44.320
<v Speaker 1>Kevin Mitnick in this one, and that's a big one,

0:41:44.400 --> 0:41:49.280
<v Speaker 1>so we'll come back to this topic. Obviously, there's seven

0:41:49.360 --> 0:41:52.040
<v Speaker 1>more on that Kaspersky list I could talk about, but

0:41:52.120 --> 0:41:57.640
<v Speaker 1>I felt that getting some insight into the motivations and

0:41:58.080 --> 0:42:01.279
<v Speaker 1>techniques used by some of these hackers would be kind

0:42:01.320 --> 0:42:05.319
<v Speaker 1>of interesting. I hope everyone out there is doing well.

0:42:05.520 --> 0:42:08.480
<v Speaker 1>Hope you're healthy and happy, and I will talk to

0:42:08.520 --> 0:42:18.520
<v Speaker 1>you again really soon. Tech Stuff is an iHeartRadio production.

0:42:18.840 --> 0:42:23.879
<v Speaker 1>For more podcasts from iHeartRadio, visit the iHeartRadio app, Apple Podcasts,

0:42:24.000 --> 0:42:26.000
<v Speaker 1>or wherever you listen to your favorite shows.