Dark mode: ON

Infosec Decoded Season 6 #20: WorldCoin

With sambowne@infosec.exchange and Doug Spindler

Recorded Thu, April 23, 2026

AI

Sam Altman’s Creepy Eyeball-Scanning Company Gets in Bed With Zoom and Tinder
Tinder and Zoom announced partnerships with Altman’s World, the company behind the creepy, eyeball-scanning orb that is meant to prove users are human.
Mozilla: Anthropic’s Mythos found 271 security vulnerabilities in Firefox 150
Anthropic’s Opus 4.6 model found only 22 security-sensitive bugs when analyzing Firefox 148 last month.
Florida probes ChatGPT role in mass shooting. OpenAI says bot “not responsible.”
ChatGPT advised the suspected shooter on what type of gun to use, the ammunition he should get, and whether or not a gun would be useful at short range. Troublingly, the chatbot also advised what time of day the most people would be on campus and where exactly on campus he might find higher populations of students gathered.
Anthropic nuked a company's access to Claude, stopping 60 employees dead in their tracks — support via Google Form is the only recourse for vague usage policy violation
Anthropic's modus operandi is to shoot first and ask questions never, with many users claiming they'd been filling the aforementioned Google Form for months now to no avail.
Chinese Workers Horrified as Bosses Direct Them to Train Their AI Replacements
Bosses are directing them to painstakingly document their workflows with the eventual goal of automating specific tasks using AI agents.
Deezer says 44% of new music uploads are AI-generated, most streams are fraudulent
97 percent of users unable to tell the difference between AI songs and ones made by a human.

Politics

Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims
Martino abused his role at a U.S.-based cyber incident response company to assist BlackCat actors.
US opens refund portal to start paying back Trump’s illegal tariffs
Over 330,000 importers paid a total of $166 billion in IEEPA duties
Southern Poverty Law Center indicted on charges that it fraudulently paid informants in extremist groups
“The Southern Poverty Law Center’s ('SPLC') stated mission included the dismantling of white supremacy and confronting hate across the country. However, unbeknownst to donors, some of their donated money was being used to fund the leaders and organizers of racist groups, including the Ku Klux Klan, the Aryan Nation, and the National Alliance,” the indictment alleges.
Sandy Hook Promise and others use anonymous tips to prevent school shootings. Hackers exposed their data
UK bans a generation of children from smoking: How it works
The legal age for buying tobacco products, 18, will rise by one year, every year, from 2027, so those aged 17 or under now will never reach it.

Infosec

Contrary to popular superstition, AES 128 is just fine in a post-quantum world
Grover's algorithm doesn't benefit from parallel processing as much as classical algorithms do, so it will still take 2**104 calculations to crack a 128-bit key.
EU age verification app can be hacked in 2 minutes, claims security expert
By deleting specific values tied to the PIN from the app’s configuration files and restarting it, an attacker can set a new PIN while still retaining access to credentials created under the previous profile.
New npm supply-chain attack self-spreads to steal auth tokens
Received a call from Google that a law firm sent documentation I was deceased? I'm alive!