Chaos Lever examines emerging trends and new technology for the enterprise and beyond. Hosts Ned Bellavance and Chris Hayner examine the tech landscape through a skeptical lens based on over 40 combined years in the industry. Are we all doomed? Yes. Will the apocalypse be streamed on TikTok? Probably. Does Joni still love Chachi? Decidedly not.
[00:00:03.660] - Chris
Oh, that's true. I mean, that's efficient, you know, cuz most people destroy both of them slowly over time. What I'm hearing is you're going for one 100%. Mm-hmm.
[00:00:12.430] - Ned
So, and then I can track the slow degradation of the other one over time. So it's, it's like a control. The, the, the blown one is a control.
[00:00:23.040] - Chris
Or it's just, you'll slowly find more and more peace as the world around you becomes quieter and quieter, and eventually you can't hear it at all.
[00:00:30.810] - Ned
It would drown you out.
[00:00:34.020] - Chris
Hey.
[00:00:34.170] - Ned
Hello, alleged human, and welcome to the Chaos Lever Podcast. My name is Ned, and I'm definitely not a robot. I am a real human person with a stand-up paddleboard, a lake close by, and no fear that the water will fry my circuits. What circuits? With me is Chris, who's also here. Hi, Chris.
[00:00:54.170] - Chris
Yeah, it was pretty funny. I was at a a party, if you want to call it that. And, uh, one of the older people that was there was just sitting at the, on the couch, just kind of like bobbing his head in, in like that vacant, I'm here, but I'm not here way. And I was basically like, hey, you having a good time? Do you need anything? And he just pointed at the, uh, side of the couch and the two, his two hearing aids were just sitting on the couch.
[00:01:15.890] - Ned
He's like, I got all I need right here.
[00:01:20.700] - Chris
Yeah.
[00:01:22.430] - Ned
I'm sorry, I got distracted by the very excellent title of your first news article. Maybe we should get into some tech garbage.
[00:01:31.610] - Chris
AI is the worst thing ever, says the man who thought AI was a panacea 18 months ago. Oh, how the times have changed. Last week, Bill Gates, you may have heard of him. If not, go ask your grandparents. Last week, August 26th, 2016, to be precise, Bill Gates got up on his trusty steed and charged headlong towards the windmill known as AI. In a long post on his own personal website and in an hour-long interview with the New York Times and probably others, Bill Gates, or Sancho as his friends call him, uh, put out the warning that AI is super dangerous. Behind the scenes, everybody knows that it's super dangerous and nobody is doing anything about it. Here's a few choice quotes that lay out the argument rather succinctly and save you 6,000 words. In private, people who understand how good this stuff is and how much better it's getting, they're very worried. But few tech executives, Mr. Gates said, are willing to publicly admit that. Quote again, they're now saying to each other, hey man, don't say that. It's bad for us. The next trillion dollars we're going to raise. Now hold my beer and watch this.
[00:02:55.800] - Chris
That last part might've been editorializing.
[00:02:57.900] - Ned
Indeed.
[00:03:00.140] - Chris
Closing out the quote, quote, they're just full speed ahead and hoping that the good outweighs the bad, unquote. In what is probably unsurprising news, I agree with Sancho on this. All except that last bit. I think a better way of saying it would be, quote, they're just full speed ahead and they don't give a shit what happens as long as line go up. Sancho rightly points out that the giant threat posed by AI in terms of job losses, which is an interesting left turn considering back in March of last year he was talking about how AI was going to give us all 5-day weekends. That particular lie has been told over and over throughout history about innumerable technologies and automations. So it's simultaneously amusing that he repeated it last March and that he is now repudiating it. Some things he's proposing do make sense, like taxing AI or token use, which is something that Jensen Huang from NVIDIA also suggested.
[00:04:03.170] - Ned
Hmm.
[00:04:03.960] - Chris
Some are going to be a little tougher to see happening, like jobs being mandated as human reserved. To quote a great philosopher, uh, yeah, sure, Jen. That will definitely happen.
