Safe Computing Is Like Safe Sex: Habits, Hackers, and the Surveillance Bill | 3 Ps in a Podcast
Featuring Richard Lowe on 3 Ps in a Podcast, with hosts Joe and Mike
TL;DR: What This Conversation Establishes
- Security is not a product you install. It is a set of habits you practice, which is why Richard titled his first book Safe Computing Is Like Safe Sex
- The weak link is never the machine, Mac or PC. It is the user, and social engineering is how attackers reach the user
- Ransomware pop-ups should be killed from the task manager, never clicked, not even to close them
- Richard’s read on the CISA cybersecurity bill moving through Congress: a smoke screen that builds a government database without actually protecting anyone
- The first security step for everybody: back up, automatically, offsite, today
This is the complete conversation from Richard Lowe’s first appearance on 3 Ps in a Podcast, the weekly technology roundtable out of Atlanta, lightly edited for readability. Where individual panelists could not be distinguished on the recording, their turns are attributed as Host.
Introducing the guest
Host: Welcome to another episode of 3 Ps in the Podcast. This week on the show: the iPhone 6s and 6s Plus sell out within 30 minutes in Samsung’s home turf of South Korea. Sprint has been hit with a pretty big lawsuit that’s coming out of nowhere, and people are scratching their heads over it. Apple, for the second week in a row, has another class action lawsuit; how will they respond? And there’s a big fight right now in Congress. All the big heavy hitters in the tech world are going at it with Congress over this new cybersecurity bill: how that affects you and what you can do to protect yourself. But first, we have a very, very special guest this week. It is Mr. Richard Lowe. He’s an author. He writes a lot of great books. His specialty is protecting yourself in this wonderful world of technology and staying on the safe side of it. He has a book with a very awesome title: Safe Computing Is Like Safe Sex. So right now, with no further ado, Mr. Richard Lowe. Hi, how are you doing?
Richard Lowe: Wonderful, wonderful. Glad to be here.
Host: Thank you so much for joining us. My pleasure. If you would, tell everybody out there a little bit about yourself, where they can find you, and what you do.
Richard Lowe: Well, I was in the computer industry for the last 35 years. My specialty was disaster recovery, computer security, and managing large computer projects. You’ve probably heard of one of the companies I worked for. It was called Trader Joe’s.
Host: Yes, we have, actually.
Richard Lowe: I managed the IT department, the support part of it, there. For 35 years I’ve been doing that, and I’ve been involved in the credit card security side, keeping credit cards secure, which is a very big task, because obviously you don’t want millions of those falling into the wrong hands. On top of that, I’ve been involved in desktop security, because when I was there, and they still do, we had thousands of users with desktops, and we were constantly getting hit by viruses and Trojan horses and all kinds of other things that caused no end of problems. As time went by, we were forced to confront that, and we resolved it pretty well, to where we weren’t getting hit nearly as often.
Then I retired two years ago because I wanted to pursue my dream of writing, and the first book I wrote was Safe Computing Is Like Safe Sex, because obviously I know that subject very well. I picked the title of that book because the similarities are there. Safe computing is not something where you can just install a program and, okay, you’re safe now, everything’s done. It’s something, as with safe sex, that you have to practice. You have to change your procedures with your computer and get new habits. Don’t click on those links right away. Make sure they’re valid first, because it doesn’t matter whether you’re on a Mac or an iPhone or an Android or a PC. If you click on a link, your computer can become infected if that link goes to an infected website. So you have to get out of that habit.
You’ve got thousands of passwords now. I have probably 500 passwords for online accounts. You want to store those passwords in such a way that they’re safe, and we’ll get into that later, I’m assuming. The point is, the processes are what’s important. A lot of books go into: install this, do this, change that. Or Mac is better than PC, throw away your PC, get a Mac. None of that’s the whole answer. It has validity, but it’s not the only thing you need to do. You need to change your habits. Once you do that, your safety improves. That’s why I wrote the book.
Is a Mac safer than a PC from viruses?
Host: It’s awesome, because a lot of people, myself included, hear “don’t get a PC, get a Mac,” but you’re never really told exactly why, and what else goes into it. Not just picking the computer but, like you said, changing your habits and creating those practices.
Richard Lowe: Yes. The Macintosh is, by design, a little bit more secure than the Windows machine. But still, the problem is not the machine. The problem is the user. And it’s not that the user’s not intelligent. It’s that these hackers use what’s called social engineering to cause the user to do something. I’m sure you’ve gotten one of those emails from a, quote, Nigerian, quote, saying you’re wanted for $2 million, they just need your help.
Host: Tons of those.
Richard Lowe: Well, that’s social engineering. That’s aiming at a soft spot, trying to stir some emotion and get you to respond. There are other forms of it. That’s a user training issue. Don’t respond to that.
