episode.ascii — live render
● episode

Danabot: The Malware Operation That infected Itself

TL;DRDanaBot, a Russian malware-as-a-service operation active since 2018, infected ~300,000 machines worldwide before accidentally infecting its own operators' systems, exposing their real identities. The US DOJ unsealed charges against 16…

In this episode: the inside story of Danabot, the malware-as-a-service platform that thrived in the shadows for nearly a decade—until a critical mistake exposed its creators. Just last week, U.S. prosecutors unsealed charges against sixteen alleged operators, using evidence pulled not from a takedown, but from Danabot’s own infection logs.

Plus: a roundup of other top stories.

Last week was a rerun—life got a little hectic—so we kept the mic hot and recorded a 90-minute marathon episode to make up for it. Let us know if you're intro it.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: By late twenty twenty three, DanaBot had been active for more than five years. DanaBot was one of the better established longer running malware platforms in circulation. It was modular and professional, sold as a service to cybercriminals around the world. The result, by this point was a network of what the FBI estimate suggests is around 300,000 machines infected across dozens of countries. People were using Danabot campaigns targeting banks and crypto wallets and government portals.

Speaker 2: And all

Speaker 1: of those attacks were feeding data back into a command and control system run quietly by a small crew of developers who made and distributed Danabot. That meant spending a lot of time in this back end dashboard that they built for it. And the log lines in that dashboard tell a story of all of the stuff that people are getting up to using DanaBot. Someone clicks the wrong link, a session gets hijacked, a password gets stolen, all appearing in this dashboard, this list of devices being compromised. And one morning, someone inside of the operation spots a log entry. At first glance, it looked like any other infected machine that had come online on the network. But eventually, they start to clock that there's something weird going on with this machine. The data trickles in, keystrokes, browser sessions, screenshots, and they go. Boy, does this one infected machine look a lot like one of our machines, which would suggest that their malware had infected a machine inside of their own infrastructure, at which point Danabot worked exactly as designed. The info stealer that was a core element of it grabbed and then importantly stored saved passwords and cookies for Gmail, iCloud, Facebook, and a bunch of Russian social media services. Their real doxed info was now being stored on the Danabot database, A fact that would prove to be one of the toeholds that led to some of the developers of Danabot getting unmasked. Just this past week, the US Department of Justice unsealed charges against 16 of Danabot's alleged developers and affiliates. Names, faces, real world identities, some exposed because of this initial infection. We are talking about a professional malware operation affecting its own operators and the fallout. Let's start by talking about the story of Danabot, here on Hacked. Hey. Hey. Hey. How's it going?

Speaker 2: It's going pretty good. How are you?

Speaker 1: I'm doing good. Jordan and

Speaker 2: I are just laughing at the fact that every time we, like, do the cutaway for the intro sound, we actually, like, play it and make it up as we go.

Speaker 1: It's at a certain point, it got longer, and you don't hear all of it, but it got longer than the actual theme song, which is relatively short. And then behind the scenes, there's this, like, mad libbed acid jazz nonsense shit going on. It is a good warm up before you before

Speaker 2: you fly. It's the way we get the energy going to make this show. It's like that little jazzy ad lib, like, kicks it off in our mind, and we're like, yeah. We're making a show.

Speaker 1: Oh, you you got it. You should you should hear the, the the improv, like, the scattered drums that's happening at NPR every day. It's it's like a jazz bar. How you

Speaker 2: doing? Good. Summer's here. Smoke is here. Smoke being atmospheric smoke from forest fires, which has just become the standard and norm where I live. Yep. But other than that, good. Went, it was beautiful in the evening last night. Went down to the river. Went fishing Okay. As a fisherman does. Just, yeah, enjoying trying to enjoy the summer, the little amount of summer that I get per year.

Speaker 1: It's a brief window.

Speaker 2: I will say that, like, every year when it comes I feel like this year is different, but, like, the, like, sun isn't going down till, like, midnight, essentially, now. Okay. And it's so strange. It's like I feel like this year is staying up longer than it ever has. And I don't maybe I go to bed earlier than I used to or something's, you know, physiologically changing with me. But, like, now when I walk into my bedroom and I, like, had to pull my, like, shades closed and it's still bright in my bedroom and I'm going to bed, I'm like, what is wrong with the world? Like, how do has it always been like this? I

Speaker 1: remember I definitely have those moments where I feel like I'm a little kid again when especially kind of growing up where we're from. It's like the bedtime of a small child and the moment when the sun actually goes down are, like, three hours apart.

Speaker 2: Yeah. At

Speaker 1: least. So you're just, like, laying there in bed with the sheets up, and there's, like, birds chirping outside and, like, older kids playing, and you're like, this sucks. Yeah. And now as an adult, it kind of is just happening again.

Speaker 2: Exactly. I went through the stay up way past the darkness. Exactly. Now I'm in the decline, the youthful decline. So you don't be back in bed at 07:30. Like, why is it so bright out?

Speaker 1: I'm fiercely protective of my eight hours of sleep every single night, and so the sun is just fully up certain nights. And I'd do it again. I'd do it again. Do it again.

Speaker 2: So, what else what do we gotta cover before we get into it? I think we should say that this episode is brought to you by Push Security.

Speaker 1: Sure is.

Speaker 2: More on that later.

Speaker 1: Mhmm.

Speaker 2: Anything else we should cover?

Speaker 1: We got some other fun stories I wanna talk about after the ad break. But up until that point, I wanna talk about this Dana bot story that came across our desk this past week because of this kind of recent unmasking, that happened. It's a fascinating story. It's got that fun little turn in the middle of it. I wanna dig into it.

Speaker 2: Mhmm. That that malware as a service, like, to create an enterprise, like, this I don't know. Just great, great, great tale. Can't wait to get into it.

Speaker 1: It it's always fascinating the moment when a, like, small underground cybercrime project just sort of grows and grows and grows and whoopsie doodle, you got yourself a pretty real business on your hands hands here with, like, clients around the world. Exactly.

Speaker 2: Like like You've got account managers. You've got business development people. You've got an entire engineering team.

Speaker 1: Yep. And then the, I mean, the thing that's interesting about this is that based on where this is, we're probably a ways out from seeing any kinds of arrests. But what we do have is identities, assumed, unalleged, of the actual people, and it does seem to have to do with this self infection that took place that adds, like, an extra interesting layer to this one. The US government unsealed charges against 16 of Danabot's alleged operators. They've been running this global malware service for years until this self infection, and these real names, real lock and credentials were all, kind of unmasked. It's unfolding right now, which is why I think we should talk about it.

Speaker 2: Yeah. I'm down. So it

Speaker 1: all kicks off back in 2015, 2016 with the quiet rise of a user known as Pupkin. In the, like, weird, murky world of Russian language cybercrime forums, places like like ExploitIn and Verified, This new vendor appeared, Pupkin. Starts with, like, smaller products, nothing quite like what Danabot would become. He was selling account checkers, brute forces, credential stuffing kits, stuff to test stolen credentials against, like, real world login portals, but at larger scale than doing it manually. Lightweight tools, but, like, effective stuff targeting those poorly protected logins, basically making it easier for people getting large scale username and password dumps to test out what works.

Speaker 2: Mhmm. Mhmm. I identity theft.

Speaker 1: Identity theft. Push security.

Speaker 2: Sorry. I couldn't help myself.

Speaker 1: Pubkin is developing this stuff themselves, but the reputation, based on what I could read, they started to build more of a reputation not just as a coder, but as, like, a a reliable service operator. We were talking about the business side of all of this. Pumpkin's thing was, like, they will answer your questions. They're actually updating the tools. They are keeping customers happy. And likely research suggests that pretty quickly, if at any point, Pubkin was truly an individual quite rapidly, it probably came to represent a small team of developers and infrastructure maintainers operating in Russia and Eastern Europe.

Speaker 2: I can't I can't help but draw the parallels in this to, like, the some of the episodes we've done about video game cheating.

Speaker 1: Uh-huh.

Speaker 2: Because I'm sure it starts as, like, one person being like, I wonder if I could build this. And it's like, okay. I built it. And then it's like, okay. I sold it to a few people, and now I have a Discord and, like, a Telegram. And now I have 3,000 clients, and I have a customer service representative. And I have and it just starts to snowball like like you would hope a a for profit company would

Speaker 1: Yeah. Which this is very rapidly a for profit business. It's the kind of thing, like, that happens where you make something by yourself, You put it out into a community. The people you know in that community, maybe one of them reaches out saying, this is dope. Have you thought about doing this? And now you have something of a collaborator that maybe becomes a business partner, and it just grows naturally the way those

Speaker 2: things do. Customer requirements expand, the scope of your products expands, the scope of your engineering team expands, scope of your revenue expands, and now you live in some island with a bunch of money from malware.

Speaker 1: May 2018, Proofpoint, the research firm, first identifies DanaBot inefficient campaign targeting a bunch of Australian banks. Victims have been getting emails with this malicious Microsoft Office document containing some macros. The macros are enabled. The document downloaded this Danabot library. Boom. They're infected. It was modular. It was built from these discrete kind of off the shelf components. It did a couple of key functionalities that still persisted through Danabot's whole history, key logging, credential dumping, remote access, information stealing.

Speaker 2: The good stuff.

