23andMe Exposed + AI Watermarks + Announcing Hotline Hacked
TL;DR23andMe confirmed hackers accessed user data via credential stuffing, with profiles of Ashkenazi Jewish and Chinese-descent users sold on breach forums. The episode also covers the MOVEit breach, AI watermarking failures, ALPHV ransomware…
Visit hotlinehacked.com to share your strange technology tale and hear us discuss it on the show assuming this experiment works (and to see the least mobile-optimized website ever created). We discuss the recent leaked 23andMe data, the MoveIt Breach, and what "out of pocket" means.
NOTE: We misspoke, the name of the show we discuss is Ransomware Files, not Ransomeware Diaries.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: I just took a DNA test. Turns out I'm 100% that victim of a massive data breach. This week on Hacked, genetics firm twenty three andMe reveals user data stolen. We're gonna talk about it.
Speaker 2: We're also gonna talk about the Move It breach, finally. It's been a few months in the making, but it seems to be tying into many of the stories and things that we're looking at and reading today.
Speaker 1: And then since the early days of generative AI, we've been hearing about how crucial a role watermarking is gonna play in fighting misinformation and maintaining copyright. How is that going? According to experts, poorly. We're gonna talk about it.
Speaker 2: Also, the group known as ALF, alpha, alpha, Black Cat, whatever you'd like to call them. The ransomware group is, back at it. So that we talked about them in the Las Vegas episodes. They are, back at it again, so we're just gonna touch on what they're up to.
Speaker 1: All that and more in this chat episode, we're packed. Scott, how we doing this week?
Speaker 2: Good. Good. I'm, moments away from jetting over to your part of the world and going to pick chanterelle mushrooms in the wild. So I'm
Speaker 1: Heck, yeah.
Speaker 2: Yeah. So I'm off for the weekend to go mushroom picking. So that should be fun. Not the mushroom type that I think most people would think, but probably going to make some good risotto. Should be nice.
Speaker 1: Maybe You can make a good risotto with the other kind of mushrooms people are thinking about.
Speaker 2: Oh my God, could you? I've never even thought about that. That seems treacherous.
Speaker 1: It wouldn't taste very good. No. It is treacherous. That's a good word for it. It would be a treacherous meal.
Speaker 2: Yeah, but we'll be kind of up in Tofino, so hopefully we'll get a little surfing into. We'll see how the waves are. But we're mostly there to pick mushrooms, so we'll see how that goes.
Speaker 1: Good times. I've actually never been up to Tofino. Me and
Speaker 2: my partner were just talking about going up there,
Speaker 1: sometime soon as well.
Speaker 2: You know what? Neither have I. Shocking
Speaker 1: Oh, sick.
Speaker 2: To everybody that I know.
Speaker 1: Island Livin'.
Speaker 2: Island Livin', but I have not not done it.
Speaker 1: Island Scott. I don't think I've ever seen Island Scott.
Speaker 2: Oh, Island Scott existed. Like, when I lived in when I lived in Hawaii, Island Scott was was full full fledged, full on. Oh, yeah.
Speaker 1: I forgot you did have an Island Scott era.
Speaker 2: Yeah, I did. I did. I would love to have another Island Scott era, honestly. Maybe that's something that I should be tuning my life for, is to become an Islander again. Board shorts? Every day. Every day. Everyday board shorts. Hawaiian print floral button ups. You know, it's a it's a vibe. It's a vibe. And I can't lie. I enjoyed that vibe very much.
Speaker 1: You know who also brings a sort of easy breezy, flower floral print, board shorts, island kind of vibe?
Speaker 2: Who's that?
Speaker 1: I'm talking about Sarah Gardner, our new patron on, our our trusty Patreon.
Speaker 2: Oh. Yes. Yes. Thank you very much, Sarah. And I think Mhmm. Walt Kimbrough would also vibe vibe pretty hard in the Hacked Island compound.
Speaker 1: I think he would. I think Walt Kimbrough has, like, I I I'm seeing him with, like, a Mai Tai, a big a big drink, like a really big island vibe drink.
Speaker 2: Him and him and Floyd Clark
Speaker 1: Him and Floyd Clark.
Speaker 2: Just running the Margaritaville constantly at the Island Villa.
Speaker 1: Yeah. That's them. They're out there. Floyd Clark, thank you very much. And, putting a pin in the whole thing, fittingly, Ender. I think I think Ender's like the dark horse
Speaker 2: of the island.
Speaker 1: He's he's sort of overseeing it. He's in, like, the in the bird's nest up top, making sure everything's okay. Maybe in, like, a lighthouse. Ender.
Speaker 2: What what a name to end things, darling, except for the sad the sad fact that we have one more, suffogen Bonnie.
Speaker 1: Oh, we did miss one. I jumped straight into the middle of the list. I'm so sorry, Sufjan Bonnie. Thank you so much for your support. It means a lot to us. And, also, we're gonna see you you get a hammock for that. You get, like, a really nice a hammock and a a drink made of a coconut.
Speaker 2: A cabana. And a cabana. Oh my god. A cabana by the by the ocean.
Speaker 1: Cabana with a coconut drink.
Speaker 3: But
Speaker 1: thank you all so much for your support. If you also wanna support, like, tech storytelling and and bullshit and about tech, I don't know if we curse on this show, you should support us. We do? Great. I should know that.
Speaker 2: I I curse on this show. Me too.
Speaker 1: So I guess I did know that. I've told a guest recently they can curse on this show, so you can curse on this show. All of you supporters, new and old, can curse on this show if you wanna support tech content and stories and chat and, hackpodcast.com. It's a great way to support the show. Direct to our Patreon, and it means the world to us.
