That Tech Pod
Welcome to That Tech Pod, a podcast co-hosted by Laura Milstein, Gabi Schulte and Kevin Albert. Each Tuesday, That Tech Pod will feature in depth discussions about data privacy, cybersecurity, eDiscovery, and tech innovations with heavy hitters in the industry. Subscribe so you don't miss an episode! Visit thattechpod.com for more information.
That Tech Pod
Why You NEED Legal Help For Any Cyber Emergency With Attorney Kevin Adler
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Today on That Tech Pod, Laura and Gabi speak with Kevin Adler.
Kevin Adler is a Cybersecurity & Data Privacy attorney who helps businesses, local governments, and individuals understand and navigate the legal issues posed by new technologies and cyber threats.
Using his experience with the Cybersecurity and Infrastructure Security Agency (CISA) and other federal agencies, Kevinprepares clients for the eventuality of a cybersecurity incident. Even in the absence of a direct threat, understanding the legal issues behind new technologies can be difficult for even the most sophisticated organization. Throughout his career, Kevinhas worked with new technologies and found inventive ways to serve his clients within existing regulatory frameworks.
Before joining Woods Rogers in 2021, Kevin won a Presidential Management Fellowship (PMF), where he took part in the U.S. government program aimed at getting individuals with unique skills into leadership positions across the federal government. As a Fellow, Kevin worked in the Department of Homeland Security Countering Weapons of Mass Destruction (CWMD) and CISA. At CWMD, he advised the Department of Homeland Security’s Securing the Cities, BioWatch, and Chemical Defense programs on intergovernmental agreements. At CISA, Kevin provided counsel for the CISA COVID Crisis Action Team and provided legal support on regulatory, intelligence, chemical security, cybersecurity, infrastructure security, legislative, unmanned aerial vehicle, and supply chain security issues. Kevin holds a Secret clearance and has previously worked on Top Secret and Sensitive Compartmentalized Information (TS//SCI) programs and projects across the federal enterprise.
Kevin graduated cum laude from the University of Nebraska College of Law with Concentrated Areas of Study in Space, Cyber, and Telecommunications Law and International and National Security Law. After graduation, Kevin supported NASA Kennedy Space Center’s Launch Services Program (LSP), where he assisted in providing legal advice to program officials.
Kevin grew up in Omaha, Nebraska, and graduated from the University of Nebraska-Lincoln cum laude with majors in Political Science and Global Studies. He also was an Intelligence Community Scholar Distinguished Graduate. During law school, Kevin was a finalist in the North American Round of the Manfred Lachs Space Moot Court Competition and interned with the United States Navy Judge Advocate General, United States Strategic Command (USSTRATCOM), and externed at the Department of Defense Office of General Counsel International Affairs at the Pentagon.
Hello and welcome to that tech pod where we discuss all things e-discovery, cybersecurity, data privacy, and tech innovations. I'm Gabby Schulte. And I'm Laura Milstein. And you know, we bring on heavy hitters in the industry every week to help us break down all of those topics. So today, Laura, who are we talking to?
SPEAKER_00Today we have a very special guest. Um, not to take away from all of the special guests we had before, but I'm really excited about this one. We've done a lot of episodes around data privacy and cybersecurity, and we typically are doing it for people that are in the weeds on it, but today we have a legal twist to it. So today we have Kevin Adler. Kevin is a cybersecurity and data privacy attorney who helps businesses, local governments, and individuals understand and navigate the legal issues posed by new technologies and cyber threats. Kevin uses his experience within the Cybersecurity and Infrastructure Security Agency, CISA, and other federal agencies. He prepares clients for the inevitability of a cybersecurity incident. Even in the absence of a direct threat, understanding the legal issues behind new technologies can be difficult for even the most sophisticated organization. Throughout his career, Kevin has worked with new technologies and found inventive ways to serve his clients within existing regulatory frameworks. Kevin, I could go on and on about your bio and deep dive into the fact that you, you know, came from Nebraska and are, I believe, now in DC, but I think I'll let you kind of get there. So I just kind of want to welcome you to the show and tell you that I'm a big fan. Yeah.
SPEAKER_03Well, Laura Gabby, thanks for letting me on. I just want to say I'm a big fan of you guys. I've been listening to your podcast for a while now.
SPEAKER_00Um I'm blushing. I'm blushing. Yeah. Yeah. So nice.
SPEAKER_03Uh yeah. I although like that's the stuffy lawyer copy right right there. I uh I've had essentially just a very exceedingly high number of very fake sounding jobs, and I've been in a lot of very fake sounding workplaces. Uh so my background is in cybersecurity and privacy law, uh, which started at the University of Nebraska College of Law, where I had concentrated areas of study in space, cyber, and telecommunications law and international national security law. Spent most of that time working for Uncle Sam. Uh, after law school, I worked for NASA's launch services program where I helped buy rockets and deal with weird space problems within the structure of American government. Uh, I mean, the way that we buy rockets is with the federal acquisitions regulation, which is the same way that we go buy janitorial services. It's just a different type of service.