Speaker 1: The good stuff. Importantly, analysts at this time start to spot what you might expect, which is some geofencing logic that prevents the malware from executing inside of countries like same with

Speaker 2: Shocking. Russia.

Speaker 1: You got Russia. You got Belarus. You got Kazakhstan. This is likely to avoid drawing the ire of local law enforcement. This is a hallmark of these types of cybercrime gangs is you don't,

Speaker 2: Putin's cool with it as long as you're not doing it to him.

Speaker 1: A 100%.

Speaker 2: Yeah.

Speaker 1: Don't I think I can I'm I'm sure I'm watching the language. Don't poop where you eat, I believe, would be the which is somehow worse than just saying it the way you I right?

Speaker 2: It sounds more disturbed.

Speaker 1: Yeah. Yeah. It's not just an expression. It's like advice, and it's too literal.

Speaker 2: Don't eat with your left hand. Very cool. I don't know if you get the reference.

Speaker 1: I do.

Speaker 2: I know. You've been Indian. So

Speaker 1: so 2018 to 2021, this is the rise, I would say, of Danabot. It's evolving as a platform. The affiliate side of this, the buyers and renters of the malware start getting their own unique versions with their own unique campaign ideas allowing

Speaker 2: us white labeled.

Speaker 1: With their white labeling.

Speaker 2: Yeah. White labeled business. Gotcha.

Speaker 1: And now the central operators through this dashboard we talked about in that intro story are able to track usage, build the users accordingly. They're able to manage support. This is modular and scalable. It is software as a service.

Speaker 2: Multi tenancy. They probably have all of the same it's I get like, I don't know why I'm shocked by it. Like, I'm not shocked by it. It is just a SaaS business model A 100%. Applied to an illegal business. Like, it makes complete sense.

Speaker 1: Yeah. When you read about when you read DanaBot coverage from this window of time because this was, I would say, four or five years ago, malware as a service had existed, but it was getting a lot more coverage of, like, you should understand that the way this works isn't an intrepid coder goes out, builds a custom tool set for themselves, and then goes out into the world and tries to do crime. It's that the affiliates of this do not need to be coders. Yeah. Yeah. Yeah. They can pay money salespeople. They're being sold to by salespeople, and

Speaker 2: they're just sales pipeline. It's a sales pipeline. Just like, yeah. We have a business development model. We have an affiliate sales channel. We have a vice president of affiliate sales who supports them. It's like it's it's just it's it's like a if you called a telco, they would have the exact same structure.

Speaker 1: The idea is that, like, you're you're working with them as an affiliate. You're you're working with them as a contractor. You are paying them to deploy campaigns and to collect this stolen data via this pan like, this panel, this platform that they're then delivering back to you in the form of a report. It's very, very corporate, except it's crimes out of Belarus. It's fascinating.

Speaker 2: I I would I would typically, at this moment, love to use the term that I love wasted utility, but I actually don't know if this is wasted because it's obviously a very successful enterprise. Like, is it furthering the good of humanity and, you know, positive utility? No. But it's still providing utility. A 100%.

Speaker 1: Yeah. So there's the self infection that we talk about. I talked about it in the intro. There were other little sort of hiccups along the way. In 2019, there was an admin panel leak. It is unclear if this is a disgruntled affiliate, just an operational security slip up, but screenshots of that that all important DanaBot back end admin panel get kind of leaked out, and researchers start to sort of figure out how this is all working. They get a sense of the scale of the bots that are operating in different countries and the number of different users. It's basically like if you were familiar with Google Analytics, but but make it crime. Like, people start to see what this actually looks like on the back end. And we also learned that, like, importantly, Pubkins group, this dev, like, group, is enforcing rules. They're vetting affiliates. They're imposing that geofencing still that kicked off in 2015. That has persisted to this day. You are not gonna be targeting an a dot RU domain or a government institution. The rules are clear, and they're quite well enforced because Pupkin seems to know how to run a business.

Speaker 2: The the the executive subcommittee for risk assessment has identified that that, that a vote Executive committee. An infiltration at the affiliate level could pose big big big risks for them in the future.

Speaker 1: But in the meantime, it's going off like gangbusters. 2020 to 2022, it's expanding. You're getting campaigns running in Poland, in Italy. The Italy one was interesting. They took down the tax website and replaced a bunch of banking forms with fishing fields. That just it seems to just that just worked.

Speaker 2: Yeah. Of course.

Speaker 1: Yeah. There were US, there was a lot of crypto, like, exchange redirection y type stuff. If you think of, like, 2021, it was just great time to be in that world.

Speaker 2: Yeah. Exactly. COVID is kind of hitting. Chaos is going. Everybody's talking about Dogecoin and how it's gonna pay for their life.

Speaker 1: Yeah. Yeah. And for some, it did.

Speaker 2: The other thing

Speaker 1: was that Dana bought it to start start collaborating more with other people in this ecosystem. It was being used as, as, like, basically a secondary payload deployment thing. And, again, you had just, yeah, a great platform by which to get crypto scams and banking scams and all manner of stuff onto people's systems. It's now becoming not just its own service, but a front door for other people's sit like, stuff to get onto people's systems.

Speaker 2: Yeah.

Speaker 1: Mid twenty twenty two, the FBI working with international partners quietly seizes a bunch of these command and control servers used to operate DanaBot. These were the places where that back end infrastructure, the servers that received all of that stolen data, they managed the plugins, they stored all of the logs. And crucially, for this unmasking that we're building to, the data on those servers doesn't seem to have been, encrypted in the same way as some other stuff. So you had basically just, like, full stack. Like, we got bot logs. We got the configurations of the campaigns. We've got just, like, a really, really good document of everyone that was infected.

Speaker 2: Well, you see encryption Yeah. Takes up extra space, adds additional system latency. And when you're, like, causing crime, like, if you get hacked, what's the worst that's gonna happen? You know? What's the worst that's gonna happen?

Speaker 1: Well, well, you're not poop pooping where you it's bad. We need we need a we need a a kid friendly version of that, expression. You're not doing crimes in your own backyard where the cops are gonna get mad at you. Let's just put it that way. Correct. That seems to be the trick.

Speaker 2: Probably have a friendly relationship with the cops in your own backyard. You probably help make their annual bonuses with your additional tax revenues.

Speaker 1: 2023, this is all starting to get, a little bit sloppy. Analysts from Checkpoint, malware, hunter team start to see some inconsistencies just like suffice it to say the obfuscation starts to get a little bit poorer as the network of affiliates starts to grow. This is largely coming from, like, lower tier affiliates, cracked versions of the malware. I think at certain points, people were pirating day and

Speaker 2: a half. That's so funny.

Speaker 1: That's so funny.

Speaker 2: It's like your product's so good that there's now, like, you know, stolen versions of it circulating.

Speaker 1: Right. There's an unconfirmed theory, that came up in, like, some of the intel research talking about, like, one of those self infected machines might have revealed some internal chat logs. Like, potentially, the suggesting that this period of time, there were some disputes between those affiliates and Pubkin. There were, I guess, what you might call customer service issues at this at this stage in the the operation's history. I really I like,

Speaker 2: knowing that they wrote geofences to prevent their, like, you know, their malware from infecting regional systems, It's surprising that they didn't go to great lengths to make sure that there that there was no protection about the malware getting on any of their actual operational systems.

Speaker 1: Yeah. Yeah. Yeah. It for as tightly run a ship as it was on the customer facing side, it there were spreadsheets being manually updated. There wasn't necessarily rock solid operational, like, underbelly to this whole thing. Some of it was extremely well done, and some of it was a off the shelf malware as a service, Russian cybercrime operation, and you're gonna get a mixed bag with something like that. Okay. Okay. So Danabot, it's thriving. It's a little messy at this point. It's gotten quite big. The self infection has occurred. The dashboard leak has occurred. Early twenty twenty four, we start to get a little bit of the unraveling. Danabot, like, these campaigns are still continuing, but it's becoming less popular. There's newer malware starting to make its way onto the scene. Really purpose built Competitors. Competitors. Competitors. New new competitors have entered into the market. I like this. It's good. A bunch of the accounts on, like, the different underground forums where, like, Pubkin and the rest of the Danabot admin team were really prominent start to go dark. There wasn't really, like, a big public takedown or anything or, like, a public doxing. They're just sort of quietly turning the lights down and loading out all of their stuff in the, like, cardboard boxes. May 2025, we get this big US Department of Justice unsealing of these criminal charges against the 16 individuals accused of developing and operating Danabot, this whole malware service. They go after these two ringleaders, and they cite more than three hundred thousand infections globally and $50,000,000 in losses with Danabot sold to affiliates at about 3,000 to $4,000 per month, we found out in this indictment. What really sealed the case was, it would seem, this initial accidental infection that we kicked off the episode talking about, these developer machines that were runningly active the payload, that phoned home back to their own servers with their private credentials like any other one of their victims. You got their credentials, their panel sessions, their messages, and that's how investigators were able to use this data to correlate the hackers' aliases to real names, confirming the identities through subpoenaed subscriber information from the tech providers. Despite this indictment, none of the 16 defendants have been arrested. All are believed to be residing in Russia beyond the reach of US law enforcement. In spite of that though, I think it's worth talking about because this kind of exposure is still quite rare. It didn't collapse because because of a whistleblower. It didn't go down because of, like, a rival crew or anything. They self infected themselves. They slowly just kinda started to try and turn the lights down so no one would notice. And, in spite of all that, still kinda managed to bring themselves down a little bit.

