851: Ryan Montgomery | The Hacker Who Hunts Child Predators Part One

27 Jun 2023 · 1 h 8 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Episode Notes: The Jordan Harbinger Show - Episode 851: Ryan Montgomery | The Hacker Who Hunts Child Predators Part One

Episode Overview In this episode of The Jordan Harbinger Show, Jordan interviews Ryan Montgomery, an ethical hacker and cybersecurity specialist focused on exposing online predators. This part of the conversation dives deep into the world of hacking, the backgrounds of hackers, and the ethical implications of their work.

Key Topics Discussed

Introduction to Ryan Montgomery

  • Background: Ryan is a professional cybersecurity specialist and ethical hacker, known for his work in exposing online predators.
  • Career: Founder of Pentester, a cybersecurity firm.

What is Ethical Hacking?

  • Definition: Ethical hackers are those who find and fix vulnerabilities in systems, often hired by companies to help protect their data.
  • Types of Hackers:
  • Black Hat: Criminal hackers who exploit vulnerabilities for personal gain.
  • White Hat: Ethical hackers who operate within legal boundaries to improve security.
  • Gray Hat: Hackers who may find vulnerabilities without permission but don't exploit them for financial gain.

The Hacker Mindset

  • Hacker Mentality: Ryan emphasizes that hacking is not just about technical skills; it's about a mindset of questioning systems and finding creative solutions.
  • Social Engineering: The concept of convincing others to give up sensitive information as a significant aspect of hacking.

Financial Aspects of Hacking

  • Ethical Hacking vs. Unethical Hacking: Discussion on the financial viability of ethical hacking and how it can sometimes be more profitable than illegal activities.

Tools and Techniques

  • Flipper Zero: A multifunctional hacking tool capable of various exploits including RFID and NFC attacks.
  • Use Cases: Demonstrates how everyday devices can be hacked, emphasizing vulnerabilities in seemingly secure systems.

The Dark Web

  • Definition: Explanation of the dark web as a part of the internet that requires specific software (like Tor) for access, often used for both legitimate anonymity and illegal activities.
  • Risks: Discussion on the dangers and ethical implications of the dark web, particularly regarding illegal marketplaces.

Cybersecurity and Society

  • Social Issues: Ryan discusses the broader societal impacts of hacking, including its role in the fight against child predators online.
  • Mental Health and Addiction: Touches on Ryan's background and experiences related to addiction, paralleling his work in rehabilitation services.

Real-world Applications and Impact

  • Hacking for Good: Ryan's efforts to use his skills for positive change, such as his work uncovering child exploitation.
  • Educational Aspects: Encourages listeners to think critically about cybersecurity and the motivations behind various hacking activities.

Key Takeaways

  • Ethical hacking requires a unique mindset and understanding of both technology and human behavior.
  • The distinction between types of hackers is crucial in understanding the cybersecurity landscape.
  • Tools like the Flipper Zero illustrate how accessible hacking tools can be, raising concerns over personal and public safety.
  • The dark web is a complex environment with both good and bad actors, highlighting the need for ethical considerations in online behavior.

Conclusion In this episode, Ryan Montgomery shares his journey from a troubled youth to a successful ethical hacker, illustrating the complexities and ethical dilemmas within the hacking world. The conversation serves as a reminder of the importance of cybersecurity in today's digital age and the potential for hackers to make a positive impact.

---

For more detailed show notes, resources, and to listen to the episode, visit [jordanharbinger.com/851](https://jordanharbinger.com/851).

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:28This episode is sponsored in part by 1-800-CONTACTS. customer service and perks like free returns, free exchanges, even free torn lens replacement. Jen loves their Express exam, which lets you renew your prescription online in under 10 minutes. It's a vision exam, not a full eye exam, but it gives you a doctor-issued prescription if you're seeing clearly with your current lenses, no waiting rooms, no dilation drops, remember those things? And with their best price guarantee, if you find your contacts cheaper somewhere else, they'll beat it. Getting contacts doesn't have to be a hassle. Let 1-800-CONTACTS get you the lenses you need right now.

0:56Order online at 1-800-CONTACTS.com or download the free 1-800-CONTACTS app today. Coming up next on the Jordan Harbinger Show. And the 90 % of the people listening to this right now that are using an exclamation point as the symbol that was required in their password, you know, that's something that hackers think of. You know, it's the first symbol on your keyboard with a digit, with a number.

1:23Welcome to the show. I'm Jordan Harbinger. On the Jordan Harbinger Show, we decode the stories, secrets, and skills of the world's most fascinating people and turn their wisdom into practical advice that you can use to impact your own life and those around you. Our mission is to help you become a better informed, more critical thinker through long-form conversations with a variety of amazing folks, from spies to CEOs, athletes, authors, thinkers, and performers, even the occasional former cult member, arms dealer, rocket scientist, or Russian chess grandmaster. And if you're new to the show or you want to tell your friends about the show, our episode starter packs are a great place to begin.

1:59These are collections of our favorite episodes organized by topic that'll help new listeners get a taste of everything we do here on this show. Topics like persuasion and influence, abnormal psychology, China, North Korea, crime and cults and more. Just visit jordanharbinger.com slash start or search for us in your Spotify app to get started. And hey, by the way, everybody, we just started a newsletter. Many of you are getting it already, but if not, go to jordanharbinger.com slash news to sign up. Every week, the team and I dig into an older episode of the show and dissect the lessons from it.

2:32So if you're a fan of the show, you want a recap of important highlights and takeaways, or you just want to maybe know what to dig into the feed and listen to next, The newsletter is a great place to do that. We've got a lot more ideas in store for the newsletter as well, none of which includes me asking for your credit card number to spam you with crap. JordanHarbinger.com slash news. Would love your feedback on it because it's new. I don't really know what the hell I'm doing. I'm just trying to write good stuff that's useful and valuable, and I need you to tell me whether or not that's the case.

3:02Today on the show, definitely no kids or no young kids in the car for this one. very explicit graphic detail in some of the posts and messages we're talking about today because our guest today, Ryan Montgomery, friend of mine, great hacker, social engineer, been doing it for a long time, long time in the game, professional level hacker, has uncovered a lot of pedophilia, child abuse, and message boards where people share this kind of child sexual abuse material. We talk pretty openly and graphically about this stuff, you have been warned. That said, it's also a conversation about social engineering, persuasion, hacking, the dark web, the underside of the underbelly anyway of the internet.

3:41I think it's a very interesting conversation. We went long because we're buddies and we can't shut up. I think you'll enjoy this conversation. I certainly enjoyed having it even though it's a dark topic. Here we go with Ryan Montgomery.

3:57I don't know you that well, but I know a lot of hackers and I got gotta say, I was into freaking, right? So phone hacking. You just don't get into that stuff in the 90s or early aughts when you're like a well-adjusted kid playing after school sports most of the time. Right. So let me first, you know, just to address the freaking thing, let me show you a payphone that is fully active and working. How do you even, if you're watching on YouTube, you just rotate the camera to show a payphone. How do you even get a payphone now in a private premises? Do you call the phone company and be like, I'd like a payphone in here?

4:31No, so that payphone, I purchased it off eBay. Okay, that makes sense. It was a refurbished 1990 ProTel. I didn't activate a line, like a landline. I routed it to an asterisk server, and now, you know, without skipping all the technical details, it receives and sends, receives and transmits phone calls. Got it, okay, so you didn't have to, like, dupe the phone company to be like, this is a high-traffic area where people might use payphones. No, no. I mean, that would have been a lot cooler of a story. It makes sense. You buy it and then you turn it into like a VoIP thing and it doesn't need coins.

5:02I thought you literally had a coin-operated phone in your house. I could make it coin-operated. Right now it's free. I have the keys and everything came with it, you know, when I purchased it. So I could activate it. And, you know, there's a service menu on there where I could charge myself to make calls. Payphones, man. I spent dozens of hours messing with payphones. And this is probably a different show. I don't want to get off too much of a tangent, but suffice to say in my area, they had to change the firmware or software or whatever they were doing because of the crazy amount of red boxing that me and my friends were doing.

5:35Oh yeah. Yeah. Well, if people want to hear it, um, I can actually, uh, I have some cool stuff. Uh, let me, cause there'll be people listening on the, on a podcast and on YouTube. Absolutely. A red box. Uh, here's what a nickel sound like. This is a dime. This is a quarter. And then in Europe, this is 10 pence, 50 pence. That was a Redbox. And then there was the famous 2600 tone, which was this. And I don't know if you recall that. Yeah. For people who don't know, Redbox was a device that would emulate the tones that a payphone would quote unquote hear when you dropped in a coin. So when you dropped in a coin, there wasn't like digital communication between the payphone and the phone company.