Speaker 2: Totally. Any other any other news now that we've got our travel stories and plans out in the open and, a bit of, patron thank you? Is there anything else you wanna touch on before we get going? Maybe a new thematic episode type that we're thinking about doing? Maybe Yeah. I think I think
Speaker 1: we maybe do. So fun little insight for users. My cat is ferociously attacking me right now. I'm just gonna pod through it. I'm podin' through. We're gonna do a little experiment, and I'm hoping the website's up and running good by the time we drop this one. So a few episodes ago, we talked about the idea of a call in show. I love call in shows. I think, Scott, you've expressed some appreciation for them in the past. Classics? They're classics. You got your love lines. You know, it's a great medium. It's a great format. And we just started thinking about what would it be like if there was, I don't know, some kind of a hotline, a hacked hotline, dare I say, a hotline hacked? I could have handed it to you on that one. You
Speaker 2: were- could've handed it to me, but you chose not to. You wanted to hit it. It's your it's your it's it's your name. You you you take the credit. You roll with it.
Speaker 1: I chose violence.
Speaker 2: This isn't Hotline Miami. It's a Hotline hack. Yeah. All good. All good. Yeah. So the the idea behind it
Speaker 1: Take it away.
Speaker 2: Let's talk let's give everybody a little thing. Is is we're gonna have a, essentially, a voicemail line. Mhmm. You can call and leave a message where you tell us a story about either a cybercrime that you committed or a cybercrime that was committed to you or that you were aware of or in the periphery for if you're, like, a security officer, and we're gonna kind of listen to these back and figure out which ones are are kind of good stories, and we're gonna turn them into episode content.
Speaker 1: You got it.
Speaker 2: What do you think of that?
Speaker 1: I think that's bang on.
Speaker 2: Is that?
Speaker 1: I think it's, like, we want those cyber crimes. We just want like strange tales of technology. Like maybe you hacked into something, maybe you solved an internet mystery, maybe you like got into a thing you shouldn't have. We just want you to either submit an audio file or leave a message at the hotline, and we'll talk about it on these hotline hacked episodes. If this worked, if it it might not work. This might be the last you hear about
Speaker 2: this. We might get no content.
Speaker 1: We might get no content.
Speaker 2: Nobody reaches out.
Speaker 1: The content might be I say this with so much love, unhinged, and we just won't do this. But I'm hoping, we talk to so many people that listen to the show, and they always have these really cool stories, and I never quite know. We never quite know what to do with all of them, whether or not they can make up a whole episode. And this is just a space where we can talk about a couple different stories, and sort of speculate about what people call in and leave leave on the hotline hacked.
Speaker 2: So there there there will be an email option to email in either text or or an audio file. If you do send in an audio file, be aware that we probably will play it in the episode
Speaker 1: Same or
Speaker 2: at least an edited version of it.
Speaker 1: Yep.
Speaker 2: Same yeah. Yeah. Same with the phone number voicemail, so be aware. If you wanna make sure it's more anonymized, just send it in some text, and then we'll digitize it into the voice of a reader and and use that. Mhmm. So or we'll read it ourselves, one of the two. Or or we'll
Speaker 1: read it ourselves. Yeah. If you wanna submit text, there's the email on the website. And as we said, it's kind of as anonymous as you make it. You can go to hothotlinehacked.com. Hotlinehacked.com to find Hotline. Take it away. Land it. Land the plane. I was gonna say,
Speaker 2: hothotlinehacked.com. Hotlinehacked.com. Is it today?
Speaker 1: Is it today? We gotta record, like, oh, man, like, weird late night infomercials for this.
Speaker 2: We should we should also tell everybody before anybody visits the website that Jordan generated the website on Chad g b t. So so it's very basic. It's very functional. It's got some pretty sweet JavaScript text coloring elements.
Speaker 1: I wasn't fishing for you to compliment the JavaScript, but I do appreciate it.
Speaker 2: Hey. Hey. Hey. I'm I'm here for you. Last week, it's Python. This week, it's HTML and CSS. Like, who are you? I'm Next thing you know, you'll be you'll be writing malware and Rust. We'll all be in trouble. Right. Then what? You'll be joining alpha. Alpha. Or alpha or alpha.
Speaker 1: And maybe Alpha. And maybe you're part of alpha or clop or any number of people getting out to stuff. Maybe you just have an interesting story. But, we would love to hear it at Hotline Hacked. Either our brand spanking new franchise or our whatever happened to that that someone asks us in five episodes.
Speaker 2: Only one of the two. Dead in the water idea. Totally. Yeah. Yeah. Speaking of which, I heard I heard this interesting I read in our news articles, it has nothing to do with anything we're about to talk about, but I just thought it was funny you you made you made us, like, used a little statement that made me realize it is, did you know that there's apparently a generational shift for the phrase out of pocket? Oh. So like, if I'm like, oh, Jordan's out of pocket this weekend, to me, that means like Jordan's kind of wildin' out. You know, he's like, he's out of pocket. Oh. But apparently, in the older generations, out of pocket means like I'm out of the office. It's like, oh, I'm gonna be out of pocket today at two. And it's, everybody's like, Oh. So I didn't I had no idea, but apparently, there's this generational gap for the for the phrase out of pocket. And I just found it interesting. I have no idea why I just inserted this, but I found it interesting. I thought you'd find it interesting.
Speaker 1: I do find it interesting. You know how I feel about idioms and etymology. See, what's interesting about that is that I thought, I think of out of pocket as neither of those things. Really? I don't think of it as being like in absentia or wilding out. I think of it as being like based about money and transactions. Oh, like you. Like the cost of the concert was like a bunch of, the example on Google, I'm not going to, someone's going to check and see that I'm reading this. The organizer of the concert was $15,000 out of pocket after it was canceled. Yeah, that's how I think of it. Yeah. Like, it's a cost thing. Like, you you you put money up for that.
