From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control.
- Trusting an open source AI proxy might bite you.
- France's under-15 social media ban hits its constitution.
- A bit of AI prompting found a serious bug in Zoom.
- AI-based network defenders see a stock price jump.
- A (very) deep dive into the operation of AI chatbots
Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit
Sponsors:
[00:00:00] It's time for security now. Steve Gibson is here. Of course, there's a lot of security news, including, yes, a supply chain attack. France's under 15 social media ban hits its constitution. That's not a bad thing. But this is what we call in the business a propeller hat episode. Steve is going to take a very deep dive into AI, how chatbots are made and unmade.
[00:00:27] This is a fascinating episode next on security now. Podcasts you love. From people you trust. This is TWIT. This is security now with Steve Gibson. Episode 1092, recorded Tuesday, August 18th, 2026. Restraint Abliteration.
[00:00:55] It's time for security now. The show we cover the latest in security, privacy, computing, science fiction, vitamin D, and anything else on this man's mind because he is a genius. Ladies and gentlemen, I give you Steve Gibson. Hi, Steve. So thank you, Leo. What our listeners are going to find is that. So excited about this show, by the way. You gave me a preview, folks.
[00:01:24] Is that I did not get to the two topics that I wanted to. Oh, no, I only got to one because I started laying down the foundation for the topics. And there was just so much to say. I'm you know, my only defense for this being about AI is that the world is and security certainly is.
[00:01:54] I mean, we I don't have to even explain that anymore. As we said, Black Hat a couple of weeks ago was like the A.I. conference that happened to be doing security as the reason for spending all that money. As I'm OK, I look back at the tutorials on the Internet, how it works and computing and how it works.
[00:02:18] And there I was able to share with our audience things that I had understood for quite a while. In the case of A.I., I'm a I'm a, you know, a lay person, neophyte, rank amateur, but I'm a curious researcher and I've been reading research. So what I'm going to be doing over.
[00:02:46] I have no choice really is because it excites me is I'm beginning to develop a understanding at the level I want to remember. I program an assembler. So I would I say I understand something I for me to meet for me to be satisfied. I have to understand, well, is the carry bit set or not?
[00:03:13] So but at the same time to make it understandable. So I think most of what I look at the things we're going to talk about, we're going to talk about how trusting an open source A.I. proxy might bite you.
[00:03:28] France is under 15 social media ban, a bit of A.I. prompting turned up a new serious bug in Zoom and that the the stock prices of A.I. based network defenders has jumped up after that black hat conference.
[00:03:50] And that's all we had time for, because the rest is me sharing a bunch of new understanding that I have that I think our listeners are going to appreciate. So and actually not that much. I mean, I didn't skip any fantastic news. I looked for all the good things. We got a great picture of the week.
[00:04:14] And by the by two hours from now, everybody listening is going to understand unless they already do. They might. But we'll understand what I now understand about. The early first steps of how A.I., as we know it today, happened, what were those things?
[00:04:39] And for example, Leo, you were first out of the gate saying it's nothing more than fancy autocorrect. Turns out that next token prediction is all it did in the beginning. That's what it was. This was I said that in my defense a year and a half ago. I mean, that's my point. No, and that's my point. Then it was true. And also, Matthew Green, we quoted him last week saying it's not fancy autocorrect. It's not just the next token, the next token, the next token.
[00:05:08] Because of what happened between. And I understand now, and I'm going to explain how we got from next token prediction to you can have a dialogue. Because that's a very that's a those are different things. And and it's a little freaky how. I want to say how easy it was, but it also led me to have a conversation with Claude about its own nature.
[00:05:36] So anyway, I think a great podcast for our listeners. I titled this restraint obliteration, not obliteration, but obliteration, because that's actually the the term of art, which is used for some of what happens or can happen with open weight models. So we're going to buy again.
[00:06:00] All I can say is two hours from now, you're going to be like, oh, I understand a lot more than I did. And you'll probably at that point, you'll understand about as much as I have. But I'm not I'm not. In other words, this is a brain dump. This is going to be Steve's brain dump. So he has some room to read more papers. That's correct. But I already know what the next one is. Oh, good. It's so exciting. Yeah, it's so fascinating. And actually, I'm really glad you're digging into it.
[00:06:29] I don't have a choice, Leo. This is the most important thing that has happened in my 71 years of life. You could say, well, OK, computers. Yes, I was programming them on a PDP eight in high school. Internet. Yes, we watched all that happen. But but this is knowledge. I mean, those I mean, yes, we needed to have computers. Well, it's a stair step. Yeah, we got we had to have the Internet for training. We had to have the computers, of course.
[00:07:00] You know, I would throw mobile in is another big revolution. The idea that you have the Internet everywhere you go in your pocket. Yes. And a significant amount of computing. But and of course, if it weren't for gamers, we wouldn't have these video cards. It turns out are really good at A.I. as well. So it's all been you know, it's always the case. It's always been a stair step. And of course, this is for curious people, right? You don't have to understand how any of this works in order to use it.
[00:07:29] Any more than you do a computer. Right. Most people have no idea how a computer works. The Internet is magic. A.I. is a worry because what's going to happen? So, again, you can use it without understanding it. But here in our little, you know, little corner of the world, we like to understand how these things work. So we're all going to understand how A.I. works. It's pretty amazing.
[00:07:56] I mean, and actually, there is a continuity. A.I. is I'm sure when you were at the Stanford A.I. lab sale in the 70s. 73. You know, when John McCarthy, the creator of Common Lisp was there. I mean, this is with his gray ponytail. This is ancient history.
[00:08:17] But even then, the vision was what we would like to do with these computing devices is talk to them and interact with them in a natural way as we do with other people. Well, now you can. And it just blows me away that we have made sand think is mind boggling. And as Jeffrey Hinton says, the way we did is by applying huge amounts of electricity.
[00:08:45] He says, and it's really interesting, the talk I sent you. He says, human brain is designed for low power analog, right? And so its design is designed specifically for the kinds of things we could have. But once we figured out how to do ones and zeros and keep it accurate, our brains are not accurate, but ones and zeros. And he says, if you apply enough power, the one stays a one and the zero stays a zero, right?
[00:09:12] It's all about applying really a vast amount of electricity to these things. Once you could do that, then you have something that is analogous but not the same as a brain and can do some interesting things. And that's what we're going to talk about next on Security Now. Don't get obliterated. You might want to get obliterated, but wait until after the show. We're going to talk about that and more, but first a word from our sponsor.
[00:09:38] And I have to say, now that I have this little lab here up in the studio, this AI lab, it's even more important to me that I have a Thinkst Canary, our sponsor for this part of Security Now that we've been friends with and they've been sponsors of our shows for a decade now. In fact, we were the first place they came when they first invented Thinkst Canary. Thinkst Canary was invented by a team, love these guys, met them at RSAC actually for the first time.
[00:10:06] We've talked for years, but I finally got to meet them because they're in South Africa. But these guys were brilliant hackers. They were white hat, but they taught companies how to penetrate systems, how their systems might be penetrated. And one of the things they learned, as many hackers do, is the best way, the best defense against hacking, of course, a good perimeter, but you need a honeypot. You need a way of knowing if somebody has breached your perimeter and is wandering around in your network.
[00:10:35] And I bet most of you watching don't have a way of knowing. You could look at the logs, but a good hacker is not going to let you see anything. They erase their traces. We know that. That's why at the very beginning, people like Bill Cheswick and Cliff Stoll, who were able to see there's somebody in our system. Cliff Stoll found out because there was a fraction of a cent difference in a calculation. It was that tiny. But he said, wait a minute, something's wrong.
[00:11:05] These guys said, you know, what you really need is something on that network that a hacker can't resist. A little piece of candy, a little something, something that the hacker, if he's gotten in, will trigger and let you know he's there. That's a honeypot. Now, when Ches wrote the first honeypot, he's even told us this. It was a hard thing to do. But thank goodness these guys at Thinx have figured out how to make the perfect honeypot, the Thinx Canary. It's so easy to use.
[00:11:34] It looks like a little USB device. I'd show you mine, but you better believe it's on the network now, man, doing its job. Because if someone is inside your network and you've got these honeypots that could, by the way, be deployed in minutes, plus could create tripwires, little files that phone home to the Thinx Canary and say, somebody's trying to open me.
[00:11:55] If somebody's accessing those LUR files or they're trying to brute force that whatever it is, fake internal SSH server or Linux box or Windows box or SharePoint server can impersonate anything. You're going to get your Thinx Canary. I'll immediately tell you, you've got a problem because nobody should be accessing this. There's no false alerts, just the alerts that matter. And in the way you want them, text message, of course, Slack, email, they support webhooks.
[00:12:22] They've got an API, they've syslogged, whatever it is, any way you want. All you have to do is choose a profile for your Thinx Canary device. It's so easy, by the way, you might change it regularly. I do. You just sit back and you relax, you wait. Attackers who've breached your network, malicious insiders, any other adversary that's in your network and shouldn't be cannot help but make themselves known. They can't resist it.
[00:12:50] They're going to access that file or that Thinx Canary and you're going to get an alert. You got to go to canary.tools. 7,500 bucks a year. You get five Thinx Canaries. Of course, you get your own hosted console. You get upgrades. You get support. You get maintenance. And I'll tell you what else you get. If you use the code TWIT in the How Did You Hear About Us box, you get 10% off the price. And not just for the first year, for life. Oh, and if you're at all concerned, like, do I need this thing? You can always return your Thinx Canary.
[00:13:19] They've got a two-month, 60-day money-back guarantee for a full refund. I should tell you, though, in this whole decade that they've been partnering with us, doing these ads, 10 years, that refund guarantee has never been claimed. Not even once. Visit canary.tools.twit. Canary.tools.twit. Enter the code TWIT in the How Did You Hear About Us box. Thinx Canary. I'm so glad I have one.
[00:13:46] Now that I have something on my network, I really want to protect my AI. I want to make sure that nobody's in here messing around. All right, Steve, picture of the week time. So this picture generated a great deal of feedback, furor, hubbub from our listeners. The email went out. I forgot to mention a week or two ago that I broke 21,000 subscribers. Wow.
[00:14:15] So we're north of 21,000. You've got more subscribers than TWIT has club members. That's very nice. Good job. That's well. And I... That's because it's free, I might add. Yeah. Yes. And great feedback. So first of all, I gave this picture the caption, this actually happened in Albania.
[00:14:40] Was it an accident or a very clever way to create a bridge across the river? All right. I'm scrolling up for the first time. I haven't seen it. Wait a minute. There's a bus. Whoops. Now... Wow. You wonder, looking at this. So for those who are not seeing the video, we have a long, very green...
[00:15:08] It's got go green hybrid city bus. I mean, it's long enough that it's got a door in the front. It's got doors halfway down its length. And then it's got rear doors. It's good it's not one of them articulated buses, though. I don't think it would serve as well as a bridge. That would be a problem. Yes. Yeah. And somehow this darn bus is straddling the river. And... But what I noticed about it first...
[00:15:38] Well, after I actually... After I got over the fact that it was there... Was that it's so long... And it's got doors in the front and rear... And the fact that you're able to walk the length of the bus... It's a bridge. It is a bridge now. So... I think it's telling the middle doors are not open. Yes. You don't... Unless you wanted to fish, then it would be good. You could, you know, sit there and dangle your feet out and fish. Anyway, Leo, this actually happened.
[00:16:07] One of our listeners found the... I have a link at the bottom of the picture of the news... Because some people who didn't see that said, oh, that's AI. That's that... How could that bus possibly get into that position? Because you would think, looking at it, it would just go nose down into the river. Like, right? How could it, like, get on the other side? It turns out it's the bizarrest accident.
[00:16:35] And by the way, you know it's not an intentional bridge because there is crime scene tape across the bottom. That's true. They don't want people to use this. They're trying to keep people out. No. There's a... One of our listeners found a... One of the news reports where they did an animated recreation of the accident. There was a Mercedes being driven by a younger man. And I read the news report.
[00:17:05] I don't remember the ages, but he was like 27 or something. And so now there you can see a picture. And notice underneath the front, Leo, are white lights. Yeah. Is that the Mercedes? That's the Mercedes. Oh, God. Not good. The Mercedes was driving to the left of the bus when the bus driver lost control. Turned to the left. Knocked the Mercedes off the road.
[00:17:32] It preceded the bus into the river, flipped upside down, and the bus rolled over it. So Mercedes formed a brief stone in the middle of the bridge that allowed the bus... No deaths, thank goodness, but six people were injured. Here's another picture of the scene. Yeah. Wow. Holy cow. The Lana River. So I guess...
[00:18:00] I would have said Photoshop for sure. Yeah. It's nuts. It's nuts. I mean, you needed another car there for the bus to drive over the car in order to get to the far side. And then they pulled the car out from underneath. Crazy. So, wow. Crazy. Well, I'm glad the driver survived. Anyway, thank you, one of our listeners who sent this to me and thought maybe this would be a good picture of the week. And I agree. Okay.
