In Memory of Man Podcast - Robot Crime Blog
In Memory of Man Podcast - Robot Crime Blog
It Was Never Intelligence. That Was the Point.
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The word “intelligence” was never neutral. It was the sales pitch.
This episode argues that the systems sold as artificial intelligence are not minds, thinkers, or neutral judges. They are privately owned prediction and sorting machines trained on human data, wrapped in language that makes people trust them, defer to them, and surrender power without asking who owns the system, who profits from it, or who answers when it is wrong.
Name the machine correctly before it names you.
Imagine waking up tomorrow and your phone is um functionally useless. Like it isn't broken, the screen works fine, the battery is full, but every single time it rings, it's a perfect clone of your mother's voice begging for bail money.
SPEAKER_00Right. A total nightmare scenario.
SPEAKER_01Exactly. Yeah. And every text message is this hyper-personalized scam from someone who, you know, sounds exactly like your boss or your bank. And the thing is, according to the people who actually build and run the internet, we are exactly 90 days away from that becoming our permanent reality.
SPEAKER_00Which is wild to think about because for a long time we've thought of our phones like our own private little castles, right? Like the open internet out there, the social media feeds, the search engines, random forums. That was the Wild West. We expect chaos out there.
SPEAKER_01Yeah, totally.
SPEAKER_00But your text messages, your direct phone calls, and your personal email inbox, that was the inner sanctum. The assumption has always been that there is a moat around your personal data.
SPEAKER_01Right. You control who has your number.
SPEAKER_00Exactly. You control who you text, who you give your email address to. It feels contained. And that creates a really um false sense of security.
SPEAKER_01Aaron Powell Well, the source material we are diving into today argues that the drawbridge is permanently down. We're looking at a really fascinating field guide by Robert Keisling. He's a Texas trial attorney who writes for robotcrimeblog.com.
SPEAKER_00Highly recommend his stuff, by the way.
SPEAKER_01Yeah, it's great. And this is a follow-up to a widely shared piece he wrote about the death of the open internet. He points out that the public web, you know, search engines and publishers has already been hollowed out by what is being called the slop economy.
SPEAKER_00Right, the slop economy.
SPEAKER_01Right. But that was phase one. Phase two is happening right now. And they are coming for your private web. They're coming for your text, your phone calls, your inbox.
SPEAKER_00We are witnessing a fundamental shift in the digital landscape here. And really our mission for this deep dive is to get you ready for it. Keislink's piece is highly pragmatic. It's deeply unsettling, but most importantly, it is actionable because we aren't here to just, you know, doom scroll via audio.
SPEAKER_01Right. No doom scrolling allowed. Okay, let's unpack this. Imagine a hurricane is sitting just offshore. We cannot stop the storm from making landfall. The weather patterns are already set, but we absolutely can board up your windows so the debris bounces off you instead of, you know, tearing street through your living room.
SPEAKER_00I love that analogy. And the objective today is twofold. First, we need to examine the underlying mechanics of this new wave of AI-driven spam. We have to understand why it is happening right now and the specific ways it operates.
SPEAKER_01Gotta know the enemy.
SPEAKER_00Exactly. Then for the second half, we are going to walk you through building what Keislin calls a 30-minute bunker. It's this highly specific checklist designed to protect your digital life for the next six months.
SPEAKER_01Six months of breathing room. I mean, I like the sound of that. So let's start with the thread itself. To understand why we need this bunker in the first place, we have to look at the massive shift in the economics of spam. Because the insiders are terrified right now.
SPEAKER_00Oh, they're absolutely terrified. And Keisling brings the receipts to prove it. He highlights a public prediction made by Nikita Beer. He's the head of product at X. Right. And Beer's literal full-time job is stopping bots from eating that platform alive. He is the guy who built the machine, and he is out there telling the public that the machine is losing. Wow. Beer predicted that within 90 days, all the channels we thought were safe from automation. So iMessage, phone calls, Gmail will be so flooded they will become functionally unusable. And he admitted they currently have no way to stop it.
SPEAKER_01That is a staggering admission from someone operating at that level of the tech industry.
SPEAKER_00Yeah.
SPEAKER_01I mean the numbers Keisling provides to back this up are just wild. Beer's team suspends 208 bot accounts every single minute.
SPEAKER_00Every minute.