Speaker 2: I I I think I I think I I see that too. Like, that's an like, that's a classic. Right. I'm out of pocket $10 for this or whatever. But it's like
Speaker 1: Yes.
Speaker 2: If I'm like, Jordan's out of pocket, does your mind go to, is Jordan in the office or not in the office? Or does it go to, is Jordan
Speaker 1: It doesn't go to East Jordan's actually.
Speaker 2: On the beach at the Hack Cabana because mine goes to the latter.
Speaker 1: Interesting. I my brain goes exclusively to Jordan did a bad business deal, and now he's feeling it. Like Wow. He spent he spent all that money on the hacked cabana, and now he doesn't have that money because of the storm that claimed the hacked cabana. That's what I think about a pocket.
Speaker 2: Okay. Interesting, but I I think we should move through this. Yep.
Speaker 1: Let's get into this one. Five years ago, there was this situation with a DNA testing service called MyHeritage. Mhmm. Someone breached 92,000,000 of this, like, DNA testing company's accounts. Do you remember this?
Speaker 2: I do not.
Speaker 1: It was sort of, it wasn't a good news story, but when they announced that the infiltrator, what the infiltrator got access to, there was sort of a sigh of relief because they got access to encrypted emails and passwords. And everyone went, oh. Sure, user data. Exactly. Everyone went, phew. That could have been bad because they never reached any kind of genetic data. I was reminded of that this past Friday when twenty three andMe, a US based biotechnology and genomics firm, confirmed a data breach of their user accounts. I would the company said that, hackers accessed certain counts of twenty three andMe users.
Speaker 2: I would say it's not just any genetic testing company. That's, like, gotta be the biggest one I know of. Like, I know
Speaker 1: They're the one I think.
Speaker 2: Yeah. I know I know lots of people that have done 23 andMe testing.
Speaker 1: Yeah. Me too. I've I I remember a few years ago, like, thinking about doing it, and I didn't I didn't not do it because of some, like, privacy based awakening. I didn't do it because I lost interest. Like, it's there, but by the grace of Go Goai. And let's be clear, not every, single 23 andMe account was breached. And it's not to say that 23andMe itself was necessarily breached. There's some nuance here. But the outcome, is is pretty gnarly. And I think it kind of paints a picture of what a spectrum of genetics based leaks can look like. So 23 me now like, this announcement came a couple days after hackers started advertising an alleged sample of this 23 me user data on the hacking form breach forms, offering to sell these profiles for between 1 and $10. And these sort of early samples, which a couple different places were able to verify, were organized based on the descent of the users. So there were, there was essentially a little cluster being sold of a 100,000, Chinese users. There was a a cluster being sold of a million, Ashkenazi Jewish descendant users. A spokes a spokesperson from twenty three me confirmed that the data that is in these leaks is legitimate. And what it looks like happened is threat actors used essentially a credential stuffing attack. Mhmm. So credentials that were in other breaches that were recycled on twenty three andMe were used to get into these accounts. Quote, they clarified, quote, we don't have any indication at this time that there's been a data security incident within their systems. It was a credential stuffing technique.
Speaker 2: Let's segue before we get into the actual hack and just talk about credential stuffing just a bit. If you're an old hacked fan, you would have listened to Problem with Passwords. I think it was one of our first four or five, podcast episodes. And I am now a believer in the password manager, and I think that this style of attack is the main reason why, you know, you need a unique password for every site or else you just become with the the scale and velocity of data exploitation style hacks where they're pulling out user records, If you have a password that's guessable, even within a reasonable timeline of months, chance chances are, you know, you're you're vulnerable to having a pretty nasty set of this style of attacks happen to you. And I just think that that's something like, I've set up my wife's got a password manager now. Everybody that I come into, I recommend them using unique passwords on everything, complex passwords, as well as changing them with frequency. And I think that's as long as we live in this antiquated password based life, which I don't think we're gonna get away from because even if we use other things as as forms of biometrics or whatever, all they do is get encoded into passwords anyway. So it's realistically, it's all just data. So Yeah. At the end of the day, the best thing to do is to just have different data for each site so that this doesn't become a problem for you.
Speaker 1: 100%. For the folks that it did become a problem for, leaked data included full names, usernames, profile photos, sex, date of birth, geographical location, and genetic ancestry results. So a pretty a pretty gnarly doxing, as doxings go. BleepingComputer found that the number of accounts sold by cyber cyber criminals doesn't necessarily match the number of 23 andMe accounts that were breached using the exposed credentials. At the heart of this whole thing is something called this DNA relatives feature. And what it It's essentially like a toggle that you can choose to use or not use that lets you find and connect with genetic relatives, indexes other people that share some sort of genetic relationship with you based on your 23andMe results. And what it looks like the threat actor did was they were, only by accessing a few 23andMe accounts through this credential stuffing, they were able to scrape enough data from the DNA relative matches to start building out essentially like a database of different people that shared certain genetic markers. This is how we ended up in a situation where you would have a breach of just, here's a list of people that share this ethnic background. You wouldn't really be able to do that without a system like DNA Relatives, unless the hacker had gotten full access to 23andMe system. But because of that feature, just through user accounts, they were able to create these, you know, million strong entrants. And given that we know more accounts were breached than have been, exposed in these leaks, we can probably assume more of these lists are gonna come.
Speaker 2: Yeah. I feel like this is gonna be one of those datasets that people will target and and will eventually, probably people will try and expose.
