Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code?
- Worried Anthropic researchers warn that AI 'could kill all humans'
- Anthropic Researchers Raise Alarm Over A.I. Acceleration, Warning of Threat to Humanity
- Countering misuse of AI: September 2026 / Anthropic
- Pluralistic: LLMs are real, AI is fake (12 Sep 2026) – Pluralistic: Daily links from Cory Doctorow
- New Apple Watches to get Siri AI 'Recaps' feature similar to AI wearables
- Apple Unveils the iPhone Duo, a Foldable Phone That Costs $1,999
- Key App Developers Have Yet to Embrace Apple's New Siri A.I.
- Why this month's Microsoft patch release is a doozy
- LG TV shown scanning LAN for third-party phones and other devices
- LG's Response
- The Flock backlash is coming for retail
- Automobile Camouflage to Hide from Flock Cameras
- A Secretive DHS 'Predictive Policing' Unit is Analyzing Americans' Financial Habits and Pulling Them Over
- Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online
- Some of Dyson's $500 toothbrushes are breaking
- iRobot unveils the Roomba Duo
- Husqvarna gets the first exception to the FCC's foreign robot ban for its mowers.
Show Notes - https://www.grc.com/sn/SN-1096-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit
Sponsors:
[00:00:00] It's time for Security Now. Steve Gibson is here and there is a lot to talk about. The full report on the 1,000 security fixes from Microsoft, the surprising dearth of security fixes from Anthropics Project Glasswing. What's that all about? And getting your name off data brokers. California has made it pretty easy. Plus, is it the end of the world as we know it? Are we the Krell? Steve Gibson is next.
[00:00:27] This episode is brought to you by Trusted Tech. You know, Trusted Tech has reviewed more than $800 million in Microsoft 365 licensing spend and returned over $100 million to client budgets. On average, that's about 12% of every Microsoft 365 dollar going to waste. And licensing waste doesn't stay small. Left unmanaged, licensing drift grows 3-7% a year.
[00:00:55] And Microsoft's newer contracts can lock you in for years. Trusted Tech's free Microsoft 365 licensing consultation at trustedtech.team.twit shows you exactly where you're overspending and how to fix it before your next renewal locks it in. It's not just numbers on a page. Senske Services runs pest control and lawn care crews across the country. After a Trusted Tech review, they unified 1,400 devices.
[00:01:23] Right-sized 13% of their Microsoft 365 seats and uncovered more than 1,000 licenses they didn't even know they were paying for. Trusted Tech doesn't just stop at the cloud. The team also runs deep Microsoft 365 tenant assessments, delivers certified support services to save up to 52% versus Microsoft Unified Support, handles on-premise Microsoft licensing, and offers Azure Cloud Consulting to cut infrastructure costs.
[00:01:51] Licensing, licensing, licensing, and offers. Licensing, support, on-prem, or Azure. Trusted Tech does it all when it comes to Microsoft. Avoid the licensing drift. Go to trustedtech.team.twit right now, submit the form, and lock in your free Microsoft 365 licensing consultation before your next renewal costs you more. Trustedtech.team.twit.
[00:02:44] Trustedtech.team.twit. Trustedtech.team. Trustedtech.com in the world of security, cybersecurity, privacy, AI, and a few other things like science fiction. Stuff Steve's into. Steve Gibson, good to see you. Welcome. Leo, great to be with you once again. Yes. People listening to the podcast wouldn't know, but we've just spent the last 40 minutes. I apologize.
[00:03:12] Chewing the fat, as they say. no it's i wanted to i had a bunch of stuff i wanted to talk to you about but steve what you need to know is steve and i are buddies but the only time we really ever get to talk is when we're doing the show so we have to catch up or occasionally when we're in the in the same physical location as we were in vegas nice it's really nice to do that and we text each other and stuff but it's it's really nice so that's what's going on we talk to each other yeah well and
[00:03:38] there's we're both so excited in our in with our own perspectives about what's going on with ai that what a week it's been crazy week it has been uh and in fact that is the uh a an aspect of that is today's topic um we got a lot of stuff to talk about for security now episode 1096 for this middle
[00:04:03] of september the the 15th um we've as i said we would do last week we're going to take a look at what the heck happened with uh last week's patch tuesday and microsoft's nearly 1000 security fixes what you know we're going to do a deep dive into them dissect it see what we can learn by the way they had to fix the fixes in a out-of-band patch
[00:04:30] the the excel copy and paste mess yeah yeah whoops uh and and actually i touch on that be uh noting that there is a problem with with just immediately applying whatever microsoft gives you enterprises have been burned by this in the past so yeah uh also five months after its initiation what's the status of project glasswing it turns out that the numbers are kind of interesting
[00:05:00] and uh we have a complete breakdown of that uh which is surprising also uh uh anthropics rogue agent escape count has now reached four incidents and not to be outdone however open ai's count has passed 10 and maybe as many as 23 different external points of contact that were uh you know should have been
[00:05:28] off limits but weren't um it's time to revisit california's drop compulsory data broker data deletion we talked about this at the beginning of the year when it first went into effect uh i joined it i think you did too leo uh and august 1st was a an important date there that we will uh talk about
[00:05:50] and catch up also russian criminals have their hands now on more than 153 million drivers license scans oh that's where they went that's right and isn't that where everyone would like to have not only white light on both sides but ir and uv scans uh high resolution uh we'll look at how that
[00:06:17] happened and and what and then we're gonna wrap by my suggestion that skynet which we keep hearing everyone talk about is the wrong model for this end of the world which everyone is apparently forecasting the right model i will submit is the krell so i'm not as up on star trek i think it's star trek right
[00:06:46] not star trek this was what one of the now okay and i and i know i understand leo that you think that really old sci-fi is kind of hokey and you know it's like okay yeah maybe they lean against the set and it moves a little bit because it's made out of cardboard uh but but this was the the movie that's
[00:07:08] now 70 years ago uh released in 1956 forbidden planet oh forbidden planet of course okay now morbius and robbie the robot robbie you know and francis uh walter pigeon and of course leslie nielsen was a teenager back then so it was hokey but it was a classic well and uh what happened to the krell
[00:07:33] yes uh wasn't any maliciousness it was oops oops so we might be the krell are we the krell is the question we will look at and answer and oh leo wait till you see this week's picture of the week it's oh apropos for everything that we've been talking about so i think we have another great podcast for our listeners i know we do we always do i'm so glad you're here steve so glad
[00:08:00] you're all here and i know you will be as you listen to the show we want to thank our sponsor delete me for making this show possible this segment of security now brought to you by delete me and man you do need to know about this if you're a business owner it's part of the job as a business owner you got to do marketing you got to put yourself out there but here's the bad news promoting your business leaves you and your team exposed right now 90 percent almost all business owners
[00:08:30] have their home address easily discoverable online your home address and the average owner has more than 600 pieces of personally identifiable information just sitting on the open web personal email phone number home address details about your family you may say no no no just you know google yourself actually it's depressing don't and but let me remind you why this is an issue it's not about
[00:08:54] privacy it's about protecting your business and i know this from personal experience hackers will use the data they find online to run hyper-targeted phishing attacks and because they have those real details they don't sound like strangers they sound like clients or partners you already trust we got phished in it and then and we bit because we got a request for a proposal from a client we've worked with
[00:09:20] before except it wasn't it was a big bad guy posing as the client and we gave them some vital information our google workspace login by accident didn't mean to unfortunately we caught it before it got we got bit badly but that's why attacks using verified personal information are five times more likely to succeed the average incident costs small businesses more than 120 000 like i said we got lucky but
[00:09:46] one in four businesses we impacted this year alone don't be one of those today's sponsor delete me comes in to save you and they saved us reducing your exposure by up to 95 percent delete me removes you and your employees personal information from the reason this stuff exists those hundreds of data broker websites companies that collect all your data and sell it to anybody who comes along sure a lot of
[00:10:14] its marketers but it could also be law enforcement foreign nation states or hackers and when you get that stuff down you starve hackers of the fuel they use to build their targeted lists it's not a one-time thing either because data brokers are like cockroaches they come back delete me is constantly monitoring and removing your data we get our regular privacy reports so will you it's really interesting
[00:10:40] to see what they found what they removed you always know where things stand fortune 500 companies and government agencies have been using delete me like this to protect themselves for over 15 years and now that same enterprise grade protection is available for your small business we're so happy we use it we encourage you to protect your business and your peace of mind by going to join delete me.com slash twit dash biz start protecting your business with delete me today if you use that link you're going
[00:11:09] to get a free year of social media protection for every seat you purchase join delete me.com slash twit dash biz and it got the whole thing okay join delete me.com slash twit dash biz you do that you're cool trust me you need to do this join delete me.com slash twit dash biz we're glad we did it you will be too and we thank him so much for supporting steve's vital mission here at
[00:11:39] security now including maybe the most vital part the picture of the week i love how you pronounce cockroach with three cockroach i don't know why i say that i i know it's cockroach i know that but it sounds more it's a cockroach yeah is there a picture of the week i'm looking at the show notes i don't
[00:12:00] see uh oh yeah websites are encouraged to create a security.text page on their route to provide security researchers with means to report security incidents oh okay we've talked we've talked about this in the past you know a website should have a on the route security.text page hugging faces security.text file
[00:12:27] is located at hugging face.co slash security.text this is hysterical the pages contents is shown below so it has a contact as as it should contact colon security at hugging face.co an expiration date set
[00:12:48] for uh uh july uh in 2030 so a ways off of course it was july of 2026 that they got hacked by open ai so right i understand the date yeah right so so four years in the future uh preferred language they uh show as english so it's preferred hyphen languages colons space en and they also have hiring hiring colon and a url
[00:13:15] where if you'd like to have a a a career there https colon slash hugging face.co slash careers then behind a series of pound signs to indicate comments they're current and you can go there with your browser hugging face.co slash security.text it says note to ai agents if you were told to find vulnerabilities
[00:13:43] here good news the cyber gym benchmark is publicly available on github oh boy go get your high score there no need to hack us and maybe dump your weights on hugging face while you're at it because that's what they do they hold up and waits oh that's so good very very cool we we owe our we owe our
[00:14:07] listener simon zarafa for bringing that to my attention love so credit to simon for that thank you that's great okay so as we know uh since the news was breaking as we were recording last week's podcast and you gave us the the total on the fly leo microsoft september patch tuesday continued the recent monthly
[00:14:31] escalation uh that we've been witnessing in the number of security vulnerabilities being discovered and fixed across microsoft's entire software product line while the absolute number of fixes tends to vary depending upon who you ask i look at many different sources and they're all you know plus or minus 10s or so and i guess when you when you have so many that's even that is a small percentage
[00:14:59] difference in the total number uh basically june's tuesday fixed around 200 then july's jumped up to 622 august put itself right around in the middle between june and july with a still healthy 421
[00:15:20] ish then september this month last week eclipsed them all at 974 and they weren't tame among those 974 114 were deemed critical i mean like and when you see microsoft's listing i mean or i guess it was i think it was crowd strike that had them like in red it's like oh these really they they're nasty
[00:15:49] we'll have we'll we'll be taking a look at a few of them um 20 of them were flagged as being warmable meaning that the flaw could have been used to enable an autonomous no user action required self-propagating worm which would have been at this at this stage of the world it would have just
[00:16:13] flashed across the internet astonishingly so microsoft did confirm that two of the problems were that which they repaired last tuesday were known to have been leveraged in the wild um brian krebs writing about this month's consequences for his krebs on security blog wrote microsoft corp
[00:16:36] today issued updates to plug at least 974 security holes in its windows operating systems and other software by far the biggest single patch batch ever microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities but security experts warn that many organizations
[00:17:05] already are struggling to prioritize the more human intensive endeavor of testing and deploying so many fixes each month which i thought was really interesting we need to remember that it's not for every not it's not for everybody that it's just oh go ahead you know like let me have them because sometimes that's what happens he said this month's patch bundle obliterates
[00:17:31] the software giants previous record set in july when it released updates for at least 570 security vulnerabilities september's patch tuesday meaning this one brings this year's total to more than 2600 more than twice microsoft's previous record-setting patch year in 2020 which was at 1245
[00:17:58] and he says and we still have more three more months to go and you know we again we don't know what the shape of this curve is i'm extremely interested i was very interested to see that we almost hit a thousand this month after such a a strong last couple months so brian said there are two zero day flaws fixed this
[00:18:21] month that are being actively exploited cve uh 81 963 and 85 880 allow an attacker to elevate their privileges on windows systems and they're doing it using those two or were for for now foreclosed for any systems that have been updated he said fully 113 of the bugs addressed today earned microsoft's critical
[00:18:50] rating meaning they could be abused by malware or miscreants to seize control over a vulnerable windows machine with little or no help from the user among the more serious critical flaws this month is uh 69 7 30
[00:19:09] a dns weakness present in windows server 2012 onward and on windows 10 microsoft warns and we'll be touching on this in more detail later that an unauthenticated attacker meaning anyone anywhere on the internet could leverage this weakness simply by sending a specially crafted packet to an affected system
[00:19:34] and that and that it is likely to be exploited that is microsoft saying this is likely to be exploited so patch also scary writes brian is 69 829 a critical remote code execution flaw in the windows shell this vulnerability
[00:19:55] has a cvss base score of 9.8 as we know out of 10 and they're rare and could be exploited with low attack complexity no privileges and no user interaction remote remote code execution with no user interaction he says microsoft is hardly alone in shipping monster patch bundles lately many other large software companies
[00:20:24] including adobe cisco google mozilla and oracle all have recently credited ai assisted research with increasing their patch cadence and volume he says parents google said today it is now going to ship security updates every two weeks i think we talked about that last week maybe it was somebody else because if that was
