Okay, so we are back with another episode of Combustible Brains. This is our third or fourth episode in a row. So props to us for consistency this time. No shout out to any listeners because we don't care about any of you. So, hello Ram. That's so not true, but yeah. We care about you a little bit. Only a little bit. Only a little bit, yeah. If you get hit by a truck, we wouldn't be very disappointed. But we would be. Okay. So, that's how we treat our listeners on this podcast, which is to say with the minimum amount of respect. Oh, shit. But that said, tell your friends and also tell your friends about this podcast and more importantly, buy our merch, which does not exist yet. But we will bring out merch that you can buy so we can buy expensive stuff that you cannot afford. That is our goal. You're really on the roll today, man. You're really on the roll. really on the roll yeah that's true i am 32 now so i am wiser as of yesterday and i'm also a little hungover so this podcast is going to be a trip so let's let's just go with that yeah this is going to be entertaining for me oh yeah and for the listener too yeah so no shout out to anybody of you this time but if you listen to one more episode we'll give you a shout out next time around okay definitely cool so uh ryan and i were talking about stuxnet a week ago and we thought this would be a good topic to talk about just in general so um stuxnet what do you think about the name the name itself sounds kind of scary to me because you know it's like an x and it says stuxnet and then you know when you go to the wikipedia page of it uh it you know directly starts with with like uh malicious computer worm and nuclear program of iran and you know all of these things together they are not comforting they are not to read it in a sentence you know way so for people that don't um follow all these things and i did not know about stuxnet until even i did not know until you mentioned it last week so yeah yeah to fill listeners up with what we are talking about yeah for sure so stuxnet was this computer virus or worm that was created by quote unquote western governments in order to spy on iran's nuclear program right that was the first thing that was done and then you know it was really interesting how this was done so you know like normally you have a computer virus the computer virus gets infected you know you steal a bunch of files you know maybe you lose some data maybe you lose some credit card information you know something like that happens uh and then that's that's it right there's some financial damage people get pissed and you move on stuxnet though was a whole different ball game stuxnet was able to actually get into an air gap nuclear facility and actually damage centrifuges that were used for refining uranium which was a whole new step up in this game right i mean that's crazy that is crazy one-fifth of iran's nuclear centrifuge i'm just reading the page dude that is crazy and again this was air gap right it was like there was no way for you know as in can't say no way but it wasn't like easy access to the internet there was like a rest endpoint which you could hit and you know try to like brute force or you know take it down by you know having like a lot of attacks on it it wasn't like that it wasn't like that that it was easy to do no and an air gap so an air gap facility maybe we should just say what that is right an air gap facility is one that is not connected to the internet so there is a literal air gap between you know a facility and then the internet so there is no way stuff from the outside talks to it so stuxnet was able to cross this gap and actually get into the facility and actually damage the centrifuge which i thought was fascinating how the hell did they do that uh i mean it's a very long story and i do not know all of it but the way they did it is i mean to be honest nobody really knows there are theories right speculations speculations but looks like they had physical access at some point so there is um there is a need to get you know your program from point a to b and the only way to do it in an air gap facility is to actually have it on a laptop that goes to the facility then infects the machine right so what these guys are doing is they're trying to get the air gap facility to actually get the air gap facility to actually get the air gap facility to actually get the air gap facility and what these guys did is they created this worm right there's a virus capable of destroying actual physical hardware and then they started infecting people or suppliers of this nuclear facility that used to you know transport materials and stuff to this nuclear plant or whatever the refining plant so they targeted i think three or four companies i don't remember their names and the hope was that they get on a laptop that is then carried over physically by some guy that has five years of experience with the air gap facility and they get the air gap facility to get the air gap facility to get the air gap facility to get the air gap facility to get the air gap facility physical access to the facility is carried over there you know it's uh connected to some sort of network and then it gets on these machines right and i think that's the only way to do it especially since it's air gap right so it has to be a physical access from someone internal like someone who actually visits the facility yeah or i