• The Time They Once Hacked Our Routers to Patch Them
    2026/08/26

    The FBI, CIA, NSA, CISA and others issued a warning about active AI-driven attacks on American critical infrastructure. Craig, who ran the FBI's InfraGard online training program, explains what's actually exposed: old controllers that open and close valves, set flow rates, decide how much acid or base goes into the water — many of them reachable directly from the internet, on networks that have been comprehensively mapped for years. Several water systems have already been shut down; one town lost power along with its water.

    Josh, who works InfraGard in his own homeland security practice, asks the right question: if an adversary can use AI to find and exploit these holes, what stops us using ours to find and patch them first?

    Craig's answer is the best story in the segment. Last year a botnet was running attacks out of tens of thousands of home routers — cheap hardware bought at Staples or Walmart, full of holes. So the FBI and NSA hacked into those routers, on private home networks, and patched them, breaking the attackers' control. Our government hacked our own equipment to fix it. As far as Craig knows it has happened exactly once.

    He's honest about the limits: defensive AI exists at Microsoft, Anthropic and OpenAI, but it can't help with vulnerabilities people don't know they have. And you can't change the consumer — people still buy cheap Android phones.

    Also in this segment:

    • Remembering Dolly Parton, who wanted to be faxed rather than called and didn't want her mind fed into an AI — alongside the Dolly Parton Experience built from lasers and technology, and hundreds of unreleased recordings
    • A defense contractor employee who clicked one email and exposed the company; Craig has worked similar cases with the FBI's Boston office
    • The two things to do about it: delete any program you haven't used in a while, on your phone as well as your computer, and put something like OpenDNS in front of your browsing so a known-bad link can't resolve

    Free newsletter: CraigPeterson.com

    続きを読む 一部表示
    14 分
  • Five Federal Agencies, One Warning — and an Argument About the Singularity
    2026/08/25

    The NSA, CISA, the FBI, the Department of Energy and the EPA put out a joint advisory last Wednesday, and the language is unusually direct: AI dramatically reduces the technical skill and the time required to attack industrial control systems. Those controllers run public works. A great many of them are reachable from the internet, and their locations are not a secret.

    That sets up the larger conversation. Ray Kurzweil wrote The Singularity Is Near twenty years ago, predicting broadly human-level machine intelligence by 2029 and human-machine integration by 2045. Elon Musk and others now say we're already there. Craig disagrees with both, and explains why with a test that cuts through the argument: can it take genuinely unrelated ideas and put them together into something new? No. It cannot. What it does is follow trees of information it already has, very fast, from many angles at once.

    He grants everything that deserves granting — reading a mammogram better than a radiologist is real, and it is still pattern matching against millions of prior images. Anyone who has used one of these tools to write code or draft a document knows the rest: it misses major things, and you are constantly correcting it.

    Then Jeff asks the better question. Set reasoning aside — what about emotion? What makes one living thing care about another? Craig's answer is that we haven't finished defining it, which is its own kind of answer.

    Also: the resolution to last week's Wi-Fi mystery, which turned out to be mesh extenders unplugged during a home renovation and never put back.

    Free newsletter: CraigPeterson.com

    続きを読む 一部表示
    11 分
  • People Would Rather Live Next to a Nuclear Plant Than a Data Center
    2026/08/19

    Matt opens with a poll finding he calls one of the great PR failures of our time: people would rather have a nuclear power plant built next door than a data center. Pennsylvania's governor has now signed legislation that effectively stops data centers unless they clear a long approvals process.

    Craig's answer isn't a defense of data centers so much as a description of what a few counties actually did. They said yes — on conditions. Generate your own power, and 20% more than you use, fed back into our grid. And pay full property tax, none of the abatement deals. It worked well enough that those counties are now tax-free for individual residents, with more power on the grid than before.

    He also separates the honest concern from the manufactured one. If a data center is pulling from a stream and returning it at 120 degrees, that's a real problem worth zoning for. But China has been found amplifying anti-data-center sentiment in the United States through social media — the nudge concept again — because they would rather the U.S. not build. Alibaba's newest Qwen is reported on par with the best American models.

