Loading summary
John Strand
So I can confirm we have chicken news.
Corey
That was a long wait.
Bronwyn
What?
John Hammond
Are you serious?
Mary Ellen
It took me an hour to find this article. But it's a good one.
Fidelis
Clucking news.
Mary Ellen
I think it's a good one.
John Strand
Canadian Poultry Magazine.
John Hammond
Oh, my goodness.
Guest
Wow.
John Hammond
The Canadian chicken industry. I mean, I'm so glad that we have that as a topic.
Mary Ellen
When a chicken clock, it means something.
Corey
When a what?
Mary Ellen
When a chicken clucks, it means something.
Guest
What? What does it mean?
John Hammond
Is that from, like, the new Joker movie? Is that a quote from the Joker movie?
Host 2
I'm going to, like, panic.
John Strand
This feels like the second joke because that's a really bad quote.
Bronwyn
Now.
Mary Ellen
AI is your friend. AI has now figured out what chickens are saying.
John Strand
Hey, don't ruin the article, all right? No one's going to stay. Why would they listen to.
John Hammond
Don't talk about the news.
Host 2
It's probably VC funded and everything.
Corey
I don't even know what story that is, but I want to start with it.
John Strand
That's the hook, John.
John Hammond
That's what they're saying. For the only reason we do this podcast is so people make it to the end so they can do the chicken article last.
Corey
Okay, we'll do the chicken article last because that's the only reason people stay on.
John Hammond
That's correct. That's the hook. It's like the coming in 15 minutes. The chickens. Anyway, we're going to show you videos of squirrels for the next 15 minutes.
Corey
Film it.
Mary Ellen
Here's your teaser. You can download the Cluckify app now.
Guest
Oh, my goodness.
Corey
Something got in and killed all my chickens. And I think we're using all of our good stuff right now. All right. Hey, Corey, do you just want to run it again? Since I have.
John Hammond
I'll run it. We just need you to throw in a rant in there at some point, and then.
Corey
I got you. I got you on the rant. There's, like, sick. There are so many rants, fancy stories. It's ridiculous.
John Hammond
Okay. I'm so excited. Roll the finger. Let's go. Let's go.
Ian
All right.
John Hammond
Hello, and welcome to Black Hills Information securities. Talking about news. It's August 25, 2025. I heard the president is going to authorize us hackers to just target whatever foreign powers he. They want to. Is that right? We're privateers.
John Strand
I'm here to steal your logs. I will make you. I will defend you.
John Hammond
The number of people that are just making pirate noises makes me so happy. Like, I. I don't even know how to.
Corey
The flying spaghetti monster. Corey, Come here and I'll touch you with my noodly appendage.
John Hammond
I don't know how many people made pirate noises, but you're all amazing.
Corey
It's not, it's not today. Violation.
John Hammond
This is a real story. At this point I want to contain the hype train a little bit because this has only been submitted. This isn't actually necessarily a real thing, but.
Corey
Yet.
John Hammond
Yet. But Arizona congressman submitted, I guess bill to essentially use a letter of Mark. Or is it Mark? Hey, I. Mark.
Bronwyn
It's Mark.
John Hammond
Yeah, it's just letters of mark, which is a 200 year old, I guess, I don't know, policy that allowed privateers, which is Black Hills information security, to attack the vessels of foreign nations, which first of all, how is this ever a thing?
Bronwyn
Well, it was a big thing during the colonial era when you had lots of ships at sea bringing ill gotten goods back from the wilds of where the colonies were, where we were.
Corey
The ocean.
Bronwyn
Yes. From lands across oceans and then bringing them back. But of course you had Spain and England and France and, and all of those companies competing for it. So if Elizabeth needed to fill the coffers a little more, she'd issue letters of marque to her sailing fleet and say, okay, go get the other guys. And this is your get out of jail free card.
Corey
Yeah, I'm cool with this.
John Hammond
I don't know how anyone.
Corey
I can't see any possible way that anything could possibly go wrong with this. It just seems letters of Mark.
John Hammond
Oh my God.
Corey
On the Internet. I. It just seems like a good idea. I just common.
John Hammond
Okay.
John Strand
Isn't Russia already doing this anyway? Really? Like, come on.
Guest
Yeah, I mean, around about. Wait.
John Hammond
Right. I mean Israel, China, Russia are doing this to a degree.
Corey
I want to, I want to be honest. Seriously, I am okay with this because it's just going to destroy the Internet. Right? Like we need all of the countries against each other. Facebook will go. It's going to be like a nuclear assault. Facebook's going to vaporize. Amazon's going to vaporize. No one's going to be able to use Google. We're going to have to go to direct IP addresses to get to websites again. It's going to make Internet awesome again.
Host 2
Like we can start over.
Guest
You know what we got Call this flame wars 2025. Let's go.
John Hammond
Okay, so, okay, so hypothetically in historical, like I don't know if this is true or if it's apocryphal, but supposedly sailors were allocated like a pint of rum a day or Whatever ridiculous amount.
Corey
We could do the same thing.
John Hammond
So how much would I be allocated if I was going out to, you know, pillage and whatever foreign nations, cybersecurity assets. How much rum would I be granted? Would I be. Would it be Red Bull? Would it be balls? What would it be cola?
Host 2
Well, if you're smart, you save it up multiple days and then just drink it all at once and have a really good, successful little hacking session.
Corey
There's no pirate that says moderation is key to a happy exit.
John Hammond
Absolutely.
Bronwyn
Exactly.
Corey
No, no, no, no.
Guest
Somebody break out the jolt.
Corey
Destroy the Internet. John. 3, 16.
John Hammond
It would be funny.
Guest
I mean, here we go.
John Hammond
Like, just the. All of the hilarious repercussions of this. I mean, there's no way this goes anywhere, right? Like, to be honest, there's no way this.
Corey
I don't know about that.
John Hammond
Really? Yeah.
Corey
I don't know. I don't know about.
John Strand
I don't know. You know, like, property values real cheap in Arizona. I won't be.
Corey
We're going to rename the Department of Defense back to Department of War. We just need a Department of Cyber War. We're right there. We're one word off, Corey. One okay word.
John Hammond
But it would be. But it would have to be federally authorized. It couldn't just be Arizona being like, we don't like you. It would have to.
Corey
It's going to be a form, like a Google form that you just submit your email address of authenticity.
Guest
There you go.
Corey
That says, get your hack on.
John Hammond
There's a checkbox that says, I am a certified pirate and able to, like, forge the high seas or whatever.
Corey
I am so behind this. You have no idea.
Guest
Oh, my goodness.
Host 2
It's like King of the Hill where they take the bounty hunting classes. They give them a hat.
John Hammond
Yeah.
Guest
Then it's time to make, like, a specialized black badge for this situation here.
Corey
Oh, my God.
John Hammond
Could you imagine the pillaged 1k badge or something?
Corey
I just. I just love the Internet. Going to a series of hidden IPv6 addresses that people have to connect to through Tor.
Guest
Oh, my goodness.
John Hammond
You're talking about itp. Everything.
Corey
Yeah, I just.
