Therefore, I urge listeners to support this station, because the double, and make no mistake about it, is out to get it. Trust me. So do the right thing, and donate now at give2wbai.org. That's give2wbai.org. And don't be surprised if you find yourself yearning for the good old days of Tricky Dick Nixon. Yes, okay, how do you follow up that? Wow, first Reagan, now Nixon. It's 8 o'clock. You're listening to WBAI in New York. And if it's Wednesday, that means it's time for Off the Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving. Now I can't make a call. We couldn't get much worse. But if they could, they would. Bum Diddley Bum for the best, expect the worst. I hope that's understood. Bum Diddley Bum! Bum Diddley Bum! Bum Diddley Bum Diddley Bum! We'll be right back. Greetings from Philadelphia, Emmanuel. And our special guest, Kevin Mitnick. Hey, how's everybody doing? You know, I didn't expect to see you in person today, but welcome. Welcome to our new studios in Brooklyn. Yeah, this is awesome. I was supposed to actually fly out to Los Angeles tonight, but I delayed my flight, so I got the opportunity to be here. So it's awesome. It's awesome. And Kevin has a new book out, and this is exciting news, especially for BAI listeners, because we're offering it tonight as a special limited edition premium. We'll get into details on that in just a moment. And the book is called The Art of Invisibility. Is that correct? Exactly. So myself and Rob Vermosi worked on this for the last year, and what inspired me to do the book was really the revelations of Edward Snowden. Because we all knew, right, at least, you know, people that were involved in 2600, that the government's monitoring us. We knew this, right? Technically. It was a technical reality. We weren't sure. You know, we didn't have the evidence. And then when Snowden came out, we go, okay, it all makes sense. But we didn't know to what degree their capabilities were. So I was thinking, wow, what about other issues where, you know, schools spy on students, employers on employees, identity thieves on people like you and I? Average folks don't even know what VPN is or how to use a password manager. What is VPN? What? I have to represent the average folks. It's a new type of brownie. No, but that's funny because when I was on the Rachel Ray show earlier today, and, you know, it's a bunch of housewives and that sort of thing. One of the, I think the co-host said VPN. Oh, no, VPN. Anyway, what I wanted to do was actually give the tools to people on the street, the everyday people, not security people or people involved in technology like us because we know this stuff, but more for people that don't know. So that's kind of what inspired me to write this book. So it's for the everyday person. It's not for the security professional. They should know these things. That's true. That's true. And they don't have time to read books anyway. But if you're interested in the things that we talk about here on Off the Hook, I can't imagine a better book to plunge into. Actually, I've got a copy right here, The Art of Invisibility. This is how solid it is. It's a heavy book. It's got a lot of really - I'm going to read some of the chapters. 300 pages. 300 pages. But just the chapters, I think, kind of tell the story. Time to disappear. Exactly. That's what it's all about, right? Because we want to disappear from - Getting off the grid. Yeah. Big Brother is everywhere. Your password can be cracked. Who else is reading your email? Wiretapping 101. Well, you're kind of an expert on that, aren't you? Yeah. I had some involvement in that in the past. So I could speak to it a little bit. Uh-huh. If you don't encrypt, you're unequipped. You know where that comes from, right? No. Where does that come from? If it doesn't fit, you have to acquit. Oh, boy. Yes. The old O.J. Simpson trial. How about that? Exactly. Exactly. So I thought it was clever. Yes. Well, I don't think he's going to sue you for that. Now you see me. Now you don't. Every mouse click you make, I'll be watching you. The police. Every breath you take. Right. Exactly. That's good. That's good. Yes. Believe everything. Trust nothing. That's pretty much true. Yes. You can run, but not hide. It's very difficult. You ran. You hid, but... Right. And how I got caught back in 1995 is I got pretty complacent. What I did at the time is I used cell phones. But back in those days, you didn't have data over cell, right? That didn't exist. So I was able to modify a US robotics modem to actually connect to a PTRE25 Novotel phone. Those are almost like brick phones and actually do 300 and 1200 bot. So I was able to dial up to the internet, if you want to call it that at the time, through ISPs like Netcom. And I used to just call different dial-up numbers or what they called POPs in different cities to make it more difficult to track the origination of the call. And I would even get switch access, hack into whatever phone company I wanted to, and monitor that POP to see if any technicians ever did a command to do a line trace, essentially. So anyway, I got complacent. I stopped looking at the switch and that sort of thing. And so because I was using a fixed location in Raleigh, it's not too difficult to, if you use a fixed location, to do radio direction finding. And what they were able to do, for those that don't know, there was a guy that became involved in the case, a guy named Satomo Shimomura. And he became involved because myself and this guy living in Israel at the time, Jonathan, hacked into his system because we thought he had the Okie 900 source code. And my hobby at the time was hacking into companies that develop cell phones to get the source code. Jonathan, he had the three letters, right? Yeah, J-S-Z. J-S-Z, I remember. Right, right, right. So I'm not mentioning his last name because I don't know if, you know, he's still, I think, a little bit paranoid. But in any event, even though the Statue of Limitations has run, so we compromised his machine. He actually, it was a bait machine. So he had TCP dump running to probably look for new types of attacks or zero days that would exploit his system so he can capture them, essentially, and kind of profile attacks. So it didn't take him long to catch on that we were in his system. And then I became suspect number one, largely due to John Markoff, right? The New York Times report. You were suspect number one every time something went wrong. Anything got broken into? Any computer, any place. Must be Kevin. Must be Kevin. I saw that happen constantly. Right, so then Shimomara went on a vigilante mission. But what he did, he was able to help the government find me because he was a smart guy. And he said, let's not look, let's not try to trace Kevin back because they should try to trace the calls back. But I had full controls of the switching systems at the phone company. So I was able to manipulate that. I can make it look like it was coming from anybody. So I used to like giving them red herrings. But he had a smart idea. He says, let's not try to trace a call back. Let's just do what they call a terminating number search, which is basically looking for numbers dialed, right? And they would just put in all the numbers for Netcom pops around the U.S. And they found, wow, there's a cell phone number in Raleigh, North Carolina, dialing that. And I would change the number daily. But what they were able to do is work out these numbers were calling it over the last few days. But it was always coming from the same cell tower, right? So then they were smart and they would just monitor that cell tower for any data calls. Because if it was a data call, it's suspicious. Because don't forget, nobody was using data back in those days at a dollar a minute. It wasn't a feature that was widely available. No, no, no, no. In