SPEAKER_01Yeah. They purge 1.7 million accounts in October 2025 alone. And then, 48 hours later, the accounts completely respawn. To use Keisling's analogy, he's a firefighter with a garden hose pointed at a forest fire.
SPEAKER_00Yeah, that's exactly what it is.
SPEAKER_01Well, wait, let me push back a little here. Because I already get what feels like a hundred spam calls a day. You know, my phone is constantly ringing with those extended car warranty scams. Is it really going to get that much worse than what we already live with?
SPEAKER_00Yes. And the reason it is about to get exponentially worse comes down to the underlying economics. In the past, running a spam operation required capital. Trevor Burrus, Jr.
SPEAKER_01Right. You had to spend money to make money.
SPEAKER_00Exactly. You had to buy expensive autodialing software, or you had to hire a massive call center overseas. The cost wasn't zero. But that has fundamentally changed because the tools to create highly sophisticated spam are now free and they're open source. Keisling points to a massive catalyst that hit the ecosystem, a piece of software called OpenClaw.
SPEAKER_01Oh yeah. Here's where it gets really interesting. OpenClaw launched in late 2025. It is an autonomous assistant software. It's totally free and it runs locally right on your laptop. You just give it access to your browser, your email, your messaging apps, and it acts on your behalf, reading, replying, drafting, sending around the clock. And by April, it hit 300,000 GitHub stars, making it the fastest growing open source project in history. The author notes it beat out massive projects like React and TensorFlow.
SPEAKER_00Which is a profound milestone. I mean, really think about that.
SPEAKER_01Aaron Powell Wait, actually for the non-coders listening, what actually are React and TensorFlow? Why does that comparison even matter?
SPEAKER_00So React is the fundamental architecture behind Facebook. It's the framework that allows modern dynamic websites to function at all. And TensorFlow is Google's brain for machine learning.
SPEAKER_01Okay, so heavy hitters.
SPEAKER_00Massive. These are foundational billion-dollar corporate behemoths built by armies of the smartest engineers on earth. And a free open source bot designed to autonomously navigate the web just shattered their growth records.
SPEAKER_01Because the barrier to entry has dropped to absolute zero. Instead of needing a server farm, literally anyone with a basic laptop can download OpenClaw for free, point it at a phone dialer or an iMessage API, and run a thousand message a day operation by sundown.
SPEAKER_00We are watching the democratization of a highly malicious threat. And to understand what this looks like when it is unleashed at scale, we can examine what just happened to the open web right before this technology trickles all the way down to your personal phone.
SPEAKER_01Yes, let's talk about pushbaganda. I know it sounds like a ridiculous sci-fi villain, but it is a very real, very modern threat. Security researchers at a company called Human exposed this massive AI spam ring. And the scale is almost hard to wrap your head around. They generated 240 million ad fraud bid requests across 113 domains in just seven days.
SPEAKER_00The mechanism of this attack is incredibly sophisticated. It goes far beyond brute force hacking. It relies on a very clever, self-sustaining, malicious loop.
SPEAKER_01So wait, let's break down the mechanics of this because I think people hear ad fraud and their eyes just glaze over. How does a bot looking at a fake website actually steal real money?
SPEAKER_00Okay, so it exploits the automated nature of modern advertising. When a brand wants to run an ad today, they don't call up individual websites anymore.
SPEAKER_01Right, nobody's calling the New York Times directly.
SPEAKER_00Exactly. They put their budget into a massive automated exchange. When a user loads a web page, an auction happens in milliseconds to serve an ad to that specific pair of eyeballs. So the spammers behind pushbaganda set up hundreds of totally fake AI-generated websites. Oh wow. And then they use bot networks to simulate millions of fake human visitors, loading those pages, triggering the auctions, and siphoning the ad budgets directly into their own pockets.
SPEAKER_01That is insane. They're essentially building fake billboards in the middle of a digital desert, driving fake AI cars past them, and charging real companies for the view.
SPEAKER_00That's a great way to put it.
SPEAKER_01But the way they lured real people into this trap is even more insidious, I think. First, pushpaganda hijacked Google Discover feeds with AI generated fake news. It was total clickbait, but hyper-optimized to manipulate the algorithm.
SPEAKER_00Right.
