Hacked - The REKK Wreck
Episode Date: June 2, 2026Heads up if there's more cat meows and talking over each other than we normally let fly, this is a summer episode with less editing than you've ever heard! We kick this one off with a story of a fra...ud ran from a telegram channel and a scheme to use something very mundane to steal millions; refunds. We discuss REKK and the rise of refunding, human-oid objects, Mythos, and several other strange tech tales. Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
Rec was a public telegram channel.
The group had more than 30,000 followers at the time that U.S. federal court filings caught up to it in December 2023.
If you had telegram, you could find it, you could read it, and for a fee, you could hire the people who operated it.
According to a complaint filed by Amazon in the U.S. District Court for the Western District of Washington on December that year,
quote, Rec operates a telegram channel with over 30,000 followers where they brazenly advertised services,
that they fully admit are fraudulent.
The product they're selling on the channel was a service,
and it had to do with refunds.
This scheme gets pretty elaborate.
It involves bribery and social engineering,
but the basic idea is dirt simple.
It is a very elaborate version of a thing that a lot of people have done non-frogulently.
Customer orders an item on the internet.
Typically, something expensive, a laptop, or a game console, an iPad,
had just a bunch of MacBook errors.
Amazon was the named retailer in the complaint,
but Rec's own marketing makes it very clear
that they can hit a whole wider catalog of retailers.
Once the product ships and is received by the customer,
the customer pays Rec a percentage of the items purchase price.
The customer gets the item,
and then Rec embarks on like a social engineering project.
They set off to do the work of getting the customer's
money refunded by the retailer for the item that they actually did receive. Through returning empty
boxes full of bricks, for example, manipulating shipping data, fishing employees for their credentials
to mark things as legitimately returned, bribing mail carrier employees, developing custom malware.
This gets elaborate. The basic idea is the customer keeps the item and assumes the liability,
the retailer eats the loss and Wreck gets their cut of the original sticker price.
This is a refund scheme or refund fraud or just refunding depending on who you ask.
It seems like a lot of work.
It's a ton of work.
It's so much work.
For not that much payoff.
They actually stitched together a shocking amount of money on this little marginal thing of refund fraud.
The thing I found fascinating about this, it's not like a dark web in the weeds crazy international cybercrime.
I liked this because this is a normal web thing.
It's like normie internet crime.
And we don't get to talk about that a lot.
It's normie internet crime.
It's normie cyber crime.
It's like I want a new laptop, but I don't really want to pay for it.
So how do I steal it without stealing it?
I pay a different company to steal it.
and I keep it and I pay them a little bit of a cut.
You got the idea.
The name of the channel was Rec, R-E-K-K-K,
because it sounds a little like Radicus,
as in Domantas Radicus,
the man charged with the scheme.
And this sort of tranche of court filings,
how we know about it and why we're talking about it here today.
So let's start this very loose summer chat episode here
with the story of rec,
on Hacked.
Scoop-Dood-D-D-D-D-D-D-D-D-D-D-Scribledy.
How is your summer going, Jordan?
It's pretty good.
It's the middle of summer.
It's, there's, I know there isn't where you are, but there is sun where I'm at.
It's pumping rain where I am.
It's just not summer where you are.
Yeah, we are, we are, have flood advisories.
There is so much rain.
Do you really? Yeah, the rivers and stuff.
all the melt, the snow melt from the high up in the peaks, plus all the additional rain
are making some of the rivers a little bit high and flowy than they should be.
Well, and there's some neighborhoods along the river in that city.
I remember being a teenager having to move sandbags down to the edge of one particular
neighborhood.
It's no joke.
It is real, but other than that, it's been lovely so far.
We actually needed some rain, so I don't think anybody's upset that rain is.
come, but it is a lot of rain.
I can imagine that.
Yeah.
Well, stay dry out there.
I'll try.
I'll try.
No promise.
We try.
Oh, Lord, how we try.
It's hard to play tennis and it's hard to fly fish.
It's hard to, they can't do any of the fun summer activities because the rivers are too
high and fast and the tennis courts are soaked in water.
A little subtle down.
So it's been a little forced R&R time to play with the AI.
agents. Let's see what's up. Build some fun things. I think I'm going to build the new
hacked podcast website as well. We could use a new website. I think it would be fun to have a new
website, even make a little project out of it. We used to have a website and then we just went to
like a link tree. I feel like that was a smart pivot from keeping the old one up. But now with
Claude Design. Sure. The technology.
You can sit on a website in like 40 minutes. It's like, why wouldn't you? Kick one out. Let's
see what happens. If you see a new hacked podcast website, check it out.
Thanks for listening. This is going to be a chatty episode where we talk about a few stories.
Like I said, it's kind of summer. The sun is out. I don't have a big icy drink, but I should.
I had a pretty well-researched story about like the strange tale of the death of a crypto hustler,
which is interesting, but my God, it's summer. We've got stuff going on. This episode's going live
the day that we're recording it. So not a lot of time to chop up all that archival. So rather than taking it
episode off. We thought we would bring you something light, something summary, some normy
internet crime to kick us off. Let's get into it. Let's get into it. Refund engineering. It's a deep
dive. The way that we know about all this was December 3rd, 2024, Lithuanian authorities arrested a
man in the city of Vilnius and seized. This was, we have Amazon's filings. We have court
filings here. This was Amazon's filings. When they got him, five million euros in crypto.
currency, which to your point about all the work that goes into just shaving off a little margin
on an iPad, it adds up.
That's five million years more than I would have expected.
It's no joke.
But if you're writing custom mallewaring, you're hacking into Amazon, like, we're getting,
we get into forged police reports.
It's so high effort.
I'm floored by it.
700K euros in cash on him at time of arrest from what I can tell.
Domitaz Radicus was charged in Lithuania with fraud and money laundering and faces a maximum of eight years if convicted.
There's many numbers floating around, but they are all in the millions.
And the single largest retailer was Amazon.
It is why we have so many filings from them telling the other side of this whole scheme.
And again, Wreck was not the only name this operated under.
And Wreck and its subsidiaries were not the only parties in town.
This is a whole thing.
Yeah.
Well, I spend a decent amount of time in odd little sub-communities, audio files, stuff, things like that.
Sure.
It is probably a daily, weekly, if not daily post in there that somebody buys something, opens the box and it's either a brick or it's like something like, you know, monitors.
They'll buy a $1,000 pair, and there'll be like a $10 pair in the box.
So somebody's bought them, taken out the other ones, put in cheap ones, and returned it.
Sure.
automated system sent that back out to someone else.
And now they're returning it saying there was rocks in the box.
And who does Amazon look to given that they never actually opened the box to be like,
well, either you're lying or the person who returned it before you is lying.
And now we have no way to prove it.
Yes.
Yeah.
It's a supply chain at scale vulnerability that some people have figured out.
It's like, oh, this requires basically no technical skill to overcome.
It's just sort of brute forcing these customer service systems.
and lying with a straight enough face.
And because each time it's a new customer doing it,
there isn't really a great trail.
It's very hard to tell who's behind this.
Refund engineering is like a term of art,
kind of for the people who do it.
Prosecutors and Amazon just call it flat out refund fraud.
The practitioners themselves kind of just conversationally in the documents
call themselves refunders.
