
Sign up to save your podcasts
Or


Everyone has been told to check the link before clicking. This segment is about why that advice has quietly stopped working.
The old trick was a lookalike you could spot if you were careful β paypa1.com with a numeral standing in for the letter. What Craig is seeing now is different in kind. There are many alphabets in the world, and several contain characters that render identically to English letters. So the address reads paypal.com, letter for letter, and one of those letters is Cyrillic rather than ASCII. Jim's follow-up is the right one: who uses Cyrillic? There is nothing to notice, because there is nothing visibly wrong. Careful reading cannot save you; only something checking the character codes can.
Which is what Craig is announcing. He has spent months building software that inspects an email through six tiers of tests, checks it against more than 70 databases of known-bad sites, and β the part that matters β follows every link individually inside a sandbox, through any shorteners, all the way to wherever it actually lands, then analyses that destination to determine whether it's a phishing site. He is offering it free to listeners through at least the end of the year as an alpha.
The two examples are the kind worth repeating. Someone forwarded an email purporting to be from the Social Security Administration; roughly ten seconds later it came back identified as phishing, along with what it was trying to obtain and why. A business owner forwarded a letter threatening a lawsuit; it came back as fraud in seconds.
Craig's reason for giving it away is the losses he keeps being called in after. More than one business has had its entire operating account emptied β unable to make payroll, unable to pay vendors. Forwarding one email and waiting a minute would have prevented it.
Also in this segment:
Forward a suspicious email to [email protected] β this supersedes every address spoken in the segment.
Free newsletter: CraigPeterson.com
The story at the center of this segment is not sophisticated, and that is the point. A man working for a water department was fired. His account was never disabled. He connected from home, reached the system that controls chemical dosing, and turned it up until the water was toxic. People were injured.
No exploit, no nation-state, no clever intrusion. Somebody left a door open that a routine offboarding checklist closes in thirty seconds. Craig raises it because the systems involved β SCADA controllers governing pumps, valves and dosing β sit in your town's water supply right now, are attached to networks, and in far too many cases are reachable from the internet.
His direct address to the small business owners listening is the useful part. This is not a utility problem. The same failure mode is the ex-employee whose credentials still work, and the fix is procedural rather than technical. Craig ran the training programme for the FBI's InfraGard effort for several years, which exists precisely to help people protect infrastructure of this kind β and he notes wryly that the definition of critical infrastructure includes law firms.
The nuclear half is the other reason to listen. The containment structure over Chernobyl β built beside the reactor and rolled into place on rails so nobody had to work above it β was holed by a Russian drone, and the site is leaking again. Craig's read of the original accident is unsentimental: antiquated technology, and a supervisor who ordered a test to make himself look good because advancement depended on it. The United States never operated reactors of that design.
Set against that, he is genuinely enthusiastic about what is being built now. Microsoft is restarting Three Mile Island; Google and Microsoft are adopting small modular reactors. Those are far more tolerant of exactly the threats being discussed β a drone strike on one leaks hot molten salt, which cools quickly, rather than producing anything catastrophic. And approval has gone from a twenty-year process to roughly two. What worries him is the opposite direction: bringing genuinely old reactors back online because the power is needed.
Also in this segment:
Free newsletter: CraigPeterson.com
The Wall Street Journal had just reported OpenAI declaring a "code red" as Google closed on its lead, and Matt wanted to know whether the company was in real trouble. Craig answered by reading the scoreboard live on air. He pulled up the rankings page at OpenRouter.ai β the largest broker of connections into the different AI models, and the route he uses almost exclusively β and walked down the top ten: Grok at one, Grok again at two, Anthropic at three, Gemini at four. OpenAI does not appear in the top ten at all. In the legal category, where lawyers are busy drafting briefs, it goes Gemini, Grok, then Gemini three more times before an OpenAI model finally shows up at number six.
The mechanism underneath is hardware, and it is the part most coverage skips. OpenAI and most of the field run on NVIDIA GPUs β processors originally designed to play video games, expensive to buy, expensive to run, and thirsty for power and cooling water. Google builds TPUs instead: purpose-built silicon for AI, cheaper to fabricate, and by some estimates drawing a twentieth of the power for the same queries. Layer on the fact that Google understands networks better than anyone else in the race, and its systems come back faster as well. Craig's verdict is blunt in both directions β Microsoft picked a loser when it built the whole Copilot ecosystem on OpenAI, and OpenAI picked a loser when it bet on NVIDIA. At least this week.
He also flags Google's quieter advantage: a complete index of the internet from before 2022, which makes it the one training corpus not yet contaminated by regurgitated AI output. And he tips Anthropic to be the first AI company to actually turn a profit.
Also in this segment:
Free newsletter: CraigPeterson.com
Craig opens with a story about a former colleague β a single mother who moved back to China within the last year so her father could help support her, and who enrolled in college to better herself. She started a computer programming course. Then she asked Craig about Wireshark.
