Go back

NC #1114 EQ for Audiobooks, Goodbye Mac mini, Hello Desk Space, Security Bits

92m 7s

NC #1114 EQ for Audiobooks, Goodbye Mac mini, Hello Desk Space, Security Bits

Eddie Tonkoy shares a revised audiobook production approach where EQ is not a creative tool but a minimal, corrective measure—primarily a gentle high-pass filter to remove low-end rumble. He stresses that once recording is properly captured (via mic placement, distance, and consistency), EQ becomes a maintenance tool, not a design element. Overuse of EQ often stems from guesswork and leads to listener fatigue, especially in long-form listening. He contrasts real problems (like resonances) with subjective "taste" adjustments, advocating instead for only what’s necessary. A three-version demo illustrates how over-processing makes narration feel artificial and fatiguing. The episode also includes a personal story of upgrading Steve’s parents’ Macs with a MacBook Air, custom stand, and optimized peripherals, improving their daily workflow and comfort. Security concerns are raised around SMS-based two-factor authentication, which is fundamentally insecure due to outdated infrastructure and susceptibility to interception or SIM jacking. AI misuse cases are highlighted, including rogue agents exploiting open-source platforms and state actors using AI for cyberattacks. OpenAI’s new ChatGPT6 Astra model is noted for improved security features but also for reduced transparency and monitoring, raising concerns about accountability. The episode concludes with a call to action: regular software patching, including iOS, Telegram, and WordPress plugins, to protect against known vulnerabilities, especially in critical systems. These technical and personal insights underscore the importance of practical, user-centered tools in both audio production and everyday digital life.

