🔒 Patreon Special

IT Pros: exclusive shows await you on Patreon, focusing on the more challenging aspects of running your practice and working with clients and employees.


669: Adam Engst (TidBITS) Slack Impersonation Malware, Anthropic's Mythos, and Why You Need a Personal AI Defender

669: Adam Engst (TidBITS): Slack Impersonation Malware, Anthropic's Mythos, and Why You Need a Personal AI Defender

Adam Engst (TidBITS) discusses a malware incident in a long-running public “Slack Bits” group where a bad actor impersonated Glenn Fleishman via a duplicate Slack display name, tricking him into downloading an info-stealer, prompting Engst to consider shutting down the 1,400-member community. The conversation shifts to Anthropic’s Mythos and Project Glasswing (as covered by TidBITS security editor Rich Mogull), which reportedly found long-standing bugs (including in OpenBSD and FFmpeg), raising concerns about AI-accelerated vulnerability discovery, defender/attacker asymmetries, costs and compute barriers, and impacts on zero-day markets. They also cover Apple’s iOS signing and update/upgrade distinctions, why Apple supports macOS differently than iOS, broader distrust in institutions, social media’s advertising/algorithm problems (including Section 230), bots and AI-driven phishing, and the idea of local, user-controlled AI agents to help protect individuals online.

00:00 Welcome Back Adam Engst

00:20 Slack Impersonation Scare

02:15 Cleaning Up a Public Slack

03:40 Mythos and Glasswing Explained

05:19 AI Bug Hunting Reality Check

08:25 Red Team Blue Team Asymmetry

09:50 Compute Costs and Access Barriers

12:19 Trust Ethics and Regulation

17:50 Personal AI Security Agents

23:34 Zero Day Markets and Exploit Kits

25:40 iOS Signing and Update Windows

27:13 Why Macs Get Longer Support

32:06 Scams Incentives and Pig Butchering

34:02 Life Offline and Misinformation

35:41 Social Media Hot Garbage

36:43 Addiction By Design

37:46 Advertising Model Flaw

38:47 Infinite Scroll Limits

39:39 Dunbar Number Reality

40:54 Platform Power Responsibility

42:46 AI Influencers And Slop

43:37 Bots And Fake Accounts

46:33 AI Phishing And Passkeys

49:21 Closed Communities Trust

53:25 CAPTCHAs And Human Help

56:08 Section 230 And Algorithms

57:46 Chronological Feed Fix

59:35 Two Week News Rule

01:02:41 Ads In Maps Backlash

01:04:10 Wrap Up And Next Part