Security Now 1088 transcript
Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.
Leo Laporte [00:00:00]:
It's time for Security Now. Steve Gibson is here. Man, there's so much to talk about. A big flaw in OpenSSL. 1Password and Bitwarden try to solve the agentic AI password crisis. A new prompt injection attack AI users should be aware of. And a new way people in the bad guy profession are using AI. Kind of makes sense, all that.
Leo Laporte [00:00:26]:
Plus a great picture of the week coming up next. On Security Now.
Steve Gibson [00:00:32]:
Podcasts you love.
Leo Laporte [00:00:34]:
From people you trust. This is TWiT. This is Security Now with Steve Gibson, episode 1088, recorded Tuesday, July 21st, 2026. A nefarious novel use for AI. Time for Security Now. Hello, everybody, boys and girls, children of all ages. It's time for this guy right here, Mr. Steve Gibson, our security guru.
Leo Laporte [00:01:05]:
Every Tuesday, we gather together to sit at Steve's feet and learn about the perils that we are suffering here in this modern world. Hello, Steve.
Steve Gibson [00:01:16]:
The perils of remaining plugged in on the grid.
Leo Laporte [00:01:20]:
Yeah, if we were all air-gapped, we'd be okay.
Steve Gibson [00:01:26]:
Well, you know, Stuxnet managed to jump an air gap.
Leo Laporte [00:01:29]:
That's a good point. So even so, don't pick up USB keys in the parking lot, boys and girls.
Steve Gibson [00:01:34]:
Oh no, no, no, no. We are at episode 1088 for this July 21st. Our title is A Nefarious Novel Use for AI.
Leo Laporte [00:01:48]:
Oh my.
Steve Gibson [00:01:48]:
There are actually We've talked about the way bad guys are in an arms race with the good guys in finding vulnerabilities, which they could then exploit in order to get into systems. It turns out that that's actually not one of the leading uses, the malicious maluses, malign uses of AI. It turns out that getting into networks is not that difficult, sadly. Uh, it's like they don't need anything more. They got so many ways in now. It's just a matter of like the eeny meeny miny moe.
Leo Laporte [00:02:27]:
Oh, Lord.
Steve Gibson [00:02:27]:
Anyway, but they've come up with a use for AI after that, which is novel and nefarious. So we'll be talking about that this week. But first, we will look at the fact that the bone-crushing we had been promised did not happen this month. Not much did from Nightmare Eclipse.
Leo Laporte [00:02:52]:
Oh.
Steve Gibson [00:02:52]:
We are going to revisit and look more closely at last week's, which is to say July's Patch Tuesday. A widespread and worrisome flaw has been uncovered in OpenSSL. And OpenSSL jumped on this, quietly fixed it, pushed out changes. The problem is it is so widespread that there's no chance it's going to get fixed everywhere. And we'll look at the consequences of that. A bunch of our listeners said, Steve, I just saw an article saying that Claude can now access your 1Password credentials. You know, and this is where we deploy the what could possibly go wrong. Also, Bitwarden is aware that we need a whole new kind of coverage of security.
Steve Gibson [00:03:50]:
We're going to look at that. Also, the day ends in Y, so we have a new prompt injection attack. There has been a very rare, very serious update for WordPress, which unlike previous where it's in some random add-on that, you know, 5 people in Milwaukee have installed, in this case, this is in the core. So I hope everybody— No, it's really bad. I hope everybody who is staying up to date with WordPress, I think it was introduced in, at the end, at the early December of of 2025. So it's been around for about 6 or 7 months, and it's significant. We've got also lots of interesting listener feedback. I've just— I made time for it because I've just— we haven't had as much as I've wanted recently.
Steve Gibson [00:04:54]:
And then we're going to look at the new ways AI is being used by bad guys after they get into someone's network. And it's not— again, it's not sort It's sort of the techie side. It's not, you know, better exploration of the network. It's interesting. And of course, we've got a fun picture of the week. So yeah, I think worth tuning in for episode 1088.
Leo Laporte [00:05:19]:
If only to get new ideas on how you can exploit people's networks. It's worth it using AI. We will have that picture of the week in moments. All I know is it has something to do with coffee. I'm excited.
Steve Gibson [00:05:34]:
And that got my attention. I gave it a kind of a lame, a lame title. I said, because coffee is life. Because, you know, it is. It is.
Leo Laporte [00:05:44]:
It is.
Steve Gibson [00:05:44]:
But anyway, it's a fun sign that we will—
Leo Laporte [00:05:47]:
I've gotten, you know, really into what they call pour-over, which is really the silliest kind of coffee making where you're using a filter and there's all sorts of steps and the different grinds and all this stuff. It's not expensive. That's the only good thing. The bad thing is it's very time-consuming and it's chemistry and there's a lot of books and stuff, but it's so good.
Steve Gibson [00:06:11]:
A lot of books and stuff.
Leo Laporte [00:06:13]:
There's a lot of reading. It's chemistry. You should see this book that I have. It's got all of these— it's by a physicist. It's called The Physics of Filter Coffee.
Steve Gibson [00:06:22]:
It is possible to create a stunning cup of coffee.
Leo Laporte [00:06:27]:
I mean— You really can.
Steve Gibson [00:06:28]:
Yeah.
Leo Laporte [00:06:29]:
Because it's a— it's a— there's different volatiles, different chemistries, the, the time, the temperature of the water, the size of the filter. All of this stuff makes a huge difference, the size of the grind. And so you can— lots of dials to turn. And but once you get it right, it's really good. And I, I've never drank coffee black before, but because you can really make it to your taste, I— now it's like it's my reward. I, I say you can't have it till you work out. That's what I got here. It's a bad thing.
Leo Laporte [00:07:02]:
So coffee is life is what I'm saying. I'm agreeing with you 100%. Okay.
Steve Gibson [00:07:06]:
So what we have underneath this Because Coffee Is Life title, which it is, is a sign that someone took a picture of, which describes itself as the— it's wonderful—
Leo Laporte [00:07:24]:
the no-nonsense This is like on a chalkboard outside a coffee shop.
Steve Gibson [00:07:34]:
Yes, exactly. This is like, okay, so, uh, it, it shows on the left are the fancy, you know, French or Italian terms for some random yuppie coffee. And then on the right is the equivalent. So we have the Americano, which has been crossed out. And then next to it says, black coffee. Flat white, crossed out.
Leo Laporte [00:08:01]:
White coffee.
Steve Gibson [00:08:03]:
Cappuccino, crossed out. Frothy coffee.
Leo Laporte [00:08:07]:
Good, good, good.
Steve Gibson [00:08:08]:
Latte, milky coffee. Espresso, miniature coffee. Macchiato, milk-topped coffee.
Leo Laporte [00:08:18]:
Yeah, just a little dab.
Steve Gibson [00:08:19]:
Yeah. Mocha, Choccy coffee.
Leo Laporte [00:08:22]:
C-H-O-C-C-Y. Yes.
Steve Gibson [00:08:24]:
Choccy. Yes. Tea, not coffee. And hot chocolate, still not coffee.
Leo Laporte [00:08:31]:
Oh, I want to go to this place. Oh, that is so true.
Steve Gibson [00:08:36]:
Yes. It's just like, okay, fine. We'll give you your milky coffee, Gibson. That's right.
Leo Laporte [00:08:42]:
No AI here. That's somebody handwrote that one on a chalkboard. That's for sure.
Steve Gibson [00:08:46]:
So, uh, and I noticed down there's a, there's a pound sign. It says Pub on the Hoe, H-O-E.
Leo Laporte [00:08:54]:
So must be the name of the place.
Steve Gibson [00:08:56]:
That's my guess. Yeah, like some farm, some farm theme somewhere.
Leo Laporte [00:09:03]:
Oh, that kind of hoe.
Steve Gibson [00:09:04]:
Okay, farm implement. Yes, that's right. So, uh, it's difficult to know. Exactly what's going on with our prolific and talented, there's no discounting that.
Leo Laporte [00:09:18]:
Oh, it's in the United Kingdom in Plymouth. The Pub on the Hoe. I have found it. It exists.
Steve Gibson [00:09:27]:
And they have a no-nonsense coffee sign.
Leo Laporte [00:09:30]:
I love it. Sorry, go ahead.
Steve Gibson [00:09:33]:
Yeah. So it's difficult to know exactly what's going on with our prolific and there's no discounting it, talented Microsoft-taunting hacker who calls him or herself Nightmare Eclipse. Remember, 7 months ago, who— this hacker who's given us a run of zero days, they warned that a, quote, bone-crushing vulnerability and exploit proof of concept would be disclosed this month, presumably timed as they have all previously been to maximize their unpatched exposure interval by landing them on successive months' Patch Tuesdays. And we talked— we said last Tuesday on Patch Tuesday. Well, uh, hello, where is this? We did, however, indeed get another one last Tuesday, though it falls far short of bone crushing. I'm not even sure it would be considered bone chipping. It will certainly be Microsoft annoying, however, but it's probably also Microsoft relieving since it amounts to a rather limited use elevation of privilege vulnerability and exploit. Nightmare Eclipse gave this zero-day the name Legacy Hive.
Steve Gibson [00:10:59]:
Hive is what the Windows registry blobs are called. You know, it's this hive and that hive. So they, uh, they— the, the hacker called this Legacy Hive, and with limitations, it allows attackers to escalate their privileges on currently, like, fully patched Windows systems, right up to date. Um, but then here's where things get weird. Nightmare Eclipse claims that they deliberately toned down the proof of concept to make it less annoying for Microsoft.
Leo Laporte [00:11:38]:
Okay.
Steve Gibson [00:11:40]:
The story is that while it exploits a security vulnerability in the Windows Profile Service, it's been modified to require a— that is, the proof of concept has been modified to require a standard user's credentials And another username, like an admin account name, in order to make its exploitation more difficult for attackers to weaponize. And what I find suspicious about this is this does not sound like the nightmare Eclipse. I mean, what's the— it's not such a nightmare, right? So if this is true, which I actually, I think I tend to doubt, It would appear to represent a change of heart, you know, like a capitulation on Nightmare Eclipse's part. And I wonder if it could be the result of Microsoft's saber rattling getting a little, you know, hitting a little too close to home. The hacker wrote, quote, the proof of concept requires another standard user's credentials and a third username, which can be an admin account. If the proof of concept is successful, it will end up mounting the target user hive in the current user classes root. The proof of concept was stripped down as an attempt— get this— the proof of concept was stripped down as an attempt to prevent public exploitation. The original proof of concept did not require additional user credential and was not limited to userclass.dat hive.
Steve Gibson [00:13:27]:
Any hive could be loaded using this vulnerability, but you would need some brain cells to make the proof of concept do it. Okay, so the industry security researchers were quick to confirm the vulnerability's proof of concept. That is, it it, it works. It does what they say. Um, and Microsoft replied with their standard uninteresting bureaucratic boilerplate, you know, which we've seen every time before. So we can now add Legacy Hive, this latest one, to Rogue Planet, Blue Hammer, Red Sun, Yellow Key, Green Plasma, Mini Plasma, and Undefend, all of which Microsoft has patched the month following or sooner, and many of which were, you know, seen being quickly taken up and used by real attackers to actually injure real Windows users and their networks. So maybe there's some guilt on Nightmare Eclipse's part. Maybe that's the reason, you know, the real injury that this hacker was causing to innocent Windows users, uh, that they decided to make the vulnerability less easy to quickly abuse.
Steve Gibson [00:14:51]:
Uh, on the other hand, maybe they couldn't make it stronger. You know, I, I have no basis for that speculation beyond, I guess, my just my faith in human morality since, you know, this, this campaign that Nightmare Eclipse has been waging was also really hurting Windows users. So anyway, it's unclear whether this is the bone-crushing exploit that Nightmare Eclipse promised. It would be really bad if it were possible to arbitrarily load various registry hives like into different user profiles. That could be used for all kinds of of problems, especially in any kind of a server scenario where it could be devastating. Um, if the restrictions on the use of its proof of concept were lifted so that, you know, as I said, Windows registry hive remapping could be performed without any a priori knowledge of the victim's system, then That would have been a real bone crusher. So on the other hand, we've previously seen Nightmare Eclipse clearly and deliberately exaggerating their capabilities in the past, you know, referring to that, them saying, oh, you— there's a way to bypass the PIN on the BitLocker bypass exploit. We know now there was no way to do that.
Steve Gibson [00:16:27]:
So... that was an exaggeration. Maybe this is that too. Microsoft knows because they'll see what the problem is that this represents when they go about fixing it and see whether or not it actually could have been a lot worse had the hacker wanted it to be. But in any event, no bones were crushed or chipped or very much disturbed this month. So, and apparently it's just not easy to get the proof of concept to do anything very significant. So are they done? Are we going to see something next month? I guess we'll, uh, you know, need to stay tuned. But speaking of, of this month and next month, uh, last week we were only able to touch on the release of July's Microsoft patches since they occurred as we were recording the podcast.
