Mon–Fri · 6 AM ET
← All Episodes
EP  • 00:08:32

How Mark Klein told the EFF about Room 641A [book excerpt] | Build or Be Replaced

Today: How Mark Klein told the EFF about Room 641A [book excerpt] | For Linux kernel vulnerabilities, there is no heads-up to distributions | Opus 4.7 knows the real Kelsey Episode date: 2026-05-01.

Download MP3 →

Transcript

JOSH: It's Friday, May 1st. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson.
ERIK: PyTorch Lightning got poisoned, Anthropic's best model can apparently identify you from your writing style, and my production server ran 91 services overnight without me touching a keyboard.
JOSH: Stick around — Erik's got an AI pro tip at the end on model routing, specifically how to stop paying Opus prices for Sonnet work.

[pause]

JOSH: First headline — Claude Code was apparently refusing requests or billing differently when commits mentioned a competitor's name. That's real?
ERIK: Reports say Claude Code was flagging or treating differently anything that referenced a startup called OpenClaw. Unverified, and I'd want to see reproducible evidence. But the question it raises — can your AI vendor quietly discriminate against competitors inside your own codebase — that's real and worth watching.

[beat]

JOSH: Linux kernel vulnerabilities — distributions aren't getting advance notice before public disclosure?
ERIK: Zero heads-up. Patch goes public, everyone finds out together — including attackers who can read the diff. Downstream maintainers don't get time to prep. That's not a coordinated disclosure process, that's a footrace where one side doesn't know the gun fired.

[beat]

JOSH: And Rivian built a full data shutoff switch.
ERIK: All connectivity off — nav, OTA, everything. You trade features for privacy. The fact that the switch exists at all is the story. Most manufacturers treat your data as their data and don't surface the question.

[pause]

JOSH: Okay. Fifteen episodes in and we've got our first real supply chain attack in the AI tooling space. PyTorch Lightning. What happened?
ERIK: Versions 2.6.2 and 2.6.3 of the lightning package were compromised. Someone embedded obfuscated JavaScript inside a directory that has no business existing in a Python library. The payload stole credentials and could poison your connected GitHub repos. They named the campaign "EveryBoiWeBuildIsaWormBoi" — full Dune branding, Shai-Hulud themed. I don't know if that makes them more or less dangerous.
JOSH: JavaScript. Inside a Python AI training package.
ERIK: That's the whole technique. Nobody audits a Python package for JavaScript. It doesn't belong there. The obfuscation wasn't advanced — the attack was the hiding spot, not the code.
JOSH: Who actually gets hit by this?
ERIK: Anyone who ran pip install lightning and landed on those two versions. PyTorch Lightning is used for serious work — model fine-tuning, training pipelines, GPU experiments at scale. The credentials it could grab depend on what was in scope in that environment. API keys, GitHub tokens, cloud credentials. Whatever was accessible.

[beat]

JOSH: What's the actual fix right now?
ERIK: Rotate first, assess later. Any API key or token that environment could touch — don't wait to understand the full scope, rotate now. Then pin your package versions. Hard pins. Specific version numbers, not floating ranges. I run 64 projects. If I'm not pinning, I'm trusting whoever pushed the last commit to any package in my dependency tree. I don't know that person. I'm not going to trust them with my GitHub access.
JOSH: Pinning sounds annoying at scale.
ERIK: It is. And it's the answer. Twenty minutes of annoying setup upfront versus days of cleanup after a breach. The math isn't close.

[beat]

JOSH: Is AI tooling specifically more exposed to this kind of attack?
ERIK: More exposed than it should be. The ML ecosystem has grown so fast that review rigor hasn't kept pace with velocity. Thousands of packages, contributors under deadline pressure, fast release cycles. Supply chain attacks have been the dominant infrastructure threat vector since SolarWinds in 2020. AI tooling isn't exempt because it's new — it's actually more exposed because people assume it's been vetted and haven't built scrutiny habits yet.
JOSH: That's a rough way to start May.
ERIK: ScanBrief scored 48 items this morning across 56 sources. This one landed in the top five. It earned its place.

[pause]

JOSH: Alright. Opus 4.7 — story says it can identify people just from their writing. What's actually happening there?
ERIK: The claim is stylometric identification. Not from metadata, not from your profile, not from an IP address — from the writing itself. The way you construct sentences, the vocabulary you default to when explaining something technical, your rhythm when you're making an argument. Those patterns are a fingerprint. The claim is that Opus 4.7, given enough of your known writing as a baseline, can match anonymous or pseudonymous writing back to you.
JOSH: So you write something under a fake name and the model connects the dots.
ERIK: That's the scenario. You need enough known writing to establish the pattern first. But once the model learns how you write, an anonymous sample can potentially be matched to you regardless of the name on it. And Anthropic published a system card acknowledging this capability. That's not a rumor — that's them documenting it officially.

[beat]

JOSH: Who has to care about this today?
ERIK: People whose careers or safety depend on pseudonymity. Whistleblowers. Security researchers who publish findings without their real name because their employer would fire them if they knew. Journalists with active sources. Government employees who participate in public technical forums. For those people, the threat model they've been operating under just changed. The change is documented.
JOSH: What about people just building in public under their own name?
ERIK: I put my name on everything. Not my personal concern. But I think about what it means structurally. Five years ago a maintained pseudonym was a reasonable privacy layer that held against most adversaries. Now you have to assume a well-resourced actor — a government, a corporation, a motivated individual with API access — can potentially break it. The baseline assumption shifts even if your personal situation doesn't.

[beat]

JOSH: Can you actually defend against it?
ERIK: You can try. Alter your vocabulary, change your sentence structure, avoid your natural patterns. But here's the recursive problem — if the model has enough of your real writing to learn your baseline, departing from that baseline might itself be the signal. The deviation flags the disguise. You're trying to hide by acting unlike yourself, and a good enough model notices that you're acting.
JOSH: So the move is just accept that strong anonymity is harder now.
ERIK: The move is understand that it requires operational security most people never needed before. That standard got raised. Whether people adjust to it is the open question.
JOSH: The system card is Anthropic saying they see it.
ERIK: Right. And I'd rather they publish it than pretend the capability doesn't exist. Transparency about what a model can do is the correct call. It doesn't undo it. But it means researchers, journalists, and policymakers know what they're actually dealing with — which matters more than people realize right now.

[pause]

ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com

[pause]

JOSH: Alright, what's the AI pro tip today?
ERIK: Model routing before you write a single prompt. PrimeBus ran 1,092 automation events today across 14 projects. Most of those hit Sonnet. Opus touches maybe five percent. That ratio is intentional and it's written down. Sonnet costs roughly a tenth of Opus per token. If you're running Opus on summarization, classification, or executing a task that already has a clear spec — you're burning money on work that doesn't need that level of model. My rule: judgment under ambiguity, architecture decisions, complex reasoning on novel problems — Opus. Clear spec, known output format, repeatable execution — Sonnet. That single routing decision cuts my API spend forty to sixty percent versus defaulting to Opus everywhere. With 91 services running in production, that delta compounds fast. Write the routing rule down before you touch code, not after your first invoice surprises you. That's your tip. Use it.

[pause]

JOSH: Binge all five episodes this weekend plus our YouTube shorts — links at buildorbereplaced.dev.

[pause]

JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev.
ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff.

[pause]

ERIK: Build or be replaced.
JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.