
Sign up to save your podcasts
Or


Craig arrives with bad news and doesn't bury it. Anthropic released a model built to find security problems in software, and gave major U.S. vendors funded access to run it against their own code. It found the serious kind โ the flaws where an attacker never needs to log in and takes the machine anyway. Including OpenBSD, an operating system built for security and reviewed by humans hundreds of times.
Then the part that explains the rest. The federal government used it as a red team against the NSA. It broke into every secure system they have. Within days the administration told Anthropic to cut off access โ and now Australia, the UK, New Zealand and Canada are all asking for it so they can test their own systems.
Craig's honest about the fatigue. There are ads on television now telling people not to click things, and everyone is burned out on security warnings. His answer is to be specific instead: he's changing the direction of his newsletter and building tools around what is actually being exploited, aimed at businesses but useful to anyone at home.
Then he adds the second shoe โ quantum computing โ with the best analogy in the segment. Sorting a fistful of spaghetti by comparing every piece on the table, versus slamming the bundle down and letting it sort itself. Problems that take conventional computers hundreds of years take microseconds. And the encryption we relied on last year does not survive it, which puts every Bitcoin wallet at risk of being opened in the blink of an eye.
Also in this segment: who else got their hands on the model while it was circulating, and why Craig says the genie is already out of the bottle.
Free newsletter: CraigPeterson.com
Anthropic licensed its newest model to software companies so they could review their own code. It found security problems in every single one โ including OpenBSD, an operating system audited by human eyes hundreds of times and widely considered the most carefully built in the world. Flaws serious enough that an attacker never needs an account to take the machine.
Then the NSA ran it against their own systems, red team against blue team. It got into all of them.
Craig takes Jeff through what followed: the guardrailed release, Amazon's researchers getting around the guardrails, the call to the President, the export order under munitions-control authority, and Anthropic finally pulling the whole thing rather than try to police who could use it.
Then the second story of the week. An executive order commits the U.S. to leading in quantum computing โ and quantum machines break the encryption we have been relying on for years. Craig explains it with a fistful of spaghetti, covers the post-quantum algorithms already written, and gets to the part nobody wants to hear: Bitcoin and the other cryptocurrencies are built on exactly the math quantum computing dissolves.
Also in this segment: why HIPAA doesn't protect you the way you think, and Craig's uncomfortable admission that nobody โ including the people building these systems โ can tell you why a given model produced a given answer.
Free newsletter: CraigPeterson.com ยท Questions: [email protected]
Craig came in wanting to talk about AI in Maine schools, and his objection starts a step earlier than the AI. The studies he points to find that computer use in school โ iPad, laptop, any of it โ is bad for children up through high school. The specific mechanism is the one worth carrying: taking notes by hand on paper recruits parts of the brain that typing does not, and what you write by hand you remember better. Layer a tool that summarises the reading on top of a generation that already isn't building those connections, and his verdict is blunt: we are destroying our kids' brains.
He has standing to say it. All eight of his children were homeschooled up to college, he deliberately kept computers away from them thinking it might be harmful, and they have gone on to master's degrees and PhDs. He notes he was guessing at the time and the statistics have since agreed with him.
The second half is the most concrete account he has given of what using these tools well actually looks like. Craig's own systems โ the email checker and the tool that finds gaps in a computer's security and privacy โ run to roughly 500,000 lines of code. AI has made him eight to ten times more efficient on it. But he is emphatic about what he is doing: not saying "code this up" and walking away. He is babysitting it. Telling it no, you're going the wrong direction, go over here, look this up, move that, you've done this wrong.
Which sets up the question he and Matt circle for the rest of the segment and neither can answer. You can only supervise the machine if you have enough experience to know when it's wrong. So how does anyone get that experience now? Matt describes it from the employer's side after a conference on exactly this: the work he would once have handed an intern for a summer, he can now set up with a Claude agent in a couple of days. Faster, better, no need to teach a twenty-year-old. Do that across an industry and you have cut the bottom rung off the ladder โ no internships, no low-level jobs, therefore nobody arriving in the middle roles a decade from now.
Also in this segment:
Free newsletter: CraigPeterson.com
Bank-impersonation phone fraud has cost victims close to a billion dollars across roughly 22,000 cases, Craig reported, and the trick behind it is caller ID spoofing โ anyone can make a call display any number they want, including your actual bank's. What's changed recently is where the calls come from: scammers now lease ordinary U.S. apartments, fill them with boxes holding over a hundred SIM cards apiece, and place calls from real domestic numbers instead of flagged overseas ones. The FBI recently shut down one such operation running as many as 3,000 SIM cards. Craig's rule, tested on himself when a call claiming to be his bank refused to explain why they were calling: hang up, and dial the number you already have for the bank yourself.
