Notary Knowledge by Derrick Spruill
"Notary Knowledge by Derrick Spruill," created by Derrick Spruill and hosted by Eddie Montes Travis and Marylyn Lee Trotter, is the definitive podcast resource for navigating the multifaceted world of notarization. This show transcends the typical notary discussion, offering a comprehensive look at the industry from both sides of the signing table.
For notaries, whether seasoned veterans or those just embarking on their professional journey, "Notary Knowledge by Derrick Spruill" provides invaluable insights into the ever-evolving landscape. The hosts delve into the latest legislative changes, industry trends, and best practices, equipping notaries with the knowledge and tools necessary to excel. They explore effective marketing strategies, business development techniques, and the nuances of building a thriving notary practice. The show also addresses the challenges and opportunities notaries face daily, offering practical advice on handling diverse situations and maintaining compliance.
However, "Notary Knowledge by Derrick Spruill" goes beyond simply serving notaries. It also aims to demystify the notarization process for individuals seeking notary services. By examining real-life scenarios and discussing the events that necessitate notary involvement, the podcast provides a clearer understanding of why notarization is essential and what to expect during a signing. Listeners gain insight into the responsibilities of a notary, the importance of proper identification, and the legal implications of notarized documents.
Derrick, Eddie, and Marylyn bring a wealth of knowledge and expertise to the table, fostering engaging discussions and sharing practical wisdom. They feature expert interviews, dissect complex legal issues, and offer life lessons gleaned from years of navigating the notary field. This podcast is a vital resource for anyone seeking to stay informed, understand the notary process, and navigate the intricacies of notarization with confidence. "Notary Knowledge by Derrick Spruill" is a must-listen for notaries looking to elevate their careers and for individuals seeking to understand the critical role notaries play in legal and business transactions.
Check out the "Notary Knowledge Reference Guide and Notary Bible" by Derrick Spruill on Amazon.
Contact Information:
Email us at MobileNotary@DerrickSpruill.com
Give us a call: 1-833-462-4632
Disclaimer: The podcast Notary Knowledge by Derrick Spruill does not provide legal advice. Eddie Montes Travis, Derrick Spruill, and Marylyn Lee Trotter are not lawyers or part of any law firm. This podcast is for informational purposes only.
Notary Knowledge by Derrick Spruill
Technology Thursdays: Mobile Hotspot Security and VPN Compliance
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Staying safe while working on the go is a top priority for any mobile professional handling sensitive data. Join Eddie Montes Travis and Marylyn Lee Trotter as they explore the essentials of keeping your internet connection private and secure during remote signings. This episode focuses on the practical steps needed to protect client information while using public networks.
• Hotspot Security: Setting strong passwords and using the latest encryption standards like WPA3 to prevent unauthorized access to your mobile network.
• VPN Compliance: Understanding why a Virtual Private Network is necessary for meeting industry standards and protecting data from hackers.
• Public Wi-Fi Risks: Identifying the dangers of open networks and how to avoid man-in-the-middle attacks when working in cafes or transit hubs.
• Device Management: Keeping your firmware updated and disabling auto-connect features to ensure you only join trusted signals.
Mastering these digital tools ensures that your mobile office remains a fortress for confidential documents. By implementing a few simple habits, you can work with confidence anywhere. Please subscribe and like the podcast to keep up with all our latest tips!
Show Notes:
• Importance of using WPA3 encryption on mobile hotspots.
• The role of VPNs in maintaining data compliance.
• Identifying and avoiding the security pitfalls of public Wi-Fi.
• Best practices for securing mobile devices and tablets during signings.
Buy Becoming a Notary on Amazon
Notary Knowledge Reference Guide and Notary Bible on Amazon
Your Sunday Notary Reading:
Notary Public Foundation: Essential Guide to Core Duties, Ethics, and Commissioning on Amazon
Your Monday Notary Reading:
Notary Operational Excellence: Mastering Certificates, Journals, Ink, and Copy Certification on Amazon
Your Tuesday Notary Reading:
Notary Fraud Shield: Real-World Tactics, Red Flags, and Refusal Strategies on Amazon
Your Wednesday Notary Reading:
The Mobile Notary Blueprint: Launching and Managing Your On-Demand Business on Amazon
Your Thursday Notary Reading:
Notary Niche Navigator: Your Guide to Loan Signings, Apostilles, I-9s, and More on Amazon
Your Friday Notary Reading:
Notary Law & Liability: Understanding State Regulations, Insurance, and Avoiding UPL
Your Saturday Notary Reading:
The Future Notary: Mastering RON, eNotary, and Complex Scenarios on Amazon
Quick & Easy Solutions: How to Increase Mobile Notary Business for More Success & Profit: with 37 Professional Tips on Amazon
Executive Producer Derrick Spruill
Writers Marylyn Lee Trotter and Eddie Montes Travis
Graphics & Illustrations by Eddie Montes Travis
Music by Thomas Bynum
This Show is Produced by Magnificent Workz
Business Solutions
To obtain more notary knowledge, explore the full collection of books by Derek Spruel and find the perfect book for your notary business. Visit any online bookstore, Amazon.com, Barnes and Noble Bookstore, Books of Million.com, Bookshop.org, Mobile Notary by DerekSproul.com, or download from Kindle to obtain your essential notary book to help with all your notarizations starting today.
SPEAKER_02Imagine this. You're a mobile notary, you've just finished a massive real estate closing, you pull into a coffee shop parking lot to grip a quick espresso before your next appointment. You lock your doors, run inside for maybe two minutes, and when you walk back out, you see shattered glass on the pavement.
