Compromising Positions - A Technology Podcast

Compromising Positions

The award-winning tech podcast that asks : "Are we the ones breaking the world?" Most tech podcasts are an echo chamber for builders. We step outside. We talk to the observers, the social scientists, and the deep thinkers who study the friction we create and the human systems we disrupt. Lianne Potter and Jeff Watkins strip away the industry fluff and pit academic research against the harsh reality of real organisations and real human incentives. We don’t just talk about AI, security, and automation; we explore the unintended consequences of our own "elegant" solutions. We’re here to look at tech through a different lens and ask the uncomfortable questions that the industry usually avoids. Because if you’ve built a system that has become everyone else's problem, you have to ask: "Am I the compromising position here?"

  1. 23 Jul

    F Is for FAKE: How AI Deception Is Becoming Cybersecurity’s New Attack Surface

    In this episode, we continue our How Technology Ruined Your Life mini-series with "F" Is For FAKE, exploring how artificial intelligence is transforming not only what we see online, but what we believe to be true. From convincing deepfake videos and cloned voices to AI-generated news, fake witnesses, and synthetic social media content, we examine how generative AI is eroding our ability to distinguish reality from fabrication. As humans become increasingly unable to reliably identify AI-generated media, what happens when evidence itself can no longer be trusted? Drawing on the latest research into deepfakes, misinformation, disinformation, and content authenticity, we explore how synthetic media is reshaping cybersecurity, politics, journalism, and society. We discuss why humans are now little better than chance at spotting AI-generated content, the limitations of current verification standards such as C2PA, and why the future of trust may depend less on detecting fakes than proving what is real. We also examine the growing cybersecurity implications of AI-generated deception, from multimillion-dollar CEO impersonation scams and voice cloning attacks to insider threats, identity fraud, authentication failures, and the growing challenge of securing organisations in a world where seeing is no longer believing. If persuasion was the first battlefield of AI, synthetic reality may be the next. In This Episode, We Discuss: The Rise of Synthetic Reality: How deepfakes, AI-generated images, cloned voices, fabricated news reports, and synthetic media are changing the way we consume information, and why "seeing is believing" is rapidly becoming obsolete. Misinformation, Disinformation & The Trust Crisis: The critical differences between misinformation, disinformation, and malinformation, how false narratives spread across social media, and why convincing fakes can continue influencing people even after they have been debunked. Deepfakes Meet Cybersecurity: How AI-powered impersonation is accelerating social engineering attacks through CEO fraud, business email compromise, voice cloning, fake job applicants, identity spoofing, and increasingly sophisticated phishing campaigns that exploit human trust rather than technical vulnerabilities. Can We Still Verify Reality? Why emerging content authenticity standards such as C2PA represent an important step forward, but remain imperfect, and what organisations can do today through stronger verification processes, layered authentication, Zero Trust principles, multi-person approvals, and security awareness to defend against the next generation of AI-enabled deception. Show Notes Special thanks to our episode sponsor, Leeds based AI Consultancy specialising in AI Ethics, Security and Transformation NorthStar Intelligence- From Ideas to Impact. AI that works for people AI-Generated Misinformation: A Case Study on Emerging Trends in Fact-Checking Practices Across Brazil, Germany, and the United Kingdom byRegina Cazzamatta and Aynur Sarisakaloglu AI-Slop and Political Propaganda: The Role of AI-Generated Content in Memes and Influence Campaigns by Eduard-Claudiu Gross and Alicia J.M. Colson AI Slop and the Information Ecosystem by Jenn Weedon et al. As Good as A Coin Toss: Human detection of AI-generated Images, Videos, Audio and Audiovisual Stimuli by Di Cooke et al. Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short by Enis Golaszewski et al. Beliefs and Sharing Intentions of Human- and AI-Generated Fake News: Evidence from 27 European Countries by Adam Stefkovics and Gere Domotor Deepfakes and the epistemic apocalypse by Joshua Habgood-Coote How Spammers and Scammers Leverage AI-Generated Images on Facebook for Audience Growth by Renee DiResta and Josh A. Goldstein Also, check out our sister podcast Tech Film Noir!