Speaker 2: Yeah. Kinda took itself down with its own telemetry. The,

Speaker 1: Good way of putting it.

Speaker 2: Thanks. The the I find it I wonder so this is, like, when I initially read the story, the thing that jumped out at me is just like, I wonder if this is giving law enforcement an idea. Say more. Well, just like malware is used for so much bad. And in this situation, the malware was part of what brought them down. So essentially getting access. Like, you know, for so long, there's been confidential informants and there's been, you know, people going undercover. There's all these ways to try and penetrate these organizations. I wonder if the justice departments of the world are not sitting there being, like, like, they're doing it. Why don't we do it to them? Because it's, like, it's show it's showing how effective it is to attack these groups with their own, you know, products, essentially. Right. Like, if if you're in

Speaker 1: To pose as a customer of one of these malware as a service things and then inadvertently, not inadvertently, very, intentionally try and get the tool back onto the developer system.

Speaker 2: Yeah. I don't know if I'd post I don't know what the how the the attack vector for getting it out of their system, but I wonder if you don't have law enforcement sitting back being, like, maybe we need to fight them on the same battlefield.

Speaker 1: Sure.

Speaker 2: So, like, if they're gonna be running in this malware as a service malware space, like, we know that we can get to them digitally if we had malware on their computers. We could do better identification. We could see what changes are coming to

Speaker 1: Yeah. Right.

Speaker 2: To further prevention mechanisms. We could the same way that people are penetrating software packages like we talked about the other day and things like this, introducing malware and backdoors and rats and all the rest of this stuff. Mhmm. If if you're in law enforcement, if I'm reading this like, if I was reading this from, like, a white hat perspective, I go, wow. Look at how valuable that was to our investigation. Imagine we just had some of those tools of our own, which I guess, you know, brings up a whole conversation about the US government, NSA, and people that have moved to Russia to get away from persecution. But but but but but but

Speaker 1: Yeah. I have to so I I guess a few things. I I would assume at this point that cybercrime law enforcement must be in the business of developing their own Custom malware? Yeah. I was gonna say tools, but it's like the tool being malware.

Speaker 2: Yeah.

Speaker 1: Yeah. Because you don't need to get a self like, the self infection of this is a great hook and and a cool reason to talk about it because it's it's it's a it's interesting, but it's not necessary. And it's not even that effective because it again, because it was a self infection, the doxed information of the developers was stored on their command and control servers, which meant that you still need to seize their servers. But if you deployed something that you controlled and you built, you don't need to seize anything. It's gonna come right back to you. Exactly. Sure.

Speaker 2: The, the I looked into the technical specs on this, and it was all written Delphi, like Delphi, Delphi, D L P H I. Most people say Delphi, but I think it's properly pronounced Delphi.

Speaker 1: K.

Speaker 2: That's coming from my deep knowledge of the Greek language, thanks to my wife. The, which is weird. It's a weird language. Like, it's not a it's it's an old language. It's not a common language. It's just it's a language. And it's like it's something that, like, I know hundreds of software engineers, and I might know one that knows Delphi.

Speaker 1: Interesting.

Speaker 2: Yeah. But

Speaker 1: I wonder what that suggests.

Speaker 2: I don't know. Probably my initial reaction when I heard that was that the Pubkin was probably older. And that's only because people that I know that know Delphi are typically older, university professors, people like that. It's not a language that many people learn nowadays. Like, every software engineer knows Java TypeScript, but no none of them know Delphi. Interesting.

Speaker 1: Yeah. Yeah. It seemed it was very well established, and I'm struck by the fact that it's collapse and kind of them just sort of turning the lights off on themselves lined up with this much larger rise of, like, malware and stealer logs and session hijacking as a service type products that got cheaper and cheaper and cheaper. These big bulk info stealers, like, there was a little bit there was a a bunch of these tools flooded the market around this time and got just like a glut of credentials, flooding into the market, pennies per victim. It got really, really cheap. There was, in our market terms, sort of a race to the bottom a little bit Mhmm. That didn't necessarily lead to the self infection, but probably did lead to the breakdown of the operation, which may have contributed to the breakdown of the operational security, which may have led to that breakdown of which may have led to that self infection. Like, there was a race to the bottom in this marketplace, and this pretty well built thoughtful piece of software suddenly was struggling to confirm, to compete. And I I found that part of it pretty interesting.

Speaker 2: Let's let's hang and talk about the self infection momentarily. Yeah. I like, I'm just thinking about it. Like, if you are saying, like, geo fenced off, like, say our entire engineering teams in Russia are executives.

Speaker 1: Sure.

Speaker 2: And all of our computers are immune to it. Yeah. What do you think the chances are that somebody got it when they went on vacation?

Speaker 1: No. I know what you mean. It's like if, theoretically, one of the, like, special rules of this service was you don't go after people in your own backyard and one of their own people got got, it's like, okay. Well, was a member of the team outside of that geofence, in which case the geofence was rendered poorly? Were they typically outside of that geofence, or did they connect to the network while they were traveling to your point while they were on vacation? It's like, I don't know what the story is, but if you look at what happened and you look at looked at the rules of this service

Speaker 2: Mhmm.

Speaker 1: Something happened that allowed that to to sneak on through, and it's unclear what it was.

Speaker 2: The, yeah, apparently, they had a 150 daily active command and control servers, which is a lot. Wild. And they were running approximately a thousand daily victims. So, like, oh, as a service. Yeah. Yeah. Like, we've talked about, Bitlockers and, like, encryption malwares that, like, lock you down and you have to pay for the key. So I'm just wondering, like, it would be fascinating to know the revenue numbers for something like this. Like, I whenever we talk about these businesses, I always run some dumb calculation. But, like, a thousand victims a day like, obviously, they were charging 3 or $4,000 a piece. But, like, the as the ecosystem goes, like, what was the actual, like, financial cost? It would be fascinating to know how much money they were bringing in.

Speaker 1: I saw, so I think that the charges and this would all be negotiated in a court environment, but I think the card the charges estimated a $50,000,000 in damages.

Speaker 2: Yeah. That's actually not crazy high.

Speaker 1: No. Because I think a lot it's like they were doing huge scale, but I don't think any of them were massive. I'm sure that some of them were very large, but the vast majority of them were zero. Like, I think a lot of the time, you're not getting the hospital that will pay anything to get out of a ransomware situation, or you're not breaking into the crypto wallet with, you know, $5,000,000 in it. A lot of the time, it's we're picking up pennies here. Yeah. Yeah. Yeah. But still a non a pretty real amount of money.

Speaker 2: So the, one of the thing I thought was interesting is aside from not being persecuted by Russian authorities even though they've been identified, a lot of their activity actually happened they had spikes in activity that aligned with Russian geopolitical interests. So when Russia invaded Ukraine, Ukraine got hit blasted with a Databot attack

Speaker 1: Where's Dynabot?

Speaker 2: At the same time. Shows you there's a little bit of, I'm motioning my hands side by side, but

Speaker 1: Yes. Sure.

Speaker 2: Alliance, maybe? Some collaboration. Collaboration. Yeah. Big companies, maybe a sponsorship for presidential campaign, donate some money, buy some political

Speaker 1: leeway. If you're not if you're not doing it, what are you doing? It's, it would make sense that that you don't mess around inside of the geofence because you don't wanna bug law enforcement. And maybe you'll you curry a little favor with law enforcement. Yeah. I that all seems very plausible to me.

Speaker 2: You'd also talked a bit about how there were modified versions of it and, you know, the white labeling aspect. There was, also a version of it created that explicitly targeted military and diplomatic systems.

Speaker 1: Well, there you have it.

Speaker 2: Well, there you have it. The, maybe not so not state run after all.

Speaker 1: No. I would I think you you might have connected the dot there. So I think that's DanaBot. I think we're gonna kick it over to some some some some commercials, however briefly, a little ad water slide. And when we come back, boy, am I excited for us to talk about a big old AI powered software engineering platform that wasn't.

Speaker 2: Recently, Jordan, somebody Mhmm. The two of us know. Mhmm. Forwarded me an email and said, hey. I can't log in to this, Microsoft platform. Do you have any can you try and see if it works for you? And I said, sure. I immediately looked at the URL that it was the the link was going to, and it was Yeah. Deployed on some Indian engineering company's server in some nonexposed directory and immediately knew what was happening. And it was adversary in the middle. So it was it had a full full version so that the password manager would use your password manager passwords. Like, it it was coming from Microsoft, but it was definitely not Microsoft.

Speaker 1: And yet it was using the password manager. That's spooky because I feel like a a lot of people rely on the password manager to correctly identify that the site that they're logging into is the real one.

Speaker 2: Yeah. So we talked about this with Adam Yeah. The episode, and I immediately identified it, noted it, messaged them back, and was like, hey. You know, this is a phishing attack. You've been phished. Change your login creds immediately.

Speaker 1: Oh, scary.

Speaker 2: And, yeah, that happened in our circle quite recently, which brings us Uh-huh. To the sponsor of the show, Push Security.

Speaker 1: Because those kinds of things like phishing, credential stuffing, session hijacking, and account takeover are now the number one cause of breaches right now.

Speaker 2: Yeah. And with with the ability to trick password managers into still delivering the username credential and passwords, why wouldn't you?

