The Writing King Your Ethical Ghostwriter. Your Story, Done Right.
This entry is part 56 of 92 in the series Richard Lowe on Air

CISA Passes, Ransomware Pays, and Stuxnet: The Return Visit | 3 Ps in a Podcast

Featuring Richard Lowe on 3 Ps in a Podcast, with hosts Artis and Mike

TL;DR: What This Conversation Establishes

  • Brought back one week after his first appearance, Richard rejoins the show as CISA passes the Senate 74 to 21
  • His verdict on the bill holds: weak, bureaucrat-built, more smoke screen than security, with one genuinely alarming amendment about de-anonymized data in “emergencies”
  • A single Eastern European cyber mafia group pulled $350 million out of one company; ransomware is a business, and the victims fund it
  • Backups against ransomware must be offline. The always-connected backup drive gets encrypted right along with everything else
  • Don’t be afraid, be prepared: fear is not a security strategy, habits are

This is the complete conversation from Richard Lowe’s return visit to 3 Ps in a Podcast, one week after his first appearance, lightly edited for readability. Hosts this episode: Artis and Mike, with Joe out for the week.

The returning guest

Artis: Welcome to another fun-filled episode of 3 Ps in the Podcast. I am Artis.

Mike: I am Mike.

Artis: And we are 3 Ps in the Podcast. We’re a P short this week; we had a call-out from Joe, but he’ll be back with us next week. This week on the show: it’s a bird, it’s a plane. Actually, it’s T-Mobile CEO John Legere with a sky-written message for Verizon and AT&T. Is 2015 Apple’s most successful year ever? They certainly seem to think so. And the Senate has passed the controversial cybersecurity bill, CISA, by an overwhelming ratio, so we’ll talk about what that means for you. Plus the tip of the week and Mike’s plug. But first, we want to introduce our returning guest, acclaimed author and cybersecurity expert, Mr. Richard Lowe. How’s it going, Mr. Lowe?

Richard Lowe: It’s going well, thank you. Glad to be here.

Artis: Thank you so much for joining us again. Anything you want to say to everybody before we get started?

Richard Lowe: Let’s just get started.

T-Mobile’s momentum and the carrier wars

Artis: The very first thing: T-Mobile right now has the most momentum in the mobile world. They’ve gained about 2.1 million customers in the last quarter. Second was Verizon with a little over 400,000, and AT&T actually lost about 800,000 customers in the same period. What everybody’s attributing this momentum to is John Legere’s audacity and willingness to step outside the box to put customers back in charge. He had a sky-written message for AT&T and Verizon telling them to stop the overage charges, which T-Mobile stopped a while back. Mike, Mr. Lowe, thoughts?

Richard Lowe: Well, I use one of T-Mobile’s other brands, MetroPCS, and they changed to the T-Mobile network a while ago. And wow, did it get better. It’s amazing. The old network wasn’t great, but once T-Mobile acquired MetroPCS and put it on the new network, it was really good. And there are no overage charges. There’s nothing. It’s great.

Mike: That’s what they were going for. They took some of that AT&T breakup money and definitely upgraded their network. And it’s probably going to get better; there’s another spectrum bidding award coming up in the next year or so, so T-Mobile will likely be looking at more towers and more spectrum. I’ve always said, if they can ever get their quality to match their innovation, they will by far be the best carrier to subscribe to.

Artis: Speaking of the other carriers: AT&T and Verizon aren’t very happy with the whole T-Mobile thing, and also with Apple’s upgrade program. T-Mobile has attributed most of their growth to the iPhone upgrade program. Their financial chief was quoted saying, “We love it. It’s interesting, it’s simplistic, it brings customers more options, and it’s been a benefit to us.” They’re by far the fastest growing carrier. Verizon’s statement was: “If Apple finances the phone, we don’t have to. But the problem comes that if the customer has a negative experience, they’ll expect Verizon to take care of the issue. I don’t think the ecosystem was fully thought through.” What do you think about that?

Mike: That’s technically not true. If the customer finances the phone through Apple, then Apple’s going to take care of all the issues regarding the phone. Verizon is responsible for the service aspects, but hardware-wise, it’s Apple. And if there’s one thing Apple stands by, it’s their customer experience. I don’t think I’ve ever seen a company stand by their product more than Apple does.

