More Secure Ways To Send Data (Transcript)

(Full Show Audio)

All right folks you have the download button on security assessment podcast
brought to you by our company Lipani security
link in the show notes below and check out all of our services software that we
offer as well as our blogs about security in all our past podcast
episodes I want to thank you all for listening and let the show begin
all right let the show begin our first episode of the security assessment
podcast I am your host Brandon and this show is going to be we're gonna try to
do a weekly show about the security every week a lot of you guys might
remember me from the technology geek podcast which I did for many many years
but recently we don't I have not done that show I've been concentrating more
on the business and things that are going on in the security world and the
hardware world all that kind of stuff so the show is gonna be a little bit
different for those of you that remember me from the technology geek podcast but
except we're gonna be focusing more on security we're gonna talk about other
things trust me tech news gadgets all that kind of stuff but more security
focused here now on this show and speaking of security news we'll dive
right in here so a lot of a lot of things really going on overseas right
now we all know obviously about the Russia and Ukraine situation but
apparently that there has been research done and people have found out apparently
Russia has hacked over 10,000 security cameras in Ukraine and they've been
using these cameras specifically to target attacks target specific cities
just their their strikes on Ukraine get updates on what's going on in Ukraine
all that so recently they have went ahead and they have Ukraine's shut down
a lot of their security cameras really to protect themselves as well as you
know Russia spying on them and things like that what's concerning to me though
is some of the camera vendors that they use over there are here in America
Ukraine has not yet released a list of what camera vendors or what kind of
cameras were infected I would really like to know that because the odds are
chance some of those camera vendors are probably used over here I know they for
the only thing we got so far about this was that the cameras are made by China
North Korea and Russia so that could be a whole sort of whole bunch of brands I
wish they would release it they have not yet I know people are trying to find out
obviously it's probably not the top thing on Ukraine's list to get out there
but is something very important if you see any weird activity or anything like
that going on on your cameras it may be something worth taking a look at so just
keep yourself you know you know kind of keep an eye on things just see what's
going on with your camera system and if you see anything obviously turn them off
right away and
talk about because it’s still all stuff in Ukraine going on but apparently Russia
hackers were inside Ukraine’s telecom giant for months and they haven’t
Russian hackers were inside Ukraine’s telecom giant Kistar forgive me if
I butchered that and apparently they’ve been in for by the last year doing cyber
attacks all that kind of stuff so one of the things that I guess is concerning
about that is if you do send any email or any information over to Ukraine your
data possibly could have gotten hung up with this America obviously has been
communicating with Ukraine for a lot of things so it’s very concerning now one
of the things they said if people need to be worried about is people using SIM
cards because of the attacks anybody that used used an ATM anything like that
anybody who’s communicated to anybody overseas you know so there’s just they
have the attackers wiped almost I mean wiped almost everything so it’s gonna be
almost impossible to find out who did it but they said there’s thousands of
virtual servers and PCs that they said that they got access to so like I said
you just be very cautious if you are speaking to anybody over there as it you
know you could have been exposed if you give any personal information so just be
concerned about that also to anybody I wanted to bring this up because I get to
get some people ask me about it 23 and me still a mess over there they’ve been
hit with about 30 lawsuits since December the breach apparently what
they’re saying is 6.9 million of their users were exposed to some point they
see roughly about 14,000 accounts were compromised so I mean it’s a big deal
over there I’m very skeptical about this the fact that I’m 23 and me is trying to
say oh it’s not our fault it’s your fault and all that kind of stuff they’re
gonna hit this is gonna be a big class-action lawsuit you know it’s going
to be like I said they’ve already gotten hit with 30 lawsuits already and I just
don’t like the way they’re handling this saying that well that if this setting
wasn’t if you turn the setting off you your account wouldn’t have been breached
so it’s your fault for not turning this thing off I just I don’t particularly
care the way they’re handling this they’re not taking any responsibility
and that is a rather concerning speaking of lawsuits if you remember in 2020 the
Google had Google got a lawsuit against them for claiming that the incognito
mode apparently they’re still tracking you in incognito mode they apparently
