Won't Fix

Won't Fix

Rob Leathern
アメリカ合衆国
言語 EN
エピソード数 13
最新 18.08.2026

From the founders of InfoHawk, this podcast explores AI-driven deception, abuse, and scams, and why they are so difficult to stop. The title references a software engineering term for a bug that is acknowledged but left unresolved because fixing it is too costly or risky. Listeners hear from practitioners who fight phishing, deepfakes, and bots, and learn about the broken systems and misaligned incentives that keep us vulnerable.

エピソード

  • Won't Fix Episode 13: With Alan Chapell of The Monopoly Report 18.08.2026 46分
    Rob Leathern speaks to privacy attorney and host of The Monopoly Report Podcast, Alan Chapell, about residential proxies, privacy and podcasting. Hear how free smart TV apps might be sharing your home IP address with strangers, and see just how broken online consent forms really are.Alan explains why current data broker laws miss these proxy networks entirely and how coming age verification rules could rewrite the open web.In This Episode:Free smart TV apps quietly bundle code that rents your home internet connection to strangers, creating vulnerabilities that look suspiciously like security exploits. Online consent breaks down with bandwidth sharing, when endless disclaimers mean nothing as consumers may have no easy way to turn the access off. State data broker laws miss the mark by hunting legacy data vendors while ignoring massive proxy networks, credit card companies, and telecom giants. AI companies pushing to scrape the entire web without limits could accidentally hand ad verification firms the ultimate legal shield against platform lawsuits. Strict age check laws could spark an arms race with clever teenagers that could end with governments requiring real ID just to browse the web. Chapter Timestamps:00:00 Introduction5:32 Residential Proxies: The "Ethically Sourced IP" Question and the LG TV Case9:48 Legitimate Uses vs. Harmful Behaviors of Residential Proxy Networks12:50 Data Broker Laws, Enforcement Gaps, and KYC14:40 Consent Problems: Revocation, Age Verification, and the LG TV Example16:56 Adware Parallels: History, Opt-Outs, and Financial Incentives23:31 Age Verification: A Looming Internet-Wide Challenge25:39 Scraping, Antitrust, and AI Companies29:40 Podcast Strategy, Guest Selection, and Speaking Recklessly41:53 Regulators, Historical Knowledge Gaps, and Industry DynamicsResources & Links:Rob Leathern (https://www.linkedin.com/in/leathern/)Alan Chapell (https://www.linkedin.com/in/alan-chapell-90711b/)The Monopoly Report (https://monopoly-report.com/)The Chapell Regulatory Insider (https://chapellreport.substack.com/)
  • Won't Fix Episode 12: With Jeff Allen Co-founder & CRO of the Integrity Institute 07.08.2026 48分
    Jeff Allen is the Co-founder and Chief Research Officer of the Integrity Institute, started in 2021. A physicist and astronomer by training, moved into data science in 2013, and has since worked all three sides of the platform-publisher relationship: for publishers chasing platform traffic, for the platforms themselves, and for political organizations navigating both.At Facebook he worked on systemic problems in the Facebook and Instagram public content ecosystems.Along with Spencer Gurley, Jeff Allen and the Institute recently published the July 2026 report which Ofcom commissioned — Fraudulent Advertising and Account Integrity: Expert Insights on Best Practice, which fed directly into Ofcom's draft Fraudulent Advertising Codes (published 10 July, consultation closes 2 October).In This Episode:Short-term ad revenue pits platform profits against user safety, making external regulation necessary to preserve long-term industry trust.Regulators need technical guidance from experts independent of Big Tech funding to build safety policies that can survive court challenges.Bad actors are using generative AI to quickly spin up realistic, multi-step scam sites that slip right past standard automated filters.Effective oversight requires a two-step system: platform self-reporting backed by independent audits from verified researchers.Scammers actively reverse engineer enforcement limits, making off-site damage and delayed user reporting persistent challenges.Chapter Timestamps:00:00 Introduction to Jeff Allen and the