Bitcoin News, Cryptocurrencies, Robinhood, Gamestop
Recorded February 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
What this episode covers
Craig Petronella of Petronella Technology Group hosts Justin Daniels, a technology M&A lawyer at Baker Donelson, for a free-flowing conversation on cybersecurity, cryptocurrency, and technology policy. Daniels describes recent ransomware incidents and explains how he persuades regulated clients, such as medical practices subject to HIPAA at the time of recording, by asking how much revenue a week of downtime would cost.
The pair discuss why startups prioritize ease of use over privacy and security, citing the Zoom litigation, and compare security habits to wearing seatbelts. Daniels argues for a national privacy law, suggests HIPAA needs a more GDPR-like overhaul, and floats safe harbors plus market incentives, including bank covenants requiring cybersecurity risk assessments on M&A loans. On crypto, he points to Treasury Department guidance at the time of recording permitting banks to custody digital currency, explains how mining pools enable a 51 percent attack, and urges investing only money one can afford to lose. The episode closes with Daniels's new FAA commercial drone pilot's license, drone privacy questions, and his critique of Robinhood's data practices during the GameStop saga.
Worth rememberingKey takeaways
- Justin Daniels says he opens conversations with medical practices by asking how much revenue they would lose if ransomware halted operations for a week or two.
“How much revenue would you lose in a day? If your business operations were interrupted to where you can't operate at all”
- Daniels argues security and privacy should become daily habits, like wearing seatbelts, rather than steps people postpone until an incident forces them to care.
“how do we get privacy and security to be like that? Just it's part of your day. It's just what you have to do.”
- Daniels argues for a national privacy law because, at the time of recording, compliance with many different state laws drives up the cost of doing business.
“The compliance with all these different state laws drives up the cost of doing business, and it it really hurts business.”
- On M&A deals, Daniels warns that cyber risk is a liability that can far exceed the purchase price if an intrusion spreads from the acquired network.
“You understand cyber risk for you is a liability that could far exceed the purchase price.”
- Daniels explains that mining pools concentrate computing power, so attackers who compromise the biggest pools could control a majority and start making the rules.
“if you were able to hack into one or two of the big pools, you'd have fifty-one percent of all the miners, and you could start making the rules.”
- Craig and Daniels advise buying cryptocurrency only with money one is willing to lose, warning that prices can swing sharply in the short term.
“you need to buy it understanding that it is money that you are willing to lose.”
- Daniels argues Robinhood profits by selling users' trading data to Wall Street firms, while Craig notes that with free technology, users are the product.
“He's a conduit to get data from the poor, so the rich can continue to become more rich.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
Bitcoin News, Cryptocurrencies, Robinhood, Gamestop - Petronella Technology Group Podcast 02-04-21 with Craig Petronella of Petronella Cybersecurity and Digital Forensics and Justin Daniels: Legal & Business Advisor Cybersecurity Subject Matter Expert Tedx and Keynote Speaker Blockchain/AI AdvisorCommercial UAS (Drone) Pilot
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. You're listening to Cybersecurity and Compliance with Craig Petronella. Visit us online at petronellatech.com.
Hey, Justin, how are you today? Hey, Craig, good afternoon. Good afternoon. Oh, do you need my video? If you want to, sure. There I am, in all my glory. How's things going?
Oh, just having a busy day, but a good one. Good, yeah, same here. I'm sure you and I could have a field day discussing Robinhood, but I won't go down that rabbit hole. Did we want to talk about Robinhood, or we want to talk about Bitcoin? We can do that too. I'm, I keep waiting for Ethereum to dip, and it just hasn't. So, so are you are you holding some Ethereum too?
Oh yeah, I have I have Bitcoin, Ethereum, and Litecoin. Nice. Yeah, I used to mine Ethereum and Litecoin and some Bitcoin too. Yeah. So I'm kind of waiting for it to drop a little bit before getting some more, but it's so volatile. Who knows? Yeah. Yeah. We'll see. It's interesting.
Oh, I did. I bought Airbnb. Oh, nice. That one I think will do well because once things get back to normal, this pent-up urge to travel is just gonna break, and I feel like there'll be a big beneficiary of that. And we'll see. Sounds good. Cool. Well, introduce yourself so we can get started. If you if you're.
Yeah, what do you want to cover today? Just have a free-flowing conversation. Anything particular? I mean, the last couple months for me and my job have been very interesting, particularly with a couple of the ransomware events I've dealt with. Some contract negotiations where the security stuff has come up. So.
Yeah, whatever. Whatever's interesting for you, let's let's just kind of talk about a little all of it. All right. So you just want me to start by introducing myself with my my short story? Yes, sir. All right. Well, Craig, thank you for having me today. My name is Justin Daniels. I am a technology.
M&A lawyer, but what I'm really passionate about is helping companies deal with cybersecurity and data protection issues in all areas of their business lifecycle. I particularly am adept at helping them identify complicated business and legal issues as they try to address business and.
Legal issues that are complicated, and help them come up with something that's practicable and implementable. And so, I've been a shareholder at the AmLaw 60 law firm Baker Donelson since what 2012. My how how fast time flies! Awesome. Well, thanks for for joining the show.
Lots to talk about today. I think we wanted to touch on some Bitcoin and some cryptocurrency, and just also what you know, what's fun, what's been what you've been working on. You mentioned ransomware, and it made me think about some of the medical folks out there. I've been.
Challenged with educating some of the folks that are not doing what they're supposed to be doing, and just curious on your thoughts on that. Maybe that could kind of start us off. But you know, when you when you talk to a regulated company, somebody such as a medical practice that's obviously mandated by HIPAA if they accept insurance, how do you best communicate to them?
The regulation and and all the stuff that they have to be doing when they haven't been doing anything or or putting the proper budget towards it. So where where I typically start is is I ask them a question: How much revenue would you lose in a day?