settled that with five billion I don’t know exactly how it’s gonna be dished
out yet they haven’t talked about it yet but I’m sure there will be a lot anybody
I guess it’s using cognitos give me a title to a few bucks so we will have to
kind of to see what happens with that and keep an eye on that going forward
and then also to that big class-action lawsuit was settled with that company
home advisor apparently they were selling people saying hey you know you
can get great leads from our company and apparently they were selling garbage
leads to people and people were I mean losing money because you’re getting all
these leads and and all that and you’re collecting tons of leads and stuff like
that and the most you you pay per lead but get a lot of leads were garbage so
apparently there was a big class action lawsuit with that and apparently
everybody’s going to be entitled to so much money I mean it won’t be you’re not
gonna get back everything you lost but I’m sure they’re they dished out at
checks I know some people I saw on the internet got you know 30 40 50 dollars
it really depends on how much you lost with those particular that class-action
lawsuit but that was another lawsuit like I said it’s a lot of lawsuits are
getting settled here early in this first part of them you know the month so but
like I said I wanted to bring that up as well there there’s been so many of these
lawsuits and it’s gonna keep going on but yeah 20 like it’s 23 in May home
advisor Google all these lawsuits got settled this week so we’re moving moving
forward so last pass the the largest I think password management company in the
world I think anyway announced on their blog that they’re going to be making
some serious changes to their system as you guys know they got hit a few times
with a bunch of cyber attacks things of that nature last pass I actually have
lost confidence in them there’s been too many attacks all and stuff over the last
couple years I think it’s not all their fault as a company gets bigger and
bigger it’s hard to sometimes to keep the security locked down well I mean it
is their fault but it’s harder for them to lock it down and their their system
is closed source so they don’t have people can’t review their code and some
of that so but they are now trying to tighten things up a little bit on their
blog they said they’re gonna be there asking customers to update their master
password to make it longer and more secure they are going to be enforcing
and enrolling multi-factor authentication and all these changes
are going to be rolling out as they are trying to go ahead and make their
systems more secure they should have been doing I know you know there’s
always been a fine line in security between usability and secure you know
secure ability in a sense of you don’t want to make something too secure that
it’s so complicated that people don’t want to use it especially if you’re a
for-profit business but you also don’t want to make it income you know too
simple and insecure because then you’re not really doing your customers a
service so that’s a very tough line to walk and specifically in the password
management business it’s extremely difficult just because of the way things
are you know it generally in this world people tend to take convenience over
security and that’s perfectly normal but when you’re running a password
management that has access to everything for people to get you have to be really
secure and I think they’ve really dropped the ball on it I personally
recommend that everybody use bitwarden that’s what I use they walk much fine
they walk it’s much I like the way they run their company much more all their
code is open source so hackers and things like that can look and see hey
there’s a bug or report to them and they can patch it I like the fact that they
have third-party audits done regularly that are public knowledge so they can
have accountability so what they do is they have we have the security audits
done once they fix the problems and all that they post the security audits up to
their customers to show hey we had an audit done we found problems we fixed it
so it keeps us honest the worst kind what really what last pass did that
really upset me about them was they had an issue they knew they had an issue
they kept it very hush-hush and then when they finally did have a breach
because the issue they never patched they they didn’t react to it well they
didn’t hate they they didn’t hand in quick didn’t react to it quick enough
their response times were terrible with it you know the whole thing with them is
just I just don’t particularly care for the way they’ve handled it and I do like
the way last pass I’m sorry excuse me I do like the way bitwarden has handled
any issues they’ve had quickly they’ve open sourced everything like they should
for a company like that they have done everything the way I would have done it
and the way I think is responsible to do it when you’re looking at you have
people’s whole lives in their database and I know you’re saying what whole lives
well yeah because most people use these passwords man for their bank accounts
for all that kind of stuff very sensitive data that really needs to be
overly secure you know it’s one of those things when you are when you’re storing