assume like there is some spy or somebody that can do it you know somebody has to do it so james bond james born and maybe james wanted it or maybe like a really hot woman did it you know who knows we're all buddy yeah maybe she seduced some dude you know oh that'll be a crazy good story yeah that'll be like a hollywood movie man i'll be at one hell of a hollywood movie let's let's go with that nsa hired uh who's a who's a actress that could go infiltrate a uranium facility i don't know this is a tough one but they did not yeah so anyway so let's create you know when you mentioned that thing uh i was thinking of you know that uh you know those uh those pendrive attacks that people do like these hackers do like they just uh you know put pendrives in like parking lots put as in they just throw pendrives in parking lots and people literally pick those up and put them like it and put those in the machine so i thought you know something like that like some five dollar pen yeah no nuclear facility dude you're joking but that's exactly how stuxnet worked it was actually is it no no i'm not kidding they actually used usb they didn't throw pendrives into the facility but the first thing stuxnet did so stuxnet was you know somehow delivered to your computer this somehow was you know physical access or whatever but once it was there it started infecting your usb usb drives that were connected to the machine and the theory the most prominent theory is so the way stuxnet seems to have worked is right you plug in a usb drive into your laptop okay and then windows you know remember like windows opens this dialogue box saying uh you know what do you want to do with this pen drive whatever you know and then there is a little icon there right so there is an exploit that they used with not the autorun exploit i think i think it was called the lnk exploit let's just google it okay uh and this lnk exploit i'm just googling it on the side as to exactly what it was let's see works oh there's a github page where where the guy wants me to click on it it's like fuck you dude i'm not going to click don't tell me there's like a code for that in on github there is the first link that showed up is some multi-channel slash link exploit i'm going to click it from i'm on a mac and this is github so you should be fine and he says it's a python link and uh there's a putty page and there's a payload.exe imagine somebody dumb enough to run a payload.exe that you find on github dude there's i'm not going to do that but apparently this is some shortcut um it says malicious shortcut so apparently it creates some shortcut and there is an exploit in windows that stuxnet used to i think it was like the rendering of the shortcut or it creates the shortcut or something which escalates privileges on your machine and that's when instead of uh you know showing you the icon or the shortcut or whatever it was stuxnet then starts taking over so that's how they actually infected you in the first place right and i think uh obviously since this is a this is a and it's not the movies so it won't have a red flashing screen saying your your you know your virus has infected your machine the cliche right so this must have been in in a in a hidden way must be operating for like really long time until someone figured it out right yeah yeah it was for a long time in fact there was a precursor to stuxnet that you remember uh talking about that like i god i forget what it was called it was called flame or dooku or something i don't remember oh those funny words right right dooku and flame and some some stuff like that exactly looks like the western governments quote unquote did some you know right they did some uh spy analysis yeah for justice they spied on these machines for looks like three to five years before stuxnet was even installed and that was the most interesting part for me because it looks like what they did was it was not just a crazy randomized infection okay so what i read about it was first they started controlling some servers around the world this you expect right because of course they're not going to say you know you know who is exactly doing it so they took over right and it's not like their ip address is gonna be seen into the hacks right no way so they took over some servers in germany some in switzerland one was actually in india i forget what it was called and then one in philippines and so on so they called these command and control servers and so they took over some servers in india and so on so they took over some servers in so they took over some servers in germany so they took over some servers in soy drown so so so so and they sent emails to these people that they wanted to infect. So there were over 1,000 targets that they wanted to infect. And the email was a very innocuous JPEG file. So I think it was like 6, 700 KB or something like that. And most of the JPEG had been stripped of data because the actual payload was in the JPEG file, right? The JPEG was just a container kind of thing for that. And I think there was one more mechanism. I think that was used by Flame. I think that was a Word document. And there was an email that they sent to these people. Like, imagine you have to be dumb enough. They said in the email, I think it was from some South Korean firm. And the email said, Hello, sir, we have a list of requests for your company. Please find them attached in the Word