SPEAKER_01Who would have thought? That's that's a good uh trivia fact that you can bring to a party.
SPEAKER_03One of the most interesting things I saw while I was there was like John Glenn's travel voucher because he traveled on official travel to space over meal time, and so he was guaranteed per diem because he's a federal employee. I think he got like a buck fifty for lunch.
SPEAKER_01Um how much does lunch cost in space?
SPEAKER_03Well, the thing is, uh, they they were running late and he actually missed lunch, and so he snuck a sandwich on board to their rocket.
SPEAKER_01Oh my god. Uh we need to learn more about that. That's amazing.
SPEAKER_03But yeah, weird space trivia aside. After that, I I went to Washington and I worked at as a president management fellow uh with Department of Homeland Security, and then later with SISA, the cybersecurity infrastructure security agency, where I did critical infrastructure protection. And now I'm at Witch Rogers, where we help uh all whole host of people, both before, during, and after cyber incidents, um, helping them get identifying all their problems and their legal risks and dealing with that within the context of a cybersecurity incident and dealing with the fallout that comes from that. We it's a really rewarding type of work because now I get to work directly with state and local governments as they uh deal with these growing waves of cyber attacks that are impacting the services to and to their communities. And I get to be there to help uh minimize any impact that these types of transfere incidents or funds transfer frauds or whatever uh have on these communities from across the US.
SPEAKER_01That's super interesting. And one of the reasons why we wanted you to come on specifically is because we've had a lot of people with cyber backgrounds that are from the tech uh tech perspective. And we talked a lot about, you know, the implications and how to what do you do to boost up your security and all that stuff. Um, but we want to know from you like what where does the legal side come into it? Um and yeah, Laura, if you want to add on to that, go for it.
SPEAKER_00For those of you who are wondering, the pause, I was really thinking, or my thing was on mute. Either way, the decision is yours there. Um but yeah, I agree with that. I think we don't want to hear about how you're not secure today. We don't want to hear about like, oh, uh, cybersecurity, don't pay the hackers. Today we really want to dive into why is a lawyer even involved? Like, well, how how do you put go into play here? So, like, I'm a corporation, somebody has hacked into my system. Great. Why am I calling you, Kevin? Can you kind of dive into that? What is your role? How do you advise people? Just tell us more about that aspect.
SPEAKER_03Yeah, no, I'm really happy to. And I I think from uh across technology disciplines, they're like, ugh, I have to talk to this lawyer guy. Like, I already talked to enough people with glasses. Why do I have to talk to this guy with glasses who is has an A Sally voice and is talking at me? Um, and and and the reason why uh is not just because I have glasses and a voice that's not fitted for a podcast, but really because we live in a legal world. I think a lot of people in technology, especially people dealing with new technologies or novel uses of old technologies, um, forget that the whole world around them still exists, and that just because you use a new word or just because your fact pattern might be new or different, it doesn't mean that all of the other law around you governing everything else in the world doesn't directly impact you. And that's kind of why I'm there. I'm kind of there for two main reasons. One, there are tremendous legal implications to how an organization deals with any type of cyber incident, with regulation, law, federal law, state law, in some cases, international law, uh, as well as more importantly, to a lot of corporations, the contracts. What have you agreed to? Uh, if you've if you're uh in the C-suite and you've signed an agreement with a vendor in the past six months to a year, I almost guarantee you that there's probably a confidentiality clause in there about just what happens if you disclose their non-public information or a specific data protection or information protection thing in there. So, like being uh existing in the world is an inherently legal thing, and the outcomes of cyber attacks are inherently legal. Um, every state in the United States has its own special flavor of data breach notification law. Uh, there's currently an attempt by the federal government to um supersede some, but not all of them. Uh, I don't think that law's gonna pass, or if it has, cut that out of the podcast. I don't know when this is gonna go to air or when that's gonna go out of committee.
SPEAKER_00Noted. This should probably this is probably gonna air tomorrow when you talk about it.
SPEAKER_03Yeah, obviously. This is this is all cinema verite. There's no editing at all. This is exactly as I say it, as it comes out. It's all extemporaneous, real, raw.
SPEAKER_00Kevin, I like that you say this, but in reality, we like barely edit. And it's not even because we think it's like better for people, it's probably more laziness.
