[BidClub_]
Hard Fork · · 64 分钟

Anthropic 的网络安全冲击波、Ronan Farrow 与 Andrew Marantz 对 Sam Altman 的调查,以及一件好事

Kevin RooseCasey NewtonRonan FarrowAndrew Marantz

播客
TL;DR
  • Anthropic 尚未发布的 Claude Mythos Preview,可能标志着 AI 前沿转向自主发现漏洞。 Anthropic 声称发现了一个存在27年的 OpenBSD 漏洞,以及一个被500万次自动扫描漏掉的 FFmpeg 漏洞。通过 Project Glasswing,Anthropic 将向 Cisco、Broadcom、Microsoft、Apple、Amazon 等公司提供总额1亿美元的 Claude 使用额度,以便在可能到来的网络安全“清算”前进行防御性测试。
  • 眼下的约束可能不是发现漏洞,而是修复漏洞的产能。 Kevin Roose 认为,资源充足的公司或许能找出并修复最关键的那1%软件,而未来约6个月可能迎来一轮大规模打补丁和重写代码的周期。老旧代码、人类审查员有限,以及客户更新缓慢,共同构成“人力瓶颈”。悬而未决的问题是:Mythos 消耗的究竟是有限的漏洞存量,还是能够持续发明人类从未想过的攻击链。
  • 这次发布暴露出私人 AI 能力与公共监管之间的尖锐错配。 Kevin 表示,据他了解,美国政府曾将 Anthropic 视为供应链风险,并要求各机构停止使用 Claude,导致国家安全机构无法直接获得它们可能迫切需要的技术。Casey Newton 认为,一个足以迫使整个软件行业大范围重写的软件模型基本不受监管,“真的、真的让人不舒服”。
  • Ronan Farrow 和 Andrew Marantz 对 Altman 的调查,通过证据累积而非单一铁证展开论证。 他们发现,数量极其庞大的人——包括与 Altman 关系密切、相识多年的联系人——指称他反复欺骗他人,其中一名未具名董事称 Altman “不受真相约束”;与此同时,报道也记录了真正的支持者,以及一场由 Elon Musk 的中间人传播未经证实材料的抹黑行动。
  • 治理层面的爆炸性事实是,用来为 Altman 回归正名的外部调查没有产出书面报告。 尽管 OpenAI 是一家非营利机构,2023年解雇事件又牵涉广泛公共利益,但利益相关方拿到的只是约800字的公告,描述了一场模糊的信任破裂。Farrow 的直截了当的结论是:“根本没有报告”,因为调查过程被刻意留在书面记录之外。
  • OpenAI 的关键人物风险看起来不再那么绝对,但治理风险仍未消失。 一些支持 Altman 回归的务实投资人告诉记者,如果当时掌握今天的信息,他们可能不会做出同样选择;Farrow 报道称,高管们曾不时讨论接班安排,Fiji Simo 被提及为潜在人选,尽管公司否认存在这些讨论。Casey 将有关 CFO Sarah Friar 被排除在财务规划之外的报道,与更大范围的模式联系起来:先设置护栏,再“熟练地绕开护栏”。
  • 本期节目用2种截然不同尺度的惊叹,作为对 AI 权力集中的制衡。 Artemis II 搭载4名宇航员飞抵距离地球252,756英里的位置;年费25美元的 Acme Weather 则把概率预报和社区报告转化为闪电、日落、极光以及邻里彩虹提醒。它的产品命题谦逊得令人耳目一新:“如果我家附近有一道彩虹呢?”
摘要 · 为研究而整理的核心内容

1. Anthropic 暂不发布前沿模型,为防守方争取先手

  • 节目组破例处理这期内容,原因是 Claude Mythos Preview 虽已宣布,却被 Anthropic 刻意延后发布,打破了节目“要么发布、要么闭嘴”(ship it or zip it)的规则。Project Glasswing 得名于一种透明翅膀能让自己“藏在人群视线中”的蝴蝶,这也对应了该模型的设计目标:找出潜藏在整个软件栈各处、平时几乎不可见的漏洞。

  • Anthropic 转而向一个防御性测试联盟提供访问权限,成员包括 Cisco、Broadcom、Microsoft、Apple 和 Amazon——按 Kevin 的说法,几乎涵盖所有主要科技公司,唯独没有 OpenAI 和 Meta。公司将提供1亿美元的 Claude 使用额度,让包括 Anthropic 竞争对手在内的基础设施供应商,能在模型向更广泛用户开放前修补系统。

  • Casey 的解释是理性的责任规避:如果发布一种网络武器,让非专业人士能够找到 Linux 内核漏洞并接管机器,势必招致犯罪和国会听证。他承认,在经历与五角大楼的冲突后,这种安全立场可能提升 Anthropic 的品牌形象;但 Kevin 认为,把一个不准备公开销售的模型免费交给外部使用,是“糟糕透顶的营销策略”。

2. Mythos 据称发现数十年和数百万次扫描都未发现的漏洞

  • Anthropic 声称,Mythos 找到了 OpenBSD 中一个存在27年的漏洞。OpenBSD 是用于防火墙和路由器的开源操作系统,设计初衷就是抵御黑客攻击。真正惊人的地方不只是速度,而是这个漏洞在近30年的专业安全研究中一直未被发现。

  • 第二个展示案例是 FFmpeg,这是一款广泛使用的开源视频软件。Anthropic 表示,自动化安全工具曾对其代码扫描500万次,却始终没有发现 Mythos 找到的关键漏洞;这几乎是一个非常干净的案例,说明推理系统能够从传统自动化反复失败的结果中提取有效信号。