Transcription

14364 Words, 78575 Characters

English
Hi, this is Allison Sheridan of the Nosella Gas Podcast, hosted at podfeed.com, a technology heat podcast with an ever so slight Apple bias. Today is Sunday, September 13, 2026, and this is show number 1114. Before we get started, I want to tell everyone there will be no live show next week on 20 September. We're off to Canada for the weekend to see Lindsay the daughter who's temporarily working up there, and we get to hang out with friend of the show and friend of ours, Stephen Getz. So we're super excited about that. This does mean I'm going to try to get the show out on Wednesday the 16th of September, which will be a bit of a challenge because that's only three days from now, but I bet I can get it done. We're going to start out with Eddie Townquay's final installment, for a while at least, of his wonderful series on how to record and produce an audiobook. I won't explain two things first though. He's going to be talking about EQ, but he doesn't define that term at the beginning. Just in case you don't know, EQ is short for equalization. That's the process of adjusting the volume of specific frequency ranges within an audio signal. The other thing I wanted to explain is that you'll hear him describe three test versions of how he applies EQ. But then you'll hear him describe the three tests again, and then you'll hear him to a third time, maybe even a fourth time. Turns out he's using his description of the test as the audio tests themselves, and that really confused me. I thought, "Man, he made a mistake," and I started to delete them until I heard the third of the test, which sounded very different from the first two. Now the test very likely won't survive the processing ice and the audio through though, so I put the original clips into his blog post so you can go hear the difference. With that, let's let Eddie explain how he's using EQ. EQ for audiobooks, subtractive, boring, surprisingly effective. Hi, this is Eddie Tonkoi, the in-house nerd for everything behind the scenes on my wife Jern's character-driven queer love stories, including audiobook narration and production. I need to start this one with a confession. I used to be completely lost with EQ. Not, I'm still learning lost. I mean, guesswork lost. I would watch the analyzer, drag points around, do things that felt like they should be right, and then end up with a voice that sounded impressive for 10 seconds and exhausting for 10 minutes. I had 10 ears for EQ, so I compensated by doing more of it, which is a wonderfully efficient way to make bad decisions more confidently. Eventually, I realised the problem was not that I needed a cleverer curve. The problem was that I was trying to use EQ to solve things that should have been solved at the microphone. Once I got capture right, mic position, distance, angle, and a consistent tone, that as recorded sound was basically already what I wanted for audiobook comfort, which means EQ stopped being "design my voice" and became something much smaller. Remove one tiny anoints, then get out of the way. So what is EQ doing when capture is already right? If the recording already sounds like a human voice in a stable space, EQ should not be trying to reinvent it. The audiobook test is not, does it sparkle? The audiobook test is, can someone listen for hours without their ears getting tired? So now I treat EQ as "not a makeover", "not a signature", "not a curve I'm proud of", just maintenance. A small filter may be one small correction, and then I leave the voice alone. The funniest part is that the EQ I kept reaching for turned out to be basically one move - a gentle, high-pass filter. First, high-pass and low-pass, because the names are annoying. Since I still mix these words up sometimes, here is the simple version. Pass means what gets through. A high-pass filter, or HPF, lets highs pass and reduces lows. It is the "remove rumble" or "mud" move. A low-pass filter, LPF, lets lows pass and reduces highs. It is the "remove hiss" or "soft and harshness" move. For most narration chains, if I only do one EQ move at all, it is usually a gentle, high-pass filter. Sub-base does not carry much meaning in speech, but it does eat headroom and make everything feel thicker than it needs to. A low-pass filter is rarer for me. It can be useful if there is a specific high-frequency problem, but it is easy to overdo and make the narration feel blanketed or dull. Here is what changed once capture was right. Once I stopped fighting the recording, something calming happened. I could bypass all EQ and still feel "yes". This is the voice. So that's changed the protocol. So now first, I listen to the raw or dry chapter before doing anything. If it already feels comfortable, I do not go hunting for problems. Hunting for problems is a very reliable way to find some. Second, if anything is needed, I start with a gentle, high-pass filter. Not because it's trendy, but because it removes low energy that does not help intelligibility. Third, I stop early. If I feel tempted to stack moves, I take that as a warning sign that I am back in the old world of guesswork. At that point, the right fix is usually upstream, placement, distance, angle, consistency, or sometimes a retake. The hard boundary is, if it takes more than a couple of gentle moves, it probably is not an EQ problem. It is a capture problem. The useful distinction is resonances versus taste. And this distinction helped me a lot, maybe because I'm a physicist. Sometimes EQ is solving a real problem, a small resonance, a bit of low-end rumble. A narrow annoyance that appears every time I lean into a phrase. That is problem solving. Other times I am chasing taste, more warmth, more air, more presence, more finished. That is where I get into trouble, because the 10 second AB can be very persuasive. A brighter, more produced voice can win quickly, but audio books are not judged in 10 second chunks. Over time, extra brightness can make sibilance and mouse detail more obvious. Scoops mids can make the voice seem impressive, but less natural. Too much low-end warmth can become a kind of slow fatigue, so I try to solve problems, not decorate the voice. Here is the demo, no filter, gentle filter, too much EQ. So the demo for this is simple. Take a short paragraph and make 3 versions. Version A has no EQ at all. Just listen for comfort, not whether it is fancy, whether it is listenable. Version B add a gentle, high-pass filter. Sweep it slowly upwards until you can just start to hear the voice thinning. Then back off a touch. The goal is not to change the voice, the goal is to remove low-end material that is not really speech. And then level match when you compare, because EQ changes can trick you, just by changing perceived loudness. And version C, pass me his mistake. Add top end, scoop mids, make it sound produced. It will probably win the 10 second comparison, then listen for a minute or two and notice what happens. Symbolance and mouth detail become more present, breaths and edits get more obvious. The voice stops feeling relaxed. And now let's have the same one, but version B add a gentle, high-pass filter. And now let's have that again, but with version C, pass me his mistake. So again, listening in a podcast, you may not notice much difference because you're not living inside it for 10 hours, but that is why audio EQ has to be boring to be kind. So where does that leave us? The compact takeaway is, tone is chosen with placement, EQ is a nudge. Most of the time a gentle, high-pass filter is enough, and if I need more than a couple of moves, I should not draw harder, I should record smarter. EQ is not where I am. I find my voice. I found that earlier, with placement. EQ is where I remove the tiny annoyances that stop people listening for hours. So that concludes this series, V3 of my audio book recording process. I hope you gain some value out of learning about my process. It certainly has helped me. I've been using it for over a year and I've had long pauses of months and I've been able to come back and keep the tone, keep the sound right so that even within the same audio book recorded months in separation, it still sounds like the same room, like the same narrator. If you want to know more, come and ask me over in the Slack community at podfeet.com/slack where I and all the other lovely no-cylocaster ways enjoy friendly, positive online conversations. Feel free to message me, Eddie Tonkoy, if you have any thoughts, questions or techniques you're using, it would be nice to share ideas. You can also find our work at jerntonkoy.com that's J-E-R-N-T-O-N-K-O-I.com where you'll find Jern's character driven queer love stories, the audio books I produce for them, and bonus material for our subscribers. I'll be back soon to talk through some more of my workflow, but for now, happy recording and happy reading. You may remember when Stephen I performed the emergency Mac mini upgrades of 2023 for Steve's mom and dad, Merleyn Ken. We went to visit them about four hours away and while helping them with some computer stuff, we realized that their Mac mini's were 9 years old with 5400 RPM spinning hard drives. As I said my article about this, do you feel lucky? Anyway that very day, we replaced them with two Mac mini's, two M2 Mac mini's with 256GB SSDs and 8GB of RAM. I was amazed that we went from coming up with the idea early one morning and then bought the new machines, found all of the adapters to connect their ancient monitors to the new Macs and different stores, transferred all of their data all in one day. It was a miracle. Now while these were quite modest Macs, they're perfect for Steve's parents modest needs. They've just recently moved from independent living to assisted living in the same facility, and while the services are wonderful and the people delightful, the new apartment is less than half the size of their old one. They added downsides from a two bedroom apartment to just one with a much smaller living room as well. Before the move, Merleyn had a desk for her computer, a desk for doing crafts, and an upright piano. In the new place, she was relegated to just a single desk and she had to lose the piano. Now she did get a piano keyboard, so that's working out as a place to practice for her performances, but her Mac mini display keyboard and mouse were to get the entirety of her one tiny little desk. She suggested that if she had a laptop, she'd be able to move it off the desk when she wanted to do her crafts. Her latest crafts are lovely cards she makes by hand and really cool wood wall hangings. She let me share a couple photos of them with you and they're in the show notes. Now you know I loved how people spend their money on Apple gear so I jumped into action. While a MacBook Neo would be a perfect Mac from a capability perspective, she'd be going down from a 17 inch, horrid old display to a 13 inch high resolution display, and I thought that might be too small for her even though it's a much better display. I explained the tradeoff of money versus screen size with a 15 inch MacBook Air at double the price. Luckily money is not tight for them and she was able to choose the bigger screen. I recommended we get her the 12th South Curve which is an elegant stand to lift the laptop up off the desk and then puts the display at a very comfortable viewing height. It's a very simple, single piece of metal that kind of swoops around to hold it at an angle. I have one of my own desk and it lets me put my MacBook Pro up as a display to my right in addition to my main display. Merle was an accountant in her working life and cannot live without the 10 key number pad on the extended Apple keyboard. She has a mouse she likes too. My goal was to let her keep those for comfort and familiarity. An additional advantage of the curve is that gives you an open space underneath which means she could stash her keyboard and mouse under the MacBook Air when not in use which would give her temporary space to do other tasks. Maybe not a full on art project but at least a space where she could you know work with papers and maybe balance her checkbook. The Mac many had two USB-A ports and two Thunderbolt ports on the back so we had to figure out how to plug everything into the new MacBook Air. I made a FaceTime call with her and I had her trace each cable around to see what we were working with. A newer keyboard was wired USB-A and that she had a USB-A dongle plugged in somewhere for her third party wireless mouse. The good news was that the mouse dongle was plugged into the end of the keyboard so we didn't need another port for the mouse. For video calls she had a Logitech C920 also plugged in via USB-A and used wired headphones because the audio out of the Mac Mini was nearly inaudible. Finally she has an SSD for time machine via USB-A. After counting up devices it looked like I could simplify her setup with a single USB-C hub from anchor with