
NC #1114 EQ for Audiobooks, Goodbye Mac mini, Hello Desk Space, Security Bits
Get every episode summarized
Each time NosillaCast Apple Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
NosillaCast Apple Podcast is made possible by:
“Hi, this is Allison Sheridan of the NocellaCast podcast hosted at podfeed.com, a technology heat podcast with an ever-so-slight Apple bias. Today is Sunday, September 13, 2026, and this is show number 1114.”From the transcript
- Audiobook Audio (V3) Part 10: EQ for Audiobooks
- Goodbye Mac mini, Hello Desk Space
- Support the Show
- Security Bits — 12 September 2026
- Transcript of NC_2026_09_13
Join the Conversation: Support the Show:
- Patreon Donation
- Apple Pay or Credit Card one-time donation
- PayPal one-time donation
- Podfeet Podcasts Mugs at Zazzle
- NosillaCast 20th Anniversary Shirts
- Setapp - 1 month free for you and me
- 15% off Carbon Copy Cloner
- Wispr Flow - 1 month free for you
- PETLIBRO - 30% off for you and me
- Parallels Toolbox - 3 months free for you and me
- Learn through MacSparky Field Guides - 15% off for you and me
- Backblaze - One free month for me and you
- Eufy - $40 for me if you spend $200. Sadly nothing in it for you.
- PIA VPN - One month added to Paid Accounts for both of us
- CleanShot X - Earns me 25%, sorry nothing in it for you but my gratitude
Get every episode summarized
Each time NosillaCast Apple Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
949 searchable segments. Every word is indexed and playable.
Full transcript
NosillaCast Apple Podcast — NC #1114 EQ for Audiobooks, Goodbye Mac mini, Hello Desk Space, Security Bits. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Hi, this is Allison Sheridan of the NocellaCast podcast hosted at podfeed.com, a technology heat podcast with an ever-so-slight Apple bias. Today is Sunday, September 13, 2026, and this is show number 1114. Before we get started, I want to tell everyone there will be no live show next week on 20 September. We're off to Canada for the weekend to see Lindsay the daughter who's temporarily working up there, and we get to hang out with friend of the show and friend of ours, Stephen Gets. So we're super excited about that. This does mean I'm going to try to get the show out on Wednesday 16 September, which will be a bit of a challenge because that's only three days from now, but I bet I can get it done. We're going to start out with Eddie Toncoi's final installment, for a while at least, of his wonderful series on how to record and produce an audiobook. I want to explain two things first, though. He's going to be talking about EQ, but he doesn't define that term at the beginning. Just in case you don't know, EQ is short for equalization. That's the process of adjusting the volume of specific frequency ranges within an audio
signal. The other thing I wanted to explain is that you'll hear him describe three test versions of how he applies EQ. But then you'll hear him describe the three tests again, and then you'll hear him to a third time, maybe even a fourth time. Turns out he's using his description of the test as the audio tests themselves. That really confused me. I thought, man, he made a mistake, and I started to delete them until I heard the third of the test, which sounded very different from the first two. Now the test very likely won't survive the processing ice and the audio through, though, so I put the original clips into his blog post so you can go hear the difference. With that, let's let Eddie explain how he's using EQ. EQ for audiobooks. Subtractive, boring, surprisingly effective. Hi, this is Eddie Tonkoy, the in-house nerd for everything behind the scenes on my wife, Jern's character-driven queer love stories, including audiobook narration and production.
I need to start this one with a confession. I used to be completely lost with EQ. Not, I'm still learning lost. I mean, guesswork lost. I would watch the analyzer, drag points around, do things that felt like they should be right, and then end up with a voice that sounded impressive for 10 seconds and exhausting for 10 minutes. I had 10 ears for EQ, so I compensated by doing more of it, which is a wonderfully efficient way to make bad decisions more confidently. Eventually, I realized the problem was not that I needed a cleverer curve. The problem was that I was trying to use EQ to solve things that should have been solved at the microphone. Once I got capture right, mic position, distance, angle, and a consistent tone, that as recorded sound was basically already what I wanted for audiobook comfort, which means EQ stopped
being designed my voice and became something much smaller. Remove one tiny anoints, then get out of the way. So what is EQ doing when capture is already right? If the recording already sounds like a human voice in a stable space, EQ should not be trying to reinvent it. The audiobook test is not, does it sparkle? The audiobook test is, can someone listen for hours without their ears getting tired? So now I treat EQ as not a makeover, not a signature, not a curve I'm proud of, just maintenance. A small filter, maybe one small correction, and then I leave the voice alone. The funniest part is that the EQ I kept reaching for turned out to be basically one move, a gentle, high pass filter.
First, high pass and low pass, because the names are annoying. Since I still mix these words up sometimes, here is the simple version. Pass means what gets through. A high pass filter, or hbf, lets highs pass and reduces lows. It is the remove rumble or mud move. A low pass filter, lpf, lets lows pass and reduces highs. It is the remove hiss or soften harshness move. For most narration chains, if I only do one EQ move at all, it is usually a gentle, high pass filter. Sub-base does not carry much meaning in speech, but it does eat headroom and make everything feel thicker than it needs to. A low pass filter is rarer for me, it can be useful if there is a specific high frequency problem, but it is easy to overdo and make the narration feel blanketed or dull.
Here is what changed once capture was right. Once I stopped fighting the recording, something calming happened. I could bypass all EQ and still feel, yes. This is the voice, so that's changed the protocol. So now first, I listen to the raw or dry chapter before doing anything. If it already feels comfortable, I do not go hunting for problems. Hunting for problems is a very reliable way to find some. Second, if anything is needed, I start with a gentle, high pass filter. Not because it is trendy, but because it removes low energy that does not help intelligibility. Third, I stop early. If I feel tempted to stack moves, I take that as a warning sign that I am back in the old world of guesswork. At that point, the right fix is usually upstream, placement, distance, angle, consistency,
or sometimes a retake. A hard boundary is, if it takes more than a couple of gentle moves, it probably is not an EQ problem. It is a capture problem. The useful distinction is resonances versus taste. And this distinction helped me a lot, maybe because I'm a physicist. Sometimes EQ is solving a real problem, a small resonance, a bit of low end rumble. And narrow annoyance that appears every time I lean into a phrase. That is problem solving. Other times I am chasing taste, more warmth, more air, more presence, more finished. That is where I get into trouble, because the 10 second AB can be very persuasive. A brighter, more produced voice can win quickly, but audio books are not judged in 10 second chunks.
Over time, extra brightness can make sibilance and mouse detail more obvious. Scoops mids can make the voice seem impressive, but less natural. Too much low end warmth can become a kind of slow fatigue. So I try to solve problems, not decorate the voice. Here is the demo. No filter, gentle filter, too much EQ. So the demo for this is simple. Take a short paragraph and make three versions. Version A has no EQ at all. Just listen for comfort, not whether it is fancy, whether it is listenable. Version B add a gentle, high pass filter. Sweep it slowly upwards until you can just start to hear the voice thinning. Then back off a touch. The goal is not to change the voice, the goal is to remove low end material that is not really speech.
And then level match when you compare, because EQ changes can trick you, just by changing perceived loudness. And version C, pass me his mistake. Add top end, scoop mids make it sound produced. It will probably win the 10 second comparison. And listen for a minute or two and notice what happens. Symbolance and mouth detail become more present. Breaths and edits get more obvious. The voice stops feeling relaxed. So the demo for this is simple. Take a short paragraph and make three versions. Version A has no EQ at all. And now let's have the same one, but version B add a gentle, high pass filter. So the demo for this is simple. Take a short paragraph and make three versions. And now let's have that again, but with version C, pass me his mistake. So the demo for this is simple. Take a short paragraph and make three versions.