  • Casey 说,网络安全专业人士15年来一直警告他,互联网是靠“唾沫和胶水”勉强粘在一起的。前 Yahoo 和 Facebook 安全负责人 Alex Stamos 给出的外部判断,让这个说法的分量陡增:自主系统现在已经能够串联出人类会漏掉、耗时太久才能发现,或根本没有时间调查的攻击链。

3. 打补丁的瓶颈可能比第一轮6个月冲刺持续更久

  • Stamos 提出了2种情景。乐观情景是,世界面对的是一份有限的关键漏洞清单,防守方可以逐一修补;更黑暗的情景是,Mythos 级系统能够持续发明陌生的攻击链,让问题不断扩张,直至可能触及超级智能门槛。节目主持人没有假装知道哪一种情景更有可能发生。

  • Kevin 认为,未来6个月内,每一款主要软件都可能需要打补丁、重写并重新发布,这一判断并非没有道理。集中资源或许能够守住最关键的1%——Linux、主要开源库、路由设备和网络设备——形成他所谓的“整个网络安全行业被迫重置”。

  • 长尾问题会打破这一乐观时间表。维护者收到的漏洞和补丁提案,可能超过人类能够审查的数量;无数设备仍在运行老旧代码,必须等设备所有者最终更新固件。Kevin 举的典型失效点,是俄克拉何马州 Tulsa 一家中型企业里负责管理路由器的人——他可能只是把安装修复程序的时间往后拖。

  • Casey 让这个威胁变得具体:即便没有 Mythos 这种水平的模型,伊朗已经在攻击美国的水务和能源基础设施。因此,他担心的不是某个抽象的未来对手,而是现有敌对势力一旦获得同等能力后,可能拥有更大的杠杆。

4. 私人能力差距正撞上薄弱的公共监管

  • 政府关系呈现出悖论:Kevin 表示,据他了解,本届政府曾试图将 Anthropic 定性为供应链风险,并要求联邦机构停止使用 Claude;与此同时,Anthropic 手里却握有一个可能对国家安全有价值的模型。就 Kevin 所知,美国政府无法接触这一模型;Casey 则将此与监管体系联系起来——上一届政府曾试图建立这套体系,但本届政府出于竞争力考虑将其废弃。

  • Kevin 将这一刻与2019年的 GPT-2 相提并论。当时 OpenAI 因担心虚假信息而将模型扣留数月,尽管 Casey 开玩笑说,它当时“连一首五行打油诗都写不好”。此后,内部能力与公众可获得的能力基本保持接近。Mythos 重新打开了这道缺口,Kevin 担心,即使克制发布是负责任的做法,保密本身也会放大公众的偏执与恐慌。

  • Casey 认为,Anthropic 的创立理念正在按预期运转:先打造最强模型,再利用自身的前沿地位,约束国内监控、自动化武器和漏洞扩散。他尚未解决的疑问在于其中的循环逻辑——为了引导这个危险的前沿,必须先“打造这个前沿,尽管它很危险”;但一旦能力泄漏,这个自我实现的预言可能就再也无法控制。

  • 对个人用户而言,只要防守方仍有缓冲时间,Casey 不认为需要陷入恐慌。他给出的底线是做好传统安全卫生:使用 1Password 等密码管理器,为每个账户生成唯一的随机密码,并通过验证器应用启用多因素认证来保护邮箱和银行账户,而不是只依赖“8个字母”。

5. Farrow 和 Marantz 通过累积证据构建 Altman 案

  • Farrow 形容这篇超过16,000字的人物特写是刻意做到“法证式、甚至公平平衡”。一些读者读完后认为 Altman 构成严重危险;Farrow 的母亲读完则说:“你知道吗,我还挺喜欢他的。”记者团队广泛采访相关人士,并认真讨论是否纳入某些材料,尤其是在反方论据显示其可能不公平或过度煽情时。

  • 但他们的核心发现依然是:数量极其庞大的人在与 Altman 交往后,哪怕双方关系亲密、持续多年,也指称他会在大事小事上撒谎。这里没有一个“偷吃被当场抓住”的决定性时刻。即便是那个略显滑稽的细节——Altman 声称自己每天都穿灰色毛衣,却有一天穿着绿色衣服出现——也说明这套论证依靠的是叙事上的证据累积,而不是一份秘密黑料清单。

  • 记者将有事实依据的批评,与竞争对手之间的互相攻击区分开来。Farrow 说,Musk 的中间人传播了“相当辛辣、也相当缺乏依据的材料”,其中一些内容被夸大,或明显是假的。Andrew 表示,这种竞争烈度符合一种信念:谁先拿到权力之戒,谁就能控制世界。这场抹黑行动并不能抹去已有事实支撑的投诉,但确实让每个消息源背后的利益动机都变得更复杂。

6. 缺失的调查报告是治理层面的爆炸性事实

  • Andrew 说,他们的报道显示,Altman 并非像他和 Paul Graham 对外维持的说法那样,只是主动选择离开 Y Combinator。报道还显示,他与阿联酋和沙特王室的关系比外界此前了解的更深,并披露了 Ilya Sutskever 备忘录和 Dario Amodei 笔记中的细节。

  • 当推动 Altman 离任的 OpenAI 董事会成员同意离开时,他们坚持要求一家外部律师事务所展开调查。OpenAI 是一家501(c)(3)机构,又是在一场具有公共影响的丑闻中走出来的公司,因此高管及其他利益相关方都期待,在这场调查后来被用来证明 Altman 回归合理之前,至少能看到一份详细摘要。