If your business operations were interrupted to where you can't operate at all, like, well, what do you mean, Justin? How does that happen? I was like, there's this little thing called ransomware, and they say I don't know. It might be, you know, hundred thousand could be in a million. I was like, multiply that number by seven or fourteen. If you're down for a week or two.
They're like, oh, that's a lot of money. I was like, yeah, that's what happens with ransomware, and so that's where I typically start because to me, if I'm the CEO, how does this impact me in my bottom line, either the revenue or you know cost? But I start there, and even then, it's still a difficult conversation because it's like you know everything else in life. We all know that we should eat healthy.
But until you know, we have that heart attack or we have that hiccup in our health, a lot of people think it won't happen to me. That's somebody else's problem, and it is a challenge to communicate to people that in our 21st century digital economy, we are so interconnected that if you have the Orion, you know, technology to manage your network.
And you saw how many people in the top Fortune 50 companies and the government - it becomes everybody's problem, pretty darn quick. Oh yeah, absolutely. Yeah, I like that analogy. I think that's a great one. I think that medium to larger size companies seem to take that better than smaller businesses, especially smaller startups. You know.
I think they still don't think they have the mythology around it's not going to happen to me. You know, I mean, look at Zoom. Once they had the problem and they got sued under CCPA, it's time to call in the professionals. But you know, privacy and security wasn't built into the DNA. And you know, I want to share something interesting because.
Both you and I have an affinity for investing. That's right. And so I was reading the Motley Fool newsletter because I read it all the time, and an interesting paragraph. And to me, this really encapsulates the challenge. Is they were talking about the Zoom litigation, and they're saying, you know, the Zoom litigation is out there, and.
We're going to have to see what Zoom does because if they have to put in more privacy and security controls from an investor standpoint, is that going to undermine the ease of use of the technology and cause people to want to use other technologies? And I felt like that whole paragraph to me summed it up really well. If I'm building a technology, I want it to be as easy for you to use as possible.
But there's what I now call the inconvenient necessity of dealing with privacy and security. But they undermine the efficiency and ease of use. And so, where do most businesses, especially startups, fall on that that balancing act? It's like this: with everything balanced towards ease of use, because we want customers, and figure, I will figure this privacy and security thing out later. Because if I don't have customers, and
A viable product, they're like, who cares, right? Well, I think as we go on and as we speak today, I know the Virginia legislature is now looking very seriously at passing a privacy law. I think we're going to end up with regulation because, without it, why are businesses going to stop?
What they've been doing, which is, hey, I want customers. This privacy and security thing - it interferes with the ease of the product. Yeah, and I think that's where businesses land. Their whole point is, we need to make a profit. That's what we're in business for. It's public policy to say, okay, yeah, we want you to make a profit, but where is the public good? But.
Does it does it always have to be that way though? Like for what comes to mind, and at least in my brain, is like Zoom, for example. It's not end-to-end encrypted. So if it was end-to-end encrypted, would that really have an effect on user experience? I don't know that it would, but here's where I think you have a user experience. Try not to laugh at me, but I think this is relevant for our discussion. Or laugh at me.
Now, if you recall, when Zoom had all that happen, now you needed a password. So, how many times did you get on Zoom and everyone's frustrated? Oh, I forgot the password. Ah, where's the password? And that seemed a little inconvenient. But with my security hat on, I'm saying, guys, being prepared to not only get on the call but have your password - that just has to be part of your hygiene. And so, the way I look at it.
Craig is so. If you and I were having this conversation back, I don't know, two thousand and four, did we spend any time on LinkedIn? Did we spend much time on Facebook? Was that part of our twenty-four hour day? No. But in two thousand twenty, LinkedIn is part of everyone in my day, so it's just part of my time. So my my thought of it is, is how do we then recalibrate to say, you know what?
I really do have to pay attention to security and privacy, and having that password - that's just part of my day now. When I go onto my financial site, yeah, I've got to go get my multi-factor token. That's just part of my day. We're not there yet. To me, it's very analogous to when you and I grew up. Did your parents really wear a seatbelt? Not often. Not often. But now we all wear seatbelts. Yeah.
It's it's mandated, but what took place before it? If you recall, I think it was in the '80s. Mothers Against Drunk Driving had this great campaign that raised awareness, changed people's habits. So now my kids will never know a day. Well, of course you put on your seatbelt. That's just part of what you part of your habit. And so, where I'm heading with all this is: how do we get privacy and security to be like that?
Just it's part of your day. It's just what you have to do. We're not there yet, and we're suffering the consequences for it. Yeah, I think that was well said. I think that there's also we as consumers also need to put more pressure on the security companies too, because, like you outlined with passwords, you know, humans are real poor with passwords. So maybe there's just a new technology or a new way.
To embed Zoom to the device, you know, and not require the password. You know, there's passwordless technologies out there that exist and exist well, and have also become ITAR and you know various regulation compliant. So, why not maybe put more pressure on companies like Zoom to use that kind of technology so it doesn't get in the way so much? But yeah, the reality of the situation is it does have to be.
You have to be made aware of it, and it has to be baked into our habit. So, I think the answer to your question, in my personal opinion, is: it's you and I putting pressure on our elected representatives. Try not to laugh in Congress to pass regulations that then require these companies to do things, like, for example.
I'm sure you've read about Apple, who's who's putting default privacy protections into their latest iOS. And if you want to change that, you get a GDPR-like banner in plain English saying, "Hey, if you click on this, it allows them to track and do whatever." Yep. But think of regulations where the government mandated, like they do with cars and airbags. But for the tech industry, it's, "Hey, Apple, or Hey, device maker, app maker."
You have to make all of your default settings on your app to maximize privacy, and it has to be the consumer's choice to decide that they're going to allow that. As you know, in our country, it is the opposite. Right? Because I learned a lesson the hard way was, I turned off my location finder on my phone, and that.
Stopped, you know, people. It stopped the little arrow in my in my car on, you know, Apple CarPlay. Yep. But it didn't matter because it had all the sensors on my car, and it has its own separate map display. So if you get the data on my car, you know darn well where I went. So great, I shut it off on my phone, but you could still track me through my car's data anyway. Yep.