Host: We’ve all done work in the tech industry, not nearly as extensive as yourself, and we get people all the time: “Well, I clicked on an email that told me all I had to do was say yes and I’d get a million dollars.” We try to stress it, and you can’t stress it enough: that is just not what you want to do.
Richard Lowe: Correct. I was just hired by a company called KnowBe4 to update their document called Cyberheist, to take into account the new attacks, like ransomware, for example, which is very deadly and affects all computers, all platforms, everything. You don’t want to get hit by ransomware. So I’m updating the book to include that, and ad blocking, and things like that. It’s a continuing thing.
What should you do when a ransomware pop-up appears?
Host: Ransomware, correct me if I’m wrong, is that where they say your computer has been seized by the FBI, pay this amount to get it back, something like that?
Richard Lowe: What typically happens is you’ll visit a website and you’ll get a pop-up that says, we found 45 viruses on your computer, click here to get rid of them. And it’ll look very, very much like it’s official, from some official company. You should immediately go into the task manager and kill that task. Don’t click yes. Don’t click anything. If you have to reboot your machine, fine, but don’t click anything, because if you do, you will install something that encrypts everything on your computer, and you are toast.
Host: That’s even if you hit the X to exit out?
Richard Lowe: You need to kill it. You don’t exit. Task manager, kill the process.
Host: I’ve gotten those a couple of times, and I always reboot the machine. Just a clean reboot.
Richard Lowe: That works. You have to be paranoid in this world, especially when it comes to this technology.
How does social engineering work in the real world?
Host: So the definition of social engineering: a non-technical method of intrusion hackers use that relies heavily on human interaction, and often involves tricking people into breaking normal security procedures. It’s one of the greatest threats organizations face today.
Richard Lowe: I can give you an example of one that hits retail chains all the time. Somebody will dress in a uniform, with a badge, looks very official, and he’ll walk in with a card swipe, the things you swipe your credit cards on, and he’ll say he’s here to repair the card swipe. The checker doesn’t know any different, so she says okay, and he installs one of his. And then they capture all of the credit card data. That is social engineering. He just convinced the checker that he was a good guy. He wasn’t.
Host: It actually happened at a tech shop I worked at in South Carolina once. That’s crazy.
Richard Lowe: It can get pretty nasty, but it’s real easy to prevent if you just engage the brain and go, wait a minute, nobody called to make an appointment. You call your tech service department, and they will tell you: no, nobody’s supposed to be there. The hacker is going to be running. He’s going to be gone. Just engage the brain, so to speak.
The week’s news: iPhone in South Korea and the Sprint penalty
Host: We really appreciate that info, and we’ll get more on that a little later in the show. I want to talk about the big news out of South Korea: the iPhone 6s and 6s Plus sold out within 30 minutes there. For those who aren’t familiar, the reason that’s big is that South Korea is Samsung and LG’s home turf. All three major mobile carriers, and there are only three in South Korea, sold out all inventory, every model, within 30 minutes. Joe, Mike, Mr. Lowe, what do you think?
Host: I don’t think it’s news. We knew this was going to happen eventually. I just didn’t expect it to sell out so quickly. Thirty minutes is pretty fast for millions of phones. It was a question before whether Apple would ever outsell Samsung or LG there, and if they did, what phone it would be. Would it be a major release or an S-year release? It turned out the first time it happened was on an S year, which is kind of surprising.
Host: One thing we didn’t see coming was Sprint, out of nowhere, getting a lawsuit with a penalty around $3 million from the FTC, the Federal Trade Commission. There was a little scheme they were doing. Joe?
Joe: Basically, it’s tricking customers into paying an extra fee of around $8 per month, based on their credit history. Sprint was creating spending limits for these customers. Say a person might have a limit of $150 before their services are rerouted to the financial department. Customer B may have a $100 spending limit. It’s all based on credit. These customers were not informed until the termination fees were placed onto the account, or until they were forwarded to the financial department. Too little, too late.
Host: What are you thinking about that, Mr. Lowe?
Richard Lowe: Well, I got hit with something like that on my cable bill a few years ago, because I’m a pretty big downloader, and suddenly, surprise, I’m not able to download for the rest of the month, and it’s only the 15th. It was out of the blue, and I called, and customer support didn’t even know they were enforcing it. They managed to put me back on, because I can complain pretty loud, but it is pretty obnoxious.
Host: It’s pretty audacious too. You need to at least tell your customers this is happening so they can plan accordingly. Our customers out there, there’s a way around it: if you sign up for auto pay, the $8 fee is waived.
Richard Lowe: That’s kind of counterintuitive. It’s like holding a gun to your head. Either sign up for auto pay, or we hit you with our financial department.
