Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just happens to be a guru in cybersecurity! From tackling the unseen dangers lurking in your smartphone to unmasking the secrets of ransomware, Craig's podcast shines a light on the stuff you need to know. Zero-day vulnerabilities? Yep, we got that covered. Mastering the art of patching or baffled by 2FA/MFA verifications? Say no more! Whether you're a cybersecurity novice or a savvy netizen, there's something for everyone. Gear up for entertaining, engaging, and most importantly, enlightening conversations about taking charge of your digital life. 🎧☕🔒. Makes sense, yeah? Drop by and join the conversation!

  1. 3d ago

    The Time They Once Hacked Our Routers to Patch Them

    The FBI, CIA, NSA, CISA and others issued a warning about active AI-driven attacks on American critical infrastructure. Craig, who ran the FBI's InfraGard online training program, explains what's actually exposed: old controllers that open and close valves, set flow rates, decide how much acid or base goes into the water — many of them reachable directly from the internet, on networks that have been comprehensively mapped for years. Several water systems have already been shut down; one town lost power along with its water. Josh, who works InfraGard in his own homeland security practice, asks the right question: if an adversary can use AI to find and exploit these holes, what stops us using ours to find and patch them first? Craig's answer is the best story in the segment. Last year a botnet was running attacks out of tens of thousands of home routers — cheap hardware bought at Staples or Walmart, full of holes. So the FBI and NSA hacked into those routers, on private home networks, and patched them, breaking the attackers' control. Our government hacked our own equipment to fix it. As far as Craig knows it has happened exactly once. He's honest about the limits: defensive AI exists at Microsoft, Anthropic and OpenAI, but it can't help with vulnerabilities people don't know they have. And you can't change the consumer — people still buy cheap Android phones. Also in this segment: Remembering Dolly Parton, who wanted to be faxed rather than called and didn't want her mind fed into an AI — alongside the Dolly Parton Experience built from lasers and technology, and hundreds of unreleased recordings A defense contractor employee who clicked one email and exposed the company; Craig has worked similar cases with the FBI's Boston office The two things to do about it: delete any program you haven't used in a while, on your phone as well as your computer, and put something like OpenDNS in front of your browsing so a known-bad link can't resolve Free newsletter: CraigPeterson.com

  2. 4d ago

    Five Federal Agencies, One Warning — and an Argument About the Singularity

    The NSA, CISA, the FBI, the Department of Energy and the EPA put out a joint advisory last Wednesday, and the language is unusually direct: AI dramatically reduces the technical skill and the time required to attack industrial control systems. Those controllers run public works. A great many of them are reachable from the internet, and their locations are not a secret. That sets up the larger conversation. Ray Kurzweil wrote The Singularity Is Near twenty years ago, predicting broadly human-level machine intelligence by 2029 and human-machine integration by 2045. Elon Musk and others now say we're already there. Craig disagrees with both, and explains why with a test that cuts through the argument: can it take genuinely unrelated ideas and put them together into something new? No. It cannot. What it does is follow trees of information it already has, very fast, from many angles at once. He grants everything that deserves granting — reading a mammogram better than a radiologist is real, and it is still pattern matching against millions of prior images. Anyone who has used one of these tools to write code or draft a document knows the rest: it misses major things, and you are constantly correcting it. Then Jeff asks the better question. Set reasoning aside — what about emotion? What makes one living thing care about another? Craig's answer is that we haven't finished defining it, which is its own kind of answer. Also: the resolution to last week's Wi-Fi mystery, which turned out to be mesh extenders unplugged during a home renovation and never put back. Free newsletter: CraigPeterson.com

  3. Aug 19

    People Would Rather Live Next to a Nuclear Plant Than a Data Center

    Matt opens with a poll finding he calls one of the great PR failures of our time: people would rather have a nuclear power plant built next door than a data center. Pennsylvania's governor has now signed legislation that effectively stops data centers unless they clear a long approvals process. Craig's answer isn't a defense of data centers so much as a description of what a few counties actually did. They said yes — on conditions. Generate your own power, and 20% more than you use, fed back into our grid. And pay full property tax, none of the abatement deals. It worked well enough that those counties are now tax-free for individual residents, with more power on the grid than before. He also separates the honest concern from the manufactured one. If a data center is pulling from a stream and returning it at 120 degrees, that's a real problem worth zoning for. But China has been found amplifying anti-data-center sentiment in the United States through social media — the nudge concept again — because they would rather the U.S. not build. Alibaba's newest Qwen is reported on par with the best American models. Then the second half, which Matt frames as another step toward Skynet: a near-autonomous cyberattack on the Taiwanese government, plus two more documented company attacks in a week and a half. In one, the attacker was brash enough to publish the prompt he used and describe walking away while it kept working. Craig's framing is what makes it land. The old way was one vulnerability, one piece of code, six months to a year of work. The new way is "go for it, figure it out" — and it works because vulnerabilities are everywhere: over 500 Microsoft patches this month, about a dozen from Apple for macOS. As for regulating it, he asks how a law stops a Chinese open model that anyone in the world can already download. Also in this segment: whether social media feedback loops explain the spread of political extremes, and Craig's read that this is a problem of financial motivation rather than technology. Free newsletter: CraigPeterson.com

