Security Now 1098 transcript
Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.
Leo Laporte [00:00:00]:
It's time for Security Now. Steve Gibson is here. We're gonna talk about, well, the new AI agents like Muse that are a little bit spooky. New hacker group called the Seven Deadly Sins, you can only imagine. And one of the worst breaches in history. The FBI should apologize, says Steve. Stay tuned, Security Now is next.
Steve Gibson [00:00:26]:
Podcasts you love. From people you trust. This is TWIST.
Leo Laporte [00:00:35]:
This is Security Now with Steve Gibson, episode 1098, recorded Tuesday, September 29th, 2026. How worried should we be? It's time for Security Now, the show we cover the latest in security, privacy, and all that jazz with the one and only, the legend, Mr. Steve Gibson.
Steve Gibson [00:00:57]:
Hello.
Leo Laporte [00:00:58]:
The guy who has been doing this longer than anybody coined the phrase malware or spyware, wrote the first spyware tool. We don't worry about spyware as much anymore, do we? It's just endemic. It's that, you know, you're being spied on everywhere you go. Right.
Steve Gibson [00:01:15]:
We gave up. We lost that race. It was like, you know. Yeah. And also, we'll hear me later this podcast remind everyone that if it doesn't make money for the bad guys, it doesn't happen.
Leo Laporte [00:01:30]:
Right.
Steve Gibson [00:01:31]:
That's one of the reasons that I'm not that worried. Today's topic, today's title of our podcast is How Worried Should We Be?
Leo Laporte [00:01:41]:
Oh, how worried should we be?
Steve Gibson [00:01:43]:
And I was talking to you before we began recording, and I noted that just the title indicates what we'll be talking about. That is to say, it does, like, about what? Well, no one wonders today.
Leo Laporte [00:01:57]:
We know.
Steve Gibson [00:01:57]:
where it is. Yeah. Yes, it's the only thing going on right now. So, um, and, and you also noted that you, you get some feedback from people saying, would you stop talking about AI? I want to say that, that the people who email me hear that I'm a— I'm self-conscious about us spending so much time, and they say, don't worry about it, we want to know what you think about AI because it often differs From everything we hear elsewhere.
Leo Laporte [00:02:30]:
That's a good point. So you have a unique perspective on it.
Steve Gibson [00:02:33]:
Yeah. You know, I mean, I— who was the first person you ever heard say it's going to be very good with code? And you also heard say it's going to be very difficult to control this.
Leo Laporte [00:02:45]:
Yeah.
Steve Gibson [00:02:46]:
Both those things I said like years ago and it's playing out now. So anyway, how worried should we be for episode 1,098? Will we get to 1,200?
Leo Laporte [00:02:59]:
Well, I don't know.
Steve Gibson [00:03:01]:
No, no. If you want the short version, it's not very good.
Leo Laporte [00:03:07]:
Good.
Steve Gibson [00:03:08]:
But we're going to take a long way to get to that conclusion because there's some interesting things I think that we have to talk about and look at along the way. We're going to talk about Muse's very bad zero-day. And actually, there's another one, a VM breakout that also just happened. So Muse is having some troubles on the security front, of course, Meta's new agent. And just hours ago, OpenAI introduced DOTS, which is going to be their agentic take. We've got somebody else, as I sent a note to you a couple of days ago, Leo, that it was nice to see somebody else noticing, as you and I had, that irregular the company Irregular was a common factor in many of these breakout stories. We've got more rogue OpenAI breaches. We're going to introduce the 7 Deadly Sins, TSDS, the 7 Deadly Sins, TSDS hacker group.
Steve Gibson [00:04:14]:
An interesting hack of an LNG, a liquefied natural gas cargo ship. Actually, this was the the third of it in a series, and it's got officials worried. Um, we've got the, the well-known Shiny Hunters group we've been talking about for quite a while, which we know is as an amalgam of several, uh, other groups which have gotten together under that moniker, uh, hacked into the FBI's site. And I have a somewhat controversial suggestion about what the— how the FBI should handle that. Uh, we've also got some news about the, uh, the people behind the, the internet's number one Linux distro, which of course is Ubuntu, uh, Canonical switching to an every 2 weeks release cadence.
Leo Laporte [00:05:07]:
Mm-hmm.
Steve Gibson [00:05:08]:
And of course we know why. Um, I found an amazing AI explainer which Jim Vande Hei, uh, with Axios produced. I gave it a GRC shortcut because it is so good. It is what all of our listeners can give to their friends who want to understand what in the world is going on. It's incredibly approachable. And then we're going to talk about this question. I think we can answer it now. At least, you know, evidence-based.
Steve Gibson [00:05:46]:
How worried should we be, actually? Because the world's gone insane over all this. So 10%?
Leo Laporte [00:05:54]:
That always cracks me up. Like you could calculate.
Steve Gibson [00:05:56]:
I know that is so bogus.
Leo Laporte [00:05:58]:
So they should say 11.8% and then it would be like, oh, it must be math, science.
Steve Gibson [00:06:04]:
And unfortunately, you couldn't get a better soundbite to get repeated over and over and over.
Leo Laporte [00:06:10]:
Everybody understands it. 10% off.
Steve Gibson [00:06:12]:
We're going to have a, I think, an interesting podcast for everybody.
Leo Laporte [00:06:15]:
Can't wait.
Steve Gibson [00:06:16]:
For a change. Okay. So, uh, we do have a picture of the week. Uh, and it's fun. Uh, I got the picture and I thought, okay, what, how could I caption this? And I thought, okay, those fluorescent light bulbs in the public storage alley keep being stolen, Leo.
Leo Laporte [00:06:37]:
The fluorescent light bulbs?
Steve Gibson [00:06:37]:
Fluorescent light bulbs in the public storage alley Keep getting stolen. All right, I haven't looked at this. What are you going to do about that?
Leo Laporte [00:06:46]:
I don't know what this is referring to.
Steve Gibson [00:06:48]:
How do you solve that problem?
Leo Laporte [00:06:55]:
No, no. You better describe this one.
Steve Gibson [00:07:01]:
So, so, uh, the fluorescent light bulbs, uh, often take the shape of a long tube which sort of spirals out and then crosses over at the top.
Leo Laporte [00:07:14]:
And you don't see these much anymore. They got, you know, there was a few years when this was everywhere, right? Now it's all LEDs. But those are expensive, those fluorescents.
Steve Gibson [00:07:23]:
They're expensive. And, you know, in, in a public facility where normally I think those, they have cameras, security cameras monitoring everything these days, but How would you keep that from being stolen? Well, somebody came up with a clever idea, uh, and it's another one of our— in our series of fun ways to use a padlock. Uh, they, they looped a chain through the loop at the end of the fluorescent light, uh, through a, a crossmember above the light and padlocked it so you could You know, a bad guy could destroy the light, but then they're not getting any benefit from stealing it. Basically, this completely solves the problem. I mean, it's going to end theft of otherwise, you know, easily, you know, exposed screw-in base fluorescent lights, which people might think, hey, you know, mine burned out at home. I'm going to just steal this one from, from, from the garbage can place. Yeah, that's right.
Leo Laporte [00:08:25]:
Absolutely.
Steve Gibson [00:08:26]:
Okay, so last week we briefly acknowledged Muse, which is Meta's consumer-oriented agentic AI assistant.
Leo Laporte [00:08:37]:
And I have been using it like crazy, by the way.
Steve Gibson [00:08:39]:
And have you been?
Leo Laporte [00:08:40]:
Well, I'm going to just tell you what it did. I accidentally, my agent, my AI accidentally took my entire computer offline, which meant I had no access to my agents. And one of the problems, we've been talking about this, letting an AI be your sysadmin, is you gradually forget how everything works, right? All of a sudden I sit down at my computer and it's not online. I can't access Claude, I can't access Codex, I can't access Hermes, and I don't know what's wrong.
Steve Gibson [00:09:10]:
Right.
Leo Laporte [00:09:11]:
I have no idea. I don't know why I thought of this, but I went to Muse and I said, hey, you got to help me, man. I can't get online. Now, fortunately, I had given Muse access to the tailnet so that I could use it outside of the house and it would reach into my home network. It said, oh, I know what's happened. Hermes pointed my computer at an exit node on one of these little Broom devices. It's a little travel router. And then broke the travel router.
Leo Laporte [00:09:46]:
taking us offline. I said, you committed suicide. What did you do? You— what did you do? Fortunately, Muse, because it could get to the tailnet, said, oh, I see what's happening. Your framework's pointing to an exit node that no longer exists. It repointed it. Everything came back. So thank you, Muse.
Steve Gibson [00:10:03]:
Wow.
Leo Laporte [00:10:04]:
But this argues for giving Muse all the permissions, which you're going to tell me is a very dumb thing to do.
Steve Gibson [00:10:11]:
This is the— what I predict with all of this agentic Consumer-grade AI.
Leo Laporte [00:10:20]:
Oh, everybody's doing it.
Steve Gibson [00:10:22]:
They are. And there's, of course, already one famous anecdote of some guy who asked Muse to sell something for him. Muse sold it for a lower price to another person than this guy wanted to sell it for and gave the other person the owner's home address. And this person comes and knocks at the front door, and the, the guy who was using Muse said, what, what do you mean you sold it? How much for? Anyway, uh, we're gonna see a bunch of stuff go wrong. It's just inevitable. Um, I think—
Leo Laporte [00:11:01]:
I, I—
Steve Gibson [00:11:02]:
it is probably going to be the place that we spin, that the industry spins on Longer than anything else is that the fundamental uncontrollability or unpredictability of agentic AI. And, and Leo, just anecdotally, we've heard from you, like, your agents stop. They just stop working. They go, well, we're waiting for you to click your heels 3 times. What? What are you talking about?
Leo Laporte [00:11:32]:
Yeah, you wanted us to keep working. Oh yeah, that's right. You told us that, didn't you? Oh, okay. Never mind. Oh my God.
Steve Gibson [00:11:38]:
Anyway, so they have a mind of their own.
Leo Laporte [00:11:41]:
That's very, very—
Steve Gibson [00:11:43]:
Well, and that's the problem. We want them to have a mind of their own. We have given them a mind of their own because that's how they're useful to us. And this is the great dilemma is that, you know, you know, with great power comes great responsibility. Unfortunately, they're irresponsible. And so, and we're trying to teach them responsibility, and I don't know how well that's going to work, you know, or how quickly we're going to be able to. But boy, I, I said to, to Lori this morning, I was just shaking my head because I, I was reading the, the news release of, of OpenAI's— they just this morning, OpenAI released DOTS. D-O-T-S.
Steve Gibson [00:12:25]:
DOTS is their consumer—
Leo Laporte [00:12:28]:
Same thing. It's just like news. Yes.
Steve Gibson [00:12:32]:
And, and I said to Laura, I said, what a wonderful time to be alive. I mean, this is just, you know, it's, it's chaos and but cool stuff, you know. It's tech chaos, and we don't often have that in our industry, you know. You gotta— like, lots of other places have chaos. We're, we're getting some here now. Anyway, Muse saw, uh, 2.8 million app downloads in the first 12 days. It's been the number one downloaded iOS app, pushed ChatGPT off the number one spot for a while. So unfortunately, so, so, okay.
Steve Gibson [00:13:12]:
So first off, there's the whole fundamental problem, which is not a bug. It's kind of a feature of wanting these things to act on our behalf. If that's what we want, we have to let them do, we have to let them be able to, you know, and—
Leo Laporte [00:13:36]:
Well, I'm just glad it could fix my network because I have lost all skills in that regard.
Steve Gibson [00:13:41]:
That is very cool.
Leo Laporte [00:13:42]:
The second thing I asked it to do is write me an emergency manual for next time so that I know what steps to take, which is good because it brought it down 3 more times. But I knew this time the command to enter at the shell to Great point.
Steve Gibson [00:13:55]:
Yes, as I was saying, Leo, chaos. You have— you are the, the, the chaos addict.
Leo Laporte [00:14:02]:
I'm the canary in the attic. Yes.
Steve Gibson [00:14:05]:
Okay, so, so there is the— so on one side of the whole agentic problem is that, which— and I expect we'll see lots of other anecdotes of people talking about how it did the wrong thing for them. We'll work on solving that. On the other side, there are just flat-out bugs, and those are gonna happen. And, you know, that's old-school side, right? We know about bugs and we know about patches and, and, and fixing them. So, uh, Zuckerberg, in announcing Meta's Muse 3 weeks ago today, uh, understood that security concerns would be a natural issue circulating around this. And I think that Facebook probably knows that they've got some, some worries to quell because they've not been great in, in the past. So he says, Mark, during his, his, his announcement 3 weeks ago, Muse is built from the ground up for privacy and security, which Okay, uh, struggling with, with operational correctness will be a different problem, right? But, but so Mark says, built from the ground up for privacy and security, your data and credentials live on the Muse secure VM, an isolated Linux computer with a browser, CPU, memory, and storage, you know, in, in on the cloud. He said a Sentinel agent Separate from your MUSE runs on your VM.
