
Sign up to save your podcasts
Or


Craig's own company, Mainstream, is currently averaging six million hacking attempts a day against its servers โ and most of them are coming from China. Separately, Iran has already broken into the systems of a major health care company Craig covers in this week's newsletter. HIPAA requires continuous monitoring of health care systems, which is exactly how anyone would know an intrusion happened at all โ and in this case, it took the company a full year to notice.
That gap is the point: continuous monitoring isn't a box to check, it's how Craig can put a number on his own six million daily attempts in the first place. A company that isn't watching that closely doesn't get a lower attack count โ it just gets a later, worse surprise.
Also in this segment:
Craig's free weekly webinars continue next week โ sign up on the newsletter page.
Free newsletter and Insider Session announcements: CraigPeterson.com
A listener mailed Craig a laptop to look at. The man has fiduciary responsibilities โ he handles other people's money โ and the machine turned out to be very badly compromised. What he had done to protect it was the basics and nothing more: Windows Defender is running, therefore he was covered.
Craig's interest is in the reasoning, not the mistake, because he hears the same reasoning everywhere and it's the thread running through the whole segment. What shocks him after thirty years in cybersecurity is how many businesses have simply given up โ treating it as a battle that cannot be won, so why try. And he sees exactly the same posture forming around AI: a tool works impressively on something small, and people extrapolate from there to everything.
Matt supplies the perfect illustration without meaning to. He had used Gemini inside Google Docs the day before for complex tables and formulas โ work he knows how to do himself โ and it tore through the job in no time flat. Genuinely useful, genuinely a convenience. Craig's response is the sharpest thing in the episode: that is exactly the problem. People are impressed by straightforward numerical work, then extrapolate to this must be good at picking military targets, this must be good at running my business, I don't need middle managers, AI can manage people.
Which is not hypothetical. Craig walks through Palantir's two-layer battlefield system โ a machine learning layer trained over years to recognise a school, an oil plant, vehicle types, uniforms and military colours, with an AI in front of it that commanders query directly, asking things like which fuel trucks can reach a given area without running dry. He notes an internal U.S. Army memo describing the Palantir battlefield communication system as very high risk due to security vulnerabilities. And he gives the number that makes human review impossible: a war generating 40-plus targets an hour. Checking whether each is legitimate would take an army of analysts. His concern is that these systems are not supplementing that judgement โ they appear to be carrying it.
Also in this segment:
Free newsletter: CraigPeterson.com
The FBI's 2024 numbers, Craig told Jim, show people 60 and older lost $5 billion to scams that year, a 125% jump from the year before โ and that's before today's AI-written phishing got as good as it now is. The click rate on phishing links has climbed from 13% a few years ago to over 50% today, driven by grammar and personal detail good enough to fool almost anyone.
Craig walked through why one classic defense, hovering your mouse over a link to see where it really goes, no longer works. He described a real example from his own testing: an email made to look like a Microsoft receipt for a $269.99 charge, with a phone number to call to dispute it. Every link in the email pointed to a genuine microsoft.com web address, because the scammers had set the page up on Microsoft's own free web hosting service โ the mouse-over trick shows a real Microsoft URL, but the page behind it is built to steal your information. His tool follows every link all the way to its final destination and scans what's actually there, catching what a simple hover check would miss.
The story behind why he built it: his father fell for a scam a few years before he passed away at 85, and it cost him. That's the case Craig says he had in mind designing a system simple enough that his own father could have used it โ forward a suspicious email, voicemail, text message, or even a QR code, and get a full report back in 47 seconds, a check that would otherwise take him 15 to 30 minutes by hand.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com โ Find out what is really open on your computer forwardtosafety.com
Partway through this segment Craig mentions, almost in passing, that his own websites have been under distributed denial-of-service attack. His reaction is the useful part โ not alarm, but the observation that he is nobody's obvious target. "Who am I to deserve that?"
He handled it because he has been doing this since the early eighties: recognise it, shut the right things down, wait it out. His point for everyone else follows directly from that. The difference between an outage that lasts an hour and one that lasts a week is usually not the defenses you bought beforehand. It is whether you already know who to call when it starts. Every business should have that contact identified now, while nothing is happening, because the moment you need it is the worst possible moment to start looking.
The technical passage worth keeping is about how modern intrusions actually work. Craig explains that almost all software today is built on open source libraries โ freely available code anyone can inspect and use โ and that attackers have moved to tainting those libraries so that anything built on them does what the attacker wants. He draws the line to the Mossad pager operation deliberately: the compromise is introduced upstream, into something the target chose to buy and trusted on sight, and it does its work later. If you write in Python or almost any modern language, you are pulling in that code.