SPEAKER_01Once a real user clicked and went to the site, the site would trick them into enabling browser notifications. You know those little pop-ups that say allow this site to send you notifications? The worst. Once the user clicked yes, the trap was fully set. They use those browser notifications to bypass the email inbox entirely and deliver fake legal threats and financial scams directly to the user's desktop or phone.
SPEAKER_00It perfectly illustrates Keyslink's concept of the collapsing internet floor. The fundamental economic engine of the internet used to be humans clicking on human-targeted ads. That paradigm is just over. Now we have AI writing the clickbait, AI clicking the bait to generate fraudulent ad views, and the AI operator is caching the check.
SPEAKER_01The machines are playing both sides of the game, and human attention is just the collateral damage. And sure, Google eventually patched the vulnerability that Pushpaganda exploited. But Keisley notes that by the time they rolled out that patch, 10 more AI spam rings were already up and running using completely different vectors.
SPEAKER_00Exactly.
SPEAKER_01The tech giants are stuck in a reactionary patch cycle and they are losing ground every single day.
SPEAKER_00And since the platforms cannot currently protect us at the architectural level, the responsibility falls squarely on you. It is time to build the bunker.
SPEAKER_01So what does this all mean for us on a Tuesday morning? It means we need to get to work. We are going to walk through this highly practical 30-minute lockdown that Keisling actually deployed in his own home. And the goal here isn't to become a cybersecurity expert. You don't need to learn to code.
SPEAKER_00No, definitely not.
SPEAKER_01This is just about systematically making your devices hostile to automated spam. Let's start with a perimeter, the phone lockdown.
SPEAKER_00For your phone, the objective is to filter out the noise before it ever rings or dings. You want to break that psychological urgency of a notification. If you are on an iPhone, Keisling recommends going into your settings, finding the phone section, and changing the screen unknown caller setting to ask reason for calling.
SPEAKER_01Okay, what does that actually do?
SPEAKER_00What this does is force anyone who isn't already saved in your contacts to talk to an automated voice assistant first. They literally have to steat their business before your phone will even light up.
SPEAKER_01That's brilliant. You are basically hiring a robot bouncer to fight the robot spammers. And for your text messages on iOS, you go into settings, then messages, and toggle on filter unknown senders. That takes any text from a number you don't know and shoves it into a separate silent inbox.
SPEAKER_00Yeah.
SPEAKER_01You can check it when you want, but it doesn't interrupt your day.
SPEAKER_00Exactly. And Android users have a very similar process. You open the phone app, go to settings, find caller ID and spam, and turn on both toggles there. Additionally, Keysling strongly advises turning on your carrier-level scam shields.
SPEAKER_01Oh, right, the carrier shields.
SPEAKER_00Yeah. Whether you use Verizon, ATT, or T-Mobile, they all have free native apps that provide an extra layer of network level blocking. You already pay for the service, you just have to actually turn the shields on.
SPEAKER_01Good tip.
SPEAKER_00Yeah.
SPEAKER_01But securing the phone is just the outer perimeter. If a malicious actor really wants to dismantle your life, they aren't going to just annoy you with phone calls. They are going to go straight for the central nervous system, your email. Yep. If a bot gets into your primary inbox, it can riff at every single password you own from your bank to your social media.
SPEAKER_00The email lockdown is where we protect the real assets. The first mandatory step here is moving past text message-based two-factor authentication. SMS codes are um fundamentally insecure now.
SPEAKER_01Yeah, they really are.
SPEAKER_00The text messages can be intercepted in transit, or worse, your SIM card can be swapped.
SPEAKER_01Wait, let's clarify that because SIM swapping is terrifying. A hacker basically calls up Verizon or ATT, pretends to be you, says they lost their phone, and asks the carrier to port your phone number to a new SIM card that they control. If the customer service rep falls for it, your phone instantly loses service and the hacker receives all your password reset text messages.
SPEAKER_00That is exactly the vulnerability. To close that door, you need to switch your important accounts to an authenticator app, like Google Authenticator or AFI. These apps generate a new six-digit code every 30 seconds locally on your device. They do not rely on the cell network at all, so they cannot be intercepted or sim swapped.
SPEAKER_01But Keysling says if you want a truly bulletproof upgrade like the gold standard of personal security, you need to spend about $40 and buy a hardware security key. YubiKey is the most common brand. It's a little physical device, usually on your keychain, that you plug into your laptop or tap against your phone when you log in.
SPEAKER_00The hardware key changes the physics of the attack.