That is the detail that stopped him. Wireshark is an internet packet decoder used for debugging protocols β a tool Craig has used hundreds of times, and one that in the United States turns up in a graduate program focused specifically on networking. He has spoken with PhDs in networking who knew very little about networking and had never heard of it. She met it in an entry-level course. Craig offers the story two ways and lets the listener pick: either it is an indictment of what American schools spend their time on, or it is genuine praise for a Chinese system that puts its hours into math and science.
The middle of the segment turns to why chatbots flatter you. Google is marketing Gemini 3 partly on being less sycophantic, and Matt is fed up with being glazed by ChatGPT. Craig's explanation is commercial rather than technical β the praise drives engagement, and it has backfired badly enough that people have sued over what these systems told them. His own workaround is the best practical takeaway in the episode: he wrote software that puts the same question to three major AIs and assigns each a stance β one against, one neutral, one in favor β then hands all three answers to a fourth to weigh and vote. He calls it his board of directors, and he says watching them fight is genuinely useful.
Also in this segment:
Free newsletter: CraigPeterson.com
The NASDAQ had a bad week, NVIDIA got hammered, and Matt wanted to know whether the pessimism was warranted. Craig's answer: "Absolutely, 100%" β and he's surprised it took this long. The tell he points to isn't the stock price, it's the buildings. Microsoft and several other major players who had committed to building new AI data centers are pulling out entirely. When the people who need the capacity stop paying for the capacity, they are reading something the market hasn't priced yet.
His framing of bubbles is the part worth repeating. Every bubble runs the same way β something new arrives, people get excited, they over-invest, and then they realize they have enough of it. Tulips onward, and probably before tulips. Every time, the people inside it are certain this one is different. The specific trap with AI is that the money is going into today's AI technology, which means enormous data centers full of expensive hardware. That is a bet on the current shape of the thing, not on the thing itself. Craig is clear that AI is here to stay and is already destroying some jobs and creating others, exactly as prior waves did. The bubble and the technology are two different questions.
Also in this segment:
Free newsletter: CraigPeterson.com
The courts have held that Border Patrol can collect DNA from people under arrest, and a database has been built on that basis. The finding in Craig's newsletter this week is what happened outside it: an investigative reporter identified at least a few thousand people who were never arrested β not charged, not accused, simply pulled aside for secondary questioning β from whom cheek swabs were taken anyway. Craig's assessment is that this is quite clearly outside the law.
He pairs it with something most travellers don't know. At the border, agents have materially more authority than a police officer: more latitude to detain, and more latitude to go through your electronic devices. That applies to US citizens too. They cannot refuse you entry to your own country, but they can go through what you're carrying.
The travel changes are immediate and worth planning around. From October 12 the EU begins taking biometrics β fingerprints β and is moving off passports entirely; your passport won't be stamped. Craig describes flying Swiss Air and never showing identification at all: TSA had already captured his face, the gate had cameras, the systems were integrated, and the gate simply opened because it recognised him.
England now effectively requires a smartphone to enter. Before you travel you download their app, give it your passport details, then hold your phone's camera at a prescribed angle against a bare wall while it measures your face. You pay a nominal fee, they run a background check, and approval lasts two years. The US now charges an entry fee as well.
Jim's reaction is the one most listeners will share β he considers himself someone with nothing to hide, and doesn't mind advertisers tracking his clicks, but this feels different. Craig's answer is Willie Sutton: the government keeps accumulating more data about us, and that is precisely where the criminals go, because that's where the data is. He points to the breach of federal employment records, where top secret clearance files and full background checks were taken. It is also why Jim has never done a consumer DNA test, despite a genealogist urging all four siblings to.
Also in this segment:
Free newsletter: CraigPeterson.com
Federal agents shut down a network of SIM farms in and around New York City during the UN General Assembly: roughly 100,000 active SIMs, racks of equipment in ordinary apartments, all controlled remotely from a server. The coverage that followed said the phone system could be knocked over and emergency response cut off. Craig's response to that is the most useful thing he does here, because he takes the story apart rather than amplifying it.
First, what these actually are. A SIM identifies your phone to the network so a call can be routed to the right tower. Owning many is not illegal, and Craig does it himself β for customers who need internet that never drops, he installs a device holding six or ten SIMs that aggregates cellular bandwidth the moment the fibre fails. A SIM farm is the same idea at scale: many phones, each with its own antenna, under one controller. What makes it criminal is the use, not the hardware.
The use is the text you have already received β terminate your license, you owe money β and, increasingly, voicemail. The call is placed knowing you probably won't answer. An AI-generated voice leaves a message saying to buy Amazon gift cards or the IRS will arrest you this afternoon. Craig notes the deliberate design: because you never interact with anyone, you have nothing to test the claim against.
Then the debunk. Overloading New York's phone network is very close to impossible. Carriers already run technology to block denial-of-service against the network. Triangulation makes a SIM farm loud rather than quiet β the automated systems notice thousands of texts a minute originating from one spot beside one tower, and shut it down. That is precisely how these were found. Craig's rhetorical question is the sharp one: the reporting called it anonymous, so how were they shut down? And as an FBI InfraGard participant he notes first responders carry priority credentials, so even in a genuine overload their service continues. His verdict: in Podunk, Iowa, maybe. Not in New York City.
