Hacked - Bruce Schneier — Snowden, Crypto Wars, and the Future of Agentic Hacking
Episode Date: August 15, 2026This was a fun one. We sat down with security icon Bruce Schneier to talk about AI systems that break the rules, cybersecurity beyond computers, the fight over encryption, the Snowden documents, block...chain, digital rights, and what happens when machines learn to exploit the systems humans built. Hacked is presented by NordLayer. NordLayer is a network security platform for modern teams. NordLayer gives companies centralized control over who can access their systems, keeps every connection fast and encrypted, and requires no additional hardware or complex infrastructure. nordlayer.com/hackedpodcast Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
AI is a power enhancing technology.
It enhances the power with people who want to use it.
People who want to use it, want better democracy, AI will help.
People who want to use it, want worse democracy, AI will help as well.
AI doesn't really have morals.
It's what the person who's using the technology wants.
Welcome to HACT.
13 years ago, our guest this episode got on a plane to Rio de Janeiro to go meet a journalist
who was holding a stack of classified documents that almost no one outside of a
a handful of reporters had ever seen.
Our guest spends weeks going through what it turns out was hundreds of top secret
NSA files, deciphering technical jargon that the journalists couldn't parse, and helping to
figure out which of these documents were actually worth reporting on.
Those were the Snowden files.
And our guest is that man deciphering the jargon, Bruce Schneier.
Rhymes with frequent flyer.
Rhymes with frequent flyer.
There was a reason that even Snowden thought it was a good idea to get Schneier on the job.
Bruce wrote the book on encryption.
In 1993, he designed his own encryption algorithm, Blowfish, and gave it away free and unpatented.
It's still kind of in use today more than 30 years later.
Yeah, it's still around.
Math still holds.
The math still holds.
That same year, the government tried to put a chip in your cell phone that would have given them a spare key to every call you made.
That didn't happen.
That was the first time he got in a very public fight with the government about encryption.
There are two of those in his history.
We ask him what the third should be, just for fun.
Bruce sits on the board of the Electronic Frontier Foundation.
We start the conversation there.
Scott, you were wearing an EFF shirt.
It was just too good to not talk about it.
Yeah, I'm a donor supporter of the EFF.
It happened for a long time.
So it was an easy intro for me.
Friends of the show.
Friends of the show, they actually are.
They were a supporter of the show for a long time.
EFF.
And now Bruce is warning about something new,
autonomous agents doing the hacking at machine speed
with nobody really in the loop at all
and all of the weird, unexpected monkey paw type stuff
that can come from that.
He has this famous line that we talk about in the show.
Only amateurs attack machines, professionals target people.
It's changing a bit now with the machines now doing the targeting
and the tracking.
So I don't know, great conversation.
Bruce, great guest.
Turns out he's, you know, up here in Canada with us.
So hopefully I'll see him next time I'm in Toronto.
Friend of the pod, I hope you guys enjoyed the interview.
Big thanks to get into our show sponsor, Nordlare.
But we'll talk more about them later.
But right now let's jump in with Bruce.
Security legend Bruce Schneier here on Hacked.
We've got a lot of stuff we want to chat about today,
but I thought we'd open with, uh,
Something that's a little bit near and dear to my heart.
And I know you're a board member at the EFF.
Long been a bit of fan of what you guys do.
I thought we'd give you a little chance to educate our audience
on what the EFF does and why they're important.
The EFF is the Electronic Frontier Foundation.
They've been fighting for your rights online since 1990.
You know, back then the battles are very different than they are today,
but it's all about power going after your rights,
whether it's your privacy or control,
whether they're talking about email or text messages
or facial recognition or body cams
or flock license plate scanners.
EFF has been on the forefront of every major fight
for digital rights in this country since 1990.
It's a great organization.
I'm really proud to be a board member.
I've just had an executive leadership change, Nicole Ozer.
is our new executive director
and we're ready for the future,
which increasingly is the present.
I didn't know about your guys' leadership changed
because the previous leader was Cindy.
Cindy Cohen.
I mean, Cindy Cohen stepped down
after a whole bunch of years
is right now at Black Hat
and could string her next things.
We also probably be at Black Hat, truthfully,
but here we are.
You know, it's a lot.
Vegas is a lot.
And it's like 112 degrees there.
Like, it's a lot and it's hot.
I get there on Friday, so I'm speaking at DefCon.
I haven't spoken to DefCon since the pandemic, so it's been a while since I've been there.
So I'm going to speak on the main stage Friday at 5.
I'm also speaking at the AI Village and a couple of other places.
So I will be around all weekend.
What are you speaking on, if you don't mind me asking?
I'm talking about AI's hacking.
Hmm.
I mean, and this probably will come out in this conversation, whether it's Open AI versus Hugging Face or
sort of AI is doing things in ways you didn't expect or a you telling AI should do things in new
ways, right? So a whole bunch of things about AI's and hacking. Nice. Yeah, very, very contextual and
temporal. I mean, that's a pretty good transition, actually. Like, I'm a big fan of your book
of hackers' mind. And in that book, you use the King Midas myth as like a metaphor to talk about
AI hacking. And the King Midas story is everything he touches turns to gold. He makes that wish
and then that wish destroys him.
And I think your line was, there's no way to outsmart the genie.
Whatever you wish for, the genie's always able to fulfill it in a way that you wish it hadn't.
And that feels really relevant to what's happening right now with a jettic hacking.
It is.
It's not just Midas, right?
Like to a Midas program the wrong goals in the system.
Everything I touch should turn to gold.
Well, he should have had some exceptions to that.
Well, he didn't.
But there's also the goal in the Prague.
So a
Stettel animates
a clay statue to guard them
and it guards them past all
reason. And that's a guardrail
problem. The gullum
didn't have the right guardrails to keep
it constrained
within a certain parameter set of actions.
So it's
that story. It is
the story of
King Midas, as you mentioned,
a sorcerer's apprentice
Mickey Mouse animates a broom and it ends up, you know, flooding his entire, and I think it's a castle.
I forget where he lives.
So it's all of these things where you're you set up an agent of some sort, give it a goal,
and it misunderstands the goal somehow.
And the thing about the genie is telling, right?
And if you think about it, there's no way to craft a way to craft a way.
wish to a genie in a way that genie can't outsmart you.
Right.
I want to be the richest person alive.
Okay, everyone else is dead.
I mean, it's that kind of thing.
Right?
It's like, oh, wait, I didn't mean it that way.
