The Entropy Podcast

Welcome to the Age of Synthetic Reality with Jake Moore

Francis Gorman

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 38:59

In this episode of The Entropy Podcast, Francis sits down with Jake Moore, Global Cybersecurity Advisor at ESET, to unpack one of the biggest technology shifts of our time: the collapse of trust in the digital world.

From deepfakes and AI-powered scams to digital footprints, remote hiring fraud, and the rise of agentic cybercrime, Jake explains how rapidly evolving AI tools are changing the nature of deception and why individuals, businesses, and governments are struggling to keep up.

The conversation explores what happens when seeing is no longer believing, how cybercriminals are already exploiting synthetic media, and why the future of cybersecurity may depend less on tools alone and more on human awareness, verification, and digital resilience.

If you’ve ever wondered how close we are to a world where anyone can fake anyone, this episode is for you.

Key Takeaways

  • Deepfakes are no longer theoretical — they are already being used in scams, impersonation, and fraud. 
  • Trust online is eroding fast, as AI-generated content becomes more realistic and accessible. 
  • Remote hiring introduces new risks, including AI-assisted impersonation and fake candidates. 
  • Your digital footprint reveals more than you think, often exposing personal details that can be used against you. 
  • Cyber awareness is still the strongest defense, especially when technology alone can’t keep pace. 
  • Children need better cyber education, particularly around passwords, privacy, and digital identity. 
  • AI is scaling cybercrime, making attacks faster, cheaper, and more convincing. 
  • Agentic AI and quantum computing could create the next major wave of cybersecurity disruption. 

Soundbites

Here are strong promotional soundbites you can use in Spotify captions, social posts, clips, or episode promos:

  1. “We’ve entered a world where seeing is no longer believing.”
  2. “Your face, your voice, and your identity are becoming easier to fake.”
  3. “The biggest cyber threat may not be malware — it may be trust itself.”
  4. “Deepfakes are no longer a future problem. They’re here now.”
  5. “Cybercriminals don’t need perfect technology — they just need believable enough.”
  6. “Your digital footprint can tell strangers more about you than you realize.”
  7. “In the age of AI, awareness is still your greatest defense.”
  8. “The next scam won’t look suspicious — it will look completely real.”
  9. “Remote work has opened the door to a new kind of identity fraud.”
  10. “We are moving into an era of synthetic reality, and most people are not ready for it.”

Francis (00:04.182)
Hi everyone, welcome to the Entropy Podcast. I'm your host, Francis Gorman. Before we dive in, if today's conversation challenges you, sparks a new idea, or sharpens how you think about the world, don't keep it to yourself. Subscribe, leave a review, and share this episode with someone who enjoys staying curious. Today I'm joined by Jake Moore, a global cybersecurity advisor at ESET, Europe's leading cybersecurity firm based in the UK. Jake researches and analyses emerging cybersecurity and AI threats whilst having a particular focus on future cybercrime.

Jake often shares his expert commentary on major TV networks, including the BBC, IT V, Sky News, and CNN. And often you will see him in newspapers such as The Times and The Independent. He is also a regular speaker on scams and appears as a cybersecurity expert on ITV's Good Morning Britain, as well as a range of other T V shows. Jake, it's lovely to have you here with me today.

Jake (00:53.274)
Well, thank you very much. Lovely to be here.

Francis (00:56.142)
Jake, it's it's great to have you here. I I I suppose you you you you're you're well accustomed to doing these interviews and and and I wanted to get you in because I think you cover a lot of topics that are quite important at the moment around AI and deep fakes. And something that resonated with me qua quite recently was at the weekend you decided to absail down the side of the E said building. Now I don't know if that was for charity or if it was just you kind of were a bit bored on a on a Saturday and and went out for a bit of crack to to scale the building.

But what you said when you posted it on your social media channels, people were kinda going, Well, that's a deep fake, et cetera. Have we already crossed the threshold from reality to synthetic generated material where people are finding it hard to say that actually happened or that is not real anymore? It's AI generated.

Jake (01:43.917)
Great question. And that question actually crossed my mind over the weekend too. So I posted it on my Instagram. And then message after message came in saying, that's fake. That's AI. Stop with this slop. Come on. And I was thinking, well, I actually did. okay, I didn't take the photo, my friend did. At the very top, you can see the Bournemouth beach behind. You can see that we're 11 stories high. I thought it was just me giving a cheesy smile, just tied up in rope.

