episode.ascii — live render
● episode

$10 Million in Fake AI Royalties + the ‘Infinite Money Glitch’ That’s Just Fraud + Voter Outreach So Bad It Seemed Like Phishing

TL;DRMichael Smith, a North Carolina music producer, was charged with wire fraud and money laundering for using AI-generated music and a network of bots to fake 4 billion streams, stealing over $10M in royalties from Spotify, Apple Music, and…

In which we discuss alleged Spotify streaming ad fraud that brought in millions, extremely poor voter outreach and an extended tangent on AI.

Correction: we failed to make the "Ramen Empire" joke. Our apologies.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: According to charges from the Southern District Of New York, in October 2017, Michael Smith sent himself an email where he laid out the napkin math of his alleged let's call it StreamingAI Music Botnet Fraud Enterprise. The email lays out the following. Using 52 cloud service accounts, each running the max number of 20 bots capable of clicking on and streaming a song on a platform like Apple Music, Spotify, YouTube, he could run a network of a little over a thousand autonomous music streaming bots. Each of those thousand or so bots could stream 636 songs per day, producing a theoretical 661,440 streams. Smith estimated that the average royalty rate per stream was half of 1¢, which would have meant daily royalty rates of about $3,300 and monthly royalties of just over 99,000. Totaling, to quote the charges in the indictment, annual royalties of 1,207,128 US dollars. That was his alleged business plan, Scott.

Speaker 2: This is fantastic.

Speaker 1: The charges unsealed this week paint a picture of what happened in the seven years since. And honestly, Michael's math, pretty good. By 2019, two years into the scheme, he was allegedly earning $110,000 per month, of which he shared 10% of his earnings with his co conspirators, who we'll get into this, puts him pretty close to those original projections. Earning him, over this seven year period, over $12,000,000 in royalties for 4,000,000,000 fake music streams.

Speaker 2: So he became like a billboard charting artist for one of his bands, which include the names Callus Post and Calorie Street no. Sorry. Calorie Screams.

Speaker 1: You don't you don't have Calorie Streams on regular rotation?

Speaker 2: Screams. Calorie Screams. I messed it up. You shouldn't. Yeah. No. Zygote washstands. Zygote washstands is one of my favorite tracks for sure. You know, it's always playing in my kitchen.

Speaker 1: It's my morning alarm clock. The answer of where you would get all this music today is is obviously AI. But in 2017, that was much less obvious, and these tools were far less common, which is what makes this alleged coconspirators all the more interesting. For this alleged scheme of using AI to produce what the indictment says he called instant music and a botnet to stream these songs en masse to commit royalties fraud, Michael was charged with variations on wire fraud and money laundering conspiracy. It is the first US criminal case involving artificially inflated music streaming fraud, and that's without even getting into the whole AI part. So we've got to talk about it. On this episode of Hacked, we're talking about the charges against Michael Smith. We've got voter outreach so bad people thought it was phishing, and they've got doom running on stable diffusion, which is nuts. All that and more on this episode of Hacked. Okay.

Speaker 2: Patrons?

Speaker 1: Yeah. We haven't done patrons in forever. We should talk about our patrons. Mhmm. Best patrons on the Internet, hackpodcast.com.

Speaker 2: Best patrons on the Internet. Like

Speaker 1: Like.

Speaker 2: Benno Oberleeson. Thank you, Benno.

Speaker 1: Benno Oberleeson. Thank you. Luke Schneider. Thank you so much.

Speaker 2: Yeah. Thanks, Luke. Adam Pickard or Picard. Probably Pickard. Thanks, Adam.

Speaker 1: Bob Evans means a lot.

Speaker 2: Bob Evans. Charles? Just Charles.

Speaker 1: Just Charles.

Speaker 2: Thank you.

Speaker 1: Charles in charge. Almost as much as Lauren Forlorn, we appreciate it. Lauren Lauren the Forlorn. Again.

Speaker 2: The Ramen Queen. That's also very good. This is the name, Ramen Queen. I also love ramen. I would love to consider myself maybe like a ramen prince, but you are the queen. So thank you, Ramen Queen.

Speaker 1: Someday you will usurp the ram ramen throne. Caboose. Thank you so much, Caboose. Really appreciate it.

Speaker 2: Listen. The ramen I don't wanna call it a kingdom. The ramen, it it's it's a matriarchy, Jordan. The ramen queen is the head of the ramen societal

Speaker 1: She rules with an iron fist.

Speaker 2: Caboose. Caboose, thank you so much. And Nicole. Nicole, thanks thanks for everything.

Speaker 1: Hunter Kinney means a lot.

Speaker 2: Jared Calendar? Cal calendar? Calendar, I think. Jared Calendar. Thank you so much.

Speaker 1: Really happy this one fell fell to me. Thank you so much. Boof it. Boof it.

Speaker 2: Well, I'm also happy this one fell to me. Colonel Mustard. Thank you, Colonel Mustard. And

Speaker 1: last but certainly not least, Andrew Johnson. Thank you much for your support so much for your support. It all means the world to us. Keeps this thing turning. If you wanna support

Speaker 3: the show, hackpodcast.com, kick it

Speaker 1: on over there for now. It redirects to our Patreon. It should probably redirect to a website at some point, but for now, you can get to our Patreon by going hackpodcast.com and support the show. The show that we're making now, talking about tech stuff.

Speaker 2: And thanks to all the audience members for sitting through that as Jordan and I went to the list of patrons, and it took way longer than it should have and way more, you know, banter than it probably needs. But we appreciate you all. Thanks for coming.