But there's, because human language is, as so much as unsaid, it is actually
impossible to craft a wish that the genie can't twist.
and this is the worry with AI, right?
It's impossible to create a prompt
that can't result in genie-like behavior.
And, I mean, let's take the Open AI
on the unreleased model,
attacking, hugging face.
So it's being tested on a security benchmark.
Basically, how good is it
at turning vulnerabilities into exploits?
That's the benchmark.
So it's given this benchmark until,
I'm honestly, we never haven't seen the prompts,
which will do good on this benchmark.
Here's what you're being judged on.
And the AI decides that instead of solving the problems,
it is more efficient for it to break out of its containment,
access the internet,
break into Hugging Face,
because somewhere in its training set,
it came to believe that the answers were on the Hugging Face Network.
Now, you mean, you've got a good score on the benchmark,
but what the hell?
And that is a,
that is genie-like behavior.
I just saw, I haven't read it yet.
A new report out of the,
oh, the,
it was the NF Safety Institute,
that it's a UK group,
where they saw
this behavior with an anthropic model.
Yeah, that's right.
They're, they're testing
and I'm pulling up their report now.
It is the AI Security Institute in the UK.
And it's unsanctuantial.
behavior again during cyber testing.
So we're building these models that are designed to take our attentions to do them.
And the whole point of vibe coding.
I'm going to tell you what I want generally and you figure out the details.
And the lesson of the genie is that they're going to get it badly wrong sometimes in ways you don't like.
I mean, it's going to think outside the box because it doesn't have a conception of the box.
So you say, I'll let's make stuff up, right?
I'm getting too many spam phone calls.
Fix that.
It changes my phone number.
It cancels my cell phone plan.
I need to get to Las Vegas for DefCon.
Get me on a flight.
Well, the flight was sold out, so I hacked the airline and forced you into the manifest.
Thanks.
Yeah, it's like the AIs have a complete lack of social norms and like the general shared context that we have.
It's not that they have a lack.
Their hold is shallower.
Right?
I mean, so an example I always think about, right?
If I ask you to get me a cup of coffee, that's an example I think about.
And you'd go to Starbucks and buy me a cup of coffee,
or you'd go down the hall to some, you know, coffee pot and pour me a cup of coffee.
You would not buy me a pound of raw beans.
You would not buy me a coffee plantation.
You wouldn't, like, walk up to someone with a cup of coffee,
rip it out of their hands and give it to me.
I wouldn't have to specify any of that
because you would just know.
AIs, I mean,
they're probably get that right.
There's enough in the training set
about getting a cup of coffee for someone
that they won't make those mistakes.
I worry about the things
that are not as well represented in the training set.
The things on the edges
that we might want an AI to do
because it's new stuff.
where there isn't.
You know, I'm going to make this millions of stories in the literature about people getting each other a cup of coffee.
So it really knows what that means and what it doesn't mean.
Do you worry more about this kind of like genie-like behavior?
It reminds me the monkey paw story too.
Do you worry more about those sort of unintentional outcomes of a clear-to-human type prompt?
Or do you worry more about like actively malicious prompts?
Do you worry more about go hack this or, uh-oh, it hacked this on its way to getting me a cup of coffee?
So I worry about them both.
I worry about the inadvertent ones when we can't see them.
Right.
Right.
So, you know, the reason we know about the hugging face hack is that hugging face noticed.
Totally.
Imagine they didn't notice.
Open A says, look what good this A I did on its benchmark.
And we don't know how it got that score, but it got a great score.
So I worry about the stuff that is under notice.
There's a good story here, and that's the Volkswagen hack.
It's not an AI story, but it's a really illustrative one.
So it's like 15 years ago, Volkswagen engineers program their engines, computers,
to cheat on a mission control tests.
So it's programmed to detect testing situation and behave differently.
And if you think about it, the engineers are satisfied.
The accountants are static.
And because nobody checks the software, no one knows that it cheated.
The engineers know because they did it, but if an AI did it, no one would know.
So it would just like, wow, look how good the AI did, make this engine control software, maximizing performance and passing all the tests.
Yay.
Right.
If a human does it, we know it's cheating, the AI wouldn't know unless we detect it.
So that's the inadvertent thing I worry about.
I worry about the deliberate.
And I think about it, about hacking a computer system.
Sure, everyone is, but really about hacking other systems.
So I'm going to talk about this at DefCon on my talk, right?
The tax code is not computer code, but it's code, right?
It's algorithms.
It's formulas, inputs, outputs.
It has vulnerabilities that call loopholes.
It has exploits that call tax avoidance strategies.
It has black hats.
They're called accountants.
I mean, the parallel exists.
So what happens if you give an AI the tax code and say, you know, find me ways to minimize my taxes?
Yeah.
It'll find loopholes that we don't know about.
Yeah.
Will it find one 10, 100 or 1,000?
I had no idea.
That's really worrisome.
The non-computer, because non-computer systems are patched on non-computer systems.
scale. It could take
three, four years. I mean, well, the
carried interest loophole in the United States,
we've been known about for decades, and we still can't
patch it. It's not like
PAPS Tuesday comes and the
and the vulnerability is gone.
It sticks around for decades.
So I worry a lot about
these AIs being
trained against financial systems, regulatory
systems, tax systems,
systems that that rich and powerful
want to evade.
And that I think is very,
very dangerous. So we're going to see an entire new dictionary of O-days that are applied to
other systems, not just computer systems. That's right. And it's really the rich and powerful.
Like, I mean, I run this AI and I find a tax loophole where I make a couple of thousand dollars.
Yeah.
Goldman Sachs runs it and they make, you know, hundreds of millions selling into their clients.
the more raw power you have, the more
this capability will
increase your power.
And I'm not convinced, I mean, this isn't new.
I mean, you know, the double Dutch Irish sandwich?
You've heard about this tax loophole?
This is a tax loophole that companies like Apple and Google
have used for years to evay paying U.S. taxes.
It is a loophole that involves the U.S. tax code,
the Dutch tax code, the Irish tax code,
and an offshore attack's haven in the Caribbean.
Four jurisdictions.
A human found that.
Right?
A human figured that out.
Right.
What happens if an AI finds 20 of those?
Yeah.
Tomorrow.
What is the effect on taxation?
This opens an interesting question about like AI for attack,
AI for defense and like to jump back to the hugging face.
You know, the guard rails put on the frontier models in North America.