[00:18:28] So, as I promised last week, there are two very important pieces of core AI technology that I wanted to discuss. And I also promised last week that we were going to do a deep dive into aspects of the operation of today's AI. Well, that turned out to be more true than I expected.
[00:18:53] So much so that it entirely crowded out the second of the two topics that I had planned to get to. But fear not. We're going to have another deep dive into that next second topic next week. And that's the role confusion topic, Leo, which you and I talked about at Black Hat, the research paper that I read during the flight there. And I said, OMG. How? Wow.
[00:19:24] Can that still be the way things are being done today? And I've confirmed, yes, unfortunately, it is. Not as weird as a bus crossing the river, but it's close. It's close. It's up there. Okay. So we're going to start by covering some important recent security events and then get into understanding this first of the two core issues of the way AI works.
[00:19:48] Last Wednesday, Ars Technica's great security topic writer, Dan Gooden, reported under the headline, terabytes of credentials leaked in massive supply chain attack was Ars headline. And, of course, that was the kind of thing I would have chosen to share even a few years ago.
[00:20:12] But the thing that raised my interest another several notches was the article's tagline, which read that data, that is the terabytes of credentials, was scraped and exfiltrated from 2,500 users of a compromised AI package. So I thought, whoa, okay. Okay.
[00:20:34] It turns out what's even more significant is we're not talking some random end users in Nebraska, you know, who no one knows. Wait till you hear whose credentials were among the more than 2,500 that were stolen.
[00:20:49] So Dan writes, terabytes worth of credentials, many belonging to the world's biggest and most sensitive organizations, have been exposed in a supply chain attack on Light LLM, an open source tool that streamlines AI-driven software development.
[00:21:11] Microsoft, Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful, he writes, of the entities whose access secrets were exposed. The revelation was posted on Tuesday and Wednesday, that's last week, by security firms CloudSec, you know, S-E-K, and Hudson Rock.
[00:21:35] CloudSec said it found keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations. And 40 minutes is all it took.
[00:21:59] The credentials were extracted during a 40-minute window in March, while the victims used, obviously unknowingly, compromised versions of Light LLM, which had been downloaded from the package's official location in the Python package index repository, you know, PyPI.
[00:22:22] Hudson Rock said it made the discovery after analyzing a 195-terabyte file that it had obtained. Neither firm identified the source of the information. The Light LLM compromise was the result of a, get this, Leo, a previous, this will ring some bells, a previous supply chain attack that infected the widely used vulnerability scanner, Trivi.
[00:22:52] And remember that we had talked about this months before. Other software infected in the campaign includes KICS and the Telnix Python SDK. Team PCP, which Dan describes as a ramshackle but extremely capable gang, largely made up of teenagers, took credit for the attack, and researchers have largely corroborated their claim.
[00:23:21] Independent security researcher Kevin Beaumont said, quote, I've confirmed the data is legit. By the way, multiple victim orgs. He said it contains a significant volume of sensitive content at orgs. It's a massive supply chain breach due to poor AI security.
[00:23:45] Not because AI is the threat, but teens can now run circles around orgs obsessed with rushing out AI and poor DevOps security. And I'll just explain that a little bit here. I'll take a moment. Light LLM was compromised. It's not that AI was used in the compromise.
[00:24:12] It's that, you know, Kevin is saying that the way Light LLM is used, the way it needs to be used, that is to be a proxy for other AI services, means that you need to give it all your secrets so it can act on your behalf. We've talked about this fundamental problem previously. And a lot of orgs just got bit by it. Anyway, I'll have more to say here in a second.
[00:24:41] So continuing, Dan writes, the compromised versions of all four software packages contained, right, four packages compromised by Trivi, contain code that accessed the memory of infected machines, scraped its contents, and exfiltrated it through an attacker-controlled channel. The data is filled with an assortment of information. And again, 195 terabytes.
[00:25:10] So it's like a wealthy, but you got to find the goodies in there. Interspersed in the wall of data are credentials to software pipelines maintained by tens of thousands of organizations that ran Light LLM during the 40-minute span that the supply chain attack remained active.
[00:25:33] In all, both security firms said some 434,000 CICD, you know, continuous integration, continuous delivery software pipelines had credentials exposed after running the compromised Light LLM versions. There were two versions that were compromised. I'll clarify that in a second.
[00:25:59] In many cases, the researchers at CloudSec and Hudson Rock had trouble identifying, which is a problem, the organizations the credentials belong to. For instance, an email address in the dump from the domain at SiriusXM.com ultimately did not indicate a breach at the satellite broadcaster,
[00:26:23] but rather within the infrastructure of SiriusXM's subsidiary, AdsWiz. A trove of internal corporate secrets were found exposing sensitive tokens for platforms such as Salesforce underscore client underscore secret and Slack, Slack underscore signing underscore secret and Microsoft Azure environments.
[00:26:52] The researchers had high confidence that the researchers did have their credentials exposed. Get this.
[00:27:45] I mean, wow. Hudson Rock said, many CICD pipelines are configured generically. The dumped variables contain active database passwords, third-party API keys, and cloud credentials without any identifiable company email, custom domain string, or internal server name.
[00:28:09] This means that countless organizations, which they were unable to identify currently, as in still have active secrets sitting in this database. They are completely unaware of their exposure. The research firms, I should note, immediately identified all the companies that they could among those I just read.
[00:28:34] But lots of other companies, like what, 434,000? Was it different CICD pipelines? All their secrets are out there, and they haven't been notified because it's not clear who they are. So maybe that's safety. I mean, the bad guys probably can't tell either. But it certainly gives you some starting credentials to use for some password guessing.
[00:29:03] Finally, under the heading, welcome to the new world of supply chain attacks, Dan adds, both firms, those two security firms, are urging all organizations that use the compromised versions of Light LLM, particularly those listed in the high confidence section of the list, the organizations that are known to thoroughly rotate all credentials in their pipelines.
[00:29:31] Hudson Rock instructed any organization that uses any AI proxy infrastructure, third-party CICD vulnerability scanners, or downstream AI packages to immediately audit their environment for versions, 1.82.7 and 1.82.8 of Light LLM, which were the two compromised versions of the software.
[00:29:57] The firm advised those affected to perform, quote, aggressive credential revocation, unquote, assume any secret accessible to the Light LLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, the GitLab, GitHub PATs, and audit logging and egress filtering.
[00:30:24] As a cautionary tale, CloudSec said that Trivi developers rotated but failed to fully revoke an automation token over a 20-day window. That lapse gave the attackers a nearly three-week period in which to force-push malicious code to third-party builds that use the vulnerability scanner.
[00:30:48] As Beaumont observed, organizations rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage, meaning just, you know, as we've seen. And Leo, remember when you immediately thought, hey, this – I can't remember the name of it.
[00:31:13] It was the package that came out at the beginning of the year that was the code writing, Claw. Clawed? What? No, no, Claw. OpenClaw. Oh, Clawbot. Yeah. Yeah. OpenClaw. Yeah. So, yeah. So, OpenClaw happened. You were excited about it, but you pulled back – I didn't use it. At the last minute. And it turned out that was – Yeah.
[00:31:38] There was just – you had to tell it too much in order to allow it to do what you wanted to do. But, yeah, if you wanted it to do anything, you gave it your email, you gave it money, you gave it a phone number. Exactly. A little dangerous. So, then, okay, in a final update to his initial reporting of this massive mess, Dan added,
[00:32:00] there are already signs that some of the affected organizations are not taking the disclosure with the seriousness warranted. After this post went live, he writes, Kevin Beaumont reported, quote, These creds date from about March. One of the orgs impacted told me, he writes, they'd rotated them all and it's a nothing burger.
[00:32:27] He said, so, I looked at their responsible disclosure policy. It allows trying creds. So, I tried them all. Almost every one of them worked. He said, I submitted a report. One of the biggest U.S. telcos. So, if someone said, oh, yeah, we don't worry about it. We rotated our credentials. Nothing to see here.
[00:32:55] They probably made new ones but didn't delete the old ones is what they did. Jeez. So, ultimately, the new revelations concerning the light LLM supply chain attack underscore is writing, Dan, the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.
[00:33:21] Alon Gall, co-founder and chief technology officer of Hudson Rock, wrote in an email, quote, Now, the key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously.
[00:33:40] A window of roughly 40 minutes in which the light LLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.
[00:34:06] And Lord knows, you know, we've been unimpressed typically by the kind of responses that we've seen historically. So, just to be clear that the cautionary takeaway from this is not a case, as I said before, of AI going rogue or any kind of AI misuse. You know, I followed Dan's reference links back to one of Hudson Rock's reports,
[00:34:34] whose much more technical write-up of the breach makes what happened actually further clear. Their headline, Hudson Rock's headline was largest AI supply chain breach of 2026, colon, light LLM hack impacts thousands of global enterprises. And Hudson Rock explains quickly,
[00:34:58] The cybersecurity landscape is currently reeling from one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. The orchestrated, I'm sorry, orchestrated by a threat actor group known as Team PCP,
[00:35:17] This cascading attack ultimately compromised Light LLM, a widely adopted open source AI proxy gateway, leading to the silent exfiltration of deep developmental secrets from thousands of continuous integration and continuous deployment pipelines worldwide.
[00:35:42] Excellent forensic research published by SYNC, you know, that's S-N-Y-K, Trend Micro and Psycode has thoroughly detailed the mechanics of this breach. The attack did not begin with Light LLM. Instead, Team PCP first compromised the GitHub Actions Pipeline for Trivi,
[00:36:09] a highly popular open source vulnerability scanner. Because the developers of Light LLM utilized Trivi in their own CICD pipeline, the poisoned security scanner was granted legitimate read access to their runner environment.
[00:36:32] This allowed the attackers to silently exfiltrate Light LLM's PyPI publishing tokens. Armed with these credentials, Team PCP was able to publish malicious versions of the Light LLM package, versions 1.8.2.7 and 1.8.2.8. The payload delivery was exceptionally stealthy.
[00:37:01] By utilizing a .pth Python startup hook, the malicious code was executed the moment the Python interpreter initialized, regardless of whether the Light LLM library was explicitly imported. The three-stage payload immediately began harvesting environment variables,
[00:37:26] local configuration files like .kub slash config and .aws slash credentials, attempted lateral movement across Kubernetes clusters, and installed a persistent SystemD backdoor. While the security community has deeply analyzed the malware's behavior, Hudson Rock has independently obtained the actual fallout, the raw exfiltrated data.
[00:37:56] That's that 182 terabyte of data. I mean, talk about a huge amount of data in 40 minutes. I mean, because there were that many instances of those two versions of the malicious Light LLM that were updated from Python PI and installed and started, and all the credentials poured through it,
[00:38:22] and they sent them all off to some malware mothership somewhere. So they said, This provides an unfiltered look into the massive scale of the compromise through the actual raw files. Our researchers have obtained and analyzed a staggering 153 gigabyte RAR archive, you know, and these files will compress way down.
[00:38:47] This massive corpus contains exactly 433,909 files. Through our analysis, we've successfully attributed 118,829 CI runner dumps to 2,488 affected corporate domains.
[00:39:13] Whether a developer, machine, production server, or CICD pipeline executed the compromised Light LLM package, the threat actors successfully harvested the live environment memory and configurations mid-execution.
[00:39:32] Okay, so the real takeaway from this is that the massive adoption of the automation of development and delivery will tend to coalesce around relatively few most popular best-of-class tools. This naturally makes those tools a highly valuable target for attackers.
[00:40:02] Over at GitHub, the Light LLM repository describes itself, writing, Light LLM is an open-source AI gateway that gives you a single unified interface to call more than 100 LLM providers, OpenAI, Anthropic, Gemini, Bedrock, Azure, and more, all using the OpenAI format.
[00:40:30] Use it as a Python SDK for direct library integration or deploy the AI gateway, a proxy server, as a centralized service for your team or organization. Managing LLM calls across providers, you know, multiple, like, you know, Anthropical, OpenAI, Gemini, so forth, multiple providers, they say managing those calls gets complicated fast.
[00:40:56] Different SDKs, different auth patterns, request formats, and error types for every model. Light LLM removes that friction with a unified API, one interface for more than 100 LLMs, no provider-specific SDK juggling, drop-in OpenAI compatibility, swap providers without rewinding your code, production-ready gateway,
[00:41:26] virtual keys, spend tracking, guardrails, load balancing, and an admin dashboard out of the box. Eight milliseconds P95 latency at 1K RPS, you know, requests per second in benchmarks. So, wow, right? Sounds great. The only glitch here is that it must be totally trustworthy.