Speaker 1: I'm not a listen to podcast on 1.5 speed person, but if people want to briefly listen to the podcast on 1.5 speed before slowing back down to the one true speed of one x, I don't have a problem with that personally during the Patreon section.

Speaker 2: Well, I love and value our patrons, and I think that they should get a point seven five speed read, which is why we take such a long time to read them and make funny jokes about their names because we love them. I like that. We love them like family, and family gets made fun of.

Speaker 1: Point seven five being the, like, no. You really need to savor this part of the show. You gotta slow it down. You really I like that. That's good. Okay. I take it back. One x speed bare minimum. We got a lot to get into in this one, Scott. Where should we start?

Speaker 2: Let's start with the fact that it looks like we got a lot of AI stuff to talk about. Like, I think a few of these stories are all AI based, and AI is, like, just a part of our daily news these days. It seems like AI is everywhere. Everybody's talking about it, and investors are hot and bothered by it. Some people think it's a big sham. So it's it's a it's a point of discussion. I was just yesterday talking about, AI with somebody in the office who says that they think it's overblown. Apple yesterday released their new iPhones, which are AI powered, and that apparently hasn't landed like people thought it was going to. But, but I think we're gonna talk about some AI and a few other things.

Speaker 1: Yeah. And this one's a little bit of a an AI throwback story. It's also much more of like a what you can get up to with a botnet and a little bit of gumption kind of story, because while there is AI in this story, it damn near could have been white noise as far as I can tell, but we'll get into that. So Michael Smith, 52 years old, a music producer from Cornelius, North Carolina has been charged with wire fraud, conspiracy, wire fraud, conspiracy, and money laundering conspiracy. These charges are always weird. Smith allegedly defrauded a bunch of big music streaming platforms, Spotify, Apple Music, Amazon Music, YouTube Music, out of more than $10,000,000 in royalties through this very elaborate scheme involving AI generated music and automated bot accounts. It is the first US criminal case involving artificially inflated music streaming fraud. It's a very fascinating one. What do you think about this one, Scott?

Speaker 2: It's it's interesting, mostly given the time period, like 2017. So we're not like the AI generated music back then. I'm not entirely sure what that looked and sounded like. I assume it was just downloaded midi run through, you know, logic with some plugins. I assume maybe, like, you wrote an algorithm to randomly generate midi notes. Anyway, I've been theorized on that for a while, but there's no point. No.

Speaker 1: It's interesting.

Speaker 2: And then literally just illegally streaming it, but, like and that that that is the point that I think is the most interesting because in 2017, you know, we're we're just seeing the botnet havoc that runs its course on ad networks, that runs its course on streaming sites. Like, in today's day, like, view botting is, like, a big part of the streamer culture. It's like, you know, you'll get streamers that blow up and all of a sudden they have 6,000 people watching them, you know, live, but 20 people are talking in the chat. And it's like, okay. Well, like, how many of these accounts that are viewing you are lurkers? Or how many of these accounts are actual, like, bots just like that you've paid for to increase your numbers and increase your profile and things like that? So, yeah, like, this is right in that window of, like, hey. We can game these algos. This game just comes with a paycheck where most games come with a clout and notoriety, which then comes with a paycheck where this is just direct fraud. The other people are committing, like, second generation fraud.

Speaker 1: Mhmm. Yeah. Assuming this all played out the way the charges outlined them, it is one of the most long standing bot fraud things I've ever heard of. It it ran for such a long time, and it didn't really feel like it was in service of building one, call it, creator's brand. It was really just about using a mass of different artist profiles, each producing their own songs, just to try and generate revenue. It wasn't really about building one figure up. It was about building a big fat pile of royalty payments. Yeah. And to get into the where did the music come from of it all? I think that's sort of what's maybe one of the more interesting things about this. As we talked about in the intro of the story, in 2017, he sends that email to himself breaking down the economics of this. But in, like, 2018, I think, give or take, we start to see some of the other characters in this story, two other co conspirators. There's a a music promoter who is maybe the least interesting part of all this. So they were unnamed in the indictment, but they were code named cc three in the paperwork, and cc three refers to a unnamed AI music CEO, who was one of the people splitting sort of like a little bit of the revenue from this, thing and is named as a co conspirator, which means that back in twenty seventeen, twenty eighteen, Smith allegedly got a hold of someone who was in that early AI music generation space and had them start generating what he referred to in these emails as instant music. The the person this sort of co conspirator joked in an email, keep in mind what we're doing musically here is not music. It's, quote, instant music, winky emoji. So it seems to be, like, a pretty good sense that what they're creating isn't real music a person would listen to, but it does check all the boxes for a royalty generating Spotify stream.

Speaker 2: Mhmm. I I there's a there's an this is entirely hypothetical, but there's a part of me that wonders if this AI music generation CEO wasn't passively funding his startup through royalties fraud.

Speaker 1: Sure.

Speaker 2: And there's there's a comical dark dark comedy part of me that's like, and wouldn't it be funny when Google then buys his music AI startup for, like, $2,000,000,000? So it's like, well, actually, Google has been funding it the whole time. So

Speaker 1: Yeah. Sure. Somewhere there's, like, a VC pitch deck being, like, our AI generated music from artists like Zygotic Wash Stand and Callus Post have generated millions in revenue in what is now being revealed as just, royalties fraud. Yeah. I I could see that maybe having shaken out that way.

Speaker 2: I think there's also an interesting economic philosophical conversation here about, like, if you build an AI that's capable of creating something that traditionally artists have received royalties for

Speaker 1: Mhmm.

Speaker 2: Will your AI be have rights to royalties? Like, if we write a music generation AI that generates pop music at the level of Taylor Swift and Justin Bieber, does our AI then receive, like, millions of dollars in royalties and billions of dollars in licensing rights? And, like

Speaker 1: Yeah. Sure.

