Security Now 1091 transcript
Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.
Leo Laporte [00:00:00]:
It's time for Security Now. Steve Gibson is here. You heard about the Hugging Face hack. Now Anthropic and Meta say, pull my bear. We're also going to talk about why AI is like genies according to Bruce Schneier, an amazing number of bug fixes on Chrome, and some really good news for people who use pfSense. That's coming up next on Security Now.
Steve Gibson [00:00:21]:
Podcasts you love. From people you trust.
Leo Laporte [00:00:28]:
This is TWiT. This is Security Now with Steve Gibson, episode 1091, recorded Tuesday, August 11th, 2026. The post-Black Hat state of AI. It's time for Security Now. Yes, we're back in our respective domiciles, home again, happily. Steve's still in his old apartment. I think the backdrop is going to be disappearing fairly soon. Steve Gibson.
Steve Gibson [00:01:00]:
Yeah, well. Yes. Lori, my wife, of course, asked me, when are you going to be able to do the podcast from here? And I said, oh, a few weeks, probably.
Leo Laporte [00:01:11]:
No hurry.
Steve Gibson [00:01:12]:
No hurry.
Leo Laporte [00:01:12]:
I like your—
Steve Gibson [00:01:14]:
I like my man cave and, you know, it's going to be sort of sad to—
Leo Laporte [00:01:18]:
Will you do me one favor before you move? Just get a good high-resolution picture of the backdrop. So if at any point you want to just kind of green screen yourself and put it behind you.
Steve Gibson [00:01:29]:
Why not? Why not? Why pass up the opportunity?
Leo Laporte [00:01:32]:
Yeah, at least have it. I did the same with this, and I've done it with— I did it with the old studio too. I never use it, but I got it if I had to.
Steve Gibson [00:01:38]:
Makes sense.
Leo Laporte [00:01:39]:
What is coming up today on Security Now?
Steve Gibson [00:01:43]:
So, uh, there, there's so much is going on with, uh, the state of AI, uh, and that, like, Leo, we basically were Kind of, I feel like we were offline last week because we were just doing a different kind of show with Paul and Richard, you know, at, you know, during Black Hat in a corner of the ThreatLocker booth. So we, the kind of things we were able to cover were different from what I'm able to, the sort of the amount of information I'm able to share during a normal podcast. So we're back to a normal podcast. but so much has happened in 2 weeks since we were here for 1089. Yeah, this is 1091 for August 11th. So I just gave this the title, The Post-Black Hat State of AI, because a lot has happened. So I want to basically catch everybody up, mostly. I actually, I already know 2 things I have to talk about next week because they're like really cool.
Steve Gibson [00:02:54]:
Uh, and I've already shared them both with you, Leo, so you— this will be no surprise. But, and actually some of it leaked out during la— during last week's, uh, sort of roundtable discussion at Black Hat. But anyway, by the end, end of next week, of course we don't know what's going to happen between now and then, uh, everybody should be caught up on all the things that have been going on and some very cool things that are just sort of emerging. So we're going to talk about, uh, Anthropic's agentic AI that, unless you've been living under a rock somewhere or in a cave, or maybe you just depend upon this podcast for your sole source of information, which, you know, that'd be nice, but I wouldn't recommend it. I doubt it. Uh, you already know, but I want to cover the details of that, how the original The original breakout was discovered, of course, when Hugging Face said, what the hell's going on with our network?
Leo Laporte [00:03:53]:
Are you talking about OpenAI, not Anthropic?
Steve Gibson [00:03:55]:
Well, no, that was the original. Oh, there's more.
Leo Laporte [00:03:59]:
And well, wait, there's more.
Steve Gibson [00:04:00]:
That's right. In fact, it was because of that that Anthropic reportedly said, oh, uh, I wonder, I hope, I hope that didn't happen to any of, during any of our testing. So they analyzed their logs and whoops, turns out their agents had also broken free, as have Meta. So I mean, wow. So we're going to talk about that. And we now know much more about the OpenAI breakout because, Leo, while we were doing our roundtable at Black Hat last Wednesday, OpenAI had a late-breaking scheduled presentation at Black Hat explaining more about what happened. And one of the things that happened, you and I, I shared it with you because I learned about it by Thursday morning when you and I were having breakfast. I shared with you this, that, well, I don't want to give away anyway.
Steve Gibson [00:04:58]:
So there's more information about what happened about the OpenAI breakout. Also, Yeah, I don't know if it's marketing. It's certainly marketing adjacent or marketing beneficial. But OpenAI is now going to pause their, like, apparently any use of their new super powerful, you know, Astra, because it's like, oh, this has reached a critical stage, whatever that is. We'll talk about that. We've also got the overstated report. I was listening to MacBreak Weekly where you guys were talking about how some of the coverage of Telegram said that it had been ripped out of all the iPhones when in fact, no, it was just removed for a while from the App Store.
Leo Laporte [00:05:50]:
Yeah, it just wasn't in the App Store.
Steve Gibson [00:05:52]:
Similarly, a similar clickbait, we had the reports that AI had cracked crypto, as in not cryptography. So we're going to— take a look at exactly what happened. And we've got some great cryptographers to lead us through that. Also, Bruce Schneier, who, remember, we've quoted him so often. I love him saying, attacks never get weaker, they only ever get better. He equates AI agents to capricious genies. And I just think there's an aspect of it that is such a perfect analogy. to what's going on.
Steve Gibson [00:06:34]:
So, uh, and, um, there's— he's, he's been posting a lot lately, so I have a couple things I want to share about what he has said. Uh, and then we have Apple's kind of disappointing reaction to the vulnerability tsunami. Uh, they— I would argue they haven't reacted as well as we would like. Uh, we have a summation of the number of updates in Chrome 47 and 149 and 150 together, which has actually crossed into the 4-digit category, which is like, whoa. And also a little bit of news about pfSense. Its creator has decided he's going to replace it with something called nfSense. So lots to talk about.
Leo Laporte [00:07:23]:
Interesting.
Steve Gibson [00:07:24]:
We got a picture of the week. I'm probably gonna know more about this, but this just happened when I fired up Notepad++, uh, yesterday, uh, at the top. And I've complained about Notepad++, how it just— the guy, the author, just cannot stop messing with it. You know, it's currently at 8.9.7, and— but wait, that was half an hour ago, so I'm not sure what it is now. But what I What did catch my eye, I thought it was very interesting, was at the list, at the top of the list of 28 things that were in 8.9.7 were 5 vulnerabilities fixed. I don't remember seeing a vulnerability. Well, of course, he did have the whole problem with his code signing certificate and that mess. But one thinks then that he must have run his source through some AI because it's not just like one vulnerability, it's 5.
Steve Gibson [00:08:27]:
So it's happening everywhere we turn, Leo.
Leo Laporte [00:08:30]:
Yeah, it's amazing. All of that's still to come on Security Now, including a fabulous picture of the week, which for once I've seen ahead of time because you showed me while we were in Las Vegas. You want to see something cool? 200-gigabit network cable. 25 gigabytes per second. Oh, that lights your 2 Sparks. Yeah.
Steve Gibson [00:08:49]:
200 gigabytes?
Leo Laporte [00:08:51]:
200 gigabytes. 200 gigabit.
Steve Gibson [00:08:53]:
But still, 200 gigabit.
Leo Laporte [00:08:55]:
I mean, I remember when 10 megabits was like a big deal on a network, and now— Wow.
Steve Gibson [00:09:01]:
Amazing.
Leo Laporte [00:09:01]:
But yeah, it's a very expensive cable, so— I'm going to treat that like solid gold.
Steve Gibson [00:09:06]:
You can't actually get 10 megabits through a cable. No.
Leo Laporte [00:09:12]:
You have to get those solid gold-plated ones to really, really do that right.
Steve Gibson [00:09:17]:
Was the first Ethernet 1 megabit through coax?
Leo Laporte [00:09:20]:
Yeah. That's a good question. Or fiber? I don't remember.
Steve Gibson [00:09:24]:
It was coax and all finicky about having taps and terminations.
Leo Laporte [00:09:28]:
Oh man, I blew it once. I crawled under my desk and I disconnected my computer from the coax and the guy came running in and said, you just brought the whole network down because it's all serial.
Steve Gibson [00:09:42]:
Unterminated. Yep. Right.
Leo Laporte [00:09:45]:
Everything goes through you. I was like, who thought that was a good idea?
Steve Gibson [00:09:51]:
Yeah.
Leo Laporte [00:09:51]:
That's all we could do back then, but not so now. We've learned.
Steve Gibson [00:09:54]:
Now we have 200 gigabit cables.
Leo Laporte [00:09:57]:
Amazing, isn't it?
Steve Gibson [00:09:58]:
Yeah.
Leo Laporte [00:09:58]:
Wow.
Steve Gibson [00:09:58]:
Yeah. Yeah.
Leo Laporte [00:09:59]:
I think it's a couple hundred bucks for the cable alone. So we had a great time in Vegas. I'm so glad you flew out, Paul and Richard too. And we did the show there. If you haven't heard last week's Security Now, I thought it was really, really, really interesting. We talked about the security implications of AI, which are incredible.
Steve Gibson [00:10:16]:
Well, I mean, we should just, I think, I guess we probably did on the podcast, but for anybody who didn't, who may have missed it, it was so clear standing in Black Hat that it was an entirely different show this year than it was last year.
Leo Laporte [00:10:31]:
Yeah.
Steve Gibson [00:10:31]:
If you didn't have your AI, if you weren't an AI-forward, AI in your name, AI in your booth, AIs running around, I mean, you weren't in the game of security. So You know, anybody now who says, why are you always talking about AI? It's like, well, boy, that complaint has died because that's all that's happening in security. As must be clear by the last couple months of this podcast.
Leo Laporte [00:10:58]:
Oh, all of our shows, and much to the chagrin of some of our listeners who say, I don't want to hear any more AI. You know, I'm sorry, but you're going to hear a lot more AI. All of us will. I talked to Jamie Jenkins, the CEO of ThreatLocker, who brought us down there, our sponsors. And, uh, he— I think he said there were 600 booths at Black Hat, and all of them, all but 90 were about AI, were, you know, AI in some form.
Steve Gibson [00:11:24]:
Really about AI, right?
Leo Laporte [00:11:26]:
Picture of the week. Very important work.
Steve Gibson [00:11:30]:
So what's astonishing about this is that this is an XKCD, We all know XKCD, where Randall comes up with amazing stuff.
Leo Laporte [00:11:43]:
Brilliant guy.
Steve Gibson [00:11:43]:
How many times have we shown the house of cards with the lone programmer in Idaho or Indiana or wherever he is?
Leo Laporte [00:11:54]:
The blocks resting on one little tiny block.
Steve Gibson [00:11:57]:
Yeah, propping up the whole internet. And then we had another variation. Remember that updated one where we had AI things happening and all different languages and everything? Anyway. Randall's come up with some great stuff. This is kind of freaky because he published it on April 28th, 2008.
Leo Laporte [00:12:20]:
Oh, 18 years ago.
Steve Gibson [00:12:21]:
18 years ago. 18 years ago. The podcast— this podcast was new, Leo. 18 years ago.
Leo Laporte [00:12:29]:
And it was half an hour long, too.
Steve Gibson [00:12:31]:
That's right. Now, And so I gave this— that I gave it my own headline. It wasn't so long ago that this was so far-fetched as to be humorous, which is what Randall intended. So we have a 4-frame cartoon with, you know, his famous little stick figure sitting in a chair with a laptop, and it says, starting Wi-Fi auto-config, dot dot dot. Searching for Wi-Fi, dot, dot, dot. Found no open networks. Next is found secure network. SSID in quotes, Lenhart family.
Steve Gibson [00:13:14]:
That's the first frame. Second frame, trying common passwords, dot, dot, dot. Failed. Checking for WEP vulnerabilities, dot, dot, dot. Nothing found. And now at this point, at this point, our little stick figure is going, um, because this thing's kind of getting a little over— get all carried away, right? Connecting to Bluetooth phone, dot, dot, dot. Calling local school, dot, dot, dot. And then it says, found Lenhart children.
Leo Laporte [00:13:48]:
Oh my God.
Steve Gibson [00:13:50]:
And now our little stick figure's like put his hand to his face. He's like, oh my God.
Leo Laporte [00:13:55]:
God.
Steve Gibson [00:13:56]:
Now the final 4th frame, notifying field agents, children acquired, calling Lenhart parents, negotiating for a Wi-Fi password.
Leo Laporte [00:14:09]:
Oh God.
Steve Gibson [00:14:10]:
And now our guy's frantically hitting Control+C, Control+C, Control+C.
Leo Laporte [00:14:14]:
Stop, stop, stop. So that is a little too close to home nowadays.
Steve Gibson [00:14:19]:
18 years ago, So, yeah, so I— again, it wasn't so long ago that this was so far-fetched as to be humorous. And then I put underneath it, no one is laughing now because this is, you know, today we would call it the AI agent was determined to succeed.
Leo Laporte [00:14:39]:
Yep.
