1
00:00:00,120 --> 00:00:05,080
Now, once they're inside the email, that gives them the ability to reset

2
00:00:05,120 --> 00:00:11,480
the passcode on all the various accounts
which are crypto, finance, banking,

3
00:00:11,599 --> 00:00:16,239
whatever, credit card, Amazon,
eBay, PayPal, whatever. Okay,

4
00:00:16,480 --> 00:00:20,359
so they can reset the passcode on
all the various accounts, but then they

5
00:00:20,399 --> 00:00:24,640
still need that second factor for example, Coinbase, whatever it might be,

6
00:00:24,679 --> 00:00:28,399
the crypto, they still need that
second factor, which is once they gain

7
00:00:28,480 --> 00:00:32,240
access to the email then and then
once they have a handle on all the

8
00:00:32,320 --> 00:00:36,200
various accounts, then the next thing
they need to do is swap out that

9
00:00:36,359 --> 00:00:41,960
SIMP. You're listening to Carrie Let'sa's
Financial Survival Network where you get valuable information

10
00:00:42,079 --> 00:00:47,439
you just can't find anywhere else to
thrive in today's trying times. You need

11
00:00:47,479 --> 00:00:54,039
the Financial Survival Network now more than
ever. Go to Financial Survivalnetwork dot com

12
00:00:54,079 --> 00:01:00,759
and get your free newsletter and gift. Financial Survival Network now more than ever.

13
00:01:03,239 --> 00:01:07,799
Welcome you are listening to watching the
Financial Survival Network of your own scary

14
00:01:07,879 --> 00:01:11,359
lotz. Well, as we get
to the end of October, we're getting

15
00:01:11,359 --> 00:01:15,799
to Halloween, and nothing is spookier
to think that somebody could get all of

16
00:01:15,840 --> 00:01:22,000
your passwords to all your banking,
to your credit cards, to everything,

17
00:01:22,040 --> 00:01:26,640
to your email and take over your
life. Well that's a real scary scenario.

18
00:01:26,840 --> 00:01:33,439
So it's appropriate for Halloween. And
our good friend Robert Ceciliano is with

19
00:01:33,519 --> 00:01:38,480
us now. He is a security
expert. Robert, you go around the

20
00:01:38,519 --> 00:01:42,319
world lecturing about this stuff, password
managers, all of this. My greatest

21
00:01:42,359 --> 00:01:46,079
fear in life. One of them, and I guess I have a few,

22
00:01:46,480 --> 00:01:53,959
is that somebody will crack the Apple
password security scheme through neural network or

23
00:01:53,319 --> 00:01:57,879
quantum computing and they'll have the keys
to the match and if you will.

24
00:01:57,319 --> 00:02:05,760
Is that fear overblown or is it
realistic? So that's entirely possible. Now.

25
00:02:06,040 --> 00:02:13,400
Password management is everything from making sure
you're using strong passwords, which are

26
00:02:13,599 --> 00:02:22,560
uppercase lowercase numbers and characters sometimes past
phrases, to utilizing a password manager that

27
00:02:22,680 --> 00:02:29,039
facilitates having a different password across every
account. And then of course there's biometrics.

28
00:02:29,080 --> 00:02:32,120
There's facial recognition, this's fingerprinting and
so forth, and then of course

29
00:02:32,240 --> 00:02:38,680
adding on additional security means two factor
authentication, and whether that's using some type

30
00:02:38,680 --> 00:02:45,080
of an authenticator app, or it's
using SMS, texts right or eye message,

31
00:02:45,120 --> 00:02:47,639
whatever it might be, and everything
you know, beyond that and in

32
00:02:47,680 --> 00:02:55,759
between, it's it's encryption and breaking
encryption codes, and all of those concerns

33
00:02:58,479 --> 00:03:00,759
need to be addressed at some level. Okay, But here's the thing,

34
00:03:00,800 --> 00:03:07,360
Like, for for most of us, most of us are using the same

35
00:03:07,560 --> 00:03:15,560
passcode across multiple accounts. The biggest
mistake. Yeah, most of us are

36
00:03:15,599 --> 00:03:21,120
not using two factor authentication for all
of our critical accounts. Okay, most

37
00:03:21,120 --> 00:03:24,319
of us. And when I say
most of us, mistake, yeah,

38
00:03:24,360 --> 00:03:30,199
And I know this because you know, statistically, that's what all the studies