fact, there was no such thing at the time. It really makes you realize how much we take for granted setting up like a travel router in a hotel, like just to get online and get data. This is crazy. You were building it. Like Verizon MiFi's that go like, you know, you have a 4G LTE. It's like, oh my God, I wish I had this back in the day. It's so easy. Yeah, no, but this is stuff you were really building out of just what was at hand. Yeah. So actually, it was actually taking a US old robotics modem and repurposing it and setting it up. So we're using the audio jack on the actual device, right? So I was able to communicate at low speeds. And eventually, I got complacent. I was using the same fixed location all the time. And eventually, Shimomura helped the FBI. They actually did radio direction finding, found the apartment. They showed my picture to the rental leasing office. And they didn't recognize me because I was really good at changing my appearance back in those days. How would you do that? Oh, I had very long hair. I had a mustache. I would change my weight. I'd change the type of clothes I wear. I'd change my gait, how I walked, everything. If someone said, Kevin- You changed how you walked? Yeah, by putting like a pebble in my shoe at first. That's good. Yeah. I wouldn't think of that. That's really good. Well, I actually read materials on this. You know, it wasn't something I just thought of, actually. So I don't remember. I mean, as a kid, I used to go to this bookstore called the Survival Bookstore in Los Angeles. And what it was, was all the underground books by Paladine Press. If you remember, by Eden Press. You know, so as a, you know, as a 13-year-old, I realized, oh, I can disappear. I can get new identities and this sort of thing. So people will think that I got caught that way. But actually, what really happened is I went, I was actually working out at the gym that night, came home, it was Valentine's Day, 1995, and I just had this really bad gut feeling that something bad was going to happen. I don't know why. It was just like this overwhelming bad gut feeling. So I actually opened up my door, go out, and I go over to the balcony, which looks over the parking lot, and I actually look back and forth over the parking lot, and I chalk it up to paranoia. I walk back inside. Ten minutes later, FBI, open up. Wow. So it's because I looked out, because it was suspicious. Some guy walks out, looks around like something's wrong, goes back in the apartment at 1.30 in the morning. That's how I was caught. Really? Okay. Yeah. I hadn't heard that. So if you hadn't walked out, they would have had to knock on a lot of doors, or would they have just given up? Well, they had a trigger fish unit device with them, which is kind of the older, the predecessor, you know, to the Stingray. And they, over time, they would have obviously nailed me, right? But if I got wind, which they did make mistakes, because when I went to log into the well and other systems I'd compromise, I realized all the credentials were changed. So I knew something was up, and I could have possibly escaped, right, at the time. And I would have if I could have. How long were you on the run for? About three years. That's simply incredible. Right. And you went from all different, so you were in Seattle at one point? Well, yeah, I was in Seattle. I was in Denver, working for a law firm. It was kind of funny, because all the partners at the law firm were like retired judges, and right, and here I was, a federal fugitive, you know, and they'd call me to, you know, because their computer wasn't working, right? So it'd be kind of funny. So I'm sure when they found out later, they were like, oh my God, right? Wow. The fox in the hen house. Fascinating. Well, this book is the third in a trilogy, the first two, The Art of Intrusion and The Art of Deception. How is this book different from those two? It's totally different. Art of Deception was a lot about social engineering attacks, and I had to fictionalize it because at the time, the government, there was an agreement that I couldn't tell my story for seven years after I was released from custody in 2000. So I was approached by a publisher, John Wiley and Sons, because they wanted a book on social engineering and how companies could prevent it. So what we did is we took real attacks that I've done over the years and just fictionalized everything. So it's like, change the names to protect the innocent, except me and I wasn't innocent. So in any event, that book was released. It became like a bestseller, at least for in the information security space. And then I was approached to do a more technical book, and I don't like doing super technical stuff because what happens, you decrease the audience and you don't sell books, right? And the whole purpose is to get the message out to as many people as possible. So then we wrote The Art of Intrusion, which was really interviewing other attackers and getting their really cool stories and vetting them to whatever degree we could. That was Ghosts in the Wires. No, that was Art of Intrusion. Oh, Art of Intrusion. Other people's stories. Art of Deception, Art of Intrusion, and then- Well, we haven't gotten to Ghosts in the Wires yet. I'm sorry, I'm getting ahead. I'm sorry. Yeah, so this book, the coolest story in that book was the first story about these guys that hacked Vegas video machines. And so that was the coolest story. And then time passed, I was finally able to write Ghosts in the Wires, which was my memoir. The seven years. That's right. The seven years. Period. It passed, right. So that was about your specific- That was my story, which became a New York Times bestseller. And that was a great book. That was a really great book. Yeah, it was kind of like when I was reading it, I'd go, this is cool. And then I'm thinking, wow, I can't believe I did all that crap. Right? That's what I was thinking. I'd go, wow, now that I put it all together, maybe I was lucky I only got five years. What gets me is they make a stupid movie like Takedown, right? And Ghosts in the Wires, that's the movie. You know, that's the story right there. I have a guy working on the script. He's a TV guy in Los Angeles. Adapting it so that it can be a screenplay. Yeah. But the thing is, it's like a project that is more on the back burner because he's already doing other television, he already has contracts to do other TV shows. So those are first priority because that's money, right? And contract. So he's also working on my script. It was supposed to be done this year. I mean, 2016. So I'm just being patient. And I really believe in this guy because he's a really great writer. I'll just tell you who it is because I put on Twitter a guy named Jeff Easton. He does White Collar and Graceland. So if you ever watch those shows. Okay. And so I'm just being patient. And, you know, when he gets it done, he gets it done. And then hopefully a production studio will like the script and they'll agree to make the movie. But who knows? Hollywood's a funny thing, you know? So, you know, I'm not, you know, I'm not keeping my hopes up. And just to keep it clear, this movie, we won't have to go out and protest? Hopefully not. Okay, good. Don't forget, unfortunately, you give up your rights when you sell your movie rights or your book rights. Basically, now the studio owns them. But since I'm working with the writer on telling the story, I really believe it will be, you know, in a more, you know, in a truthful fashion. It'll be the truth rather than trying to fill in the blanks with falsities because you don't know the real story. Well, there's certainly no shortage of new studios and methods, maybe a streaming service or something that actually produces it. But as long as the stories get out there, I think it's important. You're