Artis: To quote AT&T, there’s a little hypocrisy in their statement. Their finance chief John Stephens said: “I don’t think it’s a good deal for the customer, paying for the phone but not owning it. But I’m just a finance guy. If our management thought the customers wanted leasing, then we’d do it.” That sounds a whole lot like the AT&T Next plan, which is almost the exact same thing: a lease-to-own program.

Mike: Coming from a CFO, that statement doesn’t make logical sense, because technically, on the AT&T Next program, you are leasing the phone for a set period unless you make all the payments, and then it becomes your own.

Richard Lowe: Well, AT&T is a competitor to T-Mobile, so I wouldn’t expect them to say T-Mobile has a great idea. It’s just par for the course. What are you expecting a competitor to say?

Artis: Right. And Apple’s program is actually a little better in some ways: the phone is automatically unlocked when you get it, which is good for travelers, and it’s only a 12-month program, whereas AT&T offers 12, 18, and 24 months. Apple, T-Mobile, Verizon, and Sprint are offering only 12 months now.

Mike: I think 12 makes more sense. A lot of consumers change their devices after a year anyway, especially iPhones. The point of the program was to upgrade early, so giving people a two-year option kind of defeats the purpose. People were complaining about two-year contracts; why offer a two-year payment term? Now they’re paying for the phone visibly. Of course, they always paid for the phone, but they didn’t know it.

Artis: I think AT&T may follow suit. They’re going to have to stay competitive. Losing almost a million people in four months is not good. What do you think, Mr. Lowe?

Richard Lowe: I think you’re absolutely right. I was just reading the article here while you were talking, and what’s fascinating is the churn rate, the rate you lose customers. For T-Mobile it’s very, very low; they’re only losing 1.4%. That means people are satisfied with the service and want to stick around. And based on my experience, that would be true. I’ve been with them now for, what, three years?

Mike: I think part of it is wanting to see what they’re going to do next. With Verizon and AT&T, you’ve come to expect the status quo. With T-Mobile, you don’t know what they’re going to do next, so part of people sticking around is probably intrigue about what’s coming.

Artis: And we can look at AT&T’s loss of customers as possibly attributable to the one-year options at the other carriers. Some kind of change is on the horizon, because the whole point is to stay competitive.

Apple’s most successful year ever

Artis: Moving on: Apple has called 2015 their most successful year ever. That’s a quote straight from Tim Cook. They made a whopping $234 billion this year. They have more money in the bank than the entire economies of the Czech Republic, Peru, and New Zealand make per year. Their cash increased by $2.8 billion in the last three months alone, mostly from selling 48 million iPhones in the last quarter, a 30% increase over the same period last year.

Mike: And this is all prior to the iPad Pro coming out. Just to be clear, that quarter is June, July, August, September: Apple’s fiscal third quarter. The first three months of that were iPhone 6 sales, and the last month, really only half of it because the phone came out on the 17th, was 6s sales.

Artis: I think Apple’s on track to become the first trillion dollar company. That’s what the analysts are saying, and there’s nothing to suggest otherwise at this point.

Richard Lowe: Well, the sales in China are going to push it over the top.

Mike: Especially since it was available in China on launch day this time around; nobody had to wait. China is the biggest mobile market. If you can conquer that market, you can pretty much conquer the world. And 48 million iPhones in a quarter is more phones than a lot of manufacturers do in a whole year. They’ve still got their most impactful months coming up, so it remains to be seen where they finish, but it’s definitely looking good in Cupertino. There’s a picture of Tim Cook on this article with one of the biggest smiles I’ve ever seen.

Apple’s new Genius Bar repair program

Artis: Speaking of the 6s: Apple has a new program to cut down wait times at their Genius Bars. This past week they launched a program for the 6, 6s, 6 Plus, and 6s Plus in select stores across the US, Europe, and Japan. Instead of completing all repairs in store, for phones needing extensive repairs, the Genius Bar can use their discretion and ship the phones to an offsite repair center. Three categories qualify: the device won’t connect to a computer, it won’t power on at all, or it doesn’t boot past the Apple logo, that world-famous boot loop. And they’ll give you a loaner for the duration: a 16-gig iPhone 6.

Richard Lowe: That’s actually great. You never lose service.

Mike: People complain about having their phone sent off. Now it doesn’t matter, because you’ll have a phone to use in the meantime. That’s better than actual phone insurance. And those failure categories are hardware failures, so they’re covered under the one-year warranty as well.