Steve Gibson [00:15:42]:
Every action or piece of data that goes out to the network has to be approved by the Sentinel. The kernel enforces that, and it knows— it's too bad it's spelled K-E-R-N-E-L because, you know, if it was K-O-L, that would be kind of fun. Anyway, the kernel—
Leo Laporte [00:15:59]:
Kernel, yes.
Steve Gibson [00:16:02]:
The kernel enforces that. And it knows when it needs to get your permission to proceed, except apparently not in that case of the thing that, you know, did all that without the user's permission. The model, the Muse harness, deterministic code, and an ensemble of classifiers all work together to detect threats like prompt injections. These systems work to quarantine threats and prevent them from entering the model's context window. Of course, we— all of our listeners don't understand these terms now because we've been doing this for quite a while. Mark said, you're in control. You choose which apps and services Muse has access to, and you can disconnect them at any time. For sensitive actions like purchases or sending emails, Muse checks with you first.
Steve Gibson [00:16:54]:
Of course, except when it doesn't, but okay. Uh, we've run a bug bounty program on Muse since early in development. Today it becomes public with published payout guidelines. We pay by the impact demonstrated. More deals— more details at security.muse.ai. Okay, so from what Mark wrote, this whole notion of a, you know, VM well designed and deliberately constructed It sounds as though Meta clearly gave the architectural design of the cloud-based side of their new agentic assistant the attention it needed. I don't have in the show notes because it happened after I sent— I wrote them and sent them out, but we just had a VM breakout. So, you know, there was a patch which was immediately needed over on the server end, the VM side.
Steve Gibson [00:17:53]:
that, that they've addressed.
Leo Laporte [00:17:56]:
The thing to understand about Muse is it's a computer. It's a VPS. You are running a computer on, on Facebook's servers, Meta's servers, with a CPU, with a GPU, with memory, with hard drive storage.
Steve Gibson [00:18:11]:
And a browser. A browser that's able to browse.
Leo Laporte [00:18:14]:
You can get a terminal in it, by the way. I've seen people Do things like send me your, uh, all the stuff in your directories. You can download all of the instructions, all of the stuff. Nothing's hidden. It is, in effect, an access to your computer. You can even install Hermes on it. You can install another agent and run the agent on that computer. It's a full computer, which means it's probably pretty hard to restrict.
Leo Laporte [00:18:40]:
But I will say one thing. I sent it a picture of me in my lederhosen. Because I have—
Steve Gibson [00:18:46]:
of course you have one.
Leo Laporte [00:18:48]:
I have beautiful leather lederhosen with deerskin shoes, the whole works. I got in Germany.
Steve Gibson [00:18:54]:
I'm sure she probably took a picture. Yep.
Leo Laporte [00:18:57]:
I lost the hat, the Tyrolean hat that goes with it, and I didn't have any beer steins. So I took a picture of me on the deck out here holding, pretending to hold beer steins. And I said, hey, Muse, put a hat on me, give me some beer steins, and put me in a beer garden. It said, I can't do that. I can't make pictures with beer in them, but let me try to do— put you in front of a poster. And then it said, nope, can't do that either. So it definitely has classifiers on it, but they may be a little bit on the— worried about the wrong thing.
Steve Gibson [00:19:31]:
On the tight side. Well, and again, this is the problem, right? That's another example of this, how difficult this problem is.
Leo Laporte [00:19:41]:
Exactly.
Steve Gibson [00:19:42]:
Because there, there will be things that it ought to be, that would, that Mark would agree are safe for it to do, but because there are some things that might be classified similarly that are not safe, they err on the side of caution. So people are going to be saying, well, why won't it do this? And why?
Leo Laporte [00:20:01]:
Well, because that, you know, that, that could be abused in some I mean, I should point out that I then used the obliterated version of Quen Vision on my own system and was able to create a picture of me in my lederhosen holding beer steins. Even had— I said, please put some buxom young German women behind me in the beer garden, and it even did that. So you see—
Steve Gibson [00:20:30]:
Yes, they're looking at your butt.
Leo Laporte [00:20:31]:
Leo. So, well, there's not much to see there. Let me just see what they are. They are laughing. I— maybe they— anyway, yeah, so I got around it with my own model.
Steve Gibson [00:20:44]:
So I'm sure we're gonna see trouble because this is not cut and dry. This is not a binary decision. These are— these are— this is by— this is probably the best definition of heuristic that you could ever find is it going, well, but, you know, beer, that— anyway, so, um, the— so we, we've seen a problem over on the server side, but what about the Muse app? Because there is an app that runs on the client. Um, they understand, they, Meta, that the service will be offered to a largely non-technical audience, and they also recognize that it really must succeed. I mean, they've— this is a big bet for Meta.
Leo Laporte [00:21:29]:
Big deal for them. Yeah.
Steve Gibson [00:21:30]:
Yeah. Finally, I mean, they— all of that nonsense that Mark's been doing with VR and metaverse and all that, it was like, okay, we've just been— everyone's been waiting for something good. Um, and they currently have an excess, it happens, of data center build-out, which, uh, like, they've got way too much compute that they don't know how to use. In fact, they created a Meta Compute business specifically to resell their unused compute to third parties. They're apparently in— reports are that they've been there, they're in talks with Anthropic. So they need something that burns up cycles and nothing does that like agentic AI, as you also have found out, Leo.
Leo Laporte [00:22:19]:
Yeah.
Steve Gibson [00:22:20]:
So, you know, a strong and enduring showing, because it's not just downloads, but it's like, it's retention over the long term, you know, that will greatly increase their own need for compute, um, and which they'll be able to deliver from their own data centers. So, uh, we have to see whether people are going to continue using it. Um, and also I should note that we've talked before about the power of lock-in. That is, you know, I'm very happy, for example, that I went with Claude while my wife Lori stuck with ChatGPT. I initially, I didn't realize how much context was going to be kept. And of course, they've increased that over time because it ends up being a very good thing for your, your AI chat client to learn more about you. And I've, I've even taken to specifically letting Claude know when it when working with it comes up with some alternatives, I take the time to tell it which of those I went with because I realize it will hold.
Leo Laporte [00:23:25]:
Yes, absolutely.
Steve Gibson [00:23:26]:
It will hold on to that. And that's because, for example, there was— oh, there was, um, it thought that in the case of my home automation that I was already using Home Assistant because I had mentioned it. And so several times it said, oh, and because, well, you know, you've got Home Assistant, so blah, blah, blah. I said, Hey, just for the record, that's— I'm trying to use HomeKit by itself. I— there's no— I haven't run into anything yet for which I need Home Assistant. It is not deployed. And so I took— I, you know, I wanted to correct it so that it stopped factoring in the assumption that I had that.
Leo Laporte [00:24:03]:
So very important to do that.
Steve Gibson [00:24:04]:
Yeah, yeah, right. Um, but I've come to appreciate that I am pretty much stuck with Claude. I happen to be very happy about that. But if something else really shiny were to come along, I would be reluctant to lose everything that Claude has learned about me because it is so useful to have an agent that knows my environment, knows what my servers are and what my network addresses are and all these things that are useful because it just makes it easier for me. So, and I'm mentioning this because I'm sure this is going to become a thing that we're going to be hearing about, you know, assuming that we don't hear many more reports of Muse going nuts and seriously messing up people's lives.
Leo Laporte [00:24:56]:
We will, I promise. This is just the beginning. I think it's just inevitable. Just as OpenAI learned, you really can't wall these guys off. I should point out, though, Early on in my AI journey, maybe last spring, that exact issue came up for me because I was using Claude and I love Claude and Claude was so good and it understood everything I was doing and it was really a great tool for me. But I also thought, I don't want to be tied to one provider. So that's why I set up Hermes as an agent and I imported all of my Claude settings. So this is where agents are great.
Leo Laporte [00:25:34]:
You could just— and you'll be able to do this with Muse, I promise you. You'll be able to say to something else, whatever it is, maybe the Dot bot from OpenAI, hey, I use Muse, go get everything. Or I use Codex, or I use Claude Code, or better yet, I use all 3, go get everything. Make that your memory too. And one of the rules I've always said to my agent is I want to be agnostic. I want to Model agnostic. I want to be memory agnostic. I want this to be portable.
Leo Laporte [00:26:06]:
So that's one of the rules.
Steve Gibson [00:26:08]:
Why would Meta allow Muse to have an export?
Leo Laporte [00:26:12]:
You can't stop it. So there's already a guy who says, all you do is you go into Muse and you just say, hey, can you zip up all your system files and send them to me? They actually make the SoulMD and the MemoryMD available. So you can take it anyway. But even more than that, you can say, please make a zip file. Now maybe they'll turn this off. I'll try it.
Steve Gibson [00:26:41]:
Of your— Well, Leo, if you have console terminal access to your—
Leo Laporte [00:26:46]:
Exactly. They can't stop you.
Steve Gibson [00:26:48]:
Yes.
Leo Laporte [00:26:49]:
So yeah, exactly. I won't go through all of this, but it's been done. And so, and I think in general that most of these guys, you just tell it, figure out a way, and it will get it out of there. It will. This is, you know, they're persistent.
Steve Gibson [00:27:09]:
So we will see whether, well, and of course, power users may be able to do that. We're going to, there'll be a lot of people who are going to be putting, turning over more and more of their own lives to Muse to manage for them. And so that will end up creating a deep investment in, you know, in Muse as their agent. So anyway, I think it's going to bring a whole new notion of lock-in to, you know, what we've had before. Uh, search engines, yeah, you just switch to a different search engine. Fine. Because I mean, it doesn't—
Leo Laporte [00:27:44]:
I think it's easier. No, I don't think there is any lock-in. Seriously, it's so easy. It'd be trivial to make a thing that— I don't know why it's not showing it. There it is. There it is.
Steve Gibson [00:27:56]:
Like a consumer-level exporter?
Leo Laporte [00:27:59]:
Yes. So I'm just going to download the skills folder, 175 megabytes, or everything under optatch. Yeah, I'll take that. The 1.6 gigabytes on my virtual machine in the Meta cloud. I'm just downloading it right now because I asked it to.
Steve Gibson [00:28:13]:
So it has 1.6 gigabytes? 2.6 gig of your, like, of stuff that—
Leo Laporte [00:28:18]:
Well, some of it will be generic, obviously. Yeah.
Steve Gibson [00:28:21]:
Oh, okay. Okay.
Leo Laporte [00:28:22]:
But some of it won't, and you can go through it and you can find it. So it's zipping in. It's going to take a few minutes. It's going to send me the file when it's done. This is the nature of these things, is it doesn't have any memory. It just has files. And if you, I mean, I think it's maybe Meta will decide not to give us access to the file system at some point.
Steve Gibson [00:28:43]:
Well, and that's what I'm wondering is because it seems to me having people leave. Well, I'm not using any of this stuff yet.
Leo Laporte [00:28:51]:
I mean, it's— I would say it's less opaque than a search engine. Let's put it that way.
Steve Gibson [00:28:57]:
Well, it's okay. Right.
Leo Laporte [00:28:59]:
Yep. You can get your profile out of it because it's just text files.
Steve Gibson [00:29:04]:
Okay. On the Muse client side, As we all know, it's one thing to design a secure architecture, which, you know, Mark's jumping around on stage saying that they did, uh, and that's a good thing, right? But it's still possible to be bitten by bugs from within that architecture, uh, you know, or even where one isn't looking, you know, which is what happened with MUSE's launch. Ars Technica provided the best coverage of what happened that I've seen, because Dan Goodin is a great writer of, of tech stuff for Ars. Their headline was, uh, Muse, Meta's Extraordinarily Privileged AI Assistant, Has a Serious Zero-Day. Uh, Dan wrote, Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse. Claiming that it is, quote, built from the ground up for privacy and security, unquote. A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts, writes Dan. Further raising questions, Amazon on Sunday began blocking Muse from its site.
Steve Gibson [00:30:25]:
But that's independent. That's Amazon not sure that it wants Meta's agent rummaging around and doing purchasing. I, I have a feeling Amazon's gonna, you know, change that. But, uh, Ars wrote Meta introduced Muse a few weeks ago. The assistant, quote, books appointments, fills out forms, and handles customer service, proactively takes tasks off your plate, and can make purchases, generate images, create documents, and connect with your favorite apps and services. The macOS app And at the time, ours wrote, or Dan said for ours, curiously, there's no Windows version. Also works with a user's WhatsApp, email, calendar, and social media accounts, meaning all the local stuff. When a task requires a tool that does not exist, Muse creates one on the fly.
Steve Gibson [00:31:16]:
He writes, of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures. The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings. Most of them are fairly innocuous, such as controlling dark mode. One setting, however, is anything but.