39
00:03:30,199 --> 00:03:34,879
show. But beyond that, I
get in front of live audiences all the

40
00:03:34,960 --> 00:03:38,400
time. So I might work with, like, you know, a financial

41
00:03:38,479 --> 00:03:43,479
services professional who has like a book
of business of I don't know, like

42
00:03:43,520 --> 00:03:46,639
a billion dollars two billion dollars a
year was worth their investments or whatever,

43
00:03:47,400 --> 00:03:52,039
in clients, whatever, and he'll
have you know, his top Like one

44
00:03:52,120 --> 00:03:55,360
hundred people come in and I'll speak
to them, and I'll ask them,

45
00:03:55,400 --> 00:03:59,919
like how many of you use a
password manager? And like ten of them

46
00:04:00,280 --> 00:04:02,840
will raise their hand, And then
then the next question is how many of

47
00:04:02,879 --> 00:04:08,560
you use two factor authentication for email? And like five of them will raise

48
00:04:08,560 --> 00:04:14,759
their hand you know, and these
are moneyed individuals and then not doing much

49
00:04:14,759 --> 00:04:19,879
in the way to protect their own
data, their own devices, and these

50
00:04:19,920 --> 00:04:28,319
are this is your client base.
So if somebody breaks into your client's email

51
00:04:29,160 --> 00:04:34,680
and then begins to communicate with you
as one of your clients, right because

52
00:04:34,680 --> 00:04:40,680
they're in your client's email, and
you're thinking, this is my client reaching

53
00:04:40,720 --> 00:04:46,079
out to me, communicating via email. And if that in this case,

54
00:04:46,120 --> 00:04:53,240
you know, criminal hacker is good
enough to impersonate your client from your client's

55
00:04:53,319 --> 00:04:59,680
email, which isn't that difficult to
do? You know, they can get

56
00:04:59,800 --> 00:05:04,040
you in many ways to transfer money
out of your client's account and so on.

57
00:05:05,360 --> 00:05:10,759
It can just get as ugly as
it can possibly be. Okay,

58
00:05:11,920 --> 00:05:16,240
So I just did a presentation yesterday
for real estate agents, and real estate

59
00:05:16,240 --> 00:05:21,959
agents are handling handling a lot of
sensitive client information. They're handling wire transfers

60
00:05:21,959 --> 00:05:27,319
in many various states and so on. And I asked the same question of

61
00:05:27,360 --> 00:05:32,560
real estate agents, who are service
professionals who deal with transactions, who deal

62
00:05:32,879 --> 00:05:41,120
with sensitive data, and they're not
any more secure than your basic investor.

63
00:05:41,879 --> 00:05:49,560
Unbelievable. You do two things.
So a lot of the financial websites mandatory

64
00:05:49,600 --> 00:05:56,360
two factor authentication now even to the
point where they won't go with the SMS

65
00:05:56,399 --> 00:06:00,879
code for you to type in.
They actually make you approve it on your

66
00:06:00,920 --> 00:06:04,680
device where it says are you trying
to get into American Express? Yes?

67
00:06:04,839 --> 00:06:09,879
Or no? I say no.
That's the end of it. And the

68
00:06:10,040 --> 00:06:15,000
other thing is there's a thing called
SIM swapping. Know about this, but

69
00:06:15,079 --> 00:06:19,399
a friend of mine, she got
nailed from a crypto account. They went

70
00:06:19,439 --> 00:06:24,319
into T Mobile in New York.
She was in Florida, and they said

71
00:06:24,319 --> 00:06:28,839
they were her. Maybe they even
had some identification and they said they lost

72
00:06:28,839 --> 00:06:31,439
their phone. They got a new
phone with a SIM. They managed to

73
00:06:31,480 --> 00:06:35,920
pull out eighteen grand from a crypto
account, and they were in the process

74
00:06:35,959 --> 00:06:40,439
of trying to steal money out of
her bank account, but it was stop.

75
00:06:40,879 --> 00:06:45,160
Now that bank account, you're going
to be covered eventually, God knows

76
00:06:45,160 --> 00:06:49,279
how long that's going to take.
But the crypto account a lot more complicated.

77
00:06:49,360 --> 00:06:53,160
Had to go to a lawyer,
got to be suing these people.

78
00:06:53,800 --> 00:06:56,879
And I didn't even know in the
end if they're libel to you or not,

79
00:06:57,639 --> 00:07:00,959
if they actually did what they set
we're supposed to do. Yeah,

80
00:07:01,000 --> 00:07:04,519
So this is like disaster in the
making here. It's about the other.