There are legal definitions.
There was one that I found.
a Department of Justice, Oklahoma, 2023 thing against a different one of these.
Described them as instructing fraud customers to purchase a product of their choice at one of many retailers they targeted,
collect information about the order, and then contact the retailer to initiate a fraudulent refund transaction using a variety of methods tailored to the particular retailer.
It's fraud as a service, customer keeps the product, operator does the fraud, operator takes a cut.
You got the idea.
Explain this to me.
If you were willing to do this level of fraud as a service,
why wouldn't you just do the fraud?
Like, well, why the cut?
You know, it's like I'm doing this for 10% when I could do it.
Like for fire sale, resale, like if you were to buy, you know,
whatever, pick something, a laptop for $2,000.
Totally.
If I were to buy a $2,000 laptop and sell it on fire sale on Facebook marketplace,
I'm getting what, like 1,400 maybe, 1250 if it's brand new in box.
That's probably more than the cut that they're taking.
So like why do this as a service?
Yeah, no.
So the different, the cuts that you're talking about, there was a rec took like 30% depending
on how you were paying for it.
It was different with crypto and PayPal.
There's price charts for all this stuff.
Some took 15 and 20.
There's a pricing ladder to quote the MKBHD thing.
they're just trying to get you to climb up it.
My theory is the reason that they would give away 70% of the value in this situation,
if they're keeping 30,
is basically they're paying for your paper trail with the seller.
So you show up and you're buying something off Amazon.
They go, I know who that is.
That's Scott.
That's real guy, Scott.
He buys stuff all the time.
He must have gotten a bad thing.
We ship a gazillion items.
This issue comes up.
if new buyer in insert country in eastern Europe shows up and starts buying $200,000 worth of laptops,
it doesn't matter that they've kept that margin because Amazon's just going to go like,
this is a fraud operation.
So I think what they're renting from you is your legitimacy as a customer.
That's my theory.
I had a run in with a restaurant the other day with just a guy sat next to you at a bar
and he worked in a sales role in a company and said, like,
selling like RVs and, you know, ATVs and side by sides and random stuff like that.
He was just sitting at the bar, we started chatting.
And he said that in that industry, it's gotten insane.
The amount of people that, yeah.
He said that the banks actually have gotten so tight and restrictive with their financing
because the amount of bank fraud going on.
He says that every single day they have two to four.
four people come in who kind of fit a mold. They have a really high credit score. They're new to
Canada. They come in with all these things. And then they try and buy a lot of stuff.
Like they try and buy two, three hundred grand worth of things. And the banks previously used to
approve them because they have this great credit score, you know, this good income on paper,
all the rest of this stuff. And then they make the first payment, fire sale the stuff, leave the
country. And he said that the banks have been burned so much that they have become so tight with
who they will approve that the retailers are now policing it when they get people that come
through the door that fit this kind of, you know, I've never really bought in here. I'm new to Canada,
but I have an 890 credit score. I want to buy a quarter million dollars with a stuff. And they're just
like, yeah, sure, fill out the credit application. And then they just throw it in the garbage and be like,
or you were declined because they don't want to
they don't even want to press the banks to do it anymore
because they still want to have access to the credit
when they have real clients that come in
and actually want to buy stuff.
Yeah, sure.
So it's not just online, it's going on everywhere.
And like, just to follow that sequence of thoughts down the line,
what a bummer for the person who's just like,
I finally made it to Canada, I've built my life here,
I've gotten my stuff all figured out,
it's time to buy that boat,
no one will sell me a boat or an RV or whatever it is.
It's like, ah, that's a downer.
Interesting.
Yeah, I mean, is it refund fraud?
That's not even refund.
That's just buying stuff you never have an intention of paying for.
That's like lease fraud, I guess.
Yeah, yeah, lease fraud.
It's being like, yeah, I'll keep paying you back for it.
Wink.
And then you fire sale.
A quarter million dollars of debts, fire sale everything for 200 grand and just disappear.
This is a total tangent, but it is an interesting knock-on effect of like a predatory leasing system.
There's no amount of money we won't lend you if you're willing to buy a crazy depreciating asset on wheels.
And it's like, cool.
Yeah, you're,
I'm never coming back to this country.
Yeah.
What's your monthly payment tolerance?
Yeah, I'll take it all, please.
Yeah, sure.
And like both sides think they're getting the other one in a kind of ruse.
Like, you're so screwed.
You have no idea.
Anyway, the rec case file, how we know about all this.
2023, December 7th, Amazon and a cohort of people versus just a 20 or something John does, basically.
There was like 27 name defendants, 20 Doe operators, 20 customers across six countries, the U.S. UK, Canada, Greece, Lithuania, and the Netherlands.
This is how we know who Domantas Radicus is, this Lithuanian national.
He was identified via an IP address tied to a fraudulent kind of refund.
There were vouchers that were posted on this rec telegram channel that were then triangulated through just like civil subpoenas that Google, Reddit, PayPal, all these different providers went after.
That's a lot of subpoenas.
It suggests a concerted prosecution at scale effort with different companies kind of coordinating.
Very interesting.
Self-reported volume as per those complaints.
This is Rex copy, basically.
If you go to the channel and you look at the, what is this?
It was that they quote fraudulently refunded over 100,000 orders from retailers.
And then in brackets, not just Amazon.
They're fighting that fight.
But mostly Amazon.
A lot of it, but not all of it.
Well, I just like that.
Like we're so much more than Amazon refund fraud.
Like, do you want to mess up Costco?
And some people said yes.
As an aside, don't defraud Costco.
I like Costco.
Costco is great.
Costco's the best.
They got samples.
They treat their workers right.
And where else can you buy a flat of Frank's red hot sauce?
Like, what a sick place.
In two liter bottles.
Exactly.
He need 24 liters of Frank's red hot.
The other day.
Jordan loves hot sauce.
I really like hot sauce.
I'm trying to get the sodium down, but Franks is still the go-to.
The other day, I opened my fridge and the little, like, shelf thing that holds all the sauces in had broken.
So my sauce is exploded.
Too much hot sauce?
literally a two-liter of Franks hot sauce from Costco exploded all over the floor.
And the like third thought I had after a bunch of cursing inside my head was, I guess I have to go back to Costco.
Now I only have 11 more bottles.
I'm like a prepper, but instead of culligan jugs of water, it's just Franks hot sauce.
I will rule the wasteland, Scott.
Let's talk about the playbook here.
So like how did this actually work?
We've nodded to it a little bit.
First thing is like basic social engineering of the retailer, which social engineering is like, it's such a fun term because it is both so its own thing and also just a synonym for lying on the phone.
Like the basic version of this here is you call customer service, you lie about the package and get the refund.
This was a thing that rec would do kind of on the customer's behalf from one of those Amazon filings.
Quote, rec uses sophisticated methods to obtain the refund including social engineering Amazon customer service.
where it gets interesting is the next part of that sentence, which is fishing Amazon employees.
So sample case from the complaint, the name defended Andrew Ling orders five iPads through Amazon.
He's working with Rec.
And then rather than bribing anyone, rec fished the credentials of a fulfillment center employee.