not stuck with one mode, but definitely letting it develop slowly is the right way to do it. Right. So if I had the techniques that were like in this book that I used, you know, back in 1995, a lot of them were not available. We didn't have Tor, for example. It would have been a lot harder to track my location. Right. So I didn't write the book to, you know, to so people could evade the law and escape. That wasn't the purpose of it. It was really how about journalists and dissidents and privacy activists that really have a need to protect their privacy. Then I get into a more of an advanced section in the, in the back of the book, which really the secret to me is separating your initial connection to the internet from your true identity. The first connection, because you get all these VPN providers, oh, we don't log, you know, we don't keep connection logs. You know, that's all bull. Okay. They all do. Right. They have to. Yeah. So just got to, got to watch your language on the radio here. Oh, I forget. I had to hit the button. So yes, we're safe. That's otherwise it's a $350,000 fine for saying BS. Yes. Wow. You've been on the radio. You know, these things. Oh, okay. Okay. I saw it coming though. I was ready because I knew you were, you were, you were heading towards that conclusion. Well, and it's, it's no joke because these providers, they might be a small business. They might be a startup of some kind and when they get the, what is it? The FISA letters, some of the secret letters and, and when, when they're subpoenaed and some of these things where they're basically, they have a gag order and they have to provide stuff without a lot of people. Yeah, exactly. Great example. Right. Right. I'm not thinking of the terminology exactly right now, but it's, it's no joke. So yeah, they get put in that position and nine times out of 10, they don't really have the resources or metal to go up against the government prosecutors or whomever's coming after them for that information. Yeah. But this particular book is very much up to date and what's going on now and not how, how it was done in the nineties. Exactly. It's all, it's all new stuff, you know, and you know, the bottom line is at the end of the day, how do you protect your comms? Encryption. Right. So I walk the reader through first, I don't say, oh, use signal, use, use PGP, use, you know, you know, other, you know, OTR. I don't get to just say, Hey, use these apps. Right. What I try to do is, you know, take more of a thought process. If you don't teach a man, you don't give a man a fish, you teach a man how to fish, right? You heard the old adage, right? Yeah. So I try to teach people how to look for the right applications that, for example, provide end-to-end encryption with perfect forward secrecy. And I say, Hey, you have to use Google. You have to research it. And, and that way they could find their own apps. Right. And I think that's more important to teach them how to think and explain how their privacy could be violated. That's, that's our challenge that we face. We've been facing since we've been publishing back starting in 1984 is not just giving out the answers, but teaching people how to get the answers themselves. And also you touched upon something earlier about as what possible purpose could you have for telling these stories except to tell, to let people know how they can do it. Yeah. Obviously there's more to it than that. And again, that's, that's a challenge we face having a hacker radio show, having a hacker magazine, having a hacker conference. It's not about teaching people how to do nefarious things. It's, it's learning the theory, learning how the technology works, learning how private we actually are or are not. And I think that's, that's what you get by reading one of your books or by listening to the things that we do here. Yeah. And there's a lot of human error that could violate privacy. Like if you're not a, you know, an information security expert and don't know these things, there's a great story of a, of this, um, this agent in Los Angeles in the TV business. And, um, he buys his kid an iPad and, uh, he's under 13, obviously he's like eight years old and, you know, you can't sign up for an iCloud account being that young, either have to lie or use the parents. So he basically signed the kid's iPad into his iCloud account. So then he goes off to New York for business purposes, uh, but he really had a mistress out here in Manhattan and he's taking photographs with her. And what he doesn't know is all the photographs are being synced onto his kid's iPad. Oh my God. So the kid walks into mommy. Hey mommy, what are these pictures of daddy? And who's this lady busted? Right. Right. Busted. It deserved to be busted. But there's a lot of cases where people just for the convenience, right. And they don't know the ramifications, for example, of sharing an iCloud account. Right. Right. Because they're offering these services and you really, you have to understand the underlying, uh, foundations for these things and the tools and techniques get you to that stuff. So you can dive into those specifics and yourself, and you've got that tool in your belt. And we're going to, we're going to dive into a cloud, uh, cloud bleed in just a, just a moment. But first I want to let people know, uh, because we do have, um, uh, a limited number of these books as premiums for our ongoing winter fundraiser, uh, for a pledge of $125, you will get an autographed copy of Kevin Mitnick's new book, The Art of Invisibility. And on top of that, and this, this is also kind of interesting, you will get two of the original free Kevin bumper stickers. We have a very small amount of those left. Apparently we, we, uh, misanticipated when Kevin was going to be released and we had a few extra. And on top of that, uh, Kevin Mitnick's awesome, uh, super cool business card. Kevin, do you want to describe what that business card is? Yeah, it actually has utility. So it's a metal card. It's a metal card. And I showed it to people on the TV show earlier today and they thought it was dental tools, right? I said, you got the tool set right, but it's actually a lockpick set. So it's basically, you know, kind of a cool break apart lockpick set. Um, and it's more of a novelty, but they actually work. So the number is 516-620-3602. And what you want to do is ask for The Art of Invisibility. Uh, and, uh, we only have five. We only have five of them. Uh, so please call now 516-620-3602. A pledge of $125 gets you an autographed copy of Kevin Mitnick's brand new book, The Art of Invisibility, plus two original free Kevin bumper stickers and the lockpick slash business card, uh, of, uh, of Kevin's. And those things are incredibly popular. You've had those, uh, for, for a number of years now. Exactly. People line up just to get those. Right. And I, I pass them out whenever I can. And I always bring boxes with me when I'm ever at conferences and people just love them. You know, they don't get tossed in the trash. No, definitely not. I should mention really quick that, uh, if, if this book isn't your cup of tea or, uh, you'd just rather support the show in the station with some other amount, uh, you can still call 516-620-3602 or go to give2wbai.org. Um, tell them you're donating in the, in the name of your favorite show, which we hope is off the hook. Um, that's certainly my favorite. That's right. And, uh, you, any amount of, uh, any amount of support helps, uh, keep this station on the air, helps keep the show on the air. Um, this very show that, uh, has been keeping people updated with all these issues, um, through Kevin's case, uh, through Kevin's, uh, adventures, uh, you could, you could go back and listen to those because this is what was keeping, uh, BAI on the air and keeping those stories on the air. 