6:18The payphone would just broadcast a tone onto the phone line that said, six quarters were dropped in here. Now this dumb kid can call Japan for two minutes. So we went to Hallmark and got those recordable cards the day they came out, where you could be like, hi, grandma. And it would say that in your voice when they opened the card. And I thought, this is great because in Michigan, people used to use mini cassette recorders, which were one, super expensive. Two, if it got too cold, it changed the tape. It wouldn't sound right because it was too damn cold. If it was too hot, which it often was as well, it would change the tape, and the tone changed just a little bit, but 2600 hertz works.

6:55Maybe 2700 hertz kind of works. 28, 29 doesn't work at all, right? So you had this big problem. Well, digital, that little 10-second or five-second recorder in the Hallmark card, that thing was digitally perfect reproduction every single time. So you just put in a quarter on a phone that wasn't working totally correctly. You'd hear the tone in the speaker. You record that thing or you use a computer to emulate it. Suddenly you've got a thing that's like this big, you know, the size of a child's fist and flat and it makes tone sounds. And all I did was call Japan nonstop all day, every single day for weeks at a time and every country that I could find.

7:33And I remember an operator being like, you have to stop doing this because I would call the operator and ask him to connect me to something in another country. and they'd be like, okay, you need to put in$3.50, whatever. And I'd just do the quarter tones and she'd go, okay, and connect me. And then there must've been something printed out on their dot matrix printer that said, if a kid calls asking you to connect them to another country from a pay phone, I don't know, run it by a supervisor or ask a question. Yeah, double check this one. Right, and so, and then they did something where they modified all the phones, at least the ones I was biking to, where then you couldn't make a tone into the mic before you put a coin in, and that would stop the red box, or so they thought.

8:15So then I started putting a nickel in, it would turn the mic back on, and then I could use quarter tones after that. And I was thinking, how did you guys not think that this would happen? This is the obvious next step. That is, I mean, that's the hacking mentality. So a lot of people think, you know, and I'll keep this one short as well, you know, teaching somebody how to hack is such a broad thing to ask. You know, teach me how to hack a computer, teach me how to hack an account. There's no cookie cutter method on being a hacker. It's a mentality. And like you just said, they put a protection in place to stop you from transmitting a tone into the microphone.

8:46And you put a nickel in and figured out that there was some time that elapsed where you could play additional sounds and add more money to the phone. That is a mental advantage that you had and still have. And you'll always have that. And it's something that I believe can't be taught. So it's interesting you say that. And the reason I told that story is because people are like, shut up, Jordan. Interview the guy already. I'm glad I was able to sort of tease that out of you in a way that makes sense because you're right. There's like hacker mentality, hacker mindset where it does show up in other areas of life.

9:18From a restaurant where I ordered two lunch specials and they were like, well, I guess you can do that. And it was like still more meat than you get with the other price. And you're just like the way the system is not meant to be used. but even things like the bar exam, I mean, not cheating on the exam itself, but the prep course, I've told this story on the show, so I'll keep it super, super short. They won't allow you to take the lectures with you digitally. They want you to show up to a testing center and watch lectures every single day, take notes and study. And I was like, that's BS and it's a grift.

9:49So I said, I want the iPod version of these. I know it has to exist for people that can't get to a testing center. And they were like, you can't be in America because you're too close to all of our testing centers. You have to travel to one. And I was like, fine, I won't be in America for a certain amount of time. And they're like, we want to see your airline tickets. And I was like, okay. So I booked airline tickets that were refundable. And then they would come back with another request. And then finally, someone was like, we know you just want this. Okay. But if you copy it, we're going to sue you.

10:18And you're going to sign this thing that says you understand that. And I was like, fine, I don't need to copy it. I just don't want to go to the damn thing. So it's like, you're always kind of playing checkers or chess, I guess you would say. Right. with a system. The opponent is not a person necessarily. It's a freaking system. That's exactly right. And it is evolving every single day on the defense and the offense. Like I said, not a cookie cutter thing. If you're interested in cybersecurity, you know, that's just one aspect of hacking. Hacking can be hacking people, social engineering. It can be, you know, I guess a good social engineering example is convincing, you know, whether it be lying or whether it be manipulating your way to get to get something that you want, you know, in just a simple form, like you get on a bus every day and you tell the driver, oh, I thought I had my bus card and you do it in a convincing enough way to where they let you on the bus.

11:09I mean, it's such a, you know, a simple, simple thing, but it's, it's hacking, it's social engineering. And that can get more extreme where you could call a phone company and say, hey, I need to speak to your manager, you speak to the manager, you ask them for their representative ID, and you call them back, you tell them to transfer in-house and then you say that you're that representative you just talked to. And now you're saying you're on the phone with a customer and that customer's having problems, but the call disconnected and you have a rep ID that validates that you work at that company and you know a little more about their system.

11:38And you can exfiltrate data out of their account or make changes to their account. And it could be something, like I said, as simple as getting on a bus for free or it could be taking over somebody's entire identity, all with your voice. You are reminding me of the reps some of this takes. And I know that you didn't go to college, finish high school. And I think it's important to note that because I think people go, oh, hackers are like super genius guys that have PhDs in computer engineering. And it's actually quite the opposite. Like you said, it's kind of the opposite. It's a lot of it is kids who did who had the mindset, but also went through the reps.

12:12And what I mean by reps, man, and this will sound super familiar to you as well. I'm getting nostalgic over here. I remember calling a phone company, like you said, get some kind of ID or system or term. And they go, uh, is this system ESS seven or ESS five or whatever it is. And you go, oh crap, I don't know what that is. Right. So then you're in the IRC channel and you're like, what is the ESS seven and ESS five? And if nobody answers in time, you have to like hang up and call back. Right. Or you hang up and go, sorry, we got disconnected. Yeah. I actually don't know the versioning on this. And they're like, versioning, because that's like the wrong term.

12:48And then they go, do you mean the install, whatever? And you're like, that's Intel, right? And you write that down. And you're doing this, like, maybe 100 times a day for like your entire spring break, because you're a loser with no friends. Sorry, I'm getting very personal. Listen, I've been I've been doing it, you know, when I was a kid, for a long time. And, and, And I would learn these companies inside and out. And I'd know exactly, for example, AT &T, I would know exactly what system that agent was going to be using, exactly the error messages that they would receive when a problem would happen, and exactly what type of rep ID they would be using, the amount of digits, whether it be starting with a prefix of letters or ending with a suffix of letters.

13:32There's so many variables to it. But once you gather, like you said, all of those bits of information, you can construct that into a very convincing phone call that appears to be internal. And it still works to this day. I mean, I wouldn't recommend anybody do it. It's illegal. But it's, you know, people are the biggest vulnerability. The systems are not. Your employees, your people around you are your biggest weakness. It's funny because I didn't mean to go into like how to protect yourself from cyber, but people are always like, oh, I need the antivirus program that you use, right? I want to know how to lock down the open ports on my company's computers.

14:06And I'm like, the problem is none of those things. Yeah, you should update your WordPress site so you don't get like script kitty malware attacks. The problem is the intern who you just shared your password with, you don't think it's a big deal because that's just your Salesforce install. But what's your banking password? Oh, it's the same thing, but like has two numbers at the end of it or not even that different. And you just assume that your intern doesn't know that you bank a chase and you don't realize she wrote that on a post-it note and left it on her desk in the top of her laptop, which she just took to a Starbucks and opened for three hours.

14:42Exactly. And the 90 % of the people listening to this right now that are using an exclamation point as the symbol that was required in their password, you know, that's something that hackers think of, you know, it's the first symbol on your keyboard with a digit, with a number. They're like, wait, so my last name with an exclamation point on then or like you see that video where they're interviewing some gal on hollywood boulevard and they're like do you use the internet yes what sort of password do you use oh it's uh the year of my graduation and my pet's name and they're like oh okay how long have you been in california and she's like uh three three weeks what are you doing i'm going to universal studios do you have any pets yeah what kind a dog what's his name uh i don't know froofy cool all right did you go to high school yeah where'd you go to high school uh saint augustine well when to graduate 1999.

15:28And then it's like, so it's froofy 1999. It's just the guy does it in like 42 seconds and she just doesn't see it coming. Oh no. Anyone can look it up and look up, you know, password interview on YouTube. You'll see that video. I know exactly what one you're talking about. Yeah. People are like, this is fake. And I'm like, even if this is fake, the whole thing that that person just did is definitely not fake. Not even close to fake. Social engineering is huge and pen testing companies, cybersecurity companies, still to this day, I believe most of them, the first engagement is social engineering.