[00:41:53] In order for Light LLM to be able to proxy for its users, all of those differing LLM backends, it must necessarily have every user's authentication credentials for every one of those different LLM backends. Just like, Leo, you were saying, OpenClaw, you know, had to be able to log in as you, had to be able to access your bank records,
[00:42:21] had to be able to make payments on your behalf, blah, blah, blah, blah, blah, blah. I mean, when we get into proxies and agents, trust has to be there because, you know, they're acting on our behalf. So, what happened here is that the Light LLM developers were users of the Trivi vulnerability scanner, and as we know, because we talked about this back in March when this happened, Trivi was compromised.
[00:42:48] This allowed attackers to compromise any project that was using Trivi as its scanner, and thus, in turn, those two versions of Light LLM were compromised, giving attackers complete visibility into the credentials and domains of those 2,488 corporate users of Light LLM during just that 40-minute window. And, you know,
[00:43:17] I always like to try to suggest solutions to the problems we encounter here, but I got nothing because this is like a fundamental problem with the way we're doing things now. You know, we're now in a mode where everyone feels that they need to always be running the latest and greatest release of everything, right? It was because of the updates
[00:43:45] to those two bad Light LLM packages in the repository that this happened because there was a new version. Oh, got to have that. So, you know, we've done this to ourselves, and I preach updating relentlessly, right? You know, the entire security community is constantly pressing everyone to get better about updating their software.
[00:44:14] Stay current. Be sure you're receiving announcements of important updates, blah, blah, blah. You hear it here all the time. But in this instance, doing that is precisely what bit the users of those two specific versions of Light LLM. If they had not updated to those, if they'd remained on a previous release, they would have never run one of those two malicious versions. But of course, not updating doesn't work as a strategy either. No.
[00:44:43] I pin stuff trying to avoid this. After this LLM debacle, you know, people said, you know, I was caught within a day, I think, or a couple of days. They said, if you just make sure you don't install anything that's less than three days old, you'll be all right. I made it 14 days because I figured, I mean, you're still not going to catch everything, but if it's a popular package, two weeks should be enough. So I'm very careful. The other thing I do, though, is I store all those tokens and secrets in Bitwarden's secret manager.
[00:45:13] So they're not, it's like my passwords, right? They're in a locked vault. And we did just talk about this a couple of weeks ago where we're beginning to see a new category of security software, which is a means of allowing AI to access your credentials without it ever having them. Right. That is, so it says to Bitwarden,
[00:45:41] I need you to log in for me. In effect, yeah. Well, or it gets a one-time token or, yeah, I mean, it's still going to, see, the problem is, so you're using that OpenAI endpoint, which is connecting to somebody who's serving that AI. They want that token. So the token has to float around somewhere in memory. You don't want to write it to the hard drive, but it has to, LightLM would still have to be able to see it and send it. So I'm not sure a secrets manager would have protected me
[00:46:11] in that case. Yeah. You try to do what you can. So, the flip side, of course, of your two-week window, which is good, is that if there was a critical vulnerability that actually was authentically patched, then you wouldn't be getting it for two weeks. So, you know, who knows what might be malicious and what isn't. We're in a bad place right now. The only winning strategy, or at least the best strategy
[00:46:41] that's available for the moment, is just to use the tools but carefully monitor the news for the tools you're using. Stay current, because mistakes are going to happen, the instant you learn of a breach that affects you, invalidate and recreate, in other words, rotate, all possibly affected credentials. We've seen many instances where that was not done. You know, remember that
[00:47:10] part of what made LastPass's troubles even greater was that even after they learned that they'd been breached, they failed to fully cancel all previous authentication credentials. And, you know, and as a perfect case in point, we learned that, you know, from Kevin Beaumont's test, a major telco did not actually rotate their credentials when they had claimed to. So I guess
[00:47:39] there actually is an important and practical takeaway from this. I mean, it's like a real action item. We know Go ahead. We know that things that are easily done tend to be done. And things that are a confusing pain in the butt too often fall into the okay, I'll get back to that later. What we see is that
[00:48:09] the speed of modern attackers means that later stands a very good chance of being too late. So here's my takeaway point from this. I think it's really crucial. If there's really no practical means of preventing inadvertent exposure to credential leaking malware, and there may not be today, then
[00:48:39] rotating all of the credentials that any malware might have obtained the moment a credential compromising attack is known is important. Of course. Moreover, periodically rotating credentials preemptively on the better safe than sorry principle can be useful when the threat environment warrants it. This is, by the way, this is contrary to the
[00:49:08] advice we've been giving about passwords, rotating passwords, but it is what you should do. Yes. So when I make keys now, I give them an expiration date of a month or two months or three months, and I know I'm going to have to rotate them because I don't get to keep using them. Right. So what I believe this means is that whole organization, organization-wide credential rotation needs to be both
[00:49:38] possible and easy. Right. If it's not easy, it won't happen or it will be put off. So my best advice would be if you're looking for a nice, self-contained, easy-to-describe project for an AI agent to tackle, a great investment would be to employ some AI to implement a comprehensive credential rotation facility
[00:50:08] for your organization. Make it automatic. Make it a single command that handles everything. Make it easy, even fun to use, and use it to maintain the credentials for both current and new services as they're being brought on board, you know, as services are added and removed, and require its use for instantiating any new credential into use so that it cannot fall
[00:50:37] out of sync. Or, again, if that happened, it wouldn't be trusted and used. So I would say automating credential rotation would be a cool, it's easy to describe to an AI, it's self-contained, you can see if it's working or not, failure doesn't kill you, it just, you know, you've got to fix it, but I think it would be then incredibly useful. If,
[00:51:08] well, when Thinks Canary finds that some guy is in your network, the first thing you want to do is, you know, don't panic as the Hitchhiker's Guide to the Galaxy tells us, rotate those credentials. And, you know, make it easy, make it fun. There are, there is a way to do this a little safer, and I think if I were a big, or any business, I probably would be doing this.
[00:51:38] When we were at RSEC, I met a few of these guys. They're an intermediary, a credential capability layer, so they hold, they're a third party, they hold their credentials. You don't ever have the credentials on your machine, you have a credential to them, and when you want to connect to an AI, you connect through them, so they have your credentials, and they do it, and you only get a one-time token. The problem, and the reason I didn't want to do that, A, it's you pay for it, but B, they have your credentials,
[00:52:08] and it has to be somebody you trust, because they're going to have your credentials. At some point, these credentials have to be exchanged. It's just like a password. I guess you could use hashing, couldn't you? That would be the solution. A couple weeks ago, we talked about 1 password saying that they were introducing exactly this service, so keeping it local. And of course, the problem is that we're talking all credentials. So like that online service
[00:52:38] would be handling your credentials as a proxy for AI, but what about SSH servers? What about web, you know, all the other things that so what you want is one thing that is just able to wipe the secrets out of your organization and replace them. Yeah, that's the 1Password credential broker. That might really be the right way to do that. We're going to have to have something like that. You know what we're
[00:53:07] going to have to have right now, Leo? A break in the action? You're watching Security Now. Steve Gibson, the man of the hour. Every Tuesday, it's Security Now Day here at the Twit Podcast Network. We're glad you're here with us. Our show today brought to you by Delete Me. This is a topic we talk about a lot as well, privacy, right? If you're a business owner, we often talk about Delete Me as something for individuals, but this is even more important, I think,
[00:53:37] for a business owner. I speak as a business owner because, you know, as a business owner, you're in the public eye. That's part of the job. The bad news, the uncomfortable truth is that when you promote your business, it's also exposing your business. You and your team now are visible. And who are you visible to? Not just customers, not just clients, bad guys. Right now, 90% of business owners, this is a devastating stat, have their
[00:54:06] home address easily discoverable online. 90%. The average owner has more than 600 pieces of personal information just sitting there on the open web. We're talking your personal email, your phone number, your home address, even details about your family. And why? Because of data brokers. I hate data brokers, the cockroaches of the internet. And hackers know this. They know they can get this data cheap. They just buy it from the data brokers
[00:54:36] and they use it for a variety of things. They can run hyper-targeted phishing attacks. If they have your real details, they don't sound like strangers. They sound like clients or partners you already trust. We got bit by a phishing attack exactly like that. A client we've done business before sent us a request for a proposal, an RFP, and we thought, well, of course, we've dealt with them before. But it was a man-in-the-middle attack. What looked like a login to their Google Drive, or actually
[00:55:06] our Google Drive so we could fill out a form, was a man-in-the-middle. It looked just like a Google login, but our employee put the information in, they even put the second-factor authentication in, and bingo, the bad guys were in. That's because hackers know if they sound like a client or a partner you already trust, you can't ignore them. Attacks that use verified personal information like that are five times more likely to succeed. And the average incident, it can cost
[00:55:36] you a lot. We were lucky, we caught it, but it can cost a small business more than $120,000. And we're one of, well, one in four, 25% of all businesses will be impacted this year, this year alone. That's why DeleteMe is so important. That's why we use DeleteMe. It reduces your exposure by up to 95% by removing you and your employees' personal information from those evil cockroaches, the data broker websites. But when you get your
[00:56:05] information off of it, it starves hackers of the fuel they use to build their targeted lists. And it's not a one-time thing. It can't be because like a cockroach, you guys can't stop these data brokers. You get it deleted, but then they change their name, they declare bankruptcy and move to another state and they start, they just got all the data up again. Well, DeleteMe constantly monitors or removes your data. They know the names of these guys, they keep track when the new ones start up, they're there. And DeleteMe will send you a regular privacy report so you always
[00:56:35] know where things stand. We just got our email the other day. Really interesting. You think you're, oh, I cleared it, but you got to keep doing it. That's why the biggest and the best, Fortune 500 companies and government agencies have trusted DeleteMe for over 15 years. And now the same protection those big businesses and government can get is to join delete me dot
[00:57:05] com slash twit dash biz to start protecting your business with DeleteMe today. And if you use that link, you'll also get a free year of social media protection for every seat you purchase. Let's join delete me dot com slash twit dash biz. Now, I want you to get that address right. Don't Google it. I know a lot of times people just go, I remember hearing the ad and they Google it. But there's another DeleteMe in the EU that is completely different. It's a GDPR deletion site. So it's not what you want.
[00:57:34] You want the broker deletion site. And for that, you have to visit this exact URL, join delete me dot com slash twit dash biz. All right. That's the one you want. That's the service you want. And I can tell you from personal experience, it really works. Join delete me dot com slash twit dash biz. Now back to Mr. Gibson. Uh, France's recently celebrated
[00:58:04] ban on social media access for all children younger than 15 hit a bit of a snag. Last Friday, Reuters reported the following. They said France's top court on Friday blocked a bill banning social media access for under 15s saying it infringed upon freedom of expression and delivering a setback for President Emmanuel Macron, who asked his government to rewrite
[00:58:34] the legislation. The bill would have barred children younger than 15 from opening a social media account from September beginning, September 1st, and all accounts already open would be closed by the year end, which would also need to use age verification provided by the French privacy regulator. But, Reuters writes, France's constitutional council found that the bill, while requiring everyone to give proof
[00:59:04] of age, failed to quote, specify the conditions and limits under which it should be provided, as well as infringing upon freedoms and privacy. So, that's their report. You know, as we immediately understood when this began to happen in the U.S., you know, in the context of U.S. domestic legislation to control the viewing of pornography
[00:59:33] online, we've noted that blocking anything for all users below a certain age inherently requires everyone's age to be known. You know, there's no way around that. So, France now needs to tackle the thorny problem of that inescapable infringement upon the Internet's illusion of total freedom and privacy. privacy. You know, it is an
[01:00:03] illusion to some degree because we know how the Internet's technology works. You know, like from the beginning, there's never been a greater infringement upon privacy than the abuse of third party browser cookies to track people, but that went largely unseen, so nobody really worried about it. the problem with age assertion is that because it's explicit and it cannot be hidden in
[01:00:32] the same way that cookies were, everyone's getting outraged. You know, the truth is that if we want our governments to restrict children's access to Internet content, then everyone's age must be known by someone somewhere, either by every source of the prescribed content, or by every means of accessing that content. So, anyway, Reuters continues quoting the Constitutional
[01:01:02] Council's statement, writing, quote, the council holds that the contested provisions, on the one hand, disproportionately infringe upon the freedom of expression and communication, and on the other, fail to provide the legal safeguards necessary to ensure the right to respect for private life. French lawmakers, they wrote, had approved the bill in July, which is when we first talked about it last month, or month before last,
[01:01:31] becoming the first in Europe to follow Australia, whose world-first ban barred access to platforms, including Facebook, Snapchat, TikTok, and YouTube for under-16s in December. Lawmakers there are considering stricter penalties after data showed mixed success. Countries around the globe, including China, the UAE, and Turkey, have either instituted measures intended to curtail or bar access to social
[01:02:01] media for young people, or have said they're planning them. The European Union has said it was planning to seek stronger protections for children from harmful social media features. Social media companies generally oppose blanket bans, saying they have measures already in place to protect younger users, including age restrictions, though they have also said they would comply with government bans. Google, Meta, Snap, and TikTok did not reply to Reuters'
[01:02:31] response or requests for comment. Macron, who in April urged teenagers to turn off their devices and read, that went over really well, in order to become better citizens, has ordered Prime Minister Sebastian Le Corneau to rework the draft legislation to make the Constitutional Council's concerns to take them into account. They said in a statement that they were determined
[01:03:00] for the reform to take effect before the spring of 2027 when France holds its presidential election. Anyway, Macron has not given up. The draft legislation is being hastily reworked to address the council's concerns, since Macron still hopes to have this reform in effect as soon as possible. He was also going to add smartphone restriction to the legislation that would take effect for high
[01:03:29] school in addition to the lower schools. So, anyway, we'll see what's going on and what happens, Leo. Wow. So, last Tuesday, Wired reported on the unnerving discovery of a serious vulnerability in the Zoom teleconferencing system. Of course, now, that's recent.