people’s passwords to their personal information it needs to be tight and
fortunately last pass I think they’ve just I think at the beginning they were
ahead of their time with password managing and I think they just grew too
fast grew too big and just you know they’re they they just got bigger than
what they could handle they didn’t patch the code right they didn’t handle
security audits and everything properly and sometimes that happens bitwarden is
a lot smaller company they’re open source so that they can put the stuff
out there if you want you know their their attitude is well here’s the code
you know take a look let me know what you think if you want to run your own
password managers you can here’s our code to do it so you’re safe and secure
with it you run your own or you can buy our service I mean I think everything
the way bitwarden has done it is is appropriate and compared to last pass
they really stepped up their game so I am very very much pro bitwarden it’s the
one I recommend they are not a sponsor of this podcast I want to point that out
I’m recommending them because I personally use them I personally had
good experiences with them also – they have iOS support they have Android
support so if you’re using it on your desktop and you say hey I would like to
use this on my phone as well you can use it on your phone as well and they have
browser extensions it’s really really well done they have they’re actually
adding passkey now which is a very important thing it’s in beta it should
be out where instead of just using a password use a long key they support
biometric so if you’re on a Mac or on your phone it can use face ID you can
use ID your thumb ID your fingerprint ID like I said everything about them is
being done properly for a password manager and that’s why I am very very
pro bitwarden they are not a sponsor if they would like to I would be more than
having to take them on as a sponsor but like I said the way they are handling
the password manager I am very very for I actually have had companies in the
past that wolf said to me you know we’re not comfortable hosting on bitwarden
we’d like to host we like bit wouldn’t like to host it ourselves on our own
server so we don’t have a big bill because they got a lot of users because
you pay by the user with their their hosting count so you can actually take
bit wardens code and host your own server and I am and it’s really cool like
I said I I really like it because like I said if you’re a big company and say hey
you know we don’t want to spend you know two three thousand a month on on you
know password but we want something secure and safe you can actually use bit
what it actually has the software and everything built out for you all you
have to do is load it on your own server and you can manage it yourself so I
really like the way they do this kind of twice that they’re really as a password
manager they are right where you’d want to be and that’s why I really think if
you are going to use a password manager I strongly recommend using bitwarden
because they do they’ve got they are on the right track they handle incident
response properly I’ve looked into the way they secure stuff with encrypt stuff
like I said everything is being done right like I said I think last passage
become too big of a company and they are putting their profit over people and
insecurity you cannot do that you have to put security over profit one of the
other companies that I used to recommend that I don’t anymore is to to know to
to know to them and proton proton mail I used to be really pro both of these
companies they run they’re running encrypting email services so in other
words if you wanted to you could send an email to somebody with that was
encrypted and so they can only open if they had the password or if they had the
PGP key or anything like that but apparently recently there was a recent
document that somebody sent me back from late news late November to donota is
actually they were there they were supposed to be always okay crit you
know encrypting email keeping your email safe and stuff that and apparently when
you send an encrypt email it still is encrypted in their systems but because
of a law that came out in Germany now there is a case right now they’re being
required to be able to allow law enforcement to monitor mailboxes and
this is kind of concerning to me because one of the things they are saying this
is the way they responded to us I asked them a question about it they shouldn’t
change anything for other users their emails should continue to be encrypted
by default nevertheless to de nova sees a one-time bypass of encryption as a
security risk to all customers now that’s what they said however he goes
nothing I want to say as we emphasize surveillance measure only affects newly
received unencrypted emails so in other words if somebody sent you an email from
say Gmail or wherever you’re coming from those emails are not encrypted so if
they sent if they sent you an email like say from your Gmail account they would
capture it and read it or allow the law enforcement people to read it the
company cannot decrypt data that is already encrypted so any of your emails
that are there are safe also to they’ve added this if you send any encrypted or
end-to-end encrypted emails through to to through to to note out those messages