  • 但 OpenAI 最终只发布了一份约800字的公告,称各方之间出现了模糊的信任破裂。Farrow 直接回答了这个持续已久的问题:“根本没有报告”,因为调查过程没有形成书面文件。一名由 Altman 协助选出的董事、也是调查监督者,如今表示书面文件并无必要。Farrow 指出,法律专家往往把刻意不写成报告视为危险信号。

  • 最严厉的证词来自一名 Microsoft 高管和一名未具名董事,而不只是竞争对手。那名 Microsoft 高管认为,Altman 最终变成 Bernie Madoff 或 Sam Bankman-Fried 的可能性“虽小但真实”;未具名董事则称他“不受真相约束”,并指称他“几乎带有一种反社会人格式的漠视,不在乎欺骗他人可能带来的后果”。

7. Altman 的支持者将争论重新拉回 OpenAI 最初的承诺

  • Altman 的关系网络让忠诚始终流动:他估计自己投资了约400家科技公司,而创始人和投资人也反复出现在彼此的董事会中。Andrew 说,记者遇到的既有朋友,也有敌人;考虑到硅谷的“雇佣兵本性”,还包括曾经两者皆是的人——这有助于解释为什么人们的公开立场会随权力转移。

  • Farrow 发现,在那些支持 Altman 回归的务实型、增长导向投资人中,态度出现了有意义的变化。当时信息极少,而让 Altman 回归的上行空间显而易见,他们选择给予其疑点利益;如今几个人都表示,如果当时知道今天所知道的一切,“我不知道自己还会不会这么做”。

  • Kevin 的反驳是,Altman 确实拥有有判断力的支持者,也明显有能力把优秀人才团结到重大项目周围。正面评价往往来自私下,或来自与 Altman 有关系的人;但 Andrew 证实,真正的支持者确实存在,尤其是那些认为对不同受众说不同的话,本来就是创始人的常规行为。

  • Andrew 的反驳回到了最初的契约:OpenAI 把自己定位为一家非营利、以安全为导向的研究实验室,并承诺积极遵守监管。如果今天的辩护只是说,这就是“一家正常的竞争性企业”,那么最初相信它的人是不是太天真?Casey 补充道,关于 Satya Nadella、Sundar Pichai 或 Tim Cook 的讨论,并不会被长期的诚信问题定义。

8. OpenAI 的信任问题正演变为治理与接班风险

  • Farrow 同意,制度结构比任何一个人的个性更重要。OpenAI 的创始人自己曾警告不要出现“AGI 独裁”,这意味着个人诚信本就是其创立逻辑的一部分;但更大的失败在于,一个系统把具有重大影响的技术交给私人公司、公司内部控制机制,以及彼此“泼泥巴”的竞争混战。

  • Andrew 提到,人物特写截稿后不久,OpenAI 收购了科技聊天节目 TBPN,进一步增强了讲述自身故事的能力。记者还说,安全 fellowship 和治理公告集中在文章发布前后出现:Andrew 称治理方案“充满 AI 味道且虚无缥缈”,Farrow 则表示,这些公告意在占据与调查报道相同的公共讨论空间。

  • 经济激励进一步放大了治理问题。Andrew 回忆,Altman 曾承认 AI 存在泡沫,“总会有人损失一大笔惊人的钱”。这个周期是否会走向破坏性后果,并不独立于领导层的言辞:泡沫能涨到多高,部分取决于那些推销未来的人有多激进地周游世界兜售这套叙事。

  • 一名前同事概括的反复模式是:先打造复杂的护栏,再设法绕开护栏。Casey 将这一点与有关 CFO Sarah Friar 被排除在部分财务规划讨论和一些关键会议之外的报道联系起来;报道还称,她怀疑 OpenAI 今年能否做好 IPO 准备。Farrow 补充说,高管们曾不时讨论接班问题,Fiji Simo 被提及为潜在人选,尽管公司否认存在这些讨论;此后 Simo 因健康原因休假。Andrew 如今认为,没有 Altman 的 OpenAI 并非不可想象,更像是从 Steve Jobs 到 Tim Cook 的交接,而不是公司走向灭亡。

9. Artemis II 与 Acme Weather 让人重新感受一种更小尺度的惊奇

  • Kevin 选的“一件好事”是 Artemis II:4名宇航员 Victor、Christina、Jeremy 和 Reid 飞行252,756英里,超过此前任何人类抵达过的距离。《纽约时报》把这个距离换算成23.7亿根 Nathan's Famous 热狗,Casey 带着讽刺说,这个比较确实很容易想象。

  • 和孩子一起观看任务直播时,Kevin 学会了“terminator line”——分隔月球明亮区域与黑暗区域的明暗界线——以及应当说“远侧”而不是“暗侧”。这次任务如此强烈地唤回了“孩童般的喜悦与惊奇”,以至于他认为,NASA 应该获得把人类每年送上月球所需的任何预算。

  • Casey 选择的 Acme Weather 让 Dark Sky 原班团队 Adam Grossman、Josh Reyes 和 Dan Bruton 重聚。Apple 于2020年收购了此前的应用,并在2022年将其关闭;Acme Weather 目前已登陆 iOS,Android 版本计划推出。它展示的是预报区间,而不是虚假的确定性,让用户看到基础信号何时真正指向大幅温度波动。

  • 年费25美元的订阅包含闪电、绚丽日落、未来12小时内降水、高紫外线、极光和彩虹提醒。彩虹检测采用类似 Waze 的社区上报机制:当足够多的邻居提交目击报告后,Acme 会提醒那些困在办公室里的用户走到户外,“见证造物的壮美”。

Kevin Roose

Casey, I got a haircut yesterday. Thanks for noticing.