But no, the first thing people do is they question it. Now, the irony here is it's potentially partly my own fault here. Because all I ever talk about is don't trust what you are seeing or hearing. I've been saying this for many years. The irony comes back on a genuine photo where I'm proud to say, hey, I've been upsetting down ESET for charity. Look, I actually did it. I was genuinely scared. I really was. but hey, I pretended to smile, and there it is. And they question it. And I think, wow.

So yeah, I put it on my LinkedIn to say, look, this is really a genuine pick, but maybe we really have come to a stage where people are questioning stuff, which is actually good, but when it is real, I hadn't actually thought of the the flip side here, where actually it takes away a little bit of the buzz.

Francis (02:59.251)
It it is extraordinary and and I do find it quite funny 'cause I I I do the same thing myself. You know, I spend a lot of times going, you know, trust but verify and you know, all of these these different validation checks and then you do something cool and everyone's like, yeah, yeah, yeah, AI that like. So I I I I I I I do I do wonder what the next number of years are gonna be like. We've kind of crossed the threshold where what what what you warn in terms of a business sense and and being aware for

Jake (03:06.925)
Yeah.

Jake (03:12.717)
Ha ha.

Jake (03:20.013)
Hmm.

Francis (03:26.945)
your commercial environments, you know, d don't don't get manipulated by a deep fake or ensure that if the CEO rings you that you you check one or two things. To now it's happening in the personal world where I was just doing something cool at the weekend. I put it out there, but it's it's it's his social media life is fake life. You know, who's the real who's the real Francis or the real Jake? Like i is there a psychological impact going to happen here off this shift to synthetic generated images

That we haven't fully understood yet.

Jake (03:57.769)
Yeah, I mean the fact we're seeing AI influencers kind of says it all. That we are understanding that there's so much fake stuff out there. I mean, social media has ironically been a little bit fake ever since it started, anyway. It's everyone's best life. But now it can be just adapted to sc maybe a slightly better scene, slightly better weather, I've seen. we are now starting to question it. And actually

It it is a really good sign because if we are able to question it at that time, then that's what we've been trying to teach people about phishing emails forever. it's all about that moment. When you feel a reaction, maybe urgency or compelled to share, then that's the moment we step back and think, is this real? And that works very well in the social world where we don't want to be spreading disinformation and we don't want people to be clicking on those phishing emails, which still work in so many businesses.

Because we know that that's how the majority of entry points are still with phishing emails through a link to something else that by then you're not doing any more checks, and then you go through and and give up credentials and one-time passcodes. So it's it's a really interesting social say time that we're starting to see people question people that they know and they trust. And that is something that I didn't expect to happen. And it ironically, I I think.

From now on I'm gonna actually be thinking myself, will people think this is AI? But I I still can't actually work out why they thought it was AI. Maybe they thought I wouldn't jump off the building. I don't know.

Francis (05:34.73)
Well you proved them wrong there, I suppose. That's J Jake, let let's let's talk about deep fakes. I'm I'm sure that everyone that listens to this show will be familiar with what a deep fake is. But you talk about this quite a lot at at conferences and different things, and you've also gone to the trouble of simulating a deepfake scenario so people can can see it in in in the wild and and what it actually what it actually looks like. Do you think deep fakes

Jake (05:36.489)
Yeah.

Jake (05:41.475)
Yeah.

Francis (06:01.449)
Are only getting into a space where they're going to be used more and more for nefarious activities, or have we already crossed that threshold?

Jake (06:10.155)
Yeah, so the technology has really improved again in the last year. So for the last few years I've been trying to do these deepfake live activities because I've heard them in the news that people have been stealing money from banks and so on. deepfake CEOs, CFOs or whatever. But I personally couldn't use it to the full extent that I'd heard about it. So

over the last, say, twelve months, I've realized that it can now be used with, say, the best knowledge that is out there and the best software that's out there. So, for example, you need a very fast graphics card to make it all look legitimate. Things like that are then improving as we go. So I can actually see now in the next 12 to 24 months that we're going to see pretty much everyone being able to use this software where you can be anyone else.