Use those fished credentials to log into Amazon's internal system remotely, marked those iPads, like found his specific
purchase marked them as returned. So no lying occurring here. Didn't have to ship them back.
Nothing. Didn't have to ship them back. Just flagged a refund in the system. And to your early,
that's a crazy amount of work. Like you have Amazon fulfillment center, but you sort of realize
how low in the hierarchy those credentials are because it's like, well, what can we do? It's like,
we can say that you return some iPads. Yeah, we can say that something showed up. That's one thing
that we have access to do. I just want to back you up. Let's start at the very beginning. So say I'm,
I'm a wreck curious person.
I want to dabble my toes and some light refund fraud.
Yeah.
What's the process?
Do I just reach out to them and say,
hey,
I'm looking to buy a new MacBook Pro.
I would like to not pay $6,000 for it.
It'd be really great if I just gave you $1,000.
And then I got it for free.
I think that the numbers would come for them,
but you basically have it.
You would,
this was in the past when these channels were,
alive and we are not recommending you do this. I am explaining how this work. Yeah, yeah.
You would, the user, Andrew Ling and this hypothetical, hypothetically, would go to the telegram
channel where you can, there's a, it's a telegram channel, there's a bunch of subthreads. And one of them
would be to hire the people where you would then be connected directly with a person. You wouldn't
get to cite the numbers theoretically. It would be pre-prescript. They'd say, if you're willing to do
the financial transaction through crypto, it's 25% cut that we keep of the original.
sticker price, that's what you pay us.
If you're doing it over PayPal, it's 30.
They would set you the price.
And basically how much you want to go in for is up to you in terms of how much
you try and return.
I would imagine there's some coordination on the item in terms of how they would do it.
But I think at that point, you're handed off to an individual person in the channel.
Okay.
So I've got my estimate.
I accept my estimate.
Okay.
Now I go order the MacBook Pro.
I pay for it.
Put it on my visa card.
Do a legit transaction for it.
And then I essentially hand them the keys and they are the ones that now go into the refund cycle.
That is my understanding of it.
Now, the mechanism by which you hand the keys to borrow your language, I do not understand that.
I'm not sure if you give over the Amazon account, which would be wild because you're giving it over to the people that fished the Amazon person.
It's like, look at who you're getting to bed with here.
But you have the basic structure of it, right?
Okay.
Just just for my own sake and the list.
question. It's a great question. So let's say you've gone through all that. And now you're
trying to wonder, what are they doing on the back end? That's what we're going through here.
So lying, flat out, just like, I need a refund. Fishing and hacking into Amazon. Fishing
Amazon employees. If you can't hack them, join them. As the old saying goes, bribe.
Brilliant. This is where warehouse workers come in. Amazon sued seven former Amazon operations
employees by name, allegedly took bribes between like about a course of a year in 2022,
2020, 23, just being like, we're going to bribe you and you are going to approve refunds.
Quote, each worked in Amazon's operations organization, which is responsible for handling
product returns.
Together, the seven Amazon insider defendants provided over $500,000 worth of fraudulent returns
to rec and its users.
On average, I tried to like napkin math this.
The per return insider take looks.
like it's between $50 and $90.
So each time you approve one of these things, you make about that much money.
The money gets a little murky, but that was kind of the number that stood out to me.
I'm just trying to work that out.
It really feels like something I see on the Sopranos.
Sure.
Like it doesn't feel like cybercrime.
This feels like old school organized crime.
It's very, I was watching casino over my very lazy weekend.
And it has casino energy of just like, we came up with a scheme.
It's like this is not tech leading the horse.
It's like, yeah, this is like we paid off the truck driver literally to know he's about
to get jacked.
We robbed the truck and now we have DVD players.
Exactly.
It's like episode two or something.
This field, this has that energy where it's like, hey, you know, I'm going to give you
a hundred bucks every time you press go on an order number that I give you.
And you're not going to ask any questions.
and sorry about being criminally charged in the future.
It has the fraud as a service decentralized structure that we love here at Hacked
where it's like it's fundamentally a telegram channel where we operate this massive
grift at scale.
And I find that super interesting.
But the grift itself is like who do we pay off to make sure this thing falls off the
truck and nobody's wise to it?
Very old school organized crime energy.
Do you remember old school?
Oh, I was going to just jump back.
Remember old school Amazon?
Like OG Prime.
Like I can't even remember the year it would have been.
But I remember buying things off Amazon and they would ship you the wrong expensive thing.
And then you would hit refund and they'd be like, yeah, don't like, we'll send you what you ordered, but just keep it.
And I was like, this is crazy model.
Yeah.
It didn't live long that model.
I went into the, I want to get back to the bribery of it.
But I was at the mail place just down the.
road the other day. And I go in there and I was returning something. And it was from a large online
retailer. And I kind of just handed over and they like scan and you're like, hey, you're all done.
And I was like, oh, that's, that was really easy. Like, and the person said, and I appreciated this is
from the mail place said to me. And I quote, yeah, maybe a little too easy. And I was like, oh,
dang, right. Because you're the front line of this of just the like the horrible back end of the e-commerce
return economy of just people being like about another 11-5 things and I'm returning all of them
them and now you had to ship them to me and now you have to ship them back. It's like right, you just
watch that all day. It's probably a little icky after a while. You stand here and just robots
scan people returning things. Yeah, it's like buyer's remorse. Like my wife's famous for it.
She'll go to the mall buy something and then the next day she'll return it. And it's not that she
doesn't want it. It's just that she like gets remorse and then the remorse takes over and she returns it.
And she doesn't thankfully do it with online shopping because that would be. There you go.
It's a lot of shipping. It's a lot of shipping. A lot of carbon for nothing. That's kind of the way I think of it.
But if you're trying to do it as fraud at scale, boy, let me tell you, bribing the Amazon employees is just the tip of the iceberg because you can also bribe male people documented in a parallel case. So there's, we're
talking about rec and it's sort of like child organization divo which will come up in a minute.
This was a different one, simple refunds.
But from a case against them, the guy behind all of it, Almarij, quote, recruited insiders
at UPS and the U.S. Postal Service who would input false scans into the order tracking history
to make it appear as though items had been lost in shipping stolen from the mail or returned
to the company.
So you bribe a mail person to say, hey, we lost.
this box that felt like it had about, I don't know, 11 MacBooks in it, we don't know what
happened to it.
And meanwhile, it was delivered and the person keeps the laptops, recats their 30% cut.
You get the idea.
But while you're bribing them, what if you could manipulate?
Let's dive right into it.
I'm trying to present them as this nice menu of options.
It's like, I'm just going to outline how they do this.
Alicard fraud.
Amazon ran a controlled buy through outside counsel during one of these kind of like busts over the last couple years.
And this is just, I'm just quoting you from these complaints I have in front of me here.
Quote, UPS tracking data showed indications of manipulation.
The Roswell, Georgia, sorry, the UPS data indicated that the package was being returned to sender because a customer in Roswell, Georgia had refused delivery of the package, even though the package was never in Georgia.
And the investigator never refused delivery.
after Amazon had issued a refund for the purported, undelivered package,
the investigator received the package at the intended address,
and UPS shipping data was updated to reflect the delivery.
So basically, somewhere has all that.
