CD36: privacy focused open source routers with @jamesob and @_k3tan
EPISODE: 0.3.6
BLOCK: 697424
PRICE: 2067 sats per dollar
TOPICS: simple tips for securing your home network, privacy focused open source routers, pfsense, freshtomato, pc engines apu, hosted vs self hosted vpns
@jamesob: https://twitter.com/jamesob
@_k3tan: https://twitter.com/_k3tan
streamed live every tuesday:
https://citadeldispatch.com
twitch: https://twitch.tv/citadeldispatch
bitcointv: https://bitcointv.com/video-channels/citadeldispatch/videos
podcast: https://anchor.fm/citadeldispatch
telegram: https://t.me/citadeldispatch
support the show: https://tippin.me/@odell
stream sats to the show: https://www.fountain.fm/
join the chat: http://citadel.chat/
00:00 - New investors are more likely to own cryptocurrencies
00:40 - New investors are more optimistic about Bitcoin prices
01:27 - Gender and age differences in crypto ownership and risk perception
02:09 - Importance of mobile interfaces for banks and brokerage firms
02:25 - The influence of social media on investment advice
03:23 - Introduction to the podcast episode topic: routers and network security
06:05 - The importance of routers in home networks
08:52 - The role of routers in securing Bitcoin nodes and networks
12:20 - Tips for improving router security and privacy
30:11 - Considerations when buying a new router and using third-party firmware
43:02 - Introduction to pfSense and its features
51:04 - Overview of DNS and ad blocking
51:29 - Explanation of IP addresses and routers
52:13 - Domain name servers and ad blocking software
53:30 - Purpose of using a router and securing the network
54:06 - Experience with PC Engine's APU and running open source software
55:10 - Building your own router with Fresh Tomato or DDWRT
01:03:06 - Running a router VPN only on a portion of the network
01:06:46 - Using hosted VPNs and the trade-offs
01:12:14 - Importance of networking and securing your network
NOTE
Transcription provided by Podhome.fm
Created: 3/17/2024 8:12:03 PM
Duration: 4712.542
Channels: 1
1
00:00:00.240 --> 00:00:01.860
2
00:00:02.560 --> 00:00:03.939
and they're overwhelmingly
3
00:00:04.400 --> 00:00:15.385
choosing, digital assets over more traditional ones. And Kate Rooney is here with some new data. Makes me feel young that maybe I own some. K? Forever young. That's true.
4
00:00:16.760 --> 00:00:20.460
5
00:00:20.840 --> 00:00:26.060
This is according to our new Invest in You next gen survey conducted by CNBC
6
00:00:26.715 --> 00:00:33.775
and Momentum. Those new US investors who've gotten to the markets in 2020 or later are more than twice as likely
7
00:00:34.110 --> 00:00:39.250
to own cryptocurrencies that's compared to more experienced traders or those who started in 2019
8
00:00:39.870 --> 00:00:43.635
or earlier. That newer investor also tends to be more optimistic.
9
00:00:44.095 --> 00:00:54.899
More than a third say they think Bitcoin prices will be higher at the end of this year. That's compared to about a quarter of the larger investor base. Bitcoin, meanwhile, headed in that direction over the weekend. It's hitting
10
00:00:55.280 --> 00:00:57.175
a 3 month high above 50
11
00:00:58.135 --> 00:01:01.594
$1,000 hit that over the weekend. And individual stocks, though, are still
12
00:01:01.975 --> 00:01:04.075
number 1 with about a third of new investors
13
00:01:04.610 --> 00:01:08.630
holding shares of individual companies. But in a close second, 26%
14
00:01:09.810 --> 00:01:23.579
of new US investors own crypto. That is more than twice the level of ownership in mutual funds or ETFs, and it's more than a third of what, real estate or bond ownership is for that group. And as far as the broader population,
15
00:01:24.039 --> 00:01:33.325
1 in 10 US investors now say that they own crypto. Men are twice as likely as women to hold digital assets, and roughly half of all US investors
16
00:01:33.705 --> 00:01:36.765
say that crypto is, quote, high risk. But there are some differences
17
00:01:37.210 --> 00:01:46.670
in opinion depending on age. And about a third of those 18 to 34 say it's risky, while those over age 64 are much more skeptical.
18
00:01:46.975 --> 00:01:51.634
More than 2 thirds describe it as a high risk investment. Guys, back to you.
19
00:01:53.615 --> 00:01:56.755
20
00:01:57.079 --> 00:02:00.939
for banks, for Wall Street Banks, brokerage firms that are trying to cater,
21
00:02:01.320 --> 00:02:04.380
to this new investor base? We saw how important it was,
22
00:02:05.015 --> 00:02:05.835
to Robinhood's
23
00:02:06.215 --> 00:02:06.715
results.
24
00:02:08.215 --> 00:02:31.715
25
00:02:32.030 --> 00:02:37.330
is that they're more likely to find, investment advice on social media. They were more than twice as likely,
26
00:02:37.790 --> 00:02:45.625
than the average to get investment ideas on social media, so it may have an implication or 2 for, the financial advisers in that industry.
27
00:03:23.709 --> 00:03:27.170
28
00:03:27.549 --> 00:03:28.530
here for another
29
00:03:28.975 --> 00:03:30.915
episode of SIDEL Dispatch,
30
00:03:31.455 --> 00:03:36.435
the interactive live show about Bitcoin distributed systems privacy and open source software.
31
00:03:36.850 --> 00:03:41.110
We're back to our regular programming after last week doing a Bitcoin
32
00:03:41.410 --> 00:03:46.550
Tuesday happy hour on Twitter Spaces because I had my guests and topic fall through.
33
00:03:46.915 --> 00:03:48.215
But I'm very excited,
34
00:03:48.595 --> 00:03:49.815
for today's topic.
35
00:03:51.475 --> 00:03:52.775
Before we get started,
36
00:03:53.235 --> 00:03:53.735
James,
37
00:03:54.400 --> 00:03:55.380
I can hear,
38
00:03:55.840 --> 00:03:58.500
like, some rumbling coming from your mic.
39
00:04:00.960 --> 00:04:02.740
40
00:04:03.115 --> 00:04:05.455
41
00:04:06.795 --> 00:04:15.600
So I wanted to do a quick shout out to the rider dive freaks in the live chat. You guys join every week, and you fucking make this show truly unique and truly special.
42
00:04:16.220 --> 00:04:17.680
So thank you all for joining,
43
00:04:17.980 --> 00:04:22.065
and, a big shout out to all the freaks who support the show.
44
00:04:22.925 --> 00:04:28.945
Ciddle Dispatch, as you know, is a 100% audience funded with no ads or sponsors, so you guys make that possible.
45
00:04:29.810 --> 00:04:35.830
The easiest way to fund the show is through the podcasting 2.0 platforms. If you go to new podcast apps.com,
46
00:04:36.530 --> 00:04:46.165
choose a podcasting 2.0 supported app, search Citadel dispatch, load stats up. You can stream stats directly to the show as you're listening via the podcast feeds.
47
00:04:46.810 --> 00:04:49.550
You can also donate via lightning or paynim@sildispatch.com.
48
00:04:51.210 --> 00:04:54.110
That's also where all of all of our archives are.
49
00:04:54.605 --> 00:04:57.585
My pay name is easy to remember. It's simply Odell.
50
00:04:59.405 --> 00:05:02.225
And there's also merch available if you go to citadel dispatch.com/stack.
51
00:05:04.080 --> 00:05:07.140
Right now, the supply shortage has hit citadel dispatch.
52
00:05:07.840 --> 00:05:15.125
We are out of hats, but if you place an order, you will be first in line when they come back in stock. I can't get those nice
53
00:05:15.664 --> 00:05:17.044
trucker hats, the
54
00:05:17.664 --> 00:05:20.324
the mesh back Richardsons that I really like.
55
00:05:21.320 --> 00:05:24.300
And I refuse to compromise, so I'm hoping that my supplier,
56
00:05:25.880 --> 00:05:27.020
gets new hats
57
00:05:27.640 --> 00:05:28.140
soon.
58
00:05:28.600 --> 00:05:29.820
What else do I have?
59
00:05:31.125 --> 00:05:36.665
Yeah. If you want if you're listening to the podcast feed right now, I had some people reach out, and you're like, how do I join the live chat?
60
00:05:37.045 --> 00:05:40.650
Ciel dispatch is streamed via Twitch, Twitter, and YouTube.
61
00:05:41.510 --> 00:05:42.810
All links are at cildispatch.com,
62
00:05:43.270 --> 00:05:46.170
and if you comment on any of those platforms, it automatically
63
00:05:47.190 --> 00:05:48.250
pulls your chat
64
00:05:48.694 --> 00:05:49.194
into,
65
00:05:49.735 --> 00:05:57.900
the live feed where we can answer your questions, and you can just participate. It's it's it's really fantastic having, all the rider dive freaks join us.
66
00:05:58.620 --> 00:06:00.800
So with all that said, today's focus
67
00:06:01.740 --> 00:06:02.960
is gonna be on
68
00:06:03.900 --> 00:06:04.560
our routers.
69
00:06:05.315 --> 00:06:07.815
Those little devices that you have in your home
70
00:06:08.115 --> 00:06:09.095
often supplied
71
00:06:09.395 --> 00:06:12.375
by your Internet service provider, whether that's a cable company
72
00:06:12.710 --> 00:06:14.729
or Fios or some shit like that,
73
00:06:15.750 --> 00:06:18.650
that controls everything in your home in terms
74
00:06:19.110 --> 00:06:21.050
of Internet access in your local network.
75
00:06:21.725 --> 00:06:22.705
A lot of times,
76
00:06:23.085 --> 00:06:26.145
people just kind of disregard it. They think it's just a
77
00:06:26.925 --> 00:06:33.830
magic little device that has a very long password that is automatically generated by the Internet company that gives it to you.
78
00:06:34.210 --> 00:06:37.410
But, really, it's the command and control center of your home. It is,
79
00:06:38.295 --> 00:06:40.395
it's a little computer that is basically,
80
00:06:42.615 --> 00:06:48.240
you know, connecting all of your devices and connecting them to the wider Internet. It's a very important piece of technology.
81
00:06:49.100 --> 00:06:56.240
I think this conversation will have a lot of good overlap in terms of previous conversations. Specifically, the one I've been thinking about a lot lately,
82
00:06:57.525 --> 00:07:02.185
is that they'll dispatch 31 where we talk about home mining. And when you're home mining,
83
00:07:03.580 --> 00:07:07.840
you, you know, you have you have your your miners connected to your router,
84
00:07:08.380 --> 00:07:08.880
and
85
00:07:09.420 --> 00:07:13.280
you're potentially doxing your your IP address to your mining pools.
86
00:07:14.365 --> 00:07:21.640
You're also giving a bunch of information to whatever your router is. Your router basically knows everything that's happening in your network.
87
00:07:22.600 --> 00:07:29.260
So that was a little bit longer of an introduction than I usually do, but I'm happy to say that 2 close friends are joining us today.
88
00:07:29.715 --> 00:07:30.935
Both repeat guests
89
00:07:31.235 --> 00:07:35.735
on sale dispatch. We have James O'Byrne. James, how are you doing over there?
90
00:07:36.195 --> 00:07:39.419
91
00:07:40.840 --> 00:07:43.900
92
00:07:45.720 --> 00:07:49.785
but going on or no? No. You're you're good now. Okay. Great. Yeah.
93
00:07:50.085 --> 00:07:53.545
94
00:07:54.060 --> 00:07:57.759
95
00:07:58.060 --> 00:07:59.600
96
00:08:00.780 --> 00:08:06.935
97
00:08:08.390 --> 00:08:13.610
98
00:08:13.990 --> 00:08:27.470
A router is just this kind of, like, magic black box that you plug in an Ethernet cable into. And as long as you see the blinking lights go and the network connection comes up on your host, you know, you're pretty happy. You know, the most you might interact with it is
99
00:08:28.410 --> 00:08:31.470
turning it on and off, if you have some kind of a problem.
100
00:08:32.089 --> 00:08:32.589
But
101
00:08:33.585 --> 00:08:35.685
router is a really critical piece of infrastructure,
102
00:08:36.785 --> 00:08:38.405
for your home network. Basically,
103
00:08:39.025 --> 00:08:39.925
it mediates,
104
00:08:40.305 --> 00:08:42.950
you know, every packet that flows in and out,
105
00:08:43.570 --> 00:08:44.950
of, your computers
106
00:08:45.490 --> 00:08:48.390
to the broader Internet. So it's a it's a really important device.
107
00:08:52.214 --> 00:08:54.475
108
00:08:55.015 --> 00:08:59.035
with the advent of Bitcoin that we secure our networks.
