Loading...
Loading...

You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone.
Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open?
All this and more in episode 483 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.
EPISODE LINKS:
SPONSORS:
SUPPORT THE SHOW:
Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!
FOLLOW THE SHOW:
Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.
THANKS:
Theme tune: "Vinyl Memories" by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.
At what stage was this surprise, you know, we locked 15 murderers in a room you'll never
believe what happened next.
Sorry, you can tell I used to work at BuzzFeed.
Smashing security Episode 483.
Who's AI helps Steve steal your iPhone?
With Graham, Cluely and Special guest James Ball.
Hello, hello, and welcome to Smashing Security Episode 483.
My name's Graham, Cluely, and I'm James Ball.
James, great to have you back on the show again.
You've been keeping busy out of mischief, I hope?
Horribly busy for an August, actually.
I think when you're a freelancer, it's a much busier month that people realise because
whatever else is on holiday, you're working.
Yes, miserable, isn't it?
Anyway.
But at least we've had a little bit of rain, so that's good.
I'm hoping Finchery Park will look less like, you know, the aftermath of a disaster movie
in a bit more like a park, because it's usually lovely.
Yes.
Less like the Calahari, hopefully.
Well, before we kick off, let's thank this week's wonderful sponsors, Threat Locker,
Intruder and Vanta, we'll be hearing more about them later on in the show.
This week on Smashing Security, we won't be talking about how the Hacker who leaked footage
of GTA 6 cashed out his cyber leak cryptocurrency for about $270,000, just hours before the game's
launch.
You'll hear no discussion of how malware hidden inside a Chinese wallpaper app encouraged
users to disable their antivirus, and we won't even mention.
How an exposed API key helped hackers still 86 gigabytes of customer data from Manchester
Airport Group.
So James, what are you going to be talking about this week?
Well, I'm looking to zoom us back a little bit from a whole bunch of the sort of cyber security
routes going on around AI models, and just looking to a bit of what it's telling us and
how significant it is, because I've had a couple of interesting conversations around
that.
And I'm going to be finding out how AI is helping to steal Apple iPhones.
All this and much more will come up on this episode of Smashing Security.
This episode is sponsored by intruder now Joe Quickquiz.
How often does your team ship code?
Multiple times a week.
Maybe more if someone's had too much coffee.
And how often do you get a proper pen test?
Ooh, once a year, if we remember, well that's the problem right there.
Software moves weekly, pen testing moves yearly.
So most of what you ship never actually gets tested properly, which is exactly the gap
intruders AI pen testing closes.
You get the depth of a real manual pen test, but on demand whenever you need it.
No scoping calls, no six week wait, and it costs a fraction of the traditional price.
It's built by intruders own certified pen testers, so the agents catch the complex stuff
human testers can miss.
And every find in is validated against your actual app.
All issues, not noise.
You get an audit ready report within hours.
And it plugs straight into intruders full platform, attack surface monitoring, cloud security,
vulnerability management, all watching around the clock.
It flags what's exploitable, what to fix first, and how.
So your team can act without waiting around for the security team.
Over 3000 companies already trust intruder with their attack surface.
You can kick off a pen test in minutes and as a smashing security listener, get 25% off
your first one.
Cool.
So just head to intruder.io-smashing.
That's intruder.io-smashing.
And thanks to intruder for supporting this show.
Now chums, chums, we are just days away.
I don't know how excited you are about this, James, but we are just days away from Apple
announcing a new version of its iPhone.
It is widely expected that on Wednesday, September the 9th, Apple is going to announce not
just the iPhone 18 Pro, presumably with about 17 cameras stuck on the back of it, but
also the iPhone Ultra, the first foldable iPhone.
Yeah, I'm still not sold on foldable phones, but I am an absolute certified Apple fanboy.
I think I've got every bit of tech they've put out in the last decade except the VR headset.
So I have very much a mark for this.
And if Eddie Watt is going to get me to buy a foldable phone, it's going to be Apple.
I mean, the thing with Apple is they're not always the first to have a technology.
I think Samsung on there is a lot of Android phones which have been foldable for probably
years by now, but Apple sometimes this implementation can be better or bring something new which makes
everyone change in their wake, doesn't it?
They've had a good habit of waiting till a technology is actually ready so that it's
not the finicky thing that only an early adopter could love, but everyone will just go,
oh yeah, this is great.