81
00:07:04,680 --> 00:07:11,199
You've got to make sure that your
phone company will never give someone another phone

82
00:07:11,879 --> 00:07:17,079
with a cloned simcord that you know, it's really tough. That one really

83
00:07:17,120 --> 00:07:23,360
took me for a loop. Yeah, so I just just just two weeks

84
00:07:23,399 --> 00:07:28,879
ago. I testified as an expert
witness in a simswap case just two weeks

85
00:07:28,879 --> 00:07:32,920
ago. And the victim in this
case, which is the plaintiff, a

86
00:07:32,959 --> 00:07:40,040
client and his attorney. He lost
nineteen thousand dollars with the crypto because one

87
00:07:40,079 --> 00:07:50,639
of the telco's facilitated his SIM card
being swapped out, which meant that the

88
00:07:50,759 --> 00:07:58,839
criminals were able to get into his
coinbase account exactly, and they made like,

89
00:07:59,120 --> 00:08:03,879
I don't know how many I need
hundreds of like four and five dollars

90
00:08:03,759 --> 00:08:07,800
transfers out of his account over the
course of a long weekend. In the

91
00:08:07,879 --> 00:08:11,439
back is working, right, his
phone stopped working. He had no idea

92
00:08:11,519 --> 00:08:16,680
why correctly even get through to the
carrier, right, correct, correct,

93
00:08:16,399 --> 00:08:20,399
So there's a few things going on
there. In the case of your friend

94
00:08:20,800 --> 00:08:28,439
and my client, I would bet
that your client email was also compromised.

95
00:08:28,639 --> 00:08:31,319
Had to be, had to be, because now else could they know about

96
00:08:31,360 --> 00:08:35,120
the account. Yes, I would
bet that the client's email was compromised first.

97
00:08:35,799 --> 00:08:41,799
Same with my clients, because I'm
confident that my client's email was compromised

98
00:08:41,080 --> 00:08:46,240
first. Now, once they're inside
the email, that gives them the ability

99
00:08:46,320 --> 00:08:52,360
to reset the passcode on all the
various accounts which are crypto, finance,

100
00:08:54,000 --> 00:08:58,399
banking, whatever, credit card,
Amazon, eBay, PayPal, whatever.

101
00:08:58,799 --> 00:09:01,919
Okay, so they can reset the
passcode on all the various accounts. But

102
00:09:01,960 --> 00:09:07,279
then they still need that second factor, for example, Coinbase, whatever it

103
00:09:07,360 --> 00:09:09,519
might be, the crypto, they
still need that second factor, which is

104
00:09:09,679 --> 00:09:13,399
once they gain access to the email
then and then once they have a handle

105
00:09:13,480 --> 00:09:18,240
on all the various accounts, then
the next thing they need to do is

106
00:09:18,480 --> 00:09:22,360
swap out that SIM. And so
the main problem with swapping out the SIM

107
00:09:22,440 --> 00:09:28,240
for the user is that your AT
and ts and T mobiles and boosts and

108
00:09:28,279 --> 00:09:35,960
all that they have authorized resellers,
authorized dealers. And you know what the

109
00:09:35,960 --> 00:09:41,159
authorized dealer is. It's like it's
like a it's a guy on the corner

110
00:09:41,720 --> 00:09:48,120
of downtown Main Street between the gas
station and the convenience store and the dry

111
00:09:48,200 --> 00:09:56,159
cleaner, and he's selling gum candy
and T mobile phones and he's an authorized

112
00:09:56,200 --> 00:10:01,639
reseller. Yeah, and so in
order for and he's also selling SIM cards,

113
00:10:01,399 --> 00:10:05,759
and in order for him to activate
a SIM card, all he's got

114
00:10:05,759 --> 00:10:09,960
to do is just be an authorized
reseller. And while the big telcodes,

115
00:10:11,000 --> 00:10:13,000
the AT and T s, the
T mobiles of the world have all these

116
00:10:13,080 --> 00:10:18,200
various systems in place that require that
reseller to check ID, well, yeah,

117
00:10:18,320 --> 00:10:22,279
the reseller could say, yeah,
I saw ID. They showed me

118
00:10:22,320 --> 00:10:26,600
an ID. Whether they showed ID
or not, that's just you, honestly

119
00:10:26,679 --> 00:10:31,000
probably not an expert either and identifying
fraudulent ID. That's it. And if

120
00:10:31,000 --> 00:10:35,600
a guy walks in and says,
I'll give you one thousand dollars to swap

121
00:10:35,679 --> 00:10:39,720
out this SIM, you think he's
going to resist. And chances are he

122
00:10:41,120 --> 00:10:43,799
If somebody's walked in and said I'll
give you a thousand, they already have

123
00:10:45,639 --> 00:10:50,360
a relationship. Yeah like that.
Yeah, this is not the first time

124
00:10:50,080 --> 00:10:54,120
that reseller has swapped out a SIM
like. This is something he does.