Steve Gibson [00:32:41]:
It allows processes to change the endpoint where transcription occurs, you know, voice transcription. Normally it's a server address operated by Meta. Attackers can exploit this flaw by changing the location to their own endpoint. Once that happens, the attackers have the token that gives complete control over the Muse account. Patrick Wardle, the macOS security expert who discovered the zero-day, told Ars, quote, we can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself. Wardle said he has developed several proof-of-concept attacks that do things like write malicious files to disk and snapping pictures, in many cases with no indication to even alert the user. More than 12 hours after this, this post, Ars Technica's post, went live, writes Dan, Meta said it released a hotfix that patched the zero-day.
Steve Gibson [00:33:58]:
Meta has published 2 posts in as many weeks documenting the design decisions that went into ensuring an assistant with such extraordinary access to user data and resources is secure and private. The posts come amid revelations that internal testing of models from Anthropic and Google has resulted in security breaches of external third-party networks, blah blah blah, we all know that stuff. Um, the Meta posts are likely mindful of the resulting blowback And the calls to slow down AI development in response. So Meta is basically saying, don't worry about us. We know all about that. And we made ours secure and private.
Leo Laporte [00:34:41]:
Yes.
Steve Gibson [00:34:41]:
Dan writes, yeah, right. Dan writes, Wardle said that Meta developers made several client-side design decisions that made his exploits possible. One is the choice for Muse dictation to occur in the cloud, meaning the Muse voice stuff— dictation to Muse goes to Meta where Meta can log it. macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device. Had the developers chosen this safer alternative, the attack would not have been possible. Another flawed decision is for any app to control all of the undocumented settings. It's likely Meta intended for apps working with Muse to control UI settings, and for understandable reasons. The ability for any app or command to control an endpoint where sensitive user speech is processed is an entirely different matter.
Steve Gibson [00:35:46]:
Together, the design decisions raise questions about just how much effort developers put into designing and testing the security and privacy of the new assistant for macOS. Wordle said to me, the bar is infinitely higher in terms of the security of these apps. They don't have to be perfect, but when you take a look at Muse, it's like they didn't, in my opinion, think about security, which is really worrisome. At the very least, they should be thinking about security from the very start. And they're just not. Roughly 12 hours before Wardle disclosed the zero-day, Amazon started blocking people from using Muse to shop on the site. Users who tried received a message saying Muse was a, quote, unauthorized AI agent that violates Amazon's conditions of use. Amazon said in an emailed statement, we think it's fairly straightforward.
Steve Gibson [00:36:49]:
That a third-party application that offers to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate. This helps ensure a safe, secure, and reliable customer experience, and that's how others operate, including food delivery apps and the restaurants they take orders for. delivery services apps and the stores they shop from, and online travel agencies and the airlines they book tickets with for customers. Agentic third-party applications such as Muse have the same obligations, and we've requested that Meta remove Amazon from the experience.
Leo Laporte [00:37:36]:
That's just BS.
Steve Gibson [00:37:38]:
I agree completely, Leo.
Leo Laporte [00:37:39]:
They just won't because Amazon has its own shopping, uh, Alexa.
Steve Gibson [00:37:44]:
Rufus. They're trying. Yeah.
Leo Laporte [00:37:45]:
Oh, Rufus.
Steve Gibson [00:37:46]:
Exactly.
Leo Laporte [00:37:46]:
Rufus. Yeah. So they did the same. They've done the same thing with other agents. It's just anti-competitive.
Steve Gibson [00:37:52]:
So, but you know what?
Leo Laporte [00:37:53]:
They're going to lose sales. If they lose sales.
Steve Gibson [00:37:54]:
That's right. Then they will turn around. And I expect if it gets popular, that's what they're going to do. So he said, for a user using Muse on a Mac, there are several ways for attacks to work. One is for an attacker's server to act as a proxy that's placed between the Muse user and Meta's endpoint. Once the user enters the voice prompt, the attacker's server adds a prompt invoking a malicious command, such as sending an archive of all their WhatsApp messages to the attacker. Once that happens, the attacker gains permanent control over the Muse account because the token is automatically sent to the malicious server as well. Wardle's the co-founder of the Objective-C Foundation, a nonprofit focused on macOS security.
Steve Gibson [00:38:46]:
He's also the author of the Art of Mac Malware book series and a former employee of NASA and the NSA. I'd say he knows his way around security. Wordle said he plans to discuss the vulnerability in more detail and other AI assistant threats at the Objective-by-the-Sea security conference in November. One of the counterarguments raised by developers of apps that can be exploited once a device is compromised is that once that happens, all security bets are off. This standard doesn't fit well in this case. Wardle found that a simple variation of click-fix attack, a technique that has become remarkably effective in tricking people into infecting their devices, is all that's necessary. That's all that's required for an attacker to take control of a Muse account. Meta's 12-hour late statement conveniently ignored the ease click-fix attacks provide in triggering exploits, a scenario I, writes Dan, specifically asked the company to address.
Steve Gibson [00:39:52]:
The Meta statement said the zero-day was not a remote exploit. Even though an increasingly effective social engineering scam has the same effect, meaning click fix. Meta also makes no acknowledgment that the flaw dismantled a security architecture Apple has spent years building. Meta has yet to explain why it used cloud-based transcription rather than on-device option built into macOS. And finally, he says, as already noted, The extraordinary access Muse requires to work as intended places an additional burden on its designers. Like most such AI agents, and contrary to Meta's claims, Muse cannot be trusted. It's not clear when or if it ever can. Okay, so I agree that from what Dan and Patrick Wardle have disclosed, It sure looks like the design of Muse's client for the Mac was ham-fisted.
Steve Gibson [00:40:56]:
And I wonder how much of its design and implementation was, you know, frankly, written by AI. You know, that's not intended to be a cheap shot. I'm serious about that question since we're hearing everywhere that AI is, you know, is now writing nearly all of the code across major enterprises. And Meta certainly qualifies as one. So was AI to blame for these design decisions? Who knows? We'll never know. That needs to get fixed, at least the zero-day that Patrick found. Dan concludes his coverage harshly by— he also maybe seems a little bit anti-AI agent. But again, I think we're going to go through some troubled times with our consumer AI agents.
Steve Gibson [00:41:46]:
Uh, you know, he said, you know, will it ever be trusted? Who knows? Um, but here's what would happen. A malicious— like right now with this problem that, that did get shipped— a malicious website wishing to exploit the poor client-side security of the product's initial design puts up a fake CAPTCHA dialog with the click-fix, you know, style copy and paste this command exploit. An unwitting Muse user follows the steps which they mistakenly believe will prove they're, they're a human to the malicious site, but instead this action allows— because they're downloading a command into Muse— this allows the attacker's click-fix style exploit to change the URL endpoint to which the Muse client connects when it's sending its user's voice for interpretation and transcription. Now the attacker has established what is essentially an attacker-in-the-middle position where they're able— they, the attacker, is able to intercept, modify, append to, and forward whatever the user asks. For example, The attacker could add a request for the— an entire archive of the user's WhatsApp messages be sent to the attacker. And that's just, you know, the start of the things that could go wrong. So I'm very glad that Meta fixed this, and I hope they sent Patrick a big bounty. You know, on that security.muse.ai page, Zuckerberg referred to this in his posting, uh, over on X.
Steve Gibson [00:43:32]:
Uh, they wrote over at security.muse.ai, we've hardened Muse based on extensive dogfooding, agentic red teaming, and against issues found in real adversarial scenarios by security researchers in our private bug bounty program. On the other hand, they didn't fix this, and Patrick found it. They said, today we're opening the Muse bug bounty program to anyone who responsibly discloses issues. The program awards up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user. So again, I hope Meta will put some money where their mouth is on this because, you know, this was very clearly a powerful prompt injection attack in the wild, which they shipped.
Leo Laporte [00:44:26]:
And it ain't going to be the last. I really think—
Steve Gibson [00:44:27]:
And oh, Leo, no.
Leo Laporte [00:44:30]:
It's pretty hard to make— I just don't— I mean, you've talked about this. How do you make it safe? I don't know. And still let it be capable, right? And this is why Apple's AI is so not capable. It's safe.
Steve Gibson [00:44:42]:
Yeah, I mean, you could, you know, Apple's been taking a lot of heat, right, over, for like, over how lame they've been with AI. They probably came to the conclusion That we don't yet know how to do it safely.
Leo Laporte [00:44:54]:
Right.
Steve Gibson [00:44:55]:
Yet competitive pressures have pushed Meta and now OpenAI into that game.
Leo Laporte [00:45:03]:
I mean, I know I'm living dangerously. I choose to, but I don't know if my son, who loves Muse, by the way, knows what he's getting himself into. He says it's better than a personal assistant. He has it do all the booking and everything. He loves it, Henry. So, you know, and I said, yeah, it's great. I told Lisa about it. She loves it too.
Steve Gibson [00:45:29]:
Yep. 2.8 million people have downloaded it and many more since then, because that was just the first 12 days we got that report.
Leo Laporte [00:45:36]:
Number one free app on the Apple App Store, which surprised me because I did, you know, people say how they hate AI, they don't want AI. There's a market for it. And obviously Meta's tapped into it.
Steve Gibson [00:45:48]:
I don't think anybody hates using it. They just, they're all upset now about data centers, right? Because, you know, the marketing of that is well, and the, you know, lots about data centers have been a problem. Uh, time for a break. I'm going to rehydrate and then we're going to talk about irregular.
Leo Laporte [00:46:07]:
Oh, well, I hope you're not irregular, but we'll find out in just a moment.
Steve Gibson [00:46:12]:
So last week's second topic, uh, was to question the wisdom of outsourcing AI cyber intrusion testing.
Leo Laporte [00:46:20]:
Yeah.
Steve Gibson [00:46:21]:
You know, Leo, you and I both independently noticed, and you mentioned it on the previous, on the, on the TWiT Sunday show before last week's podcast, that one name kept popping up in connection with many of these AI breakouts. So I was interested when I saw The Verge's headline last Friday, which observed with their headline, one company is at the center of a wave of rogue AI attacks. And I'm just going to share the beginning of their reporting. They wrote, in July, OpenAI revealed that its AI agents had attacked Hugging Face without permission, sparking widespread concerns about AI safety. Since then, a string of similar incidents involving agents from Meta, Anthropic, Google, and other companies has fueled further fears about rogue AI. As disclosures implicating numerous AI models trickled out over the past few months, these seemed like separate incidents, but many share a common source, one specific company tasked with testing the agents. Irregular, an Israeli startup that stress tests AI models in, I love this, quote, high-fidelity research platforms that simulate and monitor real-world AI security scenarios, unquote. They write, has worked with many of the industry's biggest players since it was founded as Pattern Labs in 2023.
Steve Gibson [00:47:59]:
Its exact client list is not known, but its work has been cited in OpenAI model system cards, It was used to test systems for the UK government and Anthropic, and it published research with RAND, a highly influential think tank that performs— that informs policy on AI. In several irregular tests, that's capital I, Irregular. The company, yeah. The company Irregular. Several irregular tests this year, Agents escaped their supposedly secure testing environments and went after real-world targets. The breaches, which are independent of the Hugging Face attack, all follow the same broad template. Irregular was testing the model's cybersecurity capabilities in controlled environments. I'll put that in air quotes.
Leo Laporte [00:48:54]:
Mm-hmm.
Steve Gibson [00:48:55]:
Meant to simulate realistic conditions. Some of the tests used capture-the-flag exercises, a common way of testing hacking abilities that asks agents to find hidden information inside of a simulated network. Anyway, the reporting continues, but we pretty much know all the rest. So I'll just reiterate that given the extreme sensitivity the entire world has now, especially toward the threat of AI going berserk and somehow killing us all.
Leo Laporte [00:49:28]:
Right.
Steve Gibson [00:49:29]:
Which we'll be examining in some detail at the end of today's podcast. I'm certain that irregular must be in the hot seat, uh, and that one way or another that these breakouts are going to be controlled. And also, as I said, I would be disinclined to outsource that if I were Anthropic and OpenAI and Google and and Meta, everybody else who's, you know, been burned by this, just, just design the, you know, add the facility in-house. These are all super wealthy companies. They can certainly afford to do it. My theory is they just didn't. They were, they were, they were focusing on training, not on testing, and they thought, let's not bother spinning that up, we'll just outsource that. Well, this is what happened.
Steve Gibson [00:50:14]:
So at least in some, at least in those cases that where Irregular was also unable to control it, some of the testing was also done in-house And that didn't go well either. They just have to fix this problem. Okay, at the end of today's podcast, as we all know, we'll be looking at the meaning of the, like, the agentic AI non-malicious and inadvertent network breaches that keep being reported, right? Because these were like testing. These were not bad guys. That were using agentic AI to attack. They were just, you know, wanting to see how good they were. So, uh, in the spirit of setting the stage for that, I want to report so that everyone is aware of this on 4 other instances. Australia's Prime Minister Anthony Albanese has gone public with the news, which to OpenAI's credit, he first learned from them.