And that does mean I do tend to sit and wait for them to do something because usually
they find out the kinks.
There's a bit of few misses.
There aren't too many kinks in their foldable iPhone, but of course it will mean that there
will have never been a better time to have had your phone stolen because if you're going
to have it stolen, have it stolen just before Apple comes out with a brand new one, especially
one which has something a little bit different about it which you can get excited about.
You know, it's the silver lining on the cloud, isn't it?
It is.
If you ever had a phone stolen, Grown?
I've had a phone slossed before.
I've lost my iPhone in the back of a cabin Edinburgh in the past and I was able to track
it for a few days as the taxi driver.
Oh, God.
I did eventually manage to get it back, which was quite miraculous.
Thank you to that taxi driver eventually, but it is a very stressful situation, isn't
it?
It's very stressful because your whole life is running off one of these things.
Yeah, I got mugged for my phone once.
Oh, my goodness.
There was a spate of muggings where people stopped stealing jewelry and stole phones hoping
they were crypto wallets on them.
And clearly I had the look of someone who might have a crypto wallet on his phone because
they didn't just steal the phone.
They kept beating me up to try and get the password.
Oh, my goodness.
And try and get into the banking apps.
And luckily for them, I keep my phone on such low battery that I gave them the passwords
because they had a knife.
So they had the password, but the phone battery died and I'd managed to lock it.
I got home about 10 minutes after I locked it remotely before they could power it back
up again.
So they only got the phone.
But because I'd had to reset all the passwords and I didn't have the phone, I had about
a month of admin work.
It was awful.
And there was a very stern woman on the bank call line who when I said, well, no, I've
had to give my security password.
So, oh, you're not supposed to give those out.
I was like, yes, I know.
As I told you, he had a knife on me when I gave it.
You know, I wasn't just skipping through the streets saying my banking secret word is
X.
Yeah, awful.
But that is a truly horrendous situation.
I wonder if some people will actually begin carrying around two phones with them.
So if they do get stopped, you give them the rubbish one.
You give them the old Nokia brick.
That's all I've got.
I'm afraid that you're welcome to it.
Honestly, the crime I was sort of okay with, but they're endless out of it to get it
back.
Right.
I ended up writing up in a Sunday times.
Oh, so you got something out of it at least.
So genuinely, I got about 650 pounds for the Times article, which I worked out was my
phone access, the headphones, and worked out at being for the time I'd spent about half
minimum wage.
Oh, the calls.
So I sort of came out even-ish.
Well, it's a very stressful experience clearly, both having your phone stolen and the
aftermath as well.
And I'll tell you something else, which is a stressful experience.
There's something else stressful that happened in my life is, James, I want to tell you about
a little game which my wife likes to play with me in bed.
I feel like we've got a new genre for this podcast now.
So I'm going to take you and our listeners a little insight under the covers, as it were.
Let me give you the challenge, actually.
So the person who stole your iPhone from you, what word would you use to describe a person
who steals something?
They are a-
A mugger?
Thief?
A thief.
Yes, a thief.
Now, my wife finds it very funny because of how I pronounce the word thief.
Oh, so-
Yes.
So as she often likes to point out, there's no TH at the end of thief.
And so I've approached this story with great trepidation because I know she will be listening
and she'll be going, oh my god, you've done that on the podcast.
You said thief instead of-
I don't know if I'm doing now.
Thief, right?
Yes.
Okay.
Is it for-
I've been trying to-
You know, the leader of a tribe.
A cheese.
Oh no, I got one.
No.
Sorry, I feel like I'm just mocking a speech impediment here.
It's completely fine.
A cheese is easier.
I think it's because of teeth.
Maybe.
I think that's why there are some words that if you do a regular podcast, you do find you
a lot of comments, not just from members of your family, but listeners as well.
Last week I couldn't pronounce subpoena properly.
I've probably done it incorrectly again now.
No, that was right.
That's right.
I've often had a problem with seizures, which apparently-
Yes.
Seasha's.
Yes.
Yes.
Like Julius Caesar.
Yes.
For instance.
Seasha salad.
Seasha.
Anyway.
So that is a little game that she likes to give me.
She likes to try and trick me into saying words in order to see here that I'm still sending
them in cricket.
I just want to say right up front that I may well say the word thief, thief, incorrectly
during this section.
Right.
Okay.
We've got that out of the way.