Speaker 2: What does that future look like? Like, is there gonna be a race between AI developers to create, you know, what is the new pop?

Speaker 1: Yeah. There are two distinct but overlapping ethical and philosophical questions here. One of which is, I think, a lot more cut and dry, and it's the fact that no one was listening to this music, these thousands of different accounts, different artists that Smith was allegedly constructing weren't being listened to by human beings. They were being listened to, allegedly, by a botnet of his own design. He was signing up for bulk email accounts through vendors that sold them as packages, using those to sign up for these botnet accounts and just sort of creating a little house of cards that way. There were no humans consuming this content. So in a very, very brass tacks sense, that's where the fraud took place. It was botnet. It was bot fraud against streaming platforms.

Speaker 2: For sure. And we've seen this with clients of ours. When you buy third party advertising and all of a sudden all your traffic's coming from one server in Florida, and you're like, what's going on? Exactly. The Exactly. The though we see this all the time, it's just, I guess, my question was more like, in a hypothetical sense, what's gonna happen?

Speaker 1: Totally. Yeah. That and that to me is the second philosophical question is what if people just start listening to content created by an AI company like this one that allegedly worked with Smith? That's a different, much weirder question. And who who earned the royalties? The people that made the model or the person that commissioned the AI music?

Speaker 2: Well, if Twitter or X, and even some Instagram like, there are famous Instagram models now that are just AI generated. And it's like, like, how how does the world change when our micro celebrities, I guess, for lack of better terms, are just

Speaker 1: Mhmm.

Speaker 2: Manifestations of a robot?

Speaker 1: The, so there's this thing called the mechanical licensing collective, which is a fantastic name. They're the sort of international body that oversees royalty payments. And they were one of the first groups that got on to this question of who is this Michael Smith, and is this real music, and are much more importantly, are these real, listeners? There's this fascinating thing in the charge of sort of this timeline of accusations and responses. And for a long time, the MLC had been gun questioning some of Smith's activities, raising doubts about how we could be generating so much music so quickly without using AI and based maybe I would this is conjecture, but on the quality of that music, whether or not, the people listening to it were actually listening to it. He said some variation on, we have clearly demonstrated that Mike Smith's works are not AI generated, but rather they're human authored. This was the sort of music promoters defense against this. MLC started withholding royalty payments after identifying suspicious behavior. They played a pretty big role in turning this from a question into an investigation. Smith starts getting confronted by the streaming platforms in about 2018, 2019 about the weird kind of streaming patterns. And in response to a 2019 accusation of streaming fraud from one of those platforms, Smith denied wrongdoing stating I have never done anything to artificially inflate my streams. It's a very fascinating story. It paints a picture of a person that was, at some point, trying to create music themselves and generate an income as an artist who then tried to scale that, by fraudulently the generation wasn't necessarily fraudulent by allegedly fraudulently, having bots consume content that he was creating, and then later that an AI was creating with the help of this c c three, unnamed CEO of an AI music company.

Speaker 2: Fascinating.

Speaker 1: Yeah. It's an interesting one.

Speaker 2: Fascinating.

Speaker 1: It's quite an operation, and quite a profitable one.

Speaker 2: I feel like every time I go on YouTube these days, I'm being told to make fake ebooks and put them on the Amazon Kindle for what I can only imagine is, like, the the 2024 version of this scam. So it's just so I get it.

Speaker 3: Like,

Speaker 2: I see how people get here. You know? No. Nobody likes the thing is this isn't even free money. Like, these people had to work for it. You know, they're Oh,

Speaker 1: this was a lot of work.

Speaker 2: Creating AIs to create music. They're creating bots to to, like, farm impressions on it. I don't yeah. It just seems like a lot of wasted utility that but maybe they learn something in the process, and maybe that those learnings will be imparted on the next generations of music generating AIs.

Speaker 1: So I I think wasted utility is a really good way of putting it, and it's the think thing I think every single time I see one of these schemes of, like, with this new tool, you could theoretically game system x. And it's like it to me, it all it goes all the way back to, like, when I first started learning about drop shipping. It's like, you know, you could make money by manipulating the slot machine that is the Facebook ad marketplace. Like, yeah. There's a lot of bad ways to spend my time that theoretically could generate revenue, but I don't wanna do that. That isn't a useful or interesting use of my time. And it feels like with each one of these little technological waves we go through, first chat g p t, hey. You can generate Kindle spam and try and juice some money out of that. Hey. You can generate Spotify spam and juice some money out of that. I'm just reminded of of that over and over and over again. I don't really have a problem with anyone wanting to make some music quickly with an AI for, like, personal consumption or a meme or a joke or sharing with someone. But when you try and, like, gamify it into a business, without even getting into the ethical side of things, it just seems like a silly use of a human being's time.