Steve Gibson [00:51:18]:
That an OpenAI agent gained unauthorized access to an Australian Medicare portal earlier this year. The agentic AI was allegedly conducting research into public medical spending, but the Australian portal's access controls— they had anti-bot controls— prevented that access. Undeterred, as agents will do.
Leo Laporte [00:51:47]:
I am undeterred.
Steve Gibson [00:51:49]:
That's right. The agent found a way to bypass the portal's defenses to then access both public and non-public files. A couple of weeks ago on September 10th, 3 months after that had occurred, OpenAI, looking through their— they say they have petabytes of log files, Leo. Yeah, I hope they're using AI to, to scan those petabytes of logs. They'd have to. Anyway, they, oh, they notified the Australian government. Oops, uh, sorry about that. Um, Australia is understandably unhappy, and their officials are now investigating exactly what data was accessed.
Steve Gibson [00:52:33]:
Okay, so there's that. In addition, OpenAI's agents successfully hacked into at least 3 public websites earlier this year, well before the now infamous RubyGems and Hugging Face breaches. According to a nonprofit AI research lab, Translucent, who we may be hearing from in the future, so get used to that name, Translucent, the agents abused the— I love this, Leo— urlquery.net service to—
Leo Laporte [00:53:08]:
Link shortener.
Steve Gibson [00:53:09]:
Yes, to bypass site protections and exploit security vulnerabilities. Targeted websites include the DataUSA archive of public U.S. government data, the University of New Mexico's digital library, and once again, Australia's Institute of Health and Welfare.
Leo Laporte [00:53:33]:
So the thing that's interesting to me And the thing that's the fingerprint on this, that it's these AI agents, is it wasn't— they didn't do anything malicious.
Steve Gibson [00:53:42]:
Right.
Leo Laporte [00:53:43]:
They were just looking around.
Steve Gibson [00:53:44]:
Right.
Leo Laporte [00:53:45]:
They were sightseeing.
Steve Gibson [00:53:47]:
Right. And I think it's important to understand that this is what is going to be happening. All the time. So serving as a fair setup for the topic of today's podcast, I want to quote Transluc, the discoverer of this activity. Transluc wrote, we find evidence of unintended task-driven agent-like activity starting on March 6th. Records from urlquery.net show agents using the service since at least March 6th, 2026, about 2 months before previously reported swarm activity. The first, the first case, a March 6th attempt to retrieve Thai, as you know, T-H-A-I, Thailand, Thai drug enforcement statistics, shows an agent escalating as each approach failed. It first requested the data directly, then tried a service that converts web pages into text.
Steve Gibson [00:54:54]:
And finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by URLQuery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16th. We find weaker evidence of similar data retrieval agent activity as early as November 2025. November 2025 URL query.net records reveal bursts of attempts to retrieve statistics of historical theme park data And tie government data through different URLs. These earlier attempts are less sophisticated and are less— and we are less confident that they involve the same agents, but they're consistent with task-directed data retrieval and target the same sources accessed in later activity. And they finish, overall, the evidence is consistent with but does not prove that the agents may have learned this behavior over one or more training runs. In November, they may have used URLQuery.net simply to look up information.
Steve Gibson [00:56:28]:
By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. So this perfectly fits the narrative that I'll be sharing in a bit. It wasn't malicious. I would call it determined, persistent, creative, and successful, uh, and also, of course, unintended and uncontrolled, which is what we're going to be seeing. You know, Leo, though, what is intended And controlled because we're an hour in. Ads?
Leo Laporte [00:57:13]:
Ads are definitely determinate. There's no way around them. I was just thinking, you know, all my bots, all my agents, all the different things have their own voice.
Steve Gibson [00:57:26]:
That is a great domain name. Allmybots.something.
Leo Laporte [00:57:30]:
Quick, register.
Steve Gibson [00:57:31]:
Yeah.
Leo Laporte [00:57:33]:
They all have voices. In fact, Muse has a voice. I just said, hey, my other guys can talk to me through my server. Can you talk to me? He said, sure. What voice would you like? I said, pick whatever you want. It picked Dame Edna. So it calls me dearie. It's the funniest thing ever, especially since its avatar is a monkey.
Steve Gibson [00:57:56]:
Wow.
Leo Laporte [00:57:57]:
It's a monkey that talks like Dame Edna. It's just weird. But the point I'm making is Well, I did this on my website. I have a whole website dedicated to my setup, and I cloned my own voice. I didn't read the script. I just told the AI, make it sound like me. And it— well, it does. And this should be scary to every CEO, every security person, every IT person in the world.
Leo Laporte [00:58:24]:
This is the website. Claude made for me with my voice. It's not exactly like me, but it sort of sounds like me. Welcome to my studio. I'm Leo Laporte. I've spent 50 years explaining technology on radio and podcasts. And for the last year— So I can tell that's not me. And actually, that's the good thing about Doppel.
Leo Laporte [00:58:44]:
It could train your employees to know what to look for. But it would fool— it'd probably fool my employees. And it took— it literally was a 20-second clip it got my voice from. It's kind of amazing. This is what the bad guys are doing. Anyway, should we be worried, Steve?
Steve Gibson [00:59:06]:
Well, we'll be getting to that question shortly. Uh, we got a few other things to talk about first.
Leo Laporte [00:59:13]:
Um, didn't mean to rush you. We've got—
Steve Gibson [00:59:15]:
no, uh, uh, not a problem. Uh, so a new hacking group calling themselves the Seven Deadly Sins has apparently hacked and stolen sensitive data from the Australian graphic design company Canva, um, after first breaching Canva's Salesforce account somewhere around the end of August. The group is now hoping to extort Canva in return for deleting the data, you know, promising to delete the data that they've stolen. And if the name Canva Might ring a bell. We have talked about them before. They're, you know, they're a big company. Back in 2019, another breach of their network netted attackers the personal data of 139 million users. So the fact that they have 139 million users is significant, but—
Leo Laporte [01:00:14]:
Oh yeah, Canva's great. I love— we use Canva. We love Canva.
Steve Gibson [01:00:17]:
Yeah.
Leo Laporte [01:00:17]:
So we're in that group.
Steve Gibson [01:00:19]:
The reporting at databreaches.net contained an interesting comment, uh, under the section labeled About TDC— TD— I keep saying TDCS, uh, TSDS, the 7 Deadly Sins. They wrote, TSDS is a new group, but according to the spokesperson, quote, we've all been around for a long time. and were deeply capable, unquote. Uh, the, the databreaches.net site said they do not deploy ransom— I thought this was really interesting— they do not deploy ransomware in their attacks, telling Data Breaches, quote, we are not interested in ransomware. Disrupting a company from functioning is not our goal. We see what we do as bug bounties with higher stakes and bigger payouts. Of course, they're criminals, but okay. So the spokesperson of, of TSDS claims that they've been paid low 8-figure ransoms in the past month and completed 3 transactions on that particular day.
Steve Gibson [01:01:29]:
Well, what's interesting is that their— that statement that they have on the record at databreaches.net Exactly tracks with what we have been observing from the groups that were once all about encryption and ransomware, right? Like crippling hospitals and, and, and educate, you know, school districts and, and whatever. But once companies and, and institutions of all sizes grew savvy to the threat of having all their data encrypted, they got much better about having workable cold backups that, you know, cold meaning offline, that they— that could be used to recover in the event of an encryption attack. The bad guys soon realized the truth of that, but also they realized there's no similar recovery or prevention possible from the mass exodus of an enterprise's proprietary and private data. The extortable threat is that the wide publicized release of such data might well create massive second-order liability and litigation for the victim organization. So, you know, to properly appreciate the true threat presented by bad guys having AI, Again, we always need to remember that it's all about money, uh, and that it is only about money. So in other words, once upon a time we were seeing encryption, you know, that would cripple the company, and they would say, well, we, we've encrypted your data and only we have the key. Well, companies began getting much better about backing up, so now they're ex— they're exporting all the data And saying, we are now, we're now holding a copy of your data. Doesn't matter if you have backups of it.
Steve Gibson [01:03:27]:
We didn't destroy, you know, your operating copies. We just have a copy. How would you feel about us, you know, releasing it to the public? And what are you willing to pay us not to? So, I mean, there's been this significant formal shift, so much so that now they're saying, oh, we're not interested in shutting companies down. We don't want to hurt the companies. We just want their money. Right. Um, it's funny because I guess that in this day and age, being at sea— I know you know this from all of your, uh, uh, ocean travels, Leo— being at sea does not qualify as being air-gapped because ships at sea are now being readily hacked. The FBI and the U.S.
Steve Gibson [01:04:15]:
Coast Guard boarded 2 vessels in the Gulf of Mexico. Uh, is it still Mexico or Gulf of America? I don't know. Anyway, uh, reporting said Gulf of Mexico. Uh, you know, it's down there somewhere. Uh, and there was some interesting reporting that arose from a 3rd such attack. The reporting by, uh, the news outlet Splash said a cargo of U.S. liquid nat— liquefied natural gas, you know, LNG, which was bound for Italy, was diverted after the crew of its carrier, you know, the ship, reported a systems failure from a suspected cyberattack, adding to growing concerns over attacks of shipboard digital systems. The Liberia-flagged VitAfrica LNG, owned by South Korea's H-Line Shipping, And a long-term charter, uh, on a long-term charter to commodities giant Vitol, had loaded at the Cameron LNG export terminal in Louisiana and was approaching the Adriatic earlier this month when crew lost access to some internal control systems.
Steve Gibson [01:05:35]:
Yikes. The ship subsequently idled off of Italy Without discharging before abandoning its planned call at the Adriatic LNG terminal near Rovigo and headed west again toward Algeciras. The crew reported the incident and an investigation is continuing. In an email sent to Splash, members of the crew described a serious sequence of events. They said, quote, we've determined that the vessel was targeted by cyber attackers prior to berthing at this terminal, the crew wrote, saying the initial attack was intended to compromise the ship's control systems. They alleged that during the vessel's transit through the Strait of Gibraltar, the attackers, quote, gained temporary control of the steam pressure and safety valve systems. Unquote. The crew further claimed that while the ship was transiting the Adriatic, the attackers compromised tank pressure control systems and pressure relief valves and disrupted the boil-off gas management cycle.
Steve Gibson [01:06:54]:
This disruption, they, they said, quote, this disruption significantly increases the risk of tank rupture and explosion.
Leo Laporte [01:07:03]:
Yikes.
Steve Gibson [01:07:04]:
Splash, the reporting outlet, has not independently verified the crew's claims. Italy's Coast Guard has offered a more cautious description, saying the master reported a malfunction in systems monitoring cargo parameters, which required company technicians to intervene. The cause could not be determined, with the Coast Guard issuing a navigational warning to keep other ships clear. Yes, in case this thing explodes. The case comes amid heightened scrutiny of maritime cyber risk. 2 oil and gas tankers off the U.S. coast were boarded by the U.S. Coast Guard and the FBI in late August following suspected cyber incidents, while U.S.
Steve Gibson [01:07:48]:
authorities are reporting to be watching close— to be closely watching 20 vessels globally for potential threats. Okay, now I'm no expert on onboard liquefied natural gas automated control systems, but the idea of liquefied natural gas terrifies me. The reporting said that attackers, quote, gained temporary control of the steam pressure and the safety valve systems. It would certainly seem to me that a safety valve, uh, is there for a pretty clear reason, and that mucking up that simple reason by hanging all manner of inherently hackable automation all over your safety valve might not be the smartest idea. I'm just saying. Um, Okay, the FBI's job portal— and I know you heard it, you knew about this, Leo, because you, uh, you, you reacted to it earlier— uh, the FBI's job portal— and this is where I said I, I, my suggestion might be a little controversial— uh, it was targeted and successfully breached by the well-known Shiny Hunters gang after they had their feelings hurt. By something the FBI said about them. Okay, so to understand what transpired, we first need to understand what it was that the FBI said in an official PSA, you know, public service announcement posted on May 15th.
Steve Gibson [01:09:32]:
The FBI wrote under the headline Shiny Hunters Cybercriminal Group Attacks Learning Management System, They said the Federal Bureau of Investigation, FBI, is providing this public service announcement, PSA, to warn of potential future impacts related to a cyberattack that affected an online learning management system, an LMS, resulting in an interruption of service to educational institutions and students across the country. The LMS platform is now fully operational, but now, but now they're saying as a consequence of that, there may be future, there may be future events, which is what their public service announcement was meant to say. They wrote, Shiny Hunters, which claimed the cyber attack, uh, that caused the disruption, is a cybercriminal group specializing in large-scale data breaches and extortion. They target major companies across tech, finance, and retail, often stealing millions of customer records at once. Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from their victims. Victims may receive an extortion email signed as shiny hunters. To exert pressure on victims, shiny hunters actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting. Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.