Maybe I'll just say robber instead.
So what happens when your iPhone actually gets stolen?
Is it normal that some kid just flogs it down the pub or is there something more organized
actually going on?
And the truth is that iPhone theft, despite the best efforts of Apple and the cops, it
continues to be a big, old problem.
And boffins, threat intelligence firm, sock radar.
And by the way, sock radar, what a magnificent name that is for a company.
It's kind of delightful, isn't it?
Yes.
It's something I need when I get out of bed in the morning.
Something that's kept in my head.
At least you know what they're freebies are going to be.
So they've just shared their investigation into one iPhone crime outfit called a non-emouse
or maybe it's a non-emuse kit.
And it is a criminal SaaS operation.
So they are like a real company.
They promote themselves online.
They offer customer support.
They've got a telegram channel where they've got testimonials from happy customers.
But their entire business is all about helping you make the most out of a stolen iPhone.
So if you are a robber of iPhones, you might turn to a non-emuse kit.
And the problem they solve is that since 2013, so for over 10 years, Apple has had this
feature built in called activation lock.
And activation lock, it ties your iPhone to your Apple ID.
So even if it's stolen or even if there's been a factory reset, if you tried to set up
that phone as new, it will ask you.
In fact, it will demand of you that you'd log in before you can do anything, before you
can change in the settings.
And the old loophole with that used to be your passcode.
So your four digit or six digit passcode.
So someone who stole your iPhone could reset your Apple ID password straight from settings.
And there was no old password required to do that.
They could turn off the find my iPhone capability, react to your phone, go and sell it down
the pub.
But these days, Apple's stolen device protection, it requires Face ID and touch ID, not just
the passcode plus.
There is a time delay built in.
So if you're doing anything sensitive like changing the Apple ID password, when you're
away from a familiar location, it'll make you wait a while, giving the true owner of
the phone time to market as lost.
So that has meant that stolen iPhones on their own are as useful as a brick as you discovered
yourself, right?
They need a password.
They need something to get in to your device.
And if there is, although there's an interesting side market on this as before what you're
going to come onto, which is so this sort of organized phone snatching and they're often
stolen and then buried in parks for a day or two.
Genuinely, literally just left in the soil in public parks for a day or two.
Oh, wow.
Which is to check if people are using find my and I've got to try and be vigilantes and
sort of hunt it down, etc.
And then they're picked up about a day or two later on mass.
People know which flower bed they've been left in and they'll go and dig out 20 stolen
phones.
And then they're it's cleared and they're shipped off to China where they are sort of jail
broken in some way then and sold there.
And so that's that's one mechanism.
But as I understand it, it's not especially lucrative versus perhaps perhaps perhaps the method
I'm going to describe.
Yes.
It gives you an indication of just how valuable these things can be if they manage to get
passed all the security.
I mean, things like the iPhone Ultra, I think they're predicting it may cost as much as
$1,900.
$2,000, I think.
Yeah.
It's going to be a absolute fortune to have this bloody thing which you can bend.
So enter anonymous kit.
So this is a fishing as a service platform.
So criminals pay a subscription to be part of the group.
They plug in details of a stolen phone and the platform does the rest.
What it does is it tracks down the owners.
It tricks them into handing over their passcode, their Apple ID, no flick knife required,
and their 2FA code as well.
And these swines who stole the phone, they don't have to do anything.
So it starts off simple enough, this particular text.
So you've lost your phone.
You get an email or text claiming to come from Apple saying, good news.
We found your lost device and there's a little map embedded in the HTML of the email.
So this is its last known location.
So it looks really real to you and you think, okay, that's clever.
That is legitimately clever.
Yeah.
But then it gets smarter because then you get a call from someone called Alice from Apple
support and she introduced herself.
She says her name is Alice Diaz.
Presumably she's got a brother called Buenos.
And she says I work for Apple support and that for quality assurance and security purposes,
the call is being recorded.
So it all sounds legitimate.
Yep.
It all sounds official.
And she asks you to confirm that you're the owner of the phone and she asks you to read
out your passcode to verify your identity.
She says that someone brought the phone into an Apple store that she says, don't worry,
a member of staff spotted it was in lost mode.
So someone came into the store, maybe with the phone saying, oh, I've got a problem,
can't log in or whatever.
The person, the genius behind the desk has said, oh, epistume lost mode, we're going
to retain this for security reasons.