Integrity Institute1:46 The Integrity Institute's Mission and Approach3:29 The Scale of Online Scams and Fraudulent Advertising4:54 Regulatory Landscape and Ofcom's Role6:15 Development of the Ofcom Report10:33 Congressional Understanding and Regulatory Progress12:04 Media Coverage Challenges in Advertising15:02 Incentive Alignment and Regulatory Approach18:52 Data Access Challenges and Solutions21:40 Internal vs External Research Challenges24:07 The Sales Challenge in Data Science28:50 Specific Transparency Metrics and Market Impact32:46 Guidelines Disclosure and Adversarial Dynamics35:15 The "Three Slide Rule" and Off-Platform Harm40:17 Evolution of Fraudulent Content Creation43:23 Researcher Access and Data Requests45:25 Educational Needs and Trust and Safety CurriculumResources & Links:Integrity Institute (https://www.integrityinstitute.org/)Integrity Institute Report (https://www.integrityinstitute.org/research/response-to-ofcoms-request-for-research-on-fraudulent-advertising-and-account-integrity)Rob's Notes (https://robleathern.substack.com/p/robs-notes-47-on-ofcoms-fraudulent)Jeff Allen (https://www.linkedin.com/in/jeff-allen-scientist/)Ofcom (https://www.ofcom.org.uk/)Rob Leathern (https://www.linkedin.com/in/leathern/)
  • Won't Fix Episode 11: With Independent Researcher & Consultant Ben Edelman 24.07.2026 48分
    Ben Edelman has spent two decades catching online fraud that hides in plain sight — combining software engineering, law, and economics to prove misconduct empirically rather than take companies at their word. In this conversation we get into the Phia shopping-plugin scandal, how it relates to Honey and Paypal that he covered after Megalag broke the issue on YouTube, the mechanics of affiliate fraud, and his recent investigation into AppLovin's apparent app install deals with mobile carriers.In This Episode:How Ben got into fraud investigation, and what keeps him motivatedPhia's "cookie stuffing": how a browser extension can claim affiliate credit for sales it didn't driveWhether Phia's "December bug" oopsy explanation holds up, and Phia's earlier 2025 privacy “mistake”The Honey/Paypal parallels, typosquatting and the broader toolkit of affiliate-fraud techniquesMegaLag vs. the mainstream media: how independent investigators break stories nowAppLovin's nonconsensual install investigation he wants state AGs to look atWhat meaningful accountability looks like, and his advice to founders building in this spaceLinks & Resources:Ben Edelman's AppLovin investigation: https://www.benedelman.org/applovin-nonconsensual-installs/Ben Edelman's site (full archive of his research): https://www.benedelman.org Ben's list of "Investors supporting spyware": https://www.benedelman.org/spyware/investors/Edge Shopping Stand-Down Violations: https://www.benedelman.org/edge-shopping-standdown/Phia forced clicks and stand-down violations: https://www.benedelman.org/phia-forced-clicks/Honey stand-down violations and concealment: https://www.benedelman.org/honey-detecting-testers/Adware investors page:https://www.benedelman.org/spyware/investors/"Spontaneous Deregulation: How to Compete with Platforms that Ignore the Rules" (HBR article about intentional rule-breaking as a business strategy): https://www.benedelman.org/publications/hbr-spontaneous-deregulation-apr2016.pdfRob Leathern (https://www.linkedin.com/in/leathern/)Chapter Timestamps:00:00 Introduction and Background on Online Fraud Investigation1:36 The Origins: Gator Adware and Early Ad Fraud (2001)3:10 The Dark Chapter of VC-Funded Adware4:54 Transition to Independent Investigation Work6:07 FIA Investigation: Two Types of Violations7:31 Understanding Forced Clicks Through Analogies9:50 Debunking FIA's "Recent Bug" Defense12:50 FIA's Previous Screenshot Controversy14:18 The Current "Dumb Tech Cycle" and Screenshot Overuse16:20 Recurring Patterns: From Gator to Modern Shopping Plugins21:11 Startup vs. Public Company Misconduct Patterns24:40 PayPal's Due Diligence and Ongoing Modifications27:24 Media Resources and Technical Expertise30:17 Typo squatting and Google's Role31:36 The Ad Tech Attention Gap33:34 AppLovin Investigation: Install Helpers and Carrier Partnerships34:21 Wall Street Journal's Surprising Rejection40:28 Carrier Billing and Historical Context44:42 Advice for Founders: The Temptation and Risk of Cheating