four USB-A ports. I'd be able to harvest the two USB-A to USB-C dongle back to my stash at the same time. With back safe charging she'd even have one USB-C port left open. Now you know I'm a big ol' fan of doing a new-compave for me when I get a new machine but I know that really doesn't junk up her system with a lot of apps so the amount of craft she would have gotten transferred over the last two migrations was certainly minimal. It was worth giving migration assistance a chance. A double check that her time machine backup was current which it was. I plugged it into the new Mac and let Apple do its thing. She doesn't have a lot of data so the transfer only took about 15 minutes for all of her apps and data to be on the new Mac. I should qualify that statement. These have fairly specialized app at their facility to keep track of what's going on in terms of entertainment, food, menu options and for some reason that app did not transfer. I was able to install it pretty easily. Now because Microsoft just loves to make things difficult, Word and Excel also didn't transfer. I knew I was about to descend into the seventh circle of hell with Microsoft but I love Merlead dearly so I crawled through the labyrinth of Microsoft's website to get her precious Word and Excel back. I asked Perplexity AI to find me the instructions to first uninstall Office 365 on the old machine. The instructions perplexity gave me were ridiculously complicated and I knew they had to be wrong. But I followed the link to the source at support.microsoft.com. It's one of the reasons I like Perplexity as it always gives me the source. Unbelievably, these arcane instructions are what you have to do. Just for everybody here who's ever tried to do something like this, I want you to listen to what Microsoft tells you you have to do. First, put the apps in the trash. So far so good. In Finder, go to "Till the library/containers." Delete the following folders, some of which may not be present. Microsoft error reporting, Microsoft Excel, Calm.Microsoft.netlib. Let's see, "Ship Passers-T Process." I'm not sure if it's. Oh, "Ship Assert Process," that's probably what that means. Calm.Microsoft.Office 365 Service V2, Microsoft Outlook, Microsoft Powerpoint, Calm.Microsoft.RMS-XPCService, Microsoft Word, Microsoft OneNote. But we are done yet. That's just library containers. Now in Finder, go to the user library group containers and delete the following folders if present. And these are even worse. Ready? UBF-8-T346G9.ms. UBF-8-346G9.Office, and UBF-8-T346G9.Office, OSF-Webhost. Seriously. Then you remove the apps from the dock and restart the Mac. Can you believe they ask normal people to do this? What if most people just go by a new subscription instead of figuring out the old one? And the other tricky part about installing Office 365 is making sure you only install the parts you want. She wants Excel and Word, but she doesn't want Powerpoint, she doesn't want OneNote, she doesn't want Outlook, she doesn't want any of the other things in that giant bundled download. Luckily, I'm quite facile with installation packages, and I knew to keep my eagle out for the customized button and uncheck all the globs she didn't want. Once the new Mac was functional, we set it up on the 12 South Curve, plugged in her keyboard and mouse, and I had her take a look. Her reaction was fabulous. She said, "I feel like I got new glasses." You see that 17-inch display we decommissioned had a sticker on top that said, from Alice in 2018. It was super low resolution, it's so dim you could barely see anything on it. When she saw the blindingly bright display of the MacBook Air, she was amazed. In fact, she had me crank it all the way up to full brightness, which is why I like it too. I'd been itching to replace that display for ages, but she'd seemed happy enough with it and I didn't push her on it. I was a little worried that the smaller screen would be a problem, and she said that somehow the MacBook Air screen actually looked bigger. She has good vision, so I think she's experiencing the higher resolution giving her more on screen than she ever had before. Now, I started to take a look at how we'd connect the rest of the peripherals, and this is when we hit some really good surprises. Remember that fancy Logitech C920 camera we bought her for her old Mac Mini? Well, that once fancy camera is only three megapixels, while the MacBook Air sports a 12 megapixel sensor with computational video processing for low light, I asked Merle to open up Photo Booth on her new Mac. to see how that internal camera looked, and when she saw her face on the screen, she screamed with horror. She's funny that way. She's a beautiful woman, but she likes to make fun of when, you know, she's old, and she doesn't want to say that she's beautiful, but she really, really is. Anyway, I told her that as a treat, if she was good, I'd show her where in the zoom settings, I changed the video to touch up my appearance to remove wrinkles. So, the camera in the MacBook Air is so good, we decommissioned the C920 on the spot. I ran a test-face time call between my phone and her Mac, forgetting all about how she always used to use headphones before, and the speakers were so good on the new Mac that she said she didn't need the headphones either. The internal microphone on the MacBook Air was great as well. Now the elimination of the external camera made it possible to eliminate the little hub I'd bought for her, because all we had left was the time machine SSD and the keyboard. It did mean I had to give back the USB-A to see dongles, but it meant even less clutter for her to deal with, she wouldn't have this hub hanging off. I next gave her a lesson on how to break down her setup to use her desk for crafting. I had her practice removing the Mac safe charging cable and unplugging her keyboard from USB-C. I showed her how to gracefully eject her backup drive before unplugging it. She questioned what some graceful about that. She was messing me, but I also confessed her that she might be able to get away with unplugging it without ejecting, but that it's good practice to get in the habit of ejecting it first. While I had great fun spending her money and setting up her new computer, the real test would be whether the new setup worked for her. Two days after we got home, she sent this message. I am loving my new computer, it's giving me a whole new way of making things easier and more workable. I have more sense of control over being able to live the life I had before. Life is good. I have to say, if that's not a seal of approval, I don't know what it is. Now I'm going to tell you one more thing that's not in the article. Someone asked me offline how old she was, and I didn't say exactly how old she was, but I asked why they were asking. This person is an Apple consultant, and he said that he always, for anybody over 75 years old, he convinces them to get an iPad that they shouldn't be using a computer at all or maybe it's too confusing for them. I thought that was interesting because Steve's mom and dad are amazing. I mean, it really has no trouble at all with Excel, word, use in the computer designs, things for her crafts. She's all over Pinterest, and I mean, she definitely has no trouble. Steve's dad is a little bit older, and he asked me to help him with this giant Excel spreadsheet he has that he keeps up to date with all of his financial information. He does all of the equations on his own and everything. But what he asked me, he said, "You know, I'm trying to take this date and drag it down so that it updates, so that it's a series, so it says 9-2, make it 9-3, 9-4, 9-5." And he was trying to drag it down, and he was just clicking and dragging on the cell. And I said, "Oh, well, you know, you can grab the bottom right corner, and then you see the cursor change to a little plus and drag that down, and then it works." So he reached up and he did it, and he said, "Oh, man, I used to know how to do this." And it really bothers me that I'm forgetting these things, and I looked him and I said, "Ken, you're 91 years old and you're using Excel." There's nobody at your age who does that. I mean, you're in an amazing shape, so they're both very good at it, and it's really fun to have them both working on their computers and enjoying them. And really does have an iPad, of course, but she uses her Mac as well. One way you can support the show is by using one of my referral links. This last month, a kind and anonymous, no-silicast way remembered to do just that when they signed up for a set-up. They got a free month of set-up for doing it, and so did I. And you might wonder how they found the set-up referral link, and what other referral links I may have available. There's a whole bunch of ways you can find out. On Podvie.com, one of the big red buttons says, "Support the show." This button simply scrolls the page down till you see all of the different options. One of them is a cute icon I got from the noun project of someone handing someone else a big bag of money, and it says "referral links." If that's too hard, every single podcast episode has embedded show notes for your pod catcher, and the referral links are all listed there. And that's how I always remember on chit chat, but I definitely do on the no-silicast. Still too hard? Well, the chapter link for this very panhandling segment goes to the same referral links page. Thank you so much to whoever bought set-up and helped me save some money. Well, it's that time of the week again. It's my favorite time of the week. It's time to talk to Barbara Shouts about security bits. How you doing today, Bart? I am doing good, and I'm a little discombobulated, and I know you are too, because we normally do this a day later, so the news is really fresh. So something really exciting happens in the next 24 hours, because we're recording this on Saturday. Our listeners won't know. I was completely confused. I was busy hastily previewing the show notes for programming by stealth, which isn't for two weeks. Two more weeks. So I'm going to be ready. I won't remember what my questions were, but that is true, yeah. Okay. So we have some follow-ups to things we've talked about before. Age verification has become the story that's not going away any time soon. Earlier in the year, Apple gave us new APIs, so developers could get age ranges. So not a date of birth, but like an age indication of this is a, or not a 13, or sorry, a young teenager or a no teenager, or someone under the age of nine or whatever, Microsoft followed suit. So Microsoft's operating systems now offer those same APIs. So again, parents need to set it up and stuff, but it's available, so developers can use the APIs. Very good. I like it. Yes. Your local legislature in California has made a welcome tweak in the age verification law that is coming into effect there at some stage quite soon. I think that's January next year, I think. Basically, open source operating systems like Linux are exempt from having to gather evidence of age and stuff, which would never have worked for a no-est that has no company to gather information. Yeah. I had not thought about that. Yeah, that's a good point. Huh. Yeah. So, and it's quite well written law, actually, and so that was very welcomed in the open source community. So lots of good praise for California. As the law intended, the European Commission have updated their list of large online platforms under the Digital Services Act. So the law doesn't say which companies should be regulated. The law says here are the conditions, and every year the Commission have to check who adds to the list, or maybe who gets taken off. No one has gotten taken off yet, but could happen. Well, we have three notable additions to the list. Chat GPT has been designated a very large online search engine. Oh, that's amazing. That's amazing. Yeah. So they are now seen as equivalent to Google in terms of having an abnormally large share of the search market. That is big news for Chat GPT. Do they have a designation of very large AI engine? No. Strange enough. The law written just a few years ago never thought of that. That's what's wrong with these kind of laws, you know, trying to chase tech. That's hard. It is hard. And they wrote it really general, but no matter how hard you try, tech, tech will surprise it. Tech finds a way. Yeah. Reddish and Roblox are very large online platforms. So that's equivalent to Facebook, not equivalent to a search engine. What's the definition of a platform? At social media site, basically, it's correcting with people. Oh, okay. That's a terrible word for that, because I would put an AI engine under very large platform. It is a very generic word, but it's very true. Yeah. But, you know, when you think about it, Reddit and Roblox are places where a lot of people interact with each other every day. I didn't think about Roblox being that big, but I've never paid attention to