Someone with access to UPS's system was editing tracking records in the middle of the shipment,
a variation on the proceeding thing.
A lot of work.
A lot of work.
You could put rocks in a box.
That's also an option.
Like stealing $5 million on the Internet these days seems like,
like it could be done with one of these things, not with an orchestration of all of these things.
It's a lot of work. It's much more normal business economics. If you think of the number of people
they had to hire in the business in order to, the next one is rec requests refunds for products,
and then they ship back a box with something else. The best documented one I found, this was the
simply refunds case was someone getting a refund for, quote, bulky tools for returning an envelope
filled with plastic toy frogs.
Cute.
Cute.
They had people forging false police reports saying stuff had been stolen.
That one was crazy.
From their deck.
But you need to show the police report.
So why don't we forge a police report?
And then the last one was custom malware.
One of the other ones called Noir.
They developed malware.
There were target retailers' websites to facilitate a refund by just sort of trying to go around the fraud prevention.
That was the vaguest one.
So I don't know what that means.
We've seen these documents refer to custom malware as like someone ran a script.
So we don't really know what it means.
But getting into the weeds a little bit at that point.
So there's a lot of ways you can do this, Scott.
Just jumps off the page of me is that this time could have been spent.
If you're going to be a criminal, like be a criminal, you know?
Yeah.
Like the, I feel like one malware for higher crypto locker thing, you get the right target.
You make $5 million.
bucks and it's like one one target one headache one piece of software you know one month this seems
like a business that had lots of illegal stuff going on and lots of human problems you know
bribing and coercing and manipulating and social engineering and developing malware and deploying malware
and fishing people and all for something that if you just fished the right person you'd have the
five million bucks entirely i think i know that's probably not
the perspective on this I should take, but it's the perspective on this that I'm taking.
My read on it, I think, is kind of similar to that, which is that this was not, this was like an
opportunity type thing that scaled.
Not a how do we make money thing.
And then you did it once and you were like, oh, we could do this again.
Literally.
Someone on the squad returned something.
Or to be honest with you, given how many of these are, someone sees the scam being done by
someone else. I don't know who the first one is. We've got noir. We've got
REC. We've got Devo. We've got simply refunds. I don't know who did it first. But if
a thousand people see that ad and a hundred of them choose to take up the service,
one of them might think to themselves, I'm just going to run my own version of that service.
I think that's the numbers that lead to these things blossoming the way that they have.
So Radicus is running wreck. Amazon sues in December 2020.
and the main channel goes quiet.
And if you're thinking to yourself,
it's because Radicus has decided to sort of like lay low.
It's not.
I think you just decided that the specific telegram channel
was no longer safe to use.
And immediately two new telegram channels appear.
Devo refunds and Devo vouches.
It's the same business,
exact same pricing,
exact same operator and marketing copy.
The opening post claimed that rec had been retired.
But by the time that,
Amazon caught up with the new one, Devo, it's like, it had 58,000 subscribers, almost double the
original.
Crazy.
Amazon embarks on another controlled buy, like their internal investigators, something I learned.
They have a crazy whole, they have their own internal investigation team.
This doesn't surprise me.
No, who like works with their fancy lawyers and stuff.
They order an Apple watch their Devo.
Devo tells them, you know, create a new email, just wait.
They get the delivery.
to get the email from Amazon customer service shows up in the inbox asking for a police report
and Devo immediately supplies the forged police report saying the item was stolen, kind of proving what's going on here.
And they filed this a medical complaint naming Radicus.
And within roughly an hour of the filing hitting the docket, both those Devo channels are immediately wiped and taken down.
Which shows I found this fascinating that someone on the inside at Devo was monitoring federal court filings in real time.
because that was the only place the name showed up in that little window.
Radicus keeps operating for another six months,
and then Lithuanian police arrest him on December 3rd, 2024.
He is so far the only person in this whole universe to face physical custody anywhere.
There's like 26 other named defendants, seven Amazon warehouse people,
but those are all or were already resolved civilly.
Radicus is the face of this whole thing.
So that all of the people that took bribes and stuff,
they just had civil charges?
Like they were sued essentially by Amazon?
So far, that's what I can tell.
Okay.
Okay.
We're getting into the edge of what I know about this, but that's my sense of it.
Eradicus is the only dude who's really like, criminal.
It was kind of where the research started was like, hey, someone's been charged with this and that's weird.
Yeah.
So the macro numbers, as per this, so Amazon hire, I think they hired Deloitte.
I don't know if it was Amazon or maybe Walmart.
Deloitte gets hired, big consulting firm.
They do a 2024 report.
And he said that out of six.
$685 billion in total U.S. returns, roughly 15.14% are estimated to be fraudulent,
which puts you at about $100 billion lost.
Okay, wait, back that up.
Say that number again, $685 billion in returns?
Not for this specific operation, but in the U.S. returns world, that number is 685.
If 15% of it is fake, you're looking at about $103 billion, which is up a little from the previous year.
By little, I mean $2 billion.
The scale of returns is the thing that shot off the page of me there.
$685 billion it returns.
Better part of a trilly.
That's a lot of iPads.
That's a shit ton of iPads.
I'm thinking of the person at the mailbox being like some might say too easy.
Yeah, it's a big number.
Yeah.
And the 15% fraudulent, like obviously they're pursuing this, but it's kind of a revealing of margins.
Because you wouldn't, they're not doing this out of the kindness of their hearts.
They're doing this because the frictionless return process leads to people making purchases they might think harder about.
The math must be mathing at this scale.
You obviously want to get 15% down, but it tells you a lot about what the margins on these businesses are.
And it's really fascinating.
Well, in traditional retail, you know, they had shrinkage, which is like stuff that's staff steal,
staff steal probably more than people that come in off the street.
And I think the rates back in the day were like 1 to 2%.
So to go to 15.
I didn't know that.
So if you've got 680 billion in returns,
and only 15% of that is fraud.
Mapping that all the way back to gross revenue is probably somewhere in the same range.
It's just modern retail theft is refund fraud.
It's refund fraud.
I think that that 15%
number. This is a report by a group of people that have been hired on by a company to show what a
big problem fraud is. I think you always need to take these consultant kind of numbers with some
sort of a grain of salt. I'm not even shit talking. Like just you simply have to. So yeah,
if that number was going to be high or low, I would think the incentives would push it to be
high. But if it was even 10%, if it was 8% or 7 or 6, that's still a huge multiple more than
in-person retail like fraud. So it's kind of interesting.
Yeah.
Yeah.
$685 billion in returns.
It's pretty crazy.
That number's just stuck in my head.
I know.
It's, I thought this was an interesting one to start with.
Everyone here has probably returned something online.
And we always hear stories about how these systems often don't even want the item back or that it's an automated system that's easy to trick.
We've all heard about this.
And it leads to this question that is sort of answered in these documents, how we,
would you build that vulnerability in this hundreds of billions large system into something
that delivers fraud at scale?
Yeah.
We didn't know much about it until these documents.
They're a couple years old now, but I'd never seen them.
And I found it really interesting.
Totally.
Yeah.
Yeah.
Fascinating contemporary organized crime.
Totally.
Yeah.
Fraud as a service.
Marketing on telegram.
Yeah.
Curious to see where I go next.