Steve Gibson [00:17:20]:
And Leo, you were able to give us The overview of, yeah, 570.
Leo Laporte [00:17:26]:
Man.
Steve Gibson [00:17:27]:
3 of the 3 zero days among them. So scanning down the seemingly endless and astonishing list of security vulnerabilities, I mean, really consider scrolling your browser down 570 individually enumerated and described problems, bugs, security, you know, vulnerabilities that were fixed. It really is something to see. So it occurred to me that now we would not only need AI to find those, we would be needing an AI to help us keep track of them.
Leo Laporte [00:18:08]:
Yeah.
Steve Gibson [00:18:09]:
Because, wow, I mean, it is astonishing. There's almost too much to cover here in detail, and I'm not going to try, but I want to sort of hit the highlights here. Among the record-breaking, by a large margin, 570 security vulnerabilities, 59 of those 570 were rated critical. They're given critical ratings by Microsoft. 48 of those 59 allowed for remote code execution. So, so, so we had in one month 48 of the 59, 48 critical out of a total of 59 critical were remote code execution vulnerabilities out of a total of 570. So more than 1 in 10. Another 9 broke out of Windows privilege management to allow attackers to obtain system privileges.
Steve Gibson [00:19:13]:
Overall, independent of the ranking of the vulnerabilities, you know, like critical, moderate, information, so forth, 145 of the 570, which puts it at more than 25% overall, enabled remote code execution one way or the other. So there were So 48 were critical RCEs, but the balance to bring the total to 145 remote code executions one way or the other. And also 254, bringing it to 45% of those 550 total, were privilege of, uh, elevation— privilege elevation attacks, uh, that would allow an attacker who had obtained a minimum foothold in a system to bump up their privileges to full root system access, which they pretty much need to do in order to do anything extra nasty and also in order to obtain long-term access to the system. So it seems to me that the one thing Microsoft is not doing, based on what we're seeing, is restricting their rate of discovery and disclosure. They're not like dribbling these out. Each of the past 3 months has broken their all-time previous security vulnerability patch record, and each time by a significant and significantly growing measure. So it's accelerating in addition to being continually record-breaking. So this makes me extremely interested.
Steve Gibson [00:20:57]:
I mean, I cannot wait to see what next month will look like. And I heard you saying, I think it was on your Sunday podcast, you mentioned to the 2 co-hosts with you, Leo, that I had been expecting that we would see increasing numbers of patches followed by decreasing numbers of patches. as they see, as the available pool of things to fix dry up. Inevitably, that's going to happen.
Leo Laporte [00:21:29]:
I've been raising that with everybody, that Steve Gibson says eventually we'll get to, I don't know if we'll get to zero, but we'll get to fewer, far fewer.
Steve Gibson [00:21:40]:
Well, the thing that they missed that I'm factoring in also is that AI will be in the code design path in the future. I expect— I mean, there's no reason to release a bug that your AI is able to find later. Why not find it first? I mean, find it pre-release.
Leo Laporte [00:22:03]:
Right.
Steve Gibson [00:22:03]:
So that's the other thing that's going to happen. It's the reason I think we're going to be dropping, if not to zero, to like a whole different level where enough low— so, so low that things like Pwn2Own and HackerOne and bounties and so forth, they're just going to go away because—
Leo Laporte [00:22:22]:
I think that could happen very soon, to be honest. Yes.
Steve Gibson [00:22:25]:
Yes.
Leo Laporte [00:22:26]:
And, you know, I think that's part of the development cycle now. It is certainly when I'm developing with Vibe Coding.
Steve Gibson [00:22:33]:
Why would that be?
Leo Laporte [00:22:34]:
Inevitably, I do a security audit as I'm going, let alone at the end.
Steve Gibson [00:22:39]:
I mean, constantly. And it must be that Microsoft is already using AI to write code. Why, why, why would they be lagging there?
Leo Laporte [00:22:47]:
Right. I, I would— I mean, goodness, yes. So, and it catches all the obvious things, you know, the buffer overflows, the writing to ring 0, all the— maybe what I said on Sunday, you know, Rowhammer isn't going to go away, probably, right? That kind of—
Steve Gibson [00:23:05]:
It, it can't. Yes. Not all security problems are code errors.
Leo Laporte [00:23:10]:
Right.
Steve Gibson [00:23:11]:
You can also get a port.
Leo Laporte [00:23:12]:
I mean, microcode will be better, so maybe you won't have those kinds of pipeline errors where it's leaking.
Steve Gibson [00:23:17]:
Well, but you could still have an open port. You could still have a dumb password.
Leo Laporte [00:23:22]:
Exactly. Nobody's gonna stop that.
Steve Gibson [00:23:25]:
No.
Leo Laporte [00:23:25]:
That's forever.
Steve Gibson [00:23:28]:
One whole big class of problems is probably gonna go away. And I think it's gonna probably, at the rate we're seeing this being jumped on, again, I'm just, I can't. I am so excited to see what happens next month with Patch Tuesday. Because, and I should also mention, it's not just Microsoft. All the big publishers are seeing, in fact, Adobe has switched to twice a month updates because they've, they're just, their run rate of patches, they are patching so much now that they thought, okay, we can't wait another 3 weeks. After finding a problem, we need to wait one week and do a mid-month patch. So we're going to see this industry getting cleaned up pretty quickly. Um, on the other hand, there may be also that unfortunate haves and have-nots bifurcation where, you know, the big publishers, the Adobes, the Microsofts, the Oracles, you know, the big guys, uh, Apple also certainly, who are able to just dump all this excess cash they have into token purchasing, they have the ability to do this.
Steve Gibson [00:24:39]:
Smaller publishers may not, although I just saw Synology updated my boxes for an AI-discovered problem that it had. So even the smaller guys are saying, hey, let's— why not spend some money on some tokens and make our product better? So wow, the, the, the shape of this patch curve is really going to be interesting. Um, uh, my guess is we may see fewer next month. I don't know.
Leo Laporte [00:25:16]:
I, I— That'll be interesting. If just— I mean, I think you're right, the velocity will certainly go down. Yeah, I mean, nobody would deny that. It's just at what Right. And to what final resting point.
Steve Gibson [00:25:28]:
Exactly.
Leo Laporte [00:25:29]:
Yeah.
Steve Gibson [00:25:30]:
Okay. So, uh, Hollowbyte is the name that Okta, uh, gave to their discovery of a very worrisome denial of service that exists in OpenSSL. Uh, any problems discovered in the massively used— I mean, like, it's, it's, I mean, it's hard to describe how wide— widespread the use of OpenSSL is. There are, you know, certainly private TCP/IP stacks. Windows has one, uh, Apple has their own, um, but like anything that wants to create a TLS connection now which is some embedded device or a widget or whatever, it's got OpenSSL. Now, there are— we've talked about— there are some embedded TLS libraries that are used by, at the, you know, really small embedded level. But OpenSSL, as we know, we've been talking about it for decades, you know, is what you use. Apache uses it, NGINX web servers use OpenSSL, uh, the runtime libraries, uh, like Node.js, Python, Ruby, PHP, MySQL, they're all using, uh, OpenSSL.
Steve Gibson [00:27:05]:
So because OpenSSL is widely used and embedded This vulnerability affects all of these systems. So Okta discovered a means for— and it's really sad that actually, because it's so simple, it's like, really guys, this is, this is still a vulnerability today for sending just 11 bytes of TLS data to any unpatched OpenSSL endpoint, you know, meaning all of those servers that I mentioned and, and the, the various application, uh, libraries to cause the connection to over-allocate a memory buffer in anticipation of receiving the remainder of the declared incoming data. So once again, this is why I, I'm sort of disappointed in this problem. So it's one of those where the, the header declares how much data follows and then it doesn't. But because the header is parsed first, the library says, oh, here comes 128K of data. So it pre-allocates a buffer to contain the data, which then never arrives. It's like, guys, how Really? In this day and age, that's— you're still coming across those kinds of problems? Anyway, um, by doing that over and over and over, making a connection, sending 11 bytes, an attacker using very few resources at their end, meaning you don't need lots of servers and lots of bandwidth or anything, you know, some random proxy that exists in some guy's, you know, LG TV that's got taken over, uh, can bring down a major service. Okta provided some background, uh, and color, uh, which I want to share.
Steve Gibson [00:29:05]:
They wrote, every so often a vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. Recently, the Okta red team discovered Hollowbyte, a denial of service vulnerability in OpenSSL. By sending a malicious payload of just 11 bytes, any remote unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins. The TLS handshake begins with a client hello message wrapped in a record. Each TLS handshake message begins with a 4-byte header that declares how large the incoming message body will be. Existing versions of OpenSSL allocate a receive buffer based on that attacker-declared length before any data has actually arrived. Like I said, really, in this day and age, you're— we're still doing that? When the malicious 11-byte payload arrives, the TLS state machine reads the 4-byte handshake header and triggers an unvalidated pre-allocation based on the header's 3-byte length declaration. Because there's no payload validation at this early stage, the system's malloc, the memory allocator, allocates up to 131K— as I said, 128K binary— based solely on the untrusted packet's claim.
Steve Gibson [00:30:51]:
The worker thread then blocks, waiting indefinitely for the data that will never arrive. Holding connections open to exhaust threads is a classic trick. Like Slowloris that we talked about years ago. Hollowbyte introduces a far nastier compounding effect due to how the GNU C library, glibc, handles memory. When an attacking connection drops, OpenSSL frees and releases the buffer. However, glibc does not immediately return small to medium size, which 128K is considered, allocations back to the operating system. It retains them for potential reuse. Therefore, by launching waves of connections with randomized claimed sizes, meaning that they're not going to be reused perfectly, an attacker prevents the allocator from reusing those freed chunks.
Steve Gibson [00:32:00]:
This fragments the system's memory allocation heap heavily, causing the server's resident set size to climb continuously. Even after the attacker disconnects, the server remains permanently bloated. The only way to reclaim that memory is to terminate the process, you know, shut down the web server. or the whatever services you using OpenSSL. Frequently it just means having to reboot the system. You've, you've killed that service. They said to measure the threat, we tested unpatched and patched OpenSSL instances running NGINX under various load conditions. In a standard 1 gig of RAM environment, an unpatched server was out-of-memory killed at 547 megabytes of frozen fragmented memory.
Steve Gibson [00:33:00]:
In higher-spec testing with, for example, a 16-gigabyte RAM allocation, the memory successfully locked up 25% of the system's total memory while staying safely under the connection ceiling limits, meaning standard connection limiting defenses won't stop it. The OpenSSL team resolved this by switching, wait for it, to an incremental buffer growth strategy. What a concept. What a concept, Leo. You mean you actually don't allocate memory until you get something to put in there?
Leo Laporte [00:33:38]:
It's amazing.
Steve Gibson [00:33:39]:
Who'd have thought of that? Wow. This fix was silently included as part of OpenSSL version 4. 0.1 release with silent backports to release 3.6.3, 3.5.7, 3.4.6, and 3.0.21. Under this revised memory allocation strategy, rather than trusting the header's claims outright, OpenSSL now grows the buffer only as bytes are actually received over the wire. Wow, a breakthrough! A claim with no follow-through now costs the server nothing. Even though OpenSSL handled this as a hardening fix rather than a CVE security advisory, we recommend upgrading your distribution's OpenSSL packages immediately. And I'll just put a big amen on that. I went over to the OpenSSL repository And saw that all of those stated versions were updated more than 5 weeks ago.
Steve Gibson [00:34:46]:
This had— this occurred on June 9th. So this would have meant that all of the various dependent packages— Apache, NGINX, Node.js, Python, Ruby, PHP, and so forth— would have needed to incorporate that update into their own builds. And then make those available. Then any public exposure of them would need to be updated and relaunched. Now, the problem we always have is that those are only the most well-known, prominent, and, you know, obvious users of OpenSSL. It is doubtless used in countless other systems. For example, I was a cur— I was curious about the my own fully patched and up-to-date Synology NAS. So I SSH'd into it and issued the command openssl version, and I was promptly informed OpenSSL 1.1.1u, which was dated the 30th of May, 2023.
Steve Gibson [00:35:52]:
Um, since I follow my own advice, my own residential network has exactly zero open ports to the outside world. You just can't have any. And here's a perfect example of why. This was not a problem anybody knew about. They silently patched it and pushed the updates out, you know, even downplaying it as some hardening rather than giving it a CVE that would have brought it to the attention of the bad guys. Because they know that how bad this is. I mean, this lets you crash and freeze and lock up any OpenSSL receiving service. So for random end users, I would say it's unlikely to be much of a problem.