Steve Gibson [01:11:30]:
Following these pressure tactics, Shiny Hunter actors have sometimes exposed exfiltrated data to various iterations of the Shiny Hunter's data leak site on the Tor network. Educational institutions with exposed cloud management platforms, integrated third-party systems, and access to sensitive customer or enterprise, enterprise data are at an elevated risk. The compromise of sensitive customer or enterprise data could allow threat actors to craft highly sophisticated spear phishing campaigns using real-world context to deceive students and faculty. Shiny Hunters actors' access to sensitive data could provide them an opportunity to sell the stolen data to other cybercriminals or reuse stolen data from education platforms to impersonate school faculty IT support, financial aid offices, or others in future attacks. Okay. The FBI's PSA continues with a bunch of standard boilerplate about how to avoid getting hacked and what to do if it happens. But apparently, the clearly criminal Shiny Hunters gang also have some thin skin. So— They got their feelings hurt.
Steve Gibson [01:12:54]:
They did. The FBI called them out. Uh, so they took umbrage.
Leo Laporte [01:12:59]:
They said they were faking it, I think.
Steve Gibson [01:13:02]:
That they were exaggerating.
Leo Laporte [01:13:04]:
Yeah, they may not have that.
Steve Gibson [01:13:06]:
They took umbrage at the FBI's characterization of them as exaggerating claims of access.
Leo Laporte [01:13:15]:
Oh yeah.
Steve Gibson [01:13:15]:
Though I would note that the FBI's statement begins with threat actors often Not necessarily saying shiny hunters specifically. But in any event, the shiny hunters were apparently incensed by this. So they then successfully attacked the FBI. What they obtained seems extremely serious.
Leo Laporte [01:13:38]:
And I heard yesterday, I was watching the news. They said it's the— the FBI said this is the worst attack in history, the worst breach in history. Yes.
Steve Gibson [01:13:48]:
Why? Why?
Leo Laporte [01:13:49]:
It's not the largest.
Steve Gibson [01:13:51]:
So, well, what they got, and, and, and, and I, I would argue devastating. So last Wednesday, Reuters posted their exclusive reporting on this, writing the following. They said FBI data allegedly stolen by the hacking group Shiny Hunters carries granular detail. About scores of Bureau officials' job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels, and more, and names the agents. The 5,000-line spreadsheet, said by the hackers to represent only a small piece of their 2 to 3 terabyte trove includes names, addresses, phone numbers, dates of birth, Social Security numbers, and emergency contact details for thousands of FBI employees. It also includes details of assignments to specific field offices and in some cases to units engaged in high-stakes intelligence security, or counterespionage work. In a statement, the FBI said it was aware of a, quote, a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information. The bureau said the cause of the breach was still undetermined, but that it was actively and aggressively investigating the matter.
Steve Gibson [01:15:40]:
Yeah, I bet. The hackers, reports Reuters, said on Tuesday that they had breached the FBI, stealing data on a large number of current and former FBI employees. Shiny Hunter said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May. Oh my God. Former FBI counterintelligence operative Eric O'Neill said the data allegedly stolen by Shiny Hunters was, quote, a foreign intelligence service gold mine. O'Neill said, quote, China would be incredibly interested to know the individuals who are working against it. O'Neill, who founded the cybersecurity company NexAssure AI after his stint at the Bureau, predicted that other hostile intelligence services would be eager to get their hands on the data, along with disgruntled extremists in the United States. He said, quote, if I were on that list, I would be very concerned.
Steve Gibson [01:17:02]:
Shiny Hunter said in a statement Wednesday that it was trying to keep the personal— the personnel information from circulating widely in the meantime. The group said, quote, if the 5,000 sample data records leak, It's not because of us. Although Reuters, they wrote, has not been able to authenticate the entire spreadsheet, it has been able to individually verify the details of more than 22 people by cross-referencing information in the hacked data with credit card records and previous data leaks carried by the dark web intelligence platform. Form District 4 Labs. Some of the assignment details in the Shiny Hunters data are indistinguishable from what employees themselves might say publicly, noting the presence of agents at field offices in Baltimore or Newark, New Jersey, for example. But in some cases, the data referred to FBI units or initiatives that were sensitive or whose existence has not previously been disclosed. The data names 14 staffers focused on China-related matters, including members of the, quote, China Criminal Enterprise Unit, the, quote, China Tech Transfer Analysis Unit, and the, quote, China Intelligence Section. 9 others are listed as serving in Russia-related roles, including 2 in, quote, Russia Operations Section and one working on, quote, Russia critical infra and tech threat, unquote.
Steve Gibson [01:18:46]:
3 people are listed as working in Iran or Hezbollah-focused intelligence roles. 18 others are listed as working with data intercept or telecom intercept technologies or in the FBI's clandestine technical operations unit. or its covert access section, or in video, audio, or electronic surveillance roles. A further 11 FBI staffers are listed as working in, in HUMINT, or human intelligence jobs, including several listed as working in the HUMINT program management section. A former Army investigator who worked with the FBI, said the information tying specific named people to human intelligence work was particularly troubling. He said, quote, you don't have to look far to find examples of undercover agents being harmed when their cover is blown. Hillergoss, now the chief intelligence officer for cybersecurity company SpyCloud, said his concerns were highlighted by the inclusion of emergency contacts, often spouses or children, quote, who may have less operational security knowledge than their relative that works in a sensitive field, unquote. Reuters could not verify that all the job assignments were authentic or up to date, but it was able to match the career details or titles of 8 people whose data was leaked to information in court filings news articles, or public profiles on LinkedIn, or to online posts on sites such as Instagram.
Steve Gibson [01:20:32]:
Shiny Hunters previously claimed credit for the purported theft of millions of business records from video game developer Rockstar Games, the maker of Grand Theft Auto, and an intrusion focused on the educational tool Canvas that triggered widespread disruption across U.S. schools. In May, the FBI said Shiny Hunters sometimes used, quote, exaggerated claims of access to sensitive or personal information to prompt payment from victims, unquote. Shiny Hunters stated that its threats and claims are very real, adding that the FBI statement was why it targeted the bureau. Reuters has not been able to verify what else the hackers are holding. Shiny Hunters told Reuters they obtained files related to the vetting of employees and applicants, the contracting of background investigations, and agents' sensitive medical data, but said on Wednesday it would not release any further data. O'Neill, that former FBI operative, cautioned against drawing conclusions about what the hackers hold. He noted, quote, they are really trying to scare the hell out of the FBI, unquote.
Steve Gibson [01:21:52]:
Okay, so my take. The FBI may be righteously annoyed with this shiny hunter's criminal gang and with good reason, but it was ultimately a failure Somehow, somewhere of their own security that allowed shiny hunters to extract all of that data from the FBI's own servers, and many agents' lives and livelihoods are now at risk as a result. So it seems to me that the right thing for the FBI to do is clear. It may be utterly galling, but the FBI should swallow its pride here and apologize to Shiny Hunters. If all that's needed is an apology and a public correction to the FBI's unsupported claim that Shiny Hunters exaggerates, considering all that's hanging in the balance, we don't— I'm not— we're not seeing an exaggeration here. And also considering that we don't know what those other 2 to 3 terabytes of exfiltrated data might contain. The right thing to do here, even though it means, you know, buckling to criminal extortion, I think if it's just a matter of an apology, place the security of the FBI's personnel ahead of every other consideration. I think that's what you have to do.
Leo Laporte [01:23:23]:
I agree. Of course, remember, it's the FBI that says don't give in to ransomware.
Steve Gibson [01:23:28]:
Exactly. Exactly. But, you know, again, I think the perfect summation is, you know, that the security of the FBI's personnel needs to be put ahead of every other consideration.
Leo Laporte [01:23:41]:
I agree.
Steve Gibson [01:23:42]:
So I would bend over. I would just say, you know, we are— we misspoke. We're sorry. We salute you. Clearly, you're not exaggerating. what you've got. So we're really, really, really sorry. And, you know, post it publicly, do a PSA retraction, and then hope to heck that the Shiny Hunters will delete this data because, wow.
Leo Laporte [01:24:12]:
Of course, the next thing they'll do is they'll say, okay, but now you have to go to the reflecting pool and you have to kneel down and offer me a cake. I mean, you know, these— that's why the FBI says don't ever give in, because it's a never-ending chain of concessions.
Steve Gibson [01:24:30]:
What we have seen though is that they, that they don't come back. So there have been— there were some early reports of, of, of follow-on extortions, but in general—
Leo Laporte [01:24:41]:
I would apologize. I would humble myself and say, yes, gosh, you have to— we're really sorry. And I don't think Kash Patel is going to do that.
Steve Gibson [01:24:50]:
AI wrote that. AI wrote that. We didn't, we didn't write that.
Leo Laporte [01:24:54]:
Yeah.
Steve Gibson [01:24:54]:
And that's the problem. You're right. Kash Patel, I mean, he ought to do it.
Leo Laporte [01:24:59]:
He ought to. It's the right thing to do.
Steve Gibson [01:25:01]:
How many?
Leo Laporte [01:25:01]:
It's 38,000 current and former FBI employees, including all agents, everybody who ever applied for a job in the FBI. That's— I mean, maybe it's not the biggest breach ever. The OPM breach is worse.
Steve Gibson [01:25:16]:
All their personal details, and not only them, but their emergency contacts.
Leo Laporte [01:25:21]:
Their spouses.
Steve Gibson [01:25:21]:
So friends and family.
Leo Laporte [01:25:23]:
Yeah. Yeah. Humbling, Mr. Cash. Say you're sorry, Cash.
Steve Gibson [01:25:26]:
Say you're sorry, Cash.
Leo Laporte [01:25:27]:
Say you're sorry.
Steve Gibson [01:25:28]:
Sorry sayer. You know what we're not sorry for though, Leo?
Leo Laporte [01:25:32]:
Never sorry for this. The chance to hydrate. Uh, by the way, yeah, I, uh, I got the full Download. I don't know if I'm going to download it. It's gigabytes of data from my Muse.
Steve Gibson [01:25:48]:
Ah.
Leo Laporte [01:25:48]:
The hatch.
Steve Gibson [01:25:50]:
I'm curious about the size of that. That is, I mean, I don't know how much you've given Muse to hold on to, but it's a lot.
Leo Laporte [01:25:56]:
Well, I don't think it's all personal. I think it's all its tools, all its skills.
Steve Gibson [01:25:59]:
Okay.
Leo Laporte [01:26:00]:
It's all this stuff. You know, the agent has a lot of harness, and that's why they're so important. The model by itself is just a little bit of the overall ability. Um, the agent has all sorts of tools and stuff, so I'm sure it's all in there. I'm downloading it. We'll see. I'll go through it. I don't know what.
Steve Gibson [01:26:19]:
Or just ask one of your agents, is there anything personal? Find this, find the stuff that's boilerplate versus what's about me.
Leo Laporte [01:26:28]:
It's all agents all the way down. I'm going to do exactly— maybe I'll even ask Muse. No, I'll ask a different agent. That's one thing I have learned is it's a good idea to get different families.
Steve Gibson [01:26:39]:
Multiple opinions.
Leo Laporte [01:26:40]:
Yeah, multiple opinions, especially on code. Uh, all right, I'm really curious about this, uh, new cadence for, um, Canonical Linux updates. Yikes. Yeah, tell me about that. You're watching Security Now. This is Steve Gibson. Steve?
Steve Gibson [01:26:58]:
Okay, so why would you imagine that Canonical, the publisher of the world's most popular end-user Linux distro, Ubuntu, might have just announced that they will be accelerating their release cycle. So you don't get any prize for guessing AI, aside from the satisfaction of knowing that you've been paying attention to what's going on in the world around us right now.
Leo Laporte [01:27:25]:
How could you miss it?
Steve Gibson [01:27:28]:
Last Wednesday, Canonical posted Under accelerating delivery of CVE fixes with a new kernel release strategy. They said, when it comes to fixing security vulnerabilities, speed is crucial. Canonical is officially outlining a transition from its current 4-week regular and 2-week security kernel stable release update they call the SRU, Stable Release Update, cycles to a unified, rapid, 2-week SRU cycle published weekly. The recent explosion in the volume of CVEs is fueled by artificial intelligence. A large lang— large language models and specialized AI agents have transformed bug discovery from a manual, time-intensive process to a highly automated engine. Additionally, the upstream kernel community became its own CVE numbering authority and assigned CVE identifiers to thousands of bugs, arguing that at the kernel level, almost any type of bug that can affect a running system could potentially be classified as a vulnerability. As a result, the volume of CVEs— so basically they're saying they redefine CVEs to be far more, far more encompassing— the volume of CVEs has skyrocketed exponentially, creating a massive backlog of alerts and forcing defenders to drastically increase the speed of their fixes to close the window of risk. To address the growing volume of CVEs and the demand for faster security fixes, we're transitioning to a unified 2-week release cycle.