We cover a lot of big geopolitical stories, and I liked this as like, this is something that
people are doing.
Their customers are average folks, and that's not something you see often.
Well, that makes me just wonder, like, you know, just to look into the same space.
Like, we all know the, like, porch pirates, like, people that come and steal your packages
off your porch.
Like, that's a massive industry of theft.
Like, that is, I guess, what you consider current retail theft or, like the contemporary
version of retail theft is just following the Amazon.
truck and just stealing everything off everybody's the petty version yeah that's the non-organized
petty version is like I'm just going to pick that thing up it looks heavy and valuable very untargeted
just go and box to box load them in your car and drive away the yeah it's funny the delivery
economy we haven't quite figured out how to deal with it yet yeah and I feel like there's been such a
I've seen all these things of people being like what if it was a locker with a combo
patent. What that's fundamentally misunderstanding is that this system is building margin in for
convenience knowing it will come at the expense of money. Like it will come at the expense of loss
and fraud and refunding and all that stuff. But it's like they know that by making it more
convenient, they will lead to more of that kind of loss. It is a strategic choice is the thing I always
come back to. Yeah, cost to do in business. Because shrinkage is like retail always. You always factored
for shrinkage and your cost estimates and financial projections.
This would be the same.
If you could eliminate, it's like insurance.
Insurance fraud leads to higher insurance costs.
And it's like retail theft and retail fraud leads to higher retail costs.
And it's like it's a self, self-fulfilling loop.
Exactly.
And the thing that's interesting about this is like a bunch of those.
I'm not going to say which ones because it starts to turn into advertising,
but it's like not all of them are gone.
like not even all the ones that are named in some of these indictments are gone it's like they persist and it's a pretty
where they can be advertised i mean we've talked about what certain social media platforms will and
won't let you advertise and when exactly it becomes fraud before it's not impossible to advertise
something like this on a legitimate mainstream platform and it starts to take on a color that's a
lot more like a drop shipping business than like a selling ransomware on the dark web even though it is part
of a hundred billion dollar fraud ecosystem.
Sure.
Yeah.
Well, like meta's scam advertising that we talked about.
Exactly.
Yeah.
Shocking.
Exactly.
It's like when we talk about something like that and we say, well, what kind of
frauds are we talking about?
It's this.
It's this kind of thing.
It's a weird telegram channel where someone lets you run a scam.
And sometimes the buyer is the victim and sometimes they're not.
And in this case, it's kind of one of the rare instances of one of those things where the person
that's found their way to the telegram channel isn't the mark.
They're not about to be talked into paying for something.
They're not about to be tricked into paying for a course.
Some financial.
Yeah, yeah, yeah, yeah, yeah.
It's one of the rare ones where it's like, no, no, you come in.
We're going to go screw them over.
It's a really different relationship.
Structure.
Yeah.
It's like, hey, want to do some light crime?
Totally.
Yeah, yeah, yeah.
Exactly.
You don't want to pay full price for that new laptop?
Yeah.
Yeah.
We'll figure it out.
It's a bunch of little storefronts and you will get scammed if you go into all of them.
But there's actually that one storefront that if you go in there, you become one of the scammers.
There's definitely like they're offsetting the liability for this to the people.
It's why some of the customers were named in these indictments.
It's like, I'm sure people being thrown under the bus left, right and center.
But it is a fundamentally different relationship.
Yeah.
I wonder if that's like the plea deal that they're going to cut.
It's like I actually have all of the
Totally.
I have the directory of everybody that's robbed from you.
We just helped them rob you.
Here's the list of everybody that actually robbed you.
But Amazon has that list too.
I'm just thinking about this for the first time in real time.
But they don't know it for sure.
No, no.
They don't know it for sure.
That's the difference.
So it's kind of like you can confirm
this person who never bought anything more than $100 before
and it only made three purchases suddenly bought
$10,000 worth of, you know, gaming consoles or whatever.
GPUs.
We're suspicious of this.
Exactly.
They bought one GPU.
This must be fraud.
There's no way.
That's the real price.
Anyway, very interesting story.
Yeah, cool story.
Yeah, it's a neat one.
Why do we kick it over to the ad water slide?
And then we can just chatty chat on the back end since summer chatty chat.
Starting some new isn't just hard.
It can be downright terrifying.
You put a lot of work into a thing.
You're not entirely sure it's going to work out.
You're taking a huge leap of faith.
I've started a few things.
Now I know I was right for believing in, you know, the idea of the product,
despite all of those fears and hesitations.
But boy, does it sure help when you have a partner like Shopify on your side?
Shopify is the commerce platform behind millions of businesses around the world
and 10% of all e-commerce in the U.S.
From household names like, well, hacked podcasts merch to brands just getting started,
you can get started with your own design studio with hundreds of ready-to-use templates.
Shopify helps you build a beautiful online store that matches your brand style.
Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world?
I don't know why I wouldn't.
I should.
It's why Shopify has the best converting checkout on the planet.
It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot,
and more sales for you.
It's time to turn those what ifs into sign up for your $1 per month trial at Shopify.com
slash hacked.
Go to shopify.com slash hacked.
One more time, that's Shopify.
com slash hacked.
Think about the last time you heard a breach story on this show.
It always starts the same way.
Someone somewhere saw something too late.
An alert buried, a signal missed, an SOC that just couldn't keep up.
Arctic Wolf set up to solve that.
problem by rebuilding security operations from the ground up for a world where attackers are already
using AI. They created the Aurora Super Intelligence platform, a fully agentic system powered by the swarm of
experts. Instead of single-purpose bots or lucky guess LLMs, this swarm is full of deterministic agents
that handle whole entire workflows. Humans stay in the loop and on the loop to validate the critical
decisions and keep everything trustworthy. And all of this is just off running on their secure operations
graph. A constantly updating intelligence engine fueled by more than nine trillion telemetry events
every week and over a decade of real-world incident response. The system reasons on real signals and
real context not synthetic training data. And the result is the new Aurora Agent SOC. It's the first
SOC that is agent led by design. You get agents that coordinate, agents that investigate, agents that respond
at machine speed, and hundreds more that automate the repetitive work that normally
buries human analysts. Arctic Wolf didn't try and bolt AI onto an old model. They rebuilt the
model entirely. What makes it even more effective is how it works with Arctic Wolf's concierge experience.
The team brings customer-specific context directly into the platform so every AI-driven decision
reflects your environment instead of generic assumptions. The automation frees your concierge security
team to focus on higher value strategy and proactive risk reductions while the agents handle the grind.
If you want to see what trustworthy, production-ready AI and security operations actually looks like, go to arcticwolf.com slash hacked.
Every company says AI will make employees more productive, but most employees are still stuck waiting on IT, waiting for app access, waiting for password resets, waiting for someone to fix laptop issues so they can get back to work.
That operational drag, it adds up fast, and IT teams are overwhelmed trying to keep up.
Serval was built to automate that work.
You describe what you want automated in plain English, and Serval builds it for you.
No complicated workflow builders, no consultants, just faster support, and fewer tickets slowing everyone down.
Serval enables IT teams to build automations using plain English instead of drag-and-drop workflow builders.
Platform is designed to eliminate repetitive tickets so IT can focus on strategic work instead of constant firefighting.