125
00:10:54,399 --> 00:10:58,559
This is something he's known for.
And in the case that I testify to,

126
00:11:00,039 --> 00:11:05,919
there were two resellers in different parts
of the country that had swapped out

127
00:11:05,000 --> 00:11:09,720
the particular SIM of this guy's phone
multiple times over the course of two and

128
00:11:09,759 --> 00:11:16,240
three days. Wow. So what
they did was is they had actually swapped

129
00:11:16,279 --> 00:11:20,639
up the SIM, were able to
log in, change the passcode of a

130
00:11:20,639 --> 00:11:24,360
particular account, get that one time
text message to his phone via SMS,

131
00:11:24,679 --> 00:11:28,360
logged into the accounts and then swapped
the SIM back of the original just like

132
00:11:28,399 --> 00:11:31,639
that. And they did that over
a period of time, and they got

133
00:11:31,679 --> 00:11:35,919
into a number of different accounts over
a two and three day period of time.

134
00:11:37,559 --> 00:11:45,639
So that's where utilizing an authenticator app
is better than utilizing your mobile phone

135
00:11:45,720 --> 00:11:50,639
number as that second factor. All
right, So authenticator apps and any viewers

136
00:11:50,759 --> 00:11:54,639
are probably not familiar with it,
they can be a pain. Google has

137
00:11:54,639 --> 00:12:01,480
an authenticator there's a number of number
of them out there. From what you're

138
00:12:01,480 --> 00:12:05,919
saying, Robert, that is the
safest route to go rather than two factor,

139
00:12:05,960 --> 00:12:11,440
although coinbased has three factor authentication sometimes, certainly when you're opening an account.

140
00:12:13,000 --> 00:12:18,720
So all of this you really you
really got to think seriously about it.

141
00:12:18,399 --> 00:12:24,039
Yes, it requires you, as
a user, somebody who has something

142
00:12:24,080 --> 00:12:30,720
to lose and an account holder to
focus on what it is you're getting yourself

143
00:12:30,759 --> 00:12:37,360
into when it comes to setting up
two factor authentication versus an authenticator app and

144
00:12:37,399 --> 00:12:41,679
then determining what your best options are. The easiest thing obviously is the SMS

145
00:12:41,720 --> 00:12:46,080
to using your mobile phone, but
the authenticator as an actual app on your

146
00:12:46,080 --> 00:12:50,080
device is a different story entirely,
and that's the direction you want to head.

147
00:12:50,600 --> 00:12:54,000
Yeah. In addition to that,
if you ever have the opportunity to

148
00:12:54,200 --> 00:13:01,320
use a Google Voice phone number as
that second factor as a phone number versus

149
00:13:01,480 --> 00:13:07,200
your mobile phone number, utilizing Google
Voice as a phone number, your second

150
00:13:07,240 --> 00:13:13,200
factor is actually more secure than your
actual phone number. Sure you can't.

151
00:13:13,200 --> 00:13:16,240
There's no SIM involved in a Google
Voice number. You can't swap out the

152
00:13:16,320 --> 00:13:22,759
Google Voice number. So this is
why all the carriers are going to simless,

153
00:13:24,080 --> 00:13:28,480
cardless sims, electronic sims, because
they see the potential for fraud here

154
00:13:28,799 --> 00:13:35,639
and in theory, at least that
should eliminate it. But it's pretty scary.

155
00:13:35,720 --> 00:13:39,120
I mean, right now, both
of my phones are sim are cardless

156
00:13:39,159 --> 00:13:45,200
sims. So that's where you don't
actually have the SIM that can be reprogrammed.