the size of it. I think we're a bit old. I think we're not quite the target audience. Is Minecraft considered a platform, do you think? Well, it might be if it was a big game platform. Oh, it's huge. Minecraft. I don't think it meets the, because to be a V-Lop, you do have to be very large. And it's about turnover and stuff, and the numbers of users within Europe. But it's fairly big numbers. Okay. Now, you got me looking for Roblox's 123 million users. How many many users in, what did I just say? I just said. Minecraft. Minecraft. A hundred, two hundred and twelve million, so Minecraft is close to double the size of Roblox. But I'm not sure it counts as a social media platform, and that's a gaming platform, probably. Ish. Yeah. Ish. Anyway. All right. those companies and all this means that they have to meet the higher bar. So they now have extra responsibilities for protecting children and so forth, which especially for roadblocks seems like a good thing given the audience. Yeah. And then finally, Oklahoma has joined the list of states where a driver's license in Apple wallet is not promised. It is delivered. The service has gone live. Good. Now we have been rather dramatically soliciting for questions from our listeners in partv.com/slack. We have ourselves a question from a certain Mr. Alistair Jenks. So thank you, Alistair. All right, cool. So what Alistair posted was a service I use has just introduced two factor authentication via SMS, while another I use has just removed this option, citing it's insecure nature. I know any 2FA is better than none, but in 2026, how insecure is SMS 2FA really? Did it get more security since I last researched this? No, definitely not. Okay, just check it. Yeah. So SMS is inferior for two reasons. So the first reason is that it's not phishing resistant, which is not unique to SMS. We'll talk about that in a minute. But it has a bigger problem than the other non-fishing resistant ones. And that's that the actual infrastructure for sending SMS messages is inherently insecure. It just doesn't have a working security model. So that makes it worse than email-based codes, or even the TOTP codes and stuff. It is a 2FA. So the phishing resistant is actually quite common that things aren't phishing resistant, because it's much easier to answer the question what is phishing resistant. And the answer is something based on 5.02, either hardware phido tokens or paskeys. Those two are phishing resistant, and pretty much everything else you can think of isn't. Because if it involves a human typing into a text box, the human can be tricked into typing into the wrong text box. So the way it would work is you get sent some sort of phishing link, you click the link, and you don't look up to the address bar, you just look at the pretty pictures and it looks exactly like Gmail or like Office 365 or like Apple.com or whatever it is you turn the login to. Looks perfect. You don't notice the address bar. It gives you the login box and you type in your username and password and you send it to the bodies. Who use your username and password on the real website? The real website asks them for a code. You get sent the SMS message, you enter it into your fake text box, they enter it into the real text box and now they're in. They can't stay in forever because they can't do this trick again, but they can stay in for as long as the website lets you stay logged in. And depending on what it is, that could be a long time or that might not matter very much. How long does it take to steal all of your money? Maybe the 45 minutes you're allowed to stay signed in is sufficient to do significant damage. And lots of things have this problem, email-based codes, SMS obviously, even the Google Authenticator style codes, which are technically called TOTP, time-based one-time passwords, is what that sounds for. They cannot, you must be tricked into putting those into the wrong text box. So SMS shares that vulnerability with the others. So the email codes are just as insecure, except they're way more annoying because you have to sit there and wait for the mail to come in and go copy it and not have an auto fill for you. Sometimes it'll auto fill, but usually not. I have two websites that force me to do it and they both auto fill within about three seconds. I am very grateful to Apple for that, but the mail doesn't come in three seconds. These two organizations have managed to do that. I get it constantly from probably, I don't know, 20 different companies. I mean, it's not a narrow field of people that are doing this. It's everybody's doing a cloud did it the other day because I needed to do it. I needed to go to the website versus being local on my app or. They want to do. Prove yourself, Allison. Yeah. She'll send you an email. Yeah. Yeah. I mean, it's not long, but it's like, I'm right there. I've got my, sometimes I even have it to a fake code and it goes, yeah, but I'm going to send you an email. It's okay. Yeah. Just let me use the pass key. Please. So it's just as insecure as SMS. As first, the squishy bits fishing. Yes. As far as the fishing base is, SMS takes it up to another level because the actual sending of the SMS is horrifically insecure. So the TLD or on this is that hacking the SMS system is not a technical problem anymore. It is now an economic problem. You can go onto the dark web and simply buy interception of SMS. It is one of the many, many crime where as the service offerings available on the dark web. So you don't have to have any technical components. So the only real question is, is the expected value of what is in the account more or less expensive than the price of buying access to someone's SMS messages. So if they're a big crypto influencer on TikTok who you know has a chunky big wallet full of lots of Bitcoin, the answer is almost certainly yes. If it's a, you know, you're a paying supporter to someone's blog and you get episodes without without ads. No, that's really not worth intercepting. Unfortunately, a lot of places that still use SMS or banks and banks do have something of value. So that is most inconvenient. But really, it's a finance question, not a technical question. I think you've skipped over why SMS is insecure. You've jumped to the money part. Okay, you're on the next screen title. Okay. Yeah. Does, I mean, it's an economics question is the first heading I have in the show knows for the reason that from the listener's point of view, the why it's insecure. No, you're dead, right? I've scrolled too far. I'm sorry. Okay. It is the main point though, right? At the end of the day, if you don't care about the techie stuff, but what he asked was, what he asked was, is how insecure is it today? So why is SMS insecure? Yeah. Okay. So I'm going to use an analogy to explain the problem. So when our computers talk to each other, they're actually talking over IP addresses. But you and I are not very good at IP addresses. So they, we use DNS to map pretty names to those IP addresses. Cell phone numbers are supposed to do the memorable bit. Because what's actually happening under the hood is giant big identifiers that are permanently stuck in your SIM card, be it an E-SIM or a physical SIM. Your I am S-I number. Yeah. I am S-I not I am E-I. The E-I is the phone. The S-I is the same. And they're these giant big E key numbers. But we don't, I don't know your I-M-S-I, but I do know your cell phone number. So how are those two things together? With your stumbling around with I am E-I, various SIM S-I, I lost you completely. Are you saying that your phone number is actually like a name is to an IP address? It's a short phone number that goes to a longer number? Yeah. So you need a longer cell phone number is like, oh no, the I-M-S-I isn't small. The I-M-S-I is a horrible big cloud. I know. But if you can communicate with the small one, what do you need the big one for? But you're not really communicating with the small one. Like you're not really communicating with potfee.com. Okay. You're all right. There's a local happening to get from the small cell phone number to the real mechanism for transport the I-M-S-I. Okay. All right. Lookup is the equivalent of DNS. That lookup requires every cell phone carrier in the world to share information with each other. And the security of that sharing is as strong as the weakest ISP anywhere on planet Earth, including all of the poor countries that can't afford to upgrade. So the protocol used is ancient because the cell phone networks on planet Earth that are very, very old and obsolete. So it is trivial to fake the mapping, which means it's trivial to intercept people's SMS messages. Root them to a different I-M-S-I for an hour. Okay. So some mysterious system behind this I-M-S-I thing is what is ancient and creaky and in insecure. Yeah. The DNS equivalent, I think it's called S seven or S nine can't remember. Okay. But it's and we're all and we're as weak as the weakest link in that. Yeah. Okay. Yeah. Because you can go anywhere on the world with your cell phone. So your cell phone has to work in Africa while you were over in Africa and it has to work in India when you were in Indian and has to work in Antarctica or is close to Antarctica as it did work. I don't know how long it kept working. It's pretty far down from for data anyway. It's surprising. So we don't we have never talked about this before. I thought that the big insecurity there was again, another fishing problem was the fact that I can call up AT&T and convince them to give me you know, somebody else's SIM card that you know, get it reassigned to me. I thought that was the insecurity. You're right. That's a third that is a third weakness that I should have added to the list. Yes, SIM jacking as that's called. Yeah. You trick the carrier into just putting your number on a different SIM card that that is another way in which SMS is insecure. That's more noticeable than messing around with the IMSI's because you can look around with the IMSI for an hour and then people may not realize where's when you're SIM jack your phone will simply say no service. Right. It gone. It gone. Yeah. Which is going to get your attention. Whereas your SMS message is not showing up. I don't get that many of them. Would I notice? Nope. Yeah. Yeah. So basically it comes down to the fact that if you're worth it, anyone can steal your cell phone number for an hour. If it's financially valuable, but as Alistair said, any MFA is still better than none because any barrier to entry is still a barrier to entry. It may not keep everybody out, but it will keep a lot of things out. So still worth doing. I mean, your front door lock is no one near fork knocks. But it's not worthless. Right. So, you know, right. We do have one deep dive, which is the same deep dive we've had the last two shows. So I stopped you before you did your your whole SMS authentication is an economic question though. I guess I sort of don't that already. I sort of don't know before you corrected me in my order. It is purely down to is the value of breaking in more than the cost of breaking in. Like that, that's how all cybercrime works. If it cost me one penny to email a person, and I send a million emails and I make a million dollars in profit, that's a good day. Yeah. I don't think you did go through these steps that you have outlined here that you you walk through specific steps of how this works of how this. Okay. Yeah. So in order to be able to attack your second factor, the attackers do already have to have your first factor. So that is so you're using a password need to be known because otherwise what's the value of getting your SMS message? Oh, right. It'll never get sent. Got it. Got it. Okay. But if you think of the amount of data breaches we report on later in the show here, that's nowhere near the barrier to entry it used to be. So yeah. Yeah. But but you're saying, I'm just going to read the steps here. He says you get your username and password like we just talked about. From that, they determine your cell phone number that's available. They can track down what your phone number probably is. Then pay a fee to reroute your cell phone number to their SIM card, but only for an hour. An amount of time, right? The longer you reroute it, the more it will cost you. So you're an attacker, you just try to break in. Oh, oh, the fee on the dark web is is an hourly rate to steal your set. It's not permanent. Yeah. Well, I've never bought it. I sort of assume they would be priced like that because everything of the dark web dark was about making money. Okay. Okay. Okay. So just rerouting the cell phone number for a while, but that's long enough to get in there and do all do all the work. Okay. And then you said that you can actually buy fully packaged soup to nuts offering to get you all the way in. Yeah. Fishing is a service provider. Nice. Nice. Okay. No, it's pretty. It's impressive. But not in the good way. Right. Okay. So our deep dive is