516-620-3602 or give2wbai.org. We also have, um, I believe a couple of leftovers from last week. The 11th Hope flash drives for a pledge of $75. That's every talk at the last conference. It's a hundred talks, uh, all on MP4 HD video that you can copy freely on a 128 gig flash drive, which in itself is a pretty good deal for a $75 pledge. And we also have the full DVD set for those of you who still like DVDs, 100 DVDs you'll get in the mail. So you better like DVDs. That's for a pledge of 125. But again, I think the really cool thing tonight though is, is Kevin Mitnick's brand new book, The Art of Invisibility for a pledge of 125. You get your own autographed copy and, uh, two original free Kevin bumper stickers. They're the yellow stickers with the, uh, uh, black writing. Is it blue? I think it's dark blue writing on it. Yeah. It's a yellow background with a black and they're very high quality, very high quality. They are such high quality. And, and I, I think if your statute of limitations have expired, I think mine have too. There are signs that we stuck these up on, uh, road signs, uh, back in, uh, what, what year was that? 1997, 1998. They are still there. They are still there. Uh, there's been blizzards and hurricanes, all kinds of things have happened, but these stickers will last. They're good stickers. You set the standard because now when you see free so-and-so campaigns, it's that type of sticker. So it all started with, uh, your idea of coming up with a free Kevin sticker back in the nineties. And in addition to that, you'll get the, uh, Kevin Mitnick, uh, uh, lockpick slash business card. You decide which it is and, uh, it'll be the coolest business card you, you, you own, uh, all for a pledge of 125-516-620-3602. Let's, let's see those calls, uh, start pouring in. Um, but, um, wow, what, what, what, what incredible stories you have, Kevin, as far as just, uh, the things that you have been through, the things, uh, you have experienced, do you think it's possible today for somebody, uh, to, to be able to use technology the way you did back then? Yes. Well, don't forget. I had the, I had compromised a lot of the bell operating companies. So once you compromise my bell, you're kind of in control of the, you're in control of the communication, but there's no more my bell. Well, they still have switches, right? So, and they still have computer access to those switches. They still have technicians that get remote access to those switches. Hopefully they use two factor authentication these days, right? But who knows, right? So because of, uh, because of that, that situation that I had control of the switches, it made it really easy to make it very difficult for someone to track back the location. Yes. Right. And, you know, back then, like I remember I was 16 years old sitting in the computer lab at Monroe High School in Los Angeles. And I'm going to take you back to 1978. It was a Olivetti 110-baud terminal. And we used an acoustic coupler modem. We put the handset in the modem. Wow. So I was looking for the, you know, the greatest challenge. And, uh, at the time I was, you know, hacking the phone company switches. And I said, wouldn't it be cool if I could, you know, eavesdrop on an NSA conversation? So I actually got the dial-up to the ESS-1A switch in Laurel, Maryland. And when you have a switch access, you could actually create a phone number, you know, through their RC commands that allow you to create a phone number. And this was on a root, what they call the root index of 168. And what you could do, that was the audio line. And then through access to the switch directly, I could basically look for ongoing, uh, conversations that were going over particular trunks that were part of the NSA Centrex, because it was all 301-688, blah, blah, blah, blah, blah. And then I was able to tie the audio line to a trunk so I could actually eavesdrop on NSA conversations. You did this at 16? At 16. You went straight for the NSA. Most people hadn't even heard of the NSA then. Right. I, you know, I was climbing Mount Everest, right? So I wanted to, I wanted to do this. And then I heard a conversation. It was some, actually, uh, a man and a woman talking for a minute or so. I basically disconnected and never did it again, right? I tried it once and then I go, that's cool. And I never did it again. Wow. Uh, that is, that is simply, simply unbelievable. Uh, go ahead, Rob. It still kind of rankles me that, uh, in 1995, hearing about how you, uh, lashed together that internet connection of yours, uh, while I was at home, like with a cranky old 286, you had a better connection than I did and you were on the lam. Probably. Yeah. I didn't, I didn't end up on the lam until like 1992. Right. Uh, but that's, but that's, that's, that's a long story. So that was, that was your first time on the lam. There were a couple, a couple of times, but I noticed, uh, when, when you're telling these stories that you're remembering the details, you're remembering, uh, what commands you tied. You probably remember what phone numbers you dialed. Uh, pretty much. This stuff stays with you. I still remember, I still remember the RC commands to like, you know, to basically and, you know, enter translations into certain, you know, switches like the ESS 1A and the 5E. I still remember it off the top of my head. I guess when, when something is important to you, you remember it. Yeah. I remember dialing 516-667-5566 and connecting to Telenet and, uh, and, and hitting D1 for terminal and hitting return twice. Why? I can't remember things that I learned yesterday, but I remember that. Yeah. It was probably because again, you probably did it over and over and over and over again. Thanks to the people calling in 516-620-360 to remember, keep this radio station going so we can talk about things like this. WBAI was instrumental in telling the, uh, Kevin Mitnick story and telling the Bernie S story, all kinds of stories involving hackers, uh, and, and technology that we have told since we first went on the air here in 1988. Uh, and your support helps keep this radio station non-commercial and, uh, and, and, and alternative. Again, we're offering Kevin's free book, uh, new book rather, uh, the art of invisibility for a pledge of $125. You'll also get two free Kevin bumper stickers and a free Kevin, uh, not free Kevin, uh, Kevin Mitnick, um, um, business card that's metallic. It's a, it's a lockpick. Have, has, have people actually used the lockpick? Oh yeah. Yeah, definitely. Like, you know, Barry, uh, Wells in, in, in, with tool. The key. Yeah. Yeah. Right. Uh, people have been on, people have posted videos. Uh, one guy at, at, at the late, the last DerbyCon conference in Louisville, uh, actually cut his fingers because I guess he, you know, was trying to, he tore the picks off the card wrong and he actually was bleeding as he's picking a lock, you know, really crazy. Can get injured from this business card. It's the only one that, that can carry that claim. You have to demify me for any liability. Yeah. You have to be careful. Debur all of the edges when you're, when you're about to use them. Yeah. But one thing in the book that I discussed that I think is, you know, kind of important today is how about when you cross from a foreign country into the United States, basically customs and integrate immigration customs enforcement can search everything you have any type of digital device that you store data on your phone, your, your camera, your computer. So I talk about in the book of how to protect your privacy, even when you're crossing the border. Uh, I had an experience back in 2008 where I flew in from Bogota, Colombia into Atlanta because I was, uh, I was hosting, um, a panel session at the ASIS conference at the time. And I remember going through passport control and these guys, you