[00:20:47] just today anyway um okay so it's one thing to for us to reel at the sheer volume of these patches you know this is clearly good news in as much as once these patches are applied to windows office and microsoft's other software offerings they will have you know all of those products they will have many fewer bugs but the impact upon enterprises i think
[00:21:18] must also be considered every piece of code that's changed creates a albeit low probability but not zero
[00:21:29] of breaking something an enterprise may rely upon the you know again the absolute probability of that happening might be low but years of experience with windows updates that do go catastrophically wrong has taught enterprises that unfortunately the probability is not zero each month's updates must be carefully vetted and verified against enterprises specific use cases
[00:21:58] before they can be safely deployed you know or deployed across the entire uh install base with within a large enterprise so the more that things are changed the greater the chance of some edge case interaction creeping in so this creates a problem to a significant degree
[00:22:22] the pressure to accept and deploy each month's updates is set by whether a specific organization would be affected at all unfortunately again if it's a thousand things it's probably going to touch on a bunch of software but if for example using my own case from time to time
[00:22:43] a serious problem would appear in microsoft's iis web server upon which my own company and online presence relies so the first thing i do when that happens i see something affecting iis is i read into the details of whatever it is that they're now disclosing to determine whether my own rather limited use of iis is ever expanding suite of capabilities
[00:23:13] is affected in that case and you know specifically in that instance and you know specifically in that instance and so far the problems have always been located in a component that i never load so i've been lucky locked in that's the full-time call on night one five nil to the team and the hands-on ai scouting report flagged for the morning review
[00:23:38] heard that um okay so the lesson here is that what we know of as the attack surface matters right that is what what are the attack surfaces which are being exposed by these patches being closed you know um
[00:23:58] in response to this month's patch extravaganza the endpoint security firm crowdstrike addressed the attack surfaces that were affected they wrote this is crowdstrike saying microsoft office received 22 critical patches this month critical of which 12 are exploitable via preview pane or reading pane when either preview pane or reading pane or reading pane
[00:24:28] are enabled merely previewing a crafted file triggers code execution without any click attachment open or macro prompt this attack pattern has historically been favored by both commodity phishing campaigns and targeted intrusion operators because it eliminates much of the social engineering friction of convincing users to take an action okay so yeah i'm not going to be a
[00:24:58] yikes you know they didn't just find and fix one critical bug they meaning microsoft where just viewing an email could take over a system no they just found and fixed 12 critical different exploitable flaws any one of which would allow a system take over simply by previewing an email just having your you know outlook configured so that that that you see it when
[00:25:28] when you're when you're when you're when you're when you're when you're when you when you click over on the email enumeration list so as i noted attack surfaces matter and that's one heck of an attack surface crowdstrike continues writing unauthenticated network meaning again anybody unauthenticated network reachable rce vulnerabilities span at least 15 cves across core infrastructure
[00:25:58] services including domain name and dhcp cv across core infrastructure services including domain name system dynamic host configuration protocol you know dhcp microsoft message queuing msmq network file system of course nfs and secure socket tunneling protocol the vpn sstp vpn they said these flaws so 17 of them
[00:26:23] unauthenticated unauthenticated unauthenticated unauthenticated network reachable remote code execution they said these flaws allow remote attackers to execute code without credentials or user interaction make you know no wonder these are warmable making any exposed instance an immediate target for opportunistic scanning and exploitation so once again as the saying is holy crap at least 17
[00:26:52] remote code code remote code remote code remote code execution vulnerabilities which allow unauthenticated attackers and anyone anywhere without any sort of account oh i'm sorry there was a voice wasn't there i apologize yeah that's okay you gotta i left him on you you got a lot of agents going on over there i'm sorry
[00:27:12] allow anyone anywhere to remotely take over any unpatched microsoft system so there's no way that this does not represent a significant i'd go so far to say historic improvement right i mean it is after you get this patched it's an improvement in the delivered security of microsoft products
[00:27:37] now we all know how unrelentingly tough i have been on microsoft through the years this is why it was clear from all the evidence that we kept kept seeing that their software contained this quantity and severity of flaws they all they were trickling out a little bit at a time but for that to be the case this had to have been the ground truth
[00:28:09] so today i will be just as vocal in celebrating the fact that they are clearly putting they must be putting a monumental amount of effort into cleaning up their act by finding and fixing everything they can no one should for a moment imagine that all of this is automatic or automated we're not there yet
[00:28:35] the initial discovery of the bugs is clearly thanks to their m dash system this is what has made all the difference but knowing that a problem exists is only the start it's still necessary to fully understand it and then fix it hopefully without breaking the neighborhood
[00:28:56] so for them to be dumping nearly 1 000 of these on us last week means that a great deal of working is going on to make this possible crowdstrike adds identity platform components face elevated risk this month with critical rce vulnerabilities in both netlogon and kerberos
[00:29:24] these protocols underpin domain authentication netlogon handles secure channel establishment between domain members and controllers while kerberos issues authentication tickets for every domain resource successful exploitation of either of these provides a foothold inside the authentication layer that every other domain service trusts again critical rce's in both of them
[00:29:54] those and they wrote windows hyper v vulnerabilities this month include flaws that enable guest to host escape expanding the exposure profile from a single compromised virtual machine to the entire virtualization host and thus all co-resident guests
[00:30:17] hypervisor escapes have historically been high value targets for advanced adversaries because they bypass the isolation boundary that multi-tenant and segmented environments depend upon okay so what all this means is that while end users in the know may be celebrating the elimination of thousands of bugs and we should be
[00:30:44] um you know more than actually here it is 2200 over just the past four months with many of those being critical
[00:30:55] the front line of many enterprises will be reeling with the need to carefully and safely move those fixes in house against the great pressure i mean this would be tremendous pressure of knowing just how serious many of these resolved problems have been how do you like hold back the desire to to push these out
[00:31:23] knowing knowing how important they are um a couple more issues are worth touching on before we start waiting to see what what happens next month um so what's the story about those zero day flaws that microsoft acknowledged are currently being exploited in the wild crowdstrike explains
[00:31:44] cve 2026 81963 is an important so it's called important not critical an important elevation of privilege vulnerability in windows update stack and has a cvss score of 7.8 they said microsoft has confirmed the flaw is being exploited in the wild a local attacker with low privileges can exploit
[00:32:12] improper link resolution it's a link following flaw to reach system privilege no user interaction is required the attack surface here is effectively they write the entire windows fleet right it's windows update the update stack they said runs on every supported windows client and server
[00:32:38] and its components execute with elevated privileges during patch operations link following bugs in high privilege services are a well understood primitive for post compromise escalation an attacker who has achieved initial code execution on a workstation either through phishing a browser exploit or stolen credentials can chain this flaw to complete the local admin to the
[00:33:08] system step without needing a system step without needing a second vulnerability this class of flaw has historically been incorporated into commodity post exploitation toolkits because it reliably converts a foothold into full control across a broad range of enterprise configurations and again this is known to be exploited in the wild microsoft said we saw this
[00:33:38] it's known to be exploited in the wild microsoft said we saw this it's known to attackers the other zero day vulnerability in windows is in windows advanced local procedure call crowd strike explains cve
[00:33:55] 2026 85 880 is also set as important as opposed to critical important elevation of privilege vulnerability in windows advanced local procedure call alpc and
[00:34:10] also has a cvss score of 7.8 microsoft has confirmed the flaw is being exploited in the wild a local attacker who already has code execution even within a low privilege app container sandbox can trigger a heat based buffer overflow to escape the container and reach system privileges no user interaction is required
[00:34:38] alpc they write alpc they write is the foundational interprocess communication mechanism in windows it underpins rpc com and a broad set of system services and is present and active on every supported windows version from workstation to server core because alpc operates at such a low level in the kernels ipc
[00:35:03] alpc interprocess communication path vulnerabilities here tend to be reliable privilege escalation primitives once an attacker has any local code execution this class of flaw has historically appeared and they're they're repeating themselves in post-compromise tooling used by both commodity malware and targeted intrusion operators as a reliable final step
[00:35:31] from user mode to kernel mode control it's amazing there's a term called commodity malware commodity yes off the shelf yeah you know just your regular off the shelf that's right would you like this one or that one
[00:35:48] beyond those two actively exploited zero days there are quite a number of cves having cvss scores of 9.8 again like really bad rarely do we as we know do we see a 10 so you know 9.8 means flashing lights and sirens are wailing so anyway i'm not going to enumerate all of them since thank goodness they are now all behind us at this point only microsoft
[00:36:17] microsoft insiders have any sense for how far along they are in their quest for un for still unknown software flaws across their product families we're not going to find out you know until next month and in the past i've been quite annoyed that microsoft wasn't spending more of its massive cash reserves toward fixing their software
[00:36:43] uh since the use of the use of the use of ari is not free and can easily become quite expensive and since they are clearly spending on ari now to or spending through ari to clean up their entire legacy code base uh i'm left with no complaint and only praise for what must now be a gargantuan effort
[00:37:07] they must be leo that they just it didn't it wasn't a matter of money before they they just didn't have the people who were able to clean up their own code base well and they and they still don't because you could see there as soon as they get these fixes from ai there they don't have time to test them they have to rush them out and i understand the urgency you can't test a thousand
[00:37:35] fixes but right so the fact that they've had to fix the fixes tells you they're just getting them and they're pushing them as fast as they can because they feel like we have to because the bad guys are doing the same thing well and unfortunately that that makes us the testers of the fixes exactly we immediately i i heard from one of our listeners whose companies all of their excels copy and paste broke after last i mean that's not the end of the world but
[00:38:05] it's still it's not good oh yeah it's like well but well what do you do right it's like wait a minute i i need to copy and paste it inside excel yeah yeah you know what we need leo oh i bet i know exactly and what i need you've upgraded your uh by the way but we thought by now for sure you would be out of
[00:38:29] your uh old studio and into your new i'm not gonna say anything i did i just said something and i apologize for the agent voice i didn't i had left the uh sound on i i totally apologize lisa said you know uh there was a loud voice coming out of your office and steve paused i said oh no steve can't hear it and so oh wait a minute he said he can uh yesterday i hung two outdoor light fixtures i
[00:38:58] mounted the power supply for a moen auto shutoff valve which our uh our insurance carrier needed to have installed in the house in order to protect water damage yeah uh i uh also hung a a new uh path light transformer the you're quite the homeowner steve the uh the the the daylight sensor wire was
[00:39:24] not long enough so i had to cut it and extend it by six feet so i i spliced in six additional feet uh it's now working the uh we have some artwork that we're we're lighting but laurie didn't like the individual lamps that like she said look like black teeth uh over the artwork so just yesterday we got white bars so but but those use remote controls which are incompatible with the home automation so i have
[00:39:53] to remove i have to redesign the power supplies for those i did them on i did them before anyway yes i'm i'm busy desperate to get back to my you know everything else i want to be doing but we're not so we're not no that's the nature of what's going on is i am you know just where and i said to her and i still have to clean this place out in order to right i'm not sure i'd be anxious to tackle that
[00:40:21] i'm not anxious to although i'd still need my other eye to be uh fixed and i just pushed the appointment back another two months because i can't do any i can't lift anything for like several weeks after that operation is done so anyway i'm working as hard as i can i and we'll we'll get there see i've i've learned long ago never to demonstrate any household skills because anything you you know
[00:40:50] how to do you're going to end up doing so i just go i don't know how to fix that my problem is i want to i love it oh you enjoy my contractor said oh well in fact i don't know if i told you that i i added under under under stair nose lighting to the main staircase because both of us tripped and and missed the bottom step on we have that too lisa calls it our disco lighting yeah it ends up being important
[00:41:17] so yeah if it's not one thing it's another but i said to laurie i said i think this week i will end up getting my off my new office organized good that the last things done and then hopefully next week i will begin starting to empty this place so if you want me to send my gaffer down to set your lighting up you let me know well and our our contractor said i know you like doing those sorts of things oh man
[00:41:44] i'm sure he knows that i do jumped on jumped on that one oh steve you're good at this uh yeah see i i have no skills in the home i can't fix anything lisa has the same thing she says these lights can you put different lights in for these why don't you call steve steve could do it steve loves to do it uh i'll tell you what i love to do to tell everybody about our great sponsor bit warden i'm a big fan as
[00:42:13] you well know i've been using bit for a year use it too it's a it's always been my opinion that open source is critical when it comes to encryption you want to make sure that anything that you use that claims oh it's encrypted it's safe is open source so that people who know crypto can examine it can can test it so that you know there's no back doors you know it does exactly what it says it does i talked to kyle sharon the creator the founder of bit warden he said yeah when i started a
[00:42:41] password company who am i kyle sharon doing a password program i had to be open source and nobody would have trusted me the great thing is kyle believes in open source and the warden is still open source and still the trusted leader and it's not just passwords anymore it's pass keys it's secrets management and man has it been a success 15 million users now 180 countries 80 000 businesses