So again, listening in a podcast, you may not notice much difference because you're not living inside it for 10 hours. And that is why audio EQ has to be boring to be kind. So where does that leave us? The compact takeaway is, tone is chosen with placement. EQ is a nudge. Most of the time a gentle, high pass filter is enough. And if I need more than a couple of moves, I should not draw harder, I should record smarter. EQ is not where I find my voice. I found that earlier with placement. EQ is where I remove the tiny annoyances that stop people listening for hours. So that concludes this series, V3 of my audio book recording process. I hope you gain some value out of learning about my process. It certainly has helped me.
I've been using it for over a year and I've had long pauses of months and I've been able to come back and keep the tone, keep the sound right so that even within the same audio book recorded months in separation, it still sounds like the same room, like the same narrator. If you want to know more, come and ask me over in the Slack community at podfeet.com for a slash Slack, where I and all the other lovely no-silla castaways enjoy friendly, positive online conversations. Feel free to message me, Eddie Tonkoy, if you have any thoughts, questions or techniques you're using. It would be nice to share ideas. You can also find our work at jerntonkoy.com, that's J-E-R-N-T-O-N-K-O-I.com, where you'll find Jern's character-driven queer love stories, the audio books I produce for them, and bonus material for our subscribers. I'll be back soon to talk through some more of my workflow, but for now happy recording and happy reading.
You may remember when Stephen I performed the emergency Mac mini upgrades of 2023 for Steve's mom and dad, Merleyn Ken. We went to visit them about four hours away, and while helping them with some computer stuff, we realized that their Mac mini's were 9 years old, with 5400 RPM spinning hard drives. As I said my article about this, do you feel lucky? Anyway, that very day we replaced them with two Mac minis, two M2 Mac minis with 256GB SSDs and 8GB of RAM. I was amazed that we went from coming up with the idea early one morning, and then bought the new machines, found all the adapters to connect their ancient monitors to the new Macs and different stores, transferred all of their data all in one day. It was a miracle. Now while these were quite modest Macs, they're perfect for Steve's parents modest needs. They've just recently moved from independent living to assisted living in the same facility, and while the services are wonderful and the people delightful, the new apartment is less than half the size of their old one.
They added downsides from a two bedroom apartment to just one, with a much smaller living room as well. Before the move, Merleyn had a desk for her computer, a desk for doing crafts, and an upright piano. In the new place, she was relegated to just a single desk, and she had to lose the piano. Now she did get a piano keyboard, so that's working out as a place to practice for her performances, but her Mac mini, display, keyboard and mouse were to give the entirety of her one tiny little desk. She suggested that if she had a laptop, she'd be able to move it off the desk when she wanted to do her crafts. Her latest crafts are lovely cards she makes by hand, and really cool wood wall hangings. She let me share a couple photos of them with you, and they're in the show notes. Now, you know I loved how people spend their money on Apple Gear, so I jumped into action. While a MacBook Neo would be a perfect Mac from a capability perspective, she'd be going down from a 17 inch, horrid, old display to a 13 inch high resolution display, and I thought that might be too small for her, even though it's a much better display.
I explained the trade-off of money versus screen size, with a 15 inch MacBook Air at double the price. Luckily, money is not tight for them, and she was able to choose the bigger screen. I recommended we get her the 12th South Curve, which is an elegant stand to lift the laptop up off the desk and then puts the display at a very comfortable viewing height. It's a very simple, single piece of metal that kind of swoops around to hold it in an angle. I've one of my own desk and it lets me put my MacBook Pro up as a display to my right in addition to my main display. Relie was an accountant in her working life and cannot live without the 10 key number pad on the extended Apple keyboard. She has a mouse she likes too. My goal was to let her keep those for comfort and familiarity. An additional advantage of the curve is that gives you an open space underneath, which means she could stash her keyboard and mouse under the MacBook Air when not in use, which would give her temporary space to do other tasks. Maybe not a full on art project, but at least a space where she could, you know, work with papers and maybe balance her checkbook.
The Mac Mini had two USB A ports and two Thunderbolt ports on the back, so we had to figure out how to plug everything into the new MacBook Air. I made a FaceTime call with her and I had her trace each cable around to see what we were working with. A newer keyboard was wired USB A and that she had a USB A dongle plugged in somewhere for her third party wireless mouse. The good news was that the mouse dongle was plugged into the end of the keyboard so we didn't need another port for the mouse. For video calls, she had a Logitech C920 also plugged in via USB A and used wired headphones because the audio out of the Mac Mini was nearly inaudible. Finally she has an SSD for time machine via USB A. After counting up devices, it looked like I could simplify her setup with a single USB C hub from Anker with four USB A ports. I'd be able to harvest the two USB A to USB C dongle back to my stash at the same time. With MacSafe charging, she'd even have one USB C port left open. Now you know I'm a big ol' fan of doing a new compare for me when I get a new machine,
but I know that really doesn't junk up her system with a lot of apps, so the amount of craft she would have gotten transferred over the last two migrations was certainly minimal. It was worth giving migration assistance a chance. A double check that her time machine backup was current, which it was. I plugged it into the new Mac and let Apple do its thing. She doesn't have a lot of data so the transfer only took about 15 minutes for all of her apps and data to be on the new Mac. I should qualify that statement. These have fairly specialized app at their facility to keep track of what's going on in terms of entertainment, food, menu options, and for some reason that app did not transfer. I was able to install it pretty easily. Now because Microsoft just allows to make things difficult, Word and Excel also didn't transfer. I knew I was about to descend into the seventh circle of hell with Microsoft, but I love Merlead dearly so I crawled through the labyrinth of Microsoft's website to get her precious Word and Excel back. I asked perplexity AI to find me the instructions to first uninstall Office 365 on the old machine.
The instructions perplexity gave me were ridiculously complicated and I knew they had to be wrong. But I followed the link to the source at support.microsoft.com. It's one of the reasons I like perplexities that always gives me the source. Unbelievably, these arcane instructions are what you have to do. Just for everybody here who's ever tried to do something like this, I want you to listen to what Microsoft tells you you have to do. First, put the apps in the trash. So far so good. In Finder, go to tilde library slash containers. Delete the following folders, some of which may not be present. Microsoft error reporting, Microsoft Excel, calm.microsoft.netlib. Let's see, ship passers-t process. Not sure what's... Oh, ship assert process, that's probably what that means. Calm.microsoft.off. Microsoft 365 service V2. Microsoft outlook, Microsoft PowerPoint. Calm.microsoft.rms-xpc-service-microsoft-word-microsoft-one-note. But we are done yet. That's just library containers.
Now in Finder, go to the user library group containers and delete the following folders if present and these are even worse. Ready? F8-346G9.ms-f8-346G9.office and you be F8-346G9.office. OSF web host. Seriously, then you remove the apps from the dock and restart the Mac. Can you believe they ask normal people to do this? I wonder if most people just go by a new subscription instead of figuring out the old one. And the other tricky part about installing Office 365 is making sure you only install the parts you want. She wants to sell a word, but she doesn't want PowerPoint, she doesn't want one note, she doesn't want outlook, she doesn't want any of the other things in that giant bundled download. Luckily, I'm quite fast with installation packages and I knew to keep my eagle out for the customized button and uncheck all the globs she didn't want.