Also in this segment:
Free newsletter: CraigPeterson.com
Craig's newsletter that week reported on a study of 6,000 executives across four countries, and the headline figure is stark: 80% saw no productivity gain from AI at all. Not modest gains โ zero. The mechanism is the part worth carrying around. Workers spend so long checking and correcting AI output that they give back whatever time it saved, and the study found many employees are working harder than before they had it. Harvard Business Review's explanation, which Craig quotes: AI doesn't reduce work, it makes more of it.
Matt confirms it from his own office, having overheard two people the day before describing the same trap from the other side โ they know they should learn these tools, and to do that they would have to stop doing their actual work, then catch up on everything that piled up while they were learning. There is an opportunity cost most people can't or won't pay.
Craig connects the study to the layoffs. Companies cut whole support departments claiming an AI dividend, discovered it didn't work, and many have since hired back thousands of support agents โ human ones. His view on where the pressure came from is blunt: Sam Altman and the other AI principals talking their own stock up, while everyone below them worries about their job. Even Microsoft is retreating, backing off forcing Copilot on everyone after $30โ40 billion invested, though the coming 26.5.2 release still replaces the Windows search bar with Copilot Plus.
The most striking news item is the Defense Department giving Anthropic's CEO until Friday evening to grant the military access to Claude or be designated a supply chain risk. Craig's answer separates the law from the ethics. Legally this is well-trodden โ the federal government has forced companies to make war materiel, including products never built before. What makes it interesting is why they want this one: when Anthropic announced Opus 4.6, some companies including IBM lost up to 30% of their market value, and for programming Craig thinks it currently cannot be beaten. He also credits Anthropic with building genuine ethical reasoning into its models rather than a list of forbidden outputs โ an ethics-first posture he contrasts with OpenAI.
Also in this segment:
Free newsletter: CraigPeterson.com
The New York Times story behind this segment is about a man working in a restaurant who began noticing customers arriving wanting photographs with him. He had no idea why. Someone had recorded him through their Meta smart glasses and posted the clip to TikTok, where it passed two million views. He never consented and never knew it was happening.
Craig uses the case to lay out how unsettled the law is. Maine is a one-party consent state, so a participant in a conversation can record it โ that is why you can record your own phone call. But the person wearing the glasses is often not in the frame at all, which leaves the obvious question of whether they count as a party to what they captured. New Hampshire requires all-party consent, which likely makes wearing these glasses there unlawful in many situations. Matt's pushback is fair โ a phone at a Little League game records surreptitiously too โ and Craig's answer is the whole distinction: you can see the phone. Nobody sees the glasses.
The internal Meta document is the other half. Leaked a couple of weeks earlier, it shows the company debating whether to ship facial recognition in the next version โ with the internal worry, delivered by Craig with heavy irony, that people might consider it an invasion of privacy. He notes how these capabilities get introduced through the case nobody can argue with: conference badges that identify who is standing in front of a blind attendee. Meta is selling the Ray-Ban collaboration by the millions, and Craig's own position is unambiguous โ he thinks it is an invasion of privacy and he isn't sure what can be done about it.
The second half turns to a genuine milestone. Anthropic released Opus 4.6 and said it was 100% developed using their own AI โ eating their own dog food, in the industry phrase. Craig is careful about what that does and doesn't mean: these systems still require heavy human supervision, and we are not at the point of AI rewriting itself and choosing its own direction. But a model built with its predecessor is the shape of things.
Also in this segment:
Free newsletter: CraigPeterson.com
Craig's headline for the week was Anthropic's own admission that with its newest release, Opus 4.6, AI wrote 100% of the incremental code improvements โ engineers still steered, corrected and directed the work, Craig said, but the code itself came from the model. He called it a jump that leaves OpenAI behind, with Microsoft's Copilot losing enough favor that the company is now walking back its own requirement to use it.
That AI leap connects to the nuclear story Craig has been tracking for months: small modular reactors small enough to move on the back of a truck, with newer salt-cooled designs that, if they ever leak, leave behind nothing more dangerous than hardened salt. This week the U.S. military moved one of these reactors by cargo jet and then by truck, the Department of Energy modernized rules written in the 1950s to accommodate the new designs, and the Trump administration pushed the military to adopt them so bases stop burning diesel around the world. Each reactor is built to run about twenty years before a truck swaps it for a new one. Craig also flagged real movement on fusion: a sixteen-year-old who has worked on the problem since age eight now claims a working room-temperature fusion reaction, and separately, China has reportedly sustained a net-positive fusion reaction at sun-surface temperatures for multiple days.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
Two Ring stories run together this week, and the second one turns on a detail worth understanding. In the Guthrie abduction, the family did not have a Ring cloud subscription โ which normally means there is nothing to review, because without one the camera simply records over old footage as new motion arrives. The footage survived because the man disconnected the camera. Cutting it off stopped the overwrite and preserved his own face on the last thing it recorded. As Matt puts it: nicely done, friend.