    Then the second half, which Matt frames as another step toward Skynet: a near-autonomous cyberattack on the Taiwanese government, plus two more documented company attacks in a week and a half. In one, the attacker was brash enough to publish the prompt he used and describe walking away while it kept working.

    Craig's framing is what makes it land. The old way was one vulnerability, one piece of code, six months to a year of work. The new way is "go for it, figure it out" — and it works because vulnerabilities are everywhere: over 500 Microsoft patches this month, about a dozen from Apple for macOS. As for regulating it, he asks how a law stops a Chinese open model that anyone in the world can already download.

    Also in this segment: whether social media feedback loops explain the spread of political extremes, and Craig's read that this is a problem of financial motivation rather than technology.

    Free newsletter: CraigPeterson.com

    続きを読む 一部表示
    12 分
  • 1,140 Ransomware Attacks on Industry in One Quarter — 740 of Them Manufacturing
    2026/08/18

    The numbers carry this segment. Eleven hundred forty ransomware attacks on industrial companies in a single quarter, 740 of them against manufacturers. A recent Patch Tuesday carrying about 570 fixes. An Apple advisory telling anyone whose machine touches a coffee-shop network to update now.

    Craig's point is narrower and more useful than the headline count. Windows Update patches Microsoft software, and not all of it. The average computer is running roughly 60 other programs it never looks at. Older versions of ordinary things — Adobe Reader is the one he names — are what attackers are actually walking through.

    So Craig built the tool nobody was building. It reads every piece of software on a machine against a database of about three and a half million known-vulnerable versions and reports which ones have working exploits behind them. It runs for his business clients and for retirees.

    That is the shape of the advice: count what is on the machine, check what is current, and find out what stopped receiving updates and when. Three numbers, and then a decision.

    Also in this segment:

    • Jim on Quebec City's tourism campaign, and Craig — a former Canadian — on why it genuinely does read as Europe
    • The FCC's concerns about spyware in imported robot vacuums
    • A teaser for next week: what, if anything, government can actually do about this

    Free newsletter and Insider Session announcements: CraigPeterson.com

    続きを読む 一部表示
    16 分
  • Fixing Jeff's Wi-Fi, Live On the Air
    2026/08/18

    Jeff's studio Wi-Fi had been misbehaving for weeks, so this segment became a clinic — and one you can follow along with on your own network, because Craig has Jeff run the test live.

    The two bands do different jobs. 2.4 GHz travels farther and gets through walls and windows better, but it carries only a few channels, so in an apartment building or a dense neighborhood your neighbors are stepping on you. 5 GHz has the room but not the reach. Anything older than about ten years doesn't have the choice, and Wi-Fi 6, 7 and the coming 8 handle the congestion far better than what came before.

    Then the diagnosis. Go to speed.cloudflare.com — free, no signup. Speed is the least interesting number it gives you. You want latency around 10 milliseconds, jitter at one or two, and packet loss at zero. Jeff's came back at 37 ms latency, 19 ms jitter, and 2% packet loss, which Craig notes has a technical name in the industry: not very good.

    The rest of the segment is what to do about it — retest standing next to the router to separate "my house" from "my provider," metal studs and metal floors in commercial buildings, fluorescent lights and transformers, NetSpot on Windows, and the option-click trick on a Mac that shows you the interference numbers directly.

    Craig also mentions the free computer scans now available through his site.

    Free newsletter: CraigPeterson.com

    続きを読む 一部表示
    12 分
  • Why Deleting a File on an iPhone Is Different — and How the Senate Got Fauci's Texts Anyway
    2026/08/12

    When you erase an iPhone and it finishes in a second, nothing was erased. The phone destroyed the encryption key. Craig explains the layer most people miss: every individual file has its own key, so deleting one file destroys that file's key and the contents can never be recovered — unlike Windows, where a deleted file usually sits there waiting for recovery software.