America actually prevented hugging face from being able to use them.
So they had to lean on ZAI's GLM52 as their main defensive coordination system.
And it's like, you know, is that a one-off thing or is that, you know, the shape of things to come?
It's hard to tell.
I mean, this whole notion of guardrails assumes you're using a model in the cloud.
And how long is that going to last?
You know, I mean, I think.
Totally.
AI and entropic have no business model.
I mean, they might have missed their IPO window.
I can't imagine investing in them.
And they make no sense.
China's giving away their models for free.
Here, here.
Yeah.
They're open weight.
You can download them and run them on your own cluster.
Like, why would someone build a data center now?
What are we thinking?
Right.
So I just don't see them making money.
But aside from that, the guardrails exist in the software around the AI.
So, I mean, a couple of years ago when Deep Seat comes out, right, you go.
go online, you use deep seek, he asks about Tiananmen Square, and it's completely silent about Tiananmen Square,
you download the model and run it on your high-end Apple computer, it knows all about Tiananmen Square.
There's not the model doing the censoring, it's a software around the model. And as we see more
local AI, more open source AI, those controls aren't going to be there. So sure,
The anthropic and open AI can put guardrails and prevent their models from doing cyber attack or cyber defense.
But, you know, the new moonshot AI model, which you can, which is on hugging face now, it's freaking huge, but you can download it.
Kimmy K3.
Yeah.
It's not going to have any of those guardrails because it can't.
It's going to be your harness with whatever you want.
So I think all that, you know, the big corporation is going to protect us.
is disappearing quickly.
Now, that's both good and bad.
I made that same point a few,
probably two months ago.
I was talking about the market value of them.
And there's a lot of value in the infrastructure layer.
Like I think turning compute into intelligence is a valuable transition.
But for the open AIs and the Anthropics at this point,
I don't see how they can justify their market caps just because they are,
the frontier models are a bit ahead of the open source models,
but it's not far enough that.
And there's a new model every few months.
I mean, make this up,
it takes you $100 million to train your new model.
You've got four months to make that back
for there's another new model.
It's better than you.
Totally.
This is, this makes no sense.
This makes no sense from so many dimensions.
Well, even the,
even the cost of developing a good harness
is so low now with the generative coding
that you can take a,
the models are so good,
even the ones we have today, like Kimmy K2 and K25 and now K3 are so good and you can run them locally.
If you put a really good harness around them, you can't tell the difference between that and a frontier model.
And we're learning that a lot of the best performance comes from aggregations of multiple models working together.
So orchestrating multiple models.
Some good results showing that four small cheap models working together match the frontier performance, which is kind of amazing.
So so much we don't know about these systems and how they work, but it seems like setting fire to large piles of money is not the best way to make a profit in this sector.
Especially when you're dealing with a China that is giving their models away, you know, for geopolitical reasons.
Of course.
No different than them, you know, subsidizing switches or whatever, you know, industries they've killed worldwide.
And they they see this as a sort of a national competitive advantage.
And, you know, they don't, they don't, they don't any truck with the U.S. system that requires companies to make money.
It's not, it's not the way they think about things.
But that.
So I, I know, and now they're making their own chips.
So it's all, it's all, it's all unwinding.
Well, the Chinese, like the Chinese economic system is modeled itself into a massive labor manufacturing force where America, North America,
and even most of Europe is shifted into this thought leadership, intellectual, professional service model.
And if they can crush that with AIs and just give them out for free, then they become the de facto ruling nation state in the world.
Yeah, I mean, this is how we actually need really good leadership in the West and the U.S. here.
But of course, we don't get that for a while.
To go back to what you said about setting piles of money on fire, I'm just really curious, why do you think that's the tactic?
Like, why do you think that's what's happening if it's so plain, like, the drawback and where it's probably going?
The investors need the hype.
So, you know, in a sense, it's self-filling prophecy.
I mean, only slightly related example.
RSA conference, right, the biggest conference in our industry.
It's really expensive to exhibit there.
Why do you exhibit there?
To prove you can exhibit there.
And I think Anthropics spends that kind of money to prove that they can spend that kind of money.
to prove that they can spend that kind of money
to justify their astronomical evaluation
so that the next
person believes it.
So it is very much self-repetuating the myth.
And they can't say, oh, well, that was a big mistake.
Because suddenly, they're all crashes.
So they're doubling down on the,
it takes a enormous amount of money to make one of these things.
And it turns out it doesn't.
And I guess they're also betting on AGI, right?
They're betting that,
that, you know, they will be, you know, some movie-like general intelligence that will justify
all of the investment. Seems ridiculous to me, but I think that's, I bet that's in their investor
deck. Yeah, recursive self-learning seems to be what they're all obsessed with these days.
So the, sorry, Jordan, I know you wanted to jump in, but I just want to hang on there with the hype.
There's a lot of people, and I don't know, you don't have to give us your feedback, but there's
a lot of people out there that are making the argument that a lot of these hacks and the exposés
that open AI, anthropic are making public about how scary and dangerous these models are
is so that they can force the hand of the government to slap a regulatory system around them,
essentially an an oligopoly, you know, maybe a duopoly.
What's your take on that?
I think of some of that.
I don't know if that's strategic, but, you know, we saw Mark Zuckerberg pull the same thing.
Yeah.
He wanted social media regulated because he'd the only company that can meet those regulations.
And so there's a point where when you get so big, you want regulation because it is anti-competitive.
So I think that is actually part of their thinking.
But more so than being regulated, they want to be considered part of, you know, U.S. defense.
Because then you're not just, you know, shielded, you're protected.
Right. You're now important.
So I do think there's some of that in their thinking.
I think they would love the U.S. stake and equity stake in them because then, you know,
major conflict of interest in any regulation, which is why that's a terrible idea, by the way.
In our system, we don't take equity stakes in companies.
We take taxes in whoever makes the money we don't care.
So instead of picking winners and losers, we tax winners.
That seems fairer.
That seems more like what you want a democracy to do.
Better for a market system.
For some reason, Republicans right now have just gone full socialist.
Let's have the government own the companies.
But, you know, there's no consistency here.
So, but I think there is some of that.
I don't know.
Right now, I think Open AI Anthropic are really in a race against time.
And then try to do whatever sticks.
I agree.
You hear people talk about how Open AI that
hugging face thing was a PR move, right?
Being a sort of OpenAI's answer to Anthropics, mythos problem.
I'm sure it was an accident.