SPEAKER_01Oh man.
SPEAKER_02Yeah. Your unbranded laptop bag is gone. But uh you didn't just lose a piece of glass and metal. You just exposed to social security numbers, banking details, and unredacted driver's licenses of 50 families.
SPEAKER_01Exactly.
SPEAKER_02In those two minutes, your career, your commission, and your entire financial livelihood are just thrown into a leal nightmare. We're going to make sure that never happens to you.
SPEAKER_01Welcome to Notary Knowledge. I am Eddie.
SPEAKER_02And I am Marilyn.
SPEAKER_01We are bringing you another bold, direct, and uh highly experienced session. Today is all about elevating your practice to the absolute highest standards. Right. But before we get into the core of today's high-level analysis, we have some essential housekeeping. If you haven't already, you need to get your hands on the notary knowledge books by Derek Spruel.
SPEAKER_02They are foundational to operating at a professional level. Head over to the Notary Knowledge website and grab your copies right now.
SPEAKER_01Also, make sure you check out our video podcast, No Notary, featuring Eddie Montez Travis, as well as Marilyn's 90 seconds of notary for quick, you know, actionable insights you can apply immediately out of the field.
SPEAKER_02Yeah, those are great. And we have a very special promotion for our listeners today. If you are serious about modernizing your workflow, you you need the One Ledger notary e journal.
SPEAKER_01It's fantastic.
SPEAKER_02It really is. It's available right now on the Apple App Store. It was crafted by the incredible MagnificentWorks team. Because you listen to this show, you can use the promo code NOTARINKO50. That's notary paynow50. That gets you 50% off the first year's annual plan. It is an absolute game changer for compliance and secure record keeping.
SPEAKER_01It really is an essential tool. And speaking of modernizing workflows and securing your records, well, that brings us perfectly into today's segment. Welcome to Technology Thursdays.
SPEAKER_02Today's mission is a bold exploration into mobile hotspot security and VPN compliance for the modern remote and mobile notary. Right. We are synthesizing a massive amount of complex material today. We've got federal guidelines, the FTC safeguards rule, vehicle area network engineering, and major cryptographic transitions.
SPEAKER_01There's a lot to cover.
SPEAKER_02A lot. As noted in prior episodes, notaries are, to borrow a phrase from Selicia Young Jones, the White Hats and the Hall monitors against fraud. We're the good guys in the room.
SPEAKER_03We are.
SPEAKER_02But here is the hard truth. You cannot protect the public if your own digital and physical infrastructure is compromised.
SPEAKER_01Exactly. You are operating as a non-banking financial institution the moment you handle non-public personal information or uh NPI. Yeah. The regulatory landscape has shifted completely from the temporary pandemic allowances we had a few years ago. We're in a highly regulated, strictly enforced digital trust network now. You are no longer just a person with a stamp, you are a secure data node.
SPEAKER_02A secure data node. I like that. So let's start right at the perimeter where the real world actually meets the digital one.
SPEAKER_01The physical digital boundary.
SPEAKER_02Exactly. Specifically, securing the vehicle area network or the van. I brought up that terrifying coffee shop scenario at the top of the show because it actually happened. It did. Yeah. We received a message from Isaac, a notary out in Missouri. Isaac had his tablets stolen right out of his vehicle while he was running into a cafe between appointments. He's brutal. A complete disaster. The state board got involved, the clients had to be notified of a data breach. It brings up a crucial point, right? A digital lock, no matter how strong the encryption is, it means absolutely nothing if the physical device is easily snatched.
SPEAKER_01Isaac's situation is, unfortunately, incredibly common. But the good news is that it's entirely preventable. Right. Operating a mobile office from a vehicle introduces these extreme physical vulnerabilities that most professionals simply, you know, they just don't account for them.
SPEAKER_02They just assume rolling up the windows is enough.
SPEAKER_01Right, which it isn't. To counter this, mobile operators must enforce a strict zero visibility policy.
SPEAKER_02Okay. Define zero visibility for us.
SPEAKER_01It means laptops, tablets, signature pads, and physical journals must never be left in plain view. Not even for 30 seconds. But it goes beyond just throwing a jacket over your gear on the passenger seat.
SPEAKER_02Yeah, they know to look under the jacket.
SPEAKER_01Exactly. All transport bags, backpacks, briefcases, they should be completely unbranded.
SPEAKER_02Really?
SPEAKER_01Yes. No custom stitching, no business logos, no window decals on your car that identify you as a professional notary, signing agent, or closing specialist.
SPEAKER_02Okay. I am going to push back on that for a second.
SPEAKER_01Go for it.
SPEAKER_02We are business owners, right? We spend thousands of dollars on marketing, vehicle wraps, custom embroidered bags because we want to generate leads while we're out in the field.
SPEAKER_01Sure.
SPEAKER_02You're telling me I have to strip all that away and operate like some kind of secret agent just to do a mortgage closing.
SPEAKER_01I'm telling you that advertising your profession on your vehicle is essentially putting up a neon sign for opportunistic thieves.
SPEAKER_02Oh.
SPEAKER_01It says, hey, this car is filled with sensitive personal data and high-end electronics. You make yourself a target.
SPEAKER_02Wow. Okay, when you put it like that.
SPEAKER_01If you want to market your business, do it online. Do it through networking events. Do it at title offices. Do not do it on the bag that holds unencrypted or even encrypted client data.
SPEAKER_02Okay, that is a fair point. The risk of a data breach definitely outweighs the chance of a random parking lot lid. But what happens when the devices actually have to stay in the car? I know we can't just tuck them under a floor mat.