Host: We joke about Sprint a lot, but this is one where they’re trying to hang onto the few customers they have who are spending money, and that’s probably the wrong way to do it. It’s not ethical, especially if it’s not disclosed to the customer up front.
Richard Lowe: I actually like the way my mobile carrier does it: you get two gigs a month at 4G, and if you exceed that, you can either buy another package or you just get dropped to 3G and it’s a little slower. And it’s transparent. They let you know up front. You get a little text a couple hundred megs in advance. And then you can pay the extra if you want more bandwidth.
Host: And again, that’s transparency. If you’re going to charge me for something, at least let me know before I rack it up. There’s no mention of it, but I’m sure somewhere in the contract, in very tiny print you can’t read, this entire process is explained. Reading more into it: the penalty is connected to the FTC’s risk-based pricing rule implemented in 2011, which requires companies to notify consumers when they use information in their credit reports to give them materially worse terms than most other customers.
Host: Speak English, Mike.
Mike: Practically, what they’re saying is: customer A, if you have bad credit, your payment terms with Sprint will be worse than customer B, who has good credit. That should have been stated up front, but companies like to put everything in fine print. It’s like when they say “zero down on the phone” and the fine print says “pending qualified credit.”
Host: The other thing is, a lot of people who sign up with wireless carriers are looking to build their credit. Are these companies reporting their on-time payments to the credit bureaus so their scores go up? Or are they only reporting the bad marks? That could be another issue here.
The WiFi Assist class action
Host: Speaking of lawsuits: last week we reported on Apple’s patent lawsuit with the University of Wisconsin over a chip. This week it’s the new WiFi Assist feature. In layman’s terms: if you’re anywhere with WiFi, and your LTE connection is stronger than the WiFi, your phone automatically swaps off WiFi onto LTE. There was a couple, the plaintiffs in this case, saying that after they updated to iOS 9 they were going over their data without knowing it, because the suit says Apple didn’t explain the feature until it was brought up in a complaint. That suit is totaling about $5 million right now. Thoughts?
Host: Is it a class action? I just think people will find anything to file a lawsuit against these days. Some of these things are obvious if you know how technology works. If you have WiFi and you’re not on WiFi, there’s a little signal indicator on your phone. People will make claims for whatever reason. Money.
Host: At least they didn’t get hit for $862 million this time. Five million, they won’t feel whatsoever. That’s a warning penalty. That’s like they go grocery shopping with $5 million.
Richard Lowe: I actually think the WiFi Assist feature is a pretty good feature, because it will swap between your WiFi and LTE if you have a weaker signal. For most customers, data is everything nowadays, and they want it at full speed.
Host: A lot of people live in secluded areas, mountains, woods, where all you have is the WiFi. But sometimes it’s the other way around, where your WiFi isn’t that good. The feature is good, but it goes hand in hand with knowing how to use your phone.
Richard Lowe: I would say the only thing it needs, to prevent the lawsuits, is if you’re getting near the cap where you’re going to be charged more for data, they should send a text. Then it would be fine. Then, if you ignore the text, it’s your own fault.
Host: Well, that’s what they say, but remember, there was a company out there that sent texts and printed this material and still got hit for over a hundred million. It’s a slippery slope either way. Either you tell me about it up front and I ignore it, or you don’t tell me about it up front and I hit you anyway for not telling me. Again: people have to know how to use their devices. You know how much data you’re using if you know your device.
Host: One way to turn this off, for those of you who don’t want the issue: go to Settings, go to Cellular, scroll all the way down to the WiFi Assist feature, and you can toggle it on and off. It doesn’t have to be on all the time.
The Facebook battery bug
Host: Next up: last week, Facebook had a lot of controversy on the iPhone 6s. Apparently Facebook was using a crazy amount of battery life. Even when you closed the app, it wasn’t closing the way it normally should. They’ve taken to their website and blogs to clear the air. They’ve admitted there’s a problem, put out a patch, and a major update is coming shortly. What do you think? Background activity?
Host: It looks to me like someone’s trying to collect some information to use. Maybe.
Host: I think they were saying it was something about audio. Say you watched a video; sometimes the audio would still play in the background, so you were still reaching their servers, which was still using your battery. It says right here: “The second issue is with how we manage audio sessions. If you leave the Facebook app after watching a video, the audio session sometimes stays open as if the app was playing audio silently.”
Host: Is this one of those issues where, assuming most people out there have an iPhone, we need to get into the habit of closing our apps out? That helps as far as keeping the phone running smoothly, because you have RAM just like a computer. You want your battery to last, you don’t want to use as much data. Most consumers don’t really close their apps. They keep them running for fast access. But the Facebook app refreshes in real time from the server, so you don’t have to keep it running in the background.