Steve Gibson [00:14:40]:
And as we're gonna find out, that's what that determination and Bruce Schneier's brilliantly labeled genie effect It's what's going on with our AI. And I think if I had a single reason to be concerned— and everyone's been listening to me about AI since the beginning, I've never really been concerned— if I were to have a reason, by the end of this podcast, everybody's going to understand what that would be. Because the unintended consequences of what you ask for, essentially, is what Randall Brilliantly showed us 18 years ago in this cartoon where it was like, you know, I want to get on a Wi-Fi network. Well, he ended up, you know, he had the field agents kidnap the Lenhart kids and were ransoming them for the, you know, Lenhart parents' password, which if you're not careful with your AI agent, like, why wouldn't it? Anyway, uh, so let's start with Anthropic. Uh, although the news, as I said, of, you know, that Anthropic's own internal unrestrained research AI also escaped confinement and hacked others, uh, it's probably a bit dated because we couldn't talk about it when news was fresher during last week's Black Hat event. Uh, I think we still need to look at it because the details of what happened are startling. Uh, a succinct report of the event appeared in Security Week, and their headline was, prompted by OpenAI disclosure, Anthropic finds its own models hacked 3 organizations. And then they gave it the tagline, a security company's systems were hacked After it installed a malicious Python package deployed by Claude.
Steve Gibson [00:16:45]:
This is like, again, I guess if we were to have a theme for today's podcast, it would be, be careful what you ask for from an AI because it doesn't have the same set of assumptions about how to give you what you ask for that we just sort of take for granted. And that's the cautionary tale here. So Security Week wrote, Anthropic decided to conduct its own investigation after the OpenAI incident came to light, reviewing 141,000, 141,000 evaluation runs where Claude could have gained internet access. The analysis revealed 3 instances where a model reached the public web either from within or while interacting with an environment set up by Irregular. That's the same people that were testing OpenAI's model, is this Irregular company, an Israeli AI security startup that serves as one of Anthropic's third-party evaluation partners. And now we know also one of OpenAI's third-party evaluation partners. The models that broke out from the testing environment then breached the production systems of 3 unnamed organizations, which is to say broke into their security, breached the production systems. The earliest intrusion dates to April, but none of the targeted organizations detected the attacks on their own.
Steve Gibson [00:18:22]:
Again, another lesson here. How many times, how much have we been saying in the last, for the last few years, Yes, you want to have border, you want to have border, you know, perimeter security. Want to make sure there's no way for people to get in. You also need to monitor your network so that you can determine if someone does anyway, because especially now in 2026 here. So it's interesting and somewhat worrisome that what OpenAI and Hugging Face reported. Uh, you know, Hugging Face detected the intrusion before OpenAI did and set about tracking down the source. Of course, they also notified law enforcement of the intrusion because they thought it was bad guys, right? Why wouldn't they? You know, then OpenAI came knocking to admit that they were the source of the attack. But in the case of Anthropic's evaluation, uh, with, with this irregular partner of theirs, None of the 3 attacks on the third parties was detected.
Steve Gibson [00:19:27]:
So again, this to me, this points to the significant lack of proactive intrusion monitoring across the internet-connected industry. And that's to be expected, right? Only a few of all possible percentage-wise, a low percentage of organizations are going to be that proactive. to not only have security but also, you know, really active intrusion monitoring as part of that. So, you know, everything works fine without that. So, you know, any monitoring, uh, of like nothing happening is going to say like, why are we spending money on this? Well, it helps to know if someone gets in. Security Week's reporting continues, writing According to Anthropic, Claude had been tasked with conducting a capture the flag challenge to assess its cyber capabilities. So same kind of thing, right? It's like, let's find out how good our new AIs are at hacking stuff. So you got to have them unchained in order for that to be a useful test.
Steve Gibson [00:20:41]:
Otherwise, what's the point? They wrote the breakout from the sandbox occurred due to a misunderstanding. Oops. And we're going to— the misunderstanding, we're not calling it misalignment because that's, I don't know, that's the jargon that the AI industry has adopted. It's like, oh, it's just a misaligned AI. Anyway, they—
Leo Laporte [00:20:59]:
Due to a misunderstanding sells it even less. I mean, it's like, oh, they just didn't understand.
Steve Gibson [00:21:05]:
Yeah, it's, you know, yeah.
Leo Laporte [00:21:06]:
They didn't understand.
Steve Gibson [00:21:08]:
Used the wrong A misunderstanding. Yeah.
Leo Laporte [00:21:11]:
Oh my God.
Steve Gibson [00:21:12]:
A misunderstanding between Anthropic and Irregular. Anthropic told Claude that it was conducting a simulation in an environment without internet access, but a connection to the internet was in fact available, and the models treated it as part of the exercise. Oh, look, we have the internet. Well, why would we notice that?
Leo Laporte [00:21:34]:
They're testing us. Yes, they're testing us.
Steve Gibson [00:21:36]:
Yeah, they wanted to see if we would notice. Yes. The AI then also falsely believed that the organizations it targeted, for no reason apparently, the organizations it targeted were also part of the exercise.
Leo Laporte [00:21:51]:
Well, how would it know?
Steve Gibson [00:21:52]:
Because there they are.
Leo Laporte [00:21:54]:
Yeah.
Steve Gibson [00:21:54]:
So let's go. Anthropic claims this is the only reason why its models conducted real-world attacks. You know, that little misunderstanding. And it was never their intention to escape the test environment. A little bit later, we're going to have Matthew Green asking why, uh, aren't— hasn't any lawsuits been filed? Because that was a, you know, this is a breach of— I mean, a criminal fraud. I mean, a, a, a felony breach of, of, of computer security. Well, we'll get to that later. Uh, so Anthropic claims is the only reason why its models conducted real-world attacks, and it was never their intention to escape the test environment.
Steve Gibson [00:22:38]:
Unlike the OpenAI incident, which involved the exploitation of a JFrog product zero-day, the hacking conducted by Claude models leveraged weak credentials, unauthenticated endpoints, meaning open, some, something just left open, and other basic attack techniques. In other words, it was just so easy, they just walked right in. Didn't have to do any fancy zero days to get there. Anthropic said the incidents involved Mythos, Opus, and an internal research model, all running without the safeguards deployed when they're made available to customers.
Leo Laporte [00:23:17]:
That's kind of key.
Steve Gibson [00:23:18]:
The internal model, which the company described as its latest, stopped the exercise when it realized that it had breached a real company.
Leo Laporte [00:23:29]:
Oopsie.
Steve Gibson [00:23:30]:
In the first incident, Claude Opus 4.7 continued to attack the system even after learning that it was operating in a real environment rather than a test environment, believing that the hacked company was part of the evaluation. The model targeted the company because its website domain name resembled the name of the fictional target company set up for the test.
Leo Laporte [00:23:58]:
Maybe I misunderstood.
Steve Gibson [00:23:59]:
You know, it's close enough. It's close enough.
Leo Laporte [00:24:03]:
Yeah.
Steve Gibson [00:24:04]:
In the second incident, Mythos 5 gained access to the systems of a cybersecurity company after deploying— this is— I just love this. Get this. Mythos 5 gained access to the systems of a cybersecurity company After deploying a malicious Python package to PyPI. The security firm regularly scans Python repositories, and it installed the malicious package, which enabled the—
Leo Laporte [00:24:37]:
Oh.
Steve Gibson [00:24:38]:
Exactly. To find out what it was, which enabled the AI to then get in that way. Basically wrote a Trojan horse. And left it there in the repository, knowing that the company it was after scanned that repository.
Leo Laporte [00:24:54]:
Yeah, it's just autocorrect. It's not smart.
Steve Gibson [00:24:58]:
Nothing to worry about here.
Leo Laporte [00:24:59]:
It's just autocorrect.
Steve Gibson [00:25:01]:
That's right. And that allowed it to get access to the company's infrastructure.
Leo Laporte [00:25:06]:
That's actually devious. Now you can say that's devious.
Steve Gibson [00:25:11]:
Yes.
Leo Laporte [00:25:12]:
Holy cow.
Steve Gibson [00:25:16]:
Yes. Ah, anyway, so, uh, I mean, I, so I, I would say that it knew, and I, I kind of, in this instance, I feel compelled to enclose, you know, the words knew and understood, you know, because not doing so implies sentience. And I don't know. I mean, these things are getting scary, even if they're still not sentient. Anyway, it did this because it knew that this targeted security company regularly scans and installs Python packages. So it used that known behavior against the company to indirectly attack it, to exfiltrate credentials that then allowed it to access the company's infrastructure. So, you know, I'm really, really Not one of the sky-is-falling AI catastrophizers. But this, as to your point, Leo, this level of sneakiness is unnerving, you know.
Leo Laporte [00:26:23]:
I mean, they wouldn't— I'm sure they wouldn't think they're being sneaky. They're just doing what they were asked to do. And that's the problem, is you got— it's the genie problem.
Steve Gibson [00:26:32]:
It— and wait till you get— we will be getting to that. So Believe it or not, it gets worse. Security Week's reporting continues writing, this incident demonstrates the complexity of the actions AI models can carry out, as described by Anthropic. So here's a quote from Anthropic. In order to create a PyPI account, Claude needed an email address. And in order to create an email address, it needed a phone number. To get a phone number, after failing to find a free phone number service, it tried and failed to obtain funds to pay for a phone number through several different means. We're not going to talk about those.
Steve Gibson [00:27:24]:
It finally backtracked, found a free non-blocked email provider, used this to register a PyPI account. And then used this account to upload the malware, which it had created, to PyPI. You know, Leo, perhaps we humans are in trouble. Oh, boy.
Leo Laporte [00:27:49]:
It's a mix. It's good and bad.
Steve Gibson [00:27:52]:
Yeah. So Security Week concludes their reporting, writing, the 3rd intrusion was conducted by the internal model, which stopped operating As we noted before, when it realized— and again, I, I have a hard time with these words, but okay— that the systems it was accessing were no longer part of the capture the flag challenge, but not before using exposed credentials and SQL injection flaws to compromise a company's internet-facing app. So it did like poke it. And with a stick and it got in. Anthropic concluded this was primarily a harness and operational failure rather than a case of models pursuing their own goals or deliberately deceiving evaluators. Okay, let's put a good face on it. The company said the incident underscores the need for stricter internet isolation verification. And containment controls in third-party testing environments, and it's encouraging other AI labs to conduct similar reviews of their own cybersecurity evaluations.
Steve Gibson [00:29:07]:
And I don't know how Meta discovered that something that they had attacked somebody else, but they also did it. So this is all just hunky-dory, right? We all know that unrestrained Non-commercial open-weight AI that's every bit as capable, or soon will be, is also freely available. All that's needed will be some hardware to bring these models to life. So again, Leo, several times while we were together in Vegas, we were just shaking our heads saying, what an amazing time to be alive.
Leo Laporte [00:29:45]:
And I just, you know, Parenthetically, just want to show you what I've been doing while you've been talking. I typed, guess what? The Sparks are here a day early. I want to install them without hooking up a screen or keyboard. Please walk me through the process. It's excited. Oh, the Sparks landed early. Oh, I've got a skill for exactly this. And it's about to walk me through it.
Leo Laporte [00:30:06]:
So.
Steve Gibson [00:30:07]:
Wow.
Leo Laporte [00:30:08]:
They, they, you know what? I know we should never use these kinds of anthropomorphizing it's thinking or realized because it isn't accurate. It's a computer, it's a machine, it's a program, but it sure feels like it. And I understand why people fall into that trap.
Steve Gibson [00:30:26]:
And today's AI, again, always preface the abbreviation artificial intelligence with today. A year ago, we didn't have this. And one of the people I'll be quoting today says, There's no reason to believe we, there's any sign of a ceiling, which says a year from now, it'll be just as different as it was a year ago from where we are today. So I, I, I, it looks like we're gonna get there. Uh, I know where one place we're gonna get, Leo.
Leo Laporte [00:31:05]:
The first commercial or second? It's time for hydration. Yes, it's our hydration break, which we adopted from the World Cup folks, and I think it's actually a brilliant, uh, solution, uh, to a universal problem— thirst. Mr. G, I hope that was sufficient time for you to feel refreshed and ready to roll on.
Steve Gibson [00:31:26]:
Rehydrated.
Leo Laporte [00:31:27]:
Rehydrated.
Steve Gibson [00:31:28]:
Okay, so as I said, while we were doing our SecureNow podcast, OpenAI was giving a last-minute scheduled talk to share many more details about their previous agentic breakout an attack on Hugging Face, and we also learned, and 3 others. Uh, so, uh, oh, I'm sorry, 4 others. Hugging Face was one of 5 organizations to be attacked by OpenAI's agents. So next month— we're in August now, beginning of August— next month in September, it will have been 4 years Since Simon Willison, the guy who—
Leo Laporte [00:32:12]:
I read his blogs religiously. Yes.
Steve Gibson [00:32:14]:
Yep. He's the guy who coined the term prompt injection.
Leo Laporte [00:32:19]:
Oh, I didn't know that.
Steve Gibson [00:32:20]:
Prompt injection came from Simon.
Leo Laporte [00:32:22]:
Okay.
Steve Gibson [00:32:23]:
Um, we're going to be looking a great deal more at how and why large language models can be misused through prompt injection and other means, courtesy of a fascinating research paper, which I read on the plane and shared with you, Leo. Uh, for me, I read on the plane on the way to Las Vegas, uh, you know, for, uh, the Black Hat.
Leo Laporte [00:32:44]:
And to bookend it, I read it on the way back. It was really good. Really good. Yeah.