will still be encrypted so that’s a bit concerning so basically if I send you an
email from to to know that’s encrypted they can’t read it but if you would just
you know log into your Gmail your outlook or your Yahoo AOL whatever you’re using
and send me a message to my to know account they could read it so kind of I
mixed feelings about this now because they’re there I used to recommend them
to people because they’re in sending encrypted safe email you still can send
encrypted emails but before this all email sent to you was encrypted they
did not keep logs they did not keep anything like that now they’re kind of
changing their tune saying that you know if an email is sent unencrypted we can
you know we can catch it so I am a little upset about that that is not the
service they sold that is not the service that they used to have them as
well as ProtonMail bunchies encrypted email services now are starting to do
this and it’s rather concerning like you sold the fact that you know if I
somebody sent me an email it would be received and encrypted no matter what
now so only the emails I send from your company are encrypted so any emails I
get back or not I mean it’s it’s just basically saying like oh if you you know
it’s if you use our service you’re safe but if you’re gonna use receive email
from companies outside it’s different and that that’s a big problem to me
because if you’re running a bit you know it’s one thing to say email other
friends that are using Tutanota but the problem is if they offer business level
encrypt this is actually what’s on there say business level encryption all your
emails encrypted and secure yes all your emails are encrypted and secure but if
you’re running a business all these other companies are going to be sending
you emails not all those emails are going to be encrypted so that’s actually
kind of a lie because it means that any email that you get somebody if a
business logs on to their Google Google workspace account or somebody logs on
to their office 365 and shoot you an email to your Tutanota account first of
all they don’t know you’re on Tutanota because they’re just sending it to your
domain but like and then all of a sudden that email now is can be read because it
was sent unencrypted it’s just not it’s not that’s not what they sold and the
fact that they made a tool that can hang out there and catch these email so in
other words the catch they’re catching the emails before they go to the
encryption so that’s that’s a breach of security and I am not for that now
they’re even posting on their website now they’re keeping count amount of
reports that they’re asking law enforcement is asking for and stuff like
that and apparently they’ve had 121 requests for data requests for real-time
traffic they they’re listing on and that’s great that they’re listing at all
but that doesn’t it doesn’t really fix the problem it just you know make you
can make you more concerned you see how many how many people are asking for it
how many people they’re complying with so for those of you that do work in the
enterprise the there’s two big security vulnerabilities that came out this past
it was just Friday Thursday or Friday came out apparently Juniper Networks
apparently their firewalls has a critical remote code execution
vulnerability which they are have flaw apparently it’s well it’s substantial
flaw in the census it goes way way back to all even older versions so they have
released a patch for that and then also to Avanti or Pulse Secure had a zero day
vulnerability that they released a patch for it’s not really a patch more of a
fix for right now so they can patch it but so that is another one that there’s
been two big ones that came out last week and like I said luckily enough they
have mitigation take not so much patches but mitigation techniques that you can
go ahead and look that up as well anybody who got hit with the black
basta in Bubba torrent illa ransomware if you were lucky enough that you
haven’t saved the hard drive or just got hit with it recently Cisco has
announced as well as a vast that they have a decryption tool that you can run
and it will actually decrypt the data that those guys have put on your stuff
that’s what ransomware is they encrypt your data so you can get to it but these
guys actually have a tool now both of them the vast has one and now Cisco has
one as well and you can actually run this and it will decrypt your data so
you can get it back like I said it was always glad to see when they get these
tools they don’t always happen but it was really nice to see somebody finally
have a tool that can get your data back in those situations those of you by the
way don’t forget to run your Microsoft Windows update because it’s past Tuesday
was Microsoft’s patch Tuesday they patched 48 vulnerabilities on computers
I know they have some of the vulnerabilities they patched did break
things for some something IBM broke something with them and I think Adobe as
well so love updates coming out for those things but yes they have had over
48 patches came out this past week so that’s a pretty heavy patch Tuesday for
Microsoft but I think I said at least they at least they got that done also to
Adobe had some vulnerabilities with cold fusion that came out D link has some
issues a couple of them that were released that have csv’s from the CIA
