Won't Fix

Rob Leathern

From the founders of InfoHawk: conversations about AI-driven deception, abuse and scams, and why they’re so hard to stop. In software engineering, “won’t fix” describes a bug by acknowledging the issue but intentionally leaving it unsolved because addressing it is too costly, risky, or not worth the trade-offs. Hear from the practitioners fighting phishing, deepfakes and bots, and learn about the broken systems and misaligned incentives that keep us all vulnerable.

  1. 3 gg fa

    Won't Fix Episode 16: With John Canfield, Founder & CEO of BlueArc

    The question "is this business real, and should I believe what it's telling me" isn't new. It's about as old as American commerce. What's changed is that you can now spin up a company, a website, and a merchant account before lunch, and there's no correspondent in town to write you up. My guest has spent his career on the modern version of that problem. John Canfield built risk and verification systems at eBay, at WePay (acquired by JPMorgan Chase) and at Google, where he led the Ads verification and transparency initiative. He's now co-founder and CEO of BlueArc, which uses AI to verify business customers. Some themes: 1. How verification became paperwork The Bank Secrecy Act, then post-9/11 customer identification rules, hard-coded KYC as document collection — optimized for what an examiner could inspect, not what would catch a bad actor. When did "compliant" and "works" come apart? 2. Identity versus credibility He led Google Ads verification in 2020 and now argues that approach won't stop scams: identity answers who's speaking, credibility answers whether to believe them. Platforms spent a decade saying claim-level review couldn't scale, so why now? 3. Flipping the economics — who actually pays If the goal is no added friction for legitimate businesses, and if platforms can charge for deeper review, what then? 4. FTC v. Genesis Tech (filed June 2026, N.D. Cal.): we talked about this case, where the FTC alleges a network of 15 corporations and 8 individuals ran deceptive subscription apps through a shifting web of Cyprus and Delaware shell companies, continually registering new entities and merchant accounts to outrun fraud monitoring — with linked PayPal accounts processing close to $700M in the twelve months ending September 2025. Per the FTC’s standard, a practice is deceptive if it's likely to mislead a consumer acting reasonably in the circumstances and is material to their decision — no intent and no actual victims required, and net impression governs, so an ad that is literally true in every sentence can still be unlawful. Chapter Timestamps: 00:00 Introduction 1:21 Jon Canfield’s trust-and-safety background and BlueArc’s mission 3:34 Why business verification differs from verifying individuals 5:36 The missing business graph behind platform risk decisions 7:20 Legal entities are not enough: domains as a business identity layer 11:32 Balancing low-friction verification with domain control and vouching 16:36 Verification does not equal credible advertising claims 19:08 Risk-based claim credibility, transparency, and the limits of black-box enforcement 23:24 AI-enabled advertiser engagement and remediation 27:00 Proportional friction: local flower ads versus high-risk miracle claims 30:56 Scam economics and why advertisers may need to fund deep validation 34:16 Shared third-party validation and BlueArc’s next priorities 39:19 FTC material misrepresentation as a scalable policy framework 42:38 Know Your Agent: AI shopping agents, authorization, and scam resilience 46:02 Review-site integrity and adversarial manipulation Resources & Links: Rob Leathern (https://www.linkedin.com/in/leathern/) John Canfield (https://www.linkedin.com/in/johncanfieldbayarea/) BlueArc (https://bluearc.ai/)