document. And I think then you open the Word document. And this was the most badass thing that I saw. They actually took over the font rendering mechanism in Windows to exploit a buffer overflow. So imagine that. Yeah, imagine that. They created that. It's pretty elaborate, man. Dude, it's crazy. So they took over that system in Windows. So the moment the font rendering system was set off, instead of going to whatever font face, they actually redirected it to some whatever payload was actually intended to open. And that escalated privileges on their machine and took over. Right. So then ultimately, so we need to tell, like, you know, the listeners as well. And even I'm curious. So what were like the actual damages? Like, apart from like, say, one fifth of, you know, centrifuges being ruined, which is, of course, a huge thing. Was there anything else as well? And how did it cascade into like a global thing? And how was it found and all of that? Right. I think someone must have gotten really greedy at that point and tried to do a lot more than was expected of it. Yeah. I mean, first of all, to address your point, I don't know what listeners are. I'm talking about what listeners? What listeners? What listeners? So I think at the start, I think you already, like, you know, pissed everyone off and everyone left already. So it's just, you know, you and me. At this point, it's just you and me, which is good. 17% female representation on our podcast, though. Pretty good. But we're working on it. Our HR department is working on it. Everything is good. Okay. So everything's good. But more on point, the primary damage mechanism was the centrifuge. So they wanted to take over. They wanted to take over the centrifuges. So they actually stopped Iran from manufacturing uranium. So maybe let's back up there a little bit, right? So there is a growing animosity, right, over the last few years between Israel and Iran, right? And Iran. Right. And we are not taking sides here, to be clear. But there is an animosity, right? And the Americans and Iran, that's also, you know, a strained relationship, let's say. Right. Iran has been trying to build uranium, like, enrichment plants. For the last few years for quote unquote, peaceful purposes. Right. But everybody knows that, you know, no good thing stops at like peaceful purposes. Right. There's always somebody who says, okay, let's weaponize this or something like that. So. Right. Nobody knows. And it's not just Iran. It's not just Iran. Like it would be the same for US, India, everyone. Everybody. Everybody. The more power you have, you can maybe, you know, start off with good, good intentions. But having such power, it corrupts. It corrupts. Eventually it will corrupt you. So everybody. You know, tries to build, you know, nuclear bombs when they have, you know, uranium enrichment facilities. So Israel's biggest issue was that if Iran gets a hold of, you know, and there is uranium or they're able to enter a uranium on their own, then they could, in theory, build a nuclear bomb, which is going to be a huge issue for the Middle East and their area, because then they are threatened by, you know, Iran. And then everybody surrounding Iran has to build up more capability to counter this threat and so on and so forth. Right. Right. So the conflict goes to the next level. Right. And then it's significantly scarier when everyone is a nuclear power in the region. I mean, just look at the India-Pakistan tension. Right. Exactly. That's exactly what I was going to refer to right now. I mean, that is exactly the same. Right. Yeah. And there's, of course, that looming threat always. And I think that is what's called a nuclear deterrent anyway. But I mean, you know, Pakistan government having nuclear power is scary to me. Yeah, exactly. Because, yeah, I mean, for reasons. I mean, we have a clear bias here to be clear. We are very, very Indian. Right. So our perspective. Oh, very much. Right. So. And no. And again, this is not against the people. Right. We never usually speak against any people, even when we were doing the China episode. It wasn't about the Chinese people ever. And same is with Pakistan. It's like the Pakistan people are like the normal people like us will be doing the normal shit. You know, nobody cares. Right. Nobody. Exactly. Exactly. Everyone has their own life. But it's the government we're talking about. Governments are fucked. So they are just fucked. That's just how it is. So, you know, there is always a threat to people like you and me from a corrupt government. So that scares me. Right. Like if you have a nuclear threat like around, you know, in your neighborhood, that's not good for you. That's not good. Not at all. So anyway, so they have the same issue there. So what Israel and United States wanted to do, this is public, is that they wanted to neutralize the Iranian nuclear threat. Right. So there's been many ways to do this. There's sanctions. There's a lot of sanctions, obviously. Right. So you can say, you know, you cannot use uranium or you can say that you shall not buy these, you know, special refining centrifuges or you can say you can't get access to this technology and so on. But these are just rules, you know, and the moment. And again, even there, the opposition of the two superpowers. So if like, for example, back then, US was doing was against it. Right. So someone who is against US, maybe China