Whether they are real or fake. Now, in my example, I I created a completely fake person that didn't exist. But this is a time where we never even thought was possible five years ago. We never thought we'd have a fake person going for a a job and then getting offered the job because everything else just seems right. Now in this situation, I was the voice behind it. I wasn't necessarily the brain behind it because I was using Claude Co. to fire up the answers for me that was listening for questions. So I didn't really have to think too much.

I didn't have to look the part 'cause I could use the AI software to see and track my face. But really as it was me, it made me think maybe in the future the whole process will be something else. And whether that be an AI thinking for itself and getting a job, that's a a very wild science fiction thought that is becoming fact very quickly.

Francis (07:59.598)
See th that is super interesting. Using Claude as kind of your your knowledge base in in in the back end. Did you have to create some human intrinsics to cover the delay on Claude as a hmm, great question. Let me let me think about that for a minute. Or did it was it seamless? Was it was it rapid fire?

Jake (08:11.927)
Yeah.

Jake (08:15.911)
So when I tried this with 11 Labs via HeyGen last year, I did have when I was testing all this software out, there was a lag. Yes, that that and that's when I thought I would say exactly that. I would say, yeah, great question. let me just, you know, think of the right answer or the or the best scenario to give you. But it it improved. So I I put this together on Claude Code. It helped me through it. In fact,

I designed the whole process for with it in mind for salespeople. Because I'd heard that salespeople follow a manual, roughly, and they get questions and they see it on screen, then they go down to the next level of of that answer. and sometimes people in customer services are are following a manual as well, and maybe they'll only give out X certain refund once they've hit certain I don't know, time in a in a reply.

So I I built that in mind, but then I realized I could actually use this in an interview process. So every time it listened for a question, I I could design it so it would come up with three bullet points of things to say that weren't too good. 'Cause I was going for a job where I pretended I only had two years experience in this area. So I didn't want to be perfect. I was genuinely nervous. So I I needed that support and it really helped with those nerves, especially when I realized I'd only had two interviews in my life.

One at the police force 22 years ago and one with ESET eight years ago. So now having this support, it made me think that well, anyone could use this, regardless of a deep fake going for a job. These remote interviews, they can spin up very good answers that would potentially get you through to another interview. And whether that gets you to a live interview, if they're doing that, then that could be a tool that people will use.

Because AI is available and that's very difficult to mitigate against.

Francis (10:12.311)
There's just one thing that jumped into my mind when you're talking about GPUs there and, you know, the the kind of the technology stack you require to create a good deep fake. Does cloud not eradicate that barrier? Can you not just spin up something in AWS that has mountains of compute power and, you know, use that to generate the video and and and the synthetic voice as as you correlate through your video call using some sort of a an Azure virtual desktop or something?

Jake (10:36.641)
That's a gr that's a great theory. No, I didn't go that far into it because the software was available. Well, I tried it on my my home PC is is good enough, but it it still had the odd glitch in it. And in fact, it kind of it kind of made it look real. In fact, the funny thing is when I actually changed to my super fast laptop, like what specifically for lots of deepfake ideas, in fact the camera was so good.

That I had to dumb down the resolution when I went through Teams because it looked too clear. So I actually reduced the resolution. And then I because I mean my my first experiment, I was doing this with actually me, but just my face being swapped. So classic face swapping technology. And that was interesting. Blur in the background, it's me. and if you go and put your hand over your face, the funny thing is it actually pauses the video. It looks like it's a glitch, so you can still talk. So I

you can see me now, but listeners might not see. But if I cover my face now, it it it shows me still talking. But what happens is when it comes up to cover the face, it pauses just before and it glitches. It doesn't move. And then when you move your hand out of frame, it goes back to real time. That was an interesting little addition that I saw over the past few years include. But yes, if you were able to bring in more ideas to this, yeah, going through AWS and and the cloud, then it it probably could.

But where I'm seeing this move is the software is is offering these extra features that in fact over time it will move away from our machines and using however many tokens you want to spend on this type of thing, it's just going to improve and we are going to be well struggling to spot the difference.

Francis (12:26.733)
When when you put your hand up there, Jake, I had to count really quickly just to make sure you did have five or four fingers at a tongue, not six. So it's I can confirm Jake is who he says he is right now. Theoretically.