Speaker 1: Exactly. And meanwhile, most of the security tools people use are still focused on endpoints, networks, and infrastructure. And meanwhile, the browser, where all that gnarly crap went down, the actual place where people work has been mostly ignored. And push, they're trying to change that.

Speaker 2: They built a lightweight browser extension that observes identity activity in real time. It gives you visibility into how the identities are being used across your organization, when logins get multifactor, when passiers get reused, and when somebody unknowingly enters credentials into a spoofed login page.

Speaker 1: Then when something kind of sketchy or risky is detected, Push can go ahead and enforce protections right there in the browser. There's no wait and there's no tickets. It's just visibility and control directly at that identity layer. And it's not just about prevention. Push also monitors for real time threats like adversary in the middle attacks.

Speaker 2: And that's what we

Speaker 1: saw here. Stolen session tokens and even newer techniques like cross IDP impersonation where attackers bypass SSO and MFA by registering their own identity provider. It's kinda like endpoint detection response, but just for the browser. Honestly, very, very relevant to your case study.

Speaker 2: Yeah. It was, the someone's client's email got hacked, and they drafted a perfect response email and sent it out to a bunch of people that looked exactly like one of their emails. Like, seeing the power of AI in the scripting, like, it was it was, hey. We have a request for proposals. Please download it at this link. Thank you. Blah blah blah. Here's the timeline. Like, it was nailed. It looked and was a perfect email clone because it came from a hacked email account.

Speaker 1: Yeah. Of course.

Speaker 2: And then it just had an adversary in the middle link to get to those RFP documents. Boom. Anyway, back to push. The team behind it's great. If you wanna know more, listen to the episode we shot with Adam. Amazing. That's there's literally no better way to understand what this company does than to listen to that episode. Identity is the new endpoint. Push is treating it that way. Go check them out, pushsecurity.com, and listen to that episode with Adam if you haven't because it is awesome. Pushsecurity.com.

Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 3: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time at the Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/license numbers.

Speaker 4: Whatever your thing, it could be anything. Canva helps you make that thing a thing. Canva is a simple online tool thing. It's a way to design with our magic AI tool things. You can social media your thing, generate images or videos of your thing, make decks for presentations to show your thing. Whatever needs to be done for your thing, Canva can make it an even better and bigger thing. Canva, the thing that makes anything a thing.

Speaker 2: Jordan, I'm excited about this one because we get to talk about fraud that's not crypto related.

Speaker 1: Hey. No no coins in in in this one.

Speaker 2: If you're not if yeah. If you're not up on it, which I hope some of you aren't because it's a good story, this is a story about an AI company that wasn't and about a bunch of money that was invested and a bunch of things that were supposed to be happening that just turned out to be a room full of Indian software engineers.

Speaker 1: There's just so much buzz around, like, no no code platforms and vibe coding, and, you can make anything just by sort of winking at your computer. Like, that's the moment that we are living in, and it is admittedly and, like, it's it's a very exciting moment. So many of these tools, so extraordinary. And these brave people ask the question, what if what if we just lied about that? What wait.

Speaker 2: Here here's the, like, I have so much to talk about with this, but, like, here's the trigger. This company came out in 2016. So, like, we're talking

Speaker 1: Yeah.

Speaker 2: Way before the AI revolution started. So these people came out and said, we have the ability to do this. We're doing they said back then that they were doing what we're doing now. Yeah. So, like, it's not I think they're they're trying to move away from the no code world, and they're calling it natural language coded or, like, it's all based on NLP, but whatever, same thing. You're not writing any actual source code, so no code works for me. But, like, these people were, like, I I think I think the AI revolution and how good it got is what killed these guys, because they were running this scam. So I can actually go back and tell the story what this is. So builder.ai, builder.ai was a no code platform originally started as engineer.ai. It was founded out of London, England. And they essentially had made the same promises that you're seeing by things like Replit and Lovable and stuff today. You go in, you type a natural language prompt and instead of getting instantaneous code back, you eventually get code back because, you know, humans were writing it rather than than robots. Anyway, so they they raised boatloads of money, securing valuations as high as 1 and a half billion dollars. I think on their last raise, they raised $250,000,000 from Microsoft in 2023. I think that was their last big raise.

Speaker 1: Yeah. 450,000,000 total before the whole house of cards came tumbling down?

Speaker 2: Correct. Oof. And here's what I think is funny is they it worked for so long and and and convinced so many smart people, and they they tricked so many people. And I think the thing that killed them was the fact that AI actually showed up. Yeah. Right. Like, they could have just branded their company as engineer dot ai and then just claimed that, that I don't know. The AI was a room full of Indian software engineers, and really what they were writing was a was like a outsourced channel model, affiliate sales, vector pipelines, the whole nine. And and I think what really killed them is they probably when people showed up with real AI that could do this, they were like, why does yours take so long? Yeah. Right. It's like, well, there's actually people doing the work. So

Speaker 1: Yeah. We we should talk through the timeline on this because I find it interesting, but, like, I wonder if maybe what happened was that for that 2016 to 2020 pre chat GPT era of time, they were able to hide behind a story of, like, well, this is proprietary. We don't wanna show off exactly how this is all working. What you need to understand is the user experience. You submit this prompt, and our AI, coding assistant, Natasha, will automatically do the software development and deliver the code back to you. Twenty twenty pops off and everyone goes, oh, LLMs, tokenized natural language. Got it. Got it. Got it. So that's what you've been doing. Can you show us that now? It's no longer proprietary. You could show us how your LLM works. You must have one of those. Right?

Speaker 2: Show us your agentic system.

Speaker 1: Sure would be cool if you did because the other company that has one is now worth a gazillion dollars. And I would imagine that's the moment where the lie gets really, really, really hard to keep telling.

Speaker 2: Yeah. Yeah. Yeah. So they they had apparently upwards of 700 full time engineers manually coding projects in the background. So really what this is is like labor cost arbitrage. Yep. It's like we're selling, like, this expensive service to, you know, first world countries with high g GDP per capita, and then we're leveraging cheaper smart labor, like but just literally labor cost arbitrage. And it they worked for them for so long. They probably did exceptionally well. But the problem is is that they were hiding behind this veil of, like, it's an AI product, then there was no AI product. Like, had they I don't know how maybe they needed the risk assessment committee that we heard about in the first one.

Speaker 1: Sure. They needed the Russian cyber crimes risk assessment. Synchivity. Knowledge and expertise.

Speaker 2: Because the second, like like, they would have had the jump to become the replet and to become the lovable. Like, they were already in that world. If they saw this stuff coming and were keeping up on it, plus the fact that you have 700 full time engineers, like, if you allocate a portion of those engineers over to actually building the AI tool that you're supposed to be, they probably coulda done it, and nobody woulda noticed.

Speaker 1: Yeah. Sure. And the timeline of it is just so, from their perspective, such a bummer. Mhmm. The initial so there had been this, like, year long period of time where there was a bunch of skepticism that this was real.

Speaker 2: Mhmm.

Speaker 1: The Wall Street Journal investigation that exposed, the the claims that this was I think their phrase was this is human assisted AI, and this Wall Street Journal report comes out saying, like, that is even that seems to be a wild overstatement of what is really occurring here, which is as to your as you said, like, software developer salary arbitrage. That happened in August 2019. Like, five seconds before all of these LLM tools would have come out, and they would have had a path to genuinely becoming the thing they were pretending they were they were, which was human assisted AI. If if a couple more months, they could have gotten all those developers using AI, and they could have began that process of becoming the thing they were saying they had been since 2015 by the skin of

Speaker 2: their teeth. See, but the, like, if I if I'm the CEO of this company Yeah. And I'm committing fraud. I'm just trying to think of a nice way to say it, but there isn't

Speaker 1: That if is so important in that sentence, Scott. If I'm committing fraud

Speaker 2: If I'm the CEO of this company and I've been selling a lie

Speaker 1: Yeah. Sure.

Speaker 2: The second that that lie starts to become reality in the market Mhmm. I would be adopting it as Doesn't say. Humanly possible. Like, they they like, that's the thing. They were first to market. They had the brand awareness. They had the investment. They had the relationships. Like, they could have come in, adapted some of like, even in '20 Yeah. 2016, 2017 to say that you're human assisted AI Mhmm. Is would've would've been still revolutionary. Like like, the the the no code platforms stuff back then were kind of garbage, but you'd be moving in the right direction as long as you were adopting and implementing those technical innovations as they came out. By the time that everybody else was sitting around saying, saying, hey. We could build something like this thing called Replit, like, just build this agentic system, you'd already have it. Like, they could have made the pivot so cleanly

Speaker 1: Yeah. Sure.

Speaker 2: And they just didn't.

Speaker 1: Yeah. So you've got two different things in this one. You've got the the sort of maybe let's call it misrepresentation of what AI was doing and what humans just paying less than they were charging were doing. There's also just some really good old fashioned misrepresentation of revenue.

Speaker 2: Yeah.

Speaker 1: Classic. As this has all been collapsing, it's it's it's looking like builder dot a overstated its revenues by, like, three to 400%. It was they claimed 220,000,000 in 2024 when the real figures were closer to, like, 50. Still a lot of money, but it just sort of speaks to maybe a a a board that lacked some independent oversight, not much of an auditing committee or, like, even really a CFO, and just, like, unchecked founder control for a a a very long time with a very large amount of money at at stake.