SPEAKER_01Precisely. High security hardware, especially the laptop storing your private signing keys, it must be physically anchored.
SPEAKER_02Anchored how?
SPEAKER_01We are talking about locking the device to the vehicle's frame using high-tensile steel Kensington lock cables.
SPEAKER_02Oh, like the ones they use in retail stores.
SPEAKER_01Exactly. And you don't just loop it around a plastic center console, you have to secure it directly to the structural steel seat brackets. Wow. Or, better yet, you install an unbranded secure vehicle safe that is bolted directly to the chassis in your trunk.
SPEAKER_02So not just a lockbox sitting in the bag.
SPEAKER_01No, it has to be bolted down. If a thief breaks the window, they shouldn't be able to just grab a bag and run. They should have to bring an angle grinder and spend 20 minutes making a massive scene to get your hardware.
SPEAKER_02Make it as difficult as humanly possible. Exactly. Let's talk about the windows, though. We spent all this time talking about AES 256 encryption on our hard drives, making sure hackers can't break into our systems remotely. Right. But honestly, why encrypt your hard drive if the guy parked next to you at a roadside rest area can just look through your side window and read social security numbers right off your screen?
SPEAKER_01It's a huge issue.
SPEAKER_02Visual eavesdropping, right, or shoulder surfing, it seems like a massive overlooked loophole.
SPEAKER_01It is a critical loophole and one that threat actors exploit regularly. Someone sitting in the car next to you with high magnification optics, or even just a modern smartphone camera with a good zoom that can easily capture sensitive client data through your vehicle windows while you are working.
SPEAKER_02So what's the fix?
SPEAKER_01That is why visual privacy countermeasures are legally and practically mandatory.
SPEAKER_02Yeah.
SPEAKER_01On the hardware side, your laptop and tablet must be equipped with polarized microlevered privacy screen filters.
SPEAKER_02Microleouvered. Explain how that actually works for the listener.
SPEAKER_01Think of vertical blinds on a house window.
SPEAKER_02Okay.
SPEAKER_01If you stand directly in front of them, you can see right through to the outside. Sure. But if you take three steps to the left or the right, the overlapping blinds block your view completely. A micro louvered privacy screen does this on a microscopic level. It restricts the viewing angle to roughly 30 degrees directly in front of the display.
SPEAKER_02That's incredibly narrow.
SPEAKER_01It is. If someone looks from the side window of your car, the screen simply appears pitch black.
SPEAKER_02That handles the screen. But what about the vehicle windows themselves? Automotive window tinting has to play a role here in protecting the mobile workspace, right?
SPEAKER_01It does, but you have to navigate the legal and technical nuances of visible light transmission or uh VLT.
SPEAKER_02VLT, got it.
SPEAKER_01VLT is the percentage of ambient light allowed to pass through the window film. Lower numbers mean darker tint. Five percent is essentially limo tint. Which is pretty dark. Very dark. However, state laws vary wildly, and as a mobile professional, you have to be compliant with the motor vehicle code.
SPEAKER_02Right, you can't just black out the whole car.
SPEAKER_01No. For instance, California allows any darkness level on the rear side and rear windshield windows, which allows you to create a completely blacked-out rear passenger workspace. But they require at least 70% VLT on the front side windows. Okay. Virginia allows 50% VLT on the front and 35% on the rear for standard sedans. If you go up to Ontario, it relies heavily on police officer discretion regarding whether the tint obstructs the driver's view. You have to know your local jurisdiction intimately.
SPEAKER_02So assuming I know my state's VLT laws, it is not just about how dark the film is, right? It is what the film is actually made of.
SPEAKER_01Oh, absolutely.
SPEAKER_02This is something I see notaries get wrong all the time. If I am building a high-tech mobile office, I can't just go to a local shop and slap cheap metallic tint on the windows to make it dark.
SPEAKER_00Please don't do that.
SPEAKER_02Because metallic films literally bounce radio waves. They basically turn your car into a Faraday cage, heavily degrading your 5G, Wi-Fi, and GPS signals inside the cabin.
SPEAKER_01That is actually a really great point and something most people miss when outfitting their vehicles. Mobile notaries must specify high-performance ceramic window films.
SPEAKER_02Ceramic okay. Why is that better?
SPEAKER_01Ceramic tints use non-conductive nanoparticles instead of metal. Because they are non-conductive, they do not interfere with RF signals, meaning your 5G gateway gets full cellular reception.
SPEAKER_02That's huge for staying connected.
SPEAKER_01It is. And furthermore, ceramic films block up to 99% of harmful UV radiation and can reduce ambient cabin temperatures by up to 60%.
SPEAKER_02Which is a massive deal when you are running high-end electronics.
SPEAKER_01Absolutely. That temperature reduction is vital. If you are sitting in a parking lot in Phoenix in July doing a remote closing, your mobile gateways and tablets will overheat and thermally throttle.
SPEAKER_02Oh, yeah, they'll just shut down to protect themselves.
SPEAKER_01Exactly. If the router overheats, it shuts down, your session drops, and you just lost a closing. Ceramic tint is a functional IT investment, not just an aesthetic one.
SPEAKER_02That perfectly sets up our transition from the physical perimeter to the invisible one. Let's talk about network architecture, hotspot hardening, and the extreme danger of public Wi-Fi.
SPEAKER_01Yes, let's get into it.
SPEAKER_02We have a scenario from Camila in Minnesota. She was conducting a remote closing in her car, noticed she was running low on her monthly cellular data, and decided to connect her laptop to the public Wi-Fi of the cafe she was parked in front of just to finish the session.