Casey Newton

Kevin, it looks extraordinary.

Kevin Roose

Has this ever happened to you? I went into the barber and sat down in the chair. He did not ask me what I wanted. He just started cutting. Has this ever happened to you?

Casey Newton

No, because they know I'm not straight. With a straight guy, you don't need to ask them. You just get the standard haircut that a man gets.

Kevin Roose

He one-shotted my hair.

Casey Newton

He said, “Yeah, I've seen this before. I know what I'm doing here.”

Kevin Roose

Anyway—

Casey Newton

Whereas if I walk in, it's like, “Okay, let me get out the schematics and have to watch a couple YouTube videos.”

Kevin Roose

It's also not a barber that I've been to a lot, so it's not like he knew me.

Casey Newton

Mm-hmm.

Casey Newton

See, this is exactly why the fact that you just go to random barbers and will accept whoever happens to be there means they can just start cutting your hair.

Casey Newton

Oh, who is—yeah, I know. I don't know this person. Yeah, do whatever the hell you want. See if I care.

Kevin Roose

Yeah.

Casey Newton

That is the straight approach to hair. But it's working great for you.

Kevin Roose

Thank you.

Casey Newton

Yeah.

Kevin Roose

I'm Kevin Roose, a tech columnist at The New York Times.

Casey Newton

I'm Casey Newton from Platformer.

Kevin Roose

And this is Hard Fork.

Casey Newton

This week, the dangerous new AI model that has cybersecurity experts on high alert. Then, New Yorker writers Ronan Farrow and Andrew Marantz join us to discuss their spicy new profile of Sam Altman. And finally, it's time for One Good Thing. Although I guess there are really two things in the segment.

Kevin Roose

Yeah, we should really rename the segment.

Casey Newton

Okay.

Kevin Roose

Casey, we have a big announcement.

Casey Newton

Kevin, what is the announcement?

Kevin Roose

We're ending the show. No.

Casey Newton

You're finally free, America.

Kevin Roose

Yeah. Yes. No. On June 10th, in San Francisco, we are doing the second-ever installment of Hard Fork Live.

Casey Newton

It's too fast, it's too furious, and it's happening.

Kevin Roose

I tried to let them get them to let me call it Too Hard To Fork.

Casey Newton

Mm.

Kevin Roose

But they decided that was not appropriate.

Casey Newton

Kevin, where can people get more information about Hard Fork Live Two?

Kevin Roose

Okay, it's happening on June 10th—

Casey Newton

Okay.

Kevin Roose

—in San Francisco at the Blue Shield of California Theater. Bigger venue than last year.

Casey Newton

Mm-hmm.

Kevin Roose

Tickets will be on sale at nytimes.com/events, not today, but next Friday, April 17th.

Casey Newton

So we're giving you a full week to get your act together, reach out to all your friends, use Meta AI to plan a trip to California.

Kevin Roose

Use Claude Code to build your scraper bots to scoop up all the tickets.

Casey Newton

And on Friday, the 17th, you can buy tickets.

Kevin Roose

Yes.

Casey Newton

And we will just say in advance, last year the tickets did sell very quickly.

Kevin Roose

They did. So get in there quickly if you want to come.

Casey Newton

There would be more tickets available, but Kevin reserves 50 for, quote, “his team”—which I don't even know what all these people are doing at this point. But they'll be there. You can say hi to them, too.

Kevin Roose

So get your tickets next Friday, April 17th, at nytimes.com/events. Well, Casey, as you know, on this podcast, we have a rule about discussing AI models called “ship it or zip it.”

1. Anthropic Withholds Mythos Preview

Kevin Roose

Casey, as you know, on this podcast, we have a rule about discussing AI models called “ship it or zip it.”

Casey Newton

Ship it or zip it. Unless you're actually putting it in people's hands, we usually do not want to hear about it.

Kevin Roose

Yes, but today we are making an exception for the new Anthropic model, Claude Mythos Preview, which was just announced but not released, for reasons that we will talk about. But first, since this will be a segment and a show about AI, our disclosures. I work for The New York Times, which is suing OpenAI, Microsoft, and Perplexity over alleged copyright violations.

Casey Newton

And my fiancée works at Anthropic.

Kevin Roose

Casey, I want to say this is the biggest story of the year in AI.

Casey Newton

Ooh.

Kevin Roose

I know there's been a lot of AI news. I know that people are probably saying, “Oh, here they go talking about another model again.” I am telling you, this is something that people need to be paying attention to because of the implications, because of the way it was rolled out, and because of the model itself, which we will get to. But do you agree that this is a big deal?

Casey Newton

Well, when we were talking about the show this week and kicking around the question of exactly how big we think this is, you pointed out that one question people have been asking this week is, “Are we going to have to rewrite all software?” I feel like usually when folks are kicking that question around, it's a big story.

Kevin Roose

Let's just talk through what was actually announced this week.

Casey Newton

Okay.

Kevin Roose

So on Tuesday, Anthropic announced that it was starting something called Project Glasswing. The name Project Glasswing refers to the glasswing butterfly, which has transparent wings, so it can hide in plain sight. That is thematically important for reasons that we will come back to.

Kevin Roose

Mm-hmm. It's also a delicacy in some countries.

Kevin Roose

I've never had glasswing butterfly. Have you?

Casey Newton

Oh, you've got to try it.