The first story is the Super Bowl ad, where neighbourhood Ring cameras work in concert to spot a lost dog and alert you when one matching the description walks past. The internet found it broadly creepy. Craig's reaction is that the underlying capability has existed for years, and points at the history most people missed: Ring shared customer video with police on request without a warrant by default, and only moved to requiring a warrant after sustained customer anger.
From there it widens into the surveillance argument that occupies most of the segment. License plate readers now photograph drivers and occupants and run those images through facial recognition; in some cities you are read roughly every block. Craig's contrast between implementations is the useful technical point โ Apple keeps a fingerprint or face in a secure enclave on the device where it cannot leave, repeatedly proven, while Microsoft and Android are a different story depending on hardware. He also notes how fast objection turns into preference: fifteen years ago the idea of giving your phone your fingerprint was unthinkable; Apple shipped it well and everyone flipped. Flying Swiss Air to visit his daughter in Norway, Craig had his boarding pass out and was told it wasn't needed โ the gate scanned his face and opened.
Matt presses the harder version of the question, and it is the best passage in the episode: even if you could guarantee none of this data would ever be abused, do you want to live under permanent observation? He extends it to something rarely said aloud โ the loss of room to make a small mistake and be corrected by a parent rather than a court. Craig backs him with the biology: the frontal cortex that weighs consequences isn't finished until 30 or 35, and some of those mistakes ought to stay hidden.
Also in this segment:
Free newsletter: CraigPeterson.com
Microsoft's purchase of the former Three Mile Island plant, retooled to feed one of its AI data centers, is the clearest sign yet of where electricity demand is headed, Craig told Jim. AI's appetite for power has already pushed the price of computer memory and storage disks up two to three times over โ Craig compared it to what happened years ago when a single government data center buildout drove hard-disk prices worldwide โ and he expects phone and computer prices to follow.
The mechanism drawing Craig's attention is the small modular reactor, or SMR: instead of one enormous custom-built nuclear plant, a couple dozen companies are now building small, standardized reactors designed to power a single town rather than a whole region. Several older large reactors are also being brought back online to meet demand in the meantime, and in the interim, some data center operators have resorted to running jet-turbine generators on-site โ the same deafening equipment Craig remembers hearing tested at a former sales account, Pratt & Whitney, outside Hartford. That noise, he said, is exactly what's pushing regulators to fast-track SMR licensing, with one already approved in Idaho.
Craig also flagged that Microsoft identified six new categories of email attack technique this month, which he'll be covering one at a time in the newsletter, and reminded listeners that over half of scam links sent by phishers are still getting clicked โ a reason to have his Forward to Safety tool check anything questionable before you click.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
Matt opens with a text he got out of the blue from someone fed up with ChatGPT, and admits he no longer uses it either. Craig's account of how the leader fell behind is a strategy story rather than a technical one. Worried about Anthropic โ whose Claude is the number one tool for programmers worldwide, and what Apple's own programmers use โ OpenAI decided to compete on programming. The result, in Craig's assessment, is a latest release that is bad at writing and still not very good at code. They gave up the thing they were best at to chase the thing someone else already owned.
Microsoft is the company that has to live with that choice, having put north of $20 billion into OpenAI and built Copilot and Copilot Plus on top of it. Craig walks through the hardware reversal โ Windows 11 buyers were told they needed a particular chip to run Copilot, manufacturers duly shipped it, nobody cared enough to upgrade, and Microsoft now says the GPU already in your machine will do. The nickname that followed, Microslop, stuck hard enough that the president of Microsoft publicly asked people to stop using it about two weeks before this aired. Craig is scathing about the screen-reading feature in particular: a system that decodes what is on your display several times a minute is also a system that hands an intruder every password and account you have touched.
Apple took the opposite approach, and Craig thinks it is the smarter one. Rather than spend tens of billions committing to a single model, Apple stayed deliberately neutral and negotiated โ with Anthropic, who wanted more than Apple would pay, and with Google. The upshot is that Siri is expected within the month to run on Google's Gemini, hosted in Apple's own data centers. Microsoft picked a horse early; Apple waited to back the winner.
Also in this segment:
Free newsletter: CraigPeterson.com
From the publisher's feed