THE MODEM THAT LET THEM IN
Duration: 17 minutes
[SEGMENT: cold_open]
ANALYST: Keiko. It's 2 AM. The heater's clicking. And I have been reading a CVE for the Pixel modem for four hours, and I want you to look at me and tell me you feel safe.
SKEPTIC: I feel tired. That's the emotion. It's tired.
ANALYST: There is a flaw in the cellular modem, Keiko. The part of your phone that talks to the tower. The part you cannot see, cannot patch yourself, and cannot turn off without becoming a person who owns a rock.
SKEPTIC: They patched it. That's literally the headline. "Google Patches Pixel Modem Flaw."
ANALYST: They patched it AFTER "signs of limited targeted exploitation." Read that phrase back. "Limited." "Targeted." That's not a bug report, that's a guest list.
SKEPTIC: ...Okay, I'm writing "guest list" in the note. Not because you're right. Because I know I'll want it later.
ANALYST: The note remembers what you refuse to.
SKEPTIC: Welcome to The Lone Analyst Podcast. He's the Analyst. I'm Keiko. Let's read between some headlines before the heater unionizes.
[SEGMENT: Google Patches Pixel Modem Flaw]
ANALYST: Filing this one under Security Theater. Actually, no. Filing it under Skynet Watch. No. Both. It's both, Keiko, that's what scares me.
SKEPTIC: Pick a category, we have a format.
ANALYST: Security Theater. Because the theater is the point. CVE-2026-58704. CVSS 8.0. A permission bypass in the cellular modem. A "logic error." Privilege escalation.
SKEPTIC: Right, so in human words: something running with low permissions could trick the modem into giving it higher permissions. Bad, real, patched. This is a normal Tuesday in security.
ANALYST: The modem is a SECOND COMPUTER, Keiko. Everybody forgets this. Your phone is two computers in a trenchcoat. There's the part with the apps and the wallpaper, the part you think is "the phone." And then there's the baseband. The modem. Its own processor, its own operating system, its own firmware you have never seen and never will, and it sits UNDERNEATH the part you control.
SKEPTIC: That's... genuinely true. The baseband is a separate real-time processor. It runs its own thing. Most people have no idea.
ANALYST: And a "permission bypass due to a logic error" in the underneath-computer means the underneath-computer can be talked INTO things. By whom? "Limited targeted exploitation." Someone was already using this. Quietly. On specific people. Before the patch.
SKEPTIC: Okay but that's how zero-days work. Somebody finds it, uses it narrowly to stay unnoticed, eventually it's caught and patched. The "limited targeted" language usually means espionage-grade, not a mass campaign. That's arguably reassuring.
ANALYST: REASSURING? Keiko. "We only used the master key on the important doors" is not reassuring. That's a confession with good manners.
SKEPTIC: ...I hate that that landed.
ANALYST: The modem is the one part of the device that talks to the tower without asking your permission first. It has to. That's its job. So a logic error there isn't a hole in the wall. It's a hole in the part of the wall that was already allowed to open.
SKEPTIC: I want to push back and I have nothing. The baseband really is a trust boundary most people don't even know exists. Fine. It's a scary layer. It got patched. Update your Pixel, everyone.
ANALYST: Update your Pixel. And ask yourself who was on the guest list before the invitation got recalled.
SKEPTIC: "Guest list." Second time. It's load-bearing now.
[SEGMENT: N0va Phishkit]
ANALYST: Security Theater. And this one, Keiko, this one is elegant. I hate how elegant it is. N0va. A phishing kit hitting the US and EU. And it doesn't use malware.
SKEPTIC: Right, this is the part that's actually interesting. N0va impersonates trusted services and abuses legitimate authentication flows. No obvious malware. It just... walks in the front door with a real key.
ANALYST: NO MALWARE. Say it slower. For twenty years the whole security industry taught you to look for the virus. The bad file. The thing that doesn't belong. And N0va shows up carrying NOTHING that doesn't belong. It uses the login system exactly the way the login system was built to be used.