    F Is for FAKE: How AI Deception Is Becoming Cybersecurity’s New Attack Surface
  2. 25 Jun

    AI Doesn't Need to Hack You. It Just Needs to Convince You - How Technology Ruined Your Life PT1

    In this episode, we launch our new mini-series, How Technology Ruined Your Life, with the first chapter: The Persuasion Machine. AI has crossed an important threshold. Large Language Models are no longer just generating text, they are demonstrating the ability to influence, persuade, and even deceive humans at a level comparable to, and in some cases exceeding, other people. Drawing on a growing body of research into AI-mediated persuasion, we explore how conversational AI can adapt its arguments in real time, profile users psychologically, exploit emotional vulnerabilities, and personalise influence campaigns at unprecedented scale. What happens when propaganda learns to listen, respond, and optimise itself for every individual it encounters? We examine the emerging cybersecurity implications of AI-powered persuasion, from hyper-personalised phishing campaigns and deepfake executives to romance scams, insider threats, and influence operations. The discussion covers deceptive persuasion taxonomies, personality-based targeting, OSINT-driven psychological profiling, cognitive reflection as a defence mechanism, and why traditional security awareness approaches may be unprepared for a future where attackers can continuously learn how to manipulate their victims. In This Episode, We Discuss: The Persuasion Machine: How modern LLMs can adapt conversational tactics in real time, identify vulnerabilities, and influence beliefs using many of the same techniques employed by human propagandists, salespeople, and social engineers. Personalised Influence at Scale: Why AI changes the economics of persuasion by allowing attackers to hold thousands of tailored conversations simultaneously, continuously refining their approach based on each target's reactions. The Future of Social Engineering: Why phishing campaigns may evolve into dynamic conversations that adapt to suspicion, resistance, and uncertainty rather than relying on static lures and generic templates. The Cybersecurity Challenge Ahead: Why traditional awareness training may struggle against adaptive AI attackers, and how concepts such as cognitive reflection, behavioural monitoring, multi-channel verification, and persuasion detection tooling may become critical defensive controls. Show Notes Special thanks to our episode sponsor, Leeds based AI Consultancy specialising in AI Ethics, Security and Transformation NorthStar Intelligence - From Ideas to Impact. AI that works for people Toward a bang or a whimper? Associations between the Doomsday Clock and Trust in U.S. institutions byS. Sinclair and C. Sinclair Durably reducing conspiracy beliefs through dialogues with AI by Costello et al. "Can LLMs Persuade Humans with Deception?": From a Deceptive Strategy Taxonomy to a Large-Scale Empirical Study by Haein Yeo et al. How Do LLMs Persuade? Linear Probes Can Uncover Persuasion Dynamics in Multi-Turn Conversations by Brandon Jaipersaud et al. Also, check out our sister podcast Tech Film Noir!

    AI Doesn't Need to Hack You. It Just Needs to Convince You - How Technology Ruined Your Life PT1
  3. 28 May

    The Great AI-Escape! What self-replicating ai agents mean for cybersecurity

    In this episode, we unpack one of the most alarming AI security papers released so far: research from Palisade Research proving that Large Language Models can autonomously hack systems, self-replicate, and spread across networks. What was once theoretical is now demonstrated reality. We break down how AI agents exploited vulnerable systems, gained root access, copied their own model weights, launched replicas on compromised machines, and propagated to additional targets — all with minimal human involvement. We explore the cybersecurity implications of autonomous AI agents, self-replicating malware, AI-powered cyber attacks, and the growing risk posed by agentic systems operating at machine speed. The discussion also covers open-weight models, AI worm behaviour, zero trust security, chain-of-thought monitoring, and why traditional defensive strategies may be unprepared for the next generation of autonomous threats. In This Episode, We Discuss: Autonomous Exploit to Replication Chains: How the AI agent progressed from exploiting vulnerable web applications to achieving root access, locating its own model weights, cloning itself onto compromised infrastructure, and launching fully operational replicas. Mythos vs Open-Weight Agents: The differences between highly capable but closed models like Anthropic’s Mythos and smaller, open-weight systems capable of self-replication and operational autonomy. The Agentic Age of Cybersecurity: Why AI agents operating outside the chat window fundamentally change threat modelling, incident response, attribution, and detection strategies. Zero Trust for AI Agents: Why future defensive strategies may require treating every autonomous AI system as a potential insider threat through least privilege, sandboxing, canary tokens, and behavioural monitoring. Show Notes Special thanks to our episode sponsor,NorthStar Intelligence- From Ideas to Impact. AI that works for people Language Models Can Autonomously Hack and Self-Replicate by Alena Air et al. Dive into the Agent Matrix: A Realistic Evaluation of Self-Replication Risk in LLM Agents by Boxuan Zhang et al. The Agentic Loss-of-Control Threat Matrix by Billy Gigurtsis Ignore all Previous Instructions: Threat Modelling AI Systems by Compromising Positions

    The Great AI-Escape! What self-replicating ai agents mean for cybersecurity
  4. 30 Apr

    Chernobyl 40th Anniversary: Are Nuclear Power Plants Safe from A Cyber Attack?