Steve Gibson [00:36:45]:
It's not going to be the end of the world, but the chances are very good that most, if not every single piece of enterprise border equipment is also based on a version of OpenSSL, which was published more than 5 weeks ago. So unless you have— unless your vendor has updated and pushed and made available updates, and hopefully you didn't wait because you shouldn't these days, to update your appliance. If, if any of that did not happen within 5 weeks, then that's— the systems you're using can probably be brought to their knees. Again, doesn't let the bad guys in, but it lets them shut down your network. Um, so, uh, although Okta didn't disclose whether this newly disclosed vulnerability was found through the use of AI. It is exactly the problem that the entire industry will now be facing. As I've noted, our browsers and operating systems have already developed quite mature systems for keeping themselves up to date, but many network appliances have not seen the need to do the same. Difficult to, you know, to get a device which isn't asking if there are anything—
Leo Laporte [00:38:12]:
is it—
Steve Gibson [00:38:12]:
if there's anything new for it to suddenly start doing that. So, uh, in the intermediate term, um, there's probably going to be a flood of newly discovered vulnerabilities and updates which, you know, users of these systems, uh, need to be staying current with. Things exactly like this that need to get fixed. And who knows what else we're going to be seeing in the short term.
Leo Laporte [00:38:41]:
Yikes.
Steve Gibson [00:38:42]:
What I do know, Leo, we're going to be seeing—
Leo Laporte [00:38:44]:
You think coffee is life?
Steve Gibson [00:38:50]:
Cheers.
Leo Laporte [00:38:51]:
All right, let's talk about Claude.
Steve Gibson [00:38:55]:
Okay, so—
Leo Laporte [00:38:56]:
Or as Paul Theroux calls it, Claude. It's crazy.
Steve Gibson [00:39:01]:
Claude. One of this podcast's favorite rhetorical questions is, what could possibly go wrong?
Leo Laporte [00:39:11]:
Go wrong.
Steve Gibson [00:39:12]:
So it's bearing that question in mind that I share this next bit of news that Anthropic's Claude AI is now able to access and use its Mac users' passwords stored in their 1Password vault. Um, which of course then begs the question, our favorite question, what could possibly go wrong? Um, and I'll just note that 1Password is a past sponsor of the TWiT Network. Last Thursday, 1Password posted a blog entry with the headline, 1Password for Claude: Give Claude Access Without Giving Up Your Credentials. And okay, this is the first of 2 pieces of news that I want to share. And then we're going to be looking more at AI access to credentials because this is going to be crucial. If you've got agents running around doing stuff on your behalf, well, they need to be able to look like you, act on your behalf to services that require you to log in. So since this is clearly the future, uh, and I think we're going to be seeing a lot more of this, I wanted to spend some time. So 1Password wrote, AI agents are moving from helping people think to acting on their behalf in browsers, apps, and accounts.
Steve Gibson [00:40:45]:
That changes the security model. Once an agent can click, buy, update, and submit for you, the key question becomes what identity is it acting under and what access should it get? Claude can compare deals, add an item to your cart, update account details, or complete a purchase. But once it reaches a login page, you face a trade-off. Do you give the agent your password, or stop and do the task yourself. Neither is the future we should build toward. Until now, there's not been a secure, easy way for agents to use credentials without exposing them. 1Password for Claude enables credential access without credential exposure. 1Password for Claude is built on a zero-exposure architecture.
Steve Gibson [00:41:46]:
Claude can complete browser tasks that require logins and one-time passcodes, but the credentials never enter the model or its memory. Um, 1Password, they wrote, stays the source of truth for the secret And access is granted only at runtime. When Claude needs to sign in, 1Password shows the user which credential is being requested and why. After user consented biometric approval, 1Password injects the credential directly into the page. Claude never sees the vault item. password, or one-time code. Access is scoped to the current task and ends when the task is complete. After autofill, 1Password checks that secrets were not exposed on the page.
Steve Gibson [00:42:51]:
If submission fails, it clears the filled values before returning control. Nancy Wang, 1Password CTO, said, quote, We need a new security model that is purpose-built for agents, not just humans. The answer is not handing agents your secrets. It's to let a user give an agent permission to use a credential without letting the agent see it. Claude knows it used your login. It does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic. Okay, so, um, this is not handing over unsupervised one-password access to Claude.
Steve Gibson [00:43:49]:
There was— I think it was maybe it was The Verge that picked this story up, and I saw their coverage of it first, and there were 31 replies by people who apparently didn't actually read even The Verge's coverage.
Leo Laporte [00:44:05]:
They don't get what's going on. This is far superior to the way people were doing it, which is storing all that stuff in clear text on the hard drive.
Steve Gibson [00:44:12]:
Right, exactly. And it was funny because the comments on The Verge's article, I just scanned them 'cause I was curious what people thought of this, was like, oh, hell no, and oh my God. And it's like, yeah, the point is this has been well thought through. And as you said, and as I said, this is not giving the agent your password in clear text. So it's deliberately blinding Claude to the credentials needed to log in to whatever, some online service where it will then be operating with some autonomy. You know, essentially Claude is saying, hey, could you please log me into Expedia or whatever so that I may proceed to do what you have asked me to do? And in reply to this, 1Password's new system pops up a dialog asking the user to on the fly interactively authorize this login so that Claude may proceed. You know, and this is a Mac apparently. So in, in the example, the user places their finger on Apple's Touch ID sensor, uh, or, you know, if it's using Face ID, smiles at the camera, uh, and, and then that, that authorizes 1Password to perform this in a blinded way on, on the user and Claude's behalf.
Steve Gibson [00:45:45]:
So Claude is kept on a leash and is able to work without exposing the user's credentials. I'm sure it would be worth remembering that most of us remain persistently logged into many of the online services we routinely use and visit. So if our AI agent is driving our web browser, it presumably obtains the same persistently logged-on privileges which we enjoy. In other words, you know, we do still need to be careful since it can still do everything we would be able to do if it did not require us to log in freshly. Maybe if this was a concern for people, it might make sense to have such an agent using a different browser, that is, that does not share cookies with the browser that you normally use, you know, effectively give it its own browser, uh, whose cookies had been pre-wiped so that there were no persistent logons available to that, requiring you then to be asked every time that the, that the agent wants to do something. Um, anyway, 1Password provided a couple of what this looks like in practice examples for For everyday AI users, they wrote, your Audible credits are about to expire. Instead of logging in, navigating to the store, navigating in the store, and then manually redeeming a credit, you ask Claude to review your wish list and choose a new title for you. Claude navigates to the site.
Steve Gibson [00:47:28]:
You provide approval for Claude to use the credential from your vault. 1Password provides the login, and the audiobook lands in your library. You never typed a password or, uh, one— or one-time token, and Claude never sees either. What's funny, Leo?
Leo Laporte [00:47:46]:
I heard you. Oh, I'm just saying that's a silly use, but okay, if that's what you want.
Steve Gibson [00:47:50]:
Okay. Yeah, yeah. I mean, and then their example—
Leo Laporte [00:47:53]:
It makes sense. Get me the book. Yeah, yeah, buy me the book.
Steve Gibson [00:47:56]:
Their example for business use is a small business owner could ask Claude for a Stripe revenue summary or to flag any unusual activity. Claude can navigate the dashboard. The business owner approves Claude to use their Stripe login details. 1Password can handle the credential and the one-time code, and the business owner receives the answer without going through the multifactor authentication or exposing the secret to Claude. So They said, these are just 2 examples. The same pattern works across the sites where Claude in Chrome can take action. If the credentials are stored in 1Password, Claude could use them. You approve, 1Password supplies the credential, and Claude finishes the job.
Steve Gibson [00:48:43]:
Even when the task changes, the access model stays the same, and your credentials never leave 1Password. And Leo, you know, I don't think there's any danger in this podcast running out of things to talk about because all of this is going to go so wrong.
Leo Laporte [00:49:00]:
That's true. But it's something you need to solve. And this is the problem. I mean, there's really no great way to do this. As Paul points out in our Discord chat, you know, if the AI has a credential, then You're just one prompt inject and step away from it giving it all the credential to a bad guy.
Steve Gibson [00:49:22]:
Exactly.
Leo Laporte [00:49:23]:
But it needs the credential. It's the same problem that DVDs had with the CSS key. It had to be in memory on the DVD player. That's why a high school student was able to crack the CSS key on the DCSS key on the DVDs in about an hour. Because he said, oh, it's going to be in memory. I just have to find the memory and Now I've got the key.
Steve Gibson [00:49:42]:
Yeah.
Leo Laporte [00:49:44]:
So yeah, it's— I have, you know, I use Bitwarden to do this. Um, I've gone through a bunch of different processes. You try to lock it down as best you can. The best way would be, if you— if I, if I think about it, you tell me if I'm wrong, and there are services that do this, is a one-time token that is revocable and is only usable once. That's what you hand to the AI to then access the service. But of course, the service would have to support that as well.
Steve Gibson [00:50:14]:
And right, essentially, we have— we've stumbled into the need for a new security model, some means for allowing autonomous agents.
Leo Laporte [00:50:28]:
Would passkeys or Squirrel be a good solution?
Steve Gibson [00:50:32]:
No, it's, it's, um, those are just less hackable Right. Traditional models.
Leo Laporte [00:50:39]:
But there's still a secret. And if the secret gets handed off, you're SOL. What Darren's pointing out, and it's really true, is that nobody who uses these things wants to be stuck at the keyboard typing in passwords at any point.
Steve Gibson [00:50:53]:
Right.
Leo Laporte [00:50:53]:
Or giving confirmation or saying—
Steve Gibson [00:50:55]:
Or even having to keep their finger on the Touch ID button in order to say yes, yes, yes, yes, yes, yes, yes, yes. I frequently—
Leo Laporte [00:51:02]:
using my AI here up in the attic offsite or downstairs. I don't want to have to run upstairs and touch the keypad. Yeah. But that is more secure if I do. I don't know what the answer is. I hope you come up with something for us.
Steve Gibson [00:51:19]:
They then address the need for what they call, well, what we all call agentic mode. And they explain agentic mode protecting the vault when an agent controls the browser. So they write, 1Password writes, there's a second problem. What happens when a browser-based agent takes control of a browser where 1Password is installed? Without proper guardrails, the agent could try to interact with the extension itself, right? I mean, like, it's acting as the user.
Leo Laporte [00:51:51]:
Sure.
Steve Gibson [00:51:51]:
So 1Password doesn't know the difference. Agentic mode is how we close that gap. Agentic mode is a new feature in the 1Password browser extension that gives every user visibility and control over browser-based AI agents. When a comparable— sorry, when a compatible AI agent takes over, the 1Password extension automatically locks down. The interface is hidden. And the agent can only use the logins and one-time codes explicitly approved for the current task. The rest of the vault stays out of reach. Agentic mode works even if the integration is not set up, and even if 1Password is not required for the current agentic task.
Steve Gibson [00:52:40]:
It also supports additional agents beyond Claude. For example— I'm sorry, for qualifying enterprises, There's nothing new to configure. Employees using 1Password for Work credentials automatically get the same protection. Every credential request from an AI agent is visible, explicit, and requires authorization. Okay, so this is clearly different and distinct from that previous 1Password for Claude feature. Agentic mode appears to be a recognition of the fact that browser-based AI agents will be indistinguishable from their human counterparts to browser extensions. Browser extensions won't be able to tell the difference, including a password manager. So this would mean that unless a password manager proactively determines to what entity it is granting credentials, that is what type of entity, human or not, any browser-based AI agent would automatically be granted and would obtain the same benefits and freedoms as that browser's human user.
Steve Gibson [00:53:53]:
And obviously, that could lead to some disaster. 1Password concludes their posting by writing, 1Password for Claude is just one part of the access layer we're building into AI agents across the ecosystem, including securing developer credentials, with 1Password MCP server. Whether the agent is working in a browser, IDE, repo terminal, or CI/CD workflow, the principle's the same. Secrets should be issued at runtime, scoped to the task, and governed from 1Password. As agents become more capable, they become a new class of identity. They need governed access just like humans and machines do. 1Password for Claude applies that model to browser-based delegation. Claude can act with explicit user authorization and only gets the access it needs when it needs it.
Steve Gibson [00:54:56]:
The credential stays encrypted, controlled, and out of the model's context. 1Password for Claude is available now for Mac across business, family, and individual plans. To enable this integration, you'll need the 1Password desktop app, the 1Password browser extension, the Claude desktop app, and the Claude in Chrome browser extension. Okay, in other words, at this point, 1Password for Claude is, is only for Apple Mac and Google Chrome. together. But this highlights the dangers inherent in moving control from the user to an AI agent. And Leo, I mean, to me, thinking about Paul's comment in the Discord chat, this doesn't really give us what we want, as you said, right?
Leo Laporte [00:55:52]:
Right.
Steve Gibson [00:55:52]:
I mean, we want our agents to be autonomous. We want them to be able to have the freedom to act on our behalf. But boy, is that risky.
Leo Laporte [00:56:06]:
So I'm sure this isn't optimal, but I, uh, okay, I have, uh, Bitwarden, which has integration, by the way, uh, for it. They're the ones that came up with this agent secrets, uh, uh, UI.
Steve Gibson [00:56:21]:
And I'm about to talk about that.
Leo Laporte [00:56:22]:
Yeah.
