• S7, E278 - Anthropic Researcher Quits: "We Believe AI Could Kill All Humans"
    Sep 11 2026

    Send us Fan Mail

    Jacob Coxon spent three years doing pretraining research at OpenAI and then Anthropic. This week he resigned and posted a seven-part thread claiming neither company is acting responsibly with how fast they're racing toward self-improving AI. It hit 100 million views in a day.

    This episode covers what he actually said, how Anthropic's own alignment science lead responded (and the important nuance buried in that response), the questions worth asking about Coxon's timing and incentives, a fair skeptic's rebuttal, and the AI safety legislation already moving in Congress as a result.

    One thing on the title: it's a real quote, but it's Hubinger's general belief statement, not his assessment of present-day risk — he separately said present-model risk is low. Your own episode makes that distinction carefully. Worth a one-line callout in your pinned comment or community post after it's live, so the title doesn't end up being the thing people push back on in the comments before they've actually watched.

    Support the show

    Show More Show Less
    11 mins
  • S7, E277 - He Used a Police Camera Network to Track His Girlfriend 180 Times
    Aug 25 2026

    Send us Fan Mail

    Flock Safety's automated license plate readers are in over 5,000 communities and used by more than 40,000 cameras nationwide — sold to cities as a tool to catch car thieves and find missing people. But a Washington Post investigation found at least 50 officers accused of misusing the system, most of them to track romantic partners.

    This episode covers:

    • The scale of Flock's network and how warrantless searches are legally justified
    • Individual abuse cases in Wichita, Milwaukee, and New Bedford
    • The Texas sheriff's office case tied to reproductive-related searches
    • 404 Media's reporting on ICE's informal access to Flock data despite no official contract
    • Flock's "Freeform" search feature and the race/ethnicity flagging controversy
    • CEO Garrett Langley's August 13 apology and the new audit reforms
    • The historical parallel: NSA's "LOVEINT" scandal from the Snowden leaks
    • What's actually working: 39+ contracts canceled by cities in 2026
    • 3 concrete steps if your town has these cameras

    flock safety, flock cameras, license plate reader, ALPR, police surveillance, data privacy, police stalking, automated license plate reader, mass surveillance, privacy please podcast, cybersecurity, ICE surveillance, police misconduct, LOVEINT

    Support the show

    Show More Show Less
    12 mins
  • S7, E276 - Ransomware Doesn't Have to Hit Like a Hurricane (with Jonathan Sander)
    Aug 2 2026

    Send us Fan Mail

    Jonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about.

    Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now.

    Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized.

    Articles referenced:

    • Ransomware Doesn't Have to Hit Like a Hurricane (Myota): https://www.myota.io/articles/ransomware-doesnt-have-to-hit-like-a-hurricane
    • Why We Need an AI Agent Taxonomy Right Now But We Can't Have One (42 Notions): https://blog.42notions.com/why-we-need-an-ai-agent-taxonomy-right-now-but-we-cant-have-one/

    Chapters:

    • 00:00 – Catch-up with Sander
    • 14:30 – The hurricane analogy: why Myota built resilience instead of a wall
    • 20:30 – What actually makes Myota different from standard backup/cyberstorage
    • 22:15 – Why you can't build a clean AI agent taxonomy (and the six dimensions Sander landed on instead)
    • 28:50 – The hybrid agent problem: acting "on behalf of" vs. "for the benefit of"
    • 45:10 – Sander's one takeaway: get the basics right before chasing the AI hype

    Support the show

    Show More Show Less
    49 mins
  • S7, E275 - Choose Wisely: GigaWiper, Your New Delete Button & The Gold Bar Grift
    Jul 18 2026

    Send us Fan Mail


    Full Show Notes

    This week on Privacy Please, Cam breaks down four stories that all come back to one theme: choice.

    GigaWiper — Microsoft researchers uncovered a new backdoor malware built from pieces of older malware families, giving attackers the ability to decide after they're already inside a network how they want to cause damage — from low-level disk wipes to fake ransomware with encryption keys that are never even saved. Multiple security firms are independently tracking it, with no group attribution yet.

    Connecticut's new AI disclosure law — As of July 1st, companies covered by Connecticut's privacy law must clearly disclose whether their data is used to train large language models like ChatGPT, Gemini, DeepSeek, or Grok. Cam digs into why "disclosure" doesn't always mean "clarity," and what to actually look for in a privacy policy update.