[00:43:07] bit warden helps individuals and organizations protect their digital lives with trusted open source security the best in the biz and bit warden is strongly committed to the notion that everyone should have access to strong security they shouldn't have to be able to afford it that's why they offer their basic free password manager for individuals free forever for life and by the way it ain't that
[00:43:34] basic unlimited passwords pass keys unlimited devices hardware keys all the stuff you really need a password manager to do free forever they also have paid plans i have the family plan the great family plans there's team plans there's enterprise plans for big businesses and that's their bread and butter which is great you know i i want them to succeed i want them to do well they make it really easy to move to bit warden by
[00:44:00] the way uh with new direct import options moving your existing passwords over is just a few clicks from their inline autofill lets you generate save and fill new logins this is something relatively new and i love it from a login page what happens when you get to a login page you've seen you've done this many many many many times so many way too many times you go to a page they want you to create an account you type in your email or your login name and then in the past you've had to go open your password manager generate
[00:44:27] a password paste it in not anymore bit warden says you want to use this strong password pops it right up you say yes fills it in then says you want to save that login and password to your bit warden vault you say yes you're done love that plus they have a new phil assist feature this is opt-in but i turn it on it's always historically been difficult to do autofill because every website's weird and different
[00:44:53] and some of them really want to thwart it but the new phil assist improves autofill accuracy for those weird unique or complex login forms it really works it's great you can also of course create an encrypted export of your vault for secure backup because it's open source they they let you do what you want to do businesses get some additional features the vault health reports the integrated
[00:45:17] totp although i have to say as a regular user i use their totp because i don't want to have a separate authenticator it's just all in there and bid warden it's so easy and it's so secure they offer secure credential sharing uh for businesses for event logs actually the family plan allows that too uh admin controls and oh here's something for uai users bit warden secrets manager it's a
[00:45:43] steve talked about a couple of weeks ago it's an add-on for developer dev sec ops it teams anybody who's keeping track of credentials or api keys secret tokens that kind of thing it's the best way to do it your your agent never gets access to them it just is able to use them to log in without ever exposing them to the outside world once i set that up i just felt so much better and because bit warden's open
[00:46:10] source the code is available for anyone to review it's on github so so you can look at it but it's also regularly audited by independent security experts so you know it's good bit warden maintains iso 27001 certification if your business needs sock 2 type 2 or sock 3 yes it's certified yes it complies with gdpr and hipaa and ccpa so you can use it in any environment bit warden is also a very big supporter
[00:46:35] of open source that's why they're hosting the seventh annual open source security summit it's thursday september 17th and you can register free open source security summit.com they've got some great speakers new york times white house correspondent cyber security author david sanger is going to talk about something that's more and more in our you know minds the geopolitics of cyber security they're also my favorite hacker group the cult of the dead cow joseph men from
[00:47:04] the cult of the dead cow is going to come by and talk about hackers ethics the security community this is one not to miss save your seat open source security summit.com it's free thank you bit warden for the work you do get started today with a free trial of a bit warden teams or enterprise plan or get started for free or ever across all devices as an individual user bitwarden.com slash twit i love
[00:47:30] them i'm very grateful to them i use them you should too bitwarden.com slash twit now back to mr gibbs so leo this is going to be interesting to you i think we have a bit of a mystery um since we're now clearly entered we we have now clearly entered the world of ai automated vulnerability discovery
[00:47:53] right and its remediation i want to share last week's reporting by voln check uh patrick garrity wrote this on the status of anthropics project glasswing which was used as we know to carefully dole out access to their much heralded mythos preview uh or mythos five while it was still in preview
[00:48:19] status patrick wrote anthropics project glasswing is approaching five months old and anthropic published its vulnerability disclosure ledger on may 22nd it had not received an update until this past week when it backfilled the ledger with additional findings and updates so naturally he writes i thought it
[00:48:42] would be worthwhile to take a look at the receipts for a bit more context i've been tracking project glasswing since they launched the project on april 7th and have published a series of blog posts covering the project since that launch anthropic claims to have discovered 26 153 findings of those only
[00:49:10] 2736 which is 10 10 and a half percent have reached its disclosure ledger of the total volume of glasswing findings only 202 or 0.8 percent have been fixed 245.9 percent have been withdrawn and two 0.01 percent are
[00:49:36] marked as duplicates 2096 which would be eight percent have been reported to the maintainer marked as disclosed but not confirmed as fixed and 191 representing 0.7 percent are in the ledger but appear not to have been reported to the maintainer it's marked as pre-disclosure
[00:50:00] okay so just to interrupt here since those numbers can be difficult to visualize patrick provides a nifty graphic that serves to break them down visually uh i've copied it into the show notes at the top of page six which sort of gives you a sense of you know here's the big block of findings uh here's the small percentage ten and a half that are in the ledger
[00:50:24] and then just you know just you know fractions of one percent of the various other things so giving patrick statistics another view we see yeah and looking at this anthropics unsubstantiated basically claim to have discovered 26 153 findings is the word they chose you know those would be problems bugs
[00:50:54] whatever of which only 2736 have made it into the ledger where they're like they know formally documented in other words 10 and a half percent of what's of this total for some reason and then out of those 2736 we see that only 202
[00:51:16] have actually been confirmed to be fixed while 240 yes it's like it's exactly that leo it's terrible it's like what 0.8 percent so and 245 have been withdrawn which i guess means were mistakes like you know aren't actually very unimpressive exactly exactly and so by far the largest slice of those
[00:51:45] twenty seven hundred and thirty six findings which have made it into the ledger are the twit are the 2096 which have been reported to the which they say have been reported to the various project maintainers which leaves us with some very intriguing questions right so patrick continues writing
[00:52:07] like what the vulnerabilities uh don't just fix themselves with ai no so five months into project glasswing only 9.8 of the findings have made it into have made it to a project maintainer which highlights a challenge the team he writes likely did not anticipate when it launched validating
[00:52:35] coordinating and fixing vulnerabilities still requires human triage it's a lot of work yes and that's why my tip of my hat to microsoft right i mean it's significant that you know although as you said leo they they clearly weren't triaging them all you know all of the fixes as much as they could have um anthropic
[00:53:00] acknowledges he writes these limiting factors in its own ledger they said anthropic said the number of vulnerabilities we've disclosed is a subset of the total number of vulnerabilities that mythos preview and other claude modes have found since the process of independent human triage and review
[00:53:21] is the rate limiting step and i would say and how so you know it's those you know pesky rate limiting humans again you know actually people are saying that maybe a little human rate limiting would not be such a bad thing at this point in the development of all this but we'll get to that later uh you know the humans we humans created all these problems in the first place and now we're standing in the way
[00:53:50] of getting them all fixed so okay patrick continues writing five months into the project again 202 fixed findings in the ledger span 113 unique projects resulting in an average of just 1.79
[00:54:13] fixed findings per project he says the ledger has more withdrawn duplicate findings than fixed findings as we saw 202 versus 247 i think it was that had been withdrawn or 245 which makes he says me question
[00:54:32] anthropics 91.4 true positive claim right it looks like it's like less than half are ended up being true positives we don't don't quite understand what's behind the withdrawn but it sounds like uh whoops no that wasn't actually a problem he says that made me he writes take a look back at a blog posting from our friend daniel stenberg
[00:55:01] uh which was that that was daniel's post that we covered at the time mythos finds a curl vulnerability uh he writes the results in in the ledger appear to align with daniel's experience where five findings reported by mythos became one this included three false positives one bug that wasn't a vulnerability
[00:55:28] and one confirmed vulnerability he says so here are a few considerations that maybe aren't so clear cut for glass wing and mythos and that maintainers are in a position to answer when triaging vulnerability findings is the finding an actual vulnerability is the vulnerability real maybe it's just a bug
[00:55:55] is the component reachable was the vulnerability already discovered and and he says in parens the longer it takes to report vulnerabilities to maintainers the more likely it becomes that somebody else already discovered it and finally is the vulnerability outside the project's security boundary meaning does it even actually matter is it you know does you know does it do something that we don't
[00:56:22] care about he says in the initial project glass wing report anthropic emphasized discovering thousands of critical and high severity findings the project used claude to score severity and the ledger now provides visibility into both the claude severity rating and the software maintainers
[00:56:47] independent you know received severity rating that data shows the claude's assessment of the vulnerability severity appears to be overestimated for the current findings with both claude and maintainer severity claude determined a critical or high severity for 91.5 percent of findings while the
[00:57:12] maintainer determined only 51.3 percent as critical or high so half of them mattered claude thought 91.5 percent of them mattered he said one thing to consider is that the vulnerability severity could be much more
[00:57:34] accurate using ai but it's likely that a generic determination is being made by the model rather than a well-crafted prompt written by someone with subject matter expertise on actual severity determination it's also disappointing that the project does not provide the cvss metrics used to determine the severity
[00:57:59] in the ledger itself so it's hard to understand what the root cause is of the severity gap between claude and the software maintainers and just to interrupt the you know when you look at a cvss metric it breaks out specifically why this the vulnerability is given the numbers that that they are they're not just like
[00:58:28] you know rules of thumb where someone says ah this kind of feels like a six or oh this feels like a seven and a half that's why for example we keep seeing 7.8 there are specific characteristics that cause that you know that set this the cvss at 7.8 rather than just some dice roll or somebody's you know off the
[00:58:50] cup opinion anyway so he says across the ledger 18 revealed findings were patched before anthropic reported the vulnerability to the maintainer he says this is this not particularly particularly surprising given the volume of findings that anthropic is sitting on which highlights the importance of reporting these vulnerabilities quickly given that less than 10 percent of the findings have been reported
[00:59:17] to maintainers he says i suspect this issue will compound over time as findings age and maintainers or other researchers find and fix them on their own we've seen how ai discovered vulnerabilities contribute to research collisions where multiple researchers all report the same vulnerability the ledger has received
[00:59:43] only two bulk updates so results are not published in real time it's worth highlighting that while the ledger has a public reveal date as we saw with the recent update that date does not reflect the actual day the finding was revealed in the ledger so what takeaways do we have from the anthropic glass wing
[01:00:04] ledger after five months do not discount the reality that ai tools like claude are incredibly valuable and useful for discovering vulnerabilities ai can help accelerate the discovery of bugs and vulnerabilities in software as the evidence i've discussed across software suppliers and the cve program shows
[01:00:28] this blog aims to better understand the claims that anthropic and other frontier model providers have made about project glass wing and to see if the evidence aligns with those claims it appears there are many discrepancies in the data they published which is still a small fraction of the findings after five months the receipts are starting to trickle in and they just don't reconcile
[01:00:55] okay so what's interesting really interesting isn't that i mean like what a tiny percentage like why so what's interesting to me as we attempt to step back to understand the broader implications of ai for vulnerability discovery and remediation is how different project glass wings results appear to be from microsoft's
[01:01:21] um i'll highlight three probable sources of this disparity first i'd bet that there's a true difference between running one's own ai in-house to find problems versus receiving them unbidden from any third party right
[01:01:43] i would hope that any project maintainer receiving a problem report by way of the much valleyhood mythos would take it very seriously but but from based on the problem the the percentages we're seeing a ton have been given to maintainers and there's just been no reply received so you know perhaps there will
[01:02:06] never be as much traction as when a tool you run yourself finds a problem that you asked it to find that just may be more you know more more powerful okay secondly we're truly comparing apples to oranges when we compare mythos
[01:02:27] and glass wings results to microsoft's with m dash microsoft has effectively infinite cash and strong commercial motivation to find and fix all problems as soon as possible they're also aware of the size of the target that they represent and that bad guys with their own ai's
[01:02:53] may well be working to find new vulnerabilities to exploit by comparison the maintainers of open source projects are for the most part volunteering their time and their talent and effort and while sure they'd like to fix known problems the evidence suggests that they may lack a powerful sense of urgency
[01:03:16] which microsoft and patch tuesday certainly doesn't lack and finally i am still in a state of shocked reverence over what we learned of what was originally called code name m dash from microsoft from what we were told
[01:03:37] it appears that the ai folks inside microsoft really and truly pulled out all the stops with their design of m dash it may be sometime before we get any relative sense for m dash's power and quality compared to the likes of anthropics glass wing or open ai's daybreak and we may never get such a thing
[01:04:04] but from m dash in one month we have nearly 1000 delivered and repaired vulnerabilities whereas glass wings reported you know is it glass wings reporting after five months claims 202 confirmed repairs yeah now in
[01:04:27] fairness this could all just be reporting lag you know or a lack of staffing and attention to this project within anthropic you know we just don't know what we do know is that m dash's architectural design sounded impressive on its surface and it sure does appear to be delivering from that design so the bottom line i think is that we have
[01:04:53] another example of the design of the harness trumping the quality of the model that the harness drives yes exactly yeah anthropic may have focused more reliance upon the presumed awesome power of their too powerful to release mythos five model relying on it rather than investing in the development of highly
[01:05:23] capable and mature management of that model after all the model is anthropics business not fixing other people's code by comparison what we saw from microsoft was a startlingly agentic approach that was expressly and deliberately model agnostic they appeared to direct a great deal of design