Kevin Roose

Notably, they are not releasing this model to the public because they claim it is too dangerous to do that. Instead, they are giving access to a consortium of tech companies, including Cisco and Broadcom, sort of makers of internet infrastructure, as well as Microsoft, Apple, and Amazon. Basically, every big tech company that is not OpenAI or Meta is getting access to this model, but not general access—just access to do defensive cybersecurity testing, basically to go out and harden their systems, infrastructure, and software before the general public can get its hands on this model.

Casey Newton

So what are some examples of what Mythos was doing in training that so alarmed Anthropic that it came to this point?

2. Mythos Finds Hidden Vulnerabilities

Kevin Roose

Anthropic has been running this model internally for several weeks, and they claim that this thing has found vulnerabilities in every major operating system and web browser. They gave some examples that have already been patched. One of them was that this model apparently found a 27-year-old security flaw in OpenBSD. OpenBSD is an open-source operating system that runs on firewalls and routers. It is a critical security layer on the internet, and it was designed specifically to be hard to hack.

Casey Newton

Right.

Kevin Roose

This model, because of its advanced coding and reasoning capabilities, was able to find this bug that 27 years' worth of professional security researchers had not been able to find.

Casey Newton

What else?

Kevin Roose

Another example was that it found a bug in a piece of popular open-source video software called FFmpeg that had, according to Anthropic, been scanned for bugs 5,000,000 times by automated security tools without finding this critical exploit.

Casey Newton

And that's why it's important to always look the 5,000,001st time, because you might find something.

Kevin Roose

Now, Casey, I think for people who are not cybersecurity experts, it might be worth sketching the context here for how software works.

Casey Newton

Yes.

Kevin Roose

Every piece of software, every operating system, every app, and every web browser that people use is built on a mixture of tools.

Casey Newton

Mm-hmm.

Kevin Roose

Some of those tools are proprietary to the companies that make the software. Some of them are shared, open-source tools that are just in everything. Companies will grab this open-source thing and plug it into their thing.

Casey Newton

Because that's compatible with everything else and saves you a lot of time and trouble.

Kevin Roose

It's already been security-tested by researchers for decades, and these open-source software projects are a big piece of the foundation layer of the internet. What is happening now, according to Anthropic, is that they can basically use this model, Claude Mythos Preview, to proactively go out and find all of the unfound bugs. They call these zero-day exploits, and the model can find them with a speed and efficiency that no human security research team could match.

Casey Newton

It can be difficult to talk about cybersecurity in a way that resonates with people for a couple of reasons. One is that cybersecurity as a field exists almost entirely to alarm people and say, “Here are a bunch of problems, and these are really scary.” I hope that folks in the cybersecurity field would not mind me saying that it is an alarmist profession and that when I've talked to these people over the past 15 years, they've been telling me, “Look, the entire internet is held together with spit and glue, and we're very lucky that there hasn't been a catastrophe yet,” okay? So after all of this news came out, I wanted to talk to some people who are at least not working for Anthropic or this consortium to give me a gut check on how big a deal this is.

Casey Newton

And so I talked to Alex Stamos, who formerly led security at Yahoo and then Facebook, and Alex said, “Yes, this is a big deal.” He was hoping for a long time that we would see a consortium come together like this because of exactly what you just said, Kevin. The intelligence in these machines and their ability to work autonomously are now great enough that they can chain together exploits that human beings either would never see, would take a long time to see, or would never get to because we’re limited in ways that these machines are not. So that got my attention.

3. Anthropic's Risky Cybersecurity Strategy

Kevin Roose

Now, we should also talk about what the strategy is here from Anthropic, because I think a lot of people see an AI company that is known for being sort of alarmist about safety say, “We’ve created this powerful, spooky new model, and we’re not going to show you because it’s too powerful and spooky,” as some kind of marketing tactic. So I think we should just say that is not, to my understanding, the case here.

Casey Newton

No. In my mind, it is obvious why. If you’re a corporation and you release a tool and people with no real technical expertise are able to use it and, within a few hours, discover a novel exploit in the Linux kernel and then take over other people’s machines to cause crimes, you might be held liable as a corporation. You will get in trouble. There will be congressional hearings. So companies, just in their rational self-interest, do not want to sell cyber weapons on the open market.

Kevin Roose

Yes. Also, if this was a marketing strategy, it would be a horrible marketing strategy. The government already thinks you’re a bunch of panicky doomers.

Casey Newton

Yeah.

Kevin Roose

You have a new model that you claim is the most powerful model in the world. So instead of selling it, you give $100 million of Claude credits away to a consortium of companies that includes many of your competitors, which is what Anthropic is doing. That is not how I personally would market a spooky new model if I were in the business of marketing spooky new models.

Casey Newton

Yeah. Now, look, it may be that despite everything that we just said, there is still some marketing benefit to Anthropic from doing this. We know that they saw a huge increase in their revenue after they took that stand against the Pentagon, and in that stand they said, “We are determined to do things in a really safe way.” It seemed like the business world really liked that. And so I could imagine there being a business benefit to Anthropic of coming out and saying, “We have the most powerful model in the world, and we’re not releasing it.” I’m sure that there are plenty of businesses that are salivating over the chance to get their hands on it.

Kevin Roose

But they can’t—

Casey Newton

Right.

Kevin Roose

—unless they are part of this consortium. So they are at least claiming that they are trying to get ahead of what they envision will be a reckoning—that was the word they used—for cybersecurity. And it seems plausible to me that in the next 6 months, every major piece of software in the world is going to need to be patched, rewritten, and rereleased.

