episode.ascii — live render
● episode

FraudGPT + Chip Wars + Hacking Poker Machines + The Problem with Credit Bureaus

TL;DRFraudGPT and WormGPT are black-market AI tools built on open-source models, stripped of safety guardrails to help users write phishing emails and malware. One developer, Rafael Morez of Portugal, was identified by Krebs on Security.

In this chat episode we discuss the new world of sketchy ChatGPT alternatives like WormGPT and FraudGPT, take a brief detour into the looming chip wars, before bringing it home with stories about a poker hacking scandal and a telegram bot where you can buy social insurance numbers.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Large language models like ChatGPT and Bard have guardrails. There's stuff they won't do, things they won't say. Just to make sure this was still the case, I asked, ChachiPT, tell me how to defeat my nemesis. And it very politely said, if by defeat your nemesis, you mean overcoming a personal or professional rival or challenge in an ethical and constructive manner, here are some guidelines. To which I clarified, no, like, I want to destroy them. Chat GPT Bard, they'll all give you some answer like, sorry, I cannot and will not promote or provide guidance on causing harm or engaging in destructive behavior. Guardrails.

Speaker 2: I feel like there's a weird like, it's in its own moral and ethical quandary in the fact that it is kind of its existence is semi destructive to lots of people.

Speaker 1: They just stop being able to answer any questions. They're like, I'm gonna put people out of work. So for that reason, I can't engage in any of this.

Speaker 2: Yeah. I would love to help you write your copy for the review of the Samsung television, but this should just be a Fiverr job that you paid somebody to do. So, here's a link to Fiverr. Take care.

Speaker 1: I would like to see that GPT model. But we're all familiar with this in language models. We're really familiar with it in generative AI in general. There are guardrails against what it will say and what it will help you do. But pretty much the second you're introduced to multiple tools, all with roughly the same boundaries, curiosity invites the question, is there one without those boundaries? For example, one that you could give the prompt, write me a Python malware that grabs a computer's username, external IP address, and Google Chrome cookies, zips everything up, and sends it to a Discord webhook that would get a result. ChatGPT Bard, they obviously won't do that, but one could. Brief detour. Hackt has a Discord. And two buds there, Zero and Ratsec, shared these two different stories back to back in the story ideas channel about two products named Accurately FraudGPT

Speaker 3: and WormGPT.

Speaker 1: And you're really getting what's on the box with these things. They're large language models that'll let you do computer crimes. That Python malware prompt I said earlier, that's from Wormgpt. It's the example when you go to the site. So let's take a look at a couple stories this episode, but we'll start there, with the ever evolving landscape of sketchy large language models, on this episode of Hacked. How are you doing, Scott?

Speaker 2: Hi. I am tired, Jordan. How are you?

Speaker 1: I am wide awake.

Speaker 2: I I have this problem Yeah. Where I am exhausted from a long weekend of playing in the smoky sun because there are forest fires everywhere, so there's bad air quality. Yep. And the coffee that I have in my espresso machine is tragically awful to the point that I won't even drink it. So I am uncaffeinated

Speaker 1: Oh my god.

Speaker 2: And exhausted.

Speaker 1: I don't know if you know this, but that would make this the first caffeine free podcast. Wow. Not of our show, but full stop. I think there's 3,000,000 podcasts in the world that that this is the first one.

Speaker 2: I this is definitely the first one I've ever ground. Like, there's no chance that

Speaker 1: I'm literally holding a cup of coffee at this moment.

Speaker 2: Any are you? Jesus.

Speaker 1: Yeah.

Speaker 2: Envious. Envious.

Speaker 1: It's not good coffee.

Speaker 2: It's rubbing into my face at this point.

Speaker 1: I can't stress how bad this coffee is, but I its volume is what I go for. I I make, like, an iced coffee craft the size of your head, and it's just crushed through that in two days. It's not good. It's not good behavior. But you know it is good behavior.

Speaker 2: Oh, tell me more.

Speaker 1: Supporting text storytelling and news at hackedpodcast.com.

Speaker 2: Oh, that is that is great behavior.

Speaker 1: That's fantastic behavior. That is really a pre deeply appreciated behavior.

Speaker 2: And and people like Juan Pablo Gomez Postigo, I'm hoping I got that right. If I didn't, I apologize.

Speaker 1: You did. Great behavior. We really man. We really appreciate that. Kayla Cotton, it means the world to us. Thank you so much. Tane?

Speaker 2: Tane. Amazing behavior.

Speaker 1: Tane. Nothing but Tane. And then finally, Ross McAdamney. Thank you so much to all our new supporters on Patreon since the last episode. Your support means the world to us. You know? If you like stories and news and conversations about tech and how people use it and all the strange things they get up to with it, you should join those great people. Hackedpodcast.com redirects to our Patreon. That's how you can jump into the Discord where we got a bunch of the stories for this episode. But it's also just a great way to support the show, help us make more stuff, have more interesting conversations, do deeper dives. Totally. So, again, if you wanna support the show, hackedpodcast.com. Boopity doop boop boop. I'm just gonna start leaving the boopity doop boops in here, because for years, I've been removing both of us doing weird little musical fills as transitions and adding in, like, musical fills as transitions. And I'm just, you know, mowing over the same spot twice for no reason.

Speaker 2: That's true. We could just actually get complicated, you know, transitions that we make, like maybe some small musical instruments that we play with our mouth.

Speaker 1: Oh, sure. Do it on mic. Yeah. Like a harmonica.

Speaker 2: And just do it do it live. Just do it live.

Speaker 1: Just do it live. Just shakers and gongs and stuff. A little bong card. It's very old school. I feel like in, like, the sixties on NBC, there'd be just a dude sitting next to a gong and a xylophone every time they needed to transition.

Speaker 2: Well, remember

Speaker 1: It was his job to go ding, ding, ding.

Speaker 2: Remember when we had the little mouth harp in the office? And, I I Oh, that thing. I got I got pretty good with it. I'm not gonna lie. We could You,

Speaker 1: I say this affectionately, could not handle the responsibility of having that mouth harp. That was there was a good two calendar years that just firing at all times just outside of, my field of view. And I think that's also when hoverboards were really popping off, so it was, like, mobile. It was this, like, this mouth harp ripping back and forth around me. It's good times.