Jake (12:31.009)
Yep. There we go. Yeah.

Well, you say that my gosh. The the funniest thing is in my testing, I said so I was an avatar guide created of this female, and I I've got this software called Voice Mod, which is moderation technology that changes your voice into a female voice. I was speaking to my friend in my testing, and I bring my hands up, fing across my fingers, and I say, Wish me luck. And when I did that, my hand that you are seeing right now.

didn't appear. So you'd hope maybe it's the female Avatar's hand, but it wasn't even her hand. It didn't even look like a hand. It it looks very much like a bear claw that was just so strange. It honestly made me laugh. And I clip it and actually put it in my presentation to show everyone that we're in 2026. And you know what? What you point to is hands are still struggling in real-time deepfakes. Again, it's not something I would recommend people look at and

say get them to wave because in the future it'll go. But right now we're still seeing those problems. And I find that funny.

Francis (13:40.878)
It is it is hilarious and all the different pictures I've seen over the years are are are humorous to look back on and see how they've they've tried to improve them. J Jake, if if I'm a CEO or a board member or someone in a high position chief financial officer within a an in a company, and I'm listening to this conversation and I'm hearing about the hypothesis that

Jake (13:45.911)
Yeah.

Francis (14:02.067)
Soon enough the barrier will be gone and anyone can assume the identity of anyone they want and can sound like that individual, can look like that individual, etc. What safety guards can they build into their checks and balances to prevent them from getting scammed or manipulated or allowing a nefarious actor access into their business through employment, avenues, etcetera? Is there anything that you can you can look at and go, these are the things we need to start building in as hard checks?

Or is that a is that a dead landscape already?

Jake (14:29.63)
Yeah.

So it's a question that I think a lot of big organizations are thinking about, especially when they come to remote interviewing for remote jobs where they don't actually meet those people. And I've speaking to many big companies in the last six months specifically on this, and they say that they just have this problem and it's something that they can't really get rid of. And s and so I say to them they really should be thinking about meeting them at some point, even though one massive retailer said to me that they employ people in India, for example, and they can't.

But they were looking into employing a third party to go and meet those people that are in said countries. and that might seem like a very laborious get around this this problem. But we do have to start thinking about these extra issues. So I say that anyone who's interviewing, I would always put on the job spec that there will be a physical meet at some point along the chain of interviews before they hand over anything.

no money will be sent into any bank account and no laptop will be handed over until there's been some sort of physical meet. Because we do need to pull back on this because there is that worry. The extra worry after that is in fact probably not the video calling. So if if we go away from say interviews and talk about internal communications, we don't tend to have too many video conversations where we're saying, it's urgent. I need something now. I need that password, I need that bank account.

There's details. It that doesn't feel real. You might get that on a phone call though. And you might actually get that even more so through another messaging platform where it's I need it quick. And we don't tend to jump to teams for something that's immediately quick. Some people might, of course, and so back of their mind they should be thinking about it, but it's still the traditional methods, and criminals are very lazy still. So they will look at the easiest way for them. And video calling using a deep fake is actually a lot harder.

Jake (16:29.069)
Than pretending to be someone through another channel where they've already let down their guard. So it in it basically includes all messaging platform to verify who you are speaking to. There are companies out there trying to do this to authenticate those people on both end, A and B, but really if we can do that through other channels that we are already used to, and you get that phone call that says, I need something, you say, okay, but I'm now gonna pick pick up that conversation through a different channel. So if it comes in through Teams, it then goes out through Signal or through.

the landline to their office. It because if something doesn't feel right, we just just have to think about or not normal. We have to then think about those other alternatives to prove who those people are.

Francis (17:10.381)
It's interesting to break the break the medium and see does that break the the chain, especially. Yeah. It's it's yeah, I'm sure they're gonna get around that as well though, if you get a if you get a foothold on an organization you can hook your clawed agent into the back end and then become all assuming of of every channel, which is gonna be a major headache. But we won't get we're not there yet. So we let's not let's not hypothesize too much. It it is probably coming. Jake, y y y you mentioned there you you you spent the first half of your career working in the in the police force.

Jake (17:27.765)
Yeah. It's coming. Yeah.