or Russia, they will want to back Iran. Right. And they'll be like, okay, who gives a shit? And then, for example, US says no to you, I will provide you the, you know, the, the gear you need. Yeah. And this is exactly what happens because there was a rogue Pakistani scientist, A.Q. Khan, I believe his name was, and I think he helped most of the rogue governments get their hands on nuclear power. I think the same thing happened to Iran. So and not to say that Iran's government is rogue, but that's how they got it through rogue means, looks like this is a theory, right? No, it's unprovable. But that's how it is. That's what it looks like. So then ultimately, is Iran a nuclear state now? Like, do they have capabilities or? They don't have nuclear bombs yet. So they have, they are in the process of building some nuclear enrichment facility again. And the reason this is relevant today is because they got hit by a similar Stuxnet type attack in April, where after like, imagine they installed all the security measures in place from the time. And then after that, Stuxnet was deployed, right, which is what 2010. So 10 years after 12 years after the Israelis are highly believed to have done this attack in April, and they shut down their entire, they shut down the power to the entire facility. So it caused the blackout, which again destroyed or limited their facilities and caused damage and all these things. So they got When you say April, you're saying 2021? 21. Yeah. So this is, yeah. I thought it was long. So even this incidence, right, the Stuxnet incidence, when you first told me like a week ago, I thought that was like in 70s, you know, 70s and 80s. But dude, that was 2010, right? Yeah, that was 2010. That is recent, comparatively. And what you're talking about in April, that is 2021. So this is a relevant topic. I mean, Oh, yeah. So that is still ongoing. And they hit the same facility at Natanz. So like the same facility that was hit with Stuxnet was hit by another Stuxnet type attack. This time, it's unproven yet, because we don't know. Like we are in that phase. Where we nobody has decoded what was hit this time around. Maybe people are working on it as we speak. But it takes months for like antivirus companies to actually figure out, you know, what the worm was and all these things. So maybe in like a year or two, we'll figure out what happened in April 21. So it's going to take some time. But it looks like a Stuxnet type attack. So my point was, you know, like instead of dropping a bomb on a nuclear facility, which also they've done before. Oh, is it? Yeah, they have done that. So dude, these guys are brutal. Yeah, yeah. Yeah, the Israel's military is very aggressive. So they dropped a bomb. I don't think it was in Iran. It was somewhere else. I forget where it was. But yeah, they took out a radar station and then went in and dropped a bomb somewhere and destroyed completely destroyed the nuclear facility. So instead of doing that, I think the Bush administration didn't want them to do that. So what they did instead was focus on a cyber attack, which is even better because now you don't have to go there, right? It's much safer. Because your pilots are safe, you know, and it is completely deniable. You can you know, nobody can even today as we speak about it, nobody has proof about this, right? So that makes you know, physical covert operations back in the day, the cyber attacks makes those seem like not covert at all, you know, because you had to at least physically go there. Whereas now this is like covert plus plus. Exactly. And nobody even knows what happened. It's not like Bush is signing that, you know, saying like, Oh, hello, you know, like, nobody signing exactly. There is no that that reminds me of that James Bond, you know, Dan, Daniel's one of the first few movies, he's talking to Q. And Q is like, you know, we don't need agents like you anymore to go in the field, you know, everything happens through the internet only. So yeah, it's kind of like that. And that's true. Yeah, that's exactly what they did here. So they got into so you know, to, to destroy this facility, what they needed to do was to destroy the centrifuge. Because the centrifuge is really what allows you to enter. It's uranium. So without the centrifuge, you cannot enter into uranium. And if you can't enter into uranium, then you can't build a bomb. That's basically how it works. So they figured out that, you know, there is a Siemens PLC, which is a control system device that controls the centrifuges, right? And it runs at, you know, some certain frequency, like 1000 hertz or something like that. So Stuxnet goes in and slowly changes the frequency. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. change so even the smallest frequency change is going to start damaging you know what is actually happening inside there so they did that right but then if it was um you know so firstly it is so intelligent to do it so minor you know so that it doesn't get huge alarms but then eventually weren't they repairing it again and again like you know if there's little damages yeah so that's what that's what started happening so they started changing the frequency just enough and just randomized it was not like they hit all centrifuges at the same time it was like they hit one or two and then stucks not shut off for 12-13 days so it used to damage it so they first they started you know firing level yeah the first they started firing people they thought you know people are operating these things incorrectly they started looking at you know maybe it's just the you know whatever source gave them the centrifuges maybe it's just bad you know maybe the motor is bad so they spent months trying to figure out what was going on with their centrifuges because every randomly a centrifuge stops working or destroys itself you know and then the others just continue to spin as if nothing happened so dude that must have so as an engineer when something uh screws up right anything it could be anything we always try to you know uh separate out the probable causes and then go on like okay this is not it this is not it this is not it until we find the the actual cause right just imagine how frustrating it must have been for those those people because they're like dude we are trying everything all the permutations all the combinations it's not this it's not this you know they're like using the checklist are we using subpar materials are we doing this are we doing that and it's like no one knows about it it's crazy right and it must be such a complicated project you know like just our bullshit software projects we don't know what's going on imagine a nuclear facility with you know I'm assuming it's crazy complicated and everything so who knows you know and the worst thing sure it must be like the Stuxnet worm used to report back to the control systems valid data so Stuxnet once infected used to record for a while I think like 10 15 days they recorded valid data and as it was infecting so as it went to action to the command and control center for the nuclear facility it replayed data that was valid so engineers didn't know as they were recording you know that the frequency has changed holy yeah oh damn oh that is even oh that's like going in and you know the CCTVs you're like changing the world man exactly that's what they did so there was no trace of what is happening and all of this was inside the air gap so it's not like there was some human sitting outside the the control area and you know putting commands intelligently no this was the worm that was written so well yeah the worm was written so well that it could do this all by itself and it did not stay there it's you know when it used to wipe itself off after a few days and then infect another machine just to keep moving so there is dude that is it epic man yeah it was amazingly well done and that's why they started destroying centrifuges finally they realized that there's something is fishy about you know what is going on something's happening and then they finally I think found out but they have never acknowledged it so that was independently found by somebody else that they're actually you know this infection is going on oh damn okay but then so then officially Iran has never um said that oh yeah we were hit is it like that try to downplay it you remember when that Pakistani uh Air Force caught an Indian pilot you know how the Indian said you know like uh oh no damage was done it was not our plane blah blah you know we always try to downplay when things happen to you right same thing happened in Iran's case they say you know that okay we got hit by an attack but there was very minimal minimal damage our efforts are still on track we are still good you know they they pretend so right right and it will be humiliating to you know uh except that right exactly so they they don't do that so it was amazing to me how you know how sophisticated this thing was and this was not immediately you know apparent to them so which is the most frustrating thing like you said from an engineer standpoint just imagine like things are just stop working right you don't know what's going on all of your checklists are you know all of them seem fine everything seems fine and it's still screwing up yeah that was that was up so anyway I mean I found this feel sorry for yeah feel sorry for the people who lost their jobs man they were just doing their work yeah yeah there is nothing nothing you know anybody can do about it there's also a data collection module I mean this was so sophisticated the data collection module you know took over some Windows update mechanism to you know spread and collect data and all these things so they were actually scouting uh you know computers for stuxnet before they actually deployed stuxnet and this had you know remote so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so create a valid certificate so what time and what serial number to get from the microsoft licensing authority they they tried i mean they used obviously infinite amount of compute power to you know do this so right yeah and and like they say with you know these cyber attacks right the person who's attacking has all the time in the world to you know get ready get uh you know bulk basically bulked up to fight and the person getting attacked has no freaking clue until they get attacked and in this case they did not even know while they were getting attacked so yeah no true and i didn't think about that that's true man it's uh it's crazy dude this story is significantly more interesting than you know what we quickly spoke of last week because this is so dope man yeah no i mean of course it's bad okay let's not like pretend it's not bad it's not like pretend it's not bad it's not like pretend it's not bad it's not