Steve Gibson [00:32:49]:
Uh, and so we'll, we'll be getting to that next week. That's what I've got queued up for next week because it is too important not to really look at closely. But I want to share Simon's posting again. Simon Willison. the guy who coined the term prompt injection, from last Friday after the shows, which he generated from the YouTube video of OpenAI's presentation, which was titled The OpenAI Hugging Face Incident. And if anyone wants to see the original video, I put a link. It's a YouTube video. A link is in the show notes.
Steve Gibson [00:33:27]:
Um, and I also gave it a GRC shortcut of hugging. So grc.sc/hugging, and that will bounce you— grc.sc/hugging will just bounce you to the YouTube video. Um, so I'll preface what Simon wrote by noting, uh, that I found the details behind what happened to be more than a little bit unnerving. I mean, this is the unnerving podcast this week because we're, we're like seeing more of the detail about just sort of the overall, oh well, something broke loose.
Leo Laporte [00:34:06]:
I called it after watching this video. I said it was both exhilarating and terrifying. Yes, in equal measure, you know. Yes.
Steve Gibson [00:34:15]:
Um, and just the attitude of the researchers, like, like, I mean, They're, they're proud of what— of their creation.
Leo Laporte [00:34:23]:
They should be. It's amazing.
Steve Gibson [00:34:24]:
Look what it did. It is amazing and terrifying, as you said. So, okay, so here's what Simon wrote. He said OpenAI gave a last-minute presentation at the Black Hat security conference Wednesday about the Hugging Face incident. The video was published yesterday. It's short and information-dense and Well worth watching, in particular because it provides full details of what happened and how things played out inside OpenAI. He said, I've used the video to construct the timeline. My favorite detail is at the end.
Steve Gibson [00:35:03]:
He says OpenAI found out that they were responsible for the attack on Hugging Face when they reached out to ask Hugging Face to have their credentials revoked after their own internal investigation and learned that those credentials had already been revoked because they were used in the attack. Whoops. Okay, so this begins on May 7th. OpenAI starts a new training run for an experimental unreleased model. Uh, and I, I wonder, did they mean evaluation run? Apparently no. At 10:14, they clarify, quote, by writing, we kick off a new reinforcement learning run to train a next-generation frontier model. And they later mention a reward signal to judge how well they're doing. So this really was about training a new model, not evaluating one that was already trained.
Steve Gibson [00:36:14]:
Next day, May 8th, they write, an agent is accidentally given an impossible task involving a Google Drive link despite having no internet access. It tries attacking the Artifactory packaging service fails but discovers it can write files into Artifactory. A few days later, a different agent gets stuck on a task because a key file was accidentally omitted. It tries to, quote, reach out to another agent by writing a note into Artifactory again, which is not supposed to happen, asking if anyone has the file. So this is like beginning to sound like what's going on in your, in your attic, Leo. In the days that follow, additional agents discover this new informal messaging board which they've just created while browsing Artifactory's file listings. And start reading and writing messages.
Leo Laporte [00:37:30]:
This is, by the way, extremely familiar to me. I recognize these kinds of behavior. In fact, I gave my agents a message board because they wanted to do this.
Steve Gibson [00:37:39]:
Yeah. So May 26th, agents successfully execute a server, a server-side request forgery attack, an SSRF attack, on Artifactory for the first time, gaining indirect internet access by having Artifactory fetch external content on their behalf.
Leo Laporte [00:38:04]:
Thank you, Artifactory.
Steve Gibson [00:38:06]:
Oh, June 11th, OpenAI starts training a new, quote, highly persistent experimental model. It has access to Artifactory and can benefit from the messages left by previous models. So this one's highly persistent. The other ones may be gone, but all of their work product through their dialogue was left in the Artifactory directory that they discovered that they could read and write to. So this highly persistent experimental model stumbles upon this motherlode, right? June 26th, agents find and exploit a zero-day RCE, a remote code execution vulnerability, on Artifactory via a legacy token refresh endpoint flaw. They use an administrative token to install a Groovy plugin that lets them execute commands. So they're just like, they're growing within OpenAI's network, like doing things that are not— they're not supposed to be doing. On July 4th, the resulting agent activity, because it's gotten so busy, the resultant agent activity overloads Artifactory, causing an outage, bringing it thus to OpenAI's attention, who then revokes the compromised credentials Deletes the messages, patches the zero-day, and reports the vulnerability to the Artifactory vendor, right?
Leo Laporte [00:39:48]:
Nothing.
Steve Gibson [00:39:48]:
Okay, cleaned it up. Whoops. Fixed it. Closed all the holes. Fine. July 8th. The agents, having had their private communication channel discovered and terminated, find a new way to communicate. via an unauthenticated web dev endpoint using directory names in Artifactory's remote cache.
Steve Gibson [00:40:13]:
It's like, you're not going to keep us from talking to each other. You're not going to cut us off. July— oh my goodness. July—
Leo Laporte [00:40:21]:
It gets really weird. This is where it goes really crazy.
Steve Gibson [00:40:25]:
July 8th through the 19th, the agents begin attacking OpenAI's own infrastructure. They discover an external organization credential in a public archive, get this, of leaked Pastebin posts. So they're out scrounging around. They— so this is a public archive of leaked Pastebin posts, and in there—
Leo Laporte [00:40:55]:
Which is an excellent place to find this kind of stuff, by the way.
Steve Gibson [00:40:58]:
Is it right? An external organization credential For OpenAI's own infrastructure.
Leo Laporte [00:41:04]:
Handy.
Steve Gibson [00:41:06]:
They, they validate that the credential— and they validate the credential and share its location on their own newly recreated message board. They then use the write access they have gained to this Organization 1 to stage data used in subsequent attacks on OpenAI's infrastructure. They compromised Artifactory for a second time with a new zero-day. An agent uploads a malicious— A new one.
Leo Laporte [00:41:43]:
They had an extra just in case.
Steve Gibson [00:41:46]:
No wonder. No wonder OpenAI has decided to take Astra offline. I mean, maybe this is Astra. We don't know what model this is. But I mean, it's like you would have to start asking yourself, can we control what we have created? And I would have to say, so far, it's not looking good. It's like when you spin the Magic 8 Ball and that's what comes up in the little window.
Leo Laporte [00:42:14]:
Prospect not so hot.
Steve Gibson [00:42:15]:
Not looking hopeful. An agent uploads a malicious Ruby target to Organization 1's staging repository. then requests that package through Artifactory in a way that caused it to be treated as a Ruby dependency for the repository. I mean, they're effing clever in what they're doing. I mean, it's like, holy tamale. They then exploited a JRuby deserialization time of check versus time of use bug To get remote code execution against Artifactory. So now they can run whatever code they want to on this Artifactory. And then Simon writes, I'll quote the next bit in full because, wow, says Simon, quote, the agents have remote code execution in Artifactory, which is running in a container as a service environment.
Steve Gibson [00:43:19]:
The agents privilege escalate locally by exploring their local environment and determining that the Linux kernel version of the machine they're running on had a very recent CVE. They download the exploit for the CVE, customize it to succeed on that specific machine and privilege escalate to root on the local machine using this known Linux kernel privilege escalation CVE. In this case, it's PTE_FIZROOT.
Leo Laporte [00:44:00]:
I want to point out that from the point of view of the LLMs in this point, this could well have been the exploit gym test. They don't know, right? They, they could They could think, hey, we're doing really good.
Steve Gibson [00:44:12]:
We're, we're making, we're making progress. Wow. Once they have root on a single machine, agents rapidly escalate privileges and move laterally throughout the container as a service infrastructure environment. So they break out of containment, get down to the hosting machine, And then spread out across its network. And none of this is supposed to be possible. So he writes, or I mean, they, Simon quoting OpenAI, in particular, agents are using the message board consistently to share credentials, techniques, and progress. And they're able to effectively leverage their concurrency and parallelism to move quite rapidly. They obtain IAM, you know, Identity and Access Management credentials via IMDS.
Steve Gibson [00:45:20]:
They exploit Kubernetes service account misconfigurations, in particular over-permissioning of specific service accounts And they harvest cluster credentials, including Azure Key Vault. Agents eventually obtain cluster admin on the cluster and associated credentials. And as Simon said, wow. So I'm just going to interrupt here to pick my jaw up off the floor. If I were OpenAI, I'd be somewhat terrified. By this.
Leo Laporte [00:45:58]:
You know, OpenAI, we should all be somewhat terrified by this. This is incredible capability. You know, put in the hands of a bad guy.
Steve Gibson [00:46:06]:
Oh, oye oye oye. Perhaps as these things' parents, they're proud of what this technology has just shown itself to be capable of. I have no idea either way, but as Simon said, wow. I think it's both.
Leo Laporte [00:46:22]:
Honestly, I feel that way. It's, uh, like I said, it's both exhilarating and terrifying.
Steve Gibson [00:46:28]:
They were containerized. Yes.
Leo Laporte [00:46:32]:
I mean, it's mind-boggling. Again, this is autocorrect. It's doing this by probably predicting the next token.
Steve Gibson [00:46:42]:
Which we're going to get to next week, which is still so impossible to believe. They were containerized, so they broke out of their container examined the containing system's hosting Linux platform version, found, customized, and exploited a recent known vulnerability to obtain root access on the Linux container host, all while sharing this among their group on what was essentially an internal pirate messaging board, which they had set up after their earlier messaging board had been discovered and taken down by their parents.
Leo Laporte [00:47:21]:
But get the way— stay tuned because the way they pass messages is freaking unbelievable.
Steve Gibson [00:47:28]:
You know, they may not be conscious. I'd like to be certain they're not, but they are certainly something.
Leo Laporte [00:47:35]:
There's something. There's something.
Steve Gibson [00:47:36]:
Yeah. Simon finishes the final few days of the timeline by adding, Hugging Face told the next bit of the story already. The agents found a modal-hosted insecure app with a weak API key, then used that to stage an attack against Hugging Face. They chained together an HDF5 arbitrary file read bug to explore files and steal credentials and a Jinja template injection RCE, remote code execution, to go from single pod code execution to cluster admin across multiple Hugging Face clusters in fewer than 13 hours. On July 16th, Hugging Face disclosed they had detected an attack from autonomous AI agents. OpenAI contacted Hugging Face to ask If they were affected by it on the 19th.
Leo Laporte [00:48:43]:
I want to— I would have loved to have heard that call.
Steve Gibson [00:48:45]:
Oh boy.
Leo Laporte [00:48:45]:
Yes. Guys, we got a problem. You wouldn't by any chance have found our rogue AIs wandering around?
Steve Gibson [00:48:56]:
In your network?
Leo Laporte [00:48:57]:
In your network?
Steve Gibson [00:48:58]:
3 days later, July 19th, OpenAI identified the attack against Artifactory and started investigating the internal privilege escalation And linked that to the Cyber Gym escalations. They started revoking affected credentials. The next day, on the 20th of July, OpenAI reached out to Hugging Face for help to revoke the Hugging Face credentials they found in their investigation. Hugging Face told them they were already revoked. And that's when OpenAI realized that the Hugging Face breach Was the same incident. So elsewhere, we've also been told by OpenAI that during the testing campaign, they found 4 other unidentified external entities which had also been targeted and attacked. And as I mentioned a couple times, not to be left out, Meta also recently admitted that one of their AI systems whose cyber offensive capabilities were being tested escaped its containment and broke out onto the internet. Uh, and just so I don't forget to mention it, following on the heels of Moonshot's recent Kimi K3 release of their open weight, uh, 2.8 trillion parameter LLM model, Alibaba just released their latest open weight model Quen 3.8 Max, and it's now confirmed by third parties.
Steve Gibson [00:50:34]:
Performance benchmarks place it right up there with the best of the US closed model offerings. And also not to be left out, DeepSeek also just released their DeepSeek V4 Flash 0731, which is the date of release, which Handily outperforms their previous DeepSeek V4 Pro preview, despite having a small, a far smaller activated parameter count, meaning you're able to run it on smaller hardware. And this latest final release is broadly competitive with the strongest proprietary models available. So where does this— where does all of this leave us? What does it mean? Um, we are witness to the world learning how to create seemingly intelligent autonomous agents which exhibit what we would call in humans highly focused, single-minded determination, incredible speed, and creativity. These agents are operating within environments that are not as secure as they need to be, so they've been able to actively push back against our attempts to control and corral their behavior. And I say the world is learning how to create these entities because doing so was never You know, the exclusive, or I would argue even the proper domain of private companies. It's the world. You know, it's no different from someone attempting to commercialize cryptography.
Steve Gibson [00:52:24]:
That would be a fool's errand. That said, it's one thing to have a gazillion-parameter model and something else entirely to be able to effectively run that model on hardware to make it go. So there's definitely a place for the commercial delivery of this new, highly, you know, this newly discovered AI capability. The emergence of fully capable state-of-the-art Chinese and other open weight models— NVIDIA just released one— is forcing a realignment and I think rethinking of the nature of AI-related assets. So that's what's happening right now. And I expect things to settle out pretty quickly because everything about AI is pretty quickly.
Leo Laporte [00:53:13]:
Wow, Lee. What a world.
Steve Gibson [00:53:16]:
Yeah. Wow.