Artis: Is this only for customers who purchased AppleCare?

Mike: No, it’s covered as long as the phone is under either AppleCare or the one-year limited warranty.

Richard Lowe: It kind of makes me wonder why they don’t just let you keep the loaner phone and do a swap. Without that, they’ve got this second half of the loop where they have to get the customer back in to return the loaner and pick up the repaired phone. It seems like they could eliminate that whole thing. Just replace it and refurbish the one they get back. You’re going to have happy customers.

Mike: That might be something they explore case by case. Since they’re only doing 16-gig loaners and most people have at least 64 gigs, maybe that’s why. But it does make sense. And it frees the rep’s time in the store from fixing that device. Make another sale. Pretty smart move. I’m interested to see if any carriers follow suit with their insurance plans, or any manufacturers with their warranties.

Where to find Richard, and a new book announcement

Artis: Before we get to the controversial CISA bill, we want to remind everybody that you can keep up with Mr. Lowe. His author page on Amazon is at coolauthor.com. His website is thewritingking.com/. His security book is at leavemealone.com, his disaster survival book at realworldsurvival.com, and his personal blog is richardlowe.com. And of course, he has the awesomely titled Safe Computing Is Like Safe Sex. I love that title. Anything you want to tell everybody, Mr. Lowe?

Richard Lowe: Yeah, I came out with a new book.

Artis: Awesome, that’s what I was hoping you would say.

Richard Lowe: It’s a book of tips to help you deal with unprofessional behavior from the boss. I just released it. It has examples of unprofessional bosses, everything from the boss who’s harassing to the boss who’s a raving lunatic, and what do you do about it. I’ve encountered some of these bosses, and some friends have had them. It’s a short book, something you could read in a couple of lunches, and it gives you some help to deal with those people you run into in life. And sometimes what you’ve got to do is just leave. Sometimes you can handle it.

Artis: I’m sure after reading your book, we’ll be more equipped to handle those situations. Where can we find it?

Richard Lowe: Just go to coolauthor.com. It lists all the books I’ve published, and you’ll find it there. The other news is that Real World Survival Tips is on sale for the next week at 99 cents on Kindle.

Artis: Nice. Is there an e-reader version?

Richard Lowe: It’s available on the Kindle and in paperback.

Tip of the week and Mike’s plug

Artis: The tip of the week: how to use 3D Touch on your iPhone 6s and 6s Plus to peek at web pages without opening them. When you see a link in your email, a text, or while browsing, press hard on the link with 3D Touch and it opens a preview in a new window. Hold there and it shows you the page; swipe up without lifting your finger and you get a menu of further actions, like opening in a new window, copying it, or adding it to your reading list. Return to what you were looking at by lifting your finger, or press harder and it opens the page fully.

Mike: Tonight I’m plugging an object: the Nyrius Smart Outlet. You all know about connected homes; this is a connected plug. It runs off Bluetooth with a 33-foot range and connects to your smartphone, iOS or Android. With iOS you can control up to three of these smart plugs; with Android, up to seven. A lot of people complain that connected home gear has to be on your internet connection at all times; this only requires Bluetooth. For those looking to cut the cord and have remote control electronics, it’s a perfect solution. It’s available right now for $39.99, and there’s an article about it on Gizmag.

Cyber crime by the numbers

Artis: Since Joe is out, we’ll get the trivia answers next week. A little bit of stats before we jump into the CISA bill. With the threat of cyber crime, there was a recent survey that found nearly three of four adults in the United States, about 74%, say they have recently changed their online behaviors due to these threats. The most common changes: not conducting as many transactions on shared networks or shared computers, at 46%; changing passwords more often; not giving out personal info; not using public WiFi. The perception of security has also changed, which Mr. Lowe touched on last week. But 81% of these people still have not invested in any kind of identity theft protection. People know about this stuff and are changing behaviors, but the main thing is protecting yourself. Mr. Lowe, the floor is yours.

Richard Lowe: Well, I’ve been doing a lot of research on cyber crime, because I’m updating a book for a big company that they give away for free, called Cyberheist. One of the statistics: a single Eastern European cyber mafia group managed to get $350 million from a single company, just by doing spoofing, ransomware, and other techniques to get money from people.