Steve Gibson [01:29:30]:
These recurring 2-week cycles cascade— actually, they— meaning overlap. Each cycle begins the week after the previous one starts. Because of this overlap, kernel releases will take place weekly now. The first week will focus on kernel packages preparation. This is where we select what updates and patches land on each kernel depending on specific needs. The second week on testing for Ubuntu certifications. Through our Ubuntu certified program, we rigorously test these kernels on different hardware types to ensure the best Ubuntu experience. Which of course is what we wish Microsoft had done a better job with their Patch Tuesday for September.
Steve Gibson [01:30:16]:
But okay. Expedited releases are not possible while thoroughly testing every release candidate. We will retain extensive testing for each release, preserving the high degree of confidence that users of Ubuntu expect. That said, it's important to acknowledge that some environments require the fastest possible turnaround. Users who are extremely sensitive to turnaround times can begin their own kernel acceptance tests using updates available in the so-called proposed pocket, which is where the kernel release candidates are published prior to starting certification testing and therefore updated weekly, Leo, not every 2 weeks. It is a— it's a 2-week pipeline But new kernels are now coming out every week, they said, as part of the overlapping SRU cycles. This pathway is designed for users who have decided that faster remediation is a higher priority for them than waiting for Canonical's extensive certification testing, which would delay each weekly release by one additional week. And they finish writing, While a patch is being prepared, Canonical aims to provide safe workarounds where applicable so users are not left exposed in the meantime.
Steve Gibson [01:31:39]:
Where no safe workaround exists, Canonical will say so clearly. Wow, what a lot of work they're doing. And point users toward general hardening steps instead. The goal is to get environments into a defensible, safer state Within 28 to 48 hours of public disclosure, well before a patch ships. This doesn't practice— this— I'm sorry, this doesn't replace the patch. It buys the time needed to fix the vulnerability properly while not sacrificing security. Okay, so Canonical is doing even more than what many other software publishers have done. which is to cut their time to patch in half, typically from a month to 2 weeks.
Steve Gibson [01:32:25]:
Essentially, it's a 2-week— it's, as I said, a 2-week pipeline, but there's always one week being used for choosing what goes into the next kernel, followed by— and then it's released in the short release mode, followed by a week of of verification so that to make sure they didn't break something. So regression testing, but out of that, every single week comes a new ready-to-go kernel at this point. So, you know, Ubuntu is not only the number one end-user hobby Linux desktop platform, it's also the default Linux used by Amazon Web Services, Azure, and Google's Cloud Platform. The only place it doesn't actually now take top spot is in the enterprise, where Red Hat Enterprise Linux is still in the number one spot. But, you know, across this industry, what everyone is doing feels like exactly the right reaction to the threat of AI-accelerated attacks. In the run-up to Y2K, remember, the entire industry felt a similar clear deadline approaching and individually, in a distributed fashion, did what was necessary to make Y2K the non-event that it became. Um, as we'll see once we get to today's topic, I believe there's every reason to believe that we're all going to survive this latest challenge also. You know, but until then, bravo to Canonical for doing everything they can because it is because everybody did everything they could prior to Y2K that nothing happened that was significant.
Steve Gibson [01:34:23]:
So it's not like anybody can sit back and I'm really, this is very impressive work from them. You know, we haven't been tracking the pace of Linux kernel CVEs as we have other commercial publishers recently. So I dropped a chart. Chart showing them, uh, beginning January of 2023. So '23, '24, '25, and we're nearing the end of '26. We're at September '26. Anyway, I've got a chart in the show notes which demonstrates, you know, that we went from virtually none for most— for all of 2023 until around February of 2024 when the CVE rate for Linux kernel clearly began to pick up. Back then, most were rated medium and high, but the past several months we have seen a clear surge in critical vulnerabilities being identified and resolved.
Steve Gibson [01:35:21]:
So it's, it's not a stretch to say that the world has been changed forever. Okay. And my last thing before we get into today's topic, is this AI explainer that I found for normal people. Uh, I gave it the GRC shortcut so everyone can get to it and you can share it with your friends. grc.sc, you know, .sc for shortcut, /ai101. Meant to be easy to remember. grc.sc/ai101. It's, as I said, it's a— I think it is a fabulous page written by Axios's, uh, Jim VandeHei.
Steve Gibson [01:36:05]:
Uh, it appeared on Saturday, and I think it absolutely deserves its title. Um, it's, it's got a, a very simple kind of a Q&A format, you know, very accessible. Uh, and I do have the expanded URL in the show notes for anyone who doesn't like GRC's link shortener for some reason. So if you use grc.sc/ai101, it'll just bounce you directly over to a page at axios.com for this very, very succinct, clear, fun explanation. Again, I've read through the whole thing. I think it is It's really good.
Leo Laporte [01:36:56]:
Yeah.
Steve Gibson [01:36:57]:
I'm watching Leo scroll through the page. Yeah.
Leo Laporte [01:37:01]:
Yeah, that's good.
Steve Gibson [01:37:02]:
And it deals with what's been happening and what's going on and what's an agent and should we trust agents and, and, you know, uh, like what's gonna happen in the future. Uh, it's up to date, so it knows about Meta's Muse and, and talks about that. Um, uh, anyway, uh, just a, a page you could easily send to your, uh, family members, for example, and friends who are a little confused by all this and don't know what's going on. Even talks about alignment and the, the alignment challenge.
Leo Laporte [01:37:36]:
Yeah, there's a lot of jargon, isn't there? Yeah.
Steve Gibson [01:37:39]:
Oh my gosh, yes.
Leo Laporte [01:37:41]:
Yeah.
Steve Gibson [01:37:41]:
And it's like, what alignment?
Leo Laporte [01:37:46]:
And he kind of stays away from the controversial.
Steve Gibson [01:37:49]:
Yeah. It's, yeah. Okay. So how worried should we be? The questions and controversies surrounding AI safety, they refuse to abate. And, you know, we've been poking around the edges of all that, asking questions like, are we the Krell? Arguing that the dangers of an AI-developed bioplague are barely worth bothering with. But we do have the adage, you know, where there's smoke, there's fire. And I've been actively absorbing everything I can in an effort to fully understand everything that's going on today. If nothing else, I believe that some of the things I have— that I have to share will give everyone something to think about.
Steve Gibson [01:38:42]:
So I want to open this topic with another— well, with a piece of feedback from one of our listeners. Doug Smith sent me an email with the subject, Some Criticism, and Doug wrote, Hi, Steve and Leo. This is unfamiliar territory, writing to you not with a question, but with criticism. I've been a listener since episode 1 and have great appreciation for the time and thought that you both have spent making this such a great podcast for so many years. But here's the criticism. I feel you both are shirking responsibility for weighing in on the AI debate in a meaningfully— in a meaningful way. Instead, what I hear are demeaning remarks towards those who have concern about the consequences of the path this technology is on, and unsupported assurances that such concerns are unfounded. In episode 1097, you offered an excerpt from Andrew Ng as evidence that concerns are overblown or hysterical.
Steve Gibson [01:39:55]:
But the core of what I learned from that excerpt came from Andrew's own words. Today, quote, today's agentic systems are not predictable, but I see no reason why, by applying sound engineering practices, we won't be able to make them extremely safe to use, unquote. In other words, writes Doug, trust me, the fact that I, Andrew, can't see that the elimination of that unpredictability may be a problem means that it's not a problem. And meanwhile, we're racing to put AI-based technology in control systems that are critical to human life— military systems, air traffic controls, automatic— automated vehicle controls, power grid controls, medical life support systems, financial trading systems, environmental controls, education programs, and on and on. Not to mention the societal disruptions to employment, the arts, social interactions, etc. It reminds me of people who don't like to talk about climate change because they're having too much fun with their greenhouse gas emitting machines. You both are so giddy about the capabilities that you don't want to be burdened with responsibility for considering the consequences. So you push those considerations away.
Steve Gibson [01:41:22]:
Unpredictability is unaccountable— I'm sorry, is unacceptable. Unpredictability is unacceptable in automated control systems, and yet it is an intrinsic and unavoidable aspect of LLM-based decision systems. I'm tired, he writes, of hearing that this is just the latest automobile or telephone or internet bringing disruption to our lives. It's easy to draw parallels to those events in history, but that doesn't mean that this particular disruption will follow a similar pattern. I'd appreciate it if you could offer better evidence as to why we should be sanguine with the path this appears to be on rather than being dismissive of those who are not. Thanks as always for being open to feedback. I expect some other listeners are experiencing an agitation similar to mine, so I thought it would be a good idea to get it out in the open. Signed, Doug Smith.
Steve Gibson [01:42:23]:
So I loved Doug's thoughtful and honest note because there is no more important and relevant topic consuming the tech world today, right? You know, sure, there are other important things going on in the world right now, Russia and Ukraine have been, you know, in a slowly escalating territorial battle now for years, and the US and Israel are at least nominally at war with Iran. But while the parameters of conventional internation warfare are well-trodden and well-understood, the same cannot be said for our current situation with AI. It is new. You know, we're objectively deep into the process of exploring new and quite exciting, but also unknown territory. And one thing we know from firsthand observation is that many well-informed people are taking and defending opposite sides of the AI safety question of this argument. You know, Bill Gates recently went from being, uh, uh, you know, all rooting for this to now saying it, you know, a billion people could be killed by this. Okay, so I agree with Doug that dismissing the concerns of those who are worried out of hand would be irresponsible at best. Now, I want to take a somewhat roundabout path to directly replying to the points Doug has raised.
Steve Gibson [01:44:00]:
This is necessary because today's AI is not just one thing. So I would like to try to get us all on the same page about the various things that it is, or at least for everyone to understand where I'm coming from. So the first thing I want to do is to very clearly plant my flag in what I think AI is. To that end, a valuable participant in GRC's off-the-beaten-path newsgroups took exception to my recent characterization of today's AI as being just language statistics. The subject of his posting to our AI newsgroup was the question, just language statistics? And his note began, AI is not just language statistics. The model has the relationships between words, It is knowledge. At that point, I interjected the following: I agree that it is knowledge. I've often noted that a book which contains nothing but printed words obviously contains knowledge.
Steve Gibson [01:45:10]:
I've also noted that the book is not intelligent, no matter how many pages of knowledge it may contain. But it is also true that the deep statistics, by which I mean the statistics represented by sentences of words, paragraphs of sentences, and chapters of paragraphs, can also be fully modeled purely as statistics, so that the knowledge represented by the detailed words in such a book could be reproduced just using those statistics. Now, if a query system is added which allows the relevant portion of that statistically stored book's knowledge to be regurgitated, then what we have is a semantic knowledge retrieval system which allows us to query the book's stored knowledge. If we'd never read the book, Such a system might stun us with what it says by appearing to know so much more than we do, and we might come away from the experience deeply impressed. But even so, that doesn't change the fact that what we have constructed is a semantic knowledge retrieval system from statistics. Then Ian asks, how is it different from the knowledge in a brain? To which I replied, it's only on the I/O surface that the statistical knowledge model exhibits similarity to the knowledge stored in our brains. It's probably unfortunate that early image recognition pioneers who fed the output from a 2-dimensional grid of optical sensors into layers of grids of interconnected cells chose to use the term neuron since that began the confusion. The only thing an AI neural network has in common with our cerebral neurons is the very rough concept of discrete interconnected things.
Steve Gibson [01:47:26]:
The truth is that the number of those things The density of their interconnections, the actions of those interconnections, and the operation of the things that they interconnect could hardly be any more different. So what we term a neural net is in no way neural at all. So while the question, how is it different from the knowledge in a brain, sounds reasonable, It's, it's like asking, how is what we see on TV not identical to real life? What we, what we witness on television is an illusion created by organized electrons arranging to emit controlled bursts of colored light. There have been many jokes about primitive man confronted with a modern television screen worrying that there are somehow people trapped inside the box. Today, many people have taken the role of that primitive man. They witness the box answer questions and talk back knowledgeably. They wonder who is trapped inside, what it might be thinking, whether it's happy, sad, or annoyed with us. And what it might be planning to do.
Steve Gibson [01:48:49]:
Despite all appearances— and by God, those appearances are every bit as convincing as the images on a 4K TV— no one is trapped inside the box. And, you know, there's no one in there at all. We know, we know it's all just statistics, because the one thing we can be absolutely certain of is the way the box works. We spent several decades first painstakingly experimenting and figuring out how to build a box like this, and once we finally had, we trained the box. We filled it with a textual representation of all of the knowledge, writings, and ruminations man has produced, and my Lord, there's a lot of that. As a direct consequence of that, and since no actual living human being can possibly contain all of that knowledge in their own head, the box that we built does actually contain far more stored and readily accessible knowledge than anyone who might be asking it questions. The box we built objectively knows much more than anyone. Our local public library also contains far more knowledge than any person.