SPEAKER_01Oh wow. Yeah, doing that is a direct, undeniable violation of both the Graham Leach Bliley Act and the FTC Safeguards rule.
SPEAKER_02Just by connecting.
SPEAKER_01Just by connecting. Public Wi-Fi networks are inherently untrusted environments. When you join a cafe's network, you are on the same local area network as every other person in that building.
SPEAKER_02Right.
SPEAKER_01Which means anyone running a basic packet sniffer can attempt to intercept your traffic.
SPEAKER_02But people use their phone hotspots all the time for this.
SPEAKER_01And they shouldn't. Relying on consumer smartphones or standard carrier-provided consumer hotspots is no longer sufficient for our industry.
SPEAKER_02So what's the alternative?
SPEAKER_01Mobile notaries need to transition to ruggedized industrial 5G gateways, devices like the CradlePoint R1900 or the DigiTX40. These are engineered specifically for automotive use, and they provide enterprise grade firewall and network controls.
SPEAKER_02Okay, let's get deeply practical here. Sure. If I am setting up my vehicles network today and I just bought one of these industrial gateways, what exact settings do I need to flip to keep the bad guys out? I don't want broad advice. I want the definitive checklist.
SPEAKER_01Let's build the checklist. The first mandate, pulled directly from NSA warning guidelines for remote workers, is to force your local Wi-Fi interface into WPA3 only mode.
SPEAKER_02Why WPA3? I mean, we've been using WPA2 for a decade. It seems fine.
SPEAKER_01Because WPA2 relies on a pre-shared key exchange that is highly vulnerable to offline dictionary attacks.
SPEAKER_02Okay, break that down for me.
SPEAKER_01If someone captured the initial handshape when your device connects to your router, they can take that little packet of data home, run it through a supercomputer, and guess your password without ever interacting with your network again.
SPEAKER_02They just brute force it offline.
SPEAKER_01Exactly. WPA3 replaces that with SAE, which stands for simultaneous authentication of equals.
SPEAKER_02Okay, wait, explain that. How does SAE actually work? Why does it stop a hacker?
SPEAKER_01SAE uses what is called a zero-knowledge proof handshake.
SPEAKER_02Zero knowledge proof.
SPEAKER_01Right. Imagine you want to prove to someone that you know the combination to a safe, but you refuse to tell them the numbers. Instead, you tell them to look away. You open the safe, take out a specific item only found inside, and show it to them. You proved you know the secret without ever revealing the secret itself. Ah SAE does this mathematically. It prevents attackers from capturing wireless traffic and launching offline brute force attacks because the password is never actually transmitted in a way that can be recorded and cracked.
SPEAKER_02That makes total sense. And it has to be WPA3 only, right? Not that mix mode I see on a lot of default router settings.
SPEAKER_01Correct. You must disable WPA2WPA3 transition mode.
SPEAKER_02Why is the transition mode bad?
SPEAKER_01Because transition mode is extremely vulnerable to downgrade attacks. A hacker can actively block your WPA3 connection, forcing your laptop to fall back to the weaker WPA2 standard without you even noticing.
SPEAKER_02That's sneaky.
SPEAKER_01Very. You should also enable the transition disable instruction in the router's firmware to lock this secure state in.
SPEAKER_02Okay, so the encryption is locked. What is next on the checklist?
SPEAKER_01Next, you must enable AP client isolation on your local SS ID.
SPEAKER_02AP client isolation. Explain the mechanism there. Why does client isolation matter if I'm literally the only person sitting in the car?
SPEAKER_01Because you have multiple devices.
SPEAKER_02Oh, right. My phone, my tablet, my laptop.
SPEAKER_01Exactly. When you join a standard network, your device essentially shouts out, hello, who else is here? to every other phone, printer, and laptop connected. It's called ARP broadcasting.
SPEAKER_02Okay.
SPEAKER_01A hacker listens for those shouts to map the network. AP client isolation puts blinders on every connected device. It creates a soundproof booth for each connection.
SPEAKER_02So they can't talk to each other.
SPEAKER_01Right. Even if a rogue device somehow breached your Wi-Fi password and got on your network, it cannot scan, sniff, or communicate with your laptop. It can only talk directly to the internet.
SPEAKER_02That is brilliant. It essentially isolates the breach to the single compromise device.
SPEAKER_01Exactly. But we obviously want to prevent that rogue device from associating in the first place, right? So you limit your maximum connected clients to a strict number, say two devices, your laptop and your phone. Then you enforce a maxi address allow list.
SPEAKER_02What's a maxi address?
SPEAKER_01Every network card has a unique physical MC address hard-coded into it. You program the router to say only these two specific hardware addresses are allowed to authenticate.
SPEAKER_02So even if they have the password, if their hardware doesn't match the list, they're rejected.
SPEAKER_01Absolutely rejected.
SPEAKER_02Okay, so the local Wi-Fi bubble inside the car is a fortress. But what about the connection going out? The connection from the vehicle to the cellular carrier.
SPEAKER_01That is the WAN interface, the wide area network. First, you need to disable remote web administration entirely on the WAN side. You do not want anyone on the public internet to even see a login screen for your router.
SPEAKER_02That makes sense. Keep it internal only.
SPEAKER_01Second, use private access point names or uh APNs provided by your cellular carrier.
SPEAKER_02How does that differ from just regular 5G service?
SPEAKER_01Well, a standard APN puts your router in the massive public IP pool with everyone's smartphones, meaning automated internet scanning bots will constantly ping and probe your router for open ports. A private APN isolates your router from that public pool.
SPEAKER_02Okay, that's a great tip.