SPEAKER_03You know, it some could people call that laziness. I call that a feature. It's called honesty. Oh god, the romance. I love it, love it. Um but the the second aspect of of why a lawyer is even in this room at the be at all is comes with the unique part about talking to lawyers is the attorney client privilege. We've already established that if you have a cyber incident, you have a legal problem. And if you don't have the attorney client privilege, guess what? The people who are the result of that legal problem get to find out everything that you've done. Uh, this is most clearly seen fairly recently with uh Capital One. Capital One, as you guys know, a giant bank based in Washington, DC. Um, they had a pretty bad cyber incident, they have a lot of lawyers, and they hired a very well-known incident response team to deal with it. Their board was like, uh, this is bad. We want to know why this happened. And so they asked their incident response team what happened and why did this happen. And the incident response team got this request from the board and was like, Oh, yeah, well, this happened because you were bad at cybersecurity. You did all these, you had all these problems, you did all this wrong, and then this happened, detailed how much Swiss cheese the bank was was made out of. And they got sued by their shareholders. And guess what? The shareholders got that document. Why? A lawyer was copied on the email, but it wasn't done at the direction of counsel for the purpose of providing legal advice. And that's a fancy lawyer, important legal phrase for y'all to kind of understand that the attorney-client privilege is for the attorney to understand and provide legal advice to you, the client. Anything outside of that isn't really protected or is under a far lesser privilege. And so in the case of Capital One, there this is just like the board asking Laura how her weekend was. That's not privileged. You had a great time doing something, I'm sure.
SPEAKER_00And they know I was with Capital One this weekend.
SPEAKER_03I know my weekend. So because that wasn't privileged, all of that dirty laundry got out. And when you're in a crisis, you need space and time to think and speak freely. As well as the fact that as you need somebody to understand what's legally important for you to do for your various legal responsibilities. And so when I do cybersecurity incident response, a lot of people think when it comes to attorneys, that like, oh, there's just a lawyer there, they're on the email, it doesn't matter. Uh, that's not true. Things have to be at my direction. And so a huge part of my job is essentially IT project management because what may be forensically interesting for a cybersecurity incident response firm probably isn't necessarily legally important for us to know or deal with when we're trying to figure out what the companies or the businesses or the counties' legal obligation is to its citizens, its stockholders, um, its providers, its vendors, who's its customers. Um because, like, oh, we can say, like, oh, that server's bombed out, but we know on that server it just had the softball pictures for the company baseball team. Who cares? Um but we need to know this server over here where they have all of their customer information or that has a comp impact to hit a part two or whatever. Uh, and so you really need to have someone with a legal understanding driving the ship. Just make sure that you get the answers that you need to fulfill your legal obligations and to make sure that all your dirty laundry doesn't come out once those legal obligations come to roost.
SPEAKER_00So, uh, Kevin, to follow up with that, um, outside of this podcast, I work in cybersecurity, discovery, that kind of field, hence why nerd on the show that loves this stuff. And one of the things that I always do on the vendor side is when I have a client that comes to me and says this happens, I will ask them immediately, you know, do you have legal representation? Where are you at these points? So that I don't I make sure not to put them in a position that they should not be in. Do you think in a situation like that any fault goes to the vendor? Do you think fully the capital one is the client in this example should know better? Should they know automatically go to the lawyer first? Is it any fault of the lawyer to tell them when you do these things, this, this, and this? How do you kind of know when uh how to how to who to approach and when? Because I'm thinking if I'm a corporation, this happens. My immediate thought is I need to stop this now, I need to fix this now. How do I do it? I can understand why a lot of people sometimes immediately call vendor. Um, and that's why we ask them these things and kind of go through that first. But I recognize that not all vendors do that. What advice do you have in a situation like that for the corporations or for somebody in that position?
SPEAKER_03Well, I mean, in the case of somebody like Capital One, they should know better. They're like one of the largest corporations in the world with probably teams of very fancy lawyers that could be able to tell them the answer to this question. But uh we I deal with companies and organizations and communities of all sizes and all levels of sophistication, from large Fortune 100 companies with teams of cybersecurity analysts and intelligence experts to uh communities where their HVAC technician is their head of IT and their air conditioning is also not working. Um actually happened. But the the big thing is when it comes to these types of things, pre-planning is important. And people talk about incident response planning. And often what people talk about is that they make a paper plan about some type of technical response. And that's not really what incident response is, that's not what really disaster response is, that's not really what planning is. You need to plan an organizational response. Who's going to talk to what? What are people's roles, and who do you rely on? And when you have a cybersecurity incident, who you rely on, I think is really important. A lot of people have cyber insurance if they haven't had to renew recently. Cyber insurance has gotten exceedingly unaffordable and very expensive for a lot of people. But a lot of people have cyber insurance, and who you get from that cyber insurance, unless you specify, can be the luck of the draw. You can get an amazing cybersecurity incident response team and an amazing cybersecurity lawyer, or you can get people who work volume and your number 7,000 that they have to do this week. So it it all depends. And I think one of the most important things you guys what you what an organization needs to do is to think about this beforehand. Uh, I I mean, most people say, Oh, I should have thought about this after before my thing were we're hit. Uh, but and in the moment, come just calling an Andient, calling some big cybersecurity incident response team is really understandable. And at that point, it's probably fixable. The fact that you had an incident probably is something that's going to get out anyway. But how you deal with it, how bad it is, that can all be covered up with a call to an attorney who can then take over the management of that organization and bring that incident response team or that vendor or whatever under their wing. I mean, we do a lot of work where once we parachute in, we find out that the client has already called half the town or and brought in six other vendors who are all trying to do something. They're all generally not doing a very good job of any of it. But once if you have an expert, you they can assess the situation, minimize damage, minimize the risk to the attorney client privilege and the information that would be really bad if it got out right now and allow the can allow the client to be able to maneuver from there from crisis to post-crisis.
