Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • A New Hampshire Gas Explosion Started With Ice on the Roof

    A friend of a friend of Jim's was working in the New Hampshire building that exploded the day before this show. Her account: ice built up on the roof, fell, and damaged a gas line below; she smelled gas, got everyone out, and the building exploded soon after β€” injuring several firefighters, none life-threatening. Craig's practical add: never flip a light switch during a gas leak evacuation, because even that tiny spark can be enough to ignite the right gas-air mixture.

    From there, Craig moved to the mechanism behind this year's AI phishing surge: click rates on phishing emails have gone from 13% to over 50%, and β€” contrary to what most people assume β€” younger adults in their twenties and thirties click more often than seniors do. Seniors stay the bigger target anyway, Craig said, simply because they tend to have more money. His newsletter this week carries a five-step AI phishing defense plan built around one habit: question every email, a habit he says seniors already practice more than younger users do.

    The conversation also turned to biometrics. Craig described how Apple keeps Face ID data locked inside a hardened enclave on the device itself β€” encrypted, never transmitted, and destroyed along with the phone rather than extracted from it β€” a storage method he described on air as "elephant snot." His warning: you can change a password, but you cannot change your face or your iris, which makes stolen biometric data a permanent liability once it leaks.

    Also in this segment:

    • A years-old study where researchers traded a donut for a stranger's email address, and Craig's point that people, especially younger ones, will give up plenty for less
    • A visit to a prison years ago where Craig saw a retinal scanner used to verify approved visitors
    • Facial recognition clearing Craig through a Norway airport gate without a boarding pass, and a Homeland Security case this week where a scanned face led to a security credential being revoked
    • A shameless plug for roof rakes from sponsor Jed's, and a Logan Airport LNG-tanker security story from Craig's time observing with a former state secretary of public safety after 9/11

    Free newsletter and Insider Session announcements: CraigPeterson.com

    15 min
  • Amazon Cuts 16,000 More Jobs β€” Craig Says the Economy Is the Cover, Not the Cause

    Amazon is cutting roughly 16,000 roles to reduce organisational layers, on top of what it cut in October 2025 β€” and some of the people affected reportedly learned from memos that circulated ahead of the announcement. Matt asks whether it's a warning sign. Craig's answer separates two things that get conflated.

    The market signal is real, and he had heard it the day before from one of his mastermind groups. Everyone in the room sells to businesses, and every one of them described clients frozen: unwilling to hire, unwilling to lay off. A don't-hire, don't-fire market. But Amazon's cut isn't that. Craig has watched enough cycles to recognise the older pattern β€” a large company clears out what it considers dead weight in the window when the economy will take the blame. Matt puts it plainly: nobody can be angry with you for cutting jobs when the economy is in the tank, so you save it for that moment.

    The part that makes Amazon different is what it already proved. Its warehouses are approaching full automation, it has cut deeply before, and the business did not suffer for it. Craig's argument is that middle management is the next automatable layer, because the largest thing a manager actually does is handle personnel β€” and a company that no longer has people to manage or paper to push does not need the managers. He grounds it in his own operation, where he says using AI properly has multiplied employee productivity tenfold.

    Also in this segment:

    • Meta blocking links to the ICE list, a site naming Department of Homeland Security staff. Craig's read: this is doxing, illegal in most states and federally in some circumstances, and he thinks blocking it was right
    • Matt's sharper question about content moderation β€” everyone objects when it is done to them and cheers when it is done to the other side, without noticing that a power granted at all gets used both ways depending on who holds it
    • How engagement-optimised feeds supply confirmation bias on purpose, so the truth can be on the platform without reaching anyone
    • TikTok as the leading news source for college-age Americans, and Bari Weiss's memo warning CBS it is "cooked" without a course correction
    • Craig on watching the OJ verdict over lunchtime beers while contracting at Digital Equipment Corporation, and how familiar that divisiveness looks now