157
00:13:45,320 --> 00:13:48,960
You actually have to program a new
phone. So they must have some

158
00:13:50,200 --> 00:13:56,519
means of going about it to prevent
that new phone from being cloned. What

159
00:13:56,639 --> 00:14:03,840
they do at the corporate level and
at the authorized actual eighteen, took T

160
00:14:03,080 --> 00:14:07,639
store the actual T mobile store.
Like at the actual T Mobile store,

161
00:14:07,960 --> 00:14:11,559
when you walk in because you want
to swap up out a SIM, they're

162
00:14:11,559 --> 00:14:16,519
requesting your driver's license and then they
will actually scan the back of the the

163
00:14:16,519 --> 00:14:18,879
bar cord or the back of the
driver's license to make sure that it's a

164
00:14:18,919 --> 00:14:24,879
legit driver's license correct, and they'll
have that on record, and that reduces

165
00:14:24,000 --> 00:14:31,240
T Mobiles liability in that regard.
And AT and T had has similar but

166
00:14:31,320 --> 00:14:37,039
not the same processes. Keeping in
mind that prior to me testifying as an

167
00:14:37,039 --> 00:14:41,639
expert witness in the simswap case,
I'm not going to name the defendant in

168
00:14:41,679 --> 00:14:46,480
the case. The day before I
testified, I called Boost Mobile, I

169
00:14:46,600 --> 00:14:52,320
called T Mobile, I called AT
and T. I called my own AT

170
00:14:52,480 --> 00:14:56,399
and T to find out one of
my options as far as swapping out my

171
00:14:56,480 --> 00:15:00,360
SIM because my toilet, my phone
fell on the toilet. What do I

172
00:15:00,399 --> 00:15:03,480
do? And the woman on the
phone told me all my auctions, and

173
00:15:03,519 --> 00:15:07,000
she was like very you know,
direct with me and all that, you

174
00:15:07,039 --> 00:15:09,840
know, very helpful. And she
said, all you've got to do is

175
00:15:09,879 --> 00:15:13,639
going to an AT and T store
with the driver's license and they'll take care

176
00:15:13,679 --> 00:15:16,399
of you. I said, okay. I go, like, do they

177
00:15:16,440 --> 00:15:20,320
ask me for a pin code or
anything? She said, well, they

178
00:15:22,399 --> 00:15:24,120
probably won't. As long as you
have the driver's license, you should be

179
00:15:24,159 --> 00:15:28,240
fine. I said okay. I
said, but like, what if somebody

180
00:15:28,240 --> 00:15:31,559
goes in with a fake driver's license. She said, well, you know,

181
00:15:31,720 --> 00:15:35,919
they're not skilled in detecting that,
but you know, like the likelihood

182
00:15:35,919 --> 00:15:39,879
of that happening is small. I
go, okay, but if somebody does

183
00:15:39,080 --> 00:15:43,279
going with the fake driver's license,
they could posess me. Well, I'm

184
00:15:43,320 --> 00:15:48,240
not positioned to comment on that.
That was with the AT and T.

185
00:15:48,679 --> 00:15:52,759
So I called Team Mobile and I
asked them the same all the same questions,

186
00:15:52,960 --> 00:15:56,559
and they said, well, we
have on our iPads we have an

187
00:15:56,600 --> 00:15:58,360
app where we have to scan the
driver's license. I said, good,

188
00:15:58,440 --> 00:16:03,000
that's great. And then I called
Boost Bobo and I asked them all the

189
00:16:03,000 --> 00:16:06,679
same questions and they said, well, you're supposed to have a pin code

190
00:16:07,320 --> 00:16:10,879
in order to swap ont you sim
I says, well, I don't know

191
00:16:10,879 --> 00:16:15,320
what my pin code is, and
she said, well a lot of times

192
00:16:15,279 --> 00:16:21,240
it's like the last we usually suggest
either like the four numbers of your birthdate

193
00:16:21,600 --> 00:16:25,159
or the last four digits of their
social Security number. Oh, that's real

194
00:16:25,360 --> 00:16:30,159
clever there. She suggested that to
me that if you don't know what it

195
00:16:30,240 --> 00:16:32,759
is, it might be that that's
often what it is. I go,

196
00:16:32,840 --> 00:16:34,919
well, what if it's not any
of those? And she says, well,

197
00:16:36,679 --> 00:16:40,480
they can usually call corporate and they
can override that and they can get

198
00:16:40,519 --> 00:16:45,200
somebody to take care of it right
on the spot. So all of them,

199
00:16:45,480 --> 00:16:49,320
that everybody that I spoke to,
they were very accommodating, you know

200
00:16:49,360 --> 00:16:52,159
what I mean, Like they were
very nice, Like they didn't know that

201
00:16:52,159 --> 00:16:55,399
they were dealing with somebody who was
doing some research. They didn't know they

202
00:16:55,399 --> 00:17:00,240
were dealing with what we would consider
an ethical hacker, little social engineering exactly.