SPEAKER_01The potential impact of cybercrime requires that cybersecurity be viewed as a business risk rather than a simple IT issue. Just as with external threats, companies cannot mitigate internal risk simply by out-designing or out-developing malicious actors. Instead, a growing number of organizations are setting up dedicated insider risk teams to aggressively address insider risk before it strikes. By having a solid insider threat mitigation strategy in place, organizations can detect risks early on and analyze them before critical data or personnel information is compromised. From incident response to forensic investigation to litigation and regulatory response, EY Privacy and Cyber Response Professionals assist organizations to fight and prepare against the most challenging cyber attacks. Check out the latest thought leadership paper from EY on how leading organizations tackle insider risks, where it highlights strategies to defend against insider threats and how organizations can manage risks. More information can be found at eY.com slash forensics. So you talked a little bit about some examples, um, and obviously you mentioned the the HVAC uh person, but can you tell us like some an example that either something that you know or it's a hypothetical that you just like know can happen, but like really try to scare us here because you know we're we're talking about legal, yeah, the legal aspect of it, just just scare the pants off our listeners right now.
SPEAKER_03Well, so that this isn't necessarily a legal thing, but it I I want I'm I'm reaching out to all the people in charge of contracting, all the people in the C-suite. Um I deal a lot with public entities, um public entities of varying sizes and varying levels of sophistication and funds. And I've gone into situations where these entities are paying a lot of money for what should be very good services. The solutions that they pick make a lot of sense for what they want. Um the tools that they're using really are supposed to be the really good tools, and we get there and we find out that this backup uh appliance that they bought didn't work because no one plugged it in. Or uh we jump into a place and it's bombed out with ransomware and we can't get to the face. We can't get to the firewall. Not because the threat actor got to the firewall and compromised it, but because the vendor forgot what the password was. And I I I'm saying these things because that's me.
SPEAKER_01That's a hundred percent me. It is, Gabby.
SPEAKER_00It is like uh those of you who are listening, we have different passwords for basically everything in our tech pod, and I am very keen on changing them like too often. And Gabby can never remember. She will constantly be like, What's the password? And I think it's my fault because I change them all the time, but I think it's her fault because I'm like, How? How do you not know this one?
SPEAKER_03I just don't know. Yeah, but you're not providing cybersecurity to a public school. Uh not yet.
SPEAKER_00You don't know what that tech pod can do.
SPEAKER_03I I I guess you know what, like this not as limit for ambitions, although I would recommend a password manager or or some other type of solution for you guys if that is your ultimate goal. But but the thing is, like what I I say these stories because you don't know what you have unless you check it and unless you exercise it. Um that's not a legal thing, that's an organizational thing. And what we've seen time and time again across both corporate and non-corporate environments, ransomware is the first time the CEO or anyone from the C-suite has really had a real conversation with anyone from IT or the CISO's office or the CTO's office. And although many of these executives aren't necessarily technology people, um, they can smell BS from a mile away. And now that they're within a mile of their IT department, they realize that this guy that they've been spending a lot of money on uh hasn't done anything since making them Y2K compliant.
SPEAKER_00Um, Kevin, I want to switch to a different thing and the podcast today. It's um called Game Time. And what we're gonna do now is play two games with you. So the first one is called Fuck Mary Kill. Um for those of you who are listening, this game is where we typically it's done with like people or other things where we would name three people as an example, and Kevin would have to decide who he's gonna fuck, who he's gonna marry, and who he's going to kill. But we're not gonna use people today. We're going to use e-discovery, data privacy, and cybersecurity. Fuck Mary Kell.
SPEAKER_03Uh I'm gonna.
SPEAKER_00This is for the rest of your life. Rest of your life.
SPEAKER_03Yeah, no, that the I this is this is I already know the answer to this question. I don't really curse. I would have made my my stories a little bit more spicy. But um but yeah, uh, I would uh kill e-discovery, uh, I would marry cybersecurity, and I'd fuck privacy. Uh that that's a I think a very good description of my practice. That is perfect. Uh I don't really do e discovery. Uh my background is in national scriptula.