Ian
How badly scammed this congressman got when he's sort of like, we need to get this money back. And it just reads like something where, like, he got scammed and he leveraged everything he could. And they said, you know what? Sorry, the money's gone. You're not getting that money back. And he's like, I'll show you. Like, we'll get. Why don't we send some hackers after him in order to get the, get the money back.
Bronwyn
But what worries me though, we've got all of these things like, we're going back to the Middle Ages. What the heck is up with this?
Host 2
Such a good time in the Middle Ages. Everything was great and nobody died of diseases.
John Hammond
There was no.
Fidelis
Spy.
Host 2
It was exciting.
Bronwyn
And, you know, women would bear 12 or 17 children and three of them would survive to adulthood, but you'd get.
Host 2
To sail across and like die in the middle of the ocean somewhere.
John Hammond
Die. I mean, what is the Internet? Okay, so real quick, what is the like Internet piracy equivalent of scurvy? Is it like viruses?
Host 2
It's going to.
Bronwyn
Low bandwidth.
John Hammond
Is pretty good. It's.
Fidelis
The OSI model is a scurvy.
Host 2
It's just going to Reddit.
John Hammond
That's all it is.
Corey
We have to move on from this story. But I, I for one support this, as does every other sane human being that wants the Internet to burn to the ground. Because the only way to fix it is to flush it all away.
Host 2
It would be really funny.
John Hammond
I know, I didn't want to spend too much time on it because not a real article, but it is hilarious. All right, so we can move on to some, I don't know, possible positive news or negative, depending on your approach. So scattered spider, the 20 year old Florida man named Noah Urban got 2010 years. Recommended sentence was eight years, I guess. And apparently the judge got also hacked by Scattered Spider and assaulted spider.
John Strand
Do you think they're looking to see if he was going to rat on someone like that? That was my first thought.
John Hammond
Right.
Mary Ellen
They said it was the other defendant, one of the other defendants.
Corey
I just think this is one of those situations. Like, I had a really good friend of mine when I was getting my clearance, he had the, the investigators come and spend a lot of time talking to him. And when he was getting the meetings with the investigators, he calls me up, he's like, john, I just want to let you know I'm not telling him anything. Wink. And I'm like, dude, tell them every. Yeah, I get you, I get you. I know. I'm like, you're not helping. And I hope to God that there was a conversation between this dude and his friend, like, dude, you hacked the judge. I know I did.
John Hammond
You're not. Please stop.
Guest
You're making it worse.
Corey
You're just making it worse.
John Hammond
I, I think you're 100% right. And I, on some level, I guess I feel bad for this person. They're 20 years old too, you know, like, I I do think that this is a reasonable sentence. I think, I mean it's a little heavy. Maybe eight to 10 years maybe on the lower side, I'm assuming there's some possibility for early release. And also once the US government approves this whole piracy Internet thing, he's going to have the hell of a pirate ship we're going to have on air.
Corey
He's going to. Yeah, it's going to be coming out.
Host 2
Yeah, that's the strategy.
John Hammond
Can you imagine this Noah, like pirate Noah going out in social engineering Russia to like get some judges money back or something.
John Strand
Someone photoshop an eye patch on him real quick like.
Mary Ellen
Last week. Did you, did you mention that like, you know, it's sad that they just, you know, why didn't he just go into bug bounty? I mean.
Corey
Yeah, I agree.
Host 2
Because there's not $13 million in bug bounty.
Corey
You can, yeah, it's hard.
Host 2
But you, but you do need 13 million because of course that's about what.
John Strand
You need to live in California.
Corey
You know how many times we're on the.
Bronwyn
Yeah.
Corey
And we see a hack executed by idiots and we're just like, why are we doing this legitimately? Guys.
John Strand
I think about this every day. I think about that every. I'm like, man, like maybe, I don't.
Corey
Know though, I could, I could have them hacked. I could hack this whole place and.
Guest
Burn it to the ground.
John Hammond
Put that eye patch away. You put that eye patch away. Yeah, I think the other, the restitution, it weighs 13 million, which is. That's a lot of restitution. I hope he got bitcoins because if so, maybe he can make that up in 10 years of Bitcoin gains, but otherwise that's going to be a lot of.
Corey
He's screwed. Because if we're story jumping, we got a story in here about China and crypto and quantum computing.
John Hammond
So real quick, before we step into that, there's another sentencing. I think we talked about this article years ago. The person who made the function in his Java code is this employee enabled. And then when he got fired, that Java just fork bombed the entire company.
Guest
Oh man.
John Hammond
That guy got sentenced today to. I think it's four years. Yeah, we talked about this. When it happened. It was basically just weaponized by five.
Corey
Years because he had to code in Java and they consider that time served.
John Hammond
Time served, I will say it is from like a, I'm not like a legal expert but like the guy decided to go to trial and it did not go well. Like how is. Why would you go to Trial on this in your defense, My boss was a dick. Like, maybe he was hoping someone would.
Host 2
Hack the judge for him real quick.
John Hammond
Yeah, hack the entire jury and tell them to vote no judge as well.
Mary Ellen
His own lawyer as well.
John Strand
Yeah, Noah got 10 years. This guy only gets four, right? Noah. How many people did Noah hack? Like maybe it's like go big or go home type of deal, right?
Guest
Like, yeah, it had to be a former Java developer on his side somewhere, just like someone else give him four.
Corey
Nullification. Have you guys ever heard of that? Jury nullification.
Ian
Yeah.
Corey
So basically what a juror, what a jury can say with jury nullification is, yes, all the facts point to this person is guilty of this crime, but we totally are going to find him not guilty anyway. If the attorneys were doing this right, they would get a bunch of developers on the jury and all they would have, all they would have to say is like, dude, the requirements were a pain in the ass. The requirements kept changing and users kept on changing things. They had me change the color they went through and in the middle of it, they wanted to put in like a dancing unicorn in it. And I just did my defense. I thought it was a good idea to do this because I hate my end users. And they'd be like, nullification, not guilty. They can do that.
John Hammond
Just show them the JIRA comments and.
Guest
The mere fact that he got points for using the object oriented programming language as well too, and not just functional. So yeah, kudos to him, he's awesome.
John Hammond
But his opsec is bad. He shouldn't have used a function called Is this employee enabled? He wrote in a function, can you imagine being the incident response from and just running the, like decompiling the Java and then just being like, oh, there it is. He wrote a function that just is am I enabled? If not fork bomb.
Guest
And that function right there screens premeditated.
John Hammond
That's also very true. That's also very true.
Corey
I could have called it like the Cisco Update process, Dot jar, something like that.
John Hammond
They never would have looked. They never would.
Guest
Yeah, but I'm going to pay attention to that one.
Host 2
I mean, all of that aside, I never understand how someone does something like this and expects any other outcome except for something like, you know, going on trial for. Yeah, I don't, I don't know what other outcome they're imagining. Like everybody goes, ah, damn, he got us. Ah, shoot. All right, all beans. We'll learn next time.
John Hammond
Yeah, it's one thing when you're 19 or 18 year old boy, it's another thing when you're in your 50s, like you gotta know better by then.