109
00:09:00.449 --> 00:09:05.029
Sure. We have things like hardware wallets to protect and and and those sorts of things,
110
00:09:05.970 --> 00:09:07.190
for our cold storage,
111
00:09:07.569 --> 00:09:08.790
but if we're running
112
00:09:09.605 --> 00:09:10.105
nodes,
113
00:09:10.405 --> 00:09:11.385
Bitcoin nodes,
114
00:09:12.085 --> 00:09:20.110
that also have lightning network on top of them, it becomes really important that our network is something that we look at,
115
00:09:20.650 --> 00:09:21.710
to to protect,
116
00:09:22.810 --> 00:09:24.510
and that can be achieved
117
00:09:24.970 --> 00:09:25.710
through routers.
118
00:09:27.505 --> 00:09:30.005
119
00:09:30.625 --> 00:09:35.000
in a certain way, you might be vulnerable to what's called an Eclipse attack,
120
00:09:35.640 --> 00:09:39.340
meaning that, conceivably, if somebody controls the software on your router,
121
00:09:39.880 --> 00:09:50.605
they can control the nodes that your Bitcoin node is talking to, and and they could potentially eclipse you from honest nodes on the network. So that's that's just one of many attacks that, you know, might be capable if someone,
122
00:09:51.385 --> 00:09:54.899
had control over your router. So it's a it's a really critical piece of equipment.
123
00:09:55.600 --> 00:09:57.360
124
00:09:58.800 --> 00:09:59.300
basically,
125
00:10:01.745 --> 00:10:04.885
an Eclipse attack is when an attacker feeds your node,
126
00:10:05.345 --> 00:10:07.445
basically fake blockchain data,
127
00:10:09.490 --> 00:10:15.830
And the the main purpose is to either trick you into thinking you received Bitcoin that you didn't receive,
128
00:10:16.615 --> 00:10:17.995
or I guess
129
00:10:18.455 --> 00:10:23.915
I that's what's happened to to exchanges. I think it happened to Coinbase on Ethereum Classic,
130
00:10:25.140 --> 00:10:27.400
But I guess, presumably, it could also trick
131
00:10:27.780 --> 00:10:43.980
someone into thinking they didn't receive Bitcoin when they did receive Bitcoin. But it's harder. I I can't, like, really fathom how you would use that against someone. But the main way is to trick you into saying, like, look. I sent you Bitcoin when in fact you didn't because it is faulty blockchain data. But, with with Lightning,
132
00:10:45.160 --> 00:10:47.820
with Hotwallets specifically connected to the Internet,
133
00:10:48.600 --> 00:10:52.764
a lot of people might be using a Raspberry Pi Blitz or an Umbrel or something like that.
134
00:10:53.305 --> 00:10:56.764
You also have a direct security issue in terms of,
135
00:10:59.040 --> 00:11:03.779
it's a hot wallet connected to the Internet, and that's connected to your router. So if your router is compromised,
136
00:11:04.375 --> 00:11:09.275
someone might be able to drain funds directly from, your lightning hot wallet.
137
00:11:10.775 --> 00:11:15.370
I feel like we kind of just jumped in hard. I wanna pull it back for a second.
138
00:11:15.750 --> 00:11:21.770
So first off, most people in America, at least correct me if I'm wrong, Khitan. I don't know if it's the same
139
00:11:22.154 --> 00:11:22.894
by you.
140
00:11:23.355 --> 00:11:31.375
But most people here, the router they use is the router that they get in the mail or the cable provider guy brings when he comes over.
141
00:11:32.820 --> 00:11:37.639
And it's it's usually branded with, like, Verizon on it or Cablevision or something.
142
00:11:38.820 --> 00:11:40.839
And they're just kinda handed this device,
143
00:11:41.345 --> 00:11:45.605
And and they say to plug it in, and you will just protect your privacy.
144
00:11:47.824 --> 00:11:50.200
145
00:11:50.660 --> 00:11:52.200
but just different manufacturers.
146
00:11:53.220 --> 00:11:55.000
So it won't be, you know,
147
00:11:55.380 --> 00:12:01.585
it it it won't be, like, a specific, like, Verizon or anything like that. It might be. It might be like something like Optus over here,
148
00:12:02.045 --> 00:12:03.905
but it's also just a generic
149
00:12:04.699 --> 00:12:08.160
hardware like NETGEAR or TP Link or Asus.
150
00:12:08.620 --> 00:12:10.160
They might give you something like that.
151
00:12:10.779 --> 00:12:13.199
152
00:12:14.015 --> 00:12:18.035
why should they care about listening to the next hour of our conversation?
153
00:12:20.709 --> 00:12:22.889
154
00:12:23.829 --> 00:12:27.965
get more out of it. So that's one thing that we need to do.
155
00:12:28.765 --> 00:12:33.345
We can get more out of our router, but we can also utilize some of the functions,
156
00:12:34.525 --> 00:12:35.345
to to
157
00:12:35.790 --> 00:12:38.209
improve our security and improve our privacy.
158
00:12:38.510 --> 00:12:40.209
So that's probably why you'd wanna
159
00:12:40.589 --> 00:12:44.690
listen to the next hour or so. But, also, some of these, routers
160
00:12:45.265 --> 00:12:45.925
are also
161
00:12:46.705 --> 00:12:50.485
the the firmware that's on them is closed source, and there have been
162
00:12:52.465 --> 00:12:54.565
backdoors, intentional backdoors
163
00:12:55.170 --> 00:12:57.030
placed into some of these companies,
164
00:12:58.050 --> 00:12:58.870
which have,
165
00:12:59.970 --> 00:13:05.315
yeah, proprietary software that nobody can really look at. And there have been known cases of,
166
00:13:05.935 --> 00:13:06.595
you know,
167
00:13:07.135 --> 00:13:09.875
unauthorized access into home routers.
168
00:13:10.459 --> 00:13:13.360
So I'm not trying to be alarmist. I'm not trying to be,
169
00:13:14.620 --> 00:13:19.519
I guess, spreading fiber or anything like that, but, it is something to be cognizant of.
170
00:13:20.505 --> 00:13:22.185
171
00:13:22.745 --> 00:13:26.925
thing to follow-up on there. You know, there's a lot of disparate evidence
172
00:13:27.770 --> 00:13:29.710
that, nation states in particular,
173
00:13:31.130 --> 00:13:40.255
do engage in supply attacks because it's just such a a sort of asymmetric payoff. Right? If if you only have a few manufacturers of routers, if you only have a few big telecom companies,
174
00:13:40.795 --> 00:13:42.975
then, you know, inserting instrumentation
175
00:13:43.355 --> 00:13:45.459
into into these few points,
176
00:13:46.079 --> 00:13:48.820
that are deployed so widely and and mediate,
177
00:13:49.360 --> 00:13:50.660
so much critical infrastructure
178
00:13:51.120 --> 00:13:54.735
is is really, really appealing. And so, you know, I wanted to just mention,
179
00:13:55.515 --> 00:14:11.055
a few interesting things that you can look at, you know, as data points. The first is a talk that I really enjoyed by a guy named Rob Joyce, and, he was the chief of Tailored Access Operations or TAO at NSA for a while. I think he's still at NSA,
180
00:14:11.595 --> 00:14:14.574
and he gave a talk in 2016 at Usenix,
181
00:14:15.754 --> 00:14:16.254
about
182
00:14:18.100 --> 00:14:22.839
ways in which the NSA, you know, compromises networks in in pretty broad terms. And,
183
00:14:23.940 --> 00:14:26.040
I have a quote from him here, I think.
184
00:14:26.745 --> 00:14:27.404
He says
185
00:14:28.185 --> 00:14:39.750
so you'll hear a common theme throughout my talk. It'll boil down to a couple small things. The theme I want you to take away is if you really wanna protect your network, you really have to know your network. You have to know the devices, the security technologies,
186
00:14:40.210 --> 00:14:42.525
the things inside it. So why are we successful?
187
00:14:42.905 --> 00:14:53.020
We put the time in to know that network. We put the time in to know it better than the people who designed it and the people who are securing it, and that's the bottom line. So he goes on to kind of insinuate that, you know,
188
00:14:53.880 --> 00:14:56.620
you may not fully understand the devices that are,
189
00:14:57.160 --> 00:15:02.145
running your network, and I think that's that's a pretty good indication. You know, we we know from the Snowden
190
00:15:02.605 --> 00:15:14.050
leaks, for example, that, supply chain attacks are are are are fairly commonly used. So I think it stands to reason that that, you know, it's likely that a router that you could be handed from your ISP,
191
00:15:14.590 --> 00:15:22.035
you know, may well have a a backdoor on there. Another data point that's kind of an interesting anecdote is, you know, even if you're not talking about,
192
00:15:22.655 --> 00:15:25.100
say, a US security agency, you know,
193
00:15:26.300 --> 00:15:28.240
There was a a famous hack,
194
00:15:28.620 --> 00:15:29.759
a few years ago,
195
00:15:31.430 --> 00:15:31.930
discovered
196
00:15:32.274 --> 00:15:36.375
that was done by a company called Supermicro Computer Inc, and they do,
197
00:15:37.475 --> 00:15:37.975
3,300,000,000
198
00:15:38.515 --> 00:15:39.095
in revenue,
199
00:15:40.220 --> 00:15:42.080
you know, per year as of, I think, 2018.
200
00:15:42.460 --> 00:15:48.485
They manufacture motherboards, and it was actually discovered that there was a chip sitting on this thing sort of in plain sight,
201
00:15:49.264 --> 00:15:50.725
that was that was malicious.
202
00:15:51.105 --> 00:15:51.605
So,
203
00:15:51.985 --> 00:15:52.644
you know,
204
00:15:52.945 --> 00:15:56.404
pretty much any sophisticated actor, I think, is gonna try and go after,
205
00:15:56.865 --> 00:15:57.990
these these network devices.
206
00:16:01.090 --> 00:16:03.750
207
00:16:04.370 --> 00:16:05.030
I think
208
00:16:05.685 --> 00:16:06.985
for the average person,
209
00:16:07.764 --> 00:16:10.105
if you're trying to prevent a state attack
210
00:16:10.885 --> 00:16:13.225
from the United States or one of the more
211
00:16:13.820 --> 00:16:16.160
countries like a China or maybe even a Russia,
212
00:16:17.500 --> 00:16:20.560
you're probably just gonna paranoid yourself into
213
00:16:24.135 --> 00:16:24.635
discouragement
214
00:16:25.095 --> 00:16:25.595
and,
215
00:16:26.375 --> 00:16:32.490
poor user experience, very, you know, bad convenience. And I to to most people, I I would say, you know,
216
00:16:32.870 --> 00:16:41.705
you don't even include that in your threat model. You kinda just you try your best, but you you just kind of operate under the assumption that if if you're if you're targeted,
217
00:16:42.325 --> 00:16:52.190
you'll probably get owned. You know, with the supply chain attacks, a lot of times, what we saw was, you know, it was specific suppliers. They would see a Cisco switch or router go,
218
00:16:53.610 --> 00:17:00.595
to a specific place, and they would intercept it midway, and they'd put in some kind of hardware backdoor. But with the ISP routers,
219
00:17:01.055 --> 00:17:04.835
there's this element, and we we talked about it on dispatch
220
00:17:06.090 --> 00:17:06.590
34,
221
00:17:08.090 --> 00:17:09.789
when I had Seth Simmons on.
222
00:17:10.330 --> 00:17:13.230
There's this element of corporate surveillance where
223
00:17:13.575 --> 00:17:16.955
they bake in a lot of surveillance items into their
224
00:17:17.735 --> 00:17:18.235
devices,
225
00:17:19.255 --> 00:17:20.875
and into their software stack
226
00:17:21.800 --> 00:17:38.530
to both analyze what you're doing, and they claim a lot of times, they'll claim, like, oh, we're doing that so to keep the network healthy. You know, we want we wanna know how our users are using our devices to keep our network healthy, deliver you the best service. But, also, a lot of times, it's for targeted marketing and monetization
227
00:17:38.910 --> 00:17:42.290
in terms of customer data, which has become extremely valuable.
228
00:17:44.184 --> 00:17:44.924
So not
229
00:17:45.544 --> 00:17:48.924
only will a lot of these, you know, ISP supply devices,
230
00:17:50.024 --> 00:17:51.085
come with that prepackaged,
231
00:17:51.705 --> 00:17:52.845
then you have to wonder,
232
00:17:53.710 --> 00:18:05.225
not only who are they selling that data to, but can that data be compromised. Right? And and, often the case, that data does get end up compromised because they they're not able to secure their systems on their side well enough.