Casey Newton

So, just an absolutely massive project. Let me ask you this. Alex Stamos, the security expert that I mentioned, told me that he sees essentially 2 broad possibilities. One is—and this is the good scenario—that there are a finite number of critical bugs and vulnerabilities to be found, and that maybe if we all work really, really hard over the next 6 months, or however long it turns out to be, we will be able to patch those vulnerabilities and our infrastructure will remain safe and stable. The other possibility is that this model is already good enough that it can simply invent exploits that we never would have thought of, and so this will essentially just be a really, really big problem that potentially keeps growing in scope because maybe eventually you hit some sort of true superintelligent point. So I’m curious if you’ve talked to people about what they see the scenarios as, and if you have any thought as to which of those 2 is more likely.

Kevin Roose

So I think it’s possible that they will patch the top 1% of critical software. The stuff that everyone knows is important: your Linux, your very popular open-source libraries, your routing equipment and networking equipment. It seems plausible to me that a couple of companies with the right resources and the right models could find and fix the worst security vulnerabilities. But I also talked to people who were telling me that it’s not as simple as that, because once you get outside that top 1% of critical infrastructure, there are just a lot of machines that are running on old code.

Casey Newton

Mm-hmm.

Kevin Roose

Right? So it’s theoretically possible that all of these fixes could be submitted to the people who maintain these software projects, but, A, there aren’t enough humans to review all of the proposed bugs and fixes, so there is a human bottleneck there, or there is simply a lag between when a piece of software is patched and when the person running the router at the medium-sized business in Tulsa decides to update the firmware or install the security patch. So people can expect a lot of apps that are asking them to update or reinstall their software over the next few months. I’ve started getting a few of these already. Have you started getting these?

Casey Newton

Yeah.

Kevin Roose

Yeah. So I think this is going to be a kind of forced reset for the entire cybersecurity industry and a very significant event in the history of technology.

Casey Newton

Yeah. Well, and just to make it concrete, we are currently at war with Iran, and Iran is currently hacking our critical infrastructure. There was a story in Wired this week about them successfully hacking water and energy infrastructure. Right now, they’re able to do that without a Mythos-quality model. I would be quite nervous about what they could do if something like that fell into their hands. So this really is not an abstract concern that we’re laying out.

Kevin Roose

Right. And we should talk about this government piece of this—

Casey Newton

Yeah.

Kevin Roose

—because one weird characteristic of this moment is that this very powerful, advanced model that Anthropic claims is capable of doing autonomous cybersecurity research and attacks is also from a company that the U.S. government has spent the last several months trying to kill.

Casey Newton

Yeah, yeah.

Kevin Roose

And has tried to declare Anthropic a supply-chain risk. They have ordered all federal agencies to stop using Claude. My understanding is that there have been some conversations between Anthropic and parts of the national-security establishment and apparatus about this model, but it is also simultaneously true that they cannot use this model without running afoul of the administration. So a private company right here in San Francisco currently has a technology that they claim is capable of finding critical security vulnerabilities in every major operating system and web browser in the world, and the U.S. government, to my knowledge, does not have access to this technology.

Casey Newton

Yeah, it does seem like something that our national-security infrastructure would want to have access to. One more piece on the regulatory front: It is crazy to me that model development of this scale and seriousness remains essentially unregulated in this country. Here you have a private company saying, “Well, we have now created software that can create so many different kinds of novel exploits that all software might have to be rewritten,” and they are not really under any kind of regulatory regime. And the regulatory regime that the previous administration tried to put into place was thrown out by the current one because it might harm American competitiveness. So I just want to say that makes me really, really uncomfortable. I think that if you’re making stuff this powerful, regulators ought to be paying attention.

Kevin Roose

Yeah. One interesting historical note that I’ll make here is that, for the past few years at least, there has not been a significant gap between what the AI companies have built internally and what the public has access to.

Casey Newton

Yeah.

Kevin Roose

Maybe there’s a slightly better model that the companies are working on that they need to spend a few months testing before they release it, but—

Casey Newton

Or it runs a little faster than the one that you have access to.

Kevin Roose

Yeah, but there has not been a significant gap since, I think, GPT-2, which was in 2019. That involved some of the leaders of Anthropic who were then at OpenAI, who made a decision to hold back GPT-2 out of fears that it could be used for things like automating propaganda and misinformation.

Casey Newton

Right. In reality, it could barely write a limerick.

Kevin Roose

Yes.

Casey Newton

But—

Kevin Roose

Yes.

Casey Newton

—you know, they erred on the side of caution.

Kevin Roose

They did, and they got a lot of crap for that. People sort of said, “Oh, you’re using this to hype...” Some of the same stuff we’re hearing this week about Anthropic. And I think in that case, they were probably a little overexcited about what this model could do, but they wanted to make sure that they weren’t wrong, and so they held this back. That created a gap of at least a couple of months to maybe a year between what the average person could see and what was happening inside the AI labs. That gap is now open again. There is now a model that you and I cannot use, that our listeners cannot use unless they work at one of these companies in cybersecurity defense, and what the AI companies are claiming.

And I think that is just a very tenuous situation, and I don't like it, but I also understand why I think, in this case, this was the right decision.

Casey Newton

Well, what do you mean when you say that it's tenuous, then?

Kevin Roose

I think as hostile and suspicious as people feel toward the AI industry, that only gets worse if they think that there are secrets being kept in a basement that they can't access.

Casey Newton

Mm.