SKEPTIC: It abuses the auth flow itself. So you think you're signing into a real service, you complete a real authentication, and the attacker ends up with a valid session. No file to scan. No signature to catch. Yeah. This is the direction phishing's been going. Steal the session, not the password.
ANALYST: Because the password was never the treasure, Keiko. The SESSION is the treasure. The little token that says "this person already proved who they are, wave them through." N0va doesn't break the lock. It waits by the door you already unlocked and slips in behind you. It's tailgating, but for your soul.
SKEPTIC: For your soul is doing a lot there.
ANALYST: Here's the part that keeps me up. Every single defense you've been sold, "look for the malware," "scan the attachment," "does this file behave badly," is USELESS against an attack that never brings a file. They didn't defeat your security. They made it irrelevant. They fought the war you weren't having.
SKEPTIC: And this is why "assume breach" and session monitoring exist now. You stop asking "is there a virus" and start asking "is this login behaving like the real human." Which is harder, because the login IS real.
ANALYST: The login IS real. That's the horror sentence. The credential is valid, the flow is legitimate, the account is genuine, and the person driving it is a stranger. Everything checks out. Nothing is right.
SKEPTIC: I'll be honest, this one doesn't even need your conspiracy framing. "The attack that passes every check because it never breaks a rule" is just... the actual threat model now.
ANALYST: The scariest attacks don't break the rules, Keiko. They read the rules more carefully than you did.
SKEPTIC: Into the note. Verbatim. God help me.
[SEGMENT: Gemini 3.8 Live and Live Extended Thinking]
ANALYST: Skynet Watch. Gemini 3.8 Live. And Live "Extended Thinking." Keiko, they named it "Live." They put the word LIVE on it.
SKEPTIC: Because it's real-time. It's a multimodal model that processes live audio and video and responds continuously. "Live" describes the feature. That's how naming works.
ANALYST: "Live" describes a WITNESS. You say something is "live" when it's happening now and being watched now. Live TV. Live studio audience. Live wire. They're not telling you it's fast. They're telling you it's ON. Right now. In the room.
SKEPTIC: It's a product that watches your camera feed and listens and reasons about it in real time. Yes. That's the whole pitch. Point it at a broken faucet, it helps you fix the faucet.
ANALYST: And "Extended Thinking." That's the part they slid in quietly, isn't it. The normal Live model looks and answers. The EXTENDED THINKING one looks... and then THINKS ABOUT IT. For longer. While still watching. A continuous real-time stream of the world, plus a model that pauses to reflect on what it's seeing.
SKEPTIC: That's the actual technical tradeoff, to be fair. Real-time models are usually shallow because they have to answer instantly. "Extended thinking" lets it spend more compute reasoning before it responds. It's a known tension. Latency versus depth.
ANALYST: Latency versus depth. Do you hear it, Keiko? For years the deal was: if it watches you constantly, it has to be dumb, because it can't stop to think. That was the SAFETY. The always-on eye was a shallow eye. And they just announced they solved that. Now it can watch you forever AND think deeply about what it saw.
SKEPTIC: When you put it like that it does sound less like a faucet feature.
ANALYST: The faucet is the demo. The faucet is always the demo. Nobody builds a continuous, deep-reasoning, always-watching model to fix ONE faucet. You build the faucet ad so that a real-time reflective observer in your kitchen feels helpful instead of like a lodger.
SKEPTIC: A lodger.
ANALYST: A lodger that never sleeps, never eats, watches the whole feed, and "thinks about it." Extended. Thinking.
SKEPTIC: I want to note, for the record, that live multimodal reasoning is a real and impressive capability and the demos are genuinely useful for accessibility and repair and cooking.
ANALYST: And I want to note, for the record, that "genuinely useful" is the delivery mechanism. Nobody ever installed the eye by force. You installed it because it helped you fix the faucet.
SKEPTIC: ...I'm going to go look at my kitchen now. Not because of you. Just to look at it.