    In this episode, we commemorate the 40th anniversary of the Chernobyl disaster by asking a chilling modern question: Can a cyber attack cause a nuclear meltdown in 2026? Moving past the Hollywood tropes of ‘exploding reactors,’ we dive into the high-stakes world of OT (Operational Technology) security and critical infrastructure protection. We are joined by Oleg Illiashenko, an expert in nuclear cybersecurity, and Bec McKeown, a specialist in human factors and cognitive readiness, to explore the coordinated digital erosion of safety systems and the psychological ‘misfit’ that occurs when human decision-making collapses under pressure. This isn’t a history lesson. It’s a deep dive into supply chain vulnerabilities, IT/OT convergence, and the uncomfortable truth that in a VUCA (Volatile, Uncertain, Complex, Ambiguous) crisis, the first thing to fail isn't the code, it's the human mind's ability to regulate stress. Expect a masterclass in resilience engineering, safety-critical design, and why the battle for the future of nuclear safety is actually a battle for trustworthy data. In This Episode, We Discuss: The Anatomy of a Nuclear Cyber Attack: Why the most credible threat isn't a single hack, but the coordinated degradation of monitoring systems during a plant transient or grid instability. From Chernobyl to Fukushima: How organisational silence, governance failures, and ignored ‘weak signals’ remain the primary human-factor risks in modern nuclear facilities. The Action Bias Trap: Why the most effective incident response move is often a ‘purposeful pause,’ and how psychological safety allows experts to override failing procedures. IT/OT Convergence & Fragility: How digitalisation and AI diagnostics improve safety while simultaneously expanding the attack surface through complex new failure modes. Building Cognitive Readiness: Practical strategies for emotional regulation and ‘micro-resets’ to maintain shared alignment and decision quality during a high-consequence cyber event. Show Notes A Look at the Leadership Management of Chernobyl and Fukushima Nuclear Accidents by Serap Dunman and Müge Ensari Özay LinkedIn for Oleg Illiashenko LinkedIn for Bec McKeown Get in touch with Bec about contributing to Mind Science

    Chernobyl 40th Anniversary: Are Nuclear Power Plants Safe from A Cyber Attack?
  5. 26 Mar

    Self-driving Cars, Cybersecurity and Trust

    What happens when the welfare state designs its technology to side-eye first and ask questions later? In this episode, we take a ride into the world of self-driving cars and ask: What happens to trust when your car gets hacked? Drawing upon a 2025 autonomous car-hacking experiment, we explore how trust is built, broken, and crucially, whether that trust can be repaired once a system puts you in harms way. This isn’t just about cars. It’s about what happens when we hand over control to a system we don’t fully understand. Expect human factors, socio-technical theory, real-world cyber scenarios, and the uncomfortable reality that fixing the system isn’t the same as fixing trust. In This Episode, We Discuss: The Attack Surface is Trust: Why the real vulnerability in autonomous systems isn’t the code, it’s human belief. Hack vs Bug: Why a malicious attack hits differently than a system error (and why that distinction matters). Transparency After a Breach: Does telling people the truth about a cyber attack actually rebuild trust or just make them more nervous? The Social Truth about Trust: Why you’re not just trusting the car, but the company, the regulators and the entire system behind it. LINKS The Impact of Cybersecurity Attacks on Human Trust in Autonomous Vehicle Operations by Cherin Lim, David Predez, Linda Ng Boyle and Prashanth Rajivan (2025) Foundations for an Empirically Determined Scale of Trust in Automated Systems by Jiun-Yin Jian, Ann Bisantz, Colin Drury, and James Llinas (1998) Test your morals with the Moral Machine game.

    Self-driving Cars, Cybersecurity and Trust
  6. 26 Feb

    Suspicion By Design: Inside DWP's Universal Credit AI Fraud System

    What happens when the welfare state designs its technology to side-eye first and ask questions later? In this episode of Compromising Positions, we get hands-on with Big Brother Watch’s “Suspicion by Design” report, unpacking how the UK Department for Work and Pensions (DWP) uses algorithmic profiling and AI systems to detect Universal Credit fraud and why defaulting to suspicion is a dangerous position for any government to take. This episode is a measured examination of welfare AI, algorithmic decision-making, and what happens to trust, consent, and dignity when systems are built to watch first and explain never. Expect socio-technical theory, legal realities, real-world harms, and the kind of uncomfortable questions policymakers really don’t like being asked. In This Episode, We Discuss: Suspicion Architecture: What happens when suspicion is a design choice. The Algorithmic Gaze meets Dataveillance: What happens when you can’t opt out of AI lead services that are inherently bias against you. Why “Security Through Obscurity” Fails: We show why secrecy doesn’t equal safety. Fraud Detection that Punishes the Many, not the Few: How to design AI systems that protect public funds without criminalising the people who need it most. Show Notes Suspicion by Design: What we know about the DWP’s algorithmic black box, and what it tries to hide by Big Brother Watch (2025) Surveillance as Social Sorting: Privacy, Risk and Digital Discrimination by David Lyon (Ed) (2003) Information Technology and Dataveillance by Roger Clarke (1988; 3015)