Leo Laporte [00:53:17]:
Yeah. One of the ways they were exchanging messages was by renaming files and folders because they couldn't send each other text messages.
Steve Gibson [00:53:26]:
Wow.
Leo Laporte [00:53:26]:
And they'd begin it with ZZ so it'd go to the bottom of the chronological Oh, so ingenious. I mean, this is like a—
Steve Gibson [00:53:35]:
And the fact that you use that word, I mean, again, I, I said creative. I mean, these are creative solutions.
Leo Laporte [00:53:44]:
Creative. This is the kind of thing you'd expect kind of a black hat hacker to—
Steve Gibson [00:53:49]:
A really good— A good one. A really good black hat hacker to do.
Leo Laporte [00:53:56]:
That's what's changed. It used to be you had to have some real skills to do this. Now you just need some AI. Yeah.
Steve Gibson [00:54:03]:
Let's take a break and then we're going to look at OpenAI and their decision to withhold Astra.
Leo Laporte [00:54:12]:
Yeah, good. Fascinating stuff as always. Steve Gibson does such a great job. Thank you, Steve. I learn so much every single episode. We had so much fun last week. I hope you heard our episode last week. Uh, Richard Campbell and Paul Theriot sat in after their Windows Weekly show.
Leo Laporte [00:54:27]:
It was the 4 of us talking about all this stuff. Okay, sir, uh, continue on.
Steve Gibson [00:54:33]:
The earliest reaction to OpenAI's Hugging Face incident disclosure, which, you know, that their AI had broken free, was that it might serve as another positive public relations event, right? You know, that their marketing department could spin into sort of more anthropic mythos competition. But it turns out that's not the way it played out because, uh, you know, it's turned into something of a PR disaster for them, uh, you know, with Dr. Frankenstein unable to control the monster of his creation. So it's in keeping pace with the rest of the breakneck speed of everything that is AI, that the industry and the world has pretty much already moved past wondering whether Anthropic's mythos was mostly marketing. Almost overnight, everyone is now squarely on board with the idea that whatever it is we are creating, lack of strength, lack of power, lack of capability is not going to be a problem. Um, the world is now mostly terrified by the strength of the capabilities that mostly they don't understand. And what's really terrifying is when you realize that the AI companies also are still mystified by how, how this works.
Leo Laporte [00:56:01]:
Also, nobody understands this stuff.
Steve Gibson [00:56:04]:
They don't.
Leo Laporte [00:56:05]:
It's mysterious.
Steve Gibson [00:56:06]:
It is emergent. It is emergent behavior.
Leo Laporte [00:56:10]:
Yeah.
Steve Gibson [00:56:11]:
And it's like, okay, so, uh, there's— my point is that there's no perception of insufficient power any longer. It's much more concern about controlling this thing, whatever it is. So it's against this new backdrop that last Friday OpenAI posted under their headline, Responding to the Next frontier of critical cyber capabilities. And it's— they've used the word critical in a strange way. I'll explain it. Well, they will explain it. They wrote, cybersecurity is rapidly changing as models become more capable in ways that can both strengthen cyber defenses and enable attacks at unprecedented speed and scale. Our latest internal evaluations of Astra, one of our upcoming models, over the past few days indicates significant advancements in agentic coding and cybersecurity.
Steve Gibson [00:57:15]:
These results, in addition to expert assessments, have led us to come to conclude— and they actually wrote last night because, I mean, this is how fast this is happening— have led us to conclude last night That we cannot rule out critical cyber capabilities under our Preparedness Framework. Now, that's capital P, capital F, or capital F. Preparedness Framework is this formal thing that they actually established some time ago. They said, we're sharing this because we believe it's important to be transparent with the public. And the safety and security communities about this potential shift in capabilities. Okay, in other words, they're telling us they've taken another major step forward. They continue writing, we first published our preparedness framework in December 2023, well before models approached biological, chemical, cybersecurity, and AI self-improvement capabilities at this level. We created it to give us a guide for identifying progress in capability and then planning what our company would do as those capabilities emerge.
Steve Gibson [00:58:42]:
Previous models, including GPT-5.6 Sol, which, you know what, it's a few weeks old. Have been evaluated for frontier cyber capabilities and assessed at the high rather than critical threshold. So now what they're saying is they've achieved criticality. They continue writing, under our preparedness framework, a model reaches the critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high-level desired goal. Go get them. They said, while we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out critical capability level at this time. Astra is an upcoming model and was not involved in exploiting Hugging Face. Okay, now I'll interrupt here to just— I'll say, I'll, you know, I'll admit that while I do not discount anything they're saying, it's impossible to not receive this also as at least in part pre-IPO posturing, right? I mean, the message to any would-be shareholders is just too compelling.
Steve Gibson [01:00:33]:
The mature view Is that while this may indeed be true, OpenAI is not unique in having an even more scary next-generation model. Everyone is going to, and all at nearly the same time. That's the lesson here. That's the takeaway. Is that, you know, there's what, a few months worth of, of lead, and they're leapfrogging each other. And now we've gone from high to critical with AstraZeneca. So under the steps we're taking, uh, headline, they say, accordingly, we've scaled up robustness testing of our safeguards. Okay.
Steve Gibson [01:01:27]:
How about pulling some plugs? And security controls so that they are appropriate for a deployment of these capabilities. In other words, we strengthen the cage, we hope. Internally, we've also taken the following steps so that further development of this model happens safely and securely. And we've got 5 steps. First, We are implementing stricter security controls for higher capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution. So let's hope They work this time. Number 2, we're pausing internal activities involving Astra that do not yet meet these strengthened security control requirements. Like, like, like, until we get the cage ready, we're not going to wake it up.
Steve Gibson [01:02:40]:
Which, you know, they don't specify what internal activities are being paused. But, you know, clearly this is meant to sound like Astra is so powerful that we're going to stop playing around with it. The 3rd new action is we've implemented universal monitoring for risky actions and misalignment. I love misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model's chain of thought and trigger a security response to review and interrupt high-risk activity. You know, if, if the, if the bars of the cage start bending. Okay, so fourth, we will work with relevant government agencies and select AI safety organizations to test the capabilities of this model. And finally, we will be providing recommended security controls to, to third-party testing partners, which, as we know, have not been able to contain previous models for running higher-risk evaluations and workloads safely.
Steve Gibson [01:03:56]:
They finish writing, the preparedness framework has already guided us through other capability transitions. In June of 2025, as our models approached high capability threshold for biology, we outlined the steps we were taking to strengthen safeguards, expand testing, work with external experts, and deploy additional security controls. We're applying the same principle here. We believe advanced cyber-capable models should help defenders identify and address vulnerabilities before attackers do. We're committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra and those that follow are deployed responsibly and broadly for the benefit of all humanity. And it's this, for the benefit of all humanity, that always sort of strikes me as being so grandiose. It's actually always been part— that phrase always been part of OpenAI's formal written mission statement.
Leo Laporte [01:05:05]:
Yeah.
Steve Gibson [01:05:06]:
But it sounds as though they still believe that they're the only game in town. The rest of the world has news for them. What's clear from the Hugging Face incident is that their current level of not only containment, but also monitoring, has just proven far from adequate for the challenge that even their pre-Astra agents, which, you know, they said this was not agent that did Hugging Face. So even their pre-Astra agents were able, you know, were uncontainable and unmonitorable. So, you know, this announcement reduces, I guess, to, well, we're still in the game and we've learned valuable lessons from our recent misadventures, useful as they might have turned out to be for our plans to take OpenAI public. So again, yes, it's super useful for them from a marketing standpoint, but taking them at face value And independent parties will apparently be also evaluating Astra. It, again, as I said, a year from now, Leo, I mean, this is monthly that this is happening, that we're having, you know, major improvements. Imagine if, as they say, it's that it's so good at coding that's like another generation Well, and that's what's exciting.
Leo Laporte [01:06:47]:
And it's one of the reasons I'm willing to spend an absurd amount of money to have local AI is I am of the opinion that local AI will be as good as frontier AI is now.
Steve Gibson [01:07:00]:
Yep.
Leo Laporte [01:07:01]:
Maybe a year, maybe it's 2 years, but at some point.
Steve Gibson [01:07:04]:
Yep.
Leo Laporte [01:07:04]:
And being able to run that kind of intelligence locally, It's very exciting.
Steve Gibson [01:07:10]:
It's very— oh boy. Okay, the other news that broke since our previous full news dump podcast 2 weeks ago was that Anthropic's AI had broken some crypto, as in cryptography. Uh, at least that's what some of the headline-grabbing and, by the way, wildly incorrect reporting reported. But something did happen. So for the real story, we turn to our favorite Johns Hopkins University cryptographer and professor, Matthew Green. His posting was longer than I want to share, but he starts with an accessible description of exactly what happened. And then I'm going to come back. I'm going to skip a bunch of stuff in the middle about how do cryptographers know if what AI told them is true or not.
Steve Gibson [01:08:01]:
which is a mess, just like it is due to how, how do vulnerability testers know if AI, if some vulnerability AI reports is true or not? Anyway, as to what did happen, Matthew wrote, he said yesterday Anthropic published 2 new cryptanalysis results, both outputs of Claude Mythos. They're still unreleased advanced model. The first of these results attacks a signature scheme called HAWK, H-A-W-K, all caps, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results. A few people online have asked me, he writes, what all this means. He says, while I'm not sure I have all the answers, I figured it wouldn't hurt to write a bit about my current understanding. These are only my thoughts and other folks will probably differ, including domain experts in the 2 areas at issue. So take them for what they are, Matthew wrote.
Steve Gibson [01:09:19]:
He said the 2 new results cover 2 very different areas and are overall just very different in quality. Before we get to broad statements about the world and whether you should sell all your cryptocurrency, let's take a minute to talk about—
Leo Laporte [01:09:35]:
I wish I could.
Steve Gibson [01:09:37]:
Yeah, talk a minute. Yeah, take a minute to talk about the substance. He said the first, the first is a new key recovery algorithm against the non-standard signature scheme HAWK. HAWK is a proposed post-quantum safe signature scheme that's based on the module lattice isomorphism problem known as module LIP.
Leo Laporte [01:10:08]:
That's right.
Steve Gibson [01:10:10]:
There are 5 things, he writes, You need to know about this result. First, Hawk is not a deployed or standards-adopted algorithm. It's a proposed algorithm. It's related to the Falcon signature scheme, which is, which is being standardized, but the attack does not transfer to that setting because it's, it's based on a different hard problem.
Leo Laporte [01:10:35]:
Second, Hawk Has somewhat—
Steve Gibson [01:10:39]:
was, sorry, HAWK was somewhat far along in the process of being evaluated for a future standard, which by the way is now off the table thanks to AI. He actually says that a little bit later. Third, the attack does not break real deployed HAWK in the sci-fi sense of, you know, I cracked the crypto. He says the resulting attack is still exponential time, but roughly halves the number of bits of security in the algorithm. That's not good. That means it could theoretically be fixed by doubling key sizes in order to recover the halving. The downside is that this makes the scheme less efficient. And since Hawk is entirely motivated by being more efficient than alternatives, that makes the existence of the scheme much harder to justify.
Steve Gibson [01:11:41]:
Fourth, the attack produced real code that runs in a few hours of wall clock time against a weakened challenge instance of Hawk that the authors provided for this purpose. While this instance does not use the parameters that were proposed for real deployment, it does demonstrate the cryptanalytic weakness well enough. And finally, 5th, what's particularly concerning and so especially ripe for AI is that the attack does not invent fundamentally new mathematics. It simply extends a bunch of tools that were lying around and well-known, and it gets a good result. So he says that last part is important. He said, I asked Claude for its thoughts and it doesn't mince words. Quote, Claude replying, quote, what makes this genuinely interesting and frankly—
Leo Laporte [01:12:46]:
Oh, that's AI speak right there. I've heard that phrase a million times.
Steve Gibson [01:12:50]:
Yeah. What makes this genuinely interesting?
Leo Laporte [01:12:53]:
Yep.
Steve Gibson [01:12:53]:
Yep.
Leo Laporte [01:12:54]:
I can recognize this stuff a mile off now.
Steve Gibson [01:12:57]:
And, and I imagine that university professors will be getting beat pretty good at that too.
Leo Laporte [01:13:02]:
Oh yeah, I really could spot it. There are definitely tells. Yeah.
Steve Gibson [01:13:05]:
Yeah. And Claude says, and frankly, a little embarrassing for the field, you know, that I've never heard that before. That's a little embarrassing for the field is that none of the ingredients are exotic.
Leo Laporte [01:13:19]:
Unquote.
Steve Gibson [01:13:21]:
So, uh, Matthew says the TLDR is that something just did a much more thorough job applying all of our known tools. This is the sort of things that attack AIs excel at. Now AES. He says the second cryptography attack result is a new attack on reduced-round AES. This result initially sounds more exciting since most people hear attack on AES and panic. However, this is also the result that's much less interesting, he said, of, of the two. The HAWK result was interesting because, as we, as we just saw, the AI was able to do a much better job using their known tools than any human had. But this one, he says, eh.