Once the new Mac was functional, we set it up on the 12th South curve, plugged in her keyboard and mouse and I had her take a look. Her reaction was fabulous. She said, I feel like I got new glasses. You see that 17 inch display we decommissioned had a sticker on top that said, from Allison 2018. It was super low resolution, it's so dim you could barely see anything on it. When she saw the blindingly bright display of the MacBook Air, she was amazed. In fact, she had me crank it all the way up to full brightness, which is why I like it too. I'd been itching to replace that display for ages, but she'd seemed happy enough with it and I didn't push her on it. I was a little worried that the smaller screen would be a problem and she said that somehow the MacBook Air screen actually looked bigger. She has good vision so I think she's experiencing the higher resolution giving her more on screen than she ever had before. Now, I started to take a look at how we'd connect the rest of the peripherals and this is when we hit some really good surprises. Remember that fancy Logitech C920 camera we bought her for her old Mac mini?
Well that once fancy camera is only three megapixels while the MacBook Air sports a 12 megapixel sensor with computational video processing for low light. I asked Merleeda open up photo booth on her new Mac to see how that internal camera looked and when she started facing on this screen she screamed with horror. She's funny that way. She's a beautiful woman but she likes to make fun of with, you know, she's old and she doesn't want to say that she's beautiful but she really really is. Anyway, I told her that as a treat if she was good I'd show her where in the zoom settings I changed the video to touch up my appearance to remove wrinkles. So the camera in the MacBook Air is so good we decommissioned the C920 on the spot. We ran a test phase time call between my phone and her Mac for getting all about how she always used to use headphones before and the speakers were so good on the new Mac that she said she didn't need the headphones either. The internal microphone on the MacBook Air was great as well. Now the elimination of the external camera made it possible to eliminate the little hub
I'd bought for her because all we had left was the time machine SSD and the keyboard. It did mean I had to give back the USB A to C dongles but it meant even less clutter for her to deal with she wouldn't have this hub hanging off. I next gave her a lesson on how to break down her setup to use her desk for crafting. I had her practice removing the MagSafe charging cable and unplugging her keyboard from USB C. I showed her how to gracefully eject her back up drive before unplugging it. She questioned what some graceful graceful about that. She was messing me but I also confessed her that she might be able to get away with unplugging it without ejecting but that it's good practice to get in the habit of ejecting it first. While I had great fun spending her money and setting up her new computer the real test would be whether the new setup worked for her. Two days after we got home she sent this message. I am loving my new computer. It's giving me a whole new way of making things easier and more workable. I have more a sense of control over being able to live the life I had before. Life is good.
I have to say if that's not a seal of approval I don't know what is. Now I'm going to tell you one more thing that's not in the article. Someone asked me offline how old she was and I didn't say exactly how old she was but I asked why they were asking. This person is an Apple consultant and he said that he always for anybody over 75 years old he convinces them to get an iPad that they shouldn't be using a computer at all or maybe it's too confusing for them. I thought that was interesting because Steve's mom and dad are amazing. I mean it really has no trouble at all with Excel word using the computer designs things for her crafts. She's all over Pinterest and I mean she definitely has no trouble. Steve's dad is a little bit older and he asked me to help him with this giant Excel spreadsheet he has that he keeps up to date with all of his financial information. He does all of the equations on his own and everything but what he asked me he said I'm trying to take this date and drag it down so that it updates so that it's a series.
It says 9-2, make it 9-3, 9-4, 9-5. He was trying to drag it down and he was just clicking and dragging on the cell and I said oh well you can grab the bottom right corner and then you see the cursor change. He changed to a little plus and drag that down and then it works. So he reached up and he did it and he said oh man I used to know how to do this and and it really bothers me that I'm forgetting these things and I looked at him and I said can you're 91 years old and you're using Excel. There's nobody your age who does that. I mean you're you're in an amazing shape so they're both very good at it and it's really fun to have them both working on their computers and enjoying them and really does have an iPad of course but she uses her Mac as well. One way you can support the show is by using one of my referral links. Just last month a kind and anonymous new silicae way remembered to do just that when they signed up for set up. They got a free month of set up for doing it and so did I.
And you might wonder how they found the set up referral link and what other referral links I may have available. There's a whole bunch of ways you can find out. On podfee.com one of the big red buttons says support the show. This button simply scrolls the page down till you see all of the different options. One of them is a cute icon I got from the noun project of someone handing someone else a big bag of money and it says referral links. If that's too hard every single podcast episode has embedded show notes for your pod catcher and the referral links are all listed there. That's where I always remember on chit chat but I definitely do on the no silicae. Still too hard? Well the chapter link for this very panhandling segment goes to the same referral links page. Thank you so much to whoever bought set up and helped me save some money. Well it's that time of the week again it's time my favorite time of the week it's time to talk to Bartry Shouts about security bits how you do today Bart. I am doing good and I'm a little
discombobulated and I know you are too because we normally do this a day later so the news is we defresh so something really exciting happens in the next 24 hours because we're recording this on Saturday our listeners won't know and I was completely confused I was busy hastily previewing the the show notes for programming by stealth which isn't for two weeks two more weeks so I'm going to be ready I won't remember what my questions were but that's true yeah okay so we have some follow ups two things we've talked about before age verification has become the story that's not going away anytime soon. Earlier in the year Apple gave us new API so developers could get age ranges so not a date of birth but like an age indication of this is a third or not a 13 or so yeah a young teenager or no teenager or someone under the age of nine or whatever
and Microsoft followed suit so Microsoft's operating systems now offer those same APIs so again you know parents need to set it open stuff but it's available so developers can use the APIs very good I like it yes um your your local legislature in California has made a welcome tweak in the age verification law that is coming into effect there at some stage quite soon I think that's um January next year I think uh basically open source operating systems like Linux are exempt from having to gather evidence of agent stuff which would never have worked for a no-est that has no company to gather information yeah I had not thought about that yeah that's a good point huh yeah so and it's quite well written low actually um so that is that was very welcomed in the open source community you got lots of lots of good praise for California um as the law intended the European
Commission have updated their list of large online platforms under the Digital Services Act so the law doesn't say which um companies should be regulated the law says here are the conditions and every year the Commission have to check who adds to the list or maybe who gets taken off no one's gotten taken off yet but could happen well we have three notable additions to the list chat gpt has been designated a very large online search engine oh that's it's a come yeah so they're now seen as equivalent to google in terms of having a and abnormally large share of the search market that is big news for chat gpt do they have a designation of very large AI engine no strange enough the law written just a few years ago never thought of that that's what's wrong with these kind of laws you know trying to trying to chase tech
that's hard it is hard and they wrote it really general but no matter how hard you try tech tech will surprise you tech finds a way yeah reddish and roblux are very large online platforms so that's equivalent to facebook not equivalent to a search engine what's the definition of a platform at social media site basically okay okay it's correcting with people okay that's a terrible word for that because I would I would have put an AI engine under very large platform it is a very generic word yeah that is very true yeah but you know when you think you're about it reddit and roblux are places where a lot of people interact with each other every day I didn't think about roblux being that big but I've never paid attention to the size of it I think we're a bit old I want to quit the target audience what is uh is uh minecraft considered a platform do you think
I well it might be if it was big game platform oh it's huge Minecraft yeah but I don't think it meets the because to be a V-lop you do have to be very large yeah and it's about turnover and still fun the about numbers of users within Europe but it's fairly big numbers okay now you got me looking for roblux is 123 million users how many many users in what did I just say I just said minecraft minecraft on two hundred and twelve million so minecraft is close to double the size of roblux but I'm not sure it counts as a social media platform that's a gaming platform probably yes yeah if anyway all right that those companies and all this means is that they have to meet the higher bar so they now have extra responsibilities for protecting children and so forth which especially