SPEAKER_01Everyone kill e discovery.
SPEAKER_03It's very important.
SPEAKER_00I love e discovery, but I think I would have to make that decision as well.
SPEAKER_03There are other members of my team that are experts in e discovery, so I don't have to be. Uh America's about specialization in trader.
SPEAKER_00Yeah. Gabby um is keen on it. It's my least, it's my least I love e-discovery, but I do think when it comes to importance of those, unfortunately, that is the easiest one to kind of push into one of the other categories. So I would just find ways to do it in other areas. Right.
SPEAKER_03But I mean, if you if you have good privacy and cybersecurity practices, you're going to have good e-discovery practices. I mean, like it's, it's, these are all intermingled and related and incestuous practices because they all really do flow into each other. Because you have the cybersecurity event, which is why you're going to have litigation. But if you have privacy and security controls in place, you're going to have the data retention things and the other types of tools you'll need to recover data, to prevent the dis unlawful disclosure of data, and to hopefully not keep data too long that it would actually respond to the discovery request when you have to provide a litigation hold onto it.
SPEAKER_00You're not wrong. Are you ready for the next game? This is the final game today. I'm surprised my mind. Okay. I know that's what I'm going for. Okay. This game is called Would You Rather. Okay. So for our listeners, if you've never played Would You Rather, it's where two scenarios are put on play and you have to choose one of those. Okay. So Kevin, would you rather? All of your information has been given to Clubhouse, the app. Do you know the app, Clubhouse, before I continue?
SPEAKER_03Uh it's like it's a semi-anonymous thing, right?
SPEAKER_00So Clubhouse is um basically like where you can go on and like live podcast with people or live do a book reading or just talk to people, but like live in the app. And there's a lot of confrontation around it because they say it's not very secure and you shouldn't.
SPEAKER_01So we don't go on on I think you have to be invited, don't you?
SPEAKER_00Yeah, you have to technically be invited. No, we refuse to do it because like the privacy laws scare us. And so we don't use Clubhouse at this time, but a lot of people are really into it. Um, but would you rather all of your information is leaked on Clubhouse? Everybody knows what's going on with anything that you don't want to happen. It's out there, it's in Clubhouse. This is crazy. And you can potentially get your data back, but you unfortunately hired a really bad vendor. You maybe like I I am nothing against Mandiant, but you named them earlier. And I believe they're recently acquired by uh Microsoft. So during this acquisition in this fake scenario, if this is real or not, I don't know. There this happens and they're going through this crazy thing and they just forgot about you. They totally forgot about you. So for like three years, your information is lost out there. You didn't bother hiring anyone else. It's crazy. So that's scenario one. But in this scenario, at the end of three years, you get a book deal. I don't know how much it's for, but you get a book deal to describe this. So there's a plus there. But it losing all your data, anything could happen in those three year spans. Or would you rather all of your data is a leak to TikTok? Everything is in TikTok, all of your stuff is there. You again, I don't know what your problem is. You hired a bad vendor during a weird acquisition, and things just got messy. You didn't even, as a lawyer, you didn't even ask for your own advice, and your stuff is just loose in TikTok. And at the same time, in this TikTok one, when your data was taken, so is your mom's. That's horrible. Your mom's data is out there, and like your mom's a lovely lady, and her stuff is in TikTok as well. So now there's a risk. And at the end of this, you don't get a book deal, but Kanye West does make an entire album around what has happened around you. And you don't get any royalties to it, but Kanye West has made this, and now you're out there, good or bad, that Kanye did that. What do you choose and why?
SPEAKER_03These are some very convoluted scenarios. Exactly. Um but uh I I would I would I would say that TikTok one, because that already kind of reflects my current life. Um, my uh uh my information has already been stolen by the Chinese multiple times, and all I got was credit monitoring from the federal government.
SPEAKER_00Um the best thing to get credit monitoring, yeah.
SPEAKER_03Uh it is it it's the easiest, cheapest way to avoid a lawsuit. Um no, uh no, but in in all seriousness, uh yeah, I mean, I was I, along with everyone else who was ever associated with the United States military or the federal government, uh, and any dependence thereof, which is how I got wrapped up into it, um, got all of their stuff swiped up with the OPM hack in 20, whatever. And then another one after that, which was both likely believed to be the Chinese. So that's already kind of my life. And I don't like Kanye's later work anyway. So I wouldn't care if he rapped about me.
SPEAKER_00Um that's why I used him. I was just like, would I for that? Like, yeah.
SPEAKER_03I mean, like, there's some good tracks on Donda, but like it, I I like like college trap out more. I it's it's it's not bad. I just like his earlier work better.
SPEAKER_00On the like through the wire is a classic because he actually did it through the wire, and it's great. That's the best Kanye song ever made. I don't care what anybody says, it just is. Sorry, it is.