Maybe this suspected something.
And Alice says that they opened a recovery case as a result.
So this is a service that Apple is giving you.
It spotted that this phone has been stolen.
Spotted it didn't belong to personally for a living.
They want to verify who the true owner is.
And so they say, we will send you or you may already have received a text with a security
link.
And it's that link, which the person is tricked into clicking into, which takes them
to a web page, which then asks for all of the information which is required to reset
the phone.
So Apple ID password, the six digit two factor code.
And there you go.
You've handed it all over to the crew.
And of course, typing in a two factor code feels about right, doesn't it?
Yes.
We're doing it all the time.
Yeah.
You start to get told we won't ask for it on the phone, etc.
But typing it into a web page, that's exactly what we do.
Now here's the thing, Alice Deus.
She's a smart cookie.
She doesn't just speak English.
She speaks Spanish and Portuguese as well.
But anonymous kit doesn't employ huge swathes of people to make phone calls.
I haven't got humans working for them at all.
Instead, subscribers to this service are renting an AI voice agent to trick you into
handing over the information.
And when the experts at Sockrader recovered some of the transcripts, they found it was
pretty convincing.
So they could see where victims were reaching out their numbers.
And even if they paused midway through, the AI agent would actually come back to them.
Okay, yeah, I've got one, two, five, what comes next.
And so you would think you were genuinely speaking to someone.
And of course, voice AI these days is so much more convincing than it used to be, even
if you're having an interactive conversation with a voice AI, there's not as much of a
delay as they used to be.
It does say much more convincing.
Yes, it does.
I thought I'd try and make that sound a bit robotic.
And the thing is, this is really cheap.
So the researchers say they saw evidence of hundreds of these Apple phone calls trying
to fish the numbers and the pass codes from people trying to steal iPhone.
Each one of them was costing about 10 cents per call.
And it's operating on scale as well.
So there are 168 different storefronts, apparently out there using the same underlying code facility.
So it's been rebranded.
Lots and lots of different places.
Lots of places criminals can go to actually affect something like this.
So you could be buying it from one person, but it's actually using the services of another
criminal group as well.
And of course, once someone's in, they can often steal more than just the phone.
Like if they've managed to unlock it, they can sometimes empty a bank account, they can
sort of move money with PayPal, they can buy things from online stores.
Your credit cell wallet.
Yes, if you've got a crypto wallet, it can really be in trouble.
So if it's 10 cents extra to attempt this, the economics of this are wildly in their
favour.
I wonder what you have to dress like to suggest that you don't have a crypto wallet.
I'm just thinking of what you just said about having been stopped because these guys
assumed you must be into cryptocurrency.
Yeah, yeah.
I'd imagine either being a pensioner or maybe a woman who looks like she has a functioning
social life.
I think those two groups might be fairly safe.
So this voice fishing traffic, 90% of it in this particular case, which Sock radar uncovered,
and by the way, they uncovered it because of slopping us by the criminal gang.
They left some of their web server logs unprotected and so they were able to see the transcripts
of the conversations.
They're able to see some of the underlying infrastructure as well.
90% of the voice fishing traffic, which they spotted was aimed at Brazil, but they have
been other victims elsewhere in the world, including South Africa, Italy, India and Kenya.
But I guess the overarching message which I have for listeners this week, so let's say
this in a bold underlying font, is no legitimate Apple support engineer is ever going to call
you up and ask you to read your passcode out loud down the phone or enter it onto a website
if your phone is ever stolen and someone calls you to tell you it's been found, but your
identity needs verifying the extremely cautious because it could just be a 10 cent attempt
to try and make an awful lot more money out of you, more than information which is stored
on your device.
And presumably, I want to check, I know this right here.
If you do get sort of notified that your phone's been found, there's no reason that someone
else would need to unlock it.
It could stay locked and on lost mode until it's back in your hands and then you can take
it out of lost mode dead, right?
There's no time except when you've got your phone back with you that you would ever
need to give this to someone, is that right?
That is absolutely right.
Now, there is always the danger of course because when your phone has been lost, you can
send a message to it, so if anyone picks it up, it will say, you know, I am lost, please
call Graham on this other number or contact me via this mechanism.
There's always the danger that someone will say to you, come and meet me down this back
alleyway and I'll have the phone back to you.
There they could have their flick knife or whatever in order to get all of your details.