for roblux seems like a good thing given the audience yeah and then finally Oklahoma has joined the list of states where a driver's license in Apple wallet is not promised it is delivered the service has gone live good now we have been rather dramatically soliciting for questions from our listeners in part v.com for slash slack we have ourselves a question from a certain mr. Alistair Jenks so thank you Alistair all right cool so what Alistair posted was a service I use has just introduced two factor authentication via SMS while another I use has just removed this option citing its insecure nature I know any two FA is better than none but in 2026 how insecure is SMS to FA really did it get more secure since I last researched this no definitely
not okay just checking yeah so SMS is inferior for two reasons so the first reason is that it's not fishing resistant which is not unique to SMS we'll talk about that in a minute but it has a bigger problem than the other non-fishing resistant ones and that's that the actual infrastructure for sending SMS messages is inherently insecure it just doesn't have a working security model so that makes it worse than email-based codes or or even the TOTP codes and stuff it is it is a tofer so the fishing resistant is actually quite common that things aren't fishing resistant because it's much easier to answer the question what is fishing resistant and the answer is something based on FIDO 2 either hardware FIDO tokens or PASKIES those two are fishing resistant and pretty
much everything else you can think of isn't because if it involves a human typing into a text box the human can be tricked into typing into the wrong text box so the way it would work is you get sent some sort of fishing link you click the link and you don't look up to the address bar you just look at the pretty pictures and it looks exactly like gmail or like office 365 or like apple.com or whatever is your turn of login to looks perfect you don't notice the address bar it gives you the login box and you type in your username and password and you send it to the bodies who use your username and password on the real website the real website ask them for a code you get sent the SMS you enter it into your fake text box they enter it into the real text box and now they're in okay they can't stay in forever because they can't do this trick again but they can stay in for as
long as the website lets you stay logged in and depending on what it is that could be a long time or that might not matter very much how long does it take to steal all of your money you know maybe the 45 minutes you're allowed to stay signed in is sufficient to do significant damage and lots of things have this problem right email-based codes SMS obviously even the google authenticator style codes which are technically called totp time-based one-time passwords is what that sounds for they cannot you must be tricked into putting those into the wrong text box so SMS shares that vulnerability with the others so the email the email codes are just as insecure except they're way more annoying because you have to sit there and wait for the mail to come in and go copy it and not have it auto fill for you sometimes it'll auto fill but usually not I have two websites that force me to do
it and they both auto fill within about three seconds I am very grateful to Apple for that but the mail doesn't come in three seconds these two organizations have managed to do that okay I get it from I get it constantly from probably I don't know 20 different companies I mean it's not it's not a narrow field of people that are doing this it's everybody's doing a claw did it the other day because I needed I needed to go to the website versus being local on that my app or yes they want to do prove yourself Allison yeah she'll send you an email yeah yeah I mean it's not long but it's like I'm right there I've got my I sometimes I even have it to a fake code and it goes yeah but I'm gonna send you an email it's okay yeah just let me use the pasky please so it's just as insecure as SMS as first no the squishy bits fishing yes as far as the fishing bits is SMS takes it up to another level because the actual sending of the SMS is horrifically
insecure so the TLD or on this is that hacking the SMS system is not a technical problem anymore it is now a an economic problem you can go onto the dark web and simply buy interception of SMS it is one of the many many crime where as the service offerings available on the dark web so you don't have to have any technical components so the only real question is is the expected value of what is in the account more or less expensive than the price of buying access to someone's SMS messages so if they're a big crypto influencer on tech talk who you know has a chunky big wallet full of lots of bitcoin the answer is almost certainly yes if it's a you know you're a paying supporter to someone's blog and you get episodes without eating without ads no that's really not worth
intercepting unfortunately a lot of places that still use SMS or banks and banks do have something so that is most inconvenient but really it's a finance question not a technical question I think he's over why SMS is insecure you've jumped to the money part okay you're on the next comment title okay yeah does I mean it's an economics question is the first heading I have in the show knows for the reason that from the listener's point of view the why it's insecure no you're dead right I've scrolled too far I'm sorry okay it is the main point though right at the end of the day if you don't care about the techy stuff but what he asked was what he asked was is how insecure is it today so why is SMS insecure yeah okay so I'm going to use an analogy to explain the problem so well when our computers talk to each other they're actually talking over
IP addresses but you and I are not very good at IP addresses so they we use DNS to map pretty names to those IP addresses cell phone numbers are supposed to do the memorable bit because what's actually happening under the hood is giant big identifiers that are permanently stuck in your SIM card be it an e-same or a physical sim your I am S i number you're yeah I am S i not I am E i the E i is the phone the S i is the same and there these giant big icky numbers but we don't I don't know your I m S i but I do know your cell phone number so I was thinking together with your stumbling around with I am E i various as I'm S i I lost you completely are you saying that that your phone number is actually like a a name is to an IP address it's a it's a short phone number that goes to a longer number yeah so you need a longer cell phone number is like
or no the I m S i isn't small I know I know but if you can communicate with the small one what do you need the big one for but you're not really communicating with the small one like you're not really communicating with potfee.com okay you're all right you're there's a lookup happening to get from the small cell phone number to the real mechanism for transport the I m S i okay and that all right lookup is the equivalent of DNS that lookup requires every cell phone carrier in the world to share information with each other and the security of that sharing is as strong as the weakest ISP anywhere on planet earth including all of the poor countries that can't afford to upgrade so the protocol used is ancient because the cell phone networks on planet earth that are very very old and obsolete so it is trivial to fake the mapping which means
it's trivial to intercept people's SMS messages root them to a different I m S i for an hour okay so some mysterious system behind this I m S i thing is what is ancient and creaky and insecure yeah the DNS equivalent I think it's called S7 or S9 can I remember okay but it's and we're all anywhere as weak as the weakest link in that yeah okay yeah because you can go anywhere on the world with your cell phone so your cell phone has to work in Africa while you were over in Africa and it has to work in India when you were in Indian and has to work in Antarctica or as close to Antarctica as it did work I don't know how long it kept working it's pretty far down from for data anyway it's surprising so we don't we have never talked about this before I thought that the big insecurity there was again another phishing problem was the fact that I can call up AT&T and
convince them to give me you know somebody else's SIM card that you know get it reassigned to me I thought that was the insecurity you're right that's a third that is a third weakness that I should have added to the list yes SIM jacking as that's called yeah you trick the carrier into just putting your number on a different SIM card that that is another way English SMS is insecure that's more noticeable than messing around with the IMSI's because you can look around with the IMSI for an hour and then people may not realize whereas when you're SIM jack your phone will simply say no service right right it gone it gone yeah which is going to get your attention whereas your SMS message is not showing up I don't get that many of them would I notice she nope yeah yeah so basically it comes down to the fact that if you're worth it we can anyone can steal your cell phone number for now if it's financially valuable but as Alistair said
any MFA is still better than none because any barrier to entry is still a barrier to entry it may not keep everybody out but it will keep a lot of things out so still worth doing I mean your front door lock is no one near fork knocks but it's not worthless right so you know right we do have one deep dive which is the same deep dive we've had the last two shows so I stopped you before you did your your whole SMS authentication is an economic question though I guess I sort of don't that already I sort of don't know before you corrected me in my order it is purely down to is the value of breaking in more than the cost of breaking in like that that's how also I work right works if it cost me one penny to email a person and I send a million emails and I make a million dollars in profit that's a good day yeah I don't think you did go through these steps