16:00If an employee gives you access, why break in? They're gonna give you the key. When I went to DEF CON, which is a hacker conference for people who don't know, a long time ago, there's a social engineering village or whatever they call it, and there was a sound booth. It's a brilliant idea. There's a sound booth, and they'll just let people take a crack at calling Windows Tech Support, whatever, at Microsoft, and they have a speaker outside the booth so an audience can listen to a social engineer or whoever's in the audience take a crack at trying to get as far as they can. And it was really impressive.

16:31Very few of these Microsoft employees were like, I probably shouldn't give you that information. It was rare. Yeah, and the booth was a soundproof booth and you would just sit in there and there'd be people going in and out, in and out, in and out, just gathering as much intel. And then all the people listening are gathering intel as well. Like if you go first, people clap more, right? Because if you're the fifth person, you correct all the mistakes the other person made. Exactly. It's like walking through a minefield, I guess, figuratively. It's a cool little world. It is. It is a cool little world.

17:01And I want to know how you got into it. Because again, I know a lot of folks that really spent a lot of time doing that. And I was probably the most well-adjusted of my hacker friends by about 100 miles. Yeah, likewise. I grew up in not the best area in the world. And a lot of people I grew up with you know, doing the wrong thing, doing drugs. And, you know, none of them were on a computer. None of them knew how to use a computer. I was kind of a lone wolf there. And my dad's side of the family had some serious drug problems, still is going through them. And my mom's side of the family, which, you know, have been amazing.

17:36They don't have that issue, but, you know, I was in a contamination between the two. So, you know, I didn't come from a lot of money on my mom's side. We didn't grow up in the best area, but, you know, it was a lot worse on my dad's side. So being back and forth between those, it introduced me to some people that I shouldn't have been around at the ages that I was around. And it got me into some bad stuff, you know, outside of computers with, you know, with drugs and, you know, stupid petty crime and stuff like that. But computers were always my passion. You know, I don't know how to explain it in conjunction with the drugs and the petty crime outside of computers, but there was always my passion outside of that.

18:14None of my friends could relate. They just knew Ryan's the guy that's good on a computer. Ryan's the guy that I'm going to call when I have something wrong with this or somebody that's not knowledgeable with computers just thinks I could do anything. This guy can take over the planet with his computer. And I was a little kid at that time, but I spent a lot of time around older people. And some people might say, well, maybe you grew up fast, you learned a lot. And then other people would say, well, people I was around that were older, it did teach me things. And I did learn fast from them. They weren't the best influences.

18:47And I didn't carry over that knowledge into my adult life by any means, but I definitely had to grow up fast. And I definitely did a lot of things at a very young age that most kids haven't seen. I remember my parents being kind of worried and they didn't know the half of it, but they were kind of worried that, and I look back and I'm definitely right. There would be like one of my friends when I was probably 13 or 14 years old was 20, which like, that's weird. He was in college. Yeah, it is weird. And I was in middle school, right? That's weird. And there were guys older than him that we hung out with.

19:25He would come pick me up from Detroit, which is not that close to where I live. I mean, it's, I live in the suburbs and we'd drive down to another place like Southfield, which is another suburb. And we'd be dumpster diving in a cell phone store parking lot. And I'm like, wait a minute. These guys are like 40 years old, late thirties. They're hanging out with me. I'm 14. There were other kids there that were like 17, 18. It's odd. And granted we were in a very niche, very niche hobby, right? Freaking and phone hacking. It's still fricking weird. I would have been like, yo, leave the kid, the literal child at home.

19:58Because if we have to go somewhere, run from the cops, what's he's I can just hop in my car. That's not odd looking. Yeah, and not only that, but even if they didn't have any intentions on the creepy side, they would get child endangerment charges. Totally, yeah. These guys, like 20-20 hindsight, there was never anything even remotely like that. They were just geeky, weird dudes, but you would think they should have had better judgment. These criminals that I hung out with should have had better judgment. Right, right. Well, I guess the difference between your story and mine was I wanted to, you know, I was a kid.

20:30I was making dumb decisions. So I wanted to hang out with the older people and I got along with them better. I don't know why. And, you know, everybody has told me I'm an old soul or whatever, whatever that means. But I always wanted to be around older people. I've always dated when I was younger, I dated older women. A lot of them were, you know, way above my age. But I blame it on myself because I was lying about my age at one point when I was younger. Yeah, when I was like, you know, like 12, 13, 14, I was telling people I was 18, 19. And it was actually brings up a point that I actually wanted to address anyway.

21:02You know, when I was 13, 14 years old, I looked actually, you know, a lot older than I do now, which is surprising because I was whacked out on drugs and I had long black hair and piercings and tattoos and, you know, all these things, you know, that a normal, normal child wouldn't have. When I did the, you know, another podcast before this, somebody looked into me and I guess read it and started looking into me and they found that I used this name. Do you remember the MySpace days when everyone was like the scene kids and emo kids. Sure. Well, I was definitely a part of that back then. And I had, you know, the long hair with the double Monroe piercings on your lips.

21:38And, uh, you know, and I used a stupid edgy name as a kid. Sure. And people were bringing that up, you know, like trying to discredit me for all the things that I'm doing. And it's like, if they would just look at the date and they see, you know, I'll be 30 in July. Um, if you look at the date, you're, you're posting pictures of me as a 14 year old and, you know, judging me for it. And I just thought to myself, and it's pretty obvious, you know, if you, even if you go back five years in your life and you read something that you said on social media, or you read an email or a text message to somebody and you don't cringe at that.

22:08Yeah. And you have not grown. And I'm looking back 15 years ago and it's like, they're bringing to light some things. There's nothing there that's like, you know, bad. It's just, yeah, it's, it's cringe. Yeah. Leave me alone. You know, I'm trying to do something good with my life. And I have been for a long time, just leave me alone. You know, I went through a phase as a kid and I look like a weirdo. I get it, but whatever, leave me alone. You're listening to the Jordan Harbinger Show with our guest, Ryan Montgomery. We'll be right back. This episode is sponsored in part by Vital Proteins. You probably heard of Vital Proteins.

22:43They're the number one brand of collagen peptides in the U.S. and for good reason. A lot of people, myself included, take it pretty much daily to support things like healthy hair, skin, nails, bones, joints, all the good stuff that starts to matter more the longer you've been walking around on this planet. But now Vital Proteins is shaking things up, literally, you can tell a dad wrote this copy, with a brand new collagen and protein shake. And this isn't your average protein shake that tastes like chalk and sadness. This one's light, chocolatey, super smooth, and it's got something pretty unique going for it.

Read the full transcript

23:10High quality protein, 30 grams of it, plus collagen. That's pretty good ROI. Usually you're choosing one or the other, but Vital Proteins gives you both a ready-to-drink shake you can toss in your bag or fridge, zero added sugar, no artificial sweeteners, and no carrageenan. And I don't know what that is, or if that's even how you say it, but you're supposed to avoid that. If you're already taking collagen or you're just curious about how it might support your hair, skin, nails, joints, and you don't want any carrageenan, this is a super easy, tasty way to try it. Get 20 % off by going to vitalproteins.com and entering promo code Jordan at checkout.

23:44This episode is sponsored in part by Dell. Introducing your new Dell PC with the Intel Core Ultra Processor. It helps you handle a lot, even when your holiday to-do list gets to be a lot. Like organizing your holiday shopping, searching for great holiday deals, customer questions, customers requesting custom things. Luckily, you can get a PC with all-day battery life to help you get it all done. That's the power of a Dell PC with Intel inside, backed by Dell's price match guarantee. Get yours before the holidays at dell.com slash deals. Terms and conditions apply. See dell.com for details.

24:19If you're wondering how I managed to book all these great authors, thinkers, and creators every single week, it's because of my network, and I'm teaching you how to build your network for free over at jordanharbinger.com slash course. This course is about improving your relationship skills, and you're inspiring other people to want to develop a relationship with you. It's not cringy. It's down to earth. It's not awkward. It's not cheesy. Just a lot of practical stuff that's going to make you a better connector, a better colleague, a better friend, a better peer. Six minutes a day is really all it takes.