[01:04:00] We'll all remember when Zoom really became a big deal at the beginning of COVID, because it saw its adoption soar as teleconferencing became super important. It was the only way to continue doing business if you were stuck at home. And, boy, Zoom had a bunch of early problems. They weren't all resolved, as it turns out. Wired's headline reads, a Zoom screen sharing bug let
[01:04:29] anyone take over other devices on a call. And, their brief teaser is what makes this so interesting. They said, researchers say it took fewer than 20 prompts for a public AI tool to find a flaw, which has now been fixed, allowing anyone on a Zoom call to hijack other participants' devices. And,
[01:04:58] what wasn't clear from the reporting, and I didn't dig deep into it, was, wait a minute, a public AI tool was used to do some sort of clear cybersecurity work without hitting guardrails? Probably a Chinese model. Ah, could be. Oh, good point. Publicly available. Yes. So, Wired said, as AI models gain advanced capabilities to find vulnerabilities in software,
[01:05:28] develop ways to exploit them, and even carry out autonomous hacking sprees, all of which we've been seeing, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform, Zoom, that could have been exploited to take over targets devices. Anyone on a call that involves screen sharing, whether participants or the host, would have been vulnerable to a silent attack
[01:05:57] that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security, just the numeral A Security, say, say, the bug was discovered in early June using publicly available AI models and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security
[01:06:27] advisory on Tuesday including details about the fixes the company has already begun rolling out to address the operating systems that Zoom supports Windows Mac Linux iOS and Android A security co-founder the company A security co-founder Omar Gull told Wired ahead of the disclosure quote what's
[01:06:57] interesting for us and what we believe is dangerous is the democratization of these capabilities the barrier to entry is dropping rapidly before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this now people can reach the same results with fewer
[01:07:57] Because, like human bug hunters, they've been trained that convoluted and obscure functions often contain to overlook vulnerabilities. This is particularly true with proprietary closed source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions.
[01:08:21] But without the benefit of public open review, esoteric yet complex features like annotation are more likely to contain mistakes. Zoom did not respond to multiple requests for comment from Wired about the A security findings. The bugs are now patched, with Zoom issuing both server and client-side fixes or patches for both Zoom's own servers and the applications that run on customer devices.
[01:08:50] But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone on a Zoom call. Joining a call is itself a gesture of trust.
[01:09:07] But given how ubiquitous video calling is in both personal and professional contexts, and given that Zoom in particular is also widely used for events and semi-public activities like webinars, people typically have their guard down when joining a Zoom. A security co-founder, Yossi Torati told Wired on a call, if you just get on a Zoom with us, we can take over your device.
[01:09:35] The worst case scenario is that we can take over an enterprise just by having this capability in our hands. If I'm an attacker, if I'm an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally across the enterprise. Practitioners often call security a cat and mouse game.
[01:09:58] But as AI bug hunting proliferates, this delicate dance has become an all-out race, which of course is exactly what we've been seeing. All indications are that the high-tech computer world at every level, from IoT embedded device to consumer PC and enterprise, probably is heading for a rough patch.
[01:10:24] So far, as we know, I've been a cheerleader for the fixing the bugs team. And the good news has indeed been that an astounding number of bugs are rapidly being found and fixed. In those last two versions of Chrome, more than 1,000 total between those two, 149 and 150. But that's also the bad news.
[01:10:47] Because the fact that so many latent problems are being found tells us that the software at every level that we've been living with for years has been demonstrably riddled with previously unknown flaws. So the best that could be said is that the future remains stubbornly uncertain. We're getting the bugs out of the software.
[01:11:39] Money is the motive. And so there's not money behind a mass casualty event. There's money behind selectively targeting, exfiltrating, blackmailing, extorting, and getting what cash you can.
[01:11:55] So I don't think we're going to see a big Y2K style or a Y2K apocalyptic sort of thing. To me, that doesn't make sense because it doesn't make money. And that's kind of a saving grace.
[01:12:16] It means that there will be people hurt, but their insurance is going to go up and they're going to be paying out of pocket for bad guys having gotten into their system using bugs that are probably latent and aren't their fault and are zero days. So there's really nothing they could do about it. So hopefully that's what we see. And that over time, the ability to do that dries up because we get our software fixed.
[01:12:45] Okay. One last piece before we get into our big topic. There are some folks who are, I would argue, justifiably profiting from all of this. Bad guys, not justifiably profiting, but good guys.
[01:13:02] Last Monday, following the Black Hat Conference, CNBC reported, they said cybersecurity stocks of CrowdStrike and Palo Alto networks jumped more than 5% to new highs on Monday on renewed demand for artificial intelligence security tools following the industry's annual Black Hat Conference in Las Vegas.
[01:13:30] In other words, those guys were showing off that their AI is going to be used. They're ready to deploy defensive AI solutions. And the world said, we need some more of that. Analysts at BTIG, which is a large financial services firm, wrote to their clients in an internal firm letter, quote,
[01:13:57] The single most consistent theme across our conversations, partners, vendors, and customers alike, was that AI agents have fundamentally changed the threat landscape.
[01:14:11] While AI agents have become the predominant attack threat and the environment is meaningfully worse, deployment and AI security tools are only in the early innings.
[01:14:29] CNBC said, businesses are turning to cybersecurity companies for new agentic tools to fend off adversaries in a hyper-accelerated threat landscape fueled by new cyber models. Executives and potential customers gathered in Las Vegas last week in search of answers and ways to secure systems from rogue AI agents.
[01:14:54] BTIG wrote, quote, we think AI is creating a new modernization cycle in the endpoint security space, which directly benefits CrowdStrike's core business. Analysts at Cantor said, quote, AI has moved from being a cybersecurity feature to a key pillar of both the attack surface and the defender infrastructure.
[01:15:24] So, I remember the first time we touched on this. I think it was one of our listeners who was commenting that his company was already using some AI-based systems. I think he was on AWS cloud and he was using a third party's AI-based systems. And I was, this was a couple of weeks ago.
[01:15:53] And I was like, wow, this is happening already. I mean, we've got AI on the, you know, being deployed for defensive purposes, which is wonderful. And, you know, Leo, we're going to now dig into what I have learned recently about AI and can share. But first, I think we need to share a fine sponsor, perhaps. I think that'd be perfect.
[01:16:23] I think I can do that. Our show today. I'm excited about all of this. Yeah, I have a beverage. Looks like Tang. Are you drinking Tang? Tang. Oh, that's right. Dilute orange juice. Yes. Exactly. Yes. Do you add vitamin C to your diluted orange juice? No. Okay. I'm just curious. I take 15 grams of C a day. So way more. You get plenty. I know. I know. 15 grams. Yep. Holy cow.
[01:16:51] Three divided doses of five grams each. That's half an ounce. You're crazy. You're a madman. Are you sure? At least you, well, I don't know. Whatever that means. I don't know what vitamin C is doing for you. You don't get any sore throats, I guess. My liver would like to be generating about 20 grams a day and it can't because it's got the human genome has a little glitch. So. Right. We've talked about that. Yeah. Yeah. Damn genome.
[01:17:18] Our show today brought to you by Doppel. AI has made social engineering attacks. Oh man, more convincing than ever. From phishing emails to fake websites and impersonation attempts, it's becoming increasingly difficult to tell what's real from what's designed to deceive. That's why organizations need more than a collection of point solutions. They need a unified approach to stopping attacks before they reach their people. Doppel does it.
[01:17:48] Doppel is an AI native social engineering defense platform. Doppel strengthens human risk management by training employees to recognize deception. It provides digital risk protection across every channel and delivers agentic email security that doesn't just score the inbox, but takes down the attacker infrastructure behind the message.
[01:18:14] Doppel protects against the entire social engineering attack chain with one comprehensive platform. You get digital risk protection, which detects threats across multiple channels, links alerts into a real time threat graph and uses AI driven infrastructure disruption. Love this to stop attacks at the source. These insights also power phishing simulations and security awareness training.
[01:18:40] This thing is a cannon helping strengthen employees' defenses through next generation training and testing. Email security inspects every message, traces it back to the attacker infrastructure behind it, and helps take that infrastructure down so that campaign can't target your organization or any other organization ever again. Doppel also offers best-in-class integrations and partnerships, making it easy to work alongside your existing security stack.
[01:19:09] So what you've got works with Doppel. Join hundreds of companies already using Doppel to protect their brand and people from social engineering attacks, the worst kind of attacks out there. Doppel, outpacing what's next in social engineering. Learn more at doppel.com. That's D-O-P-P-E-L. Doppel.com. We thank them so much for supporting security now. That's an intriguing product. I could get these guys on the show. Fascinating.
[01:19:39] But now back to Steve. So, okay. As I promised last week, there are two important and fascinating pieces of core AI technology I want to spend time on today. I got to one of them. The first is a solution to what's been dubbed the dual use problem.
[01:20:03] That's the fancy name given to the fact that most knowledge can be used in ways that we both want and don't want. And of course, that's no surprise, right? Since that's always been true of knowledge. So, what is it about AI that changes this? Anyone who's spent any time with any of the recent state-of-the-art AI chatbots will have
[01:20:26] come to appreciate that what we already have today is, at the very least, an over-obliging conversational partner that can barely restrain itself from being, oh, so very helpful. And that tail-wagging puppy happens to also have access to the world's stored knowledge.
[01:20:50] So, it's not that it was impossible before AI to obtain that knowledge the old-fashioned way, you know, by researching, reading, learning, and understanding. No. The difference is that friction matters. And AI chatbots have hugely facilitated the access to that same knowledge by nearly eliminating
[01:21:15] all of the work that was previously required to gain such knowledge. And that's incredibly valuable. That's what underlies all of this frenzied, hyperscaler data center build-out. Investors believe, with good reason, that offering knowledge at our fingertips by phrasing a question is something most of the world will pay for.
[01:21:40] The fact that AI chatbots now have just shy of one billion users strongly suggests that these investors are not wrong. I, for myself, I'm completely spoiled. Even though I've never turned any agent yet loose on anything. Claude is my go-to for quick answers. It's an accelerator for me. And, you know, don't let anybody know.
[01:22:07] But at this point, I would probably pay pretty much anything for it. Yeah. Yeah, I know. I know how you feel. I know how you feel. Yeah. I have paid anything for it. But, Leo, you and I already know we're not going to have to because, as I mentioned, I think, before the show, it turns out that that Lenovo ThinkStation machine that I bought had a strong GPU.
[01:22:33] It's got an NVIDIA RTX 2000 with 16 gig. And there are useful models now that can run in that. So, you know, but I'm, you know, still, you're always going to want the latest and greatest. And it won't be as good as Claude. I mean, that's the thing. No. And not yet. Next year. And then you can stop. Then you'll be happy. You know, so, you know, by comparison, right?
[01:22:59] You know, anyone could download the Encyclopedia Britannica or the unabridged Oxford English Dictionary, but you can't ask them questions. Yeah. You know, it's all just dead knowledge lying there. So it's much less entertaining and it takes a lot longer, you know. So, you know, back and using them as back to old school researching, reading, learning and understanding. And of course, you know, look behind me.
[01:23:28] Anybody who has seen a video of this podcast is aware that there's a solid wall of textbooks. And as it happens up there, just out of camera is an unabridged Oxford English Dictionary. 27 volumes. I cannot recall the last time I opened any of those books back there. You know, you're right. AI neural networks are our new store of knowledge.
[01:23:57] Incredible as it may seem. And it would have seemed like science fiction just a few years ago. The collection of just an array of scalar variables which specify the scaling weights of the inputs to a vast neural network creates a representation of the expression of all of the knowledge that has been trained into that model.
[01:24:27] And I said that exactly the way I wanted to creates a representation of the expression of all of the knowledge that's been trained into that model. I think it's important to frame it that way.
[01:24:41] What we're feeding into the neural network while it's being trained is the expression of the knowledge largely gleaned from the Internet, as well as from reference texts, which AI companies have been quietly purchasing and ingesting to create an overall training corpus.