Host: Any program that’s really using the server rather than device storage, you don’t have to keep running. It refreshes, because it’s on the server, just like email. Also, for those of you on iOS 9, Apple has installed a battery section in Settings where you can see the percentage of battery each application is using. If you tap on it, it shows you the life cycle of the app’s usage: how many minutes on screen and how many minutes in the background. If you’re not familiar with your device, this is a good time to dig through your phone and see what’s new. We can prevent a lot of this stuff just by reading. It also tells you how long your last cycle was between charges, over the last 24 hours or up to the last six days or so.
Host: Just like we said at the start of the show, a lot of this is the user. If you take a little time to understand your device and these policies and procedures, you’ll have a smoother operation, just like a computer. You’re not going to buy something and just wing it, or you’re going to have viruses, hackers, ransomware, and dead batteries. And then you’ve got to call Mr. Lowe to get you out of trouble.
Host: Or just buy his book. Safe Computing Is Like Safe Sex. Got to keep those condoms on. Mr. Lowe, any thoughts on the Facebook issue?
Richard Lowe: Well, Facebook, I don’t know how many lines of code there are, but there have got to be hundreds of thousands, if not millions. There are bugs in software, and things happen. It looks like they jumped on it pretty quick, and they’re going to fix it. I could say they should test better, but it’s a bug, and they happen. They happen in everything. Even the space shuttle and the space station have bugs. Even your phones have bugs. I know it’s disconcerting, but that’s part of life. The key point is: how quickly did the vendor get to it? And here it seems like they worked pretty fast.
Host: It was a little under six days, I think. They hit it pretty quick.
Richard Lowe: That’s blindingly fast, for something affecting hundreds of millions of people. I would say kudos to them. A failure on quality assurance, but a good job on recovery.
Host: Big recovery job. “We’re just going to sneak this one in here and see if anybody notices.” That’s how most companies with software operate. They release a patch super quick to fix a bug, like Apple with iOS 9.0.1. “We’re going to come out with 9.0, collect as much data as we can, and when they find out about it, we’ll release 9.0.1.” Got him.
Apple deletes 250 data-mining apps
Host: Speaking of Apple and data collection, that moves right into our next story. Over the course of last week, Apple deleted over 250 apps from the App Store, because they were secretly mining users’ data. One of Apple’s biggest pet peeves is user privacy.
Host: I was just joking that they collect it themselves. No, they’re serious about this.
Host: This past Monday they revealed what happened. These apps were accessing personal information like your Apple ID, your serial number, things of that nature. The possibilities are kind of endless with that info. It affected a little over a million users, and it was mainly a Chinese developer kit called Youmi that was responsible.
Richard Lowe: How many apps came from them? Is this a company that produced these apps?
Host: It’s a company that provides a software development kit used to put apps into the App Store. The developers using their kit didn’t know that Youmi was taking the data. It’s not exactly clear how many, but the vast majority of the 250 came through it.
Richard Lowe: Doesn’t Apple have to accept the apps first? Don’t they do security checks?
Host: They do, but they base it off what you claim your app does. They ask if it will collect data, the privacy agreements you have to agree to as a developer. And you say no, of course. So this one looks like it slipped through the cracks. A key note in the article: it wasn’t really the individual developers’ fault; it was the kit provider that collected the data on top of their apps.
Richard Lowe: Companies like Google and Apple, Google did this a while ago too. They deleted quite a few apps that slipped through, and they’re all tightening up their security. Apple’s pretty good about it, because this is a prime way in to infect phones and computers: these applications. People trust them. Usually the security prompt says, “I have god rights to your machine,” and you don’t really have enough information to say, I don’t want to give it that. So it has to be handled at Apple’s or Google’s end, and it looks like they’ve done a pretty good job. Something slipped through, it was buried deep in a library, and I’m sure they’ve tightened their procedures. I don’t want to minimize it, but things happen, and the key is how quickly they jump on it once they find it.
Host: We can also look at it from a numbers standpoint: 250 versus over a million apps. And just a few weeks ago in September, over two dozen apps, also Chinese, coincidentally or not, same thing: Xcode, the program you use to make the apps, was tainted. They’re trying to tighten all the loose ends. Apple is the most valuable company in the world, with the biggest customer base, and they got to it fast.
Host: None of these apps were named specifically, but as consumers, we have the ability, before we download an app, to read the reviews and the permissions. We need to get into the habit of doing that more often. A simple review read can steer you to a different app of the same quality with better reviews. These are our computers.
Richard Lowe: I’ll put it into a different perspective. The thing to remember is: your browser has access to a lot of data. If you let an app into your browser, whether it’s on a phone or a Mac or a PC, it can see everything you type, including your bank accounts, including your medical records, and everything else you do on that computer. And it doesn’t need any special privileges to do that, because it’s buried in your browser. So you do need to be careful. You do need to read those privileges and say, no, I don’t want him having god rights to my computer. I don’t know this guy.
