Connect with us

Technology

The Ultimate Online Privacy Guide

Published

on

By Douglas Crawford

Introduction

Edward Snowden’s NSA spying revelations highlighted just how much we have sacrificed to the gods of technology and convenience something we used to take for granted, and once considered a basic human right – our privacy.

It is just not just the NSA. Governments the world over are racing to introduce legislation that allows to them to monitor and store every email, phone call and Instant Message, every web page visited, webinar software and every VoIP conversation made by every single one of their citizens.

The press has bandied parallels with George Orwell’s dystopian world ruled by an all-seeing Big Brother about a great deal. They are depressingly accurate.

Encryption provides a highly effective way to protect your internet behavior, communications, and data. The main problem with using encryption is that its use flags you up to organizations such as the NSA for closer scrutiny.

Details of the NSA’s data collection rules are here. What it boils down to is that the NSA examines data from US citizens, then discards it if it’s found to be uninteresting. Encrypted data, on the other hand, is stored indefinitely until the NSA can decrypt it.

The NSA can keep all data relating to non-US citizens indefinitely, but practicality suggests that encrypted data gets special attention.

If a lot more people start to use encryption, then encrypted data will stand out less, and surveillance organizations’ job of invading everyone’s privacy will be much harder. Remember – anonymity is not a crime!

How Secure is Encryption?

Following revelations about the scale of the NSA’s deliberate assault on global encryption standards, confidence in encryption has taken a big dent. So let’s examine the current state of play…

Encryption Key Length

Encryption Key 01Key length is the crudest way of determining how long a cipher will take to break. It is the raw number of ones and zeros used in a cipher. Similarly, the crudest form of attack on a cipher is known as a brute force attack (or exhaustive key search). This involves trying every possible combination to find the correct one.

If anyone is capable of breaking modern encryption ciphers it is the NSA, but to do so is a considerable challenge. For a brute force attack:

  • A 128-bit key cipher has 3.4 x10(38) possible keys. Going through each of them would thousands of operations or more to break.
  • In 2011 the fastest supercomputer in the word (the Fujitsu K computer located in Kobe, Japan) was capable of an Rmax peak speed of 10.51 petaflops. Based on this figure, it would take Fujitsu K 1.02 x 10(18) (around 1 billion) years to crack a 128-bit AES key by force.
  • In 2016 the most powerful supercomputer in the world is the NUDT Tianhe-2 in Guangzhou, China. Almost 3 times as fast as the Fujitsu K, at 33.86 petaflops, it would “only” take it around a third of a billion years to crack a 128-bit AES key. That’s still a long time, and is the figure for breaking just one key.
  • A 256-bit key would require 2(128) times more computational power to break than a 128-bit one.
  • The number of years required to brute force a 256-bit cipher is 3.31 x 10(56) – which is about 20000….0000 (total 46 zeros) times the age of Universe (13.5 billion or 1.35 x 10(10) years!

The NUDT Tianhe-2 supercomputer in Guangzhou, China

128-bit Encryption

Until the Edward Snowden revelations, people assumed that 128-bit encryption was in practice uncrackable through brute force. They believed it would be so for around another 100 years (taking Moore’s Law into account).

In theory, this still holds true. However, the scale of resources that the NSA seems willing to throw at cracking encryption has shaken many experts’ faith in these predictions. Consequently, system administrators the world over are scrambling to upgrade cipher key lengths.

If and when quantum computing becomes available, all bets will be off. Quantum computers will be exponentially more powerful than any existing computer, and will make all current encryption ciphers and suites redundant overnight.

In theory, the development of quantum encryption will counter this problem. However, access to quantum computers will initially be the preserve of the most powerful and wealthy governments and corporations only. It is not in the interests of such organizations to democratize encryption.

For the time being, however, strong encryption is your friend.

Note that the US government uses 256-bit encryption to protect ‘sensitive’ data and 128-bit for ‘routine’ encryption needs.

However, the cipher it uses is AES. As I discuss below, this is not without problems.

Ciphers

Encryption key length refers to the amount of raw numbers involved. Ciphers are the mathematics used to perform the encryption. It is weaknesses in these algorithms, rather than in the key length, that often leads to encryption breaking.