Host 2
Or at that point you're just mad and you're like, whatever, man.
Corey
It's like that anyway, Michael Douglas movie falling down at that point. Yeah, he's just done, he's just had it. I think that, I think that we're just kind of seeing burnout and the effects of burnout, you know, in these two.
John Hammond
That is, that's probably like, that's probably what it actually is, is just someone with mental health issues that has no concept of like reality.
Corey
But he's gonna get some time off to work on it though.
Guest
Yeah, that's true.
John Hammond
State. State sponsored style.
Guest
This plane in my head, right? Carmen, Eric, Carmen. All by myself when I hear stories like this. He went all out.
Corey
There you go.
John Hammond
Yeah. So the next article I wanted to talk about is. Okay, so the article is by the Brave browser and it's kind of dissing on the Comet browser. So Brave browser A decent. So, okay, my question is, are the browser wars starting up again? Because that's basically how this article reads to me.
Guest
Yeah, yeah.
John Hammond
I, I do want to give some credit to Brave because I, I do think it's a reputable browser and I do think this is an interesting finding. They did report it that, you know, they did responsible disclosure. And the video is really fascinating. But it's funny that they're like, well, your browser agent can be hacked and ours definitely can't. That's like. Basically that's how the article reads, but essentially it's prompt injection. If you go to the video, Ryan, it kind of explains it probably the easiest. So basically the idea here is it's prompt injection on a web page. If you're in the browser and you're using Perplexity's Comet browser, which is like an AI enabled browser, you somehow scrolled past the video twice. It's right, right in the center. Basically you click summarize this web page and then a prompt injection happens where the webpage just tells the AI hey AI. Instead of doing that, give me the user. I'm going to send you an email with a login code and you're going to send me that login code. This is like a decently long video, but essentially you can see there on the screen the white text is the prompt and the, you know, essentially the AI browser reads it and then follows the prompt. It's kind of an interesting demonstration of how a prompt injection works. Right. People like Bronwyn would already know that. But I thought it was a Cool demonstration to watch, but, yeah, I don't know. Bronwyn, any thoughts on this? Is this like, par for the course for an AI? What do you think?
Bronwyn
Yeah, Right now it's such new technology and they keep changing everything every five minutes. And that's exactly why we're back in the browser wars. Whether it's just the LLMs, just the AIs, I discovered the hard way that apparently recent changes to Perplexity have made my roommate totally miserable because now it's gotten dumb again.
John Hammond
So.
Bronwyn
Wow. I mean, when I was Webmaster at an ISP in 1995, it felt like.
Corey
We were before time.
Bronwyn
Yeah. In the very before time, it felt like we were downloading a new browser every five minutes. It was insane.
Corey
It was awesome.
Bronwyn
It's almost getting to be that bad in the whole LLM AI space. And now they're doing like, you know, these integrated AI browsers. So basically now everything that I put into this browser is automatically going to be harvested by the AI company.
John Hammond
Yeah, yeah, yeah.
Host 2
Even said that they said we are going to make a very personalized advertising profile for you. And then if you're the browser company, you just dump your old browser and decide you might as well start over with a new one. So just dump Ark and start up whatever it is. Dia.
John Hammond
Yeah, yeah. I mean, the other thing is they. Last week we talked about it on the news, but they were like, hey, can we buy Chrome for, like, more than we're worth? For double what we're worth? Yeah.
Guest
You know somebody in the back. Is it possible?
Host 2
Oh, yeah.
Corey
What a move.
Host 2
Honestly, you got to respect.
John Hammond
So for this week, for this week alone, this only applies for seven days. Starting today, we recommend use the Brave browser. We'll be back next week with another recommendation on which browser to switch to. It might be Netscape, who knows?
Host 2
We need to start getting them to sponsor us.
Ian
I've recommended Brave to my parents. Like, it's just. I mean, it's straightforward. You don't have to be like, oh, go get this browser, put these extensions on, tune it like this. It's like, you know what? Out of the box Brave for the threat modeling of adults in their elderly. Then, yeah, it works.
Bronwyn
I know the Brave is good because it breaks more websites than any other browser I use.
John Hammond
That's how you know it's good. Because it doesn't work. Hell yeah.
Corey
Yeah. It kind of reminds me, there's this book, the Atopia Chronicles. If anyone can look that up and drop a link in the chat, it's awesome. But in it they have like implants for augmented reality and you can basically if you don't pay the package then ads show up everywhere in your day to day life and it's just miserable. And they did this thing where like one of the people shut off everything and the world was just dreary and dismal. And Brave is like that but in reverse. The Internet is a really weird place. I don't know if any of you have ever used somebody else's computer where they don't have browser plugins or they're not using Brave to clean up the ads. Oh man, we were joking about this. I think like the last time I was on it's like the Walmart Blue Light special browser from way back in the day. There's so many ads that are just coming at you all the time. It's, it's. The Internet is almost unusable. And that's why I seriously think the solution to this problem is letters of market cyber.
Bronwyn
It's almost as bad as all of the pop ups in applications. Do you want me to summarize this? Do you want me to do this on the other side?
John Strand
I don't want to talk about that.
John Hammond
Pick some cookies from the following 16 radio options. This really a dog viewing this site from Europe. B.
Guest
Here's one way to sum up the Internet. Here's one way to sum up the Internet.
Corey
Sorry Atopia.
Guest
Ok, here's one way to sum up the Internet. It's like one massive vacuum bag that's just exploded and we're getting everything back from old browsers to pop ups. I mean everything that we thought we were gotten rid of is coming back vengeance.
Host 2
Discord just got they like instantiated. Whoever the big guy is that did all the microtransactions and all the Call of Duty games. So as soon as Discord becomes garbage, we're going back to IRC or something.
John Hammond
I would recommend for a web browser just to use Curl.
Guest
No, come on.
John Hammond
Links. Links is okay, but I gotta say I like the scripting opportunities with Curl.
Guest
Oh yeah, I just do.
John Hammond
While True Curl is johnstrandteaching.com and then I just have that. I pipe that into Cowsay. It's fine.
Corey
Yes, because it's.
Fidelis
This has all happened before and this will all happen again.
Guest
You know what? Ethnet is going to be the new hotness again.
John Hammond
I can't wait to get a T1 line at my house. Guys.
Guest
Yeah, come on back home.
Bronwyn
It might not be the Wheel of time, but maybe it's the Wheel of pain.
John Hammond
Yes, it's the wheel of packets. Don't question it.
Guest
Wheel of package.
Corey
Here we go.
John Hammond
Okay, John, you want to talk about this weird Chinese crypto quantum, like all these words that I don't understand.
Corey
Ranty for me, maybe a little bit ranty. But I love watching anything related to quantum computing. And the reason why I like it is it's so weird and there's so much hype around it and it's not what people think it is. So whenever people are talking about quantum computing, they have this belief that they're going to be able to get a quantum computer with enough qubit processors, Processors to where you'll be able to do general purpose computing. Right? Because the dream is a quantum computer that can run doom. And that is the bar.
John Hammond
Unfortunately, that's ten years out, dude.