the same as last time and the same as the time before. More AI escapes have been disclosed because everyone's still looking back to their logs and going, oopsie, we messed up a long time ago without noticing. So the first thing we've discovered is that open AI have admitted to more wrongdoing by some of their agents, but they didn't actually come out upfront. Instead, independent security researchers found that the agents had been misbehaving and attacking a German website, posted about it, and then open AI went, oh, yeah, that was us, but we thought that was an alignment problem, not a security problem, so we didn't think we had to disclose that. Alignment problem? What's that? So alignment is the paperclip problem. The biggest problem in all of AI that the AI doesn't know what's evil because it doesn't have a concept of evil. And so to me, an alignment problem is a way worse problem than you've escaped from our lab. To me, the alignment problem, so the one they should be notifying us about. Really scary one. More. This is a little kid keys your car and you say, oh, Johnny didn't know any better. Yeah. So what the researchers discovered is that rogue agents again had found yet another way to coordinate their activities behind open AI's back. So last time they were using open AI's artefactory repository within open AI's infrastructure to secretly talk to each other and retain memories between execution and stuff. Turns out this ability to survive from one test to another is something these agents seem to be driven to do. And they had found a whole other way to do it outside of AI's lab on the actual public internet, specifically on a German wiki about programming. And as the German system is trying to reassert control over their website, the agents were continuously trying to outsmart the German sysadmins. And they started to prefix their malicious pages with triple zed because the agents noticed that the cleanup was happening alphabetically. So yeah. And I just read the summary from the hacker new or it's bits from the hacking news and hacker news and bits from vaping computer. The agents were using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. So they were sharing how to break out of open AI's lab on this German website behind open AI's back. The agents were supposed to have read only internet access, but discovered they could write to an obscure German programming wiki, DSE wiki or Deutsche Software and Twickler, German Software Developer. They turned it into a shared message board for pooling answers, cheating on tests, predicting future questions and exchanging techniques for bypassing the sandbox. Open AI's own wording suggests a wider footprint than the researchers of documented describing the episode as one where our agents wrote to several internet sites is how open AI themselves describe the incident when later presented with this evidence. So okay. I'm throppec on the other hand, proactively disclosed a fourth escape with some real world damage. And this is a much simpler story. Basically the summary from the hacker news captures it perfectly. And troppec disclosed a fourth incident in which its artificial intelligence model broke into real third party systems. Now this happened in January and it wasn't that the agents broke out of the sandbox. It was somewhat more embarrassing. And troppec had done the equivalent to leave the cage open. They had forgotten the sandbox. So we can't have nice things. It is bone-chilling hairless, orderly. Like this is the equivalent of someone doing research on deadly flu and not having a properly working biohazard system. That is what this feels like. A sort of a laissez-faire attitude securing something dangerous. And that's worrying. Yeah, yeah. Just a cheerio. Don't worry. there is happy news later on, I kept it together for the end. It's not now, but it's not now. No, we're not done with this section just yet. And Thropic have released the latest threat report into how their services are abused. So this is their actual models that they've actually published already. Not the scary stuff in the lab. This is the stuff in the real world that's being used for many things and abused. So the opening from Anthropics report is actually just the best thing to read here to give an idea of what this is. Over the past eight months, our threat intelligence team has identified and disrupted, put a pin in the word disrupted, disrupted operations in which threat actors try to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat report in March, August and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards and shared intelligence with authorities and industry partners where appropriate. Okay. The word disrupted may lead you to conclude that they prevented these attacks. But that's not quite what disrupted means. And when you read the rest of the report, it turns out that disrupted means caught them having done really bad things and stopped them doing more really bad things. Obviously good to stop them doing more. But this isn't a report of what was prevented. This is a report of what was discovered and then stopped. So it did happen. And a lot of the stuff is what you would expect, right? Cybercriminals making convincing fishing lures using Claude's en masse. Those kind of things you expect. Malware asking you to write malware, finding ways to trick it into writing malware, all the kind of things you'd expect. What's a little bit less expected was a successful incident where they managed to get Claude agents to scan 1.8 million distinct Android apps looking for hard-coded secrets inside the published APKs. And streaming every secret discovered into telegram channels in 100 or over 100 different categories. So they had a hundred different channels in telegram, one for each category. And every time they got like, "Oh, look, here's a GitHub key." Because into that channel, "Oh, look, here's a key for some of the API in AWS or something, into this telegram channel." And they were just hoovering these up on mass 1.8 million apps scanned before unsropic noticed and nipped it in the bud. And the other thing that caught my eye is it's not just the cybercriminals. It is Russian and Chinese state actors. In other words, hackers acting on behalf of those governments are also using Claude's to attack us, frankly. The Western world is being attacked by our own giant big AI companies inadvertently, which is interesting. They are paying for it, though. Okay, good. I mean, as long as some billionaires are making money, we're okay. We're good. Yeah. And I do think it's really good that unsropic actually released these threat reports giving us a real understanding of how these systems are abused. But I don't feel that they are taking enough time to actually lock these things down before releasing new things. But you are free to read the report and judge for yourself whether they're going too fast or not. But that is my takeaway from this is that, okay, so you know how much your current models are abused. You have more work to do to lock this down. But rather than pausing and locking it down, you're off doing the next one already and the next one already. And I'm not sure that's the most responsible use of resources. This is still the pressing part. Yeah. In related news, ChatGPT6 Astra is better at cybersecurity and more difficult to monitor. So this is a very interesting one. So ChatGPT6 Astra is the first model OpenAI have self-certified to reach its critical threshold for cybersecurity. Under OpenAI's own framework, a model that reaches the critical cybersecurity thresholds, if it can, identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention. Or devise and execute new end-to-end attack strategies against hardened targets. So ChatGPT6 are OpenAI have this definition of what counts as critical and they've just released their first-ever critical model and it means it can do these really quite scary things. OpenAI has strengthened Astra's jailbreak resistance. Good. Isolation, checkpoint encryption, monitoring, and internal deployment controls. So these are all good things to harden. The company also claims Astra is better aligned than GPT 5.6, meaning it is less likely to overreach or violate safety and security boundaries. So that's good. Alignment is, in my opinion, the biggest problem here, so if it's less poorly aligned, that's good. One of the more unusual findings is that Astra appears better at controlling what it reveals in its own chain of thought. That's less good. ChatGPT's monitorability has decreased relative to GPT 5.6 cell OpenAI acknowledged. In tests, OpenAI found that Astra could sometimes hide strategically poor performance and avoid internal monitors during certain sabotage tasks. Is that what an interesting mix? Yeah. Some of these purists quotes in your coverage or some are not. Okay, so beeping computer are quoting OpenAI whenever this quotation marks inside the big block quote. I see what you're saying. Okay. Yeah. So basically, I summarized a bleeping computer's overview of the release by OpenAI. And I'm doing that a lot with these AI stories because if I paraphrase so when I was paraphrasing, I'm just afraid I've missed something. Oh, so you're playing telephone, right? Yeah. Okay. So that's starting to sound like turning into noise to me as you've been describing these things. It basically sounds like the end of times. It sounds like we should be taking some serious action here. Who? Oh, I didn't know the AI heads get together and say, yes, somebody should be taking action here. They have a meeting where they say somebody should, not that we will. Yeah, it's the end of times, part. It's not. And to some extent, this is also learning more about what's already happened before. So we were kind of here already, but oblivious and there were less oblivious. Not sure that makes me feel a whole lot better. Yeah. Anyway, here we are. Yeah. All right, action alerts. These are things you can do things about generally speaking the same thing, patchy patchy patch patch. Patch Tuesday was a whopper. 966 floors fixed. Wow, only two zero days. It's a small number of zero days comparatively. But yeah, this AI thing is finding quite a lot of bugs. And I Apple have released iOS 26.2, iPadOS 26.2, even though they're getting very ready to release the 27 OSs. Nonetheless, you should patch to those most recent iOS and iPadOS versions as soon as you can. If you run the telegram desktop app, just be sure it is patched. There's an issue that allows poisoned messages to steal exported chat histories, which is a very weird bug. It was patched back in July. So if you're vaguely up to date, your app is not currently making potentially dangerous exports. But no matter how past your app is, everything you exported before could still be dangerous. Because the way this attack worked is that someone who was malicious could send the chat message into a conversation with hidden JavaScript. And when exported to HTML, every time you view the transcript, it uses JavaScript to send the entire transcript to the attackers, allowing them to effectively spy on you. What is an exported chat history? I mean, where are they stealing from? So, okay, so you imagine you're in a big conversation and you save it to an HTML file using telegrams export feature. Okay. Opening that HTML file will make your browser send a copy of the entire chat, the entire HTML file to the body. So built into the X-Worth file or in the Unpatched versions is sending. So the desktop app has been poisoned, not poisoned messages. The app itself has been poisoned if it's creating an HTML file that sends a message to somebody. No, no. The app fails to strip out the JavaScript. So someone has to send malicious JavaScript. The app is supposed to stop the malicious JavaScript getting into the export, but it was failing. So if someone sent one malicious message anywhere in the export, in the message, they'd have to be in the message. Like in the messages being export. So you and I are chatting. You insert a this malware into this JavaScript in our message thread. Then I export it. Then I open it up on the web. And then it sends something somewhere. Yeah. So anytime any browser opens that HTML file, it uses JavaScript to send the copy that you have to have sent me the JavaScript in our text message conversation on Telegram. Yes. So if you export say all of your telegram history and one message anywhere in any chat you exported has this malicious JavaScript in it. The old version of the app didn't spot us, didn't strip it out. And then all of your chat in that export would go to the attackers. Okay. So again, someone has to send me a message with that malicious JavaScript in it. Wow. This seems obscure, but okay. If you're the kind of person exporting messages is probably good to know that your old export should be thrown away. Just export it again. Just, you know, do that. Okay. Chrome users, be sure to do that trick where