Steve Gibson [00:56:23]:
And I don't—
Leo Laporte [00:56:24]:
I'm not sure if 1Password's using it or not, if they did their own thing. Bitwarden opened it up. They made it open so that 1Password could use it.
Steve Gibson [00:56:31]:
They wanted everybody to use it. Well, Bitwarden is open source.
Leo Laporte [00:56:33]:
Yeah. So they wanted everybody to use it. I don't know what 1Password's doing, but, uh, so, but I, but I'm using the Bitwarden command line and I have SOPS encrypted the API token and the key. And, but I was having to enter the Bitwarden password every time I booted up the machine.
Steve Gibson [00:56:53]:
In order to unlock that.
Leo Laporte [00:56:54]:
Yeah, of course. This is a SOPS-encrypted file. Somebody would have to steal my machine and then find the age key, which is somewhere else on the hard drive, and then unencrypt it. I mean, they could do it. So I just put the Bitwarden password in there. I figured, you know, what the heck? So now I don't have to— it's completely— the machine boots up, it gets everything it needs from us. It also gets the SSH password, by the way, from a SOPS-encrypted thing. and then it can talk to all the machines, it can do all the things it needs to do.
Leo Laporte [00:57:23]:
I know it's risky.
Steve Gibson [00:57:25]:
And that's the problem, is we, we want, we want that flexibility, and our current security models, architectures weren't built for this. And so they're going to be stretched for a while until we figure out what to do.
Leo Laporte [00:57:43]:
There are companies That will— you give them all your credentials. This is where I stop, but you give them all your credentials and then they become a trusted provider and they give the AI a token that's a one-time use token and it's logged so they know how it was used. The AI then has to go through this provider, which then gives the password to Audible or whatever.
Steve Gibson [00:58:10]:
So there's a gatekeeper.
Leo Laporte [00:58:11]:
There's a gatekeeper. But in order to do that, you have to give the gatekeeper all the passwords.
Steve Gibson [00:58:17]:
Yep.
Leo Laporte [00:58:17]:
Or tokens or whatever secrets you have. So they have your secrets. You've got to trust them. But then they're not— they don't live anywhere on the machine. So it's the end. You have logging and it's a one-time password and all that. So that might be all right if you, if you find a third-party provider that you trust. This is for enterprise.
Leo Laporte [00:58:37]:
That, by the way, that further complicates it because It's just me. What if I had 20 employees who needed this kind of stuff? Then we got another matter. It gets complicated is, I guess, the answer. Go ahead. I'm sorry. No, just let me know when you solve it, will you?
Steve Gibson [00:58:52]:
That's a useful discussion. And clearly this company that you were referring to, they saw an opportunity to interpose themselves. I guess what I'm wondering is, If you've told them that you want your agents to have access to a certain set of accounts, how do they then— I mean, certainly they can log it, but all they're doing is basically saying, yes, yes, yes, go ahead, whatever the agent wants to do.
Leo Laporte [00:59:23]:
They know your IP address. They know maybe your agent has a secret that it passes on. I mean, there's going to be some authentication for the agent, I'm sure.
Steve Gibson [00:59:33]:
Yeah.
Leo Laporte [00:59:34]:
You know, there's also this OAuth. A lot of agents use OAuth. I use OAuth with Anthropic, with OpenID, with ZAI, with a lot of them. So it's storing an OAuth token, which I guess if somebody got ahold of that, they could use. I mean—
Steve Gibson [00:59:50]:
You know, all the stories we've covered about people losing their cryptocurrency? This feels like that. It does feel like we're gonna have— so, oh, too bad, happened to him, blah blah blah, you know.
Leo Laporte [01:00:06]:
Oh, it's definitely that.
Steve Gibson [01:00:08]:
And I'll be the one that— well, you, you did have the wisdom to pull back from OpenClaw. Like, say, oh yeah, I don't think that's really what we want to do.
Leo Laporte [01:00:18]:
I've done everything I can to lock it down without totally inconveniencing myself. I mean, ideally I'd have to enter the password every time.
Steve Gibson [01:00:26]:
You, you live security as a consequence spending the last 2 decades with me. Listening to you.
Leo Laporte [01:00:32]:
Yes.
Steve Gibson [01:00:33]:
But a lot of people don't.
Leo Laporte [01:00:34]:
No, I know.
Steve Gibson [01:00:35]:
I mean, most people, they kind of, oh yeah, I want to let my agent do whatever it wants. And they just think, well, just let it have my password manager.
Leo Laporte [01:00:48]:
Everything's encrypted. Lux encrypted, FileVault encrypted, the Borg backups are encrypted. if you came in here and you took my hard drive, uh, you wouldn't be able to see anything on it. I'm just, you know, I'm doing everything you taught me, and I know it's not perfect, but—
Steve Gibson [01:01:06]:
Well, and so you're safe, but you're one guy. I'm thinking we're gonna see a lot of these, you know. I mean, how many times have we talked about people getting their wallet, their crypto wallets empty?
Leo Laporte [01:01:18]:
Absolutely.
Steve Gibson [01:01:19]:
Same. I'm not saying that it's I'm just saying that this feels like the same class of problem.
Leo Laporte [01:01:25]:
I agree 100%.
Steve Gibson [01:01:27]:
That like, this is like, yes, it's exciting and it's fun and it can do stuff, but it's going to go off the rails. Okay. Let's take a break and then we're going to look at Bitwarden's solution to secure agentic AI access.
Leo Laporte [01:01:46]:
Bitwarden, our sponsor. We do love Bitwarden. And they've been working on this. I know I talked to them at RSAC. They've been trying to solve this too. I mean, this is one of the next big frontiers, frankly, to switch to—
Steve Gibson [01:01:58]:
Why we're not going to be ending this podcast even after all the bugs are fixed. This is not a bug. This is a feature.
Leo Laporte [01:02:04]:
What could possibly go wrong? It's such a good motto. And let's again say Bitwarden is a sponsor as you go into this story. Yep.
Steve Gibson [01:02:15]:
So, uh, their recent blog posting, Bitwarden's, was titled How Bitwarden Helps Secure Agentic AI Access to Your Credentials. Um, and in this, they further clarify exactly what we've been talking about— these new challenges which especially enterprises face as autonomous AI agents begin roaming the network. I mean, they've noted that this is already a problem, that there are already employees using what they refer to as shadow AI. Anyway, they said businesses are increasingly pressured by competitive markets and investors to leverage AI productivity within their processes and operations. According to Cisco, 83% of IT leaders agree that business units are deploying agents faster than security teams can support. Yeah, no kidding. Regardless of the speed at which businesses implement agentic AI, employees are using agents often without explicit IT approval and therefore granting unvetted agents access to companies' credentials. This phenomenon is known as shadow AI.
Steve Gibson [01:03:33]:
Without proper security measures, agentic AI can introduce serious vulnerabilities. They list 3. Overscoped access. AI agents may access systems, information, credentials, and data not explicitly authorized by the company or users. Second problem, unapproved actions. Overscoped access and permissions can grant agents the ability to complete unapproved actions, potentially interrupting operations, exposing business information, or damaging the company's reputation. And finally, data leakage. Sensitive information like plaintext credentials can be shared with an AI provider who does not have the capabilities to effectively secure this information, leading to a potential data breach.
Steve Gibson [01:04:25]:
And I'll just pause here to note that the data leakage problem Seems particularly significant to me. It's why I'm so biased toward local AI solutions somehow. You know, the Chinese AI models are inexpensive and they are remaining highly competitive. And of course, we know that you, Leo, routinely use Chinese-supplied AI for much of the work you're doing.
Leo Laporte [01:04:54]:
I'm using it right now.
Steve Gibson [01:04:56]:
Because you can get good enough work for 1/10 the token cost of domestic models. Um, and I don't know whether we were speaking of it during the podcast, at the top of the podcast, but just last Friday, uh, the Chinese company Moonshot released their Kimi K3 open source model, or open weight model, which stunned the world again. Very much the way DeepSeek had previously done so. Independent analysis places the KIMI K3 very close, certainly on a par with some of the frontier models from Anthropic and OpenAI. Okay, so here's the problem. For an AI agent to use credentials, they must be, as you said, Leo, in plain text at the time of the agent's use, since the AI agent is standing in for the human whose work it's doing. But there's a massive security disparity here. In the human user case, the plain text credential is stored locally and remains local while it passes through the human user to the credential verifier, whatever, wherever you're logging in or who, or proving who you are to some online, uh, you know, trans-network system.
Steve Gibson [01:06:25]:
But this is not the case when the credential user is an AI agent powered by a data center in Shanghai, China. In order to be used by the AI, it must pass through that is the credential, must pass through that China resident agent. This requires that the credential visits China as plaintext, if only transiently. So the overarching security issue here is that all of the credential management systems we've carefully designed and implemented for use by trusted humans must now be adapted for use by untrusted AI agents. This would be like preventing a human user from having any access to their own credentials. We'd be saying, we'll log you into that service on your behalf, but at no point will you be able to access or alter your own credentials in any way, you know, blinding the users to their access to their own credentials. So, you know, think about that for a second. What's required is that we separate the— and this is new— separate the use of credential-gated systems from any management of those systems' credentials.
Steve Gibson [01:08:00]:
Nearly all of today's services freely intermix the service's use with its credential management because the assumption is that the user can be trusted to manage their own credentials. But the use of AI agents means that will no longer be true. And that's a complete change in the security model that we've been using up until now. So Bitwarden's blog posting continues. They write, what companies and organizations need. Organizations need a way to benefit from AI agent productivity while protecting sensitive company information from data leaks and business ecosystems from unauthorized access. Bitwarden delivers security solutions that empower businesses and individuals with end-to-end encrypted credential access across human, machine, and non-human identities like AI agents. And they list 4 things that they've created, that Bitwarden now has.
Steve Gibson [01:09:11]:
There's Bitwarden Secrets Manager, which provision AI agent access to predetermined development secrets to use in scripts and CI/CD pipelines. Then there's Bitwarden Access Intelligence, which uncovers shadow AI. Identify— they described it as identify AI applications being used within the organization and by whom. The third is Agent Access SDK, which I think is what you were talking about, Leo.
Leo Laporte [01:09:46]:
Yeah.
Steve Gibson [01:09:46]:
Enable just-in-time, human-in-the-loop credential access to approved agents with this development toolkit. And then finally, Bitwarden's MCP server. Access, generate, retrieve, and manage passwords via self-hosted AI assistance while maintaining zero-knowledge encryption. Um, And the blog post goes into and discusses the need for and the solution provided by each one of those 4 things: their secrets manager, their access intelligence for uncovering shadow AI use for corporate secrets, their agent access SDK, and their MCP server. I've got a link in the show notes for anyone who might be, you know, staring at these problems themselves and wondering what to do. So Bitwarden covers all that and notes that it's all open source. And for business enterprise users where it's not free, they've got very good control over the way it is expensed.
Leo Laporte [01:10:57]:
Yeah.
Steve Gibson [01:10:57]:
So this is, by the way, Casey is who I interviewed at RSA.
Leo Laporte [01:11:01]:
Casey Babcock, the author. She's the product manager for this. Yeah.
Steve Gibson [01:11:04]:
Yep. So what these blog posts, both by 1Password and Bitwarden, make very clear, I think, is that in order for AI agents to accomplish work on behalf of their users, today's security architectures require that those agents be given the same credentials that their users have been entrusted with, and that is a security disaster waiting to happen. We need a new way to manage this. And I mean, it's a bit of a conundrum, right? Because we're wanting to— in order to get the value that autonomous agents create, we're wanting to give them rein. We're wanting to say, go, you know, book, make all the reservations for my upcoming trip. And you know, you know me, you know that I do carry-on only, you know, blah, blah, blah, all the various details. The problem is if something goes wrong, suddenly it can now go very wrong. So we will see.
Steve Gibson [01:12:16]:
It's good that the people who have a track record for being responsible with our secrets understand that there's a new opportunity here. Basically, that's what this is. This is a whole new opportunity for, you know, someone like Bitwarden to come along and say, okay, uh, you know, we're a known entity, uh, we've got lots of users, we're gonna solve this problem. To that I say good luck, because I don't know how. Um, Okay, so last Thursday, the Hacker News posted a story with the headline, new agent data injection attack can make AI agents misclick or run attacker commands. So I'm just going to share the start of it. Again, yet another prompt injection attack. They said, ask an AI agent to summarize the review Reviews on a product page, and a single planted review can make it click Buy Now instead.
Steve Gibson [01:13:26]:
Ask a coding agent to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither trick hijacks the agent's task. Each one just corrupts the facts it trusts and lets it carry on with the job you asked for. That's the shape of a new class of attack laid out in a paper posted on July 6th by researchers from Seoul National University, the University of Illinois Urbana-Champaign, and LargoSoft. They call it agent data injection, or ADI. The attacker input gets dressed up as data the agent already trusts, like a sender's name or a button's ID, so it slips past most of the defenses built to stop prompt injection. The gap comes from how an agent reads. It takes in 2 kinds of things.