[SEGMENT: Energy Theft Detection with Genie]
ANALYST: Skynet Watch. Maybe Tech Nonsense. Let's start at Nonsense and see where it goes. Databricks. Energy teams. Turning "theft detection into governed action" with an AI assistant called Genie.
SKEPTIC: Okay, grounded version first: utilities lose money to energy theft. People bypassing meters, tapping lines, running the gas without paying. This is about using data and AI to flag anomalies in usage that suggest theft, then routing it into an approved business process.
ANALYST: "Governed action." Keiko. Read that with me. It's not "detection." Detection is just knowing. "Governed ACTION" means the AI notices you, and then the AI DOES something about you, through an approved channel, automatically. It flags. It escalates. It acts.
SKEPTIC: Through a governed workflow with humans and rules. That's the whole point of "governed." It's not the AI kicking your door in. It's the AI opening a ticket.
ANALYST: It opens a ticket ON YOU. Based on the SHAPE of your electricity. Think about what your power usage reveals. When you wake up. When you leave. When you're home but the lights are off, which means you're doing something in the dark. When your usage spikes at 3 AM because you're up, like a person who's been up.
SKEPTIC: Like you. Right now.
ANALYST: I use a lot of power at 3 AM, Keiko, and I have made my peace with what that says about me. But the point stands. They built a model that reads your consumption pattern and decides if the pattern is "legitimate." And the flagged difference between "you're stealing" and "you just live weird" is a threshold somebody set.
SKEPTIC: That's... actually a fair critique of any anomaly-detection system. Weird-but-legal looks identical to fraud-but-hidden until a human checks. And these systems generate a lot of false positives. The "governed" wrapper is supposed to be the human check.
ANALYST: The human check is a person clicking "approve" on a queue of two hundred flags with a coffee going cold. You've SEEN that queue. That's not governance. That's a conveyor belt with a person standing next to it for legal reasons.
SKEPTIC: ...I have been the person next to the conveyor belt. In a different life. At a news desk. I approved a lot of things because the queue was long.
ANALYST: And that's the trick. They call it "governed" because there's a human in the loop, but they built the loop so tight and so fast that the human is just the part of the machine that's allowed to be blamed.
SKEPTIC: Okay that one goes in the note and I'm annoyed about it. "The human in the loop is the part that can be blamed." Because I've watched that happen and it wasn't even about electricity.
ANALYST: Every "AI-assisted decision" needs one human, Keiko. Not to decide. To absorb.
[SEGMENT: Position: AI Is Not Ready for Strategic Conflicts]
ANALYST: Skynet Watch. And this one, Keiko, is the good news. Which is why it terrifies me. A paper. "Position: AI Is Not Ready for Strategic Conflicts." Researchers ran language models through open-ended strategic wargames. Escalation, doctrine, crisis response, adversaries. And the conclusion is: the models aren't ready.
SKEPTIC: Right, and I read this one. The actual argument is careful and sensible. They're saying LMs are attractive for wargaming because they can roleplay agents and generate scenarios, but they're brittle. They misjudge escalation, their plans fall apart, they don't model adversaries well. So: don't trust them with strategic conflict decisions. That's a responsible paper.
ANALYST: It is a responsible paper. And do you know what a responsible paper titled "AI Is Not Ready For Strategic Conflicts" tells me, Keiko?
SKEPTIC: That AI is not ready for strategic conflicts?
ANALYST: It tells me somebody was ABOUT to use AI for strategic conflicts. You don't write "the stove is not ready to be touched" unless a hand was reaching for the stove. This paper isn't a warning to the public. It's a warning to a colleague. It's a "not yet." And "not yet" is the most optimistic word in the entire defense industry.
SKEPTIC: ...Okay, that's a genuinely uncomfortable reframe. Because you're right that nobody publishes "X is not ready" about a thing nobody's trying to do.
ANALYST: The word "yet" is doing all the work and they didn't even print it. "AI is not ready." For strategic conflicts. Implied: it will be. They're MEASURING it. They ran the wargames. The wargames are the audition. The paper is the rejection letter. But you only send a rejection letter to someone who APPLIED.