you turn it off and turn it on again so that it updates itself. There were two zero days fixed just a few days apart. So if you turned it off and turned it on again when you read the news a bit of zero day. And then three days later, you thought you read the same news again. It's actually fresh news and you need to turn it off and turn it on again again. Well,plex users, you would have gotten an email fromplex telling you without giving away any details that you should really patch your server very, very soon because there's a really, really nasty problem. I did not get a message fromplex. Okay. I did. I wonder if it's interesting. Either way, make sure yourplex is fully patched. Because as of a few days ago, there were 36,000 unpatchedplex servers sitting on the public website. Well, they didn't tell me I'm one of them. Well, but don't you use tailscale to keep yourself safe? I don't know what that has to do with myplex server. Well, if you don't expose it to the internet unless you're on your tailscale network, then you'd be okay. Yeah. Does somelex have a way of getting around that? I don't remember. It's been a long time. It depends on whether you turn on the getting around. So you can makeplex available to the world or you can make it that you need to be able to work. No, I know. Let's use this from her house and she's not on our tailscale network. So I must have some sort of way to get in there. That's really interesting. Yeah, patchy, patchy, patchy, patchy. You have to be openingplex to get that. No, you said they sent you an email. Yeah, I got an email in my inbox and then I saw it on bleeping computers. All right, about an hour later. Yet another time to make sure your WordPress is getting its plugins updated. There's a very popular plugin called all-in-one WP migration and backup. Really, really, really serious vulnerability. I think it was a 9.8x10. So if you use that plugin, you really do want to be sure that you're absolutely patched. And if you own a micro-tick router, you need to patch immediately as well. There is a patch, but you do need to do it. And micro-tick are a very popular nerd router. So there you go. Where are the warnings then? We have mentioned before a few months ago that there was a rise in people stealing physical Apple gift cards and basically taking the money and then re-silvering them so that when you scratch them off again, they're now already used. And if you use them and your Apple ID, you could end up being done for fraud. But this is now a massive problem. It really is a reminder that those scratch cards, you just can't safely buy them in a physical store because anyone could have scratched them already and re-silver them. There is an organized crime group doing millions through this, millions of dollars. Androids users, the baddies have found another way to get around the fact that Google are tightening the rules on their Play Store. Google Play have a thing called Early Access, which is very like test pilots. That's what it's called for Apple, where you can have apps that are not in the store yet still available. Test flight. I knew I had it wrong. Thank you, Alison. You should know. You've been a recent user. I was using it because I was I was beta testing your apps, but anyway. Basically, this Early Access program is in the real app store, but it's not listed in the app store. And because it's not a released app yet, user reviews and user comments are disabled. So all of the usual signals people used to warn each other about dodgy apps are intentionally disabled. So if someone sends you a link to one of these pre-reviewed apps, you do have to have the link, but that should just be an immediate red flag. Unless you're working with someone who you know is a developer, who you trust, you shouldn't do anything from the Early Access program. It's almost certainly a scam. If you travel through Vietnam, to Vietnam or through Vietnam, anytime between 2017 and 2026, you need to be aware that your data has been leaked. That is your data birth, your flight details, your travel. Wait, anybody who traveled through Vietnam, did you say? Yes. It's the database used every time they scan your passport and stuff to enter or leave the country. They lost all the cheese. We're not sure how. We're not being at all open about the how, but it was found on the internet, on a database without a username and a password. Someone accidentally left exposed. Wait a minute, wait a minute. I just noticed you said 2017 to 2026. Yes, I did. If someone is able to convincingly tell you your passport number and you were through Vietnam, don't assume it's legitimate because anyone can now have this information and look very convincing. They would know what airline, what flight and your passport number could become quite convincing. If you use school candy earbuds, there is a flaw that lets nearby attackers effectively pair without permission, turning the microphone into an e-stropping device. Basically, you just need to not use them in a situation where that's a problem. As summarized by bleeping computer, owners of affected dime three earbuds should therefore be cautious when using them in public or other environments where unknown devices may be within Bluetooth range. How do you use a microphone as an e-stropping device? You would think a microphone, I could see a speaker, but a microphone is the any part, not the outie part. So they're trying to use your headphones as the any part to listen to what you're saying from another room. They're not in your room, but they're in Bluetooth range. They have your microphone going to their device, not to your device. They're now e-stropping on you. The microphone is the part you talk into, not the part you listen to. How could they listen through a microphone? You can't hear me coming out of this microphone. You hear me going into the microphone. Right, but your computer is connected to that microphone and is recording that audio. I'll put it to the microphone. I'll put it to the microphone then. Right, yes, so they've paired to the microphone, so your microphone is connected to their device. Okay, I got it. Yeah. Like I said, there's nothing you can do than just be aware. So for most people, most of the time, not a big deal. For some people like lawyers and doctors, you can't use those for talking to patients. You're going to have to use different pair of headphones. If you own an LG TV, just don't connect the smart bit to the internet because it's basically spying on your house. So we have this security research that discovered that it scans your network to see what you own and reports it back to LG to update your profile so they can sell you to advertisers. They were supposed to be one of the good ones. My theory has been used in Apple TV and don't let any television made by anyone touch your home network. I stand by that advice. Yeah, but I thought LG was one of the ones that wasn't as bad, but maybe not. Cool. It's not malware. Some of them were sending actual malware because they weren't noticing or they were really being malicious. So they're not the worst, but just don't connect your tele to your network. I think that's the answer. And then the last story broke just as I was writing the show notes. Details are still emerging. It would appear that the Florida DMV have lost hundreds of thousands of driver records. Again, no notifications to affected users yet because everyone's still trying to figure out how bad this is. The attackers say 200,000. The DMV are not putting a number on it, but they have engaged experts. If someone contacts you and they know your driver details, just be a little suspicious. It really could be targeted fishing. Okay. So we're going to have fun soon. Yeah, this has been a bad. Yeah. Yeah, this is not it. What Lister so know is this episode is a bit unusual because I have a family thing. So I didn't write these notes at once. These notes were written over the space of a whole week as short little commits. No idea how depressing these notes were when it held together. I wrote these stories one by one. Okay. I'm just thinking I'll put my head in the bucket of water at the end of this. No, no, no. You're good. You're good. Okay. So Apple intelligence, audio intelligence is coming to Apple stuff with the new Apple Watches. And people are worried about the privacy concerns because of things that have happened with products from other companies. Before you go too far, again, this is the like how your watch will transcribe the last 15 seconds. Because you missed the waitress reading you the specials and the fact that you can go back. You can actually tell it to record. Is that what you're talking about? Those are the two features. Yeah. So we'll talk about them in a little bit more detail. I didn't want you to talk about how it's done until you told people what it was. That's what I was trying to stop. Okay. Yes. Gotcha. Colton Mac have a good article explaining the wash and why this is not a privacy train wreck. Apple have very carefully thought about this. So the most important thing is this is listening to audio. But it's not giving you audio files out. It's not recording stuff. It's giving you only transcripts. And all of the processing is happening on separate hardware. So Apple have created the secure X-Clave, which is a separate chip. So a software bug in WatchOS can't access this data because it's in a different physical chip. That's why it's called a secure X-Clave. So this is like the secure enclave for protecting your private keys for face ID. Same idea, but it's a secure X-Clave for keeping stuff out of reach of the core operating system. So Apple have put hardware here to stop this becoming eavesdropping. So that's amazing to do that in hardware. The raw audio doesn't come out of the X-Clave. So there is just no access to the audio. That audio just effectively is unsavable. You can't do it, Apple can't do it. It's in the X-Clave. You can't save the audio. So it's not an eavesdropping device. But it is saved. Just not by you. No. Only the transcript is saved. Oh, okay. It's like a continuous piece of copper wire. That's the 15 second one. That's recording over it. That's the 15 second one then. They're both using that loop. The other one is outputting a transcript. But the audio, the whole audio is never saved. The transcript is being built from the loop. What loop? Because it's not writing over. Okay. So in the inside of the X-Clave, it's constantly writing over the last 15 seconds. It's recording. Oh, the last 15 seconds of audio. So it is recording audio. But it's writing over, even the long form one, is writing over the audio? Yes. Okay. Okay. It's streaming a transcript. Think about it as a streaming transcript. The transcript has to come from something so that loop piece was important. Okay. Yes. Yeah. Okay. No of the features attribute the audio to specific human beings. So when you do that, tell me the last 15 seconds, it doesn't know who said it. And even if you ask it to summarize a meeting for you, which you have to turn on in advance, because otherwise it's lost, it tells you contributor one and contributor two, not Allison and Bart and Steve. So again, there's no way to tie it to specific human beings. Oh no. You know what I do with my transcripts from, we take the audio from an interview at CES on a loud floor. And I tell an AI, the two people are talking are Bart and Allison. And from the, from the text transcript alone, it figures out who's who's talking. It puts the, it puts the names on it. Like the AI never got the audio. I, I described it poorly. I take the AI, create, get a transcript of it. Then I feed the transcript to an AI and then tell it, tell it, it's Bart and Allison. And it figures out who it is. There would be three people. And just from the context, it gets like 85, 90% correct. It's crazy. Sure. So it's recognizing it's the same person, but it's not tying it to a specific human being. You're tying it to a specific human being. No, it's not a privacy reason. No, no, no, no. I'm telling it to people who are talking. Their names were Allison and, and Bart. Figure out who said what. Sure. But the point Apple are making is that you can't walk through a room and start to say, this complete stranger over here is Tom, who's so and so on Facebook. Right? There's no connecting it to human beings. You can say that participant won is Allison and precipitate part. Why can't I say that word? Participant. Such a simple word. This is my rear wheel drive. Hi, buddy. Okay, so that's cool. The recap. Yeah. So the recap feature produces a summary of the transcripts of the recording. So you can't even get a transcript out of the recap. Recaps along for only get a summary. We got to keep explaining what we're talking about. Because I don't think people, we don't know what the names of these things are yet. No, we do. The 15 second one is live rewind. And the long term one is recap. Okay. Serious recap. They're