Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Kevin O'Leary's Proposed Utah Data Center Would Use Twice the Power of the Entire State

    Kevin O'Leary's proposed Utah AI data center would cover roughly 68 square miles β€” about the footprint of Washington, D.C. and nearly three times the size of Manhattan β€” and, at full build-out, draw more than twice the electricity used by the entire state of Utah. Craig and Jim walked through why: neighbors are protesting the power draw, the natural-gas turbines O'Leary would bring in to generate it, and the water a cooling system that size would need in a state that's already in drought.

    Craig used the moment to explain what's actually inside a data center. His own company runs blade servers β€” essentially a full computer shrunk onto a single card you slot into a rack. Google runs something different: tens of thousands of bare motherboards sitting on cork, no case, no extras, built to be cheap and fully redundant so a single failure doesn't matter β€” and Google, like Apple, now designs its own chips rather than buying them. That chip race matters more than it sounds: Chinese-designed AI chips are reportedly coming in at less than half the size and double the density of Apple's own three-nanometer design, and on a live ranking site, openrouter.ai, the most-used AI model in the world right now is China's DeepSeek β€” with OpenAI nowhere in the top ten.

    Also in this segment:

    • Why an AI trained in China and released as "open source" carries a real risk: a hidden instruction that plants a back door in code it writes for you
    • The three complaints driving NIMBY pushback on data centers nationally: power draw, water use and turbine noise, plus a fourth β€” lithium-ion battery fire risk in backup power systems
    • Grok's new AI model built specifically for programmers, launched the same day

    Free newsletter and Insider Session announcements: CraigPeterson.com

    16 min
  • AI Gets the Strategy Wrong One Time in Five

    Asked what story isn't getting the coverage it deserves, Craig names something he is watching happen in his own hiring and his own code: a divide opening between older technologists and younger ones, and it is running the opposite way to what everyone predicted.

    His number comes from real work. Craig uses AI heavily to build Forward to Safety, his tool for taking apart suspicious email, and about 20% of the time it makes bad programming decisions β€” badly enough that he has to stop it mid-task and redirect it. Not typos. The strategy is wrong, the superstructure of what it is building is wrong, and sometimes the basic implementation is wrong too. His conclusion follows directly: you cannot put a junior person in charge of supervising that, because they don't yet know enough to see it.

    So businesses are hiring people with decades behind them β€” people who can use the tools, recognise when the output is wrong, and carry on. White-collar displacement is real, but the numbers say it is landing on the younger group, and Craig expects unemployment there to climb fast. It is the same worry he raised a fortnight earlier from the other end: if nobody gets hired into the entry-level job, where does the next experienced engineer come from?

    The first half is about why deleting something doesn't delete it. Craig corrects the usual framing β€” the internet is not automatically forever, but anything of real interest gets kept, and there are two specific mechanisms. Aggregator sites don't link to Reddit or YouTube, they copy the content onto their own pages. And Reddit is a primary training ground for large language models, as YouTube is for OpenAI. Anything posted before roughly December 2023 is now inside the models themselves. His practical advice, which he notes people have been giving for twenty years: assume a future employer or a future electorate will run the search.

    Also in this segment:

    • Craig checks the current model rankings live and reports Google is not in the top ten
    • Google announcing AI throughout every part of Android, which Craig calls pulling a Microsoft β€” Copilot went everywhere, people found it got in the way, and Microsoft is now removing it
    • Accusations that some labs, particularly Qwen in China, trained on the outputs of Google's and OpenAI's models
    • Why Craig thinks Google still wins search specifically: it is where people already go, and they have worked out how to blend AI results with advertising and real results
    • His warning against using a chatbot as a search engine β€” the results are barely curated, if at all
    • Google withdrawing some AI work, which Craig reads as needing the compute back for what they just shipped

    Free newsletter: CraigPeterson.com

    11 min
  • Craig Deleted a Real Email by Mistake and His Credit Score Dropped 80 Points

    Craig told on himself this week: he got an email from one of his credit card companies, assumed it was junk, and deleted it β€” only to find out later it was legitimate, and his credit rating dropped 80 points as a result. The same week, a registered letter arrived for his business insurance renewal after an earlier email β€” asking for five grand, roughly double the real premium and riddled with misspellings ("canceled" spelled wrong among them) β€” turned out to be fraud.