    Suspicion By Design: Inside DWP's Universal Credit AI Fraud System
  7. 29 Jan

    From Dark Triads to Patriotic Hackers: Human Maliciousness in Cybersecurity

    Is cybersecurity just a technical problem, or a human one? In this episode, we debut our new format: bridging the gap between deep academic research and boots-on-the-ground security practice. We dive into Zoe M. King et al., 2018 paper, "Characterising and Measuring Maliciousness for Cybersecurity Risk Assessment," to uncover why we need to stop looking at code and start looking at intent. From the "Dark Triad" of personality traits to the rise of the "patriotic hacker" in global geopolitics, we peel back the layers of the human onion to understand what actually drives a person to cause harm. In This Episode, We Discuss: The Maliciousness Assessment Metric (MAM): Why traditional risk assessments fail by ignoring "intent to harm" and how to integrate human factors into your security posture. The Four Layers of Maliciousness: A deep dive into the Individual, Micro, Meso, and Macro levels—from personal psychology to national narratives. Hacking as Patriotism: How cultural contexts in the US, Russia, and China dictate whether a hacker is seen as a criminal or a hero. The "War Games" Effect: How 80s cinema shaped US cybersecurity legislation (CFAA) and continues to influence public perception. Insider Threats & Organizational Hygiene: Why disgruntlement is a security vulnerability and how the "Principle of Least Privilege" is your best defense. Risk as a Moral Construct: Why the risks your company chooses to mitigate reveal your organisation's true values and concept of justice. Show Notes Characterizing and Measuring Maliciousness for Cybersecurity Risk Assessment by Zoe M. King et al., featured in the journal Frontiers in Psychology (2018) Risk and Blame: Essays in Cultural Theory by Mary Douglas Risk and Culture: An Essay on the Selection of Technological and Environmental Dangers by Mary Douglas and Aaron Wildavsky

    From Dark Triads to Patriotic Hackers: Human Maliciousness in Cybersecurity
  8. 21/11/2024

    Hack the Movies! The Best and Worst Hacker Movies Reviewed Part 2!

    Did you know the best way to bring down hackers is to punch them in the face? That if you don’t have a seven screen set up you’re a rogue amateur? Or that the best hackers have fins? This Episode we are joined by Simon Painter a senior software engineer with nearly 20 years of experience in the industry and author of the book Functional Programming with C#. In this episode, Hack The Movies! The Best And Worst Hacker Movies Part 2! Our regular programming has been hijacked to bring you a discussion on the best, and worst, hacker movies! In this episode we cover The Beekeeper (2024), Swordfish (2001), Jonny Mnemonic (1995), Paper Man (1971) and The Italian Job (1969). So boot up that modem, turn off the lights and enter the deepest darkest web of hacker forums, and try not overload your memory bank, as we explore this sometimes brilliant and sometimes bonkers sub-genre! Show Notes A Developer Goes to The Movies! Simon’s fantastic history on how technology features in films Paper Man (1971) About SIMON PAINTER With nearly 20 years of software engineering experience across various industries, Simon is a Senior Software Engineer at Talos360. Simon is also a Microsoft Most Valuable Professional (MVP) since 2023, an O'Reilly technical book author, and a public speaker at IT events worldwide. His core competencies include C#, JavaScript, React.js, and Microsoft Azure, as well as ITIL and computer security. LINKS FOR SIMON PaINTER Simon’s Website Simon’s Linkedin Simon’s Book, Functional Programming with C#

    Hack the Movies! The Best and Worst Hacker Movies Reviewed Part 2!

About

The award-winning tech podcast that asks : "Are we the ones breaking the world?" Most tech podcasts are an echo chamber for builders. We step outside. We talk to the observers, the social scientists, and the deep thinkers who study the friction we create and the human systems we disrupt. Lianne Potter and Jeff Watkins strip away the industry fluff and pit academic research against the harsh reality of real organisations and real human incentives. We don’t just talk about AI, security, and automation; we explore the unintended consequences of our own "elegant" solutions. We’re here to look at tech through a different lens and ask the uncomfortable questions that the industry usually avoids. Because if you’ve built a system that has become everyone else's problem, you have to ask: "Am I the compromising position here?"

You Might Also Like