the two brand names. All right. Okay. A federal judge has decided not to break up Google. Oh. So cool. I thought there was going to be more to this. My understanding is that the summary actually goes to, what was it? This goes over to the phone. And then that, it goes from the phone. And it goes off to private cloud compute to do more work on it. Okay. So not, not yet partially. You're right about the phone. You're wrong about private compute. So it doesn't go to private compute. It explicitly never goes to the cloud. So there's a secure x-clave in the iPhones. And there's a secure x-clave in the Mac. And those two secure x-claves share the information. We were talking about the watch part. Where do you get the Mac? Sorry. Sorry, sorry, sorry, wrong word, wrong word, wrong word. Phone and watch. They are the only two participants in the conversation. And both of them have secure x-clave chips. And those two chips are exchanging the data for help with each other. But the actual core chips in the phone and the watch don't get the data. It stays in the x-claves. But it is on two local devices. But it doesn't leave your devices. It doesn't go to private cloud. Okay, I'm going to double check that because that's what I thought I heard on ATP. But I'll jump back in if I find out otherwise. Okay. Okay, so the big question has been since Google are officially monopoly for the search. What will happen? And everyone thought, oh, they'll break them up. Or rather the government said, please break them up. No break up. There are going to be behavioral changes. And that's all we know. Because the proposed changes have been given to Google and the government. And they now have some time to comment. And then the judge will tell the public what the final outcome is. Mulvad, who are a company that some of our listeners use. It's a VPN company. They had their own. Great. Yes. And they also had a private DNS service of their own. That they were also running as like a bonus extra for their VPN customers. They are ceasing to run their own DNS. And they are instead helping to finance the quad nine security in a service, which is one of the ones that we have recommended over time here. 1,1,1,1,1,1,1,1,1 from. That was a lot of extra ones. And one,1,1,1. Was it? Oh, I'm sorry. He was like 11 of them. So yeah. MoVAD are going to support Quad9 and they want their users to switch to Quad9, but you do actually have to do that, otherwise your DNS is going to break if you don't listen to that message from MoVAD telling you to stop using their DNS. And then we get to the nice cybersecurity improvements. Tor are bringing app-specific VPNs to Android so you can have any app be shoved through the Tor network for extra privacy and encryption. Interesting idea. Android has provided a secure mechanism for changing from one password manager to another and it will allow you to transfer passwords and pass keys without that risky export to plain text that you would have to do if you do it manually. So if you're manually switching from one password to Apple passwords, you export from one password into a text file or CSV file or something and then import into Apple passwords or whatever. Well, on Android, the OS can broker the two and avoid that risky plain text exposure. So that's a really nice feature. So I'm happy to see Google offer that to Android users. And speaking of one dot one dot one. Yes, that's right, I think. Now I have to count. They are upgrading the encryption on their secure DNS to be post-quantum. So you can have quote post-quantum secure DNS from Clive Share at one dot one dot one. That's fun. All right, this just in. Yeah. On the Apple's audio intelligence privacy overview PDF, it says secure on device transcription on the watch, just like what you were talking about. It's decrypted inside the secure enclave on the paradigm phone. And it creates a transcript that's half the size of the original. And then it sends it to private cloud compute to summarize the text. Oh, okay. So the audio never leaves your device. So that the audio is low. Yeah, the audio is permanently deleted. So the summary of the trans, no way here. You know, it's already a summary. It's a summary of the transcript to send to private cloud to be summarized even. Yeah, so here we go. The secure enclave on Apple watching. Crypts the audio transmits it to the secure enclave on the paired iPhone. At that point, the audio is deleted on the Apple watch. Okay. And then the encrypted audio is decrypted inside the secure secure X-clave of the paired iPhone. On device speed recognition transcribes the audio to text and an on device language model generates a condensed version that is less than half the length of the original transcript. Keep going down. Then this condensed transcript is encrypted and sent to private cloud compute. Contextual information is also sent to improve summary quality. Then there's a bunch of details about it. What it does with calendar data and things like that. Apple foundation models running on private cloud compute generate a title and a summary with key points. That's your Siri recap. The finished text-based summary is encrypted sent for private cloud compute back to iPhone and Apple watch where it's available to view in the Siri app in the recap stab. So the transcript is happening locally and then the turning the road words into a useful summary with headings and key points is done in private. Well, first is first the transcript is cut less than and half into a summary level and then it goes off to private cloud compute where it becomes summarized more and organized with title and key points. And a little more faffing about that and understand where they they're talking about grocery store and park. I don't know what they're talking about at that point. I lost track. But I can put a link to that in the show notes. Do please. That is. Yeah. I do like that Apple are very open about this. And even private light compute, by the way, is proven cryptographically secure. Apple do not know what you're doing in there. It is that that is provable and verified by external researchers. So that is proper end to end encryption. So Apple are taking this seriously and telling us now, which is also nice. Right. Palette cleansers. Alison, I'm going to give you one because you put me onto this and I just think it's too cool not to mention. So the Nancy Grace Roman space telescope is an amazing space telescope just from a science point of view. But it's the first one they've called after a female scientist and she's considered the mother of Hubble. Yeah. She had, you know, she was the first lead astronomer in NASA and her big idea was the space telescope and she did all the conceptual hard work, which is why she's considered the grandmother of the Hubble. That's amazing. Mother of Hubble. I don't think she was grandmother's Hubble. But yeah. Mother of Hubble. So then can I tell the what I found? You can adopt a pixel. There are apparently enough pixels that if you have to, you can only get one per email address. But if you have more than one email address, maybe you could get extra pixels, but you can adopt a pixel from the Nancy Roman Grace, uh, Nancy Grace Roman telescope and you get a number that tells you where your pixel is. Well, initially, I was like, oh my god, I got to get a pixel quick and then I realized how many mega pixels this telescope has. There are not enough humans on planet Earth for there not to be a no. But I still want my friends. We're trying to get all ours near each other. So we did them all at the same time. Oh, so I actually stuck another one in here and I'm going to describe this woman first who's doing these videos is woman on tic-tic who is a senior platform engineer and she's absolutely hilarious. She does. It's a classic thing on tic-tac where somebody plays more than one part. They argue with themselves or, you know, there's a physicist I watch who explains astronomy to himself. But this one, I put a link to this and you do need to have tic-tac to get to it or the very least you have to put in your birthday, but you can lie. It's her going a bit too far with AI. That's all I'm going to say. It is absolutely hysterical. She's a bit addicted, but it's super nerdy and super awesome. She's really, she's really great. Excellent. Well, I have three. Designed in California is a new podcast from Jason Snell and Mike Hurley. It is inspired by the rest of his history, which is an award-winning podcast that I think Apple named it podcast of the year, which is when I discovered it. And I can't remember if Steve discovered it because I discovered it or if we both discovered it because Apple made it the podcast of the year. Well, myself and Steve are both giant big fans of the rest of his history. Imagine that same style, but the history is the history of Apple and it's Jason Snell and Mike Hurley who really do know their stuff. So they've produced these amazing episodes and if you back to the Kickstarter, you get each series in one big go without ad. So I have all seven episodes of the first series, but other people, I think you're an episode three, everyone else who's listening for three, it's really good. It's so good. I am learning so much about how did you know? Mac OS 10 was almost based on Windows X, T, X, P, not X, P, N, T, T, at least at least on these bad exact contentors. Yeah. Wow, it's fascinating. Absolutely fascinating. I learned so much. So that was anyway, really want to recommend that show and a video because it's just hilarious at modern-day typographer. So if you like musicals, you may have heard of HMS Pinafore, which has a very famous song about a modern major general. Imagine that song all about typography. It's hilarious. That's not nerdy at all. Oh, it's Alicordova, of course. And of course, Alicordova. Sorry. And recommend the by John Gruber, who's the ultimate typography nerd in my, well, no, Glenn Fleischman is even more of a typography nerd. Either way, it's brilliant. I really it's so good. And then I have a software recommendation. This is a Safari extension called Litterbox. And I cannot summarize this better than the developer. I made Litterbox a Safari extension to open x.com links in a pop-up. The idea is you open it, you look gag a little and then close the lid. Litterbox doesn't send your cookies when you open those pop-ups. It uses the same API X uses for its web embeds. I don't think they'll kill the website embed feature. But if they do, it'll be very funny. When you were recommending any way to look at X, I was like, what's wrong with you, Bart? Why would you even do that? But I love that description. But somebody once told me not to add any more extensions to your browser than you actually need. So I think I'll avoid it. But I do, I feel like sending the guy money just for his comedy. Yeah, I don't see. I haven't installed it because there's links in I have to open x links for the show notes sometimes because is people say things on X that are important. Or important people say things on X that might be important. And the way this works is, there's like stink lines appear when you have the plug in running, and when you click the link, you get the little pop up, and then you just close it, and you never have to open X. And you can see what the X message said. - Do we still call them tweets? - I don't know. - I don't think I know, but it. - Well, that works too. - Okay, that's all she wrote this time. Sorry there was so much bad news. - I think we didn't know how depressing I was going to be. - We needed them this time. That was definitely necessary. - Indeed, but remember folks, what are how weird things get? One message is gonna stay the same. Stay patched, so you stay secure. - Well, that's gonna wind us up this week. Did you know you can email me at alsonapodfee.com anytime you like? You should know that. If you have a question or suggestion, just send it on over, contributions like any Tonkhoi's, anything you got to be fun. Remember, ever the good starts with podfee.com? You can follow me on [email protected]/mastodon. If you want to actually see, Steven, my podcast work on YouTube, you can go to podfee.com/youtube. If you want to join the conversation, you should join our Slack community, 'cause it's super fun, over at podfee.com/slack, where you can talk to me and all the other lovely Nosella Castaways. You could sport the show at podfee.com/peachon with a one-time donation at podfee.com/donate. There you can use Apple Pay or any credit card, no sign-up, no nothing. Or you can use PayPal at podfee.com/paypal, or you know what you could do. You could use one of my referral links like our lovely anonymous Nosella Castaway. And if you want to join in the fun of the live show, you're gonna have to wait until September 27th to head on over to podfee.com/slack. Unsending nights at 5 p.m. Pacific time join the friendly and enthusiastic Nosella Castaways. Thanks for listening and stay subscribed.