By far the most common ciphers that you will likely encounter are those OpenVPN uses: Blowfish and AES. In addition to this, RSA is used to encrypt and decrypt a cipher’s keys. SHA-1 or SHA-2 are used as hash functions to authenticate the data.

AES is generally considered the most secure cipher for VPN use (and in general). Its adoption by the US government has increased its perceived reliability, and consequently its popularity. However, there is reason to believe this trust may be misplaced.

NIST

The United States National Institute of Standards and Technology (NIST) developed and/or certified AES, RSA, SHA-1 and SHA-2. NIST works closely with the NSA in the development of its ciphers.

Given the NSA’s systematic efforts to weaken or build backdoors into international encryption standards, there is every reason to question the integrity of NIST algorithms.

NIST has been quick to deny any wrongdoing (“NIST would not deliberately weaken a cryptographic standard”). It has also has invited public participation in a number of upcoming proposed encryption-related standards in a move designed to bolster public confidence.

The New York Times, however, has accused the NSA of introducing undetectable backdoors, or subverting the public development process to weaken the algorithms, thus circumventing NIST-approved encryption standards.

News that a NIST-certified cryptographic standard – the Dual Elliptic Curve algorithm (Dual_EC_DRGB) had been deliberately weakened not just once, but twice, by the NSA destroyed pretty much any existing trust.

Encryption

That there might be a deliberate backdoor in Dual_EC_DRGB had already been noticed before. In 2006 researchers at the Eindhoven University of Technology in the Netherlands noted that an attack against it was easy enough to launch on ‘an ordinary PC.’  Microsoft engineers also flagged up a suspected backdoor in the algorithm.

Despite these concerns, where NIST leads, industry follows. Microsoft, Cisco, Symantec and RSA all include the algorithm in their products’ cryptographic libraries. This is in large partbecause compliance with NIST standards is a prerequisite to obtaining US government contracts.

NIST-certified cryptographic standards are pretty much ubiquitous worldwide throughout all areas of industry and business that rely on privacy (including the VPN industry). This is all rather chilling.

Perhaps because so much relies on these standards, cryptography experts have been unwilling to face up to the problem.

Perfect Forward Secrecy

Perfect Forward Secrecy 01
One of the revelations in the information provided by Edward Snowden is that “another program, code-named Cheesy Name, was aimed at singling out SSL/TLS encryption keys, known as ‘certificates,’ that might be vulnerable to being cracked by GCHQ supercomputers.”

That these certificates can be “singled out” strongly suggests that 1024-bit RSA encryption (commonly used to protect the certificate keys) is weaker than previously thought. The NSA and GCHQ could therefore decrypt it much more quickly than expected.

In addition to this, the SHA-1 algorithm widely used to authenticate SSL/TLS connections is fundamentally broken. In both cases, the industry is scrambling fix the weaknesses as fast as it can. It is doing this by moving onto RSA-2048+, Diffie-Hellman, or  Elliptic Curve Diffie-Hellman (ECDH) key exchanges and SHA-2+ hash authentication.

What these issues (and the 2014 Heartbleed Bug fiasco) clearly highlight is the importance of using perfect forward secrecy (PFS) for all SSL/TLS connections.

This is a system whereby a new and unique (with no additional keys derived from it) private encryption key is generated for each session. For this reason, it is also known as an ephemeral key exchange.

Using PFS, if one SSL key is compromised, this does not matter very much because new keys are generated for each connection. They are also often refreshed during connections. To meaningfully access communications these new keys would also need to be compromised. This makes the task so arduous as to be effectively impossible.

Unfortunately, it is common practice (because it’s easy) for companies to use just one private encryption key. If this key is compromised, then the attacker can access all communications encrypted with it.

OpenVPN and PFS

The most widely used VPN protocol is OpenVPN. It is considered very secure. One of the reasons for this is because it allows the use of ephemeral keys.

Sadly this is not implemented by many VPN providers. Without perfect forward secrecy, OpenVPN connections are not considered secure.

It is also worth mentioning here that the HMAC SHA-1 hashes routinely used to authenticate OpenVPN connections are not a weakness. This is because HMAC SHA-1 is much less vulnerable to collision attacks than standard SHA-1 hashes. Mathematical proof of this is available in this paper.

The Takeaway – So, is Encryption Secure?

To underestimate the NSA’s ambition or ability to compromise all encryption is a mistake. However, encryption remains the best defense we have against it (and others like it).