say the cybersecurity infrastructure security agency so that was in the news
this week as well coders if you use JIT lab don’t forget they also had a
vulnerability this week you have to patch against so quite a bit of patching
going on this week I mean it always does a second week second Tuesday of every
month is always patched Tuesday from Microsoft and most companies go ahead
and follow suit with that sort of stuff also – I do want to bring up as well we
have a big piece on our website about signal really did a real deep dive into
signal on our website because I felt it was important I know a lot of people
especially recently friends of mine are looking for more secure messengers not
just for personal use but for their businesses and signal is is about as I
mean about as secure as you can get as far as a messaging platform meant that
it was created by the guys who invented whatsapp and when whatsapp got bought by
Facebook apparently Facebook said they weren’t going to compromise the
integrity of it but apparently they have they do collect metadata and stuff like
that on whatsapp even though it’s supposed to be a secure messenger again
profit over people and so now these guys went out a bunch of years ago and
started signal and it really is quite a you know it’s it’s a 501 nonprofit was
founded in 2018 and unlike all the other messengers out there they actually do
encrypt and and nobody can read it but you and the guy person that’s receiving
it that’s not by the way Facebook messenger Snapchat Skype Google chat
text messages they are not and and encrypted the only ones that are end to
end encrypted right now are whatsapp allegedly signal definitely and I
message definitely so those are two important things to remember if you’re
going to send somebody a message you need to be safe and secure I guess it I
message or the signal I recommend either or either or if it’s fine and whatsapp
is supposed to be secure and I’m not exactly sure how much I trusted there’s
a lot coming out about Facebook collecting metadata collecting phone
number linking that to people’s Facebook accounts so they can figure out who’s
sending these encrypted messages and all that so I would be I’m hesitant I like
whatsapp I do use whatsapp but if I’m gonna send something safely and securely
I usually use I message or signal yet the one thing that stinks about I
message is the person has to be on an iPhone or you know you can’t you can’t
get it I mean that’s the only thing I mean I wish I wish Apple would open up I
message to to Android just because I think it would be I mean RCS eventually
might fix this but it would make end to end encryption much safer and much
better I think anyway but I mean Apple’s never gonna do that they’re a
for-profit company they’re they’re not gonna give I message out to just anybody
because they they want people to be locked into their platform with the blue
bubbles and all that so they’re not going to they’ve already talked about it
many a time saying that well if we put I message on Android it might make it so
easy for people to get off of Apple so they’re not going to do that I wish they
would though because it would just be so much better because I message it the way
the way they store stuff the way they message I go it’s just so much safer
than than Android I mean RCS is going to make it better but it’s not going to
make it it’s gonna make it a little bit more secure but not as much as it
because SMS messages are unbelievably insecure but like I said specifically I
wish they would but so what I do is if I know the person has an Android I tell
them I want to use signal talk to them because signal is cross-platform it even
works on the desktop and all that kind of stuff it works on your desktop it
works on Mac or Windows or it’s pretty much like since it’s since it’s just an
app it’s it’s cross-platform which is very nice but the one thing I am
concerned about signal though is they have made it public on their blog this
is they are a nonprofit you know they are they do burn through a lot of money
so they are looking for donations so I actually donate a few bucks a year to
them because I do use signal I know it’s not much but if you all donated a few
dollars to them you know it would help them out they are a nonprofit they are
really my whole issue is I well I do like signal and I think they are a great
platform I don’t know if enough of their users care enough about security that
they’re willing to pay for it that’s the issue with security sometimes is you
know somebody may use signal and say oh this is a wonderful great platform it’s
very secure they do everything to you know authenticate they do everything
right but the problem is the majority of people that use it probably don’t care
enough about it to pay for it I know specifically a lot of journalists use
signals so they can talk to their sources securely I know a lot of
countries are using it right now especially in well actually some
countries actually signal is gonna pull out of because they can’t get like I
think it’s England wants them to make it eat you know want them to decrypt the
messages so they can read them and signals like no that’s not what we do
we’re not decrypting our messages we’re pulling out of England like so but I