233
00:18:06.005 --> 00:18:10.825
234
00:18:11.190 --> 00:18:13.049
maybe gaining access to Verizon's
235
00:18:13.670 --> 00:18:15.610
systems, and then, you know, Verizon
236
00:18:16.150 --> 00:18:21.095
themselves maintain some kind of a backdoor into equipment that they're giving out to customers, for example, you know, that
237
00:18:22.534 --> 00:18:24.475
that could that could end up poorly.
238
00:18:27.735 --> 00:18:39.955
239
00:18:41.215 --> 00:18:41.955
240
00:18:42.495 --> 00:18:43.460
what happened was,
241
00:18:44.020 --> 00:18:45.960
I use a router at home,
242
00:18:46.580 --> 00:18:47.960
that I sort of built,
243
00:18:48.340 --> 00:18:50.899
and we can talk a little bit about that later. But,
244
00:18:51.335 --> 00:18:54.555
in order to get Internet actually up to the 3rd floor of my house,
245
00:18:55.975 --> 00:19:00.395
in the process of, you know, getting ready to run Cat 5 through my walls. But, basically,
246
00:19:01.330 --> 00:19:06.150
I needed to use a little, wireless receiver manufactured by Asus.
247
00:19:06.770 --> 00:19:07.270
And,
248
00:19:08.315 --> 00:19:09.695
yeah, I was I was,
249
00:19:10.154 --> 00:19:11.695
looking at TCP traffic
250
00:19:11.995 --> 00:19:12.495
and
251
00:19:13.195 --> 00:19:16.014
or I'm sorry, network traffic, and, I saw
252
00:19:16.940 --> 00:19:22.860
this mysterious traffic on a on a port that I didn't recognize coming from the Asus host. And I looked that up, and,
253
00:19:23.500 --> 00:19:24.800
it turns out that
254
00:19:25.865 --> 00:19:28.044
they're yeah. They're this this little
255
00:19:28.424 --> 00:19:30.924
network device ships with the server that it runs,
256
00:19:31.625 --> 00:19:33.164
that has a known vulnerability,
257
00:19:34.210 --> 00:19:35.830
that allows remote code execution.
258
00:19:36.530 --> 00:19:37.030
And
259
00:19:37.330 --> 00:19:42.710
so, you know, that's obviously not something that's not network traffic that I wanna facilitate because,
260
00:19:43.155 --> 00:19:44.695
you know, that could lead to a vulnerability.
261
00:19:48.115 --> 00:19:52.375
262
00:19:53.060 --> 00:19:55.140
263
00:19:55.460 --> 00:19:56.920
to see to some of these,
264
00:19:57.460 --> 00:19:58.040
you know,
265
00:19:58.580 --> 00:20:00.120
devices that are out there.
266
00:20:00.635 --> 00:20:04.095
Yeah, you've gotta be very, very careful with what you put into your network.
267
00:20:04.715 --> 00:20:05.455
And so,
268
00:20:05.995 --> 00:20:06.495
yeah,
269
00:20:06.875 --> 00:20:09.855
having open source software is probably a better
270
00:20:10.320 --> 00:20:12.500
outcome than, something that's,
271
00:20:12.880 --> 00:20:13.860
you know, proprietary.
272
00:20:15.120 --> 00:20:17.460
273
00:20:18.605 --> 00:20:19.905
depending on where you live,
274
00:20:20.924 --> 00:20:21.424
some
275
00:20:22.285 --> 00:20:23.565
some Internet providers,
276
00:20:25.240 --> 00:20:28.620
and you see this a lot when they, like, bundle in phone
277
00:20:29.080 --> 00:20:29.740
and video.
278
00:20:30.280 --> 00:20:31.020
They they
279
00:20:31.320 --> 00:20:33.420
they say that you can't use another
280
00:20:34.155 --> 00:20:34.655
router,
281
00:20:35.435 --> 00:20:36.175
or modem.
282
00:20:36.955 --> 00:20:39.535
If you have fiber, then you don't need a modem, but,
283
00:20:40.635 --> 00:20:46.420
they'll they'll tell you that you can't use another device except the device that's supplied for them, and they kind of, like, brick their
284
00:20:47.600 --> 00:20:55.065
software stack in a way that, like, you you can't, like, you can't use the you can't use the TV or you can't use the phone unless you use their device.
285
00:20:56.405 --> 00:20:57.465
For those people,
286
00:20:58.165 --> 00:21:00.745
I mean, besides trying to find a better ISP,
287
00:21:01.340 --> 00:21:03.600
a lot of times you don't have competition there.
288
00:21:05.020 --> 00:21:07.920
First, I would say, if you go for the Internet only plan,
289
00:21:09.020 --> 00:21:10.480
you have a lot more,
290
00:21:11.565 --> 00:21:14.145
wiggle room. There's a lot less they can do.
291
00:21:15.565 --> 00:21:22.399
Even if they tell you you can't use your own, device, most of the times, you can figure out a way to use your own device.
292
00:21:23.919 --> 00:21:24.659
But, also
293
00:21:25.840 --> 00:21:28.340
and I guess we should probably go into this. I don't know
294
00:21:29.045 --> 00:21:33.465
if we go into it now, but you can run a device that sits within,
295
00:21:35.125 --> 00:21:45.575
you know, you you can run a a device that sits within your home network that everything else connects to except for, like, the ISP stuff, like the TV or the phone or whatnot. Right?
296
00:21:46.615 --> 00:21:48.135
297
00:21:48.855 --> 00:21:50.075
what a router is,
298
00:21:50.534 --> 00:22:00.590
sort of metaphorically, it's basically like almost a diplomat. So, you know, you have a country of people that's, you know, the the hosts on your network, your laptops, your phone.
299
00:22:01.450 --> 00:22:03.950
And then the router is like a diplomat that communicates
300
00:22:04.335 --> 00:22:08.115
with the rest of the world, and all all communication goes through the diplomat.
301
00:22:09.375 --> 00:22:09.775
And,
302
00:22:10.735 --> 00:22:16.410
so what you could do is sort of, like, have a diplomat to the diplomat. So you could introduce your own device,
303
00:22:17.750 --> 00:22:19.290
and all the ISPs
304
00:22:19.590 --> 00:22:21.930
router knows about is that that single device.
305
00:22:23.565 --> 00:22:29.345
And in that way, you can insulate your hosts from, the device that ISP has given you.
306
00:22:32.000 --> 00:22:37.940
307
00:22:38.880 --> 00:22:41.005
of what I think you could probably,
308
00:22:41.545 --> 00:22:42.265
sort of,
309
00:22:42.665 --> 00:22:47.005
do if you're just not even you know, if you're just starting down this rabbit hole,
310
00:22:47.630 --> 00:22:52.130
I think the first thing that you want to do is actually log in to your router page.
311
00:22:52.909 --> 00:22:55.565
Your router page is something that you can,
312
00:22:56.005 --> 00:22:57.385
it's like the interface,
313
00:22:57.765 --> 00:22:58.505
the command,
314
00:22:59.365 --> 00:23:02.745
that Matt was talking about earlier, the command the control center.
315
00:23:03.210 --> 00:23:04.350
And, basically,
316
00:23:05.450 --> 00:23:06.510
when you log in,
317
00:23:07.210 --> 00:23:09.710
the website is, like it's httpcolon/
318
00:23:11.255 --> 00:23:12.635
192 dot 168.one.one.
319
00:23:14.055 --> 00:23:24.539
I've seen it as 192 dot 168 dot zero dot one. I've also seen it as 10 dot zero dot zero dot one. It really just depends on the manufacturer and the maker of your router.
320
00:23:24.919 --> 00:23:28.220
But if you're on the same network, you should be able to call to,
321
00:23:28.895 --> 00:23:32.275
that router and log in. And the first thing that will happen is,
322
00:23:32.655 --> 00:23:34.495
you'll be presented with a,
323
00:23:35.855 --> 00:23:36.915
a login page.
324
00:23:37.720 --> 00:23:41.740
If you've never done this before, you will probably get a default,
325
00:23:42.920 --> 00:23:43.580
I guess,
326
00:23:44.760 --> 00:23:49.155
username and password, and that default username and password is admin.
327
00:23:49.535 --> 00:23:52.275
Usually, it's admin and the password is admin.
328
00:23:52.575 --> 00:23:55.235
Sorry. Yeah. Or the password is just password.
329
00:23:55.850 --> 00:23:57.070
So there are weak,
330
00:23:57.610 --> 00:23:58.110
passwords.
331
00:23:58.570 --> 00:24:02.650
So the first recommendation that I have is to log in using these,
332
00:24:03.210 --> 00:24:03.710
default
333
00:24:04.705 --> 00:24:05.764
username and password
334
00:24:06.144 --> 00:24:09.445
and change the password to something a little bit more secure
335
00:24:09.825 --> 00:24:10.725
using a,
336
00:24:11.184 --> 00:24:12.164
password manager.
337
00:24:12.470 --> 00:24:14.730
And you wanna make sure that you save that password
338
00:24:15.110 --> 00:24:19.290
in case you need it for the next time. Otherwise, you're gonna have to reset the router.
339
00:24:20.095 --> 00:24:21.155
So that's not fun.
340
00:24:22.415 --> 00:24:24.515
So be sure to change that in the administration
341
00:24:24.815 --> 00:24:28.755
function of your router. Now the reason that I'm saying this is because
342
00:24:29.100 --> 00:24:30.540
if, for example, you bring,
343
00:24:31.580 --> 00:24:38.215
you know, someone, a friend or family comes over and they want access to your Wi Fi, You give them the password to your WiFi,
344
00:24:38.595 --> 00:24:41.895
and they can just easily go into 192 dot 168.1.1
345
00:24:43.315 --> 00:24:46.054
and log in to your router control room,
346
00:24:46.660 --> 00:24:47.640
using the,
347
00:24:48.220 --> 00:24:50.120
a default username and password.
348
00:24:50.820 --> 00:24:53.640
349
00:24:54.274 --> 00:24:59.955
350
00:25:00.355 --> 00:25:02.615
yeah, Airbnbs and people's homes,
351
00:25:03.100 --> 00:25:06.160
they usually have left their routers at,
352
00:25:06.700 --> 00:25:10.640
yeah, on on sort of yeah. It's just the default.
353
00:25:11.154 --> 00:25:13.894
So it's not ideal, and I've seen this at,
354
00:25:14.434 --> 00:25:24.310
other businesses as well when they you know, you log in and they provide you with free Wi Fi access. You get in, and, you can then control their router as well. It's not a very good look.
355
00:25:24.770 --> 00:25:25.270
Now
356
00:25:25.730 --> 00:25:31.565
357
00:25:31.945 --> 00:25:34.925
panel you're talking about. You can set up a secondary guest network
358
00:25:35.260 --> 00:25:36.560
that basically isolates
359
00:25:37.180 --> 00:25:39.920
your hosts from, you know, anybody who might come over.
360
00:25:40.460 --> 00:25:44.640
361
00:25:45.005 --> 00:25:46.225
get that administration,
362
00:25:47.165 --> 00:25:53.745
username and password something different to the default. So that's number 1. Number 2, your Wi Fi password itself.
363
00:25:54.290 --> 00:25:54.870
When you,
364
00:25:55.570 --> 00:25:57.110
give out your Wi Fi password,
365
00:25:57.970 --> 00:26:00.230
it needs to be something not the default,
366
00:26:00.530 --> 00:26:02.150
and it needs to be quite secure.
367
00:26:02.825 --> 00:26:06.445
So what I would recommend is if you go onto the eff.org
368
00:26:07.385 --> 00:26:11.005
website, there is a word list that you can use to roll dice.
369
00:26:12.409 --> 00:26:16.350
So, basically, what you do is you roll, 5 dice and say you get a 3257
370
00:26:18.330 --> 00:26:18.830
3251
371
00:26:20.705 --> 00:26:21.904
2, you you Google, you,
372
00:26:23.585 --> 00:26:28.245
basically use that number, and it will give you a word. You put 5 of those words together,
373
00:26:28.630 --> 00:26:34.330
and you roll your dice 5 5 times, and you'll be able to get a nice clean password,
374
00:26:34.790 --> 00:26:41.225
that is relatively secure and random. So that's what I would recommend as well is making sure that your Wi Fi password
375
00:26:41.684 --> 00:26:44.985
is secure, and it uses at least WPA
376
00:26:45.525 --> 00:26:47.145
2 on the encryption method.