To the best of anyone’s knowledge, strong ciphers such as AES (despite misgivings about its NIST certification) and OpenVPN (with perfect forward secrecy) remain secure.

As Bruce Schneier, encryption specialist, fellow at Harvard’s Berkman Center for Internet and Society, and privacy advocate famously stated,

Trust the math. Encryption is your friend. Use it well, and do your best to ensure that nothing can compromise it. That’s how you can remain secure even in the face of the NSA.”

Remember too that the NSA is not the only potential adversary. However, most criminals and even governments have nowhere near the NSA’s ability to circumvent encryption.

The Importance of End-to-end Encryption

End-to-end (e2e) encryption means that you encrypt data on your own device. Only you hold the encryption keys (unless you share them). Without these keys, an adversary will find it extremely difficult to decrypt your data.

Encryption

Many services and products do not use e2e encryption. Instead they encrypt your data and hold the keys for you. This can be very convenient, as it allows for easy recovery of lost passwords, syncing across devices, and so forth. It does mean, however, that these third parties could be compelled to hand over your encryption keys.

A case in point is Microsoft. It encrypts all emails and files held in OneDrive (formerly SkyDrive), but it also holds the encryption keys. In 2013 it used these to unlock the emails and files of its 250 million worldwide users for inspection by the NSA.

Strongly avoid services that encrypt your data on their servers, rather than you encrypting your own data on your own machine.

HTTPS

Although strong encryption has recently become trendy, websites have been using strong end-to-end encryption for the last 20 years. After all, if websites were not secure, then online shopping or banking wouldn’t be possible.

The encryption protocol used for this is HTTPS, which stands for HTTP Secure (or HTTP over SSL/TLS). It is used for websites that need to secure users’ communications and is the backbone of internet security.

When you visit a non-secure HTTP website, data is transferred unencrypted. This means anyone watching can see everything you do while visiting that site. This includes your transaction details when making payments. It is even possible to alter the data transferred between you and the web server.

With HTTPS, a cryptographic key exchange occurs when you first connect to the website. All subsequent actions on the website are encrypted, and thus hidden from prying eyes. Anyone watching can see that you have visited a certain website, but cannot see which individual pages you read, or any data transferred.

For example, the BestVPN.com website is secured using HTTPS. Unless you are using a VPN while reading this web page, your ISP can see that you have visited www.bestvpn.com, but cannot see that you are reading this particular article. HTTPS uses end-to-end encryption.

Secured website Firefox

It is easy to tell if you visit a website secured by HTTPS – just look for a locked padlock icon to the left of the main URL/search bar.

There are issues relating to HTTPS, but in general it is secure. If it wasn’t, none of the billions of financial transactions and transfers of personal data that happen every day on the internet would be possible. The internet itself (and possibly the world economy!) would collapse overnight.

For a detailed discussion on HTTPS, please see here.

Metadata

An important limitation to encryption is that it does not necessarily protect users from the collection of metadata.

Even if the contents of emails, voice conversations, or web browsing sessions cannot be readily listened in on, knowing when, where, from whom, to whom, and how regularly such communication takes place can tell an adversary a great deal. This is a powerful tool in the wrong hands.

For example, even if you use a securely encrypted messaging service such as WhatsApp, Facebook will still be able to tell who you are messaging, how often you message, how long you usually chat for, and more. With such information, it would be easy to discover that you were having an affair, for example.

Although the NSA does target individual communications, its primary concern is the collection of metadata. As NSA General Counsel Stewart Baker has openly acknowledged,

“Metadata absolutely tells you everything about somebody’s life. If you have enough metadata, you don’t really need content.

Technologies such as VPNs and Tor can make the collection of metadata very difficult. For example, an ISP cannot collect metadata relating to the browsing history of customers who use a VPN to hide their online activities.

Note, though, that many VPN providers themselves log some metadata. This should be a consideration when choosing a service to protect your privacy.

Please also note that mobile apps typically bypass any VPN that is running on your device, and connect directly to their publishers’ servers. Using a VPN, for example, will not prevent WhatsApp sending metadata to Facebook.

Identify Your Threat Model

When considering how to protect your privacy and stay secure on the internet, carefully consider who or what worries you most. Defending yourself against everything is almost impossible. And any attempt to do so will likely seriously degrade the usability (and your enjoyment) of the internet.