SPEAKER_01Also, physically lock the SIM card inside the gateway using a custom SIM pin to stop SIM swapping exploits. Because if someone actually breaks into the car and steals the SIM, they could hijack your data plan.
SPEAKER_02Wait, hold on. Even if I lock down my router with WPA3 and I have a private APN, isn't my cellular carrier still watching every website I go to?
SPEAKER_01I've heard carrier DNS is incredibly leaky. Mm-hmm. How do we blindfold the carrier?
SPEAKER_02You are absolutely right to distrust default carrier DNS. Domain name system servers translate human readable websites into IP addresses. Default carrier DNS is almost always unencrypted, heavily logged, and often sold to third-party data brokers.
SPEAKER_01Which is terrible for privacy.
SPEAKER_02To fix this, you must force encrypted DNS at the router level. Configure the gateway to use secure, zero logging public resolvers. Things like Cloudflare at 1.1.1.1 or Google.
SPEAKER_01But how do I know my laptop isn't just ignoring the router and using its own leaky DNS settings?
SPEAKER_02By setting a strict firewall rule.
SPEAKER_01You enable DNS over HTTPS or DNS over TLS, which encrypts the DNS request so it looks like regular secure web traffic. Crucially, you set a rule in the gateway to block all outbound traffic on standard port 53.
SPEAKER_02Port 53, what is that?
SPEAKER_01Port 53 is the unencrypted default for DNS. By blocking it, you force every single client on your network to use the encrypted resolver. It prevents DNS hijacking, local eavesdropping, and keeps the cellular carrier entirely in the dark about your destination traffic.
SPEAKER_02I love that.
SPEAKER_01There is one more hardware configuration that is incredibly practical for vehicle operations, and it has nothing to do with hackers, but everything to do with keeping your business running.
SPEAKER_02Oh, the power issue.
SPEAKER_01The power issue, yes. If I finish a remote online notarization, a RON session, I might have a massive multigigabyte high-definition audio video file that is uploading to the cloud. Right. If I get to my next appointment and turn off the car's ignition, the cigarette lighter or the inverter dies. The router powers down instantly, and that file corrupts mid-upload. State boards have literally suspended commissions over lost session recordings. This is exactly why industrial gateways are critical. To solve that, you wire the gateway directly to the vehicle's ignition sensing harness, not just a standard accessory port.
SPEAKER_00Okay.
SPEAKER_01Then you configure a shutdown delay timer in the router's software. Setting it to 30 or 60 minutes ensures the router detects that the engine is off, but continues drawing a low amount of battery power.
SPEAKER_02So it stays alive long enough to finish the job.
SPEAKER_01Yes. It gives the system ample time to securely finalize those massive video uploads without packet loss or data corruption, and then gracefully shuts itself down before draining your car battery.
SPEAKER_02It is those little operational details that separate an amateur from a professional. Truly. Now, we've secured the physical hardware and we've built a fortress around the local Wi-Fi. Let's get right into the software tunnels that keep this data moving securely across the country.
SPEAKER_01The VPN protocols.
SPEAKER_02Yes. And this brings us to a wildly frustrating scenario from Adrian in Florida. Adrian handles high volume RON closings while his partner drives them between appointments. Nice setup. It is until things break. Adrian's video feed keeps freezing and crashing every time his vehicle switches cell towers on the highway, and state laws mandate absolutely uninterrupted session recordings. If the video drops, the notarization is legally invalid, the mortgage doesn't close, and Adrian loses his client.
SPEAKER_01That's incredibly stressful. But Adrian's issue isn't the ARN platform failing, and it probably isn't his cellular signal strength either.
SPEAKER_02What is it then?
SPEAKER_01The problem is the underlying VPN protocol struggling with the physics of mobile network transitions. Security architects have to carefully evaluate tunneling protocols because they behave very differently under the stress of cellular handoffs.
SPEAKER_02Let's break down the big three protocols then. A lot of legacy corporate systems still force people to use OpenVPN.
SPEAKER_01They do. OpenVPN is the old open source workhorse. It's highly configurable and extremely resistant to deep packet inspection firewalls, especially if you run it over TCP port 443, making it look like standard HTTPS web traffic.
SPEAKER_02Okay, so it's stealthy.
SPEAKER_01It is, but it has a massive code base. Yeah around 400,000 lines of code, insecurity, complexity is the enemy. A larger code base means a larger attack surface, frequent vulnerability patching, and very heavy processor resource usage, which drains mobile batteries fast.
SPEAKER_02Got it. Then there's WireGuard, which everyone in the tech space praises for its speed.
SPEAKER_01WireGuard is incredible for specific use cases. It is lean, roughly 4,000 lines of code, making it highly auditable by security researchers. It is blazing fast because it operates in the kernel space, and it uses modern, highly efficient cryptography like ChaChat 20 for symmetric encryption.
SPEAKER_02Stop right there, Chachoney. Don't let the fun name fool you, but explain why it's better for mobile than the older AES standard we always hear about.
SPEAKER_01Think of it like packing a suitcase. Older encryption methods like AES require hardware acceleration to be fast. They need you to fold everything perfectly, taking up time. Specific computing resources, Chacha 20 is a stream cipher. It essentially vacuum seals the data instantly on the fly, regardless of whether the hardware has a dedicated cryptographic chip. That is why it is so much faster and less battery intensive for mobile tablets and phones.
SPEAKER_02Okay, so WireGuard is fast, secure, and lean. Why doesn't Adrian just use WireGuard to fix his video dropping issue?
SPEAKER_01Because of a massive catch for mobile users. WireGuard relies on stateless roaming.