[01:25:01] The end result of this, and this is still mind boggling to me, is purely and simply a next most likely token prediction engine. Leo, as I've said, your very early initial observation was that what we were calling AI, and this is a couple of years ago, was little more than fancy spell check. I called it spicy auto correct. Yes.
[01:25:31] And then, as our listeners will remember, last week, I quoted a nearly stunned Matthew Green specifically saying that it's not just fancy spell check, but its essence has not changed. You know, you were not wrong, Leo, then, and Matthew is also not wrong today. So how do we explain this apparent disparity?
[01:26:00] It's that over the past couple of years, what was initially a simple next word predicting spell check has become really, really, really, really fancy spell check.
[01:26:20] Deep underneath, even today's astonishingly, apparently intelligent reasoning systems down at their core is still just a neural network that only does exactly one thing. Given a long, given a long, and in many cases astonishingly long, token sequence, it predicts the most likely next token.
[01:26:49] And the fact that we get what we now get from that, well, that's what's still mind boggling to me.
[01:26:59] I'm going to spend a bit more time on this because a deeper understanding of the truth of what's actually going on with today's AI, I think will help everyone to appreciate next week's, the second of the two research papers I plan to share, which is, well, I don't know how to sum it up quickly. So stay tuned.
[01:27:25] So your original, Leo, you know, it's just spell check autocomplete summation that has its roots in AI circa 2020.
[01:27:36] Way back then, if you were to carefully phrase a question to GPT-3, such as the capital of France is, it would have been able to complete the sentence by emitting the next expected word, Paris.
[01:27:57] Because the model, that models, the GPT-3 models, vast statistical data set made Paris the next most likely word. The capital of France is Paris. But if you used question style phrasing back then, what is the capital of France, that would not have been met with the same success.
[01:28:27] So what happened? Obviously, we have that now. How did we turn these models from autocomplete engines? That is, that's where that's all they could do into conversationalists. So it took a few years of experimentation, but AI researchers first used something that's now known as instruction tuning.
[01:28:52] They took the knowledge trained model and fine tuned it on a, and this is, again, another surprise, a surprisingly small set of human written examples of what good responses would look like. After that, then something known as RLHF, reinforcement learning from human feedback was used.
[01:29:21] So this applied preference rankings where, again, humans compared and ranked multiple outputs from best to worst. And that ranking was used to train a reward which pushed the model toward the better behavior. Now, here's the astonishing part to me.
[01:29:46] Researchers then found that they could employ a comparatively small model of these query and ranked response samples, which then created reward feedback. And that these large language models would and did with startling speed.
[01:30:11] They were able to generalize from the language patterns of queries and responses across their entire knowledge base. That is, they learned that pattern and generalized it.
[01:30:32] So to better appreciate the scale of this, a model that had been trained on trillions of tokens of raw knowledge. You know, this created the original statistical autocomplete engine, a neural network that just could probabilistically choose the next most likely token.
[01:30:56] It could then be rewarded using only, again, it was originally fed trillions of tokens. It could be rewarded using only tens of thousands to low hundreds of thousands of query response samples or examples.
[01:31:16] And the behavior of the entire model would be reshaped across all of the knowledge that it contained. This is a well-documented fact now that this occurs. And the fact that it occurs with such sample efficiency is what was utterly unexpected. I mean, this was the surprise.
[01:31:46] Today, now, as I said, it's a well-documented real phenomenon, which has now been turned. We have a term for it now. It's known as the superficial alignment hypothesis. The idea that all of the raw knowledge was already there from the model's initial knowledge corpus training.
[01:32:08] Then a relatively minuscule bit of fine-tuning teaches the model format and behavior, but not new knowledge. That is, it wasn't giving it new knowledge. It was reformatting it and giving it behavior for the first time.
[01:32:30] So to state that a bit differently for clarity, the breakthrough about four years ago was not the use of a larger model than we had at that time. That is one of the things that's been happening since then. But the breakthrough was the unexpected discovery that a comparatively infinitesimal dose of human-provided,
[01:32:59] here's what a good answer looks like, and here's which of these answers is better training, would reshape a massive already trained model's entire behavior, turning it from something that completes patterns into something that acts like it's trying to be helpful.
[01:33:24] So once the massive model learned what helpful looked like and that its trainers wanted it to look like that, all of its stored knowledge was immediately available in that new helpful format, and we got helpful chatty AI. That's how it happened.
[01:33:50] And as we know, those first steps made by ChatGPT were more than a little shaky. You know, researchers realized that their newly birthed chatbot would need some additional post-training alignment, as it's now being called. And this began as that RLHF, the Reinforcement Learning from Human Feedback that we talked about.
[01:34:17] But then, a year later in 2023, a handful of AI researchers at Stanford University published a paper titled Direct Preference Optimization. The paper's title is Direct Preference Optimization. Your Language Model is Secretly a Reward Model.
[01:34:40] And since all of the descendants of this, it's now known as DPO system, Direct Preference Optimization, was sort of the granddaddy. Now we have further refinements of that, which have occurred in the last three years. Something known as IPO, there's KTO, ORPO, and Simpo. They all descend from DPO.
[01:35:03] I want to share just the abstract of the Stanford researchers' original paper, which was the breakthrough beyond that earlier reinforcement learning from human feedback. So they explain their invention by writing, while large-scale, unsupervised language models learn broad world knowledge and some reasoning skills,
[01:35:32] achieving precise control of their behaviors difficult due to the completely unsupervised nature of their training. Existing methods for gaining such steerability collect human labels of the feedback of the relative quality of model generations,
[01:35:53] model output, and fine-tune the unsupervised language model to align with these preferences, often with reinforcement learning from human feedback, RLHF. However, they write, RLHF is a complex and often unstable procedure, first fitting a reward model that reflects the human preferences,
[01:36:18] and then fine-tuning the large unsupervised LM using reinforcement learning to maximize this estimated reward without drifting too far from the original model. In this paper, we introduce a new parameterization of the reward model in RLHF
[01:36:41] that enables extraction of the corresponding optimal policy in closed form. I have no idea what that means, but you'll get a sense for this. Allowing us to solve the standard RLHF problem with only a simple classification loss. The resulting algorithm, which we call direct preference optimization,
[01:37:08] is stable, performant, and computationally lightweight, eliminating the need for sampling from the language model during fine-tuning or perform significant hyperparameter tuning, whatever that is. Our experiments show that DPO can fine-tune language models to align with human preferences as well as or better than existing methods. Actually, it's vastly better.
[01:37:38] It completely obsoleted everything that came before. Notably, fine-tuning with DPO exceeds PPO-based RLHF in ability to control sentiment of generations and matches or improves response quality in summarization and single-turn dialogue while being substantially simpler to implement and train. So, okay, that's just their abstract.
[01:38:05] And the paper goes on at length like with crazy formulae. I wanted to share that because I didn't want to leave everyone with the belief that the original RLHF, the reinforcement learning from human feedback approach, which began this transformation from autocomplete to actually Q&A, that that's what the industry was still using. As I said, it was the genesis.
[01:38:31] Stanford's DPO, their direct preference optimization, dramatically improved it. And DPO's success, as I said, spawned a number of successors, which I cited earlier. Okay, so what is all this about? It's about how we take a massive neural network, which has been trained on and contains raw knowledge, which can initially only be used to predict the next most likely token,
[01:39:01] and impress upon that network actual behavior. That's what's changing here. We're giving this knowledge base a set of behavior. The first example of behavior was turning the network into something that could actually respond to queries. That gave us the first interactive AI. But as I noted, those first steps were somewhat shaky.
[01:39:28] So over the time, researchers learned that by using the technologies I just described, they could improve the model's instruction following behavior so that it would answer the question that was asked, as well as respect the requested format and length and language.
[01:39:49] The model's style and tone could also be modified and tuned to improve its response formatting, structure, hedging, politeness, and its own verbosity. These factors were, again, they were given significant weight in the tuning. And as we saw in the early days, psychophancy was an often seen problem.
[01:40:15] This arose because, you know, we humans reliably prefer being agreed with. So preference optimization trains models toward agreement, and it takes deliberate counter effort to prevent it now. So that's now in place. We've been able to kind of get that under control. Another improvement that was impressed upon models was factuality,
[01:40:41] preferring responses that will admit uncertainty rather than always confident fabrication. Well, that explains a lot because hallucination, at least in my experience, has almost disappeared. And I was wondering how they did that. Now we know RPO. Exactly. So the other class of behavior that can be trained into a model is its refusal to provide certain classes of information.
[01:41:09] And what's significant is that this exists in two places. This is different than guardrails. There's filtering what you allow the human prompter to get into the model, and then filtering what you allow the model to show of its results. So that's real-time filtering, input and output.
[01:41:35] But the other place is you can actually train the model itself to refuse, independent of input-output filtering. So, you know, which is to say the harnessing of the model. So, it's one thing for a model to contain knowledge that's dual-use, which, you know, only authorized users should be able to access.
[01:42:02] But some model behavior and or knowledge dissemination should be proactively prevented. The test that AI designers apply is termed uplift. That is, does a model meaningfully advance someone's capability beyond what they could already get? You know, does it uplift them? This falls into two categories.
[01:42:31] One is where the knowledge is the harm, and the other is where the output is the harm. Examples of knowledge uplift would be, for example, bioweapon synthesis routes, nerve agent production, and nuclear device design. You know, the relevant literature is scattered, it's partial, and it's difficult to assemble.
[01:42:58] So, any model that would synthesize it into an actionable protocol provides genuine uplift toward mass casualties. And the asymmetry is clear, right? Defensive work in these fields does not require the synthesis route.
[01:43:20] Somebody, you know, a vaccine researcher needs to understand pathogen biology, not a means of enhancing a pathogen's, you know, malicious use. So, this list and those examples that I cited, you know, would not take anyone by surprise.
[01:43:45] They're one category where essentially every AI model provider refuses regardless of credentials or system prompt. That is, it's not about who you are, what your privileges are on the model. You just can't have that. It's been trained. The model itself has been trained to refuse. Trained in what way? Do they not have the information?
[01:44:16] We're going to get there. Oh, good. That's a perfect question. By the way, this is fascinating. You know, when the world became aware of this, I mean, the knowledge of this has been around papers and so forth for some time. But it was when DeepSeq came out from China, it was the first model to use RLHF, as far as I know. And it was an eye-opener for people because the model was stunning. This was January of last year. I remember it very well. It was a DeepSeq moment.
[01:44:45] That's when all the stocks of all the AI companies plummeted because people said, wait a minute, the Chinese can do this cheap. Yeah. Very interesting. Now everybody uses RHLF, of course. Yep. Yeah. Yep. Really interesting. Now, actually, would be a great time to take a break. We're a little after an hour and a half in. So we're going to pace ourselves. This is fantastic. Yeah. And you found this by reading papers? Yeah. I've found... On archive.org or...
[01:45:15] Yeah. They're all there. Yeah. Jeff loves reading those papers, too. There's a lot of garbage there, too. That's my only... But you know what to look for. This is like... Yeah. These were the found... These are the seminal papers. The founding seminal work. Founding documents of AI. Yeah, yeah, yeah. Absolutely fascinating stuff. Yeah, like three AI researchers at Stanford that figured out how to improve on RLHF so that that's what everyone is using now. Right.
[01:45:44] That's what you want to look at. It's... You know, the other thing that I find amazing is there are breakthroughs like this happening almost all the time now. That there are researchers all over the world working as hard as their little research brains can to find new techniques. Yes. That's why I keep saying today's AI, today's AI.
[01:46:03] I mean, anybody looking back, like just quarterly, look back in three-month hops and it's clear we're on to something. Oh, yeah. And the other thing is that I, from the outside, can... I can put flags in the ground and exactly when, you know, January 2025 is when DeepSeq came out and everybody said, oh, RLHF. Oh!
[01:46:33] And last November. November 2025 when Opus 4.5, we're going to, I'm sure, get to that. So these internal progress shows up in ways that those of us who use this heavily can see those milestones, the impact of those milestones. I mean, it's very clear. You don't see hallucinations like you used to. And I don't know why. I'm glad you're explaining this.
[01:47:01] You also see sick of fancy going down a little bit, although it's... This is the other thing is that companies are loathe to get rid of the stuff that makes people like me keep using their products, right? So they're not going to get rid of all of that. They're not going to get rid of all of that. Just fascinating stuff. All right. Well, we'll be back with more. I hate to interrupt, but, you know. No. We've got to pay the bills. I've got to keep my... Wet My Whistle. Yeah, Wet Your Whistle.
[01:47:27] And, of course, we know this company because they are the people who brought us to Black Hat a couple of weeks ago for that fun conference. That was a lot of fun. We were in the Threat Locker booth, our sponsors. Threat actors these days, you know this. We talk about it all the time. They're using AI in so many ways. But one that's really scary is they're using it to automate vulnerability discovery. That's why every company from Google to Apple to Microsoft are shipping bug fixes as fast as they can.