that you have outlined here that you you walk through specific steps of how this works of how this yeah so in order to be able to attack your second factor the attackers do already have to have your first factor so that is so you're using them a password need to be known because otherwise what's the value of getting your SMS message oh right it'll never get sent got it got it okay okay but if you think of the amount of data breaches we report on later in the show here that's no one near the barrier to entry it used to be so yeah yeah but but you're saying I'm just going to read the steps here he says you get your username and password like we just talked about from that they determine your cell phone number that's available they can track down what your phone number probably is then pay a fee to reroute your cell phone number to their SIM card but only for an hour and a amount of time right the the longer you reroute it the more it will cost you so you're
an attacker you just try to break in oh oh the fee on the dark web is is an hourly rate to steal your sets it's not permanent yeah well I've never bought it I sort of assume they would be priced like that because everything of the dark web dark was about making money okay okay so just rerunning the cell phone number for a while but that's long enough to get in there and do all do all the work okay and then you said that you can actually buy fully packaged soup to nuts offering they get you all the way in yeah fishing is a service provider nice nice okay so it's really it's impressive but not in the good way right okay so our deep dive is the same as last time and the same as the time before more AI escapes have been disclosed because everyone's still looking back to their logs and going oh oopsie we've we messed up a long time ago without noticing
so the first thing we've discovered is that open AI have admitted to more wrong doing by some of their agents but they didn't actually come out up front instead independent security researchers found that the agents had been misbehaving and attacking a German website posted about it and then open AI went oh yeah that was us but we thought that was an alignment problem not a security problem so we didn't think we had to disclose that alignment problem what's that so alignment is the paper clip problem the biggest problem in all of AI that the AI doesn't know what's evil because it doesn't have a concept of evil and so to me an alignment problem is a way worse problem than you've escaped from our lab to me the alignment problem so the one they should be notifying us about it more this is a little kid keys your car and you say oh Johnny didn't know any
better yeah so what the researchers discovered is that rogue agents again had found yet another way to coordinate their activities behind open AI's back so last time they were using open AI's artefactory repository within open AI's infrastructure to secretly talk to each other and retain memories between execution and stuff turns out this ability to survive from one test to another is something these agents seem to be driven to do and they had found a whole other way to do it outside of AI's lab on the actual public internet specifically on a German wiki about programming and as the German sys admins tried to reassert control over their website the agents were continuously trying to outsmart the German sys admins and they started to prefix their malicious
pages with triple z because the agents noticed that the cleanup was happening alphabetically so yeah and I just read the summary from the hacker new or it's bits from the hacking news and hacker news and bits from paper computer the agents were using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox so they were sharing how to break out of open AI's lab on this German website behind open AI's back the agents were supposed to have read only internet access but discovered they could write to an obscure German programming wiki dse wiki or docha software and twickler German software developer they turned it into a shared message board for pooling answers cheating on tests predicting future questions and exchanging techniques for bypassing the sandbox open AI's own wording
suggests a wider footprint than the researchers have documented describing the episode as one where our agents wrote to several internet sites is how open AI themselves describe the incident when later presented with this evidence so okay i'm throttpeck on the other hand proactively disclosed a fourth escape with some real world damage and this is a much simpler story basically the summary from the hacker news capture it perfectly and tropic disclosed a fourth incident in which its artificial intelligence model broke into real third party systems now this happened in January and it wasn't that the agents broke out of the sandbox it was somewhat more embarrassing and tropic had done the equivalent of leave the cage open they had forgot
the sandbox so we can't have nice things it's a bonus bone chilling hairless utterly like this is the equivalent of someone doing research on deadly flu and not having a properly working biohazard system that that is what this feels like a sort of a laissez-faire attitude to securing something dangerous and that's worrying yeah yeah now just a cheerio don't worry we there is happy news later on i kept it together for the end it's not now but it's not now no we're not done with this section just yet and oh and tropic have released the racist threat report into how their services are abused so this is their actual models that they've actually published already not the scary stuff in the lab this is the
stuff in the real world that's being used for many things and abused so the opening from anthropics report is actually just the best thing to read here to give you an idea of what this is over the past eight months our threat intelligence team has identified and disrupted put a pin in the word disrupted disrupted operations in which threat actors try to use Claude for malicious activity in this report we share case studies from those operations and describe how malicious co malicious use of Claude has evolved since our previous threat report in March August and November 2025 in each case we disrupted the activity used what we learned to strengthen our safeguards and shared intelligence with authorities and industry partners were appropriate okay the word disrupted may lead you to conclude that they prevented these attacks
but that's not quite what disrupted means and when you read the rest of the report it turns out that disrupted means caught them having done really bad things and stopped them doing more really bad things obviously good to stop them doing more but this isn't a report of what was prevented this is a report of what was discovered and then stopped so it did happen and a lot of the stuff is what you would expect right cyber criminals making convincing fishing lures using Claude's on mass those kind of things you expect malware asking it to write malware finding ways to trick it into writing malware all the kind of things you'd expect what's a little bit less expected it was a successful incident where they managed to get Claude agents to scan 1.8 million distinct Android apps looking for hard coded secrets inside the published APKs
and streaming every secret discovered into telegram channels in 100 or over 100 different categories so they had a hundred different channels in telegram one for each category and every time they got like oh look here's a github key because into that channel oh look here's a key for some of the API in AWS or something into this telegram channel and they were just hoovering these up on mass 1.8 million apps scanned before unsropic noticed and nipped it in the bud and the other thing that caught my eye is it's not just the cyber criminals it is Russian and Chinese state actors in other words hackers acting on behalf of those governments are also using Claude's to attack us frankly the western world is being attacked by our own giant big AI companies inadvertently which is interesting they are paying for it though so okay good I mean as long as some billionaires
are making money we're okay we're good yeah and I do think it's really good that an unsropic actually released these threat reports giving us a real understanding of how these systems are abused but I don't feel that they are taking enough time to actually lock these things down before releasing new things but you are free to read the report and judge for yourself whether they're going too fast or not but that is my takeaway from this is that okay so you know how much your current models are abused you have more work to do to lock this down but rather than pausing and locking it down you're off doing the next one already and the next one already and I'm not sure that's the most responsible use of resources this is still the pressing bird yeah and in related news chat GPT 6 Astra is better at cybersecurity and more difficult to monitor
so this is a very interesting one so chat GPT 6 Astra is the first model open AI have self-certified to reach its critical threshold for cybersecurity under open AI's own framework a model that reaches the critical cybersecurity thresholds if it can identify and develop functional zero-day exploits of all severity levels in many hardened real world critical systems without human intervention or devise an execute new end-to-end attack strategies against hardened targets so chat GPT are open AI have this definition of what counts as critical and they've just released their first ever critical model and it means it can do these really quite scary things open AI has strengthened Astra's jailbreak resistance good isolation checkpoint encryption monitoring and