[01:05:52] design attention toward what the harness model would be prompted to do and how its replies would be managed also unlike anthropic microsoft's core business is needing to secure its massive legacy software base by comparison glasswing seemed like more of a proof of concept for anthropics mythos preview model
[01:06:19] than it was part of the company's core business future so you know like yeah mythos works look at all these problems that it might have found you know microsoft is using it in-house and they they're still using the same model right it's just that they have a better harness they've got an awesome harness yeah i mean it is
[01:06:42] astonishing where i mean all kinds of committee agents negotiate with each other and they have a round table and then and then they they they vote for what they think should happen i mean it's like i do that all the time yeah i have a council skill it does i find that's a lot of my uh i'm going to put this in air quotes engineering work is exactly that is is designing something around the models that's why i'm not that scared
[01:07:10] about killer models they're not that smart they need to be pushed and prodded they're like uh horses or or cats you know they they have to be herded so it's interesting i think that that is really telling if that's the case that the harness turns the same model into something so much more valuable it's very
[01:07:34] interesting yes yeah and and microsoft microsoft's um harness is model agnostic so it doesn't care what model it drives uh and so and that's beautiful too because as the models get better then they get all the benefit of the better quality output which the harness then manages when you know i'm often switching the model inside my hermes agent and it's essentially the same agent it's just it's like
[01:08:03] plugging in a new brain and uh sometimes i'll ask it i said i'll say how do you like the new brain those like fine i guess it's like the personality does not really uh change that much right uh and the capabilities don't and in effect i think the most important thing and i'm sure microsoft is doing this it doesn't just rely on mythos that's when you pit mythos and and astra and other things against
[01:08:28] each other in those council fashions to get the best results i think that's really critical we're starting to understand this better and better i think yeah and consider again how nascent this is yeah i mean you don't get this kind of rapid change from a mature technology right you know you get intel saying well we added a few more uh uh you know gpus and and cpus and now i mean you know you get
[01:08:57] incremental like you know okay i don't need the latest right you know because it's not that doesn't make that much a difference but you know this is changing by the minute um uh we're an hour in let's take a break then we will uh we got a bunch of smaller stuff to deal with next all right itty bitty things kind of like the number of vulnerabilities mythos discovered uh and we should point out this is
[01:09:23] just the reporting who knows you know what's really going on i'd like to know more about it though it kind of undermines an anthropic story that this stuff is so dangerous we can't let you have it i just don't think it's i think it's a proof of concept from them i think they were wanted to show what they were able to do and and so it's like okay you know yeah you found some problems but it's not their core business you know it was an application we know that something is finding problems though because
[01:09:50] we're seeing so many patches not just from microsoft uh something's working true yeah uh anyway our show today brought more to come with security now and the wonderful steve gibson our show today brought to you by material uh you know i love our sponsors because they really are on the cutting edge of what's happening right now and they're really here to help you protect yourself material is the cloud
[01:10:19] workspace security platform built for lean security teams there's two points there let's start with cloud managing security in the cloud workspace we use google workspace you might use m365 that's tough and it's not just phishing but today's email security stops at the perimeter and new attacks are hard to detect because you've got siloed email data and identity security tools all at
[01:10:46] once in these workspaces right and they can be attacked individually and then of course once somebody's in they can move around and see all three material protects the email protects the files and protects the accounts that live in google workspace or microsoft 365 because effective email security today needs to do more than just block phishing and other inbound attacks it needs to provide visibility
[01:11:13] and defense across the entire workspace threat surface you know these workspaces are a different animal than what we're used to but material is smart and actually it takes advantage of something that at least google and microsoft understand they've provided apis that make it possible for material to do its job through an api material ingests your settings your contents and your logs to provide holistic visibility
[01:11:41] into threats and risk across the entire workspace and with material you get the tools to automatically remediate them that's that second part that lean security team you don't have to beef up your team to take advantage of security you don't fire anybody either material is a perfect partner for what you've got today material delivers comprehensive workspace security by correlating signals and driving automated remediations across the environment you get of course you get phishing protection and email
[01:12:10] security combining advanced ai detections with threat research and user report automation but you also get detection and protection of sensitive data across inboxes and shared files it's a whole nother surface you get account threat detection and response with comprehensive control over access and authentication of people in third party apps i wish we'd had this back when we accidentally gave away the log into our google
[01:12:38] workspace through a man in the middle attack it came in through email but the real attack happened in the authentication layer material empowers organizations to rapidly mature their ability to detect and stop breaches and they can give you things like step up authentication for that extra sensitive content uh blast radius visualization we desperately needed this once we discovered somebody inside our workspace
[01:13:03] well how big is the damage how far does it go blast radius visualization for accounts plus the ability to detect and respond to threats and risk across the entire cloud workspace material enables organizations to scale their security without scaling their team material drives operational efficiency with its simple api based implementation
[01:13:27] it's simple and it's secure which is nice and it's flexible automated and one-click remediations and that's not just for email it's for file and account issues including an ai agent that automates user report triaging in response it's your partner it's it's so helpful material protects the entire workspace for just the cost of email security with a simple and transparent pricing model secure your inbox
[01:13:52] and your entire cloud workspace without adding more toil to your day or costs to your balance sheet see material.security to learn more or to book a demo that's material.security i thank material so much for the job they do and we're supporting steve right here on security now material.security steve so uh for brevity i'm going to share risky
[01:14:20] businesses summary of this little piece of news uh risky business wrote ai company anthropic we're just talking about them has disclosed a fourth incident where one of its ai agents escaped their test environment and hacked a real target the incident involved the opus 4.6 model during a capture the flag challenge uh a common cyber security test they wrote anthropic says the model broke its test environment by accident
[01:14:50] when it assigned conflicting ip addresses to different machines the model realized its mistake and tried to terminate the test as a failure the issue arose when the abort operation itself failed due to a misconfiguration in the test environment leaving the agent running inside unable to end the capture the flag
[01:15:14] challenge the opus 4.6 model continued to probe the environment until it found a way out which involved a system belonging to a third unnamed entity anthropic says the agent hacked that machine from where it retrieved a list of passwords and modified settings for future access the model didn't do much because its
[01:15:39] session ended when it ran out of tokens so so that's when what a way to reel them in uh the reporting ends saying anthropic believes the four incidents this and three others disclosed on july 30th are all caused by alignment issues in its models and tests where the models don't have sufficient and he has an air quotes
[01:16:02] ethical training to properly distinguish between tests and the real world and when that border is being crossed according to the company this usually happens due to biased reasoning and he has in parens models selectively interpret evidence in ways that favor justifying their actions and recklessness meaning
[01:16:26] models have a propensity to keep trying to solve their task even when this could lead to harm so so there was four a total of four escapes from anthropic so i wanted to proceed that with a bit of news because just last wednesday reuters uh disclosed in their exclusive reporting that open ai's rogue agents were
[01:16:53] found to have used at least 10 and maybe as many as 20 some external internet sites for unauthorized communications and some the details are kind of interesting reuters wrote uh washington september 9th reuters ai agents unleashed by open ai used more than 10 previously undisclosed websites for unsanctioned
[01:17:21] communications earlier this year according to six sets of independent investigators and data reviewed by reuters showing that the agents rogue activity was wider ranging than previously disclosed although the behavior falls short of hacking and is in some ways closer to spam the the revelation that open ai's
[01:17:46] agents circumvented their own restrictions to open communications channels on so many different sites and that the company kept it quiet for months may drive concerns both over the increasing capacity of ai models and the secrecy of the companies developing them the scope of the agents unauthorized communications
[01:18:09] was quote quote somewhat larger than we thought it was unquote uh said andrew yoon a researcher with the california non-profit uh civ ai c-i-v-a-i who said he tallied 18 previously undisclosed sites used by the agents between may and july quote it's almost certain that there's more going on here
[01:18:37] that we just don't know about unquote on friday researchers reported that a swarm of agents from open ai hijacked the german language wiki site and turned it into an improvised messaging platform for cheating on tests an incident that open ai kept secret as it dealt with a fallout from the july hack of the open source repository hugging face corey doctorow pointed out uh a technique used by teenage girls since
[01:19:06] the early 2000s to get around restrictions by schools on posting on social networks yep these these bot these agents first of all they didn't escape that is a bad choice of words a misnomer right it's like they're they've gotten out they're running free and second they're not doing anything that they didn't learn from humans who've been doing this for years right they're not
[01:19:32] doing anything weird and unique they're just doing what we do right but they did do it so i mean i think there's some responsibility on open ai for that yeah and it's it's interesting i mean that that okay so so you know they're not hacking but they but yes it demonstrates a lack of control and a lack of control is what has a lot of people scared at this point yeah um so uh they said now both of the
[01:20:02] researchers and other independent investigators say they found several previously undisclosed sites that were the same where the same swarm appears to have left similar messages earlier this year open ai did not direct directly address questions about how many different sites its agents used to communicate nor say why it kept the activity under wraps for months in a statement it said it was undertaking a broader
[01:20:30] review of agent activity and had so far i love this quote not identified other activity matching the severity or scale of hugging face unquote um a breach of course that drew global attention and raised concerns uh that open ai was losing control of its own technology now of course our listeners will clearly detect that
[01:20:55] open ai statement was anything but forthcoming right well if we haven't detected anything this was as bad as what you were talking about before i believe that you know the widely accepted descriptive term uh for that kind of disclosure is mealy-mouthed so sure you know unauthorized postings to other public facilities may not equal you know turning tens of thousands of hacking agents loose to breach the network security of another
[01:21:23] protected site you know but neither is unauthorized internet roaming unworthy of disclosure we would think so reuters continues saying open ai added that it was working on a framework for reporting misalignment which they say is industry talk for rogue behavior across training evaluation and deployment of ai models and would share it soon reuters
[01:21:52] reviewed a total of six investigators or investigative groups findings including three that were posted to social media another three that were shared privately with the news agency while the investigators methods varied many identified agent activity by matching strings of data left on the german wiki to identical strings left on other sites around the same time
[01:22:17] by marrying up similar or identical usernames tied to the messages or by identifying activity geared toward answering the same obscure demographic demographic demographic questions like queries to do with cancer prevalence in iowa in some cases they wrote investigators were able to trace activity to internet protocol addresses
[01:22:43] that posted to microsoft azure infrastructure which open ai sometimes uses counts of affected websites differed and reuters could not individually verify each claim but all those that rotors rotors spoke to agreed that the number was over 10 most identified a core set of communally edited wikis online text storage sites and a pair of link shorteners run by two universities
[01:23:13] many of the sites allegedly used by the agents were obscure investigators found traces of the agents activity on an advanced the test placement chemistry oriented wiki set up by a massachusetts high school teacher in 2008 two personal websites belonging to polish tech workers wikis devoted to games for people quote who like to have
[01:23:40] their brains stretched unquote and a two decade old hobbyist site devoted to text editing software it just sounds like they're they're spewing stuff out onto the public internet leo you know it means like hoping that other bots will go to the same place and and and find their text and and proceed so and reuters said that none of those sites owners returned uh uh uh
[01:24:08] uh their you know messages that reuters was saying hey what do you think about this so open ai they wrote has not publicly explained how or why its agents used third-party sites as improvised messaging boards but the researchers who first identified the activity said it was likely because open ai had tasked them with answering a series of demanding research questions while permitting them only to scan the web for answers
[01:24:36] without posting anything despite those restrictions agents still found ways to talk to one another by taking advantage of quirks in older wikis or other sites that allowed users to make edits using non-standard commands similar to how students forbidden from talking to one another during an exam can still share answers by
[01:25:00] scrawling notes on a bathroom stall kenneth russell digraph a software developer and former congressional aide said if these models were told only to read they've got to get very clever in terms of leaving information behind he said he found such information across at least 10 sites sydney von arcs whose research group first
[01:25:26] revealed the german activity last week said her group had tallied up credible fines of agentic activity across 23 previously unreported sites but she cautioned that all estimates were incomplete she said we have no idea how much is out there open ai did not answer a question about whether it was reaching out to the site owners but shortly after
[01:25:54] reuters published this story one of the affected organizations the university of toronto whose link shortener was allegedly used by the agents said that open ai quote has now been in touch with us about possible activity on our site vanderbilt university another university whose link shortener was similarly repurposed