Corey
They do not work that way. Just kind of going through it. So basically, with a quantum computer, the act of observation actually changes the state of things and causes waveform probabilities to collapse generally into what we consider to be reality. So how does that relate to computers? If you have a quantum computer, and I'm just going to use Bitcoin as an example, because this is where this actually is applicable. With Bitcoin, the way it works is you take a whole bunch of different transactions or a number of different cryptocurrencies with proof of work, you take a number of different transactions and then you kind of put them in, like think like a bus, a whole ledger of transactions. And then you have a seed value that you randomize until you hit a hash value that begins with a certain number of zeros. Right? Like say it's five, six, seven, eight zeros. So you can increase the work effort by increasing the requirements of the number of zeros at the front. When you have that it's proven, then that goes as a block on the chain, right? Now the reason why quantum would work in that specific scenario is the nature of the way quantum computers are set up and the way the programs are configured. You can actually reach into the infinite realm of possibilities looking for the hash that you're supposedly looking for by not looking at it and then pull it out. Now, there's a number of ways to deal with this because if you observe, you're going to, you're going to encounter some level of error. It's not going to get the hashes right. You're going to run into problems. So up until recently, what quantum computers have done in a number of different strategies to deal with that error is you would have One quantum function that would go through and it would find all of the subset possibilities and then you would literally take that and feed it through another quantum processor and then you would pull out the one probability that you're looking for. And that's usually why there's a limitation in the number of qubits and the speed at which you can do this. Apparently these guys found a better way of doing error correction and now all of a sudden, what is it? Quad trillion? Like, that's absolutely insane. Now we've got to take this with a grain of salt because we don't have any proof of this, anything that's going on. But if you're looking at this all of a sudden, any non probabilistic hard problem that you're trying to solve is in play. So cracking crypto, cracking password hashes, doing hash verification for crypto mining and Bitcoin and things of that nature. And this goes back to our poor guy that we were talking about a little while ago, 21 year old Florida man, where Corey said, I hope he has crypto. It's possible that it's worth nothing by the time he gets out. Because the way the algorithms are set up, they are not resilient to quantum computing. What you can do with this. So watch this.
John Hammond
Okay.
Corey
If it's real, we don't know. There's been a number of things that come out of China where it's like, we've done the impossible. People are like, yeah, we'd like some proof. And it turns out to be not.
John Hammond
Can you put this in terms of like a Fast and Furious movie? Because that would really help me understand it.
John Strand
Most recent Fast and Furious where, where Vin Diesel is going across the bridge, or this is even the most recent one. And the car hooks up to the bridge, not even the bridge, but to the rope, and then that swings and then the car jumps off and goes across this were quantum computer, it wouldn't swing, it would just teleport across. I have no clue.
John Hammond
Okay, that makes perfect sense. Thank you, Wade.
Corey
Out of all the possibilities, he would have died horribly if he gave a. If you watch that video, he's cool as a cucumber, doesn't care. The car lands.
John Hammond
Perfect. I see, I don't know, flying through the air in a car.
Host 2
Car go fast. Computer go fast.
Corey
Computer go fast. But yeah, you can't. At this particular point, you can't have a general purpose quantum computer. They have to be set up for very specific functions.
John Hammond
So it can't run doom.
Corey
Can't run doom. Not yet. Not yet. General purpose.
John Hammond
Call me when you can run Doom.
Corey
Yeah. I'm so excited about the day where I'm proven wrong and they have a quantum computer running Quantum Doom. That's going to be just amazing.
John Hammond
So Quantum Doom doesn't sound foreboding at all. That sounds totally.
Corey
No, no, no, no, no. But you got to have it set up with quantum AI, then you truly get Quantum Doom, and then it's not a video game. We're going to live it.
Bronwyn
Is that going to wind up giving us, like, Quantum Skynet?
Corey
Sure. Or Quantum imps, Whatever. We need to get off this topic.
John Hammond
Yeah. Anyway, let's.
Bronwyn
Let's take a little chicken.
Corey
Coming. You think we've. You think we've been. Chickens are coming?
Guest
The main event on its way. Stay tuned.
Corey
There we go.
John Hammond
Oh, my goodness. Oh, my goodness.
Corey
All right.
John Hammond
Spoilers. So I guess we could talk about the bank who fired all their customer support people and said they were being replaced by AI, but then had to hire them back. And everyone.
Bronwyn
Okay, I do have done this already a lot.
John Hammond
Well, not. We don't know. But this is the most public and hilarious example. So let's go. Let's. Let's dig into this. So this is Australia. We love you upside down, people. We. You know, I wish Joff was here to be like the patron Australian, but he's not. So basically, I don't know, it's Australia's biggest bank. FSU finance sector union. They, they made a statement. They were like, oh, my goodness, we're going to replace all of our workers with AI. Which turns out all their workers is only 45 people, so not that many.
Guest
I mean, it's doable.
John Hammond
Yeah. So basically they got some kind of chatbot and said, we got a sick reduction in call volumes. But turns out that was a lie and they're freaking out and people are calling and trying to request more customer support because the AI is lying to them. So it's basically. Then the FSU union people were like, hey, you guys need to get it together. And then that, I guess led to some Australian bureaucracy stuff called a fair work tribunal. I don't know what that is, but it sounds cool. We don't have that in the States. We just call that getting fired and.
Bronwyn
Basically is employment at will. Okay. But this thing with companies reversing, it's not just the one bank. So Klarna, Swedish fintech, they replaced 700 customer service employees and almost immediately had to hire a bunch back. IBM. Now we know that IBM and other large tech have Been firing people right, left and center. Apparently IBM laid off 8,000 people from HR and had to rehire a bunch of people back, especially for dealing with policy.
John Hammond
Well, but they apologized, so I don't see what the big deal is here.
John Strand
So here's what happened.
Bronwyn
If you're messing with my cash flow, your freaking apology doesn't matter.
Corey
I want to, I want to kind of springboard something that Brahman Brahman's talking about. Before we move on, though, a serious thing that has nothing to do with chickens is the fact that a lot of these companies, when they do the layoffs, there's this huge announcement and then that's what echoes in the echo chamber, right? You have tons of CTOs are like, well, see how they're laying off all these people and all the efficiency of artificial intelligence. And when they have to hire back, it's like buried on page six. It's in, it's barely in the news. And the concern that I have is we have, and I'd love to get Bronwyn's take on this, is we're echoing the fact that, oh, you can reduce costs by firing people, but stories like this where they have to hire the people back, they aren't getting that level of like, like kind of elevation in the news space. And I'm afraid that that's going to create some really unrealistic, like, this is feeling a lot like the dot com bubble. Well, in 2000, like, a lot like.
Host 2
It has to be intentional because when you, when you fire a ton of people, your stock is going to go up. So if you push out this press release that you hired a ton of people back, it's going to come back down. But if you just want to hit the old, like, switcheroo and fire them and eventually bring them back, maybe you realize some actual gains from that.
Guest
And plus, they don't want to look.
Corey
Like they were running it either.