    California's Delete Act (DROP) — A correction and a deep dive: DROP has been live since January 1st, not launching in August as previously stated. What actually changes on August 1st is enforcement — the date data brokers become legally required to act on deletion requests. Cam walks through exactly how to submit one at privacy.ca.gov.

    The Phantom Hacker gold bar scam — A 78-year-old Phoenix woman nearly lost $600,000 in gold bars to a scammer posing as a federal official — until she turned the tables and called the FBI herself. Cam covers the arrest, the courier-for-hire business model behind it, and the billion-dollar scale of phantom hacker scams since 2024.

    Tips for this episode:

    • Back up your data offline — wipers don't negotiate, there's no ransom to pay your way out
    • Search privacy policy updates for "train," "AI," or "language model" before skimming past them
    • California residents: submit a DROP request now at privacy.ca.gov so it's queued before enforcement begins on August 1st
    • No real government agency will ever tell you to convert your money to gold, crypto, or gift cards — hang up and call the agency back yourself

    Sources referenced:

    • Microsoft Security research on GigaWiper
    • Connecticut Data Privacy Act (CTDPA) amendment, effective July 1, 2026
    • California Delete Act / DROP platform, cppa.ca.gov
    • FBI IC3 reporting on Phantom Hacker and gold bar scams
    • AZFamily coverage of the Gary Christopher arrest, Phoenix Sky Harbor Airport


    Chapter Timestamps

    00:00 – Cold Open 01:30 – GigaWiper: Choose-Your-Own-Destruction Malware 04:00 – Connecticut's LLM Data Disclosure Law 06:15 – California's Delete Act & DROP Platform 08:30 – The Phantom Hacker Gold Bar Scam 11:30 – Recap & Close

    Support the show

    Show More Show Less
    10 mins
  • S7, E274 - Your Password Is Already For Sale
    Jun 29 2026

    Send us Fan Mail

    Last year, every major outlet ran the same story: 16 billion passwords exposed. Apple. Google. Facebook. The largest breach in history.

    It was overblown. Security experts tore it apart within 48 hours.

    But here's the thing: the real story underneath that headline is actually scarier. And nobody covered it.

    It's called infostealer malware. It's been quietly running on millions of devices — stealing passwords, bypassing MFA, and feeding an underground credential economy that's behind nearly every major breach of the last two years. Ticketmaster. AT&T. Coinbase. All of it traces back here.

    In this episode, I dig back into that story and break down:

    • Why the 16 billion number was a "fearset, not a dataset"
    • What infostealer malware actually is and how it gets on your device
    • Why MFA doesn't fully protect you from this (and what does)
    • The underground marketplace where your stolen credentials are sold within 48 hours
    • The stat that should genuinely keep you up at night: 67 seconds
    • Six things you can do right now to protect yourself

    SHOW NOTES

    Episode: Your Password Is Already For Sale

    Last year, the 16 billion password story dominated headlines. The headline was overblown — but the real threat underneath it, infostealer malware, is what nobody talked about. It's an industrial-scale credential theft economy running quietly in the background, and it's the engine behind almost every major data breach of the last two years. We dug back into it because it's only gotten worse.

    Resources mentioned:

    • Check if your email has been breached: haveibeenpwned.com
    • Free password manager: bitwarden.com
    • Premium password manager: 1password.com

    Key sources:

    • Cybernews — original 16 billion credential report (June 2025)
    • CyberScoop — "The 16 billion password breach story is a farce"
    • Flashpoint / DeepStrike — 1.8 billion credentials stolen in 2025 report
    • Microsoft Security Blog — Lumma Stealer breakdown
    • IBM X-Force Threat Intelligence Index 2025
    • Verizon Data Breach Investigations Report 2025
    • SANS Institute commentary

    Connect:
    🌐 theproblemlounge.com
    📺 YouTube: The Problem Lounge Network

    Support the show

    Show More Show Less
    20 mins
  • S7, E273 - Inside Shiny Hunters And The New Era Of SaaS Breaches
    Jun 4 2026

    Send us Fan Mail

    Gabe and I dig into Shiny Hunters and why the scariest cyberattacks now look like ordinary logins instead of dramatic break-ins. We map how credential theft, social engineering, and SaaS data exports turn basic security hygiene into the difference between a close call and a headline.