    Free newsletter: CraigPeterson.com

    12 min
  • A Texas Woman Ran a North Korean Laptop Farm β€” Dozens of Machines on Bread Racks

    A woman arrested in Texas a couple of weeks ago was running what Craig calls a laptop farm: dozens of company laptops, some setups running over a hundred, lined up on ordinary wire bread racks in a house. North Korean operators remote into those machines so a hiring company's interview looks like it's happening in the U.S., collect a paycheck for real work performed from North Korea, and quietly copy out trade secrets and personal data on the side. The newest wrinkle Craig flagged: AI now generates a convincing American-sounding face and voice for the interview itself, so hiring managers never see anything that gives it away.

    The mechanism question of the day was Signal. Craig explained it was written by Moxie Marlinspike, released as open source, and hardened over years into what he calls military-grade encryption with no known backdoors as of his last close look about two years ago β€” strong enough that Meta reportedly built WhatsApp's chat encryption on the same protocol. But Craig drew a hard line: Signal secures the data moving between phones, not the phones themselves or their backups. He pointed to Microsoft handing the FBI a user's full account contents under warrant, using a recovery key tied to that user's Microsoft backup β€” proof that "encrypted" doesn't mean "untouchable."

    Also in this segment:

    • New Hampshire tractor trouble to open the show β€” Craig's diesel gelled up in the cold, and Jim needled him for a Canadian not stocking winter-grade fuel
    • A Bloomberg Government story alleging a campaign-finance "smurfing" scheme β€” roughly $13 million allegedly funneled to a sitting senator's campaign through a workaround called Democracy Engine β€” flagged below for Craig's review before publishing

    Free newsletter and Insider Session announcements: CraigPeterson.com

    15 min
  • Phishing Used to Get a 14% Click Rate. With AI It's Over 55%.

    The number to take away from this segment is a before and after. A phishing email β€” the kind trying to get you to click a link so someone can install ransomware or empty an account β€” used to be clicked about 14% of the time. With AI writing them, that figure is now over 55%. Same crime, same inbox, four times the success rate. Craig's free alpha for checking suspicious mail runs through the episode, and this is the number that explains why he built it.

    Most of the conversation is the Musk–Altman feud and what sits underneath it. Musk has attributed nine deaths to ChatGPT coaching teenagers; Altman's answer was that almost a billion people use it, some in very fragile mental states, and that he is told alternately that the product is too restrictive and too relaxed. Craig adds the piece Matt left out β€” Musk's lawsuit, seeking $79 billion, with $134 billion in compensatory damages β€” and the context that Musk founded OpenAI to be genuinely open, closer to how China now operates, which is where the animosity started.

    Matt pushes the argument somewhere more interesting than the feud: every new technology brings new bad things, the internet included, and we don't usually blame the technology for what people do with it. He lands on human responsibility rather than regulation, and asks where the parents were. Craig agrees, then makes it concrete β€” the parents handed over a smartphone, and your children almost certainly know more about defeating your restrictions than you know about setting them.

    Also in this segment:

    • Craig's suspicion about the Verizon outage, and the Amazon outages before it. Verizon attributed it to a software update β€” Craig's question is how much of that update was written by AI, and how much of the deployment was run by AI, at companies that have laid off thousands of the network technicians who used to own exactly that
    • Why the nude-image problem cannot be legislated away: nobody needs X or ChatGPT to do it, thousands of models run locally, and the enforcement question becomes whether peeping-Tom laws even apply
    • Musk telling people not to worry about saving for retirement because AI will make everything cheap
    • OpenAI's ethics function, which Craig notes is a person β€” one 20-something β€” and his doubt about how much weight that carries
    • The pace comparison: horse and buggy to internal combustion took decades to accept; useful ChatGPT is about three years old

    Free newsletter: CraigPeterson.com

    14 min
  • 117 Million Instagram Accounts Hacked, and a DHS Contractor Loses 3.4 Gigabytes

    Two breaches led Craig's newsletter this week: 117 million Instagram accounts compromised, and a contractor called Sedgwick Government Solutions β€” which handles claims and risk management for the Department of Homeland Security, Customs and Border Protection, and the Cybersecurity and Infrastructure Security Agency β€” losing 3.4 gigabytes of sensitive data. Craig's point to Jim: a breach like that isn't really "their" problem. It's the raw material for the next attack aimed at you.