377
00:26:47.669 --> 00:26:48.169
WPA
378
00:26:48.549 --> 00:26:56.250
isn't something I I think that that's been well known to be vulnerable at this point. WPA 2 with a decent password
379
00:26:56.705 --> 00:27:05.365
is pretty good, and then the new encryption standard, I think, is now WPA 3, but that's on newer routers. And I don't have that at my place, but,
380
00:27:06.070 --> 00:27:21.835
your newer models of routers will probably have that encryption standard as well. So that's the second tip that I'd, I'd I'd give is to change your Wi Fi password to something a little bit longer and a little bit more secure. And then the third thing in the as James mentioned,
381
00:27:22.615 --> 00:27:24.370
for the for for,
382
00:27:25.310 --> 00:27:28.210
in this in this router control room panel,
383
00:27:28.750 --> 00:27:32.850
you can set guest Wi Fi's. And what that will do is it will
384
00:27:33.855 --> 00:27:38.355
broadcast another Wi Fi to which you would give another password to, and
385
00:27:39.375 --> 00:27:40.595
all of your guests,
386
00:27:41.460 --> 00:27:48.200
or or devices that you don't trust will sit on this guest Wi Fi. And that guest Wi Fi won't give you
387
00:27:49.205 --> 00:28:00.799
the access to your trusted network, and it won't give you access to any other devices within the within the network as well. And so things like your Samsung TV, a Chromecast,
388
00:28:01.179 --> 00:28:03.200
security cameras, work laptops,
389
00:28:04.139 --> 00:28:05.360
these are the types of,
390
00:28:05.905 --> 00:28:06.565
I guess,
391
00:28:07.425 --> 00:28:14.405
devices that you want on a guest network rather than on your trusted network. Your trusted network should ideally have
392
00:28:14.720 --> 00:28:16.900
things like, your Bitcoin node,
393
00:28:17.280 --> 00:28:20.419
your Calix OS flashed mobile phone,
394
00:28:20.799 --> 00:28:22.580
your Linux laptop maybe.
395
00:28:23.205 --> 00:28:28.345
These are the types of devices that you you know and trust, and those go into the trusted area.
396
00:28:28.645 --> 00:28:36.700
Everything else kind of goes out to this guest. And when your friends come over and you've got family over, you give them the guest Wi Fi password.
397
00:28:37.559 --> 00:28:39.500
So those are my top three tips
398
00:28:39.924 --> 00:28:41.544
for just getting started,
399
00:28:42.245 --> 00:28:44.985
when it comes to routers at home.
400
00:28:45.765 --> 00:28:46.505
401
00:28:50.400 --> 00:28:51.140
402
00:28:53.679 --> 00:28:54.179
And,
403
00:28:56.515 --> 00:28:58.615
yeah. No. That that that is great.
404
00:28:59.075 --> 00:29:03.315
So we have some basic router tips if you're just using
405
00:29:05.700 --> 00:29:11.000
if if if you don't wanna go too far down the deep end right now and you just want some quick,
406
00:29:11.460 --> 00:29:11.960
easy,
407
00:29:13.105 --> 00:29:14.485
improvements you can make.
408
00:29:15.184 --> 00:29:20.804
They're not perfect, but they're they're quick, easy improvements that you can literally do within, like, 10 minutes.
409
00:29:21.800 --> 00:29:26.220
I would add that a lot of routers, like, if you look at them, it'll tell you,
410
00:29:27.880 --> 00:29:31.525
like, on the router, it'll say where that admin page is,
411
00:29:33.505 --> 00:29:40.410
rather than going back and scrubbing to where Katan listed out the common IP addresses that they give you.
412
00:29:41.830 --> 00:29:50.755
And usually, it'll say the password and the the username, the default password and username on the device, which is one of the reasons why you should change it. Because even ISPs that
413
00:29:51.534 --> 00:29:53.955
make it something presumably more secure,
414
00:29:54.770 --> 00:29:59.670
if someone is at your at your place, they can just pick up the router, and they can
415
00:30:00.050 --> 00:30:02.310
they can see what the login information is.
416
00:30:02.770 --> 00:30:03.270
Right.
417
00:30:04.845 --> 00:30:06.945
So I guess at this point,
418
00:30:08.525 --> 00:30:11.025
do we dive deeper? Is this Well, let me
419
00:30:11.370 --> 00:30:18.510
420
00:30:19.050 --> 00:30:23.505
I think many many people don't realize that if you put a device on your network,
421
00:30:24.445 --> 00:30:29.184
you know, and that device has access to the broader Internet, let's say, buy a smart TV or,
422
00:30:29.810 --> 00:30:33.190
you know, some kind of a media device, and you put it on your home network.
423
00:30:33.890 --> 00:30:36.870
There are all kinds of things that that device could be doing,
424
00:30:37.250 --> 00:30:52.660
and you have no way of of really knowing. You don't have any way of examining the code, or you don't really even maybe know what the the hardware actually is in there. And that could be doing any number of things like surveying, you know, the computers that you have, the services that are running. You know, it could be telling the outside world that you have a Bitcoin node running.
425
00:30:54.020 --> 00:30:59.414
So it's really, really important if you can, if it's easy to to isolate these devices to a separate network.
426
00:31:04.570 --> 00:31:05.070
427
00:31:06.490 --> 00:31:11.070
428
00:31:12.184 --> 00:31:14.605
429
00:31:15.065 --> 00:31:19.440
430
00:31:29.675 --> 00:31:39.100
431
00:31:39.880 --> 00:31:42.380
using an ISP supplied router. I don't know.
432
00:31:42.680 --> 00:31:43.580
Whatever you think.
433
00:31:44.520 --> 00:31:55.110
434
00:31:56.850 --> 00:32:04.195
instead of this router, and I wanna replace it with that. What what should I get? What what should I do? Should I just go on Amazon and just buy a device?
435
00:32:06.575 --> 00:32:09.955
436
00:32:10.760 --> 00:32:14.940
isn't sort of known by your ISP is is maybe an improvement because
437
00:32:15.559 --> 00:32:21.215
if somewhere in some database, your name is next to, say, a a router model number, then,
438
00:32:22.255 --> 00:32:26.355
it makes it more feasible for, you know, an attacker to
439
00:32:27.039 --> 00:32:33.700
see maybe what, you know, vulnerabilities are associated with that that model of router. So if you kind of bring your own router,
440
00:32:34.825 --> 00:32:39.245
even though, you know, maybe, a router you might buy off the shelf might still have some vulnerabilities,
441
00:32:40.185 --> 00:32:44.650
associated with it. At least it's not, like, right next to your name in a row on some database.
442
00:32:48.570 --> 00:32:55.434
443
00:32:56.375 --> 00:32:57.514
just like we flash,
444
00:32:58.215 --> 00:33:02.510
our mobile our our pixels with the Calix OS. You can also flash,
445
00:33:02.910 --> 00:33:04.690
routers with more open source,
446
00:33:05.230 --> 00:33:06.130
router firmware,
447
00:33:07.070 --> 00:33:09.730
that so I have, for example, a Netgear
448
00:33:10.065 --> 00:33:13.445
r 7000. It's it's it's a fair fairly popular model,
449
00:33:15.025 --> 00:33:19.045
and this thing is, like, you can put, you know, DD WRT.
450
00:33:19.530 --> 00:33:20.809
You can put Fresh Tomato on it.
451
00:33:22.570 --> 00:33:24.590
And and what this is is just
452
00:33:25.370 --> 00:33:25.870
our
453
00:33:26.250 --> 00:33:27.470
our our open source
454
00:33:28.085 --> 00:33:29.945
firmwares that, you know,
455
00:33:30.885 --> 00:33:33.705
open up a lot more capability than, say, Netgear's
456
00:33:34.085 --> 00:33:35.545
stock standard issued,
457
00:33:36.245 --> 00:33:36.745
firmware.
458
00:33:37.169 --> 00:33:43.590
So if you are looking to get a router, make sure that it is like, if if if you want to go
459
00:33:44.049 --> 00:33:49.165
into this a little bit further, then you can, see if that model is available for flashing,
460
00:33:49.705 --> 00:33:51.565
on the websites of these, like DDWRT
461
00:33:52.105 --> 00:33:52.605
or,
462
00:33:52.980 --> 00:33:58.120
Fresh Tomato, and that could give you a little bit more, room to to grow with your router.
463
00:33:58.820 --> 00:34:12.359
464
00:34:12.819 --> 00:34:17.079
it's worth making sure that the firmware that you're running is up to date,
465
00:34:17.700 --> 00:34:18.200
because,
466
00:34:18.845 --> 00:34:19.585
you know,
467
00:34:20.365 --> 00:34:24.605
routers have a lot of vulnerabilities associated with them, and they're constantly being discovered. And so,
468
00:34:25.244 --> 00:34:26.704
it's likely that the router
469
00:34:27.060 --> 00:34:35.880
shipped with an older version of the firmware than probably is current. So it's, you know, it's it's a pretty easy process to update your firmware, so that's something, for people to look at as well.
470
00:34:36.545 --> 00:34:39.184
471
00:34:39.505 --> 00:34:43.204
Yeah. Keep your router firmware up to date even if it's issued
472
00:34:43.585 --> 00:34:44.885
by, a company.
473
00:34:46.030 --> 00:34:48.690
Yeah. And it's proprietary. It's a good worthwhile,
474
00:34:49.550 --> 00:34:51.170
thing to do. Definitely.
475
00:34:52.030 --> 00:35:00.115
476
00:35:00.655 --> 00:35:04.400
I I think that's really interesting, and I think there are some really good projects out there
477
00:35:05.279 --> 00:35:08.500
depending on what hard hardware you have. You know, I know pfSense,
478
00:35:09.200 --> 00:35:11.460
for example, has been around for a very long time,
479
00:35:12.105 --> 00:35:15.385
and it is an excellent project. And I think we're gonna talk a little bit more about that. But,
480
00:35:16.665 --> 00:35:23.619
you know, I think you also have to be a little careful because when you start wading into 3rd party firmware, you know, you start introducing,
481
00:35:24.400 --> 00:35:25.839
more third party trust,
482
00:35:26.565 --> 00:35:29.705
unless you're really gonna sit down and scrutinize a project. And so,
483
00:35:30.565 --> 00:35:33.385
you know, sometimes I worry with a lot of things that,
484
00:35:34.290 --> 00:35:37.110
something that is marketed as being security focused,
485
00:35:37.490 --> 00:35:38.870
you know, prepared by,
486
00:35:39.810 --> 00:35:41.590
somebody who is in a device manufacturer.
487
00:35:41.965 --> 00:35:45.425
I mean, that, you know, that could easily be a honeypot. And so
488
00:35:45.965 --> 00:35:47.825
it introduces a little bit of complexity
489
00:35:48.285 --> 00:35:51.825
into thinking about your your threat model here because,
490
00:35:52.430 --> 00:35:57.570
I think if you're gonna go the route of a 3rd party firm where you have to sort of scrutinize who it's coming from.
491
00:35:58.190 --> 00:35:59.070
492
00:35:59.950 --> 00:36:02.745
I agree. I I would agree with that, analysis.
493
00:36:03.605 --> 00:36:07.625
Yeah. I I think there are projects like pfSense, which I think
494
00:36:08.070 --> 00:36:10.010
are are working in the,
495
00:36:10.630 --> 00:36:12.090
I guess, the the the
496
00:36:13.190 --> 00:36:16.895
the the open source community and that it's not like that these,
497
00:36:17.375 --> 00:36:19.135
open source communities haven't had,
498
00:36:19.695 --> 00:36:22.995
I guess, vulnerabilities in the past. That's not that's not the,
499
00:36:24.710 --> 00:36:28.089
it's not like a stop gap. You can't just completely say open source routers
500
00:36:28.470 --> 00:36:30.869
are are are gonna be vulnerability free,
501
00:36:32.069 --> 00:36:32.569
but
502
00:36:32.925 --> 00:36:36.305
they do provide some level of assurance that there's no,
503
00:36:36.685 --> 00:36:37.345
at least,
504
00:36:37.645 --> 00:36:38.865
you know, backdoor.
505
00:36:39.405 --> 00:36:46.670
And, again, if you're not scrutinizing the code, then it's probably a a little bit more difficult to say. So I I completely accept your point,
506
00:36:47.050 --> 00:36:54.615
that, yeah, you know, some of the well, like, well known ones, maybe not a honeypot, but some of the more, you know,
507
00:36:55.975 --> 00:37:04.710
508
00:37:06.210 --> 00:37:08.390
that's claiming to protect your privacy.
509
00:37:08.945 --> 00:37:20.140
Right? Like, there's a bunch of them that that are out there specifically. Like, that I think that is a a low hanging fruit because, I mean, we even see under the announcement tweet that I said that we were gonna have this conversation.
510
00:37:21.240 --> 00:37:29.345
There was a couple people that posted just, like, no name company routers that I'd never heard of that just you go to the page, like, we are gonna protect your privacy.
511
00:37:29.885 --> 00:37:31.025
We're here for you.