Speaker 1: Yeah. I think that's I shouldn't
Speaker 2: say they probably will expose, but they will try. 100%. This and this is also gonna be one of those things that, like, once it's out, you know, it becomes the the classic thing of, like it's like the, Ashley Madison hack. It's like the damage is already done. If you were in there, it's like the damage was done. It's like they don't need to you don't need to sell it or, you know, there's no way to look to monetize this, but it's like if if all of your genetic data is floating around on the Internet, it's like the damage is kinda done, especially if somebody can be like, oh, I just got an insurance application for Jordan Blumen. Yeah. Plug him in, Oh, yeah, his data's here. Oh, look, he's got hereditary markers for X, X, and X. It's like, Okay, denied.
Speaker 1: You kind of beat me to the thing I wanted to bring up, which is that, like, I don't really know When I think of, like, a breach form, like, where people are buying and selling this information, I don't really know what the people buying and selling stuff there would want to do with genetic information. It's just not really compatible with making money through cybercrime in the, like, short, short, short term. But what we know is that the information that's in these data breaches that we think of as being bought and sold from cyber criminals tends to end up on a long enough timeline getting packaged up and bought and sold and bought and sold. And it kind of works its way up the chain of legitimacy until phone numbers and emails, and then we're in non legitimate breaches find their way into the databases of real companies. And that's what I'm worried about with this, is that the long play on this is selling these to companies that shouldn't be buying this data illicitly, but have a huge financial cert incentive to have it. I think that's where genetic breaches go. And it's, it would be an icky world if that's where it goes.
Speaker 2: But we don't live in an icky world, do we, Jordan?
Speaker 1: I I sure hope not. I sure hope not. I the last thing on this one, I went down a bit of a rabbit hole because I I saw that first story from a few years ago. I remembered it. And I went looking for, like, breaches and data leaks relating to genetic information. And there's this WAPO story from, 2022, quote, since the beginning of last year, more than a dozen medical labs, genetic testing companies, and fertility firms have disclosed breaches affecting more than 3,500,000 people, according to a cybersecurity two zero two review of data breaches. Wow. And it's just interesting to me that, you know, small labs that have the actual, like people's genome, like genes, like the actual raw data are as good an attack target as like a massive company like 23andMe, if you're trying, depending on how granular this data is. And it just sort of makes me reflect on how the more and more genetic data we start producing and digitizing, the bigger a target's going to become. And unlike a credit card, there are some things you can't really change when they get leaked.
Speaker 2: See, the the the the the problem is, like, this data is super valuable too to the person. Like, if you know you have specific markers for heart diseases and cancers, you can be well aware and more up on making sure that you're checked and tested. Totally. You know, there's a lot of positive that can come out of this data. Yeah. So it's sad that, you know, it just becomes one of these things where it's like, well, there's a bunch of negatives that can come out of it too, and it's just a byproduct of the world we live in. But think over the next hundred years, we'll see changes come to the industries Mhmm. That we're worried about having this data, and hopefully changes come to the industries that we hope have this data.
Speaker 3: Yeah.
Speaker 1: It's
Speaker 2: true. Like, if my family doctor knew what I'm like, you know, medical history of your parents is such an important thing. And it's like, well, this is, you know, your DNA essentially is the codified version of the medical history of your family. So it's like, now that they've deciphered the codes, you know, having the code is a good thing. And it's like, I think that this is probably something that in society we don't take advantage of enough. No, it's true. From a wellness and health perspective.
Speaker 1: Yeah. I want to see us getting better at like leveraging genetic data and be really like, I think a lot of the ways big companies handle data breaches, it's like, I'm regularly kind of disappointed by it. Cause like anything, it's PR. You're trying to minimize a situation. You're not necessarily being totally forthright with what happened. And this is such a delicate, sensitive thing that like we need to build systems of security and trust to allow us to have this information and to use it to the best of our ability. Because the potential upside isn't like a better chat messaging app. It's like people's lives. It's the stakes are very, very high. We should be advancing this and getting better, but, like, man, we we just we need more trust and more security in these systems, because icky icky shit will happen.
Speaker 2: That, to me, is a perfect segue to the MoveIt breach, if you wanna talk about MoveIt breach.
Speaker 3: Heck,
Speaker 1: yeah. Let's talk about the MoveIt breach.
Speaker 2: So so MoveIt is a data transfer system created by Progress Software that is built to be a movement system of high security to move hypersensitive information, corporate secrets, personal information, HR stuff, anything that's, you know, you need to move, but you wanna make sure it doesn't get out there. You know, like, if you go to their website, they they have first sentence at the top of the page is talking about security standards and protocols and cybersecurity things. Anyway, so one of these pieces of software, MoveIt by Progress, got compromised. And it's not the first one of its kind to be compromised because it's actually hacking groups that target these styles of software because they know that they're so valuable. So it's same thing. Same thing as the genetic data. It's like the if you put a bunch of valuable information into a place, people that want valuable information are gonna try to get it. And it's the same thing with MoveIt. So so MoveIt was behind, I believe it was the MGM hack or one of the Vegas hacks or both of them maybe. Can't remember. It was behind the Sony hack that's that we talked about last time, and it's been behind a boatload of other hacks. Like, they're estimating something like 600 organizations of fallen prey to one ransomware's group's use of it.
Speaker 1: Yeah.
Speaker 2: So even the the vulnerability, the CV that came out on it was given a 9.8 out of 10. So, like, essentially, out of all the severity that, like, a potential vulnerability in a piece of software could have, this is, like, one of the top. Yeah.
Speaker 1: So I didn't know what move it was. And the thing that put this onto my radar like you said, last episode, we talked about these sort of what were then brief early murmurings of another Sony leak. And I was fascinated, as you brought up, to find out that it was part of what's looking maybe by the numbers like one of the biggest hacks of 2023, not a singular hack. Part of this much, sort of a supply chain attack involving this file transfer protocol, maybe you could call it, MoveIt.
Speaker 2: File transfer system?