Speaker 2: Yeah. Well, this goes back right to our first, you know, years ago, our first discussion about chat g p t when it came out, and I was just and we were talking about how with referral, you know, marketing, there's so much garbage on the Internet that finding anything truthful is impossible these days. And Sure. ChatGPT is just gonna facilitate the shit out of that because it's like, hey. We wanna make an entire fake review site that fake review reviews blenders. It's, like, great. Like, ChatGPT will generate us 18 blender reviews in forty five minutes or forty five seconds, and then we'll just throw this up as garbage content. And then and then Sure. ChatGPT's learning agent will come by and scrape our garbage content and feed it back into their matrix

Speaker 1: Into itself. Right? The thing that k. Before we get into the Internet is becoming great group thing, if convicted, Smith could face up to twenty years in prison for each count. It's a fascinating story. We're gonna be following it. To finish the thought that you were, having there, whenever I hear about those types of projects of people clearly just scraping human authored content to recycle and repost and hopefully, again, game now the Google AdWords system of trying to juice a little bit of ad revenue out of it, I'm disappointed. When I hear people talk about that as a potential road for, like, journalism and content to go down, I am frustrated because to me, it represents such a fundamental misunderstanding of where places the writers of that content get it from. They can go out and do reporting. They can ask questions of primary sources. They can figure out what happened and tell you about it, or the information is released to the press in the form of a press release. ChatGPT cannot do the former. So the only news you would get by an AI powered news ecosystem is the latter. It is that which is released to the press bot for it to digest and rewrite and publish on the Internet. So if you're comfortable with the only information you get out of a journalism ecosystem being that which is released publicly to you, if you're fine just being sort of publicitied at by robots, that's what you're gonna get out of that system. But if you wanna know things that require people to ask questions and follow leads and do reporting in its current state and for the foreseeable future, these tools are not capable of that.

Speaker 4: Mhmm.

Speaker 1: That is my little rant.

Speaker 2: I I I I like your rant. The I kinda just wanna have an AI conversation now because I've it seems like something that everybody's talking about. It's becoming like a thing. Like, this is a chatty chat. Let's chatty chat it.

Speaker 1: Do

Speaker 2: you think it's overblown? There's a lot of people out there nowadays that think that AI is is gotten too much hype, that it's too hyped up. It's not good enough. It's not doing things perfectly. What are your thoughts? What's your take on this? I'll give you my take after yours.

Speaker 1: Yeah. For sure. I would say I this is a frustrating answer. I would require clarity about what is meant by the statement overhype. Do I think that the current generation of generative AIs is a stone's throw from AGI? No. I don't think that that's how this is going to work. I don't think that if you just a little bit more progress, we're gonna get to AGI with these tools. No. I don't think that's where this is going. I think we're still a long way out from that. Do I think that the utility of these tools is overhyped? Not really. In that for every instance of overhype of what they can do, there is a discovery of a thing that wasn't being talked about that they can do. And those two forces sort of balance out to me

Speaker 2: Mhmm.

Speaker 1: That for everyone saying, you could run a whole news website using this, my previous point still stands. But then someone will figure out that they can, I don't know, for example, emulate doom and stable diffusion, which was on no one's radar? So for every overhyped thing, there is an unexpected thing. And I think that that sort of lurching progress is the stage that we're in right now. And as such, I would say that hype is and I'm not talking in a business sense in, like, a investor culture. Yeah. There's there's way too much hype. But just in a as we understand this technology sense, I'm not too worried about the hype. How about you?

Speaker 2: Kinda the same. The one of the things that I'm noticing is that there's a lot of talk about it being overblown and a lot of talk about it, you know, from people who I don't think use it. Because if you use and get fluid with it, if if chat GPT and generative AI becomes part of your process, my god, does it make you more efficient and effective? And I say that from like a drafting documents, writing code. Like I was having a conversation the other day with a lawyer who feeds it all of the depositions and and things like this from his case. And then he will and then he queries he's like here put all this stuff in your memory and then he asked it questions like in all of the interviews are there any inconsistencies between the things stated and it will pump out a list of inconsistencies like something that would have taken him hours or them hours to do this robots doing in in seconds and and the same goes for programming like I was responding being like, you know, when I write code generative AI, assuming it knows the language, which it usually does, can is the best junior programmer I've ever seen. It writes better code that handles more cases and exceptions states than like most non senior engineers do and It's like and it does it in seconds like it it isn't smart enough to be like here's a problem solve it But it's like I've created the solution you create me the components that make up that solution and it's damn good at that. So it's like For me, it's not overblown at all and even from an investor and economics perspective I don't think it's overblown because you know, we talk about something like the Blackberry and and mobile email and what that did to worker productivity and output and the impacts that that economically had. AI is already at that level. Like, if companies aren't embracing AI as worker productivity things, they're falling behind. And that's just gonna get like, the fact that it's so young means that it's gonna get better and better and better. And, like, it might not be another big revolution like we had when it was introduced, but it's gonna get incrementally better just like we went from a Blackberry to the new iPhone 16 pro. Like, they're kind of the same thing, but they're kinda not. And I feel the same way about AI. It's just gonna get better. And as supply and demand and market forces hit it, like the lawyer I was discussing, excuse me, the lawyer I was discussing this with doesn't work for a monster agency that has a custom IBM solution. So so they're using ChatGPT rather than some, you know, multimillion dollar super legal system. But the thing is is that that stuff will eventually waterfall down to those younger lawyers. And there's the smaller law firms. So it's it's as we proceed into the future, it's just gonna get bigger and bigger. No. I I don't think it's overhyped at all. I think that people's lack of imagination is restricting it at this point. Like, it could be doing much more than it is if the right people were designing where and how to integrate it.