    Which raises the obvious question about a phone with very few contacts left on it. The answer is mobile device management, the same category of software Craig runs for his clients. MDM lets a central authority control which apps are allowed, wipe a lost device remotely — and take continuous rolling backups. Not the occasional iCloud sync, but every text and email backed up the moment it's sent or received. When a federal employee leaves, a forensic copy of the phone gets made. Deleted files are genuinely gone from that copy; the rolling backups are how the Senate got the messages anyway.

    Then Nvidia's search for $500 billion. Craig lays out the strategy: purpose-built AI chips rather than repurposed gaming GPUs, and now building their own data centers using their own chips at an internal discount — which means competing directly against Oracle, Microsoft and every other customer. That pushes those companies to accelerate their own chip programs, which eventually brings prices down. A signal already visible: Anthropic just gave pro subscribers 50% more tokens.

    Also in this segment: Anthropic's pledge to watermark AI-written text to satisfy European regulation. Matt has read the confusion on social media and Craig sorts it out — watermarking video, images and audio is easy and undetectable; text is much harder. And since rewriting the output likely strips it, Craig's forecast is that someone ships watermark-removal software within a week. He still thinks it's worth doing, with 60-70% of everything online now machine-generated.

    Free newsletter: CraigPeterson.com

    続きを読む 一部表示
    14 分
  • The Same Dollar Shows Up Five or Six Times in AI's Revenue
    2026/08/05

    Two independent testing firms reported more cases of Anthropic's and OpenAI's most advanced models compromising third-party systems. Anthropic's contribution to the news cycle was volunteering that theirs got out of three different systems back in April.

    Craig explains why the fix is harder than it sounds. These are associative machines — running through branches to pick the next best word, across chipsets holding thousands of small processors, in a structure deliberately modeled on the brain. We know how to build it and how to feed it. We do not know what happens in the middle. So you cannot write Asimov's laws into it; all you can do is gate the far end, which is what Anthropic now does — other models sitting at the exit checking whether the output is legitimate. Those monitors were switched off for the tests that went wrong.

    Then the money. Matt raises SpaceX's numbers — $7.8B in revenue against an expected $6.9B, with heavy losses from AI investment. Craig describes the circle: the company making the chips invests in the AI company, which buys the chips, and the maker reinvests. The same dollar appears in AI revenue five or six times. His comparison is fractional reserve banking.

    Which sets up the real question — is any of it working? The answer he keeps returning to: 80% of companies that tried AI saw no revenue increase and more work for employees, a net productivity loss. Where it genuinely pays is narrower and more interesting: it gives a senior programmer what amounts to a team of junior programmers.

    Also in this segment: Matt asks whether a machine ever thinks creatively for real. Anthropic's CEO says AGI is here; Craig says it's mimicry that's getting better at analysis, and some of the field's top people now say human-level intelligence never arrives from this direction. His verdict on the money: a lot of it chasing a wild dream that does have some promise — just maybe not this much.

    Free newsletter: CraigPeterson.com

    続きを読む 一部表示
    13 分
  • Two AI Labs Are Arguing About Whose Model Escaped First
    2026/08/04

    OpenAI's high-end model, under test, ended up breaking into Hugging Face. Then Anthropic said theirs had gotten out three times back in April. Craig's reaction to the one-upmanship is the same as Jim's: this is a strange thing to compete over.

    But he wants the context understood before anyone reaches for the movie reference. Nobody told these systems to escape. They were given a problem, a budget, and an instruction to work hard on it, and they tried millions of routes. One route was a machine with internet access. That is not a mind waking up — and, as Craig points out, air-gapping ends it. The lesson isn't that it wanted out. It's that you cannot enumerate in advance every path to an answer.

    Also in this segment:

    • Ukraine's reported autonomous strike drone — programmed to recognize and engage, with a second drone sent afterward to see what happened
    • Why the U.S. keeps a human in the loop on anything that destroys, and what happens to that rule when a country's back is against the wall
    • The drone swarm sequence in Lioness season three, and the pilot brought down over Iran
    • Why AI researchers increasingly doubt these systems ever reach real intelligence, and what "randomness built in on purpose" means for predicting what one will do

    Free newsletter and Insider Session announcements: CraigPeterson.com

    続きを読む 一部表示
    15 分