SPEAKER_01Okay. But how does a little piece of plastic on my keychain stop a hacker in a basement halfway across the world who already managed to steal my password?
SPEAKER_00Because the cryptography requires physical presence. A hardware key uses asymmetric cryptography that verifies not just the password, but the physical location of the key itself. A hacker in another country might have your password, and they might even be able to intercept an authenticator code if they're sophisticated enough. Right. But they physically cannot push the gold button on the USB key sitting on your desk unless they break into your actual house. They cannot log in. It completely neutralizes remote automated attacks.
SPEAKER_01Okay, so we have the bouncer on the phone, we have the physical cryptographic key for the email. Now we need to bring it back to the browser because we just talked about how that pushpaganda attack specifically weaponized browser notifications to bypass security.
SPEAKER_00The browser lockdown requires a ruthless approach. You go into your browser settings, find the section labeled site permissions or notifications, and you look at the list of websites currently allowed to ping you. Revoke permissions for anything you don't explicitly recognize.
SPEAKER_01Actually, I have to push back on this one. Kiesling says to turn them all off. But surely I want notifications from my bank if there is fraud, right? Or what about my weather app? I live in a place with severe storms. I need to know if there's a tornado warning.
SPEAKER_00I know, it feels counterintuitive. But Kiesling is incredibly firm on this point. The answer to website notification prompts is permanently no. There is no website on Earth where the right answer is yes. Not your bank, not the weather, not a news site.
SPEAKER_01Well why? If the weather site is legitimate, what is the actual harm?
SPEAKER_00Think about the underlying psychology and architecture of a push notification. It is designed to command your attention on their schedule, pulling you out of your context. This is the difference between push and pull information.
SPEAKER_01Okay, push versus pull.
SPEAKER_00Right. If you need information from your bank, you open the bank's secure app, or you type their verify address into the browser. You pull the information on your terms. Allowing websites to push alerts directly to your screen creates an open, persistent vulnerability. It trains your brain to react instantly to a pop-up. That conditioned reflex is exactly the vector these new AI rings are exploiting.
SPEAKER_01Okay, the push versus pull framing makes a lot of sense. The convenience of a weather alert isn't worth keeping a window open for a burglar. Permanent no to browser notifications.
SPEAKER_00Absolutely.
SPEAKER_01So that covers the tech settings, the physical perimeter of the bunker. But Kiesling argues that the tech is only half the battle. The true defense requires upgrading the human firewall. We had to fundamentally update how our brains process incoming information because the nature of the trick has completely changed.
SPEAKER_00Totally. For the last 20 years, internet users were trained to spot spam by looking for sloppiness. We looked for typos, weird formatting, or sentences that sounded like they were poorly translated from another language. The mental model was if it looks unprofessional, it's a scam.
SPEAKER_01The classic, dear sir, I am a prince with $10 million email. We all know how to spot that a mile away.
SPEAKER_00Keisling warns that this old rule is dead and buried. The new spam, powered by autonomous agents like OpenClaw, is grammatically perfect. It is emotionally precise. And most dangerously, it uses your actual name, your specific details, and information scraped from massive data breaches and public social media. The new tell for spam isn't sloppiness anymore. It is hyper-specificity from a stranger.
SPEAKER_01That is the most chilling part of this entire guide. If a message arrives that feels perfectly tailored to you, that knows your current situation, but it's from an entity you don't actually have a relationship with, you have to assume it's AI.
SPEAKER_00Right.
SPEAKER_01The personalization is the trick. It's designed to lower your guard by making you feel seen.
SPEAKER_00And this psychological manipulation extends far beyond text on a screen. The human firewall has to adapt to the voice cloning threat as well.
SPEAKER_01This is the stuff of actual nightmares. Keisling points out that voice cloning takes about five seconds now. If someone has just 30 seconds of audio of your kid's voice from a public TikTok video or a podcast or a voicemail greeting, they can clone it perfectly.
SPEAKER_00Yeah.
SPEAKER_01They can make it sound exactly like your child calling you crying, saying they've been in a car accident and need you to wire money immediately to a hospital or a tow truck.
SPEAKER_00Because when a parent hears their child crying in distress, the prefrontal cortex, you know, the logical reasoning part of the brain essentially shuts down. You enter a pure panic state. And the attackers know this.