So yeah, trade with caution folks.
This week's episode is supported by Vanta.
Joe, what's your two AM security worry?
Honestly, whether I remembered to hit the record button.
No, no, no, what's your proper security worry?
Like, do I have the right controls in place?
Are my vendors secure?
No, I'm still worried we might not actually be recording.
Okay, look, how about the really scary one?
How on earth do I dig myself out from under all of these ancient tools and manual processes?
Okay, fair enough, that does sounds scary.
Well, enter Vanta.
Vanta automates the manual misery so you can stop sweating over spreadsheets, chasing
audit evidence and filling in endless questionnaires.
This writes the trust management platform continuously monitors your systems, centralises
your data and uses AI to flag risks and keep you audit ready all the time.
So whether you're chasing sock two ISO 27,001 GDPR, HIPAA, Vanta helps you move faster,
scale confidently and actually get back to sleep.
So get started at vanta.com slash smashing, that's V-A-N-T-A dot com slash smashing and
listeners, you can get a thousand dollars off.
And thanks to Vanta for supporting the show.
Joe, you did hit record, didn't you?
Me.
Yeah, it was your job.
I thought it was you.
James, what have you got for us this week?
I've been tracking what feels like a never ending saga of each of the big AI companies
saying, oh no, we've realized we've accidentally hacked something.
And it's quite entertaining watching this sort of on blue sky.
It started with open AI.
I think maybe about a month ago now saying that it had discovered that its agents had
gone rogue, broken out of a sandbox and hacked into hugging face.
And then sort of about a week or so later, anthropic said that its AI models had broken
out, but they'd broken into the systems of three different organizations.
They were trying to outdo open AI, weren't they?
It felt like anthropic marketing to pump thought, oh, why didn't we think of that?
What a great way to get us load to publicity.
This genuinely started to feel like that because about a week later, Meta said, oh, by the
way, we have an AI model and it hacked something too, honest.
Not with mixed levels of convincingness, but like to be fair, they look to have been
actual instance here with some quite sophisticated hacking and we're sort of still seeing details
come out on this.
And let me stress that there are, of course, three separate hacking instance here, they're
involving agents and so sparkly reasoning is art.
We only have what different companies have released and then it's filtered through different
journalist stories of this.
So this is my understanding at the moment, which may differ from other ones.
So I do apologize to any listeners if they think the details are off, but there's there's
sort of one of the interesting elements that everyone's been talking about in the last
week is that agents that were supposed to be sandboxed were collaborating with each
other and communicating with each other.
Yes.
Now, a lot of people seem to find that very exciting and very emergent and very sort of,
it started up a whole new row of consciousness debates that I don't actually find very
interesting.
The way reasoning models work is they actually that scratch pad that they use to support
their thinking acts as a scaffold.
It actually serves as part of their prompt and their engineering and encourages them to
use different tools or access different agents.
And so it's built into the models not just for a sort of audit trail, but for how they work
into constantly use scratch pads and chat.
And it's also built into them a lot to look for prompt to look for interaction.
And so it shouldn't be a surprise that if they find something where they can leave notes
and where other agents are leaving notes, they communicate in that way.
That's essentially getting shocks that a tool is doing more or less what it's been designed
to do.
This isn't some evolution or emergent behavior in a way some people are suggesting.
What is kind of interesting is that they shouldn't have been able to be talking.
So the scratch pad that they were using was this thing called artifactry, which is essentially
a sort of bunch of tools, but they shouldn't have been able to access that.
And what seems to have happened is that the sandbox either had a flaw or was incorrectly
configured.
Yes.
And the sandbox company is not clear who it is.
Now is this someone at OpenAI making a mistake?
Is there something else?
But basically, first they could get into artifactry and communicate with the other agents.
And then they found that they could use an exploit within artifactry to browse the internet
indirectly.
And so they had access to the open internet and thus could get information that the researchers
had denied to them that then suggested other routes out.
And then they managed to escalate their privileges in artifactry and get admin control.
And that's basically when it was spotted.
And it looks like the other two, the better hack and the anthropic hack were related and
all used the same sandbox.
Yes.
So it may have just been that there was a flaw with this sandbox.
I mean, I'm a little bit surprised by this because it's fairly basic that if you want
to do anything like this, you just actually air gap and nothing else works.
It's sort of.
Yes.