know, swipe my pass. No, this guy swipes my passport and his eyes were going back and forth, back and forth. And immediately I knew there was a problem. Yes. Right. Without him. And he goes, Hey Kev, you know, he was like, like now he's my buddy. Um, some guys want to talk to you downstairs. Don't worry. Everything will be all right. So he goes, go get your bags. And when I went to get my bags, I'm powering off my computers because I have my encryption keys in memory. Right. And basically it was like this fishing expedition. Like, why were you in Columbia? Um, they, uh, uh, it was like hours of being detained essentially for them to investigate me because maybe because of my prior background. And at the end of the day, I already made up my decision. I'm never going to give up my credentials to anything. Yes. So I used a little bit of social engineering where I remember I was in the room and I had, you know, several laptops with me and I tell the guy, I said, you could look at these laptops over, you could look at my Mac book and all this, but you can't look at this one. And you know, this is, has my private data on there. And that one was just basically almost like a Chromebook with nothing on it. Right. And I said, okay, here, I'll log you into my Mac here. Oh no, no, no. We want that computer. Oh no, only my Mac in this book. I'll let you see. I can't let you see this computer. They actually fell for it. Couldn't believe it. Wow. And so no interest in where I had my client data or anything else. They're only interested in the Chromebook. So I go, well, do you want me to log in as user Kevin or as the, the administrator, right? And they go, what's the difference? I go, well, one has access to all the, oh no, the one with all the files. So I go, then I go, I really don't want to do this, right? Oh no, you have to do, you know, so we're going to take all your equipment. So I did it and they don't know what they're doing. Right. So anyway, I knew after a certain period of time, because I called my attorney that they would either have, they'd have to let me go because I'm a U S citizen. They can't say you can't come to your own country. But nowadays people are getting searched, you know, consistently as they cross the border. So in the book, I give people the tools to make it harder. For example, what people might not know is like, for example, if you have an iPhone with touch ID, a government, well, a court could actually order to you to unlock the phone with your thumbprint or your fingerprint, but they cannot order you yet to reveal your password because that's testimonial. You have a fifth amendment, right? So what I tell people like in the book is just reboot your phone. And when you reboot the phone, don't put in your passcode yet until you pass through customs because then your touch ID won't work. You know, so simple tips like that, that, uh, make it harder, you know, um, to get access to your personal information that the government has no business looking at. Wow. Uh, and now you don't recommend people use their thumbprint as, as security for their, for their phones. No, no, no. But many people do for convenience. So it's a way of disabling that temporarily. Right. To the point, like, uh, when I travel, you know, I always have, you know, complete clones of my system knowing that my computers could be taken, uh, at any time. And, uh, basically what I do is like, I'll store stuff on, on a server, you know, that's encrypted and I'll just push stuff up there and pull it back down when I'm back in the U S or I'll even go through the trouble of encrypting my whole drive, um, you know, and, you know, and sending it somewhere in the USA. And once it's received, then basically wiping my drive and then going through, you know, customs, not because I'm doing anything illegal, but what I have to protect is my client's data. I do security testing. I have a company where we break into systems of our clients with authorization and I have a lot of client data and I have to protect it. Fair enough. Wow. Uh, just, uh, I should, uh, point out, uh, there's only two books left. So 516-620-3602, pledge of 125 gets you Kevin Mitnick's new book, The Art of Invisibility, Autographed, and you'll also get two not available anywhere, free Kevin bumper stickers, the originals from the late nineties. And you'll also get as a bonus Kevin Mitnick's business card, which doubles as a lock pick set. So, uh, wow. What a, what a, what a deal. It's only being offered tonight. 516-620-3602. Rob. I have a small, uh, a small but pleasant update for people who have pledged, uh, in past, um, fundraisers of ours for a previous version of our hope drive. Um, those were delayed as, uh, as people know, but, uh, I spoke with the staff today who are, as we speak, duplicating those and, uh, they'll be mailed out over this week and next week. So they, they will be on their way to you. That's great news. And my apologies for giving out inaccurate information. Oh, actually, no, it just changed. We have one book left, one book left, not two, one. Those numbers are going down. The numbers of, of people pledging, no, that's going up. And that's what we want to see because you add numbers together and believe it or not, you wind up with a huge number and things are looking up here at WBAI. I know that, uh, we've had our, our rough spots, but, uh, we're, we're raising more in recent weeks and that's a great thing to see. Uh, I'm seeing a real turnaround in, um, in, in, in positivity and, um, very optimistic for the future. Well, and it is worth noting. It is only because of other listeners having contributed in the past that we're able to broadcast to you now. So to build upon that and, uh, come to you again in the future, we need your donations, anything, uh, five, 10, $15, whatever it takes. Yeah. That goes to crucial infrastructure and day-to-day operations here at the station. These are just gifts. We are thanking you for contributing to this community radio station. But, uh, really the goal is to fundraise for WBAI so we can continue to broadcast, uh, here in the tri-state area, as well as streaming to you over the internet anywhere in the world. 516-620-3602. That's the number to call. Get that last Kevin Mitnick book, The Art of Invisibility. Or if you want the, um, uh, the 11th Hope thumb drive or the 11th Hope, actually flash drive, I think is the official way it's referred to, uh, or the 11th Hope DVD collection. Um, those are available as well. 516-620-3602. The important thing is the radio station remains a strong voice. And Kevin, while you were on the run, while all these things were happening, we were talking about you on these airwaves and people found out about it. If, if we had a, a, a free Kevin demonstration, remember that day we had, uh, uh, demonstrations while you were in prison all around the world, Moscow, uh, North Carolina, uh, New York, Los Angeles, I was, you, you mentioned that you were in prison and you actually, what'd you see? You saw something? Well, I actually saw, uh, I saw an airplane dragging a free Kevin banner. Uh-huh. That was like, oh my God. Uh-huh. Now, how did they do that? Right? Yeah. So I was actually surprised. You know how we did that? We did that through organization, through, uh, communicating. This radio station was so key in that. We even had a skywriter in, in, uh, New York, in, in Brooklyn. Unfortunately, it was a windy day and nobody saw it, but we did it. We did it, we, I know, cause we paid for it, uh, so we had all kinds of, of cool things that were going on. By any means. Yeah. But the thing is, and I have to thank you, Kevin, because you kind of gave us the jump start, the hacker community needed in the world of activism. Right now, you see hackers jumping into high gear when something happens that requires a lot of people