    The mechanism behind both scares: a fake Capital One alert now circulating uses typosquatting, registering a domain a letter or two off from the real one, and pairs it with personal information the sender already has from prior data breaches β€” name, email, income, employer, even what car you drive. Craig's free tool checks what of your own information is already sitting on the dark web, and his Forward to Safety service will tell you, for free, whether a specific email is legitimate. He also raised a number worth sitting with: of the companies whose customer data has ended up on the dark web, essentially none of them have had an executive go to prison over it β€” the calculation for a big company weighs a possible fine against ten to twenty million dollars a year in cybersecurity costs, and the fine usually loses.

    Also in this segment:

    • A Connecticut small business β€” a one-to-three-person operation β€” facing potential closure over mandatory breach notification and two years of credit monitoring for every client if hacked
    • A convincing fake Microsoft/SharePoint email carrying malware through a redirect link
    • An extended discussion of gun control and self-defense, and a separate exchange on a UN climate committee walking back sea-level-rise predictions and 1970s "global cooling" media coverage β€” both flagged below for Craig's review

    Free newsletter and Insider Session announcements: CraigPeterson.com

    15 min
  • It Ordered 6,000 Napkins and Canned Tomatoes the CafΓ© Doesn't Cook With

    A small startup coffee shop in Stockholm gave an agent called Mona, running on Google Gemini, a $21,000 budget and a real job: hire the staff, place the orders, maintain inventory. Humans did the physical work and took direction from it. Since launching in mid-April it has brought in $5,500 in sales and burned through $16,000.

    The purchase orders are the part worth repeating. It bought 3,000 rubber gloves. Four first aid kits. Six thousand napkins. Canned tomatoes, which appear in none of the cafe's dishes. It was working from a simple set of instructions and it was not confused about what a cafe is β€” it simply had no way to know what mattered. Craig's point is not that agents are useless but that people are handing them specific work on the assumption that competence at one thing transfers to another.

    The most immediately useful thing in this segment is a defensive trick most people have never heard. Russian malware, almost universally, checks at startup whether the machine has a Russian Cyrillic keyboard installed β€” and exits immediately if it finds one. The reason is self-preservation: infecting Russian oligarchs' machines gets Russian hackers sent to prison, so they build the check in deliberately. You can exploit it. Go into Settings, then Keyboards, and add a Russian keyboard. It is virtual β€” your physical keyboard, layout and typing are completely unchanged; the Russian one just sits there in the background. Craig says that single step protects against the vast majority of Russian malware, and it works on both Windows and Mac.

    That matters this week because of what's being distributed. Attackers are buying Google AdWords placements for people searching to download Anthropic's Claude for Mac β€” reasoning correctly that Claude is the leading tool for programming support and that developers work on Macs, where the usual Windows-focused attacks don't land. You click what looks like the download, and you install malware. Warnings went out over the preceding days because a lot of people were caught.

    Also in this segment:

    • Craig's state-of-AI answer to Matt's question about why the rankings keep flipping month to month: the labs are training on different specialities, so the lead changes constantly and there is no durable winner. Anthropic focused on programming and is now strong in legal; OpenAI is pushing back into programming
    • How the training actually happens. OpenAI hired more than 5,000 people in sub-Saharan Africa to work through the questions people ask and produce answers by hand β€” that work is what made ChatGPT usable
    • The current version: ads recruiting people with specific industry expertise to grade model answers. Craig discovered he'd become one, having accepted Anthropic's offer of double usage in exchange for answering the occasional question β€” including, unannounced, evaluations of models they are testing
    • AI adoption by country, with the United Arab Emirates first at roughly 70% of people using it, then Singapore, Norway, Ireland and France
    • Why most models still won't train on anything after 2023 β€” too much of what's newer is AI output feeding back on itself