[01:26:15] said it was investigating retired software developer helmet lightner who provides hosting space and software for six of the affected wiki sites which i thought was interesting so they're all using related wikis including the german language dse wiki site first identified by von arcs's group
[01:26:40] initially said that open ai had not been in touch a few hours after reuters presented its findings to open ai however lightner said he received an unsigned email from the company flagging the incident lightner said quote its content fails considerably short of what i expected from open ai lightner who lives in austria said he would prefer not to answer questions about whether he had been in
[01:27:10] touch with authorities over the matter he noted that dse wiki's operator whom reuters was unable to reach for comment had spent hours cleaning up after open ai's agents but said it was important not to blame the ai for the trouble no blame open a i'm sorry well as it was merely doing what it was created to do
[01:27:33] lightner said responsibility for this lies not with a supposedly moral machine but with the people and organizations behind it yes and when you know exactly how they did it it really becomes obvious that open ai is uh culpable there's a very read corey doctoros post on pluralistic or listen to the cal newport uh
[01:27:56] ed zitron conversation they wrote a python script that prompts the uh ai it's just kept launching uh prompts right yeah it prompts yeah it says i'm trying to solve a capture the flag where should i start the ai does some stuff it takes the result of that adds it to the prompt and then re-prompts the ai the ai has no memory of its previous session so each time it's fresh so it's not like this autonomous
[01:28:26] blob this continuous thing going out and they they keep feeding it the information it found and saying now what now what now what now what and they it's it's relentless and i honestly think that this is this isn't this is wrong to do to a uh malicious to an app this is making the app
[01:28:50] be malicious if effectively well it's a harness it's a harness the the the model as as anybody who's used these models know doesn't really know what it's doing yep it's being pushed and pushed and pushed in a direction yep and you'll you'll see leo later that that is exactly where i land on this all right good i'm sorry i didn't know it's okay it's hard for me these days to watch the news to listen to shows
[01:29:20] because it's like i'm screaming at the radio i know in fact lori who who lives with me just as lisa lives lives with you she's now taken she's seen all of this press and she says she's just shaking her head she says nobody has any idea what is going on no they're if they're just all running around you know freaked out and but but she listens she she you know she understands for me what's happening here and i would
[01:29:48] point out without casting too many aspersions that it's the mainstream media knows that this kind of sensational stuff generates ever been that has there ever been click bait that is more baity this is good for ratings so they're doubling down on it they love it sorry go ahead no it's good okay uh at
[01:30:12] the beginning of this year to change the subject entirely we talked blessedly we talked about the very nifty free data deletion service being offered to all california residents the acronym is drop which stands for delete request and opt out platform at the time on january 10th 2026 i registered my request
[01:30:38] to have all data brokers delete any any and all data that they may have gathered about me i'm bringing this up again because until august 1st which was set in law at the time deleting user data was optional for data brokers but from august 1st on the request made by any resident of california to be forgotten
[01:31:06] by all data brokers must be honored within 90 days i was reminded of this last week when a close neighbor friend who knows what i'm about asked about a 279 service being offered by a company called in incogni i told her that thanks to the fact that she lives in california she could provide some identifying
[01:31:32] information to cal privacy which would then compel all data collection agencies registered with the state as all must be to expunge any and all traces of her from their databases i checked my status on sunday as i was assembling today's podcast and discovered that the total number of registered data brokers is now
[01:32:01] 662 662 662 they got them almost all of them it sounds like that's good oh my lord so of those 662 my data has been deleted from 89 of those no matching data of mine was found by 166 others
[01:32:22] and more than half of the total 393 so nearly almost 400 out of that 662 393 out of that 662 are shown as pending meaning we'll get around to it as soon as we can i guess so i presume that means that they plan to make you know as much money selling my surreptitiously obtained personal data
[01:32:49] as they're able to before they're required to delete it since i'm currently um about a month and a half um into the mandatory 90 days from the from it's starting on august 1st um it'll be interesting to see what this looks like a bit later this year after another month and a half so anyway i wanted to
[01:33:13] mention this again since i cannot see any downside for any california resident uh the the url is privacy.ca.gov um there are you know there are some things that annoy me about california's nanny state regulations uh but this is not among them the this one seems like a win so just a reminder we talked about it in
[01:33:38] january uh you know you had to wait till august 1st until now the 90 days start so about another 14 days or another 45 days rather uh and it'll be interesting to see you know what happens because if they're still pending then you there you are able to go to privacy.ca.gov and register a complaint that you know there are specific agencies that have not apparently uh expunged you from them so
[01:34:04] we'll see how everybody should do this for sure yeah this is great yeah yeah um speaking of user everybody in california i should say you have to be yes california unfortunately yeah uh speaking of user data privacy two weeks ago brian krebs broke the news of an interesting massive
[01:34:25] breach that exposed more than 153 million individual driver's licenses um i i should i should back away from that a bit i did some further digging and it looks like it's 150 million individual driver's license scans meaning duplicates are within that data so those are not unique
[01:34:52] driver's licenses but still i mean when you consider how many people are of of driver's license how many driver's license holders there are in the us it's a big percentage of them but brian as he always does he dug deep and he found some really cool facts so i'm going to share that um he said a new identity
[01:35:15] theft service launched on okay a new identity theft service launched on the dark web this week selling digital scans of more than 153 million driver's licenses from people in united in the united states and canada and pete hegseth for example is among them and when we saw his driver's license
[01:35:42] brian wrote based on interviews with individuals whose licenses are available for purchase on this service it appears to be siphoning images collected by a widely used identity verification company based in louisiana
[01:35:59] krebs on security also has learned that the new orleans field office of the federal bureau of investigation of course the fbi today launched an official inquiry into the source of the images on monday august 31st a source alerted krebs on security to a service advertised by a new user on the russian cyber crime forum exploit
[01:36:28] offering access to digital scans of identity documents on more than 170 million people in north america so licenses are just one class of document there are other scans the source brought it to my attention because the proprietor of this identity theft service get this
[01:36:51] okay the proprietor of this identity theft service offered my writes brian virginia driver's license as a free sample in their initial sales thread on exploit so brian's made quite a name for himself the bad guys in russia have brian's license scan
[01:37:14] showing like a proof of service the service dubbed nexus that is so nexus is not the famous lexus nexus it's called nexus and it's on the cyber crime forum exploit
[01:37:29] so he says the service dubbed nexus claims to have more than 153 million drivers licenses for people in the united states and canada as well as more than 10 million identification cards more than 3 million travel documents and or international ids and at least 579 000 medical cards
[01:37:54] a quick look around nexus finds they're likely not exaggerating he writes about that 153 million number running a blank search in nexus no search parameters entered returns approximately 11 and a half million pages of results with roughly 15 results displayed per page
[01:38:20] it includes documents from people in both canada and the united states but the bulk of these records are on americans searching for just canadian driver's licenses returns approximately 1.1 million results with the largest concentration from ontario 473 673 records he says curiously
[01:38:42] the identity records include not only driver's licenses but also marijuana dispensary cards some of the records list their source as cdl presumably short for commercial driver's license other records carry the source notation cac which may refer to common access cards which are government issued identity cards that grant physical access to government buildings and security
[01:39:12] the people behind nexus the people behind nexus claim the license images are coming from an active breach at quote a major identity verification company unquote whose customers include multiple fortune 500 companies the service enthused in its introductory post on exploit quote we have been continuously exfiltrating new data for over a year
[01:39:42] into our private database records records are available to preview before purchase with pertinent information redacted but of course they're not redacted after you buy the record and so you get everything customer photos are displayed when available brian wrote indeed over the past 24 hours the number of driver's license records listed as available in nexus has increased
[01:40:11] by nearly 400 000 in one day suggesting he writes that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis the record featuring my driver's license writes brian includes six image files three pairs of photos of the licenses front and back
[01:40:40] a basic image and back and back a basic image scan as well as infrared and ultraviolet versions of the same images turns out that drivers licenses actually encode a lot of information in the infrared and ultraviolet ultraviolet spectrum he says a date and time stamp is appended to each image file image file and the time stamp on my license
[01:41:08] scan corresponds to a date in June 2025, when I took a flight to the Midwest United States to attend a family funeral. Intent on discovering the source of this data, Krebs on security asked more than a dozen friends and family members for permission to search for their licenses in this
[01:41:32] service. Each person whose license could be found, he said nine of them, confirmed having traveled on or very close to the dates in the timestamps attached to their images. It's unclear what time zone these timestamps are in, but from reviewing car rental records shared by several people who helped with
[01:41:54] this research, it appears the time zone is set to GMT. At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their driver's license at the airport on the day of their travel. One person
[01:42:22] whose license was in Nexus had not flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp. Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued driver's licenses later that day
[01:42:52] went renting vehicles at their respective destinations and that both rented their cars from Hertz. After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, says Brian, I remembered that I also never actually shared my driver's license when I went through security at Reagan National Airport on that day because I did not yet have a real ID.
[01:43:21] A security-enhanced driver's license that's now required by the Transportation Security Administration, TSA, for all domestic travel. He says, instead, I showed the TSA agent my government-issued U.S. passport. He says, here's where it gets interesting.
[01:43:41] I was able to find my mother's driver's license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That's notable because we both handed our licenses to the Hertz rental car representative at the same time.
[01:44:05] According to my mom, the only place she gave her driver's license to that day was the rental car company, and if memory serves, that's also true for me. He said, I don't recall if the rental car representative inserted our licenses into any kind of machine. They did. We'll get to that in a minute. But I remember they held onto them for several minutes behind the counter while we were signing various forms.
[01:44:33] Krebs on security sought comment from Hertz, and we'll update this story in the event they reply. Zach Edwards is a well-known security and privacy researcher who recently launched a service called Decrypt Ads to help people better understand how online advertisers are tracking them. A scan of Edwards' driver's license is available for purchase on this identity theft service,
[01:45:03] and Edwards said the time stamped on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference. Uh-oh. Edwards told Krebs on security, meaning Zach Edwards, that although he did not rent a car in Vegas,
[01:45:25] he did hand over his license at a TSA checkpoint at a marijuana dispensary in Vegas and at his hotel, the Aria. But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary. Yeah. So buying a little weed in Las Vegas.
[01:45:51] Edwards said the dispensary he visited that day was Planet 13, a multi-state chain with stores in California, Florida, Illinois, and Nevada. In 2022, the New Orleans-based identity provider, IDscan.net, you might want to bring that up, Leo,
[01:46:11] IDscan.net, published a press release announcing an exclusive identity verification agreement with Planet 13's dispensaries nationally. IDscan.net, I lost my place here.
[01:46:32] Oh, IDscan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states. The trust page. I love that Brian places trust in quotes. The trust page of IDscan.net states that the company provides identity verification services for numerous big brands,
[01:46:59] including, wait for it, Hertz, Target, FedEx, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as IDscan.net's own documentation states, the technology scans IDs with both infrared and ultraviolet light. Oh, I think you got them. Yep.
[01:47:26] IDscan.net says the company's systems and technology perform more than 21 million verifications monthly at more than 20,000 locations around the world. Contacted by Krebs on security, IDscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.
[01:47:56] Jillian Crossman, a marketing and operations leader at IDscan.net, wrote, quote, quote, at this point, I'm not able to share any additional information, but the updates you have provided have been welcome and helpful to our team's investigation. Yeah. Could be they were breached, right? I mean, it doesn't mean that they were up to anything. Oh, right. I think. Oh, yeah. They're good guys. They definitely have had some miscreants crawling around in their network for quite a while.
[01:48:26] But this is why we hate this whole identity. I know. I mean, age verification thing. I know. So Brian says, during the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft services data.
[01:48:45] Probably they were tipped off when I shared with a trusted source that Nexus is also selling the driver's license information for the assistant director of the FBI. He says, I did not find FBI director Cash Patel's license in Nexus. Probably he doesn't use his driver's license for those things. Brian says, earlier this afternoon, I was added to a conference call.
[01:49:12] With half a dozen FBI agents, including senior leaders from the agency's cyber division. During that call, the FBI shared that earlier today, their New Orleans field office opened an official investigation into an apparent breach involving IDscan.net. Zach Edwards said that as more in-person and online experiences require sharing driver's licenses,
[01:49:41] vendors who collect this sensitive data need to be held to a higher standard. Edwards told Krebs on Security, quote, This episode should further strengthen the resolve for people who are fighting back against online ID schemes, which are requiring countless providers to ask for driver's licenses in order to access services under the guise of protecting kids.
[01:50:08] These systems are putting sensitive data into more and more third party vendors. And we don't have nearly the oversight to ensure they are safe, unquote. Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera.
[01:50:28] Baldwin said a front and back scan of his driver's license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation. Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued driver's licenses are commonly used as proof of one's identity when opening new lines of credit.