to sign a petition or to show up someplace or to voice their opinions. The practice that we got was, was at the turn of the century. We'd never done this before. Hack, the hacker community was, was not known for activism of any sort. The phrase hacktivism pretty much came about while you were languishing in jail. And, um, I, I don't think we would be where we are now were it not for what you had to go through. Yeah. And, you know, and the support that, uh, 2600 gave me and the people that became involved was, um, it was amazing. Um, it really helped me get through my trials and tribulations. And, uh, even though I knew that I was under the control of the U S government, it still made me feel, you know, wonderful that people actually cared. Is it hot in this room? It's hot, very hot in this room. So it reminds me of something that I have in the book. Okay. Yeah. Cause I was actually going, wow, it's warm in here. So there was this, a story in the book and the art of invisibility where this, uh, guy was really angry with his, uh, with his wife because she left him for another guy and she got the house. So what this guy would do is, you know, she made a mistake. She never changed her nest password. Right. For a, for the thermostat. Okay. Right. So this guy would, uh, access the, uh, nest over, over the internet, of course, with the credentials. And when she was out of the house or, you know, on vacation or whatever, the thermostat goes all the way up. Oh boy. Right. And before the person gets home, it goes back down to normal. So he kept this up for months and they'd get these like huge electric bills. Right. So just a crazy, just crazy stuff that in the research of the book, you know, uh, really funny stories. Uh, uh, Bernie's on the phone and, uh, I know, uh, we're talking about the radio station and how, uh, we, we, we told stories about people going through hell. Bernie himself went through hell. I remember. And, um, and in fact, he would call in from, from prison virtually every week and, and listeners really, uh, got some eyeopening news on, on, on what people had to go through both in the hacker community and people who are imprisoned. And I, I, I think were it not for WBAI being here, uh, so few people would have actually learned about that. And two worlds wouldn't have, um, have come together quite as well. Uh, Bernie, you must have, have some memories of that period. Yeah, that's right. Uh, both Kevin and I were, uh, on, in, in federal custody at the same time, um, overlapping. And unfortunately for Kevin, he was in a lot longer than I was, but, um, he wasn't beaten up like you were though. You, you really, uh, I did get a good, a good slamming once, but in any case, the, uh, um, the feeling that Kevin just described of knowing that there was a support community out, out on the outside while you're in a steel cage was just an enormous, an enormous relief because it was a very isolating experience being locked in a steel cage for, uh, months and years. And, um, emotions, I don't know if you probably agree with me on this, Kevin, but, but when you're in prison, emotions seem to be multiplied several times. It's like a being in a pressure cooker. So having this whole community, um, of WBAI and the hacker community, uh, um, listening and knowing what was going on and asking questions and saying, Hey, this isn't right. It was, uh, was, uh, a huge breath of fresh air. Otherwise, you know, it might've been, it would have been far harder, but I wanted to also touch on what Emmanuel said that prior to 1995, when, uh, both Kevin and I were, uh, apprehended by federal agents, uh, separately, um, the hacker community really had not gotten its, uh, its feet wet in the, in the, in the activism, uh, uh, area. And, uh, I am really glad that to have been around the beginning of when that was happening, being at the center of it as Kevin was, um, and now we take it for granted that, you know, hackers, activists, it's almost one in the same in, in a lot of ways. So, um, I, I really want to thank the listeners to this station who have been listening all that time since the mid nineties and before and, and watching this community develop, the hacker community develop on WBAI and through 2600 and through the HOPE conferences, um, into a really, uh, a social justice community. And that's what this radio station, WBAI is really all about is social justice and how to be really well informed about what's going on in this world. And in, in, in this stage show particular from a technical standpoint, how, what's going on and how to protect yourself. So this book that Kevin is offering, uh, to us, thank you for donating them is a, it's a great way to learn more about it. I don't know if there's any more copies left, but even if there's not any copies left, please call the station right now, five, six, area code 516-620-3602 and pledge whatever you can to support this station, this community of people that really care what's going on and can, can, can advise you from a technical standpoint, how to protect yourself. Again, 516-620-3602. If you'd rather do it online, it's give to WBAI.org. And, um, thanks for your support. That's what keeps this whole community going. You know, it's, it's interesting, Bernie, um, that we just yesterday released volume 14 of the Hacker Digest. What that is, is a compilation of an entire year. And volume 14 was 1997. That's when we really started talking about Kevin Mitnick's case, uh, and virtually every issue. And I remember going through, um, the letters, letters to the editor, and we received a fair number of letters that said, why are you supporting this guy? You shouldn't be doing this. You should just talk, be talking about technology. Uh, and there were, there were some vocal critics saying that we should not be involved in issues of social justice. And we get that to this day. You know, we're talking about all kinds of horrors that are coming in with the new administration and, and we get mail from people saying you should not be involved in this at all. Similar to the way people in Hollywood, uh, get, get, uh, uh, demands from people to only do their job and not participate in that conversation. It's all related. It's all part of the same conversation. And you can learn so much by, by sharing your expertise and, and, and just basically, uh, putting your own unique perspective onto the whole thing. Yeah, it's not, it's not, it's not comfortable for us to just be frivolous and, uh, and be into the latest gadget, uh, for the sake of it. These things matter. These things have an impact on society. And, uh, uh, had we not had this, um, this history, um, to tell the world that hackers aren't going to accept judgment, uh, lightly, um, we, we wouldn't, we wouldn't be able to have the conversations we can have about, um, hacking as a positive thing, a positive force for people that are making things that are innovating, uh, in, in, uh, the educational environment and, and elsewhere, places that really need, uh, uh, that to encourage and, and, um, have that enthusiasm for technology as we're, um, creating, uh, people who will be contributing to society in the future. They've got to have these tools. They have to have an understanding of this stuff and not just sort of passively accept what, uh, authorities say to them or what, uh, an application is forcing them to do based on someone else's, uh, choices for them. And, uh, yeah, that's, that's part of what we, we try to get out, um, through the magazine and, um, and it's, it's grown and evolved and it, it incorporates all of these different things, um, as, um, as an initiative for a really, really large community and, and a diverse one at that. Yeah. I've always felt the, uh, the activists in the hacker worlds are, are very, very naturally intertwined. I was never an activist who