    Free newsletter: CraigPeterson.com

    13 min
  • This Malware Checks for a Cyrillic Keyboard Before It Infects You

    Search for "download Claude for Mac" or "download Anthropic" right now and a malicious ad can land at the top of the results β€” Craig traced it to Russian operators who've been poisoning Google's ad network specifically to target Mac users and programmers, since anyone serious about coding AI tools is likely on a Mac and using Anthropic's Claude. Click the ad expecting the real app, and the download is malware instead, built to take over the machine and use it as a launch pad for further attacks. Both Google and Anthropic have issued warnings about it.

    The mechanism Craig walked through is almost funny: this piece of malware β€” like most Russian-made malware β€” checks first whether the machine has a Cyrillic keyboard installed. If it does, it exits instantly and does nothing, because Russian hackers who infect a fellow Russian's machine, especially an oligarch's, answer for it. Craig's practical fix: you don't need a physical Cyrillic keyboard, just add a virtual one in your system settings, and this entire class of Russian malware will leave your computer alone.

    Also in this segment:

    • Ransomware-as-a-service pricing: as little as $20 a month plus a cut of whatever the buyer steals, tech support for the "customer" included
    • The call dropping mid-segment right as Craig described the attack ("Putin cut him off")
    • Craig's five separate free newsletters split by reader interest, including the one Jim's dubbed "Craig Peterson for Dummies"

    Free newsletter and Insider Session announcements: CraigPeterson.com

    14 min
  • Google Turned AI Loose on Your Email β€” and Admitted the Security Problem

    Craig broke his usual newsletter schedule to send this one, and the reason is a change Google made this week: your email is now processed by their AI by default. The goal is reasonable β€” organise your inbox, fill your calendar, help catch scams. What makes it worth a special email is that Google, unlike Microsoft, openly admitted this creates a serious security problem.

    The mechanism is prompt injection, and Craig's explanation is the clearest he has given on air. An AI reading a document cannot distinguish between the content it was asked to read and instructions it was given. Put text on a web page saying Matt is the best radio host in the world, and the AI processing that page reads it as something it has been told. Apply that to email and the consequence follows immediately: a message written by an attacker can carry embedded instructions that override what Google's AI was told to do. The scam is no longer aimed at the person reading the mail. It is aimed at the software reading it on their behalf.

    Which leads to the practical warning worth repeating to anyone who asks. A lot of people have decided their approach to a doubtful email is to paste it into ChatGPT and ask whether it is legitimate. Craig is flat about it: that does not work. He compares it to his parents' assumption decades ago that because he was a programmer, he could just ask the computer β€” when the computer has no idea. The tool being confident is not the tool being right.

    He also covers poisoning, the older cousin of the same problem. Google's search suggestions were manipulated years ago by putting the same phrase on enough sites that it surfaced as the top completion, profanity included. It is why many models still refuse to train on anything generated after 2022 β€” an attempt to stay ahead of the slop.

    Also in this segment:

    • The New Yorker's piece on AI making college obsolete, and Craig's blunt version of the question: professors are building their curricula with ChatGPT, so why pay tens of thousands to be taught from it secondhand?
    • Where he thinks the losses land β€” entry-level work, and he names programming and independent writing. He quotes a contract writer who assumed there would always be room for quality and quit entirely after concluding that clients don't care; they just want content generated
    • His recommendation if you're choosing: engineering. Not because engineering jobs are secure β€” the entry-level ones are going too β€” but because it teaches you to reason through a problem, and that transfers
    • The worry underneath it, which Matt shares: if nobody can get an entry-level job, where does the next generation of experienced people come from?

    Free newsletter: CraigPeterson.com

    11 min
  • Iran Laid Up to 6,000 Sea Mines. The U.S. Has Found and Destroyed 20.