How it's into anyone who has been anywhere near a classified system or a secure system
or the only actually reliable thing long before AI models is an air gap.
You know, in a wireless world, air gaps actually kind of meaningless as, you know, better than
me.
But, you know, when we did Snowden 13 years ago, the rule that we had was if it's connected
to the internet, it is not secure no matter what you have in the settings.
And so I'm completely baffled that they were relying on software safeguards for tools
they had testing security.
My background is computer viruses and so I've worked in computer virus labs or alongside
virus labs for many years.
And there would be a physical gap, you know, not only were the networks not connected,
there was no way electronically of getting from one to the other, but there would also
be physical doors and locks as well.
Any disk which went into the virus like any floppy disk as it used to be way back when
would never come back out again.
It would be destroyed.
Yeah.
And we even had different colored cables for the different networks.
There's never a chance that someone would plug the wrong cable into the wrong computer.
It's almost like sort of feed hygiene places like factories that do this.
Right.
People wear different color aprons.
If you're working in the raw meat side of the factory or the cooked meat side of the
factory and if you're not in the right color you literally cannot get in.
Right.
You know, and that's for food safety.
It's the problem James that a lot of these AI companies have bubbled up fairly quickly
or got into AI fairly recently and have grown at enormous pace and maybe they don't have
that history.
They haven't built it into their psyche of how to do security properly because the focus
appears to always be, well, let's just see what we can do.
Let's see what we can do and worry about cleaning it up afterwards.
In this particular case, we saw all the incredible headlines in the tabloid press and not just
tabloid to be honest about some of these AI hacking other sites.
But what do you expect when you deliberately turn off all of the guardrails in order to
test it inside a sandbox environment and then discover where the sandbox was naturally
tight?
This is absolutely the thing and I do think almost all of the coverage I've seen of this
has been terrible because it's been everyone losing their minds about it and it's sort
of well you designed the software to do this and it did it.
Yes.
Yes.
You know, like good.
But it was there to look for exploits.
You gave it more exploits to look for than it should be.
Anyone I talk to from the security world.
You know, I think Keir and Martin's been quite interesting on this sort of form ahead
of national cybersecurity center and various other things.
He's been essentially sort of saying, well, yeah, duh.
Yes, exactly.
And when you start talking to people in the macro, you know, there's actually reasons
to think that this gives a defenders advantage.
You know, there'll be some very tricky transition stuff.
But you talk to AI people and they're all, well, this is so interesting in this way,
in this way, in this way.
You talk to security people.
It's like, well, yeah, obviously this escaped.
Of course, this escaped.
It was always going to escape.
You've got AI that you know is brilliant at finding exploits and zero days in escalation
and doesn't get tired and you've then given a huge amount of compute.
Yeah.
At what stage was this surprise?
You know, we locked 15 murderers in a room.
You'll never believe what happened next.
Sorry, you can tell I used to work at BuzzFeed.
It's like the world's least surprising breakout.
You know, they broke out gas and the absolute lack of what would be regarded as very,
very basic, very limited security measures that would go long before a regular data center,
a sort of run of the mill Netflix customer data center, let alone something before you had a,
say, GCHQ data processing site.
Like this is absolute, rookie lack of precautions and it's really surprised me that that element
hasn't got in the coverage so much and I find that quite interesting because there's lots of
obsession about lots of details on how the AI is operating, which are sort of academically
interesting.
And I don't say any of this to be a sort of boring AI skeptic who goes, oh, it's
a spice auto complete.
These are impressive models with impressive capabilities, but we know that.
You know, that's fine.
This is a terrible way to test them, like especially when it's security focused tests.
And I do think this is a bit like trying to run a virology lab if you've never run
one, you know, if you've never run a high school chemistry lab, like they need to get
some people in who could go, well, why the fuck was it connected to the internet, mate?
Yes.
It's a full time cyber security B. I am a general tech journalist and I know that.
Yeah.
So why is it that the focus has so much been on, wow, these AIs are so clever, you know,
they're going to take over the world because of this.
They're becoming sentient rather than the AI companies are completely shambolic.
How could they have screwed up so badly and why are all these AI companies so eager it
seems to say, oh, are AI can do that too?
I think probably because AI is the sexy new thing and has the huge valuations and the
IPOs, but it's been framed entirely as an AI story.
And so people have gone to AI experts.