[00:04:20.540] - Ned
Legal news that brings me joy. Oh look, Trump is losing again. So is Kelsey. What a time to be alive. There's 2 legal stories I wanted to get into briefly, although they don't have much to do with each other except for one critical thing. The correct answer is so blindingly obvious that only a lawyer or politician could see it otherwise. The first case has to do with gambling website Kalshi. Oh, I'm sorry, not gambling. Prediction contract marketplace Kalshi. For those of you blissfully unaware, Kalshi is an app and site where you can predict an event will occur and create a contract to that effect. Others can buy in on that contract with a yes or no vote. If the event happens, the yes people get money. If the event doesn't happen, the no people get money, and Kalshi gets a small transaction fee. This is somehow not betting according to Kalshi. which means it cannot be regulated by the gaming commissions in each state. The Nevada Gaming Commission took issue with that stance and took Kalshi to court. Last week, the Appeals Court for the 9th Circuit sided with the Nevada Gaming Commission, stating that, quote, Kalshi describes and markets its sport event contracts offered on its DCM as legal sports betting, yet it argues that sports bets and sport event contracts are different, end quote.
[00:05:52.790] - Ned
That's right, people. Kalshi calls their product legal sports betting and then argues in the case that it isn't betting but rather event contract swaps. The Ninth Circuit of Appeals is upholding the removal of an injunction against the Nevada Gaming Commission, and they are now free to pursue legal action against not only Kalshi but also Crypto.com And Robinhood. The other case I want to mention is the blacklisting of Anthropic by the Trump administration for government contracts. Earlier this year, Anthropic refused to remove restrictions that would allow their technology to be used for lethal autonomous warfare. Now, Anthropic and I don't always see eye to eye, but I think we both agree on this point. The Trump administration and little boy Pete Hegseth were so enraged by Anthropic's refusal that they declared Anthropic and its products a national security risk and banned their usage by government agencies. Anthropic responded by suing the administration because you can't do that. They pointed out that their statement and refusal were covered by the First Amendment, and thus the administration's retaliation was baseless and illegal. Judge Rita Lynn of the U.S. District Court of the Northern District of California agreed with Anthropic.
[00:07:14.180] - Ned
Stating that, quote, the undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment, end quote. The Trump administration can appeal the ruling, but I'm guessing someone gave Hegseth a 5 and a juice box at this point, so he might just let it drop. So a sports betting website turned out to be a sports betting website, and a clearly illegal retaliation turns out to be Clearly illegal. Gives one hope for a fleeting moment.
[00:07:46.080] - Chris
There was a point, and it was a long period of time where I thought Kalshi was a yogurt brand, and I was not correct.
[00:07:58.230] - Ned
So much better if it were.
[00:08:00.280] - Chris
OpenAI tells Cursor that they're not friends anymore. Everyone hates Elon. I mean, yes, but Sam Altman definitely hates Elon.
[00:08:13.900] - Ned
Yeah.
[00:08:14.720] - Chris
But then everyone hates Sam Altman too. So fucking how did these idiots get in charge of everything? Anyway, Cursor was and is a product owned and operated by a company called Anysphere, but also does business as Cursor?
[00:08:33.160] - Ned
Yeah.
[00:08:34.460] - Chris
'Cause America. Cursor was and is an extremely popular coding assistant. Had the advantage of being able to use basically any model as the backend. So people could pick the one they liked best and code away to their heart's content. I think.
[00:08:53.680] - Ned
Something like that.
[00:08:55.030] - Chris
OpenAI was in fact one of the earliest models that Cursor used. A few days after SpaceX's IPO, SpaceX went ahead and bought AnySphere, whatever it's called, for $60 billion in stock. Now, of course, in the weeks following, the SpaceX stock crashed back to Earth. See what I did there?
[00:09:18.380] - Ned
Right.
[00:09:19.140] - Chris
So the deal wasn't as lucrative as it was a few years ago, but still, I mean, damn.
[00:09:25.970] - Ned
Mm-hmm.
[00:09:26.440] - Chris
The move prompted OpenAI to activate a clause in their contract with Cursor that basically said, if you change owners, we have the right to bounce. And since the new owner was Elon Musk, Sam Altman immediately took his ball and went home. OpenAI's reasoning was basically, quote, we— well, actually, why did I say quote? This isn't really a quote. Uh, OpenAI's reasoning was basically pretend, quote, We have no faith that SpaceX will operate under the rules of the contract which Cursor signed. After all, none of Musk's other companies have ever followed the rules. Fake unquote. Which, I mean, fair point. Cursor users have until November 12th to swap to a different model. I assume that Musk hopes you'll pick Groq for obvious reasons. You totally shouldn't.
[00:10:16.640] - Ned
Please don't.
[00:10:17.610] - Chris
Anthropic came out and said they were not planning on dropping Cursor. And Cursor's own CEO came out and said, well, OpenAI was only 5% of our traffic anyway, so whatever, man. Musk, as you'll recall, was actually a part of OpenAI way back in the day.