512
00:37:32.285 --> 00:37:35.270
513
00:37:35.830 --> 00:37:36.330
Invisibox,
514
00:37:36.630 --> 00:37:41.450
and, I I went out to their website and kinda trolled around their GitHub a little bit. And,
515
00:37:41.865 --> 00:37:42.765
you know, it's
516
00:37:43.465 --> 00:37:47.244
that stuff is really it takes a lot of time to size up if there isn't
517
00:37:47.545 --> 00:38:00.545
a really big community around it, if if there isn't, you know, a long history of the project, if, there aren't a lot of eyes on the code base, you essentially have to read through everything that's in there, or get someone you trust to do that and and sign off on it. So,
518
00:38:01.204 --> 00:38:03.305
yeah, it's it's it it can be very difficult.
519
00:38:04.484 --> 00:38:08.184
I wanted to make another note, though, about buying your own router.
520
00:38:10.470 --> 00:38:12.010
There are a few
521
00:38:12.790 --> 00:38:14.470
products out there now that are,
522
00:38:14.950 --> 00:38:17.130
really nice from a user experience standpoint.
523
00:38:17.704 --> 00:38:20.285
You know, Google and Amazon both have products
524
00:38:20.744 --> 00:38:25.244
that are these mesh routers where, you know, you buy maybe they sell you a pack of
525
00:38:25.910 --> 00:38:28.970
3 router nodes, and you can kind of add, you know,
526
00:38:29.510 --> 00:38:32.150
nodes as necessary and just put them around your house. And,
527
00:38:32.549 --> 00:38:37.474
I actually installed one of these for my mom because I thought it was, you know, simple and, you know, it'd be easy to maintain.
528
00:38:38.174 --> 00:38:40.674
And I was surprised to find that the administrative
529
00:38:41.454 --> 00:38:44.994
software for these routers is a cloud hosted product,
530
00:38:45.970 --> 00:38:56.115
you know, from from one of these companies. And so, you know, you have a mobile app on your phone that allows you to do the administrative stuff, instead of being hosted just on, the router itself.
531
00:38:56.494 --> 00:38:59.075
And that to me is a is a pretty big
532
00:38:59.535 --> 00:39:00.355
red flag.
533
00:39:01.135 --> 00:39:05.420
So I would recommend, you know, if you're if you're thinking about this kind of thing, if you're conscious security,
534
00:39:06.600 --> 00:39:07.100
don't
535
00:39:07.400 --> 00:39:09.100
get a router where the administrative
536
00:39:10.795 --> 00:39:12.734
functionality is on some cloud.
537
00:39:13.675 --> 00:39:15.214
So be careful of that.
538
00:39:19.250 --> 00:39:21.030
539
00:39:23.810 --> 00:39:25.910
540
00:39:26.515 --> 00:39:31.805
541
00:39:34.500 --> 00:39:35.960
They're all pretty much proprietary,
542
00:39:37.540 --> 00:39:38.760
and they all basically
543
00:39:39.220 --> 00:39:40.200
on the like,
544
00:39:40.795 --> 00:39:46.335
we talk about it a lot on dispatch, this idea of convenience versus privacy and security trade off.
545
00:39:46.795 --> 00:39:49.615
They tend to go more towards the convenience side,
546
00:39:51.490 --> 00:39:52.950
which is unfortunate because,
547
00:39:54.049 --> 00:39:57.270
in theory, it's a really cool concept that you can just
548
00:39:57.945 --> 00:40:02.765
buy, like, a package of of 5 devices and put them all around your house and and have,
549
00:40:05.599 --> 00:40:08.020
and have have Wi Fi wherever you need it,
550
00:40:08.400 --> 00:40:09.460
with little administration.
551
00:40:10.160 --> 00:40:13.700
But your trade off there is is usually security and privacy.
552
00:40:14.125 --> 00:40:17.745
We have BTC pins asking if there's any open source,
553
00:40:18.285 --> 00:40:20.305
do it yourself mesh Wi Fi
554
00:40:22.290 --> 00:40:22.790
options.
555
00:40:23.490 --> 00:40:25.670
This is a question that I've wondered myself,
556
00:40:26.210 --> 00:40:30.035
that I do not have an answer to. Do do either of you guys have an answer to this?
557
00:40:31.555 --> 00:40:32.775
558
00:40:33.234 --> 00:40:36.295
configuring this, but, you know, one thing that you could do
559
00:40:36.755 --> 00:40:37.234
is,
560
00:40:37.555 --> 00:40:51.685
I think it would be pretty tractable to set up repeaters that are open source. But I I don't really know of any products. You know, I think, I actually don't know the technology that they use for meshing because the nice thing about meshing, obviously, is you don't have to switch networks
561
00:40:51.985 --> 00:40:53.925
as you're navigating the access points.
562
00:40:54.865 --> 00:40:58.240
But, but, yeah, I'm not sure of any open source solutions there.
563
00:40:59.420 --> 00:41:07.895
564
00:41:09.635 --> 00:41:11.815
Oftentimes, like you said, under a different
565
00:41:12.115 --> 00:41:15.095
it's it's an access point, so it's like a different Wi Fi name.
566
00:41:16.069 --> 00:41:25.825
While the mesh the idea of the mesh is, like, 2 devices can connect to each other and then boost your signal or whatever, and you can also, like, add an Ethernet
567
00:41:26.845 --> 00:41:33.984
component to it, like, on a far reaching area, and then that all connects into your your network. And they do make it very simple. And, unfortunately,
568
00:41:35.750 --> 00:41:37.849
in my research, there's there's
569
00:41:39.030 --> 00:41:40.890
really, your option ends up being,
570
00:41:42.915 --> 00:41:44.935
like like James said, is repeaters,
571
00:41:46.515 --> 00:41:53.380
or hardwired access points where you, like, run an Ethernet cable to an area, and then you connect it to an access point.
572
00:41:53.920 --> 00:41:54.420
573
00:41:55.200 --> 00:42:03.674
574
00:42:05.310 --> 00:42:07.170
So, yeah, you can use your existing,
575
00:42:09.470 --> 00:42:10.610
electricity cables.
576
00:42:11.390 --> 00:42:19.525
One goes near the router, and the other one goes stairs where you you need it, and the wires or the signal comes through the electricity cables,
577
00:42:19.985 --> 00:42:20.965
out of your home.
578
00:42:21.819 --> 00:42:24.640
So that's another option, but I think,
579
00:42:25.420 --> 00:42:27.440
the speed on those is questionable.
580
00:42:27.740 --> 00:42:31.119
581
00:42:31.805 --> 00:42:42.700
But then it did I remember as a as a young kid, it it blew my mind that you can, like, plug in onto one wall outlet and then plug into another wall outlet and get Internet. It's like a cool concept.
582
00:42:45.080 --> 00:42:52.875
So we were talking about PFSense earlier. Should we should we start with PFSense? Should we dive into that? I mean, Umbrel just added it, so it's, like, on a bunch of,
583
00:42:53.895 --> 00:42:59.595
it's on the radar of a bunch of Bitcoiners all of a sudden. I know you, Catan, dove into it really deep.
584
00:43:01.000 --> 00:43:05.020
What is pfSense? How would people use it? Why is it
585
00:43:05.640 --> 00:43:07.635
Yep. Why is it good? Okay.
586
00:43:08.575 --> 00:43:12.435
587
00:43:12.815 --> 00:43:17.710
It is a router firmware, or a router operating system, so to speak.
588
00:43:18.089 --> 00:43:21.069
You flash it onto basically any potato device,
589
00:43:21.849 --> 00:43:22.910
but, generally,
590
00:43:23.745 --> 00:43:26.065
the Netgate, which is the company that,
591
00:43:26.625 --> 00:43:27.365
that produces,
592
00:43:27.985 --> 00:43:28.485
pfSense,
593
00:43:29.025 --> 00:43:34.260
also sells hardware alongside the free open source software, and you can get one, from them.
594
00:43:34.560 --> 00:43:35.460
There's other
595
00:43:36.080 --> 00:43:38.820
hardware that is, available. But, basically,
596
00:43:39.684 --> 00:43:40.825
instead of using
597
00:43:41.125 --> 00:43:41.625
a,
598
00:43:42.325 --> 00:43:43.944
your your Internet service provided,
599
00:43:44.964 --> 00:43:46.905
router, you would use this device
600
00:43:47.285 --> 00:43:49.050
and plug into the
601
00:43:49.430 --> 00:44:03.325
into the WAN section your Internet, and then the LAN section would be all of your other devices. So you can use an existing router to put in a and put that into access point mode. And from there, you'll get Wi Fi as well as 4 other ports,
602
00:44:03.704 --> 00:44:05.964
that way you can connect all your devices into.
603
00:44:07.170 --> 00:44:08.150
So the the
604
00:44:08.530 --> 00:44:11.030
p f sense router, again, it's very similar to,
605
00:44:11.330 --> 00:44:13.030
your router, but it has,
606
00:44:14.050 --> 00:44:14.869
more functionality.
607
00:44:15.205 --> 00:44:15.705
And,
608
00:44:16.085 --> 00:44:19.785
obviously, you log in to that page, and you can do things like,
609
00:44:20.805 --> 00:44:21.305
connect,
610
00:44:21.925 --> 00:44:22.165
your
611
00:44:22.805 --> 00:44:23.925
connect all of your
612
00:44:24.645 --> 00:44:30.089
sorry. You can connect the router to a VPN, and then all devices on your network
613
00:44:30.390 --> 00:44:34.329
are then also protected by the VPN. So that's one really, really cool,
614
00:44:34.855 --> 00:44:43.195
use case. That's not to say that these consumer grade routers can't do it. They can. The open sourced flashed consumer grade routers or even some, you know,
615
00:44:43.710 --> 00:44:50.609
Netgear routers and, you know, TP Link and Asus routers may also give you the functionality of connecting through to your
616
00:44:51.635 --> 00:44:54.295
VPN, like, mobile VPN or something like that.
617
00:44:54.595 --> 00:44:59.395
But you some of these devices are very low powered and low
618
00:45:00.620 --> 00:45:01.680
they have low specifications.
619
00:45:01.980 --> 00:45:02.480
So,
620
00:45:02.860 --> 00:45:04.960
you might not get the full bandwidth,
621
00:45:05.500 --> 00:45:06.800
of your Internet connection
622
00:45:07.340 --> 00:45:11.605
on these, you know, consumer grade routers. Whereas if you have a separate dedicated hardware,
623
00:45:12.625 --> 00:45:17.265
that runs pfSense, you might be able to get the entire full bandwidth that you,
624
00:45:17.985 --> 00:45:20.170
that that, yeah, that that can occur through,
625
00:45:20.550 --> 00:45:21.290
the VPN.
626
00:45:21.830 --> 00:45:23.530
So that's one thing that you can do.
627
00:45:23.830 --> 00:45:27.185
The other thing that you can do is, put on an ad blocker,
628
00:45:27.645 --> 00:45:29.105
so you can start to,
629
00:45:29.885 --> 00:45:41.360
you know, mess around with what you want on your network and what you don't want on your network. So things like trackers and ad blocks and those sorts of things, can be managed from the pfSense router.
630
00:45:42.095 --> 00:45:45.475
You can also look into hosting a VPN server.
631
00:45:45.935 --> 00:45:56.480
So what that means is instead of connecting like, a VPN client would be to connect through to something like Malvad or IVPN or something like that, a VPN server allows you to connect
632
00:45:56.780 --> 00:45:59.724
back to your home such that you can connect,
633
00:46:00.045 --> 00:46:16.190
to your network and access devices and services running in your home from anywhere in the world. And so your pfSense router can do that. That's not to say that other devices in your network can't do the same, but this is a one example of another thing that you can do with your pfSense router.
634
00:46:16.755 --> 00:46:17.555
You can also monitor traffic,
635
00:46:19.075 --> 00:46:20.775
limit bandwidth to certain devices,
636
00:46:21.234 --> 00:46:24.605
and you can create guest networks. All that sort of stuff will,
637
00:46:25.840 --> 00:46:29.460
yeah, will yeah. And you can also use VLANs, which is kind of like
638
00:46:29.840 --> 00:46:30.900
virtual LANs.
639
00:46:31.520 --> 00:46:33.140
So you can, create
640
00:46:33.835 --> 00:46:34.335
existing,
641
00:46:35.194 --> 00:46:44.100
using your existing hardware, like the the cables. You can, you know, create more networks out of that. So those are the types of things that you can do with a pfSense router.
642
00:46:44.880 --> 00:46:47.845
That's not necessarily to say that, you know, you can't do it with other
643
00:46:48.885 --> 00:46:50.105
firmware flash routers,
644
00:46:51.125 --> 00:46:56.105
or the stock standard routers, but it is a open source project that you can utilize,
645
00:46:56.750 --> 00:46:59.890
and that I've been using for a very, very long time in my home.