  • Won't Fix Episode 10: With Lindsay Kaye & Will Herbig of HUMAN Security 17.07.2026 47分
    On July 7, 2026, HUMAN’s Satori team exposed NewsJunkie, a massive, coordinated connected television (CTV) device-spoofing operation that generated up to two billion invalid bid requests per day, per seller.In this episode of Won’t Fix, we go inside the investigation with Lindsay Kaye (VP of Threat Intelligence) and Will Herbig (Senior Director of Media Research) from HUMAN Security to break down how this sophisticated fraud was uncovered.We then zoom out and the conversation to talk about the connected TV ecosystem in general and how AI and automation are changing the security threat landscape in general. Resources & Links:HUMAN Security Website: https://www.humansecurity.com/The Full NewsJunkie Report: https://www.humansecurity.com/learn/resources/human-disrupts-ctv-device-spoofing-newsjunkie/Lindsay’s Book (Dissecting the Dark Web, No Starch Press): https://nostarch.com/dissecting-the-dark-webRob Leathern (https://www.linkedin.com/in/leathern/)Chapter Timestamps:00:00 Introduction1:13 Team Backgrounds and Roles at Human Security3:31 Understanding the News Junkie Operation Structure5:27 Key Anomalies That Exposed the Fraud8:32 Scale and Impact of Invalid Traffic10:14 Evolution and Persistence of the Operation14:15 Residential Proxies and Infrastructure Connections20:24 AI-Generated Fake Business Identities23:44 Disruption Strategies and Industry Response26:48 Systemic Gaps and Supply Chain Compliance Issues31:48 Device Attestation and Technical Solutions34:41 AI's Impact on the Security Landscape41:33 Investigation Methodology and Future Outlook
  • Won't Fix Episode 9: With Juliet Shen, Cofounder & HOP at ROOST 07.07.2026 46分
    Juliet Shen is cofounder and Head of Product at ROOST (Robust Open Online Safety Tools), a nonprofit building open-source trust-and-safety infrastructure for platforms of every size. She has done anti-abuse product work at Google and Grindr, and was the first trust-and-safety product manager at Snap, where she helped launch early cross-platform efforts to combat child exploitation. ROOST's website is https://roost.tools.Across her career, Juliet kept running into the same maddening pattern: every trust-and-safety team, at every platform, quietly rebuilding the same rules engines, review queues, and reporting pipelines from scratch, behind closed doors, and at enormous cost. ROOST is a bet that online safety should be shared, open infrastructure rather than proprietary secret sauce, available free to any platform or site that needs it. We talk about that, and a lot more.Key Highlights:Every tech company shouldn't have to build their trust and safety tools from scratch behind closed doors. It’s an expensive waste of time when open-source infrastructure could solve the exact same foundational problems for everyone.PMs and engineers need to step up and lead in the trust and safety space. They are the ones who can actually bridge the gap and get policy, operations, engineering, and legal teams talking to each other.AI is great for knocking out the easy, baseline moderation tasks. But when a situation is highly nuanced or something the AI hasn't seen in its training data, you still absolutely need human judgment.As social media breaks apart into decentralized networks, a one-size-fits-all safety system won't work anymore. We need modular tools that let platforms look at who the user is, how they're behaving, and what they're posting as separate pieces of the puzzle.Good moderation is often less about analyzing the post itself and more about knowing exactly who is behind the account or the app. Right now, our lack of solid identity verification is a massive blind spot for digital safety.Chapter Timestamps:00:00 Introduction 1:34 Career Journey and the Problem of Redundant Tool Building 5:30 The Role of Product Managers in Trust and Safety Teams 7:34 Impact of LLMs on Trust and Safety Operations 11:27 Focus Areas and Child Safety Priority 12:55 The ABC Framework and Actor Trust Challenges 16:54 Community Building and TrustCon Participation 19:13 Signal Sharing vs Tool Sharing Philosophy 22:43 Open Source Approach and Scaling Challenges 23:59 Future Roadmap and Research Partnerships 28:52 Reviewer Well-being and Mental Health Considerations 32:00 Centralized vs Decentralized Moderation Models 37:15 Government Role and Open Source Support 39:52 Success Metrics and Measurement Challenges 42:50 Standards, Testing, and Future Directions Resources & Links:Rob Leathern (https://www.linkedin.com/in/leathern/)Juliet Shen (https://www.linkedin.com/in/julietshen/)ROOST (https://roost.tools)