  2. 11 set

    Won't Fix Episode 15: With Alexios Mantzarlis, Co-Founder of Indicator

    Alexios Mantzarlis has spent his career on the unglamorous side of the internet. He founded the Italian fact-checking site Pagella Politica, then led the International Fact-Checking Network, then spent several years at Google building an adversarial red team focused on content risks from generative AI. In 2024 he became the founding director of Cornell Tech's Security, Trust, and Safety Initiative, a role he left in June 2026 to go full-time on Indicator, the independent publication he co-founded with Craig Silverman to investigate digital deception. He now runs it from Rome. If there's a through-line, it's that the cheapest new technology always finds the oldest scams first. In the past year alone, Alexios has written about a North Korean hiring scam; an AI-generated podcast network pumping out 11,000 episodes a day; an AI bot that became the single largest contributor to Community Notes on X; Grokipedia citing a neo-Nazi forum as a source; face-swap apps in the Apple and Google stores; "cheater buster" websites selling fabricated infidelity reports; TikTok content farms; AI avatars impersonating real journalists; lookalike ticket sites and thousands of ads for nonconsensual nude generators that Meta has kept running despite a year of documentation. We talked about his latest investigation: roughly 8,000 Reels featuring AI-generated women posing as fired Costco, Aldi, and Home Depot employees, leaking "insider secrets." The videos funneled to survey sites promising a $750 gift card that didn't exist. Alexios and Benjamin Shultz traced the whole thing back to a single affiliate account and to a scam pipeline where AI generates the video, the captions, and the landing pages. Chapter Timestamps: 00:00 Introduction 2:20 Alexios’s path from platform trust and safety to independent reporting 4:36 Why public investigations can drive platform action 8:09 Fact-checking and Community Notes 11:33 The AI-generated retailer gift-card scam 14:57 AI used throughout the fraud pipeline 17:36 Recommendation feeds and reduced source context amplify scam reach 22:34 Affiliate IDs reveal the scam’s business model and coordination 27:20 Responsibility across the infrastructure chain 30:50 Journalism and trust and safety staffing 33:30 Transparency, EU ad data, and pro-speech accountability 35:47 AI bots in Community Notes and monetization-driven misinformation 41:29 Sources, sustainability, and Indicator’s next investigative tools 47:51 Closing warning against dismantling trust and safety Resources & Links: Rob Leathern (https://www.linkedin.com/in/leathern/) Alexios on Indicator (https://indicator.media/authors/alexios-mantzarlis) Alexios Mantzarlis (https://www.linkedin.com/in/mantzarlis/) Some of Alexios's pieces: AI-generated Costco employees — https://indicator.media/p/ai-generated-costco-employees-got-over-100-million-views-on-facebook-and-instagramMeta ran at least 11,000 ads for AI nudifiers this year (Sep 3, 2026) — https://indicator.media/p/meta-ran-at-least-11-000-ads-for-ai-nudifiers-this-year-many-from-easily-detectable-repeat-offendersHow to red team an AI tool for safety — https://indicator.media/p/how-to-red-team-an-ai-tool-for-safetyLatvia's "man drought" and passport-bro content — https://indicator.media/p/how-tabloid-claims-about-latvia-s-man-drought-fueled-a-misleading-social-media-frenzy-and-polluted-gWhat I learned running an adversarial test on an AI text detector — https://indicator.media/p/what-i-learned-running-an-adversarial-test-on-an-ai-text-detectorThis AI-generated podcast network publishes 11,000 episodes a day — https://indicator.media/p/this-ai-generated-podcast-network-publishes-11-000-episodes-a-day-it-s-also-ripping-off-media-outletAn AI bot is now the top contributor to Community Notes on X — https://indicator.media/p/an-ai-bot-is-now-the-top-contributor-to-community-notes-on-x

  3. 27 ago

    Won't Fix Episode 14: With Ajit Varma, Head of Firefox at Mozilla

    My guest, Ajit Varma, is Head of Firefox at Mozilla, where he leads Firefox strategy and product. He joined Mozilla in late 2024, from Meta, where he worked on monetization and business messaging for WhatsApp. He's also worked at Google and various startups in his 20 years of product leadership in Silicon Valley, and is based in the Bay Area. We talked about trust as a business strategy — Mozilla's bet that in an era of data harvesting and opaque algorithms, being the browser people can actually verify is worth more than scale. That means no in-house AI model, a choice of LLMs in Firefox, a master switch to turn AI off entirely, and revenue that doesn't depend on watching you. Ajit covered the nuances of data brokers, prompt injection and the tradeoffs between safety and privacy. From there, what a browser even is once it reads pages and acts on your behalf rather than just fetching them — model choice, shipping deliberately slower than the competition, and the parts nobody has solved yet. On agents: what consent means when software acts as you and spends your money, his argument that agents could route around the platforms taking a 30% cut, and where the next middleman forms if they do. And finally, who pays for the open web when agents do the reading — including Mozilla's own advertising business, its privacy-preserving ad infrastructure, and whether people will pay directly for software they trust. Chapter Timestamps: 00:00 Introduction 3:18 Mozilla's Mission: The Open Internet and Nonprofit Structure 5:11 Becoming the Most Trusted Software Company 9:51 AI as New Gatekeepers and Firefox's Response 16:19 Privacy, Felt Privacy, and User Awareness 19:59 AI Agents, Browser Automation, and the Human Element 24:02 Job Applications, Agent Spam, and Asymmetric Information 27:33 Advertising, the Open Web, and Data Brokers 32:42 Firefox's Approach to Ad Blocking and Tracker Transparency 43:41 Mozilla's Revenue Model and the Google Search Deal Resources & Links: Ajit Varma (https://www.linkedin.com/in/ajitvarma/) Firefox (https://www.firefox.com/) Rob Leathern (https://www.linkedin.com/in/leathern/)