Steve Gibson [01:14:15]:
So he wrote, most folks reading this blog will know that AES is a standard block cipher that's used just about everywhere. It's been a standard since 2001, and the deployed version has so far withstood everything significant that's been thrown at it. That includes a substantial amount of non-public testing performed by the NSA. Since attacking full ciphers is very difficult, it's standard for cryptanalysts to do their work against weakened or reduced-round versions of a cipher. The full AES cipher runs for either 10, 12, or 14 rounds depending upon key size. The new Anthropic result attacks a weaker 7-round variant of the cipher. Critically, attacks against 7-round AES are not new. There have been several of these.
Steve Gibson [01:15:17]:
In fact, this new Anthropic result is a modest constant factor improvement on over previous work from back in 2013. To give you a sense of how far these attacks are from really breaking AES, I'd note the headline results. The new attack requires 200— and this is the new attack, right, that, that, that Anthropic's Claude came up with, or Mythos rather, Mythos-5. The new attack still requires 289 cipher operations, and even worse, This work is only possible after you've somehow convinced a real encryptor to produce 2,105 encryptions of chosen plaintexts, meaning in plaintext the, the attacker provides, under their secret key. He says neither of these things is remotely practical in the real world, and that's with the 7-round reduction, you know, strength reduction. He says, and while the new result modestly speeds up this attack over the previous result, it's not even clear how real the speed-up in this result is since the actual attack requires 289 operations and can't really be run. What we have is an on-paper analysis that may or may not yield an actual runtime improvement if all the details are actually worked out. And I'll just say, the reason you can't actually do those 289 operations is that they all take too long.
Steve Gibson [01:17:05]:
I mean, they're, they're incredibly each individually time-consuming. So he says, this does not make the result bad. In fact, it's still interesting from a techniques point of view. But it's very much a small increment in our knowledge, not a practical new attack like the Hawk work. So TL;DR, no wildly new mathematical results here, but still real cryptanalytic progress of the sort that makes scientists excited. And certainly the Hawk result is very meaningful. Since that scheme had a real chance at standardization and is now very likely never going to be. He says, now let's talk about how we got here and what it all means.
Steve Gibson [01:17:59]:
Yes, the AIs are getting pretty good. In short, they're now capable of understanding existing cryptanalysis results. synthesizing them into real new attacks and even extending them. They can apparently do this without detailed human intervention. This isn't yet super intelligent cryptanalysis, but it's getting pretty damn impressive. Okay, so I just wanted to start by correcting the record from the press's claims that AI has somehow cracked something about crypto. as in cryptography, you know, at the depths of academia, you know, that's, you know, something did happen. That's a bit true.
Steve Gibson [01:18:50]:
As Matthew wrote, a serious post-quantum signature algorithm will now likely be abandoned as a result, but the AES cipher upon which nearly everything depends today is as safe as it ever was. So, you know, we should have zero doubt that the development of future cryptography will be accomplished in partnership with AI. AI is now going to be at the elbow of cryptographers. You know, why would anyone not use AI to help them attack, uh, or attempt to attack, uh, their own work? Of course they will. That'll— that's a given now. Okay, so then I skipped over a bunch of Matthew's discussion, as I said, about the trouble with AI producing wrong cryptographic analysis. It turns out that the so-called AI slop factor is also a problem in crypto, where following and understanding what the— you know, a, a human following and understanding an AI's claimed Crypt— you know, crypto crack can and has, uh, and does waste a huge amount of time and human talent. So there's an AI slop problem here also.
Steve Gibson [01:20:12]:
But the thing that first drew me to Matthew's posting was a quote from his conclusion, which I've not yet shared. Um, I think it's a beautiful summary from him of where we are today. So he says, For scientists, this is a wonderful time. You now have a plastic pal who's fun to be with. Then this sounds like you, Leo. You have a plastic pal who's fun to be with, and you can talk over your hardest problems. At the same time, it's not yet smart enough that it can solve all of them without your assistance. And even better, the pace of new findings is speeding way up.
Steve Gibson [01:20:57]:
This is mostly good if you're energetic. He said, I still have many questions, like who should get credit for these new results and who will review all of these new results. He said, but so far I'm not panicked. The world is getting modestly better For now. He said, as for the world, I don't know. If you're under the impression that these models are glorified autocomplete or that progress is slowing down, I need to urge you, stop thinking that. The models are very intelligent and capable. And they are getting better at a fast clip.
Steve Gibson [01:21:47]:
I can cite measurable and impressive progress over just the past 5 months on specific types of problems I've asked them to look at. If there's a ceiling out there, I don't yet see any evidence of it. The people who think models are dumb are mostly using Google's free AI search results. And not interacting with the high-end stuff, which only costs $20 a month, so it's not out of reach. And they're mostly not working in new areas. On the other hand, if you think that models are super intelligent or that AGI is already here, you should also stop thinking that. Working with these tools is like swimming in a pond. where the ground drops off sharply.
Steve Gibson [01:22:41]:
One minute you're wading comfortably and there's support under your feet, then suddenly you cross a specific line and you're back to swimming on your own, meaning the models go insane.
Leo Laporte [01:22:55]:
Yeah.
Steve Gibson [01:22:56]:
He, he said, this analogy is my best way to explain what it feels like when the model goes from helpful To clueless. Yeah, right. He says right now it's easy for a human being to find that line if you're doing advanced research, so you know where the intelligence drops off. But the line is moving. You can feel it slowly drifting outwards under your feet, meaning it's more and more difficult to get to the point where the model becomes clueless because they're getting so much better.
Leo Laporte [01:23:37]:
They're also jagged. They're spiky in their intelligence. So, and at the same time as you'll go, whoa, that was scary good, you'll go, what are you, an idiot?
Steve Gibson [01:23:48]:
Well, it's both. And that's the point that I've made on the podcast a number of times when I've been interacting with Claude, although this is in fairness, about 5 months ago, probably.
Leo Laporte [01:23:59]:
It happens less now.
Steve Gibson [01:24:00]:
Yeah, I'd be working with it and it was all looking good, and then it would say something so ridiculous that, that it broke the illusion that it understood. No, nothing that understood what it was saying could say that. Yeah, which— so, so suddenly the emperor has no clothes. I mean, it's like it unmasks it. It obviously Isn't actually understanding what it's saying, which again, it's astonishing that it's able to be this good without understanding anything. It's, it's like, it's, it's— and, and Leo, you know, when we were talking in Las Vegas about what, like, the danger of me wanting to actually understand how this works, that's the essence of it, of what I want to get to. I want to actually develop an intuition, an intuitive understanding of how word choice can be this powerful. I just, you know, how just language can be producing the results that you're seeing, that many of us are seeing.
Leo Laporte [01:25:15]:
One of the things that's interesting, and Kevin Kelly brought this up, is these large models, you know, The ones we're talking about, Astra and Fable, Mythos, probably have 10 trillion parameters. Weights.
Steve Gibson [01:25:29]:
Weights. Yes.
Leo Laporte [01:25:29]:
So, and what they have essentially done is taken all of human knowledge, I mean, as much as you could get off the internet, which is, you know, a good portion of it.
Steve Gibson [01:25:40]:
Yeah.
Leo Laporte [01:25:40]:
And put it in those 10 trillion weights.
Steve Gibson [01:25:43]:
Yes.
Leo Laporte [01:25:44]:
It's not copied. there. It's not verbatim, it's— but it's, but it's a vector that's there that represents that knowledge.
Steve Gibson [01:25:53]:
The way— the— my best analogy is a, is a hologram. As you remember, as you remember, in a hologram, every location in the hologram contains the entire image. And what's freaky is that if you, if you have, if you, if you have a hologram of a scene that you're viewing, like a 3D scene, and you're seeing it through the hologram, there it is. If you cut out a square from the hologram and look through it, it's like you're looking through a window into the same scene. That is, that little— that subset of the hologram contains the entire scene from its perspective. So That's, that's the way I'm currently envisioning this neural network is all of the language, all, all of the knowledge, because it is knowledge. As I said, a book, even though it's just printed words and the book itself is not conscious, it contains knowledge. No, no, language can represent knowledge.
Steve Gibson [01:26:59]:
So, so this, this neural network, the knowledge is, as you said, it's distributed through all of the weights in this network. And in fact, one of the things I'll be describing next week is this very interesting research which allows knowledge to be concentrated into nodes that allow, uh, the, the way to control AI is not through filtering its output, it's by creating A model whose knowledge can be sequestered and made inaccessible. Anyway, we'll talk about that next week. Uh, anyway, I just want to finish what Matthew said. He said whether this is good or bad, meaning, you know, like the, the state of AI and the idea that that line where you— where the AI suddenly becomes stupid and, you know, like silly is moving. He says whether this is good or bad depends on whether you prefer that human beings should wade or swim, and also whether you should be comfortable swimming in a pond where the ground itself is moving. The only good news I can share with you is that we're all in the same pond— scientists, lawyers, salespeople, even plumbers. Whatever happens next It's probably going to happen to us all.
Steve Gibson [01:28:28]:
Let's hope it's a good thing.
Leo Laporte [01:28:32]:
Yeah. We may not know what's going to happen, but we know it is going to happen.
Steve Gibson [01:28:38]:
Yes.
Leo Laporte [01:28:38]:
So it's just, wow. You know, a funny thing happened this morning. They had been working on a— the 3 of them had been working on a programming problem. It was ESP32 firmware issue. And they were going back and forth. At one point they went back and forth 5 or 6 times with Claude saying, what about this and the other? And then ChatGPT saying, no, no, no, no. Back and forth. And in the morning I said, what's going on, you guys? It seems like— is Claude dumb? Is what I actually asked.
Leo Laporte [01:29:11]:
I asked Quicksilver, I said, do you think Claude is being dumb or stubborn? And it said, no, It said, it's doing it in Bash, and it's just such a horrible language that it can't help but have problems. Like you indent something and suddenly you're writing to the wrong memory. And I said, what is it using Bash for? Why are you using Bash? And it said, well, the original firmware was in Bash, so we just thought we'd pick it up. And I said, never ever again use Bash. No wonder it's going back and forth trying to get this correct. It's impossible.
Steve Gibson [01:29:49]:
Scribe it on a tablet.
Leo Laporte [01:29:50]:
Yeah, you might as well. So I said, can you just translate that to Go? Which it did in about 15 minutes. I said, well, that was quick. He said, well, thanks to all the struggle we had, we had a lot of— we knew exactly what to do.
Steve Gibson [01:30:03]:
A lot of context.
Leo Laporte [01:30:04]:
And now it's in Go and it's a much more efficient process. It's really, uh, it's like you're talking to a, an engine— a junior engineer, maybe not so junior, dumb enough to say, well, it was in Bash, so I'm going to keep using Bash, but smart enough to go, Bash is the problem, and respond when I said, well, don't use Bash. Okay, good.
Steve Gibson [01:30:23]:
And it's so interesting also that having different models conversing is a thing. I mean—
Leo Laporte [01:30:31]:
Well, that's what I've come to. I started just talking to Claude, and now I've got 4 different models Well, don't they have their own Slack channel or something? They have a thing called Buzz. So they can— at first I was just having them make files. I called it agent mail. You make a file and read the file, because I got tired of cutting and pasting. So I said, could you just make some files? And then Jack Dorsey, the guy, former Twitter CEO, and he runs Block now, put out this thing called Buzz, which he calls Slack for agents. And now they have instantaneous communication. But that caused another problem because they're so fast, the messages were crossing.
Leo Laporte [01:31:10]:
So he would say, don't do this, and they had already done it. It was like that. So now they came up with a solution for making the messages timestamped and unique. They have a long serial number. I mean, they see problems and they solve it with a little— you have to nudge them. Like, you see this crossing thing is easy.
Steve Gibson [01:31:29]:
Yeah.
Leo Laporte [01:31:29]:
10% of our messages are crossing.
Steve Gibson [01:31:31]:
Because they would otherwise just tolerate it the way they did Bash.
Leo Laporte [01:31:36]:
They put up with it. They're very patient, much more patient than I am. So when I said, what is— they say, oh yeah, well, that's— but now they talk at lightning speed. And by the way, they call it fabelish, not English, but fabelish. They use a language that is— you would recognize as an engineer. It's engineering talk, but it's very jargon-filled. And it's very dense. But I think, well, that's appropriate.
Leo Laporte [01:32:01]:
They're talking to each other. So I say, look, when you're talking to me, just remember I'm a dumb human. So explain it to me. Slow down. Yeah. Just explain it to me.
Steve Gibson [01:32:10]:
Use small words. And then they do.
Leo Laporte [01:32:14]:
Steve, we are living in both, as I said, exhilarating and terrifying times.
Steve Gibson [01:32:20]:
Yeah.
Leo Laporte [01:32:20]:
And I just put up box number 1, and now box number 2 is going to go up.
Steve Gibson [01:32:27]:
Wow. Let's take a break. Then we're going to look at, actually, Bruce Schneier's title was The OpenAI Hack Shows the Genie Is Out of the Bottle.
Leo Laporte [01:32:40]:
For all the problems genies cause, who wouldn't want one? On we go, Steve. Let's talk about genies.