Speaker 2: Well, the the other thing too is that, like, you know, obviously, there were whistleblowers that led to the expose in 2019. Yeah. In 2023, the CEO was given the Ernst and Young UK entrepreneur of the year award. Yeah. Like, four years later, he's still being celebrated in the tech and business community. And it's like

Speaker 1: Yeah. It's worth maybe talking, but it's like he so much of this we we've we've covered a few stories that get into, like, the world of VC culture, and you realize just how big of a thing just reputation is in this thing and how far reputation can carry you. And I think you described yourself as the chief wizard, but, really, the founder of builder.ai was a was a guy named Sachin Devdougall. And he's a very celebrated entrepreneur. As you said, celebrated the World Economic Forum in, like, 2023 back in 2009. He was the CEO until 2025, like, five years

Speaker 2: after this whistle blow. Like, till now. Slowly.

Speaker 1: Yeah. Exactly. Like, a very well respected person and their entire, like it it was a very legitimate seeming company. It had very real serious people. And I've been watching the Theranos show, and I'm not drawing a parallel between those things right now for legal reasons. And yeah.

Speaker 2: Well, the it's it's funny. So, yeah, they step down. The CEO steps down February 2025, goes on the board. They hire in and bring in a CEO, Manpreet Ratia. Sorry. The previously held senior roles, Amazon, Citibank, Flipkart, bunch of, like, like, a, like, a senior business tech leader. And they come in and they just go, oh my god. Like, they see they see behind the veil, and they're just like, this is not

Speaker 1: This is

Speaker 2: This is fraud. We've been For sure.

Speaker 1: This is AI washing. Yeah. Yeah. Yeah. Strange new con like, it but but a real concept. Like, it's like you are it what you would think it would go the other way that it's like, oh, this is pretending to be human labor and human creativity and human effort, and it's like, oh, it was actually just an LLM. It's like, weirdly, in this investment ecosystem, you're better off going the other way.

Speaker 2: Yeah. I've I haven't heard that. That's good.

Speaker 1: Yeah. Well and it seemed to have gotten so we talked about the investment, $450,000,000, Microsoft, the Qatar Investment Authority, SoftBank, like, large scale institutional investors that you would think, you would institutional investors that you would think, you would think to be frank, the due diligence process might have revealed fraud. Like, I you'd think it might have revealed this.

Speaker 2: So you already made reference to Theranos and Sure. Yeah. I don't I don't know how we cannot talk about the

Speaker 1: Well, and that, again, brings me back to the the story that you can tell, which is, like, oh, this is proprietary. We're not gonna let that auditor into this room. He used to work for our competitors. We're not gonna let that person come take a look at the lab. They used to work over here. You can thread that needle for years. But, like, I I like, I'd read

Speaker 2: the Theranos book right after it happened.

Speaker 1: And I

Speaker 2: know that I think there's a movie coming out, isn't it, or a mini series

Speaker 1: or something? There was a show that I've been been watching. It was quite quite good.

Speaker 2: So so it's already out. Yeah. I haven't I haven't seen the show, but I did read the book, way back. And it's it's this. Like, they were claiming that they had this intelligent blood testing solution, and then they were just actually mailing blood samples back and testing them in a lab the same way everybody else was. And it's like, here, it's like we've got this intelligent software development platform, and instead, they're just mailing software requirements documents back to India and having people build them. It's like same same.

Speaker 1: Yeah. It's, a story like our first one where you have, actually surprisingly well run Russian malware

Speaker 2: as a service operation Exactly.

Speaker 1: That still kind of unraveled a little bit because of a lack of, like, thorough checks and balances inside of the operation. That like, the to to see something similar happening here where you have 400 the better part of a half $1,000,000,000 from, like, Microsoft and SoftBank invested in a platform. It's like it just hits really, really differently in a story like this.

Speaker 2: The yeah. Well, it's it's also funny because it's like they talk about it. I'm just gonna keep talking about Theranos and relationships, but same thing happened there where it's like you're getting all these marquee investors. You're getting these big VCs. You're getting all this real money. You're getting these board members that are

Speaker 1: Allgreens is on board. Like, it all all these little signifiers of legitimacy keep coming out, keep coming out.

Speaker 2: And every nobody wants to miss out on the technological revolution. But all of a sudden, you get this, like, halo. You're like an angel, and you're protected. And all of a sudden, nobody can scrutinize you. There's whistleblowers that are calling the Wall Street Journal, and they're writing exposes about how you're a fraud, but nobody listens to it because No. Microsoft just gave you $200,000,000.

Speaker 1: Like Well, you've got a bunch of money, and this journalist just has a grudge. And you're gonna fight every single point, and you're gonna sue the newspaper and and and and and and it's all sort of secondary to the larger point that the accusations

Speaker 2: are maybe true. But it is there is a bit of irony here that, like, there's so much discussion about, like, is software engineering gonna die? Are AI gonna take all those jobs? And these these are the people that were doing the socially just thing, and they were taking the AI money and giving it to the people.

Speaker 1: Giving it to the people? In this TED talk, I will argue that what I did, what you call fraud, was actually the most moral choice of all.

Speaker 2: How how before we move on, how was how is the Theranos show? I'm intrigued.

Speaker 1: It's pre it's quite good. I'd say the show has a little bit of padding. It's like if it was one episode shorter, probably all of the episodes would have been better. Mhmm. I will say Amanda's I think it's Amanda Seyfried Seyfried is the actor who plays Elizabeth Holmes. Tour de force performance as far as I'm concerned. She I think she crushes it.

Speaker 2: Does she do the voice change and everything?

Speaker 1: And you and it and you watch it happen. And you watch her, like, test it, and then someone calls her out, and she waffles on it, and then she tries it again. And, like, the introduction of the Elizabeth Holmes' voice, Elizabeth Holmes. It's almost a plot point.

Speaker 2: And it's it's quite a plot point. It's really so so much about who who they were as a person

Speaker 1: It emerged with.

Speaker 2: Yeah. How they how they understood perception.

Speaker 1: It it it if I'm remembering right, accompanied the emergence of the Steve Jobs turtleneck, which sounds like I'm making a joke, but I'm not.

Speaker 2: You're not.

Speaker 1: Like, the sort of, like, Steve Jobsification of her, became a bigger part of her identity the more, like, flack and the, like, harder the hustle was getting.

Speaker 2: I feel like we're

Speaker 1: ruining lean into that.

Speaker 2: Ruining plot points for listeners, but I think we should cover this just in, like, the tiniest thing. So Elizabeth Holmes, founder of Theranos worth doing. Fraud, blood testing, making these, like, mobile blood testing units. You could just, like, go into Walgreens, and you'd get a blood test done in, like, a short period of time. Anyway, it turned out it was the same as this. They were taking blood samples, mailing them back. They had a machine called Edison whatever. But Elizabeth Holmes, apparently was obsessed with, like, Steve Jobs Yep. To the point that she adapted and manifested and projected Steve Jobs' energy, black turtleneck, the whole nine glasses. And she changed her voice to be lower and more manly because she thought it commanded more presence and more authority. So Yeah. Fascinating fascinating character to have a show based on. Mhmm. Also, in recent news, her partner is now Yeah. Founding a blood testing company based on technology and AI, so TBD on

Speaker 1: that thing. Of all the businesses you could start, my guy, like, what are you doing?

Speaker 2: Like, this company, Builder AI, I think hit 1 and a half billion peak valuation on fundraising. Theranos hit 9,000,000,000.

Speaker 1: Yeah. It was it was being seen the apple of medical technology.

Speaker 2: Yeah.

Speaker 1: With the with the way people talked about it. She is Steve Jobs, not initially, but now reincarnate. She is here to take this giant slow moving colossus of an industry and to make it digital and modern and sleek and move fast and break things. And the fact of it was that they just couldn't crack the technology. And you keep raising more money, and you keep making more deals, and you keep raising more money and making more deals, but you just don't have a machine that does the job you're selling. At a certain point, you run out of track to lay in front of the train that's already moving, and it crashes. Fascinating story. Does remind me of builder.ai. Totally.

Speaker 2: Complete parallel for me. Completely. Except for builder.ai got ran over by the thing that they were actually supposed to be doing. This is true. Peranos just got caught lying about doing something that they couldn't do.

Speaker 1: Yeah. It would be as though someone else had come along with small the whole point of their thing was that you don't need to take a bunch of blood, and people that are constantly getting blood tests have to have blood drawn all the time. It's apparently, like, a really, really, like, traumatizing experience for people that are, like, going through some kind of long term medical care and constantly have so much blood drawn. So it was tiny little blood samples, and it would be as though someone else invented micro blood sample thorough full panel blood testing in the middle of them lying saying they had invented it. It's like, oh, how did you do it?

Speaker 2: Show us yours, and we'll show you ours. Show us yours.

Speaker 1: You wanna just, like, speed run some little news stories before the end? It's been a minute since we've chatty chat.

Speaker 2: Let's do it.

Speaker 1: Let's do it. I guess, first and foremost, dub dub, Apple w WDC just happened.

Speaker 2: Crazy. You

Speaker 1: got any thoughts on

Speaker 2: that one? God. It took them long enough. It would be my main thought. Is, as somebody that's been waiting for an iPad version of the Mac Book forever, like, I recently bought an iPad, Jordan knows this, because I wanted something to write notes on. That's literally the only reason I spent a grotesque amount of money because they are so expensive now. I could have bought another MacBook for this for less money than an iPad.