203
00:17:00,600 --> 00:17:06,480
And so that all being very helpful
and being very helpful is what gets

204
00:17:06,920 --> 00:17:11,440
you and I a liquidated bag account. So there's a few things that you

205
00:17:11,480 --> 00:17:14,960
know, we want to as system, but you want to put in place

206
00:17:15,000 --> 00:17:18,160
now. Number one, you want
to do your own research on your own,

207
00:17:18,480 --> 00:17:23,279
you know devices, you don't in
calling your own telcode and finding out

208
00:17:23,319 --> 00:17:26,880
you know, if somebody posed as
me, what would by options be.

209
00:17:26,200 --> 00:17:30,160
You want to make sure right now
that you have an additional passcode on your

210
00:17:30,240 --> 00:17:33,400
account, that's not your last four
of your social and your in your birth

211
00:17:36,000 --> 00:17:37,920
Yeah right, if anybody is going
to swap out your sim, you want

212
00:17:37,920 --> 00:17:42,559
to make sure that it's not going
to be easy. And then beyond that,

213
00:17:44,440 --> 00:17:48,920
in your digital life, I suggest
that everybody use a password manager.

214
00:17:48,559 --> 00:17:52,759
So a password manager, of course, is a software program that manages all

215
00:17:52,799 --> 00:17:56,359
your passwords. And when I say
all of your passwords, that means that

216
00:17:56,480 --> 00:18:02,480
you should have multiple passwords, that
your using the same passcode twice, which

217
00:18:02,519 --> 00:18:07,240
is really important because look at I'm
fifty five years old, I don't know

218
00:18:07,880 --> 00:18:12,440
more than three or four passcodes that
I possess in military or four. It's

219
00:18:12,440 --> 00:18:18,200
my Google passcode, it's my Apple
passcode, it's the passcode and my password

220
00:18:18,240 --> 00:18:21,799
manager, and I think the one
for my alarm system. That's it.

221
00:18:22,000 --> 00:18:27,279
That's all I know. My password
manager remembers the rest. And often people

222
00:18:27,440 --> 00:18:30,200
say, well, what if the
password manager gets hacked. I'm not worried

223
00:18:30,240 --> 00:18:33,640
about that at all. And the
reason why I'm not worried about that is

224
00:18:33,640 --> 00:18:37,920
because password managers are security companies.
The low hanging fruit is not the password

225
00:18:37,960 --> 00:18:41,279
manager for the hacker. The low
hanging fruit is the fact that we are

226
00:18:41,480 --> 00:18:45,680
using all the same passcodes across multiple
accounts. And what the bad guys do

227
00:18:45,799 --> 00:18:48,720
is they use a tool called credential
stuffing. So here's an article that I

228
00:18:48,759 --> 00:18:52,440
wrote. I think you could see
that over my shoulder over here right.

229
00:18:52,599 --> 00:18:56,960
Credential stuffing, What it is and
why you should be concerned. A recent

230
00:18:56,240 --> 00:19:03,799
credential stuffing attack on twenty three and
meters left most people bemused if they noticed

231
00:19:03,799 --> 00:19:07,599
it at all. Similarly muted response
to following the leaks of millions of user

232
00:19:07,640 --> 00:19:15,079
records. Basically, an anatomy of
a credential stuffing attack is what the criminals

233
00:19:15,079 --> 00:19:18,519
will do is they'll go to the
dark web and they'll grab millions and millions

234
00:19:18,519 --> 00:19:22,839
of stolen records, and they'll feed
those millions of usernames and passcodes into a

235
00:19:22,920 --> 00:19:30,160
credential stuffing software program. And your
credentials are then stuffed into this software and

236
00:19:30,400 --> 00:19:33,519
they'll see if they can get it
to twenty three and meters. They'll see

237
00:19:33,559 --> 00:19:37,119
if they can get into Amazon to
PayPal, the eBay to your email,

238
00:19:37,240 --> 00:19:41,839
and so on, and they'll stuff
your credentials in say the top one hundred

239
00:19:41,920 --> 00:19:48,960
five hundred one thousand websites, and
the software will log the bad guy in

240
00:19:48,279 --> 00:19:52,160
remotely. That's credential stuffing. Right
now. The way you keep the bad

241
00:19:52,200 --> 00:19:56,119
guy out is number one, you
never use the same passcode twice. That's

242
00:19:56,200 --> 00:20:02,359
number one. Number two, you
used two factor authentication with all your critical

243
00:20:02,400 --> 00:20:06,880
accounts, all of them. Okay, let me show you something here.