Artis: Wow.

Richard Lowe: If you’re familiar with the concept of ransomware, it’s where your computer is hijacked and you have to pay some amount of money, usually around $500, to get your computer back. And they’re making hundreds of millions of dollars off of it.

Mike: People are actually paying this stuff?

Richard Lowe: Apparently. At that amount of money, it’s more than a few. But your choice is to throw your computer away or pay the money. And paying the money doesn’t always work, is my understanding. I’m not sure I would do that. Having a good backup is a better solution. A good offline backup. You have to keep it offline. If it’s online, it can also be infected by the ransomware.

Artis: Okay, I didn’t actually know that. I thought any backup would be fine.

Richard Lowe: No. A lot of people have another hard drive that they always keep turned on, and they copy files to it. The ransomware will zap that hard drive. Some people copy over networks, and the ransomware will catch that too. You actually have to have it on a hard drive or a disc that is offline, that you put in a closet and only back up to once in a while.

Mike: That’s very important, because a lot of people are taught that any backup, online, offline, or a combination, is okay.

Richard Lowe: And I just had a long conversation with the folks at Carbonite, which is an online backup utility; you install it and forget it, and it backs up your system. They can actually recover from ransomware. They keep multiple versions of the data they back up, so you can call them and they’ll work with you to get your data back. So all is not lost, if you’re smart enough to do a good backup, either using something like Carbonite or Livedrive or one of the other products, or an offline backup such as a hard drive or DVD or Blu-ray. If you don’t do a backup, then you’re pretty much stuck.

Mike: We deal with that quite a bit with cell phones too, people just not backing their stuff up.

Richard Lowe: With cell phones it’s even easier, because on both Android and iPhone, you just turn it on. It’s built in. There’s not a lot of excuse there, other than you didn’t know.

Artis: Or some people just don’t think they’ll ever need it. Until they lose all their contacts and photos and everything else. They always have that one photo they just have to have, life or death. Definitely keep that backed up.

What is spear phishing and how do companies get breached?

Artis: A couple more stats: only 50% of consumers said they trust the retail industry with their personal data, and even fewer, 41%, trust the government with their information, which is a good segue. Also, 93% of survey takers said they’d like the public and private sectors to do more to fight cyber crime: more money invested in cybersecurity, more qualified people hired to handle it. And some tips: create stronger passwords, don’t open unknown email attachments, keep your firewall up to date. Also, most companies don’t ask for personal information through email; they’ll call you or send actual correspondence through the mail. If you get an email asking for a Social Security number or anything like that, more than likely you shouldn’t put your information there. Thoughts?

Richard Lowe: Yeah. When you get an email that has a link in it that says, come here to fix your account, or you owe money to the IRS, don’t click on the link. Just go to your browser and type the address in yourself. That way, when you log in, you’ll usually find out the email was totally bogus. I usually just delete them and not even worry about it.

Mike: That’s the best practice, for sure. Also, when you’re browsing online, if it’s a secure website, you’ll get a lock at the top, and sometimes it’s green, to let you know it’s secure.

Richard Lowe: That’s very important when you’re on wireless. And my book goes into that.

Artis: You were talking about that email attachment thing last week. A lot of people fall for that. That’s called phishing, right?

Richard Lowe: Phishing is where somebody will send you an email saying you need to log into Bank of America, and the website you click on isn’t anything to do with Bank of America. It grabs your password and username and then sends you over to the real Bank of America site saying “password failed,” so you never even know, until of course your account’s drained. And there are multiple types of phishing. Spear phishing is where a hacker will actually investigate who’s at a company, find out the names of the CEO and other executives, and then send tailored phishing messages to each person in the company with information that makes it seem more real. You might get a letter that seems to be from the CEO, with his name and personal information that makes it seem like it really is him. That’s called spear phishing, and it’s usually done for espionage purposes.

Mike: That’s some pretty heavy stuff. They’re putting in so much work just to not do the right thing. They dedicate so much time and effort to figuring out ways to screw people out of their hard-earned money.

Artis: I think the people who perpetrate these crimes are banking on the fact that maybe four out of ten people don’t pay attention and will pay, and the other six have either had it happen before or are educated enough to know it’s a scam.

Richard Lowe: Well, to infect a company, all it takes is one.

Mike: I’m sure that’s their biggest target: just that one person who’ll click and bring down the whole company.