  4. 18 ago

    Won't Fix Episode 13: With Alan Chapell of The Monopoly Report

    Rob Leathern speaks to privacy attorney and host of The Monopoly Report Podcast, Alan Chapell, about residential proxies, privacy and podcasting. Hear how free smart TV apps might be sharing your home IP address with strangers, and see just how broken online consent forms really are. Alan explains why current data broker laws miss these proxy networks entirely and how coming age verification rules could rewrite the open web. In This Episode: Free smart TV apps quietly bundle code that rents your home internet connection to strangers, creating vulnerabilities that look suspiciously like security exploits. Online consent breaks down with bandwidth sharing, when endless disclaimers mean nothing as consumers may have no easy way to turn the access off. State data broker laws miss the mark by hunting legacy data vendors while ignoring massive proxy networks, credit card companies, and telecom giants. AI companies pushing to scrape the entire web without limits could accidentally hand ad verification firms the ultimate legal shield against platform lawsuits. Strict age check laws could spark an arms race with clever teenagers that could end with governments requiring real ID just to browse the web. Chapter Timestamps: 00:00 Introduction 5:32 Residential Proxies: The "Ethically Sourced IP" Question and the LG TV Case 9:48 Legitimate Uses vs. Harmful Behaviors of Residential Proxy Networks 12:50 Data Broker Laws, Enforcement Gaps, and KYC 14:40 Consent Problems: Revocation, Age Verification, and the LG TV Example 16:56 Adware Parallels: History, Opt-Outs, and Financial Incentives 23:31 Age Verification: A Looming Internet-Wide Challenge 25:39 Scraping, Antitrust, and AI Companies 29:40 Podcast Strategy, Guest Selection, and Speaking Recklessly 41:53 Regulators, Historical Knowledge Gaps, and Industry Dynamics Resources & Links: Rob Leathern (https://www.linkedin.com/in/leathern/) Alan Chapell (https://www.linkedin.com/in/alan-chapell-90711b/) The Monopoly Report (https://monopoly-report.com/) The Chapell Regulatory Insider (https://chapellreport.substack.com/)

  5. 7 ago

    Won't Fix Episode 12: With Jeff Allen Co-founder & CRO of the Integrity Institute

    Jeff Allen is the Co-founder and Chief Research Officer of the Integrity Institute, started in 2021. A physicist and astronomer by training, moved into data science in 2013, and has since worked all three sides of the platform-publisher relationship: for publishers chasing platform traffic, for the platforms themselves, and for political organizations navigating both. At Facebook he worked on systemic problems in the Facebook and Instagram public content ecosystems. Along with Spencer Gurley, Jeff Allen and the Institute recently published the July 2026 report which Ofcom commissioned — Fraudulent Advertising and Account Integrity: Expert Insights on Best Practice, which fed directly into Ofcom's draft Fraudulent Advertising Codes (published 10 July, consultation closes 2 October). In This Episode: Short-term ad revenue pits platform profits against user safety, making external regulation necessary to preserve long-term industry trust.Regulators need technical guidance from experts independent of Big Tech funding to build safety policies that can survive court challenges.Bad actors are using generative AI to quickly spin up realistic, multi-step scam sites that slip right past standard automated filters.Effective oversight requires a two-step system: platform self-reporting backed by independent audits from verified researchers.Scammers actively reverse engineer enforcement limits, making off-site damage and delayed user reporting persistent challenges. Chapter Timestamps: 00:00 Introduction to Jeff Allen and the Integrity Institute 1:46 The Integrity Institute's Mission and Approach 3:29 The Scale of Online Scams and Fraudulent Advertising 4:54 Regulatory Landscape and Ofcom's Role 6:15 Development of the Ofcom Report 10:33 Congressional Understanding and Regulatory Progress 12:04 Media Coverage Challenges in Advertising 15:02 Incentive Alignment and Regulatory Approach 18:52 Data Access Challenges and Solutions 21:40 Internal vs External Research Challenges 24:07 The Sales Challenge in Data Science 28:50 Specific Transparency Metrics and Market Impact 32:46 Guidelines Disclosure and Adversarial Dynamics 35:15 The "Three Slide Rule" and Off-Platform Harm 40:17 Evolution of Fraudulent Content Creation 43:23 Researcher Access and Data Requests 45:25 Educational Needs and Trust and Safety Curriculum Resources & Links: Integrity Institute (https://www.integrityinstitute.org/) Integrity Institute Report (https://www.integrityinstitute.org/research/response-to-ofcoms-request-for-research-on-fraudulent-advertising-and-account-integrity) Rob's Notes (https://robleathern.substack.com/p/robs-notes-47-on-ofcoms-fraudulent) Jeff Allen (https://www.linkedin.com/in/jeff-allen-scientist/) Ofcom (https://www.ofcom.org.uk/) Rob Leathern (https://www.linkedin.com/in/leathern/)