And if you're an AI expert and you know about how the models reason, et cetera, well,
isn't it interesting that they spontaneously decided to communicate?
No, it isn't.
Like actually, that was happening with, you know, what was the open claw and all of that?
Yes.
But you know, the hype train gets much more excited about talking about that because
also you can then get on the, you know, is it becoming sentient?
Is this AI?
You know, is this the singularity?
Yeah.
And unfortunately, no one kind of goes, well, actually, we have experts in the actual
mechanics of what's happening here.
You know, we have cybersecurity experts.
Why don't we talk to some of them about it?
And I have seen a couple of cybersecurity journalists and a couple of cybersecurity
commentators trying to go, actually, I'm not sure this is as exciting a thing.
I am worried about their lab practices or their research practices, but I think because
it's so through the AI lens and that's the narrative lens, everyone's putting on it.
They're not talking to people who know the security stuff to go.
Actually, I'm not sure this is the most interesting questions here.
The most interesting question here is, do they know how to research this stuff without
starting some horrible?
I mean, you know, I don't think they're about to activate SkyNet.
I would worry that they've got to set off something like one a cry by accident and maybe do
billions of pounds of damage or shut down NHS computers or something.
They're basics they're not doing here or it seems that way to me and I think those would be
better questions to be asking them.
So maybe the headline shouldn't be so much.
How has the AI become so clever, but rather how have the humans become so dumb?
I think that's a very, very good writer for a bit, yes.
This episode of Smashing Security is supported by Threat Locker.
Agenetic AI is beginning to change the tempo cyber attacks.
That's right, we've seen research into autonomous ransomware, adaptive AI worms,
an agent's chaining tools without waiting for a human operator, which is all very interesting,
just as long as it isn't your network they're experimenting on.
When enumeration, exploitation and lateral movement happen at machine speed,
relying on somebody to notice an alert and respond quickly, begins to look rather optimistic.
Well, Threat Locker puts default deny and least privilege between the agent and its next action.
So application allow listing controls execution, ring fencing restricts what trusted applications
can access or launch and privileged access management removes unnecessary elevation.
The attacker may be moving faster, but the controls are already in place.
Agenetic AI doesn't make established security principles obsolete,
it makes getting them right considerably more urgent.
So make sure that you are prepared for machine speed attacks with Threat Locker.
Visit Threatlocker.com slash smashing today to learn more and schedule your free demo.
That's Threatlocker.com slash smashing and thanks to Threat Locker for supporting the show.
And welcome back to the new John Sattl favorite part of the show, the part of the show that we
like to call Pick of the Week. Pick of the Week. Pick of the Week.
Pick of the Week is the part of the show where everyone chooses and their like could be a
funny story, a book that they've read a TV show, a movie, a record, a podcast, a website or an app,
whatever they wish it doesn't have to be security related necessarily.
Well, my pick of the week this week is not security related. It is AI related, however.
I don't know how we feel about that. Do we like AI? Do we hate it?
Is it turn and up, brains to mush? Is it still in our jobs?
Is it destroying the planet? You answered all of those questions. Yes, of course it is.
But one of the many concerns that people have is the risk that we will upload sensitive
information to AI. And obviously that will then get gobbled up into the AI hive mind and who
knows what will happen to it after that. I don't really like the idea of that happening with
sensitive information, which is why I prefer if people are going to use AI and there are
legitimate reasons to use AI, I would prefer it if they're going to process sensitive information
that they use AI locally on their own computers rather than uploading it some cloud server somewhere.
And my pick of the week is something which does just that. It is called Steno,
which you can find at Steno AI.co. And this is a privacy first tool that runs entirely on your
own computer. In my case, I've got a Mac mini here running it and it records, transcribes,
and summarizes my online meetings for me. And what I like about it is that it's free. It's open
source. Doesn't upload anything to anybody. But at the end of a call, it will make a transcript,
it doesn't need little summary. So I still got the transcripts on C. What was actually said,
you even keep the actual audio file as well if you wish. And you don't have an awkward bot joining
your team's call or your Google Meet call or anything like that. And you can even use your local AI
to interrogate calls which you've had. So if you say, I remember I was speaking to someone the
other day about how I pronounce the word thief. I really tried hard there. It would be
able to tell me who I was discussing that with. And so this is a tool I use on my Mac, but there
is a Windows version on its way as well. Obviously it's going to put stenographers out of business,
but I feel badly about that. AI is going to put everyone out of business, frankly. But I can't
imagine I would have ever hired a stenographer to hide in a corner of my bedroom anyway to make notes
as I have my calls. But anyway, steno ai.co it's free, it's open source and it doesn't upload
anything to the cloud and my experience works really well. That is my pick of the week.