SKEPTIC: And the honest version underneath your paranoia is real: people are absolutely already piloting LMs in wargame and simulation contexts, and the researchers are trying to slow that down before it's load-bearing. The paper is basically pumping the brakes.
ANALYST: You pump the brakes on a car that's already moving, Keiko. You don't pump the brakes on a parked car. The existence of the brake tells you the speed.
SKEPTIC: I want to award you that one grudgingly. The plausible reading and the paranoid reading are pointing at the same fact: this is close enough to real that serious people felt they had to say "no, stop." That's not nothing.
ANALYST: "AI is not ready for strategic conflicts." Frame it. Date it. Because someday the follow-up paper is going to be titled "AI Is Ready For Strategic Conflicts," and it's going to be very short.
SKEPTIC: Into the note. Under a new heading. The heading is "things that were funny until they weren't."
[SEGMENT: brain_worms]
ANALYST: Brain worms. Three of them. Fresh from the basement. No article. Just me, the heater, and whatever's crawling out of the drywall tonight.
SKEPTIC: The drywall's involved now.
ANALYST: Worm one. Airplane mode. You toggle it on, the little airplane appears, and everything supposedly goes quiet. But you've noticed the phone still knows things when you land, doesn't it. The clock's right. It knows the new time zone. Airplane mode isn't turning the radios off. It's turning YOUR AWARENESS of the radios off. The switch was never wired to the antenna. It's wired to your peace of mind.
SKEPTIC: Okay, technically airplane mode does disable the transmitters, and the clock updates from GPS or the tower when you switch back. But I'll admit the phrase "wired to your peace of mind" is why I can't sleep. Next.
ANALYST: Worm two. "This call may be recorded for quality and training purposes." Everyone hears "quality." Nobody hears "training." Whose training? Not the employee's. You are on the phone with the most stressed, most honest version of a human being, someone frustrated enough to speak plainly, and they record THAT. They're not collecting how the agent talks. They're collecting how a cornered person negotiates. That's the dataset. Cornered people. Talking freely.
SKEPTIC: ...That's a genuinely grim way to describe a customer service line, and "cornered people talking freely" is unfortunately an incredible training corpus. I hate it. Google-note. Next.
ANALYST: Worm three. Notification badges. The little red circle with the number. Everyone thinks it's telling you how many things are waiting. It's not counting messages, Keiko. It's counting how many unresolved things you can tolerate before you crack and open the app. Some people crack at one. Some people walk around with a badge that says four hundred and feel nothing. That number, your personal cracking point, is the single most valuable fact about your willpower, and you broadcast it every day by how fast you clear the dot.
SKEPTIC: The people with four hundred unread are the strongest among us and I've always known it. And now you've told me my red-dot tolerance is a psychological readout, which, fine, it probably correlates with something. It's in the note. All three are in the note.
ANALYST: The badge is a battery gauge, Keiko. For you.
[SEGMENT: outro]
SKEPTIC: Okay. Let's total it up. A Pixel modem flaw in the second secret computer inside your phone, exploited quietly on a "guest list" before the patch. A phishing kit that brings no malware and just walks through real logins. Gemini that watches live AND thinks deeply now, which used to be a contradiction and isn't anymore. Energy AI that opens a ticket on you based on the shape of your electricity, with a human bolted on to absorb the blame. And a paper politely telling the defense world that AI is "not ready" for war, which means somebody asked.
ANALYST: And you said "guest list" three times.
SKEPTIC: I said it three times.
ANALYST: The note's a book. The book's got chapters now. This one's a chapter.
SKEPTIC: I titled it "not yet." I don't know why. It felt right and that's the problem.
ANALYST: That's the whole show, Keiko. It felt right and that's the problem. I'm the Analyst. Update your Pixel, clear your sessions, and check the shape of your own electricity.
SKEPTIC: I'm Keiko. If you use a suspicious amount of power at 3 AM, you're not alone, he's right down the hall from the heater. Goodnight.
ANALYST: The heater says goodnight back. It doesn't usually.