like pretend it's not it's bad and we are not like taking sides of you know either iran or us or any country but do this like whatever they did was awesome yeah no that was very sophisticated that's why i found it fascinating and for somebody that really wants to read this i think read on this or watch stuff on this um i read a book maybe i'll link it in the podcast notes i'm very bad with names i think it is called road to zero day by kim somebody i forget names i'll put it in the podcast like notes and then there's another hbo series i believe which is called zero day i think it's on youtube or hbo i forget we'll put we'll put all this stuff in show notes it was awesome so anybody who really wants to you know explore this topic should get into it and you know look around see for yourself quite fascinating stuff yeah i was gonna ask you how is there not a movie on this yet but then i read in uh wikipedia it says black hat like michael man's 2015 movie black hat you oh i haven't watched that but i don't know yeah see is actual stuck snit okay okay no there's just references they're talking about okay yeah i'm just googling on the side this will make an epic movie oh if if it hasn't been done yet i'm not sure but if it hasn't been yeah it's on amazon prime it's called zero days i just googled it it's directed by alex gibney i watched this one it's a really good movie it's a documentary so you should watch it people you know who are interested in this go for it dude this must be awesome yeah nice did you see that china hit a power plant in india with a similar attack i think last year where they shut off uh the power grid is it no i had no idea what what any names any any anyone who admitted uh no there is no admission that uh you know we were hit and so on but this is there is proof so the chinese uh you know hackers they hit uh some power grid and they shut off the power grid and they shut off the power grid in mumbai and shut it off at will so imagine they're critical infrastructure and they shut it off at will so if there is ever a war you know therefore is going to turn off power true man and when you know it's always like that right when you actually start damaging civilians the civilian cities civil life that's when the country comes to knees faster you know rather than you know trying to brute force through the military because the military is always going to be badass right yeah so i think it's kind of like a kind of like a kind of like a kind of kind of They know how to defend, you know, they are like warriors. But when you bring the war into cities, that's when shit gets real. But I think this critical infrastructure is the worst, man. Like, I really do not like this idea that, you know, some warring government is turning off critical infrastructure in your country. The power grids, especially, I think, are very vulnerable. And, you know, it might seem like, okay, you might not get your Netflix for one hour, but not everyone is watching Netflix, right? It's like hospitals and critical infrastructure. And, you know, all of those things are also affected by, you know, such things. Exactly. And complete disarray. It's not just like the traffic signals turn off, you know, it's not just that. No. And everything causes chaos when such things happen. Yeah. I mean, this comes back to, you know, how much do you trust the government? So, it's a topic for another day. Well, when it comes to China, when it comes to Chinese government, of course not. Nobody trusts them. And unfortunately. So, okay, this could be a completely wrong statement, but I'm not sure how epic India is with cyber security because I've not heard the best of the, you know, news or, you know, like articles when it comes to India and cyber security. Like, I don't know how epic India is while defending from attacks, you know, from these rogue governments. I could be wrong. No, the thing with Indian intelligence is generally they are extremely low key. They're never in the media. So, it's very hard to predict for you and me what they're actually doing. I personally have read zero things about them. So, either. You know, either they have taken care of things in the background. I'm sure there's something. They must have. Yeah. I mean, all the IT know-how we have. I'm hoping that at least our people, you know, have enough grunt to defend. And the fact that we're still alive means either they haven't attacked or we are so bad as that. It's silently just blocking all the Chinese. Yeah. Because. Yeah. Let's be honest. I mean, China has been trying to do all this shit to US, to India, you know, all the countries who they find as threats. Right. And to be fair, it's also the other way. Right. The United States will attack on China with cyber weapons. India probably does the same thing. It's always a back and forth. Right. So, because you have to. It's like jiu-jitsu. You know, you cannot just defend all the time. Some days you have to go on the offense and, you know, finish the threat. But you have to go on offense to defend yourself in a way, you know. You have to. Yeah. So, it's, you know, it's a very precarious situation. But, you know, they did hit Indian infrastructure, right? Especially a power plant, a power grid. Come on. I mean, if they're able to do stuff like that, we are not able to defend against them. Maybe more protection, you know, protections are in place now. But at least