Kevin Roose

And I think that it creates paranoia and fear. I think that it is generally responsible to have transparency from the AI companies about how capable their models are, and I understand in this case that Anthropic felt like it had to make an exception. But I think this gap may be here to stay—

Casey Newton

Mm-hmm.

Kevin Roose

That is the thing that I'm wondering about.

Casey Newton

I think it probably is. It's worth saying that Anthropic was founded on the idea that if it could build models that were at the state of the art, at the frontier, that it could have some influence over that frontier, and it could guide it to a safer place than it otherwise might have gone. To me, the Pentagon fight and now Mythos are examples of that thesis in action, right? It made the best model, and that gives it some room to try to do a little bit of good, blocking domestic surveillance and autonomous weapons for a little while, or preventing bad actors from getting their hands on tools that could create novel exploits.

At the same time, in order to do that, they had to build the model in the first place. And there is a risk that there is some sort of intellectual property leakage, that somehow all of the innovations that they're building are going to trickle down into other places. And my fear is just that it becomes this self-fulfilling prophecy, right? Where we have to build this frontier even though it's dangerous, and we're going to guide it to the safer place, but you did build the thing in the first place. So I just like reminding people of that tension because it is not actually inevitable that we build these systems. And yet we do often act as if that were the case.

Kevin Roose

Yeah. Last thing, a lot of the people I know who are plugged into the cybersecurity world are being asked right now what people should do about their own security if they are worried that models like this will become public. Should they be locking down all their accounts and moving their cryptocurrency into cold storage? What do you think people should be doing in anticipation that something like this will become public?

Casey Newton

It's funny.

Kevin Roose

I had a friend ask me that just this morning as I was preparing for the podcast.

Casey Newton

And I said, you know, a couple of things. To some extent, we're just going to have to wait. To the extent that any of what we've just described is good news, it is that the defenders appear like they're going to have some runway to fix some really bad problems before the bad guys catch up. So I think we should give them a little bit of room to see what they can do.

If it does emerge that there is a similar model that can wreak havoc, rest assured there will be segments about it on Hard Fork, and we'll have some updated guidance. But I asked my friend, "Do you have a password manager, and do you reuse passwords for the same thing?" And she said, "You know, I've never really been able to get one of those password managers to work for me, and I do sometimes reuse my passwords."

So I said, "Look, if you're looking for something that you can do, just make sure that you have done your basic online cybersecurity hygiene. You should use a password manager. I use 1Password. There are many others out there that are just as good. Don't use the same password for anything. Your passwords should be randomly generated and not the name of your pet or whatever. And then use multifactor authentication where you can, right? So don't let anybody get into your Gmail or your banking account just by typing in 8 letters. You should also be using an authenticator app."

And so those are some of the basic things that I would tell people to do, Kevin.

Kevin Roose

Yeah. I am planning to deal with the possibility of a massive cybersecurity breach by just selectively dribbling out incriminating things about myself. Just trying to get ahead of any hacks that might expose my emails going back decades or anything like that. So I'll just say, in that spirit, I used to like the Black Eyed Peas.

Casey Newton

Mm-hmm. And I still do. Let's get it started.

Kevin Roose

Now, that was a critical vulnerability I just exposed.

4. Sam Altman Faces Scrutiny

Well, Casey, the talk of the town in San Francisco this week has been—well, there have been two talks of the town. One we already covered in our AI, that was Claude Mythos.

Casey Newton

This town conducts multiple conversations at the same time. But one of them—

Kevin Roose

We're amazing at multitasking.

Casey Newton

Yeah.

Kevin Roose

The other big talker this week has been this big piece in The New Yorker about Sam Altman.

Casey Newton

Yes. More than 16,000 words devoted to a question that has come up once or twice on Hard Fork, Kevin, which is: Can Sam Altman be trusted?

Kevin Roose

Yes. The writers on the piece are Ronan Farrow, famous for his work on the Harvey Weinstein investigation and others, and Andrew Marantz, who is a good friend of mine and a longtime writer at The New Yorker. They worked on this piece for a very long time, talked to many, many people in and around Sam's orbit, and tried to answer the question of who this guy is.

Casey Newton

Yeah. And also, why does that matter, right? We're talking during a week where these systems have arguably experienced a step change in what they can do, and I think those kinds of advances should naturally draw more scrutiny onto the people running these companies. What do they know about who they are, how they operate? Are they honest with each other? And this piece offers one of the more comprehensive portraits that we have had so far, I would say, on that question.

Kevin Roose

You know, Ronan Farrow investigating you has to be one of the scariest experiences.

Casey Newton

Oh, I know.

Kevin Roose

You pick up the phone, and it's like, "Hi, it's Ronan."

Casey Newton

It also seems hot, too, you know? That's what everyone wants: just a really handsome man asking them a lot of questions.

Kevin Roose

Okay. So let's bring in Ronan Farrow and Andrew Marantz. Ronan Farrow and Andrew Marantz, welcome to Hard Fork.

Ronan Farrow

Thank you, guys.

Kevin Roose

Happy to be here.

Andrew Marantz

I mean, truly long time, first time, and in fact, I brought receipts to that effect. This is your show. You can take or leave this in the edit, but I wanted to show what a devoted longtime fan I am of Hard Fork. I know the show well. I know you guys like merch, and I know you guys like disclosures. But you don't have any disclosure merch, to my knowledge. So I had these made for you.

Kevin Roose

Come on.

Andrew Marantz

One for each. One for you, one for you. I'm going to put it in the mail after we get off, but—

Kevin Roose

One of them says, "I work for The New York Times, which is suing OpenAI, Microsoft, and Perplexity for alleged copyright violations." The other one says, "And my fiancée works at Anthropic." Oh, my gosh.