decided to become a hacker. I was, I was a hacker who used a hacker outlook, who, um, was interested in seeing how things are, seeing how things work, seeing how things could be improved, how they could be subverted, what have you. And this knowledge led me to things that, uh, that awakened the activist spark in me and basically, uh, brought me down that road. So it's, uh, it's, it's really flip sides of the same coin, I think. Okay. An update. All the books are gone. So, uh, if, if you do call in, uh, don't ask for that because you'll be disappointed, but you can still get the 11th hope, 100 DVD collection. You can still get the 11th hope, uh, flash drive collection. As long as those, uh, don't get depleted 516-620-3602. Or you can, as, as a listener just did simply donate, uh, as a $25 donation. Thank you very much for that. It all adds up. It all keeps this radio station going. Hey, Kevin, I said, we were going to talk about cloud bleed a little bit. Uh, and, and we were talking about the cloud and how people, uh, stick all their private information in there and wow, uh, I guess the reckoning finally happened where all these passwords were, were revealed, uh, and, um, and people's private information. Guess what? It's, uh, it's in other people's hands now. Are you surprised? No, not really. I mean, uh, you know, the guy who actually discovered this, uh, uh, Taviso, if I'm pronouncing his right name, Armand, uh, Armandy, uh, he's with the Google, uh, zero project. So this guy is extremely brilliant. What is the Google zero it's basically a project by Google where they have all these security, uh, you know, very bright minds, brilliant minds and information security. They find bugs and they report them. They get them fixed and, uh, they make things better. Right. So it's like, kind of like Google's ethical hacking squad, so to speak. So the guy that, uh, what's his name? Uh, George Holtz was on there once on, um, and he got, uh, Ian beer and really, really some bright, bright minds in this. So, uh, uh, I guess, uh, uh, uh, from what I read, from what I recall from, uh, Tavis's blog, he was working on a, a different problem and realized he was getting this, these chunks of uninitialized memory getting returned to him. So he started investigating and realized that there was a bug in the proxy, um, that CloudFair was using that would allow you to dump memory from the proxy, right? And essentially that's where you could see just, you know, raw data, whether it's, uh, SSL or whatever. And what's, what was, what he found was, you know, credentials, you know, for, uh, many of, uh, CloudFair's customers and that sort of thing. So it was, uh, it, it, it reminded me of Heartbleed. Heartbleed was, you know, a very similar, you know, bug in open SSL and that allowed you to, you know, dump memory, uh, a certain amount of memory. And, uh, and the same issue existed, uh, with CloudBleed and, uh, CloudFair fixed it, but, uh, who knows who took advantage of the bug for, you know, since it existed. I don't think it existed for too long. I think, you know, um, I'd have to reread the blog. I think it was like, uh, for maybe under a year. Wow. Uh, well, um, Kevin, I want to thank you so much for, uh, for being here and talking about all this and for continuing to do what you do. You, um, you spend a good amount of time, um, going all around the world giving talks, right? Yeah, pretty much. So what I do these days is, uh, I run a pen testing company and companies hire us globally to break in physically, technically using social engineering, testing wireless networks, SCADA, just the whole, the whole thing. And, uh, why they do this is they want to look at, you know, are their security controls effective? And if not, how do we shore up our defenses? And I'm always looking for really good, uh, and expert level senior people. So you can always send the resume to info at mitnicksecurity.com. Uh, the other thing I do is I'm on the speaking circuit. So I go to lots of different conferences and events and I speak about information security and, uh, I work on special projects. I'm, um, I'm also, uh, a partner of a company out of Clearwater, Florida, um, called Know Before. And through this company, we offer simulated phishing attacks. So what companies could do is phish their own employees, right? So it becomes a teachable moment when they fall for the phish. Can you give us an example of how that would work? Yeah. So basically we have, we have an account, we have a console with a, you know, a lot of different phishing campaigns. And, uh, for, for those that don't know what a phish is, it's basically like John Podesta just recently got hacked. He received an email purportedly from Google and, uh, uh, that basically said his account was accessed from an unauthorized IP address or something of that nature. He sent it over to his IT guy. The IT guy said, oh yeah, that email's real. He goes ahead and clicks on the link, puts in his credentials and that sort of thing. And that's how his emails were stolen eventually and handed over to WikiLeaks. So these are like typical phishing attacks. A 14 year old could do them, right? But a lot of companies are getting victimized with ransomware and the vector is social engineering using spear phishing, for example. Uh, there's another type of phishing where you don't even try to get it. You don't try to get on their systems. You basically just try to trick the CFO or their delegate into wiring millions of dollars. It's called CFO fraud and people are gullible, gullible enough to actually do it. Wow. So, so, uh, Stu Showerman and I back four and a half years ago decided, hey, how can we better train people at companies not to be so gullible? So we have a training course, but one of the most important things is the inoculation. How do you inoculate people from being gullible when it comes to phishing attacks? So then we actually let IT departments at companies actually do phishing campaigns against their own users when they fall for them, right? For the phishing, it becomes a very teachable moment. And then they could be trained and hopefully through this inoculation process, they're going to become much smarter, much trained. So they could really, um, catch any real phishing attacks that come in the future. So I imagine you have a pretty high success rate at, uh, at getting into these, um. Oh, a hundred percent when I'm doing security testing. A hundred percent. A hundred percent get it right through, uh, when the vector, when they allow us to use social engineering attacks. When companies actually test for the first time, because, you know, before they, uh, sign up for the product, they actually do, you know, they do a first phishing test, you know, just, and that's not spear phishing, that's simple stuff. And there's about a 30 to 35% click rate, right? Now that doesn't mean they're exploitable, of course, because, you know, in a phishing attacks, you have the exploit, the con, then you have the con, and then you have to exploit usually the software that resides on the desktop, right? Or if they're foolish enough to, you know, click on a Java applet, then you got code execution immediately. But anyway, um, it's amazing how many people will fall for phishing attacks. I mean, uh, I mean, again, you know, John Podesta did, you know, and he's Hillary Clinton's campaign manager, but this happens in businesses all the time. And again, what the criminal side is doing is actually deploying ransomware through this technique because that's how they're making money and they're making a ton of money. So the ransomware basically encrypts all their files and they have to pay somebody usually in Bitcoin to get it unencrypted. And exactly. And they actually walk you through how do you, how do they make it very easy, right? How to Western you