Richard Lowe: Then you’re heading into cyber terrorism and cyber warfare type stuff. That’s when it gets really crazy.

What was the Stuxnet virus and what did it do?

Artis: You start seeing stuff like the whole North Korea thing with Sony earlier this year. This is crazy, man.

Richard Lowe: If you really want to have some fun, read up on the virus called Stuxnet. S-T-U-X-N-E-T. That’s a cyber virus that is believed to have been created by the United States and Israel to attack Iran. And it is nasty. It’s very specific. It was specifically targeting the centrifuges in Iran’s nuclear program, and it was very successful. It caused the motors to fire wrong and actually caused the centrifuges to rip themselves out of the ground.

Mike: That’s crazy. And there’s that threat right now with Russia threatening to mess with the underwater fiber internet pipelines, which is another scary thing to think about: the whole US internet grid going down.

Richard Lowe: That would be an interesting day. Most companies wouldn’t be able to function.

Artis: A lot of companies run strictly on the internet. Just imagine your average teenager without a cell phone. That’s terrifying enough. Multiply that by a few hundred billion dollars and it gets real crazy.

CISA passes the Senate

Artis: To jump into CISA: the vote was last Tuesday, and it was an overwhelming result. The support was 74 to 21. None of the Republican candidates running for president were present to cast a vote except Lindsey Graham; Rand Paul was not either. So, 74 to 21, not even close, and everybody’s up in arms. Mr. Lowe, what do you think happens next?

Richard Lowe: Well, the bill itself just allows Homeland Security to collect certain kinds of data. One of the alarming things is that one of the amendments to the bill actually says that under emergency conditions, the federal government can get sensitive data that is not anonymized, meaning they can get data with your phone numbers and things like that in it, and find out who you are, in an emergency situation. And they define what an emergency is. Overall, the bill’s pretty weak, but that amendment is where the privacy problem comes in.

Mike: That’s crazy. They’re always talking about protecting data, and they pass a bill that literally allows them to do quite the opposite.

Richard Lowe: They’re trying to build up a database of cybersecurity threats. I think the idea is sound, but the bill doesn’t look like it was made by computer people or people who know what they’re doing. It was made by government bureaucrats, and maybe even espionage people. It’s very weak, and it really doesn’t do very much. There’s not a lot to be afraid of in it. It’s something they threw together to placate people. That’s the word.

Artis: So if you’re deemed a threat now, do they have the right to harass you?

Richard Lowe: This doesn’t give them the right to harass. This is more of a data collection bill. They’re building up a database, similar to the medical database being built up, of patterns of threats, so they can hopefully predict where attacks come from and learn more about the kinds of attacks. But it could have been a better bill. It may have started as a better bill; you know how committees are.

Artis: Looking at some of the comments: Edward Snowden said a vote for CISA is a vote against the internet. People are saying this is the day the internet died. And then you have the bigger organizations, go figure, the American Banking Association and the Telecommunications Industry Association, saying, “We applaud the Senate for moving this important bill and urge congressional leaders to act quickly and send it to the president’s desk.” There’s a lot of optimism that Obama will sign it into law soon.

Richard Lowe: He will almost certainly sign it.

Mike: Wouldn’t that kill the Freedom of Information Act?

Richard Lowe: Nothing to do with each other. This is a bill to allow the government to collect data about security problems, unauthorized accesses, things like that. The Freedom of Information Act lets you get information about a government program or a government document. They’re two different things. They really have nothing to do with each other. Good question, though.

Artis: There are a few security researchers who have come out against the bill, saying it does very little to improve security and instead spreads user data broadly across the government’s IT systems. Pretty much confirming what you said, Mr. Lowe.

Richard Lowe: What I’m hearing from my security friends is that it’s basically more of a smoke screen. And one of them calls it, kind of humorously, the AT&T Verizon Protection Act. A lot of bills go through and people get alarmed about them, and maybe they should, and certainly we should discuss it. But this isn’t a bill I would be super alarmed about. I’d be more alarmed that it’s pretty lame. If we’ve got cyber attacks from Russia and North Korea coming in, we should be doing something a little stronger to protect ourselves, like the electrical grid and the internet itself.

Artis: And based on what I read about the North Korea hack, apparently that was a very easy thing for them to pull off, which is scary to think about.