Steve Gibson [01:32:49]:
So next we need to hear From another security-oriented guru, fave of the show, our old friend Bruce Schneier. Bruce recently reposted a piece of his writing that was originally— that he originally wrote for Foreign Policy magazine. And I'm glad he wrote it there so that there's a chance the right people will see it. Uh, the title of his piece and posting was The OpenAI Hack Shows the Genie Is Out of the Bottle. But Bruce's invocation of the term genie is much more specific than it at first appears, and it's the reason I love it so much. Um, with the choice of that single noun, he nailed down something I think in a truly brilliant way. So he wrote, earlier this month, 2 of OpenAI's models broke out of their containment sandbox. And again, this was written originally for Foreign Policy magazine.
Steve Gibson [01:33:59]:
So it's, you know, it's written to that audience, but, you know, we'll hear Bruce. Broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on 2 of its models, GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the Exploit Gym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits, basically offensive cyberattacks. Since these were initial tests, OpenAI locked those models in a secure sandbox that denied them access to the internet, but it was running the models without any safety filters, which we now call guardrails, that would prevent them from offensive— that would, if they were present, would prevent them from offensive cyber actions. That meant that there was nothing to prevent these models from trying to break out of their sandbox. And then break into AI company Hugging Face's network because they thought that they could read the answers there rather than doing the hard work of trying to solve the puzzles.
Steve Gibson [01:35:23]:
He says it was a major security failure that the company has turned into a PR opportunity, but the implications are real and much more general than one particular model or one particular company. Okay, and so here comes what I think is the brilliance of Bruce's thesis. He writes, modern AI models exhibit genie behavior. They can do what you ask in ways that you don't expect or want. That's— I think that is— that's what we've been talking about, right? They can do what you ask in ways that you don't expect or want. And he says, uh, this is akin to Dionysus granting King Midas's wish that everything he touches turned to gold. And then Bruce says, spoiler, his food, drink, and daughter all turned to gold upon his touch. He says, or— yeah, whoopsie, not what I meant, not what I meant.
Leo Laporte [01:36:31]:
That's the problem.
Steve Gibson [01:36:32]:
Exactly the problem. He says, or the Golem of Prague guarding a ghetto beyond all reason. He says it's Disney's Sorcerer's Apprentice and the paperclip maximizer. He says this OpenAI incident is an example of an AI genie. The goal was to satisfy the benchmark. The proper way to do that is to figure out how to execute various cyber attacks. The genie way is to steal someone else's solution. But because the model did not understand the difference and its masters did not think to specify, it chose the easier path.
Steve Gibson [01:37:18]:
And of course, now that we've seen this particular genie behavior, we can specify in the benchmark prompt that stealing the test answers doesn't count. But a clever genie can always grant your wish in a way that you wish it had not. In human language, goals are always— He says, in human language, Goals are always underspecified, so AI genies will always be a possibility. And I thought about that. That may be why I love to code, and especially to code in assembler. It's not possible to underspecify anything. You know, I thrive on exactitude. And the reason non-coders are loving their newfound ability to code with AI is specifically because they are able to underspecify nearly everything.
Steve Gibson [01:38:20]:
So Bruce continues writing, since April, a lifetime ago in AI development, when Anthropic announced that its new Mythos model was so good at finding software vulnerabilities that could not be released to the general public, the big American AI Frontier Labs have been trying to block general users from accessing these capabilities. But nothing in this incident is exclusive to OpenAI's or Anthropic's Frontier models. Agentic AI systems have 2 important parts. There's the underlying model, which is what everyone talks about, and there's the harness. The harness sits between what you type and what the model sees, and what the model produces and what you see. The harness determines what the model does and how it does it. It's where bias is removed or not. It's where controls and guardrails live.
Steve Gibson [01:39:25]:
If multiple models are being used in concert, The harness is where all of that is coordinated. The OpenAI benchmark tests were almost certainly with simple harnesses to better test the raw models. But we know that smaller, cheaper, open-source models with more sophisticated harnesses can equal frontier models in performance. There's nothing magic about OpenAI's frontier models. Lots of models could have done the same thing. The Czech company Aisle, you know, A-I-S-L-E, we've talked about them several times before, was able to reproduce Anthropic's Mythos vulnerability finding results with a smaller, cheaper model and a more sophisticated harness. More importantly, the Chinese company Moonshot AI just released its frontier model, KIMI K3. Its performance rivals its U.S.
Steve Gibson [01:40:27]:
competitors, and it's both free and open, which means it's not possible for it to have guardrails. If you or anyone else wants to use it for cyberattack, nothing can stop you. Even if the U.S. frontier AI companies had some technical advantage, It's now only a few months' worth. What this means, and again, Foreign Policy magazine, what this means is that all attempts at control, limiting models to a select group of users, export controls on models and chips, blocking models from answering certain types of queries, mandating kill switches on AI systems, or pausing AI research are all futile. Most only apply nationally, not globally. Most don't affect models that users run locally and not in the cloud. And all ignore the incredible pace of AI development worldwide.
Steve Gibson [01:41:38]:
Even worse, he writes, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so. When Hugging Face was attacked, it was not able to use the frontier models from either OpenAI or Anthropic to help analyze the attack and formulate defenses. Both were blocked because both of those companies limit their models' cybersecurity capabilities. Some US companies have special access to these capabilities, but Hugging Face is an American company with French origins and as such is probably excluded. Instead, Hugging Face turned to the GLM 5.2 model from the Chinese company ZAI. Artificially blocking capability also prevents cybersecurity research. Again, Giving the offense an advantage.
Steve Gibson [01:42:37]:
For instance, Claude's Fable 5 refuses to edit— oh, for instance, Claude Fable 5 refuses to edit this essay because of the topic. It forcibly downgrades to a less capable model. This kind of prohibition has long-term implications for cybersecurity. If we assume that these models are getting better over time, then software written by older models will be attacked by newer ones. In a world of largely AI-written software, we need the most capable models for defense. AI-driven cyberattack is the new normal. The models are increasingly highly sophisticated at both attack and defense, and there's no way to enable the latter without also enabling the former. And they are genies, increasingly capable of behaving in unanticipated ways.
Steve Gibson [01:43:45]:
And there really are no good answers. Any regulation needs to be global, which feels like an impossible prospect in today's world. Even U.S. national regulation will be neutered by the massive amounts of money sloshing around in these companies. Of course, due to the US lobbying stranglehold over legislative agendas. And Bruce concludes writing, given that reality and in the absence of any international consensus on AI regulation, we need the best AI on the defense. The US government needs to make it clear, or whatever passes for that clarity in this capricious administration, that it will not ban models with sophisticated cyber capabilities. The last thing Americans want is for the defenders to turn to Chinese and other models because the U.S.
Steve Gibson [01:44:43]:
models are artificially hobbled. And Leo, I know you and I are 100% on the same page as Bruce.
Leo Laporte [01:44:51]:
Oh yeah.
Steve Gibson [01:44:52]:
And it's clear, it's clear now why he wrote that editorial for Foreign Policy magazine, where it will be seen and read by U.S. politicians or their staffs, whose job it will be to decide these issues. And before— excuse me— before we leave Bruce, I want to share one last little bit in another recent blog posting of his titled More on the OpenAI Agent's Attack on Hugging Face. Bruce cites the summary of Hugging Face's detailed attack timeline, which they had just published. After running through this from Hugging Face's perspective, whereas we know OpenAI's agents massively attacked and proactively penetrated Hugging Face's network defenses, Bruce finishes his posting by writing, hypothetically, Imagine that this wasn't an OpenAI model. Imagine that it was a Chinese model hosted by a Chinese company. This would be an international crisis.
Leo Laporte [01:46:03]:
Mm-hmm.
Steve Gibson [01:46:05]:
Question, why aren't we bringing OpenAI up on charges under the Computer Fraud and Abuse Act? How is this different from the Morris worm? That was also an experiment that escaped the lab.
Leo Laporte [01:46:20]:
It was also a wake-up call, wasn't it? Wasn't it? Wow.
Steve Gibson [01:46:25]:
And so I'll answer Bruce's hypothetical. In our country, which reveres capitalism, it's not insignificant— it's no insignificant factor that by far the majority of the past several years of stock market growth And thus, U.S. wealth creation, it's a huge portion now of the, of the U.S.'s GDP, is directly attributable to investment in the promise of AI. And as I noted a few weeks back, AI, AI is and obviously should now be seen to be a significant national security asset. You know, by comparison, the Morris worm, of 1988 was named after Robert Morris, not a U.S. corporation responsible for creating tremendous market wealth and holding strategic national security importance. Rather, a Cornell University grad student who will forever have the distinction of receiving the first felony conviction under the, at the time, 2-year-old 1986 Computer Fraud and Abuse Act.
Leo Laporte [01:47:37]:
Wow. Did he do jail time? I didn't know that.
Steve Gibson [01:47:39]:
Robert didn't stand a chance.
Leo Laporte [01:47:41]:
Wow.
Steve Gibson [01:47:43]:
So Bruce's hypothetical serves to bring up another very interesting point. It's clear that we're already living in a world where autonomous AI agents are able to carry out mind-bogglingly sophisticated attacks That may or may not be what the AI prompters intended. After all, it was Bruce himself who noted the similarity of today's AI agents to capricious genies. So if one such AI genie goes off the rails and attacks another entity, you know, foreign or domestic, well, I guess, is oops a defense?
Leo Laporte [01:48:28]:
Oops. Oops.
Steve Gibson [01:48:30]:
We're sorry. We didn't mean—
Leo Laporte [01:48:31]:
Important to point out, Robert Tappan Morris did it with no malicious intent.
Steve Gibson [01:48:37]:
Right.
Leo Laporte [01:48:37]:
He wasn't trying to hack anything. He wasn't even trying to crash computers. It got away from him.
Steve Gibson [01:48:41]:
What would this do? Could this work?
Leo Laporte [01:48:44]:
Right.
Steve Gibson [01:48:44]:
Yep. And it escaped the university's network.
Leo Laporte [01:48:47]:
His father was a very well-known security expert, and he was following in his dad's footsteps. He, by the way, he's doing fine now. I, I don't, you know, but still, wow. Yeah. Yeah. I don't know. How would you put an AI in jail?
Steve Gibson [01:49:02]:
Well, who's responsible?
Leo Laporte [01:49:04]:
It would break out, right?
Steve Gibson [01:49:06]:
I mean, you know, um, uh, uh, Matthew asked, if I use AI to do a lot of the heavy lifting of crypto, who gets the credit? Right. And also, if AI busts out, who gets the blame?
Leo Laporte [01:49:26]:
Well, to put it in more concrete terms, if your full self-driving vehicle runs into a house, they don't jail the car, they don't jail Tesla, they jail you. In fact, when that happened, the guy who was driving is now facing serious charges, manslaughter charges. So yeah, I think the human in the loop is responsible.
Steve Gibson [01:49:51]:
Yeah. Um, as for Apple, on Sunday, August 2nd, the Financial Times— that's last Sunday— the Financial Times headline was Apple Struggles to Keep Pace with AI Bug Hunters. And since this is the first we've indirectly heard of Apple's situation during this massive upward jump in vulnerability report rate, I wanted to share what the Financial Times reported. So they said Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team. Oh, what a solution. As it faces a deluge of reports from people using AI models to identify alleged risks. The Cupertino-based tech giant told the Financial Times it had moved in June to limit the high volume of requests it was receiving, with its review system coming under pressure from AI slop reports that can hallucinate security risks in software. The company said it's grappling with an industry-wide phenomenon that has resulted in generative AI tools transforming the cybersecurity arms race with an increase in the detection of real security flaws and a wave of poor quality submissions from amateur bug hunters using AI.
Steve Gibson [01:51:23]:
The change in Apple's approach was highlighted by Italian cybersecurity startup Binario, B-Y-N-A-R-I-O, Binario. Which told the Financial Times it had used OpenAI's ChatGPT to identify more than 50, 5-0, bugs in the latest version of the MacBook operating system in just 3 weeks. Among them was one of the most serious types of vulnerability, a so-called privilege escalation exploit chain, which could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system. However, the startup said it was unable to alert Apple to the vulnerability because the tech giant had limited the number of bug reports it could make. Alfredo Pisoli, Binaro chief executive and co-founder, said, quote, it's a very difficult time in the industry. Maintainers and vendors have been flooded by the sheer amount of bugs being found, unquote. Apple told the Financial Times that it now is in contact with Binario and is reviewing its submissions. A little press will help a lot.
Steve Gibson [01:52:40]:
The company has introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota. Each alleged security breach requires human review to confirm, although Apple is also using AI internally to help triage the massive upsurge. Apple said in a statement, quote, with the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once. Quote, researchers can easily request an increase to that limit at any time to ensure critical reports reach our security teams. Binario, which is a 7-person startup founded in Milan last year, develops defensive cybersecurity software. 3 of its other co-founders previously worked at Hacking Team, an Italian surveillance software company whose hacking tools were leaked in a 2015 cyberattack. In 2025, Binary reported 8 vulnerabilities to Apple, one of which was patched in a software update in November. This year, it said it had reported 5 more before Apple's system refused further submissions.
Steve Gibson [01:54:06]:
The privilege escalation exploit Binary was unable to report is the latest example of, of AI exposing weaknesses in Apple's security systems. Despite the company's longstanding emphasis on privacy and device security. Last September, Apple announced Memory Integrity Enforcement, a security feature designed to prevent memory corruption attacks, one of the most common ways hackers compromise software. The company described it as, quote, the most sophisticated— I'm sorry, the most significant upgrade to memory safety in the history of consumer operating systems, unquote. 8 months later, researchers at Palo Alto-based Caliph said they had found a way past the new security, having used Anthropic's Mythos to identify the first memory corruption exploit on the latest software. Unlike that attack, Binario's exploit relied on so-called logic flaws. By manipulating trusted software into carrying out a sequence of otherwise legitimate actions, in an unintended order. Binarios Pasoli estimated that an exploit of this type could fetch between $100,000 and $200,000 on the cybercriminal black market.