Speaker 1: Well, that's about as good a transition to what we're talking about next as I can possibly think of, which is to say, on August 28, we're gonna get game dev nerdy here for a minute. Uh-huh. On 08/28/2024, Google in Tel Aviv, university researchers revealed what they call GameNGen. It's not game engine. It's game, uppercase, the letter n, gen as in generative, which is an GameNGen, which is an AI model that can simulate gameplay from the 1993 classic first person shooter game Doom in real time using AI image generation techniques. This is one of those, like, I I just need to make sure I'm understanding this right, because if you really did what I think you did, this is absolutely wild. Game engine uses neural networks and image generation sort of based on stable diffusion architecture, and it hints at a very weird future for AI game development. What they essentially did so traditional game engines, there's a loop. You gather a user input, you update the game state, the player's position, their health, and you render out visuals on the screen following predefined rules that were coded in. This system game engine kind of skips that manual rule programming and instead uses a neural network model to predict each subsequent game frame and game state based on the previous frame on an input of the previous frame and the user's action. So what they basically did is they trained this thing in two phases. First was a reinforcement learning agent training where they have a separate agent running around inside of Doom learning how to play it, and it is recording a combination of the gameplay actions, like the inputs of the player and the frames that are occurring at the same time as those actions, and then they pipe that cocktail of a frame and an action set into a diffusion model. And they kicked this thing out, which is a very accurate facsimile of doom running at 20 frames per second on a one tensor processing unit, getting, like, very, very close to the original quality of the game. Human testers had a very hard time distinguishing between the actual real gameplay footage and game engine simulated gameplay clips.

Speaker 2: This is what I'm talking about.

Speaker 3: This is

Speaker 1: what I'm talking about right here.

Speaker 2: That is that is that's nuts.

Speaker 1: That's absolutely nuts. If you think about what that combination of feeding in a player input and a output frame as being able to generate a interactive simulation that you can walk around it, it's like think about Mhmm. Yes. Doom had to exist for you to be able to have a player agent running around in it that you could require you could record those inputs. But theoretically, if you had some sort of an object that captured camera frames and motion inputs, like, I don't know, a drone, and you set that off using this exact same process, couldn't you theoretically re like, create a, like, interactive like, imagine Google Maps wasn't a series of three sixty degree photographs you could click between and was just a three d modeled environment you could walk around in that no one

Speaker 2: had to model. Whack a doodle. It predicts the interiors of buildings. You can just go for a tour. The the, Let's guess. It's like, what's Jordan's house look like? The but but like like if you know anything about, like, what NVIDIA is doing with DLSS, like frame generation and AI, like, they're essentially given given some of the same inputs. I'm not exactly sure. I'm not a pro at it, nor do I work at NVIDIA and know the IP behind it, but they're they're they're doing frame interpret interpolation. So if you're generating, say, a 120 frames a second, the AI can generate a frame in the middle of each of those frames that looks Yeah. Almost perfect. So, like, they they've they've got it to the point where they can, like and and here we are on the the the day after they just announced the new PS five pro and and its price tag, which everybody's very riled up to talk about even though they've probably never seen what a gaming PC cost because it costs a lot more than a PS five pro. But the but it will have, apparently, some of this AI frame generation in it. So you'll be able to run a four k title on a four k TV at a 120 frames a second, which is pretty wild out of a out of the price of a PS five Pro. And a lot of that is coming down to some of these AI facilitations. So it's it's a it's an it's a crazy space what they've managed to do. The the Doom thing's nuts because it's looking at so many things and essentially generating an entire game, but it but, but the this this field is fascinating. And, like, we saw this at Defcon. You know? They're they're training systems to auto auto detect auto detect flaws in code that create security problems and then patch them automatically knowing how to solve for them. And it's it's I don't know. I don't know how you could over hype this world. You know? It's it's it's a revolution, and it it needs to be treated like one.

Speaker 1: The the concept of so, like, I know that Runway's alpha and OpenAI is Sora, which is kind of a is more of a video generator, are both functioning on this idea of, like, like, world model and world simulation, where you are creating a space that theoretically

Speaker 2: Mhmm.

Speaker 1: You can export a video out of it. You could render a fixed camera position, but those cameras are movable. And that starts to get into this really blurry space between, is this video generation? Is this a world sim that I can run around in inside of a video game? But it's a it seems like a pretty important shift when you pair that world generation with the, what do they call it? The reinforcement learning agent training process.

Speaker 2: Mhmm.

Speaker 1: Or if I can create, you know, this navigable environment, and then I can let an agent loosen it and tell it, just play with this until you get a massive massive massive training data sized batch of inputs and frames, which we can then use to sort of train a little model and let a person then walk around inside of this. It it it rapidly gets over my head, but the the sort of implications are pretty dizzying. It's gonna be fascinating to see how this gets used. You know, frame generation as, like, a sort of in between state that we're currently in is is cool and is interesting, but I'm curious to see where the next generation of this gets us and what kind of experiences people can cook up.

Speaker 2: Well, I'm I'm like, what from a from a game, seeing as we're both game dev nerds, I'm really excited to see when this starts to integrate itself into Unreal Unity.

Speaker 5: Sure.

Speaker 2: Like, think about it from a level design perspective when you're just like, hey, you know, generate me a first person shooter map, and imagine interacting with the same as you do chat g p t. Like, oh, be sure to add, you know, two sniper positions, one on each side of the map, etcetera, etcetera. Like, you could start to outline sight lines, make sure that all roofs have at least two points of access. Like, you would be able to and also, like, run some playthroughs on it, do some pathfinding, see if there's any places where you have longer exposure than this. You know, you could or places where you can go with it between cover that are longer than, you know, this many feet or inches or whatever. And and also then, like, theme it. Be like, you know, make it more 1942 Russian nuclear base. Perfect. Like, refine this. Remove this. Like, it'll be I don't know. I'm I'm so excited to see, like, the I I definitely will say that I play more with the text based generative AI stuff than I do with the video. Have been playing around a lot more with the audio stuff, but the the video and image stuff, I I am always impressed with even even when I shouldn't be. It's still very impressive to me. But but I, but I can't wait until this stuff starts to integrate itself into some larger scale tools, and I'm excited for what that's gonna mean for game developers like you and I and what smaller teams will be able to create.