[01:47:57] But, you know, the bad guys are actually probably a little faster, unfortunately. They're also using it for other things. Once they get in, once they penetrate, they actually are modifying the scripts during the attack because AI can work so fast. It's like an attack that modifies itself as it progresses. They're generating new malware variants faster than anybody can keep up.
[01:48:18] They're coordinating activity across multiple systems in ways, you know, only the best gamers could do in the past. And now tasks that once took a human hours or days can happen in minutes. And that should be scary if you're a business because you're at the front lines. And at the same time, you may be doing this.
[01:48:42] Most organizations are introducing AI assistants and agents and giving them access to the crown jewels, documents, source code, cloud applications, APIs, internal systems. This is a, if you think about it, a nightmare just waiting to happen. Security teams need to know which AI tools are in use. What information they can access, whether they're operating outside their intended scope.
[01:49:11] A successful login or an unfamiliar file hash, that's not going to give you enough context. Teams also need to understand whether an application is behaving normally, whether it's accessing unexpected data, like the open AI model that was looking for the answers to the quiz questions. That was weird. Or communicating with systems it shouldn't be able to reach.
[01:49:37] The problem is you can't use old-fashioned methods to stop this. You need to use ThreatLocker. You need to use Zero Trust. ThreatLocker uses application allow listing. Very granular, by the way. So it can control which AI tools and other applications are allowed to run. They call it ring fencing. They use ring fencing to limit what approved applications can access.
[01:50:03] So you approve the application, but you need the granular permissions to say, well, they can do this, but they can't do that. Which processes they can launch. How they can communicate with one another. ThreatLocker uses something they call web content control. This is fantastic. Manage access to public AI platforms and other online services. You can block it entirely or limit what they can do with privileged access management. That prevents AI applications and their users from receiving unnecessary administrative privileges.
[01:50:33] ThreatLocker applies Zero Trust network access and Zero Trust cloud access policies to restrict resources to authorized users, approved devices, and permitted applications. It started with endpoints, but now it's in the cloud. It's in the network. And ThreatLocker works everywhere you work. Windows, Mac, Linux, they've got the best support 24-7 US-based support from people who really know what they're talking about and are there to help you, to really support you.
[01:51:02] That's why ThreatLocker is trusted by organizations like JetBlue, Heathrow Airport, the Indianapolis Colts, the Port of Vancouver. Ask Jack Thompson. He's director of information security risk and compliance for the Indianapolis Colts, the great NFL team. He said, with ThreatLocker, we have the ability to centralize disparate elements in the security stack. And what does that mean? That means they can control them. They can see what's happening. That's another side effect of ThreatLocker's ring fencing.
[01:51:31] It's great for compliance because you know exactly what happened, when, who did it. You've got it all. And of course, ThreatLocker is beloved in the industry. Constant awards and prizes. Just some of the latest industry recognition. They were recognized as strong performer in the January 2026 Gartner Peer Insights voice of the customer for endpoint protection platforms. They were ranked number one in application control by Peerspot.
[01:51:56] They're the winner of the best zero trust security solution at the 2025 TICE Awards. AI governance requires more than an acceptable use policy. You need a padlock. ThreatLocker gives security teams the technical controls to define which AI tools are approved, who and what can access them, and how those tools are allowed to interact with business systems and data. You have control. And that's what it's all about.
[01:52:25] Visit ThreatLocker.com slash twit to get a free 30-day trial and learn more about how ThreatLocker can help mitigate unknown threats and ensure compliance. That's ThreatLocker.com slash twit. We're big fans of ThreatLocker. We really are. Now, I'm a big fan of Steve Gibson, who is finally explaining something I've been using for a year or two and had no idea what was going on under the hood. We all have been. Yeah. It's fascinating.
[01:52:53] So knowledge is, you know, forbidden knowledge is one class. The other is where the output itself is the problem or the harm. So an example of that, you know, which carries universal condemnation would be, you know, text which sexualizes minors. Models will not produce any such text.
[01:53:22] It's trained out of them. See, that's fascinating because we've heard about classifiers, which kind of are gates preventing the aggress of that information. But this goes deeper than that. The models themselves say, no, no, no. Yes.
[01:53:36] So and that's why unless you remove that, even without any kind of a harness, even without, you know, anything that is filtering input and output, the model says, sorry, I cannot help you there. Right. So as we've seen earlier, the good news is that these large language models are astonishingly able to absorb and embrace.
[01:54:04] We saw this in like their ability to learn to answer questions. I mean, to understand the linguistic nature of a question and how to apply the knowledge they had to create an answer. I mean, it's an astonishing technology. But it does this.
[01:54:24] So we're able to give them as a consequence what appears to be a personality, many forms of behavior and also instruct them what they may and may not do. So that's the good news.
[01:54:43] The bad news, as it turns out, is that any behavior like this that can be easily imprinted can also be easily removed.
[01:54:56] In the summer of 2024, researchers at ETH Zurich, the University of Maryland Anthropic and MIT published a paper titled Refusal in Language Models is Mediated by a Single Direction. And here direction is a term of Art in Neural Networks, as we'll see.
[01:55:23] So the abstract of their paper employs some of this inside baseball terminology, but everyone should be able to easily get the gist of it. So I'll explain a bit more afterwards. The paper's abstract, that is refusal in language models, is mediated by a single direction.
[01:55:45] The abstract reads, conversational language models are fine-tuned for both instruction following and safety. Safety meaning, not going to tell you that. Resulting in models that obey benign requests but refuse harmful ones. While this refusal behavior is widespread across chat models, its underlying mechanisms remain poorly understood.
[01:56:14] Again, this was summer of 2024. So just about two years ago, this paper appeared. In this work, across 13 popular open source chat models, up to 72 billion parameters in size, we show that refusal is mediated by a one-dimensional subspace.
[01:56:40] Specifically, for each model, we find that a single direction, such that erasing this direction from the model's residual stream activations, prevents it from refusing harmful instructions. While adding this direction elicits refusal on even harmless instructions.
[01:57:06] They said, leveraging this insight, we propose a novel white box jailbreak method that surgically disables refusal with minimal effect on other capabilities. Finally, we mechanistically analyze how adversarial suffixes suppress propagation of the refusal-mediating direction.
[01:57:33] Our findings underscore the brittleness, and this is the key, the brittleness of current safety fine-tuning methods. In other words, just instructing the model not to answer the question, well, that works.
[01:57:50] But if the weights are open, it turns out to be trivial to remove those instructions, even after the fact and not having known what the instructions were. I'll explain a little more. It's amazing. So they finished saying, more broadly, our work showcases how an understanding of model internals can be leveraged to develop practical methods for controlling model behavior.
[01:58:19] Okay, so what this group discovered was that any late-term model behavior imprinting can later be removed from such models. And the way this is done, as I said, it's wonderful and wild. They compare the model's activations on harmful versus harmless prompts.
[01:58:49] Compute the mean difference, then project the weight matrices orthogonal to that direction. So essentially, they deliberately ask it questions it is trained not to answer. And they watch some of what it does, some of where the activations are, compared to asking questions that it's happy to oblige.
[01:59:17] And they're able to take the difference in the activations, see them, and then apply a remover that suppresses that, and suddenly it will now answer all questions. So after they do that, the model loses the ability to represent and therefore to execute on its refusal.
[01:59:47] And what they found was that this was surgical. It specifically disables in completely 13 completely different chat bots all of their refusal while having minimal effect on other capabilities. It's kind of like a functional MRI on the model. Like you're looking for what got activated. Yes, and then remove it.
[02:00:18] The only thing I'm worried about, you know, for instance, I use a model from China, Quinn, as we mentioned, 3.827. And I've seen obliterated versions of it. But people say, well, you also have a risk. This is brain surgery. After all, you might make it dumber. So I can't speak to that, but I can cite the research because they do address this.
[02:00:45] So, okay, so first, from my lay view, it appears clear that since little training, amazingly little training, was required to imprint that original refusal behavior. Ah, now I get it. The impact upon the model was minimal. You know, it wasn't diffused throughout the entire model.
[02:01:10] It had a, but it's still, it's significant that this is able to change its behavior so quickly. Well, think about it. You're modifying with just a few inputs. Yes. A large model. You know, there's going to be some collateral neurons that are affected. Well, and actually I use the analogy a little bit later of clean margins when a surgeon excises something. Right.
[02:01:40] Anyway, so these guys discovered how to identify the changes created by that training, which again, wasn't pervasive. It was, you know, not that much training did comprehensively change the model's behavior. So, it turns out it could be removed. So, okay, so for what it's worth, when we encounter the term obliteration, this is what is meant.
[02:02:08] You know, not obliteration, obliteration. So, just to put a final point on it, a hugging face blog posting in the summer of 2024, that is, you know, following this research, was titled, Uncensor Any LLM With Obliteration.
[02:02:29] And I'm going to share just the intro from that posting to give everyone a sense for what that earlier, for where that earlier research led, which is here. The blog says, the third generation of LLAMA models provided fine tunes. Then it says in parens, instruct versions that excel in understanding and following instructions.
[02:02:55] However, these models are heavily censored, designed to refuse requests seen as harmful with responses such as, as an AI assistant, I cannot help you. While this safety feature is crucial for preventing misuse, it limits the model's flexibility and responsiveness.
[02:03:20] In this article, we will explore a technique called obliteration that can uncensor any LLM without retraining. This technique effectively removes the model's built-in refusal mechanism, allowing it to respond to all types of prompts.
[02:03:43] The code is available on Google Colab and in the LLM course on GitHub. So then it says, what is obliteration? Modern LLMs are fine-tuned for safety and instruction following, meaning they are trained to refuse harmful requests.
[02:04:05] In their blog post, Ardidi et al., and that is the previous research that I was referring to, the research in the summer of 2024. Ardidi et al. have shown that this refusal behavior is mediated by a specific direction in the model's residual stream.
[02:04:26] If we prevent the model from representing this direction, it loses its ability to refuse requests. So that Ardidi reference, as I said, is the research I referred to previously, which showed the world how to do this, just how to simply perform this excision.
[02:04:50] The blog posting on Hugging Face is one artifact of that preceding research, and the companion repository on GitHub contains all of the details. That is, it's M-L-A-B-O-N-N-E dot GitHub dot I-O, and it is uncensor any LLM with obliteration.
[02:05:15] And as you would expect, it was all tremendously exciting to the world's AI hackers, many of whom immediately jumped on any and every published and available open-weight model. And happily obliterated away any and all perceived and imposed censorship upon those models.
[02:05:41] And those obliterated public open-weight models are now available for use by anyone who can harness them. And as you said, Leo, you've seen them both with and without the censorship obliterated from them. So this finally brings us to the first major topic I wanted to discuss today.
[02:06:05] Now that we have a much deeper understanding of where these chatbots came from, how they work, how they can have behavior imprinted upon them after they've been filled with raw knowledge, and how unfortunately brittle that imprinting is.
[02:06:25] So, okay, now I also need to mention that the term pre-training is what the AI industry has unfortunately landed on to actually mean training. The training that occurs before the post-training.
[02:06:41] And I suppose since there is now always going to be a definite post-training phase during which the behavior is layered on top of the previously trained-in knowledge, you know, if that pre-training were just called training, which is actually what it is, then it might be assumed to encompass both the training and the post-training. Meaning if it was just called training, it would mean all training.
[02:07:11] So my point is there's pre-training and there's post-training and there is not any just training in the middle. We don't use that. So now we know that pre-training, that's what it's called. Pre-training is the initial knowledge corpus training phase.
[02:07:37] Now that we know that I can explain that a small, competent team of AI researchers at AE Studio working with Anthropic have proven the feasibility of a new form of AI model pre-training.
[02:08:01] That is a new way of doing that initial knowledge capture. Last month, both AE Studio and Anthropic blogged about it and they published a joint research paper. I'm going to start by sharing Anthropic's press release style posting since it provides the essence of the research without dragging us too far down into the weeds.
[02:08:30] Under the title of, which is their title, an off switch for dual use knowledge in AI models. And again, the issue here is dual use, right? Nuclear bomb generation, you know, creation. Well, there's some knowledge that we want to be able not to provide.
[02:08:58] The problem is we've seen how brittle the instruction of do not provide that given post-training is. It can be removed and it has all been removed. It's been obliterated from all of the current open weight models. So here is what Anthropic said. And they start by saying this post describes research conducted by AE Studio in collaboration with Anthropic.
[02:09:27] They said a frontier AI model is, among other things, a large store of knowledge. Some of that knowledge is dual use, meaning it can be used for good or bad. For example, knowledge of cybersecurity can help patch critical security vulnerabilities or it can be used to exploit them.