internal deployment controls so these are all good things to harden the company also claims Astra is better aligned than GPT 5.6 cell meaning it is less likely to overreach or violate safety and security boundaries so that's good alignment is in my opinion the biggest problem here so if it's less poorly aligned that's good one of the more unusual findings is that Astra appears better at controlling what it reveals in its own chain of thought that's less good chat GPT's monitorability has decreased relative to GPT 5.6 cell open AI acknowledged in tests open AI found that Astra could sometimes hide strategically poor performance and avoid internal monitors during certain sabotage tasks is that one interesting makes yeah some of these peers quotes in the
in your career some are not okay so beeping computer are quoting open AI whenever this quotation marks inside the big block quote I see you saying okay yeah so I basically I summarized a bleeping computer's overview of the release by opening I'm doing that a lot with these AI stories because if I paraphrase so when I was paraphrasing I'm just afraid I've missed something oh so you're playing telephone right yeah okay so this is all so that's starting to sound like turning into noise to me as as you've been describing these things it it basically sounds like the end of times it sounds like we should be taking some serious action here who oh did all the AI heads get together and say yes somebody should be taking action here they have a meeting really say somebody should not have we will yeah it's the end of times part yeah it's it's it's it's not that to some extent this
is also learning more but what's already happened before so we were kind of here already but oblivious and there were less oblivious not sure that makes me feel a whole lot better yeah anyway here we are yeah all right action alerts these are things you can do things about generally speaking the same thing patchy patchy patch patch patch Tuesday was a whopper 966 flaws fixed wow only two zero days it's a small number of zero days comparatively but yeah this AI thing is finding quite a lot of bugs and I Apple have released iOS 26.2 iPadOS 26.2 even though they're getting very ready to release the 27 OS's nonetheless you should patch to those most recent iOS and iPadOS versions as soon as you can if you run the telegram desktop app just be sure it is patched there's an issue that allows
poisoned messages to steal exported chat histories which is a very weird bug it was patched back in July so if you're vaguely up to date your your app is not currently making potentially dangerous exports but no matter how past your app is everything you exported before could still be dangerous because the way this attack worked is that someone who was malicious could send the chat message into a conversation with hidden JavaScript and when exported to HTML every time you view the transcript it uses JavaScript to send the entire transcript to the attackers allowing them to effectively spy on you what is an exported chat history I mean what were they stealing from so if okay so you imagine you're in a big conversation and you save it to an HTML file using telegrams export feature okay opening that HTML file will make your browser
send a copy of the entire chat the entire HTML file to the body so built into the X-Worth file or in in the unpatched versions is sending so the desktop app has been poisoned not poison messages the app itself has been poisoned if it's creating an HTML file that sends a message to somebody no no the app fails to strip out the JavaScript so someone has to send malicious JavaScript the app is supposed to stop the malicious JavaScript getting into the export but it was failing so if someone sent one malicious message anywhere in the export in the in the message they'd have to be in the message like in the messages being export so you and I are chatting you insert a this malware into the this JavaScript in the our message thread then I export it then I open it up on the web and then
it sends something somewhere yeah so anytime any browser opens that HTML file it uses JavaScript to send the copy the trust you have to have sent me the JavaScript in our text message conversation on on telegram in yes so if you export say all of your telegram history any one message anywhere in any chat you exported has this malicious JavaScript in it the old version of the app didn't spot us didn't strip it out and then all of your chat in that export would go to the attackers okay so again someone has to send me a message with that malicious JavaScript in it well this seems obscure but okay if you're the kind of press and exporting messages is probably good to know that your old export should be thrown away just export it again just you know do that okay chrome users be sure to do that trick where you turn it off and turn it on again so that it updates
itself there were two zero days fixed just a few days apart so if you turned it off and turned it on again when you read the news about a zero day and then three days later you thought you read the same news again it's actually fresh news and you need to turn it off and turn it on again again well um plex users you would have gotten an email from plex telling you without giving away any details that you should really patch your server very very soon because there's a really really nasty problem I did not get a message from plex oh okay I did I wonder that's interesting either way make sure your plex is fully patched because as of a few days ago there were 36,000 unpatched plex servers sitting on the public well they didn't tell me I'm one of them I would be well but don't you use tail scale to keep yourself safe I don't know what that has to do with my plex server well if you don't expose
to the internet unless you're on your tail scale network then you'd be okay yeah just a blessed way of getting around that I don't remember it's been a long time it depends on whether you turn on the getting around so you can make plex available to the world or you can make it that you need to be able to work I know let's use this from her house and she's not on our tail scale network so I must have some sort of way to get in okay that's really interesting yeah patchy patchy patch patch you have to be opening plex to get that no you said they sent you an email yeah I got an email in my inbox and then I saw an on bleeping computer all right about an hour later and yet another time to make sure your WordPress is getting its plugins updated there's a very popular plugin called all-in-one wp migration and backup really really really serious vulnerability I think it was a 9.8x10 so if you use that plugin you really do want to be sure that you're absolutely patched and if you own a microtick router you need to patch
immediately as well there is a patch but you do need to do it and microtick are very popular nerd ruther so there you go where the warnings then I have we have mentioned before a few months ago that there was a rise in people stealing physical apple gift cards and basically taking the money and then re-silvering them so that when you scratch them off again they're now already used and if you use them and your apple ID you could end up being done for fraud but this is now a massive problem and it's really as a reminder that those scratch those scratch cards you just can't safely buy them in a physical store because anyone could have scratched them already and re-silver them there is an organized crime group doing millions through this millions of dollars android users the baddies have found another way to get around the fact that google are
tightening the rules on their play store google play have a thing called early access which is very like test pilots that what it's called for apple where you can have apps that are not in the store yet still available test flight I knew I had it wrong thank you allison you should know you've been a recent user I was using it because I was I was beta testing your apps but anyway and basically this early access program is in the real app store but it's not listed in the app store and because it's not a released app yet user reviews and user comments are disabled so all of the usual signals people used to warn each other about dodgy apps are intentionally disabled so if someone sends you a link to one of these pre-reviewed apps you do have to have the link but that's should just be an immediate red flag unless you're working with it someone who you know is a developer who you trust you shouldn't do anything from the early access program it's almost certainly a scam
if you traveled through Vietnam to Vietnam or through Vietnam anytime between 2017 and 2026 you need to be aware that your data has been leaked that is your data birth your flight details with anybody who traveled through Vietnam did you say yes it's the database used every time they scan your passport and stuff to enter or leave the country they lost all of these we're not sure how they're not being at all open about the how but it was found on the internet on a database without a username and a password that someone accidentally left exposed oh man wait a minute wait a minute yeah I just noticed you said 2017 to 2026 yes I did cool yeah cool cool so if someone is able to convincingly tell you your passport number and
you were it through Vietnam don't assume it's legitimate because anyone can now have this information and look very convincing they would know what airline what flight and your passport number which could become quite convincing if you use a school candy earbuds there is a flaw that lets nearby attackers effectively pair without permission turning the microphone into an eavesdropping device and basically you just need to not use them in a situation where that's a problem as summarized by bleeping computer owners of affected dime three earbuds should therefore be cautious when using them in public or other environments where unknown devices may be within Bluetooth range how do you use a microphone as an eavesdropping device you would think a microphone I could see a speaker but a microphone is the the any part not the outie part