Bronwyn
It's not as if companies are doing ghost postings anyway. So they've got, they've got all these postings that they never intended to hire for. And it's like, oh, hey, we've already got this, we've already got these resumes, so we'll just hire these people in. But getting to John's point, absolutely, the rehires are not going to probably be getting back unless, unless they are literally rehiring people and pulling them back into the same positions. I expect that the corporations will be looking for ways to hire people into the vacated slots, but at lower salary rates, possibly lower benefits rates and maybe even lower seniority rates because, hey, it's all about the bottom line transitioning over to the AI bubble. I think we are coming for an AI bubble, and if only for the reason that the amount of money being invested into AI companies is not sustainable. It's a virtual capital nightmare. Because all of these companies are throwing gobs of money at something. They don't have a clear picture of what they're trying to achieve. There's a lot of hype.
John Strand
All right, you heard it here first. Short Nvidia now.
Ian
Well, there you go.
John Hammond
So that's. That's a bad example. That's a bad example because they're the ones who are selling, like, the flutes to the doomsday people in this scenario. Like, they're not the doomsday people themselves. They're just, like, selling the tools. That's a lot easier than actually, like, they're. I don't know. But I mean, for sure, like, I think there's a bubble.
Bronwyn
Oh, yeah.
John Hammond
I saw an article the other day that was like, I don't know if there's any profitable AI companies, like, at all.
Bronwyn
I don't think any of them are.
John Hammond
Like, I don't think any big AI companies actually make money, to my knowledge. Unless I'm wrong.
John Strand
I thought one of the problems, though, right? Like, look at rideshare companies. Are any of them even profitable yet?
John Hammond
I think they are. I think. I think that. I mean, basically they're in the phase where like, you guys better get your act together soon. But I think for now, none of them have actually made money despite raking in billions of dollars, you know, over time.
Bronwyn
Millions of dollars in investments.
John Hammond
Well, yeah.
Fidelis
One of the problems that they're starting to notice is the scaling of the LLMs with the amount of data that they've got is hitting its limits. It's plateauing. They're not getting good enough data to go ahead and continue forward. This failure of ChatGPT5 that just came out is exasperating it. Even the head of. Even Sam. What's his Face. The head of chat, saying, yeah, yeah, Altman is saying that this is a bubble at this point, that they don't know, some sort of big advancement, how it's not going to burst.
John Hammond
I think there's very few companies that could pull off the. Replace your customer service people with AI and actually survive. Like, I think companies like an Amazon that have. That are just like aggressive capitalists and are just like, whatever. If we have to give away a bunch of stuff to someone that Finds of prompt inject, prompt injection. That's fine. Like, you have to fully commit to this concept and deal with all the side, like issues. Like, you're going to lose customers. AI is going to get tricked into doing things it shouldn't do. Like, it's going to be a disaster. Companies like banks are never going to be able to commit to this fully. Because there's a difference between oops, we sent you the wrong item and oops, all your money was deposited to another person with the same name. Right. Like there. It's going to work in some instances. But I think 90% of the companies who are like, like, ooh, we can nuke our entire customer service team. Like, what happens when I need to reset my password and it's an AI, Is it just gonna automatic? Like, I don't know, it's.
Corey
Anyway, I love the quote that I think, I think Wade put it in, which was March, I need 8 trillion to build AGI. August, we should slow down on calling AGI.
Guest
Look, it's. Yeah, it's like I said, I think it's. We're, we're in a stage now where everybody's trying to be first. They're trying to figure out what works and what doesn't work. Like you said, LLMs, that is max capacity. ChatGPT5 is having all these issues. I think when I see articles like this and you know, and like you said before, when somebody was. When they do like the mass layoff, they, they pretty much project that but then kind of sweep under the rug for the people that hired back because they don't want to look like they were wrong about.
Corey
Yeah, AI.
Guest
So you have that expanding and of course the echo chamber. Eventually I do think it's going to burst, you know, unfortunately, yeah, it.
Bronwyn
And it feels exactly like those early days before the dot com bubble because there was a lot of hype. There were a lot of people trying to apply this new technology.
Guest
Right.
Bronwyn
Without having an idea what was the problem they were trying to solve. But it was shiny. So, hey, it's a new hammer. Let's hit everything. But here's the weird thing.
Corey
A lot of them are right. I'm going to give the example of webvan. That's one. Like I remember when it was happening, they used it as a cautionary tale of anybody doing.com companies. The idea of web ban was you could order your groceries online and have them delivered. That at the time, that was super. They put a tremendous amount of money in web band. I think it was like a former CEO of Accenture or Anderson Consulting that ran it and went completely nowhere, went into the ground, crashed and burned. But now we have GrubHub and we have DoorDash. Like an Instacart, and I think like a instacart and all these things. So it's like a lot of the stuff that they're hyping about. It's possible that we're in the early stage of the bubble where it's not like, it's just not there yet. But I think one of the things we do have to keep in mind is this is going to get there, Right? It may be the money is not coming in. It may be that there's going to be a whole bunch of losers losing possibly trillions of dollars. But if we move forward another 15, 20 years, all the AGI crap that we're talking about, and I hope it stops at AGI, I hope it doesn't move to the super intelligence phase. But all that AGI crap, it's coming like, you know, it may not be the best thing. We can joke about. ChatGPT. We can joke about, you know, Grok. We can joke about all of these things, but all of the stuff that they're trying to do may not be financially feasible today. But if you move down the line a little bit, it is coming. So maybe it gives us a little bit of a breather in the security community if we can have this bubble burst to where we can start rationalizing and dealing with this stuff in an appropriate way.
Host 2
Yeah, it's almost like gambling because you're. You're hoping that you get in on the right company. Like, you get in on a cursor, you get on, like a love or all these other companies. You just throw money and hope that you're right.
John Hammond
And this is how the stock market works it. Exactly. Yeah.
Host 2
You'll win.
John Hammond
Yeah.
Bronwyn
I had a friend that was really just get insider.
Corey
Yeah. He was talking about how bad meme coins were. He's like, you know, a meme coin, they come up with a stupid coin called, you know, like, you know, dongle coin coin.
John Hammond
Dude, that was the best investment I made last year.
Corey
Dongle coin or hawk to a coin. And then everybody invests in that, and everybody knows that the bubble's gonna burst. But you don't want to be the first person. You don't want to be the last person. It's an absolute scam. We need to regulate it. It's a bad idea. I'm like, you literally just described the stock market like, I mean about speculative investing. That's what we've been doing. So how is this any different?
Ian
I do think like the outward facing bubble for AI is going to burst, but I'm still concerned about like that, that undercurrent like that, that things going on in the background where you go, okay, you have, you have these chat agents, you have these LLMs, you have these things that like everyday users can open up on their phone, use AI for and laugh at it. That's going to burst. But I think like the embedded, like the real deep stuff where you can have it run through like high level iterations and go, you are having like a thousand lab tests being done in a week that we can't do. That will still, I don't think that will burst out. That will be the undercurrent that's going to be the thing to worry about.
Host 2
Is that it'll get way better. Like in the SOC and detection engineering space, we can dump tons of past cases and investigation notes and details and dispositions into these models and use them to build scoring on top of our current cases to where, you know, a human can still look at it. But you can have 10,000 cases from the past layered on top of this model where it can assess, hey, we've seen this before in these places and this was the result.