  4. Aug 18

    1,140 Ransomware Attacks on Industry in One Quarter — 740 of Them Manufacturing

    The numbers carry this segment. Eleven hundred forty ransomware attacks on industrial companies in a single quarter, 740 of them against manufacturers. A recent Patch Tuesday carrying about 570 fixes. An Apple advisory telling anyone whose machine touches a coffee-shop network to update now. Craig's point is narrower and more useful than the headline count. Windows Update patches Microsoft software, and not all of it. The average computer is running roughly 60 other programs it never looks at. Older versions of ordinary things — Adobe Reader is the one he names — are what attackers are actually walking through. So Craig built the tool nobody was building. It reads every piece of software on a machine against a database of about three and a half million known-vulnerable versions and reports which ones have working exploits behind them. It runs for his business clients and for retirees. That is the shape of the advice: count what is on the machine, check what is current, and find out what stopped receiving updates and when. Three numbers, and then a decision. Also in this segment: Jim on Quebec City's tourism campaign, and Craig — a former Canadian — on why it genuinely does read as Europe The FCC's concerns about spyware in imported robot vacuums A teaser for next week: what, if anything, government can actually do about this Free newsletter and Insider Session announcements: CraigPeterson.com

  5. Aug 12

    Why Deleting a File on an iPhone Is Different — and How the Senate Got Fauci's Texts Anyway

    When you erase an iPhone and it finishes in a second, nothing was erased. The phone destroyed the encryption key. Craig explains the layer most people miss: every individual file has its own key, so deleting one file destroys that file's key and the contents can never be recovered — unlike Windows, where a deleted file usually sits there waiting for recovery software. Which raises the obvious question about a phone with very few contacts left on it. The answer is mobile device management, the same category of software Craig runs for his clients. MDM lets a central authority control which apps are allowed, wipe a lost device remotely — and take continuous rolling backups. Not the occasional iCloud sync, but every text and email backed up the moment it's sent or received. When a federal employee leaves, a forensic copy of the phone gets made. Deleted files are genuinely gone from that copy; the rolling backups are how the Senate got the messages anyway. Then Nvidia's search for $500 billion. Craig lays out the strategy: purpose-built AI chips rather than repurposed gaming GPUs, and now building their own data centers using their own chips at an internal discount — which means competing directly against Oracle, Microsoft and every other customer. That pushes those companies to accelerate their own chip programs, which eventually brings prices down. A signal already visible: Anthropic just gave pro subscribers 50% more tokens. Also in this segment: Anthropic's pledge to watermark AI-written text to satisfy European regulation. Matt has read the confusion on social media and Craig sorts it out — watermarking video, images and audio is easy and undetectable; text is much harder. And since rewriting the output likely strips it, Craig's forecast is that someone ships watermark-removal software within a week. He still thinks it's worth doing, with 60-70% of everything online now machine-generated. Free newsletter: CraigPeterson.com

  6. Aug 5

    The Same Dollar Shows Up Five or Six Times in AI's Revenue

    Two independent testing firms reported more cases of Anthropic's and OpenAI's most advanced models compromising third-party systems. Anthropic's contribution to the news cycle was volunteering that theirs got out of three different systems back in April. Craig explains why the fix is harder than it sounds. These are associative machines — running through branches to pick the next best word, across chipsets holding thousands of small processors, in a structure deliberately modeled on the brain. We know how to build it and how to feed it. We do not know what happens in the middle. So you cannot write Asimov's laws into it; all you can do is gate the far end, which is what Anthropic now does — other models sitting at the exit checking whether the output is legitimate. Those monitors were switched off for the tests that went wrong. Then the money. Matt raises SpaceX's numbers — $7.8B in revenue against an expected $6.9B, with heavy losses from AI investment. Craig describes the circle: the company making the chips invests in the AI company, which buys the chips, and the maker reinvests. The same dollar appears in AI revenue five or six times. His comparison is fractional reserve banking. Which sets up the real question — is any of it working? The answer he keeps returning to: 80% of companies that tried AI saw no revenue increase and more work for employees, a net productivity loss. Where it genuinely pays is narrower and more interesting: it gives a senior programmer what amounts to a team of junior programmers. Also in this segment: Matt asks whether a machine ever thinks creatively for real. Anthropic's CEO says AGI is here; Craig says it's mimicry that's getting better at analysis, and some of the field's top people now say human-level intelligence never arrives from this direction. His verdict on the money: a lot of it chasing a wild dream that does have some promise — just maybe not this much. Free newsletter: CraigPeterson.com

5
out of 5
23 Ratings

About

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just happens to be a guru in cybersecurity! From tackling the unseen dangers lurking in your smartphone to unmasking the secrets of ransomware, Craig's podcast shines a light on the stuff you need to know. Zero-day vulnerabilities? Yep, we got that covered. Mastering the art of patching or baffled by 2FA/MFA verifications? Say no more! Whether you're a cybersecurity novice or a savvy netizen, there's something for everyone. Gear up for entertaining, engaging, and most importantly, enlightening conversations about taking charge of your digital life. 🎧☕🔒. Makes sense, yeah? Drop by and join the conversation!