know over like Ukraine and places like that they have been using signal to
communicate securely between whatever they’re doing over there with all that
stuff so I do know a lot of people links in America thought of journalists use it
I do know a bunch of people use it for communicating with their company if
they’re sending around trade secrets stuff like that but I know but like I
said my whole issue is is signal saying well we need you know we need to raise
money we’re gonna keep this going we’re a nonprofit and my whole issue with that
is well you know I don’t know if enough people using it care about it enough to
pay for it I mean I pay five bucks you know I’m which is nothing when you’re
looking at I think they said their runway cost runway cost is how much it
cost to run the company nonprofit I think they’re saying it will cost like
12 to 15 million a year that’s that’s a lot of money to run a nonprofit but
again they’ve got server costs they’ve got server hosting things of that nature
so you know that’s kind of part of it and also to authenticating the phone
numbers and things like that so there’s there’s a lot going on there and it’s
not cheap to make a secure service and since they are open source and since
they are you know nonprofit you know it’s a little more complicated again
they’re not a for-profit company they’re putting security over people so that’s
why I’m very much pro you know giving them money because they are actually
creating a wonderful service and putting the security over profitability but
unfortunately they rely on donations like I said I don’t know if there’s
enough people that care about that service or care enough about what’s
going on behind the scenes to be able to you know keep going I would imagine
probably the founders they did very well selling to Facebook what’s app and
imagine that they may actually put more money in to keep it going but there’s no
guarantee with that I hope signal doesn’t go out of business because they
have been done a lot of good work recently and help protect a lot of
people and I just I don’t think they’re gonna be able to come up with enough
money and keep going the same thing goes for Firefox you know Mozilla Firefox is
like the alternative to Chrome they’re the alternative to a lot of other
browsers and you know Mozilla is another one putting security over everything
else they are a nonprofit organization but the problem is is again when you’re
making a browser that’s pro security you know pro putting people first in your a
nonprofit you have to rely on people donating and I don’t know if enough
people I mean Mozilla has a big user base but again I think people just
download it and use it and I don’t think enough people care about the security or
what Mozilla is trying to do here to be able to to get enough donations to pay
for their you know tens of millions of dollars a year and cost of running so
you know it’s a it’s a very weird situation we’re in right now when it
comes to you know security in the sense of you know these companies are trying
to be nonprofit so they can put their put users first but it’s also tough when
you’re trying to you know gain you know trying to earn money you know it’s it’s
a different it’s a different situation I know specifically places like I think I
know I know Firefox has run into some really tough issues and even signal as
well and in places like China Egypt Cuba Iran places like that where they’ve
actually banned Firefox and banned stuff like signal because of they don’t like
the end-to-end encryption stuff and all that and again you know it’s I mean it’s
a fortune for those people that yeah they can’t use a service because their
country is against it especially in places like China and stuff where they
are companies are must provide you know a way for them to read data and so that
that’s that’s kind of the whole controversy behind tick-tock is you know
the people are using tick-tock and toasted over there and and since it is a
Chinese company you know they do have you know the the right in China to look
through data and stuff like that of their people but since that is since
Americans and other countries are using him that’s kind of where the security
issue comes in is if it’s somebody who’s an American citizen do they have the
right to look through it and it says it is hosted over in China do they have or
you know are they looking through you know Americans data and so that so that
that’s kind of why they did the ban on tick-tock because you’re dealing with a
country that is is allowed to you know spy on their people but we don’t allow
that in America well the problem is you have politicians and stuff like that
that have tick tock on their phone and they’re in all these private discussions
and stuff like that so that’s kind of where the controversy kind of came in
with tick-tock and like I said you also have other companies as well other
countries as well that like like I said like Egypt and Cuba and places like that
where you know they don’t they’re allowed to spy on their people too and
then when it’s an Americans data that’s where the kind of the controversy comes
in so like I said there is that I feel that security and encryption is a human
right but a lot of other countries don’t feel that same way so that’s like I said
that’s part of the problem also – one of the others I wanted to bring up as well