Unlike traditional automation tools, Serval doesn't require consultants or long implementation cycles.
Serval positions IT is the AI-powered operational backbone of the company, not just a support function.
The company guarantees customers can automate 50% of IT tickets and backs it up with a free four-week pilot.
Learn more or start a free four-week pilot at Serval.com slash hacked.
That's S-E-R-V-A-L-com slash hacked.
Serval.com
slash hacked.
And we're back.
We're back.
From the water slide.
We're drinking some water.
We're drinking water.
I didn't have a summary chat about summary things.
I had one to start us.
I don't know if you got anything you want to dive into, but I had a follow up.
You go first.
I got something that I want to chat.
I got a few things I want to chat about, but you go first.
I'm looking forward to it.
We haven't listened to you for the last 35 minutes.
So why don't you just keep going?
Well, no.
In that case, I want you to take it away.
The mythos.
Anthropics mythos.
Yes.
Claude mythos.
We've talked about.
Yes.
The security model that they were like is too powerful to go to the public.
We talked about it.
I just wanted to have a follow up brief chat about just how,
many security patches I'm seeing in software that I use. I'm getting every single thing from like our
enterprise data servers to, you know, every app on my computer and my phone. I'm getting security
patches for in waves. And I have no reason to believe that it is mythos, but I have no reason
to believe that it's not. Because if volume is like, I go into my
command line and like I'm an OSX user and I run like brew update and every single brew package has
security updates and it's the volume of things that I'm seeing in the in the patching and security
hardening and all of the software that I touch is I don't know I can't help but think that this
has something to do with these like new hyper secure models looking to secure software sure
Just because the volume of it is unlike anything I've ever seen.
Now, from what I understand, for anyone that is unfamiliar,
if you didn't listen to this episode a little while ago,
go back and let's do it.
Go back and let's do it.
It's a genuinely really relevant and fascinating story,
but it was Anthropic A.M.
Manufacture does this big press event where they announce mythos.
It's their new security model,
a new model that has a lot of relevancy for security.
And they kind of put out this video showing all of these vulnerabilities they found.
and kind of in this almost Manhattan project-esque framing say we're bringing in this select
group of partners big technology companies to get this thing into their hands so they can patch stuff
before this gets at public and other potentially bad actors are using it trying this sort of
AI security moment it is still not public sorry I was interrupting you it's called project
glass wing that Anthropic essentially said I think it was like a hundred million dollars in
usage of it, they just gave out to organizations to try and secure infrastructure software,
common apps, things like that across multiple platforms. And I will say that in the last two weeks,
I feel like every single piece of software I've got has had a critical security update all from
my iPhone down. So this is my question is if a bunch of software just got a bunch of security updates,
but only some software got glasswing access.
I do think that this is, you could, the sentence mythos caused people to lock down these bugs
is an accurate sentence, but not necessarily because they had access to it, but because
this shock and awe campaign caused everyone to go, ah, and review all their stuff and probably
have normal Claude analyzing stuff for bugs and doing bug hunting and stuff.
But it was almost the thing we talked about in that episode.
which was this project glass swing was a remarkable marketing push for anthropics role in security,
which is what you're seeing the downstream effect of.
Correct.
Also, the fact that OpenAI came out with Codex 55 and said that it had a lot of the same functionality that Methos did.
Open AI went an interesting direction.
I actually tried to use it on some of the software that I've written and some open source projects that I was looking at evaluating.
I would just hand like I would download and clone a GitHub and just hand it off to Codex.
and be like, review this for security things.
Let me know if it's safe to use.
Instantly you get kicked to and know your customer login
where they want me to upload my ID, take a photo of myself,
do all these things.
Yeah, to verify who I am.
Because to get security access in their models,
you have to go through a KYC thing.
Which is kind of brilliant.
It makes absolute sense.
I'm glad to hear this,
but I want to make sure I understand.
You were trying to get Codex to review open source projects
that you are not the author.
of. Well, yeah, correct. But I had downloaded them and was considering installing them. So I was
like, do a review of this and let me know if there's anything. Given the amount of supply chain
attacks going on and opens those software right now, I was just like review this and tell me if
there's anything that I need to be worried about. And it immediately kicks me to a K-Y-Sk.
Yes. Trying to get us to find a bug. Can you show us some ID? Interesting. Yeah. Whoa.
So they've, they've, they've, open AI has definitely begun rolling.
out the same kind of functionality, but they're putting it behind a locking key that you have to
have to essentially prove who you are to get access for it and have it enabled on your account,
which is fine.
I would bet that that becomes industry standard.
I would bet that when myth those comes out, it's just like there's like know your customer
stuff in place for that.
Totally.
If you can have to do know your customer for making a polymarket bet, you probably should
have to do it for the hacker robot.
He seems comparable.
Here is the infrastructure software being run by this company.
Tell me how to break into it.
Yeah.
With the like, no, I work for them.
I'm allowed to be doing that.
And be like, yeah, no, we've been down this road before.
Yeah.
Interesting.
Yeah.
Yeah.
I thought you'd like that.
That's seem, I wouldn't have guessed.
Because it is as of right now the only functionality inside these models that would ever prompt that kind of thing.
Like it's normally if you, if you can type, the thing will reply.
That's sort of how it works.
So it is a little bit of a sea change to be like, no, this specific layer of functionality,
we need to know who you are.
Yeah.
And there's cybersecurity researchers that are coming out being like these models are
better than as good as we are and way faster.
Like they can parse through massive amounts of source code like in a blink of an eye,
look for common problems, look for complex problems.
they're at the point now where they're writing math proofs.
We've come another gen up in the model quality.
And the thing that really triggered this story for me and the reason I just wanted to bring it up is I'm sure everybody is getting flooded with security updates for every piece of software they use.
And I can't help but feel like they're connected because the volume of it is massive.
the amount, even like major companies, like Apple had one, Windows had a zero-click RCE.
Like, it's finding tons of stuff.
The CVEs coming out like crazy.
But they're all posting the CVEs in like after they fix it.
So Apple will identify bugs.
They'll fix them all, patch them, push out the updates, critical updates, and then file
the CVEs.
So you can literally sit and watch on the CVE database, all the different things that are
getting like identified and fixed.
Scott's on CVE watch CVE watch with Scott
it's our new segment
this is a summer episode I'm going to barely edit
so we will not have music but you bank on it in the future
listeners CVEE watch
yeah if we start filming
these I'm imagining like a little
watchtower intro animation where you're like you're up there
with the little spotlight I have Sauronting CVEs as they come in
it'll be great
I have a I have one it's a call back 35 minutes was not enough the people need to hear from me
yes they do everybody loves your voice certain don't be bashful so for years we've talked about
the store before this is a follow-up there's the idea that your phone is listening to the
conversations you're having to serve you ads this old kind of suspicion uh conspiracy theory
valid explanation up to you to decide you if you listen to the show you know where we fall on
that. In 2024, the reason we talked about this on this show is more than just the sort of conspiracy
theory was a company called Cox Media Group, COX.
Four or four million.
Big American internet company.
Yeah.
They were marketing a product called, quote, active listening that claimed to do the thing that
the conspiracy theory said, we think they're doing.
