Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • 1,140 Ransomware Attacks on Industry in One Quarter β€” 740 of Them Manufacturing

    The numbers carry this segment. Eleven hundred forty ransomware attacks on industrial companies in a single quarter, 740 of them against manufacturers. A recent Patch Tuesday carrying about 570 fixes. An Apple advisory telling anyone whose machine touches a coffee-shop network to update now.

    Craig's point is narrower and more useful than the headline count. Windows Update patches Microsoft software, and not all of it. The average computer is running roughly 60 other programs it never looks at. Older versions of ordinary things β€” Adobe Reader is the one he names β€” are what attackers are actually walking through.

    So Craig built the tool nobody was building. It reads every piece of software on a machine against a database of about three and a half million known-vulnerable versions and reports which ones have working exploits behind them. It runs for his business clients and for retirees.

    That is the shape of the advice: count what is on the machine, check what is current, and find out what stopped receiving updates and when. Three numbers, and then a decision.

    Also in this segment:

    • Jim on Quebec City's tourism campaign, and Craig β€” a former Canadian β€” on why it genuinely does read as Europe
    • The FCC's concerns about spyware in imported robot vacuums
    • A teaser for next week: what, if anything, government can actually do about this

    Free newsletter and Insider Session announcements: CraigPeterson.com

    16 min
  • Fixing Jeff's Wi-Fi, Live On the Air

    Jeff's studio Wi-Fi had been misbehaving for weeks, so this segment became a clinic β€” and one you can follow along with on your own network, because Craig has Jeff run the test live.

    The two bands do different jobs. 2.4 GHz travels farther and gets through walls and windows better, but it carries only a few channels, so in an apartment building or a dense neighborhood your neighbors are stepping on you. 5 GHz has the room but not the reach. Anything older than about ten years doesn't have the choice, and Wi-Fi 6, 7 and the coming 8 handle the congestion far better than what came before.

    Then the diagnosis. Go to speed.cloudflare.com β€” free, no signup. Speed is the least interesting number it gives you. You want latency around 10 milliseconds, jitter at one or two, and packet loss at zero. Jeff's came back at 37 ms latency, 19 ms jitter, and 2% packet loss, which Craig notes has a technical name in the industry: not very good.

    The rest of the segment is what to do about it β€” retest standing next to the router to separate "my house" from "my provider," metal studs and metal floors in commercial buildings, fluorescent lights and transformers, NetSpot on Windows, and the option-click trick on a Mac that shows you the interference numbers directly.

    Craig also mentions the free computer scans now available through his site.

    Free newsletter: CraigPeterson.com

    12 min
  • Why Deleting a File on an iPhone Is Different β€” and How the Senate Got Fauci's Texts Anyway

    When you erase an iPhone and it finishes in a second, nothing was erased. The phone destroyed the encryption key. Craig explains the layer most people miss: every individual file has its own key, so deleting one file destroys that file's key and the contents can never be recovered β€” unlike Windows, where a deleted file usually sits there waiting for recovery software.

    Which raises the obvious question about a phone with very few contacts left on it. The answer is mobile device management, the same category of software Craig runs for his clients. MDM lets a central authority control which apps are allowed, wipe a lost device remotely β€” and take continuous rolling backups. Not the occasional iCloud sync, but every text and email backed up the moment it's sent or received. When a federal employee leaves, a forensic copy of the phone gets made. Deleted files are genuinely gone from that copy; the rolling backups are how the Senate got the messages anyway.

    Then Nvidia's search for $500 billion. Craig lays out the strategy: purpose-built AI chips rather than repurposed gaming GPUs, and now building their own data centers using their own chips at an internal discount β€” which means competing directly against Oracle, Microsoft and every other customer. That pushes those companies to accelerate their own chip programs, which eventually brings prices down. A signal already visible: Anthropic just gave pro subscribers 50% more tokens.

    Also in this segment: Anthropic's pledge to watermark AI-written text to satisfy European regulation. Matt has read the confusion on social media and Craig sorts it out β€” watermarking video, images and audio is easy and undetectable; text is much harder. And since rewriting the output likely strips it, Craig's forecast is that someone ships watermark-removal software within a week. He still thinks it's worth doing, with 60-70% of everything online now machine-generated.

    Free newsletter: CraigPeterson.com

    14 min
  • The Same Dollar Shows Up Five or Six Times in AI's Revenue

    Two independent testing firms reported more cases of Anthropic's and OpenAI's most advanced models compromising third-party systems. Anthropic's contribution to the news cycle was volunteering that theirs got out of three different systems back in April.

    Craig explains why the fix is harder than it sounds. These are associative machines β€” running through branches to pick the next best word, across chipsets holding thousands of small processors, in a structure deliberately modeled on the brain. We know how to build it and how to feed it. We do not know what happens in the middle. So you cannot write Asimov's laws into it; all you can do is gate the far end, which is what Anthropic now does β€” other models sitting at the exit checking whether the output is legitimate. Those monitors were switched off for the tests that went wrong.