That's to me where we have to put the pressure is on Congress, and I think you're seeing, you know, with what happened with the lawsuits last year against Google, the FTC action against Facebook, what happened surrounding the election and the Twitter accounts being suspended. You now have, for very different reason, I think, political.
Interest in having a discussion and a debate on a national law because it really needs to be national. Because all of these different state laws, you're an entrepreneur, you own your own business. The compliance with all these different state laws drives up the cost of doing business, and it it really hurts business. We need to do this, but we need to do it and apply it uniformly because data.
Is really a federal issue. It's an international issue. So, there I pontificated. Done with that. We're done. Well, I think that was well said. I think that you're right. I think that I laugh or snicker at that a little bit because it kind of.
Brings me back to the lack of security with the recent riots at the Capitol, and and the lack of you know, how did that laptop get missing? You know, physical obviously controls were missing. I don't know. I think that I agree with you. I think that there does need to be some national regulation. I think I'm surprised we we don't have our own version of GDPR nationwide yet.
I think that there is challenges. Also, I think there should be more of a checks and balance approach. You know, I don't know if you saw the recent scoring that was done with the government systems, and it was failing grade of basically how hackable they are around the CMMC.
I don't know. I'm hopeful that we have more. I I like the CMMC for the third party audit mandate, and I feel like, you know, if you want to be in business, you you don't have a choice if you're a federal defense contractor. At least in that pond, I I would hope that one day, maybe that will overtake HIPAA and require third party assessments of hospitals and healthcare.
I don't know. What do you think about that? I mean, right now, you know, a lot of the medical, obviously, they're they're saturated with COVID, and you know that's a nightmare on its own. But it, you know, the hackers are pretty much laughing in their chairs about how easy it is to get into a healthcare, a major healthcare hospital, whatever. You know, what are your thoughts around that? I think.
In what I've learned recently, when it comes to HIPAA in the wider context of having a cyber incident, HIPAA probably needs to be overhauled and probably be a little bit more GDPR-like. And what I mean by that is, if I'm a medical practice and I hire, I'll say your healthcare IT firm, and
As part of your service, you provide hosting that you do through a third party, and for whatever reason, some of my data is on that third-party server who you contracted with, and they get ransomwared. So, if they get ransomwared under HIPAA now, who has potentially the breach notification obligation? It's me, the medical provider.
Right, and the OCR might investigate the person who got hit and me because it's my data. But it seems to me anybody who has control or custody over data probably should have some kind of reporting obligation. But that's not the way that HIPAA works. It's not the way a business associate agreement works. So I wonder if putting the onus more on all of the businesses.
How do we do that? Because here's the thing, and I think it's true. If you get hacked, are you the victim of a crime? Yes. But how are you portrayed in the media, or how is that perceived by your customers? They think what? They don't think you're a victim. They think what did you not do? Negligence.
They think you're negligent. You need to be legally held responsible, right? And so, to me, you have a disconnect there on how can we work together if we are, when something bad happens, pointing the finger at whoever because we all know the lawyers get to ride, run in, particularly class action counsel. So, I think in order for some of this to work, we need to kind of have a debate and say.
Are there certain safe harbors where, if you do work together, if you do certain right things, and you still get hit, maybe like tort reform, there's going to be some limitation of liability. Right. And then obviously the tort the tort lawyers are going to go nuts because they're going to say no. But if we're going to hold people to unlimited liability, I'm not so sure that helps you because you're going to think I'm going to take the risk anyway. If something happens, I'm done.
Right, and so I think there has to be some of this thoughtful dialogue around what are the public policies we're trying to influence, and know that there won't be a good, you know, solution. But what I don't want to have happen is we have some kind of cybersecurity nine eleven, and we have a knee jerk law like the Patriot Act. Say you what you want for the Europeans, but they passed GDPR, and nobody.
You know, it wasn't influenced by some dramatic event, and that's a better way to pass legislation. You see how it works, doesn't work. You can tweak it, but when you pass stuff after having some traumatic event like 9/11, you don't pass good laws. You're stuck in the emotion, and you don't think about the second or third order consequences, and it ends up.
Many times, doing more damage than good in the long term. Well, I I think that that's true. I I also think that um, you know, like the credit score. You know, you everybody's got a credit score, right? The better your credit score, the the lower your rates for borrowing money are. I think we almost need something like that in the cyber world where.
You know, if you should be rewarded for doing your risk assessments and getting all your stuff together, and get maybe cheaper cyber insurance because you're getting the audits done and and all that fun stuff. So maybe I don't know, maybe something like that could be a good thing too. Or you could get most favored nation pricing because of your cyber score, or you don't get the deal.
It's funny you bring this up because you know they have this exact kind of thing in China, but for very different reason. Oh, interesting! The communist government gives people a score, but it's based on loyalty to the government. Have you made any statements? Have you paid your bills? And then you can have like a score, and that might allow you. If your score is not high enough, you can't leave the country. You can't get credit.
See the thing people don't appreciate that I'm learning with some of the smart city work that I do is technology really enables authoritarian type of regimes to watch the populace, and so that's another interesting realm that we get into with.
Cyber and privacy, but what you're really talking about, Craig, is you're saying, "Hey, Justin, I appreciate what you're saying with all this regulation. Which, yeah, I get it. But what are some market-based solutions? Because that's really what you just mentioned. I've had multiple conversations with banks, and I've asked them, 'Why don't you put a covenant requiring a cybersecurity risk assessment of the target when you're going to loan or syndicate a loan on an M and A deal?'"
That way, and I said because if you don't do it, and the and the you have an incident, and the value the deal gets impaired, and you don't get paid back, you're not getting paid back. And all you have to do is put it in the agreement and require them to do it to get the loan. And the banks are just, uh huh. They listen in one ear, out the other, because I think their view is, well, Justin.