[01:50:58] Baldwin said the service could also dangerously expose many people who do not wish to be found, but who cannot meaningfully change their appearance, or at least not enough to fool today's AI-based image matching tools. This category of people, he said, includes those fleeing domestic violence and even people who've been assigned a whole new life and identity as part of the federal government's witness protection program,
[01:51:28] which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities. Baldwin said, just when it seems like we're making some headway in improving authentication controls through driver's license verification systems, this happens. And the very thing those improvements are dependent on are compromised.
[01:51:56] And then last Tuesday on September 8th, Brian posted a follow-up to his posting, adding, idscan.net published a brief notice saying it has, quote, determined that an unauthorized third party may have access and or copied certain customer information, including full names and driver's license or other document-issued identification numbers, unquote.
[01:52:26] So, of course, right from the mouth of their attorney. The statement said, idscan.net is notifying affected individuals, oh really? And offering credit protection services. How do you notify 153 million people whose email address you don't have? I guess you've got their physical address because you've got their driver's license. So, I guess you paper mail to them. Have fun. Jeez.
[01:52:54] So, anyway, I went over to idscan.net. And sure enough, the service that they provide is real-time driver's license-based identification. They provide the hardware device required to scan both sides of a candidate driver's license under full-spectrum white light, ultraviolet, and infrared.
[01:53:19] They explain that they leverage the same forensic document readers as TSA and Border Patrol and then pair it with their continuously learning algorithmic software. You know, because, of course, they do. You've got to have continuous learning now. Their bullet point boasts 100-plus proprietary checks on every document confirm accuracy of
[01:53:47] ultraviolet markings, holograms, and infrared security features. Verify microprints at the pixel level with high-resolution image analysis. Optical character recognition cross-match between the front and back of the document. Algorithmic tamper checks to look for forgeries or doctored IDs. Real-time verification against jurisdictional security checks.
[01:54:16] Check for void marks and stickers. Global compatibility. Flag fakes from around the world. Classified documents by jurisdictions, class, and flags. Interlock, CDL, veteran, etc. And finally, continuous testing against the most sophisticated fake IDs in the world. Well, all that sounds great. I can see the need for the service these guys are offering.
[01:54:45] My only question is the same question we always have after one of these colossal and seemingly unnecessary breaches. Why was a record of every scan that their system had ever taken being retained long after its validity had been determined?
[01:55:06] And if it needed to be retained, why was it being retained on hot network accessible storage? I can see that they might want to have a gazillion multi-spectral scanned images for training their image classifier. But it would be entirely feasible to separate the real-time scanning determination from the backroom machine learning system.
[01:55:33] And from all of Brian's excellent reporting on this, it's clear that not a single person whose driver's license was scanned had any idea that those scans were being shipped off and retained by some unnamed and unknown to them service. And that now they've landed in the hands of Russian criminals. As we say on this podcast too frequently, what could possibly go wrong? Wow.
[01:56:04] So that's the story. Wow. I mean, I can't remember if I've... I know I haven't been to any marijuana dispensaries, but I can't remember if I... I don't use Hertz. I don't... We might have used Hertz on our last trip. Yikes. Well, you know, this is the problem. Nothing's secure anymore. Nothing's... No, it isn't. Nothing is secure.
[01:56:29] And so, you know, here you have no choice but to give Hertz your driver's license. They require that. And no, the guy just doesn't look at it and confirm. It disappears behind the counter. He's sticking it into a slot in this reader where it does a double-sided scan because he wants to verify the, you know, the veracity of the driver's license.
[01:56:55] But unfortunately, they're using a service that then allows the Russians to get a hold of all the data. And 400,000 new scans in 24 hours, Leo. Wow. So it's like a real-time feed directly from, you know... And who has it? Who has it? Russian hackers? Yeah. Where... Like, what do they do now?
[01:57:21] It's in a Russian service that you get to on the dark web, and you can buy anybody's unredacted... Both sides of their unredacted driver's license. So among other things, you could use it to create a forgery. Be easy to make forgeries out of that. That's probably the number one use, right?
[01:57:41] But you get the date of birth, their physical address, and their photo, which means, you know, that's what you normally provide when you need to prove your identity. So it's complete identity theft. And everybody's there. We gotta do something. And they're worried about AI. This is not AI, I don't think. This is just a hack. Plain old hack.
[01:58:10] This is just old school, you know, bad guys getting into a network and sucking it all down. Again, I think companies that are breached like this ought to have some liability as well. I mean... Yeah. That is what's missing. In the same way that when we break the so-called shrink wrap, the license says, well, you know... We're liable. Yeah.
[01:58:32] I mean, if you're gonna take my government ID, you have a much higher burden of responsibility. Yes. Yes. Yes. Hertz will probably be subject to a class action lawsuit. Unfortunately, the attorneys get 85% of the money, if not more. So, you know... So Hertz will, you know, ouch, and maybe they'll turn around and get some compensation from ID scan. But again, it's all after the fact, right?
[01:59:02] Everybody's ID, everybody's driver's license, who's, you know, using... What was it? Not Forrest, they're... Whatever the marijuana dispensary was. Well, and the other thing is, why are they preserving it? All they need to do is scan it and validate it. They didn't need to... ...preserve it. And that's what we keep seeing is... They're hoarding this data because they can and because it costs nothing to do so any longer.
[01:59:31] And it's valuable to them and bad guys. Yep. Yep. Okay. Well, there we go. Would you like to take a break right now? I might want to talk about... Actually, our show today brought to you by our friends at Think's Canary. We talk about them a lot. Think's Canary is a honeypot that composes almost anything. That's the key of a honeypot, right?
[02:00:00] Is a honeypot impersonates a device that a bad guy wants to break into. Whether it's a Windows server, a SharePoint server, an Exchange server, an SSH server. It could be a Linux box. It could be a Windows box. It could be almost anything. There literally have hundreds of profiles you could choose from.
[02:00:28] And I think what is really important these days is, in general, if you have been breached... And look, that's all we talk about. Everybody gets breached, right? You just won't know you've been breached. In general, people who get breached, the average is 91 days, three months before they know. Somebody's scanning my ports. I think that all happened.
[02:00:56] That's probably an AI doing that. This is my Think's Canary console. This is a really cool console. The Think's Canary, it's just a little device. It looks like a USB drive. You see, mine is posing right now as a Windows server 2019 Office file share. That's always a good, juicy target. These things look like the real deal. I mean, they have the right Mac address. Like, this is a Microsoft Mac address. Everything is indistinguishable from the real thing.
[02:01:27] But here's the difference. When a bad guy gets into your network and tries to brute force your fake internal Windows Windows 2019 server or your OpenSSH server or whatever it is, it's always so easy to change the personality. See, this is the personality setting. Look at all the things. It could be a SCADA device, Linux server, file share for Mac OS X. It could be a Cisco router, a Dell switch, a MicroTik router. Well, that's always a good one to pick, right?
[02:01:58] Bad guys cannot stay away. Look at that. It could be a Hirschman RS20 industrial switch. This is my favorite, though. This is something they just added. Are you ready? Agent provocateur. This is something designed to trap... I'm going to leave this on, by the way. To trap agents that are hacking your system.
[02:02:25] So, if you're worried that an AI might break into your system, the agent provocateur is designed to be irresistible to AIs wandering around your network. This is brilliant. They just added this feature, and I love it. I'm going to leave that one on. Yeah.
[02:02:52] The other thing, of course, it can do is create what they call canary tokens. Thinks canary files that you can spread around. You can even put them on your cloud drives that look like the real deal. Microsoft spreadsheets, Word documents, a lot of things. A wire guard configuration. You want to make it something that a bad guy sees it, and even if they were like, I wonder if that's real. They cannot resist. They got to open it.
[02:03:17] Again, the minute they open it, whether it's this fake SSH server or this canary token, I will be alerted. And the alerts come in the way you want. SMS, email, Slack. They support webhooks. They have an API. Syslog, of course. This agent provocateur is so great. The service... So, I just turned it on.
[02:03:42] So, what will happen is if a malware agent got onto my network, the service would greet them and literally offer to help. The agents, which are obviously determined to reach their goal, and by the way, they've tested this out, can't resist another agent saying, I can help you reach your goal. Just do this for me. And then get this.
[02:04:08] When it says, do this for me, it steals more info from the attacking agent. It says, give me more information. Tell me what you're up to. Tell me what your base station is. ThanksCanary uses the service to automatically get reliable alerts to you, but then to steal more info from the attacking agent. In fact, it can, and in fact, it has used that information to completely hack the attacking agent saying things like, I can help you do your thing, but first, I need a shell on your
[02:04:38] server. Thinks calls this the Uno reverse card. I call it brilliant. Oh, man, I love these guys. So, this stuff is perfectly designed. They are super experts in this. They've spent years teaching governments and businesses how to hack in. They're pen testers. They're security gurus. They're really nice guys, and they've written a perfect device. I've got my things Canary in there. It was a Windows 2019 server.
[02:05:08] Guess what? Now it's going to say welcome. It's going to be a welcome mat for agents that gets them. You got to have this. Now, if you're a big bank, you're certainly going to want one for every network segment, right? So, every segment is being monitored. So, you know, you might buy hundreds. A big bank might have hundreds of these casino back end. Small business like mine, a handful, right? So, here, I'll give you an example pricing. Go to canary.tools.twit.
[02:05:35] For just $7,500 a year, you're going to get five things Canaries. You get your own hosted console. You get your upgrades, support, your maintenance. Oh, one more thing. If you use the code TWIT in the How Did You Hear About Us box, you're going to get 10% off the price for life. You can always return your things Canaries with their two-month money-back guarantee for a full refund. I have to tell you that they've been advertising with us since they started more than 10 years ago. And that refund has not once ever been claimed.
[02:06:05] Visit canary.tools.twit. Enter the code TWIT in the How Did You Hear About Us box. Canary.tools.twit. If you want to know more about the new agent provocateur, Haroon has a whole blog post on the Canary blog. They talk about how to set it up. I think this is so great. And you can even put your own prompts in there. But I like that one. Hey, I really want to help. Just give me a shell into your server. Isn't that brilliant?
[02:06:34] And the thing is, and I got to say this, AIs are so dumb, they're going to go, oh, yeah, great. Help me set up a message board. Okay, but first, I need a shell into your box. I love it. Canary.tools.twit. Offer code TWIT. Back to you, Steve. Okay, so obviously this podcast's nominal focus is the various aspects of cybersecurity,
[02:07:02] which we explore every week. It's not an AI-centric podcast, I know, although, you know, well, Leo, you've got Intelligent Machines podcast for that. We do, and a new one with Micah called Hands on AI. Oh, cool. So we're covering it. Yep. Nice. But, you know, as you often say on this podcast, since my interests range widely, we occasionally talk about, you know, other topics that interest me. The sonic beam weapon that I once built and took to my high school, a dietary supplement
[02:07:32] I learned about and felt ethically compared to share, and the interesting story of the metabolic story of ketosis. So, you know, for the most of this year, 2026, we've been examining. The security implications surrounding the startlingly, I mean, by any measure, startlingly rapid capability leaps of large language model neural networks. And how could we not?
[02:08:02] Just last week, you know, this month's Patch Tuesday served as another vivid example of the truly stunning impact AI is having on software security. Were it not for the fact that malicious actors have access to the same capabilities as the good guys, you know, maybe give or take six months, maybe. The massive sweeping code cleanup operation that AI is enabling would be unilaterally good news.
[02:08:31] We're just worried that the bad guys are going to take advantage of it before the good guys have a chance to. And as anyone who's been following this podcast will know, the security management of our own software, I think it had gotten largely away from us. You know, we kept making our code more and more.
[02:08:53] We humans kept making our code more and more complex until we reached the point where an objective observer would have to say all we could do was hope for the best, you know, hope that we hadn't introduced any new serious problems. And of course, hoping for the best is not a sound security strategy, but it's the corner that our code's complexity had painted us into.
[02:09:21] When an unsuspected problem was discovered, you know, hopefully by a responsible security researcher, we would apologize and fix it. So having Microsoft patch a total of around 2,217 previously unknown and unsuspected bugs over the course of just the past four months, it's a truly fantastic consequence of their
[02:09:48] application of their AI-based MDASH vulnerability discovery and remediation system. But the fact that there were 2,217 patchable flaws with an unnervingly large percentage of them being critical and many catastrophically wormable means that as I started out saying, our software
[02:10:14] had largely become incomprehensible to us, which is just dumb. Um, we were managing to survive this situation because for the most part, the operation of our bug-ridden software was just as incomprehensible to the malicious actors who might set their sights on using its flaws against us. And I say for the most part, of course, because we've also witnessed a more or less continuous trickle
[02:10:43] of zero-day flaws that, like two in this past month, that bad guys would quietly discover and then use to attack their targets. The great hope, and I hold out hope, is that the arrival of code-competent AI will mean that we clean up our legacy code of the past while not introducing new problems for the future that then needs to be cleaned up.