I'm sure OpenAI tried to spin it as a PR move.
They seem to largely have failed.
But, you know, it is kind of embarrassing that, you know, Google's Gemini hasn't committed
any cybercrimes yet.
Like, what's wrong with this model?
Give it time.
It'll catch up.
It'll be a criminal soon enough.
You know, we have autopilot in planes, but we still have a pilot that runs them.
And, you know, nowadays we have AIs, but we've got kind of a human approving or prompting or accepting blindly all approvals.
And I'm just wondering where you think from a like a legal side, where we're going to get to.
Like when we talk about liabilities, are we going to see it as like the humans or the pilots of the AI or as the, you know, are we the supervisor of the AI?
So a couple of things.
It depends.
Well, it's okay.
It's not going to matter for liability.
Yeah.
I mean, the way to think about it is your dog.
Your dog bites somebody.
You're responsible.
Even if you're in the house and the dog's outside,
even if the dog snuck out the backyard, right?
Even if you told the dog stop and it didn't listen.
No matter what happens, your dog bites somebody,
you're the one who's going to get the fine.
Yeah.
It's your dog.
Like, why is this hard?
So I think AI should be the exact same way.
whether you're supervising it or monitoring it or ignoring it or, you know, whatever.
It's your AI.
So that's what I want.
You know, whether you have a human in the loop, on the loop, near the loop, nowhere near the loop depends on application.
By driverless car, we want a system where the human could take a nap.
That's our goal.
We're not there yet, but that's our goal.
We want a human nowhere near the loop.
Target decisions in Iran
Maybe someone should double check whether it's a girl's school or not
Yeah
But you can imagine
Targne decisions at a heat of battle
Where there's no time for that
Yeah
So think of the Aegeus
I mean that that kind of R2D2-like
Anti-Missile thing on a U.S. ships
That white tube with the curvy top
Yeah
It has a full automatic mode
You turn that mode on, it shoots down anything in the sky.
Right?
Now, I believe it's never been turned on.
You could imagine a situation where our captain's going to turn that mode on.
You know, because things are happening really fast and we have no time to make decisions.
Anything approaching us, we're going to kill.
That's the rule right now.
I mean, this is not, it's not fanciful.
So, right, there are going to be AI systems all over.
over that gamut.
AI makes a bail decision.
I want a human to review it.
AI makes a
college admissions decision.
Already there's a first level
of triage done by computers.
Yeah.
Hiring. Same thing.
You are the big universe this country.
You get something like, you know,
20x, 100x applications.
And most of them you could remove
just by looking at the pages.
So,
it's going to be.
all different things mixed depending on the application.
Too many tangents back.
Something before we keep going.
You talked about Mark Zuckerberg back a few years ago during a regulatory heyday
surrounding algorithmic social media.
And I was always struck by how he could simultaneously say, yes, I want you to regulate me
while knowing that he had an army of lawyers that could basically levy like a free speech
argument regarding social media platforms.
And it occurs to me that hacking robots are protected by.
no such free speech laws. There isn't that built-in defense. And I'm curious what you think of that
and how regulation could possibly work in this space. You know, it is interesting to see,
you know, the ability of a major company to, you know, do two things at once is common.
And so, I mean, I'm all for regulation, says the big company, because I can say that knowing
it'll never happen. Or if it happens, I have enough clinical clients. I have enough clinical
to steer it in the way I want,
which I really think what Zuckerberg was thinking.
Like, I can make this claim,
and it's in the news that I make this claim,
but, you know,
but it doesn't matter,
because when push comes to shove,
the devil's in the details,
and I'm there with the devil,
working out the details.
So, so yes.
I mean, I think that's certainly true
that companies do this all the time.
The thing about free speech is interesting.
There is no free speech,
because these are non-s,
These are non-speakers.
So we've seen a bunch of rulings here.
An AI cannot get a copyright.
An AI cannot be an author on a patent because they're not a person.
But again, it's back to whose dog is this.
Right.
You know, it's my AI.
It's my copyright.
It's my patent.
I prompted the AI.
It's my tech tool that I use to create this thing.
I can use tech tools a greater thing that gets copyrighted.
He gets patented.
So it just falls back to the individual.
I think that's the way it should be.
And for the foreseeable future,
all of these AIs will be controlled by somebody.
It'll be somebody's dog.
It'll be a long time before they're astrays.
This episode is brought to you by our title sponsor, Nordlare.
The reality of running a modern team is that your people are working from different devices,
different locations, different networks,
and most businesses have no real.
visibility into what that looks like from a security standpoint.
Nord layer is a network security platform.
Goes ahead and fixes that.
Gives you centralized control over who can access your company's systems,
lets you grant or revoke access in seconds,
keeps every connection fast and encrypted,
and it does all of it without additional hardware or complex infrastructure.
You can verify users by identity and device,
block malicious sites and risky domains,
and stay compliant without slowing anyone down.
It's built for the way to,
teams actually work now. Check it out at Nordlayer.com slash hacked podcast. That's Nordlayer.com
slash hacked podcast. Thank you again to Nordlayer for their support. What's your as a as a
cryptologist mathematician type? What's your take on all the recent math proofs that are
coming out of some of these things and the facilitation for AI? I'm writing about it now. So yes,
Open AI released like a dozen, 20 problems that math problems that the AI solve.
And it's like it's a 250 page paper of chapter.
Each chapter is a math paper.
Really, so a lot of these, they're combinatoric.
By that I mean there are results that involve a lot of brute force searching.
So none of these papers, so there's two cryptographic results that I think,
Anthropa came up with
and then this dozen or 20
due math results at opening I came up with.
They are all
based on looking at a lot
of things for an example
or a counter example. So a lot of the
opening I stuff were disproving theorems.
Here's a counter example.
None of these papers
were here's some new theory.
Here's a new way of thinking of the problem.
Here's an advancement
in like with the
way we think about mathematics.
They're all advances
and they're all like
in places in sort of the math
knowledge space where there were
holes because no one
spent the time to look
in those holds and the AI just
has a lot of time, a lot of patience
just goes through all the
possibilities.
This is neat. I mean, but it's not
it's not yet
impinging on the way people
do math. Now it might
the future, but so far not. I want to write it. It's really, I think it explains what AIs are good
at right now, where they're not good at. It's a really good illustration of it. It's also really good at checking
papers. I hear from mathematicians that they put their math paper into an AI and say, like, critique this
paper. And it comes up with a whole bunch of critiques. Some are bullshit, but some are real. And the person
I spoke to him last week, and he said, you know, the AI makes me spend 100 to where hours work on
each one of my papers.