646
00:47:00.350 --> 00:47:05.730
647
00:47:06.355 --> 00:47:10.295
client side. They can do on their individual devices. But the cool aspect
648
00:47:10.995 --> 00:47:11.735
of having
649
00:47:12.035 --> 00:47:17.160
a router that you have full control over is that you can do it network wide.
650
00:47:18.100 --> 00:47:23.400
When when Katam was talking about a VPN, for instance, you can obviously just run,
651
00:47:24.145 --> 00:47:27.205
a VPN client on your computer or your phone or something.
652
00:47:27.744 --> 00:47:31.365
But if you want all traffic on your network to go through a VPN
653
00:47:33.099 --> 00:47:38.079
using one of these open source projects, or as Catan said, even some of the more closed,
654
00:47:38.540 --> 00:47:40.240
options offer that functionality,
655
00:47:41.099 --> 00:47:42.079
allow you to
656
00:47:43.464 --> 00:47:50.365
do it network wide or an ad blocker network wide rather than individual ad blockers every time you're on a on a browser.
657
00:47:52.609 --> 00:47:53.829
Catan, so
658
00:47:54.609 --> 00:47:55.109
pfSense
659
00:47:56.369 --> 00:47:58.789
is now integrated into Umbrel, I believe.
660
00:47:59.505 --> 00:48:03.285
But Umbrel is a ras Raspberry Pi platform pretty much.
661
00:48:03.585 --> 00:48:05.444
It only has one Ethernet port.
662
00:48:06.330 --> 00:48:12.110
Is that is it is that a practical option for people? Like, how does that how does how does that fit in?
663
00:48:12.890 --> 00:48:18.684
664
00:48:19.065 --> 00:48:20.924
665
00:48:21.224 --> 00:48:22.525
666
00:48:22.904 --> 00:48:24.924
I have not seen any news on that.
667
00:48:25.500 --> 00:48:41.055
That's the first time I You wouldn't you wouldn't run it on a Raspberry Pi. Right? Like, that doesn't make sense. Well, it doesn't make sense. You need 2 Ethernet ports at minimum. A Raspberry Pi only comes with 1 unless you get some sort of adapter or extension or something like that that is also compatible with pfSense.
668
00:48:42.329 --> 00:48:47.390
That's gonna be, you know, something that you'll need to sort of research up. But generally speaking,
669
00:48:47.770 --> 00:48:51.150
the pfSense routers will typically work with
670
00:48:52.185 --> 00:48:56.045
Intel network into interface cards that had some problems with Realtek,
671
00:48:56.425 --> 00:49:00.765
which is the other option, but I I've heard that that is getting a bit better.
672
00:49:01.350 --> 00:49:02.970
But, yeah, stick to Intel,
673
00:49:05.030 --> 00:49:08.650
network interface cards, and you can put them into any computer,
674
00:49:09.005 --> 00:49:26.005
and they usually have 4 ports. So the first port is for your WAN, so that's your Internet coming in. And then the second and third could be for a LAN, so your local area network that you trust, another LAN for your guest, and maybe a third for, you know, security cameras or something like that.
675
00:49:26.705 --> 00:49:29.605
So that's, you know, sort of sort of how you'd use those ports.
676
00:49:29.905 --> 00:49:35.540
But to put it into a Raspberry Pi, yeah, I would not yeah, I don't think that that's a wise idea.
677
00:49:36.480 --> 00:49:44.405
678
00:49:44.785 --> 00:49:49.845
in terms of performance because, you know, there is potentially a lot of data being ferried back and forth there.
679
00:49:50.680 --> 00:49:52.300
I see curious mind 123,
680
00:49:53.079 --> 00:49:56.220
asked a question that I I think is good to touch on. He says,
681
00:49:56.680 --> 00:49:59.740
or they say, can I just use a Linux machine for this stuff?
682
00:50:00.985 --> 00:50:01.485
And,
683
00:50:02.745 --> 00:50:07.965
I wanna step back and and remind people, you know, this wasn't obvious to me before I got into computers, but
684
00:50:08.570 --> 00:50:14.430
your router is really just another computer. It's, it's it's it's much like your host system, except it has,
685
00:50:14.890 --> 00:50:25.505
as Catan was talking about, you know, these network ports that are just pieces of hardware, and then there's some software configuration on there and some programs that are running that know how to, you know, route TCP packets or,
686
00:50:26.080 --> 00:50:30.720
do do DNS, which we'll talk a little bit about. And pfSense is actually just,
687
00:50:31.120 --> 00:50:32.740
a fork, I think, of FreeBSD,
688
00:50:33.040 --> 00:50:34.725
which is a famous Unix distribution,
689
00:50:36.005 --> 00:50:40.105
known for security. And so all PSense really is is is a nice,
690
00:50:41.205 --> 00:50:42.105
GUI interface
691
00:50:42.820 --> 00:50:45.400
on top of some unique software configuration.
692
00:50:45.700 --> 00:50:46.200
And
693
00:50:46.580 --> 00:50:51.720
all the box that you're running on it is is just a computer with, you know, some Ethernet ports.
694
00:50:52.805 --> 00:50:55.944
And, so I think it's it's it's good to keep that in mind.
695
00:50:57.525 --> 00:51:01.250
Matt, do you think it would be interesting at all to talk a little bit about, like, DNS,
696
00:51:02.030 --> 00:51:09.410
697
00:51:10.085 --> 00:51:11.705
698
00:51:12.325 --> 00:51:13.925
699
00:51:14.325 --> 00:51:22.380
let's let's step back a little bit and talk about, you know, just some really basic Internet fundamentals here at a very, very high level. So I don't wanna scare anybody away, but,
700
00:51:23.660 --> 00:51:30.785
there there is a notion on, the Internet protocol of an IP address, which you've probably heard of. And, essentially, all that is,
701
00:51:31.405 --> 00:51:37.185
is a unique number associated with a host on some network. So on the global Internet,
702
00:51:37.724 --> 00:51:39.410
you know, we have a a certain
703
00:51:39.950 --> 00:51:41.730
set of numbers. And, basically,
704
00:51:42.350 --> 00:51:43.890
when you are given,
705
00:51:45.310 --> 00:51:52.285
Internet service by an ISP, there is a single IP address or a single number that identifies your router to the rest of the world.
706
00:51:52.585 --> 00:51:57.220
And then the router basically translates any traffic incoming to it,
707
00:51:57.839 --> 00:52:02.260
to the specific computer on your network, which has a a different
708
00:52:02.715 --> 00:52:04.555
numbering space, a numbering scheme,
709
00:52:04.955 --> 00:52:06.415
to dole out to hosts.
710
00:52:06.795 --> 00:52:16.260
So, basically, computers know about this one number that identifies some other computer out there on the network, but, obviously, we work in terms of names. You know, I wanna be able to type google.com instead of 8.8.8.8
711
00:52:17.040 --> 00:52:17.620
or something.
712
00:52:19.200 --> 00:52:23.494
And so there are there's a software that runs called domain name servers,
713
00:52:24.115 --> 00:52:24.615
and,
714
00:52:25.155 --> 00:52:26.595
you yourself can have,
715
00:52:27.234 --> 00:52:33.160
a domain name server. And, basically, what that does is it translates a human readable name to this IP address.
716
00:52:33.700 --> 00:52:42.185
And the way that ad blocking software works is, you configure your router to basically tell a host when it connects, hey. By the way, I'm offering a DNS
717
00:52:42.805 --> 00:52:44.345
service. You can use it.
718
00:52:45.365 --> 00:52:48.345
And then when the host decides to use that DNS server
719
00:52:48.920 --> 00:52:49.420
and,
720
00:52:49.800 --> 00:52:53.340
you know, your browser queries the DNS server for ads.google.com
721
00:52:53.960 --> 00:52:55.340
or what, you know, whatever it is,
722
00:52:56.515 --> 00:52:57.015
The
723
00:52:57.315 --> 00:53:01.575
DNS program on your on your PSN router or or your pie hole or whatever,
724
00:53:02.674 --> 00:53:06.650
basically resolves is is configured to resolve that address to 0.zero.zero.zero,
725
00:53:07.670 --> 00:53:11.930
which will not serve any traffic. So, basically, we come up with a long list of known
726
00:53:13.015 --> 00:53:13.835
ad addresses
727
00:53:14.295 --> 00:53:18.155
that we then assign to a specific, you know, the 0 IP address.
728
00:53:24.450 --> 00:53:26.070
729
00:53:30.290 --> 00:53:31.109
Right. So
730
00:53:31.915 --> 00:53:40.415
so, I mean, like, a a way to kind of, like, a way to kind of look at at what we're doing here is is is the idea is to basically put, like, a bodyguard
731
00:53:41.630 --> 00:53:43.250
between you and the Internet. Right?
732
00:53:43.950 --> 00:53:45.090
733
00:53:46.990 --> 00:53:54.905
734
00:53:56.150 --> 00:53:56.650
We
735
00:53:57.750 --> 00:53:59.130
James, you've been experimenting
736
00:54:00.230 --> 00:54:03.530
with PC Engine's APU and running open source,
737
00:54:04.549 --> 00:54:05.770
software on that.
738
00:54:06.455 --> 00:54:09.435
How's that experience been like? Is that a good option for people?
739
00:54:10.695 --> 00:54:12.475
740
00:54:14.119 --> 00:54:17.100
desire to, you know, sit for hours and debug,
741
00:54:17.960 --> 00:54:26.525
you know, various Linux configuration issues. Mean, I'm certainly glad I did it. I had a I had a ball doing it. To be honest, a lot of the ways that I've learned,
742
00:54:27.145 --> 00:54:30.045
you know, what I know about computers is through,
743
00:54:30.369 --> 00:54:31.030
you know,
744
00:54:31.410 --> 00:54:34.869
doing various things with home networking and, you know,
745
00:54:35.330 --> 00:54:37.910
setting up a media server in high school. And I think
746
00:54:38.315 --> 00:54:48.140
these are just you know, they're these experiences can be frustrating, but, the frustration really forces you to kinda learn. And when your network connection is disabled because, you know, you don't have the right
747
00:54:48.779 --> 00:54:52.380
device driver installed for a wireless card and you're, like, digging through,
748
00:54:53.019 --> 00:54:59.454
forms to figure out some patch that you might go apply. You know, it's very frustrating, but you you do end up retaining a lot of the skill,
749
00:55:00.315 --> 00:55:02.734
that that's necessary to do that stuff. So
750
00:55:03.730 --> 00:55:04.930
there there's this,
751
00:55:05.410 --> 00:55:08.950
NIM called doctor Duh, and, you can go to github.com/doctorduh.
752
00:55:10.210 --> 00:55:14.325
And he's put together all kinds of interesting guides on security. He's got a really good one for,
753
00:55:14.885 --> 00:55:18.985
how to securely set up a a UB key configuration and, you know, move your SSH
754
00:55:19.685 --> 00:55:23.900
keys, onto it if if that's your thing. But he's also got a really good,
755
00:55:25.019 --> 00:55:26.000
guide on,
756
00:55:27.420 --> 00:55:34.785
how to build your own router, essentially. And like I was saying earlier, really, this just amounts to obtaining some hardware,
757
00:55:35.565 --> 00:55:36.625
you know, that has
758
00:55:37.005 --> 00:55:38.465
a decent Ethernet capability,
759
00:55:39.480 --> 00:55:40.280
and then,
760
00:55:40.760 --> 00:55:43.180
putting a Linux distribution on it. He actually,
761
00:55:44.280 --> 00:55:46.380
has instructions for both Debian
762
00:55:46.680 --> 00:55:47.500
and OpenBSD,
763
00:55:47.960 --> 00:55:48.540
I think.
764
00:55:49.325 --> 00:55:53.904
And so, you know, you you you get this piece of hardware. It has some Ethernet ports. It has a
765
00:55:54.444 --> 00:55:55.025
a a wireless,
766
00:55:56.125 --> 00:55:56.625
card,
767
00:55:56.960 --> 00:55:57.940
and you install
768
00:55:58.560 --> 00:56:01.220
Linux. And he walks you through setting up
769
00:56:01.680 --> 00:56:04.805
all of the various parts of what a router does. So you set up,
770
00:56:05.204 --> 00:56:08.585
DNS, you set up, IP tables rules, which basically,
771
00:56:08.885 --> 00:56:10.585
you know, allows you to articulate
772
00:56:11.045 --> 00:56:12.585
how you want traffic,
773
00:56:13.599 --> 00:56:15.380
to be regulated within your network,
774
00:56:17.359 --> 00:56:18.180
ad blocking,
775
00:56:19.599 --> 00:56:22.705
DHCP service, which I I probably won't talk about.