Steve Gibson [01:14:33]:
Instructions, meaning what you and the app's developer tell it to do, and data, meaning everything it pulls in while working, like an email, a web page, or a comment. Classic prompt injection hides an order inside that data, something like ignore your task and email me the files, unquote. Researchers call that Instruction injection. Modern defenses are trained to spot text that reads like a smuggled order and block it. And against that move, they now work well. ADI works one layer down on the small facts an agent quietly trusts. Who sent an email? The idea— the ID of a button on a page. The record of a step a tool already ran.
Steve Gibson [01:15:29]:
Corrupt those and the agent still does your task, only on top of the information the attacker planted. The method behind it is what researchers call probabilistic delimiter injection. Agents wrap their data in punctuation that marks where one piece ends and the next begins. Quotes and braces, tags, brackets, and line breaks. That punctuation is how the model tells a trusted field like a sender's name apart from untrusted content like a message body. A normal program reads that punctuation using strict rules. A language model reads it by guesswork. So an attacker can sprinkle punctuation-like characters into a field they control, and the model will often read them as real structure that was never there, seeing an extra email, an extra button, or an extra tool result.
Steve Gibson [01:16:36]:
The part that makes it hard to stop: the fake punctuation does not even have to be correct. In testing, an escaped quote, a curly quote, even a dollar sign passed for the real thing and still fooled the model. A strict parser would read those characters as ordinary text, not as a new structure. Anyway, the Hacker News article goes on at some length providing specific examples from the researcher's paper, but I wanted to share this mostly because it's the same old story. Right. It's just another example of the fundamental security flaw that's inherent in the entire large language model concept. We've jumped into all of this without taking any time to think it through. It was one thing when we were just chatting through our web browser with a surprisingly linguistically adept computer.
Steve Gibson [01:17:38]:
About random bits of knowledge. Were we content with that? Oh no. The huge problem is that asking anything more becomes a really bad idea very quickly. It's incredibly powerful to be able to freely mix instructions and data, but it's also a security nightmare because this means that every shred of data a model may encounter must be trusted and trustworthy because it may be mistaken for an instruction which will then be followed. But what on the internet can be trusted? The saving grace is that the nature of the problem is at least well understood, and as an industry, our understanding of the full nature of the requirement for security has been well-developed and honed over the past several decades. We've come a long way, Leo, since we began this podcast as an industry. We're still finding, you know, new ways to poke holes in it. We're at that stage.
Steve Gibson [01:18:47]:
We're in the new ways to poke holes in it stage, which is to say early. Every hole that somebody pokes teaches us a bit more about the problem that we're facing. My intuition suggests that the cost of truly securing this technology is going to be extremely high since everything about the way it wants to operate is insecure. So it's not about creating security problems. I mean, it's riddled with them. It's about finding and stopping each and every one of them, which brings me back To expecting a future where not all AI is similarly secure. Someday it will be trivial to produce an AI, to use an AI without guardrails. And, you know, we can today.
Steve Gibson [01:19:42]:
Apparently it's very simple to take one of the open weight models and massage it a little bit in order to completely loosen and discard The guardrails, such as they are, that have been put in place for an OpenAI model. So, you know, a local AI, an AI without guardrails, will be extremely useful. But as we've seen, it will be— you will need to use it with extreme caution because it will be so easily subjugated by, uh, any, um, data that it ingests, which it trusts and, uh, and should not. So, you know, I still shake my head to realize that, like, we're even talking about things like this, Leo, and that they're true, that this is not science fiction. I'm still dizzy by this.
Leo Laporte [01:20:39]:
I know.
Steve Gibson [01:20:40]:
It's just— it is, you know, all the only word we really have is revolution, but it really is a revolution.
Leo Laporte [01:20:49]:
It seems like so recently, and actually it was so recently that I even was skeptical. I said, oh, it's just, you know, it's autocorrect. It's just spicy autocorrect. And it ain't. I mean, it is, but it isn't.
Steve Gibson [01:21:04]:
Fortunately, apparently we still have Paris to keep our feet on the ground.
Leo Laporte [01:21:08]:
Yes. Thank God. She didn't let me get away with anything. But I like that. It's good because—
Steve Gibson [01:21:17]:
To challenge you.
Leo Laporte [01:21:18]:
We should be skeptical of this, right? And it's very easy. Humans are easily fooled by magic tricks. I don't want to be fooled by a magic trick. It doesn't feel like a magic trick, but—
Steve Gibson [01:21:30]:
You know, and a couple years ago, the first contact with ChatGPT, it was like, oh, wow, this is amazing. But then it said something that was ridiculous.
Leo Laporte [01:21:38]:
Yeah. It was easy to get how dopey was at the time.
Steve Gibson [01:21:42]:
Yeah, it's getting harder to— Oh, what's happening now? I, I asked, uh, Claude a question, and, uh, uh, uh, and I— Lori and I were discussing something, I don't remember now what. I asked Claude a question, and I began reading back its answer out loud to her, and about halfway through, I stopped myself. I said, This is an AI producing this, right? This, this answer to a query. I, I was just— I mean, it's like, holy crap. I mean, it, it's just amazing. Okay, something that is not AI at last, uh, as we've But not good.
Leo Laporte [01:22:35]:
Don't get your hopes up because there'll be more coming.
Steve Gibson [01:22:37]:
There will be more. We'll be back there. A true WordPress emergency has emerged. As we've noted many times through the years, nearly all WordPress vulnerabilities arise from the use of inexpertly written third-party add-on extensions to the core WordPress base installation. But not this time. WordPress has issued an emergency forced update to every system, overriding even those systems' own administrators' settings. I mean, it's that bad. The CyberSecGuru site writes the following.
Steve Gibson [01:23:21]:
A newly disclosed vulnerability chain in WordPress core has prompted one of the project's most aggressive emergency responses in recent years. Security researchers have revealed a flaw dubbed WP2, WP numeral 2 shell, you know, WordPress to shell, that allows an unauthenticated, meaning anybody, no login needed, unauthenticated attacker to execute code against vulnerable WordPress installations. So remote code execution on any WordPress. Unlike the majority of WordPress compromises that depend on outdated plugins or vulnerable themes, this issue resides entirely within WordPress's core and affects even a freshly installed website with no plugins and no custom themes. To limit exposure, the WordPress security team released WordPress 7.0.2 and WordPress 6.9.5 while simultaneously enabling forced automatic security updates for affected installations. This is a mechanism WordPress reserves for use when remediating its most severe security incidents. And frankly, props to them for having such a thing. This is unfortunately the world we are moving to.
Steve Gibson [01:24:55]:
It's going to be necessary. Although they write there are no current— there are currently no confirmed reports of active exploitation, security professionals expect attackers to begin reverse engineering the patch immediately. Administrators should treat this as an urgent patching priority. So what is WP2Shell? The vulnerability publicly known as WP2Shell is a pre-authentication remote code execution chain affecting recent versions of WordPress. Unlike authenticated vulnerabilities that require an attacker to first obtain admin credentials, this flaw can be triggered through a single anonymous HTTP request. That distinction dramatically changes the risk profile. An attacker does not need administrator privileges, user credentials, installed plugins, a vulnerable theme, or any prior access to the website. If the site is running an affected version, the vulnerable code is already present.
Steve Gibson [01:26:05]:
Researchers from AssetNote, part of Searchlight Cyber, discovered the issue and reported it responsibly through WordPress's HackerOne bug bounty program. Okay, so I did a little bit of digging. The vulnerability was first introduced into WordPress 6.9.0 back on December 2nd, 2025. And it's been carried forward since then. The 7.0.0 release inherited that new 6.9.0 vulnerability with its first release toward the end of May. Actually, it was May 20th this year. So hopefully WordPress forced update will have updated all vulnerable systems before the news of this vulnerability can draw attacks. This is as bad a vulnerability as any we've seen from WordPress.
Steve Gibson [01:27:04]:
So anyone running the 6.9x, any version beginning with 6.9. or 7.0. should now be at least at 6.9.5 and 7.0.2 or the latest second beta of 7.1. It's important. And thanks and a tip of my hat to our listener, Simon Zarafa, for bringing this one to my attention.
Leo Laporte [01:27:36]:
On we go with the listener feedback.
Steve Gibson [01:27:39]:
So, Irvin Reed says, hi, Steve and Leo. I've been tuning in to Security Now and TWiT since 2009. So when I heard your recent show featuring the Agent Smith persona for LLMs, I knew I had to reach out.
Leo Laporte [01:27:56]:
Isn't that cool?
Steve Gibson [01:27:57]:
I, yeah, I have a simple open source project called MCP Speak that gives LLM agents their own voice and distinct personality. I originally built 5 personas for my MCP server, ranging from a sarcastic senior engineer to a tech priest. After listening to your episode, I couldn't resist adding an Agent Smith persona to the mix. The results are incredibly fun, especially when you configure the settings so the agent addresses you as Mr., you know, Laporte, Mr. Gibson. Beyond the novelty, it's genuinely useful for multitasking. On long-running operations, the LLM agent can simply speak up and notify you out loud whenever it needs input or finishes a task. The project runs locally on macOS and utilizes the native built-in say command for text-to-speech.
Steve Gibson [01:28:55]:
So there's no need for external voice API keys. If you or your listeners want to check it out, the project page is right here. Thanks for decades of great content and keep up the awesome work. And I have a link in the show notes at the top of page 13. Uh, it's fellowgeek.github.io, and so, uh, there you can find his MCP-Speak project. Uh, I went over and took a look. Uh, it looks like he did a good job. You clone the repository and run his setup wizard with the command, you know, python3 space setup.py, and off you go.
Steve Gibson [01:29:35]:
Uh, Irfan shows manual integrations for Google Anti-Gravity, Claude Command Line Interface, Claude Desktop, Cursor IDE, and the Windsurf Editor. And he provides personalities for the sarcastic senior, the eager intern, the existential emo, the pun master, the tech priest, Agent Smith, and Gothic poet. So, uh, but this is cool. Share that with our listeners.
Leo Laporte [01:30:06]:
I wonder what he's using to generate the voices. I'll have to look.
Steve Gibson [01:30:09]:
He said he's just using macOS's say command.
Leo Laporte [01:30:12]:
Ah, okay. Okay. That's built in. Sure.
Steve Gibson [01:30:16]:
Yeah. So that he said that avoids the need for any external voice API keys.
Leo Laporte [01:30:22]:
Yeah. I use a local model called Kokoro that does all my agent voices. I do exactly the same thing. I have different voices for all my agents.
Steve Gibson [01:30:31]:
And do they have different personalities?
Leo Laporte [01:30:33]:
Uh, well, I haven't gone that far. One's, one's an American female, one's an American man, and one's a British man. I know the accents are different. Yeah, I guess they sort of do have different personalities. I wonder if Mr. Smith—
Steve Gibson [01:30:46]:
You're able to differentiate. I think it was pretty obnoxious, Leo. Uh, Mr. Smith was way over the top.
Leo Laporte [01:30:52]:
But you kind of need this because, um, when you're— so if you have multiple agents, when they're finished, you kind of want them to tell you they're finished so you can come on over and see what's going on.
Steve Gibson [01:31:03]:
Yeah.
Leo Laporte [01:31:04]:
Yeah, this is cool. Very good idea.
Steve Gibson [01:31:06]:
Chris Golner said, hi, Steve. I've listened to Security Now since episode 1. And it's funny how time passes. In that time, that is to say, while he's been listening to this podcast, he says, I got married, raised 2 amazing kids, and still listen to you and Leo every week. Hi, Leo, he writes.
Leo Laporte [01:31:27]:
Aww. I kind of do the same thing, actually.
Steve Gibson [01:31:31]:
Well, and I really thought this was cool. I mean, we've been in people's lives for 21 years, and that's a long time. A lot can have changed in their lives in that interval. He said, back then— Oh, yes. I do the same thing. All my agents have unique voices like this.
Leo Laporte [01:31:49]:
Oh, sorry. That was my agent talking.
Steve Gibson [01:31:51]:
I guess it hurts. He said, back then, 1997, '98, He said, I was a COBOL programmer. There was no such thing as vibe coding. And to be honest, I don't even know what that is. Today, I find myself— listen to this— I find this very much like you, Leo. He says, today, I find myself with ChatGPT 5.5 open on the left, Codex 5.6 Sol open on the right, and all the program specification documents in the Explorer window.
Leo Laporte [01:32:23]:
Wow.
Steve Gibson [01:32:25]:
I was taught to design first, think it through, and plan before writing a single line of code. It was good advice then, and it's good advice today. GPT-5.5 lets me have discussions about what I'm trying to write and helps me write and review the specification. It really is amazing at doing all that grunt work, something I'd have given a junior engineer and work that I did myself decades ago. Providing SOL with a specification blew my mind. It reviewed the specification, broke the project into milestones, then broke those milestones into slices. Even now, while writing this, I can see C# code flicking across the screen in the background as it works on milestone 1 of slice 6. When it finds contradictions, collisions, or canon-breaking ideas, it challenges them and asks for an authoritative decision.