Speaker 1: Yeah. So Sony confirmed that they were part of this MoveIt breach. For them, it was 6,800 users. Data extortion gang, CLOP, has claimed responsibility for the breach. The breach seems to have exploited a zero day vulnerability in Move It. And it's looking, as I said, like probably, yeah, one of the biggest hacks of 2023, and potentially in like, over the last couple years, it's looking like, you mentioned the 600 through one ransomware gang, it's looking like to date, the total impact is about eleven fifty organizations, 56,000,000 individual users across that, at a global cost of close to 11,000,000,000 as of time of recording. Pretty, pretty astonishing. Affected entities so far have include Shell, British Airways, Sony, and the US Department of Energy. Progress Software, you mentioned, is the owner of MoveIt, did patch the sort of zero day flaw back in May. But, clearly, as we are seeing this month, the damage has already been done.
Speaker 2: This this vulnerability, I think, dates back to April, if I'm not mistaken. I think the first first things you heard about it dated back to April. And it it's so they patched it pretty quick, but, of course, like any kind of system software that has remote deployments and stuff, whether IT departments around the world patched fast enough, things like that, or whether there was already access granted, and then people had already exploited it was it was a thing. So the way the exploit works too is it's kind of a classic SQL injection. So, like, they can kind of force a piece of SQL into an like, into a query going into it, which then causes remote code execution. So I think what they were doing is using it to deploy web shells and remote like, essentially remote access shells so they could get in kind of either, a, go through the database, which is full of highly sensitive data transfers because that's where they were. Sure. Or or they could, you know, create new accounts, etcetera, etcetera. So I know that they were using it as a jump off point to launching attacks further into networks, which is what I think happened with Sony, if I'm not mistaken. They managed to kind of get in and kind of spider through the networks. So not good. Massive public facing service that has a massive, you know, remote shell exploit, and and the world's paying the price for
Speaker 4: it. So
Speaker 1: Yeah. There's typically, like I don't know. It's always sort of hard to maybe none of these attacks ever really have that much of a narrative, but it's a lot easier to make a narrative when it's a hacking group going after one individual target. This is so strange because you have, like, shell strange because you have, like, Shell, British Airways, and the Department of Energy. You also have, like, health care facilities to sort of go back to what we were talking about with genetics. A bunch of sensitive information has already been confirmed as having leaked, as being stolen as part of this vulnerability. Lab test results. Born Ontario, a government birth registry recently disclosed a MoveIt related attack. Looks like hackers stole data from 3,400,000 people, including 2,000,000 babies, expected parents, and people seeking fertility care. Data gathered over, like, a decade, as part of this this attack that was not explicitly targeting birth registries, but because this was a supply chain attack of a very commonly used, like, tech utility. They just sort of got the keys to a bunch of different castles, including, one with 2,000,000 babies in it.
Speaker 2: And Sony.
Speaker 1: And Sony. Yeah.
Speaker 2: And Sony. Yeah. And your PlayStation. The, yeah, big, big, big problem, big hack, big vulnerability. And the reality is there's probably still unpatched versions of it kicking around, so I think we're still seeing, like, there's still exploits and hacks connected back to this coming coming up now. So it's just it's it's it's it's funny that it's a piece of well, it's not funny. It's it's ironic that it's a piece of software that was acquired, set up, and configured to make sure that privacy was upheld and, you know, to reduce the risk of stuff like this. And then next thing you know, that's the main thing that's kicked the kicked the door open on it. So
Speaker 1: Okay. When we come back from the break, why don't we talk about, AI watermarks and our our our the folks over at Alpha. Alpha. Alpha. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, That's shopify.com/hacked.
Speaker 4: Whatever your thing, it could be anything. Canva helps you make that thing a thing. Canva is a simple online tool thing. It's a way to design with our magic AI tool things. You can social media your thing, generate images or videos of your thing, make decks or presentations to show your thing. Whatever needs to be done for your thing, Canva can make it an even better and bigger thing. Canva, the thing that makes anything a thing.
Speaker 2: Study
Speaker 3: and play. Come together on a Windows 11 PC. And for a limited time, college students get The best
Speaker 2: of both worlds.
Speaker 3: Get the Unreal College Seal, everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft three sixty five premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com/studentoffer. While supplies last, ends June 30, terms at aka.ms/collegepc.
Speaker 5: When you need to build up your team to handle the growing chaos at work, use Indeed sponsored jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.
Speaker 1: Before we started recording, we were like, we gotta pick a way to say it. And then both of us immediately, the second it started, we were like, alpha alpha alpha. Like, we went immediately back to not knowing how to say their name. It is unpronounceable.
Speaker 2: Yeah. Black Cat was their original name, and that's like, that's a word that I know how to spell it.
Speaker 1: Yeah. Sure.
Speaker 2: Black Cat.
Speaker 1: I got my feet under me with that one.
Speaker 2: Alpha. Alpha. I I just gotta call it Alpha. So So, yeah, anyway, Alpha is back. Tell me about it. They're back, stirring up some stuff. Yeah. So they compromised a Florida circuit court, and apparently have stolen a bunch of employee information, including, applications for careers and things like that, I think
Speaker 1: Mhmm.
Speaker 2: Is what I read. So the they were, related to the MGM stuff, and, yeah, they just keep keep going. So I'm not sure if this is associated with the same kind of way that they got access to MGM, whether it was a phone call to an IT department that led to a endless amount of problems. But but they're back, and they're still still mucking around. So
Speaker 1: Interesting. Yeah. Because my my memory of the the casino hack was that Alpha was responsible for the ransomware, and Scattered Spider were the social engineers. And you raise a really fascinating question of, like, does Alpha do the social engineering too? Like, what is their capacity? I think we gotta start reading more about these folks.
Speaker 2: Maybe one zero call hotline hack dot com, and, we can can play it on the show.