SPEAKER_03Um, but but but but regardless of that, um yeah, one one thing a lot of folks need to think about TikTok is that although the Trump administration went about talking about TikTok in probably the worst potential way to have talked about it and went about trying to deal with it in a very inartful way, which is kind of emblematic of their regulatory approach to a lot of different things. Um whereas a lot of their attempts were maybe malevolence tempered tempered by incompetence. Uh, here it was um national security tempered by incompetence. Uh TikTok I mean, as as recently as I want to say yesterday, I read an article. Um all of their data is taken from their users. And what exactly what data do they actually take, the extent of that data is unknown, but they take a lot of information and all goes back to Beijing. I mean, that is both a requirement of how kind of TikTok works because it's heavily algorithmically based, right? And that algorithm lives, breathes, and is monkeyed with in China. Um and what they can do with that data legally in China is anything. The the Chinese uh uh government has a series of data laws and national security laws that essentially allow them to demand at will without any real judicial due process like we have here in the United States, any type of information from any company that holds any type of data of any value. And so they could be doing whatever they want with your data. And I I find that fundamentally different than how people talk about FISA in Section 702 here in the United States. There's there are problems with the way there are not problems, but there are criticisms that you can make about US intelligence collection for foreign people, but when it comes to collection on US persons, um there's a level of judicial due process where someone has to go to a court and make a case and obtain a warrant to collect the information for a clear national security purpose aimed at not you. Um which none of those judicial rules exist in China. The concepts that we talk about in the United States when discussing Chinese law isn't is that China isn't really a rule of law country. Uh the phrase that we use to kind of describe it is different laws for different people at different places at different times, which means it's which means it means you lose if you have a problem there.
SPEAKER_01So answer me this. Um for the average user of TikTok, who's somebody like you know, I you know, I just go on there for 20 minutes and I'm just like spare, you know, killing some time. Um for the average uh user, what is the risk of, you know, when you say like China has my data now, like why should I care about that?
SPEAKER_03I mean, why should you care about that? I mean there's there's a level of it, rather about it. I I mean like from like a social conception of it. I mean, TikTok is already well known to suppress to suppress speech that is negative to China or things that the Communist Party of China doesn't like. Things like democracy and oppression in Hong Kong, the genocide of Uyghurs, the the war in Ukraine and Russian war crimes there as well, uh, while promoting things that the Chinese government likes, which are isn't the this this Chinese government party system great, everyone's so happy here, everyone in America is so unhappy. And even though maybe us three are very unhappy or very happy here in the United States, I don't know.
SPEAKER_01Um depends on the day.
SPEAKER_03Depends on the day.
SPEAKER_01Um depends on the alternative location.
SPEAKER_03The there are there are problems with them as a platform as a whole, but on top of that, the what they're using their data collection for is unknown. They've previously stated that they weren't they stopped doing that, that they stopped sending data to China. And we've discovered recently that they never stopped. And based off how their technology works, I don't think they like it. They can stop. Uh yeah, I mean this is an unfair and deceptive practice. Um the FTC has gone after uh people for far smaller actions, and we don't know the full extent of the types of data that they're collecting or even when they're collecting the data. Um, there's been a long history of supply chain attacks by Chinese companies for hardware manufactured in China, where they've installed from the hardware uh spyware to see what people are doing, sending back information to China. This has happened with cameras, this has happened with uh computers, and you don't know when they're tracking or what they're tracking. And when it comes to TikTok, I mean they may have uh established policies, they may have stated this is what we collect and this is what we don't collect. But given what we've already discovered, that information is still going back to China, I think that there's a level of skepticism, at least for me, that what it says it's doing is the only thing that it is doing. And if someone can forensically prove me wrong, then I'm wrong. Uh I I haven't seen the source code of whatever they do. But it's there's a lot of unknown unknown here, which doesn't exist with a lot of other technology companies. Or even with other technology companies that might be collecting things that we don't like or we don't want, we can go take them to court uh here in the United States, where there's a level of rule of law where you can get whatever is due to you if there's any damages that you can prove. Or if you can't do that, your state attorney general or your um or the FTC can go after them and find them a huge amount of money. Or in the European Union, the if you're there, uh the European author regulators love going after foreign companies for for collecting people's information and then moving it offshore. Uh they haven't done it with to TikTok or any Chinese companies yet, to my knowledge, but they find Google billions of dollars for doing the same type of thing in a much more transparent way.
SPEAKER_00Yeah. Uh we actually are doing an upcoming episode around TikTok, and we may have to invite you back on to join us for that one. Um, because there's just so much to dive into when it comes to TikTok and and what's going on with everything in that. And it and it's interesting, scary, exciting to an extent. Like uh for the Gen Z people, they're like, this is incredible. And for the millennials and above, we're kind of like, is it? Um so I don't know. Like you guys remember Vine? Uh yeah, I remember Vine. It was like really hot for at least six months.