  • Won't Fix Episode 8: With Dave Kleidermacher of Google 30.06.2026 54分
    Dave Kleidermacher is a vice president of engineering at Google, leading engineering for Android security and privacy. His scope encompasses Android and the Made-by-Google world — Pixel, Nest, Fitbit, and the Play Store.We talked about Android's answer to scams: smarter defenses that use AI as a shield (on-device detection that catches scams as they unfold), and a deeper structural pivot to "Actor Trust" — establishing provable, cryptographic confidence in who or what a source is rather than forever trying to detect bad things.Dave has been steeped in these topics for a long time so we get into a bunch of great territory, and I think you’ll really enjoy the conversation.Key Highlights:Consumer platforms must pivot from traditional vulnerability exploitation defenses to fighting scams and fraud, which make up 99% of actual practical threats facing users today.The future of mobile authentication lies in reversing security asymmetry through "actor trust" cryptographically verifying the source device rather than relying on human intuition.Big Tech players like Apple and Google need to publish a transparent, accountability driven joint priority roadmap to accelerate cross-platform security for critical defenses like caller verification.Mobile network operators remain a critical structural weak point in consumer safety due to privacy-invasive habits like silent third party app installations and outdated location-tracking protocols.Chapter Timestamps:00:00 Introduction and Background3:01 The Shift from Vulnerability Threats to Scam Prevention ‎6:01 Real-time Voice Spoofing Capabilities and Demonstrations ‎8:19 Platform Defense Strategies and the Whack-a-Mole Problem ‎11:00 Actor Trust and Cryptographic Verification Approach ‎15:37 Google's Security Key Success and Developer Ecosystem Verification ‎17:35 RCS Standards and Industry Collaboration Challenges ‎27:19 Business Caller Verification and Stir Shaken Limitations ‎31:59 Privacy-Security Balance and Binary Transparency ‎41:30 Consumer Role and Stakeholder Responsibilities ‎43:27 Future AI Landscape and Industry Recommendations ‎49:47 Advertising Technology and Platform Accountability ‎Resources & Links:Rob Leathern (https://www.linkedin.com/in/leathern/)Dave Kleidermacher (https://www.linkedin.com/in/davekleidermacher/)
  • Won’t Fix Episode 7: With Jeremy Philip Galen of Charlemagne Labs 19.06.2026 39分
    My guest today is Jeremy Galen, founder of Charlemagne Labs. Jeremy spent twelve years at Meta working in privacy, safety, and security — most recently five years as a product manager in trust and safety, focused on machine-learning content enforcement, account access, impersonation, and plagiarism.He left to start Charlemagne Labs, a New York startup building what he calls a "digital bodyguard" — an on-device AI assistant, Agent Charley, that steps in before a worker clicks a dangerous link or pastes sensitive data into a chatbot.The company's research recently landed in Meta's safety report for its frontier model, Muse Spark, where Charlemagne's benchmark measured how capable leading AI models are at multi-turn social engineering. His core argument is that the old "think before you click" model of security is broken, and that risky digital behavior should be treated less like a moral failure and more like a public-health and system-design problem.Learn more about Jeremy and the company at https://charlemagnelabs.ai/Listeners who sign up for the Pro plan can get 6 months for free if they use the promo code ROB2026. Key Highlights:Selling consumer security software is a non-viable market because consumers buy what they want, while businesses buy what they need.The open internet operates as an active battlefield where users face direct threat vectors from sophisticated foreign adversaries.Falling for