Speaker 1: Maybe we can talk about it. It's an interesting one because, like we never really have a great sense of the timelines. We read about a story, and it feels like the very next week week, the same crew of people is onto stuff. And I do wonder, like, is there a lag in the publicity of these attacks, or are they really cooking it that quickly? Did they really just wrap up doing a full Ocean's 11 and immediately kick it over to a Florida court judicial circuit where they, dropped a bunch of information on the website. It looks like the Florida circuit didn't, court didn't pay the ransomware, and that's why the data was moved. I'm so fascinated by that, the, like, internal conversations. That's something, there was the, yeah, Ransomware Diaries was so cool about that, because it was specifically concerned with that process of negotiating ransomware, and making the decision of whether or not you want to pay for it. And that's, there was such cool reporting of that, because it is such a private, secure process that people don't want to let people into, people don't want to talk to journalists about. And the fact that he was able to do that, if you never listen to that show, go back and listen to the feed drop we did, last year with them. A very fascinating one.
Speaker 2: The yeah. It's interesting because it's like a hostage negotiation, essentially, and it's like, do you pay the terrorists? Totally. It's like if you if you become, like, Caesars so here's the thing. Like, my wife listened to the episode we talked about Vegas and was like, Hey. You know, Caesar's paid it and was back up and running. MGM didn't. Why didn't they just pay it? And it's like, well, it's tough. You know what I mean? It's tough. Cost it cost them a $100,000,000 in, like, lost revenues and stuff, so it's not it's I'm sure the ransom was less, but at the same time, once you become known as the organization that pays Yeah. Do you open yourself up to more attacks? I would say yes. Mhmm. Like, it's not gonna it's not gonna be the last time this happens.
Speaker 1: So No. Definitely not. And I feel like Vegas of all places would have a lot of, like, I don't know. They put a lot of thought into how you deal with a criminal messing with your system. Like, whether it's on the casino floor type criminal, it's like, no, there's the there's the old Vegas way this shit is done. And I I'm not just saying that's what happened there, but it feels like I don't know. It kind of reminded me of that.
Speaker 2: Yeah. Yeah. If if Vegas was not a publicly or conglomeration of publicly traded companies these days, if it was still back in the old days when it was mostly allegedly mafia run, I'm sure this would be resolved in a much different way.
Speaker 1: Yeah. I mean, if you're gonna go after if you're gonna go after a place that's run by the mafia, and I'm I am making no claims about MGM. I'm sure that is a different time.
Speaker 2: Yeah. Yeah.
Speaker 1: But you know what? I'd probably wanna do it from behind a keyboard.
Speaker 2: Yep. Yep. I said allegedly, intentionally there. No. Yeah. Yeah. Yeah.
Speaker 1: We need to just print allegedly on the, like, box art of this show. Like, we're just we're speculating wildly. We try and be informed.
Speaker 2: Speculating wildly. Speculating wildly. We're we are out of pocket on hacked.
Speaker 1: Which one? Now there's ambiguity.
Speaker 2: Yeah. Yeah. Exactly. All of them.
Speaker 1: All of them. Okay. So we mentioned this a little bit at the top of the show, but when generative AI first started kinda kicking around, people started talking about, people started exploring, okay, well, what is the downside of this, giant earth shattering new technology? And along with, the impact it's inevitably going to have on the creator economy, there's the question of misinformation, both of which people started positing that watermarking could be a very useful technique. The ability to run an image or piece of text through something and try and quickly figure out, you know, just like a check mark, this was or was not generated by AI. Major AI companies, OpenAI, Alphabet, Meta, Amazon, and they immediately said, we are committing to developing watermarking technology to counter misinformation. It was the sort of thing that was gestured towards whenever that, whenever that very present threat was brought up. Google's DeepMind introduced a sort of beta version of its watermarking tool, SynthID, in late August. It is a it's sort of the answer that comes up a lot when people raise those very, very important questions. We are talking about it because of a really fascinating piece in Wired that dropped, about a computer science professor at the University of Maryland, Sohail Faizi, who, after this long, research project over the last six months, has stated that there is currently no reliable watermarking for AI images currently used. He and his small team were able to break all types of air AI watermarking that they tested. Thought this was probably worth talking about. So there's two different types of watermarking. Right? There's there's the watermarking that's visible to the naked eye. You know, a watermark in the corner. You can think of the Getty Images type thing. Yep. That's also funny in the context of AI. Yep. The other type, I didn't know this phrase, it's called low perturbation.
Speaker 2: Mhmm.
Speaker 1: And that basically just means it's invisible to the naked eye.
Speaker 2: Yeah.
Speaker 1: So he was testing specifically these low perturbation watermarks that would allow a user to quickly check an image for whether or not it was generated by AI. And I'm just going to quote him here. The results of his study, he deemed them to have, quote, no hope. He was Him and his team were able to, the phrase is washing out the watermark.
Speaker 3: Mhmm.
Speaker 1: And it was exceptionally easy. He also, I found this interesting, demonstrated how pretty simple it was for those same watermarks to then be added to human generated images, leading to false positives. So it's not just that the current state of these watermarks is crackable. It maybe suggests that the very concept of an easy to apply watermark that is not visible to the naked eye could then be, misused to create these false positives that render it even less useful in the first place.
Speaker 2: But the my mind immediately goes to, I feel like you could train an AI to detect and remove these AI generated watermarks. A little bit. Yeah. Like, you get a big training set of AI images that have the watermarks and a big training set of images that don't have the watermarks. You feed it in and then train it up and be like, okay. Here's a watermarked image. Yeah. Is this image watermarked? Yes. Remove the watermark. Boom. Done.
Speaker 1: Yeah. Generate
Speaker 2: I feel like AI would be great great at doing that.