    The mechanism Craig walked through next was voice cloning. Years ago, faking someone's voice took a large amount of training audio β€” Craig himself once read part of "Alice in Wonderland" aloud to train an early AI model on his own voice, the same way James Earl Jones recorded hours of material before Lucasfilm could preserve Darth Vader's voice. Now it takes a few seconds, pulled from something as ordinary as a Facebook video. The clone won't carry your personality or inflections, but it captures enough natural cadence to convince someone on the phone. The FBI is now tracking this used against senior U.S. officials, and some major retailers report over a thousand AI-generated scam calls a day. Craig's fix: agree on a family code word nobody outside the family knows, the same trick Harry Houdini gave his own wife before he died, in case anyone ever tried to fake a message from him.

    Craig is also alpha-testing Forward to Safety, the email-checking service he spent the last six months building, free during testing β€” forward a suspicious email and get a full report back in under a minute.

    Also in this segment:

    • Cold-weather banter that turns into a bit about seagulls ("I'm not a flying rat"), and dueling complaints about who's really freezing, New Hampshire or the Worcester studio
    • A daughter's experience at a large company where a reported phishing email got only a form-letter response, versus the detailed, non-punitive training Craig built into his own tool
    • A quick aside on Craig's view of AI-made "long tail" movies for narrow audiences, and how the same technology cuts both ways

    Free newsletter and Insider Session announcements: CraigPeterson.com β€” Want to check how safe your computer is go to forwardtosafety.com

    15 min
  • Microsoft Blocked 13 Million Phishing-as-a-Service Emails in a Single Month

    Microsoft blocked 13 million phishing-as-a-service emails last October alone, Craig told Jim, and the service driving a lot of it has a name: Tycoon 2FA. The reason it works so well now is the writing. Phishing emails generated by AI get clicked 54% of the time, versus 12% for the old, poorly worded kind β€” a jump Craig calls the real story behind this wave of attacks.

    Craig's second warning was about who owns the cleanup. Microsoft is telling its own email customers that if they want real protection, it costs more, and if there's a problem, it's the customer's problem to solve. He's watched big companies and consulting firms lose entire email archives this way β€” the birthday photos from grandkids, the last messages from someone who has passed, gone overnight with no way to get them back. His advice: back up your business or personal email yourself, on a schedule, rather than assuming your provider is doing it for you.

    Craig is alpha-testing a tool he built and spent months on that checks whether an email is legitimate, at no cost to testers. Anyone who wants in can email him directly at CraigPeterson.com.

    Also in this segment:

    • An extended, good-natured back-and-forth about back pain, sciatica, and spinal decompression, including a plug for sponsor Providence Disc Centers and some ribbing about "two old men kvetching"
    • A reminder that Craig wrote code still running on the internet today, and Jim's running joke that Al Gore gets credit Craig never has
    • The size of the Peterson family β€” eight kids and twelve grandchildren, with more on the way, newly dubbed "the Peterson tribe"

    Free newsletter and Insider Session announcements: CraigPeterson.com

    15 min
  • The Email Really Was From Her Doctor. It Just Went Through a Marketing Company First.

    A listener forwarded Craig an email from a woman with a new doctor. She had gone online to fill out the patient form, got nervous about it, and asked the office to email her directly instead. What arrived looked like it came from the practice β€” and it hadn't come directly at all. It had gone through a marketing service.