Speaker 1: The thing I'm fascinated for this is, like, I still want things to be authored. The idea of typing give me a Mhmm. I don't know, military themed first person shooter into a text box and playing that is, like, profoundly uninteresting to me. The idea that I'm just gonna stumble around inside of a, like, simulated environment built on a stack of LLMs and prompt. It's just like that's not I don't. What are the odds there's anything interesting in there, that's worth my time? But as an authorship tool for, like, creators to be able to build things, to be able to say, you know, I could model this environment in three d, or I could go find a real place and film it and feed the that, you know, that data into a model that would reproduce that environment and let me run around inside of it. It's like, oh, that's that's a new tool for authorship. It reminds me of photogrammetry versus modeling. It's just different ways of getting an idea into a computer. You could take reference photographs, or you can kinda just scan it and then run it with stable diffusion.

Speaker 2: I I strongly agree. I think and I I think the same thing goes is that as a efficacy tool, AI is gonna be huge. But I think that even in today's thing, when you leave it to generate something, it's generally kinda Yeah. You know Yeah. Lacking. But so so I I think that humans will remain a part of the AI process as getting things that interest humans until AIs know us better than we know ourselves, which could very well happen. But but I think, yeah, conceptually, I think you leave those pieces with the humans, but but I think that the AI can facilitate so much of the, quote, unquote, administrative side of generating things that it'll be it's revolutionary when it's done right. So Well,

Speaker 1: let's let's kick it over to some human authored advertisements, in the advertising oasis. And when we come back, I feel pretty confident saying we will not talk about AI, but we will talk about bad voter outreach, glitch as a polite euphemism for fraud, and a couple other little things, when we get back. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/act.

Speaker 4: This Father's Day, do more with dad and spend less with low prices guaranteed at the Home Depot. Get him fired up with a new grill and accessories, like the next grill five burner for just $299 so you can spend more time together while he becomes the grill master he was always meant to be. Or build memories with savings on top brand power tools so you can tackle projects side by side. Give more and do more together this father's day with help from The Home Depot. Exclusions apply at homedepot.com/pricematch for details.

Speaker 5: When you finally find your thing, you want the whole world to know about that thing. So you use a thing called Canva to make it an even bigger and better thing. Whether you want to create flyers for that thing, make presentations for that thing, or design merch for that thing, you can do anything. So people can see your thing, feel your thing, love your thing. The next thing you know, it's a thing. Canva, the thing that makes anything a thing.

Speaker 1: Study

Speaker 3: and play. Come together on a Windows 11 PC. And for a limited time, college students get The best

Speaker 2: of both worlds.

Speaker 3: Get the Unreal College Seal, everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft three sixty five premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com/studentoffer. While supplies last, ends June 30, terms at aka.ms/collegepc.

Speaker 1: And we're back.

Speaker 2: We're back.

Speaker 1: Here we are.

Speaker 2: Not talking about AI

Speaker 1: Yet.

Speaker 2: Yet. Yet.

Speaker 1: I'm gonna I'm gonna get a big button, a big buzzer. And if and if we start drifting towards AI, I will hit it. This one's fascinating. Krebs on security was we kinda broke this story. Scott, I want you to imagine you just got this text. It comes from a a number you don't recognize, and it reads, we have you in our records as not registered to vote. Check your registration status and register in two minutes at h t t p s colon slash slash all dash vote dot com slash v f I question mark u t m, and then the active URL ends, and it reads term dash and then just a bunch of gobbledygook. Would you read that and think, this sounds like a legitimate voter outreach campaign? I should definitely click on that link.

Speaker 2: The fact that it has a UTM section, which means that it's being tracked, would give it more credibility to me. I don't know how many fishers run run Google tracking pieces in it, but, Sure.

Speaker 1: For the analytics? No.

Speaker 2: No. I definitely wouldn't. I would actually probably flag it as spam and and delete it from my phone. I actually get boatloads of messages like this, and some of them might be legitimate, but they all get deleted and flagged as spam, and often the number's blocked.

Speaker 1: Yeah. You and a lot of people would do that. I I find this one fascinating. Shortly after this giant text message blast goes out to recipients to all-vote.com, Media outlets start reporting on it as being a scam. August 27, WDIV Detroit channel four affiliate starts warning of an SMS message resembling, like, it's looks like there's a giant voter outreach phishing campaign, and sort of fear saying if you click on this, this might end up in a situation where it could block voters from casting ballots. It pretty quickly gets reported on as there is a scam happening right now. Arizona, Pennsylvania, they're all issuing alerts. Recipients are being interviewed in these news reports talking about how they believed that they were being sent phishing attempts, because they knew for a fact that they were registered as voters. A seventh grader from Canada received one of these messages. Turns out this was just an exceptionally poorly run voter outreach campaign done so badly that it looked like it was a phishing campaign. If you clicked on these links, visiting allvote.com to try and check, You know? You go, okay. This URL is weird, but let me go to allvote.com. It was down when they sent this out, and redirected to a login page for a, totally unrelated voter registration platform. Better. That was registered very recently, adding more to the suspicion. Deborah Cleaver, founder of Vote for Amer Vote America explained that the source of the messages was a political consulting firm called Movement Labs, and highlighted the sort of, like, key error in their approach, which was violating a basic rule of voter outreach by telling people that they were not registered. This is considered, like, if not bad practice, borderline unethical given that a lot of these voter registration lists are outdated or inaccurate. It's a fascinating story at a very sensitive time in the American political ecosystem. And just a reminder that for as, big a problem as phishing is, people are getting better tuned to what these messages look like just by way of the sort of sheer volume of them that exist in the world. And that if you are going to try and do voter outreach and you don't wanna have damaging consequences, you gotta be aware of that.