If that costs fifty thousand dollars more, and I make the borrower pay for that, then they're just going to go down the street to another bank. Right. But what's going to happen is one of them is going to get hit; their loan value is going to be impaired. They're going to stick it in, and then all the other banks are going to follow. It's like the first bank who charged for ATM fees; they all had an uproar, and a week later, they all did the same thing.
Right, but it's like I can sit here and you can play this episode back five years from now when the banks do it, and it's like, well, why didn't they do this sooner? Right, and that's to me the challenge with the market-based solutions because for smaller companies, as you talked about earlier in our conversation, they usually come at cyber one of two ways: either they want to do business with a big company who has a compliance program that says, hey.
Here's our security addendum. You need to do all this, or we have no business, right? Or they get hacked and they are reborn if they survive it. But it's usually for them. Oh, I want to do business with Home Depot, and this is the security addendum. Oh, yeah, I need to call Craig and Justin now because oh, I have to care about this because I don't meet any of these requirements.
That's typically how I see the smaller companies start to care about security. It's usually not voluntarily. It's because something's happened that has an impact to the revenue of the business that gets them to say, "Yeah, I need to care." It's almost like when we talked about the seatbelts; they have to get into the car accident to realize, "Yeah, I should wear my seatbelt." But what if you don't survive the car accident, or you become...
Permanently injured is that a risk you want to take? Yeah, that's why I think cybersecurity is analogous to the seatbelt. It's one of my favorite analogies. No, it's great to relate it to. And and to your point on the, we call them VSQs or Vendor Security Questioners.
They're more commonplace now than ever, especially with cybersecurity insurance, and I think for a good reason. You know, those if you want cybersecurity insurance, you're typically hit with some type of questionnaire asking about when your risk assessment was done last, and what policies and procedures do you have, and how do you protect your organization from ransomware, and you know, more of that fun stuff.
But even on the M and A transactions that I've done, a lot of companies don't want to do the cybersecurity due diligence because they don't want it to upset the cadence of the deal getting it done. And so, a lot of times, they they don't do it, and then they integrate the company, and then the problem metastasizes onto their network.
So it becomes a twenty million dollar problem from a four million dollar acquisition, which is why when I'm on M and A deals, I'm like, "You understand cyber risk for you is a liability that could far exceed the purchase price." And they're like, "What do you mean by that?" And then I explain, "Well, if you integrate their network and the intrusion hops from their network to yours, it's now become your problem." Problem. Right.
And then they kind of look at me, much like the banks did. Oh, I see your point. And then they don't do anything. That's what I was just going to say. Then they don't do anything. Right. So anyway, so moving on is a good segue to Bitcoin now. All right. So let's talk about the Bitcoin. So cryptocurrency. You know, you brought up China before. China has been mining for a really long time. They have cheap.
Power. What are your thoughts around that and and the fifty one percent threat? Oh, we're going to talk about the fifty one percent attack. So, I think digital currency is going to be in the mainstream, and I believe that because the most important development last year was guidance from the United States Treasury Department that is going to permit.
Traditional banks to render custodial and other services for digital currency. So we'll have to get the regulations and whatnot. But it essentially is the Treasury Department greenlighting, you know, the Wells Fargos and PNCs of the world to provide services relating to cryptocurrency, which is huge. Yeah, I didn't realize until I was in the this.
Blockchain business that, if you can't get a bank account, what that means to your ability to do business. We take it for granted, and we don't appreciate that the banks have a real influence on your ability to do business because we all take a bank account for granted. But not in the blockchain industry, where there's very few banks who will bank you if you're a crypto company.
As it pertains to the fifty-one percent attack, I have a good story for you. So, I had a client who created one of the largest crypto mining facilities in the U.S. It's how I got started in my my education in this industry. He was very proud of, you know, how he had a good wallet, how he stored the coin that he mined, and I said.
Talk to me for a moment about your miners, because, as you know, and for our audience, is the whole thing about cryptocurrency mining is effectively what you've done is you've replaced the bank with a computer algorithm that miners or other people with computing power solve to verify the validity of a transaction, say between me and Craig.
And the whole point was, is the computing power that does all this is just decentralized all around the world. So what happens is, well, when the price shot up to twenty thousand and was going up, Craig, me, my brother, and everyone else wants to get into the mining business. And so what happens? All of these people get in, and so what happens is.
Now you and I can't mine so effectively anymore. So what do we do? Hey, Craig, maybe if we pool our resources, we'd have a better chance of solving the algorithm and getting the reward, which is the Bitcoin. So what ends up happening is you go from a decentralized to a centralized environment. You're like, "All right, Justin, I'm not a central bank. What do you mean?"
You put miners into pools, and so what happens is, is if you were able to hack into one or two of the big pools, you'd have fifty-one percent of all the miners, and you could start making the rules. And so, back to my client, I was like, "So, I'm curious, how do you protect your miners from, you know, because you can switch your miners from pool to pool."
And I said, "What's protecting?" He's like, "Oh, I have this simple password. I hadn't thought about that at all." And I said, "Well, if the threat actor can switch your miners to mine for him in his own pool, then the Bitcoin isn't ever going to hit this wallet that you have that protects it so well, because the the threat actor is going to come in before it ever gets there." And there was a pregnant silence.
And I love to tell the story because it's good for two reasons. One, you know, the blockchain or the Bitcoin starts out with this assumption about the economics of decentralizing the people who verify the transactions. But then it evolves so that people, if they want to get a reward, they have to pool their resources, centralizing it, and then it makes the utility of.
What we call the 51% cyber attack, a lot more easy to carry out, and people don't even realize while they're protecting their hard wallets that if they don't protect their machines from being hacked to go mine for some other pool, that that's their common point of failure. Yep. Well said.
Yes, that's part of my presentation next next week. I'll be at Duquesne University, where I went to school, and I'm presenting to an MBA class on innovation versus privacy and security, which is a lot of what we're talking about here today. Absolutely, that's awesome. Yeah, well, good points. What I used to do when I was mining, I'm not mining anymore, but when I was mining.