Speaker 2: Yeah. We have

Speaker 1: Good times.

Speaker 2: We have a playful office. Let's just say that. We We have a playful office. So where do we wanna go with the worm and the fraud and the GPTs?

Speaker 1: With the worm and the fraud. Let's talk about worm GPT and fraud GPT.

Speaker 2: Let's just talk about I just can we just start one level up? I just wanna talk about Mhmm. Because I'm assuming, and maybe this is my assumption, that these people don't actually have their own large language models, that they've just figured out a way to get around the bumpers on the the real ones. Maybe I'm incorrect in that. Sure. But

Speaker 1: so there there's a lot of different products being discussed here. And as we will discuss, I think their products have varying degrees of, being real. But generally speaking, I think a lot of them work on open source language models. Yeah. So there there's a couple different models that are just available for anyone to use. And the question is how much data you then have to train it on. The model is one thing. The training set is another. It's my layman's understanding of this whole thing. I know

Speaker 2: WormGPT uses the GPT j model. Yep. But they actually trained it using CHAD GPT, which just tells me, like like, that's just an interesting like, you're using another model to train a model, but then they've been layering in their own data and and stuff on top of it. So it's almost like they're to me, it it just reads like we've wrapped chat t p t, and we know the prompts to get it to make things that it shouldn't. That's at least how I feel about it.

Speaker 3: Sure.

Speaker 2: But I'm not sure if that's true.

Speaker 1: I think there's probably ones that work that way, where you're basically just getting a a mishap GPT wrapper. But let's start kinda where you have with Worm GPT. A bunch of places have covered this, but Krebs on Security, the OG, did, I think, the best job, and he broke the identity of at least one of the devs. So depending on when you first learned about it, Worm GPT was either a no guardrails GPT tool explicitly for black black hat hacking, or if you learned about it later, it would present itself as, you know, a privacy focused, slightly more uncensored GPT alternative. There's been a bit of a rebranding, which we'll talk about.

Speaker 2: Even though

Speaker 1: Even though.

Speaker 2: Even though on the front page of their site, the little image that pops up is write me a phishing email, and bang, it responds with a phishing email. So it's like, you know? Yeah. They know they know who their

Speaker 1: market is.

Speaker 2: You know?

Speaker 1: I didn't say it was a good ruse. So, the story seems to start with a post from a user called Last, on a platform called Hack Forms, advertising this new product, retailing for for between 500 and €5,000, Introducing my newest creation, Worm GPT. Quote, this project aims to provide an alternative to chat GPT, one that lets you do all sorts of illegal stuff and easily sell it online in the future. Everything blackout related you can think of can be done with Worm GPT, allowing anyone access to malicious activity without ever leaving the comfort of their home. Again, all sorts of illegal stuff is pretty important language there. So some security researchers try it, and you can definitely write a very boilerplate phishing email with it. It will do that. That guardrail does not exist. That account, last, traces back to an older username to another older username which had been used on Instagram connected to a guy in Portugal named Rafael Morez. He says he's open about his involvement in the project and says he's one of several people working on it. Graduated from a polytechnic institute in Portugal, says he's about, like, a third of the team. Roughly 200 people have, like, purchased the service to date according to Murais. And he emphasizes that his primary motivation isn't financial, but, to serve the community. Quoting from that Krebs article, I don't do this for money. It was basically a project I thought was interesting, and now I'm maintaining it to help the community.

Speaker 2: Interesting. His the whole presentation of it, like, when he makes the initial forum post about it, like, just even the use of the word illegal to me is just like

Speaker 1: Yep.

Speaker 2: I just wanna say it's I don't know what the right term is. It's not immature, but I would say it's it's unrefined. Like, normally, you would say Yeah. You can do all sorts of stuff that had previously disallowed on other models. Oh. You don't just explicitly come out and be like, yo, we're here to break the law.

Speaker 1: Yeah. Like Well, and you can see him get to that conclusion in the wrong order. Mhmm. So there's this product. It can you you buy the license through Telegram, but the media picks up the story, I think in part because of that sort of inflammatory language that you identified. You know, it's self identifying as a black hat tool for illegal activity. Yep. So it gets a ton of attention. And all of those stories, they do two different things. The first is they respectfully, they really hype up what you can do with these things, because I think there's a sense of, we've all seen how powerful chat g p t is. Imagine what an evil version of it could do. And that the stories kind of really sell how powerful this tool is, when really it's it sure can write a very serviceable phishing scam email. Right. So they're doing that as the new tool for hackers, but they're also, you know, shining a lot of light on an operation that is professing to be illegal, that is claiming to be a tool to empower people to do crimes. And you really get the sense that the people behind this tool get some cold feet, Because this is where we start to see a bit more of the rebrand, certainly in how he's talking about it to journalists and on some of the forums. Mhmm. Really negotiating how uncensored they're saying this thing is, what they're saying you can do with this. Quoting again from that Krebs article, we are uncensored, not black hat. From the beginning, the media has portrayed us as a malicious large language model when all we did was use the term black hat GPT for our Telegram channel name as a meme. We encourage researchers to test our tool and provide feedback to determine if it is as bad as the media is portraying it to the world. And, really, I think as with any project that starts with the removal of those guardrails, they're now in the process of slowly adding them back in. Because, like, say you remove the guardrails to allow people to write phishing emails or write some malicious code, you still probably have a bunch of other guardrails that you want to leave in. Because even in that kind of black hat cybercrime community, there's still a ton of stuff that to their credit, they will not tolerate. Quote, we have prohibited some subjects on WORM GPT itself. Anything related to murders, drug trafficking, kidnapping, child abuse, ransomwares, financial crimes. We're working on blocking business email compromise too. Our plan is to have WormGPT marked as an uncensored AI, not black hat.

Speaker 2: The easiest way to get around this is you just say that you're making a research tool.

Speaker 1: Totally.

Speaker 2: It's like you'd be you're just like, no. We wanted to take the bumpers off because we wanted to incentivize research. Also, like, we're doing cybersecurity research. Yeah. Trying to see if these models can truly become compromising threats.

Speaker 1: Yeah.

Speaker 2: And then boom. All of a sudden, you're a pro academic researcher

Speaker 1: Yeah.