Speaker 1: Yeah. Your solution to AI just happens to be the kind of thing that, AI would be really, really great at undoing. It's sort of a bad situation to find yourself in. In. This, yeah, it raises this question of this isn't the only one of these studies that's going on pretty much the second we realized we were entering a like era of watermarking being really important. A A bunch of different studies kicked off. There's a University of California one, a Santa Barbara, Carnegie Mellon. They have all found very similar things to Sohail's study, which is that these are susceptible. The interesting idea here is that I think maybe these just, we start thinking of these not as like a silver bullet, and as a small part of a much broader way of addressing misinformation and copyright that are invited by this new technology. It's sort of like a means of harm reduction against the really, really low effort AI fakery. You could imagine a super it's not the kind of thing you'd wanna trust for everything, but, like, a filter almost on a social media platform or an email client that is just parsing for the really, really low effort stuff, but that you shouldn't be relying on as, like, a real true test of whether or not something was authored by a human. I remember when ChatGPT first came out, there were tons of teachers running, ChatGPT essays through essentially these tools that came out within days of ChatGPT that were tasked with like checking whether or not it was AI generated. And we all kind of quickly had this reckoning that, like, this is not this put put this tech back in the oven. It's not ready yet. Mhmm.
Speaker 2: It's like the the it's the same as the traditional watermark. Right? Like, it's essentially a road bump. Yeah. Like, if you wanna get rid of it, you can. That's
Speaker 6: a great
Speaker 2: point. Like Adobe Photoshop's Smart Fill probably gets rid of most
Speaker 6: of them.
Speaker 2: A 100%
Speaker 1: of those.
Speaker 2: And it's Exactly. So but it's essentially you have to you have to cognitively take the step to violate the copyright.
Speaker 1: Yeah.
Speaker 7: And I
Speaker 2: I guess that's probably the biggest the biggest checkbox for it is, like, being able to show that people actively did do something to bypass the copyright when you do find them. The idea of having some form of like, images are pixels. Right? Like, they're just data points, Literally, just a grid of data points, run through compression algorithms and a bunch of other things depending on what type they are. But the trying to put something into a grid of data points that can't be either a detected or b removed is very hard.
Speaker 1: Mhmm.
Speaker 2: If you know what you're looking for, very easy. Mhmm. So, yeah, I I it's it's gonna be a real tough one, you know, unless they're also hashing the file and providing the, like, you know, checksum for the file and you have to validate that the file has been modified.
Speaker 1: Mhmm.
Speaker 2: Then it's very, very tough.
Speaker 1: Yeah. Because I have such a deep disrespect for my own time, I end up watching a lot of, like, tech announcements and press events and stuff. And I'm always intrigued by like the recurring narratives that occur when companies have to announce new technology, let's call it. And I'm intrigued to see, I imagine there's a lot of pitch decks and public presentations that are sitting in like private drives right now that spend a lot of time talking about security and artificial intelligence. And I would imagine that if I could do a search for the term watermarking, it would come up a lot. And I'm very intrigued. The thing I wanted to take away from this story is like, almost like loading it into my brain, so that the next time I see a big company talking about watermarking and how watermarking with AI will only make this more secure or will make misinformation harder. Not to necessarily say, well, that's just a lie outright. Like, I don't think it's that. But to, sort of, like, carry a little bit more skepticism about that as we continue to wade into this AI generative art era.
Speaker 2: Well, on those same drives with those same slide decks talking about watermarking, there's probably slide decks full of artificially intelligent or AI generated images and AI generated copy. Totally. Maybe even in the same slide deck. Yeah. It's like every pitch deck I've seen in the last year has had some form of AI generated images in it and some form of copy that's been accelerated, edited, or entirely generated via Sure. AI. So I think the I think we're there, you know?
Speaker 1: We're there.
Speaker 2: With Microsoft's I think we're there. Like, I know Microsoft's looking at building I'm not even looking at is actively, if not getting ready to deploy, if maybe it has deployed and I just don't use Microsoft Office enough, but they are generating essentially an assistant inside of Office that will fast track tons of things for you, whether it's writing an email in Outlook, editing something in in Word, maybe even smart, like, smart figuring out what your spreadsheet design is looking to do and then just finishing it for you. So I think it's going to be, I think it's we're there. I think it's going to be good, but it's going to be bad. There's going to be bad things too, just like everything. Like if you look at this entire podcast, it's because we have technology. And technology, I think, is largely seen as good, but there's some bad there too.
Speaker 1: Oh, definitely. So Yeah. I'm, I think you are right about all of that. I'm very intrigued to see what the next I think it's I'm fascinated to see as it gets baked more into the stuff we're already using. Like, I've become a a chat GBP user for a bunch of different things. But I think for a lot of people, it being woven into the places they're already being productive, Google Docs, Microsoft Office, that's gonna be when it either does or doesn't become a big part of people's habits. Because, like, I'm this is one of the first pieces of technology where I'm realizing that, like, I don't know, the little bit of a bubble that I'm in when it comes to new technology. Like, I have friends who like tech. I like tech. We do a tech show. And in my mind, ChatGPT showed up, Midjourney showed up. I'm like, this is all anyone's gonna be using in six months. And over six months have passed, and a lot of people in my life are not regularly using these tools. Like, okay. Mhmm. There's there's, there are different there are different threads of tech users, and being cognizant of that is something that I don't know. It's been a really fascinating process watching a big, big tech shift happen and realizing that it's not all happening at once.
Speaker 2: I was, I was sitting in a friend's backyard a couple months ago. We were having a beer, and their brother showed up, and their brother's fiance, and she was in university now. She's still in university. She's doing a master's or something. Sure. And she was talking about how she uses it to summarize her readings.
Speaker 1: Right.
Speaker 2: Like, you just copy in digital text. So she's gotta read 200 pages a week or something.