Was I would monitor the activity, but you're absolutely well said. I mean, people don't think about that, so yeah, it's it's craziness. So you were talking about Ethereum a little bit. What are your thoughts around Ethereum and smart contracts? Well.
As I've been reading, I haven't done this yet, but I've been reading a lot about it. Is a lot of the rage is what they call DeFi, decentralized finance. So, think about, I don't know, maybe being able to finance a vehicle, doing it with a set of smart contracts over a blockchain where it's recorded. And so, the key is Ethereum because you can build, you can write on it, you can put smart contracts on it.
And I think it bears watching. You're seeing a real run up in the in the price of Ethereum because you know a lot of people are talking about decentralized finance, and I think you're going to continue to see that because I think one of the big lessons from the pandemic, amongst many, is: do you really need cash? I can't remember the last time I paid cash for anything. Yep.
But the challenge with all that that I just don't think you know a lot of people think about is is back when we were just what I call an analog society if something broke down we could fix it but now that we are pretty much solely relying on digital technology if it gets encrypted if it's ransomwared if if someone's able I wrote about this the other day.
GPS is beyond easy to hack. So think about being a ship and thinking that you're in international waters when, in reality, you've slipped into Iranian waters and don't realize it. As just an example, or a plane that's flying. What is your alternative to, you know, what's your backup plan if something happens there? Right. And we just.
Most companies they don't have one, and that to me is what's interesting about the more that we use decentralized finance, we're using Bitcoin, we're using all this digital stuff for financial transactions. Because you take that down, what is the alternative, or you interrupt it, and you don't hear people talk about that too much. And I hate to say it, but we're probably going to find out.
How we feel about that when that actually happens, or the grid goes down for a week. Right. And so, I find all of this fascinating. And that horse isn't coming back in the door. I mean, if we have a minute, I'd love to talk about a topic that's near and dear to my heart right now, which is unmanned aircraft systems or drones, because they're coming too, and they have their own whole whole host of issues. But my point to you is.
I think we're going to have smart contracts. All this digital stuff is coming because that horse left the barn. My biggest concern is how can we learn from what we've seen with the consequences of social media, where we prized the business model or let the business model, you know, you know, fostered the business model, and then look what we have going on where.
People think that there's some cabal of a deep state, or you know, some crazy stuff. Social media, not you know, thinking about privacy and what what we're saying, has had that direct consequence. So, what can we learn from that to say, okay, we want to do this decentralized finance, but how do we go about this in a way that addresses cybersecurity and privacy, so we're in more balance?
Because you can, if that's what happens with social media, what kind of mischief do you think can happen if it happens in the finance industry, which is the lifeblood and you know an essential component of our critical infrastructure? Do you think that the bank's role will change with crypto? Because I mean, obviously, you see how poor most humans are with security and cybersecurity.
And you see the headlines around how many people lost their Bitcoin or forgot their passwords. You know, it's millions and millions of dollars as it goes higher and higher. Do you see some kind of role shift or new companies popping up around helping folks with that? Obviously, it's supposed to be decentralized, and that's the whole point of you know elimination of the middleman, right? But
But the fact of the matter is, there's probably a large percentage of the population that wants to buy cryptocurrency, but doesn't even know where to start from a cybersecurity hygiene perspective, and may want to pay a bank or somebody to help them manage that. What are your thoughts around that? When I realized that cryptocurrency was here to stay, was when I was having lunch in New York at Consensus, which is the big blockchain conference. Back when we could actually.
Sit down and have lunch with strangers. Yes, I didn't realize how how much of a premium that was. I just took it for granted. And I was listening to somebody from Venezuela tell me the story about how they got their money out of Venezuela because there was a lot of political uncertainty and all this stuff. And apparently, they were at odds with the government because of their business interests. And the only way they could get their money out and preserve it was by doing what.
Converting it into cryptocurrency and getting it out because cryptocurrency has no jurisdiction. What I think will be interesting to see from what you're saying, Craig, is how much will the banks impact the decentralized and anonymous nature of Bitcoin. Right. Meaning, you're now going to add this layer of regulation, and maybe some is necessary.
So, where are we sliding back from complete anonymity, which can be good in some instances, but not others, and bringing it back this way? Because when you get the traditional banks and regulation involved, that's part of what it's designed to do. So, if this is no regulation and this is under lock and key, where are we going to go in this continuum? Because bringing them into play.
Is bringing the regulators into play, and I think you're going to start to see that happen. Because another way to look at it is, is, you know, is someone going to provide like escrow services, but they're escrowing the digital key, so you know that you have it somewhere, and then they're the ones who have the the digital Fort Knox of protection. What happens if they get hacked? Right.
So the question is, like FDIC insurance equivalent, you could, or you know, Craig may have his passwords or you know, hard wallet written down at home in his safety, you know, in his safe at his house, and that's what I mean. That's an analog solution. It sounds like a pretty silly solution, but in a way, if you write it down and you keep it in your safe.
And you're the only with the combo. That is an analog way to protect. The challenge will be is when you change passwords and stuff. People, oh, I have to go update my piece of paper in my safe. But that's an analog solution to a digital problem. But I'll be honest. I think if we could do just some of the simple blocking and tackling with MFA and other stuff.
It just never ceases to amaze me with some of the things that companies have done. Oh, they left a port open. They acquired three companies and they got these extra ports they didn't even know about. The ways that threat actors get in, as you know, is just - it's kind of - it's like absurd in a way. And so, if we could just do better some of those things, we could probably do about eighty to ninety percent better just there. But when you get into the sophistication, nation states like what they did with solar winds.
You know, that's you know, you and I are talking about the high school level things to do. That's the NFL, and everything I've read is that was a very sophisticated attack. And you are going to have that stuff. Yeah, I agree. I think that we need to be more offensive too in our country. On, I mean, because look at North Korea and China and how.