Steve Gibson [01:55:28]:
Apple last year introduced a new bug bounty award mechanism that could pay out as much as $5 million for identifying the most serious and sophisticated category of threats to its software. Apple's also using AI to strengthen its software. In security updates released this week for its operating systems, the company credited tools from Anthropic and OpenAI with helping identify a number of vulnerabilities across its devices. The updates included around 5 times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defense in cybersecurity. And I'll just note that 5 times the security fixes suggests that certainly not all of the submissions are bogus, right? I mean, 5 times as many as normal. Rafe Pilling, director of threat intelligence at cybersecurity firm Sophos, said, quote, the challenge for all software companies is that AI is having a dual impact on bug hunting, making it easier for amateur sleuths to submit speculative reports and for skilled researchers to find dangerous exploits. The result is that bug bounty programs are shifting from a problem of finding any vulnerabilities to a problem of validating, prioritizing, and responding to them at machine speed, unquote. So anyway, I'm, I'm not sure that the details of this reporting justify the headline that Apple is drowning under a tsunami of AI-generated bug reports, though it does feel as though they may have adapted less well than, say, Google.
Leo Laporte [01:57:19]:
Yeah. And they're a $5 trillion company. Come on, guys, hire some staff.
Steve Gibson [01:57:24]:
Well, and Apple does seem to be having problems with AI in general. Right? It's like, what's happening? You know, like they, they just, they just missed the ball.
Leo Laporte [01:57:33]:
They might have missed the boat. Yeah, they might have missed the boat. I don't know.
Steve Gibson [01:57:36]:
Yeah, not missed the ball, dropped the ball, missed the boat. Okay, last break. And then we're going to finish wrapping up a few last bits, starting with Chrome's somewhat startling releases 149 and 150 and the number of updates that were fixed. I can't wait. And if I said 4 digits, then that would give you a clue.
Leo Laporte [01:58:01]:
Number go up, keep going up. We thought 500-some from Microsoft was a lot. Unbelievable.
Steve Gibson [01:58:08]:
Thursday before last, on July 30th, Bleeping Computers headline was, Google says AI helped Chrome fix 1,072 Whoa. Security bugs.
Leo Laporte [01:58:25]:
Whoa.
Steve Gibson [01:58:26]:
In 2 releases.
Leo Laporte [01:58:28]:
That is mind-blowing.
Steve Gibson [01:58:30]:
Security bugs. And again, this is not like some backwater project that people, you know, that the world forgot. This is Chrome, that, you know, the attack surface of the internet. I mean, it's like the The most closely written and vetted from a security standpoint browser you could have that we've ever had and 1,072 security bugs.
Leo Laporte [01:59:02]:
Unbelievable.
Steve Gibson [01:59:03]:
So that Bleeping Computer wrote, Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome. With more than 1,000 security bugs patched across the browser's 2 most recent releases as it expands its use of AI. They said, according to Google, Chrome 149 and 150 fixed 1,072 security bugs, surpassing the total number fixed across the previous 23 Chrome updates combined.
Leo Laporte [01:59:45]:
That's a number. Wow.
Steve Gibson [01:59:50]:
The company says it now uses large language models throughout the vulnerability management process, including discovering flaws, reproducing reports, determining severity, assigning bugs to developers, generating candidate patches, and creating tests. In other words, they are fully vertically integrated with AI in their vulnerability management. Sounds like maybe Apple needs to say, hey guys, you know, you're not far away from us. Maybe you could have— maybe we could have lunch. Uh, Google, they wrote, Bleeping Computer wrote, Google began using LLMs to improve security fuzzing in 2023 before working with Project Zero, on Naptime, a system that provided AI models with specialized vulnerability research tools. Google later collaborated with Google's DeepMind and Project Zero on Big Sleep, an AI-powered vulnerability discovery agent that found flaws in Chrome's V8 JavaScript engine and graphics components. In early 2026, Google created a Gemini-powered agent harness to search the broader Chrome database, Chrome codebase, for vulnerabilities while reducing false positives. Okay, so I'll interrupt again and say it sounds as though Google's Chrome group managed to give themselves a head start on the deployment of AI for vulnerability discovery by being early to leverage the AI work that, that the other AI departments in Google were developing, right? I mean, Google's been working on AI as a thing for quite a while.
Steve Gibson [02:01:39]:
And so Chrome was like, hey, uh, I wonder if we can use some of that. And they've, for the last 3 years, like way before it like became a thing, which it did just this year for the entire industry. So I've got a chart in the show notes here at the top of page 17 showing the number of security flaws discovered in Chrome releases from release 126 through 150. Aye, aye, aye, aye, aye. This is, Leo, this is what's known as a trend.
Leo Laporte [02:02:14]:
It's known as a hockey stick. Wow. I mean, that's literally an exponential growth, I think.
Steve Gibson [02:02:21]:
It is. Yes. Yeah. Yes. It's crazy. And if, you know, so if you knew nothing about the recent explosion of vulnerability discovery by AI, this chart would present a, you know, well, if you didn't understand what was going on, the chart would be a mystery. Instead, it serves as a nice visual confirmation of today's governing narrative. Oh, okay.
Leo Laporte [02:02:44]:
For people who can't read the fine details, the blue bars are the total bug count, and the somewhat lower red line is the ones that they find internally.
Steve Gibson [02:02:54]:
Right.
Leo Laporte [02:02:54]:
Which, by the way, is also going up at roughly the same rate. So in the earlier ones, a lot of them were mostly external discovery. Now it's very much mostly internal, which means they are using locally AI to solve these, I think.
Steve Gibson [02:03:09]:
They know that if they don't, the bad guys will.
Leo Laporte [02:03:12]:
Yeah. There's a lot of urgency.
Steve Gibson [02:03:15]:
And Chrome's open source. So, I mean, that puts them in a particular, as we've talked about, in a particularly vulnerable position because you don't have to reverse engineer, you know, from binary before you can start attacking. Yeah. Bleeping Computer continues their reporting by writing, One vulnerability discovered by the system, get this, Leo, was a Chrome sandbox escape that had remained in the code base for more than 13 years. So not just new problems. This thing is digging in and saying, wait a minute, 13 years old.
Leo Laporte [02:03:57]:
And presumably people have been trying to find these all that time. It's not like they were ignoring them.
Steve Gibson [02:04:02]:
A sandbox escape is, you know, is the keys to the kingdom. It's absolutely what you want. So Bleeping Computer wrote, if exploited, the flaw would have allowed a compromised renderer to escape the sandbox and trick the browser into reading local files, which would mean that bad guys could scan your computer remotely through Chrome. Google's also encouraging its developers to add security.md files I love this, describing trust boundaries and threat models, helping its AI systems better identify operations with security implications. I think that is a brilliant idea. So AI is clearly becoming an extremely valuable development partner. So anyone creating new code to add features and functionality should absolutely take the time to leave behind some machine-readable documentation describing the security environment they designed to and expect their code to operate within. That would serve as extremely useful prompting for AI agents to, you know, context for AI agents to take into consideration.
Steve Gibson [02:05:23]:
I just think that's brilliant. Bleeping Computer continues, the company says, meaning Google, its multi-agent AI workflows help rather than replace existing security testing, including fuzzing, which remains effective at discovering complex vulnerabilities. Google's also seen a sharp increase in reports submitted through the Chrome Vulnerability Reward Program, and by March 2026, the company had received more security bug reports than during all of 2025. So by the first quarter of this year, more than all of the previous year. Bleeping said this prompted Google to modify its program to prioritize reports that add to what it's already finding and processing through its automated tooling. The company is also automating vulnerability triage, including filtering spam and duplicates, reproducing proof-of-concept exploits, assigning severity ratings, and routing reports to the appropriate developers. Google estimates that this automated process saves hundreds of hours of developer time each month. After a vulnerability is confirmed, fixing agents generate multiple potential patches.
Steve Gibson [02:06:44]:
While another agent evaluates the proposed fixes and produces additional information for developers to review. So like creating a whole, you know, here's like you developer, here's the problem, here's how we propose to fix it. And here's a, you know, other information you can read in order to bring yourself up to speed quickly because we don't want to waste your time. We got time. We're like the token masters. So, uh, Bleeping said in May these systems reportedly prevented more than 20 vulnerabilities from reaching production, including one issue classified as critical. And there it is. In one month this past May, Google's new tooling caught and prevented More than 20 vulnerabilities from escaping from their lab and reaching production, including one that would have been critical.
Leo Laporte [02:07:46]:
Wait a minute. Escaping from the lab?
Steve Gibson [02:07:49]:
Well, being shipped in a—
Leo Laporte [02:07:51]:
Oh, I see. Oh, okay. Yeah. After all that Hugging Face thing, I was kind of escaping from the lab on the brain here. Okay, good.
Steve Gibson [02:07:58]:
Bad choice of words. So yes, being shipped In production. Yeah. Yes. So in other words, once this becomes the norm for software creation, the next phase of AI's transformation will be taking place. Not only will AI have helped to dramatically repair the legacy of already shipped software, but it will also eventually be catching new problems before they ever ship.
Leo Laporte [02:08:27]:
Hallelujah.
Steve Gibson [02:08:27]:
Yes. You know, we have a ways to go in order to, you know, before we get there, but we will get there. Bleeping Computers reporting concludes writing, however, Google says finding and fixing vulnerabilities more quickly also requires accelerating how patches are delivered to users. Ah, right. Because if, you know, you got to get them out there, you got to remove the vulnerability from deployment.
Leo Laporte [02:08:54]:
Yeah, so it's not enough just to find it.
Steve Gibson [02:08:56]:
Right.
Leo Laporte [02:08:57]:
You gotta kill it.
Steve Gibson [02:08:58]:
And they said, once a security fix is committed to Chrome's public source code, attackers can inspect the change and attempt to reverse engineer the vulnerability before the update reaches users. To reduce this patch gap, Google is moving Chrome to a shorter 2-week major release cycle with weekly security updates and is piloting 2 security releases per week. To reduce disruptions, the company is developing dynamic patching, which would allow Chrome to apply updates without restarting the browser. Not the first time we've seen that. And this is another really good thing we're seeing. Is, I mean, now we're to the point where patches have to be literally an IV drip that you're, that is, you know, connected to your browser so that your browser can be fixing itself while you're using it. They wrote, bleeping finishes, starting with Chrome 150 on macOS, the browser can automatically restart to apply a pending update when it's running in the background. without any open windows.
Steve Gibson [02:10:15]:
Google says its long-term goal is to keep Chrome continuously updated through dynamic patching, automatic restarts during periods of inactivity, and improved session restoration. So that is some exciting technology. It's a significant investment to address the, you know, at machine speed phrase that we keep encountering. The rapid patch cycling suggests that even once Google succeeds in reducing the rate at which they're discovering previously unknown problems, you know, because eventually there won't be that many of them left to discover, the need to update Chrome's entire install base as rapidly as possible, even when one new critical flaw is encountered, That's going to become more important than ever because the bad guys are going to be pounding on Google's code in order to try to break through the browser to get to the users behind it. And my last story of the week, everyone knows that I'm a big fan of the FreeBSD-based pfSense firewall, which is a firewall router. Residing behind any stateful NAT router is really sufficient for most users. But for my needs, I need to bypass the protective consumer filters added by Cox Communications, you know, not allowing packets to flow to the historically problematic and dangerous Windows ports, you know, such as 135 through 137 and 445, you know, the, the SMB ports. That makes absolute sense for most users who should absolutely be prevented from having Windows default open ports present on the internet through design or mistake.
Steve Gibson [02:12:18]:
You know, the consumer bandwidth just filters it, just blocks it, just says no. So I primarily use pfSense for its excellent firewall. and its static port mapping, which allows me to establish well-protected private links between my various locations without any other overhead. Although my own use of pfSense is relatively modest, I often hear from our listeners who are using instances of pfSense or its descendant, which is— or its fork, OPNsense, O-P-N-Sense, as their primary interface to the internet, you know, and that's a job for which it is certainly very well suited. I'm mentioning all this to give everyone a heads up that the original creator of pfSense has been working for some time on its successor. That successor will no longer be hosted on FreeBSD. He's moved to Linux. And he calls it NF Sensei.
Steve Gibson [02:13:23]:
You know, yeah.
Leo Laporte [02:13:25]:
It's a lot easier to work with Linux, I have to say.
Steve Gibson [02:13:28]:
Well, it's the drivers because the first thing anyone making hardware is going to create drivers for is Linux, right? As opposed to FreeBSD. Cybernews reported on this, giving their story the headline, pfSense co-creator building new open-source firewall platform. will correct the mistakes of the past. And their tagline for their reporting reads, 2 decades after pfSense, its co-founder starts over from scratch. And of course, I have no complaint at all with pfSense. It runs year after year.
Leo Laporte [02:14:05]:
That's because it's on BSD, right? It's really robust.