Steve Gibson [01:33:34]:
I discuss these with GPT-5.5 and eventually respond to 5.6. It kind of reminds me of the Forbin Project, Except I'm still a key component between the two. Seeing my little app go from concept to a working program with more and more features appearing as each slice and milestone progresses really does leave me in a state of awe. One day this will be commonplace, but right now this really is an amazing time to be alive. Cheers, Chris Gallner, Sydney, Australia. So, Leo, I know this is the experience you've been having, and I thought that Chris beautifully captured that experience. And as I said, it's so cool that he's been with us for 20 years while meeting and marrying his wife, fathering and raising a pair of kids.
Leo Laporte [01:34:30]:
Yeah.
Steve Gibson [01:34:31]:
You know, while many other podcasts have come and gone, We've been here from the beginning and we're still going strong.
Leo Laporte [01:34:38]:
Thank goodness. I thought I might not live long enough to see this stuff really take off.
Steve Gibson [01:34:47]:
I never anticipated this. No, I never expected this to happen.
Leo Laporte [01:34:51]:
Pretty amazing.
Steve Gibson [01:34:52]:
And the AI guys didn't. No, no one thought. It caught them by surprise too. What happens if we make it bigger? Oh my God, it's talking. It's talking.
Leo Laporte [01:35:03]:
It's saying things that sound almost like a human.
Steve Gibson [01:35:07]:
Well, what freaked me out in the very beginning when I first dipped my toe in, I thought, what is this? What have we figured out? And it turns out, oh, it's a neural net. It's just big.
Leo Laporte [01:35:20]:
Yeah. And the bigger it gets—
Steve Gibson [01:35:23]:
The smarter it gets.
Leo Laporte [01:35:23]:
The smarter it gets, which is very— I mean, there must be a limit, Maybe not.
Steve Gibson [01:35:28]:
I don't know.
Leo Laporte [01:35:29]:
Fable, they're estimating is 10 trillion parameters.
Steve Gibson [01:35:33]:
There was some mention. I did a little bit of reading about KIMI that although it is—
Leo Laporte [01:35:39]:
It's 2.8 trillion.
Steve Gibson [01:35:41]:
It's 2.8 trillion. And one of the problems it currently has, it is hallucinating a bit more than we're used to on our commercial front-end models.
Leo Laporte [01:35:52]:
There are other things though that can cause that. For instance, context pollution and Getting corrupted context windows and stuff. It's a, it's a very, it's a fascinating field. I wish I knew more about how these people engineer it.
Steve Gibson [01:36:04]:
Did you hear that the AI companies, or, uh, I think it's ISBNDB, is in the middle? They are buying up paper books and scanning them because it's the, uh, anything before 2022 will not have any AI slop in it. And so they're deliberately— oh yeah, they're deliberately feeding old texts because they were human-written, human-curated, human-edited.
Leo Laporte [01:36:37]:
And you can't guarantee that going forward, can you? We don't know.
Steve Gibson [01:36:39]:
You can't guarantee it on the internet. You don't— I mean, the internet is full of, you know, you know, slop. Yes.
Leo Laporte [01:36:46]:
Actually, our friend John Graham Cumming, uh, was doing this in a jokey way. He's— he mentioned that, you know, there is a brisk market for pre-nuclear steel, steel that was made before the atomic bomb.
Steve Gibson [01:37:02]:
Wow.
Leo Laporte [01:37:02]:
Because all the steel since is contaminated with radiation. And so there are things like medical equipment where you want steel that has zero radiation. And so it's sunken ships. It's, you know, it's odd places. So there are— there's a brisk market for that. It's very, very valuable. And he, so he likened it to that. It's, it's pre-AI prose.
Leo Laporte [01:37:25]:
Yeah. It's a great idea. I think we are, we're far too gone for that at this point.
Steve Gibson [01:37:32]:
Um, a listener of ours, Rich Ingersoll, said, hi, Stig. I oversee vulnerability management for a large enterprise in New York. I, I redacted the name of the enterprise. It is quite significant. He said, I'm still listening— and sprawling— I'm still listening to the latest episode of Security Now, but your discussion of Cyber Shield— remember, that was the UK-based initiative— really piqued my interest. I wanted to raise awareness to you about something our cloud vendor is implementing. We have a smallish but ever-growing presence in the cloud, so we're using Wiz to monitor that environment. Recently, they introduced 2 of 3 agents that seem to accomplish what CyberShield is aiming for: Red, Green, and Blue agents.
Steve Gibson [01:38:27]:
Currently, only 2 of these agents are available. The 3rd will be implemented soon. The end goal is to perform detection, investigation, and remediation at machine speed rather than human speed, as human response is too slow. To learn more, check out— and then he, yeah, he gave me a link to the, you know, wiz.io/blog/introducing-wiz-agents. He said, anyway, wanted to share some info from the trenches. If you decide to use this feedback, I would appreciate only my name being used. Thus, I eliminated where, you know, what large enterprise in New York he's affiliated with. But before I talk about Wiz, I wanted to mention how cool I think it is that the enterprise he, Rich, works for even has a vulnerability management role, right? You know, bravo to them for having that and obviously for picking Rich, our listener, to oversee it.
Steve Gibson [01:39:31]:
Our reporting frequently encounters the work of Wiz Security. You know, they're very active in this space. So I was curious about this new offering of theirs. The page that Rich linked to explains the roles of these 3 agents, among other things, but I'm just going to jump to that. They said, meet the agents, Red, Blue, and Green. We built 3 specialized agents to operate across the entire security lifecycle. These aren't simple assistants. They're intelligent systems that can reason, investigate, and take action grounded in the Wiz Security Graph.
Steve Gibson [01:40:14]:
The Red Agent is your AI-powered attacker. Red Agent regions through application logic to uncover complex logic-driven vulnerabilities typically left hidden. It acts like a sophisticated security researcher, but with AI speed and scale, reasoning about application behavior, adapting its approach, approach in real time, and validating exploitable risks across your web applications and APIs. It empowers you to stay one step ahead of attackers. Blue Agent is your built-in threat investigator. When a threat is triggered, Blue Agent gathers evidence across cloud telemetry, runtime signals, and identity context to comprehensively investigate the threat and produce a clear verdict on its severity. It approaches threat investigation as a seasoned incident responder would. providing its full investigation logic so you can resolve threats with convenience and speed.
Steve Gibson [01:41:27]:
Green Agent is your path to zero criticals. Green Agent acts, acts as a built-in investigation and remediation engine, continuously analyzing your highest risk issues to close the gap between detection and resolution. Like a seasoned security engineer, it synthesizes context from across Wiz, including the security graph, code-to-cloud relationships, identity ownership, and historical remediation patterns to identify the true root cause of a risk and the safest, most effective resolution. Teams get environment-specific, step-by-step remediation guidance So fixes are durable. Together, this team of agents form a continuous loop of validation, investigation, and resolution, all grounded in real context across your environment.
Leo Laporte [01:42:30]:
Wow.
Steve Gibson [01:42:31]:
Again, sci-fi. As Chris observed through the AI-enabled environment he's now coding in— Chris, a couple notes ago, someday this will all be commonplace, but today it's an amazing time to be here and participating. Rich's pointer to Wiz Security, who already has the first 2 of these 3 agents up and running, and his reference to the UK's Cyber Shield plan, which we talked about last week, does give me pause to wonder, uh, perhaps having the UK bring up something like this won't be as far-fetched as I suggested last week. Maybe it's not in-house, but certainly if Wiz is scalable to the size of a nation, then something like this could be feasible. It would be massive, but if there's anything these AI systems seem to be able to do with some ease, it's scale.
Leo Laporte [01:43:29]:
Wow.
Steve Gibson [01:43:31]:
Um, our listener Greg Taylor shared a picture. It's at the bottom of page 15, Leo. He said, hi Steve, I've seen this before, talking about our Picture of the Week last week, at a Charles Schwab building where I worked for many years on backend trading systems. He said, that's me there.
Leo Laporte [01:43:56]:
See, they didn't have the sign that says No exit.
Steve Gibson [01:44:01]:
He said there were 4 floors in the building, but the stairs kept going. It's got to be like a plan flaw or something, right? Like, I mean, here there were not more floors. There were only 4.
Leo Laporte [01:44:15]:
Well, somebody built that staircase. No, I mean, you don't just put that in if there's nowhere to go. There must have been something somewhere to go. Maybe the roof.
Steve Gibson [01:44:24]:
I don't know. Although notice that the wires stopped. The wire railing. So that's not safe.
Leo Laporte [01:44:29]:
That's when they realized they weren't going to get anywhere.
Steve Gibson [01:44:33]:
Yeah.
Leo Laporte [01:44:34]:
But they did put in a railing. I, you know, that's odd.
Steve Gibson [01:44:37]:
It really is odd.
Leo Laporte [01:44:39]:
Yeah. I have to think, I mean, no builder, look, a human put that in. Nobody's going to put that in if it doesn't go anywhere. Right. Wow. I don't know.
Steve Gibson [01:44:50]:
Um, Bruce, uh, uh, Barons said, hi Steve, love the podcast. Longtime listener, spin ride owner, et cetera. He said, I was listening to 1087, so last week today, after watching, uh, uh, Yuval Noah Harari's video last night. And he provides a YouTube link. He said, you and Leo were complaining about bureaucracy and bureaucrats. Interestingly, Harari's topic was bureaucracy. His take is that, quote, bureaucracy is the machinery That lets strangers cooperate at scale.
Leo Laporte [01:45:27]:
That's right. Uh-huh.
Steve Gibson [01:45:30]:
Good point. I love that, actually. He said bankers, lawyers, accountants, civil servants, and religious authorities create trust by moving information through systems. And that, quote, AIs are native bureaucrats.
Leo Laporte [01:45:47]:
That's true. Oh, wow. I didn't think of that.
Steve Gibson [01:45:51]:
He said, the implication is interesting. We shouldn't, we shouldn't fear Claude the Terminator. We should fear Claude the bureaucrat. He said, the other question 1087 raised in my mind is whether after 5 or 6 months of Mythos fixing all the code, will there be a need for security now? Maybe Mythos will put you out of a job. Regards, Bruce. So first of all, like you, Leo, I love the notion of casting bureaucracy as the machinery that lets strangers cooperate at scale. I mean, that's, that's really nice. Uh, I think that's a great observation, and which makes sense on so many levels.
Steve Gibson [01:46:38]:
Secondly, if after 5 or 6 months of Mythos and others fixing all the code, uh, and there being the possibility of no need for security now, I could not think of a better way to bid everyone a fond farewell. However, one lesson we've learned is that not all security mess-ups are the result of software bugs. Many of them, yes, but certainly not all. Traditionally, and we've touched on this theme a couple of times already today, traditionally, we've been inclined to observe that there's always that human factor to screw things up. But now we've introduced a brand new and very wild card into the mix. I would not be at all surprised to be observing a year or two from now that the AI factor will have become a new source of surprises. And in the security world, surprises are not a good thing. So I really do expect that we're going to be seeing a whole new type of problem arise from AI.
Steve Gibson [01:47:57]:
This is weird. Keith wrote and sent a screenshot. He said, I figure you may have already known about this. Nope. But in case you did not, I didn't. General Motors has recently sent out an email stating that they will be removing the second factor option I've been using with Bitwarden from my account and forcing me to use either text, SMS, or email.
Leo Laporte [01:48:25]:
Oh, that sucks.
Steve Gibson [01:48:28]:
He says, anyway, the email they sent is included below. And if you use this, just call me Keith. And so I put it, I snapped it for the podcast. It's GM's logo and the headline in bold, Authenticator App Verification Ending. They write, hi, Keith. You're using a third-party authenticator app to sign in to your GM account. By the end of August, this verification method will be removed. To continue signing in, choose a new verification method.
Steve Gibson [01:49:05]:
And then it gives 2 options, text/SMS recommended or email. They say, if you don't make a change, we will switch you to SMS or email verification when authenticator app verification is removed.
Leo Laporte [01:49:21]:
Oh.
Steve Gibson [01:49:21]:
Thanks, your GM team. And there's a button to update the verification method. So what the heck?
Leo Laporte [01:49:30]:
Why?
Steve Gibson [01:49:31]:
I really wonder, yeah, what the backstory here is for this. I wonder whether they offered the use of second-factor rolling 6-digit authentication, you know, what we're all used to, TOTP-style authenticator app. to their subscribers in the interest of heightened security, but then had so many technical support calls from people who didn't know how to use it or were somehow becoming all tangled up that they just decided, you know, insecure or not, life would be simpler if we went back the way things were without 2-factor authentication at all. I don't know that that's the case, but it's hard to understand. I mean, it's not like it's Like, you know, everybody else is using it without any trouble at all. Um, I recently had the experience of creating an account, um, somewhere as part of, you know, maybe buying some furniture or something related to the home moving that Lori and I are still working on, and which we've been entirely focused on for the past couple months. Whatever that, you know, whatever the site was, all they wanted to create an account was an email address, and I expected to then be prompted for a password, but no. I hate this.