social engineering scams is entirely situational, rather than a reflection of an individual's intelligence.Real-time, automated AI interventions are far more effective at enforcing digital hygiene than relying on static digital literacy training.Over 90% of modern cybersecurity incidents originate from human risk vectors where an individual is directly targeted or manipulated.Chapter Timestamps:00:00 Introduction and Guest Background1:02 Career Transition and Startup Journey2:33 Consumer vs. Business Security Market Analysis3:56 Personal Motivation and Scam Prevalence5:09 Social Engineering Sophistication and Victim Blaming8:01 Big Tech vs. Startup Challenges13:59 Fundraising Reality and Survivor Bias18:05 Digital Hygiene and AI-Powered Protection22:06 Privacy-First Architecture and Local Models28:18 Democratizing Security and Luxury Concerns31:59 Meta Collaboration and Industry Standards35:16 Founder Advice and Problem Selection38:08 Company Information and Target MarketResources & Links:Rob Leathern (https://www.linkedin.com/in/leathern/)
  • Won't Fix Episode 6: With Tate Jarrow, Founder & CEO of Rebound 05.06.2026 47分
    Tate Jarrow is the Founder and CEO of Rebound (https://trustrebound.com), a consumer anti-scam company. Before founding Rebound, Tate was an Army infantry officer and Airborne Ranger, and then a Special Agent at the U.S. Secret Service.At Google, he helped start a company called Beacon through the Area 120 incubator, which was then acquired into Google One.Key Highlights:What Rebound is building: "Antivirus but for scams" — software that sits on a user's device across macOS, Windows, iOS, and Android, sees what the user sees, and alerts when it detects an inbound scam. Currently in alpha, heading into paid beta within the month, with general availability targeted for summer.Why now: Normal people have zero real defense against scams. Law enforcement don't have resources for individual cases, and platforms are hard to reach for recovery. Existing consumer cybersecurity is rooted in 20-year-old problems (antivirus, credit monitoring) and isn't built for AI-powered, personalized, scaled attacks.“You can't arrest your way out of cybercrime”: Cyber criminals run transnational organizations as businesses with P&Ls, so the real lever is changing the economics.Google: Tate started in legal/investigations chasing cybercrime actors on Google platforms, got frustrated by the gap between business incentive and what could actually be done. Two of his Area 120 teammates are now on the Rebound team.Scam overconfidence: Tate shares that a GASA study found the #1 predictor of being scammed is confidence that you can spot one — overconfidence is the actual risk factor. Every demographic gets hit.Regulation and data: US regulation is 20 years behind. The real risk now is social engineering powered by leaked addresses, phones, emails, and contacts. He wants companies held accountable for the social engineering risk they create, not just PII in the narrow legacy sense."Caring guardians": People in tech are the de facto security help desk for their parents, friends, and families. Rebound is building features so a tech-savvy family member can have visibility into risk across the people they care about — plus in-app trust verification (one-click identity check) for the "is this actually my friend messaging me?" problem.Chapter Timestamps:00:00 Introduction and Background1:26 Rebound's Mission and Product Overview3:39 Technical Implementation and Current Status4:45 Motivation Behind Consumer Protection Focus7:45 Google Journey and Area 120 Experience14:59 Law Enforcement Perspective on Cybercrime18:30 Evolution of Cybercriminal Organizations21:07 Current State of Consumer Protection30:04 Regulatory Environment and Government Role37:25 Community Protection and Cross-Platform Challenges43:00 Product Vision and Future PlansResources & Links:Rebound (https://trustrebound.com)Tate Jarrow (https://www.linkedin.com/in/tatejarrow/)Rob Leathern (https://www.linkedin.com/in/leathern/)
  • Won't Fix Episode 5: With Platformocracy's Jonathan Bellack 22.05.2026 53分