    • Shiny Hunters’ scale, loose structure, and why takedowns rarely stick
    • Why ransomware and extortion keep growing as a business model
    • How the tactics evolve from Microsoft 365 and developer creds to SaaS platforms like Salesforce
    • Credential stuffing, vishing, and smishing as “low-friction” intrusion paths
    • The Snowflake-style failure mode of missing MFA and weak password practices
    • Password reuse and how consumer breaches can cascade into enterprise access
    • Data retention and why old records increase privacy risk
    • Vendor risk and the shared responsibility model for identity and data
    • Practical steps that improve security without relying on perfect users

    If you guys have not been to our website, theproblemlounge.com, check it out. Got some new blogs up there. Sign up for the newsletter. Support us, follow us. Let’s get this out to more people.


    Support the show

    Show More Show Less
    24 mins
  • S7, E272 - They Know What You Watched
    May 23 2026

    Send us Fan Mail


    SHOW NOTES

    The Pornhub breach is being reported as a data story. It's actually a story about shame as a weapon.

    In December 2025, a hacker group called ShinyHunters claimed to have stolen 200 million records from Pornhub Premium users — including email addresses, locations, and intimate watch and search history. They sent extortion demands. The data was verified as real.

    In this episode of Privacy Please, Cameron Ivey breaks down:

    ✅ What was actually stolen — and why it's worse than most breaches ✅ The three-way blame game between Pornhub, Mixpanel, and a mysterious 2023 employee access ✅ Why ShinyHunters is one of the most dangerous and active hacker groups operating right now ✅ The bigger question nobody's asking: why does this data still exist? ✅ Five things you can do right now to protect yourself

    🔗 RESOURCES MENTIONED:

    • Check your email in breaches: haveibeenpwned.com
    • Freeze your credit: annualcreditreport.com (links to all three bureaus)
    • Data removal: DeleteMe — joindeleteme.com
    • Follow the reporting: bleepingcomputer.com | malwarebytes.com/blog

    📰 SOURCE REPORTING:

    • BleepingComputer — ShinyHunters extortion demand (December 2025)
    • Malwarebytes — Pornhub/Mixpanel/SoundCloud breach roundup
    • Euronews — Pornhub investigation coverage
    • Reuters — user data verification
    • Panda Security — breach overview

    🎙️ Privacy Please is part of the Problem Lounge Network 🌐 theproblemlounge.com 📺 YouTube: The Problem Lounge Network

    If this one hit different — share it.

    Support the show

    Show More Show Less
    17 mins
  • S7, E271 - One File to Rule Them All
    May 5 2026

    Send us Fan Mail

    In this episode of Privacy Please, Cameron Ivey investigates Palantir Technologies — a data analytics company founded in 2003 with CIA backing that has quietly become embedded across nearly every major arm of the U.S. federal government.

    This week's investigation covers:

    The USDA Deal On April 22nd, the Department of Agriculture signed a $300 million blanket purchase agreement with Palantir to build "One Farmer, One File" — a unified digital profile for every American farmer. The deal was awarded without competitive bidding.

    The IRS Bombshell The same week, The Intercept revealed — based on documents obtained by watchdog group American Oversight — that Palantir has been running financial crime surveillance operations inside the IRS since 2018. The IRS has paid Palantir over $130 million for access to a platform that cross-references bank records, tax filings, transaction histories, and more across millions of Americans.

    The Immigration Enforcement Machine Palantir's ICE contracts — now over $145 million — power the agency's case management, deportation targeting, and real-time location tracking of immigrants. A tool called ELITE creates individual dossiers on deportation targets by pulling data from the Department of Health and Human Services.

    The Pushback That's Working New York City's public hospital network canceled its Palantir contract after community organizing and City Council pressure. In the UK, 229,000 people have signed petitions to remove Palantir from the National Health Service. Public pressure is moving the needle.

    Five Things You Can Do Right Now Cameron closes with specific, actionable steps every listener can take — from requesting your IRS transcript to freezing your credit to contacting your representative about sole-source contracting.

    Privacy Please is part of the Problem Lounge Network. New episodes weekly. theproblemlounge.com

    Chapter Markers

    • 00:00 — Cold Open
    • 01:30 — Intro & Show Welcome
    • 02:45 — Act One: The USDA Deal
    • 06:00 — Act Two: Who Is Palantir?
    • 11:30 — Act Three: The Empire Expands (ICE, Policing)
    • 17:00 — Act Four: Your Tax Returns Are In There Too
    • 24:00 — Act Five: The Layer Nobody's Talking About
    • 30:00 — Act Six: The Part That Gives Me Hope
    • 34:30 — What You Can Actually Do (5 Tips)
    • 39:00 — Closing Reflection (Adjust timestamps after editing)

    Support the show

    Show More Show Less
    22 mins