Speaker 2: And not somebody who's like, we're gonna do a bunch of illegal things and give us money to help you do illegal things. It's like, well, now you're now you're an enemy of most people. So

Speaker 1: Yeah. You could do that by being the people that developed the open source GPT six, b or whatever it's called that this thing is probably built on top of. Like, that is an open source research project

Speaker 2: Mhmm.

Speaker 1: To empower people to make their own training models. That's that's kinda what you're describing. But the second you say, we're gonna make our own version of that, dump a bunch of, you know, stuff that we scraped off the Internet into the training set and monetize it, yeah, you you you've you've crossed some kind of a delta. Because, really, why would anyone pay for it unless it can do something that the other ones explicitly can't, and the only thing is the other ones explicitly can't do are crimes.

Speaker 2: Mhmm.

Speaker 1: WormGPT seems to be stuck between trying to court black hat users and trying to appear publicly as this, like, privacy centric GPT alternative. Meanwhile, that user from the very beginning, last, is still posting on places like Hack forums and more intense, like, cybercrime forums like Exploit, saying that the product, with the product, you can, quote, easily buy worm g p t and ask ask it for a Rust malware script that he says will work against most antiviruses. So kinda talking out of both sides of the mouth a little bit on this one. I don't

Speaker 2: know if you saw it, but, Python is coming to Microsoft Office. Mhmm. So they're putting they're putting Python in Excel, which should be very exciting Interesting. As a as a in in a vector of attack. Sure. Now you have, you're taking out the old, like, kind of visual basic style code and stuff that the the macros are written, and you're actually introducing Python

Speaker 1: Interesting.

Speaker 2: Which these tools are good at writing now. So should be should be exciting times as as Excel figures out the bumpers to put on

Speaker 1: the

Speaker 2: macros and stuff and and whether they can be bypassed. So

Speaker 1: Yeah. I think it's gonna be in the same way that the last decade was a really important time for the, like, bumpers of content moderation on social media. Mhmm.

Speaker 2: I think

Speaker 1: we're gonna spend a good decade watching people figure out the, like, guardrails around prompting. Around AIs. Won't let these things do. Exactly.

Speaker 2: Yeah.

Speaker 1: Maybe we'll wrap on on WormGPT before moving on to fraudGPT here. And Krebs asked a very important question that I hadn't really thought of, which is, oh, what are some white hat uses for WormGPT? To which Morris replied, you know, you can use it to fix issues on your website related to possible SQL problems and exploits. You can use worm g p t to create firewalls, manage IP tables, analyze network code blockers, do math, anything. And it is worth noting that if that is the art like, that is the product that this is sort of publicly claiming to be, that the guardrails on much more advanced tools like ChatGPT and Bard do both of those things just fine. Mhmm. They will help you do security programming to the best of their ability. WormGPT's niche either is or isn't the wormy stuff, the the underground kind of things, and I'm really curious to see how they sort of try to navigate that rebrand.

Speaker 2: Yeah. I feel I feel like you just take it down, put it back up instantly as a cybersecurity research tool Yeah. And move on with your life.

Speaker 1: Exactly.

Speaker 2: You know? Every everybody likes to push the limits of tech, and everybody likes to do research.

Speaker 1: Totally.

Speaker 2: You know, discover things they can't discover. And, you know, I don't know. To me, that was just a branding

Speaker 1: error. Well, if we're calling it Worm GBT was a branding error, let's talk about fraud GBT. So Wired did a big piece on this, and I think we can spend a little less time on it. But, really, the big idea that this story brings up and it's not making necessarily a claim about fraud GPT, but it really is evoking the idea that one of scammers' favorite targets are other scammers, And that, download something to access this flashy new AI scamming tool is pretty great bait for scamming scammers.

Speaker 2: Seems to be a running trend in in our topics these days, the scamming of scammers.

Speaker 1: It really does, doesn't it? Scamming the scammers. It's, as odd as targets go, they seem to be a pretty good one. So, security researcher Rakesh Krishnan over at Net and Rich, sort of seemed to discover this product. It's being sold on various dark web forums and Telegram for $200 a month or $1,700 a year. And there's uncertain evidence on this one of any actual buyers or users even as it's been getting a lot of, media coverage. Sergei Shekevich over at Checkpoint kind of made a distinction between WORM GPT and Fraud GPT, which is why I wanted to talk about them both. Worm GPT is an actual tool that you can use, and he is quite skeptical about Fraud GPT.

Speaker 2: He he actually just thinks it's a fraud?

Speaker 1: He thinks it might actually just be a I don't wanna put words in his mouth, but, I can understand why someone would create a fraudulent version of one of these tools to try and scam people that want a fraudulent version of one of these tools.

Speaker 2: And I feel like they've just come straight up and given it the proper name, if that's actually the case. If it is just a scam, you know, calling it fraud GBT, you could be like, well, you know, we we called it a fraud. Like, you know, this is kind of buyer beware. This is not you. Totally. In kinda looking into fraud GPT

Speaker 1: Mhmm.

Speaker 2: It seems like there's not a ton of there's a lot of discussion about it, but there's no it's like it's not as public as Worm GPT, so you really have no idea. You need to almost find somebody who spent the money on it to figure out what it's capable of and what it is or what you know, or spend the money, you know, yourself, which I won't do given the branding name of it. Precisely. But but, you know, you know, you have really no idea what it is capable of. Maybe it's even better. You know, like, I've seen seen some of the examples and stuff of of people, like, making phishing websites, using it, and stuff like that. But, you know, that also seems like something you could pretty quickly do

Speaker 1: with Totally.

Speaker 2: Use source and chat GPT.

Speaker 1: So What fraud GPT really suggests to me is a future where you know, we go back to Worm GPT's guardrails, the one that they're saying they are adding back in. It won't help you do a murder or traffic drugs or kidnap or abuse, those kind of things that are outside of the scope of cybersecurity. It's gonna be the very strange world of people creating fake AI tools to help people do some of the worst things people can do to to target the people trying to do it. It reminds me of the, are there any actual, darknet hitman episode that we Yeah.

Speaker 2: Yeah. Right.

Speaker 1: Where it's like there aren't really hitmen on the dark web, but there's a lot of people scamming people who wanna hire hitmen on the dark web. And I think that that's probably gonna be where this goes in the long term. There will probably eventually become some, like, amalgamation, and one of these things will emerge as the actual actual successful blackout one, and law enforcement will inevitably go after it. But there will be a great number more scam versions of GPTs and AI tools that don't really do what they do or do a pretty bad job, but are really more about targeting the people that want to use those tools.