SPEAKER_03Yeah, that's kind of what like someone from my high school became like Vine famous.
SPEAKER_00Um and did you really make it if you're Vine famous though?
SPEAKER_03I don't know. He he got a Game Boy game, I think. Um he made it. He made it. Yeah, he's a DS game. I'm jealous. Um but I I mean that the format's kind of the same. I uh I mean I I'm clearly not cool. I'm a computer lawyer. I I don't know how less cool I could get, but computer lawyer. I like it.
SPEAKER_00I'm not with culture. You're cool to us. You're cool. We wanted you on here because of your your cool degree. Anyone who self-identifies as cool is not cool for us. If you're like, I don't think I'm cool, I'm like I don't know, Laura. We're self-voted the best podcast, the number one tech podcast in the fucking world. Like, actually, I heard recently we were self-voted the number one tech podcast on Earth, which I was like, oh my god. How come we're not up there in Mars yet? It's crazy. It's crazy. Um, so Kevin, just to dive in and totally cut you off from what we're talking about and mix it up a little bit. Um, we have had such a good time with you on the show, and I know we're taking up so much of your time. So we want to give you one more question, and this one is a weird one. Obviously, all my questions are kind of odd. So I like love. I love love, I love dating, and I think everything relates to dating in some manner. Everything you do is the same thing as when you're dating. This is going, but it is every it is. No, everything is about dating. Like, think about it. You're like, oh, I need to go to the grocery store. And I'm like, do you? Let's talk about that relationship. No, uh, bad metaphor. But if we were to say cybersecurity and data privacy, they got married, because in a lot of ways they go hand in hand, but then you know, some things aren't working out, and maybe they're looking at having a divorce, separation agreement, depends on you know what state they got married in. I don't know. What does that relationship look like? Should they stay married? Do you advocate for the divorce? How do they get along? You are now Kevin, uh, the you know, I don't know, the the love therapist for cybersecurity and data privacy. They've come to you for some marriage advice. What do you say?
SPEAKER_03Well, I I guess I I have two things. One is I I think that they're married and they need to stay together for their kids, which is the company. Um, because like it there, it's those two things are I think are really inseparable. Um a lot of people say, oh no, but an EDR tool looks at things or whatever. At the bottom line, if you have good cybersecurity practices like access control, like lease privileges, all these types of very basic types of zero cost cybersecurity things that all businesses ought to have already implemented, but probably haven't because why would the IT person have to want to do their job? They're too busy not doing their job. Um and that aspect of it, you know.
SPEAKER_00You really have it out for IT people.
SPEAKER_03I love IT people.
SPEAKER_00The whole time I was like, I love those people. That's how I get paid. I'm like, oh, your IT people aren't stepping up. I will. But like so, so I I say this because I I see I see the worst of it.
SPEAKER_03Like I'm an instant responder. I come when there's the the house is burned down. Um and when your house is burned down due to an electrical fire, you're not saying, like, man, that electrician I hired was great. Uh my house burned down. Um you're you're probably talking about it. And often often when we jump into a situation, the person in charge of cybersecurity is a really good person and they just had they got got through a sophisticated actor. Because you can do everything right and still lose. But just like dating, and this is the second thing I want to say there's a lot of catfishing in the cybersecurity and data privacy world. And often you think you match with somebody, and oh man, you're you got the hots for this girl uh or guy, and and everything you could have wanted in it. Uh, man, they're sophisticated, they they know all this stuff, they got the best tools, and even better. They're they're so cheap. How can they be this cheap? It's so good, I love it. Or they're expensive. I'm spending a lot of money because I deserve it. You know, I'm gonna treat myself with this perfect, fantastic cheap.
SPEAKER_00I don't know if that's like really or he's expensive. Like I it's whatever, or cheap date, then he's great.
SPEAKER_03Yeah, I uh what whatever your preference is, whatever you're into, it's what they are. And then once once you get deep into the relationship and you guys hit hit your first speed bump, you realize it was all le sham and there was really nothing there. Uh, I've seen organizations that claim to be the Navy SEALs of cybersecurity. And wow, we we we parachute into a situation and they brought down their DC before we could do any type of collection on it for some reason. Not like there's anything important on a DC in a cybersecurity incident. They just felt like doing that. Um so I I say that because because cybersecurity and privacy are so important, are the core parts of every business and organization and entity these days. Uh, getting catfished means it's not just going to sync your relationship with that vendor or business or person, it's going to sink you. Um and you deserve better. And so you need to really vet who you're talking to before you guys commit to a relationship. Uh, and so to to make full circle to this terrible metaphor, uh cybersecurity and data privacy are important, but who your who is your cybersecurity to your data privacy or vice versa, uh is an important choice that you need to take with care and consideration because jumping into a relationship like that may spell a nasty divorce where you have all of your systems encrypted.