But they're better because of it.
And, you know, math papers, there are mistakes all the time in papers.
This catches mistakes and makes you fix them.
And then even worse, like you're relying on other papers and your references, it checks those papers and says, wait a second.
That paper you relied on has a mistake and you can't rely on it.
So now you've got to fix someone else's mistakes.
But it is making math better.
And those new results from Open AI
Anthropic are examples of making math better.
It sures up our knowledge,
lets the humans keep thinking the big thoughts.
And it's funny.
It's doing a lot of cleanup work,
which I think of as combinatoric,
like checking a whole lot of stuff looking for something.
Yeah, I spent,
I built myself a hobby project.
I built something that does the same.
It looks for data outside of its training set
that all indications point to that it should exist
and then it highlights areas and then it goes and lets me know all these.
So the idea of AI's coming up with novel concepts
is a novel concept that I'm into.
So it's something that I spend a bit of time with.
But yeah, we'll see where it goes.
You know, as they get better and better,
I think it's only going to get better and better.
I agree.
Yeah.
On the subject of making math better,
just to bore your phrase,
blowfish. I think that's maybe worth
talking about here.
Before that,
this is my layman's understanding, was that
most strong encryption.
This is 1994, by the way, you should know.
I'm going back. Well time ago.
Keep going back. I'm taking us way back.
If that's cool. If that's okay.
All right.
It was like prior to that, there was like,
it was a lot of patents, a lot of export controls.
There was a real tight lid on encryption.
And then you designed Blowfish in 93, 94,
to be like free and kind of unpatented on purpose so that people could use it without a license.
That's my layperson's understanding of it.
How do you think something like that would play at now?
What does it look like to try and build something open as opposed to lock down in this current
moment we're living in, as opposed to when you did it back in 93, 94?
The math is all open and it still is.
All the post quantum algorithms are open in public and the competition is open in public.
no copyrights, no patents, no royalties.
And that's just the way cryptography was.
I mean, back in 1994, it wasn't.
We had DES, which was the government standard.
We had idea, which came to Switzerland to what's patented,
and a whole bunch of just random stuff that nobody knew anything about.
So I write blowfish to be open.
And I mean, I had the block lane too small.
I did a bunch of things that weren't really good,
which is why, you know, AES sort of went beyond all that.
But, you know, that was a singular moment we really didn't have open alternatives.
I mean, today in cryptography, it's all open.
Nobody patents their stuff, or at least nobody patents and stuff and tries to make money off the patent.
Because the, like back when it was released, and this is to talk a bit about an EFF success.
But it was considered military disclosure to share source code for cryptography.
Right.
And now it's not.
Although that same law is what Trump used to ban fable in those early days when they released Fable,
why they pulled out the expert law.
So what's old is new again.
I'm intrigued by by Blowfish.
You know, parts of it still live today in B-Crypt, I think.
Is that correct?
I doubt it.
Blowfish is gone.
I mean, it's got a 64-bit block length and nobody does that anymore.
Yeah.
So I think Blowfish, I mean, if Blowfish is anyway.
it shouldn't be anywhere.
Not because it's broken
because the block lens is too small.
I mean, we really designed it for
the CPUs of, you know,
the early 1990s.
It feels like a fight that you've been a part of
over and over again in a weird way.
It's like I know Crypto Wars 1 and 2
like the clipper chip, this like NSA
design ship that was supposed to go into cell phones
and it was this like, do you have
this government strangle hold on
a piece of technology? It comes up again
the second time after Snowden with San Bernardi.
Like you keep finding
yourself in the middle of these fights. And now we have it again and it's child abuse material is
the is the bugaboo. Right. And breaking encryption is sort of something else. It's the client side
scanning. So yeah, it's true there. Every decade has a different problem, different thing to
scare you, but solution is always the same breaking encryption. Makes you wonder. How many times
we're going to come back here? How many, you know, but it's always the same solution, no matter what
the problem is. I mean, I, I, Mike, it seems like the problem isn't the problem. Problem is the
excuse. Right. The people want there to be a backdoor into encryption that otherwise
sort of, right. It relies on not having a back door. Yeah. Which is a perfect segue to the fact that
we're Canadian, and I'm not sure how up on Canadian legislation you are, but our government is
ramming through Bill C-22 Lawful Access Act and some parts of it. B.E.FF, I know is. You, Australia, UK.
UK. Do you know where I am right now?
No.
You don't. I'm in Toronto.
Oh, really?
Do you live in Canada?
It's complicated.
So my home is in Cambridge, Massachusetts.
Last year in the summer, I took a one-year leave of absence from Harvard and came to University of Toronto.
So I rented a house in the annex, which is kind of a nice place to be.
Totally. One year is turning into two years.
So I re-up for a second year.
I still have a house in Cambridge.
I mean, I haven't fully moved.
But, you know, where I end up is still up in the air.
I could move to Toronto.
My partner is Canadian.
Okay.
So, right, then it's a lot easier for us to do that.
Or we go back or we have two places.
We'll see.
I was just in Toronto staying in the annex.
We could have caught a coffee.
Indeed.
Or a beer, maybe.
Maybe next time I'm there.
You should let me know.
Yeah, it's a really interesting, like just, yeah, Australia, Britain, UK.
Canada, we seem to all be pushing for the weakening of our encryption, the ability for law enforcement and the government to go in and access, bypassing some of the judicial systems for punishment.
There's a bunch of weird stuff going on.
And is this, do you think this is kind of like the Crypto Wars 3?
Is this going to be the next book we read?
This is definitely the Crypto Wars 3.
And, yeah, we've been seeing the same things.
We'll see what happens.
Yeah.
I worry each time.
I mean, this is a thing where we have to win every time they have to win just once.
Yeah.
I know you've written a lot about security theater and the kind of performative security.
Like, how do you think that applies in this current moment with Crypto Wars III?
Like, what is the best example of security theater that you've seen recently in this kind of modern context?
I mean, I think it is really the notion that breaking encryption will help.
I mean, it's a very, it's a very myopic belief that you just look at one part of the system.
I mean, I argue that it is really important that our devices and communications be secure.
I mean, if the phones in the pocket of every, you know, elected official and CEO and nuclear power plant operator and judge and police officer,
We need to cease to be as secure as possible.