SPEAKER_02Explain what that means when I'm driving down the interstate.
SPEAKER_01When you drive from one cell tower sector to another, your cellular carrier frequently tears down your connection and assigns you a completely new IP address. Sure. Because WireGuard is staless, it doesn't maintain a constant awareness of your session. When your IP address suddenly changes, the protocol gets confused, drops the tunnel, realizes you are at a new address, and initiates a brand new handshake.
SPEAKER_02And how long does that take?
SPEAKER_01That entire process takes a few seconds. That causes a brief reconnection loop. For loading a web page, you won't even notice. But for a continuous, high-definition RON video feed, that brief loop drops the stream, violating the legal requirement for continuous recording.
SPEAKER_02Wow. So if OpenVPN is too heavy and WireGuard drops the video during tower handoffs, what is the actual solution for a moving vehicle network?
SPEAKER_01IGF2 IPsec. It was built specifically for mobile environments from the ground up. It utilizes the Mobike extension, officially defined in RFC 45505.
SPEAKER_02What does Mobike actually do?
SPEAKER_01It allows a mobile client to seamlessly change its IP address without dropping the underlying security associations.
SPEAKER_02So it knows you moved.
SPEAKER_01Right. When your car hits a new cell tower and get the new IP, Mobike simply updates the address in the background without tearing down the cryptographic tunnel. Your video feed stays perfectly stable, frame by frame, while switching towers.
SPEAKER_02That sounds like the silver bullet. Is there a downside?
SPEAKER_01There's always a catch. The catch with IKV2 is that it relies strictly on UDP ports 500 and 4500. It is a very rigid protocol. If you park at a hospital, a military base, or even a highly secure corporate client's office and try to use their guest network, their enterprise firewalls will almost certainly block those specific UDP ports, and IKE2 cannot disguise itself to bypass it like OpenVPN can.
SPEAKER_02Which is exactly why the entire cybersecurity industry is shifting away from traditional VPNs entirely, moving towards ZTNA 2.0 zero trust network access.
SPEAKER_01Precisely.
SPEAKER_02I love explaining ZTNA with this analogy. A traditional layer three VPN like OpenVPN is like giving someone the master key to a corporate office building. Once they authenticate at the front door, they are inside the building. They can wander the halls, jiggle every doorknob, and see what servers are vulnerable. Yep. But ZTNA is like a VIP bouncer. The bouncer checks your ID at the door, escorts you down the hall directly to one specific room, lets you only interact with the exact files in that room, and watches your every move the entire time.
SPEAKER_01That is the perfect analogy. ZTNA enforces layer seven per application micro-segmentation. It operates on a strict, never trust, always verify model. Instead of connecting your laptop to a corporate network, your device connects to a secure cloud trust broker.
SPEAKER_02Okay, so the broker sits in the middle.
SPEAKER_01Their broker acts as a middleman. Before it connects you to the Auron platform, it performs continuous endpoint health checks.
SPEAKER_02What exactly is it checking?
SPEAKER_01It is verifying your multi-factor authentication, checking your operating system patch level to ensure you aren't running vulnerable software, ensuring your host firewall and endpoint detection software are actively running, and it can even check your GPS markers to ensure you are physically located within your commissioned state's borders, which is a massive compliance requirement for remote notaries.
SPEAKER_02So what happens if the worst case scenario occurs? Say I am connected via ZTNA, I'm in the middle of a session, and somehow my laptop gets compromised by a zero-day exploit. Does the hacker get access to everything I'm connected to?
SPEAKER_01No. And that is the beauty of microsegmentation. Because the underlying network infrastructure is completely cloaked from the user, and you are only granted access to a single application session through the broker, the attacker cannot scan the network or move laterally. Exactly. They can't jump from your laptop to the title company's servers. The breach is completely isolated to that single localized instance.
SPEAKER_02That level of isolation is crucial, especially when we transition into the core of what we do. The identity verification and the cryptographic seals that actually make a digital document legally binding in a court of law.
SPEAKER_01Right. This is where it gets very serious.
SPEAKER_02Let's look at two complex scenarios that highlight this. Penelope and Connecticut shared her on-platform login password with her administrative assistant just to help set up a high-volume session.
SPEAKER_01Big mistake.
SPEAKER_02Huge. Meanwhile, Julian in North Carolina had his business email compromised by a sophisticated phishing attack. The central question for both of them is how do we prove to a judge that the digital seal wasn't misused by an impersonator?
SPEAKER_01This gets to the absolute heart of what a digital signature actually is versus a simple electronic signature. We have to draw a hard line between those two terms. Please do. An electronic signature is just a type name, a click checkbox, or a digital image of your wet signature pasted onto a PDF. It has no inherent security, no cryptographic backing, and is incredibly easy to forge.
SPEAKER_02Right. I could copy and paste your signature image onto a contract in five seconds.
SPEAKER_01Exactly. A digital signature, however, is a cryptographic seal, specifically a paid easy B tamper evidence seal built on public key infrastructure or uh PKI.
SPEAKER_02Breakdown PKI for us. This requires the notary to have an X.509 compliant digital certificate from an accredited certificate authority like Identrust, correct?
SPEAKER_01The Certificate Authority acts as the ultimate digital notary for you. They background check you, verify your identity, and issue you a digital certificate. This certificate contains a public key, which is mathematically bound to a private key.
SPEAKER_02Okay.
SPEAKER_01The strict unbending legal requirement here is soul control.
SPEAKER_02And that is where Penelope and Julian failed.