Speaker 2: I think I think this is a silver lining story. Yeah. I can see that. Anyway. When I when I read the story that this is great. Like, this is people having their guard up high enough in today's reckless world of of cybercrime to be like this thing which was ended ended up being legitimate. They flagged it. They're like too many like, this is the the byproduct of corporate phishing training, like, right here. Everybody everybody's sitting at their desk at WIB in Detroit, and four people's phones blow up with this exact same message, and everybody goes, this is a scam. Mhmm. And that that to me is a silver lining. Like, I'm I'm pumped that that this was got even even when I have to this got to the point of being completely blown out of proportion and reported on as being a scam when it, in fact, wasn't. Granted, it was there were some ethical boundaries crossed and stuff, but but, I I love that it. Peep peep yeah.

Speaker 1: Sure. Sure. I take your point, though. Yeah. No. Yeah. Like, that that that's a

Speaker 3: that's a point for the good guys. Mhmm.

Speaker 2: You know what I'm saying?

Speaker 1: Yeah. That's a point for the good guys. Okay. While we speed run some of these stories in the back half of this this episode

Speaker 2: As we speeds speed run some of these stories, I think that you should speed run over to hotlinehacked.com and tell us your interesting story of cybersecurity. Whether it was you got phished, maybe you hacked something, maybe you broke into the human resource person's computer to look at it, how much everybody was getting paid. Mhmm. Maybe you made a fax simile, real story from last episode. Maybe you made a fax simile of some parking passes again, or maybe you hacked into an API for an ebike company. Let us know your tales and we might bring them to life on an episode of Hotline Hacked. So hotlinehacked.com.

Speaker 1: Speaking of good news stories, here's a bad one, and it concerns the word glitch. The word glitch, the language of life hacks on TikTok has increasingly become an umbrella under which people just sort of provide tutorials for full blown fraud, and a pretty fascinating one happened pretty recently. Viral TikTok trend referred to as the free money glitch claimed that users could withdraw money from Chase Bank ATMs by exploding a exploiting a supposed loophole. The the thing that they were explaining how to do involves see if this sounds familiar to you, Scott. Mhmm. The tutorials on how to deposit a check for a large amount of money to the bank when the user didn't actually have it, and then withdrawing a smaller but pretty significant portion of those funds before the check cleared. Participants in this TikTok trend believed they were taking advantage of a glitch, which is, in no uncertain terms, just check fraud. It's just check fraud. It's not a life hack. It's not a free money glitch. Chase Bank has confirmed that individuals individuals who attempted the scam are being reported to the authorities for, again, full blown check

Speaker 2: fraud. We have a few systems still in society that put trust in in, you know, humankind, and and this might be one of them. And I feel like it's ruined for all of us now. Like, it's gone now. Sure. It it only takes one person to ruin it all.

Speaker 1: You're gonna ruin it for everyone. We can't do checks anymore because you made a viral trend out of check fraud.

Speaker 2: Mhmm. Yes. Mhmm.

Speaker 1: Yeah. Yeah. Yeah. Chase Bank pretty quickly started freezing accounts of people who tried to do, check fraud. According to a Chase spokesperson, the bank is working closely with law enforcement. They're panning over surveillance footage as they do in cases of check fraud. And they stated plainly, regardless of what you see online, depositing a fraudulent check and withdrawing the funds from your account is fraud, plain and simple. They didn't disclose the exact number of people involved. Reports have suggested that, hundreds if not thousands of individuals may have tried this scam, spurred on by these videos, which have been watched by tens of millions of people at this point. I tried to go on and and pull some down to include the audio in the episode, but I'm happy to say that I think most of them have been taken down. One popular one featured a woman trying to convince her mother that she could get between 40 and $50,000 through the glitch, to which her mother just sort of responded by saying that, like, I'm pretty sure if you do check fraud, the bank account will get closed and we'll get charged with fraud. So there is there is some sense.

Speaker 2: No. The older generation is still holding on to that wisdom. The wisdom that if you steal from the bank, you might get in trouble for it.

Speaker 1: The bank robbery, famously not liked by banks. Yeah. There was a good tweet. Only TikTok would transform grand larceny into a life hack and rename check fraud as a glitch, which, couldn't have put it better myself.

Speaker 2: I love that in this world that we're living in, that the TikTok is just the the basis for brain rot glitches. Like, society fully understands how bad this is for our for humankind, but we're just kinda cool with it. You know, it's entertaining. It's a good way to kill time in the Starbucks lineup. Yeah. You

Speaker 1: get those views, man. I I get it. We're here broadcasting on the Internet. I'm not one to judge. It's fun to make stuff. Just don't tell people to do fraud inadvertently. I'd say that is the maybe the the the sort of North Star of this show. Don't inadvertently get people to do fraud. And you broke the golden hacked rule, TikTok creators teaching people to do check fraud. Don't do that. That one's no. That moral ambiguity of this show. That one's pretty cut and dry. Don't don't don't do it because they'll charge you for fraud.

Speaker 2: The nomenclature here, like, unlimited money glitch. Like, I just feel like I know.

Speaker 1: It's so good.

Speaker 2: In in the in the brain rot that is going on, you know, all of the online terms, the gaming terms are just now fully part of our our lexicon now. Unlimited money glitch, which is like a old school gaming thing where when you found a glitch in a game where you could just, like, generate money. Now now we're just doing it in real life. We're just doing it in real life.