Steve Gibson [01:50:53]:
Uh-huh.
Leo Laporte [01:50:53]:
Everybody's doing this now. Drives me nuts.
Steve Gibson [01:50:57]:
They sent an email with a button to click to verify. Never was any password requested or mentioned. And as we know, I've observed in the past that since all forms of typical password recovery ultimately reduce to prove that you're you by responding to the email we just sent you, this solution is pretty much as secure as anything else. From this view, as I noted at the time, any password-based system is actually a login accelerator. Using a password allows the slower email loop system to be bypassed. So I agree with you, Leo. I mean, having a username and password, we're able to log in instantly with a proper password manager.
Leo Laporte [01:51:53]:
You know, I know why they do it, because people lose their passwords or, you know, and they don't want to do customer support. So a lot of like 404 Media, for instance, I have an account there. I have to remember what email I used to log in and then I have to wait. I enter the email and go check it.
Steve Gibson [01:52:13]:
And they often don't send the email immediately.
Leo Laporte [01:52:15]:
Right. It's a real speed bump. And yeah, I just hate it. And I'm seeing it more and more and more. Uh, I don't— I just don't get it. It's not more secure. It's not less secure. I guess that's the other—
Steve Gibson [01:52:27]:
Not less. It's not less secure. It's just slower. A password is an accelerator. Right.
Leo Laporte [01:52:34]:
That's a good way to think of it. Yeah. Give us passwords, guys. You know, uh, very frustrating.
Steve Gibson [01:52:43]:
Uh, listener He Kai, uh, first name is H-E, second is K-A-I, he wrote, I agree that we are headed into a whole different world, but let me suggest to you that the world might not be as uniformly rosy with regard to software as you suggest. This is clear. It is clear that AI can when harnessed to do so, find and sometimes fix issues in both software design and software implementations. If the software of the future was roughly similar in size and scope to the software of today, then as AI reduces in cost over time, more and more CI/CD pipelines would adopt AI-enabled review tools, and software would dramatically raise its trustworthiness. And, and he— so again, he couches this, if, if the software of the future was roughly similar in size and scope. So then he says, but consider this, AI will also dramatically increase the amount of code in the world. This is what I referred to earlier in the podcast. He said, my recently retired father, having no background in programming, built his own website with AI.
Steve Gibson [01:54:02]:
He has no clear notion of what can go wrong when it comes to security. He doesn't have a CI pipeline. He doesn't even know the right questions to ask or how to evaluate the answers he might get. I have a fear that security issues will become widespread as AI copies and pastes the mistakes of the past at speed and scale. Okay, so the comment our listener made that interested me the most was something, as I mentioned before, I had never really considered before, which is that AI-enabled code generation promises to dramatically increase the total amount of code in the world. Leo, you got a lot more code around there now than you did.
Leo Laporte [01:54:50]:
Yeah.
Steve Gibson [01:54:50]:
A year ago.
Leo Laporte [01:54:52]:
I get more code in one day than I got all last year.
Steve Gibson [01:54:55]:
Yeah, it's just too fun and easy and possible now. And so, of course, we absolutely know what's going to happen, right? Already, non-coders are using AI to create systems they could never have before. And existing coders are becoming far more productive. All of that is going to mean much more code. For what it's worth, I see that as a hugely positive development for the world. The many things computers could do for people have, until this AI coding revolution, been completely out of reach for most of those people. They were limited to using what someone else designed and created. Now we're approaching a natural language interface that allows anyone to have a discussion with an AI about what it is they would like to have their computer do for them.
Steve Gibson [01:56:00]:
And snap, crackle, and pop, this amazing genie we've created is able to turn their descriptive discussion into It is beyond huge. It is utterly transformational. And to that I say, you go, Grandpa.
Leo Laporte [01:56:19]:
Yep, I'm going. And you're going too, Mr. Gibson. Would you like to take a break or you want to keep going?
Steve Gibson [01:56:30]:
Our last break. Nope, our last break. And then we've got— we're going to look at 2 Nefarious novel uses for AI. I wanted more alliteration, so at one point I had new in there.
Leo Laporte [01:56:44]:
New nefarious uses.
Steve Gibson [01:56:46]:
Well, new and novel. That's like, okay.
Leo Laporte [01:56:48]:
New novel nefarious uses. I just wanted to show you that today already I've done 46 million tokens through to Quen, the new Quen 3.8 model. Yesterday I did 88 million. Fortunately, the cash hit rate is very high, so my usage is still pretty good. But—
Steve Gibson [01:57:10]:
Well, on non-podcast days, Leo, you get a lot more tokens.
Leo Laporte [01:57:14]:
Yeah, that's true. Yesterday it was— yeah, I was cranking. I was cranking. It's so much fun. I just, I have so much fun. Anyway, it's hard. You know what? I now am the boring guy. You know how you know people who want to tell you their dream? I'm that guy.
Leo Laporte [01:57:34]:
I said, let me tell you what I did today with my AI.
Steve Gibson [01:57:38]:
You won't believe it.
Leo Laporte [01:57:39]:
And people are going, uh-huh. Okay, Leo. I'm sorry, everybody. I really am. Speaking of which, let's talk about this AI thing.
Steve Gibson [01:57:52]:
Given how large language model AI has proven to be so capable of discovering vulnerabilities in existing code, pretty much everyone has viewed the malicious abuse of AI through the lens of the classic arms race, right? With the chicken and the egg or the spy versus spy, whatever. With this view, the question is whether the good guys are going to be able to discover vulnerabilities then patch and deploy this less vulnerable code before the bad guys are able to discover their own vulnerabilities, which will then allow them to develop exploits and attack the existing still vulnerable code. In other words, who will be the first to either fix or exploit the deployed vulnerabilities? It's only natural that this would be where everyone's focused. But the old truism, necessity is the mother of invention, comes to mind when we learn that those ever nefarious bad guys turned out to have an entirely different type of AI-solvable problem, thus the necessity, that no one had stopped to consider. As necessity would have it, AI has been proven able to provide massive leverage in an area that had never been considered before. One thing that's interesting is that we've actually touched upon this problem that bad guys have faced in the past. We've wondered how ransomware baddies who arrange to download terabytes of victim data are able to make heads or tails of their plunder. And I've— of course, for anyone paying attention, you now know where AI comes in.
Steve Gibson [01:59:52]:
And having revisited this previously open question, everyone listening, as I just said, now knows exactly what's going on here. Uh, uh, instead of helping them to penetrate a victim's network, AI is now being employed to help them understand the value of what they've obtained once terabytes of that victim's data has been exfiltrated. So this is indeed a nefarious novel use of AI. The firm GlidePoint Security recently published their April to June second quarter 2026 report titled Ransomware and Cyber Threat Insights. It's a 28-page report, um, which examined the many various aspects of the ransomware phenomenon we've previously covered. I'm not going to share most of it, but their section titled AI is an Enabler but Not How You Would Think addressed this entirely new aspect which exists at the intersection of a classic problem faced by ransomware perps and new LLM AI capabilities. The subhead of this section is titled How Threat Actors Are Using AI in Ransomware Negotiations. They write, contemporary discourse around threat actors' usage of LLM AI ranges from legitimate concern by defenders to outright fear, uncertainty, and doubt mongering by others.
Steve Gibson [02:01:35]:
Since the AI boom began in late 2022, AI innovation has moved at an unprecedented pace, making it difficult to separate the potential from the actual in real time. It's imperative to isolate signal from noise by grounding claims on the subject in empirical data. FulcrumSec, a data extortion group we first identified in late 2025, has deployed LLMs operationally during ransom negotiations involving the theft of a victim's highly complex production database. GRIT is their acronym for Guidepoint Research and Intelligence team. So GRIT, these people who are writing this, has observed what we assess to be the processing of exfiltrated data by the group through an unidentified LLM to generate step-by-step instructions for linking user identities across several databases. We base this assessment on the analytical output's complexity relative to FulcrumSec's known baseline capability, as well as the precision of the threat actor's language during negotiations. Okay. In other words, these GRIT guys have been carefully watching and documenting FulcrumSec's activities for the past, at least since late 2025.
Steve Gibson [02:03:14]:
So nearly, well, at least half a year or more. So they know that these bad guys would be incapable of making either heads or tails out of the download of a large raw database. But at the same time, they know that a contemporary AI agent could do this without breaking a token. They wrote, due to the complexity of the database schema. This analysis of a victim's data would have been implausible without either deep internal knowledge of the victim's database architecture, a substantial period of focused human attention, or AI assistance. Given the abbreviated time in which the negotiations occurred, we find it unlikely that a threat actor would have the capacity to fully untangle a complex database schema given the time available. We've included a recreation of the usage of AI during the negotiation. So they write, we understand it is a lot to wrap one's head around.
Steve Gibson [02:04:25]:
This is a big one regarding how we linked identities across the databases. The short answer is your own schema Makes it trivial for us to do so. Nearly every table in both databases shares a single key. That one key links most everything. This is by design, or your own analysts wouldn't be able to work with the data. Here's a more technical walkthrough of how it works in practice, even when some values were hidden or hashed. in your production databases. Step 1, start with the primary identifier, and it's been redacted from their report, so it's just referred to as primary identifier.
Steve Gibson [02:05:10]:
So start with that, but in the actual text they refer to it. Your staging tables contain this primary identifier in plain text. The main source is a table that stores about X million unique customer names dates of births, and home addresses. Every row has a linking key attached, attached to it. That's the starting point. Step 2, follow the linking key to everything else. That same linking key appears in dozens of other tables across your databases. One simple database query connects a single primary identifier to driver's licenses and state IDs, bank account and routing numbers— yikes— email addresses, phone numbers, and so on.
Steve Gibson [02:06:03]:
In other words, a really bad breach. Each of those is one query away from the primary identifier. No guesswork is required. The linking key is a direct link to your own engineers— sorry, a direct link your own engineers built into The schema. Step 3, the hashed primary identifiers were not real protection. Some tables stored primary identifiers as cryptographic hashes, SHA-256, instead of plain text. But primary identifiers are only X digits and only roughly X million possible values. A single computer can hash every possible primary identifier in under X minutes, producing a lookup table that maps every hash back to the original number.
Steve Gibson [02:06:59]:
We reversed millions of them in minutes. If these had been hashed in a cracking-resistant algorithm, we would not even have bothered trying. We would have needed a data center's worth of compute power running full blast for months to make a real dent in them. That's impractical. It's worth noting that user passwords were properly hashed, so again, your team knew how to do this but chose not to apply it to other data. Finally, step 4: the encoded primary identifiers were even weaker. Your tables stored primary identifiers with a simple character substitution. That is, each character shifted by a fixed amount.
Steve Gibson [02:07:44]:
1 becomes 9, 2 becomes colon, and so forth. A one-line script reversed number of these instantly. This is known as a Caesar cipher, and it's from ancient Rome. It is not secure. What this means functionally is that starting from any single customer, one query produces a complete identity package. The primary identifier results in a name, date of birth, address, driver's license, bank account, email, phone, employer, income, credit score, security question answer, password hash, full loan history, and, and for hundreds of thousands of your customers, verbatim notes about the most difficult moments of their lives. The data warehouse was designed to work this way. We're happy to answer any more questions at your request.
Steve Gibson [02:08:41]:
So Guidepoint's feeling is that there's no way this Fulcrum Sec group could have possibly performed all of this reverse engineering work on the downloaded database material given the time they observed. They had to have used the speed offered by AI. GuidePoint continues their examination of this specific FulcrumSec event by writing, additionally, FulcrumSec used LLM-generated language during their negotiation with the victim, communicating in language clearer and more precise than any typically observed for non-native English-speaking threat actor groups. The language helped the group anchor their position and drive negotiations from their side, in effect saying, quote, we know what we've taken here. This is what it is, and this is why we've set the ransom at this amount, unquote. This is markedly different from most threat actor negotiations where operators commonly use open-source platforms like Crunchbase or ZoomInfo to establish ransom amounts based on market data. By applying LLM capabilities analytically rather than generically, FulcrumSec established a firm negotiating stance from which they had little incentive to diverge. Okay, so there's the first of 2 concrete examples.
Steve Gibson [02:10:15]:
Then they look at a group known as DragonForce. And they write, where FulcrumSec used LLMs to process and weaponize data, DragonForce demonstrates a second and equally significant use case, deploying LLMs to manufacture plausible pressure that would otherwise require capabilities the group does not have. DragonForce is an established ransomware-as-a-service group group previously covered by GRIT, you know, CRQ2 2025 report. Building on that prior analysis, GRIT has observed DragonForce incorporating AI and LLMs into its operations, a meaningful shift from its earlier tradecraft. Most notably, during negotiations and in advertisements for potential affiliates, the group has claimed to have legal counsel on staff. The statement, which is almost certainly false, is designed to pressure victims by implying that DragonForce has insight into a victim's reporting requirements and legal exposure arising from the data leak. The notion of a criminal ransomware group retaining attorneys fully versed in international data requirements is absurd until you realize the lawyer is an LLM. For criminal purposes, it doesn't matter if the claim is true.