Host: That’s actually a little scary, because I’ve seen it happen. I’ll search for something in Google, and two, three weeks later I get an ad banner while I’m searching for something different.
Richard Lowe: It’s important to keep in mind: your browser has access to everything you do, because people spend half their life in their browser, and it sees everything.
How do phones and smart cities track your location?
Host: I was with a group of folks last night having a conversation about this. Apple has just acquired a pretty big artificial intelligence company. These are things we need to be interested in, because as of right now, if you have location services turned on, your phone kind of predetermines where you live and where you work. It’s following your patterns. If they’re bringing an AI company on board, this thing is going to dig even deeper.
Host: I use maps a lot, and my phone will literally tell me: if you take your normal route to work, there’s a delay on your route. That’s a little scary. It’s convenient, it’s helpful, but at the same time they’re digging in our privacy. I don’t know if you guys have seen the movie with Will Smith, Enemy of the State. That movie was about the government spying on us through our televisions. Now it’s the cell phones. Everybody has a cell phone. The easiest way to get to everyone is a cell phone.
Richard Lowe: Let me give you a for-instance that adds a little context. You’re walking through your supermarket, down certain aisles, looking at certain things, let’s say Pampers. You get home, and your computer starts showing you ads for Pampers. You didn’t even take your cell phone out of your pocket. How does it know? I’m not saying it knows that now, but it could. If you live in a city with a lot of WiFi, it’s collecting the IP addresses of your devices.
Host: Smart cities are going to happen soon.
Richard Lowe: Exactly. I actually have plans to write a book on everything that’s known about you by the big advertising companies, and how they put it together. It’s fascinating. There are even cameras in stores that could, they don’t do this now, but they could follow your eyeballs and see where you’re looking, and based on that, put ads on your phone.
Host: Just like Minority Report, when Cruise walked into the subway and it scanned his eyeballs and sent him ads based on his likes and dislikes.
Richard Lowe: These companies build this profile so they can send you advertisements. That’s their main job. They know where you are. They know who you are, because they know what you’ve got. They even know how fast you type.
Mike: There’s actually a new product out there, a WiFi interface that turns your vehicle into a mobile hotspot. Some really good things can come from this, but there are security threats to pay attention to. Think about leaving work on Friday: there’s traffic on your route, you have to get gas, go grocery shopping, pick the kids up. Your phone could rearrange all those stops in the order that’s most beneficial to you. That’s future stuff, and it could be helpful. But at the same time, you’ve got people out there who want to take advantage, and now they know where you are, where you shop, they can follow you. Technology is awesome, but man, it opens the door to so many more threats. And that’s the plug-in device; Chevy and all these companies now advertise built-in WiFi right in your vehicle. Wherever you are, we’re recording where you are.
Richard Lowe: I’m sure it’s only a matter of time before the police officers can stop your car from their car.
Host: Like a bait car. Hit a button. With that WiFi enabled, GPS location is going to be enabled too. I was talking to a guy the other day and asked: if someone commits a crime, the first thing they do now is go for your cell phone and social media. They can find everything they want off that device.
Richard Lowe: Well, your typical user doesn’t even have a PIN on his phone to lock it. So they’re right in there without any trouble. You just gave them the keys.
Host: And people don’t even know it. But then again, you’ll get into some political stuff if police officers have the ability to just stop your car. They don’t have to chase you anymore. We’ll see what the future holds. Remember those old AT&T ads: “Do you think this is possible? You will.” Back to the Future had a hoverboard; there’s a real hoverboard now, from a pretty legitimate company. And Michael J. Fox tried on those Marty McFly Nikes, the self-lacing ones. Those are the only shoes I’ll pay over a thousand dollars for. Late for work, just jump in them.
Host: You’ll only save like 30 seconds. Hey man, that 30 seconds can be the difference between making it to work on time, especially in this Atlanta traffic.
Tip of the week: contextual reminders with Siri
Host: We’re going to do something a little different: the tip of the week, the plug, the trivia, and then we’ll give Mr. Lowe the floor to round us out. The tip this week is how to set contextual reminders with Siri, thanks to iOS 9. Before, if someone texted or emailed you something, you had to remember it or screenshot it, then manually make a reminder. Now Siri has received a major intelligence boost. She understands terms like “it” and “this.” Say you get a text: “Are we still on for dinner Wednesday at 8?” You can say, “Siri, can you remind me about this?” and there’s your reminder, without doing it manually. The same works for email and pretty much anything with a time, date, or place. Hold down the home button to talk to Siri, or use Hey Siri if you have it enabled.