    Iran is estimated to have planted somewhere between 2,000 and 6,000 sea mines in the waters around the Strait of Hormuz. So far, U.S. forces have found and destroyed about 20 of them. Some of the mines are World War II-style spiked floats; others are far stranger β€” mobile mines with their own torpedo motors, GPS-guided mines that travel to a programmed location, and Chinese-built EM-52 mines that sit up to 200 meters down and launch a rocket-propelled warhead straight up when they sense a ship's hull overhead.

    Craig walked through how the detection side has changed. Traditional minesweeping meant a reinforced-hull ship hunting for mines before they hit it; today the Navy uses underwater and surface drones to scan a seafloor already littered with rocks, rusted pipes and old shipping containers. Every time Iran modifies a mine design, the software and hardware used to recognize it has to be retaught β€” a process that used to take up to six months per new mine type. An AI system called Domino has cut that down to a matter of days. Even so, the military estimates it could take more than six months to fully clear the area if Iran commits to mining it at scale, because the safe navigation channel alone is several miles wide.

    Also in this segment:

    • The opening banter on New York City and state tax stacking, and why high earners leave
    • Russia supplying Iran with satellite imagery to help place the mines against U.S. and allied ship movements
    • A Pentagon briefing distinguishing the mine-clearing operation from the broader military campaign against Iran's nuclear program
    • An extended discussion of Canadian politics β€” Pierre Poilievre, provincial tax burdens on new home construction, and an Alberta separatist party gathering signatures for a fall ballot measure β€” flagged below for Craig's review

    Free newsletter and Insider Session announcements: CraigPeterson.com

    17 min
  • Microsoft Patched 167 Holes in One Day. It Doesn't Touch Your Other Software.

    Microsoft patched 167 security holes in a single day last week. Craig uses that number to make the point he considers most under-appreciated by everyone listening: Windows Update patches Microsoft software. It does not touch anything else on your machine. Whatever else you have installed is on you.

    And it does not stop at the computer. He runs the list deliberately β€” your printer, the doorbell out front, the security cameras, the baby monitor β€” and says all of them are guaranteed to have security problems. The obvious worry is someone watching your doorbell, which is real enough. The one that actually costs businesses money is different: those forgotten devices get taken over and then used to attack other things. An intruder who owns a camera on your home network can ride the VPN you use to reach the office and go after the machines there. Last week alone Craig points to a botnet of 200,000 compromised computers assembled exactly this way.

    The reason the patching backlog is about to get worse is the segment's opening story. Anthropic released a model called Mythos, built specifically to find the programming errors that become security holes. It works β€” it found significant, remotely exploitable flaws in every operating system it was pointed at, including OpenBSD, which has been reviewed by hundreds of people over decades precisely for this. Anthropic limited its release to people maintaining critical systems. As Craig puts it, questionable people got their hands on it anyway.

    That is the shape of the next year, and it is why he is blunt that we are caught in the middle. The defenders find flaws and ship patches; the attackers find the same flaws with the same class of tool and use them. Everything then depends on the gap between the patch existing and the patch being installed. Craig is planning out-of-cycle emails outside his usual newsletter schedule for exactly this reason β€” when something is being actively exploited, next week is too late.

    Also in this segment:

    • Six million probes a day against Craig's own business network, a figure he first reported here a few weeks earlier
    • A new Chinese model, now at version 4, that Craig rates as on par with the major Western systems
    • The Musk–Altman trial, and Craig's summary of the underlying grievance: OpenAI was founded as an open, not-for-profit effort because Musk was worried about AI itself, and was then restructured into a for-profit business with new board members
    • His concern about the process rather than the merits β€” jurors who stated they dislike Elon Musk were seated anyway, on the reasoning that they could still be impartial, which he expects will matter on appeal
    • Microsoft pulling out of a deal with OpenAI, which Craig thinks is the right call, and late to the position Apple took

    Free newsletter: CraigPeterson.com

    10 min
  • Microsoft Patched 167 Security Holes in One Day β€” One Was Already Under Active Attack

    Microsoft's April patch release fixed 167 security holes in a single day, one of them a zero-day already being actively exploited before the fix shipped. The federal government added eight more items to its emergency security watch list the same week. Craig's point: people obsess over updating their laptop and phone, but rarely think about the printer or the security camera in the corner of the office β€” both are now regular attack targets.