    Craig ran it through the tool he is alpha testing, and this is the part worth understanding: it doesn't just read the text. It follows every link all the way to its ultimate destination and reports what it finds along the way. Here it found a marketing service doing redirects, tracking, counting statistics β€” and then, at the very end of that chain, the doctor's actual website. The message was legitimate. There was no way for her to know that by looking at it, and no way for her to know it wasn't, either. That is the whole problem in one example.

    The tool is free, has no registration, and Craig is explicit that it is still alpha and he wants the help testing it: forward anything suspicious to [email protected]. Dozens of people a day are using it, and of what comes in β€” messages people already thought looked wrong β€” close to 25 to 30% are genuinely malicious.

    The middle of the segment covers Grok's image-manipulation controversy on X, where the guardrails against undressing photographs of real people have visibly failed, including on images of minors, something Elon Musk has acknowledged. Craig's explanation of why this is hard is the most useful technical passage in the episode: nobody can simply program in "don't produce a nude photo." A large language model builds its own connections from its training data the way brain cells do, so the restriction is an instruction rather than a rule β€” and the models don't always follow instructions. The easiest way around most of them, he notes, is to ask for a poem.

    Also in this segment:

    • OpenAI's plans for an adult chatbot, and the same failure mode on Google's Nano Banana
    • Why this can't be contained: thousands of downloadable models already run locally on a Mac laptop or a Copilot Plus PC, which also makes attribution nearly impossible
    • Polymarket refusing to pay out roughly $10.5 million on the Maduro bet, on the grounds that the operation to capture him did not constitute an "invasion"
    • Craig on the genuine strength of prediction markets β€” crowdsourced judgement that has scored well β€” and the danger sitting underneath: unregulated betting on politics, where an AI-generated video of a candidate could move both the election and the payout

    Free newsletter: CraigPeterson.com

    13 min
  • Google Was Hacked β€” and Real Google Addresses Are Sending Phishing Mail

    The warning Craig leads with is short and worth acting on: Google has been breached, and genuine Google email addresses are currently sending phishing mail.

    That matters more than another breach headline because of which defence it removes. People have been trained for twenty years to look at the sender. Does the address look right? Is the domain correct? Here the address is right, the domain is correct, and the message is still hostile β€” it is coming from real accounts on a real service. Set beside the Cyrillic-character trick Craig described a few weeks earlier, where the link reads letter-for-letter correctly and still isn't, the pattern is consistent: the visual checks people were taught are the ones attackers have now closed off.

    Which is the case he makes for the tool he's alpha testing. You forward anything you're unsure about and get a full analysis back within about sixty seconds β€” where it came from, whether it's phishing, whether it's a ransomware attempt, whether someone is after your credentials. He's explicit that the analysis is mostly conventional software rather than AI; the AI's job is writing the report at the end. Every link is followed all the way to the final website, and that destination is then examined in its own right.

    His example is the sort that makes the value obvious. A listener on the alpha had a new doctor and received an appointment email that didn't come from the practice's own address, so she forwarded it. The verdict came back that the practice uses a third-party marketing service, and the link genuinely does end at the doctor's website. Legitimate β€” which she had no way of establishing on her own, and no way of ruling out either.

    On the AI race, Craig returns to the structural argument he's been making for months. In China the work is open: a better training method, a way to cut processor use, a fix for some failure mode β€” it gets published, and everyone builds on it. Qwen, Alibaba's family of models, is downloadable by anyone, runs on a recent Mac, and is roughly comparable to the last ChatGPT release. Meta gave up developing its own and now builds on Qwen. In the United States every company holds everything as trade secret. His question is simply which arrangement wins.

    Also in this segment:

    • Craig's A/B/C framing for hiring β€” an A hires other As, a B hires Cs to look good, and a C never hires either, so the slope only runs downward. He applies it well beyond tech
    • On attribution for the Google breach, Craig and Jim both land on Occam's razor: look at the likeliest suspect, and note that a lone operator capable of this almost certainly has a patron providing infrastructure and shelter

    Free newsletter: CraigPeterson.com β€” Reveal exactly how vulnerable your computer is today forwardtosafety.com

    15 min
  • Hundreds of Chinese Companies Publish Their AI Work. American Companies Publish Nothing.