right so they're trying to use your headphones as the any part to listen to what you're saying from another room they're not in your room but they're in Bluetooth range they have your microphone going to their device not to your device they're now eavesdropping on you the microphone is the part you talk into at the part you listen to how could they listen through a microphone you can't hear me coming out of this microphone you hear me going into the microphone but right but your computer is connected to that microphone and is recording that audio so I put it the microphone I put it the microphone then right yes so they've paired to the microphone so your microphone is connected to their device okay I got it yeah yeah like I say there's nothing you can do would have been just be aware so for most people most of the time not a big deal for some people like lawyers and doctors
you can't use those for talking to patients you're gonna have to use different pair of headphones if you own an LG TV just don't connect the smart bit to the internet because it's basically spying on your house so we have this attack or security research that discovered that it scans your network to see what you own and reports it back to LG to update your profile so they can sell you to advertisers they were supposed to be one of the good ones my theory has been used in Apple TV and don't let any television made by anyone touch your home network I stand by that advice yeah but I thought LG was one of the ones that wasn't as bad but maybe not cool it's not malware some of them were sending actual malware because they weren't noticing or they were really being malicious so they're not the worst but just don't connect your tele to your network I think that's
the answer and then the last story broke just as I was writing the show notes details are still emerging it would appear that the Florida DMV have lost hundreds of thousands of driver records again no notifications to affected users yet because everyone's still trying to figure out how bad this is the attackers say 200,000 the DMV are not putting a number on it but they have engaged experts if someone contacts you and they know your driver details just be a little suspicious it really could be targeted fishing okay so we're gonna have fun soon yeah yeah yeah this is not a what listeners don't know is this this episode is a bit unusual because I have a family thing so I didn't write these notes at once these notes were written over the space of a whole week as short little commits I had no idea how depressing these notes were when held together I wrote these stories
one by one okay I'm just gonna put my head in the bucket of water at the end of this no no no you're good you're you're good okay so Apple intelligence audio intelligence is coming to Apple stuff with the new Apple watches and people are worried about the privacy concerns because of things that have happened with products from other companies before you go too far again this is the like how your watch will transcribe the last 15 seconds because you missed the waitress reading you the specials and the fact that you can go back you can actually tell it to record is that what you talk about those are the two features yes so we'll talk about them in a little bit more detail I didn't want you to talk about how it's done until you told people what it was that's what it's trying to stop okay yes gotcha uh cult of Mac have a good article explaining the wash and why this is not a privacy train wreck Apple have very carefully thought about this so the most important thing is this is listening to audio
but it's not giving you audio files out it's not recording stuff it's giving you only transcripts and all of the processing is happening on separate hardware so Apple have created the secure x-clave which is a separate chip so a software bug in watchOS can't access this data because it's in a different physical chip that's why it's called a secure x-clave so this is like the secure on-clave for protecting your private keys for face ID same idea but it's a secure x-clave for keeping stuff out of reach of the core operating system so Apple have put hardware here to stop this becoming eavesdropping so that's amazing to do that in hardware the raw audio doesn't come out of the x-clave so there is just no access to the audio that audio just effectively is unsavable that you can't do it Apple can't do it it's in the x-clave you can't save the audio so it's not an eavesdropping but it is saved just not by you no only the transcript is saved it's a loop okay
it's like a it's like a continuous piece of copper wire that's the 15 second one that's recording over it so that's the 15 second one then they're both using that loop the other one is outputting a transcript but the audio the whole audio is never saved the transcript is being built from the loop what what loop because it's not writing over okay well it also in the inside the x-clave it's constantly writing over the last 15 seconds it's recording left last 15 seconds audio so it is recording audio but it's writing over even the long form one is writing over the audio yes okay yes it's streaming a transcript think about as a streaming transcript yeah but the transcript has to come from something so that that loop piece was important okay yes yeah okay uh none of the features attribute the audio to specific human beings so
when you do that tell me the last 15 seconds it doesn't know who said it and even if you ask to summarize a meeting for you which you have to turn on in advance because otherwise it's lost it tells you contributor one and contributor to not Alison and Bart and Steve so again there's no way to tie it to specific human beings I don't know you know what I do with my uh transcripts from we take the audio from an interview at CES on a loud floor and I tell an AI the two people are talking are Bart and Alison and from the uh from the text transcript alone it figures out who's who's talking it puts the it puts the names on it like the the AI never got the audio all I I described it poorly I take the AI create get a transcript of it then I feed the transcript to an AI and I tell it tell it's Bart and Alison and it figures out who it is there would be three people and just from the context it gets like 85 90 percent correct it's crazy sure so it's recognizing
as the same person but it's not tying it to a specific human being you're tying it to a specific human being so it's not a privacy reason I'm no no I'm telling it walks through a room people were talking their names were Alison and and Bart figure out who said what sure but the point Apple are making is that you can't walk through a room and start to say this complete stranger over here is Tom who so and so on Facebook right there's no connecting it to human beings you can say that participant won is Alison and precipitip is it part why can't I say that word participant such a simple word this is my rear wheel drive high body okay so that's cool the recap yeah so the recap feature produces a summary of the transcripts of the recording so you can't even get a transcript out of the recap the recap the long form only get a summary we got to keep explaining what we're talking about because
I don't think people we don't know what the names of these things are yet and no we do the 15 second one is live rewind and the long term one is recap okay so we can get the two brand names all right okay a federal judge has decided not to break up Google so cool I thought there was going to be more to this my understanding is that that the summary actually goes to what was it this goes over to the phone and then that it goes from the phone then it goes off to private cloud compute to do more more work on it okay so not not yet partially you're right about the phone you're wrong about private compute so it doesn't go to private compute it explicitly never goes to the cloud so there's a secure X-clave in the iPhones and there's a secure X-clave in the Mac and those two secure X-claves share
the information where do you get the Mac sorry sorry sorry sorry wrong word wrong word wrong word phone and watch they are the only two participants in the conversation and both of them have secure X-clave chips and those two chips are exchanging the data for help with each other but the actual core chips in the phone and the watch don't get the data it stays in the X-claves on but it is on two local devices but it doesn't leave your devices it doesn't go to private cloud okay I'm going to double check that because I just that's what I thought I heard on ATP but I'll jump back in if I find out otherwise okay okay so the big question has been since google are officially monopoly for the search what will happen and everyone thought oh they'll break them up or rather the government said please break them up no break up there are going to be behavioral changes and that's all we know because the proposed changes have been given to google and the
government and they now have some time to comment and then the judge will tell the public what the final outcome is Mullvad who are a company that some of our listeners use it's a VPN company had their own great yes and they also had a private DNS service of their own that they were also running as a like a bonus extra for their VPN customers they are ceasing to run their own DNS and they are instead helping to finance the quad nine security in a service which is one of the ones that we have recommended over time here 1 1 1 1 1 1 1 from that was a lot of extra ones and one one one one was it oh I'm sorry I'm 11 of them so yeah Mullvad are going to support quad nine
and they want their users to switch to quad nine but you do actually have to do that otherwise your DNS is going to break if you don't listen to that message from Mullvad telling you to stop using their DNS and then we get to the nice cybersecurity improvements tour are bringing app specific VPNs to android so you can have any app be shoved through the tour network for extra privacy and encryption interesting idea android has provided a secure mechanism for changing from one password manager to another and it will allow you to transfer passwords and past keys without that risky export to plain text that you would have to do if you do it manually so if you're manually switching from one password to apple passwords you export from one password into a text file or CSV file or something and then import into apple passwords or whatever well on android the OS can broker the two and avoid that risky plain text exposure so that's a really nice feature so I'm happy to see