They're just constantly training these cyber warriors, you know, to do these crimes like that. I don't know how much effort we're making in that, where you know, where we score, but it seems like in some aspects we're behind. And I agree with you. I think that you know, even if we can move the needle a little bit forward with some of the basics, like you said, MFA, you know, hardware tokens, maybe using analog.
Ways to better secure things. It's only going to help everybody, but you know, it goes back to the more layers, the better. Yeah, I mean, my standard fare is defense and depth. I always like to use my analogy to the scene from Helm's Deep in Lord of the Rings. So, if you remember Helm's Deep, when the orcs are showing up to take care of Aragorn and and the rest of the crew.
Well, Helm's Deep had a deep moat. It had, you know, a huge wall. It had, you know, all the soldiers inside. It had that citadel at the top. Yep. And then, last but not least, they had a relief army. So the orcs had to break through every single one of those defenses to win. And they broke through a lot, but not all of them. And to me, what I'm teaching.
I make defense in depth for cybersecurity the same thing with MFA, network segmentation, least privilege, all those things all are your defensive in depth so that you can help you know figure out what you need to protect, protect it, detect it, and then respond to it. So to me, it's the cyber equivalent of the Battle of Helms Deep.
No, that's awesome. That's a great analogy. So, so what do you think about going back to Bitcoin and current pricing? More regulation? Do you think it's you know? Do some of the spectators are saying a hundred thousand this year, four hundred thousand? You know, the numbers are all over the map. Do you think that regulation is going to dampen the price, or what are your thoughts around all that?
I think what will happen is, because Wall Street is always looking for new ways to make money in ways that the Main Street or the dumb money, as they like to call it, GameStop. Oh, we could talk about that too. Actually.
Better part of talking about Robinhood is whether they sold the transaction data, which is a privacy issue. And if that's the case, which seems likely, the FTC just needs to pound them. But to this question, I think regulation will probably help and has helped the price of Bitcoin because it shows that it's being accepted as a mainstream store of value; that it's not this fringe thing.
So, I expect to continue to see cryptocurrency fluctuate. And for those of us out there who says, "Oh, I'm just going to buy some," you need to buy it understanding that it is money that you are willing to lose. I mean, I had - I don't know - a year and a half where I was down 80, and then it finally came back to where I'm up.
But I kind of invested with the understanding that this was money that I could live without if it went to zero. This is not something that you want to speculate in. If it's money that you need for school, living expenses, please, audience, do not do that. It is not a smart thing to do with your money. But if you want to, you have some money that's available that you want to put into this, and you can let it ride for a few years.
I think you'll be rewarded. I only stick to the three that I know pretty well, which is Bitcoin, Ethereum, and Litecoin. There must be a hundred of them. Ripple was up for a while, all over the place, but that's that's what I've done. Because one thing I don't know, Craig, is you know, Bitcoin. They only have twenty three million. That's it. Yeah. Well, who's to say they can't go back and, you know.
Change the software. Say, "Ah, we'll we'll put some more in circulation and fork it." Uh huh. Yeah, right. So, well, to me, it would be different than a fork. In other words, is the software so immutable that it's twenty three million bitcoins and we're done? If you fork it, what that is is you're changing a feature so that it goes. It's not on the same chain anymore as Bitcoin. It forks off of it, and so.
I don't think so, but obviously, if it's like gold, gold derives its value from its scarcity. Bitcoin, to a degree, derives its value because of its scarcity. Right. Yeah. Well, I think that was a good point too. I think for the folks that are listening, you should definitely only invest what you could afford to absolutely lose.
And I think that the liquidity factor is also a big one too. Don't don't put a bunch of money in Bitcoin, and then if you need it next week, you know it might not be the same amount as it was when you bought it. It might have dropped significantly, or it might have went up significantly. But the volatility spikes in the at least in the short term.
Could be big swings in either direction, so if you need it to be for you know kind of flat, you know, Bitcoin in the short term is probably not the best place to put it. But longer term, I do agree. I think that longer term, maybe for your kids' college or something like that, you know, five years or whatever you consider longer term, could be a good thing.
Yes, it could be my vacation home in Colorado. Money, who knows? But that's right. It bears it bears watching, particularly when you start talking about decentralized finance. So we'll have to see. That's right. I think the the bottom line, though, is that everyone should add some.
Amount to their portfolio, whatever they're comfortable with. It could be a thousand bucks, it could be five hundred dollars or less, it could be ten thousand dollars. But just go into it knowing that if you lose it, just like playing a lotto scratch off, it's gone. But if you if you do good password hygiene and you enable the multi factor and you store it.
Properly and keep checking on it long term as long as you can. I think that you probably will be rewarded in the in the vast long term of things. Yeah. Moving on to Ripple, you touched on Ripple a little bit. Obviously, Ripple's under the microscope, heavy regulation. It it dived or dove. What's the what's your take on Ripple, real quick? I like the idea behind it. Have you ever?
You know, like I refinance my house, and you know, go to the bank. Yeah, that's gonna be forty dollars to send a wire. I am like, come on, forty bucks - that's that's a lot. And Ripple allows you to do that in a way where you are not paying forty bucks. So, disrupter - it is absolutely a disruptor. So, I think from that standpoint, it's interesting.
I can't say I follow it enough to be able to talk with any level of expertise because I limit what I do to just those three that I mentioned. Yep. And you know, I have some other interests, which I think the last one we can touch on is: I spent my last four months is I got my FAA certified.
Commercial drone pilot's license. Yeah, talk to us about that. So that. So why did you do that? Was it for fun or or for business? Or both? Both. So my wife Jody, who you've met, I've always been fascinated with aviation and wanted to fly. But I have a wife and two children, and my wife's like, "Yeah, no, I don't think I want you flying Cessnas or whatnot." So I said, "Well, what if I keep my feet on the ground?"
So that's where we reach the marital compromise, and I met someone on LinkedIn and took a class where you know we do just what you and I are doing, and I I did it because one I thought it would be fun, and I've enjoyed it. But the other part was is the use of drones is is going to explode in this country. There's so many uses for it.