Speaker 1: Yeah. They're not cheap.

Speaker 2: The, I don't know if that's actually true, so don't hold me to it. But there it was so much money that I feel like I could have bought another laptop. The, yeah, it is just like, why did they not like, iOS is based in macOS. Like, they're the same core, essentially, different, like, UI kits. Yep. But, like, the new iPad UI kit is so similar to just macOS. And I imagine Liquid Glass, the new UI template

Speaker 1: file, but sure.

Speaker 2: Yeah. It's gonna come to macOS. Like, they're just gonna be the same. So, like, can we just make them the same?

Speaker 1: Never. Never. No. They will literally never do that. I love seeing window management. I love that they just gave us, like, a menu bar and the the the soft lights in the upper left hand corner. All great. I I love that. It will make things a lot more efficient. Finder and the horrible files app converging towards Finder is good. Mhmm. The the old ism, which is that you buy a Mac, you're buying a computer, you buy an iPad, you're buying a list of things you're allowed to do Totally. Still remains unfortunately true. Like, this episode will be edited inside of Logic, and I will use plugins that I am not able to use in the Logic for in the iPad version. It's like, well, until my core functionality of a computer is added to the list of things I'm allowed to do on an iPad, it can't become my my daily driver. But but we inch ever closer.

Speaker 2: My my new iPad Air has an m like, I can buy a MacBook Pro with the same, like, logical infrastructure as my iPad has in it. It's the same chips. Same chipset. Same everything. So, like, why can't I just run like, why can't I just choose to run macOS on it? Like, just let me.

Speaker 1: No. But what if instead what if instead we used all that processing power to run the bougiest animations on everything you've ever seen in your entire life?

Speaker 2: Yeah.

Speaker 1: We call it liquid glass, which I don't hate as much as some people, but I am assuming is gonna have to change so significantly before the actual launch in September because it is quite often completely unreadable. Yeah.

Speaker 2: Yeah. I if you wanna talk about UI design Sure. Yeah. I think it's cool. I think that usability wise is gonna be tricky, especially for accessibility. Mhmm. Is it so groundbreak? Like, is do Gaussian blurs and lens effects impress me? Like, they were in Photoshop two. It's like Yeah.

Speaker 1: Windows Vista is the thing everyone's acknowledging is that, like, you've done this, like, refractive light glass thing. It's like that's it's nice. It's fine.

Speaker 2: It's cool. The one thing, and you brought it up and you made tag to it, is that, like, the amount of processing and rendering power. People that I've seen running the dev version of iOS 26, I think is what it's called Yeah. Because they jumped 1923

Speaker 1: They're doing the car naming thing.

Speaker 2: Year thing. Yeah. Anybody that I've seen running it talks about how much detail is rendering into every UI piece. Like, the new finder app has, like, drop shadows and shadings and renderings and and yeah. Knowing that as a gamer, the first thing I do on Windows is turn all of that off so that my computer runs faster. Certainly. When I'm talking about a mobile device with a mobile device battery in it, running non mobile device chipsets, like, I'm in no rush to care that I'm gonna have beautiful gauzy and drop shadow blurs and blah blah blah. Yeah. I'm gonna care more about the fact that my iPad gets more than two hours of use before the battery dies.

Speaker 1: Yeah. The exactly. But don't worry. We're making a thinner phone at the expense of the size of the battery. It's gonna be a lot of fun. Yeah. That's interesting. The I was sitting there with a clicker. I didn't actually do this, but I was metaphorically sitting there with a clicker trying to count out every time they said the word Siri in the talk.

Speaker 2: Oh, really?

Speaker 1: Like, just in the back of my head. And I didn't watch every second of it, but I would guess maybe one time they brought it up. There was, like, a very fascinating talk about Apple intelligence and Siri without talking about Apple intelligence and Siri because we are in this little window of time where they have made a lot of promises they

Speaker 2: That

Speaker 1: Which is funny because there were there were stuff inside of this that is what the Apple intelligence announcement probably should have actually been. Really, really good transition translations Yeah. Using onboard LLMs. That's an great. Table stakes for a mobile operating system in 2025. Keep it coming. There was a lot of little quality of life things depending on, like, nice locally run LMs that you can tell the Apple story about privacy and on device, and it's your thing. All of that's great. But now it's in the shadow of this, like, Siri will be God, Apple intelligence will run your life for you story they told, like, nine months ago. And, they're sort of just, like, they painted themselves into a corner.

Speaker 2: Let's let's let's hang here for a sec because I am and I know a lot of other people who are, like, into AI. Like, and I will now say that I'm, like, into AI. Like, an Mhmm. AI guy. Apple is shockingly behind Oh, yes. For a company that has endless money.

Speaker 1: Yeah. Yeah. Yeah. Yeah. I know. It's like a problem. Like, it's like yeah. It's like the building's on fire. Like, it looks a little toasty in there. Like, yeah. I know. It's really bad.

Speaker 2: Siri has been around for so long. They have made like, and this is no not a knock on the Siri team. I'm sure they're doing things. But as a user Yes.

Speaker 1: It doesn't feel like Siri has improved

Speaker 2: since the first time I used it.

Speaker 1: No.

Speaker 2: Use Siri to turn on and off smart lights in my house, and that is it.

Speaker 1: And and Oh, and by the skin of its teeth, can

Speaker 2: it do it?

Speaker 1: Like, it's really rickety.

Speaker 2: And and that alone is, like, a a nightmarish scenario that it doesn't understand 90% of the time. Yes. And it's like and nowadays, we have, like, the Johnny Ives, which is not the right pronunciation of his name, moving to OpenAI, and they're talking about making a screenless AI device. And it's like there is there's good like, I can have a conversation with Grok. Mhmm. Who else has voice mode? OpenAI. Gemini has voice mode. Gemini's is great. Yeah. Yeah. Like, I can have conversations with these AIs that are doing deep research and, you know, retrieval augmented generation and all kinds of stuff in the background. And then I ask Siri to, like, turn off the lights in my office, and she's just like, I'm lights.

Speaker 1: And you're like, what? No. I don't wanna listen to some electropop. It's it's really not good. No. Here's my my theory. So in the in, dub dub this year, they also spent a bunch of time on Spotlight.

Speaker 2: Mhmm.

Speaker 1: They're like the Mac tool where you command space and you can search for files. And it's always been, like, very useful, but a little hack half baked through a bunch of secondary pieces of software like Raycast that, like, gave you a bunch of functionality. You can transfer to the shortcuts. Exactly.

Speaker 2: Of them.

Speaker 1: Yeah. And I would say some of them got Sherlock'd a little bit, which is to say Apple built their functionality.

Speaker 2: Exactly. Yep.

Speaker 1: Yep.

Speaker 2: If anybody doesn't know Spotlight was stolen from a third party not stolen. God. I'm gonna get myself into trouble in this episode. All of the functionality that's in Spotlight now, wasn't originally in Spotlight, and it was a third party app called Sherlock.

Speaker 1: And and which has since become a shorthand for this kind of thing happening. Anyway, there's all this functionality now built into Spotlight. Like, you can string together shortcuts. You can tell it to do pretty complex things, and it's it's a tag based system. It you need to activate the, like, little, like, I'm sending a message part of it. But in spotlight, you're like, oh, this is all of the hooks into this system in a little little a little text box. Not quite a natural language text box, but you're dangerously close to having a thing that is closer to what Siri should be in Spotlight than what Siri currently is. Mhmm.

Speaker 2: And

Speaker 1: so it's this question of if you build all of these hooks into the operating system, you get Spotlight to the point where it can almost use the computer for you. You've built a lot of the scaffolding of saying, now we're just gonna run a large language model on top of it that can connect through to those. And I would bet, an API that you can expose to other large language models that's like, here's the couple 100 hooks that we use to get into macOS. If you're approved, you can hook into these too, and people can say, you know what? Same as I use, Google Search as my default in Safari, I would like Gemini to be the default, voice conversation voice assistant. And, yes, I would like to give it permission to use my system for me.

Speaker 2: Yeah. Well, couple things to that. Yes. That API hook for other system is already done. OpenAI built, it's called MCP, model context protocol. And, essentially, all of the feature set that that has been exposed to Apple shortcuts and all the rest of those, all those, you know, application interactive, you know, functional ex exposures will all be bundled up in MCPs eventually. And not only will Apple's OS provide an MCP, but, like, each of those apps will have one. Like, there's a I love that. I can't remember you said it, but somebody recently said, like, if you're a SaaS company and you're not exposing yourself on MCPs for agentic use, then you will be replaced by a system that does.

Speaker 1: That does. Because that's how people are gonna be querying these systems. Correct. I think that's

Speaker 2: The next thing I'll tell you is I'm not sure what you use for web browsers, but one of the things that I found helpful is there's, like, this I can't remember exactly what it's called. Let me just pull up my settings here. But I'm using Firefox, and there's the ability to do, like, custom search engines. So you use, like, bang GPT or bang perp. Like so when you open up a new tab and you have, like, the Google search or, like, the search bar comes up, I started with, like, like, exclamation point GPT, and then anything I type gets sent to chat GPT 4.1. Anything that I type after bang perp goes to perplexity. Anything after bang grok goes to grok. And so it's, like, 90% of the time when I'm googling stuff now, I'll I'm using googling as a verb.