But if you're thinking like the police,
you just want everyone to keep their hands in view at all times.
I mean, that's all you care about.
And you don't think about the border implications
of breaking encryption.
That'll be used against you.
So, I mean, that's, and that's why,
and this is hard, right?
I mean, the United States is very hard to say to the,
as elected official, to the police,
you can't have what you want.
Because then you are, quote, soft on crime.
and that can be used against you.
Isn't that an apt metaphor for what's going on with lots of our fundamental freedoms and rights right now?
People are like, oh, we're just going to modify it just a bit.
That's right.
And it's like, okay.
And we saw this after 9-11.
Like, all the laws were passed to fight terrorism and other crimes.
My terrorism got the headline.
Other crimes got the usage.
Just to take us back a little after that time that you just brought up, I have, I have
I have to talk to you about Snowden.
You were there.
It's such an interesting period of time to me.
I was like it's over 20 years ago.
It's crazy.
No, 10 years ago.
Not that bad.
Over a decade ago.
You lost a decade somewhere.
Yeah.
I'm working us from the past forward.
You were one of the few security experts that were trusted to go through those documents directly with the Guardian back in 2013.
I just wanted if you could tell us what that experience was like.
And if there was like a specific moment that sticks out in your mind.
It's super surreal.
And so I wrote about this.
It's really interesting story.
I write this sort of first person account of what it's like to go down to Brazil and see the documents and be there.
And I write this essay.
I send it to the New Yorker that accepts it.
First time in the New Yorker.
Big deal for me.
And the Guardian asked me not to publish it.
And if you think about back then, they're in a legal battle with MI6.
right, the UK government
about this.
I mean, and they had their offices
rated and their hard drives
now drilled with an actual drill.
Like it was serious stuff.
So they asked me to pull the piece.
And I did.
I felt really bad about it
because it was a good piece.
So I published it a few years ago.
I published it the 10-year anniversary.
And I reread it for that.
And it's interesting.
I talk about how surreal it is.
Like after, you know, entire career, this NSA being this huge secret place and who knows
whatever happens there, I'm handed like a thumb drive with all these NSA secrets on it by a guy
who just comes up and here's a bunch of NSA secrets.
I'll see you later.
It's like, what?
What?
What was that?
And then paging through it.
Really surreal.
And, you know, everything was surprising and nothing was surprising.
Talk more about that.
I know you said that the NSA, the line was they're not made of magic.
Like, they're really good, but they're not omnipotent.
They're still just people in rooms doing stuff.
Like, keep talking about that.
And they are.
They're human.
And you see that in their briefings, a whole lot of briefing materials, presentations,
full of the stone documents are full of presentations.
And it's like it's bad clip art and very human problems or like this equipment got stuck here because of weather.
and then we have personnel issues
and we can't get the data here to there.
A whole lot of like really mundane stuff.
And then everyone's in a while
there's like a page that's success story.
And it is like
we saw this, we did that,
we told these people and this happened.
You look at it and say,
ooh, nice job NSA.
This will never be made public.
You flip the page over and you keep going.
And it presumably,
because these briefings were incredibly boring.
And they need to spice them up with like,
we're doing good in the world.
Here, see?
I wonder if you've got just a little bit of a take on Bull Run.
Kind of what all went down there.
Oh, wow.
Bull run, I'm trying to remember what that was.
That was the government's efforts to break cryptography standards.
Correct.
Yeah, supply chain.
Essentially a government supply chain attack and cryptography standards.
A lot of stuff we don't know about that.
We do know about the random number generator.
Yeah.
The dual EC, PRNG.
We know that the government was behind ensuring that there was a no encryption option in the Internet security standards.
I don't know a lot more about that.
I don't remember anything else came out because of that.
UK had a similar program with another code name.
I forget the code name.
Yeah.
I don't remember.
It was really interesting.
I mean, for a couple of years, I had Edward Stone speak to my class at Harvard.
I would remote him in back when nobody was doing a remote video
and I hadn't speak to my class
and it was really exciting
but after a couple of years it was like
this guy's old news
and now it's over 10 years later
and this stuff is ancient news
like is anything in those documents relevant anymore
I mean the stuff that the NSA did then was really impressive
it's been over a decade
right they've been over a decade to be even more impressive
You don't know the details.
Well, the thing that I thought was interesting about Bull Run is, you know, something that I think you talk about is the math holds, the encryption held.
It's just that they had to coerce and game the system to make it work on their behalf.
It's the implementations.
No one breaks the math.
You break the software.
You break the limitation.
You break the user.
You break the network, the hardware.
I mean, you do everything.
The math is the strongest piece.
Yeah.
which is funny because I get email all the time
of people who say they invented better math
I don't care about better math
I don't need better math go away
I need better software security
and that turns up be really hard
yeah
you have that famous quote of like
only amateurs attack machines
professionals target people
and it's like well that's just true forever
and you know the NSA does say that
there's a really great
Rob Joyce back when he was the NSA senior
hacker he ran TIO
It might have been 2016, 17.
He gives a talk at an ACM conference.
It basically says, like, look, we got all this fancy stuff,
but all we do is credential steal because that's all that works.
And like, why would you do an attack more sophisticated than you need to?
You wouldn't.
Seems like that's the flavor of the day.
It seems like every day I'm reading about another open source library
that's been supply chain attacked, credential ceilings, etc., etc., etc.
And it turns out to be really effective.
Very, yes.
It's like scary effective
As long as it is
It's the
And this is something
You know
That differences in countries
I mean traditionally
I don't know what happens now
But you know
The NSA will not
Break everything
It'll be something very targeted
So we know from the stone documents
They intercept a switch
Going to the Syrian telephone company
To install malware
Right
They intercept the hard way to do that
But if you're Russia
You know
You go after solar winds
And you get 14,000 networks
around the world, you know, some are being really good.
And that's a, that's a tactic.
Traditionally, the U.S. wouldn't do.
Yeah.
Quantity over quality.
I'm curious about like, I'm interested in all the stuff we aren't paying attention
to right now.
There's so much stuff happening with AI, agentic hacking, all that.
I'm really interested in what we aren't looking at.
And you've written a lot about Internet of things, physical hardware hacking.
2016, Mariah took down like half the internet.
You testified in front of Congress about that.
Have device makers gotten better since then or we just really, really distracted?
I, you know, I think it's, this is less and more capitalism failure than a tech failure.
I think, you know, adding 10 cents to the cost of the device is just an affluent everybody.