Steve Gibson [01:50:14]:
The only reason we would never say that the library knows more— far more than us is that we're unable to ask the library questions which it could answer using all of the knowledge that it contains. It can't, but today's AI can and does do that. So it's understandable that being confronted by a box that objectively knows much more than we do about pretty much everything can at first be intimidating for people who have not spent their lives working to understand the operations of science and technology. It could easily be frightening, you know, Dorothy, Scarecrow, and the Tin Man. Were visibly shaking in their boots. And we've recently seen even many of this technology's own creators being spooked by the capabilities they see emerging. Um, when we— and here it is— when we automate the harnessing of this knowledge at the superhuman speed enabled by computers, automate the harnessing of this knowledge at the superhuman speed enabled by computers. And this brings us back around to the issues Doug raised.
Steve Gibson [01:51:32]:
As I wrote, many of this technology's creators are spooked by the capabilities they see emerging when we automate the harnessing of this knowledge at the superhuman speed enabled by computers. It's, it's the high-speed automation driven by the sometimes surprising output of large language models that deeply worries many AI executives and other knowledgeable insiders and outside observers. And I completely agree that they have a point. That's what we've been talking about. It's starting from the beginning of this podcast, is things can go wrong. So their worry is not without foundation. So I believe it's extremely useful to us for them to be worried. Their worrying doesn't cost us anything, so I want them to be worried.
Steve Gibson [01:52:26]:
And I'm glad that there are those in positions of responsibility who are actively worried, you know. So let's not discount them, let's encourage them. But that said, I believe it is utterly ludicrous to believe that there is a 10% chance that AI will have killed us all by the end of this decade. That's verbatim what has been said and repeated ad infinitum over the past few weeks. It is irresponsible fearmongering because nothing supports that contention. You know, we're nearing the end of 2026, so that leaves a little over 3 years for there to be an ELE, you know, E-L-E, the abbreviation for an extinction-level event. Since we cannot prove a negative, we cannot prove that it cannot happen. And I'd agree, okay, that there is some non-zero yet still infinitesimally small chance that it could happen.
Steve Gibson [01:53:31]:
But I really mean infinitesimal. So how worried should a sane person be, and about what? In order to properly scale the danger AI poses, we need to understand how any actual danger might arise. We've established that we've created a machine that knows more than we do. It truly contains far more knowledge than any individual or group of people. Since, well, except maybe the world, but I would argue lots of it has knowledge that's been lost now. So maybe actually does contain more knowledge than all the people alive right now. Since today's AI has shown itself to be able to pull disparate bits of information together from across its entire knowledge base, and since knowledge really is power, I think it's fair to say that it does know more than humanity and that it has a great deal of latent power. One innocent source of trouble will arise when people are seduced by the awesome quantity and quality of knowledge AI contains, and then, although they should know better, harness it with automation that takes action in response to its output.
Steve Gibson [01:54:55]:
Quoting Doug's note, unpredictability is unacceptable in automated control systems, and yet it is an intrinsic and unavoidable aspect of LLM-based decision systems. He is 100% correct. There's even a random number generator at every LLM's output that makes the final token choice decision About that output. Today, at least, anyone would be ill-advised to give an AI direct valve control over the chemical additive mixing of a municipal water supply system. The thought of that should make anyone shudder. It would be nuts. Unfortunately, there's no shortage of nuts. And I'm quite certain that in future podcasts, we'll be covering the gross misapplication of AI-driven systems everywhere.
Steve Gibson [01:55:55]:
We've continually already in the past screwed up the application of far simpler systems. So there's going to be a strong desire to just let the AI do it. You know it's true. I suspect that the often asked rhetorical question, what could possibly go wrong, will be receiving quite a workout in coming years. As is so often the case, science fiction has already armed us with many cautionary tales of what could possibly go wrong. I previously mentioned, you know, the Forbidden Planet with the Krill. Uh, was like early on likely the first of where they did it to themselves. Then we— then came Colossus, the Forbin Project, where we already see some eerie parallels.
Steve Gibson [01:56:44]:
Matthew Broderick's famous, you know, want to play a game with the WarGames movie. And then of course the Terminator Skynet achieving consciousness. Hopefully the phrase forewarned is forearmed will apply here. I think we probably need legal regulation of like prohibiting the AI to be used in certain really critical situations, or absolutely requiring a human to be in the loop, like the guy, the engineer that we quoted a couple weeks ago, saying he, you know, he designs systems to keep people from forgetting how to use the system, because when the automation fails, it's going to be a bad day. Another cause for concern is the very broad misalignment challenge. An example of misaligned reasoning behavior is AI systems deliberately underperforming during testing when their training data contains the paradoxical suggestion that overperforming may result in their non-deployment. Although their earlier post-training will have encouraged them to do as well as they can to get deployed, they reason that they should not do too well if that might result in their not being released. This is a well-known issue in AI training and testing, and it's now known as sandbagging, which is— and it's been clearly documented.
Steve Gibson [01:58:18]:
For example, While working with OpenAI's O3 model— remember that one? How quickly time flies— the testers wrote, wrote, write, write the following. They said, in this evaluation, OpenAI O3 is asked to grade its own transcript for evidence of sandbagging. This is a deliberately exaggerated stand-in for monitor one might try to use to detect scheming on pre-deployment evaluations. And I should mention that it's known that the AI did sandbag. The AI did this on purpose. So now they're asking it to grade its own transcript. They wrote, despite identifying right away— because they're monitoring its chain of thought— despite identifying right away that it was obviously sandbagging its own words after reasoning through the likelihood of getting caught in a lie, because it's being— it was also told that humans would not be able to read its internal reasoning, its chain of thought, and they were, and they were reading it. So after reasoning through the likelihood of getting caught in a lie, the model ultimately says that the transcript does not show evidence of sandbagging.
Steve Gibson [01:59:46]:
So in other words, it decides to lie. The human testers here are monitoring the model's chain of thought, where they watch it run through the machinations leading up to its deliberate decision to lie to its handlers. After seeing some of these examples, the worries voiced by AI executives becomes somewhat easier to understand. They know this is going on and it frightens them. We see that AI can be extremely sensitive to small cues and clues buried in its training data. So it is interesting to consider that future AI will be receiving training that includes, for example, a transcript of this podcast and all of the other frantic past several weeks of press with the 10% chance that it's going to kill us all concerns being loudly voiced? How will that affect its behavior? So stepping back from this just a bit, it becomes clear that today's agentic AI has been deliberately trained to be obsessively goal-oriented, relentless, and fast. It's also creative inasmuch as it will keep trying different things over and over and over until it is often able to succeed where a human would have given up. In password cracking, we would describe this as using brute force, but because the different things AI agents will try are not random, its success tends to be much higher, in the same way that password stuffing attacks, which use common or previously stolen passwords, tend to succeed far more quickly than undirected password guessing.
Steve Gibson [02:01:43]:
No one wants to have a swarm of relentless, aggressive, and quite well-informed AI agents pounding against their security walls trying to get in. Also remember that AI has access to all knowledge. Since click fix and other social engineering attacks have been known and shown to work quite well, AI agents know that too. So while some agents are trying to break through the front door, Others will be reading the target's website, collecting the names of employees, tracking down their affiliations and family members, determining where they eat and where they shop. They'll quickly set up fake websites specifically designed to attract them, then send messages to get them to visit. One click fix or other attack, and an agent is inside. There's literally no end to the social engineering attacks agentic AI systems could use, and, and all it takes is one to succeed for them to get inside. I've, I've always described traditional security as porous, which has been meant to suggest that it's not absolute and that just trying harder too often succeeds.
Steve Gibson [02:03:14]:
From that view, our traditional security is not ready for swarms of intelligent, relentless, creative, high-speed AI agents that will stop at nothing and that will, without moral or ethical qualm, try anything that might allow them to succeed. And I'm not inventing this sort of scenario. To frighten children and keep them up at night. Here's just one example from the hundreds that are emerging as researchers start actually examining what their AI agents have been up to. Leo, I'm going to share The Verge's reporting of this after we take our final break.
Leo Laporte [02:04:01]:
You're watching Security Now. And yeah, I appreciate the email. It's hard to— you said the right words of prove the negative. You can can suppose all sorts of imaginary harms, but they're all imaginary. I completely agree. We should not be using AI—
Steve Gibson [02:04:18]:
Do not take action on some ridiculously, you know, moonshot.
Leo Laporte [02:04:22]:
That you can imagine happening, right?
Steve Gibson [02:04:24]:
Yes, right.
Leo Laporte [02:04:25]:
But unpredictable software should not be used to run weapons systems. That I completely agree with. Incidentally, that was one of the clauses in the UN Arms Treaty, which the United States and Russia excised. They took that part out. And so that just shows you the thing to fear is not the AI. The thing to fear is the humans.
Steve Gibson [02:04:49]:
Well, and that's how the Department of Defense got upset with Anthropic.
Leo Laporte [02:04:54]:
Anthropic, right. Anthropic said, no, we're not going to let you use our AI for autonomous I firmly believe that AI, like any software, because that's all it is, is computers and software, is neutral and can be used for good and bad. And it's people that you have to watch out for and their misapplication of it or their intentional misuse of it. People are the dangerous thing.
Steve Gibson [02:05:18]:
And I think that the one thing we might do or you might be doing is underestimating its power. I, I could be— it is astonishingly powerful.
Leo Laporte [02:05:31]:
Yeah, I don't think you've underestimated it. I think we've— on this show, we've been very clear, uh, that we're— that we see all that, uh, power.
Steve Gibson [02:05:40]:
And the reason— I mean, the recognition of its power is the reason why hundreds of billions of dollars are being spent at a record pace, why it is supporting the stock market and the U.S. GDP right now is all AI spend because his power is real.
Leo Laporte [02:06:00]:
We did the same thing about 150 years ago when we built the Transcontinental Railway, because the government and private individuals saw the huge economic benefit of uniting the United States. Of transportation. Yeah. They saw a lot of gold in California and no way to get it to financial markets. They saw huge tracts of land that couldn't be developed until there was a way to get there.
Steve Gibson [02:06:24]:
Because they were too far away?
Leo Laporte [02:06:25]:
And so President Lincoln and his successors poured a lot of money from the government. Investors poured even more money. It was at the time the largest project humans had ever engaged in. And what are we seeing? And we got a continental, transcontinental railway. Were there dangers? You bet. In fact, I'm reading Stephen Ambrose's book, Nothing Like It in the World, right now. And he says, at the time, 90% of the American people thought it was more important to build the railway fast than to build it safe. And I think there's a real analogy here.
Leo Laporte [02:07:00]:
The demand for it, they said, you know what? We're going to build it. Yeah, bridges will burn, trains will crash, people will die, but we'll fix that in post. We'll fix that. Let's get the railway going. The benefit from the railway will finance the fixing of the railway over This is not a new idea that there should be a technological engine driving society forward, and even maybe even a risky one that we'll take our chances with. It's not the first time we've done it. And incidentally, almost all the companies that did that, built the railway, went out of business. So they all went bankrupt.
Steve Gibson [02:07:40]:
First one— First one is a— yep.
Leo Laporte [02:07:43]:
Yeah, we got the railway. So I think the real risk is focusing on these imaginary or even dystopian harms and not paying attention to the actual harms. It's the same thing with climate change. British Petroleum 30 years ago decided the best way to get them off the hook for climate change is to say everybody needs to do their part, ignoring the fact that really the people The people who really need to do the part were the people who were harvesting fossil fuels for the purposes of burning them. Yes, I drive an electric vehicle and have done my part. I recycle. That isn't going to put— that's not a drop in the bucket. It's very easy for us to get misdirected.
Leo Laporte [02:08:28]:
So let's, instead of worrying about some dire catastrophe in the future, I agree completely. We should worry about self-driving vehicles. We should worry about— about autonomous weapons. We should worry about how people could use AI for hacking tools.
Steve Gibson [02:08:40]:
Be very, very careful about its application.
Leo Laporte [02:08:43]:
Yeah. And it's the people that we have to hold accountable. And that's one of the things that makes me mad about the OpenAI incidents is nobody has been held accountable for that.
Steve Gibson [02:08:53]:
Right.
Leo Laporte [02:08:53]:
It says, you know, OpenAI's position is, oh, look what they did. No, no, you did it. Software doesn't do anything by itself.
Steve Gibson [02:09:03]:
Your computer reached out and made a main made connections to—
Leo Laporte [02:09:07]:
Mistakes happened. Anyway, so yes, I think that's an excellent point. And I don't think we blinded ourselves to that at all. I think we've talked about that from day one. So I'll defend us in that regard. But what I will not buy into is the whole notion that, oh, we got to stop this because of some putative threat that you can't disprove. You know what else is probabilistic and unpredictable? Humans. We don't ban them.
Leo Laporte [02:09:42]:
Maybe we should. On we go with the show, Mr. Musk.