    Jonathan spent thirty years inside the machine — product leadership at DoubleClick, executive roles at Google, and a founding role at Harvard's Applied Social Media Lab. A year ago, Jonathan started writing Platformocracy, a newsletter with a simple, uncomfortable thesis: tech companies didn't set out to govern us, but they do now. Billions of people are subject to rules they didn't vote for, enforced by systems they can't see, with no meaningful right of appeal — built, in many cases, by people who genuinely wanted to do the right thing.We talk about how that happened, what it looks like from the inside, and the question that may define the next five years: what happens when AI floods every platform with infinite synthetic content, and the only thing standing between us and the noise is an algorithm the noise was engineered to exploit?Key Episode Takeaways:The Governance Illusion: Tech platforms have evolved into unelected global governments that impose top-down rules on billions of users who have zero democratic input or meaningful right of appeal.The Category Mistake: Treating platforms strictly as private businesses that can refuse service ignores the reality that they host deeply rooted human communities where "exiting" the platform means abandoning essential real-world relationships.Decomposing Social Media: Effective regulation requires breaking "social media" down into three distinct product categories—media consumption, community networking, and creator relationships—because a blanket approach fails to address the unique harms of each.Shifting the Regulatory Burden: Instead of forcing mass identity verification, regulators should require platforms to accept enhanced safety obligations and standardized parental controls if they choose to profit from serving children.Inverted Safety Baselines: Unlike heavily regulated sectors like automotive or food hospitality, tech platforms operate on a model where they maximize user safety only up to the point that it threatens their profit margins.Episode Highlights:00:00 Introduction1:43 The Challenge of Corporate vs. Community Framing2:54 The Evolution from Community Management to Corporate Governance20:48 Age Verification Concerns and Technical Challenges24:47 Historical Context and Generational Perspectives27:46 AI, Anonymous Accounts, and Platform Integrity37:19 AI's Potential for Improved Parental Controls42:40 Regulatory Approaches: Enhanced Obligations for Serving Children45:18 Profit vs. Safety Standards in Tech Industry50:43 Procedural vs. Substantive Law in Platform GovernanceLinks:Read Jonathan's newsletter: https://www.platformocracy.comJonathan BellackRob Leathern
  • Won't Fix Episode 4: With Indicator's Craig Silverman 01.05.2026 50分
    Craig Silverman is an award-winning journalist who has spent more than 15 years researching and reporting on the manipulation of our information environment. He is currently the co-founder of Indicator, a media outlet dedicated to exposing digital deception and teaching digital investigative and OSINT (open-source intelligence) techniques.Prior to launching Indicator, Craig was a national reporter at ProPublica, where he focused on investigating digital platforms and online manipulation. Before that, he served as the media editor for BuzzFeed News, where he pioneered innovative approaches to exposing digital disinformation and media manipulation.Key Episode Takeaways:The Industrialization of Deception: Digital manipulation has shifted from lone actors into a massive, industry backed by venture capital and brutal supply chains, including Southeast Asian "scam compounds" that merge human trafficking with high-tech fraud.The "Manufactured Organic" Loophole: Brands are now using "clipping" and industrial-scale UGC campaigns to generate billions of views through paid creator networks that mimic authentic posts.An Incentive to Cheat: The current digital economy creates a "race to the bottom" where deceptive or violative content often sees higher engagement and lower costs than honest ads.Ad Revenue Cannibalization: By failing to police undisclosed marketing, social platforms are letting a shadow ad economy thrive that actively drains budgets away from their own official, trackable ad businesses.Deterrence Through Public Examples: Instead of trying to automate everything, platforms could flip the script by making high-profile, public examples of agencies that openly brag about their deceptive tactics on social media.Episode Highlights:00:00 Introduction and Background of Craig Silverman01:21 Early Collaboration and Scam Evolution04:27 Indicator Media's Mission and Approach08:29 Undisclosed Marketing and UGC Campaigns13:21 Scale and Enforcement Challenges20:51 Platform Cannibalization and Business Impact28:29 AI Labeling Audit Results34:15 Community-Based Detection and User Skills39:17 Affiliate Marketing Case Study46:48 Systemic Incentive Problems49:13 Conclusion and ResourcesLinks:Craig SilvermanIndicatorRob Leathern