Mike’s plug: where to find Richard
Mike: Good evening, folks. Tonight my weekly plug is for author Richard Lowe. His author page on Amazon is www.coolauthor.com, C-O-O-L-A-U-T-H-O-R dot com. His regular website is www.thewritingking.com, spelled out. His security book’s site is www.leave-me-alone.com, which is pretty hilarious. He has a book on disaster survival at realworldsurvival.com. And take a look at his blog, www.richardlowe.com. Awesome web address, by the way.
Host: Thank you for that, Mike. Mr. Lowe, did he get everything? Any other way people can follow you?
Richard Lowe: He got the websites. The book is called Safe Computing Is Like Safe Sex, and the blog for it is www.leave-me-alone.com. The other book is Real World Survival Tips, and both are available on Amazon, in Kindle and paperback format. The advantage of Kindle is, if I do an update, it goes straight to your Kindle.
Host: All you e-readers out there can catch Mr. Lowe. When it comes to privacy, there’s almost nothing more important these days.
Joe’s trivia: the first internet service provider
Joe: First we’re going to answer the question from last week. Actually, we’ll ask Mr. Lowe and see if he can figure this one out. Put him on the spot. The question was: there was a company who claimed to be the nation’s first internet service provider. Would you happen to know who that is, Mr. Lowe?
Richard Lowe: The first internet service provider, and it was a company, not the government… it’s not ringing a bell.
Joe: I’ll give you a hint. You had to access by means of POTS or X.25 dial-up. Their initial rollout supported 1,200-bit modems, and you were billed by time. It was pretty expensive.
Richard Lowe: It might be CompuServe.
Joe: Not quite.
Richard Lowe: AOL?
Joe: You’re getting warmer. It’s a service like that. CompuServe, which actually started in 1979, had a command line interface. But the first company to claim to be the first internet service provider is Prodigy.
Richard Lowe: Oh, yeah. I should have thought of that. I started on CompuServe, so that’s what came to mind.
Host: Mr. Lowe, I was with you on the AOL. I’m a 90s baby, so that’s pretty much the only thing I knew until 2000. For you guys out there who got stumped, it was Prodigy. If you were born after 85 or 90, you probably would never have known the answer without research. We’ve got another one for this week: name the year in which the number portability act passed. It has to do with wireless numbers, landline numbers, voice over IP numbers. A law passed that allowed you to take your number from one carrier to another. We’ll revisit it next week. Get your brains working.
The CISA cybersecurity bill
Host: Before we hand the floor to Mr. Lowe, let’s give him a big round of applause. This last topic is a big one: the fight for privacy in cybersecurity. There’s a new bill going through Congress right now. The goal is to tighten online security, but the way it’s written, the Cybersecurity Information Sharing Act, otherwise known as CISA, infringes on certain civil liberties and privacy that users have, using back doors, as they call it, to allow access to user data. Mr. Lowe, give us some insight: background, opinions, all of the above.
Richard Lowe: Okay. What CISA does is basically say that all breaches and all problems that relate to security need to be reported to the Homeland Security Department. They want to build a database of security problems and so forth. The problem is that, the way it’s written, there are really no particular limits on how much data the government can keep, or on protecting that data. It just says: we’re going to keep all this data. And they’re trying to solve a problem that I think the industry is solving itself, because the Target hack was super expensive, and the eBay hack, and all these things. The industry wants to solve these problems. Credit card companies are now making these little chips in the cards. I’ve been getting new credit cards like crazy in the mail to solve this particular problem. And I don’t know about you, but I don’t necessarily want the government knowing everything that happens on my computer, and all the breaches that might happen with my computer. As a matter of fact, I’d like them as far away as possible.
Host: Agreed, 100 percent.
Richard Lowe: I admit there’s a place for the government, like they control the internet itself, but I don’t think they need to be down at that level. It gives too much power to them. And this is only the tip of the iceberg; there’s more coming. But the worst part of this act is that it doesn’t actually protect anybody against anything. It doesn’t have any protection in there. It’s almost useless. I’ve been following the security papers, and the security personnel who are much higher up than me on the food chain are basically saying this is just a smoke screen. It really doesn’t do anything. And besides that, it even weakens privacy and security. So I would say: write your congressman, tell him you’re not interested in this, and tell him to come up with a real security bill instead of this thing.
Host: That’s pretty much what Apple and Twitter and Google and, I think, 19 other companies are trying to do. They have online petitions saying exactly what you just said: get a real solution to this issue. What they have right now is smoke and mirrors.
Richard Lowe: They’ve got a much bigger problem than Google and Apple and these other companies, and that’s how to protect the nuclear power plants and the electric industry and gas companies and all of the underlying infrastructure, which all runs on computers, which is all on the internet. Why focus on places like Google when the real problem is protecting stuff closer to home that’s more vulnerable? And of course the Department of Defense needs to be protected, because I’m sure they get hacked all the time. There are probably thousands of attempts per second against the Department of Defense. I don’t think I’d want to be one of their security people.