776
00:56:23.345 --> 00:56:29.605
But it's it's really educational because you get to see all the different parts of what a router actually does. You get to configure it yourself.
777
00:56:30.400 --> 00:56:33.220
And then by the end of it, you know, you have something
778
00:56:34.400 --> 00:56:36.980
that's using very a very, very general toolset
779
00:56:37.485 --> 00:56:40.865
to secure your network, which I think is really important. Because, again, you know,
780
00:56:41.245 --> 00:56:47.480
if I were if I were an attacker and I wanted to compromise as many high value targets as I could, I'd probably try and infiltrate,
781
00:56:48.180 --> 00:56:48.839
you know,
782
00:56:49.700 --> 00:56:53.160
a project like PSense that is that is made for
783
00:56:54.205 --> 00:56:57.105
this kind of thing. Whereas if if you follow this guy's instructions
784
00:56:57.725 --> 00:57:01.505
and you go through and you set up the specific software packages, these are very general,
785
00:57:01.885 --> 00:57:02.205
very,
786
00:57:03.710 --> 00:57:04.450
time tested,
787
00:57:04.910 --> 00:57:08.930
you know, very scrutinized software packages, and so it's just kind of a more basic tool set.
788
00:57:09.950 --> 00:57:12.175
So I'd really recommend that to anybody who's
789
00:57:21.630 --> 00:57:23.250
card that I use is is
790
00:57:23.550 --> 00:57:26.130
is definitely weak as compared to,
791
00:57:27.150 --> 00:57:34.434
you know, a router you might buy off the shelf. I don't know if that's still the case, but, that's a little bit of a bummer. But, I'm still really happy,
792
00:57:35.055 --> 00:57:41.650
you know, I'm using it because I I have familiarity with all the software, and it's and it's just a Debian box. So, you know, I think that's,
793
00:57:42.770 --> 00:57:43.990
that's a good way to go.
794
00:57:46.605 --> 00:57:49.905
795
00:57:50.845 --> 00:57:56.339
And, yeah, I might I might get more details from you a bit later on on all of that because I you know, as
796
00:57:56.740 --> 00:58:09.974
similar to you, I just play around with these things, and I learn as I go. And, you know, keeping your skills sharp and those sorts of things is something that I just generally want to want to keep progressing with, so I'll I'll I might hit you up, James, on on that.
797
00:58:10.380 --> 00:58:12.080
798
00:58:12.940 --> 00:58:18.645
799
00:58:19.525 --> 00:58:21.705
800
00:58:22.565 --> 00:58:23.225
you know,
801
00:58:23.605 --> 00:58:24.505
it's an existing,
802
00:58:24.965 --> 00:58:25.465
router,
803
00:58:26.645 --> 00:58:31.060
that I use as a just a wireless access point. So instead of,
804
00:58:31.680 --> 00:58:35.460
you know, having the wireless in the box of the pfSense router,
805
00:58:36.235 --> 00:58:38.495
I use a wireless access point,
806
00:58:38.955 --> 00:58:40.895
with, you know, fresh tomato.
807
00:58:41.995 --> 00:58:45.710
And there, I've been able to get, like, a VLAN setup.
808
00:58:46.170 --> 00:58:48.110
So what that means is,
809
00:58:49.130 --> 00:58:50.990
you can broadcast 2
810
00:58:51.964 --> 00:58:58.065
Wi Fi signals. One signal is your trusted Wi Fi, and the other one is a guest Wi Fi,
811
00:58:58.840 --> 00:59:04.140
for which I can control all the rules on the pfSense router and say, okay. I don't want anyone
812
00:59:04.520 --> 00:59:05.580
getting onto
813
00:59:05.960 --> 00:59:06.460
my,
814
00:59:07.000 --> 00:59:08.140
my trusted network,
815
00:59:09.035 --> 00:59:12.975
and I want it to have a VPN, and I want it to have ad blocking.
816
00:59:13.275 --> 00:59:13.775
So
817
00:59:14.155 --> 00:59:14.735
you can,
818
00:59:15.035 --> 00:59:16.895
you you know, you can configure your,
819
00:59:17.355 --> 00:59:22.000
your your your guest network how you want it. So that's something cool that comes out of,
820
00:59:22.380 --> 00:59:29.155
having these sorts of, routers that allow you to have VLANs and tag things and those sorts of extra functionalities,
821
00:59:29.695 --> 00:59:31.475
which Fresh Tomato does.
822
00:59:32.735 --> 00:59:39.630
There's heaps of other things that Fresh Tomato enables as well, and we've spoken about those, you know, opening up a a a
823
00:59:40.970 --> 00:59:45.815
a VPN server as well as connecting through to a VPN client. Those sorts of things,
824
00:59:46.355 --> 00:59:51.095
are all available on Freshtomato as well if, you know, you wish to to look at that.
825
00:59:51.634 --> 00:59:54.214
There's lots of guides on how to flash your router.
826
00:59:54.830 --> 00:59:58.350
You can or, on on YouTube, I'm sure you can search up,
827
00:59:58.830 --> 01:00:04.050
how you how you flash these things. It's fairly similar to your Kallix OS phone.
828
01:00:04.565 --> 01:00:11.465
The other thing is, though, when you are doing something like this project, keep in mind that there might be other people in your household,
829
01:00:12.190 --> 01:00:14.770
and it might be it might take longer than you expect.
830
01:00:15.390 --> 01:00:21.730
So just be mindful that you do this during maybe outside work hours as more people work from home and use your Internet connection.
831
01:00:22.705 --> 01:00:30.245
If the Internet's down for even just, you know, 5 minutes, people start to scream may start to scream in your household. So just be mindful of that.
832
01:00:31.470 --> 01:00:33.890
And then yeah. Like, just yeah.
833
01:00:35.790 --> 01:00:38.930
That's something that you sort of, yeah, wanna just sort of manage
834
01:00:40.515 --> 01:00:41.015
expectations
835
01:00:41.315 --> 01:00:53.270
around how long things are gonna take. The other thing you can also do is buy a separate router from, like, Gumtree or something, like a a normal router, and play with that and learn in that environment, use that as a testing environment,
836
01:00:53.570 --> 01:00:54.230
and then
837
01:00:54.585 --> 01:01:00.285
bring that across to a production environment. So that's another way you can sort of test things out and test the waters.
838
01:01:00.905 --> 01:01:02.765
So that's what I've been doing as well.
839
01:01:05.130 --> 01:01:06.349
840
01:01:07.450 --> 01:01:08.190
you've used
841
01:01:08.490 --> 01:01:08.990
pfSense
842
01:01:09.609 --> 01:01:10.829
and Fresh tomato
843
01:01:11.210 --> 01:01:12.109
Fresh tomato.
844
01:01:12.615 --> 01:01:13.435
Do you have
845
01:01:13.815 --> 01:01:15.915
a I don't know how I wanna pronounce tomato.
846
01:01:16.775 --> 01:01:21.655
Do you have a preference there if if people are trying one for the first time, which they should try first? Or
847
01:01:22.660 --> 01:01:25.460
848
01:01:25.940 --> 01:01:28.200
how, you know, how much you want to,
849
01:01:29.140 --> 01:01:31.555
get involved or get get dig deeper into this.
850
01:01:32.595 --> 01:01:34.454
Networking can get extremely
851
01:01:34.994 --> 01:01:36.694
complicated, and pfSense
852
01:01:36.994 --> 01:01:37.494
provides
853
01:01:37.954 --> 01:01:39.015
not only the beginners,
854
01:01:39.340 --> 01:01:48.615
but also a very, very advanced toolset. But if you just wanna focus, like, say, for example, you've already got a router and you can flash it with Fresh Tomato or DDWRT
855
01:01:49.315 --> 01:01:49.875
or something,
856
01:01:50.515 --> 01:01:51.575
you know, that you
857
01:01:52.434 --> 01:01:53.095
can relatively
858
01:01:53.395 --> 01:01:57.150
see that it has, you know, a lot of community support and those sorts of things,
859
01:01:57.610 --> 01:02:00.030
then that is a a way to learn.
860
01:02:00.570 --> 01:02:04.030
And then if you want to go even further, then
861
01:02:04.645 --> 01:02:10.345
PFSense would be the way that you can go, and then you can go full blown like James and get, you know,
862
01:02:11.045 --> 01:02:14.690
Debbie in packages and and, you know, all of that command line stuff.
863
01:02:15.150 --> 01:02:30.160
It really is kind of a choose your own adventure, but I think the thing is to start somewhere and securing your network. As I said, the basic steps are to just secure your Wi Fi password, keep your router up to date. These are the sorts of basic tools you can start
864
01:02:30.460 --> 01:02:31.680
and then go from there.
865
01:02:32.460 --> 01:02:39.355
866
01:02:39.655 --> 01:02:49.350
probably, you know, will not make their own router. And I I, again, I really wouldn't recommend that unless you have a keen interest in figuring out, you know, the ins and outs of networking. But,
867
01:02:49.810 --> 01:02:55.575
but, yeah, you know, Catana, I think your your your three points of advice and maybe adding update your firmware,
868
01:02:56.674 --> 01:02:59.734
absolutely solid, and I think everybody should look at doing that stuff.
869
01:03:03.610 --> 01:03:05.850
870
01:03:06.490 --> 01:03:13.204
Can you run the router VPN only on a portion of your network and say leave the guest network without the router level VPN?
871
01:03:13.984 --> 01:03:17.445
Because the VPN may impact our work computers and what we can access.
872
01:03:17.750 --> 01:03:19.450
873
01:03:20.150 --> 01:03:24.570
So, for example, I'll give you, so what I've got is I've got a guest network,
874
01:03:24.950 --> 01:03:26.730
and it's got my Samsung TV.
875
01:03:27.385 --> 01:03:32.125
My Samsung TV also has this program called Kayo Sports, which is,
876
01:03:32.745 --> 01:03:34.765
a streaming sports service,
877
01:03:35.065 --> 01:03:36.525
and it doesn't like VPNs,
878
01:03:37.430 --> 01:03:43.610
because it's all sort of it's kinda like Netflix. They they they go around whack a mole ing all the, the VPN IP addresses.
879
01:03:44.285 --> 01:03:49.345
So what you can do is that for that particular device, you can say, alright. This IP address,
880
01:03:49.645 --> 01:03:51.744
I want you to go through the normal,
881
01:03:52.240 --> 01:03:53.860
tunnel, like, the the usual,
882
01:03:54.480 --> 01:03:55.780
un VPNed traffic
883
01:03:56.080 --> 01:04:09.095
and all the other devices I want on the VPN. So, yes, you can sort of mix and match what you exactly want or what device you want to have VPN to and what you don't want. You can even bundle them into one whole group. So say, for example,
884
01:04:09.880 --> 01:04:14.540
you and that's called an alias. So, basically, you take, alright, these three devices,
885
01:04:15.160 --> 01:04:16.300
those IP addresses,
886
01:04:16.600 --> 01:04:18.140
I want under unVPN,
887
01:04:18.440 --> 01:04:23.484
and then you just tell your router or you create a rule that says for these particular,
888
01:04:24.345 --> 01:04:25.645
this particular alias,
889
01:04:26.750 --> 01:04:28.770
I I don't want that on the VPN.
890
01:04:29.070 --> 01:04:31.570
So, yes, you can do that. It is yeah.
891
01:04:35.375 --> 01:04:39.555
892
01:04:41.180 --> 01:04:43.280
893
01:04:45.580 --> 01:04:49.760
I mean, you could have, like, a separate access point that is VPN only.
894
01:04:50.994 --> 01:04:51.494
895
01:04:52.674 --> 01:05:16.145
Yes. You can. Yeah. Or so if you want, you can have, you know, 2 access points, but that like, I think, for me, I didn't want 2 access points, so I wanted more of a a VLAN approach. I just wanted that one hardware. So all I have is a pfSense box and a a wireless access point, but you can put 2 wireless access points, one going into a VPN tunnel and one just freehold
896
01:05:16.849 --> 01:05:17.829
for everything else.
897
01:05:18.530 --> 01:05:22.450
That's that's always a possibility as well. Basically, what I'm thinking is, like
898
01:05:22.930 --> 01:05:23.750
899
01:05:24.530 --> 01:05:25.030
for
900
01:05:25.435 --> 01:05:27.615
people that might have come out of our home minor,
901
01:05:28.795 --> 01:05:29.295
dispatch,
902
01:05:30.555 --> 01:05:34.095
and they have, like, a bunch of ASICs that only connect via Ethernet,
903
01:05:34.960 --> 01:05:37.140
they can connect those to an access point
904
01:05:37.920 --> 01:05:40.020
and just have that one access point
905
01:05:40.480 --> 01:05:40.980
run
906
01:05:41.600 --> 01:05:45.825
a VPN if they if they don't wanna put the rest of their home network under a VPN. Right?