24:46Five, really, but five-minute networking was taken. And many of the guests on the show subscribe and contribute to the course. So, hey, come join us. You'll be in smart company. You can find the course at jordanharbinger.com slash course. Now, back to Ryan Montgomery. Dude, I am not a celebrity by any stretch, but there's enough internet stuff that sort of puts me in a public eye. There's a Google talk where I'm just like a fat slob with a terrible haircut, and I can't do anything about that at all. Understood. Right? Yeah, but that's you. And this is worse. yes it's worse though it's i mean hey man it's it's a it didn't bother me in the slightest bit because it's it'd be one thing it's like they pulled something off the internet and it was like this guy is trying to help save kids is actually this secret horrible person that uh that right does all these horrible things like there's no secrets in this the stuff that's out there publicly about me like i told people yes i did drugs yes i committed crimes as a kid uh You know, I did stupid things that kids would do.

25:47Yeah, I used a stupid name. Like I was, you know, I'm pretty public about the dumb stuff I did as a child. You know, if you have a problem with that and that hinders your thought or your opinion, your opinion, manipulate your opinion on me helping children or attempting to help children, then I apologize. But, you know, I don't know what to tell you. These are the same people whose parents wore, you know, polyester bell bottoms and probably met at like an orgy in the 60s and they're like how dare this guy ryan like emo music that i hate yeah well it was more so that the edgy name and i would assume that you know and you know like back in the day there was like zoe suicide and yeah of course carla curb stomp you know like those crazy names if you googled scene names you would see but you've done some other incredible stuff that should easily outweigh that i mean you started a rehab at by the time most people were having their first beer, you had founded a rehab center.

26:42Yeah. Is that accurate? That is accurate. So long story short, I was dating a girl named Angelica and I knew her since I was a kid as well, actually. She ended up in Florida for her own personal reasons. And I was still living in Pennsylvania at this time. And I was flying back and forth to see Angelica. It was like one week out of each month. And I would fly back and forth to Florida and I'd see her. And she lived right near a Starbucks in South Florida. And, you know, every time we'd go to the Starbucks, it would be packed with a ton of these people. And I would see the same people every time.

27:14And they'd all be talking about drug rehab. And they'd be talking about saying, hey, if you know anybody in Pennsylvania that needs treatment, you know, we'll pay you this. You know, it was a pretty significant amount of money per person that you can send to rehab. I asked her about that. I was like, why are all these people bringing up that, you know, they'll pay me to put people in rehab? I never heard of anything like that before. work because every rehab I ever went to as a kid was all government, you know, subsidized and Medicaid sends you there. Yeah. Judge sends you there or, you know, their Medicare, Medicaid facilities.

27:45So all these people, they're driving around in Mercedes and BMWs. They got nice watches. They look like they just got clean a couple weeks ago, you know, and they're talking about, you know, a couple thousand dollars per person. And I, you know, I found out from my ex-girlfriend that that's a thing called patient brokering, which is a felony. Oh, it is. Yeah. So you can't, There's no such thing as giving a kickback in the healthcare space. You're brokering human beings. I see. I mean, that sounds fair now that you explain it. Yeah. Because to me, I'm like, oh, lead generation. Oh, maybe this is a little gross.

28:13Yeah. So, you know, I'll go into that too, because, you know, after I found out it was illegal, which I never ended up doing it, I didn't know anybody that had private insurance in the first place to get them to travel to Florida, even if I did want to make that decision. But I went, you know, I did my research. I had a background in internet marketing as, you know, as well. and I did some research and I found there was a lot of treatment marketing companies out there. So I would call them up. You know, they were running PPC campaigns on Google, just, you know, pay per click. And when they would pick up the phone, it would sometimes be one facility and then another time it'd be a different facility or then other call centers, it would be the same guy picking up.

28:50But depending on what type of health insurance you had, they would send you to whatever facility paid, you know, that insurance company would pay the highest for it. The problem there is a lot of the facilities, including mine, are dual diagnosis. They change it from substance abuse to substance use. So it's dual diagnosis, substance use, and mental health disorders. And, you know, let's say somebody has a severe eating disorder, but they're also addicted to some type of narcotic or drug. You know, they call a treatment marketing phone number, and they get in touch with some guy. They say they have, let's say, a Blue Cross Blue Shield PPO that has a low deductible, and they know it's going to pay very high.

29:29That person with an eating disorder needs to go to an eating disorder clinic that also helps people with drug addictions. But instead, these marketing companies were sending people to whatever places were going to be paying them the most money. And that didn't sit right with me. And I thought, okay, well, I can do these same things. I can run the same campaigns, but I can work with the right facilities and send them to the right places. So I started a company called thetreatmentsource.com, which was just basically a landing page on a website and I did some very targeted Facebook campaigns and I didn't have the budget behind me in the beginning of this project to do what a lot of those marketing companies were doing.

30:06But the campaign started to work very well and I was putting people into treatment but wasn't making a ton of money at that moment. Once some rehabs found out that, hey, this guy can get people in and he's doing it through the legitimate routes and they have private health insurance And you can't do like a cost per acquisition or a cost per client because that's where the patient brokering comes in. But you can pay somebody, you know, a flat fee for their services. So I would go to these facilities while I was still dating this girl, flying back and forth. I'd show up at these rehabs and say, hey, here's my site.

30:40This is how many, you know, leads on average that we're bringing in. Which when I say we're, I'm talking about myself. But, you know, they didn't know that at the time. Yeah, me, myself and I, the three people that work at my company. Exactly. Exactly. This is right in the beginning of the treatment source, which was very short lived, actually, but it worked. And I talked to a bunch of treatment centers and they all threw up money separately. I had contracts with each one. I could not put a number of clients on that contract because the second you put a number in association with the dollar amount, it becomes a crime.

31:08Right, because you can break it down into a per-client price. Yeah, exactly. Gotcha. So I did a good job in that area. I made sure that the people that needed help were getting the right help that they needed. And I ran into a guy who I got along with better than the other facilities. I didn't have a problem with anybody, but we became friends pretty quickly. And he stayed in touch with me. And one day he calls me. I still live in PA at this time in Pennsylvania. And he says to me, hey, you won't come to the Fort Lauderdale airport right now. like just joking with me and I'm just waking up and I'm like, yeah, okay.

31:42And then, you know, I end the call. I booked my flight within three hours and then I call him maybe, I don't know if it was a couple hours after that or not, but the same day I call him and I say, Hey, I'm at the Fort Lauderdale airport and he's not believing me. Like, you know, I genuinely got on a plane and flew that same day. Wow. I went and met up with him, picked me up at the airport and I went back to his house. I stayed with him for about a week. We discussed, you know, some marketing ideas. And at that point, I had a contract with a facility he owned prior. I had no ownership in that facility.

32:11So after that week was up, you know, I decided, well, if I can stay with him until I find a house to buy in Florida or somewhere to stay or get my own place, I'll do that. He offered to let me stay with him. So I did. I flew back to Pennsylvania. I got a U-Haul, put my car on the back of it with a trailer, drove down to Florida and stayed at his house. And I convinced him. And, you know, he also had part in this decision, but to sell his shares in his rehab and to start one with me. So I dropped all my contracts with all the other facilities and did all of the marketing from my own facility that started the first one.

32:42And I filled that one with the marketing campaign itself. The treatment source was gone. We did the marketing for the facility directly. And that turned into a partial hospitalization, intensive outpatient and outpatient facility. but we didn't have any medical detoxes. So we would have to send them to other facilities. You know, let's say someone's going through withdrawal from whatever drug or alcohol, they would have to get detoxed medically and then they'd be sent to us for their treatment. We thought that, you know, after, you know, we brought in some money and things were going well, we provided great quality care, which I can get more into that if you're interested.

33:18We opened two detox facilities as well. So I ended up having three facilities with 144 beds, 120 employees, and I was the CEO of that facility. So it was an honor. I was able to help a ton of people and, you know, start a cool scholarship program for people that were just like me that didn't have money, didn't have insurance, needed help and didn't have a three-month wait, you know, where these other facilities have three-month waiting lists. Oh, man. Imagine being an addict. You decide to get clean and they're telling you, sure, in 90 days you can come in. I mean, you could be dead by then if you're that far down.

33:50Yeah, that's exactly the point. It's, you know, you can't tell an addict to wait three months. They don't have three months, especially now in 2023. 23. It's the number one leading cause of death, 18 to 49 years old for the last two years. And, you know, an addict doesn't have three months to wait. And so I started that scholarship program, which meant, you know, you come to treatment, you fly to Florida and you stay for as long as it takes until the clinicians say that you, you know, you're ready to go or you walk out the door on your own. But I did that. And, you know, that was super successful in my opinion.