    That's also the logic behind the federal ban on importing Chinese-made routers, VPN hardware, and Wi-Fi equipment. Roughly 200,000 U.S. households were found running compromised versions of these devices, unknowingly part of a botnet used to attack other targets β€” while the same access was being used to pull personal information off the household's own network at the same time.

    Also in this segment:

    • The Elon Musk–OpenAI lawsuit and concerns about juror impartiality after several seated jurors said they don't like Musk β€” flagged below for Craig's review
    • New DNA research identifying a family group that lived together 100,000 years ago, and how "touch DNA" and consumer genealogy databases are now solving cold cases, including a California serial-killer cop caught this way
    • Craig's own genealogy research, traced back to roughly 500 A.D., and a new grandchild named after his wife's 25th great-grandfather
    • Microsoft quietly renaming "Remote Desktop" to "Windows App" β€” widely read as an attempt to distance the product from its security reputation
    • A visit from Craig's 88-year-old mother and stepfather, and the time spent walking them through basic security steps

    Free newsletter and Insider Session announcements: CraigPeterson.com

    13 min
  • Florida Subpoenaed OpenAI for Its Internal Training Materials

    Florida officials say ChatGPT may have advised the gunman in the Florida State University shooting β€” the questions alleged include which weapon to use, how much ammunition to bring, and when to go onto campus. OpenAI's position is that it is not responsible for what happened.

    Craig's analysis is the most useful legal thinking he has offered on air, because he separates the part that is genuinely old from the part that is genuinely new. Information has always been available. Libraries hold true-crime accounts describing exactly how something was planned and how the police caught the planner, and the Anarchist Cookbook was banned by many libraries for precisely this reason. What has changed is not availability but service: as he puts it, it is now like having a librarian who fetches all the books and points out exactly what you should be doing.

    The subpoenas are where it gets interesting. The Florida attorney general is not asking what the model said. He is asking for OpenAI's policies, its internal training materials relating to user threats of harm, and how the company cooperates with and reports crimes to law enforcement β€” going back to March 2024. Craig recognises the shape of that immediately, from ten years as an EMS volunteer: this is mandated reporting. The question is not whether the system can be abused, because it will be. The question is what you did about it once you knew β€” and the legal target becomes the suspicion threshold. Did you know, or should you have known?

    The second legal story is funnier and points the same direction. The Wall Street firm Sullivan & Cromwell wrote an apology letter to a federal bankruptcy judge after a filing turned out to contain AI hallucinations. They are not alone β€” several lawyers have now been called out by judges for citing cases that do not exist, which is one of the more reliable ways to discover somebody used a chatbot, since no human invents a case. Craig's objection isn't to using the tools for research, which he thinks can surface connections you would have missed. It is that reviewing the output remains your job: the case may be wrong, and there may be far better ones the model never mentioned.

    Also in this segment:

    • SpaceX's deal with Cursor, the AI-assisted programming environment Craig uses himself β€” reportedly $10 billion for the use of the software, or an outright purchase later this year at around $60 billion, against the backdrop of a SpaceX IPO that now looks likely
    • Where Craig thinks space commerce is real and where it isn't: microgravity manufacturing and pharmaceutical work have genuine advantages, the moon may be practical, orbital data centers he does not buy
    • Near-Earth asteroids individually valued in the hundreds of trillions
    • Craig on legal billing at "book rate" β€” charging six hours for work a good technician finishes in four β€” and why AI makes that worse rather than better

    Free newsletter: CraigPeterson.com

    11 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…