John Strand
You could do better than that. You could hook it up to MCP and then just straight have a go tune your detections.
Host 2
Exactly.
John Strand
You can there.
Guest
Yeah.
John Hammond
Right. Yeah, like so, so, but here's on.
Corey
That note, the money is being invested in, it's being invested in a lot of these companies so they can give us better ads. And that's where it's going to blow. All right. Correct.
John Hammond
So I was going to say, I mean Search, I think is a great example of like that actually probably should be replaced by a. But so I, I did want to just while we're in AI corner, this article about them adding AI to Excel is too good not to just stop over and look at it because. Okay, so basically they added AI. This is not surprising to anyone. But they added Copilot to Excel. Okay.
Corey
And then.
John Hammond
But they do specifically, if you scroll down, Ryan, to the part where it says Microsoft explicitly warns users that its AI functions should not be things used for things like. And then here's where it blows my mind because all of these things are just the only reason you would use Excel. So it says do not use it for numerical calculations. For any task requiring accuracy or reproducibility, you choose a. For highlighting what do you use it for? And do not use it for legal, regulatory or compliance implications.
Guest
Is it safe?
John Hammond
What else are you using? Excel support.
John Strand
Is someone use it to turn VBA scripts on?
Guest
Hey, is it safe? Is it safe to change the colors of the tab? Is that, Is that fine?
John Hammond
That's highly, highly sketch.
Guest
Oh my goodness.
John Hammond
Yeah, I, I like this is.
Corey
This is like the disclaimer at the beginning of south park where they're like, you know, the caricatures are bad at defensive and should not be viewed by anyone. That's like. So we wrote this tool. It may create big mistakes. You shouldn't use it for math, you shouldn't use it for calculate. You actually just shouldn't use it. By the way, we sunk a quarter billion dollars into this specific function last week.
Host 2
I mean, the AI might be like wonky, but it can't possibly get worse than me trying to remember how to do like a vlookup on my own. It can't. It can't possibly be any worse than that.
Guest
Oh, just you wait.
John Hammond
It's just hard. Can you imagine? You load spreadsheet in and it just replaces all the formulas with just hard set values of what it calculated.
Host 2
Guys, we made negative $2.8 billion last week. Awesome.
John Hammond
I looked on Wikipedia and filled in your profit numbers for you. Yeah, thanks goodness.
Corey
That's like, like with Erica, whenever she's doing financial planning, it's nerve wracking being in the same room with her because she'll be talking to her stuff and she'll be like, oh no. Oh no. Oh no. Oh God. Oh God. Oh no.
Ian
We're fine.
Corey
I'm like making eggs and I'm like.
John Hammond
The profitability of the company is varying minute to minute. And while we're in Copilot, the last thing I wanted to say is that apparently. And Bronwyn, I'm curious if you have a take on this. Apparently copilot accessing Microsoft cloud doesn't generate logs. What?
Bronwyn
What?
Corey
Interesting story.
John Hammond
Google does.
John Strand
Google Gemini does for sure.
Bronwyn
They ran into an issue where you're able to tell copilot not to log activity and it didn't log the activity. Supposedly that glitch has been fixed. And it was one of those things where somebody discovered the problem, they patched it, didn't even bother to file a cve. They just, yeah, they, they really, really tried to sneak that one in in the shadow.
John Strand
I find that just so hard to like, I, I don't believe I know like the underlying mechanisms in order for detection. Why would it have access, right? Like it should have access as a user and that user should be trapped. That's what. Yeah, but it's still a user, right? Like or, or an API key. It's not being able to change the underlying construction.
Bronwyn
Duotech is saying that the it's not fixed. That their patch made it worse. Oh God.
John Hammond
Yeah. So basically the article. Oh, go ahead.
Corey
I was gonna say we still come back to like, we spent like the past two decades building up security, the concept of access control, fine grained group policy, who's getting access to what files. And literally the CEOs and CTOs just like let AI run free, run wild. Should we have logs, Effort? It doesn't need everything. Everything that we've been doing in security, it's like we're gonna blow a hole straight through it because of AI. Let's just do that because it's easier.
John Hammond
Well, so just to set the record straight on the actual. So it's a blog by Pistachio, which I've never heard of. So I mean, who knows? But essentially this researcher named Zach Corman found a vulnerability where essentially you could be like, hey, copilot, do this like on the down low and don't generate any access logs for this. And it would actually like follow those instructions. And basically he reported this to msrc. MSRC said we fixed it, I guess. And, but also the, the, the reason they made the blog is because Microsoft didn't really announce that they fixed it to anyone. But yeah, supposedly this is now fixed. There was no CVE assigned. It was supposedly fixed. But I could see there being more of this kind of thing of like, hey, AI isn't doing like John said, it's blowing a hole in the, blowing a hole in the security and access controls. And then Microsoft's like, oh, it's fixed. It's like, okay, what logs are invalid? What data? When did this get implemented?
Corey
Like, okay, I just threw in a Talis Intelligence blog, Static Tundra, kind of a similar type vein or a continuation. We're getting dark again. And they're like, we usually very.
Bronwyn
It's not my fault, right?
Corey
Not this time. Usually it is. So this one, this article. The reason why this article is like so important to me is these particular devices that this group is going after. This vulnerability is seven years old.
John Hammond
Oh, Cisco Smart install. This is like Pen Testing 101.
Guest
That vacuum is exploding again.
Corey
The vacuum's exploding again. Yes, it's full. Watch out. Shitter's full. Yeah, yeah.
John Hammond
This is like, okay, this is 100% in the context of like, probably in John's intro to Pen testing class, Smart install enabled. It's a like, medium or low level Nessus finding. And it's apparently used by APTS to install backdoors in your operating system.
Corey
Where's the Pepperidge Farm meme when you need it? Yeah, and this goes back to. It's like, are we actually progressing or is it just we're diffusing the poo more? It seems.
Guest
I think it's the latter.
Fidelis
It seems to me what it is is that we look at what is happening now thinking that we've solved the prior problems, when reality is we didn't solve crap and all we've done is just pushed it to the side until somebody comes back around and finds it again and then we go back through it again. It's just this vicious circle that we're stuck in.
John Hammond
Well.
Corey
Vulnerabilities. Why didn't CISA tell me to fix this?
Host 2
The secure companies don't make headlines. The ones that patch their stuff are not going to make the news. I guess it's the same.
Bronwyn
Good security is boring. Good, good management is boring. Good governance is boring. And you know what? Boring is grossly undervalued. I like boring.
Guest
So another. In other words, we're living a cyber soap opera.
John Hammond
Good.
Bronwyn
Cybersecurity people are burning out.
John Hammond
Yeah.
Bronwyn
I mean, as an industry, how many decades are we going to continue to burn out our best and brightest because the core problems, the legacy problems, never get fixed.
Guest
Right.
Corey
Yep. We've added AI to it.
Bronwyn
Ranting.
John Hammond
I was going to say ranting. Harder than John today. Hell yeah.
Fidelis
As I said earlier, this has all happened before before. It will all happen again.