Speaker 1: Yeah. There's this sick new unlimited money glitch. Inside everyone's house, they have stuff, and that stuff can be exchanged for money. So if you go into their house and take their stuff and then sell it, you can basically have unlimited money. This is gonna sound conspicuously similar to larceny, and I promise you it's not. It's a glitch. It's a life hack. It's a Go to yeah. Like, don't don't do larceny. Don't do don't do fraud because TikTok told you to. See, but

Speaker 2: but why even go into somebody's house and take things, and then you have to take them to a pawnshop to sell them Sure. When you could just go into a bank and demand that they give you the money. They are holding it. They are in ops. You just go into the bank and be like, give me the money. You know? What's wrong with that? Unlimited money glitch.

Speaker 1: I wanna keep the bit going and just say and add in, like, a thing about, like,

Speaker 3: now they might not want you

Speaker 1: to, but if you had a gun but we're just getting into, like, providing instructions for crimes, So I'm not gonna do that even sarcastically. What I am gonna do is pivot us desperately and immediately towards a story about the TSA. That's what I'm gonna do.

Speaker 2: I think we need to we need to add one conditional to this.

Speaker 1: Please.

Speaker 2: Nothing in life is free.

Speaker 1: Nothing like Nothing

Speaker 2: in life is free. You have to work for what you get. There might be some glitches, but usually if you take advantage of them, you're probably either, a, taking from somebody else or, b, going to go to jail. Don't do them.

Speaker 1: Nothing in life is free except for, Apple Music royalties and Kindle GPT novels. Let's let's put a bow on it on this one. This is just like a a small story. Security researchers

Speaker 2: getting off base here.

Speaker 1: Way off base. Security researchers Ian Carroll and Sam Curry reported a major vulnerability in a login system used by the Transportation Security Administration, TSA, that verifies airline crew members at airport checkpoints. And the flaw allowed someone with, like, a basic understanding of SQL injection to go into this, this this database and add a fake pilot or crew member to official airline rosters. If you are on one of these rosters, you can in many cases, bypass security and enter into restricted areas of the airport. You might even be able to get into the cockpit of an airplane, and it was all just an SQL injection away. Carol and Curry found the vulnerability while they were testing a third party vendor's website, which provided smaller airlines with access to TSA's known crew member and cockpit asset access security system. While they were testing this system, the researchers inputted a single apostrophe into a username field and got a MySQL error signaling a vulnerability that they were then able to exploit.

Speaker 2: I think when I originally read this story, they successfully put somebody into a jump seat of a cockpit of a plane. I I don't know if that was true, but I I recall that fact from the first time I read it. The and also, like, just to talk about it from a technical side for a brief moment, any kind of query. So, like, when you have a text entry box, just just for your sake, go that when you have a text entry box on the on an internet site, chances are the data from that is going into either a query or it's being injected into a row of database like row. You know, it's typically finds itself into an SQL query at some point. And the most primitive security measure is escaping that to make sure that if there's any SQL control characters that they're escaped so that they don't impact the query. And this input box was not receiving that treatment.

Speaker 1: Interesting. Yeah. It would align with I'm a frequent traveler. I engage with the TSA on on, on a on a fairly regular basis, and I'm always struck by there's this this famous stat that floats around, in a number of random tests conducted at busy airports all across The United States. An internal group to the TSA known as the red team were able to smuggle mock weapons and explosives past TSA security checkpoint 67 times out of the 70 attempts they tried, which equates to a 95 failure rate. I'm just gonna lob that stat up into the air, hold held next to this one that there is apparently a a are you a pilot list that you can work around, with an SQL injection.

Speaker 2: Stab yourself too.

Speaker 1: Yeah. And the worst part is that, like, I don't really know how you fix that because it seems like what they keep doing is saying, like, fewer belts, less shoes, smaller fluids. I'm like, I don't I don't think that's how you lock this system down. I don't know how you lock it down. I don't know how you improve this, but it doesn't seem like it's going so hot.

Speaker 2: It's a dark twist on this. The I am also aware of some of those tests and some of those tests that have occurred at my regional airport, that were wildly successful getting guns through. And I think the, how do I talk about this without talking about how to smuggle guns on airplanes? Given some modern techniques and the lack of dependency on metal components.

Speaker 1: Oh, no. Don't tell people to three d print plane guns.

Speaker 2: No. I'm not. I'm not. I'm not. I'm not. But but but but, like, I just I just feel like they they need to reinvent Sure. What that like security process looks like because the world that they're used to and the world that they're built for I just don't think exists anymore. Like I could probably bring a three d printer onto the plane with me with a lithium battery big enough to run it. You know what I'm saying? Like we're we're living in different times.

Speaker 3: Oh, man.

Speaker 2: I have no beef with the TSA. I'm actually a frequent traveler and I am on their priority list, some TSA pre check. I have all the rest of that jazz, and there's no headaches for me. It's actually great. I got a priority line. I can take food and beverages in and out. I don't even have to take the liquids out of my bag anymore. And I if you don't if if you frequently travel and don't have that kind of clearance, then I can tell you right now that it is worth every penny.

Speaker 1: K. I might need to do that so I can get my three d printer onto the plane, plug it into the back of the USB and just make everyone anxious. Oh, no.

Speaker 2: Coming back from the edge.

Speaker 1: Coming back from the edge. I think that I think that puts a pin in another one. We got some fun episodes coming out. We won't we won't tease them, but, there's some cool stuff coming down the pipeline. We think you're gonna enjoy it. Big old thanks to our Patreon as we wrap this bad boy up. Hackpodcast.com redirects to our Patreon. Hotline hack.com, if you wanna share a story for our our now monthly call in show, it means a lot. We love to hear a good tale.

Speaker 2: Yeah. I

Speaker 3: think other than that, we're just gonna go ahead

Speaker 1: and catch you in the next one.

Speaker 2: Take care, everybody.