34:21It wasn't profitable, but it felt good. And I feel that I help, you know, a good amount of people that way. So heart disease and cancer don't kill more people than, what is it, fentanyl? Yeah, I mean, I can double check the statistic. Let me see. Or maybe it's the age group, right? Because maybe cancer and heart attacks are above. I guess there's a debate on it, which I didn't know that here. I watched something yesterday, Jelly Roll, I think it was, on Joe Rogan. And I think he said it was an opiate overdose every 11 minutes with death. But yeah, maybe this is fake. So I'm looking at the fact check on that.

34:54And it says, fentanyl is not the leading cause of death for adults in the US and the CDC data from 2020. The top three causes listed are heart disease, cancer, and COVID. Well, we'll find out in a couple of years. Yeah, let me know if you find out otherwise, but I definitely heard it many times. So I know that it surpassed 100 ,000 in 2021. I think we can safely say either way that if you are already addicted to something, you have a great chance of dying, especially if it's an opiate. So we don't have to split hairs on it. It doesn't matter. Yeah, but don't discount the Xanax, the Coke, all the new things.

35:24People are dying from them too with fentanyl. This fentanyl's in everything, all the different types. I hadn't thought about that, but you're right. There's people, friends of friends, who went to a party and tried cocaine and it was laced with fentanyl and they're dead. And it's like, that's... Back when I worked on Wall Street, people would be like, hey, you look tired. And I'm like, yeah, I need a Red Bull. And they're like, forget that crap. Come into my office. And you're like, oh. But now it's like you could just die from that because he just bought it and hasn't tried it or has a higher tolerance.

35:52That's just reminding me too. And this sounds absolutely insane. I know before I'm saying it, but back when I was a kid, heroin was like a thousand times safer than it was today. I stopped using drugs around 17. I knew of one person that died of an opiate overdose and it was mixed with other things. And now almost everyone I grew up with is dead. A couple of my family members are dead. There's a story I think I talked about on another podcast, That's how I found my best friend dead. He did well for a year straight. And I walked in and found him in his bathroom. He was gone. And he made the mistake one night.

36:30He was completely fine. He just made, he had one slip up and he was gone. I just can't imagine why people would want to do that. But I guess I can understand being an addict and not being able to stop. I don't know. I don't associate with that completely as being an addict for life. I don't believe that I am personally, but I do. I definitely know that some people are. It's hard for me to understand everybody's opinion on it or everybody's everybody's mindset on it, especially for my my best friend. He was just like you and I, you know, he just made a mistake one night and that was it. Sorry to hear that.

37:04Yeah. I mean, I'll save all the details for the story of the story because it's it makes me upset to talk about. Yeah, you don't have to relive that gruesome, devastating moment for sure. It's just, I think it makes a lot of sense. It illustrates the way that you grew up and how that informs your rehab practice. And that all sets a good baseline for, okay, I'm an entrepreneur. Obviously, I'm a doer. You dropped out of high school and started a business by age 22 that most people would be lucky to have when they're in their 40s. And it was based upon helping people, but also making money. and I know you do things like you're an ethical hacker, which, well, first of all, tell us what that is because a lot of people have never heard those two words put together.

37:43Gotcha, so an ethical hacker is, I like to call myself a cybersecurity professional, but an ethical hacker is somebody that, there's three different types of hackers. There's a black hat, a gray hat, and a white hat. Black hat is somebody that commits crimes. Gray hat, someone kind of in between where like, they'll hack your website, they'll send you an email saying, hey, I found a vulnerability in your site, you should probably fix this without permission. And then a white hat hacker would be, you know, let's say Jordan contacted me and said, hey, I want you to test my site. You know, we have rules of engagement.

38:12We have scope. And we do something with his full permission. That's like a 30 ,000 foot view of what that means. But that's something else I wanted to talk about is there's some titles online saying number one ethical hacker does this, does that. And I'm not a self-proclaimed number one ethical hacker. The reason why that title became a thing is because there was a website out there for, you know, there's some training stuff there and there's some competitive stuff. And I'm number one. I found that. Because I was like, number one, how does he rank? And then I was like, oh, here's where he's ranked on this training site for being like in the leaderboards.

38:47Okay. Yeah. So it wasn't always a training site. So half of the site is training. So if you don't know anything at all, you can learn on there. And then the other side is competitive. So if you end up solving these simulated challenges, which are just like real life environments, some most of the time, if you solve them first, you get extra points and those points will allow you to move up on a leaderboard. And since there's 2 million users on this website, almost, I think it's just shy of 2 million in number one on there was very difficult for me to get. That doesn't mean I'm the best hacker in the world.

39:16That just means that I worked very hard to get to where I was at. And, you know, I want to make it clear that I'm not a self-proclaimed best hacker like Kevin Mitnick or somebody like that. I think Kevin Mitnick did say he was the best hacker. I could be wrong on that. Yeah, well, he would say that. And also, I'm not sure everyone else agrees with him, but we'll leave that. I don't agree with him. I do not agree with him. You're probably a better phone freaker than Kevin Mitnick. I won't say that, but I will let other people say that. And I will. And I've look, he was nice to me. And I will say this, but his modesty does not comport with the hold on.

39:49How do I phrase this? His opinion of himself may be slightly different than his skill level reflects. anyway. Yeah, I understand where you're going with that one. I got you. Yeah, that happens to people, whatever. Not a big deal. So ethical hacking, penetration testing. When I was doing the social engineering stuff, I worked with a lot of pen testers. I know you run pen tester.com, which we'll link in the show notes. Oh, thank you. This is like, so just to, I'll save you a second here. The difference between white and black hat hacking is kind of like, if I want to test if my store is secure, I might hire somebody to break in and I'm standing there watching them pick the lock and then go to the cash register and pry that thing open and get through the little gate I have to the office.

40:30And I go, okay, I need a stronger lock, a stronger door. I need a little metal grate. Thank you. And they say, no problem. The black hat version, the guy just breaks in and robs me and then says, if you want your stuff back, you can, or if that, maybe I just get robbed. Or if I'm lucky, they say, if you want your stuff back, send me 10 grand in Bitcoin and I'll return the computer. So I stole from you. Yeah. They ransom you. Right. And then the gray hat in between, I would say, is the guy that comes into your store. He steals all the money out of your cash register. But before he walks out, he shows you how he did it and hopes you don't call the cops.

40:58Right. And says, I'll give you this back, but there's more holes in your business that you're going to want to pay me to find. Exactly. I wouldn't recommend black hat or gray hat to anyone. You know, if you're going to do this, do it the right way. There's a lot more money doing this the right way than the wrong way. Trust me. I wanted to ask about that because I know some cyber criminals and many of them have gone to jail. I wonder when you did the calculation, like, okay, I can do some bad stuff and make money, but there's more money in legitimate business period. And we see this pretty much universally.

41:26Even the Italian mafia now just owns legitimate businesses for the most part, even if they muscle some contract here and there on sanitation, according to some people, it's like, it's, there's still more money just owning a building in Manhattan than trying to extort immigrants or whatever. Right. So I guess for me, it wasn't really a turning point type of decision. It was more of a, you know, once, Once I stopped being an idiot kid and I stopped using drugs and I started the rehab at such a young age, I didn't have time to be an idiot like that. And, you know, I was doing well financially. So I think it was just kind of the way that God pushed me in my life.

42:01I can't give you like a turning point because I was never like arrested for a federal crime or anything of that sort. It changed me. I don't know, man. I think I was just I was just very busy. I was doing well financially and I didn't need to break the law to do that. I love that. But I also, of course, want to hear about some of the black hat stuff you've done because I can't be the only one admitting crimes. And the statute of limitations has long since passed. Yeah, I understand. And, you know, I can only get into certain things because of some, I guess, credibility and some of the nonprofits that I'm going to be working with that also work with federal government.

42:33I want to make sure that I'm a credible person. Yeah, of course. You know, one thing I did talk about was it was a Bitcoin mining botnet. And, you know, it was something I did as a young kid because, you know, I believe that was back 2013 or 14, maybe 12 or 13. I'm not entirely sure. You know, it was one of those three years. There was these things called Java drive-bys. And have you ever heard of a Java drive-by? No. Browsers used to have Java applets that you could run, you know, applications in your browser that were Java. You'd get a message at the top of your screen and it would say run once or run always.

43:08and there were some exploits out there called Java drive-bys. Some would mean you would have to click a button to allow the Java applet to run and then others would be zero clicks. So they would go to your website and they'd get infected. They don't exist anymore because browsers don't support Java applets. But I had this website, which I won't name the domain name, but I had the website and it looked like they could mine Bitcoin in their browser. And there was a popular Bitcoin forum back then where if you signed up, you'd be considered a newbie member. So anything you said, nobody was going to take seriously.