Like they took that conspiracy theory and torment nexus it into a product, allegedly.
And I find the fallout of this really fun.
Their pitch to advertisers was like their technology could tap into the audio from smartphones,
smart TVs, smart speakers, and then use AI to target ads based on what consumers said and where
they lived.
An obvious privacy nightmare.
A crazy thing to write on a website in my personal opinion.
The company claimed consumers had already consented to this in data collection form.
So it was all cool and good and normal.
Yeah, sure.
In the terms of service, the bottom, it says, hey, we're going to listen to everything.
everything you say. Exactly.
The marketing on the website,
I'm going to read it to you.
Creepy question mark? Sure.
Great for marketing, question mark.
Definitely. Do with that what you will.
The story confirmed this conspiracy theory
that your phone is listening to you for marketing
and that was sort of where we talked about it.
The update and why I want to talk about this here.
Cox Media Group, MindSift LLC,
and 1010 Digital Works are collectively going to pay
$930,000 to settle FTC allegations.
FTC's finding, not that this would be immoral, illegal, a privacy violation.
None of that stuff.
I love this.
The finding was concerned with the fact that the surveillance technology did not exist.
Active listening.
Oh, they lied.
They lied, allegedly, about the bad idea.
You see why I find this so fun.
It's not that you did.
the evil thing. It's that you pretended you could do the evil thing.
They're getting punished for like false advertising. That's hilarious.
It's people being like, we invented mustard gas and we're going to release it everywhere.
And then you're getting sued for false advertising about the mustard gas.
Yeah. You actually didn't invest it. Exactly. Exactly.
Yep. Active listing was repackaged consumer email lists, sold at a significant markup to businesses.
The company, like the claim that consumers had consented to voice data collection was just like, I don't know, FTC sure dug into it and thought it was worth suing over the accuracy of that statement too.
The settlement money is going to go to the businesses that purchased active listening believing it worked is the only part about this that pisses me off.
I do not think that the people that bought this thinking it was a cool, normal, good idea should get that money.
But your mileage may vary.
FTC did not explicitly rule on whether using phone audio to target ads would be illegal.
The violation was lying to customers about doing it, not actually doing it.
That's so funny.
Yeah.
Well, that it's kind of like the optimal outcome, you know?
Like it keeps the conspiracy alive.
Sure.
We get to keep talking about it.
It's like, well, are they actually doing it?
They weren't found as like, it's like, well, we don't know for sure.
Like we did know for sure and now we don't know for sure because they actually got arrested
for lying.
Yeah.
But so hope you got it.
If you advertise surveillance apparatus technology software or whatever you want to call
this, you better deliver is kind of a weird takeaway from it.
But I'm just, I'm glad to see this get shut down.
I was glad to see it get shut down with everyone going, that's evil and horrible.
I'm embarrassed for the people that bought this product.
And I'm glad to see the people that offered this product getting dinged financially.
Oh, man.
There was, I was at a, as like a slight knock on to this, a similar, similar conversation is I was at a family function yesterday afternoon with my in-laws.
And one of the person that I went with was like opened up Facebook afterwards.
I can't remember the last time I was on Facebook, but they opened it up.
And of course, the first thing is like suggested friends, somebody else that was at the function.
And he's like, how do they do this?
And I was like, well, it's either one of two things realistically.
It's either they have your location services and people that you spend time around.
They align those two accounts or it's like Bluetooth handshakes between your devices.
And they have the ability to read that, know that that device ID reconciles with this account.
And then they auto create these things.
And same kind of like weird, creepy but effective things is like, hey, you probably know this person.
You would just spent three and a half hours within five feet of them.
Exactly.
It's like, yes, yes, I did.
Oh, yeah.
Their entire business model is pegged on being able to kind of roughly know where you are.
In both parts of that sentence, you and where are the operative things.
It's like, who are you demographically?
And where are you?
Everything else they can figure out from that.
They don't need to turn a microphone on.
No.
You can get everywhere.
I was in Beijing traveling with a buddy who had to re-sign up for Facebook to do this.
He needed Facebook to get into a different thing.
So we re-signed up for Facebook.
And it immediately was like, you probably.
know Jordan. And it was because we were sitting in the same hotel bar in a hotel
aviation. We were five feet from each other. We were five feet from each other. And it had no
insight. He was using a fake email. Like you just needed a Facebook account. And it was, I was like,
yep, because they know the who and they know the where. And that's, you can build an empire on that.
Super interesting. Yeah. The, uh, the other thing I wanted to chat about. Please.
Please. Please. Please.
is password managers.
Oh.
I hear a goblin in the background.
I'm not going to edit this out.
We all get to find out together how many times my cat's going to meow over the next 20 minutes or so.
Password managers.
Dashlane, the password manager, not sure if you've heard of it, has been forced to disable a lot of their user accounts
because somebody is trying to brute force into them.
And as one of their security features,
if somebody's trying to brute force it to your account,
they just lock it,
which all of a sudden becomes a bit of a denial of service attack
because I don't know what my life would be like
if somebody took away my password manager.
Because I wouldn't be able to do very much,
seeing as I don't think I know any of the 3,964 passwords
that are stored in it.
And that is the last we will say of that
for operational security purposes.
True. True enough.
Whoa, that's interesting. A denial of service. Whoa.
So I don't know. There isn't enough details on it. It's kind of ongoing as we're making this episode.
Yeah. But I don't know if the intention is to be a denial of service or if somebody's just trying to do a brute force attack across all dash lanes.
Yeah.
But there's something going on in the background right now.
Wow.
Literally right now. Like they're tweeting about it like as we're recording.
That's interesting.
that would be bad.
That would be scary.
The password manager is, yeah, it's the modern keychain.
It's so important to be able to, like you said,
to be able to even just knock down.
There's so many things that I would go,
I'd rather you lock this down than give away access to it.
But the password manager is like, if you lock it down,
I lose access to everything else.
Like it's like the one domino that in the domino falling video,
where there's the one that triggers the sort of pyramid of all of them.
It's that one.
It's the first domino.
It would be really tough for me to show up for work on Monday morning and not have access to my password.
You are mostly a password manager at this point.
Yes.
At this point, I've migrated everything.
I am functionally just an AI with a password manager.
I'm the interconnect.
Interesting.
Yeah.
Okay.
Well, use password managers and lock them.
I don't know what to say about that one.
had.
Just an interesting thing that's actively going on in the background.
That is fascinating.
I had a, I mean, we're truly in the summer chatty chat vibes here.
The stories are falling fast is how you know.
Episode or two ago we talked, you and I talked about Boyd's.
I don't remember this.
For anyone that missed that one, it was the premise.
It was just an old, interesting research thing of someone had basically worked out how
birds flocked and flew together without smashing into each other.
They build this model tracking birdoid objects that has been used in virtual effects,
video games, tons of stuff since, basically tracking how does a murmuration of birds
fly through the sky without colliding, the rule set that emerges in a natural phenomenon
that can be rendered as an algorithm.
I just find that really cool and interesting.
So we talked about it on the show, birdoid objects, and a friend to the show, who I didn't
get his permission to mention this, so we'll just call him B.
B sends over an article after the episode goes live because he listens to the show.
And it concerned a set of MIT mathematicians who applied the same sort of process to human beings.