Identifying to yourself that being caught downloading an illicit copy of Game of Thrones is a bigger worry than being targeted by a crack NSA TAO teamfor personalized surveillance is a good start. It will leave you less stressed, with a more useable internet and with more effective defenses against the threats that really matter to you.

Of course, if your name is Edward Snowden, then TAO teams will be part of your threat model…

I will discuss steps you should take to help identify your threat model in an upcoming article on BestVPN.com. In the meantime, this article does a good job of introducing the basics.

Use FOSS Software

Ultimate Privacy Guide Illustration 03 01The terrifying scale of the NSA’s attack on public cryptography, and its deliberate weakening of common international encryption standards, has demonstrated that no proprietary software can be trusted. Even software specifically designed with security in mind.

The NSA has co-opted or coerced hundreds of technology companies into building backdoors into their programs, or otherwise weakening security in order to allow it access. US and UK companies are particularly suspect, although the reports make it clear that companies across the world have acceded to NSA demands.

The problem with proprietary software is that the NSA can fairly easily approach and convince the sole developers and owners to play ball. In addition to this, their source code is kept secret. This makes it easy to add to or modify the code in dodgy ways without anyone noticing.

Open source code

The best answer to this problem is to use free open source software (FOSS). Often jointly developed by disparate and otherwise unconnected individuals, the source code is available to everyone to examine and peer-review. This minimizes the chances that someone has tampered with it.

Ideally, this code should also be compatible with other implementations, in orderto minimize the possibility of a backdoor being built in.

It is, of course, possible that NSA agents have infiltrated open source development groups and introduced malicious code without anyone’s knowledge. In addition, the sheer amount of code that many projects involve means that it is often impossible to fully peer-review all of it.

Despite these potential pitfalls, FOSS remains the most reliable and least likely to be tampered with software available. If you truly care about privacy you should try to use it exclusively (up to and including using FOSS operating systems such as Linux).

Steps You Can Take to Improve Your Privacy

With the proviso that nothing is perfect, and if “they” really want to get you “they” probably can, there are steps you can take to improve your privacy.

Pay for Stuff Anonymously

One step to improving your privacy is to pay for things anonymously. When it comes to physical goods delivered to an actual address, this isn’t going to happen. Online services are a different kettle of fish, however.

It is increasingly common to find services that accept payment through Bitcoin and the like. A few, such as VPN service Mullvad, will even accept cash sent anonymously by post.Ultimate Privacy Guide Illustration 04 01

Bitcoin

Bitcoin is a decentralized and open source virtual currency that operates using peer-to-peer technology (much as BitTorrent and Skype do). The concept is particularly revolutionary and exciting because it does not require a middleman to work (for example a state-controlled bank).

Whether or not Bitcoins represent a good investment opportunity remains hotly debated, and is not within the remit of this guide. It is also completely outside of my area of expertise!

Source: Bestvpn.com

Modupe Gbadeyanka is a fast-rising journalist with Business Post Nigeria. Her passion for journalism is amazing. She is willing to learn more with a view to becoming one of the best pen-pushers in Nigeria. Her role models are the duo of CNN's Richard Quest and Christiane Amanpour.

1 Comment

1 Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

WhatsApp Introduces Web Calling, Call Transfer, QuickHD Features

Published

on

WhatsApp Web Calling feature

By Aduragbemi Omiyale

WhatsApp has been updated with a web calling feature, allowing users to now make and receive audio and video calls, both one-on-one and group, directly from WhatsApp Web.

A notice from the Meta-owned messaging platform disclosed that this feature works without the need to download any app.

It was disclosed that this update was made to WhatsApp to make it easier for users to make calls wherever they are and on whatever device, phone or laptop.

Users will have access to features available on their other devices, including screen sharing, reactions, and a dedicated Calls tab with full call history and favourites, all from their browsers.

WhatsApp noted that calls from this feature are end-to-end encrypted, with no time limits and at no cost, as it is the same private experience they expect from the platform.

WhatsApp has also been embedded with easy call transfer, enabling the movement of an active group call from one device to another without hanging up. Users can seamlessly transfer calls to WhatsApp Web or Desktop when they arrive home to collaborate on a larger screen – or vice versa.