I don’t really have much more to say about that particular bill, other than it’s really not worth very much. It’s a little scary in that it sets some precedents, and it doesn’t provide much protection. It’s a lot of hot air. I would much rather see them get industry together in a conference and start creating security standards, and a way for various companies to talk together in a safe environment and work out some of the security problems themselves.
Host: And that works, because isn’t the internet itself an example of that?
Richard Lowe: The internet was originally created by DARPA, but then companies got together and added things to it and came to agreements: yeah, we’re going to handshake by turning our hand to the left three inches, and this is our secret handshake. The companies are able to do this, and really all they need is to be invited to do it. They’re working in that direction. I’m not sure there’s a role for government here at all. There is a role in protecting the power system and the internet itself and the other essentials of life. But I don’t think there’s a role in protecting Walmart or these other big companies. They can do it themselves, and they can get together and talk. We do that all the time in the security industry.
Host: Questions? No, this is awesome information. It’s very eye-opening, because they throw this stuff at you through the media: “We’re trying to protect you, this is good for you.” You never really have anybody who knows whether it actually does what it says it does. So thanks, Mr. Lowe, for that insight.
Richard Lowe: I think this is more of a smoke screen. I don’t think it does anything, really. And that seems to be the consensus of the people involved in the fight against it.
Host: One person was quoted as saying this is not a cybersecurity bill, it is a surveillance bill. Like what came out a couple of years ago, that the government is actually spying on people through their phones. Let’s be honest, let’s not pretend they haven’t been doing that. But it was in secret. This wouldn’t have to be. They’re just telling you: hey guys, we’re watching.
Host: It’s scary, because people live through their phones. It’s no different from your computer before phones were popular. If someone committed a murder, the first thing they’d do is grab your computer and see what you Googled. With a phone, there’s just more to dig through, and the location services create a whole different world, because you have a pattern of movement to associate with whatever information is found on the device.
Richard Lowe: For Android, and I was kind of interested to find this out, I have location services turned on, and there’s a place in Google you can go, log in, and see where you’ve been. Everywhere I’ve been is on that site. Everywhere, down to within a few feet. It has my whole path through the whole world, unless I left my phone at home. It was quite interesting. I actually needed it for something, so I thought it was kind of cool. But it’s a lot of data that they have. They do let you erase it, though.
Host: They say: just don’t let your girlfriend or your wife get hold of it, you sneaky little devils out there. The funny thing is, that’s how a friend of mine found out about it. Someone posted on a social network how to find their significant other. So I looked at my phone and checked, and it was there. If you reroute yourself from work to home, it’s going to show where you went. I showed a lady that one day and she was amazed. It showed her all the way down in Cancun, Mexico, exactly where she went: a hospital, a church, all these different places. It records everywhere you go, how many times you go there, exactly what time you were there, and how long you stayed.
Richard Lowe: And you gave it permission to do that, by the way, because you turned on the location service.
Host: It’s at the beginning, when you set the phone up. People probably just skip right through it, because they’ve got the new shiny device and they want their home screen.
Richard Lowe: I turn it on because I think it’s pretty cool, and I like looking at where I’ve been. But when you think about it, if it got into the wrong hands, and you were doing something not quite kosher, it probably wouldn’t be something you’d want. Then again, if you were trying to keep track of where your teenage kids were going, maybe it’s a good thing.
Host: Six of one, half a dozen of the other. There’s a lot of good about it. Let’s see the glass as half full on this one. Even if this bill gets revised or rejected altogether, this whole location tracking isn’t going anywhere.
Host: I think they should just stick something inside of you when you’re born. Then we don’t have to worry about it.
Host: It ain’t going to be that far away from that. Think about it: you don’t have to worry about anybody committing a crime anymore. “We just saw you see yourself take that vehicle. Come on, put yourself in handcuffs.” But just think about how many cameras there are. They’re everywhere now, on the street, light poles, everywhere. I was speaking to somebody the other day who works in a roadside assistance program. He said the highways have so many cameras that nobody knows about; they can locate you to within feet of where you call in.
Host: The first time I saw that happen was 1999, in New York City. A friend of mine got a letter in the mail with a picture of her vehicle tag at a location, running a red light, and a big fat ticket. In 1999. Imagine what they can do now. I think they can get you speeding now; in Virginia or Florida, they have these signs on the side of the road that say your speed is being monitored.
Richard Lowe: Well, you can fit a camera in the head of a pin now, I think. Or at least in a button. It could be anywhere.
Host: So people, just do what you’re supposed to do. Welcome to the 21st century. And beyond. Like Buzz Lightyear: to infinity and beyond. It’s crazy. It gives you a lot to think about.