with tuna tuna Noda and proton mail one of the other issues I have with this
whole situation with them capturing encrypted email and and the reason I do
have a big issue with this is because a lot of places news outlets will say well
hey use you know email us at this website and it’ll be an attitude to know
the address or at a proton mail address that if you’re a whistleblower and
you’re going to email them from an email address that’s not a to denote account
we’re not a proton mail account um you’re you’re exposing your information
out there if you’re trying to silently whistle blow something you’re not going
to be able to you know it’s there they’re catching non encrypted emails so
kind of ruins the whole point of being a whistleblower and the privacy you know
these companies think oh hey we’re using you know tuna Nova or proton mail so that
we’re getting these things securely you’re not actually and that that’s kind
of what the concern is is you have a source that is coming to you thinking
they’re sending it to you securely via an encrypted email message but it’s not
it’s actually getting caught because it’s unencrypted what you with the best
way to do would be to go ahead and create a to denote account or a proton
mail account and send it to that address from so sweet stain because if it stays
to denote a to to denote our pro time at a proton mail it’s encrypted so that
would be the only way you’d be able to protect yourself but the problem is a
lot of people most people don’t know that and that’s kind of the the dangerous
and the scary part of the whole situation they do have open source
software out there stuff like global leaks which is a open source software
completely free for a company to put in place and what it actually does is it
actually allows your source to submit data to a news organization securely
anonymously and safely I’ve actually looked into this I’m actually gonna
write something up for the web plate eventually about this I haven’t gotten
to it yet but I will and I’ve actually really done an in-depth look into their
systems and what it does is it actually sends you actually upload completely
anonymously they don’t save any logs on the server or anything like that and
then what it does you upload the actual data to the server and encrypts it only
the person on the other end that’s in charge of looking at you know that data
can actually open it and view it nobody else and even the server admin can look
at that data because it’s encrypted it’s only available to the person that’s in
charge of that server as far as the person that’s in charge of reading it
whether it’s legal or a report or whatever like that it’s much more
secure way of doing it like I said it’s called global leaks I’ll put a link in
the description below they’re not a sponsor it’s completely free it’s open
source and like I said it actually is a much more secure way for your contact or
your whatever whistleblowers whatever to send data to a reporter or to news
organization and they’re completely it’s completely anonymous there’s no logs or
no nothing and this way they can get it up to you securely without risking their
lives or their jobs or whatever they’re trying to leak out to you just sending
an email through to to Nova proton mail is not a secure thing anymore unless you
do it through you know through proton mail or through to to note I and most
people don’t know to do that so it’s actually quite a not as a secure way of
doing it sending it via email but like I said global leaks is a it’s a completely
open source piece of software any company anybody can use it you could set up be
set up the server takes me 20 minutes to set up and then like I said somebody can
go right to the site whatever upload stuff and then the person that’s marked
as the receiver or the reviewer can go ahead and review it and see if what
they’re gonna do with it but like I said the even the server admin cannot see it
it’s all encrypted all the database stuff is all encrypted all the passwords
or everything is the software was done so well and with the thought of
protecting sources it’s a really great I wish more people would use it
unfortunately it’s one of those things where it was created I don’t know how
many people are actually using it but I wish more people would because it is
such a great piece of software and again that is global leaks if you don’t know
how to install it reach out to us we can always help you out with that this isn’t
an ad but it is something that most news organizations really should know about
and like I said they’re what it amazes me to is like I said it is open source
it is completely free and I like I said I wish more more organizations would
would use it I think it will be eventually it’s just gonna take time to
get people on board with it so and that is like I said global leaks I will put a
link in the show notes as well so folks I’m gonna wrap it up on our first
episode like I said if you you can listen to all of our old shows which we
don’t have yet this would be the first one like I said at the panty security
calm also to check out all of our services and everything we offer at our
site like I said lapani security calm and I want to thank you for listening
and we will talk to you on the next episode thank you very much