The platform further said it now has QuickHD, which allows for an improved video experience at the beginning of a call. With QuickHD, users can now enjoy high-definition video immediately in the very first few seconds of the call.

In addition, it has launched noise suppression to remove the background noise around callers so their voices come through clearly to the person on the other end, even in loud or busy environments. This can be managed at any time in in-call settings.

WhatsApp said these features are rolling out gradually and will be available to everyone soon, expressing its desire to make WhatsApp calling simpler to use.

Continue Reading

Technology

Modded Hosting With Reliable Backups: Biome Types Guide

Published

on

Modded Hosting

Modded Minecraft worlds take weeks to build. Custom biomes, terraformed landscapes, established bases — losing any of it to a corrupted chunk or a failed update is devastating. Backups aren’t optional for modded servers. They’re essential.

Modded hosting with reliable backups protects everything players have built across every minecraft biome types the pack introduces — without requiring manual backup routines that nobody remembers to run.

Why Modded Worlds Are More Vulnerable to Data Loss

Vanilla Minecraft worlds are relatively stable. Modded worlds have more ways to break. Mod updates can corrupt chunk data if block IDs change. Crashes during chunk generation leave partial files. Automated farms that run while no players are online can cause chunk-level issues over time.

Biomes added by mods require extra care. Changing biome mods later can cause unexpected problems. If the old biome data no longer exists, Minecraft may not know how to read parts of the world anymore. The Minecraft Wiki explains that every generated chunk keeps its own biome information in the save. Modded biomes require their mod to be present to load correctly — removing the mod without migrating chunks first causes permanent data loss in those areas.

Minecraft Biome Types: What Mods Add

People often focus on giant mountains or rare structures, but smaller biome changes matter too. A carefully designed minecraft grass biome can completely change the appearance of an entire region. Once that combines with improved forests, rivers, and mountain generation, exploration naturally takes longer because there’s almost always another interesting place nearby. There’s a massive difference once biome mods are installed. Biomes O’ Plenty alone adds over 80 biomes. Terralith adds another 95 plus, although it still builds worlds using Minecraft’s regular generation system rather than a custom one. Oh The Biomes You’ll Go adds tropical and fantasy biomes not found in either.

Each of these creates a richer world to explore — and more unique terrain to protect. A player who spends two sessions exploring and settling in a modded cherry blossom grove loses something irreplaceable if that chunk gets corrupted without a backup.

Content creator and modpack player Noxite has described modded biome exploration as one of the most memorable experiences in the game — “every new biome feels like discovering a location that exists only in your world.” Backups protect that discovery.

Many players only start thinking about backups after something goes wrong. It’s surprisingly easy for a modded world to develop problems. Maybe the server restarts halfway through chunk generation, or a mod update changes world data in a way the old save no longer understands. Even experienced server owners don’t get through every update without issues. Sometimes everything looks fine until someone explores a new biome and discovers broken chunks. At that point, having a recent backup is usually the simplest solution instead of trying to repair damaged terrain piece by piece.

What a Reliable Backup System Looks Like for Modded Servers

For modded worlds, backup requirements go beyond vanilla minimums:

  1. Daily automated backups — at minimum; hourly for active community servers
  2. Full world backups — not just player data; entire world folder including all dimensions
  3. Pre-update snapshots — automatic backup triggered before any mod or server update
  4. Offsite storage — backups stored separately from the server to survive hardware failure
  5. Easy restoration — one-click restore to a specific backup without technical support

Biome backup

Protecting Every Biome You’ve Explored

Minecraft biomes wiki entries for modded biomes often include notes about save compatibility across versions. The community’s experience is consistent: mod updates break worlds more often than player actions do. Regular backups are the only reliable protection.

Choose modded hosting with reliable backups that runs automatically, stores multiple restore points, and makes restoration simple. The time investment in setting up proper backups is always less than the time lost rebuilding after a preventable data loss event.

Continue Reading

Technology

5 Ways AI is Transforming Consumer Intelligence and Analytics

Published

on

AI consumer analytics

The rules have changed. How companies actually know their customers — really know them — looks almost nothing like it did ten years ago. Old-school research methods are drowning. Too slow, too narrow, too dependent on humans manually stitching together datasets that have already gone cold. Markets shift in days now, not quarters. And the cost of a slow read on consumer behavior keeps climbing. This isn’t just a tooling upgrade. The underlying logic of how businesses decide what to build, what to charge, and who to reach has been gutted and rebuilt from scratch. Staying reactive isn’t a strategy anymore. It’s a liability.