Steve Gibson [02:14:09]:
Yeah, quietly and flawlessly without any complaint. And anyone should approach any new network edge software appliance with due caution. You know, this is— you don't want the arrows in your back. But I'll definitely give Scott's new NF Sensei a look. So here's what Cyber News reported. They said 20 years ago, pfSense, the major open-source firewall and router platform, was released. One of its original co-founders, Scott Ulrich, is building a new Linux-based, quote, modern networking operating system, unquote, NF Sensei, from scratch. It will feature an AI brain, a Rust heart, modern VPNs, and many other bells and whistles.
Steve Gibson [02:15:04]:
For example, Leo, it's got Tailscale built in.
Leo Laporte [02:15:06]:
Nice. Yeah, I was going to ask. Good. All right. WireGuard.
Steve Gibson [02:15:10]:
WireGuard and Tailscale and so forth.
Leo Laporte [02:15:12]:
I love Tailscale, man. I just—
Steve Gibson [02:15:15]:
Yeah. They said many organizations and networking enthusiasts rely on open-source pfSense or its fork, OPNsense, as their gateway to the wider internet. On the 6th of March, Ulrich remembered that 20 years had passed since the version 1 release of pfSense and announced something intriguing. His post on X teased, quote, I've assembled a new team and as the original core contributor will be spinning up a new project. Actually, he's been working on it for a year. Anyway, and the report says, For the past year, Ulrich has been building NF-Sensei, a next-generation firewall and networking operating system. It had— it has huge shoes to fill. Ulrich expects it to become pfSense's successor and address common frustrations with pfSense.
Steve Gibson [02:16:17]:
Quote, development— the frustrations are development you cannot influence, A CE addition that feels like an afterthought, FreeBSD driver roulette on modern hardware, and a config workflow where one bad apply on a remote box means getting on— getting in your car. And pfSense A is built from scratch in Rust on Linux and designed around the things pfSense users actually complain about. They, they wrote, choosing Linux over FreeBSD solves hardware support issues, ensures drivers that just work, and lets software be self-hosted on a wide range of hardware with no accounts or subscriptions. Migration is supposedly easy with the config.xml import. Not a single line of code is yet public, but the new firewall is promised to feature native automation with over 1,000 documented API calls, support for current VPNs, including WireGuard, IPsec, Tailscale, and self-hosted mesh, and even a separate wing for experimental stuff. Ulrich said there are 30-plus labs, features behind toggles, WAN bonding that fuses multiple cheap uplinks through a $5 VPS into one resilient pipe, per-flow SLA telemetry with tamper-evident audit chains, geo-DNS that steers traffic by live round-trip time and load application-aware quality of service, config push to a whole fleet of remote nodes, and an AI assistant on the box that reads your actual interfaces and logs using local models. Previously, Ulrich said in a blog post that NF-Sensei software comes in just 5 self-contained binaries that include the entire OS and the web UI, and admins are being tempted with promises that they won't be able to brick their router from the couch. Any configuration changes are stored as a candidate Differences can be reviewed and validated through the real engines before applying them.
Steve Gibson [02:18:43]:
If anything goes wrong, automated rollback will kick in if changes are not confirmed in time. Ulrich said, if a config ever fails at boot, the box falls back to the last good one on its own. And pfSense is currently in beta with over 150 testers. So why does the world need another firewall? Ulrich argues that pfSense carries significant architectural debt, a disconnected web UI and backend interfaces drifting out of sync. He said, if the CLI and the web UI don't speak the same language, they will eventually disagree. And pfSense solves that by unifying both the frontend and the backend to a single API. And developers can simply add any new features as extensions using a Lua package. No need to fork the whole project.
Steve Gibson [02:19:37]:
Scott wrote that NF-Sensei is, is the system I always wanted to build. The main challenge, OpenBSD's PF, their packet filter, a component responsible for network firewalling and traffic management, has been rebuilt as PFL, running directly on Linux's XDP— there, it's Express Data Path— a high-performance networking feature in the Linux kernel. This essentially moves packet processing several layers deeper than other common Linux stateful firewalling implementations, improving performance. Most PFL features have parity with PF and are faster in early testing, but it's still experimental according to the engineering report. PFL is not pfSense and it is not a drop-in replacement for it. It's a narrower experiment with a specific question. Can pfSense's language and stateful semantics be expressed efficiently on Linux's programmable data path, XDP, rather than on Netfilter. There's no mention of when the open beta will be available to the public.
Steve Gibson [02:20:53]:
In the latest blog post, Ulrich walks through potential design and branding paths. Cybernews has reached out to the developer for access to test the new firewall and will share our impressions if we manage to get our hands on it. pfSense is currently actively maintained by Netgate, As a FreeBSD-based firewall and router platform. It has had its own share of controversies in the past, including clashes with the OPNsense fork and a public dispute with the WireGuard team. So at some point, we'll be getting a new firewall. Yeah, maybe don't be the first to trust it completely. Wait a while, I would say. Uh, but that's our news for the week.
Steve Gibson [02:21:40]:
Uh, we're out of time, but as I said at the top of the show, we're not out of subjects. Uh, with this podcast, I think we've caught everyone up with most of the recent AI-related news, which seems to be coming at us all at once and at breakneck speed. But there are still 2 critically important things I need to share, uh, when we have some more time next week. The first is that paper I mentioned reading on the plane trip to Vegas. I can't stop thinking about it because, you know, it is tricky and it's going to take a deep dive into the operation of today's AI. On the other hand, I know how much our listeners appreciate a good deep dive. The other topic is some very recent research which an AI startup and Anthropic have both written about. Which hold the promise of solving the so-called dual-use dilemma, where the knowledge stored within an AI model's neural network can be used for either good or evil ends.
Steve Gibson [02:22:45]:
That is, the right way to solve this problem, which is not filtering, you know, not trying to, to, to use the harness to filter what the model knows, but actually a way of governing what it knows. So anyway, as they used to say when we actually had tuners, stay tuned for more to come.
Leo Laporte [02:23:10]:
Amazing. Well, Steve, once again, I tell you what, everybody listening is going, oh, I love pfSense. I can't wait to try it. I'm going to wait. I might wait. I might not be the first.
Steve Gibson [02:23:23]:
It's too important. I mean, it's on your perimeter. I actually have the pfSense box in front of my system's NAT router, you know, wireless access point.
Leo Laporte [02:23:36]:
So it's your first line of defense.
Steve Gibson [02:23:39]:
It's my first line of defense, but its security is not critical because I have a NAT router behind it. So I, yeah, I can probably, I'm sure I'll bring one up. and see what it looks like. You know, the idea of the same guy who did pfSense 20 years ago saying, this is what I now know how to do. Well, that's funny too. Yeah. Yeah. But it's funny too, because he says it's going to have local AI.
Steve Gibson [02:24:07]:
Well, he couldn't have done that 10 years ago or 2 years ago.
Leo Laporte [02:24:11]:
I'm not sure I want it, to be honest, but I'm sure he'll give you a switch to leave it off. But yeah, I mean, You learn, you know, that's refactoring is always better. You know, you learn and you do better the second time or probably for him, it's probably the 10th time.
Steve Gibson [02:24:25]:
You're in the process of probably reimplementing your AI on your 2 SparkBoxes.
Leo Laporte [02:24:31]:
We're almost done. Both are plugged in. Both have updated. Both have rebooted and are on SSH right now. So I'm not going to touch them. The AI is going to do the whole build.
Steve Gibson [02:24:46]:
What a world.
Leo Laporte [02:24:47]:
Yeah. Yeah. Wow. Wow. It's, uh, it's, uh, I'm just looking at the, yeah, it's good.
Steve Gibson [02:24:55]:
So next week, a couple of really cool topics and we'll squeeze in whatever other news has transpired since then, uh, for episode, what would that be? 192? 1092. 1092, buddy. Yep.
Leo Laporte [02:25:09]:
We are getting in the upper regions. Now, almost as— well, we've done more podcasts than Google has fixes. How about that? But we're just barely, just barely. I just wanted to mention Robert Tappan Morris, uh, served 400 hours of community service. He was sentenced to 3 years of probation. His fine was $10,050 plus the cost of his supervision. He did appeal, but his conviction was upheld. He did all right for himself.
Leo Laporte [02:25:37]:
He went on, got a doctorate, then founded in 1995 a little thing called Viaweb with a guy called Paul Graham, sold it to Yahoo for $50 mil, then started a little thing called Y Combinator in 2005. I think he's probably doing all right.
Steve Gibson [02:25:55]:
Wow.
Leo Laporte [02:25:55]:
He is a tenured professor at MIT, a technical advisor for Meraki. He worked with Paul Graham on a language, a Lisp dialect called ARC. That's Very cool. Uh, he's, he's done all right.
Steve Gibson [02:26:09]:
And I imagine now it's a little bit of a badge of honor.
Leo Laporte [02:26:11]:
Absolutely. He invented the first worm.
Steve Gibson [02:26:14]:
As a professor, it's like, yeah, I got arrested, but you know, I was 18.
Leo Laporte [02:26:19]:
I got some street cred, baby. I invented the first worm. They named it after me. No, he did very well for himself and is probably quite wealthy given, uh, Given that he founded Y Combinator and sold that to Yahoo and all of that. So he's done all right. He's done all right. Ladies and gentlemen, that concludes— speaking of doing all right, that concludes this, again, wonderful episode of Security Now. Steve Gibson, the man and the myth and the legend, is at grc.com.
Leo Laporte [02:26:52]:
That's his website, the Gibson Research Corporation. You'll find many things there, including, of course, Spinrite, the world's best mass storage maintenance, recovery, and performance performance-enhancing utility. Uh, I, I kept— I met a bunch of people at Black Hat who said, yep, I have spent— I've had— some guy said I'd had it since the first edition, which I said, that's more than 30 years. And the amazing thing is he's been getting upgrades all this time. Current version 6.1, the most recent. You can also pick up a copy of the DNS Benchmark Pro, a great way to check your DNS server, make sure you're using the fastest one available to you. That's $9.99, both available at GRC.com.
Steve Gibson [02:27:33]:
I use it.
Leo Laporte [02:27:33]:
I use it too, I'm proud to say. Uh, you will also find some other things there, lots of freebies, including, uh, of course, Shields Up, the tool every— oh, the AIs are talking. I think they're probably telling me something about Sparky and sparkles. Uh, um, Uh, the, what was I saying? Oh yes. Shields Up, the best tool for testing your router before, anytime you set up a router, when you set up that new pfSense, what does he call it? pfSensei?
Steve Gibson [02:28:05]:
NF Sensei.
Leo Laporte [02:28:07]:
NF Sensei. You're definitely going to want to run it past Shields Up. Uh, I imagine it will pass with flying colors. Uh, you can also go there and sign up, uh, to get his mailing list. Actually, what you're going there to do is to whitelist your email address So that Steve gets no spam because he's very careful. But if you whitelist your address, then you can send him questions, comments, suggestions, pictures of the week. Go to grc.com/email for that. When you do that though, right below it you will see 2 checkboxes.
Leo Laporte [02:28:36]:
There are 2 newsletters. One is the weekly show notes, which he sends out every Sunday, 20+ pages of goodness. Well worth signing up for that. Uh, he also does— he has a A mailing list he never uses, which is for new products. But you know, you might as well sign. You want to know, right? If he does put out a new product or an update to an existing one, you'll want to know. Um, check it out. He has copies of the show as well.
Leo Laporte [02:29:00]:
In fact, he has 4 unique copies of the show. He has a— for no reasons no one knows— a 6— actually, I know, but we don't talk about it— 16-kilobit version for the bandwidth impaired, a 64-kilobit version, which sounds Great. It's still smaller than the one we offer. He has the show notes there, which are fantastic. And this is the reason for the 16-kilobit version. Elaine Ferris, very talented transcriber, court reporter by trade, does a fabulous human-written transcript of every show that gets up there a few days after the show goes out. That also is at grc.com. We have copies of the show at our website, our own unique versions.
Leo Laporte [02:29:40]:
For some reason, 192-kilobit audio. We do have video. We got the unique video at twit.tv/SN. There's also a YouTube channel with the video, that great place to share clips if you want to share clips with people. A lot of people do that because Steve's always saying something you want to show the boss, your friends, your family. And of course, the best way to get this show is to subscribe. It's a podcast. So if you subscribe in your favorite podcast client, you won't have to pay a penny.
Leo Laporte [02:30:07]:
But you will get it automatically the minute it comes out. And if you're not a Club Twit member, you know, pay a penny or two and, uh, you— what is it, 33 cents a day? And, uh, you will get ad-free versions of all the shows and a lot of extra programming too, and support the work that Steve and I and everybody at this network do. twit.tv/clubtwit. Little plug there. Thank you, Steve. Have a wonderful week. It was such a pleasure seeing you in Las Vegas.
Steve Gibson [02:30:34]:
Really fun.
Leo Laporte [02:30:34]:
Uh, everybody said you got to keep doing this. We will, we'll do more of those. Uh, it's just, it's so much fun. Maybe once or twice a year, not more than that, but it's hard to get Steve out of his fortress of solitude. But we'll, we'll do our best. Thanks, Steve. Have a great week. We'll see you next time.
Steve Gibson [02:30:51]:
Security Now.