Francis (17:39.403)
When when you look back on cybercrime then to what we're seeing now, has there been a shift change or have things just evolved naturally? What what's the what's the difference you've you've seen from the the investigative lens to the to the private world?

Jake (17:55.213)
Great question. how things have changed has been a steady line. I think we definitely predicted where we were going, but what we didn't have any control on is how much input the government would have into that investigation. Because the money is not there for particularly the UK government. And we have we were telling them fifteen years ago that there are these issues that are coming. Moore's law was one back then. We were talking about

you know, the size of data, you know, each couple of years it's going to double in data. So we're gonna have really think about what we investigate when it comes to digital forensics, let alone the capacity of cybercrime. And I was there for the birth of the dark web, VPNs and crypto. And they really threw a massive spanner in the works. In fact, so many spanners in the works that made it an absolute nightmare. And we had to really step back and think, how on earth are we going to to look into this? We can't be

Giving all of our data back, sorry, all of the laptops back and other hard drives just because we can't get into them, because encryption's so good. And the fact that encryption was blocking so much of what we could see became a major problem. But really the the greatest tool that we as humans have is that awareness. And we were giving out awareness to the public from the cybercrime team, from a very unbiased organization that's nothing, we're not selling anything at the police.

And I tend to do that a lot still now. As I speak to these companies and go, look, this is the awareness. This is actually your superpower. It's to question stuff because they're only going to get better. The distance between cat and mouse is huge. We're not going to prosecute all these criminals, even though the public gets angry that the public sorry, that the criminals aren't getting caught. And you have to even if they do get caught, we're very rarely hearing those stories where they actually do time in prison.

Because the evidence might not be there because again, they've been using encryption and the dark web. So we have to put the onus back on us, which is a real painful side part to this whole area of crime, which we're not used to. It's like saying, you know, we just have to go and fight the attacker who's got a knife coming at you. That doesn't feel right. But in cybercrime, we kind of are having to say, look, they're gonna get they're gonna attack you. So these are the best tools you've got, and the best one is to just

Jake (20:21.813)
stand back and be aware of them. But it just sounds like we're powerless. But hopefully more and more people learn.

Francis (20:29.527)
Talking about learning, do we need to change how we teach in our schools to make cyber security and cyber awareness far more prominent within the curriculum? I know within Ireland where we're not very tech heavy, yet all of those students will eventually grow up to take a majority role in technology spaces, whether it's IT or security or software development or or whatever it is, but yet we don't seem to prepare children

Jake (20:53.794)
Mm.

Francis (20:59.573)
For the world that they're living in, because i if I go to a restaurant now and I sit down and there's kids at a table next to me, 80% chance they've got an iPad in front of them. And they're they're already doing something that the parents are are unaware of in some world that they're not familiar with. How how do we how do we change the narrative that we get people more informed and it's not just a box that distracts, it's far more powerful.

Jake (21:08.597)
yeah.

Jake (21:14.787)
Mm.

Jake (21:24.141)
So I think the difference here that a lot of people often forget about is tech and cyber are still very different. Kids at one year old can use tech. They by two, they know how to swipe. and by three, they're playing those games. And we look at that and go, Wow, that's amazing. But really, is it? It because they're designed for e every age, from one to a hundred and one. And and that's the beauty of technology, especially with touch screens.

And so it's about cyber, but we can't teach cyber until the the schools have got behind it. And it's it's only in the last say really ten years or less that they've started to attack the whole subject of online bullying and other issues which they might incorporate in this whole cyber world, but they're about the social things that have been enabled by the internet.

such as bullying. And of course that needs a lot of support. Absolutely. But when my kids have gone through school and they've been t given a password to get into their, let's say, Google Classroom, and it's the first three letters of their first name and the first three letters of their second name, and that becomes their password, you then realise that they're not teaching them about passwords from an early age. Because now I know every single kid's password.

in that class and probably that school. And therefore they've missed a massive trick there. That should have been the moment they said, whoa, just before we actually log you in, we're just going to give you a lesson on passwords. Everyone come up with something? Great. Don't share it. Brilliant. And you're not able to use that elsewhere. They would have to make it a dumbed down version of that. But that's the essence of the first step towards a password manager. And then you teach them all the way through. Because I guarantee there are kids out there.