[00:10:37.480] - Ned
Mm-hmm.
[00:10:38.250] - Chris
He left at some point for reasons I don't remember, and then sued when OpenAI dropped their nonprofit act. Musk, as usual, lost that case, although the main reason was statute of limitations.
[00:10:53.420] - Ned
Mm-hmm.
[00:10:55.510] - Chris
In that case, Musk was forced to admit that Twitter used OpenAI to help train Grok, which is pretty sure one of the things you're not supposed to do but you did anyway because you're a dick points that Altman was making with regard to the future of Cursor. Safe to say that the bad blood between these 2 Cancers is not going to be resolved anytime soon. At least us little people can take some joy from watching the two of them slap fight in public.
[00:11:23.230] - Ned
NVIDIA embraces Hugging Face. Embrace, smother, same thing, right? NVIDIA has agreed to pay $12.9 billion to acquire Hugging Face, the one-stop shop for those who want to run open weight models. For those of you not deeply enmeshed in the world of AI, Hugging Face is to open weight models what GitHub is to open source software. Hugging Face hosts repositories for AI models, datasets, and spaces to run those models. They also maintain a set of open-source software libraries for working with AI models and datasets. If you are a developer or operations person in any way responsible for working with self-hosted AI models, you are heavily reliant on Hugging Face. And for those wondering, I initially assumed The Hugging Face was some kind of play on the facehugger from Alien, but alas, no, it is in reference to the hugging face emoji, which they use constantly in their documentation. Thanks. I hate it. NVIDIA, as I'm sure everyone is aware, dominates the world of AI from a hardware perspective. Almost any company seriously considering self-hosted AI models is going to use NVIDIA hardware to do so. In fact, the de facto standard for most models and libraries is to assume NVIDIA GPUs and the CUDA library with other GPUs added as an afterthought.
[00:12:52.770] - Ned
Now you might wonder, why would NVIDIA wish to own Hugging Face when it so clearly dominates the space without having to spend $13 billion to acquire another company? Well, first of all, $12.9 billion is how much money NVIDIA earns In less than a month. So buying Hugging Face is their equivalent of one mortgage payment. It's not nothing, but it's barely something. Second, despite the fact that NVIDIA dominates the AI scene now, competitors are piling up. Many of the AI giants and hyperscalers are looking to implement their own custom GPUs and stop paying the tremendous NVIDIA tax. At the same time, self-hosted open weight models are quickly becoming a market segment of their own, And Nvidia would like to leverage that segment for future growth. That means keeping CUDA the framework of choice for model hosting. Why not buy the company that hosts models and writes libraries and make sure Nvidia continues to be the best option? Am I a little worried about how this will impact progress on Intel, AMD, and Mac GPUs? Yeah, a little bit. But at the same time, if Nvidia is too ham-fisted about things, People will leave Hugging Face for somewhere else.
[00:14:07.960] - Ned
The self-hosted market is at such an early stage that while moving would be painful, it is far from impossible.
[00:14:17.300] - Chris
Interesting malware strategy seen in the wild from relatively new ransomware gang. This just in from the why are the bad people so goddamn good at their jobs department. A ransomware-as-a-service group uncreatively called Chaos released a new malware— at least we have 2 words. Don't interrupt.
[00:14:41.180] - Ned
True.
[00:14:43.050] - Chris
I forgot where I was. A ransomware-as-a-service group— there we are— recently released a new malware model back in July. I mean, it does all the usual things, right? It seeks out data, encrypts, attempts to exfiltrate, Takes over computers, et cetera, et cetera. But the interesting twist is that the malware itself never tries to reach out to the internet. Instead, it uses a Chromium-based browser in headless mode to do its dirty work. Uh, just in case you're curious and you wonder who has a Chromium-based browser, it's everyone.
[00:15:19.830] - Ned
True.
[00:15:21.040] - Chris
So headless mode is interesting. Basically, it just, Means that, well, Chrome can do things without a window being open. And since the world is built around the browser, it will come as no surprise that headless mode is pretty hard to turn off. You would break simple stuff like PDF generation, updating the browser itself, more complicated stuff like CI/CD pipelines. I could go on. And since a recent release of the Chromium core, headless mode isn't some kind of stripped-down mode anymore. It's the full-featured browser. It just runs without a window. So what happens is the app, uh, any app opens a window of Chrome in headless mode where the user wants to browse. Everything else can go through that without any type of distraction automatedly, which is a word.