Speaker 8: Mhmm.
Speaker 2: She just dumps it into ChatDpT. Sure.
Speaker 1: She's
Speaker 2: like, summarize this for me, and bang. Yeah. Out comes, like, you know, three or four pages of, like, you know, everything that you need to take away from it. It's like, wow. That's a that's a that's a use case.
Speaker 1: Oh, yeah. It's funny. I, I thought I'd figured out was a total tangent. We talked about AI hallucinations a little while back, and those are particularly bad when you're asking it questions, that it's trying to derive the answer from its own internal data set. Like if you ask it about a law or a health situation or anything like that, it might just make things up. And I'd started to feel like I had sort of found the workaround to that, which is that always provide it your own data set. Yeah. You can always be bringing in your own information and saying, I want you to work off of this. Beyond just the ability to quickly look back up at the data and make sure something is accurate, I also just found it got much better results. I got my first full blown hallucination using that technique.
Speaker 2: Really?
Speaker 1: It was like kind of spooky to me. I was looking at it, writing full on the wrong thing. Like it was just going on a total fantasy, unrelated to the text I had just provided it. It was really weird to watch. Like, because Chat TvT doesn't just sit there with a loading bar and then show you the presented text, you get to watch it type. There was something so creepy about watching it just sort of like wax fantastical and make crap out
Speaker 2: of me like, dog,
Speaker 1: I just read what I gave you. And I'm just asking you to synthesize it into notes so I can remember it later. What are you what is any of this? So I like I want to just keep banging the robots stream of electric sheep. Like, they're making shit up still. Don't trust it yet. Like, use it. It's a powerful tool. But if there was a calculator that just dot five plus five equals nine sometimes, like, you'd be very cautious using that calculator.
Speaker 2: Yep. Hey. There is, I know we're, like, wrapping up here and just kinda shooting it. So so here's a here's a good one. Remember when we were talking about video game hackers and free to play games and how they're Oh, yeah. Run with video game hackers? So Counter Strike two released. The new version of Counter Strike came out, and they have essentially instituted kind of what I said. They put in a prime status upgrade. So for, like, an additional, like, $20, you become a Prime player, and Prime players play with other Prime players. So essentially Woah. Essentially, they've created a situation where you've essentially paid a cheating bond. You get a few other little perks with it, but at the end of the day, it's the biggest change is that prime players get matched with other prime players. And because you've paid for it, now there's a good chance you're not going to cheat.
Speaker 1: Mhmm.
Speaker 2: So it's it's a cheating bond. Yeah. So anyway, I just thought it was cool as a as a old school Counter Strike player.
Speaker 1: I remember that idea that you had. Yeah. You a cheating bond. That's a really good way of putting it. Is Counter Strike two out or is that no. Counter Strike two is it's been out forever or, like, a long time. Right?
Speaker 2: Well, yeah. Yeah. But they just did a full rebuild of it. So, like, I think it was a few weeks ago, two, three weeks ago, the new new That new new. The full CS GO went away, and Counter Strike two came out.
Speaker 1: Oh, okay. Okay. Because I was like, I thought I thought it came out in, like, 2012, and then I'm seeing 2023. I was confused. That's fascinating. I think that that makes a ton of sense.
Speaker 2: Yeah. It's a game that's had Valve anti cheat. Like, Valve anti cheat was created for Counter Strike, essentially. And it's it's got a very active anti cheat, but there's still people that cheat and hack in it. So so this is just a way to get around that. You know, so many of these free to play games are just overrun with hackers and cheaters that, you know, hey, you love this game? Do you love it enough to pay $20 not to get frustrated every time you die to a cheater? It's like, yeah. I do. Interesting. So Yeah.
Speaker 1: Bring it up.
Speaker 2: Hotlinehacked.com. Make sure you go
Speaker 1: to it. Final ring of the bell, Scott. Hotlinehacked. What is it? Where do
Speaker 2: they go? What should they do? Go hotlinehacked.com. You want to call the number and leave us a message, and please don't use this just to send us weird things.
Speaker 1: Yeah. Nothing good.
Speaker 2: There's also an email in there that goes to an anonymized email box that we're gonna go through. Please don't send us malware. Elf, we're super sorry we don't know how to pronounce your name. Please don't use this as an attack vector. It needs us. Yeah. Send us send us some stuff if you're interested, if you've got a good story, if you've done something or if you've seen something or if you allegedly know of something, we'd love to to hear about it. And, if we think it's good, then, you know, maybe it'll be in an episode coming up.
Speaker 1: Stoked to hear from you. Thanks for listening to another one. Thanks for making it to the end, and, we'll catch you soon. We'll catch you on Halloween with a very fun episode of Halloween Hack.
Speaker 2: Oh, yeah. Special guest.
Speaker 1: Special guest.
Speaker 2: Special guest.
Speaker 1: Looking forward to it. Catch you in the next one.
Speaker 2: Take care.
Speaker 6: You can't reason with the sun. Trust us. We've tried. This summer, it's time to put that angry ball of fire on mute. Columbia's Omni Shade technology is engineered to protect you from the sun's harsh rays that can burn and damage your skin. The sun is relentless, but so is our gear. Level up your summer at columbia.com to spend more time outside and less time slathering on aloe lotion. You're welcome. Columbia, engineered for whatever.
Speaker 7: Your team just added its sixty seventh AI tool and also your sixty seventh security blind spot. The good news, the Vanta agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over 16,000 fast moving companies like Ramp, Cursor, and Harvey, who are shaping the future with AI and staying ahead of AI risk. Get started at vanta.com.
Speaker 8: Athletic Brewing Company crafts award winning nonalcoholic beers for those who wanna be part of every round. With over 185 flavor awards, they're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company fit for all times.