That are now not kids, that are now in their young twenties. And and anecdotally, I know this has happened, where people are in their young twenties and they still love that first password they got in their first year of high school. Year seven, boom, they got given their password. They love it. It's stuck into their head because it's whatever, and they're still using it because they can still remember it without a password manager. And that's where it inherently falls apart.

Francis (23:49.314)
It's human nature, isn't it though? It's the it's the easy the easy track. It's a very good point, Jake. I I I I often thought about the cyber education aspect, but s breaking it down to a to a macro level in terms of here's your password to your Moodle or your Google Classroom or or whatever the technology is. And then they give them an awful password to start off with that as you said probably follows them for the next decade or more until, you know, eventually something bad happens. Ca can we talk about digital footprint? I

Jake (24:05.922)
Mm-hmm.

Francis (24:18.347)
I think when we were talking the last time I was telling you I I watched your video where you upset one of the the news anchors t telling her about the dangers of of where you post and the pictures and the information that comes back from those pictures, etc. it's it's such an important topic though. People don't understand the level of metadata that is encapsulated in what they share online and what that can lead to. Can you just talk the listeners through that scenario and and and what it revealed to

Jake (24:38.338)
Yeah.

Francis (24:47.201)
To that lady that that that you were sitting down with.

Jake (24:48.385)
Yeah. So yeah, she's an actress and she was asked by ITV if I could go and do a deep dive into her data and and she said absolutely yes, I give you full permission. why not try and find out where my kids go to school? And I thought that would that'd be a a great way to prove to someone that their data is out there. And she's effectively an influencer as well now, so she lives on her social pages and gives away a lot of information.

But she was to to give her her dues, she was very good at blurring her kids' faces, blurring her kids' emblems on their school jumpers and outside the school. So she was trying to make it difficult. So it wasn't a a case of, if you just look at exhibit A, here is where your kid goes to school, because it's your first image on your Instagram. Adds to a little bit more. In fact, I used a lot of AI to to help me. long story short, I was able to find where she lives, the kids' schools.

the kids' birthdays, passwords that her and her husband had used, and and in one case were still using one of. everything because everything's on the internet. If you know where to look or know what tools to use, it makes it very easy. And and people don't think they're going to be targeted specifically. And luckily most people aren't, but it does raise it once you become a little bit more well known, like this actress with say a quarter of a million followers.

And it it's just a way of reminding people that actually a lot of information's out there. and a lot of it's not behind a paywall, even. It's just freely available. and so yeah, I was able to use an AI tool to unblur some parts of the image of the ones that that were trying to hide the school that her son was at. and that actually took me on a route to then find out where she lived. and then when I showed her.

I didn't expect her to start crying on TV. I didn't know what to do. the producer loved it, but I was sat there panicking, thinking I've just made someone cry live on TV. But the essence of what I was doing was to really prove that point and hammer it home that we need to be thinking about what we're putting online.

Francis (27:03.479)
It's so true. I suppose I suppose the the realization of the amount of exposure that you've given away on on unknowingly, I suppose it creates that that emotional reaction. But but it is it is really important for people to understand that every picture you take and every post you put up does leave that digital footprint. S speaking of digital footprints, Jake, when when you look back on your experience in the police force, when we get into modern day forensics

Has that now become a minefield to be able to differentiate between AI-generated images, AI generated content, et cetera? Because if if I look at this myself, say if I create a document using Claude, and then I copy it into a different Word document, I I immediately get rid of the Python Pie differentiator that allows you to say that was synthetic content. Now it just looks like Francis created a document. Like, how easy is it how I mean

Jake (27:58.061)
Mm-hmm.

Francis (28:01.803)
I know it's easy to generate the content and to probably trick the systems because they're not f that that lineage isn't isn't there currently. But how difficult will it be for forensics teams to trace that back to go, actually that's false that's false document, that's false image, that's that's not like is is that a minefield in and of itself now?

Jake (28:20.513)
Yeah. We can't ever say a hundred percent in this area though. So you'll get a percentage of a confidence score. And there are lots of deep fake tools out there that will look at images and videos. And I've used a lot of them. And sometimes they say 99% sure this is a deep fake. Interestingly, I've always kept those and then I've used the same tool a few months later and and then got the a brand new image that I've created that I knowingly have created through complete deep fake technology, put it back through.