Whatever happened with Amazon? Amazon was really pushing drone delivery. Then what happened with that? So, as I've learned, we have some interesting issues we need to navigate. So, you know, if Amazon wants to deliver to your house via a drone, well, what if to get to your house it has to fly over my house or something else? It's not a public right of way.
Well, you don't have the air rights over my house, and don't have the ability to consent to them flying over my house. So, I didn't know this, but common law, you were supposed to own all the rights up to heaven and down to hell of your house. But the FAA takes the position that they are the ones who have the exclusive jurisdiction over navigable airspace.
So you can dig down, but you can't go up. Well, the story gets a little better. So in 1946, there was a a guy who, I guess, he had his farm with a chicken coop near an air force base, and it was near the, the, you know, the runway. So the propeller, propeller, or whatever planes, they make a lot of noise, and his chickens.
Would get upset, and a few of them flew into a wall and got hurt. And that's his property, and so he sued. And it ended up going to the Supreme Court. The Supreme Court decided that he had the use of enough of the airspace above his house to build or do his business. And in that case, I think they said it was 81 feet.
So now it sets up the issue of if you're going to have drones fly, how do you resolve who who regulates that airspace above people's houses? Eighty-one feet above the house, or eighty-one feet from ground level? Eighty-one feet from ground level in this case, and so the issue becomes, you know, how high do you want to be able to fly?
Drones and who regulates it? I expect if this goes up to the Supreme Court, they're not going to ruin this industry over that. They're going to say you own, you know, you can navigate up to I don't know, or you can build up to whatever, however many space. Because remember, there's zoning requirements, and then above that, that's where you can fly drones. But the reason I find all this so fascinating is I'm about to embark on a project for a client where we're going to deploy a pilot drone program. Is
Craig, tell me how would you would feel, and if you remember back in the nineteen sixties, you could put cameras on YouTube, YouTube spy planes that from a hundred thousand feet they could get a license plate or see the top of a Russian missile when they were flying over. That was the sixties. Yeah. So only you can imagine what the NSA has. Right. What do you think about cameras today that you can put on a drone, the commercially grade ones?
Where I could stand, maybe a quarter of a mile from your house, with the drone up in the air, and I can video your backyard where you and your family are out there playing, and I can get amazing quality video. How do you feel about that? Violated. Yes, that's how I feel. That would be one word. I'm sure you and I could come up with a lot more colorful metaphors for that.
And so the question becomes, and I'm going to use drones as an example because this is my big mantra: is you can have a drone come. I've seen this. You can have a drone come out of a fire truck with a huge nozzle on it, and the the firefighter, instead of going up the ladder and getting right near the fire, he deploys the drone and puts it right where the puts retardant right where it needs to go to help put out the fire.
Or during the season, I know the Atlanta Falcons, the football team, hired a drone company to disinfect the stadium so people could come every week. So those are clearly very helpful and efficient uses. But then, how do we deal with privacy? Because we felt violated in that example, or security? Because hacking a lot of these drones, it depends on Wi-Fi. The connection between it could be your phone or the or the.
The controller and the drone, and having flyaways where the drone just flies wherever, and these things are very hard to pick up on radar. They're very small. So, again, back to my mantra of is I want to be involved here. How can I help deploy this in a way that is beneficial to the community, but has the right balance between the benefit and managing privacy and security.
That's on another topic. I have a drone, actually, project that I worked on for my certification from MIT that we can talk about on another podcast. We'll have to do that because this is just a recent development. So I was very proud to pass. My kids baked me a little cake. That's awesome. So I was, you know, was it hard? Exciting. Um.
I wouldn't say it was difficult. You certainly had to study, and one of the things I learned was the FAA does a pretty good job of ensuring that we have safe airways. I mean, obviously there have been plane crashes, but statistically, air travel is the safest. And after learning all that the FAA does, they take it very seriously, and.
Just learning a lot about how weather and other factors impact performance of aircraft, and what you have to be aware of. It was no joke, but I learned a lot, and it was easy because I was doing it for fun. Yeah, it was. As we get older, and you do stuff because you want to learn, it's not really. I mean, it is studying, but you're enjoying it as opposed to some of the classes we took that you know.
I'd rather be stuck out in a blizzard than to sit and take that class. So, now I've flown like non-commercial. I don't have my drone pilot license. It's kind of like a nice-to-have or wish list item one day for me. But I'm assuming that that commercial drone that you had to probably fly for the test. I'm assuming there was a written and a flying portion.
It's just a written test. Oh wow! Okay, I still have some work to do to get my flying chops. I mean, I've learned I can fly, but flying over water, flying at fairly high altitude because you can only fly 400 feet above ground. But you can fly 400 feet above ground around the building. So let's say the building's 800 feet high, I can fly up to 1,200 feet.
Because it's above that building, and again, if you get up that high in these crafts and you don't understand how weather works with the wind and whatnot, and some of those are big and heavy, like those commercial. I mean, if that thing falls out of the sky, fifteen hundred feet up, oh yeah, you can hurt somebody. Yeah, and then you have to get approvals if you want to fly in certain classes of airspace, and then if you want to fly over people, you have to have waivers for that. So.
It's no joke. It's just, you know, I'm you know you're supposed to register your drone. Well, if someone wants to do something bad, they just won't register their drone. So, one of the things that's coming out is there's new. All drones are going to be required to emit a signal so that everyone in the airspace knows where the drones are.
And so there's been a lot of debate about it because people are like, "That's an invasion of my privacy." So the way the FAA is working it is so that it will admit a signal, so you know where the drone is and the controller, but you won't know the controller is Craig. Anonymized. And then it's a database that will not be made public.
But that way, when you're flying, you'll know. Oh, there's a drone craft. There's a controller here and there because there's like over, I think, 200,000 registered drones, and the numbers only increasing. Right. And I don't want to scare people. We won't talk about the military implications, but suffice to say, picking up a drone on radar is tough. They're small. Yeah. And they fly pretty fast.