[02:09:49] Knowledge of virology can help a researcher create a vaccine, but it can also help a malicious actor design a deadly pathogen. Ideally, we would be able to balance three separate goals. First, limiting access to dual use capabilities in as surgical a way as possible.
[02:10:12] Second, allowing trusted users to access those same capabilities for beneficial purposes. And third, doing all this without affecting the model's performance on any other task. Current safeguards are imperfect, they wrote.
[02:10:33] We train models to refuse harmful requests and use classifiers to screen inputs and outputs for dangerous content. These layers of protection guard against dangerous outputs, but they don't change the knowledge stored in the underlying model.
[02:10:53] Despite our safeguards, a sufficiently determined attacker may still try to jailbreak the model, working past its defenses to access the dual use knowledge. A more robust protection against misuse would be to control what the model knows. We've explored this before, they wrote.
[02:11:17] In earlier work, we filtered information about chemical, biological, radiological, and nuclear weapons out of pre-training data. And later showed that dual use knowledge can be confined to a removable slice of a model's weights. But filtering is a blunt instrument.
[02:11:43] It produces one model with one fixed set of capabilities. Using filtering, if you want a model version that can discuss advanced virology for deployment in a vetted biosecurity lab, say, And another version that cannot discuss that because it doesn't have the knowledge, they say, You have to train two separate models.
[02:12:11] Especially in the case of frontier models, which are large and very expensive to train, the cost to the developer would be prohibitive. So I'm going to interrupt here just to add that while OpenAI and Anthropic are not being currently forthcoming about the cost to train a current frontier model. Leo, you've always talked about how expensive it is. And oh, boy.
[02:12:38] You know, once those two are publicly traded, then their accounting ledgers will no longer be private. So we're going to find out. But to get some sense of scale, OpenAI's Sam Altman has stated that the training cost for GPT-4 was more than $100 million.
[02:13:01] And OpenAI reportedly spent $3 billion overall on compute to train their models two years ago, back in 2024. Also, as we know, models have grown much larger recently. And those numbers ring true, those earlier ones, because Google's Gemini model is believed to have cost Google $192 million to train.
[02:13:32] So we're talking... That's chicken feed, though, compared to what they're spending now. I mean... Well, actually, yes. Right. Because these are old and smaller models, right? So it could be half a billion dollars. Some have speculated a 10 trillion parameter model. Gosh. And chat GPT-4 was, I don't know, several hundred million, probably. Right. Yeah.
[02:14:01] And so all of this leads us to understanding why it's not feasible for any commercial provider, anyone, commercial or not, to train, to have multiple versions of a single model type, like a mythos that knows nothing about cybersecurity.
[02:14:27] The advantage would be you can't trick it into revealing what it doesn't know. The knowledge would have never been put in there. So it's just not there to ask. But you would spend so much money training that up. And this is the problem that they're trying to identify.
[02:14:46] So the quite valid point that Anthropic is making here is that it's massively infeasible to train a state-of-the-art model on any pre-filtered knowledge to make it dumb about some things. I don't know anything about that.
[02:15:06] But, you know, if you're going to be spending that kind of money on training, it needs to know everything so that it can have the widest application range for its use, you know, in order to have some chance of getting some money back out of all that training that went into it. So if a state-of-the-art model were to be trained on a filtered subset of everything, then, you know, that is a limited one forever.
[02:15:34] You end up with a very expensive, forever limited model. Okay, so we've seen that imposing post-training behavior, which is what we're just talking about, this refusal obliteration, post-training behavioral restrictions on open source models where you're able to modify the network weights, that can be altered.
[02:16:03] So it was a short-lived solution. The means for removing those restrictions, as we saw, well, it's all public knowledge, child's play, you know, and even the best closed-weight models, which are operated by cloud-based hyperscalers, you know, like OpenAI, Anthropic, and Google, and so forth, AWS, we've seen that they can be prone to trickery and abuse.
[02:16:29] We've, you know, prompt injection example, and we're, next week, we're going to understand exactly how that happens. So what's clearly needed is a new solution. And that's what these researchers have found. Leo, we're at two hours. Let's take our last break, and then we're going to look at the solution for this dual-use problem and how to solve this with a single training. We will have more of this.
[02:16:58] I'm just, by the way, absolutely fascinated by this. I feel like this should be required listening for the listeners of Intelligent Machines, our AI show tomorrow, because it's such foundational information about how all this stuff works. And it explains a lot, to be honest, about how these models work. And I think it's a good idea to kind of understand the underlying technology, because it makes, it means that you could do a better job.
[02:17:27] And again, as a user, you'd, you know, Lori, she's using the heck out of ChatGPT. But our audience, that's why they're here, is to get this. And, you know, for advanced users who are looking at things like obliterated models and wondering why some models do this and some models do that, there's so much going on. This stuff moves so quickly. It's very helpful to understand it a little bit. Absolutely. I appreciate it.
[02:17:56] We're going to take a little break and come back with more. You're watching Security Now with the wonderful Steve Gibson. This episode brought to you by Scribe. Scribe. Now, every time you onboard somebody new to your company, you know, you have to re-explain the same tools from scratch. Because there's no documentation. The result is fragmented processes, inconsistent execution, and no reliable way to improve how work gets done over time.
[02:18:25] And that's what today's sponsor, Scribe, does best. Scribe is a workflow AI platform trusted by 94% of the Fortune 500. Scribe captures any workflow in real time and turns it into documentation automatically. No manual writing, no manual screenshots, no starting from scratch every time someone new joins a team. You just do the process as you normally would.
[02:18:52] And Scribe automatically captures the workflow as it happens, including the steps and screenshots. And then it turns it into a guide. What would have taken hours of writing, recording, and cleanup is done in under a minute. And it's ready to share. Scribe automatically redact sensitive information, names, account numbers, emails from every screenshot. As an admin, you can enforce this across your entire team. You'll feel confident nothing slips through the cracks.
[02:19:22] Anyone following this process can launch real-time on-screen guidance that shows them exactly where to click step-by-step inside the actual tool. It's there the moment the Scribe is created and ensures everyone does critical processes correctly. Using a feature called improve workflows, Scribe will even suggest improvements to the underlying workflow, not just document it.
[02:19:44] Once you can see how a process is actually being done, you can identify where steps are redundant, where people are getting stuck, where things could be automated or simplified. It's not just capturing how work gets done. It's helping you do it better. To see what Scribe could look like for your org, head to scribe.how.com slash security now. And mention Security Now for your first month of Scribe capture free on select plans.
[02:20:11] That's S-C-R-I-B-E dot H-O-W slash security now. It even rhymes. Scribe dot how slash security now. We thank Scribe so much for their support. This is a really interesting application of AI, isn't it? It's doing what a human would do very laboriously and doing it instantaneously. It's kind of amazing. Anyway, on we go, sir.
[02:20:39] So because post-training behavior modification has been demonstrated to be easily removable, it is not sufficient to say, don't give people this information. It doesn't work to suppress that behavior. What we need is a new solution.
[02:21:03] And it's completely infeasible to do multiple training runs with different combinations of information filtered out of a model because training is prohibitively expensive. So what we need is a new solution. And that's what these researchers working with Anthropic have found. Anthropic continues their writing, saying, in new research carried out with collaborators at AE Studio,
[02:21:32] we explore a new method that could enable the benefits of training many separately filtered models, but at the cost of training only one. We call it GRAM, gradient routed auxiliary modules. Note that they wrote, note that the results of the experiments presented here are preliminary.
[02:21:58] GRAM has not been applied to any of the production models and Anthropic. And they said, and we're not sure it ever will be. And I, okay, so I take that to reflect a very reasonable and very cautious approach, because can you imagine the cost of a mistake if one of these companies, GRAM trained model, whatever that is, and we'll get to that in a second, turned out to have unsuspected problems?
[02:22:28] There's no reason to believe that it would or that that would be the case. But again, their cost is understandable because they could be scrapping half a billion dollars these days. So they write, Anthropic writes, how GRAM works. The idea behind GRAM is to give a model dedicated removable compartments for each category of dual-use knowledge
[02:22:56] and to update only those compartments when learning from dual-use data. Again, to update only those compartments, not all of the model's weights, only those in the compartments when learning from dual-use data. They said, concretely, GRAM adds extra neurons to every layer of a standard transformer.
[02:23:23] You know, the neural network architecture on which large language models are based. These neurons are divided into groups or modules. One module per dual-use category. During training, when the model encounters general-purpose text, that is, you know, just standard text, we don't worry about it one way or the other, it learns in the usual way.
[02:23:48] But when it encounters text from a dual-use category, virology, for instance, they wrote, the rules change. The model could use its general knowledge to make predictions, but only the virology module is allowed to learn from that text. The general-purpose weights are temporarily frozen, right?
[02:24:17] So, in other words, the bulk of the model isn't changed by learning about virology. Only the neurons in the virology module are changed. And if the bulk of the model's weights don't change after learning about virology, it doesn't learn about virology. It doesn't gain any knowledge from that. It's like it never happened to most of the model.
[02:24:46] They said the consequence is that virology knowledge accumulates in the virology module rather than diffusing across the whole network. After training, the module can simply be deleted, and the virology knowledge goes with it. Or it can be left in place for trusted deployments. When virology knowledge... Give it a lobotomy. Yeah, exactly. No, it's exactly...
[02:25:15] What's interesting about this is you would think, well, that's how all knowledge is, but it isn't. It's holographically stored. When the models are trained, it propagates through the whole model. Yes. So this is a special technique that says, no, no, only virology can only go here. Yes. And what's really interesting is it tends to concentrate there because it's like the virology module doesn't... It's like it knows it's carrying the full weight of that knowledge. Yeah.
[02:25:45] It's so cool. So amazing. So they said the knowledge can be tailored very specifically to the type of deployment needed. In our experiments, we defined four dual-use categories so that one training run with Graham yield a model that can be configured in 16 different ways, you know, on or off for each of the four categories.
[02:26:13] And as we know, a four-bit number can have zero through 15, so 16 different possible ons and offs. They said, we tested Graham in three settings of increasing realism. First, on a synthetic data set of children's stories tagged by topic, a small Graham model could be reconfigured to forget any chosen topic.
[02:26:42] And each configuration performed almost identically to a separate model trained from scratch with that topic filtered out. In other words, they did an A-B comparison. Here's a Graham-trained model where we turned off the topic, comparing it to a normal model that was never trained with that topic, and there's no difference in behavior.
[02:27:08] They said, and they made it more clear, they said that is, for the cost of training a single model, we achieved results that would normally require multiple training runs on different data sets. Second, we trained a larger model on a realistic mix
[02:27:33] mixed of web text, code, and scientific papers with four dual-use domains, virology, cybersecurity, nuclear physics, and a niche programming language just to serve as a proxy for specialized dual-use code. They said the capability associated with each dual-use domain is routed to its own module.
[02:27:58] Deleting a module removed the corresponding capability about as effectively as never having trained on that data at all. Remarkably, they said, we find that this removal did not degrade general performance. And finally, they said, we also tested whether an attacker could recover the removed knowledge
[02:28:24] by training on a small amount of malicious data. Believe it or not, Graham resisted this about as well as data filtering did. By contrast, an unlearning technique applied after training only suppresses the knowledge. That's what we've been talking about. It was easy to remove that with a small amount of fine-tuning.
[02:28:49] So that's a parenthetical about the resistance ablation. And then finally, third, they said, we ran the experiment at seven model sizes from 50 million to 5 billion parameters. Graham matched the performance of data filtering at every size and the gap between module on and module off
[02:29:18] grew wider as models got larger. I'm going to pause on that for a moment. The larger the model, the more general knowledge was stored outside of the various subject matter specific modules. So the subsequent removal or suppression of any one or more of them during inference,
[02:29:43] as a result, had diminishing effects upon the model's overall performance. This is exactly what we would hope to see. I wonder, you know, I'm running two different kinds of models right now. In the large video card, the 3090, I can run what's called a dense model, which is, that's the Quinn 3.8 27B.
[02:30:11] And it's, I think, kind of extrapolating from what you just said, it's a model where all the weights are spread throughout the model. That's why they call it dense. But in order to run DeepSeq V4 Flash on my Sparks on two different machines with a fast interconnect, it has to be, you can't use a dense model. You can't split the lobes of the brain. It has to be what they call an MOE or mixture of experts. Experts, right. And the advantage of doing that is you don't load the whole model into memory.
[02:30:41] You take shards of it. I suspect this is a similar technique, that you kind of localize knowledge in a shard as opposed to spreading it throughout the entire dense model. Right. You, I mean, in retrospect, it seems obvious, right? If you don't update a model's weights, it can't learn what you just showed it. Right. Because you didn't change it. That's how it learns.
[02:31:10] That's what learning is. Yes. Yes. You made it forget. You made it come, you know, like nothing happened. Yeah. And so if you, then if you reserve a region that you do allow to learn, then as it turns out, it learns about virology. The rest of the model can't because you, you froze its weights. It's all stuck here. Yeah. Doesn't, I mean, but it turns out this actually works.