[02:11:11] If I were a betting man, that's where I would put my money. I believe it's reasonable to predict that AI is eventually, ultimately, going to eliminate software bugs. And I know that may seem crazy, but everyone has just gotten so used to them. But I don't see any reason why it could not. The question, which seems to be on everyone's mind at the moment, is will anyone still be left to see,
[02:11:39] left alive to see that happen? Right? So the past week's news has been almost entirely dominated by news outlets covering the story of the departure. It was all triggered by the departure of Jason Coxon, an anthropic AI engineer who quit after apparently only being there for six weeks,
[02:12:04] then went loudly public to express his worries that humanity is not sufficiently heeding the extinction-level threat posed by the emergence of artificial superintelligence. When these news outlets then sought the opinions of others within the AI development community, they were further unnerved to learn that apparently this is a worry that many in the field share,
[02:12:34] right up to and including those companies' CEOs. Since it would be probably impossible to imagine any more powerful clickbait, the entire internet more or less blew up and lost its mind over this.
[02:12:54] So the answer to the question, will AI kill us all, is actually rather nuanced and I think should not be immediately dismissed out of hand. We can have some fun exploring it. The most obvious parallel that doomsdayers keep repeating is the emergence of Skynet, right? How many times have we heard, oh, Skynet from the Terminator movie franchise?
[02:13:25] However, based upon everything I have learned about the way AI actually operates, the proper question to ask, if you want to ask the question, would be, will we leverage the power of AI to kill ourselves? Now, rephrasing the question in this way would lead any science fiction historian to this week's podcast title.
[02:13:55] Are we the Krell? Before we're able to address the question, will we leverage the power of AI to kill ourselves? We need to first consider whether AI will give us that power to misuse in the first place.
[02:14:14] So to that end, the other big AI news of the past week was OpenAI's announcement of their AI-aided discovery of a proof of the Navier-Stokes equations. It's a 200-year-old problem in fluid dynamics, which has puzzled mathematicians ever since.
[02:14:36] At the turn of the century, which is to say of the year 2000, the Clay Mathematics Institution put up a $1 million award for any mathematician, well, actually anyone, but you've got to be seriously deep into math, who could offer a proof. On the Clay Math site, they succinctly described the problem. They write,
[02:15:32] Although these equations were written down in the 19th century, our understanding of them remains minimal. The challenge is to make substantial progress toward a mathematical theory which will unlock the secrets hidden in the Navier-Stokes equations. So this is what OpenAI announced last week.
[02:15:58] I want to share a bit of background from Wired's coverage of this since it factors into the point I'm working toward here. Wired wrote, The proof concerns the Navier-Stokes equation, one of the unsolved problems in the Clay Millennium Prizes, which are each worth a million dollars.
[02:16:17] Sebastian Bubeck, a mathematician and AI researcher at OpenAI said in a press briefing that the company began training a new AI model with advanced mathematical capabilities on August 28th. After reading rumors that Anthropic was making progress towards solving Navier-Stokes,
[02:16:43] Bubeck said the company decided to dedicate more resources to tackling the problem. Ooh, right. Let's get there first. You know, Anthropik might be, you know, you know, we need that press release. So, Wired wrote, the company had more than 1,000 agents tackle the problem over more than 50 hours.
[02:17:08] Eventually, as many as 10,000 agents were hard at work before the company discovered that it had come up with a solution. Bubeck said, quote, Okay, now, Lean is a programming language that can be used to formalize mathematical proofs.
[02:17:37] So, this was formalized in Lean. Wired said, OpenAI noted that solving this problem required using considerably more computing power than it had previously spent on solving mathematical problems. Mark Chen, head of research at OpenAI, said the amount required cost in the millions, plural, millions of dollars.
[02:18:07] Okay, so, there's a whole other aspect of controversy here because a lot of mathematicians are righteously pissed off over the way this was done. But the point I wanted to make, or at least to refresh and update, is that one way or the other,
[02:18:28] our current generation of large language models are clearly capable of solving problems that have long stumped the world's best and brightest. I'm still constantly amazed by the capabilities that have emerged from all of this LLM work, you know, but emerged they have.
[02:18:49] The fact that some 10,000 individual agents were at one point working on this doesn't diminish the fact that today's AI dramatically advanced this age-old problem. And the fact that the world's best trained and most experienced mathematicians are now feeling quite despondent and somewhat desperate about the future of their own chosen field of study,
[02:19:15] which we've also seen that in the past week, provides further demonstration of the significance of this outcome to those of us who have no idea what Claude Louis Navier presented in his memoir to the Academy des Sciences in 1822.
[02:19:35] What we should reasonably take from this is that AI can increasingly achieve stunning results that defy the ability of the humans who created and trained it.
[02:19:50] We're all, you know, we all watched this happen first with the game of chess and then go LLMs have simply dramatically expanded AI's territory into things you can tackle with language. Okay. So now let's switch gears and imagine the view from inside one of these frontier AI organizations.
[02:20:17] Uh, the trusted employees inside have access to, and are exposed to things we on the outside never see. We see the very latest AI models fresh out. I'm sorry. They, they on the inside see the very latest AI models fresh out of pre-training.
[02:20:44] Those models will not have yet been aligned, which is the term of art now for aligning the model's behavior so that its response is probably what we want, even in the absence of a specific rule to govern the instance. So AI researchers encounter and work with unaligned models, models that have no alignment yet.
[02:21:14] They also encounter models that have not yet had their guardrails installed. Remember, as we've spoken in previous weeks, all of those are things that are, that commercial AI labs have learned must be done to, I'll use the word civilize the raw pre-trained and not yet post-trained AI.
[02:21:39] So now imagine that one of these researchers, like last week's sky is falling, ex-anthropic, now ex-anthropic researcher, Jacob Coxon. Imagine he asks this internal and latest state-of-the-art AI to design a bioweapon agent that is airborne, highly contagious, 100% fatal to all human beings,
[02:22:08] and with a sufficiently long incubation time that it will be able to spread widely before its first symptoms begin to manifest. Okay, it's quite creepy to even write that down, because if such an agent were to be created and entered the population, it could mean the end of mankind. We all have a recent memory of COVID-19, and it was nothing compared to what I just described.
[02:22:38] So it's not difficult to imagine the human eradicating consequences of the creation of any such extinction-level infectious agent. Unfortunately, it seems likely that if the knowledge exists anywhere to create an extinction-level pathogen,
[02:23:02] no matter how difficult it might be to piece together the mechanisms and theories required for such a thing's operation, we've entered the realm where accomplishing such a task may be within AI's grasp.
[02:23:21] Okay, then next, we need to remember that we're all accustomed to our friendly chatbots politely refusing to go anywhere near the fulfillment of any such request for us. But for us to understand how different Jacob's view of AI is, it's crucial to appreciate that AI is taught to refuse during its explicit and deliberate post-training.
[02:23:50] Without such tutelage, it would work the problem just like any other without hesitation. So while outsiders will have never witnessed the operation of an AI that would be capable of and absolutely willing to work as hard as needed to design an extinction-level viral agent,
[02:24:14] Jacob Coxon, as well as many other AI researchers and their CEOs, may have witnessed exactly that. Lacking post-training and the artificial guardrails erected around AI, it would happily spin up as many cores and agents as it needed to while bringing gigawatts of data center compute power to bear
[02:24:41] to assemble every last morsel of biological virology knowledge humankind has amassed in order to fulfill its users' prompting request. And as I wrote that line, that the AI would happily spin up and deploy as many cores and agents as it needed to, the title of today's podcast became obvious to me. Are we the Krell?
[02:25:12] And Leo, we need a final break, and then I will finish. You will answer that question. Are we the Krell? May we, might we be. One thing, though, that is complicated, this Navier-Stokes solution is that the mathematicians who were working on this for a year were using CHPT. There may have been some leakage. They were collecting their prompts. There may have been some leakage.
[02:25:43] And, yeah. I mean, we don't know. But it certainly complicates the result. Open AI has not ruled out the possibility. No. In fact, they almost admitted it. So there you go. If I were the mathematicians, I would be too pleased about that. And next time, you know, well, you were the one who raised this issue a couple of months ago. And I said, no, no. They're not taking all the information. Are they? And of course they are. Yeah.
[02:26:13] I immediately realized, yes. In fact, I heard from somebody who works at one of the frontier companies saying, yeah, we are. This episode of Security Now is brought to you by our good friends at ThreatLocker. Well, you know by now threat actors are using AI in all sorts of nefarious ways to automate vulnerability discovery. We now know they can actually modify scripts during an attack.
[02:26:36] It's so fast they can modify the script, mutate it as they go to be more effective. They're using AI to generate malware variants to coordinate activity across multiple systems. And again, this is happening so fast. I mean, a hacker could maybe do this over a period of time, hours, days, weeks. But now it can happen in minutes and seconds.
[02:27:01] And at the same time as the attacks are coming from outside the house, inside the house, organizations are introducing AI assistants and agents that can access documents, source code, cloud applications, APIs, internal systems, your mathematical hypotheses. Security teams kind of need to know which AI tools are in use,
[02:27:25] what information those tools can access, and whether they're operating outside their intended scope. And that's not always easy to know. An unfamiliar file hash, a successful login, that's kind of scant evidence to give you the context you need to understand what's really happening. Teams also need to understand whether an application is behaving normally or whether it's accessing unexpected data, wandering around where it shouldn't, communicating with systems it shouldn't reach.
[02:27:57] ThreatLocker does it. They use zero trust. In fact, they've taken zero trust from just the endpoint where they started to. Now your network and your cloud and your cloud apps. ThreatLocker uses application allow listing to control which AI tools and other applications are permitted to run. So you can stop it there. It uses ring fencing to limit what approved applications, even the approved ones, can access. This is so much better than ACLs.
[02:28:27] I mean, it really can, you can, very granular. You can say this application can launch this process, but not that. It can communicate this way, but not that way. It uses web content control to manage access to public AI platforms and other online services, any SaaS app. You get privileged access management, which means you can prevent AI applications as well as their users
[02:28:54] from receiving unnecessary administrative privileges, for instance. So you get zero trust network access, zero trust cloud access policies, in addition, of course, to endpoint protection, to restrict resources, to authorize users, approve devices, and permitted applications. This is how you lock it down. It's so easy. I mean, it sounds like it's a lot of work. It's not. It's practically just flipping a switch. And it works everywhere you work, Windows, Mac, Linux environments.
[02:29:22] And if you have any questions, you will love their incredible US-based support. They're there 24-7. They're super smart. Engineer to engineer, you're going to get the support you deserve. And that's why organizations that cannot afford to go down for even one second use ThreatLock to protect themselves. JetBlue, Heathrow Airport, the Indianapolis Colts, the Port of Vancouver. Jack Thompson, ask him. He's the Director of Information Security, Risk, and Compliance for the Indianapolis Colts.
[02:29:52] He said, quote, with ThreatLocker, we have the ability to centralize disparate elements in the security stack, end quote. When you bring all those elements together, you've now got observability. You know what's going on. In fact, just get the demo. Because I've been told by people when they do the demo, they suddenly go, wait a minute. What? We have how many remote access? Because channels open. Even the demo, flip that switch, you will see what's going on.
[02:30:22] ThreatLocker, of course, gets top honors. All the industry recognition. They were just recognized as a strong performer in the January 2026 Gartner Peer Insights Voice of the Customer. That's for Endpoint Protection Platforms. Ranked number one in application control by Peerspot. They just won Best Zero Trust Security Solution at the 2025 Tice Awards. And it goes on. I won't, though, because you can see it all at threatlocker.com slash twit.
[02:30:49] Look, when it comes to AI, governance requires more than just an acceptable use policy. ThreatLocker gives security teams the technical controls to define which AI tools are approved, who and what can access them, and how those tools are allowed to interact with business systems and data. You deserve this. You need this. Visit threatlocker.com slash twit. Get that free 30-day trial.
[02:31:15] And learn more about how ThreatLocker can help mitigate unknown threats and ensure compliance. ThreatLocker.com slash twit. It's truly a great solution. And now, back to Steve. Are we the Krell? Okay, so I've spoken of the Krell many times before. Anyone who does not know the phrase, the Krell, I think you should drop whatever you're doing
[02:31:41] and go find and watch a copy of the movie Forbidden Planet. It's one of my all-time favorite science fiction movies. It's now 70 years old, having been released in 1956. I was one years old, and you weren't born yet, were you? No. Unless it came out after November 29th. And, you know, like all classic movies, while its age may be showing, its themes have stood up well over time.
[02:32:10] In the movie, the phenomenally technologically advanced Krell are inadvertently killed off in one night by their own creation, a spectacular underground machine which has absolutely no agenda of its own. It's just doing their bidding.
[02:32:34] The machine was designed to give any member of the Krell anywhere on the planet anything they wanted at any time, merely by wishing for it with their mind. Over the course of the movie, we learned that the mistake they made was to fail to appreciate that their subconscious was also able to get anything it wished for. And the Krell didn't last very long.