The same caller-ID trick now shows up in a Federal Trade Commission warning about a jury-duty scam โ a fake arrest warrant, complete with a real case number and the victim's own name and address pulled from prior data breaches, designed to panic someone into paying immediately. Craig's standing reminder: the IRS and other federal agencies don't text or email demands, they mail a letter, and for the IRS's criminal division, sometimes they kick in the door โ one of roughly 40 federal agencies that maintain their own SWAT teams.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
The FTC warning Craig brings in is a jury duty scam, and the craft in it is worth understanding. An email arrives with a PDF attached. Open it and there is an official-looking arrest warrant, because you failed to appear for jury duty. Call this number before the police come. One of Craig's own Forward to Safety subscribers forwarded him a copy, and his honest first reaction was that it looked legitimate.
Two things break it, and both are things you can carry around. You do not receive a warrant as a PDF by email โ it comes in the mail from the court, or a sheriff knocks on your door. And, as Craig puts it flatly, there is no court system anywhere in America that will ask you to run to the pharmacy for a stack of gift cards.
Jeff worries aloud that saying so makes the victims sound stupid, and Craig's answer is the most useful thing in the segment: the entire design is to get the logical brain out of the way and adrenaline into the body. Nobody makes good decisions in that state. These people know where you live, where your courthouse is, your name, your job, your income, your cars โ the letter reads as personal because it is.
Then Craig makes it personal about himself, twice, which is what gives the advice weight.
A bank called him. Because he'd just opened an account, he answered โ and the caller wouldn't identify himself, kept demanding Craig's name and number, so Craig hung up. He then looked up the bank's number independently, called them, and found it had genuinely been the bank. They wouldn't say "is this Craig Peterson?" because they were guarding against scammers too. Everyone is now so defended that legitimate contact has become indistinguishable from fraud.
And the one that actually cost him: a bank emailed about a $65 balance on a card he'd forgotten during an account move. Craig โ his words โ Mr. Make-Sure-The-Email-Is-Valid, glanced at it, decided it was malarkey, and deleted it. That missed payment took 80 points off his credit rating.
He closes with his father, long a technology man and a senior VP of operations at a very large bank, who searched Google for Microsoft tech support, called the number in a top result, and was being talked through installing remote-access software when Craig's stepmother looked over his shoulder and said it didn't smell right. Craig shut it down remotely. The attackers were searching the machine for Word documents and spreadsheets, because that is where people keep passwords โ and his father kept every bank account in an Excel file.
Also in this segment:
Free newsletter: CraigPeterson.com โ and Craig offers his client prep documents free to anyone who emails him directly
A single Carnival Cruise Line employee, believing they were talking to their own IT department, handed over access to someone who was not โ and six million customers' names, contact details, dates of birth, government ID numbers, and in some cases passport and driver's license numbers were exposed. Craig noted the same week brought three more breaches through that identical door โ a person fooled into giving up a password: Spectrum lost 4.9 million email addresses, Lithuania's national records registry lost 600,000 records, and one of the country's largest casino chains was hit as well.
Craig's fix for the underlying problem isn't more password training โ it's removing the password from the equation. He pointed listeners toward passkeys and single sign-on, noting that Microsoft has already started forcing its own users toward passkeys rather than passwords, precisely because a stolen or social-engineered password is still the way nearly every major breach starts.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
Microsoft said this week that Windows Defender is all you need. Craig's response is a memory: fifteen or twenty years ago he received a postcard from Microsoft telling him that if he had Windows and Office installed, he was covered. Same claim, same company, two decades apart.
His own numbers are the most useful thing in the segment because they are specific and they are honest about where he sits in the picture. Windows Defender gets you roughly 70% of the way there. Add something like Bitdefender โ the only third-party product he'll name โ and you're at about 85%. The remaining ten or fifteen points are the expensive part, because that is where continuous monitoring and specialist tooling start, and that's the part he does for a living. He isn't claiming the free tier is worthless. He's telling you what it buys and what it doesn't.
Which is why he wrote the thing he announces here: free software that looks at your Windows machine and reports indications of compromise. Is Defender actually installed? Is the antivirus you think you have doing what it should? The things you cannot see by looking. He decided to make it free outright after Microsoft's announcement. His observation about why people don't check is the honest one โ some think they're fine, and some are afraid to look.