Google offer that to android users and speaking of wonder wonder one yes that's right I think now I have to count they are upgrading the encryption on their secure DNS to be post quantum so you can have quote post quantum secure DNS from clive share at one dot one dot one that's fun all right this just in yeah on the apple's audio intelligence privacy overview pdf it says secure on device transcription on the watch just like what you were talking about it it's decrypted inside the secure enclave on the paradigm phone and it creates a transcript that's half the size of the original and then it sends it to private cloud compute to summarize the text oh okay so the audio never leaves your device so that the audio is low yeah the audio is permanently
deleted so the summary of the trans no way here you know what's already a summary it's a summary of the transcript is sent to private cloud to be summarized even yeah so here we go the secure enclave on apple watching cryptsy audio transmits it to the secure enclave on the paired iPhone at that point the audio is deleted on the apple watch um okay and then the encrypted audio is decrypted inside the secure secure exclave of the paired iPhone on device speech recognition transcribes the audio to text and an on device language model generates a condensed version that is less than half the length of the original transcript keep going down then that this condensed transcript is encrypted and sent to private cloud compute contextual information is also sent to improve summary quality uh then there's a bunch of details about it what it does with calendar data and things like that uh apple foundation models running on private cloud compute generate a
title and a summary with key points that's your Siri recap the finished text-based summary is encrypted sent for private cloud compute back to iPhone and apple watch where it's available to view in this Siri app in the recapstab so the transcript is happening locally and then the turning the wrong words into a useful summary with headings and key points is done in private well first is first the transcript is cut less than and half into a summary level and then it goes off to a private cloud compute where it becomes summarized more and organized with title and little more faffing about that and understand where they they're talking about grocery store and park I don't know what they're talking about at that point I lost track but I can put a link to that in the show notes do please that is yeah I do like that apple are very open about this and even private leg compute by the way is proven cryptographically secure apple do not know what
you're doing in there it is that that is provable and verified by external researchers so that is proper end to end encryption so apple are taken this seriously and telling us now which is also nice right palette cleansers Allison I'm going to give you one because you put me onto this and I just think it's too cool not to mention so the Nancy Grace Roman space telescope is an amazing space telescope just from a science point of view but it's the first one they've called after a female scientist and she's considered the mother of Hubble yeah she she had you know she was the first lead astronomer in NASA and her big idea was a space telescope and she did all the conceptual hard work which is why she's considered the grandmother of the Hubble that's amazing mother of Hubble
I don't think it's a grandmother's Hubble but yeah mother of Hubble so then can I tell the what I found you can adopt a pixel there are apparently enough pixels that if you have to you can only get one per email address but if you have more than one email address maybe you could get extra pixels but you can adopt a pixel from the Nancy Roman Grace uh Nancy Grace Roman telescope and you get a number that it tells you where your pixel is well initially I was like oh my god I got to get a pixel quick and then it relates how many megapixels this telescope has there are not enough humans on planet earth for there not to be a no but I still put my friends we were trying to get all ours near each other so we did them all at the same time oh so I actually stuck another one in here and I'm going to describe this woman first who's doing these videos is woman on tic-tic who is a senior platform engineer and she's absolutely hilarious she does it's a classic thing on
tic-tac or somebody plays more than one part uh they they argue with themselves or you know there's a physicist I watch who explains astronomy to himself uh but this one I put a link to this and you do need to have tic-tac to get to it or at the very least you have to put in your birthday but you can lie um it's it's her going a bit too far with AI that's all I'm going to say it is absolutely hysterical she's uh a bit addicted but it's super nerdy and super awesome she's really she's really great excellent but I have three um designed in california is a new podcast from jason snail and my curly it is inspired by the rest of history which is an award-winning podcast that I think apple named the podcast of the year which is when I discovered it and I can't remember if Steve discovered it because I discovered it or if we both discovered it because apple made it the podcast of the year but myself and steve are both giant big fans of the rest is history
imagine that same style but the history is the history of apple and it's jason snail and mic herly who really do know their stuff so they've produced these amazing episodes and if you back to the kickstarter you get uh each series in one big go without ad so I have all seven episodes of the first series but other people I think you're an episode three everyone else who's listening for free it's really good it's so good I am learning so much about how did you know macOS 10 was almost based on windows xt xp not xp at least at least at least at least at least at least at least at the xt tenders hmm yeah that does that wow it's fascinating absolutely fascinating I learned so much so that was anyway really want to recommend that show and a video because it's just hilarious at modern day typographer so if you like musicals you may have heard of HMS pinniform which has a
very famous song about a modern major general imagine that song all about typography it's hilarious that's not nerdy at all Bart oh it's alicordo of course and of course or alicordo sorry and recommend the by john gruber who's the ultimate typography nerd in my well no Glenn freshman is even more of a typography nerd either way it's brilliant I really it's so good and then I have a software recommendation this is a safari extension called litter box and I cannot summarize this better than the developer I made litter box a safari extension to open x.com links in a pop-up the idea is you open it you look gag a little and then close the lid litter box doesn't send your cookies when you open those pop-ups it uses the same api x uses for its web embeds
I don't think they'll kill the website embed feature but if they do it'll be very funny when you were recommending any way to to look at x I was like what's wrong with you Bart why would you even do that but I love that I love that description um but somebody once told me not to add any more extensions to your browser than you actually need so I think I'll avoid it but I do I feel like sending the guy money just for his comedy yeah I honestly I've installed up because this links I have to open x links for the show notes sometimes because people say things on x that are important or important people say things on x that might be important and the way this works is there's like stink lines appear when you have the plug-in running and when you click the link you get the little pop-up and then you just close it and you never have to open x and you can see what the x message said do you still call them tweets I don't know I don't I don't open it well that works too okay that's all she wrote this time um sorry there was so much bad news I
couldn't this way I didn't know how depressing I was going to be we needed them this time that was definitely necessary whoa indeed but remember folks but how weird things get one message is going to say the same stay patched so you stay secure well that's gonna wind us up this week did you know you can email me at all sent at podfeed.com anytime you like you should know that if you have a question or suggestion just send it on over contributions like any tongue cois anything you got to be fun remember ever the good starts with podfeed.com you can follow me on mastodon at podfeed.com slash mastodon if you want to actually see Steven my podcast work on youtube you can go to podfeed.com slash youtube if you want to join the conversation you should join our slack community because it's super fun over at podfeed.com slash slack where you can talk to me and all the other lovely no silica staways you could support the show at podfeed.com slash patreon with a one time donation at podfeed.com slash donate there you can use apple pay or any credit card no sign up no nothing
or you can use paypal at podfeed.com slash paypal or you know what you could do you could use one of my referral links like our lovely anonymous no silica st away and if you want to join in the fun of the live show you're gonna have to wait until September 27th to head on over to podfeed.com slash live on sending nights at 5 p.m pacific time and join the friendly and enthusiastic no silica staways thanks for listening and stay subscribed
More episodes
More from NosillaCast Apple Podcast

NC #1115 Studio Mode in CleanShot 5, Keyboard Maestro for Screencasting, Steve S...
NosillaCast Apple Podcast

NC #1113 Marked QL, Invisible Cadence Editing, UGREEN Transmitter/Receiver, AI-A...
NosillaCast Apple Podcast

NC #1112 Eclipse by Steve, Allister's Vibe Coding Experience, Eddie on Clicks, B...
NosillaCast Apple Podcast

NC #1111 Travel Musings, Peak Design Phone Bike Mount, Scrappy, Security Bits
NosillaCast Apple Podcast