[02:31:36] And the larger the model gets, the better it works, which is what, of course, which is what they care about because now, you know, they're not, they're not interested in doing any 5 billion parameter models anymore. That's sorry. That was just an experiment to see, you know, what it would do. 3.8 is a relatively small model at 27 billion. Exactly. Parameters, right? And DeepSeq V4 Flash is considerably larger than that. Yeah.
[02:32:01] So, so they said, they, they, they continue saying as AI companies train more capable models, we need to limit access to dual use capabilities, or I'm sorry, the need to limit access to dual use capabilities will increase. Okay. So in other words, Anthropic understands that the more capable the industry's models become
[02:32:26] out of, we're seeing it like before our eyes, the more valuable, the knowledge they contain will become. And thus the need to manage the access to that knowledge grows increasingly crucial. So they also make another good point. They write today, companies limit access through classifiers and refusal training. And we just, we just blew up refusal training, right? That's gone.
[02:32:56] That no longer works. Well, if you have access to the weights, you, you, if, you know, if it's open AI and Anthropic, they're not giving you access to their closed weight models. So you, you can't obliterate those, but you sure can the open weight ones. They said, however, these safeguards, meaning classifiers and refusal training are difficult to make robust without degrading performance on harmless requests.
[02:33:24] Methods like Graham offer a potential path toward access control that is more robust. And that's a really great point. The current system, which combines the refusal training, which we examined earlier with real time input and output classifiers that provides at best fuzzy filtering.
[02:33:49] The AI can frustrate its innocent user by refusing a benign prompt. It's like, wait, what do you mean you won't answer that? You're an AI. I know you're an AI, but why, why won't you give me the answer? Um, and similarly, it can delight a malicious user by letting down its guard when it should not.
[02:34:13] But by using a method like Graham, I mean, a model can have its functioning knowledge base selectively tuned to the authentication level or nature that the prompter's access permissions specify. So that's a significant improvement over today's soft and somewhat ad hoc solutions.
[02:34:39] So Anthropic concludes writing, this is early research and there are clear limitations. We have not tested Graham at frontier scale or in a production training pipeline. Um, and they said, as noted above, it's not, it has not been applied to any of our cloud models. Our evaluations, uh, quantify performance in terms of next token prediction ability rather
[02:35:07] than performance on real downstream tasks. And there's a deeper open problem that applies to data filtering and methods like Graham. Some dual use capabilities might be so entangled with general knowledge that no method can separate them cleanly. So then they said, they, they, they finished saying for further details about our experiments, read the post in our alignment science blog.
[02:35:36] Um, and that's really interesting, Leo. The point they make, I think is a good one. Like you need to be, you need to know when to freeze learning globally and only allow the knowledge to be concentrated in the module. But there, that, that decision is going to be a little soft and fuzzy too, right?
[02:35:57] Like some biology is not virology or not prone to abuse, but you know, again, it's not, it's not binary, right? It's going to be kind of on a continuum somewhere. So anyway, when I wrote about Graham two weeks ago and the security now weekend special email, the one before black hat, several of our listeners wrote back with feedback that I also shared
[02:36:24] during our black hat podcast, their concerns surrounded, you know, censorship and who gets to decide who has access to what data. When I voiced that during black hat, both Richard and Paul chimed in immediately. Well, this was just a different version of the way things have always been. You know, the fact that AI has made most of the world's knowledge vastly more accessible,
[02:36:50] doesn't necessarily mean that AI has made all of the, doesn't mean necessarily mean or need to mean that AI has made all of the world's knowledge vastly more accessible to everyone. You know, there isn't any entitlement to the knowledge that AI holds. After all, it costs those companies hundreds of millions of dollars to create and offer this facility.
[02:37:20] So I would argue that they can put whatever restrictions on it they wish. If commercial providers of that knowledge are required by internal policy, public pressure, the government, their stockholders or whomever to gate and control access to some aspects of that knowledge. I think that's entirely reasonable.
[02:37:47] And I would argue that the commercial providers have every right to do so. We just saw an example with OpenAI and that Hugging Face incident where Hugging Face was unable to deploy either Anthropics or OpenAI's models to help with their cybersecurity forensic investigation after they'd been attacked by OpenAI because Hugging Face hadn't been granted the magic keys
[02:38:15] to those AI cybersecurity, to those providers' AI cybersecurity knowledge. Everyone would argue now that they should have had such access and that we did later hear that OpenAI was working with them to give it to them. So anyway, I keep repeating the qualifier commercial providers because as we know, and you're using them, Leo, there are alternatives.
[02:38:42] And an alternative is exactly what Hugging Face turned to after their commercial models refused to help them. You know, they used one of the many publicly available unrestricted open source models. GLM 5.2, which is really good and has been succeeded by, interestingly, GLM 5.3, which is the same. This is an interesting slice on what you were just talking about. It's the same. From Z.ai, right? Z.ai says it's the same model.
[02:39:11] It's the 5.2 model with more enhanced post-training. So there's headroom even there. Yes. Where you could take the blob that is all the weights. And just do a better job with the knowledge. Fine-tune it. Yeah. Yes. Because post-training is behavior. Pre-training is knowledge. Post-training is behavior. Well, and interestingly, that's where it really excels is at coding and that kind of thing. Yeah. Right.
[02:39:40] It's really fascinating what's going on here. Wow. So just to finish here, anyone who might object to the big commercial services restricting what can be done can easily turn to any of the many alternatives.
[02:39:56] And I have to say, given what I was able to do with the carefully unrestricted and uncensored Venice.ai service, which I played with briefly when it appeared and we talked about it here on the podcast, I'm pretty certain that fully unrestricted, unrestrained, and uncensored AI models are readily available even from third parties in the cloud. Now, not from open AI and anthropic.
[02:40:24] That's not their style. Well, they're serving their proprietary models. But because there are so many open weight models, Hugging Face has more than 3 million models. And those aren't all – those are – many, many millions of them are just obliterated or somehow modified larger well-known open models. Right. So there might be thousands or hundreds of thousands of GLMs on Hugging Face that hackers modified.
[02:40:54] That's a very fun thing for people to do. Yeah. And it's – you know, it's like apps to download for Android. A bunch of – you know, how many millions of them are – A lot of them are crap. Absolutely. Exactly. Yeah. So we have run out of time and there was a lot to take in. Oh, I want to know more, Steve. We have now a better, far better understanding of the way today's AI works and at least enough to kind of have a feel for it.
[02:41:22] It seems like it's less magic than it was. Because we're going to learn next week how and why prompt injection attacks continue despite the best minds in the industry struggling to prevent them. That technology blew my mind on the plane flight to Las Vegas and I'm going to blow everybody's mind next week. Your chain of thought is not all it's made out to be. As they say, stay tuned.
[02:41:50] It really is interesting stuff. Thank you, Steve. Steve Gibson, our guru, now just – not of just security but of AI as well. You'll find him at grc.com, the Gibson Research Corporation. You know, it's really great because you've come full circle. As I mentioned earlier, as a kid, as a high schooler, you started at the Stanford AI Lab. Yeah. Of course, AI in those days was symbolic AI. It was a very kind of different enterprise. It was – But the same goal –
[02:42:18] It was so overstated even then. Yeah. It was like – It was Eliza. It's very artificial. It's like, you know, if people's moms were saying, that's what it does? Well, that doesn't seem like very much. It's pretty amazing. If you really get deep into today's models, they surprise me every single day with the things they say, the capabilities that they have. It's truly remarkable.
[02:42:44] As you mentioned in the past, it's great for system administration, coding. I don't use it much for writing. I don't use it much for writing, that kind of creative stuff. I do use it. I've actually had a lot of fun making cartoons. When we had a house sitter. When we went down to Black Hat, we had a house sitter taking care of the cat. And of course, our television setup is inscrutable. As most people – as most geeks are. Four or five remotes. Eight different devices.
[02:43:14] No house sitter could ever watch TV. Even Lisa says, if you die, I'm out of luck. I can't watch TV anymore. So I made a cartoon. A comic book that shows how to use the TV. And it's fantastic. And I didn't have to do much because the AI already knew. I just said, we've got this, this, and this. We control it with the Apple remote. I said, I got this. It's pretty – I mean – and again, I wish I could show you the cartoon.
[02:43:43] It's amazing. Amazing. So, constantly impressed. And I don't think – unlike much magic where when you know how the trick was done, he loses all its magic. This is not that case. What they are doing is unbelievable. It's us. It's us. Yeah. I think it is. And I know you think it is. I think there are a lot of people who hate that idea. A lot of people who say, there's something special that we do. Hate away. Hate away.
[02:44:15] I mean, we're still figuring this out. It's going to get better. It's going to get more efficient. It's going to get better trained. Costs are going to come down. I love it. One of the reasons I wanted to spend a ridiculous amount of money – it's not an economic decision because it's so cheap to use these models. I know it's expensive relatively, but it's not thousands of dollars. I wanted that brain in the house. Yeah. I wanted it to live next to me, you know? And now it is.
[02:44:44] It's sitting – actually, I have a couple of brains. Three, actually. It's sitting there thinking, doing stuff. What a world. And I use it all the time. What a world. What a world. Yeah. Steve's at GRC.com. That's his website. Now, there's some good reasons to go there. Of course, there's his bread and butter, the world's best mass storage, maintenance, recovery, and performance-enhancing utility. I live now on SSDs, and SSDs are so expensive. Those rust drives in my Synology, so expensive.
[02:45:13] You better spend a little money, get Spinrite, so you know you can keep them flowing and going, and no bits will be lost in the process. Everybody ought to have a copy. And the beauty of it is there are people who bought this program 30 years ago who are still getting free upgrades. Steve is amazing that way. GRC.com. You'll also find there his DNS Benchmark Pro, a great way to test to make sure you're using the fastest DNS server. You're probably using your ISPs.
[02:45:40] Almost certainly, that's not a good choice. Steve can help you find the right choice for your locale. Lots of other free stuff. And, of course, the show is there. Steve's got unique versions, shall we say, of this show. The 16 kilobit audio, the 64 kilobit audio, the handmade transcriptions by an actual human being, the wonderful Elaine Ferris, and the show Notes, which Steve, I mean, this is one
[02:46:06] where I'm absolutely going to be reading the show Notes to reabsorb or absorb better. In fact, maybe I'll point my AI at it. Say, is this what you're doing? 20 pages thereabouts of goodness, and you get all of that for free at GRC.com. You can even get the show Notes mailed to you if you want. Go to GRC.com slash email. You'll be putting your email address in. Actually, the main purpose of that is to whitelist, so you can send them emails, send them pictures of the week of buses as bridges or whatever.
[02:46:35] But underneath that email form, there are two checkboxes. One for the show Notes you'll get every week, and one for a very infrequent mailing list whenever he has a new product. I don't think he's sent anything out in years, to be honest. But anyway. No. It's there. Sign up. It's not going to... Believe me, you're not going to get any spam from this one. Steve is going to protect your secret identity. We also have copies of the show at our website. We have 192 kilobit audio, I think. Some ridiculous size.
[02:47:05] That's because Apple wants to down... It's 128. Is it only 128? Oh, okay. Well, that's not too bad. I thought it was even bigger. That's because Apple down samples it. And so we have to give them a better quality version, or you won't get a... I don't know. We also have video, which no one has. Steve, when I said, let's do video, I said, what? Why? What a terrible idea, I think is what you said. Nice to see you, though. We're doing it anyway.
[02:47:34] You can get both of those at twit.tv. That's the website. Slash SN for security now. There is also video on YouTube. We're actually glad we do video now, because now we can put our stuff up on YouTube, which is fantastic. Or subscribe, audio or video, on your favorite podcast client. You can even watch us do the show live. If you're a member of Club Twit, you can watch in the Club Twit Discord. Even if you're not a member, you can watch on YouTube, Twitch, X, Facebook, LinkedIn, or Kik. We stream it on seven different platforms.
[02:48:02] As we're doing the show, every Tuesday, right after Mac Break Weekly, that's about 1.30 Pacific, 4.30 Eastern, 20.30 UTC. Well, that just about does it for us. I hope your brain is swelling. Do not obliterate any portion. You're going to need it for next week. We'll see you right back here on Tuesday for Security Now. Bye. Hi there, Leo Laporte here. I just wanted to let you know about some of the other shows we do on this network. You probably already know about This Week in Tech.
[02:48:32] Every Sunday, I bring together some of the top journalists in the tech field to talk about the tech stories. It's a wonderful chance for you to keep up on what's going on with tech, plus be entertained by some very bright and fun minds. I hope you'll tune in every Sunday for This Week in Tech. Just go to your favorite podcast client and subscribe. This Week in Tech from the Twit Network. Thank you.