1. Real-Time Data Processing and Pattern Recognition

Consumer intelligence used to run on stale numbers. Analysts dug into data weeks — sometimes months — after whatever actually happened. Modern AI kills that lag. Entirely. These systems chew through enormous volumes of behavioral data on the fly, surfacing patterns that human teams couldn’t find in the same timeframe with ten times the headcount. Machine learning algorithms can process millions of customer interactions, transactions, and behavioral signals simultaneously — pulling clean signal out of what would otherwise be undifferentiated noise. A retailer can track sentiment across social media, reviews, and support tickets right now, catching a brewing problem or an emerging trend in hours rather than weeks. Inventory shifts, pricing moves, message pivots — all of it happens before a trend fully crystallizes. That’s a different game entirely.

2. Predictive Analytics and Consumer Behavior Forecasting

Here’s what actually changed: AI stops consumer intelligence from being a backward-looking exercise. Instead of cataloguing what customers already did, companies can now forecast what they’re likely to do next — and with striking accuracy. Advanced ML models thread together historical patterns and live behavioral signals to predict churn, flag high-value prospects, and project demand across entire product lines. A telecom company can spot which customers are quietly drifting toward a competitor before they ever make the switch — and intervene first. That’s not a marginal improvement. It’s a fundamentally different posture. Resources flow toward the segments that actually matter, rather than spreading thin across the whole base and hoping something sticks.

3. Personalization at Scale

Consumers expect personalized experiences. Full stop. Meeting that expectation at scale — for millions of people at once — is simply beyond what human analysts and traditional segmentation can deliver. Machine learning models read individual purchase histories, browsing patterns, preferences, and demographic signals to build dynamic profiles that drive product recommendations, custom messaging, and tailored interfaces. When building and refining these individualized profiles, marketers who need to enrich their first-party data with verified behavioral signals rely on audience data providers to ensure their models are trained on accurate, high-quality consumer information. An e-commerce platform can serve each visitor a genuinely different experience — different layouts, different offers, different content — all built around that visitor’s unique fingerprint. Conversion lifts. Lifetime value climbs. People respond when recommendations actually fit their lives, not just the average of everyone else’s.

4. Sentiment Analysis and Brand Perception Monitoring

Knowing how consumers feel about a brand means wading through unstructured mess. Reviews, comment threads, support tickets, social posts, video captions — none of it parses cleanly by hand at any useful speed. Natural language processing handles it. NLP systems automatically scan text-based content across digital channels, classifying sentiment as positive, negative, or neutral while bucketing feedback by topic, product feature, or customer segment. An automaker can track online conversations about a specific reliability concern and catch it before it snowballs into a full-blown reputation crisis. No waiting for quarterly surveys. No lag. Brand perception monitoring becomes continuous — and decisions about product fixes, messaging shifts, or service interventions get grounded in real signal rather than gut instinct.

5. Competitive Intelligence and Market Positioning Analysis

Competitive intelligence used to mean manual tracking, sprawling spreadsheets, and perpetually incomplete pictures. AI automates the entire collection-and-analysis loop. ML models watch competitor pricing moves, product launches, promotions, and messaging shifts across digital channels — then stack that data against a company’s own position. Gaps surface. Threats register earlier. A financial services firm can monitor exactly which themes competitors are pushing on social media and which ones are actually generating engagement — then sharpen their own positioning accordingly. Real-time visibility into competitive dynamics means strategic calls about where to invest, which markets to enter, and how to stand apart in crowded categories aren’t made blind anymore.

Conclusion

What AI has done to consumer intelligence isn’t incremental. It’s structural. Real-time processing of massive datasets. Forecasting future behavior instead of autopsying the past. Personalization that reaches millions, not hundreds. Continuous sentiment monitoring. Automated competitive tracking. None of these were realistic options a decade ago. They are now. Companies that wire these capabilities into their core operations make faster, sharper decisions — ones that show up directly in revenue, satisfaction scores, and market share. Those that don’t will keep falling further behind. And the gap between organizations that wield these tools well and those still grinding through traditional approaches? It’s not closing. It’s widening every quarter.

Continue Reading