SPEAKER_00I mean, you are the data privacy to my cybersecurity.
SPEAKER_01Oh, wow, that's so romantic, Laura. Fuck yeah. Thank you so much. Um, Kevin, you handled that question way better than I thought was possible. I was like, where the hell is this question going? And you answered it beautifully. And uh also thank you so much for being on our podcast today.
SPEAKER_03Hi, thanks again for having me. Um, always a pleasure. If uh any of you guys have any strange legal questions, you can reach me, Kevin Adler at Woods Rogers. Uh, and that's kind of my thing, dealing with strange technology problems or weird law problems. Again, my degree started with the phrase space law.
SPEAKER_01So oh, that's true. I feel like we have a lot of we can have a whole other episode about space trivia.
SPEAKER_00Kevin, we're gonna be bringing it back for so many episodes. At the end of this, you're gonna be like, am I a part of this podcast? Um, so yeah, until then, thanks again, Kevin. Really appreciate your time. Thanks.
SPEAKER_01Laura, we just talked to Kevin Adler, um, the uh computer lawyer extraordinaire. Uh, I like that you called him computer lawyer.
SPEAKER_00I can see your great life. A computer lawyer. I like that a lot. Yeah, I mean I love that he really works as a lawyer directly with cyber and data privacy. I don't think we've had a lawyer on from that angle. We've obviously had the legal approach and different attorneys on, but I like where he was coming from. I think he scared me in a lot of things, which is always, as you know, one of my favorite things. Um, but I also want to know if you can close your mouth as if it was wired shut and sing through the wire like Kanye did. Like, do you think you are better than Kanye at that?
SPEAKER_01Through the wire.
SPEAKER_00No, I can't do it. Yeah, like how did he do it? How the fuck did he do it? For those listening, like if you know, reach out to us. Uh, what were your thoughts on Kevin? I mean, I think he was great.
SPEAKER_01I thought I really wish we had more time with him because I really wanted to know more about the space facts, to be honest with you. Yeah, I agree. Um, but everything he was talking about was very interesting, very, very useful. But honestly, my for anyone who doesn't know me, I'm a nerd about space.
SPEAKER_00Yeah, I mean, we're bringing it back so we can move quickly into it. Yeah, ask it. What is the hottest planet in the solar system? I'm not a planet, so I can't really answer, but it would be me.
SPEAKER_01Oh sh.
SPEAKER_00No, but seriously, just try. Can you plant it uh with these heat? Okay, I just it can't not make everything weird. Um uh which planet do you think is the hottest in the solar system?
SPEAKER_01Uh Uranus. That's that's very far from the sun, so no.
SPEAKER_00I know, but I but I like to make everything kind of go back to Uranus. Okay, okay, okay. The hottest planet is obviously going to be a combination between Saturn and Neptune.
SPEAKER_01Okay. That's incorrect, but I love your enthusiasm. What is it? The hottest planet in the solar system is Venus.
SPEAKER_00Uh, of course it is, because women, uh, men are from Mars.
SPEAKER_01Yeah, that's why. Or is it Venus? Women are hotter than men. No, it's because Venus has an atmosphere that acts like a greenhouse effect, so it traps in heat, so but it doesn't release any heat. I don't know. So it just keeps getting hotter and hotter and hotter. I think I have the same problem. I literally think that's what I have. Now we know why. That also knows that that also happens to Laura, so you know exactly how that feels. It's crazy. No wonder.
SPEAKER_00I'm always just like, I can't help it. Oh my lord. Well, if you want more, yeah, if you want the facts on uh Kevin or the legal aspect, legal tech in general, cyber data privacy, or space, because now we have really expanded this podcast. Uh, when we talk about tech innovation, it's about the global view, not including in the US, but you know, all those planets. Please reach out to us at contact at thattechpod.com. If you haven't yet, subscribe to us. Don't be crazy. We have a lot of new stuff coming out. We have merchandise that if you're not wearing again, be ashamed. Step up, go over to www.thattechpod.com, see what you've missed, see what is coming up, get some gear, and uh again swing over to LinkedIn slash that tech pod, Instagram, Twitter at that tech pod. We know those two social media platforms are terrible. As it turns out, we decided we don't care, but we are proud to have where are we at now? Almost 5,000 subscribers um on our website.
SPEAKER_01Correct.
SPEAKER_00Yeah.
SPEAKER_01Also, if you just want to help out the pod, uh go to Spotify or Apple Podcasts, wherever you're listening to this podcast, and give us a five-star rating or a view. We would love you to the moon and back.
SPEAKER_00And if you're hot enough, we would love you to Venus back and back.
SPEAKER_01See ya next week. See you next time.