Closing advice: back up, verify, protect
Host: Mr. Lowe, we appreciate you coming on. Do you have any closing thoughts for us?
Richard Lowe: The key to having safe computing, which is one of my specialties, and the book is called Safe Computing Is Like Safe Sex…
Host: Buy it. Buy it now. We will find you.
Richard Lowe: …is to change your habits to be safe. It’s like drinking and driving: don’t drink and drive. Just don’t do that, and you’ll be safe. Don’t click on links in emails that you don’t absolutely know are safe. Don’t give out personal information on websites that you don’t absolutely know are the right website. Look up at that URL, that address up there. Does it say Bank of America, or does it say Bank of America with “of” spelled F-O instead of O-F?
Host: Bank Fo America.
Richard Lowe: That is a common technique called phishing. It looks just like the Bank of America site, but it ain’t. You put in your account information, and then you’re on the real Bank of America site, and they have your data. You’ve just got to keep your eyes open and watch things.
And the number one advice, the first thing people need to do if they’re not doing it now, is back up their computers. Get a product; there are several of them. Carbonite is one, Livedrive is another, and there are dozens of others. Those two cost, I think, 60 or 70 bucks a year: unlimited storage, backup over the internet, automatically. You just install it and forget it. There’s absolutely no excuse, assuming you have an internet connection, to not have a backup anymore. Then, if you’re clobbered by a virus, or your hard drive crashes, or your girlfriend throws your computer out the window because she’s mad at you, you’ve got a backup somewhere else in the world. You could even have a hurricane totally wipe you out, and your data is somewhere else. Your pictures, your personal pictures from your childhood, all the pictures you took on vacation, your checkbook, your taxes, everything is on people’s computers now. For Christ’s sake, back it up.
Of course, computer people are the last people to back up. We always say back it up, and then I go rescue computer people’s computers, and there’s no backup, ever.
Host: They say doctors are the worst patients. There you go.
Richard Lowe: So the first thing to do is get one of those products, install it, and get a backup. And of your phone: if you’ve got an Android, and I’m sure Apple has the same thing, it will automatically back up to your Google account. Do that, because if you lose your phone, you lose that data. And speaking of phones, there’s a little app you can have that lets you erase it remotely. If somebody steals it, you click a button and boom, it’s gone. Put that on your phone.
And you need to install antivirus, whether you’re on a Mac or not. I know Mac people say they can’t get viruses, but you can. You need all the usual tools. But the weak link is the person. I go into this a lot in my book. You have your computer, and you let a guest come in and use it. He doesn’t know your security procedures, and guess what, he probably downloaded a virus. Or you let your teenager use it overnight. That teenager is probably looking at porn, and your computer is infected. Boom, you’re gone. All these things are covered in the book: how do you let your teenager use the computer and still have it be safe, for example? There are ways to do that. The book goes through what we call best practices in the computer industry. These are the things you should do on a regular basis. Just get in the habit of doing them.
Host: Everybody out there secures their home with an alarm system, protecting physical things from being taken. But the things that are more valuable to us are our banking information, our logins and passwords, our data. That stuff you can’t get back. They take that, they take your whole life. Your Social Security number. Physical things, TVs, computers, you can get those back. And like Mr. Lowe said, if someone steals a device, you can wipe the data away. But it’s pointless to secure your physical home while you’re allowing intruders in through a different hole. If you’re securing your home, secure your mobile and electronic devices also.
Richard Lowe: You can also get a product called, interestingly enough, LoJack for Laptops. You install it on your computer, and there’s a phone version. If your laptop or tablet is stolen, it works just like LoJack on a car: it tells you where it’s at, and you can send the cops there to pick it up. And LoJack for Laptops also allows you to wipe the computer clean, so the thief doesn’t get all that data. Because that’s the other scary thing: not only did you lose your data, but they have it.
Host: Very valuable info. We’ll be linking to all of Mr. Lowe’s sites and where you can buy his book. Once again: buy the book. Guys, give him a round of applause. Thank you so much, Mr. Lowe.
Richard Lowe: You’re welcome.
Host: Everybody, we’ll talk to you next week. Remember: stay safe, in sex and in computing. This is 3 Ps in the Podcast. We’ll see you next week.
Find Richard Lowe at thewritingking.com/.
Quotable moments
Safe computing is not something you can just install a program on. It’s something, as with safe sex, that you have to practice. You have to change your habits. — Richard LoweShare on X
The problem is not the machine. The problem is the user. And it’s not that the user’s not intelligent. It’s that hackers use social engineering to cause the user to do something. — Richard LoweShare on X
Your browser has access to everything you do, because people spend half their life in their browser, and it sees everything. — Richard LoweShare on X
Related appearances
Frequently Asked Questions
Part of Richard Lowe on Air, his complete run of podcast, radio, and video guest appearances.