244
00:20:07,119 --> 00:20:10,279
Carry really quick and I know that
like the clock is ticking on us here.

245
00:20:10,720 --> 00:20:12,960
Yeah, So on my website,
right, I scroll to the bottom

246
00:20:12,960 --> 00:20:17,640
of the website and actually go to
my homepage. Right, go to my

247
00:20:17,680 --> 00:20:25,960
homepage and on the bottom of my
homepage, one second you'll see one second,

248
00:20:26,279 --> 00:20:29,559
I know the clock is ticking.
Thank you for your patient sofa tight

249
00:20:29,599 --> 00:20:33,079
down. Here you see the cybersecurity
awareness check right, and you see check

250
00:20:33,119 --> 00:20:37,880
it for email has been breached.
And we click on email checker. Hey

251
00:20:37,920 --> 00:20:41,440
to watch this right, so check
it for email hasn't breached. I type

252
00:20:41,480 --> 00:20:45,000
in R O B E R T
S I C I L I A.

253
00:20:45,200 --> 00:20:48,519
N Oh what side this? What
side are we on? Right now?

254
00:20:48,759 --> 00:20:55,480
We're on protect now LLC dot com, Protect now LLC dot com, Protect

255
00:20:55,960 --> 00:21:00,119
now LLC dot com right all right, which is my website and at the

256
00:21:00,160 --> 00:21:07,359
bottom of the homepage, research my
email address robertsisanwimail dot com and then you

257
00:21:07,400 --> 00:21:11,920
see your email and possibly a password
of in stolen in the following breaches.

258
00:21:12,240 --> 00:21:17,720
Now what this means is is that
my email address, Robert tis leonoimail dot

259
00:21:17,720 --> 00:21:22,160
com has been a part of numerous
data breaches, not because I did anything

260
00:21:22,160 --> 00:21:26,759
wrong, but because these particular companies
were hacked. Okay, So this tool

261
00:21:26,920 --> 00:21:32,039
that we have on our website allows
us, allows me and my team to

262
00:21:32,559 --> 00:21:38,720
facilitate you researching over twelve billion stolen
records. We have access to twelve billion

263
00:21:38,759 --> 00:21:44,000
stolen records, so including email addresses
and passcodes. So you see right here,

264
00:21:44,039 --> 00:21:47,440
like right at the top, a
data dub of a massive collection of

265
00:21:47,480 --> 00:21:52,319
three thousand alleged data breaches was found
online, including eighty million unique email addresses

266
00:21:52,319 --> 00:21:56,559
and associated passcodes. Oh my god. Okay, we have the ability to

267
00:21:56,640 --> 00:22:00,359
allow you to research all of that. Here. In July twenty eighteen,

268
00:22:00,400 --> 00:22:04,319
Apollo had what is it, dumb, I don't even know how many millions

269
00:22:04,359 --> 00:22:11,759
of records in pass roads allow uh
is Yahoo? Yes, one hundred and

270
00:22:11,759 --> 00:22:15,359
twenty six million unique email addresses.
Right, here's a bitcoin for him from

271
00:22:15,400 --> 00:22:19,759
back in twenty fourteen, Billy,
we have five million and nine million using

272
00:22:19,799 --> 00:22:26,920
it, the one that makes custom
links yes, right to read exactly redirect

273
00:22:26,000 --> 00:22:30,599
so you don't have to use these
monster URLs. So Bittley got hacked too,

274
00:22:32,160 --> 00:22:37,720
Bitley code halfway mom discus Juice books
showing this is exactly why you need

275
00:22:37,759 --> 00:22:45,640
the pass word manager to create those
in those unique passwords for every site.