back then, they turned off the power. And it was not that long ago. It was like a year ago. Right. And, you know, that's also, you know, one of the things I'm unhappy. About when, you know, more and more and more things are turning into connected tech. And, you know, all of that stuff. So, I always think that, especially when reading these news articles and all of that. You know, when more and more critical things start being connected to the internet. You know, medical stuff. You know, all of that. You are just adding more attack surface, right? To just get screwed. And some places, I believe, it's not even needed for those things to be turned into. So smart. You know, smart this, smart that. Yeah. Like your TV does not need a camera, right? Exactly. And again, if it's just TV and shit, it's okay. Like, yeah, maybe you can't watch. Okay. Maybe someone is spying on you. Again, that is bad. And that's a totally different topic. We both are, you know, we care about privacy and all. But here, you know, even infrastructure. Maybe like hospitals. Maybe like, you know, oxygen. Okay. Maybe that's like internet connected now. Okay. Who knows? As in. And if it is, then you're just. You're screwing, right? You're screwing with the patients by just having some conveniences. You're actually allowing those to be breached. Yeah. That's direct life. Yeah. That's bad. Do you think these patient like critical stuff is connected to the internet? I hope not. But no idea, man. Look, I look at it like this. Okay. Like even IT companies, like the tech people, like, you know, our people, they aren't always the best in defending. Right. They get attacked. They are like, they are into the know-how and yet they, you know, they sometimes act like noobs. Right. Whereas this, we are talking about medical staff. Right. They don't know about all of this. They're not supposed to know about all of this. They are good at their job, which is medical stuff. Right. And if IT companies and, you know, tech people get hacked, then what's the chance that, you know, these people have done it well and they won't get hacked. You know? Yeah. It's always that scary feeling. Yeah. No, that's, that is very scary indeed. Especially, see the power grid in my opinion is the worst one. Because if you hit a power grid, you hit hospitals, you hit schools, you know, you hit everything. You hit your first responders, you know, if the power is off, you can't do anything these days. So what if you turn off ventilators, you know, you're screwed. So yeah, it's going to be, it's going to be interesting how these, how these people, you know, how these companies protect themselves in the next few years. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. I think China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, China, exactly man and especially all these critical ones i mean it's okay if the netflix goes away for a while yeah no and i mean see the thing is there is at some point if a state actor is against you you can't really do anything i think that's one thing that stuxnet or you know or dooku or whatever these things they prove is that if the nsa and the cia and some israel you know cyber security arm or whoever china if somebody has decided that they are going to target you you are fucked so that is uh exactly especially if it's like at a personal level then you can like just forget it i mean if you are at a target list at a personal level then you are even screwed like if it's at a government level okay you might have resources to you know help defend that but if you are alone you're screwed right you're fucked you're fucked that is because the zero days that they exploit these zero days even you're fucked you're fucked you're fucked you're fucked you're fucked you're fucked companies that make this software right this link exploit or this auto run exploit or this font exploit this windows exploit this windows update exploit even microsoft didn't know about them you know or the certificates that they stole from i think it was j micron and some real tech or media tech or one of these companies they are actually signing things as if they're valid and they're stealing certificates you know from legit manufacturers legit companies so there is no way you can stop something like that as in literally there is no way because no patch exists when the exploit hits so you cannot protect against you know these exploits not possible exactly that's why they call it zero day right that those are always the worst and it's always the fact that zero days are you know first sold and you know in the communities who know this they know it first maybe it's sold to the bidders and later it comes to the media later we all come to know okay oh this was an exploit okay it was there for the past five years or something like that and then you know you're fucked you're fucked so you don't think so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so so after it was patched so nobody can exploit it that's the idea but right but even there i would say um again if the person who found it is a good uh good player you know the the the white hat type of person yes they will you know tell the correct company but if it's a black hat they will obviously sell it at the at the black market and even versus even if they sell it to the the main company and that is patched do people actually update their devices and you know that's