43:42But if you were on there for a while, you had a senior member title. And I wanted to see like, okay, if I can get into one of these senior members accounts, I can post this website, infect these computers, which I know if they're all into Bitcoin and Litecoin, they probably have good computers. Because that's a big factor when it comes to mining. If you have good hardware, your computers are probably going to be good. You know, I took over a couple of these senior accounts, said that this website was legitimate. And that botnet spread in the Bitcoin community. Its sole purpose was to mine Bitcoin in a pool.

44:15It was not like your average Trojan where I was looking through webcams or taking over control of your computer. Obviously, I could update the file in case I needed to bypass some sort of - You just wanted processing power. Right. So there was more to the story, but it was a stupid thing that I did. It was, you know, luckily it is past the statute of limitations. It's long gone now. I didn't hurt anybody. If anything, I, uh, maybe I increased their power bill by a couple of pennies. You know, that's, you know, a little, a little story from my past, but, you know, a lot of the dumb stuff was before that, even on aim and sure.

44:50And digital gangster was another site that I was a big member of. And there's a lot of those stories. When you say aim, are you talking about AOL instant messenger? Yep. You admit a crime, I admit a crime. So I used to, I probably shouldn't say when this is. Ah, screw it. In law school. I was like, oh, everyone uses AIM. And everyone, it was like the first year people use laptops. And you're in a law lecture. And I was like, what are they talking about? What is everybody talking about? Everyone's using AIM right now. And so I got a Linux partition on my laptop hard drive. And I got some PCMCIA card that, I threw a good Wi-Fi card in there.

45:28and I got something called like, the logo was a pig. It was like air oink or whatever. I can't remember the dang, the air snort maybe. And you ran the card in promiscuous mode and it would just grab all the traffic off the network. Yeah, it was air snort and it would put the card in monitor mode and they used to call it promiscuous mode, I believe. Yeah. Yeah. It was a wireless cracking utility. And back then, I believe it was WEP keys, which were cracked in seconds. Seconds, yeah. Yeah, nowadays it's a little different, But it's still easy to capture a handshake. And the world hasn't changed much.

46:01It's just the technology has gotten more advanced. So essentially, I was running like man-in-the-middle attacks on my classmates, which is, and I'll leave it here, a great way to find out how little people think of you when you can see their private conversations. Like, I apparently didn't learn my lesson from the phone calls and just started eavesdropping in my classes. and you won't unsee the unvarnished communication between your classmates about how much of a POS or dork or whatever they think you are because you know there was no agenda other than just like pure truth bomb and they would never tell you that to your face.

46:36So I don't recommend that course of action. No. It's not good. It's not good for the ego. I deserve to get knocked down a peg. There's a part of me where I was like, this is the universe being like, hey, you want to do this kind of crap? Fine, have a little dose of this. And it's like, ugh. No doubt. Maybe I should stop. So, all right, bug bounties. I used to just get in trouble for finding bugs in software, but you used to get paid. Tell me how that works. Bug bounties are kind of a blessing for a lot of hackers out there because most large companies now have programs where they'll pay for you to find vulnerabilities.

47:07They'll tell you the scope, what's in scope, what's out of scope, meaning what not to touch, what to touch. Depending on the company, they'll pay out for big amounts of money for certain criticalities. So if it's something low informational, it might be$100, where if you find something that could damage the company, it could be$30 ,000,$100 ,000,$1 million. And in Apple's cases, if you find a zero day in an iPhone, it's a million dollar bug bounty. I think it has to be considered a zero click exploit, meaning no interaction from the user. But that's a million dollars, whereas a couple of years or maybe 10 years ago, that type of thing would get you put in prison just for putting it on the internet.

47:50This is the Jordan Harbinger Show with our guest, Ryan Montgomery. We'll be right back. If you like this episode of the show, I invite you to do what other smart and considerate listeners do, which is take a moment and support our amazing sponsors, all of the deals, discount codes, and ways to support the show. Those are all on one page, jordanharbinger.com slash deals. And you can always search for a sponsor using the AI chatbot on the website as well, jordanharbinger.com slash AI. It's not always right. It did tell a few people, myself included, that my mom was racist, but otherwise it's quite useful.

48:23JordanHarbinger.com slash AI is where you can find it and check it out. Thank you for supporting those who support the show. Now for the rest of part one with Ryan Montgomery. Yeah, like I would crash a BBS and I remember if I liked the board and I crashed it maybe by accident by finding a glitch, I would call the sysop. And I remember one guy I called the police instead of just being cool. And I was like, dude, I called you to tell you I found a bug and you just try to get me in trouble. Fine, someone else is going to find the bug and trash your site. And the cops didn't do anything because they were like, so you turned off his computer over the phone?

49:01Like, don't do that, kid. Right, they don't care. Yeah, they don't care. And then I was like, oh, now what I'm going to do is post the bug on a bulletin board system full of hackers, and I'm going to put your number to your BBS and be like, go ahead and try the bug it's on this website you can go ahead or not website it's on this bulletin board you can just log in with a new account and try the colorworks bug right now and it'll crash the whole site and they had to uninstall that because they were down for days and days because he didn't know it was crashing it every time he would just boot up again somebody would log in five minutes later and crash it and i just thought oh my god you know like never piss off hackers even though that was a script kitty thing that i had but like why do that just be cool they're trying to help we're trying to help sometimes 100 yeah and yeah even whether it's script kitty or not, that it's, you know, denial of service attacks that would be considered as, you know, even if it is the most script kitty attack that I can think of, it's one of the most damaging because it makes your, your website, your business, your product unusable until that person decides to stop.

49:57Yeah, exactly. I didn't think of it like that, but yeah, they had to like uninstall that. And the vendor of that, it was like ASCII colors and the vendor of that ASCII colors program had to write a patch, which they didn't do overnight. Right. So they lost and it's all because some cis op neckbeard guy wouldn't just be like, oh, cool. Thanks, bro. I'll disable that for now. Yep. Egos. You got to let the ego go. Totally agree with you. Now, though, we have the dark web. And can you explain this a little bit? Because I try to explain onion routing and I just sound like a complete dork. Basically, and correct me where I make a mistake here, but basically the military, I think it was, set up a browser that they allow the public to use because the military also uses some of the layers of this network to communicate or get intelligence or whatever.

50:42And the more people using it, the more noise there is. And it's essentially all encrypted. And so they want a lot of noise from people who are not doing top secret things and they want it all heavily encrypted. So you don't essentially know what is going on on that internet connection. And then of course, on top of that, you use a VPN to mask your location, ideally oh definitely i always recommend using a vpn on top of tour and disabling javascript if you're using for for any reason even if you're just trying to be anonymous you don't have to be a criminal to want to be anonymous right tour is the web browser that uses quote-unquote dark web which uses something yeah i hate the terminology i genuinely hate the dark web but uh like the terminology called dark web because it's it is the onion router that is right it's an open source project that was made for anonymity.

51:27That's what it was. Criminals exist on the clear web, as we're going to get into, and they exist on the dark web, quote unquote. The reason why I bring this up is I did an episode a while ago about the Silk Road with an author who wrote a book about the guy who founded the Silk Road, which was essentially a dark web. The way they explain it is not going to be accurate, but it's like Amazon for illegal stuff. And it was like hit men, drugs, psychedelics, stolen whatever's stolen IP, stolen actual stolen merchandise, stuff like that. It was just a place where you could buy illegal things using Bitcoin.

52:00Yeah, Ross Ulberg. Yeah. I actually know Ross's mom. You know, I don't know anything. I told you before, I don't know much about politics, but when Trump was trying to, I think, get reelected, she was trying to get a pardon for, like, I think, is it a pardon when they release people from prison? Yeah. Or clemency, maybe. Yeah, clemency. That's what it was. So she was traveling around the country wherever Trump was having rallies. who was getting all these people out, you know, trying to get Ross out of prison. I never met Ross. I just ran into his mom. And, you know, she swears up and down that he never hired hitmen or anything like that.

52:34He also got robbed by, I think, the Secret Service. They took his Bitcoin, didn't they? And that guy got caught and fired. Some government agency stole money in the middle of the investigation. I believe one of them is still locked up to this day. And Ross got two life sentences. All of his appeals exhausted. and he's in no parole. Yeah, it's, well, I'll save my opinion, but I think it's a little bit heavy-handed for what actually happened, according to the book anyway. Yeah, well, I mean, I've been on the Silk Road and I didn't purchase anything on it, but I've been on Silk Road. I've seen how the site works and I understood the concept behind it.