Richard Lowe: Internet hacks like that are almost trivial to pull off. They’re almost frightening in how trivial they are. A distributed denial of service attack is easy. That’s where you get multiple computers, sometimes hundreds of thousands of them, all attacking the same target at the same time, usually trying to bring a server down by just overwhelming it.

Mike: Just a whole bunch of attempts on those servers, back to back to back.

Richard Lowe: Viruses take over personal computer systems, not necessarily to take information from you, but to take control of your computer and use it in distributed denial of service attacks. They’re called botnets, and sometimes they have millions of systems that all have viruses on them. Their purpose is to be able to make distributed attacks. And spam: they can work as spam relayers, so spam goes through your system and out. It becomes very hard to trace at that point, because it’s going through a million different systems.

Artis: It just gets lost in translation.

Richard Lowe: That’s one of the things about getting your system infected: it’s not just you it’s affecting. Your computer becomes a tool for the criminal.

Mike: Since you said that, that’s almost to the letter what Tim Cook was saying about encryption: you can’t keep out the bad guys and let in the good guys. You can’t keep out one and leave the other.

Richard Lowe: Yep. I run a firewall and three antivirus programs on my computer all the time, because I don’t want to be infected. And I have multiple backups and all kinds of stuff. I use this for my living. It’s a Windows machine, so a little different than you guys like, but it works. It does have 16 cores.

Mike: Nice. I’ve got a custom-built one myself on my Mac with 16 as well.

Richard Lowe: Mine was custom built too. I do videos and things. But anyway, CISA. I think it’s a lot of to-do about not very much. There are things in it you might be alarmed about, but really, it doesn’t go far enough to secure the internet, and it’s the wrong direction.

Artis: That seems to be the general consensus. There are a lot of holes and problems with the internet that need to be fixed, and this doesn’t do anything for that. Do you think they’re going to make it better?

Richard Lowe: Well, IPv6 is coming out and being slowly rolled out. TCP/IP, which is what the internet runs on, was created back in the 1970s, and it’s not good enough for the internet anymore. I could go technical, but I’m not going to. So they created IPv6, which is a better version. It’s more secure. As it rolls out, and it’s going to take years, the security of the internet will improve. They’re also putting improvements on domain names and things. But when you’re talking about billions of devices out there on the internet, it takes time. You can’t just wave a magic wand and the internet’s secure.

Why is the Internet of Things a security problem?

Richard Lowe: You were talking about smart plugs earlier. Well, there are security issues with those smart plugs. A hacker can take control of a smart plug or a smart light bulb or a smart alarm that’s on the internet. Now, I’m not sure I care if a hacker has control of my smart light bulb. But maybe I do care if he has control of my smart alarm system. That’s called the Internet of Things, and it’s becoming very big. Your smart plugs are an example. And it introduces a whole bunch of new security concerns. How do you patch those? How do you keep them up to date? Do you firewall them? This creates more and more stuff that needs to be protected. You’re talking tens of billions of systems and hundreds of billions of devices on the internet. It just becomes bigger and bigger. And it’s amazing that it all works. You think about it: it’s amazing it all works.

Mike: One of my major concerns with everything being connected: if hackers can hack into your smart bulbs or your smart alarms, they can definitely hack into your car if it’s connected.

Richard Lowe: The car is a big problem.

Artis: Like we were talking about last week, where the cops could stop a car.

Richard Lowe: If a cop can stop it, so can a hacker. And what about the cops? Do they have smart cars too? Maybe the criminals can stop the cop cars that are chasing them. It becomes a whole bunch of questions that need to be asked when you make these smart things.

Mike: Their dash cams and body cams are already connected to online servers. With certain criminals, you’re looking at the possibility of tampering with legal evidence, things that can be used in court.

Richard Lowe: I think the body cams and dash cams are great, because now it’s no longer a he-said-she-said situation. You can actually see what happened and come to a judgment based on real data. But exactly what you said: if it’s online, it can be hacked. And it’s not that hard to change video. If they can hack into the server, changing the video is like turning on a light at that point. Or deleting the video.

Artis: I like when you said it’s a bill to protect AT&T and Verizon.

Richard Lowe: That’s one of my friends. He says it’s the AT&T Verizon Protection Act, and I thought that was funny.