Speaker 1: Quotes. Yeah. Yeah. Yeah.

Speaker 2: I'm not even sending my questions to Google anymore. I'm going to one of the AI assistants. So it's bringing me back a summarized cited answer with exactly what I'm looking for rather than me having to spend ten minutes looking through pages looking for it.

Speaker 1: Which I think you bringing up connects through to my biggest argument for why Apple might not want to be territorial about the LLM natural language layer that lets people interact with the computer being theirs. Like, there's there's an argument to, like, yes. We have a lightweight LLM right on the phone privacy. Great. That's cool. People hate Siri, and they've been getting bruised up by that for years. So how much they wanna own that conversation layer is undecided, probably dependent on the quality of the model. But the bigger argument is that right now, Apple and Google are in this, like, tango of antitrust cases with the US government, European regulators around the world dependent on these questions, very old questions of how many billions of dollars is Google allowed to pay Apple in order to be the default search engine? How much money is a company allowed to pay before it becomes an antitrust issue? And going, you know what? You're right. We should never have been letting them pay all that money for search queries. Now the large language model layer, which no one can say there isn't a lot of competition for

Speaker 2: Totally.

Speaker 1: You can say that about Google search, but you can't say it about the LLM layer. That, we let tons of people give us billions of dollars to put that on the iPhone. And I'm like, that to me is a really, really good argument to build your system in such a way that if people like talking to Gemini, you can let them control the iPhone with Gemini. Yeah. It sounds very unappily, but it seems like all of the signals are pointing in that direction.

Speaker 2: Yeah. I'm not an Android user, but know a lot of people that are. And, my brother got a new phone at Christmas and had it, and it came with Gemini Pro. And it was still 1.5 Pro at that point, I think. I don't think 2.5 is out. And it's no longer Pro. They've dropped the Pro, just so you know. Yeah. It's now just 2.5. But the

Speaker 1: Google changed the name and the thing and made it confusing in the process.

Speaker 2: Exactly. Exactly. Shocker. But he he'd, like, never really used it. And I was just, like, we would be sitting having a conversation about something, and I'd be, like, just ask Gemini. And he just, like, got into the habit of being, like Yeah. What percentage of vote blah blah blah. Like, any question you have,

Speaker 1: and boom. Talk to your computer.

Speaker 2: Yeah. Talk to it. It's just puking out cited answers, and you're just like, there there's the answer. Like, we could have sat here and argued about it for forty five minutes. Now we have the answer.

Speaker 1: Yours can do that now. Yeah. Yeah. I think that's gonna be that spotlight, I'm very excited as an iPad user for window management in 2025 on my thousand dollar computer. Mind blowing concept. Yeah. But I think the actual future of all this stuff was hidden in that little spotlight demo where it's like, oh, you can you can kinda talk to it a little bit. Oh, you can have it string together shortcuts things recurrently almost like a little as oh, like, there's a lot of functionality hidden in that, like, five minutes of the demo.

Speaker 2: So he I'm just gonna go back in time here. I'm not even sure if this was on the episode or just in a passing conversation that maybe you and myself or maybe me and a friend of the pod, Matthew Satchel, had had or Matthias, the art director who did our art for the show, is I made that same argument when Siri came out originally. I was like, they have all these hooks. They just need to expose it to Siri. They need to do all this stuff. They just need to, like they they're building the ecosystem. It's gonna be good. That was ten years ago. It's still not good. Like, it has those hooks. Siri has those hooks. I'm just hoping they get a reasonable voice model to to run Siri.

Speaker 1: I think Spotlight shows that they're panic building the hooks in the background. Yeah. And it's just how they go about exposing them to those those LLMs because Siri was always a non LLM based conversation. Like,

Speaker 2: okay. Well, that sucks.

Speaker 1: We know that sucks. We know this rips. Just put it all together, guys. Like, you have all the parts for this to be good.

Speaker 2: I watched, I did watch I actually didn't watch dub dub the whole thing, but I watched some like, I saw the pieces that made sense that I care about.

Speaker 1: Highlight reel.

Speaker 2: Yeah. Yeah. And, but I did watch the Apple AI MLX MLX? Yeah. The MLX presentation of, like, their entire Apple LLM kit.

Speaker 1: K.

Speaker 2: And they've built an entire infrastructure. Like like, the anyway, that's not into AI, like, running running yeah. Running DeepSeeker one, which is a free open source model provided to us by our friends in China, requires, like, a supercomputer. Like, to run it efficiently, you need, like, 470 gigabytes of VRAM. So if you were to buy NVIDIA chips and NVIDIA cards at the time to do that, like, not even the consumer ones like we have in our PCs, but, like, you'd be, like, 6 figures ish close to.

Speaker 1: Yeah. Sure. You can

Speaker 2: buy a $10,000 US Mac Studio m three that has 512 gigs of unified memory running at an insanely high memory bandwidth speed of, like, 871 gigs a second. And you can put DeepSeeker one on there and run it essentially at a functional speed. So for $10 Yeah. Apple has built hardware that is like like, that m three Ultra Studio with 512 gigs of memory is built for nobody besides AI people. Right. Like, there's nobody else needs five. Like, it doesn't matter what kind of rendering you're doing or anything. Like, you're you don't need that kind of VRAM and

Speaker 1: You haven't seen these liquid glass textures yet.

Speaker 2: It's got that's true. We all need an m three studio to run our OS.

Speaker 1: No. I take your point, though. Yeah.

Speaker 2: But but, anyway, the the MLX, like, they're they're the Apple AI stuff is actually pretty cool, and they're actually doing some pretty cool stuff. And they're exposing a lot of abilities to make it really easy for people to, like, fine tune models. So, like, low rank adapters, create low rank adapters, which if you don't know what that is, is like a custom trained model that gets attached to the other model to change some of the weightings. Take DeepSeek r one and feed it, like, 10,000 examples of our customer service tickets.

Speaker 1: Sure.

Speaker 2: And it'll create a little adapter, a little model, you know, augmentation that we glue to the r one. And then all of a sudden, we have this, like, customer service model that's been custom trained to deal with our customer service. And they're they're really starting to build for that future where enterprises are looking to internally leverage AI. I think more so than, you know, you're seeing with the Googles and the OpenAI is where they're building to service the market, the generalist market rather than building, you know, siloed custom solutions internally, which I think Apple's kind of isolated off and said this could be a big thing. And I kind of agree with them.

Speaker 1: Yeah. I mean, they're in an interesting position. Like, Google's operating system is a web browser. Like, they're they're just they go after like, they they do developer conferences, and they have platforms. And, hey, maybe AR will be the future. I don't know.

Speaker 2: X x r, Jordan.

Speaker 1: X r. My apologies. My apologies. Yeah. But it's just a fundamentally different company. Like, their hardware like, what is their hardware for developers? Like, it's it's just not this they're not analogous to one another, which is what makes the fact that they're in some ways ahead so fascinating. But it does speak to what Apple could kind of rush in from the rear on, which is that kind of stuff.

Speaker 2: Totally. And and, again, like, the couple things I wanna talk about there. But, the first is change takes time, especially the bigger an organization. Right? Like, if you're if you're a one person shop, if you're an independent consultant to small business, it's just one person. You can change and you can pivot quickly. If you're a 60,000 person logistics company, like like, the change The

Speaker 1: ships move slowly.

Speaker 2: Exactly. And and so so it's like there's gonna be two different models working there, and they're gonna be competing a bit. Like, you're seeing that with, like, AI startups. Like, there's so many of them coming online so fast. A, because AI is facilitating their development, their research, their planning, their everything. You can just move at a pace that's unprecedented. As a small team, next, it's like big, big companies are just looking at marginal gains, marginal shifts. Like if you're delivering natural gas to the households of North America to keep their houses warm in the winter, it's like, you know, you're you can't move as quick because of stricter security, risk liabilities, etcetera, etcetera. So it's like, yeah, it's gonna be it's gonna be a fascinating decade. Like, by 2030, it's gonna be fascinating. Second thing I wanna talk about there was how badly I want a pair of AR glasses her XR glasses.

Speaker 1: Really? Mhmm.

Speaker 2: You're in. I'm in. Do you want the

Speaker 1: now to clarify, XR as in the current generation of functionally VR glasses with pass through of video, or do you want to go over to the other side, which is the glasses with the teeny tiny non mapped hood? Like, which side of that do you think is I'm talking useful in 2025?

Speaker 2: I'm talking the Google XR prototypes bands, but with screens in your eyes. They are they are literally the contact lenses from my dystopian graphics. They have cameras. They have microphone.

Speaker 1: About that because we got an email unpublished because I think some people went looking for that.

Speaker 2: Oh, really? Yeah. Unpublished. I just wrote it as a hobby as, like, a probably project. I should publish it now. But the, it'd be maybe a little too real to publish now. Anyway, they have microphones. They have cameras. They have everything. Like, if you haven't seen the demo of them, you should watch it. Like, somebody wearing them will, like, look at a bookcase and be, like, like, just briefly glance their eyes past a bookcase and then be, like, hey, Gemini. Do I have a book on, you know, UI design? And they'll be like, yes. The third book on the second shelf. Yep. It's like, okay.