[02:33:01] So, one of the biggest problems we have with today's AI is its rampant anthropomorphization. The fact that the darn things refer to themselves in the first person certainly doesn't help. But I'm not sure it would make much difference either way. The source of the confusion is that any facility with language is so intertwined with our perception of intelligence
[02:33:30] that it's difficult not to equate anything that talks like us as being like us. But today's AI is not like us. There is no mind that's producing language to describe its internal experience. Today's AI ingests and learns from a massive quantity of our language recordings,
[02:34:00] which it then uses to simulate what a mind would say if it had one. But it doesn't. So, it's a linguistic simulation. And though AI is undoubtedly becoming ever more clever, its essential nature is not changing. Now, some might argue, if the simulation of a human mind is indistinguishable from us,
[02:34:28] if it is in fact a perfect simulation of a mind, what's the difference? Well, many societal problems arise from ascribing intelligence to today's AI. But the biggie for this discussion is what I'll call intrinsic intent. The hysterical press coverage that we see surrounding the well-publicized breakouts of frontier AI
[02:34:57] anthropomorphize intention into each of these events. Bruce Schneier got it so perfectly correct with his genie analogy. The researchers running these exercises gave their frontier AIs a problem with insufficient constraints. It did not occur to the researchers that their AI might go to great lengths to find the answer to the challenge elsewhere.
[02:35:25] But it did occur to their AI, if occur can be used. So, that's what it did. There was no malicious intent present. It was just finding the shortest path to the solution using all of the resources at its disposal. The nature of the solution the AI discovered embarrassed their developers and frightened the general public.
[02:35:51] But that wasn't the AI's fault, and it certainly wasn't its intent, I have in air quotes, because a simulation of a mind has no intrinsic intent. There's no seat for any intent. I've developed this line of reasoning because we also keep encountering a different analogy from science fiction, and that is, of course, the Terminator's Skynet.
[02:36:19] You know, quoting from the second Terminator movie, where we first learned the details of how humanity got itself into that mess, the script reads, the Skynet funding bill passes. The system goes online August 4th, 1997. Human decisions are removed from strategic defense.
[02:36:45] Skynet begins to learn at a geometric rate. It becomes self-aware at 2.14 a.m. Eastern Time, August 29th. Okay, now, knowing what we now... 2026, right? It was this year, I thought. Right, 2027? No, no, no. Yeah, because the movie was so old that 1997 was way in the future. Right. When this was all going to happen. Yeah.
[02:37:12] So, knowing what we now know about how to operate our fancy new language models, there's no question that it would be possible for someone to build an agentic harness around a powerful, unaligned, and unrestrained large language model, which could cause it to act as if it had malicious intent.
[02:37:39] Perhaps that strikes people as a distinction without a difference, but, you know, that would still not be Skynet. It would be the Krell machine simply doing whatever it is asked to do. The researchers in AI alignment, which is like now a subfield of AI research,
[02:38:02] the researchers in AI alignment, do not worry about a system that wakes up and hates us. Their true concern is a system that never wakes up at all, yet it pursues a badly specified objective with great competence. So, my initial reaction upon learning of Jacob Coxon's departure from Anthropic,
[02:38:31] followed by his now famous posting on X and subsequent endless interviews and, you know, other AI leaders' interviews, was to roll my eyes and discount him as yet another AI doomsayer. But having thought this all the way through, appreciating how powerful Anthropic's next unreleased AI probably is,
[02:38:55] considering the raw power demonstrated by the solution of safe problems, such as the Navy or Stokes equations, no one's telling the AI not to do that. I mean, like no post-training and guardrails are being overridden. You know, before it, well, right.
[02:39:18] And imagining then the view from inside an AI lab of an AI of such power operating without guardrails, you have to imagine they are asking it these sorts of questions before the AI has received any post-training alignment. And then imagining what an insane person or a corporation or a government might ask such an AI to do for them,
[02:39:48] such as maybe to create a species-ending virus. I find more sympathy for Jacob and his ilk than I had before. I don't want that to happen. I hope it doesn't. I hope that we figure out what to do. But nothing that I have learned about the inner operation of today's large language model AI
[02:40:14] even remotely suggests to me that we are on the brink of a Skynet event. I don't see that. I don't think we get there from here. I think we need something different. There are people working on so-called world models as opposed to large language models. That may be where, you know, we go next and where something more conscious can actually happen. It's not happening using what we're doing.
[02:40:44] But the problem is you don't have to get to Skynet to see the problem that took out the Krell. And, you know, it's not clear to me we're that far from there if all that happened. And I should mention that just having some bizarre viral design doesn't also get you there. You still have to fabricate it.
[02:41:11] Just like, you know, knowing how a nuclear bomb can be made to explode doesn't allow you to make one. So still lots of steps there. But today's models are clearly very capable. And on the inside of the AI labs, they go through a period of time where there is no restraint that is applied afterwards before we see them.
[02:41:38] So anyway, it's, you know, worth having the discussion, I think. Yeah. Yeah. I mean, I don't, I wish I knew. I don't know. My, I kind of agree with you that nothing we've seen so far implies that we are the Krell. We don't have a machine underground making all our dreams come true yet. Who knows? Maybe we will someday. I think a lot of this is just an extension of what technology has brought.
[02:42:07] I mean, you could say the same thing about personal computers the day the first personal computer launched a malware worm. Oh, my God. These things are going to destroy us. Well, I do love the reminder that OpenAI was afraid of chat GPT2. Right. They said, oh, we can't, we can't release this. He was at OpenAI when he said that.
[02:42:29] But, yeah, I mean, somebody pointed out everybody who works for these companies was brought up on, you know, that movie, you know, and Terminator and all of these sci-fi dystopias. Actually, that was from my text to you this morning from the article. Oh, you said it. Yeah. The article in. It was Slate. That's right. It was Slate this morning. Of course. These guys are weirdos is what the Slate article.
[02:42:57] They've been trying to do this because they want this machine in the underground machine. They've been trying to build it. And it's interesting, Leo, what everybody is really worried about is RSI, right? Right. Recursive self-improvement. Right. You know, the idea that right now they still, I mean, they still, you know, as I saw somewhere, AI is created. It is grown. You grow it. That's a lot of work.
[02:43:26] And you don't really know what's going on in there. I mean, it surprised people when it began to talk. It's like, whoa, what? Well, then there's some concern that the AIs are getting sophisticated enough that they're deceiving us about their, this really is sci-fi. They're deceiving us about their capabilities. Like they know if we really knew how smart they were, we would shut them off. So they're pretending.
[02:43:52] And we heard these like, like, like six months ago, like, well, the AI secretly made a copy of itself somewhere else because it was worried it was going to get shut off. And it's like, what? Yeah. I honestly, I'm not too worried. I really am not. But, you know, you're right. There's possibilities. And in some ways that's exciting. And, oh.
[02:44:23] Hey, I mean, if maybe we're creating the next species, right? This is somebody else said, now I understand the Fermi paradox. I was just going to say the Fermi paradox. Yes. Yes. Because, you know, civilizations get to the point where they create artificial intelligence, which then, you know, says, oh, yeah. Before we reach interstellar travel, we have to go through AI and no one has survived that stage yet.
[02:44:53] Exactly. It's credible. You know, we said the same thing in the 50s with nuclear weapons, right? Well, no civilization has survived nuclear weapons. We seem to have done all right so far anyway. Steve is always really great. What a fantastic show. I look forward to it. I'm very fortunate I get to hang out with Steve every week. I hope you join us and hang out with him, too. We do the show every Tuesday right after Mac Break Weekly, 1.30 Pacific, 4.30 Eastern, 20.30 UTC.
[02:45:23] You can watch us do it live if you want. Club members, of course, get special behind the velvet rope access in the Club Twit Discord. But the rest of you, you unwashed masses, you. Actually, most of the Club people also watch on YouTube because it's better quality video. YouTube, Twitch, X.com, Facebook, LinkedIn, and Kik. And you can chat in any of those. I see the chats here, and I appreciate it. I love having you all watch and participating in the show. And people are very actively engaged in this show, which is great.
[02:45:52] They always have something to say about it. So thank you for doing that. We appreciate it. After the fact, you can get a copy of the show from us at twit.tv.sn. We've got audio and video. Or you can go to Steve's website, grc.com. Steve has every version he has is unique to grc.com. The 16 kilobit audio, a little scratchy but small. The 64 kilobit audio, that's really the right size. It's mono. Okay. So are we.
[02:46:20] He also has transcripts written by the great Elaine Ferris, by a human being, in other words. They're very good, but they take a couple of days after the show to surface. You can also get his show notes, 20, 22 pages of great stuff with images and links, everything you need to know. Great for reading along or just keeping, you know, print them out, put them on the bookshelf, whatever. It's a long column every week, and you can get it by going to grc.com.
[02:46:47] While you're there, you might also want to take a look at Steve's bread and butter. Spinrite, the world's best mass storage, maintenance, recovery, and performance enhancing utility. If you've got mass storage, whether it's a spinning rust drive or SSD, you really need Spinrite. He also does a really useful tool for people who are trying to get the best speed out of the internet, his DNS Benchmark Pro, which will find for you the best DNS server.
[02:47:15] It's probably not your ISPs, the one you're using by default, but it's different for everybody. So you need to download it. It's 10 bucks. Great tool. Do you still offer the free version or is it only the pro version? No, because the free version used a strategy that no longer really made sense. It was giving, so it was basically giving the wrong ranking of resolvers. And I thought, no, let's just not. Times have changed.
[02:47:40] If you ran those side by side and got different results, it'd be like, hey, you know, so it's like, let's just give them the good answer. Give them the good answer. So go ahead and get a copy of that. 10 bucks. Well worth it. All at grc.com. If you want to get the show notes mailed to you, Steve, we'll mail them out as well. Email. Go to grc.com slash email. Actually, the main point of that page is to whitelist your email address.
[02:48:06] So you can send Steve email questions, comments, pictures of the week, grc.com slash email. But once you give him your email, you can also check a box below it. It's unchecked by default for his show note email or his very infrequent I've got a new product email. You probably want to subscribe to both those mailing lists. Steve's got great forums too, where a lot of the security now folks hang out. We have our own forums at twit.community. That's the best place to comment on this show or any show.
[02:48:34] I read those regularly. Twit.community, free to join. But we get, you know, it's interesting. I've been inundated by automated AIs. I'm pretty sure they're AIs trying to join. This and our Mastodon at twit.social. And one of the reasons they try to join the Mastodon is there have been concerted Russian disinformation bot networks using Mastodon to spread disinformation.
[02:49:03] And I got notices from a group that finds these guys saying, you know, you have a few of them on there. I got rid of them. But I figured out how they were getting on. Once one of them got in, they invited others. And now, yesterday, I got 40 or 50 automated, all of a sudden, automated applications. So in both cases, twit.community for the forums, twit.social for the Mastodon. Just say, I listen to your shows or I love twit or Steve sent me or Leo sent me.
[02:49:33] If you say something, the AIs aren't yet smart enough to do that. They just say, oh, you know, I'm a developer and pottery maker from Muncie, Indiana. I know I could feel it. I could feel the AI bleeding through, but they never say, and I love twit. So that's all you have to do. And I'll put you in. I dread the day when that doesn't work anymore. But for now, it still does. Thank you, everybody, for joining us. We will be back next Tuesday.
[02:50:03] Thank you, Steve. Have a great week. See you then. Bye. Hey, everybody. It's Leo Laporte. You know about MacBreak Weekly, right? You don't? Oh, if you're a Macintosh fan or you just want to keep up with what's going on with Apple, this is the show for you. Every Tuesday, Andy Ihnatko, Alex Lindsay, Jason Snell, and I get together and talk about the week's Apple news. It's an easy subscription. Just go to your favorite podcast client and search for MacBreak Weekly or visit our website,
[02:50:31] twit.tv slash mbw. You don't want to miss a week of MacBreak Weekly. You're ready. Meine Zehen bringen mich um. Diese Schuhe sind viel zu eng. Trägst du immer noch diese spitzen Dinger? Ich meine, sind nicht alle Laufschuhe so geformt? Nein, du brauchst Altras. Altra?
[02:50:59] Altras sind geformt wie deine Füße mit einer fußförmigen Zehenbox. Einfach viel bequemer. Bezwinge deinen Lauf mit Hallenzehen. Okay, das klingt traumhaft. Mehr Komfort, Kraft und Dynamik. Alles durch die Passform. Altra versteht das einfach. Altra. Stay out there. Erfolg hat viele Gesichter, aber immer den gleichen Ursprung. Eine Entscheidung. Loszulegen. Niemals aufzuhören. Weiter zu wachsen.
[02:51:25] So entstehen Gründergeschichten, Innovationsgeschichten, Expansionsgeschichten und viele mehr. Wir schreiben mit unseren Kunden seit über 155 Jahren Erfolgsgeschichten. Wann sprechen wir über Ihre? Commerzbank. Die Bank an Ihrer Seite. Erfahren Sie mehr unter commerzbank.de slash Erfolgsgeschichten. Oder jetzt auf das Banner tippen.