Mike: They’re connected all the way around. Even with emergency services: 911 was created by AT&T a long time ago. A lot of the spectrum this equipment uses is owned by AT&T. They’re connected a lot of different ways in this thing.

Don’t be afraid, be prepared

Richard Lowe: But I think the important thing is not to live in fear. That’s what I wrote my book for. Safe Computing Is Like Safe Sex is: don’t live in fear, just protect yourself. Do the things that are smart. Put in a firewall, put in some antivirus, don’t click on a link. I have hundreds of tips in there. Just change your habits and don’t be afraid. If you’ve got a good backup, you don’t need to be afraid of anything. You can recover. If you don’t have a backup, well, then maybe you should be afraid.

Artis: So basically what I’m hearing is: your book, and you, are pretty much going to save the world.

Richard Lowe: Well, we’re going to keep you from being afraid. I’m not necessarily going to save the world, but the world shouldn’t be afraid. There are things to be concerned about, but even then, don’t be afraid. Learn about it and then counter it. I might be worried about cyber terrorists hacking my system, so I’ll put up some firewalls and make sure they can’t. Don’t be afraid. Fear is not a very good thing to be in.

Mike: Don’t be afraid, be prepared.

Richard Lowe: Exactly. And that’s the whole subject of both of my books, Real World Survival and Safe Computing Is Like Safe Sex. Most people are taught to be afraid of this kind of thing and to try to avoid it. But it’s really about knowing how to counteract it and being prepared. Learn about it. Actually read, look up the words in the dictionary, read about how to prepare for it, and then read about how to counter it. Instead of thinking your computer is something you take out of the box and it’s safe. It’s not. Maybe you need to do some things, on Windows or Mac or Android or iPhone, whatever. Learn what the threats are, and then how do you counter them. One of the things in my Real World Survival book is situational awareness. Instead of being afraid, just be aware of your surroundings. Muggers look for people who aren’t aware, who are staring off into space or not paying attention. If you’re aware of your surroundings, there’s less chance they’re going to mug you, because you might remember their face, you might see them, you might hit back. But if you’re half asleep while you’re walking, then you’re a target. That’s really what the security thing is: be aware of the situation and prepare for it.

Artis: With your book and other tools out there, people are getting more educated about it. Unfortunately, not on as large a scale as it probably should be, but the numbers are going up, and that’s a pretty decent trend. Well, I guess we’ll wrap it up, guys. Mike, anything to add?

Mike: No, I’m good.

Artis: Mr. Lowe, anything to add?

Richard Lowe: Nope. It was a good show.

Artis: Thank you so much for joining us. Let’s give a round of applause to Mr. Lowe.

Richard Lowe: I’m taking a bow.

Artis: For Mr. Lowe, for Mike, and for the absent Joe, I’m Artis, and thank you so much for joining us. We’ll holler at you next week. Have a wonderful evening.

Find Richard Lowe at thewritingking.com/.

Quotable moments

If you’ve got a good backup, you don’t need to be afraid of anything. If you don’t have a backup, well, then maybe you should be afraid. — Richard Lowe
Share on X

Your backup has to be offline. The ransomware will zap the hard drive you keep connected, and it will catch the network copies too. — Richard Lowe
Share on X

Don’t be afraid, be prepared. Fear is not a very good thing to be in. Learn what the threats are, and then counter them. — Richard Lowe
Share on X

Related appearances

Frequently Asked Questions

Why do backups need to be offline to protect against ransomware?
Ransomware encrypts every drive it can reach, including the external drive that stays plugged in and folders shared over the network. A backup only survives if the malware cannot touch it: a drive in a closet, a disc, or an online service that keeps multiple file versions.
What is spear phishing?
Targeted phishing built on research. The attacker learns who works at a company, who the executives are, and sends each person a tailored message that appears to come from someone they trust. It is the espionage version of the mass phishing email, and one click is enough.
What is a botnet?
A network of infected computers, sometimes millions, controlled by criminals. The machines are used to launch distributed denial of service attacks and relay spam, so an infected home PC becomes a weapon aimed at somebody else.

Part of Richard Lowe on Air, his complete run of podcast, radio, and video guest appearances.

📁︎ Cybersecurity

🏷︎ Backups🏷︎ Cybersecurity🏷︎ Phishing🏷︎ podcast guesting🏷︎ Privacy Rights🏷︎ Ransomware