knew the funds. They give you a little tutorial. This is how Bitcoin works. Just give us the money here and you'll get your files back. Yeah, you get one, you have one Bitcoin number. I think one Bitcoin is what, two grand now? Something like that. Well, it's not that much, I don't think, but. Just to quickly point out for any listeners who are unfamiliar, but interested in searching out more info, this is phishing spelled P-H-I-S-H-I-N-G. Yeah, not the kind you do with your grandfather. At least, hopefully not. And when we use this vector, right, I've been doing, I've been running this pen testing company since 2003 when I was finally off supervised release. And whenever a client allows us to use social engineering and scope of a pen test, we've always get it. We always can at least find one user inside an organization that gives us complete access to the network. So they can say, don't use social engineering, but that's not realistic because the average person out there who is a social engineer isn't going to say, oh, they don't want me to use social engineering. Yeah, I'm not going to use that. I'm not going to violate that rule, right? But the second attack vector that works very well today is exploiting web applications that are internet facing that have bugs because companies develop them not using SDLC, which is the security development lifecycle, or they buy them from vendors who don't do the same. But with social engineering, I mean, the real work comes in in the information reconnaissance is actually researching the company, researching the target, trying to get a domain that they would trust from a customer, supplier, or vendor. So once you figure out the trust model that somebody is likely going to fall for, actually executing the attack is a simple part. The hard part, and how do you, you can build a target list quite easily. You can go to LinkedIn, you can put in a company name, and you can search for people's positions like network engineer, system administrator, database administrator, and you can quickly work out who has privileges inside the company, right? But that's not to say that's the best way to get your foot in the door. The best way is to target people that are not technically astute, right? Sales and marketing, for example. So you get some sales guy, and you're sending a PO, which is a PDF file, which has been booby-trapped. So once the guy opens it, you get control of his machine. And then once you get your foot in the door of the network, then you use technical exploitation to get admin rights on that person's box, and then move yourself through the network. For example, when we get on a Windows network, Active Directory network, we always get domain admin, always, because we use a tool called Responder. I'm not going to go through how the Responder works, because we don't have that much time, but you could Google it, right? And basically, we're able to capture hashes across the wire, and I have a couple of very fast GPU password crackers. I get like 900 billion NTLM hashes a second, which is how Windows hashes passwords using NTLM and NTLM v2. 900 billion a second. 900 billion a second. So if I take a nine-character password, I could just crack it in a few hours, no matter if it's uppercase, lowercase, symbols, letters, doesn't matter, right? So if you're running Active Directory, and you're not deploying the proper security controls, it's game over, right? The adversary is going to get in, they're going to get domain admin, and they're going to get access to everything. So when somebody gets the treatment from you, as far as the pen testing, and they realize how vulnerable they are, and then you tell them the steps to take, are they secure at that point? Not necessarily, because a lot of companies don't take all the steps, because it takes time, it's expensive in some cases. But as, you know, it's basically maturing their security program. So as we test stuff, find bugs, they fix maybe some or all of the bugs, they hire us again six months, a year later, to do the test again. We find the ones they didn't fix, we find new ones, and it's this constant cycle of trying to mitigate the risk, right? But it's not just hand in the pen test and everything is, you know, everything is fine. Not at all, because everything changes. Every day, they're installing new applications, there are new people that are joining the company, there's always new things to exploit. That's right, that's so true. Kevin, how would somebody contact you if they want their company to be subjected to your scrutiny? They can go to mitnicksecurity.com, that's M, like Mary, I-T-N-I-C-K, security.com. And that's our company website. And I imagine if they want to get you to speak someplace, the same website? Yeah, same site. You know, so through that site, we do the services of, you know, penetration testing and speaking and speaking. I'm represented by an agent, so it goes right to the agent. Any interesting gigs coming up? When's the next one? Next one's in Florida. I don't know who the client is, but I know it's in Miami. Then right after that, I go to Santiago, Chile. Oh, wow. Speaking for Intel, which is their big energy company out there. I just did several speaking events for VMware in Orlando, which went really well. And when I'm doing these events, it's not just getting up on stage and talking and showing a PowerPoint presentation. I actually show the latest exploits, you know, the ones that work when we're doing pen testing. So it becomes like a magic show. And how I originally got into hacking was through my love of magic. Awesome. Well, that's another story for another day. Kevin, so good to see you again, and we look forward to doing this again in the future, having you at a HOPE conference, and all the best. Yeah, absolutely. I love being here. It's great to see everybody again, and I want to thank all the 2600 supporters for everything that they've done for me, and especially you, Eric. And I hope to see everybody around again at the next HOPE conference. And don't forget, there are 2600 meetings this Friday coming up all around the world. Do you know we have about 150 meetings? I just counted them, and I didn't realize how many we had. That's a lot of meetings, a whole lot of meetings. But there's one here in New York coming up 5 p.m. Friday at the new location, right, Rob? Yep, the atrium. The atrium on 3rd Avenue by 53rd Street, half a block from the City Group building. We'll be back again. I'm not sure we're on next week, because next week I think there's some special programming. We'll let you know via the website and Twitter account, Hacker Radio Show. We will see you when we see you. Have a good night. Bye. I'm shouting. From the plan on it's true. I'm shouting. There's so much we could do. I'm shouting. I'm shouting. I'm shouting. I'm shouting. I'm shouting. I'm shouting. Because it's hard to believe. I'm shouting. It's so easy to see. I'm shouting. We're waiting for every fly. I'm shouting. For the very last time. I'm shouting. Oh, baby, this one's for you. I'm shouting. For everything that you do. I'm shouting. Until the battle is won. I'm shouting. We'll live the fight on and on. I'm shouting. And when you add it all together. And when you roll it in a ball. And when you watch another pyramid. As it's about to fall. Remember you were there. Remember if you cared. For those who held that ground. When it all came down. I'm shouting. Oh, baby, this one's for you. For everything that you do. Until the battle is won. We'll live the fight on and on. Oh, baby, this one's for you. For everything that you do. Until the battle is won. We'll live the fight on and on. I'm shouting. I'm shouting. Shout it out. I'm shouting. I'm shouting. Shout it out. Shout it out. I'm shouting. I'm shouting. I'm shouting. I'm singing. We'll be there.