  • Won't Fix Episode 3: With KTLYST Labs' Assaf Kipnis 24.04.2026 42分
    Assaf Kipnis spent years hunting financially motivated bad actors on Meta's e-crime team and in Google's Ads Trust & Safety org.He now runs KTLYST Labs, where he's building the threat intelligence tooling he always wished existed inside big platforms. We get into the practical realities of scam fighting — what's actually changed in the AI era, what hasn't, and why so much of the industry's effort gets aimed at the wrong targets.About the guest: Assaf Kipnis is the founder of KTLYST Labs. Previously: Meta e-crime, Google Ads Trust & Safety, ElevenLabs, LinkedIn threat intel.What We Cover:Why AI isn't reinventing scams — it's just adding a more convincing final layer to playbooks that have existed for years.The asymmetry problem: bad actors run conferences, sell each other tools, and share playbooks on Telegram, while defenders can't share findings across teams at the same company.A case study in what actually works — how changing product, policy, and operations together pushed a misinformation-for-profit ring off the platform in a week.Why "accounts taken down" is a near-useless metric, and the "learned futility" it creates inside big trust & safety orgs.The Swiss cheese model of abuse prevention, and why chasing a single silver-bullet solution keeps companies chasing their tail.Where regulation has teeth (banking) and where it's mostly performative (social media), plus the cross-platform gap no one is addressing.How AI is changing investigative work — compressing a week of open-source research into two hours — and why that makes entry-level talent pipelines a real concern.Episode Highlights:00:00 Intro01:06 Professional Background and Career Journey ‎03:47 AI's Role in Scaling Rather Than Changing Scams ‎07:05 Adversary Collaboration vs. Defender Silos ‎09:02 The Frame Rate Discovery Example ‎10:26 KTLYST Labs and Operationalizing Threat Intelligence ‎12:40 AI's Impact on Investigation Work ‎15:15 Career Entry Points and AI's Impact on Junior Roles ‎20:38 The NextTag Affiliate Program Attack ‎23:00 The Misinformation Campaign Investigation ‎27:52 The Limitations of Location-Based Solutions ‎30:30 The Futility of Single-Solution Thinking ‎33:47 The Reality of Platform Defense Goals ‎34:50 Government Regulation and Enforcement Challenges ‎40:31 The Problem with Takedown Metrics ‎Links:Assaf KipnisKTLYST LabsRob Leathern
  • Won't Fix Episode 2: With Project Brazen's Tom Wright 16.04.2026 42分
    Investigative journalist Tom Wright (Project Brazen) joins Rob Leathern to discuss the staggering rise of Benjamin Mauerberger, a South African money launderer who utilized crypto exchanges and high-level political "state capture"; to fund a billionaire lifestyle of super yachts and private jets while evading an international dragnet.Tom shares more about the dark underbelly of a $200 billion global scam industry where industrial-scale "pig-butchering" complexes in Southeast Asia target citizens around the world.Key Episode Takeaways:The "state capture" playbook enables global fugitives: Large-scale money launderers use their wealth to gain political protection, setting national digital policies and even attending cabinet meetings to integrate criminal proceeds into traditional banking systems.Cryptocurrency serves as a high-speed financial superhighway: Modern fraud has moved beyond traditional banking into crypto "piping," allowing scammers to move value across borders with frictionless speed and scale.A "double victimization" cycle defines the scam industry: The global fraud network relies on a brutal labor model where workers are often human trafficking victims lured by legitimate job offers only to be imprisoned and tortured within scam compounds.Economic impact now