276
00:22:45,039 --> 00:22:48,960
I mean, I have my standard
password, but I change it every single

277
00:22:49,160 --> 00:22:53,799
month. And you know, so
like all the old ones that are out

278
00:22:53,799 --> 00:22:57,759
there aren't going to do anybody any
good and all likely good. How often

279
00:22:57,799 --> 00:23:02,440
should you change your password on your
email? So here's the deal, right,

280
00:23:03,000 --> 00:23:06,960
Like I don't you know, like
I haven't changed my password in an

281
00:23:06,960 --> 00:23:11,839
email for a while because I use
two factor authentication. So here's the deal,

282
00:23:11,920 --> 00:23:15,720
right, even if they have your
password, if you have two factor

283
00:23:15,759 --> 00:23:22,319
authentication, whether it's Smaster or the
authenticator app, right, better the authenticator

284
00:23:22,319 --> 00:23:27,519
app or use Google Voice number,
even if they have your passcode, they

285
00:23:27,559 --> 00:23:33,200
can't get in if they don't possess
your mobile soon. Right, So the

286
00:23:33,279 --> 00:23:36,559
idea is to make the data useless
to the thief. So changing up your

287
00:23:36,599 --> 00:23:38,640
password is always a good thing,
okay, And if you want to do

288
00:23:38,680 --> 00:23:41,319
it, every month. Fine,
But for most of us, I would

289
00:23:41,400 --> 00:23:45,960
I say that security needs to be
easy. If it's not easy, you're

290
00:23:45,960 --> 00:23:51,200
not going to do it. So
I would rather you use a different passcode

291
00:23:51,200 --> 00:23:56,079
across every account, use a password
manager that manages all those various passwords,

292
00:23:56,400 --> 00:24:00,079
and then have two factor authentication.
If you do that, in most cases,

293
00:24:00,119 --> 00:24:04,400
you're going to keep the bad guy
out because most other people aren't doing

294
00:24:04,480 --> 00:24:08,480
any of those things. You become
a teper target. They become the path

295
00:24:08,480 --> 00:24:14,599
of leash resistance. Makes sense about
it, yeah, totally. And then

296
00:24:14,599 --> 00:24:18,519
two factor authentication right Like, next
thing you do is you just google it

297
00:24:18,799 --> 00:24:25,319
team wo factor Gmail. Right now, when you do that on the first

298
00:24:25,319 --> 00:24:29,960
page of serch you see two step
verification at my account dog Google dot com.

299
00:24:29,960 --> 00:24:32,720
You could do the same thing for
yao, the same thing for AOL.

300
00:24:33,000 --> 00:24:36,839
And the main, main thing for
most of your listeners viewers is that

301
00:24:37,160 --> 00:24:38,880
you've got to tighten up email.
Man, Like everybody's got to tighten up

302
00:24:38,920 --> 00:24:44,119
email. Email. If they get
into your email, bad guys say own

303
00:24:44,440 --> 00:24:48,759
the email, you own the person. So that's it. The first thing,

304
00:24:48,079 --> 00:24:52,160
no question about it, all right, I know your crunch for a

305
00:24:52,160 --> 00:24:55,160
time, Robert, where we find
you. How do we get that neat

306
00:24:55,200 --> 00:24:59,559
little security checkup that you just showed. I tell everybody going to protect now

307
00:24:59,799 --> 00:25:03,400
LA dot com, Protect now LLC
dot com. Scroll towards the bottom and

308
00:25:03,440 --> 00:25:07,599
you'll see use our free email checker
to check if your email address and or

309
00:25:07,640 --> 00:25:11,559
your passwords are part of any specific
data breaches. All right, excellent.

310
00:25:11,640 --> 00:25:15,759
Hey, you got a question for
Robert myself, Just send me an email

311
00:25:15,799 --> 00:25:21,119
at kl at Carrie LUTs dot com. And there's a link to Robert's site

312
00:25:21,160 --> 00:25:25,640
in the show notes of this interview
on Financial Survival Network dot com. Make

313
00:25:25,640 --> 00:25:27,200
sure you use it while you're there. Sign up for your free newsletter.

314
00:25:27,319 --> 00:25:32,519
Robert always a pleasure, always enlightening, and always gives me something to think

315
00:25:32,559 --> 00:25:36,599
about what I should be doing that
I'm not. And that's the most important

316
00:25:36,640 --> 00:25:38,319
thing. Hey, you buddy,
I appreciate you. Hey. Likewise,

317
00:25:38,359 --> 00:25:41,359
take care, Robert, have a
good day. Thanks for listening to Carrie

318
00:25:41,440 --> 00:25:48,640
Letz's Financial Survival Network your solution to
today's trying times. For the latest,

319
00:25:48,680 --> 00:25:55,400
go to Financial Survivalnetwork dot com.
Financial Survival Network now more than ever