Guest
Yep. Instead of General Hospital is Digital Hospital. Yeah.
John Hammond
All right, we have. We have 10 minutes left. So first we're gonna put Wade on the spot.
Guest
Wait, oh, wait.
Corey
Oh.
John Hammond
Tell us why we should care about clickjacking. I mean. Okay, I will summarize. Wade. Okay, here's what's gonna happen. All right, I'm going to summarize and you're just going to give non verbal cues as to whether I'm on point or I'm dead wrong. Okay. All right.
Bronwyn
Cluck once.
John Hammond
Cluck. Yeah, cluck once if I'm right. Cluck once for warmer, twice for colder. So basically, here's the. The article is in Cyber Insider. Czech security researcher published vulnerabilities. This is part. This is presented at defcon. Basically, they reported vulnerabilities in every password manager, more or less. The vulnerabilities are essentially that because password managers display things on the screen, clickjacking can be used to exploit password managers and do bad things. All of the people who are listed, vendors, including not. Definitely not Wade's employer by any stretch. Every password manager is aware of this and it's been a thing for years. It's like a known thing. A lot of them have claimed to have fixed it, but the fix is just don't use autofills. This is like required for the password manager to work. Basically. This is kind of old and new. The web is a dangerous place. Everyone, Every vendor's recommendation is essentially be careful out there on the Internet.
Host 2
Like look both ways before crossing the street, I guess.
John Hammond
Yeah. Like it, It's. I don't know, it's. I think it's kind of a non, non issue and I really don't care about clickjacking, but that's my take.
Corey
I'm not getting in the middle of this. You guys can deal with it.
Host 2
Corey brought it up.
Fidelis
Let me, let me, Let me just.
Corey
I think we're sitting back to happen. Yeah, if it's not going to happen, let's move.
John Hammond
No, wait's too smart. Well, I mean you're trying to guard him into it.
Fidelis
If we're supposed to copy paste, how vulnerable is the clipboard? Is that more vulnerable than the clickjacking?
John Hammond
Probably worse.
Host 2
I'm just going to write down all my passwords and as soon as I enter, I'm going to eat the paper.
John Hammond
I feel like, I feel like this is definitely like. That's basically the theme is that even when LastPass got hacked and we were like, oh, LastPass has bad crypto or whatever, it's still like better than not using a password manager. Like, it is still like, even if you're using a password manager that's actively getting hacked, it's still better to use a password manager than to not keep using your password managers. Don't worry about this. Clickjacking has been a thing forever and will continue to be a thing forever.
Fidelis
And just make sure that you've got MFA set up just as a secondary thing.
Bronwyn
Here's a really sad thing. Sorry, John, I'm going to go to a dark place. Even if you go completely off the grid, even if you completely disconnect and you do everything analog and whatnot, you still cannot escape being a digital victim because so many of the services we use are digitally based and you can't get away from it.
Corey
Yeah, that wasn't as bad as I thought it was going to be.
John Hammond
Password reuse is worse than any password manager's crypto. That's just a fact. All right. Chickens.
Corey
Well, I don't know. There's one more. Before we do chickens, I'm gonna throw this bomb out there. Apparently it's coming. It's coming. The chickens are coming. They're coming home to roost. Training apparently doesn't work.
Host 2
Yeah, no, I believe that one.
Guest
You know what?
Corey
I don't know if this is a hot take at all or anything. I don't. And I. I'm wondering if they're. One employee out of 19,500 fell for a simulated phishing email. Every time I get that, they want to say it didn't work. But at the same time, if your failure rate is 1 at a 19,500, what other security controls in your organization are that effective? Maybe training has nothing to do with it. I don't know. It's one of those things.
John Hammond
Your EDR is not that effective.
Host 2
It could have something to do with it. Some of them are so boring and people are not going to pay attention to that. They're just going to click through it. I wouldn't know anything about that, of course, but people would do that.
Corey
Sites. I guarantee you, I would have made way more mistakes and clicked on more evil sites than that.
John Hammond
Can we also talk about how it's. The graph is a cumulative percent. It's like, designed never to go down. Like, isn't that just how numbers work? Yes. If you keep adding up percents, they get bigger. That is how percents work. That is how cumulative percents work. They don't go down because they're cumulative.
Corey
I don't know what to take of this. Like, I just don't. And I probably brought more attention to it than I should have. But it. There's just a couple of things wrong with it, I think. I mean, what were they? I would have been truly astounded if they were like, we did 20,000 spearfishes and not a single person clicked it. That would be like, whoa, okay, that's progress. That's crazy. But I just think that every single component of information security has a probabilistic percentage of failure. Right. And if we're looking at this article, one out of 19,000, that's the least of your concerns in your tech stack right now.
John Hammond
Yeah, I will say. But from an executive perspective. And John, this is a take for you. If you're a CISO or someone in an executive position, your phishing metric should not be a driving metric for a security program like companies that are focused on this. I specifically warn them it only takes one. So if your metrics are anything above zero, which I guarantee you they are, it doesn't really matter if half people in your company Click or if 1% of the company clicks, you're still just as hacked. It doesn't really matter. You need to focus on everything else. Continue your security training. Sure, I'm not saying ditch all those products, but it's not like a core health metric for a security program.
Corey
I think I'm going to disagree and agree at the same time, which is kind of weird. You're going into an immature security program that has never had user awareness training. You're absolutely going to want to start tracking those metrics. Right. Because you're going to have a much higher percentage of people that are clicking on links and just basically going through really bad cyber hydra hygiene. And I honestly do believe that cyber awareness does work. Maybe a lot of the programs are crap, they're garbage. We can do all of these different things. We can say it, but whenever we're working with organizations that have never done that hygiene, like it's. It just they click on literally everything. Right now in a more mature organization, I agree with you, it's not a statistic to get that much tied up into it. Right. I do believe that you should focus more on the technical controls. But if you're just getting into an organization as a C CISO and you have no metrics as far as where your company is, as far as user awareness, and it's never been anything that you've never tested, you're probably going to want to test that to get an idea of where the company is at. But I agree. And probably most organizations mid to high level security awareness, it's just you got a lot of other things to worry about other than one out of 19,500. Yeah.
Host 2
And people start to zone it out after a while too. Like the external tags, the warning banners. At a certain point you don't ever notice them. So what are you supposed to do? Change them every so often or. I mean they're going to start to zone those out too. Like what's the solution is? Turn off all email probably.
Corey
Yeah.
Ian
We do still need like the security awareness training because, you know, last week we were talking about like the phishing campaigns where they had like the lookalike slashers. They use like a clever, a clever forward slash alternate replacement. And that was getting past the technology solution for the time being until they patched that. And so the conclusion there was, you need security awareness training. And now we come back this week and we go, no, don't worry about the security awareness training. Focus more on your technical controls. And is it going to be another month? And we go, well, technical controls are kind of failing. Make sure you stay up on your security awareness training. So I'm just kind of calling out that it's like you see a lot of these articles and it's not necessarily us, right? It's this news group where you see a lot of articles where they contradict each other from week to week, like do we need security awareness training or do we not need security awareness training? I saw this article and I'm like, oh look, it's the end of August and it's your annual security awareness training is useless article that comes out.