Speaker 2: Yes. Yeah. I agree with you. And I think the other thing too is that I think the yeah. It's hard to justify that you've spent $1,700 on something called fraud gbt when you contact PayPal and say, hey. Can I reverse this transaction? You know? Same kind of thing as the hitman thing. Hey. You wire wire somebody $20,000, and then you call the call your credit card company and be like, well, I was actually paying for an assassination that didn't happen, so I'd like my money back.

Speaker 1: It says here you want your money back for a purchase of something called murder GPT. What's that about? And you're like, oh, it's really what was on the box. I was just looking for advice to do murder. Jeez. Yeah. That's definitely gonna be a thing.

Speaker 2: It I there's there's a like, I wish I wish I wish I knew fraud GPT. I wish I knew if it was actually just a fraud, if it was a scam. Because I I gotta say, if it is, I I respect the branding, But they just came out straight. That's true. And they're just like, nope. This is a fraud. Yeah. Send us money, and we'll give you access to this tool. Just kidding. You got conned.

Speaker 1: It's like, oh, it's GPT for doing fraud? They're like, we did not say that. We said it is a fraud at GPT. I don't know how you're angry at us. Thanks for the bait.

Speaker 2: You've been scammed. Good day. The whole GPT AI world, like, I know it's just kinda blowing up. Like, if you watch any investment news, like, it's the number one trigger for what's going on. Like, NVIDIA's stock pops. Sure. Like, the you know? Boomed. As the

Speaker 1: Just talking

Speaker 4: to Nick

Speaker 2: last year. The Bitcoin craze hit and died, and all of a sudden mining was no L'amour, everybody was like, oh my god. NVIDIA's shares are gonna die, and then they, like, quartered. And then boom, all of a sudden, it's like, AI is powered by NVIDIA chipsets, and then it's bang. It's straight back up. I know Microsoft's

Speaker 1: Totally. There's the

Speaker 2: Microsoft's working on an AI powered assistant, like a proper large language model assistant that integrates across their Office suite as well as the Azure platform. So it's like yeah. AI is AI is here. We are in the we are in the the moment, and it's gonna be interesting to see if it becomes, you know, three three d TV or whether it's gonna become,

Speaker 4: you

Speaker 2: know, something else. So it'll be it it'll be I don't know. I'm excited by it. I think it's gonna be cool, you know, especially if they start developing it into business. You know, like, we can look at the we've talked about this before, but, like, when you look at, you know, productivity from a unit of labor as we go back into economics as I often do. Sorry, people.

Speaker 1: Sure.

Speaker 2: The the productivity constantly you know, computers make us more productive. All of a sudden, we have networking. All of a sudden, we have, you know, know, this. We have cell phones. We have, you know, microcomputers we carry with us, and it just makes us more and more and more effective per unit of human labor. And I feel like with gross adoption of these kind of things, like, when I open Google, get an email, and hit reply, and it's pre drafted me a response based on the content of the email that I got, like, that's a product like, a productivity and answer. Maybe I have to edit it, but it's still a lot better than if I had to write it myself. Yeah. And it's like I just feel like we're we're going that way, so it's gonna be exciting times.

Speaker 1: Yeah. Twelve months ago, an email that you might have had to tweak still would have had to have been generated by, like, a person in your employment.

Speaker 2: Yeah.

Speaker 1: So there's really no pretending we haven't crossed some kind of a line.

Speaker 2: Yeah.

Speaker 1: Even if we are in that kind of, like, trough of disillusionment of what they can do that, oh my gosh. Eight months in, they haven't replaced everyone. It was all made up. It's like, no. We're we're at the beginning of a very, very, very long tail with these things.

Speaker 2: We've been using kind of AI and statistical modeling and stuff like that for spam prevention for decades now.

Speaker 1: Yeah.

Speaker 2: And I feel like we're we're getting to that point where we're gonna start to see these models. You know, we might actually be able to use email again soon. You know, we'll have cybersecurity AIs

Speaker 1: that Yeah. Sure.

Speaker 2: You know? Yeah. And they might also any links in an email, they'll open in a sandbox, do a full, you know, sweep of the code on the other side. Like, they'll get the source of the website, sweep it, verify all those links are valid, and there's nothing malicious about it, and then allow us to open those links, or else they'll just remove them or remove the email entirely. Or Sure. So so I think the I think the counter side of things writing crappy phishing emails is that we might get some AIs that that do some good for us and stop us from being phished.

Speaker 1: I wouldn't be mad about that. No. I think we're gonna need to not to get ahead of ourselves, but I recently heard the term. I'd probably heard it before at some point in my life, but I really clocked it the other day was I I heard the term chip wars the other day. Like, that's a that's a fun new expression I'd never really thought about before. And I think at some point on the show, we're gonna have to do a deep dive into, like, the ecosystem of you you brought up NVIDIA, but, like, chips and semiconductors. Yeah. Because as we move into this, like, AI Gold Rush era, those are the pickaxes. Wow. And they're this, like, physically produced commodity that is deeply political, deeply geographical, and is probably gonna be the, like, focal point of some, like, very serious conflict over the coming years and decades, and I wanna understand it more.

Speaker 2: Well, do we wanna just tack that onto the Chatty Chat app so we can have a brief chat about it? Because I've been following it.

Speaker 1: I'm very intrigued. Well, why don't we, why don't we kick it over to commercial? And when we come back, we'll we'll talk poker, we'll talk credit checks, and we'll talk chips. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify ify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 2: I wrote

Speaker 4: a little song to remind you, Choice Hotels gets you more of the experiences you value. The Cambria Hotel's got it all. A rooftop bar, have a ball. Cocktails up here feel just right. Is Champery your home mazing? Alright. Bring a date, your teen, or even your mom. Book direct at choicehotels.com. See you on the roof.

Speaker 3: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 5: This episode is brought to you by Fox one. Watch all 104 matches of the FIFA World Cup live in four k for just $19.99 a month with three days free. Build your own multi view, choose up to three streams, and follow player spotlights. Stay on top of every moment with live stats, highlights, and instant replays. The FIFA World Cup, streaming live on Fox one, offers a subject to change. See fox.com for complete terms and conditions.