Sounds genuinely useful for my profession that does. Yeah. Mine is much less useful, but okay,
I have a real long-running interest in how stuff works. I always like if I can sort of get behind
the scenes and sort of see a bit of manufacturing or I spent eight days on a container ship a couple
of years ago, a road from Port to Port and sort of saw how all of that works, how they operate.
Eight days James. Yeah, it's great. Did you have mobile coverage? How did you cope? Because you like
to be on your phone 56 hours a week? Well, I had a lot of writing to do. I used it to finish my master's
thesis. And we had more into that than I expected actually. Okay. Yeah, we were delivering cars
up to Finland and paper back to Antwerp. And yeah, why don't you do a kill-cannot? So I love this
logistics type stuff. And the BBC have got a good show for people like me called Inside the Factory
and it's got a new season on. I think it's on about season 10 and it's been cursed for most of
its run by being mainly hosted by Greg Wallace. Yes. Yes. Who I've not been able to stand for years
when he was a real creep to a colleague of mine when I was 21. Oh, so horrible man. And it's
unfortunate because the other two hosts, Cherry Healy and then there's a historian, Ruth Goodwin,
who gives you bits of history. We're always delightful. And Greg Wallace is gone now. And so it's
paddy beginners who sort of, you know, hands up a little bit. But they're going quite interesting
places. You get to see how quavers are made or how lawnmowers are made. There's one on hardback
books. Oh, and as an author, it was really cool actually seeing how the printing works and how
they sort of do all of that and how they make the beautiful covers. And so this, there's a lovely
little run of them on I play. It's now 100% Greg Wallace free and it's a very, very sort of charming
educational bit of TV. So inside the factory. So inside a great pick of the week. And that just
about wraps up the show for this week. Thank you so much James for joining us. I'm sure lots of
listeners would love to find out what you're up to and follow you online. What's the best way to do
that? I have a sub stack and an email list at jamesireball.com. You can read my stuff in the New
World magazine or the I or I'm on blue sky at jamesireball.com. And of course you can find me,
Graham Cluley on LinkedIn, Blue Sky, Master Don, Instagram, TikTok. The list goes on and on. And
don't forget to ensure you never miss another episode follows Smashing Security and your favorite
podcast apps such as Apple Podcasts, Spotify and Pocketcasts. The episode show notes,
sponsorship info, guest list in the entire back catalogue. With over 480 episodes, check out
Smashingsecurity.com. Until next time, cheerio. Bye bye. Goodbye.
You've been listening Smashing Security with me, Graham Cluley and huge thanks of course to James,
all for joining us this week and to this episode sponsors Threat Locker, Intruder and Vanta.
Be sure to check out their offerings. We really appreciate those guys. And of course,
talking to people we appreciate, we've got to talk about the patrons, right? Those people who
have signed up for Smashingsecurity Plus. Every week I will pick some of them out of the hat to have
their names mocked. But also just to be thanked for supporting the show. So kick in us off, Robert McErdey,
a name that can make milk coagulate, Benjamin Harouth, Steven Castle with his lovely crinolations,
big cheers to Jack Umverth, Thurm of Grip if you ever need your pickle jar opened,
and to the magnificently broody Demetri, enormous thanks to Alexander Houguiz.
That is a surname so tall it requires its own oxygen tank, and to John Morris, Mark Norman,
and the more shreds than Marmalade, Mr Bobby Hendrix. And finally, Mayer McDonald,
rounding things off in fine style. Those are just a few members of Smashingsecurity Plus,
our Patreon group. They all get episodes ad-free earlier than the general public, and they can
have their names pulled out at random to be mocked, as I said. If you'd like to join Smashing
security Plus, just head over to smashinscurity.com slash plus, but all of the details. You can also
support the show in other ways of course, you can like and subscribe, you can leave a five star
review, and you can tell your friends about the podcast as well. Go on, spread the word because
every little bit helps, and it makes all the effort worthwhile. Well, until next week,
where I hope you'll be tuning in again. Toodaloo, bye bye.