Stripped it of the metadata, because that's the one thing that they definitely do look at, and then it's say, we're confident this is actually a genuine image. Or in fact, it'll always say a 1%. So it then flips it completely the other end and says, Yeah, we we think this is only 1% chance this is a deep fake, even though I generated it. it's even harder when it comes to text because every time we're talking to AI, it learns from us. Every input, it learns how to better output. And

We're talking about billions of lines of data that's going into it. we might be able to spot it ourselves, but only if we have context, usually. So if I know how you write, and then I see something that's written by you but it didn't feel right, then I might know something to base it on. Something's odd about this. You never normally write in bullet points, but now you are. That's a question that only a real human kind of spots. Whereas those typical word

Collections that we see that AI tends to do will just wane off over the next few years because we're spotting them. The ones that will just say a few words together. The unbearable truth, for example. It's something that we weren't saying many much. If you look back at, say, how Texas evolved, but now it's seen a lot more. It's not this actually that's the problem, it's this. That kind of format.

that we're seeing a lot more of. But then that changes. So it it it's really difficult. And I do use a lot of AI detection tools on text that I see, particularly through, say, white papers and so on. Because if I don't want to be reading something that I think is AI, and I think a lot of people are equally the same, because it loses that respect in that document that you're then reading, that it didn't actually come from the person that stuck their name on it. And so we don't want to kill it.

Jake (30:48.353)
So I think we're just in that transition phase and we don't really know where it's headed yet, but it it's definitely in that change now.

Francis (30:55.041)
Yeah, i it's it's a brave new world. I'm I'm even looking at, you know, Claude Fable since it came out and its its capabilities with with Claude Code. You can literally envisage something and have it created within a thirty-five minute, you know, time span and then and then retrospectively improve it till you know you burn through your entire salary on tokens, but that's a different problem.

Jake (31:00.215)
Hmm.

Jake (31:03.704)
Yeah.

Jake (31:14.723)
Pretty much. Well, you know what? Over the weekend I was testing Fable and I had four occasions where it said, We're not carrying on with this because I was saying it was for research and it actually what I've realized, it's it's got a lot more guardrails in than I assumed. 'Cause of course Claude Mythos is this big worry. So they give us Claude Fable and I guess what that really is just doing is saying, you've thrown the word security in there and I I'd change it. I mean I put cyber research, I put

security researcher, all these things, it would run off and then five minutes later it says, I'm not carrying on, which I hadn't seen before. So that's an interesting change. Of course I could then just go to Grok and say, Can you do it for me? And it goes, Yeah, don't worry.

Francis (31:57.462)
Yeah. Yeah. Here's here's the schematics to a missile, yeah. I am grok. Yeah, yeah. It is it is it is hilarious. Then you look at the Chinese models and they're starting to get benchmarked on on par as well. Which which which which leads me to to a question that I've been really playing with. I would say very much so in the last three months, and it's vulnerability versus exploitability. Are you seeing a shift change in the companies you're working with where

Jake (31:59.181)
What do you want? Yeah. Yeah.

Jake (32:08.734)
Yeah. Yeah.

Francis (32:25.921)
the amount of vulnerabilities have become avalanche levels. Like they're the it's it's it's it's getting out of control. You go to do a build and deploy and next thing the tools are lighting up like a Christmas tree going. You've got 70 vulnerabilities, 100 vulnerabilities, you fix them the next day you go and another 30 and the production teams are are are losing their minds. But nobody's talking about exploitability. Okay, yeah, you've got 70 vulnerabilities in the base image or in that piece of code, et cetera. What is the exploitability of it?

Jake (32:37.409)
Yeah.

Jake (32:44.939)
Mm.

Jake (32:52.835)
Mm.

Francis (32:54.881)
Has has vulnerability management taken a step turn with the amount of vibe coding and synthetic code and tools like MITUS and Glasswing projects that have just unearthed a mountain of vulnerabilities, but not necessarily exploitabilities.

Jake (33:01.459)
Mm.

Jake (33:07.127)
Yes, great point.