Speaker 1: Yeah. It reminded me I saw that tech demo. It's very similar to the Orion AR tech demo that Facebook did eight or nine months ago, whereas, like, you managed to get actual Heads up. The heads up display tracked into a pair of what kind of look like normal glasses, chunky, but like a pair of glasses with a heads up display mapping real world content mapping content into the real world. And, you know, pick your poison a little bit, but I'm sure more likely to use one created by Google and more likely, I would say, to get value from the software provided by Google. That's just my personal experience. I'm not a big meta product person.

Speaker 2: Yeah. Me either.

Speaker 1: I don't love having it in my pocket. I'm very disinclined to put it on my face. And for however much that's

Speaker 2: still my life.

Speaker 1: And for however much that's still true about Google, it is, I would say, just for me personally, less true. Like, I'm more likely to wanna pop a pair of those on. Mhmm. Yeah. I'm intrigued by that. I'm curious when that's gonna get to consumers because I've I've heard that while that that's a mass production issue. That, like, you it's like, yes. We can do it. It. We can make 11 of these, and they're incredible. And it's like, amazing. Can you make 7,000? They're like, no. Yeah. It's like, okay. We'll come back when you can do that because I'll give you money. Like, I would genuinely like a pair of cool glasses that can talk to me and see the world. That sounds kinda neat.

Speaker 2: That as somebody who liked the first iPad, I remember, like, Steve Jobs, you know, his classic speech sitting on stage, and he's like, it's really powerful to hold the power of the Internet in your hands. I can't remember his exact words, but he was like, this is like a it feels monumental. Mhmm. And I feel like glasses like that, if built very well Exactly. Functioning very well, will feel like that. It will be like, oh my god. Like, I am the the technology and life are interwoven now rather than, like, two separate silos. Like, I go use technology in my life, but, like, now they're

Speaker 1: Yep.

Speaker 2: They're together. And that's gonna be it's gonna be a cool thing. It might be scary, and it might lead us to seeing ads on literally everything. But Sure. Which is another thing cool to talk about. I know we should probably wrap this up because we're just, like, shooting it now. But Yeah. All good. There's been a lot of conversations about what a post Google search world looks like for advertising. Sure. Like, if perplexity Gemini I'm just literally looking at all of the bookmarks on my Of course. Gemini, OpenAI, Grok, Cloud, Perplexity are all feeding me the answers. I'm never going to web pages to find them.

Speaker 1: No.

Speaker 2: And Google searches like, so much of Google's revenue is associated to their ad side. And, like, what does the world look like when it's not serving those ads anymore? There's no value to them. Nobody's looking at those ads. And

Speaker 1: I would agree. And I'd say it brings up an even larger question of, like, well, ads are the financial engine of the Internet, and you could just scale that question up like, well, what even really happens to the Internet at that point? Like, for the last fifteen years, we've been living in an economic situation where Google makes, and I'm gonna round some numbers here, a buck for every penny that Conde Nast or the New York Times or any one of the actual creators of this content tend to make off of advertising. Mhmm. They they monetized the new Internet, which is now the old Internet, better than anybody else, and they became one of the largest companies on the planet as a result. If you were no longer driving any traffic anywhere and you're just querying information from a database that was previously barely financially viable due to advertising, and there's now no eyeballs to see the advertising, what is the economic model that makes any of the content produced on the Internet viable.

Speaker 2: Mhmm.

Speaker 1: That to me is completely unclear. If you were in the text business, I'm like, oh, I I just don't know how that's gonna work for you. It barely works now. This won't improve that at all.

Speaker 2: My my gut response to that is and that there's an interesting I heard this on a podcast the other day, and they were talking about how AI is creating two types of people. Mhmm. Hyperconsumers of content and hyper producers of content. Right. And I think that's just that's only gonna get bigger and bigger as I'm trying to figure out the nice way to say this. Crossing my fingers and and hoping that AI leads to a life where we're not as busy, for lack of better words, where, like, we see economic efficiency growth substantially while not requiring human output to go up in equivalency, if that makes sense. Like, you know, so much and I talk about this in somewhere that will become public at some point. The technological revolution obviously grew us, grew our economic efficiency as it facilitated us to work better, faster, and harder, but it came at the cost of, like, me having a pager, a Blackberry, an email. There's an expectation that every time something gets done, I get a message, I get a notification, I have to respond to it. I'm hoping that AI is the disconnect for that, where now all of a sudden it's like, we can grow our economic efficiency, but we can steal a bit more of our life back. I can disconnect and still be a productive member of society, etcetera, etcetera. Like and so, I forgot where I was going with this.

Speaker 1: Yeah. We were talking about the scale of production of the information Oh, yes.

Speaker 2: Yes. Yes.

Speaker 1: Versus the consumption of

Speaker 2: them. So what do people do in their spare time? They consume or produce content. Mhmm. And it's like, I think I think that the monetization of content is only gonna get bigger and bigger.

Speaker 1: My worry is that when it's, like, literally a commodity at the scale that it's at, it's like, what were the deals that Reddit did? And I'm just thinking of, like, an individual creator could theoretically make enough money to live by putting ads on a really popular blog. Sure. Reddit can command a deal for Anthropic or Perplexity or any of these companies, but they need to be producing, like like, what, like, 3,000,000 tokens of AI parsable information a day? Like, it's like, no. It's literally a commodity. Think of bales. Think of giant, like, shipping containers worth of human output.

Speaker 2: Mhmm.

Speaker 1: That's what's valuable to these systems. Unless right now. Unless we start going like, no. If you have the the the actual answer to a human query, that's valued in a different way. That's not we're not the little bit of language that we're using to feed into the system is like, no. You can't monetize that the same way as that. Problem. Or no one will produce those answers, and the answers, and the Internet will stop being useful. It'll have to start making stuff up. There it you you need to find a way to make the answer creation process monetizable on the Internet, or you won't have answers.

Speaker 2: Yes. But I guess, to to route back, I think that you're gonna see, like, just to speak to the content that I'm talking about, like, hyperproduction of content is, like, people like, let's talk more about the Spotify deal with Joe Rogan. Sure. Like, I think we're gonna see more of that stuff. Big influencers, big content creators Sure. People A

Speaker 1: different kind of content Yeah.

Speaker 2: And a different relationship. Of that is gonna be, I think, maybe one of the big buy byproducts of that. So it's, like, figuring out I agree

Speaker 1: with that.

Speaker 2: How to put ads and content and product in front of people who are consuming content. And I think that that's that's I think, truthfully, and this is gonna sound weird and dystopian, but, like, the Twitches of the world, the, YouTubes, like, those are the things that are gonna get more and more valuable. As humans have less to do due to AI, they will consume more because idle hands are the devil's playground.

Speaker 1: I I think you're getting to the maybe the heart of it, which is the, like, how many websites haven't I clicked on because the Google automated response was serviceable? Probably quite a few. Just human nature. The answer is right there. I read it. I don't need to continue on. How many songs written by AI have I listened to on Spotify? None. How many books written by Aya have I read recreationally? A book takes six hours to read. None. Information is a commodity is the value of that will be driven down, but the value of authorship and our relation to authors, creators, video, audio, whatever it

Speaker 2: is Perspective. Country.

Speaker 1: That remains valuable for the economics of how it will be created will change

Speaker 2: Mhmm.

Speaker 1: And the labor behind that will change. But as of right now, the thing I keep coming back to when it's like humans will need to do truly nothing, there's nothing you can't do better, it's like, what's your favorite song written by one?

Speaker 2: Yeah.

Speaker 1: Because I can I can list 50 songs that have, like, mattered to me so much, and not one of them was written by AI? And I would guess that that list will remain entirely human authored because that's what's valuable about it is my relationship to the author.

Speaker 2: To totally. I I I think that AI can't do doesn't understand human emotion. I think it understands it from a clinical perspective, but, yeah, but it but it doesn't understand it. So it will never have that same connection. Like, the but but the thing is for me is that the like, we're already living in a world where where major influencers are essentially full grade a celebrities. Like, you know, like, they're they're like, it used to be micro celebrity. We joked about it for decades. It's like, oh, yeah. Yeah. Macro. And, yeah, now it's full blown macro. Like, if you're a if you're a top 10 streamer, like, other celebrities wanna meet you and things like like, you know what I'm saying? Like, they they they they

Speaker 1: they wanna come on the stream. They wanna come on the pod. They wanna come on the show.

Speaker 2: So so my perspective entertainment is gonna become the new platform for marketing. And it has always been a platform for marketing, but I think that it's gonna become the biggest platform for marketing.

Speaker 1: Interesting. I'm curious what people are gonna feel about the thirty minute appended because we we've tried doing chatty chat episodes. We've done very structured stuff. This had, like, a night a story, then another story, and then what I thought was gonna be five minutes of talking about dub dub, and you just got, like, I'm curious. I hope I hope y'all like it. It was quite fun to do.

Speaker 2: We used to make this thing called well, the we used to make this thing called hacked after dark. And this essentially felt like a hacked after dark because it's like Jordan and I usually sit on these calls after we make the episode and before we make the episode and talk about this stuff. So maybe we just leave the mics on

Speaker 1: and the cameras on and just Honestly, if you like this, let us know because we could just keep doing this and and keep all the the chatty chat as, like, a nice little vestigial thing hanging off the end of the episode, which was, of course, brought to you by Push Security

Speaker 2: Absolutely.

Speaker 1: As always. Very fun. I think without any further ado, we'll catch you in

Speaker 2: the next one. Take care.