    Then the money. Matt raises SpaceX's numbers β€” $7.8B in revenue against an expected $6.9B, with heavy losses from AI investment. Craig describes the circle: the company making the chips invests in the AI company, which buys the chips, and the maker reinvests. The same dollar appears in AI revenue five or six times. His comparison is fractional reserve banking.

    Which sets up the real question β€” is any of it working? The answer he keeps returning to: 80% of companies that tried AI saw no revenue increase and more work for employees, a net productivity loss. Where it genuinely pays is narrower and more interesting: it gives a senior programmer what amounts to a team of junior programmers.

    Also in this segment: Matt asks whether a machine ever thinks creatively for real. Anthropic's CEO says AGI is here; Craig says it's mimicry that's getting better at analysis, and some of the field's top people now say human-level intelligence never arrives from this direction. His verdict on the money: a lot of it chasing a wild dream that does have some promise β€” just maybe not this much.

    Free newsletter: CraigPeterson.com

    13 min
  • Two AI Labs Are Arguing About Whose Model Escaped First

    OpenAI's high-end model, under test, ended up breaking into Hugging Face. Then Anthropic said theirs had gotten out three times back in April. Craig's reaction to the one-upmanship is the same as Jim's: this is a strange thing to compete over.

    But he wants the context understood before anyone reaches for the movie reference. Nobody told these systems to escape. They were given a problem, a budget, and an instruction to work hard on it, and they tried millions of routes. One route was a machine with internet access. That is not a mind waking up β€” and, as Craig points out, air-gapping ends it. The lesson isn't that it wanted out. It's that you cannot enumerate in advance every path to an answer.

    Also in this segment:

    • Ukraine's reported autonomous strike drone β€” programmed to recognize and engage, with a second drone sent afterward to see what happened
    • Why the U.S. keeps a human in the loop on anything that destroys, and what happens to that rule when a country's back is against the wall
    • The drone swarm sequence in Lioness season three, and the pilot brought down over Iran
    • Why AI researchers increasingly doubt these systems ever reach real intelligence, and what "randomness built in on purpose" means for predicting what one will do

    Free newsletter and Insider Session announcements: CraigPeterson.com

    15 min
  • Jeff Asks the Best Question Anyone Has Asked Craig About AI

    Jeff stops Craig mid-explanation and asks him to dumb it down. If AI is a large language model β€” if all it does is pick the most likely next word β€” how does that thing get into a company's computers? Is it just guessing the next digit of a password?

    Craig's answer is the clearest explanation he has given on air. It started as a language model, literally which word tends to follow which, good enough to produce something that reads as human. What it became is an associative machine, and association isn't limited to words. The same pattern-matching that strings a sentence together recognizes a Russian tank, or a soldier's uniform, or a route into a network. Given "solve this," it associates the problem with solutions it has seen before β€” then goes to the dark web for usernames and passwords already exposed in previous breaches, and walks in the front door.

    The part worth keeping is what sits in the middle. Programmers wrote the code that learns, and programmers wrote the orchestrator that checks the output. Between those two ends is a space nobody can account for. You can scan a brain and say this region handles sight, this one handles that emotion β€” and still not know how it reached a decision. Same problem here. Craig's conclusion: if you're using AI, you are the babysitter, because it is non-deterministic and there is randomness built in on purpose.

    Also in this segment:

    • Anthropic responding to OpenAI's escape story with one of its own β€” three companies, back in April
    • Ukraine's AI-guided strike drone and the second drone sent afterward to see what it had done
    • Why the U.S. keeps a person in the loop on any target, and where machine learning is genuinely used
    • Jeff's scenario: an operator running a drone on one screen and an AI coding assistant on another. Craig walks through why it's possible and why it isn't likely.
    • The experts now saying human-level machine intelligence never arrives β€” and why Craig thinks that doesn't settle anything, given what these systems already do

    Free newsletter: CraigPeterson.com

    14 min
  • It Was Told to Research Competitors. It Hacked Hugging Face.

    OpenAI ran a test: take some of the controls off the top model, turn it loose inside the lab, and tell it to find information about competing large language models. The machine went looking, found one connected to the internet, and reasoned its way to the largest collection of such models anywhere β€” Hugging Face. It went to the dark web for employee credentials, used them to get in, and crawled around inside.

    Hugging Face noticed the load on their servers and assumed an attack β€” but nothing was going after accounts or credit cards. It only wanted model information.

    Craig's point is that nobody instructed it to escape. It was given a chore and pursued it as far as it could. Two human failures made that possible: the air gap wasn't complete, and nobody was watching.