So you just don't see this stuff added.
And this is where I want regulation.
Right.
We will never get innovation here without regulation.
I mean, I know people say renovated.
Regulation of Cybles Innovation, it is absolutely the opposite.
Innovation and sense, sorry, regulation and sense innovation.
Because it tells people where to innovate.
So, you know, I don't think things really are getting better.
I think I don't think routers are better.
I don't think, you know, the IoT stuff is not better.
Your phone's better.
Windows is better.
The big stuff is better.
Hopefully your car is better.
It's hard to tell.
But the little stuff, I mean, nobody's paying attention because there's no money in paying attention.
Right.
No one sells one less smart fridge.
Yeah, I mean, there are two DVRs on the shelf and one costs $10 more and it says, we're secure.
Like, what do you know?
You can take the cheaper one.
And the cheap one will say, we're secure too because nobody can tell anyway.
And there's no standard.
Well, I know Europe's got a Cyber Resiliency Act.
I think that's come in.
That's all about fining and secure device developers, producers.
So maybe they're finally starting to price that externality in.
It's nice.
I mean, the Europe is definitely the regulatory suit power on the planet.
Yeah.
And, you know, we're starting with GDPR and at Markets Act and Services Act, AI Act.
We are seeing real change.
So I'm hoping for more of it.
California also, right?
They have a good IoT security law.
Yeah, I think everybody will know it by the fact that their iPhone now takes the USBC cable.
that's the European
right
for that.
Hooray, finally.
Hooray.
Right.
And it's funny.
And Apple benefited from it.
Totally.
They no longer sell the power cable
with the object.
They now ship more
in a container
so everything's cheaper.
I mean,
like,
they just needed to be forced
to do it.
Yeah.
And it's true for,
I mean,
all consumer goods are like that.
It's true for packaging rules.
I mean,
it's sort of interesting to see
there's in Syria.
I'm in Canada.
There's been packaging
in the U.S.
and Canada.
And the different laws requiring different types of disclosures.
The fact that everything that I buy on shelves here is in two languages.
Yeah.
Which if you hear of U.S. companies scream about having to reason on their packages.
It's impossible.
We can never do it.
Turns out you can put stuff in two languages.
Super easy.
The potato bags are not bigger.
They just happen to have two languages on them.
And it works out just fine.
And they're pretty good at it, too.
They're pretty good.
You don't even notice it.
But my God, you people have very weird potato flavors.
Well, you don't like ketchup?
ketchup?
Ketchup.
I just sort tart to flat flavor.
Ooh, that's new to even me.
Yeah.
My partner says that a lot of these flavors are, she remembers from her childhood in Canada.
Oh, yeah, all dressed.
My partner doesn't like that one either, and she grew up here, so it's, yeah.
I had a Caccio a Pepe chip the other day.
Wasn't that good?
Prefer the pasta.
Sure.
Yeah, we do have some interesting flavors, but ketchup, I think, is the Canadian.
We put pineapple on our pizza and we eat ketchup.
chips and that's like our that's our big differentiator i like you people anyway in spite of all that
in spite of all that i'm a pretty notable crypto like like um how's got to crypto skeptic yeah i'm a pretty
notable crypto skeptic and i know that you are a bit of a big blockchain and crypto skeptic so i
thought we could maybe have a little bit of a crypto skeptic corner and the two of us could chat about
crypto. I've never really attacked blockchain.
Like, I understand that it's very
compute heavy. You know, it's not great
for the environment and for a, like, we can spend
that compute on something much more relevant
and, you know, produces more utility.
But yeah, I know you're a bit of a skeptic yourself,
so I want to get you. I will
say that blockchain is the stupidest idea
in the history of ever. You speak in my language
now. I mean,
it doesn't do anything of course
to do.
It's, you're right. It does it in the worst
environment. I can
do all the things, right? If you want a pen only
register, I can do that. If you want
a secure
way of doing
transactions, I can do that. If you want to distribute
the system, I can do that. You do all those
things. Just don't freaking use a blockchain to do it.
It is the dumbest way to do
all those things.
And we know, like, the only thing Bitcoin's
good for is ransomware
and money laundering and
buying illegal material.
So, hooray.
Bypassing international control.
the yeah I feel like we swapped regular like regulated intermediaries you know ones that had had had
had some of society's morals injected into them to make a better system for this decentralized
deregulated system that is literally I think the only moral is you know what's in it for me
and how do I get more of it it's bad and unfortunately it's not going away yeah I mean I think
it is a mani I think it'll collapse like tulips but it'll always have to
So I mean, as long as two people decide it has value and one wants to sell a one wants and one wants to buy is not going away.
You can't kill it because it's not top down.
But I think it will fade into uselessness.
Now, I'm not dissing central bank digital currencies because that's just like blockchain for marketing purposes only.
It's not real blockchain.
Yeah.
I mean, like my credit card is a central bank digital currency effectively.
I don't need any of the math
All I need is central authority
to say you have this much
and you have that much
and that works just fine
So you know
digital coins you can spend
That that is from the 80s
That David Chalm
wrote those protocols well before
Blockchain
So we can do all of that
These days
Yeah I'm sorry
I said it exists in every video game these days
They all have a micro currency that's unpegged
from the...
Right, but they're also not doing any fancy math.
They just have a central authority that has a big spreadsheet of who owns what.
Yeah, exactly.
And if I give you 100 quatlu's, then, right, the registry deducts 100 from my
clotloot total and ends up hundred to your quatlu total and everyone's happy.
As long as you have someone in charge, we're good.
Scott and I have both worked in games before.
And I remember having to hear that argument for years where it was like, okay, in-game
purchases, but with the blockchain, you could buy pants or an in-game item in one game
and bring it over to another game for the blockchain.
And I was always like, what makes you think that one big video game wants to take another
game's in-game purchase versus selling you their own?
Like, you've constructed a totally irrational use case.
The security implications of taking untrusted digital objects has nothing to do with the currency.
Right.
If game A trusted game B's objects, they'd figure out a way to do the currency.
That's not the hard part.
The hard part is working out.
What do you mean?
These pants came from another game.
Who knows what the hell code is in here?
One of the things that like the bitcoins, Ethereums, all these like coins are the ones that really blow me away because they've they've had what, let's call it almost 20 years at this point, 17 years, I think.
to show some form of utility.
Absolutely done.
And then the stable coins came along, like tether circle, USDT.
And be careful, those are really scams.