SPEAKER_01Completely. The digital certificate proves your identity, but you must maintain absolute soul control over your private key, which is usually secured by a strong password, a physical smart card, or a biometric token. By sharing a password with an assistant, Penelope legally invalidated every notarization done under that credential because she cannot prove she was the one who applied the seal.
SPEAKER_02Wow. And Julian.
SPEAKER_01Julian, losing control of his email, is equally dangerous if his private key recovery was tied to that inbox. It fundamentally breaks the chain of trust.
SPEAKER_02But the major RON platforms, companies like Proof, DocuSign, NotaryCam, they know humans make mistakes. They have built-in countermeasures to defeat that kind of impersonation, even if an email is hacked or a password is shared.
SPEAKER_01They do. They rely on what we call the five layers of on security.
SPEAKER_02Let's walk through them.
SPEAKER_01The five layers are a verification gauntlet. Before a signer or even a compromised notary credential can execute a live session, they must pass these checks. First is knowledge-based authentication or KBA.
SPEAKER_02The famous credit questions. Which of these streets did you live on in 2014?
SPEAKER_01Precisely. The system generates dynamic out-of-wallet questions directly from Credit Bureau databases. The signer must score at least 80%, usually answering five questions in under two minutes. Hackers who stole an email password rarely have access to a victim's 20-year credit history to answer those quickly.
SPEAKER_02Second is credential analysis. The signer holds their government ID up to the camera. It's not just a person looking at it. AI algorithms scan the ID, checking optical variable details, holograms, machine readable zones, microprinting, and expiration dates for any digital signs of tampering or forgery.
SPEAKER_01Third is biometric verification. The platform uses facial recognition algorithms to compare a live, 3D biometric scan of the signer sitting in front of the webcam to the 2D photo on that newly verified ID.
SPEAKER_02And it checks if they're real, right?
SPEAKER_01It requires liveness detection, making the signer turn their head or blink to ensure a hacker isn't just holding up a printed photograph of the victim to the camera.
SPEAKER_02Fourth is the live visual verification. This is where the human element returns. The notary looks at the signer on the high definition video feed, confirms their identity against the ID, checks for signs of duress or coercion, and confirms their willingness to sign in real time.
SPEAKER_01And finally, the fifth layer is the application of the digital seal in the full session recording. The platform applies a tamper evident SHA 256 hash to the final PDF.
SPEAKER_02Let's explain hashing because it sounds intimidating. How does a hash actually stop tampering?
SPEAKER_01A hash function takes a digital document and runs it through a complex algorithm to generate a unique fixed-length string of letters and numbers, a digital fingerprint. Let's say you hash a 50-page mortgage document.
SPEAKER_02Okay.
SPEAKER_01If someone tries to alter that document after the signing, if they change a single decimal point on the interest rate or alter a single pixel in the signature line, the document's underlying data changes. If you run it through the hash function again, it generates a completely different fingerprint. The PDF reader instantly compares the new fingerprint to the original one sealed by the notary, sees the mismatch, and throws a massive red warning that the document has been tampered with.
SPEAKER_02Let me put on my overwhelmed business owner hat for a second here.
SPEAKER_01Let's hear it.
SPEAKER_02We are throwing around terms like SHA 256, X.509, NCS, PKI. It sounds like cryptography alphabet soup. I just want to stamp documents and get paid. Why do I, as a notary, need to care about specific encryption algorithms, especially with this FIPS 143 deadline looming in 2026?
SPEAKER_01You have to care because the federal government is aggressively rewriting the rules on what is considered legally secure. And ignorance is not a defense against compliance failure. Fair enough.
SPEAKER_02So what happens on September 22?
SPEAKER_01On September 22, chaos for anyone who didn't prepare. All legacy cryptography, algorithms like SHA1 for signatures or RSA 1024 keys are officially banned for federal and financial sector transactions.
SPEAKER_02Banned. Wow.
SPEAKER_01If your digital certificate or your RON platform still uses those deprecated algorithms on September 22, your notarizations will be rejected by title companies, Fannie Mae, and County Recorders. The transactions will simply fail.
SPEAKER_02So any hardware token or software module you use has to be FIPS 143 validated. What makes 143 so much tougher? Why the transition?
SPEAKER_01FIPS 143 aligns with international ISO standards and introduces incredibly aggressive testing for non-invasive side channel attacks.
SPEAKER_02I need an analogy for a side channel attack. How does someone steal a private key without actually hacking the software?
SPEAKER_01A side channel attack is like figuring out the combination to a bank vault, not by guessing the numbers on the dial, but by holding a stethoscope to the door and listening to the microscopic clicks the gears make when they turn.
SPEAKER_02Oh, that's wild.
SPEAKER_01Hackers do this to computers. They literally measure the heat fluctuations, the electromagnetic emissions, or the microsecond variations in processor timing on your laptop while it is generating a digital signature.
SPEAKER_02You're kidding.
SPEAKER_01I'm not. By analyzing the electricity coming off your machine, they can reverse engineer and extract your private cryptographic keys without ever breaking your passwords.
SPEAKER_02That is terrifying.
SPEAKER_01It is, and it is a reality. FIFS 140-3 validation ensures your cryptographic hardware and software modules have dedicated physical and logical mitigations to scramble those emissions and defeat those specific extraction methods.
SPEAKER_02So it's non-negotiable.
SPEAKER_01If you are handling mortgage closings, federal documents, or sensitive NPI in late 2026, you simply cannot operate without it.
SPEAKER_02Okay, so the technical standards are getting highly harmonized at the federal level, which is good. But the administrative laws we have to follow are still an absolute mess. Which brings us to the massive, glaring issue of contradictory compliance.