rivals Fortune 500 revenues: Estimates suggest the US economy loses approximately $200 billion annually to these scams—a figure that exceeds the annual revenues of automotive giants like GM or Ford.Jurisdictional arbitrage creates a "cat and mouse" regulatory game: Criminal entities constantly shift operations to less regulated territories, such as moving from the Seychelles to the Turks and Caicos, to evade tightening anti-money laundering oversight.Reputational "whitewashing": Questionable financial entities attempt to gain mainstream legitimacy by sponsoring world-class athletes or prestigious events to obscure their underlying involvement in global money laundering networks.Episode Highlights:00:00 Intro01:45 The Genesis of Billion Dollar Whale04:47 Evolution from Traditional Fraud to Crypto-Enabled Scams08:13 Mauerberger's Rise and Political Connections10:35 Mauerberger's Flight and Current Status15:48 The Crypto Money Laundering Operation24:40 The Human Cost and Complexity of Scam Operations27:14 Challenges in Reporting and Government Response32:34 The Broader Implications and Future OutlookLinks:Project BrazenBillion Dollar WhaleTom WrightRob Leathern
  • Won't Fix Episode 1: With tofu's Jason Zoltak 07.04.2026 42分
    In this first episode of Won't Fix, Rob Leathern talks to Jason Zoltak.Jason is the founder and CEO of tofu, which is using AI and machine learning to fight fraud and deception in hiring and recruiting.About Won't Fix: In software engineering, “won’t fix” describes a bug by acknowledging the issue but intentionally leaving it unsolved because addressing it is too costly, risky, or not worth the trade-offs.Hear from the practitioners fighting phishing, deepfakes and bots, and learn about the broken systems and misaligned incentives that keep us all vulnerable.Key Episode Takeaways:The Identity Fraud Pivot: tofu shifted from an AI resume screening tool to a fraud detection platform after discovering that remote hiring has enabled a massive surge in sophisticated identity misrepresentation.Near-Universal North Korean Infiltration: Virtually every company hiring for remote technical roles is now a target for North Korean IT workers, with some applicant pipelines reaching 80% fraud rates.The Fragmentation Vulnerability: The lack of a "digital passport" and the break in verification when moving a candidate from LinkedIn to an internal ATS creates a massive security gap for fraudsters to exploit.Shift in Security Ownership: Candidate fraud is transitioning from a Talent Acquisition burden to a CISO priority as companies realize recruiters lack the budget and expertise to fight organized cybercrime.Economic Scalability of Fraud: Fraudsters aren't looking for long-term tenure; they use deepfakes and proxies to "job stack," collecting multiple salaries simultaneously for a few months before being caught.The "Confirmation Bias" Trap: Once a candidate reaches the final interview stages, hiring managers and recruiters are psychologically prone to ignore red flags, making them vulnerable to sophisticated identity theft.2:29 Jason's Background and tofu's Evolution4:09 Discovering Candidate Fraud Through Direct Investigation5:04 Market Response and Business Pivot Decision6:35 Personal Motivation and AI Identity Challenges8:17 Spectrum of Fraud vs. Embellishment in Hiring10:25 Prevalence of North Korean IT Worker Infiltration11:30 Evolution of Fraud Techniques and Identity Theft13:18 Root Causes: Platform Disconnection and Identity Verification15:26 Security vs. Talent Acquisition Budget and Responsibility Issues17:36 LinkedIn Verification Challenges and Behavioral Incentives19:20 Impact of Thin Digital Footprints on Legitimate Candidates21:35 False Positive Management and Digital Footprint Requirements24:16 Interview Process Fraud: Deepfakes and Proxy Detection26:01 Sophisticated Deepfake Case Study and Technical Evidence28:17 Economic Incentives and Scaling Strategies for Fraudsters29:26 Corporate Espionage and Strategic Target Selection32:15 Recruiter Incentive Conflicts and Trust Erosion36:13 Critical Case Study: Final Round Interview Fraud Detection37:28 Government Regulation vs. Private Sector Solutions39:39 Upcoming Product Launches: ATS Reconnaissance and Continuous Monitoring

人気の国

このポッドキャストはこれらの国のポッドキャストチャートにも登場します。