  6. 24 lug

    Won't Fix Episode 11: With Independent Researcher & Consultant Ben Edelman

    Ben Edelman has spent two decades catching online fraud that hides in plain sight — combining software engineering, law, and economics to prove misconduct empirically rather than take companies at their word. In this conversation we get into the Phia shopping-plugin scandal, how it relates to Honey and Paypal that he covered after Megalag broke the issue on YouTube, the mechanics of affiliate fraud, and his recent investigation into AppLovin's apparent app install deals with mobile carriers. In This Episode: How Ben got into fraud investigation, and what keeps him motivatedPhia's "cookie stuffing": how a browser extension can claim affiliate credit for sales it didn't driveWhether Phia's "December bug" oopsy explanation holds up, and Phia's earlier 2025 privacy “mistake”The Honey/Paypal parallels, typosquatting and the broader toolkit of affiliate-fraud techniquesMegaLag vs. the mainstream media: how independent investigators break stories nowAppLovin's nonconsensual install investigation he wants state AGs to look atWhat meaningful accountability looks like, and his advice to founders building in this space Links & Resources: Ben Edelman's AppLovin investigation: https://www.benedelman.org/applovin-nonconsensual-installs/Ben Edelman's site (full archive of his research): https://www.benedelman.org Ben's list of "Investors supporting spyware": https://www.benedelman.org/spyware/investors/Edge Shopping Stand-Down Violations: https://www.benedelman.org/edge-shopping-standdown/Phia forced clicks and stand-down violations: https://www.benedelman.org/phia-forced-clicks/Honey stand-down violations and concealment: https://www.benedelman.org/honey-detecting-testers/Adware investors page:https://www.benedelman.org/spyware/investors/"Spontaneous Deregulation: How to Compete with Platforms that Ignore the Rules" (HBR article about intentional rule-breaking as a business strategy): https://www.benedelman.org/publications/hbr-spontaneous-deregulation-apr2016.pdfRob Leathern (https://www.linkedin.com/in/leathern/) Chapter Timestamps: 00:00 Introduction and Background on Online Fraud Investigation 1:36 The Origins: Gator Adware and Early Ad Fraud (2001) 3:10 The Dark Chapter of VC-Funded Adware 4:54 Transition to Independent Investigation Work 6:07 FIA Investigation: Two Types of Violations 7:31 Understanding Forced Clicks Through Analogies 9:50 Debunking FIA's "Recent Bug" Defense 12:50 FIA's Previous Screenshot Controversy 14:18 The Current "Dumb Tech Cycle" and Screenshot Overuse 16:20 Recurring Patterns: From Gator to Modern Shopping Plugins 21:11 Startup vs. Public Company Misconduct Patterns 24:40 PayPal's Due Diligence and Ongoing Modifications 27:24 Media Resources and Technical Expertise 30:17 Typo squatting and Google's Role 31:36 The Ad Tech Attention Gap 33:34 AppLovin Investigation: Install Helpers and Carrier Partnerships 34:21 Wall Street Journal's Surprising Rejection 40:28 Carrier Billing and Historical Context 44:42 Advice for Founders: The Temptation and Risk of Cheating