SPEAKER_01This is the administrative nightmare for modern mobile notaries. Because you handle non-public personal information during real estate and financial transactions, the Graham Leach Flyley Act legally categorizes you as a non-banking financial institution. Right. That designation places you directly under the jurisdiction of the Federal Trade Commission's safeguards rule.
SPEAKER_02And this is where the paradox happens. The FTC safeguards rule mandates that you must securely destroy and purge all customer NPI. That means draft documents, temporary ID scan uploads, transition caches. You have to purge them within two years of its last use to minimize the impact of a data breach.
SPEAKER_01That's the federal rule.
SPEAKER_02But state notary statutes demand that we retain our electronic journals and the encrypted audio video recordings for seven to ten years. Right. How in the world do you reconcile a federal mandate to delete data with a state mandate to preserve it?
SPEAKER_01It requires meticulous architectural planning. The only solution is strict data isolation within your storage environment.
SPEAKER_02How do you set that up?
SPEAKER_01Short-term transaction data, draft contracts, and ID verification caches must be segmented into a temporary holding zone. You have to configure automated lifecycle policies to purge that specific data segment to appease the FTC's strict two-year window.
SPEAKER_02Okay.
SPEAKER_01Conversely, the official cryptographic hash chains, the final sealed PDFs, and the MISMO certified audio video recordings must be transferred immediately to an immutable tenant isolated cloud repository designed specifically for that seven to ten year retention lifecycle. You have to split the data based on its legal classification.
SPEAKER_02You also have a requirement under the FTC rule to formally designate a qualified individual to manage this written information security program. I get questions about this constantly. Do solo operators really have to hire a chief information security officer?
SPEAKER_01No, no, you don't need to hire an executive. A solo notary can designate themselves, or they can contract a virtual CSO.
SPEAKER_02Okay, that's a relief.
SPEAKER_01But the key is documentation. You cannot just assume the role in your head. You must have a formally documented security policy signed by you, stating that you are the qualified individual responsible for overseeing vendor risk, network security, and data purging.
SPEAKER_02And there are physical digital conflicts in the state laws, too. Look at states like California and Arizona.
SPEAKER_01Yes, those are prime examples of the friction between legacy laws and modern tech. Those states legally require that any notarization affecting real property, like grant deeds, quit claim deeds, or durable powers of attorney, it must capture the physical ink thumbprint of the signer in the notary's physical journal.
SPEAKER_02Which makes sense for fraud prevention in 1995. But when you try to execute a transaction on a modern remote platform, you run into a severe workflow clash. It's a mess. I am sitting across from a signer doing everything digitally on a tablet, and suddenly I have to pull out a black ink pad and a paper journal just for a thumbprint.
SPEAKER_01Right. You are forced to run a hybrid workflow. You are managing the digital audio video session, applying cryptographic seals, and simultaneously collecting paper-based thumbprints that cannot be digitized under current statutes.
SPEAKER_02Is there any way around that?
SPEAKER_01Alternatively, you rely strictly on fully remote platforms that have spent millions of dollars to successfully certify alternative, state compliant identification mechanisms that satisfy the thumbprint requirement digitally. But, you know, those are rare and expensive.
SPEAKER_02It is a delicate, often frustrating balance of navigating localized physical statutes while answering to massive federal digital privacy mandates.
SPEAKER_01It really is.
SPEAKER_02We are wrapping up our time today. If you take away anything from today's high-level analysis, let it be the concept of defense in depth. Security is not a single software toggle you flip in a settings menu. Not at all. It is an ecosystem. It is zero trust network access blocking lateral movement. It is the physical lockdown and visual privacy countermeasures of your vehicle. It is proactively upgrading your infrastructure to FIPS 143 cryptography well before the 2026 NIST deadline. And it is gracefully navigating the razor-thin line between federal privacy data purges and state level retention laws.
SPEAKER_01Every single layer matters. A failure at any tier compromises the whole. The physical hardware protects the network, the hardened network protects the live session, and the advanced cryptography protects the final legal document.
SPEAKER_02Absolutely.
SPEAKER_01But looking at this chaotic, often contradictory patchwork of state-by-state RON laws, I want to leave the listener with this final thought to consider. The Secure Notarization Act is slowly making its way through federal legislative channels, aiming to establish nationwide baseline standards for remote notarizations across all 50 states.
SPEAKER_02Oh, that's going to be interesting.
SPEAKER_01Will this federal harmonization finally resolve the administrative nightmare of operating across state lines? Or will it simply ignite an even more complex, prolonged web preemption battles between local state jurisdictions fighting to maintain their authority and federal privacy watchdogs enforcing a national standard?
SPEAKER_02That is the multimillion dollar question on the horizon. And how it plays out will redefine this industry forever. We want to hear your thoughts on it. Email your questions to Derek at DerekSbrule.com. We will try to answer as soon as possible at the end of our shows.
SPEAKER_01Exec producer Derek Sprill, lead writer Marilyn Lee Trotter, Graphics Eddie Montez, Travis, Music Thomas Bynum, produced by Magnificent Works Business Solutions.
SPEAKER_02Don't just be listener of the knowledge, be doers of the knowledge. This is notary knowledge. Until next time.
SPEAKER_03Are you truly protected as a notary public? Navigate the complex legal framework with confidence using notary law and liability by Derek Spruil. This essential guide provides a deep dive into state regulations, ensuring you stay compliant across jurisdictions. Learn how to properly use errors and omissions insurance and master the critical boundaries to strictly avoid the unauthorized practice of law. Protect yourself, your commission, and your business. Get your copy of Notary Law and Liability by Derek Spool on Amazon.