53:08It might not have, you know, he might've been a very intelligent guy. I don't know if it was just him as like the administrator. He went by Red Pirate Roberts. I don't know if it was just Ross by himself or if it was a bunch of people. the idea was great except he let people control what was put on the site he was specifically you know you can't sell weapons here there were not hitman services on his site but he was accused of hitman stuff outside of it and no child pornography there were some rules but uh a lot of stuff on there and mostly drugs and fake ids hacking services for hire whether they were real or they were fake they were there a lot of stuff like that there are other marketplaces out there I don't know all of them, but I know there was another one called Alpha Bay.

53:51Yeah. And the owner of that one got arrested and he didn't get a life sentence because he didn't make it that far. I believe it was the first night or somewhere near the first night he hung himself in his cell. Oh, man. Yeah. Yeah. The guy was, you know, living large in some Asian country. And I think he had a couple of Lamborghinis and a couple of houses. And, you know, he wasn't very smart about making money that way. but he unfortunately killed himself, and he probably did because he knew that there was no chance he was ever getting out. It's interesting to see a pedophile get a certain number of years, or somebody who's done, maybe killed someone with actual malice, and then you find somebody who facilitated the selling of mushrooms and other things online.

54:38Granted, maybe a lot of times, and ends up with a life sentence and dies in prison. It's just a little bit like, all right, what are we doing here, folks? Yeah, I can. I mean, look, I'm no lawyer. I'm not the law. And I don't advocate for anybody using substances. You know, people are going to do what they're going to do. People are going to use drugs, whether they're illegal or they're not illegal. Yeah. And if I was still a child doing drugs and I had a choice between buying drugs from Tommy on the corner or buying drugs from somebody where I could read reviews from 10 ,000 customers. Right.

55:09I think I'd pick the one where I knew what I'm getting, you know, and I'm not saying that what he was doing is all right. but I agree with you to choose between the two. I'd pick his, his service. Yeah, I agree. It's a totally different show about law and public policy and, you know, the misuse user misuse of the internet. But the moral of the story is make your own fake IDs. Don't buy them in the dark web. Um, don't do that. I'm kidding. Um, man, there's so much to talk about that. I just, we'll have to get to some of your hacking tools in a, in a little bit. Actually, you know what? Screw it.

55:39I want to hear about you. You showed the flipper X on a YouTube video and how it works where you're sort of using this little device to create men in the middle attacks. You had another device that was a radio hacking device. So the flipper zero and the hack RF. Oh, flipper zero. Yeah. Yeah. Yeah. I don't have them in my pocket. Oh no, actually I do have a flipper in my pocket. Happen to be carrying that with you. That's normal. Yes. I'm a normal guy. Tell us a little bit about that thing. You don't have to demonstrate anything, but I'm curious. Like, I think a lot of people are going, wait, you have a hacking device that just happened.

56:08and you're at home and it's in your pocket. It must be useful. It intrigued me because it did a lot of things in a small package. Yeah, anyone right now can purchase one. The thing is that they're going to be disappointed when they buy it because it's limited to what software you're running. And if you don't know which type of software and which type of files to load this thing up with, you're very limited to what you can accomplish with it. I'll go through with the protocols. So it has NFC, which could be access control or doors. It could be... Key fobs, yeah. Think key fobs and other things like that.

56:40Key fobs, as well as your credit cards and debit cards, if they're tapped to pay, they have EMV, which is, this can read your credit card and give me your entire credit card number and expiration date just by waving it across your pocket if you don't have an RFID blocking wallet. It does NFC, it does RFID, which is similar to NFC in regard to the access control, and it's more widely used for access control than NFC. NFC could do more than that. But RFID, I believe, is also what's in your dog, if you have a chipped dog. I think most key fobs, at least the ones that I've used, are also RFID. Those little gray things you use to get into your apartment or whatever.

57:17Exactly. Yeah, they'll look like a credit card, but they'll be blank. And it's access, you know, it's a fob to get into your building or into, you know, office. It has the functionality to not only read them, but to emulate them. So if I go up to you, let's say you have a fob that gets into your office, and I copy that fob with the flipper, I can then emulate that same fob at your office and your door will think I'm you. It's a very low-skill attack, but this device is widely available. And you're as dangerous as the software that you install on it. So you have those two things and you have sub-gigahertz, which is, I believe it's with the firmware that I'm using, it's 300 megahertz to 900 megahertz, which is enough of a range to do car key fobs, garage doors, gates, It's, you know, even intercoms at Walgreens, CVS, Lowe's.

58:04Oh, really? Intercoms? I didn't think about that. That's funny. Well, you know, the buttons in the aisles where you're requesting assistance. Oh, yeah. You would capture the frequency with this device. Basically, you're recording it almost like it's a microphone for radio. You're recording that signal and then you're replaying it later on. And if it's a static signal, like it is at, let's say, a CVS in the cough and cold department. I got a cold right now. That's where I'd be going. I'd click the button, I'd ask, you know, and then someone would come. But the intercom would say assistance needed in the cough and cold department.

58:36But at that time, I'd be holding the flipper up to that device. I'd capture the signal, replay it. And then the intercom would do the same thing as if I pressed the button. That's funny. So you just walk into CVS and you're like, I know I'm going to need them to unlock the cold medicine. So as soon as you walk in, you hit the thing in your pocket and stroll right over there and the guy's waiting for you. Exactly. Or, you know, there's some files out there. like you know if you want to be like a nuisance there's you know cvs chaos walgreens chaos low is chaos where where it takes every single button in the store and some that don't even exist at certain locations and the intercom just goes ding ding ding ding ding ding and some of the buttons they can't go over to deactivate because the buttons don't exist in the store oh no it's right it's in the system that they have but the button's not active but it's still right take a signal oh God.

59:20Yeah. So the employees are like, we don't even have a cosmetics department in here. Like, why? I don't know how to turn it off. So then they probably have to go into the back to turn it off. So it does that. It does infrared, which I don't get TVs and air conditioners, soundbars, DSLR cameras, anything that uses infrared, which you'd be surprised a lot of things do. It can not only read and copy an infrared remote, but replay the signals a lot stronger than your average remote. So it does that as well as other access control stuff. Do you remember the TV? There was a device, not quite like this, but there was a device that - TV be gone.

59:56Yeah. That's funny. It read my mind. Wow. That device really can do a lot of things. No, that the TV be gone. Yeah. You'd push the button and it would just send like a universal, it would cycle off for 500 different TV models and turn off all the TV. And so does this. Even if you buy this off the website, you leave it with the stock firmware on it, it does have a universal TV remote where it cycles through all the major brands and you can turn the TV off, go through the volume, mute the TV, change the channel. It has that built into it by default. Yeah, sports bar chaos. Yeah, sports bar chaos.

1:00:32But when you start to put custom firmware, I'll give you one example. There's a specific type of firmware you can put on here. By the way, firmware is software for chips, like semiconductors. So people are like, what is that? Just think software and you'll be fine with following the conversation. It's ones and zeros. The correct amount of ones and zeros goes into this device. And then there's a version that, you know, if you press your garage door opener, normally that code would be a rolling code. A rolling code changes every single time that you press the button. So your garage door is expecting that next code.

1:01:04So let's say you're in your driveway, you press your garage door button and the code is 123456. The garage door says, okay, that's a valid code, I'm going to open. And now 123456 is no longer a valid code. 123457 is a valid code and that's the next one in the sequence. But it's a little more complex than that. But if you get my point, it changes every time you press that button. Cars use that and stuff now, or they're supposed to. Exactly. Some key fobs do that and garage doors do that. And many things use rolling code systems. but a few of the major brands like security plus i believe 1.0 2.0 and i think it's came came have been broken by some firmwares on this device specifically so if i capture one of your garage door attempts one of your when you press the button i capture it i now know the next sequence i know you know forever i can continue to open your garage over and over and over again with just one capture the way that you would kind of know somebody's doing that to you is if they open your garage door and you click your button, your garage door doesn't open, you know that it's out of sync by one.

1:02:07You click it two times, then it starts to work and you know that it's out of sync by two. If I open your garage door five times with this device, then you got to click your garage door opener six times for it to be back in sync. That's very interesting. I know back when I lived in Hollywood, there was a notice kind of going around. We didn't have Nextdoor or whatever, but there was a Facebook group and it was like, hey, don't park your car in your driveway, which is impossible because people don't have big garages, especially in the Hollywood Hills. But there was this gang of, it turned out to be like Russian gangster kids.