907
01:05:46.125 --> 01:05:48.385
908
01:05:48.685 --> 01:05:51.105
as to how which devices and which,
909
01:05:51.630 --> 01:05:58.130
it it it can be done at the device level. It can even be done at the port level or or the network level, the subnet, so to speak. Yeah.
910
01:06:00.555 --> 01:06:08.974
911
01:06:11.030 --> 01:06:13.210
912
01:06:14.390 --> 01:06:20.005
It depends on how security critical what your building is. And, I'd say given their track record, I mean,
913
01:06:20.385 --> 01:06:21.605
I wouldn't necessarily,
914
01:06:22.625 --> 01:06:23.845
buy from them, but,
915
01:06:24.305 --> 01:06:26.085
obviously, can depend on your project.
916
01:06:28.900 --> 01:06:30.360
917
01:06:32.420 --> 01:06:38.734
Before we wrap up, should we should we talk really quickly about why someone would wanna use a hosted VPN in the first place?
918
01:06:46.370 --> 01:06:50.045
919
01:06:50.585 --> 01:06:52.605
And so if all you're trying to do is
920
01:06:53.065 --> 01:06:55.645
circumvent, you know, location based restrictions,
921
01:06:56.740 --> 01:07:02.200
You don't so much care about the privacy per se. You know, a hosted VPN can be a good option.
922
01:07:04.315 --> 01:07:08.095
923
01:07:09.835 --> 01:07:13.010
924
01:07:13.710 --> 01:07:13.790
the
925
01:07:14.510 --> 01:07:15.250
you're you're sort
926
01:07:15.870 --> 01:07:18.530
of routing your traffic through a third party and,
927
01:07:19.470 --> 01:07:27.665
you know, that that can mean all sorts of things depending on who they are. Right. Obviously, like, the answer with a lot of the stuff is that you just need to use host to host encryption,
928
01:07:28.250 --> 01:07:30.990
and not rely on your your transport layer being
929
01:07:31.290 --> 01:07:32.190
actually encrypted.
930
01:07:33.610 --> 01:07:34.750
But, but, yeah,
931
01:07:35.184 --> 01:07:40.885
I don't have anything against them. But, you know, again, any service where, you know, you can just pay in Bitcoin,
932
01:07:41.424 --> 01:07:57.405
I think is an appealing target for a honeypot. I like Mulvid. I've used Mulvid before, but I don't know who runs it. I don't know why they run it. So Right. So so there's a trade off. Right? There's a so there's when you talk VPNs, there's basically 2 types of VPNs if you're talking about an end user. There's
933
01:07:57.944 --> 01:07:58.825
934
01:07:59.480 --> 01:08:03.660
self hosted VPN where you're running the VPN software yourself
935
01:08:04.200 --> 01:08:07.900
on ideally hardware you control, but a lot of people will do it on, like,
936
01:08:09.175 --> 01:08:10.555
on on some kind of server.
937
01:08:12.295 --> 01:08:25.449
And you you host a VPN yourself, and you route your traffic through that VPN, and any traffic that comes out the other side of that that VPN will have your dedicated IP address that's attached to your
938
01:08:26.535 --> 01:08:27.755
self hosted VPN.
939
01:08:28.295 --> 01:08:31.915
With a hosted VPN, you're trusting the VPN provider
940
01:08:32.615 --> 01:08:36.270
to not be keeping logs. Your traffic is going through them.
941
01:08:37.450 --> 01:08:42.270
If you're using a shitty VPN, you might even have given them additional personal information besides
942
01:08:43.045 --> 01:08:51.784
your traffic and your IP address because you you pay with a credit card or something like that. But in the case of MOLVAD or IVPN, you you pay with Bitcoin.
943
01:08:52.510 --> 01:08:59.810
MOLVAD I I don't think the IVPN requires it either, but MOLVAD does not ask you for an email address even. It doesn't even ask you to set up a password.
944
01:09:01.135 --> 01:09:03.715
They give you, like, an account number, and you just pay with Bitcoin.
945
01:09:04.975 --> 01:09:08.515
The benefit there with something like a with these hosted VPNs
946
01:09:09.190 --> 01:09:11.130
is if they aren't fucking you,
947
01:09:11.510 --> 01:09:16.090
which there's no way for us to verify independently if they are or not. But if they aren't,
948
01:09:16.845 --> 01:09:28.270
you almost you have an anonymity set almost. You have you're you're sharing the IP address with a bunch of other people. There could be a 1,000 Mullvad users all using the same Canadian IP address at the same time.
949
01:09:28.730 --> 01:09:30.910
So when it comes down to something like
950
01:09:32.170 --> 01:09:32.910
a miner
951
01:09:33.485 --> 01:09:36.625
and you're connecting to, let's say, slush pool with your miner.
952
01:09:38.685 --> 01:09:45.159
Slush pool doesn't require any identifiable information, but they have your IP address. But if you use a hosted
953
01:09:45.539 --> 01:09:46.039
VPN
954
01:09:47.300 --> 01:09:55.095
with them, then they don't really even have your IP address. They they have this shared IP address that is shared by a bunch of different people. So there's,
955
01:09:56.050 --> 01:09:59.750
I I would say, specifically, in the distinct case for miners,
956
01:10:00.050 --> 01:10:01.190
to me, it seems,
957
01:10:01.970 --> 01:10:04.470
like an obvious option, a hosted VPN.
958
01:10:04.815 --> 01:10:11.555
I would say the trade off, maybe there's a little bit more nuance on the trade off in terms of routing your whole network through a hosted VPN.
959
01:10:13.055 --> 01:10:13.555
Right.
960
01:10:14.700 --> 01:10:17.360
961
01:10:17.980 --> 01:10:19.600
I use my my entire,
962
01:10:20.380 --> 01:10:25.605
network goes through a hosted VPN, and the reason that I'm doing that is because I know
963
01:10:25.905 --> 01:10:28.085
that my Internet service provider
964
01:10:30.430 --> 01:10:30.930
100%
965
01:10:31.950 --> 01:10:32.450
logs
966
01:10:33.070 --> 01:10:35.650
all of my metadata, whatever that is,
967
01:10:36.110 --> 01:10:38.655
and keeps it on file for 2 years.
968
01:10:39.434 --> 01:10:41.695
So I'm trying to sort of somewhat
969
01:10:42.635 --> 01:10:45.135
obfuscate that as much as I possibly can,
970
01:10:45.915 --> 01:10:47.454
and so that is what
971
01:10:48.240 --> 01:10:49.940
why someone could potentially,
972
01:10:50.960 --> 01:10:52.100
be doing this,
973
01:10:52.480 --> 01:10:55.300
routing it through to another server who which
974
01:10:56.385 --> 01:11:08.070
975
01:11:08.610 --> 01:11:10.070
for your your ISP.
976
01:11:10.690 --> 01:11:14.950
Fortunately, on the hosted VPNs, there's many options. It's a global marketplace. Right?
977
01:11:15.275 --> 01:11:19.535
978
01:11:19.915 --> 01:11:21.855
979
01:11:22.235 --> 01:11:27.680
I I basically have a few boxes on a few, you know, clouds that I don't run,
980
01:11:28.540 --> 01:11:32.560
that I, you know, have WireGuard software running on. So what I do is,
981
01:11:33.114 --> 01:11:36.175
on my phone, I have WireGuard configured to route all the traffic
982
01:11:36.554 --> 01:11:39.054
to those servers, you know, as opposed to,
983
01:11:39.594 --> 01:11:51.135
directly through the mobile networks or whatever Wi Fi I'm connecting to, kind of out in the wild because, you know, as you guys are saying, it's it's it's it's a more explicit trust model in terms of, you know, where
984
01:11:51.514 --> 01:11:52.735
you're directing your traffic.
985
01:11:57.355 --> 01:11:57.855
986
01:12:01.000 --> 01:12:04.380
Yeah. I mean, I know both of you guys have to go. I don't wanna keep you too long.
987
01:12:05.320 --> 01:12:06.780
I appreciate your time.
988
01:12:07.425 --> 01:12:09.925
Do you wanna should we wrap up with some final thoughts,
989
01:12:10.385 --> 01:12:12.965
before we wrap this up? You want Catan, you wanna start?
990
01:12:14.600 --> 01:12:15.820
991
01:12:16.440 --> 01:12:18.540
now with the advent of Bitcoin,
992
01:12:19.080 --> 01:12:24.025
and Bitcoin particularly on our own home networks in the form of lightning network,
993
01:12:24.745 --> 01:12:27.645
it's probably wise to start upping your security
994
01:12:28.185 --> 01:12:35.460
with, some networking basic networking tips, and then going down the rabbit hole. I've provided throughout the dispatch some practical,
995
01:12:36.240 --> 01:12:39.460
tips for you to to do so. And so I think
996
01:12:40.395 --> 01:12:46.494
starting is always better than just leaving it and hoping that it's going to be secure. So
997
01:12:47.195 --> 01:12:49.054
that would be my closing remarks.
998
01:12:52.700 --> 01:12:56.640
999
01:12:57.535 --> 01:13:00.435
I mostly mostly just have Esoterica to offer.
1000
01:13:01.695 --> 01:13:09.320
But, yeah, I I I think networking is really, really worth looking into. So kind of whatever the next step for you is, I think it's worth taking because,
1001
01:13:09.780 --> 01:13:10.980
you know, at this point,
1002
01:13:11.460 --> 01:13:15.560
this is the infrastructure that that kind of runs a lot of our lives, and,
1003
01:13:16.215 --> 01:13:19.195
you're never going to not benefit from understanding
1004
01:13:19.574 --> 01:13:23.355
more about how it works and, you know, how you can preserve your own privacy.
1005
01:13:25.239 --> 01:13:27.340
1006
01:13:27.800 --> 01:13:30.860
Thank you for joining us. Thank you to the freaks who joined us.
1007
01:13:31.480 --> 01:13:34.475
I hope to have both of you on the show again soon.
1008
01:13:36.455 --> 01:13:41.355
Catan is a little bit too humble to shill it himself, but he runs a consulting service,
1009
01:13:41.655 --> 01:13:43.355
called Ministry of Nodes.
1010
01:13:44.150 --> 01:13:45.770
You can go to ministry of nodes.com.au.
1011
01:13:48.550 --> 01:13:52.810
If you have any questions, you can book some of his time, and pay him in Bitcoin.
1012
01:13:54.055 --> 01:13:55.995
I think he owns ministry of nodes.com,
1013
01:13:56.375 --> 01:13:58.795
but the redirect isn't working right now.
1014
01:14:00.190 --> 01:14:01.570
You should fix that, Catan.
1015
01:14:02.110 --> 01:14:03.730
1016
01:14:05.070 --> 01:14:06.449
1017
01:14:08.095 --> 01:14:09.075
one of the best,
1018
01:14:09.535 --> 01:14:10.915
resources in the space.
1019
01:14:11.695 --> 01:14:14.435
So thank you, Catan, for everything you do. Thank you, James.
1020
01:14:15.215 --> 01:14:17.075
And thank you, Freaks, for joining in.
1021
01:14:17.600 --> 01:14:18.820
Hopefully, I will have
1022
01:14:19.440 --> 01:14:21.780
a awesome dispatch lined up for next Tuesday,
1023
01:14:22.719 --> 01:14:33.730
so stay tuned for that. And, rabbit hole recap will be later this week instead of Thursday because we're doing it live in Dallas on Saturday. And I I believe, James, I'm gonna see you there. Right?
1024
01:14:34.690 --> 01:14:36.070
1025
01:14:36.450 --> 01:14:42.150
1026
01:14:46.745 --> 01:14:47.485
1027
01:15:01.275 --> 01:15:10.400
1028
01:15:35.855 --> 01:15:37.555
motherfuckers. I am jet. Hey.
1029
01:15:38.655 --> 01:15:40.355
You wanna hear a good joke?
1030
01:15:40.735 --> 01:15:43.360
Nobody speak. Nobody get jokes.
1031
01:17:23.700 --> 01:17:30.680
Giving a fuck away. So tell Big and Johnny and mommy to get the fuck away. Here's a gun, son. Now run, get it the cutaway.
1032
01:18:22.025 --> 01:18:24.364
1033
01:18:24.824 --> 01:18:26.605
for bit block boom this Saturday
1034
01:18:27.217 --> 01:18:27.957
and Friday
1035
01:18:28.257 --> 01:18:28.917
in Dallas.
1036
01:18:29.777 --> 01:18:30.997
Stay humble in StackSats.