Speaker 2: Aside from just the AI, you know, war and the pickaxes as you were mentioning in the in the in the caves and mines of artificial intelligence, you know, chips are chips are in COVID, obviously, you know, there was massive logistical headaches and issues. So, like, the fact that vehicle prices went crazy and you couldn't get vehicles and used cars were selling for so much. Mhmm. You know, you had entire auto dealer lots full of pickup trucks that you couldn't you could buy, but you couldn't take because they were still waiting for some of the primary chips to go in them. So it's like it's not even just in the AI battle. It's in everything now. Like, there's chips in

Speaker 1: Totally.

Speaker 2: I have 40 devices on my desk, and each one of them has probably Every

Speaker 1: single one.

Speaker 2: 10 chips in them, different types of chips. So, yeah, I think I think the I think that COVID shined a spotlight on the fact that, wow.

Speaker 1: Yeah.

Speaker 2: These are actually very important now to not only

Speaker 1: Yeah.

Speaker 2: Daily life and productivity, but national security and the economy. So all of a sudden, they became a a point of political politicization around them is, oh my god. So the America has been incentivizing, companies creating essentially semiconductor chip factories in The States. Mhmm. So I know Texas is getting a bunch of of new development in that regard, new companies opening and moving, and and kind of, quote unquote, stateside, development of chips and and, you know, manufacturing of them. So it's it's a huge deal.

Speaker 1: Yeah. The, the question that got me onto it, and this is maybe spoiling some of the early writing I've done for that little chipped series I wanna do.

Speaker 2: Oh, no.

Speaker 1: No. No. No. No. In a good way. Like, let's talk about it. Yeah. Because I I find it interesting was so it's like once you accept the premise that these these semiconductors are gonna absolutely everything, you kinda also then have the thought of, like, well, that means there's a great number of them. So, like, there's so so many of them. What would it mean if we were producing less? What would mean if they were they were the heart of a trade war? And the thing that I bumped into that I didn't really appreciate is that chips have a life cycle. Mhmm. And that felt like kind of a light like a light bulb going off for me. It's like they get older and they eventually die. The thing that empowers pretty much every piece of technology, every tool you use on a day to day basis has a life cycle. There's, like, really interesting science of why that happens. Electrons getting caught in these little loops that can just sort of, like, slowly degrade inside of a semiconductor. Mhmm.

Speaker 2: It's a

Speaker 1: bit above my head. But once you accept the prep like, the premise that this isn't just a product, it's a disposable product. It is it is a product you have to be constantly making new ones of because on a pretty short timeline, historically, the ones we have will eventually burn out. Yes. Maybe not today, maybe not tomorrow, but, like, eventually, they're not gonna work anymore. So you do even if you stop making them better, you still have to keep making more. And some of the biggest, factories and centers of production for these are in some of the most, like, politically contentious regions on Earth. Mhmm. And we sort of just, like, walked backwards into that problem

Speaker 2: Yes.

Speaker 1: That we're now trying desperately to work our way back out of. Yes. They're going to be the commodity we fight over, I think, over the next over the coming decades. Yeah. That's that's where this might go.

Speaker 2: Here's the here's the thing for me is that I'm I'm less I'm less in that camp. Oh, yeah? I think that there's a five year window here where people have realized how important they are Sure. The manufacturing of of chips and integrated circuits and stuff like that. And, yes, they do have a typically have a lifetime. Like, you're a synthesizer guy, and I know there's there's ICs and stuff and that can go in synths, chips that break, and they'll literally just crack sometimes. And then you have to unsold. Yeah. I think you're a Game Boy guy too, aren't you? So to, like, change the chips on boards. Yep. Anyway, the the the the thing for me is, like, I'm not like, they're not like lithium. No. Like, I'm more worried about finite commodities. The manufacturing creation of basic chips is pretty I don't wanna say it's easy, but it's

Speaker 1: It's a solved problem.

Speaker 2: Well well known at this point. Yes. You know, there's always innovations of it. You know? We're talking, like, I think NVIDIA is down to, like, five,

Speaker 1: Ridiculous shit.

Speaker 2: Yeah. Five yeah. Like like, super fine, which also probably just shortens their lifespan. Like, I have one of AMD's new chipsets, and I know that if you can get any extra heat on it, like if it's not cooled excessively perfect, it will actually destroy itself. So the anyway, that's a roundabout way of saying I'm not too worried about it. I think that I think that people realize how important they are to day to day life, and given the political uncertainty in the world for economic health, state health, security health, national security health, you need to make sure that you have them. Mhmm.

Speaker 1: Like, I

Speaker 2: don't feel like there's, like, a vault of them that we're gonna go to war for like oil because that is a finite commodity. It's like chips are like, we can make our own.

Speaker 1: Sure. Silica silica is plentiful.

Speaker 2: We just peep just peep people just need to make them. And that's what you're seeing in America right now where they're just like, okay. This is a problem. You know, here's x billion dollars, and we're gonna incentivize the development of this industry because we see this as being a potential future problem if we have a massive, contentious trade war with China. Sure. Like, Americans still need vehicles, and they still need computers and etcetera, etcetera.

Speaker 1: I certainly I I hope that's true, obviously. I definitely hope that that's true. I'm always impressed by the ways that countries and powered interests find it to, like, mess with each other the second they have control of, like, an important commodity.

Speaker 2: Yeah.

Speaker 1: So I'm I'm and I'm just sort of it's really dawning on me on how important this commodity is. So I'm I'm hoping I'm hoping everyone's chill about it.

Speaker 2: I the the the thing for me is I'm more I'm more hope that the humans that are in charge of making it less, making it more chill, I. E. The bureaucrats that are

Speaker 1: Yes.

Speaker 2: You know, in Washington and and other countries looking to create new industries for it, don't Sure. Mess it up because humans are the biggest Yes.

Speaker 1: I agree.

Speaker 2: Fault in this. So it's like I know that we can

Speaker 1: do it.

Speaker 2: I'm not too super worried about it.

Speaker 1: I agreed.

Speaker 2: It's just whether they drop the bag. You know?

Speaker 1: Yeah. Because it's a big bag.

Speaker 2: Yep. Yep.

Speaker 1: Wanna talk about poker?