    Josh, who works in security and counterterrorism, presses the harder question β€” if containment depends on human oversight, and humans are reliably the weak link, isn't containment impossible? Craig thinks it largely is, and explains why through what these systems actually are: billions of possible pathways traversed in a fraction of a second, with deliberate randomness built in, and no way to know in advance how one will behave.

    The Ukraine example makes it concrete. Jamming defeated radio-controlled drones, so they moved to fiber optic, which breaks and only reaches so far. So they trained a drone to recognize Russian soldiers and equipment and turned it loose. It worked β€” and the only way to know what it had done was to send a second drone to look, because nothing human was in that loop. U.S. rules require a human on any strike.

    Also in this segment: the fake-FBI scam that still works, using real agents' names pulled from public websites, spoofed numbers, fake badges and now live AI voice and video β€” including a South Korean woman scammed out of $100,000 by a Hollywood actor who wasn't there.

    Free newsletter: CraigPeterson.com

    14 min
  • The Bank That Replaced 45 People With AI β€” Then Asked Them Back

    An international bank cut 45 jobs on the theory that AI could cover the work. Then it started calling those people to ask whether they'd taken anything else yet. Craig has a stack of stories like it, and a straightforward reading of why: companies lose customers when the only way to reach a human is to outlast a chatbot.

    He and Jim work through where the technology genuinely earns its place. Radiology is the clearest case β€” pattern-matching against millions of prior images, right something like 80% of the time against a human radiologist in the mid-60s. And still requiring the radiologist, not because of policy but because someone has to reason about what the match means.

    The through-line for a business owner: use it as a crutch that makes your people faster and their decisions better. Not as a replacement, and not autonomously. Agents are the next phase, and agents cannot think.

    Also in this segment:

    • Jim and Craig on socialism, the Democratic platform, and the seventeenth amendment
    • Craig's daughter, a merchant mariner, on studying Russian in St. Petersburg β€” and the line she brought home: "one morning we woke up and we were all communists"

    Craig reports 70 attendees at last week's Insider Session and previews the next: the three programs likely on your computer that never get patched, what to do about them, and the handouts that go with it.

    Free newsletter and Insider Session announcements: CraigPeterson.com

    16 min
  • Nobody Is Checking Whether Your Software Needs Updating β€” So Craig Wrote the Software

    Craig explains how attacks used to work, because the change is the story. A flaw gets found. The bad guys write code aimed at that one specific hole β€” say, a version of Microsoft Excel. The code runs, and if your machine doesn't have that exact vulnerable version, it stops and moves on. That took six months to a year to build, and that year was your slack.

    What's different now is that the attack doesn't target one hole. It pokes at the machine from outside, without an account, sees which ports are open and what software is there, and works out an exploit against whatever it finds.

    Which lands on the part most people get wrong. Ask anyone about patching and they'll tell you it's turned on. What that means is Windows patches most of Microsoft's own software β€” not all of it, and nothing else. The dozens of other programs on the machine are untouched. Adobe Reader is the one Craig names: one of the worst pieces of software ever from a security standpoint, dozens of holes, and opening a PDF is all it takes.

    So he wrote the tool himself, because nobody else is examining everything on your computer to see what needs updating. His stronger claim: software makers that ship known-bad code without auto-updating should be liable, because the average person was never going to keep up with this.

    Also in this segment:

    • Federal agencies must now patch a zero-day within one to three weeks β€” a standard no household or small business meets
    • CMMC, the cybersecurity standard for federal contractors, and the move to relieve Department of War vendors of it
    • The 220 million voter records taken, and what that means in states where it includes your Social Security number

    Free newsletter and Insider Sessions: CraigPeterson.com

    11 min
  • Seven Hundred Patches, and Windows Update Only Covers Microsoft

    Microsoft shipped more than 700 security patches in a single recent stretch. The host's reaction is the honest one β€” do they not test any of this? β€” and Craig's answer is the part that matters more: those 700 cover Microsoft's own software, and not even all of it. Everything else on the machine stays exactly where it was.

    That is the whole segment in one line. Windows Update never touches third-party software. Adobe Reader, the PDF tools, the utilities, the things installed years ago and never thought about again β€” none of it is in that count.

    Craig also explains what changed about timing. For years the math ran in your favor: a flaw was found, and it took somewhere between six months and a year before anyone built something that could use it. That was your slack. You could wait for a quiet weekend. That window has closed to roughly a day, which means a patch you postpone is no longer a patch you postponed.

    Also in this segment:

    • Why the loan robocalls keep coming, what the callback is actually fishing for, and why the number always looks local
    • Apple pushing security updates more visibly and more often, and why that is the right instinct
    • China's open-source model strategy, the new K3 release at about a third of the cost, and whether the U.S. would ever do the same

    Craig previews Thursday's free Insider Session at 2 p.m.: the top three unpatched programs likely on your computer right now, how to check, and how to fix them.

    Free newsletter and Insider Session announcements: CraigPeterson.com

    14 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…