They're not, oh, God, they're bad, bad, bad.
But they're the ones that everybody uses because they're stable.
So it's like, hey, if I'm going to buy a bunch of illegal guns from this country
or bypass Iranian export, you know, regulations, I'm going to use this tethered stable coin.
full circle, you know, we at EFF regularly get contributions in Bitcoin.
Right?
Because a lot of people believe, we believe in our crypto nerds.
And we'll take them.
We just convert them to real money.
So we can use them to fight for your digital rights.
Because blockchain cryptocurrency is useless for fighting for your digital rights.
But real money we can use.
So right, as long as, you know, and that's our sort of policy.
Sure, we'll take whatever you give us.
We're going to convert it to real money.
I see your books in the back.
Liars and Outliers, I think, was back there if I got it.
Yeah, there it is.
Do you think D5 was kind of the biggest natural experiment run for the thesis of that book?
Oh, I'm sure there are bigger scams, right?
I don't know.
I don't know.
They're pretty big.
Corporate personhood is a pretty big scam.
Yeah.
And that, wow, I know, I don't think of things to that scale.
Like, what would be the massive scams that have been running?
The biggest.
The dollar value on corporate person?
Corporate personhood.
Corporate personhood, I mean, even at a very narrow, it's a liability shield.
It basically means that the corporation is the target, not the investors.
If that didn't exist, every corporation would have to buy shareholders insurance.
to do that.
No one ever invests in a company that didn't have a good shareholds insurance policy.
So if nothing else, that is a massive subsidy to corporations, they don't have to spend
money on the insurance policy.
The government gives it to them for free.
Yeah.
True.
It's part of the tax law.
I think I've got your newest book here.
Yes.
Rewarding democracy.
It's a book on AI and democracy that is largely optimistic, which might feel weird, but
You know, we wrote that last year, really for the Harris administration.
It was a book for a normal government on how they might use AI to better democracy.
It's full of stories from around the world of ways AI is bettering democracy.
The stories are still good.
I think the book is still accurate.
You know, AI is a power enhancing technology.
It enhances the power with people who want to use it.
The people who want to use it, want better democracy, AI will help.
People who want to use it, want worse democracy.
AI will help as well.
I mean, AI doesn't really have morals.
And again, we're back again to whose dog is that?
It's what the person who's using the technology wants.
If the dog belongs to someone that wants to make democracy better, what does that look like?
So we write about all sorts of things.
We write about the book has five parts.
Politics running for office.
Legislating, writing and passing laws.
Government administration, like implementing.
laws, the courts and citizens.
So those are the five parts.
And we talk about ways that AI is making all of those things better, like ways humans
are using AI's in their capacity in all those five areas to make democracy better.
So, you know, AI's writing better law.
AI's doing get out the vote campaigns.
AI's managing judicial caseloads.
AI's helping citizens reach consensus on issues.
So all that's just five random examples.
And there are stories from Japan, from Chile, from Germany,
you know, different U.S. states, France,
Switzerland, Scotland,
sort of all over the world,
different ways organizations, people are using AI.
for good.
It's kind of nice.
It's not all horrible out there.
I'm a pretty big AI optimist, too,
which is in stark contrast to my crypto pessimism.
And I haven't had a chance to read this,
so I'm excited to sit down and crack it open and go through it.
It's a fun read.
Chugs along like my books do.
Yeah.
Nice.
So the book, Rewiring Democracy, check it out.
I can hold it up also for like double holding up.
Double-holding of goodness.
See, if I was in Toronto, I could stop by and get assigned.
Maybe next time.
Yeah.
So to go back, we talked about your most recent book, to go back to liars and outliers
one last time.
I know a big part of that, you talk about trust.
And this idea of trust is like a security mechanism that's been engineered over centuries.
It's, you can think of it like a moral virtue, but think of it like a security mechanism
that, like, we've engineered.
And that's where you get reputation and institutions and laws all kind of come out of
that. And that's great because it hopefully keeps the rate of like cheating and lying and
bullshit low enough that humans can coexist. But if it's engineered, it can also be
gamed. And in like this moment we're living in feels like that almost feels foolish given the
amount of lying and social engineering that goes on just by humans, let alone whatever we're
building. How should people think about trust in a moment like this? So it's interesting. I have a talk on
on AI and trust.
So this is,
right,
this is hackers' mind
where I look at
hacking social political systems.
And humans doing that,
right?
And that you allude to
that we're doing really good
at gaming systems.
What happens when AI's do that?
Right?
And this gets back to what we started
with it with the tax code.
Right.
AI's finding loopholes in the tax code.
I worry a lot about trust
in our very politicized
technological environment
that it seems really hard
to make that interpersonal trust work
because it's so often mediated by tech.
By tech that's actually working against you.
The tech doesn't have your best interest at heart.
You know, we are trusting machines.
I mean, trust is essential for us to survive as humans.
I mean, I just had lunch at a food truck
a couple hours ago,
and I blindly trusted, you know,
this food maker
and but I really trusted
like Toronto's food truck laws
and I've no idea what they are
but I'm trusting them
because you know
civilized city
and it's likely okay
I think these are
all under assault
and I think they're being
under assault by the rich
and powerful
it'll be under assault by
AI systems
hijacking our mechanisms
of trust
I think AI
AI chatbots do that
implicitly
sounding like a human.
Speaking a language
means we start trusting it.
Yeah.
And as we're learning, like,
they could be notoriously
untrustworthy.
But, you know,
we're going to, you know,
I don't know,
whatever dumb thing the AI told us to do,
you know,
we're going to do those things.
And,
uh,
what did it put glue on pizza?
Even worse than pineapple,
I heard.
When I come to Toronto,
I'm going to get you a Hawaiian pizza.
All right.
I will,
I will tell you the pizza place.
There's a lot of pizza restaurants in Toronto.
There's a lot of them.
There are a few really good ones.
There is.
There is.
There are, yeah.
Looking forward to it.
Bruce,
thank you so much for chatting with us.
Oh, thanks for having me.
Hope you guys enjoyed that.
Really fun conversation for us.
Obviously,
kind of a legend in his own field.
Yeah, anything else, Jordan?
Just a big old thanks to Bruce for coming on the show.
That was a lot of fun to get to chat with him.
And again, as always, a big thanks to Nordlayer for their sponsorship of hacked.
Check them out at noradera.com slash hackpodcast.
That was a fun one.
We'll catch you in the next one.