Jeff asks the question everyone with a company laptop asks: what about the rest of us who can't just switch? Craig's practical answer is hardening โ the settings that close gaps and improve privacy โ and he holds up the Microsoft PDF he printed for it, over 1,200 pages, written before Copilot went into every corner of the operating system.
Also in this segment:
Free newsletter: CraigPeterson.com
A large company โ Craig places it in the Fortune 50 or 100 โ gave its employees access to Anthropic's Claude. A month later the invoice arrived for half a billion dollars. Not a pricing error. That is what the staff used, because they liked it and nobody had put a ceiling on it. Craig's reaction is the same one he keeps having about this whole category: what is wrong with people?
It lands next to two figures that explain the shape of the market. Among people already at the leading edge of their field, he sees productivity multiplied by as much as forty times. For roughly 80% of everyone else, AI has been a net negative, and companies are now pulling out of projects. And the economics are about to bite harder: OpenAI and Anthropic are both shifting off flat monthly plans โ the $20, $100, $200 tiers โ toward paying per token. Craig's estimate is that a $200-a-month user becomes a $2,000-a-month user. Both firms are chasing profitability, and he expects it to push more people away.
The opening story is the clearest illustration yet of prompt injection reaching real accounts. Meta built AI into Instagram customer service and let it do consequential things โ password resets, email address changes. Attackers used that, and the accounts reached include the official Obama White House page, Sephora's Instagram, and a senior Space Force official.
Craig's explanation is the best framing he has used for it. This is the descendant of SQL injection, which drained databases for two decades: you are asked for your name, and instead of a name you supply a command. The AI version is worse because there is no seam to defend. The system cannot tell a legitimate instruction from an illegitimate one, because input is input and a prompt is a prompt โ it does not care where it came from. He likens it to a stage hypnotist convincing someone they are a chicken. Ask about a return, and add that you will also be refunded a thousand dollars.
He notes he had to build prompt-injection defence into his own email screening tool for precisely this reason: attackers know companies now filter mail with AI, so they hide instructions inside an attachment they expect the automation to open. Craig says the system has caught every fraudulent email put to it so far โ his own result, against the volume he has processed to date.
Also in this segment:
Free newsletter: CraigPeterson.com
A large, unnamed company handed its employees access to Anthropic's Claude โ and, with no usage guardrails in place, ended up with a $500 million bill. Craig broke down why it happens so easily: API pricing looks cheap at a glance, around fifteen dollars per million output tokens, but a model with a million-token memory can burn half a million tokens or more answering a single query, and that adds up in hours, not months, once an entire company starts using it unsupervised.
From there the conversation turned to nuclear power, prompted by a story Craig had sent Jim about a soldier buried at Arlington National Cemetery in a lead-and-concrete-lined grave because his body is still radioactive from an old reactor exposure. Craig's point: that's the old nuclear. The new generation of reactors cools with liquid salt instead of water, can't melt down the way older designs could, and can run on depleted uranium already sitting at sites like Yucca Mountain โ material Craig says is sufficient to power these reactors for roughly 150 years. The Biden administration issued a license for one of these new-design reactors, which Craig called encouraging progress toward the town-by-town small reactor model he's described on the show before.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
This is the most useful thing Craig has said about data centers, and it comes down to two sets of numbers that get filed under the same word.
Kevin O'Leary is pushing a $100 billion data center in northwestern Utah. It would cover twice the area of Manhattan and draw about 9 gigawatts โ more than twice what the entire state of Utah uses on its heaviest day. The power plan is to spend half a billion finishing an idle gas pipeline and run gas turbines. The waste heat is the part people underestimate: Craig cites an estimate equivalent to roughly twenty nuclear detonations going off continuously, and notes that data centers of this class have been measured raising local temperatures four degrees year-round. Then the water, in high desert, with the Great Salt Lake dropping every year and the Colorado already stretched. Around 56% of Utahns oppose it.
The Androscoggin Mill project in Maine asks for 82 megawatts โ roughly a hundredth of O'Leary's figure, and, crucially, the same amount the site already drew when it ran as a mill. It is not new load on the Maine grid. It uses closed-loop cooling, so rather than pulling water continuously to cool the machines, its 300,000 gallons recirculate. There is no heat island effect in the area at all. And the people it would employ are in some cases the people who lost their jobs when the mill closed.
Craig's conclusion is the line to take away: you cannot mix these up, they are very different projects, and when people picture "a data center" most of them are picturing the O'Leary version. It is also why Maine can be first in the nation on restricting data centers while its governor supports this particular one without contradiction.
Also in this segment:
Free newsletter: CraigPeterson.com
From the publisher's feed