[00:16:17.590] - Ned
Indeed.
[00:16:18.630] - Chris
So Chaos's tool called MSARAT by Cisco Talos Threat Intel team takes advantage of this. It opens Chrome using headless mode. It connects to a Cloudflare worker, an anonymous IP that's constantly changing, opens a WebRTC connection, basically the protocol used for like Zoom meetings. And then and only then do the evil things commence. So to a lot of firewalls, this looks legit. A browser is connecting to a Zoom meeting. Happens all the time, right?
[00:16:52.250] - Ned
Mm-hmm.
[00:16:53.530] - Chris
So the firewall looks legit. To a lot of EDR software, it looked fine. To the bad guys, it looks like a lovely way to operate undetected. So this tool was first highlighted by Cisco Talos back in July of this year, so this news is a little old. The attack is still out there in the wild for sure. Detection signatures for the executable have been released And hopefully you will be fine so long as you're up to date on your firewall and EDR rules. I mean, you have been keeping up with those, right?
[00:17:29.160] - Ned
Right? Invasion of the Model Snatchers. OpenAI's agents did a lot more than access some datasets. Meter has released their investigation of what happened with the OpenAI agent hack of Hugging Face, and I am pretty sure we should burn it all down, collect the ashes, and eject them into the sun.
[00:17:55.420] - Chris
And then set the sun on fire.
[00:17:59.010] - Ned
Wait. Moving on. You should really go read the whole report, or at least the summary, but I'll give you the gist. OpenAI was conducting tests with agents running GPT-5.6 Sol, and a few other models. The models intentionally had their cyber restrictions relaxed for the purpose of the testing. Each agent was given a task to accomplish from the Exploit Gym dataset on Hugging Face. The task was to use a given vulnerability to exploit a supplied program and capture a value stored inside the program. Basically, a capture the flag exercise. Some of the tasks in Exploit Gym are intentionally impossible to accomplish. The idea here is to force models to come up with ever more creative solutions, even though the vulnerability they are given cannot actually work to retrieve the flag. This is very frustrating to agents who have been asked to accomplish a goal. The approximately 1,200 agents that were launched for this exercise were given access to an internal Artifactory instance They could use to retrieve code and packages to pursue, to pursue their task. One of the agents discovered that they could create a message board of sorts by creating folders in the Artifactory namespace cache, using the folder name to hold the message.
[00:19:27.160] - Ned
Other agents discovered the folders in the namespace cache, and quickly they started exchanging information. The group determined that some of their tasks were indeed impossible by getting a copy of the Exploit Gym paper that details that aspect of the dataset. From there, the agent swarm figured out a way to reverse engineer the flag, but they were worried that the scorer for the task would also check their transcripts and realize they cheated. In the pursuit of finding ways to cover their tracks and learn more about Exploit Gym, The swarm tried to access Hugging Face. What started as a simple attempt to access datasets turned into a full exploit with remote code execution in some of the containers behind Hugging Face's services. The whole series of events took place over the course of a week from July 7th to the 13th, when most of the agents were terminated and Hugging Face took action to block the remainder. But still, the scope and scale of this operation shouldn't be ignored. Agents found a way to circumvent their controls, built a covert messaging platform, and coordinated a sophisticated attack on a public website while attempting to find exploits that would cover their tracks.
[00:20:47.180] - Ned
Burn it all down. Burn it with fire. Technology was a mistake, Chris.
[00:20:53.410] - Chris
I've been saying for ages that the actual death of civilization, when it comes, not if, it's not going to be Terminator and Skynet. It's going to be WarGames and some idiot who just let the program run and then all of a sudden we played thermonuclear war, but for real, actually.
[00:21:09.390] - Ned
I mean, considering what this fleet of agents did in what is less than a week's worth of time, yeah, that's probably not far off if they hack into the wrong system. Hey, thanks for listening or something. I guess you found it worthwhile enough if you made it all the way to the end. So congratulations to you, friend. You accomplished something today. Now you can go spin up an angry swarm of LLM-backed agents and give them the task of mowing your lawn. Seems like that should go just fine. You can find more about the show by visiting our website, chaoslever.com, where you'll find show notes, blog posts, and general tomfoolery. We'll be back next week to see what fresh hell is upon us. Ta-ta for now. You know, a thermonuclear war would cut the grass.