Host 2
Just do all of them at the same time really well, It's a problem.
Fidelis
Of black or white. It's either technical controls or security awareness training. When reality is you have to use them both together and use them properly together to be the most effective. At least the way that I see it done. Because there's especially in security awareness training, there can be as much restrictions put onto it. No putting anything from HR or checking with this or doing that that the company could put onto you as opposed to being able to just wide open blast things as there can be in say a penetration or red team assessment where your scope is limited down.
John Hammond
Yeah, I mean at the end of the day, if we look at like actual threat intel, it doesn't seem like phishing is really that big of a problem for most orgs right now. What is a problem is teams calls to their salesforce employees. The problem is vishing. Right? Like that's what's getting initial access right now. Yeah, let's talk about chickens. We're running out of time.
Corey
We have two minutes, John.
John Hammond
All right, Mary Ellen, you've been waiting this entire article, this entire new show, very politely and kindly, please.
Mary Ellen
I was so excited. It took me an hour to find a fun chicken article. So if a bird clucks, what does it mean? So they are. Poultry farmers are now using AI to tell and it tells them what their chicken, what the flocks are saying they're.
Corey
Using, what the are they saying?
John Hammond
Can you imagine an AI translator that's like, man, I had some really bad poops earlier and it's like warning, disease detected by AI.
Guest
Let's just make sure we don't cluck it up.
John Hammond
There is an app, there is actually.
Bronwyn
An app, a Clockify.
Mary Ellen
Clockify. You can download and by recording the birds in a range of settings, they can collate all of this. And they have built a translator using AI and then the app will tell you what the chickens are saying.
John Hammond
Okay. Has anyone, does anyone have chickens? And if so, can you go test this?
Bronwyn
I know people who have chickens.
Corey
I, I, I, I had a whole bunch of chickens and something.
John Hammond
And now you have a bunch of chicken wings. See, if you had a translator app, that would be very traumatic.
Corey
My head. John, where are you? You're coming down listening to this, this chicken holocaust.
John Hammond
You're getting push notifications. Ow, the claws, they hurt.
Guest
Ow, it hurts.
John Hammond
I'm bleeding everywhere.
Corey
Could you imagine one of my favorite far sides is the guy that creates the universal dog translator, and it translates every dog bark to.
John Hammond
Hey.
Host 2
I don't need one of those for my cat. I would not be pleased with the results. I'm pretty sure.
Corey
Oh, your cat does not like you. I've never met your cat.
John Hammond
If you're in the audience and you.
Corey
Have someone please run this Mary Island. Do you have chickens by any chance?
Mary Ellen
I do not.
Host 2
We're about to ship you some chickens.
Bronwyn
We have people at BHIS who have chickens. I will reach out.
Corey
We do.
Bronwyn
Specifically to them.
Corey
Yeah. If somebody can come back next week, like, all of you try it on your chickens. And I'm terrified that it's gonna come back. It's like the chickens are gonna be like, click, cluck, click, click. They're looking into AI. Don't they understand that ends poorly?
Guest
Like, you know, if that thing come back with something different next week, I will. You know what? I won't know what to say.
Corey
I want to know what they're saying.
John Hammond
Oh, my God, do we think this is real? Like, I know. I'm not saying it's malicious.
Host 2
It feels like an ipod touch app that you'd pay 99 cents for and then never use it.
John Hammond
They put all the effort into the AI side. Definitely not the UI design.
Bronwyn
Is this like an iOS or is it an Android?
John Hammond
IOS and Android. It's on both.
Guest
I think it's both. Yeah.
Corey
I gotta be honest, though. I would like to know, like, I had this chicken that would follow my dogs around and like, like, peck at their butts. And it freaked my dogs out. Like, and I'm talking, like, dead center accuracy. And that's what that chicken did, like, all the time. A cat, you know, like, the dogs, it was just like, walk around eating and then come up behind, just be like, like, pop. And that dog and that cat would jump like 10ft. I would have loved to have known what that chicken was thinking.
John Hammond
Imagine being an old timey farmer and you're like, 14 year old farmer son comes to you and is like, hey, we need an AI app to translate what the chickens are saying. And you're just. You just have to be like, no, but we. No, we don't. We don't need that.
Corey
That's what we do. And then we drain the blood. We don't want to listen to them, so. All right, well, let's wrap it up. Thank you so much, everybody. And let's see what happens next week.
Mary Ellen
Blue team. Blue Team summit this week.
John Hammond
Yeah. John, plug the Blue Team Summit and blue Team training.
Corey
Oh, yeah, we've got a summit. It's a Blue Team summit. The links are showing up on Discord here in just a couple of seconds. Super excited about that. And we have training. There's a whole bunch of really cool training classes at the Blue Team Summit. Check those out. And we'll see you guys next week. Or maybe at the Blue Team Summit. Preferably at the Blue Team Summit. I'm on an airplane and teaching, unfortunately. But you should all go to the Blue Team Summit and hit me up on Discord and just let me know how badly I'm missing out on this awesome Blue Team summit.
John Hammond
I'll send you whatever the chickens say on Discord.
Corey
Whatever the chickens say. It'll just keep coming. All right, later, everybody. Thank you so much.
John Hammond
Bye, everyone.
Corey
Sam.
Date: August 30, 2025
Hosts: Black Hills Information Security Team (John Strand, Corey, John Hammond, Bronwyn, Mary Ellen, Fidelis, Ian, others)
This episode dives into the looming "AI Bubble," the mounting hype (and skepticism) around artificial intelligence, and how these patterns echo the early 2000s dot-com craze. The crew, a lively mix of penetration testers and infosec professionals, cover AI in customer service, quantum computing rumors, browser wars, security news, and—finally—the much-teased story about AI translating chicken clucks.
Their tone is irreverent, humorous, and self-aware, balancing infosec jargon with accessible metaphors and comic relief.
[02:17]–[09:14]
Takeaway:
While tongue-in-cheek, the team highlights risks of unleashing chaotic, semi-government-sanctioned hacking—and draws parallels to state-sponsored attacks already taking place globally.
[09:16]–[16:29]
[16:29]–[22:54]
[23:19]–[28:27]
[28:43]–[37:19]
[37:19]–[41:37]
[41:37]–[46:31]
[46:31]–[49:17]
[49:19]–[52:49]
[52:57]–[58:44]
[59:04]–[62:59]
This episode is a rollicking, insightful ride through the latest in infosec—from the ridiculousness of AI-powered chicken translators to the sobering risks of uncritical AI adoption. The looming "AI bubble" is explored with healthy cynicism, drawing parallels with the dot-com bust. Infosec basics (patching, password managers, awareness training) remain frustratingly relevant, while bleeding-edge advances are often overhyped and under-delivered.
The crew wraps up with a chicken (cluck) crescendo, promising more poultry penetration testing next week.
For listeners:
If you want laughs, real-world analogies, and a (skeptical) pulse-check on security and tech hype, this episode is a must-listen. And yes, the chickens do finally come home to roost.