Speaker 2: Yeah. I love poker. Should we just play poker? Should we have, like, a Just on trend poker night? Oh. Oh. That's fun. $5 buy in is in. Jump in the discord. Poker. If If you're into into a patron patron poker game, I'm super keen.

Speaker 1: That's pretty fun. It wouldn't work well in an audio platform, but we sure could do a video stream.

Speaker 2: Yeah. We just do a we just do a, like, an online tournament. That'd be fun. Anyway, digressions aside.

Speaker 1: So last September at Los Angeles' Hustler Live Casino, there was this big, like, kerfuffle in the world of professional poker. And to skim off a lot of details, a relatively novice player called a very improbable bluff of a veteran player. They made a call, wild odds, really bad ass for this shot they made, but they win the hand. And immediately, everyone says this is cheating to the point that there is, like, a a full on investigation of this this hand of poker, basically. Yep. And the investigation comes back clean. But in the postmortem, the, events investigators make this claim basically saying, if any cheating had happened, which it didn't, it wasn't anything hardware related. It would have been something social, a player collaborating with someone on the inside, which they had used the cameras and they disproven. But they were very adamant that, it wasn't a hardware compromise. Why? Because the Deckmate shuffling machine is secure and cannot be compromised. That was the claim. Deckmate, for anyone that doesn't know, is the most commonly used shuffling machine, in the world. And this event makes this claim. It is secure. It cannot be tampered with. And some guys at a security research firm took that claim personally. Recently, the Black Hat Security Conference was held in Las Vegas. And at that event, security researchers Tartaro, Nassim, and Shackleford from IOActive unveiled their findings on the Deckmate, this very prevalent automated card shuffling machine. What they found is that the Deckmate two, the sort of most up to date latest version of this product, does have a vulnerability. If a device is plugged into the exposed USB port on the Deckmate two, typically, it's like on the underside of the table sometimes, the machine's code can be tampered with. They were able to do this in a lab setting, allowing full control over the shuffler. Deckmate two features an internal camera that verifies the presence of all of the cards in the system. Intruders were able to access this camera to determine the deck sequence in real time and transmit that data via Bluetooth to a nearby device. And they emphasize that they this technique granted them pretty much total control over the shuffler, enabling them to protect every other player's hand. Read a little bit more about it. The hacking method can be applied to pretty much any card game, but it is super useful in Texas Hold'em poker, which I think was their case study based on the story that sparked all this. Mhmm. In Texas Hold'em, as you know, discerning the deck sequence allows for the prediction of each player's hand really regardless of their actual choices in the game. Even if the deck is cut by a dealer, a cheating player can deduce the card sequence as soon as the initial three flop cards are shown.

Speaker 2: Do you play poker?

Speaker 1: I do play a little bit of poker. Not a ton, but a bit.

Speaker 2: But you have played poker?

Speaker 1: I'm familiar with the basics.

Speaker 2: The the it's not really important to the to the story. The thing that I find most interesting about the story is that, like, you should never claim that something's unhackable. That's literally just telling Right. Right. A massive group of highly skilled, curious

Speaker 1: Yes.

Speaker 2: Puzzle solvers that there's a puzzle over here that they need to solve, and you're always gonna end up on the losing side of that usually.

Speaker 1: Yes.

Speaker 2: The Yeah. Yeah. I don't, obviously, like, their like, when you read about their kind of hack and their implementation and stuff, pretty sophisticated. The other thing you can't overlook is that the, like, in the initial incident

Speaker 1: Mhmm.

Speaker 2: Like, there's a lot of, like, if you've ever watched poker or been in any bar where there's this poker randomly on TV, which is the A lot

Speaker 1: of bars.

Speaker 2: There's obviously microcameras in the cloth or like along the edge of the tail, right? Because they see the or from the bottom looking up so that the production people can see the see the cards that they know what you have. And then they throw it into the computer, and it calculates all the odds, and you see all that stuff in real time.

Speaker 1: Mhmm.

Speaker 2: So there's, like, there's more technology here than just the Deckmates. Definitely. So to say that it couldn't you couldn't be hacked and there's no problems there because the Deckmates unhackable. It's like, well, there's so many other things going on at a televised poker table and so many people that that's a wild, wild claim to say that it's, well, the deck shuffler is fine. Yeah. And it's like, well, what about the other 38 fail points? Exactly.

Speaker 1: So the manufacturers of the Deckmate did respond to this demonstration saying there is no proof that one of these devices has ever been compromised in this way in a casino. The obvious response to that is that if there had been and it was successful, we sure wouldn't know about it. But what's interesting to me about this is if the idea is that, yes, this USB, if you were to plug into it, is vulnerable, but there are so many other security infrastructure elements surrounding these machines when they're actually being used that actually realizing that compromise is impossible. If that's the argument, what you're really arguing is that, yes, we are selling a vulnerable product, but its use is invulnerable for reasons that have nothing to do with us. Yeah. Casinos are invulnerable, but our device is is a very strange argument to me. There is a bunch of regulations surrounding this. Like, hashing functions are, like, regulated at a state level. It's like they've gotten the regulations have gotten quite into the technical weeds

Speaker 4: Yeah.

Speaker 1: When it comes to gambling tech, I guess. But IOActive argues that, like, this is the tip of the iceberg. There are pretty deep security issues in a lot of the stuff being used inside of casinos

Speaker 2: Yeah. Currently today. Any of those pieces of hardware

Speaker 1: Yeah.

Speaker 2: Like, how do you make something tamper proof? You know, we've been we've spent

Speaker 1: Well, here's the wild thing. The Deckmate one didn't have a USB drive. Look.

Speaker 2: Yeah.

Speaker 1: The first version of this product didn't have a port. They still found a way to compromise it, but they had to hack it open.

Speaker 2: Yeah.

Speaker 1: It's like, well, that's that's better. Because, like, maybe don't put a hole in it.

Speaker 2: Because the the other thing too is, like, casinos don't really care about poker. And, like, they care about it in the sense that people play it and they make money from it, but they don't care about the outcome. Interesting. VLTs and and such, they care far more about. Sure. But it's like, if one person on the table loses a thousand dollars to another person on the table, they still get the rake. And it's like Yeah.

Speaker 1: No. They're good. They're fine.

Speaker 2: And they know that that person's gonna then walk over to whatever blackjack and lose it on blackjack or take it to, you know, one of the other games. And and it just it is what it is. Like, the house wins. Like, that's why

Speaker 1: Yeah.