one of the things we were talking about right yeah no that is um i mean zero day or not there are actual exploits that are found by companies themselves right so exploit security patches security vulnerabilities it's so important to update your devices i cannot i cannot like overstate this you have to update devices the moment your updates are available for them and i think lately since the past maybe you know two three four years android has been giving great security updates every quarter you know like most of the time and i think it's been giving great security updates every quarter you know people at least like samsung or google they have been giving i think at least quarterly security updates right and i'm assuming ios also does a great job at that so always always keep your devices on your network updated yeah at least the popular phones right so you know any mainstream phone from samsung gets security updates regularly iphones obviously they have been doing that for the last few years uh but all these sketchy manufacturers especially like in india there are so many sketchy phones that are sold right like the chinese phones are sold right like the chinese phones or you know off-brand phones like nobody's going to do a lot dude a lot of them and even um i uh again this could be a wrong statement but even the so many thousands and thousands and thousands of chinese phones say for example companies make those if they due to the sheer amount of volume of the phones they make even these companies aren't able to address each and every phone with all the updates right so say maybe you got a new xiaomi phone okay so the new phone of course will get great updates right and all their old phones also get miui updates for years and years but are they having security updates which are updated every quarter or you know something like that definitely i don't know exactly because of the sheer amount yeah the sheer amount is one thing but also like come on like if you buy a chinese phone you are you are already being spied on that is all this is obvious so actively spied on exactly spied on because this is how and this is not for some greater cause or that you are incredibly important no they just want your data that's how they make money you know so yeah i always love to give that example of xiaomi you know a few years ago they announced that the profits on hardware will be five percent or zero percent or something like that and everyone cheered in the crowd yeah i always you know think of that example it's like no don't cheer on it man it it that means they're gonna take your data of course they're gonna take your data or uh or this is going to go to next level when you're going to take your data and you're going to take your data and you're going to take your data and then we plug you into the metaverse then we're going to take your entire brain with us if you haven't heard that episode do check that out shout out to our episode shameless plug it's truly a shameless plug but go back and listen to the metaverse episode and all the other episodes and buy our merch so which does not exist yet so yeah man dude what do you think we should make some merch some combustible brains merch yeah man some savage brain art you know with a combustible brain logo below it yeah man yeah man yeah man yeah man yeah man yeah man yeah you're an artist yeah well kind of makeshift artist yeah i think i rise to the occasion when i need to that's fine our listeners are also makeshift listeners so we can give them some makeshift you know makeshift merch and we can we'll price it really high like 100 200 so you and me will get rich i'm hoping because no one will buy it that's we are hoping there is one sucker somewhere not even us or maybe oh maybe we need to make some combustible brain nfts maybe that could fund this entire uh project you know so through that man if somebody wants to buy a picture of a brain for seven million dollars send us an email we are game we will send you a brain for seven million so send your brain yeah okay dude i think with this i think we can call it a wrap i think yep until next time until next weekend super interesting interesting topic though man super interesting and uh also we were only kidding we actually don't like you at all so the little appreciation that we had for you in the previous episodes all fake i'm just taking a shit on our listeners today for for fun you're just like literally you're on fire with that you're like no screw you okay you're listening screw you well they aren't buying our and they aren't listening to our podcast so at this point they're not shit they're not listening to our podcast they're not sharing there are people who are sharing but yeah most aren't sharing most aren't sharing like i see stats i see them you know most of our listeners suck so why should we give them any credit you know if you want to improve this please share the link to our podcast if if you guys don't want pb to shit on you more yeah exactly do it do it do it share yeah and then we can be friends again but until then it's uh it's going to be tough so so conditional so conditional yeah like all modern relationships these are based on uh you know strictly materialistic goals i think it's i think we should call it before this goes out of hand i'm just gonna laugh for the next like five minutes so let's call it let's call it a day okay bye man yep you