It is is a brilliant point, and we're living that right now. So these huge companies and the banks in the UK that are playing with these projects are learning very, very fast. And we've opened up to the world to go and test out and find those issues, and they're doing it at scale. And I think that's actually what we're noticing more is that scalability really

panics everyone. What we may see is the production of software slow down actually. Because you if you look back at everything, let's take take IoT for example. IoT has always been designed to just look good and work straight out of the box. Who cares about security? Just press this button and way, you'll have everything connected in your house. Your fridge freezer will be buying you milk by the weekend. It's the best thing ever. And no one gave two hoots about the security because

They didn't want to spend the extra money or time in building that in. And there's someone at the top saying, get it out. It's Christmas coming up. We need to sell these. So we've had that force from majorly IoT, but really with other software. Whereas now we're having to slow down. Patching, slightly different. We're probably not going to see the bigger updates from Apple every I don't know how well every year they've got the new iOS, but

every so often they're they're waiting to do the bigger ones. In fact, only last week they did introduce a quicker update because they noticed these extra issues they've got with them. We might just see that happen more as well. And I don't think we can blame them if they do take longer to produce what they want because an app or a service is not as good as they say it is if it isn't secure. So they do have to get that right, even though they're being forced to get on it quick because they need to sell whatever they're making.

Francis (34:59.403)
Makes a lot of sense. I I think again it's another watch item we're gonna have to look at over the coming months and see where it where it goes. Jake, before we finish up, can I ask you you've been in the industry quite quite some time now. You you've seen it all from both the the public and and private sectors. If if if you look out across the next three to five years, what worries you most?

Jake (35:04.065)
Yeah.

Jake (35:21.301)
I am currently just playing more and more with agentic AI and the way it can be used worryingly maliciously. I think if we talk at the three-year mark, that's what's worrying me now. At the five-year mark, I'm gonna just throw in a little dollop of quantum because that is when we start to really see a big change. And I'm saying five, maybe to seven years. So at the at the beginning of this.

We're seeing this is uptick in agentic scam scale attacks. But if we throw in that power of quantum computing, which let's face it, it really is on its way, that I think together we've got a cocktail of potential disaster. So we need to get ready now and to be quantum ready and to be agentic ready, scam ready, and get everyone on board.

But unfortunately, so many people at the top stick their heads in the sand and think, that's too big and I might be retired by then.

Francis (36:28.077)
Like that. And and we we nearly went an entire entropy podcast episode without anyone mentioning quantum, but now you've brought it up. So we're we we we we haven't broken the streak just yet. The the the the quantum thing is actually really interesting in terms of I've been in a number of demos lately with some of the big players, IBM and others, where they're using quantum computing in its current form to sharpen

Jake (36:33.079)
Nearly.

Jake (36:39.149)
Hmm.

Jake (36:49.059)
Mm.

Francis (36:54.529)
the AI models and algorithms to run on classical systems. So they're already kind of fine-tuning heuristics and and different parameters to to sharpen those models up because they can look at them in a slightly different mathematical way. Now, you know, this stuff kind of blows your head when you get into the into the nuances of how it all works. But as that improves, you're gonna see what you just said there, the agentic level and and large language models

Jake (36:56.428)
Yep.

Mm.

Okay.

Francis (37:21.803)
Being applied to much more niche use cases after being fine tuned elsewhere, but run then on the classical systems, which in itself is going to be a step change from what we're used to at the moment.

Jake (37:31.075)
Massively. And that is the major worry at the moment. It's not just the, you know, h harvest now, decrypt later scenario. We're we're actually starting to see, like you mentioned there, that connection. And when they have got the compatibility between AI and quantum, it might genuinely sound like it's science fiction. But when when they do get together and they inevitably will, we're gonna have to be ready for it. And I just don't think

The big companies are ready and the small and medium size are definitely not ready for this. And if we then can't trust communications, we're gonna have to restart the internet on a completely different base. And so we do need to get that right now. But everyone's trying to sell the latest cool app that is AI powered because it sounds cool because marketing companies have just gone crazy over the term AI.

Francis (38:28.108)
I think Jake, on that on that note, we'll we'll finish up. It was an absolute pleasure having you on. I really enjoyed the conversation. A lot of insights in there for the listeners. And thank you for taking the time out to speak with me today. Thank you.

Jake (38:39.105)
thank you, it was great.