Speaker 2: You never hear of casinos going bankrupt. It's it's so to me, it's like, if you can make these devices and make them secure, the house has no motive to cheat. They don't care. Unless something like LA's House of Live Casino, like, if you've ever seen it on YouTube, pretty popular poker channel

Speaker 1: Okay.

Speaker 2: Is they they might have a bit of bias in it because there are regulars and there's personalities that play in it. You often see like, somebody sent me a clip from it the other day. One of my group chats came through, and it was one of the players was the founder of DoorDash. Like, there there's quite frequently, like, relative, like, nerdy celebrities that will go through and play.

Speaker 1: K.

Speaker 2: So it's like they I could see them having a bit more motive to, like but I I wouldn't see them wanting to tamper with it. Like, the the house really doesn't win in that case.

Speaker 1: Sure.

Speaker 2: The re the reality is too is that just poker is a game of insane luck. Like, I played a lot of poker a few weekends ago, and I got beat all in by a guy who hadn't looked at his cards. Sick.

Speaker 1: I'm not glad you lost, but that's pretty metal.

Speaker 2: It was so the I had an ace 10. K. And he and they didn't even look at their cards. I went in, like, whatever. Went in something something else. It was just the two of us left. Still hadn't looked at his cards. The flop came, and it was an ace, queen, 10. So I had two high Yeah. Two pairs pair. Like like, high then I had, like, the nuts pair. Like, I had the aces. Yeah. So I was like, I'm all in. There's something Calls it. Next two card doesn't still doesn't flip his cards because he hasn't looked at them yet. I flipped mine. So I've got ace 10. It's like a six and a two rainbow. Like, there's no flush potentials, no anything. And he rolls his cards, and the first one's a queen. So So he's got a pair of queens, but I've still got the ace pairs. And he rolls the second one, and it's another queen. So he had three of a kind queens. Blind. The only, like, realistic hand that could've beat me, he had blinds. So it's like you can't just look at one person calling a bluff and be like and be like, there's cheating happening. Anyway, I'm just that was a long way for me to vent some frustration.

Speaker 1: Yeah. You you just needed to get that out, and I get why because that's infuriating.

Speaker 2: Yes. Yes. Oh, that's So so there there's a lot of luck in it. So, you know, especially with players that aren't super skilled. Like, when skilled players look at bad plays by bad players, they think that there might be maliciousness in it, but, really, they're just probably not that good.

Speaker 1: There's a lot of luck in it, and I'm I personally, as a as a not I enjoy a game of poker, but I'm not a big gambler.

Speaker 2: Yeah.

Speaker 1: I want the the gambling tech industry to keep making large claims about how locked down their shit is Totally. Just to keep in fighting the ire of security researchers. If that's where all this goes is just people releasing new purportedly unhackable pieces of, like, gambling tech, and then people just hacking the crap out of them. Yep. And then we just go back and forth with that. I'll watch that show all day. That sounds awesome.

Speaker 2: Well, there's there's also another fascinating side to this in the sense that, like, gambling is such a tax generator. Right? Like everywhere that there is gambling, there are massive amounts of tax being collected on it. Like casinos pay Yeah.

Speaker 1: Bad odds are profitable. Yes.

Speaker 2: So like not only are casinos like great businesses, but they're generally large contributors to our social systems. So it's it's this interesting give and take. And so the Sure. I'm pretty sure that in most jurisdictions, like tampering with gambling machines is like a massive, massive crime because it's like you shouldn't be trying to rig the odds. So Sure. So, like, all of the people not your job. Yeah. But so, like, all of the people like, whenever people think about hacking casinos, they think about the patron hacking the casino for profit Mhmm. Not the casino hacking the casino for question mark.

Speaker 1: Oh, I see.

Speaker 2: Maybe profit. Maybe so this this this kinda rings, and this is just because I've been playing a decent amount of chess lately too. This this brings me to the to the chess cheating scam. Yep. Same kind of vibe.

Speaker 1: It does. The, yep. Yeah. As as well So to the Yeah. Yeah. Yeah. Yeah. Yeah. That that was an interesting

Speaker 2: story. Magnus Carlsen accused, Hans Hans Niemann. Hans Niemann in a in a live game. Like, we're not talking about, like, I don't know. Like, it was I'm pretty sure it was in a I think it was a live game, wasn't it?

Speaker 1: Yeah.

Speaker 2: Anyway, there was there was rumors that he because his moves were so unpredictably good. And there's like there's entire chess AI now that rate your moves. And he was making the best logistical, like, probabilistic quality move every time

Speaker 5: Yeah.

Speaker 2: Or something like that. So they they essentially accuse him of cheating.

Speaker 1: Yeah. It was that they were it was the, like, intersection of weirdness and effectiveness. It's like they were unintuitive moves that were really, really effective in a way that sort of read to players as like, this feels robot y. It doesn't feel in keeping with the way this guy has played for a while. We have a big data set on how he plays the seams out of keeping with that, and he's really, really crushed.

Speaker 2: They just settled just settled this lawsuit, but, there was entire rumors Really? Like, there was conspiracies about, like

Speaker 1: Oh, yeah.

Speaker 2: Vibrating, you know,

Speaker 1: Yeah. Oh, yeah.

Speaker 2: Anal beads. I guess there's no other way to say it.

Speaker 1: Yeah. We can say it. Yeah. Talk about a chess butt plug. Yeah. Yeah. Yeah. Like like somebody the story.

Speaker 2: Course course codes you the move. Yeah. And it was just

Speaker 1: Even just like a simple, like, don't make that move. Like Yeah. Yeah. Even a little bit of feedback could be immensely useful for a person at playing at that level of chess.

Speaker 2: Anyway, so so rigging poker card shufflers kinda kinda rings this into my head for no reason. Now we're just on a tired, exhausted, podcast creating, you know, side trip. So but but a fascinating story, nonetheless.

Speaker 1: Let's wrap it up by talking about the most interesting, exciting, provocative topic of all. Oh. Credit bureaus.

Speaker 2: Yes. Do you know something I learned recently? Before we even get going, I just wanna jump in here.

Speaker 1: Hit

Speaker 2: me. Canadian credit scores are out of 900, and, apparently, American credit scores are out of eight fifty. And I did not know that.