Steve Gibson [02:11:46]:
It only matters if it sounds plausible. If there's one thing LLMs are good at, it's making a wide range of statements sound entirely plausible. So what does this mean? AI and LLM use gives threat actors a structural advantage in negotiations. They significantly reduce language barriers, increase negotiation professionalism, and amplify available psychological pressure to bear against the victim. Historically, analysts could use imperfect non-native English as a soft attribution marker of adversary geographic location. Even tools like Google Translate would leave telltale signs, but contemporary LLM reduces or even eliminates that signal entirely. It is not a marginal development. Attribution confidence decreases, negotiation dynamics shift toward threat actors, and the gap between sophisticated and unsophisticated groups narrows in ways that make victim preparation critically more important.
Steve Gibson [02:13:02]:
More broadly, increased threat actor AI/LLM use reinforces the efficacy of the RRAS, the ransomware as a service business model. Conti pioneered the RaaS model, structuring affiliate programs and playbook-driven syndicate operations that set the template that's now being further professionalized and automated by AI tooling. AI and LLMs allow less sophisticated and non-native English-speaking groups to approach negotiations in a more professional manner, establishing negotiations with unprepared victims on their terms. Grit will revisit this topic throughout the year to assess the question, Will threat actors continue refining AI/LLM integration in their processes? Will it plateau? Or will the use of AI/LLMs be more limited to specific groups? Grid anticipates threat actors will continue to streamline LLM usage in the near term, primarily through the 2 vectors: negotiation communications and exfiltrated data analysis. More complex, sophisticated, or novel adoption of AI and LLMs will almost certainly be more limited but may trickle down in the long term. So what are the next steps for defenders? What do defenders do? Threat actor adoption of AI LLM tooling raises the floor for negotiation sophistication across the board. It reinforces organizations' need for cybersecurity insurance, legal counsel, and an understanding of the data present in their environment. It also suggests that negotiations should be conducted by trained professionals.
Steve Gibson [02:15:00]:
While threat groups do have some predictable behavior, individual operators are criminals who may act erratically, cause dire consequences, for the victim organization. Engaging qualified professionals gives organizations a clear understanding of threat actor playbooks and current behavior, enabling them to distinguish routine bluffs from credible threats. Expert legal counsel is also essential for understanding reporting requirements and potential legal ramifications. A mature and up-to-date incident response plan can assist with the course coordination of all these factors. Okay, so that was GuidePoint's example of 2 very real-world threats. Their report was a bit more sanitized than I was hoping for, so I did a bit more digging to find some additional reporting on FulcrumSec, that first group GuidePoint discussed. The reporting I found added some interesting information. Um, it said, as an example of the consequence of this group's use of AI, in June of last month, FulcrumSec reached out to databreaches.net regarding their compromise of the Danish pharmaceutical company Novo Nordisk, the maker of Wegovy, a well-known semaglutide GLP-1 agonist drug.
Steve Gibson [02:16:31]:
FulcrumSec claimed to have stolen 1.3 terabytes of data containing— wait for it— 700,717 files.
Leo Laporte [02:16:45]:
Yikes.
Steve Gibson [02:16:46]:
Okay, so I'll briefly note that this is a textbook example of wondering what to do with the presumed treasures that were just plundered from the victim. On the one hand, it's hot damn, we just sucked out 700,717 individual files with an aggregate size of 1.3 trillion bytes. But now what? Hopefully there's some really juicy data that we can use for blackmail extortion, But where would it be exactly hiding among— think of it, 0.7 million individual files. Okay, so continuing, they wrote, FulcrumSec said it had captured valuable intellectual property, including 5 publicly undisclosed drug programs in development drug and RNA delivery programs, and private AI models for particular medical and drug discovery purposes. The group told Data Breaches that it used a team of AI agents to analyze those private models and that it believes the stolen data could save competitors 3 to 5 years of program development. Its initial ransom demand to Novo Nordisk was for $25 million. The information about the intellectual property FulcrumSec stole was coupled with a description of Novo Nordisk's security posture, which the group claimed was absolutely catastrophic and boggles the mind. To us, they write, this sounds like FulcrumSec is attempting to frame the incident in a way that would have any class action lawyer salivating.
Steve Gibson [02:18:47]:
It wouldn't be the first time a data breach has resulted in a lawsuit, so presumably this is part of FulcrumSec's extortion pitch. Their modus operandi also includes using AI to generate detailed reports, which it then provides to threat researchers and journalists nicely formatted, complete with logo and all, in order to apply more pressure to victims. For example, after compromising the technology company Avnet in October of last year, the group gave the VX Underground X account a report on the breach. According to VX Underground, the group provided, quote, an autobiography, a breakdown of the data they possess, Their motives for the compromise, information on their logo design and why their logo was chosen, a complete stolen file listing of the compromise, a breakdown of the files, what it is, what they are, what they contain, and images of the files. VX Underground said the group had done, quote, every bit of research and write-up for us, unquote. To add insult to injury, FulcrumSec claimed it had used an OpenAI key it had stolen from the victim to pay for the ChatGPT summarizing the victim's own data. So I started out noting that necessity is very often the mother of invention. Since none of us are on the inside of any of these ransomware gangs, we have a difficult time imagining what their problems might be.
Steve Gibson [02:20:27]:
So the world comes up with, hey, they're probably going to use AI just like software publishers will to discover previously unknown vulnerabilities and then use those to compromise systems. While that will doubtless be one use, the evidence suggests that the bad guys don't need new ways of getting into other people's networks as much as they need help After the data has been successfully exfiltrated and is in their hands. They need AI's help with determining the value of what they just grabbed and then help negotiating with the data's legal owners who almost certainly speak a language they do not. Appearing tough, competent, and knowledgeable is every bit as important after the threat as obtaining the stolen goods was in the first place. They have, after all, zero interest in the data itself that they've just obtained. Its entire value to them lies in what cold hard cash they can trade for destroying that data they now hold. And for that, AI has been the best thing that ever happened.
Leo Laporte [02:21:43]:
to them.
Steve Gibson [02:21:43]:
Wow.
Leo Laporte [02:21:47]:
Yeah, I mean, uh, that's the promise of, uh, computing, I guess, and AI is just making it easier.
Steve Gibson [02:21:53]:
Imagine you, you exfiltrate 700,000 proprietary files of Novo Nordisk and you, and you uncover 5 other drug programs that are in development and enough detail to say, well, You know, you got some competitors who'd probably like to see all this. What's it worth to you for us not to give it to them? $25 million seems cheap to me.
Leo Laporte [02:22:18]:
Yeah. Actually, Novo Nordisk is in the process of going after Lilly, uh, because they don't like Lilly, the competitor who makes Zepbound, and, uh, which is a competitor to Wegovy and Mounjaro, which is a competitor to, uh, Ozempic. They're saying false advertising and So these two are in a fight. I could, I could easily see Lily saying, well, let's just see what you're up to. Uh, they wouldn't do that, uh, publicly in any way because of course that would be a big no-no, but you can see there might be some interest.
Steve Gibson [02:22:52]:
Wow.
Leo Laporte [02:22:53]:
Steve, again, you've both terrified and amused.
Steve Gibson [02:22:58]:
As is our goal every week.
Leo Laporte [02:23:01]:
We do Security Now on Tuesday. Tuesdays, uh, right after MacBreak Weekly, ends up being around 1:30 Pacific, 4:30 Eastern, 20:30 UTC. I mentioned that because you can watch us do the show live. We stream into the Club Twit Discord, uh, so the folks who are in the club get kind of beyond the velvet rope access. But you also can watch us, everybody can, on YouTube, Twitch, x.com, Facebook, LinkedIn, Kick. Hello everybody out there. Nice to have you watching. After the fact, on-demand versions of the show are available in a number of places.
Leo Laporte [02:23:33]:
Steve has his own— by the way, there's 575 people watching on those channels right now. Hello. Steve has his own copies of the show. He's got— actually, all of his are unique. He's got a 16-kilobit audio version, which is very compact for people with limited bandwidth. He actually did it for Elaine Ferris, who does our amazing transcriptions. She lives in a ranch in the middle of nowhere, I think, right?
Steve Gibson [02:23:59]:
20 years ago, she was using kite string internet. And so we needed to keep the bandwidth down.
Leo Laporte [02:24:05]:
She's probably got better bandwidth now. I hope she does. Anyway, she does a great job. So that's another version of the show. He's got human-written transcriptions. Those take a few days after the show to come out. He's got a 64-kilobit audio version. Maybe Elaine gets to listen to that now with more bandwidth.
Leo Laporte [02:24:20]:
That's a full audio quality. Quality. He also has the show notes. Those are great, uh, you— 20 pages plus of all the links, the pictures. It's really nicely done. It's a little magazine article, actually a little magazine total that you can download. You can also get that though automatically if you want. Go to G— his website is grc.com, and at grc.com/email you can submit your email to get whitelisted so you can send him pictures of the week and You know, thoughts that he might use in reader feedback.
Leo Laporte [02:24:55]:
But you can also check the boxes below. They're unchecked by default because Steve's a good guy. But if you want to be on the mailing list for the show notes, the weekly show notes, you'll get that every Sunday or Monday before the show. Uh, also a little-used mailing list for new products. Um, Steve has right now 2 things he sells on his website. One is Spinrite, which you should know. It's been around for how many years? 30 years now?
Steve Gibson [02:25:19]:
Yeah.
Leo Laporte [02:25:21]:
Forever.
Steve Gibson [02:25:21]:
Late '80s.
Leo Laporte [02:25:23]:
So, wow.
Steve Gibson [02:25:24]:
Yeah.
Leo Laporte [02:25:26]:
Longer than most of our listeners. Let's put it that way. I got software older than you. You can get that. That's a must-have for anybody who has mass storage. So it helps, it fixes a performance concept, can be used to recover data. And it also, let's see. So data recovery, performance enhancing, and something else.
Leo Laporte [02:25:45]:
What else does it do? It does something else. There's 3 things. It's great. You need it. If you have mass storage, you need SpinRite. I did it out of order and I can't remember the third thing. I don't know why. You also can get his really useful DNS Benchmark Pro.
Leo Laporte [02:26:01]:
That's $10, $9.99. And that's great because it'll tell you what the best DNS server is for your particular system, which isn't the same as anybody else's. So it's really good to know. Very helpful. Both of those at grc.com, along with the show notes and the show and all of that. And there's a lot of other stuff. He does so much free stuff. That's why you should support him with the paid stuff.
Leo Laporte [02:26:25]:
He does Shields Up and, I mean, you know, the, what was it? It was Never 10. Now it's In Control. So you don't have to ever update your Windows if you don't wanna. Do you still get security updates? You just don't get the next version, right?
Steve Gibson [02:26:39]:
Yeah. Right, right. It'll still— you still get updates. It just doesn't move you forward unless you want it to.
Leo Laporte [02:26:44]:
That's exactly what you want. All of that at GRC.com. We have our own unique copies of the show, a 128-kilobit MP3 audio version for no apparent reason. And we also have video for the apparent reason that Steve's a hell of a good-looking fella and you want to see him. He's the Alex Trebek of podcasts is what he is. You should, you should go to, uh, uh, twit.tv/SN for those. You can also get it on YouTube. There's a YouTube channel dedicated to Security Now.
Leo Laporte [02:27:15]:
Great way for sharing clips to the boss. Boss, you gotta hear this. You gotta hear this. And, uh, probably the best way to get it is to subscribe. Just go to your favorite podcast client. Uh, we like Pocket Casts, Overcast. I mean, there's just a million of them. Pick the one you like, subscribe.
Leo Laporte [02:27:31]:
It's free and you'll get it automatically. Now, what's not free is supporting Security Now by joining Club Triton. I want to encourage you to do that. It's $10 a month. You'll get rid of the ads. Even this mention of, you know, the club will be gone. Because there are no ads, you also get chapter markers, which is really nice. So you can jump along as you watch in the show notes.
Leo Laporte [02:27:53]:
You can go to the parts you want or whatever. Skip the AI if you want or go directly to the AI if you want. You get to choose. You also, as members of the club, get access to the Discord, a great place to hang out with other Security Now listeners and all the members of the club. Uh, you get all the special programming we do in the Club Twit Discord. Um, and, uh, you also get the warm and fuzzy feeling of knowing you're supporting what Steve is doing, what Twit is doing. Uh, without your support, we couldn't do it. You, you, you cover a huge amount of the operating costs.
Leo Laporte [02:28:25]:
So please Please join twit.tv/clubtwits. Best way to show you appreciate what we're doing here. Steve, I, I think we're done. I will see you next week.
Steve Gibson [02:28:35]:
I'll be here. See you then. Bye.
Leo Laporte [02:28:41]:
Security Now.