  7. 17 lug

    Won't Fix Episode 10: With Lindsay Kaye & Will Herbig of HUMAN Security

    On July 7, 2026, HUMAN’s Satori team exposed NewsJunkie, a massive, coordinated connected television (CTV) device-spoofing operation that generated up to two billion invalid bid requests per day, per seller. In this episode of Won’t Fix, we go inside the investigation with Lindsay Kaye (VP of Threat Intelligence) and Will Herbig (Senior Director of Media Research) from HUMAN Security to break down how this sophisticated fraud was uncovered. We then zoom out and the conversation to talk about the connected TV ecosystem in general and how AI and automation are changing the security threat landscape in general. Resources & Links: HUMAN Security Website: https://www.humansecurity.com/The Full NewsJunkie Report: https://www.humansecurity.com/learn/resources/human-disrupts-ctv-device-spoofing-newsjunkie/Lindsay’s Book (Dissecting the Dark Web, No Starch Press): https://nostarch.com/dissecting-the-dark-webRob Leathern (https://www.linkedin.com/in/leathern/) Chapter Timestamps: 00:00 Introduction 1:13 Team Backgrounds and Roles at Human Security 3:31 Understanding the News Junkie Operation Structure 5:27 Key Anomalies That Exposed the Fraud 8:32 Scale and Impact of Invalid Traffic 10:14 Evolution and Persistence of the Operation 14:15 Residential Proxies and Infrastructure Connections 20:24 AI-Generated Fake Business Identities 23:44 Disruption Strategies and Industry Response 26:48 Systemic Gaps and Supply Chain Compliance Issues 31:48 Device Attestation and Technical Solutions 34:41 AI's Impact on the Security Landscape 41:33 Investigation Methodology and Future Outlook

  8. 7 lug

    Won't Fix Episode 9: With Juliet Shen, Cofounder & HOP at ROOST

    Juliet Shen is cofounder and Head of Product at ROOST (Robust Open Online Safety Tools), a nonprofit building open-source trust-and-safety infrastructure for platforms of every size. She has done anti-abuse product work at Google and Grindr, and was the first trust-and-safety product manager at Snap, where she helped launch early cross-platform efforts to combat child exploitation. ROOST's website is https://roost.tools. Across her career, Juliet kept running into the same maddening pattern: every trust-and-safety team, at every platform, quietly rebuilding the same rules engines, review queues, and reporting pipelines from scratch, behind closed doors, and at enormous cost. ROOST is a bet that online safety should be shared, open infrastructure rather than proprietary secret sauce, available free to any platform or site that needs it. We talk about that, and a lot more. Key Highlights: Every tech company shouldn't have to build their trust and safety tools from scratch behind closed doors. It’s an expensive waste of time when open-source infrastructure could solve the exact same foundational problems for everyone.PMs and engineers need to step up and lead in the trust and safety space. They are the ones who can actually bridge the gap and get policy, operations, engineering, and legal teams talking to each other.AI is great for knocking out the easy, baseline moderation tasks. But when a situation is highly nuanced or something the AI hasn't seen in its training data, you still absolutely need human judgment.As social media breaks apart into decentralized networks, a one-size-fits-all safety system won't work anymore. We need modular tools that let platforms look at who the user is, how they're behaving, and what they're posting as separate pieces of the puzzle.Good moderation is often less about analyzing the post itself and more about knowing exactly who is behind the account or the app. Right now, our lack of solid identity verification is a massive blind spot for digital safety. Chapter Timestamps: 00:00 Introduction 1:34 Career Journey and the Problem of Redundant Tool Building 5:30 The Role of Product Managers in Trust and Safety Teams 7:34 Impact of LLMs on Trust and Safety Operations 11:27 Focus Areas and Child Safety Priority 12:55 The ABC Framework and Actor Trust Challenges 16:54 Community Building and TrustCon Participation 19:13 Signal Sharing vs Tool Sharing Philosophy 22:43 Open Source Approach and Scaling Challenges 23:59 Future Roadmap and Research Partnerships 28:52 Reviewer Well-being and Mental Health Considerations 32:00 Centralized vs Decentralized Moderation Models 37:15 Government Role and Open Source Support 39:52 Success Metrics and Measurement Challenges 42:50 Standards, Testing, and Future Directions Resources & Links: Rob Leathern (https://www.linkedin.com/in/leathern/) Juliet Shen (https://www.linkedin.com/in/julietshen/) ROOST (https://roost.tools)

Descrizione

From the founders of InfoHawk: conversations about AI-driven deception, abuse and scams, and why they’re so hard to stop. In software engineering, “won’t fix” describes a bug by acknowledging the issue but intentionally leaving it unsolved because addressing it is too costly, risky, or not worth the trade-offs. Hear from the practitioners fighting phishing, deepfakes and bots, and learn about the broken systems and misaligned incentives that keep us all vulnerable.