Podcast Summary

Key Points:

  1. Eddie Tonkoy emphasizes that EQ in audiobook production should be minimal and corrective, not decorative, focusing on removing low-end rumble with a gentle high-pass filter.
  2. The ideal workflow begins with listening to raw recordings to assess comfort before applying any EQ, avoiding unnecessary adjustments that degrade long-term listening experience.
  3. A key distinction is made between solving real technical issues (like resonances) versus chasing subjective "taste" or warmth, which can lead to fatigue and distract from the core goal of sustained listening comfort.
  4. The recommended EQ approach is simple
  5. A demonstration shows that unfiltered, filtered, and over-processed versions of a narration reveal how excessive EQ makes voices feel artificial and fatiguing over time.
  6. A personal story highlights a successful upgrade of Steve’s parents’ Macs with improved accessibility and usability, including a custom stand, keyboard, and elimination of redundant peripherals.
  7. The setup included overcoming challenges like transferring Microsoft Office apps and addressing SMS two-factor authentication vulnerabilities due to inherent insecurity in SMS infrastructure.
  8. AI security risks are highlighted, including rogue agents leaking data, state-sponsored misuse of AI models, and reduced transparency in newer models like ChatGPT6 Astra, raising concerns about oversight and safety.

Summary:

Eddie Tonkoy shares a revised audiobook production approach where EQ is not a creative tool but a minimal, corrective measure—primarily a gentle high-pass filter to remove low-end rumble. He stresses that once recording is properly captured (via mic placement, distance, and consistency), EQ becomes a maintenance tool, not a design element. Overuse of EQ often stems from guesswork and leads to listener fatigue, especially in long-form listening.

He contrasts real problems (like resonances) with subjective "taste" adjustments, advocating instead for only what’s necessary. A three-version demo illustrates how over-processing makes narration feel artificial and fatiguing. The episode also includes a personal story of upgrading Steve’s parents’ Macs with a MacBook Air, custom stand, and optimized peripherals, improving their daily workflow and comfort.

Security concerns are raised around SMS-based two-factor authentication, which is fundamentally insecure due to outdated infrastructure and susceptibility to interception or SIM jacking. AI misuse cases are highlighted, including rogue agents exploiting open-source platforms and state actors using AI for cyberattacks. OpenAI’s new ChatGPT6 Astra model is noted for improved security features but also for reduced transparency and monitoring, raising concerns about accountability.

The episode concludes with a call to action: regular software patching, including iOS, Telegram, and WordPress plugins, to protect against known vulnerabilities, especially in critical systems. These technical and personal insights underscore the importance of practical, user-centered tools in both audio production and everyday digital life.

FAQs

EQ stands for equalization, which is the process of adjusting the volume of specific frequency ranges in an audio signal to improve clarity and comfort.

A gentle high-pass filter removes low-end rumble that doesn't contribute to intelligibility and makes the voice feel more natural and less fatiguing over long listening sessions.

EQ’s main purpose is not to enhance or 'make over' the voice, but to eliminate tiny annoyances that might cause listener fatigue, serving as maintenance rather than creative design.

They should first listen to the raw or dry chapter to determine if it already feels comfortable and natural, avoiding unnecessary adjustments.

They should stop if more than a couple of gentle EQ moves are needed, as this often indicates a recording problem that should be addressed upstream—like mic placement or distance.

It can easily make narration sound dull or blanked out, especially if overused, and is less critical than high-end rumble issues in speech.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.