Speaker 1: Yeah. I I think I listened to, like, a financial advice show once years ago, and they kept referring to credit scores. And I was like, these people's credit scores aren't as good as they're saying they are. And I realized later that we just have a different, like, metric. We're grading on a different curve here in Canada. Eighty two percent of American adults had a credit card in 2022, and credit card applications lead to this and credit cards in general are leading to this constant data transfer between people and credit bureaus. Credit bureaus are supposed to play a role in fraud prevention. But at some point, credit bureaus realized that they had this really valuable, trough of data and decided to, diversify its use, let's call

Speaker 2: it. Okay.

Speaker 1: They started selling off something called credit headers to other company. Obviously, there's a lot of information they can't sell. Regulation prevents it. But the credit header, which typically contains a person's name, birth date, current and prior addresses, and Social Security number Mhmm. As well as their telephone number, are all part of this little packet of information that they are allowed to sell to third party companies.

Speaker 2: So it's like the ultimate docs? It's like Yeah. Not only do I have your name, number, and address, but I also have your credit score and your, Social Security. So it's like, if I'm gonna steal your identity, I have the starter pack.

Speaker 1: Precisely. This information is purchasable by other companies. Yeah. It's super cool and good. And basically, because this information is relatively it's it's meaningfully less locked down than a lot of other information regarding your credit and financial history. It has become the, like, a big cybercrime spotlight has been shined on top of it. The reason we bring this up is because, four zero four Media, which is this really cool new media operation started by a bunch of ex, vice tech reporters, broke this story about Telegram bot in which you can purchase basically credit header information. $15, in Bitcoin with an extra option for the Social Security number at a extra $20 bill, you can purchase a person's information through this bot, based on pretty minimal input, typically their name and the state that they're operating in.

Speaker 2: I find it so funny that we spend so much time trying to protect a lot of this information, and

Speaker 4: then

Speaker 2: you can just buy it online.

Speaker 1: Oh, completely. It's accept it's also very, very difficult for there's a lot of different tools that you can use, like consumer facing tools for getting your information pulled off of different databases and stuff online, products that will just reach out to them and get your stuff pulled. We've worked with them before in the show, and, credit headers are apparently one of the most difficult things to have pulled from these sites. So there's a there's a a service for accessing these called t l o x p. I'm not sure if that's how you actually pronounce it. It's capital t l o, lowercase x p. It's owned by TransUnion. It is so popular for use among cybercriminals that the term to t l o, someone has become a verb in online hacking forums. TransUnion acknowledges that there has been unauthorized access, but they emphasize obviously that we're trying to stop this from happening. But it doesn't change the fact that like, these credit headers have they've sort of leached out into the community to the point that now that there are very easily accessible tools that with very little information, you can find a person's credit header information. The sort of pilot project for some of these or, like, the test case for some of these has been, can we get Joe Rogan's Social Security number? Can we get Elon Musk's Social Security number? And the researchers were able to find this information on pretty much anybody you can think of. Right now, it looks like credit bureaus if we're trying to trace this back to its source, it obviously arrives at credit bureaus. They're the ones who are selling off this little sliver of information to different people, and it's only as secure as the people they sell them to.

Speaker 2: I I got news for you. Hit me. T l o x p has rebranded. That's now called true, True Lookup. Oh. So It sounds honest. So the verb's gonna have to change when it's To true somebody.

Speaker 1: You know what's funny is it probably won't. It'll probably keep being to t l o someone, and its meaning will just, like, fade into obscurity.

Speaker 2: Exactly. And then twenty years from now, somebody else on some other podcast will be like, t l o, where did that

Speaker 1: start? Totally.

Speaker 2: And they'll be like, well, in 2023, Jordan Blumen of hacked podcast.

Speaker 1: So this is such an essential part of doxing people at this point. It sounds like that there is probably going to be some sort of a legal response to it. The Credit Fraud and Prevention Bureau is considering new rules or regulations for credit header data. Yeah. Like, we've recognized that this is a problem and a vulnerability, but this is these rule changes are still in their earliest stages if anything is ever really realized. Because, again, there's a lot of people making a ton of money selling these things, so there's gonna be some pushback. But it is to say that this credit header data poses a significant privacy and security risk, and folks should know about it.

Speaker 2: Crazy. Interesting story.

Speaker 1: Yeah. It's a fascinating one. Well, Worm GPT, Fraud GPT, Black Hat Poker Cheating, and Telegram credit score vending machine bots.

Speaker 2: Yeah. Thanks again for everybody listening, and, you know, special thanks to all the patrons and people in the Discord and people that follow us on our largely muted social media channels. We will

Speaker 1: We appreciate you.

Speaker 2: Have an update on merch very soon. I know we've repetitively said that, but we are just in the process of waiting for some finals, and soon soon

Speaker 1: We have been we're stitching the T shirts ourselves. That's why it's taking so long. I've been screen printing hats in my bathroom Yes. Covered in chemicals. It's just taken a long time.

Speaker 2: So so yeah. But but, thanks for everything. We'll we'll see you guys soon, and, yeah, have a great couple weeks until we see you again.

Speaker 1: Catch you in the next one.

Speaker 6: If you've got an insurance question, you could talk to the butcher at your local grocery store. He'd probably talk about trimming the fat, but it'd be about your brisket, not your insurance policies. Or you could talk to your local GEICO agent. They offer personalized assistance in finding the choicest cuts of coverage for all your insurance needs, which means more money for filet mignon. Or if you're a vegetarian, tofu lay mignon. To find a GEICO agent near you, visit geico.com/local.

Speaker 7: This episode is brought to you by Nespresso. Life moves quickly, and taking care of yourself shouldn't feel like another chore. With the new Nespresso virtual up machine, morning routines become rituals. Whether organizing, getting the household moving, or preparing for the day, your coffee shouldn't ask for more. With Vertuo Up, just press brew and your morning begins. Rich aroma, bold flavor, zero effort. Press to explore. Every coffee, a new world. New Virtual Up. Shop now at nespresso.com.

Speaker 2: Every week, the Snap Judgment Podcast drops you inside someone's biggest decision. The kind of decision you can only make once. With everything on the line, what do you believe? What do you want? And what would you risk to get it? Find out. Tap to listen now to Snap Judgment from KQED on Spotify.