1:02:37They would ride around in Range Rovers. You'd see them on surveillance cameras. They would stop and park and suddenly like a BMW door trunk, whatever would open. And the guy would run in, ransack the car and leave. There was somebody in the car with a laptop or whatever, some sort of device that would just go through and try every possible code for the FOBS, whatever, the RFID, whatever it was using. That would be considered a brute force attack. Yeah, it was a brute force attack, yeah. They would know the right frequency to send. They would know exactly what to send, and then they would loop through.

1:03:09Let's just say it was an 8-bit code, and they would just go through each one until it opens. And there's a more advanced way of explaining it. There's a thing called a De Bruyne sequence. It would make that time a little bit faster, well, a lot faster than going just one. two, three, four. You know, that's a little more technical. If you're interested, look into roll jam attacks, which is how you can abuse rolling codes without having to actually crack the rolling code. They're called roll jam attacks. And if you're interested in the DeBruyne sequence, there's something cool by a hacker, Sammy Kamkar, who made this awesome kid's toy into a garage door opening machine.

1:03:46That's funny. It's super interesting stuff. You should check it out. Hackers, man, are so interesting. I remember one of the talks at DEF CON, again, this is probably like almost 10 years ago now, maybe even more. There was a guy who had a similar-looking radio device, and it could broadcast aircraft IDs. Well, it could read and broadcast aircraft IDs. Yeah, so my hacker ref does the same thing, and it's called an ADS-B. So ADS-B is what you would be receiving on, and it will give you the call sign of the airplane. It will give you their altitude. It'll give you the location on the map. And there's an option as well to transmit ADS-B, which is not legal, I'm guessing.

1:04:25It's definitely not legal whatsoever because you could represent to, let's say, I live near an airport. So a small plane could believe that you are at whatever altitude with this call sign going in this direction. And you could cause a problem. You know, that's kind of dangerous. But something like that is available for anybody to do if they have the right knowledge or, you know, They spend some time trying to learn how to do that stuff. So one of the talks at DEF CON was a guy who, a hacker saying, hey, we got to be careful because I got an antenna and this device and this, I don't know, is it like he laid up on top of Google Maps or MapQuest or whatever was available at the time.

1:05:03And he's like, look, here's all the planes in the area. And he's like, what if we simulate by spoofing two or three or 23 planes that aren't there and we put them near an airport? It's pure chaos. What happens if we do that and we put them near buildings? This is after September 11th, of course. You cause massive terror. Okay, now what happens if I put them heading towards the White House? And it's like now we have a military response potentially, or at least they're going to have to make sure that that's an error and those aircraft are not actually there. But talk about terrifying huge numbers of people.

1:05:38Yeah, you could cause mass panic with such a small, simple, easy to set up thing that, you know, a consumer can buy, you know, it's not really talked about often and I'm not going to explain how to do it either. But, uh, you know, it's, it is scary to know that there is, there's criminals out there that don't know much about computers and can take this interview. They'll do their own research. And I hope that they, uh, you know, that they, they don't figure out how to do stuff like that. I'm thinking, look, most of the people who are creative, smart enough to figure reverse engineer, what we're talking about are people who could either figure it out on their own or are going to have better things, hopefully better things to do than that.

1:06:18I would hope so. Yeah, I would hope so. I believe that you're right there too. I mean, most of the time, the smartest people that I know are not criminals. No, there's more money to be made in legitimate operations. And if you really want to be kind of criminal, join the freaking NSA already. Yeah. Yeah. Get permission. Right. You get permission. At least you won't go to prison. I've got some thoughts on this one, but before I get into that, I wanted to give you a preview of one of my favorite stories from an earlier episode of the show. Megan Phelps Roper, she used to belong to one of the most hateful religious cults in America, the Westboro Baptist Church.

1:06:54She was born into this church and she later escaped. To hear her tell the story firsthand is really incredible. I started protesting when I was five years old, but even at that first picket, there was a sign that said, gays are worthy of death. So God hates fags is what Westbrook's message that we became known for. We were the good guys and everyone outside the church was evil and going to hell. And we had the only message that would bring the world any hope. We had to go and warn people, these terrible things are happening. And if you want this pain to stop, then you have to change because God isn't going to change.

1:07:30After the September 11 attacks, we had the sign that said, thank God for September 11. What were we thinking? This massive crowd comes down. We were at this corner of this intersection of these three streets. By the time they actually reached us, we're just enraged. There was no space between us and them. It got really dicey. One of my cousins gave his signs to somebody else and like started standing on top of a trash can pretending like he wasn't with us. They were, again, incredibly intense because obviously the circumstances are so sobering. It brings me incredible sadness to think about now.

1:08:05I can't do this forever. My family, they would refuse to have any contact with me at all once I left. Somebody that we had confided in sent a letter to my parents and told them that we were planning to leave. And then that email came in and we left. For more with Megan, including the details of her harrowing experience and escape, check out episode 302 of The Jordan Harbinger Show. All right, that's it for part one. Part two coming in just a few days, if it's not already out by the time you hear this. All things Ryan Montgomery will be in the show notes at jordanharbinger.com or just ask our super smart, all-knowing AI chatbot.

1:08:45Transcripts in the show notes, advertisers, deals, discounts, ways to support the show, all at jordanharbinger.com slash deals. I've said it once, but I'll say it again. Please consider supporting those who support the show. And yay, newsletter folks, highlights, takeaways from the most popular episodes of the show going all the way back. Jordan Harbinger.com slash news is where you can find it. And I will reply to you if you reply to me there. So you can send me snarky comments and passive aggressive feedback. Jordan Harbinger.com slash news. And don't forget about six minute networking. Also at Jordan Harbinger.com slash course.

1:09:19Basically everything's on the website. I'm at Jordan Harbinger on both Twitter and Instagram or connect with me right there on LinkedIn where all the not crazy people are because you can see their names. That's got to be it, right? Twitter, crazy, Instagram, crazy, LinkedIn, people behave because you can report them to their boss. At least that's my running theory. And it's why it's the one of the only acceptable places to even have a conversation online these days. Unfortunately, this show is created in association with podcast one. My team is Jen Harbinger, Jace Sanderson, Robert Fogerty, Millie Ocampo, Ian Baird, and Gabriel Mizrahi.

1:09:55Remember, we rise by lifting others. The fee for this show is you share it with friends when you find something useful or interesting. The greatest compliment you can give us is to share the show with those you care about. If you know somebody who's interested in the dark web, hacking, social engineering, or just needs a wake-up call about what kind of gross people are out there predating, definitely share this episode with them. In the meantime, I hope you apply what you hear on the show so you can live what you learn. And we'll see you next time. This episode is sponsored in part by Conspirituality Podcast.

1:10:25You know how I'm always talking about critical thinking and spotting manipulation? Well, there's a podcast that's all about dismantling New Age cults, wellness grifters, and conspiracy mad yogis, basically the wild overlap of spirituality and misinformation. It's called the Conspirituality Podcast. The hosts, a journalist, cult researcher, and a philosophical skeptic dive deep into how this stuff spreads from Project 2025 and the Heritage Foundation's dystopian vision of the future to how former leftists get pulled into far-right conspiracies. An interesting episode to check out is called Speaking Truth to Goop, where Jen Gunter breaks down the pseudoscience behind the wellness industry in a way that is super entertaining and eye-opening.

1:11:02It's sharp, funny, and makes you a lot harder to fool, which, if you listen to this show, you know I'm all about that. From exploring cults to analyzing our cultural and political landscape, The Conspiratuality Podcast will help you stay informed against misinformation and resist fear tactics. Find Conspirituality on Apple Podcasts, Spotify, and wherever you get your podcasts.

From the publisher

Ryan Montgomery (@0dayCTF) is a professional cyber security specialist, the founder of Pentester (JORDAN15), and an ethical hacker known for exposing online predators. [This is part one of a two-part episode. Watch this space for the second part later this week!]

What We Discuss with Ryan Montgomery:
  • What kind of background creates an ethical hacker?
  • For that matter, what is an ethical hacker?
  • What is the difference between white hat, gray hat, and black hat hackers?
  • Do ethical hackers make more money than hackers who are less than ethical?
  • What is a Flipper tool, and what can it be used to hack?
  • And much more...

Full show notes and resources can be found here: jordanharbinger.com/851

This Episode Is Brought To You By Our Fine Sponsors: jordanharbinger.com/deals

Sign up for Six-Minute Networking — our free networking and relationship development mini course — at jordanharbinger.com/course!

Like this show? Please leave us a review here — even one sentence helps! Consider including your Twitter handle so we can thank you personally!

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

More from The Jordan Harbinger Show

All 575 episodes
851: Ryan MontgomeryThe Jordan Harbinger Show · 1 h 8 min
Listen in VO