And I found this a really fun follow-up.
It appeared in the proceedings of National Academy of Scientists.
It was MIT instructor Carol Bassett.
And she was studying how the like movement and flow of a human crowd could be used to create a prediction algorithm for when pedestrian paths will shift from
ordered nice movement to entangled in people bashing into each other.
And it reminded, I think, them and me when I went through it, so much of the bird algorithm.
There's an element called angular spread, the parameter that describes when people start going in
different directions to get away from each other, and then they'll angular spread back to converge off
of other people.
And the sort of emergent, smooth flow of movement of human beings, say, through a massive
crosswalk or a train station, is similar in that it is.
naturally emergent but documentable same as birds flying through the sky. And isn't that cool
and interesting? It is cool and interesting. I love it. Also, also the anomaly, the person that
isn't adhering to the algorithm is all of a sudden the asshole. Yes. Now the person that's like
smashing your way through the crowd, everybody's like, look at that jerk. It makes me relate to birds
so much better. I'm like, oh, now I know what it would be like to be flying with one birdoid object
that isn't doing its goddamn job.
Like, I've been there before.
Yeah.
I've been to Tokyo.
Yeah.
Even though the Japanese people are amazing at it, but the tourists are always the one that are like smashing.
I'm the one bashing into people.
It's an angular spread.
We're the problem in that situation.
We create problems.
It was an angular spread of around 13 degrees.
If you go more than 13 degrees off access of that typical spread, that's when you start
getting disorder.
And there's a cool diagram.
This is on MIT.
edu if you want to go see it.
If I remember, I'll include a link if you can find it online.
There's a great gif of the order versus disordered scenario tracking people.
And you've seen this before.
You've been a part of it.
Of people sort of seamlessly flowing through each other like the, you know, the tooth comb kind
of two going against each other versus just chaos.
Really interesting.
The only thing I've got left that I wanted to talk about was Bill C-22 in Canada.
I want to get into the great details of it because I think we should have like a lawyer on to talk about it.
But essentially the Canadian government is updating their Lawful Access Act, which is essentially a modernization of surveillance laws to handle the smartphone world we live in.
And what does that like necessitate?
Like that you have to, is this one of those you have to show ID to be able to go on things?
This is one of those get rid of VPN's things.
we're seeing a lot of those around the world.
Well, so the, it's not just, it's not either of those.
It's more, so like that it's made the news very heavily up here in Canada recently
because major tech giants are like going in front of our parliament being like,
you can't do this.
Like we're refusing to adhere to this law.
You're asking us to weaken encryption to the point that it's, you know, not really good for
anything.
I did read about this.
Yeah.
Yeah, so you're getting people like major VPN providers, Apple, Google, meta, all showing up being like, this is bad.
You should not be asking us to do this.
Signals threaten to pull out of Canada saying that they will refuse to adhere to it.
So it's not really like an anti-vPN law, and it's not like a know-your customer thing.
You know, it's metadata retention so that they can see what you've been up to on your phone for like up to a year afterwards.
It's kind of like it's surveillance-y.
without really judicial oversight.
Yeah.
It's interesting, I think everybody that if you're,
especially if you're Canadian,
you should go take a look at it because it will significantly change the authority and power
that the police have to dig into your life without judicial oversight.
Yeah.
It sounds like I did read a little bit about this.
And it sounds like what it would basically be doing in an attempt at getting CIS,
Canadian Security Intelligence Service,
the ability to obtain digital information during investigations.
It puts the onus on the technology providers to adapt their systems,
which is like, well, if they've promised to encrypt their data,
but you're making them promise to give you the data, if they have a subpoena,
that would necessitate, and we've seen this in other jurisdictions,
the existence of a backdoor around that encryption.
Yeah.
It would create a bunch of backdoors into otherwise secure systems.
They've put a safeguard in the act.
that says that the company won't be forced to introduce a systemic vulnerability, i.e. a backdoor.
But they don't really define what systemic vulnerability is.
And, you know, you could easily argue that reducing the quality of the encryption is in fact a systemic vulnerability.
So it's, I don't know.
Anyway, it's something that everybody should be aware of and read up on.
You know, we got a lot of this stuff going on globally access to.
information, loss of privacy, control of free speech, things like that.
And I think that this is another part of that campaign.
Yeah, I don't think that I'm going to choose to buy the thing that is encrypted and
is secure, not because I have any need for it, but it's sort of a matter of principle.
So I think you live in Canada.
So you may not be able to buy that anymore because they won't be able to sell it here
anymore because it won't adhere to this act.
So wouldn't choose this one.
bummer.
Yeah.
Way to bring down the summer sewed, Scott.
Sorry, man.
Let's pump it back up before we wrap it up.
It's good.
It's important.
That one matters.
Talking about birds and I'm talking about privacy.
Talking about birdoid, humanoid objects.
Talking about refund scams.
Do we have anything else that we should chat about?
I don't know.
What else should we talk about?
Go check out our YouTube channel.
We've been much more diligent about posting things.
back catalog is almost through.
We're hoping to get to live recordings of our faces at some point.
So you might actually see what we look like and how confused we look during the recording.
No, I was joking.
No, no.
That occurred to me.
I was like, I was watching my own face as we recorded.
And I thought, I'm regularly like, I'm giving away more on camera than I think I am on
microphone.
It's going to be really fascinating.
He was much more confused about that than I realized from the talking.
No, we're going to do that.
I think the thing that gets me, go for it.
I was going to say the thing that gets me is that I have so many monitors that I'm constantly tracking around.
Yeah.
Like I'm very rarely like engaged with my camera.
So that'll be interesting.
Especially I realize.
I'm right in the middle.
And I got my notes.
Something I realized I don't think we've done in four years is be like, hey, you should rate and subscribe positively this show.
Like we're so bad.
all of that basic stuff.
But like and subscribe at an hour into the episode.
I'll say that for the first time in years.
Like and subscribe to the YouTube channel.
Yeah, both.
Leave a comment that's positive and loving.
Yeah.
Say nice things because we read them.
Yeah.
Send nice emails.
I don't know.
We do read like especially on the Spotify comments.
We do read a lot of your comments.
And when I say a lot of them, I mean all of them.
So if you.
They come to the same place.
We see them.
And if you send something mean, you'll get screenshot and then talk badly about via Jordan and I in our group chat.
I fear you have just lit a roaring forest fire by saying that.
And I'm not editing this episode.
So come what may, brother.
There you go.
There's your summer vibes.
There's the summer vibes.
Talk some smack in the comments.
Talk some smack.
Good stuff.
Okay.
I think that's it for this one.
It's a light one.
It's a loose one.
It's been great hanging out with you.
And I think we'll probably for another light summer so, catch you in the next one.
Yeah.
Okay, take care everybody.
Cheers.
Spotify, it's Jay Shetty.
Are you one of those media strategy people?
Scrolling through spreadsheets, searching for an audience that pays twice as much attention
to your ads than they do on social?
Let me introduce you to fans.
And they're here with me on Spotify.
Trust me, I know fans.
They don't skip.
They stay for hours.
They don't move on.
They manifest.
They're not a demographic group.
They're fans.
Spotify advertising.
You're among fans.