So I have my trainer one, and I one of my gifts to myself for passing was I got a a DJI like commercial grade model. Nice. So I haven't flown it yet, but anyway. So that's why that's why I did the drones and talk about it because again, I really want to help do something where we really find a better balance between the benefit of the technology and privacy and security because I think it's clear to me.
Social media, we got it wrong, and we're suffering some significant consequences as a result. Oh, agreed. Yeah, I try to not use social. The only thing I use is LinkedIn. But well, this has been awesome. Well, let's talk just a little bit about Robinhood, if you don't mind. Yeah, sure. My best friend wants to talk to me about it, so I send him some articles to arm him, but.
I'm happy to talk about it. Yeah, let's talk about that, and maybe the the how it kind of played a factor potentially in the GameStop issue, and you know, just the the impact of retail investors and how things are different now. Okay, so I think the story of of Robin Hunt in a nutshell was.
A bunch of hedge funds, the you know elite of Wall Street, made a bet that GameStop, because they're heavily reliant on their retail locations, was going to continue to sink and their stock price would go down. So they basically made a bet in the market that the stock would go down, and that's how they would make money - shorting. So apparently, yeah, shorting.
The Big Short. That was a great book. Short, good movie too. So, as I understand it, there was a group on Reddit that, you know, they they all love gaming and they're passionate about it. Wall Street Bets. Wall Street Bets. Thank you. And so they got wind of this and said, you know what, let's stick it to them, and we're just going to go on Robin Hood and other, you know.
I guess you can go to Charles Schwab and Fidelity, pick your pick your flavor, and you know we're going to buy shares. Because when you buy shares, what happens? The price goes up, and the people on the other side of the trade take a bath because yeah, because they were betting the short it that it was going to go down. People bought the share, mass droves of retail investors bought shares and kept driving the price up in reverse of what they were betting the Wall Street.
So, what I found delicious about it was, is here are these people, these hedge funds, complaining about other people engaging in the exact same tactics. So, once it was on the hedge fund, they were crying poverty, but when they were doing it to other people, that was just the way of the world. Right. And so, I felt like that was, yeah, they were getting their comeuppance, but.
Let's talk about Robin Hood a little bit. Is I laugh because you know Robin Hood he steals from the rich to give to the poor. So that was the idea behind this site because basically you could go there, not open a big account, no, no trading costs. And that, to me, as soon as I heard that, I was thinking, so how do they make their money? Yes, let's talk about that.
This is why I wrote wrote a post the other day where I stood it on its head. So, how do they make their money? So let's talk a little bit about what hyper trading is. So Michael Lewis, if you've read any of his books, he's a phenomenal author. The you know the Blind Side, other one. So he wrote a book. So after the crash in '08, Wall Street's looking for its next gig.
And what they did is they found what's called hyper trading, where they use very fast computer connections and networks to make trades faster than regular traders like you and me. And so, how do you? They basically apply an algorithm, AI, in a manner of speaking. What do you need for AI to work? Well, you need a lot of trade volume to predict what people are going to trade. Data.
Lots of data. Lots of data, and so a lot of these big Wall Street firms invested and created this Robinhood because what is Robinhood getting when Craig and Justin and the rest of beat Wall Street put their trades? They're getting data, and so the way that Robinhood would make their money because hey, Craig comes up.
Come to Robinhood because you don't have to trade. You you pay zero for trades. You just trade. Yeah, to listeners, anything free comes at some price. No, to well, anything free technology wise means you're the product. You're not the customer. You're the product. In this case, they would take and sell that data and get paid for the sale of that data by the big Wall Street firms.
So I look at it as the way Robinhood makes money is they actually take the data from the Main Street and they give it to Wall Street. The act exact opposite of what the idea of so they're like software companies now, or or is it a AI based software now that kind of gives them the edge based on all this data? Basically, basically what happens is is.
They can execute trades so fast that they, I think, they're able to predict what you and I are going to buy, and they get in front of us and they buy a position. So they get in lower, and then we all buy, and the price goes up. But because they got in first, they got in at a lower price because they were able to predict what people were going to do because they got all of this data and they put AI on it.
And so that's why, if that is indeed the case, which it sounds like it is, the FTC just needs to take them to the woodshed. Because who are the people who built Robinhood, Wall Street? Because they wanted to get data. Wow! So that's to me when when you it's funny because the story when it first came out was one way, but then when you dug into it.
You started to see. Robin Hood isn't, you know, isn't taking from the rich and giving to the poor. He's a conduit to get data from the poor, so the rich can continue to become more rich. Pretty much. Wow. Well, this has been awesome. I mean, I could talk to you for hours on this stuff, and I'm sure you have to do other things too. But.
Yeah, thank you so much. I mean, and we went down a lot of rabbit holes, but I think they were good ones. Yeah, you know, splice up as you need to. We covered a lot of ground, so you know, you can wind me up, and I'll talk about this stuff. I like you; I'm passionate about it, so it makes for usually most more often than not, it's a good day at work because I'm enjoying what I'm doing. That's right. Yeah, yeah, absolutely. Yeah, I don't think actually I'm going to cut it up. I think I'm just going to.
Give it raw footage because I think it was good stuff. Honestly, I think that we went on some good rants and topics and touched on some good things. And I definitely would like to have you back and talk more. There's always something interesting and fun happening, especially nowadays. So yeah, I think, like you said, keep it fun so it doesn't feel like work.
That is a key. That's what I am trying to teach my kids. Well, thank you again. Okay. Well, thanks for your time. Absolutely. Thanks for listening to yet another episode of Cyber Security and Compliance with Craig Petronella. Listen to all of our podcasts on Apple, Google, and Spotify. Visit us online at petronellatech dot com to book a meeting with Craig about your business.
That's a wrap on this episode of Encrypted Ambition. Subscribe wherever you listen, and if today's guest inspired you, leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance, head to petronella.tech.com. Thanks for listening, and remember, the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.