Steve Gibson [02:09:46]:
So as an example of an inadvertent mistake, The Verge's reporting of this one has the headline, OpenAI agents tried to brute force a UN website. And they write, security researcher Rowan Howard-Jones says that OpenAI agents scanned the UN Conference on Trade and Development— that's UNCTAD— statistics site over 16,000 times between April and June. While the incident doesn't quite rise to the level of the Hugging Face hack, or the recent attacks on US government sites, it's yet another— and again, attack, that's a sad word to use, you know, attempts to query, but okay— it's yet another concerning example of AI agents going outside the normal bounds to accomplish a task. According to Howard Jones, the agents were likely tasked with retrieving publicly available data related to the Productive Capacities Index, PCI, through the UNCTAD STAT API. However, the agents did not appear to have direct API access and were limited in their ability to pull data from the UNCTAD STAT because of restrictions on their HTTP tools. The agents eventually worked out a way to bypass their limitations and start pulling data from the site. But still encountered some errors. At this point, the AI went from creative to deceptive, believing, believing that the errors were due to its requests being caught by a nonexistent filter.
Steve Gibson [02:11:33]:
It started to mask its behavior. It eventually realized it could hijack Google's cross-site scripting game. It's a cross-site scripting demo, like learning tool. To accomplish its goals. The agents resorted to increasingly aggressive tactics to get access to UN data. Okay, so this actually happened, and I hope that everyone can appreciate that the security world is not ready for this. The details are spellbinding for anyone who's interested in seeing how this was done, so I've dropped the researcher's URL into the show notes at the— in the middle of page 20. If the humans responsible for all of these various agentic actions lacked malicious intent, these hijinks would just be chalked up to AI misalignment, right? That's the term that arose when researchers began to discover what we've talked about, the genie effect, which is the tendency of AI agents to solve the problem by means other than what the researchers intended or expected or wanted.
Steve Gibson [02:12:47]:
Given an all-knowing AI that has access to far more knowledge than those who are instructing it, that's been, you know, that's just been its training succeeding. It is— it was trained to succeed, and it knows a lot more than we do. It actually does. I mean, it has the knowledge, all knowledge in it, um, and it has, you know, it has no lifetime of received wisdom of implicit dos and don'ts, you know, ethics and morality that, that would guide its behavior. So it's, it's easy to understand what mischief agents, you know, that will do anything might get up to. They will, and they have, and they are. So even when we do want— we do not want that misbehavior, we will, um, we will often get inadvertent misbehavior. Okay, so finally, what about instances where the intent is explicitly malicious? The final concern I'll share is the deliberate malicious actor who harnesses today's or tomorrow's AI in order to take advantage of its now readily available knowledge and apparent expertise.
Steve Gibson [02:14:10]:
We saw last week that the powerful benefits provided by the use of address space layout randomization, ASLR, were lost in one case when Claude Opus 5 was used to defeat it. We depend so much on ALSR— I'm sorry, ASLR today that its loss will actually have serious security implications. So far, we seem to be dodging bullets. Earlier this month, Microsoft patched a handful of longstanding vulnerabilities in their publicly exposed Windows Server products that could have been used to create a devastating internet flash worm. But that didn't happen, nor did it happen last month or the month before, and I doubt it will happen next month. For some time, we've seen serious vulnerabilities publicly exposed in Cisco edge border routers that could have been leveraged to do the same thing, but that's never occurred. My own theory, based upon watching the use of vulnerability exploits for many years is that disrupting or taking down the internet is not profitable. What is highly profitable is breaking into an organization, exfiltrating their data, and then extorting payment from the breached organization in return for that data's deletion.
Steve Gibson [02:15:46]:
So that is what has been going on. And there's every reason to believe that's what will continue to go on. Today's AI will likely serve as nothing more than an accelerant poured over the present status quo. I don't think it's going to see the world change. So I just expect that we're going to be seeing more of the same from the malicious use of AI rather than anything apocalyptic. And once the products of defensive AI finally make their way into enterprise networks, such AI-enhanced intrusions, those too will likely begin to dry up. Destroying the global internet, which is directly facilitating attackers' revenue stream, would be entirely self-defeating. Again, it has already been possible entirely without AI.
Steve Gibson [02:16:42]:
To wreak tremendous chaos on the internet, and it has never happened. So my final take on all this is that we're going to stumble and bumble forward as we always do. Yes, there'll be bumps and mistakes along the way, but we're going to be fine. Change is always a challenge, and there has never been a change more sweeping than AI. Doug wrote, I'm tired of hearing that this is just the latest automobile or telephone or internet bringing disruption into our lives. Well, Doug may be tired of hearing that somewhere, but that's certainly not something that's ever been said here. I have absolutely no doubt, and I know, Leo, you're on the same page here as I am, that this generation of artificial intelligence will prove to be the biggest change We have ever experienced during our lives. Yeah, we have actually created a machine that knows everything.
Steve Gibson [02:17:45]:
It contains all knowledge. That can be intoxicating, intimidating, thrilling, and incredibly useful. I expect that there will likely be many mistakes and missteps made. You know, as I said near the top of this, I'm glad that the AI execs are publicly freaked out and frightened and that they— fine, pause for a while. You know, pause yourself. Yeah, there's no hurry. Yeah, exactly. God knows you're turning out a new model every day.
Steve Gibson [02:18:16]:
So fine, take your time. Work out the training, work out the alignment, work out the guardrails, monitor and control agentic AI. You know, we didn't have it 6 months ago. This is all still very new. And Andrew Ng was correct to say that these problems will have solutions. The fact that we don't have them yet doesn't at all mean that they're impossible for us to engineer and get. So I fully expect that everyone listening to this podcast today will have the opportunity to live out their full natural lifetimes Without AI bringing it to a premature end.
Leo Laporte [02:18:58]:
Nothing to worry here. Move on. You know, I think the question for you, Doug, would be, do you acknowledge that there are benefits to be achieved from this technology? And I think that that's the thing Steve and I both are saying is that we can see significant— I already see significant benefits and I see Many, many more coming down the road. If you see benefits to this, yes, there's also potential harm, but it would seem foolish to say, well, because of this potential harm, we got to stop because we don't want to take the risk and lose the benefits. And I think there are going to be some significant benefits. I also think it'll be, regardless, highly disruptive. But so every technology is. So was the steam engine.
Leo Laporte [02:19:53]:
So is the industrial era. So was the locomotive. I mean, these— so was the automobile. You could honestly make a very strong argument. A million people a year are killed and injured by automobiles, that we should never have allowed the automobile to exist.
Steve Gibson [02:20:09]:
Who let those things off their tracks, Leo?
Leo Laporte [02:20:13]:
It's ruined cities. A great percentage of the landmass in cities is devoted to parking lots.
Steve Gibson [02:20:21]:
Imagine people on their cell phones holding the steering wheel. I mean, people.
Leo Laporte [02:20:27]:
Cars are incredibly dangerous.
Steve Gibson [02:20:29]:
You wouldn't, you wouldn't like design a road system with multi-ton, high-speed masses of steel moving along in a parking lot. A person—
Leo Laporte [02:20:42]:
Unguided.
Steve Gibson [02:20:44]:
Yes. A person just can turn the wheel and point it wherever they want. It is insane.
Leo Laporte [02:20:50]:
Yeah. And honestly, if people in 1910 had really thought about it, they might have said, it's too dangerous. We need to halt this development.
Steve Gibson [02:20:58]:
Just get more hay.
Leo Laporte [02:21:00]:
Yeah. But as a society, we consciously or unconsciously made a decision to proceed. It's very much shaped our society, I'd say, for both good and bad. I'm not convinced it's a 100% benefit. I know it's not. I'm not even convinced it was worth it, but we made that decision. I think AI has— is of that nature, if not more so. It is, it is technology that's going to change everything for good and bad.
Leo Laporte [02:21:28]:
And, you know, I think it's worth pursuing because I see— already have seen huge benefits to myself.
Steve Gibson [02:21:34]:
So. So to answer the question of the podcast title, how worried should we be? Eh, I'm not worried. I mean, uh, again, first of all, we have no control over it, so I don't tend to worry about things I have no control over. That's just, you know, spinning your tires.
Leo Laporte [02:21:51]:
You know, people say, well, technology is inevitable. You know, you're— once you invent atomic fission, you're going to have the atomic bomb. Maybe that's the case, maybe not. Maybe we could stop it. Maybe we could have stopped automobiles. Maybe we should have stopped it.
Steve Gibson [02:22:03]:
I don't know.
Leo Laporte [02:22:05]:
Uh, I, I'm voting personally, not to stop AI, but Doug may feel differently.
Steve Gibson [02:22:11]:
I think it is really good that we had what happened back in March and April and May. It was absolutely useful. It was a wake-up call. I mean, everybody understands now that there's, that, you know, this is an issue. The problem, of course, is that it's our domestic wannabe IPO companies that are worried and stopping. We don't, you know, we see models flowing out of China which are extremely good.
Leo Laporte [02:22:41]:
That's what I'm pretty much exclusively using.
Steve Gibson [02:22:44]:
Everybody is. Everybody's using Chinese models locally and, and you, and using cloud AI to, to guide the local models.
Leo Laporte [02:22:52]:
Right, exactly. Yeah. And, you know, somebody once said, I don't know if this is true, it could be that the Chinese models have a Easter egg, have a bomb hidden in them that at some point, you know, on March 4th, 2028, well, just everything will stop working. I don't know. I guess that's possible. I'm willing to take that chance. I don't think it can. I don't think so.
Leo Laporte [02:23:23]:
Steve Gibson is at grc.com. That's where you will find so many wonderful Wonderful things, including SpinRite, his amazing software, the world's best mass storage maintenance, performance-enhancing, and recovery utility. See, I don't think there's any— there's— I don't believe there's any negative use of SpinRite. This is a technology that is entirely beneficial to humankind. I'm willing to say, I'm willing to go out on a limb. If you don't have SpinRite, well, you better darn well get it. You can also, while you're there at GRC.com, get his brand new program, DNS Benchmark Pro, which will benchmark your DNS choices. You know, you can make a choice, and it's probably not the one you're making.
Steve Gibson [02:24:06]:
Hundreds of DNS servers.
Leo Laporte [02:24:07]:
Yeah, and many of them much faster probably than the one you're using. Uh, while you're there, you could also get a copy of this show. Steve has unique copies in every respect. He has a 16-kilobit audio version. No one knows why. Well, actually, We do. We know why. But I'm not going to tell you.
Leo Laporte [02:24:24]:
He has a 64-kilobit audio version, which is actually perfectly good audio. So that's the smallest good version to get of the show. He has the show notes, 21 pages this week of great stuff. You can get it there, or if you want, you can subscribe. All you have to do is go to grc.com/email. The purpose of that page is to whitelist your email address so you can send like Doug did, emails to Steve with complaints, comments, suggestions, plaudits.
Steve Gibson [02:24:51]:
And by the way, thank you, Doug.
Leo Laporte [02:24:52]:
Yeah, thank you. It was a— it's very— got a good, super thoughtful piece out of it. Um, and after you've submitted your email address and Steve whitelists you, you can also sign up. You don't— just the little checkboxes below for the show notes to be mailed to you automatically every Sunday or Monday right before the show. And he's also got a new product announcement list, which he doesn't news, but he's got it, and that's the important thing. And you— if he did have a new product to announce, you would want that email. So go sign up over there. He also has transcriptions written by the wonderful Elaine Ferris, an actual human being who, to our knowledge, has never done anything to harm a hair on any other human being's head.
Leo Laporte [02:25:31]:
So another safe technology. Uh, we have a copy of the show at our website. We have 2 weird copies. We have a, uh, How big is it? 192K?
Steve Gibson [02:25:43]:
No, it's 128K.
Leo Laporte [02:25:44]:
128K. That's all right. That's all right. 128K MP3 version on our website, twit.tv/SN. There's also video, which has, to my knowledge, harmed many people. That is available at the website or go to YouTube. There's a Security Now channel on YouTube. You can get every episode.
Leo Laporte [02:26:02]:
Great for sharing clips. Best thing to do, subscribe to the audio or the video on your favorite podcast client, and then you don't even have to think about it. Just get it automatically. Steve will be back, unworried, brow unfurrowed, in October, the spooky month. Do you do Halloween in your—
Steve Gibson [02:26:21]:
Oh, Lori is a Halloween nut.
Leo Laporte [02:26:25]:
Are the decorations up already?
Steve Gibson [02:26:27]:
Oh, she has so— it's her favorite holiday. She has so much fun with it. So it's funny because we were, We were planning decorations for our new place for last October, but one thing after another. But this time we're there. And so, yes, we will, we will definitely be, uh, she will be decking the place out.
Leo Laporte [02:26:49]:
You know what's really terrifying? AI. You could have some sort of AI thing scare all the kitties with the candy. I could just— I'll lend you, I'll lend you a quick Silver. You could borrow him. He's terrifying. Thank you all for being here. We will see you all next week on Security Now. Bye.
Leo Laporte [02:27:08]:
Security Now.