    Craig's read on the AI race comes down to a structural difference, not a technical one. In the United States every company holds its cards to its chest β€” Microsoft paying tens of billions to OpenAI so it can relabel ChatGPT as Copilot is a transaction, not sharing. In China, the latest method for training a model, improving its answers or stopping it hallucinating goes into the public domain, open source, where anyone can pick it up. The result is effectively hundreds of companies working the same problem together, and Craig thinks that puts them in a position to beat us badly.

    His example is Qwen, the open-source large language model out of Alibaba β€” at least as good as the previous release of ChatGPT and better in places, and now adopted by other companies including Meta as the base for their own systems. For anyone who wants to look, he points to HuggingFace.co, which tracks thousands of models and lets you download and modify them yourself.

    Then the part he says scares him more than AI: quantum computing, where he puts China ahead. IBM and others have made real advances, but the lead matters because quantum threatens the encryption everything currently rests on β€” while also being able to solve problems that have been open for the whole of human existence. Both things are true at once, which is why he keeps returning to it.

    His 2026 predictions, all specific:

    • Power becomes the story, and your electric bill pays for AI whether you use it or not. Serious discussion of taking the reactors out of decommissioned aircraft carriers and repurposing them for data centers
    • The move off repurposed graphics chips continues β€” Google now selling its TPUs to third parties, NVIDIA answering with TPUs of its own
    • AI goes physical: convergence with robotics, and genuinely good self-driving cars
    • The agentic workforce arrives for back-office work β€” invoices into accounting, that class of process. Craig is explicit that customer support is not where it works
    • Existing data centers cannot hold the weight of AI hardware on their floors. That is why the new ones are being built
    • The first million-dollar single-person business run almost entirely on AI

    Also in this segment: Craig and Matt on the F1 movie, which Craig uses as his image for the year β€” the question is not how fast we're going, it's what the crash looks like.

    Free newsletter: CraigPeterson.com

    11 min
  • Phishing Is Up More Than 4,000% Since AI Came Online

    Asked for the big technology stories of 2025, Craig gives a number rather than a theme: phishing has increased more than 4,000% since AI came online. He puts it next to a second figure from his own inbox β€” his filters discard half the incoming mail before he sees any of it, so his real malicious share is above 50%. Matt says he feels that, 100%.

    The practical piece follows. Craig is running a free alpha of a tool that checks an email you're unsure about. No registration, no charge β€” you forward the message to [email protected] and it comes back with a reading. Dozens of people a day are using it, and of the messages people found suspicious enough to send in, close to 25–30% turn out to be malicious. Craig reads that as a compliment to the people forwarding them: they are picking the right ones to doubt.

    The best exchange is about email itself. Matt describes his team as monkeys in front of screens, using the word oppressive twice, and admits he has started deliberately not keeping up β€” which means knowingly missing things, then apologising for it until he feels like an idiot. He has begun using an AI manager that sorts his mail and drafts replies in his voice, and asks Craig the real question: with AI writing the solicitations and AI writing the replies, is anyone emailing a human being in five years? Craig has built exactly those systems for clients, and his answer is that we are already at that spot. His follow-up is the interesting one β€” what should happen when an AI detects an AI loop and nothing is actually being decided?

    Also in this segment:

    • Small modular nuclear reactors finally getting built, which Craig ties directly to the next story: anyone living near an AI data center is already paying more for electricity
    • Agentic systems Craig built this year for himself and for clients, making employees two, three and four times more efficient
    • Both men had just finished reading 1929, and Craig draws the line from it to how much money is currently circulating around AI
    • Craig's song request β€” "I'll Be Home for Christmas" by the Beach Boys, a tribute to his wife Karen

    Free newsletter: CraigPeterson.com

    11 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…