SPEAKER_01Aaron Powell, which brings us to the ultimate behavioral defense. The one rule Keysling says is worth more than every other technical setting combined, the second channel verification rule.
SPEAKER_00Tell us how this actually works in practice.
SPEAKER_01It is about enforcing a hard pause. If an emergency call comes in from a number you don't recognize, even if it sounds exactly like your loved one, you hang up the phone immediately. You then call that person back at the number you already have saved for them in your contacts. So you just hang up and call the save number. You are forcing the communication onto a channel you control.
SPEAKER_00Exactly. And the same strict rule applies to the workplace or financial transactions. If you get an urgent text from the boss asking you to buy gift cards or wire a $5,000 invoice, you get up from your desk and you walk down the hall to ask them face to face. Right. If you get an email saying a relative needs bail money, you verify it by calling another family member.
SPEAKER_01These scams rely entirely on an engineered reaction. They want to trigger your fear, your urgency, your sympathy. They want you moving so fast you don't stop to think. Moving unknown text to a silent folder works because it breaks that urgency loop. You check the folder on your time with your armor on, refusing to give them that panicked reaction, forcing that pause, and verifying on a second channel, that is how you win.
SPEAKER_00You are taking control of the interaction back from the automated system. You are breaking their tempo.
SPEAKER_01Okay, so we've built the bunker, we've locked down the phone with a digital bouncer, secured the email with a physical hardware key, killed the browser notifications to regain our attention, and established the second channel verification rule. But I think it's really important to manage expectations here. Kiesling is very upfront about this this bunker will not stop the wave.
SPEAKER_00No, the wave of AI slop is still coming. Your inbox is still gonna get weird. You are still going to receive strange, hyper-targeted messages. A bunker doesn't change the weather.
SPEAKER_01But it ensures that when the wave hits, it bounces off your filters instead of draining your bank account. It ensures that the clone voice gets hung up on instead of you rushing to wire money in a panic. It buys you time. Keisling estimates this 30-minute investment buys us about six months until companies like Apple, Google, and the major telecom carriers can build a new normal at the infrastructure level.
SPEAKER_00Right. And that new normal will likely be much more restrictive than the internet we enjoyed five years ago, but it will be better than the peak of the storm we are entering right now. I also want to address a very common reaction people have when they hear all of this laid out. It's very easy to ask: is this some grand coordinated conspiracy?
SPEAKER_01Yeah, it feels like there must be a villain twirling their mustache behind the curtain, orchestrating this collapse.
SPEAKER_00Keyslin's insight here is profound and honestly a bit darker than a simple conspiracy theory. He says it is not a conspiracy, it is an emergent failure of an open system. Nobody planned this and nobody controls it. We simply built a digital market that heavily incentivized and selected for cheap engagement, what he calls slop. And now we have released a technology that produces that exact slop at an infinite scale.
SPEAKER_01A market failure. That makes it so much harder to fight because there's no single bad guy to arrest. It's just the inevitable result of the incentives we created.
SPEAKER_00And Kiesling makes a point of saying he isn't a Luddite. He loves AI, he uses it daily to parse documents for his legal work, but he frames the current crisis perfectly. He says, the lighter is brilliant, the forest is dry, we're gonna have a fire. We've introduced this incredible fiery technology into an ecosystem that currently has absolutely no immune system to handle it.
SPEAKER_01The lighter is brilliant, the forest is dry. That is an image that is gonna stick with me. We are boarding up the windows because the fire is already spreading. As we wrap up this deep dive, I want to leave you with a final thought to mull over, building on the source material we've discussed today. Kiesling actually teases the subject of his next article, and it is a deeply unsettling concept.
SPEAKER_00The implications go far beyond personal inconvenience.
SPEAKER_01Today, we've talked entirely about protecting your own bank account and your personal inbox. We focused entirely on the individual. But consider what happens to the bedrock of our society. Think about our justice system. Think about what happens to courts, to trials, to police reports, when absolutely no one, not the judge, not the jury, not the lawyers, can tell whether a submitted audio recording, a crucial email, a text message, or even a video witness statement is actually real.
SPEAKER_00It undermines the entire concept of evidentiary truth.
SPEAKER_01If reality is this incredibly easy to fake on your phone today, right now, with free open source software, how does a jury of your peers ever find the truth tomorrow? Do we figure that out? Stay in the bunker, trust your gut, and always, always make that second phone call.