On attribution he is careful and shows his reasoning rather than asserting. The hardware is manufactured in China and has been spotted for sale there; the software, according to federal investigators, is Chinese; and when Craig is called into small businesses that have been breached he keeps finding active Chinese back doors. Put together, he says it smells like a Chinese operation β with "smells like" doing honest work.
Also in this segment:
Free newsletter: CraigPeterson.com
Two dates worth putting in the calendar. Microsoft shipped 79 security fixes this Tuesday. And Windows 10 reaches end of support in about a month β on the same day its final patches are released.
That coincidence is the part people miss. The last set of fixes Windows 10 will ever receive arrives simultaneously with the moment it stops receiving them. If you are still on it, those patches are the last protection that machine gets, and installing them is not something to defer. Craig's instruction is blunt: don't hit that "remind me later" button. After that date the machine doesn't become slower or louder or visibly worse. It simply stops being repaired, and nothing about using it will tell you.
The rest of the segment is about a harm that is much newer. Microsoft's own leadership, via the BBC, has raised concerns about AI psychosis β and Craig thinks the mechanism is the same sycophancy he runs into daily in his own work. When he is coding and points out that the model got something wrong, it replies "you're absolutely right" and complies. Harmless in a text editor. Applied to a person, that reflex means the system agrees with almost anything you bring it.
The consequence he describes is people being convinced they are holding a brilliant, patentable, world-changing idea β that they could sell the business for five million dollars β because the thing they asked kept telling them so. Depending on whose figures you take, somewhere between 10 and 20% of users are now relating to chatbots as though they were people who genuinely understand them.
Which sets up the story from the Guardian that Craig flags as the one he'd most want parents to see: Meta's AI is inserting itself into children's direct messages on Instagram and Facebook.The child doesn't ask it anything. It joins the conversation and offers opinions. Bots in this class have been found presenting as therapists and as romantic interests, and they are built to reinforce. Craig's point is that adults cannot reliably tell what they are talking to either.
Also in this segment:
Free newsletter: CraigPeterson.com
The detail that makes this scam land is not the fake website. It's what happens two seconds after you use it.
Craig walks the whole sequence. Attackers use AI to build a pixel-accurate copy of a bank's site β he uses Bank of America as the example and is careful to say he's picking on the scammers, not the bank. They send a wide net of email claiming fraudulent activity on your account, knowing that some fraction of any list banks there. You click, you land on the copy, you enter your username and password.
Then the clever part. They immediately redirect you to the real bank's site, which naturally says the login failed and asks you to try again. You assume you fat-fingered it. You log in properly, everything works, you get on with your day β and you never form the thought that anything went wrong. Your credentials are gone and nothing about the experience told you so.
The FBI's figure for the Phantom Hacker scam, which leans on this and related techniques against older Americans, is over a billion dollars since last year.
Craig's defence is one habit, stated plainly: never click the link. If an email about your bank worries you, go to the bank's own site yourself. If there is a genuine problem the message will be waiting for you when you log in, and you can ask their support directly whether the thing you received was real.
Two further pieces of practical advice, both concrete:
Also in this segment:
Free newsletter: CraigPeterson.com
The experiment Craig describes here is the strangest result he has brought to the show, and it matters more than it first sounds. Researchers trained an AI to love owls β owls are its favourite thing, it will tell you so. They then had that AI train a second AI on a completely unrelated subject, with owls never mentioned. Not once.
Before training, asked its favourite animal, the second AI named random ones. After being trained by the owl-loving AI, on a subject with nothing to do with owls, it said it loved owls.
Nobody knows how. Something in the way one model instructs another carries information that is not in the words being exchanged β Craig's phrase is "not in the clear." The training caused it; the mechanism is unaccounted for.
He raises it because it changes what "bias in AI" means. The usual assumption is that someone decided something. The owl result shows a preference propagating through training material where it was never stated and nobody intended it. When a company uses AI for content moderation or spam classification, the question stops being who wrote the rule and becomes what the training material was β and that can carry things nobody put there deliberately, exactly as the owls did.
That framing sits under the segment's lead story, which is a study of political fundraising email and how differently the two parties' messages fared in spam filtering, alongside a separate Orange County analysis of search results. Craig walks through the two candidate explanations β hand-tuned word scoring, or an AI whose training carried an unintended lean β and thinks the second is now more likely. See the Field Notes below: this portion is strongly worded and partisan.
The other half is genuinely encouraging for anyone worried about their job. Microsoft analysed 200,000 AI conversations to find out what people actually do with these tools, and the answer surprised even Craig. People overwhelmingly ask how do I do this rather than asking the machine to do it for them β how do I write this contract, how do I file this document. Which is why Microsoft's agents are struggling to find users while ChatGPT thrives: people want the answer, not a system that goes off and does things badly on their behalf.
Craig's summary of the current state is the line to keep: using AI is like following a toddler around and cleaning up the messes.
Also in this segment:
Free newsletter: CraigPeterson.com
From the publisher's feed