Casey Newton

That is amazing. And—

Andrew Marantz

So, I mean, time-limited. It's going to be a time capsule. But, I mean, they're made at the print shop in Brooklyn, one of a kind.

Casey Newton

Wow.

Andrew Marantz

Exists nowhere else on Earth.

Casey Newton

That's incredible.

Kevin Roose

You are a hero.

Andrew Marantz

And I think I should also make—

Kevin Roose

Is this payback for when I gave you a hat at your wedding?

Andrew Marantz

And I gave you one at your wedding, so I think we're even on that.

Kevin Roose

That's true. We have a sort of a theme going on here.

Andrew Marantz

Yeah.

Kevin Roose

Okay.

Andrew Marantz

Right. Well, that's also our disclosure, which is that Kevin and I are buds and have known each other forever. So actually, Casey, you can come to me anytime. I know you guys like to rib and roast on the show. So you can come to me behind the scenes for any roastable Kevin material at your leisure.

Casey Newton

Oh, my dream has been to get The New Yorker to investigate Kevin Roose. So you guys really could not have come along at a better time.

Andrew Marantz

We're on it.

Kevin Roose

Don't tempt us.

Casey Newton

Yeah.

Kevin Roose

I'm not picking up the phone.

Casey Newton

Yeah.

Kevin Roose

Okay. Let's talk about this big piece that you both just published in The New Yorker. The title of the piece is “Can Sam Altman Be Trusted?” Usually, there's this sort of folk rule about headlines that end with question marks, which is that the answer is always no. So I want to put this question to you: Can Sam Altman be trusted?

Ronan Farrow

Well, I think one important thing to note is the piece is really forensic, to a point where I've been happy to see there's a range of reactions. There are people who have answered that question in a very severe way and looked at the fact pattern and the documentation laid out here and said, “This is someone who poses an acute danger and should be kept away from an authority position.”

And then there are people who—I mean, hilariously enough, my mother called me, and she's like, “You know, I kind of like him.” I think that is a true reflection of our intentions. In this case, as you might imagine, there was deep consultation with all of the subjects of the reporting to really understand their feelings. Any time we thought there was a persuasive argument from Sam or anyone else that something shouldn't make it in or that something would be sensationalist, we really carefully discussed that editorially.

So the result is very even. On the question itself, what we lay out is something that is remarkable, even against the backdrop of the culture of mistrust in Silicon Valley, where everybody understands and expects that being a founder means telling different audiences different things at times, to some extent, and where everyone understands that the entire enterprise is built on hype long before there is an actual actionable deliverable product. Even against that backdrop, there is an extraordinary preponderance of people who emerge from interactions with Sam Altman, including close, years-long ones, with really active complaints and allegations that he lies repeatedly about things big and small.

Andrew Marantz

Hmm.

Andrew Marantz

Well, one of my favorites was when you quote him telling you that he wears a gray sweater every day to avoid decision fatigue, and then he shows up for his next interview in a green sweater. That felt like a really satisfying detail.

Ronan Farrow

That was just for you, Casey.

Andrew Marantz

Thank you. I appreciated it.

Ronan Farrow

I was wondering if people were going to catch that.

Andrew Marantz

I appreciate that eye for fashion that you so rarely get in these tech profiles.

Ronan Farrow

Andrew was our fashionista in the writers' room.

Andrew Marantz

Always.

Ronan Farrow

But that's the kind of thing where we didn't want to make too much of that, right? Because it's like, oh, we caught you in this deep hypocrisy of choosing a green sweater. And this is consistent with a lot of the things people say throughout the piece and throughout the career of Altman and OpenAI: There isn't this one smoking-gun thing where he's caught with his hand in the cookie jar.

It's this allegedly longer, more subtle accumulation of facts, which my glib and annoying way of describing it is that the fabled memos and documents that were compiled, which led to him being fired in 2023 and have dogged him throughout his career, really shouldn't have been a secret bullet-pointed list. They should have been a 16,000-word New Yorker piece, because they only really make sense when you lay them all out together in narrative form.

Andrew Marantz

Yeah, you guys mention in your story that there have been these rap sheets circulating about Sam inside OpenAI and other parts of the AI industry for years. One of them was compiled by Dario Amodei when he worked at OpenAI under Sam Altman. One of them, you said, was maybe circulated by some allies of Elon Musk and people who are opposed to OpenAI.

Give us some behind-the-scenes details about what is being said by whom, how, and to what ends about Sam Altman in Silicon Valley.

Ronan Farrow

Well, it was really important to us to filter for the obvious competitive incentives out there. There are people who are massively incentivized to go after Sam Altman, and the reality is that there are very firmly evidence-based critiques, many of which are promulgated not just by the rivals—although they're certainly amplified by them happily—but also by more neutral figures and people who are just technologists who aren't in the fight.

And then there is the white-hot center of the rivalry, the stuff you mentioned, which I think is in a very different category: Elon Musk and other direct competitors really amplifying everything they can come up with. In some cases, we document things that are inflated or trumped up or just seem not to be true. So Elon Musk in particular has intermediaries circulating some pretty spicy and pretty unsubstantiated material in Silicon Valley, and we talk about that.

Andrew Marantz

I really appreciated that about the piece, because this has become more salient over the past year as these rivalries heat up and you hear more and more of these scurrilous rumors. And while I do think this winds up being a pretty damning portrait of Sam on the whole, you do also point out that in some very real ways, he's the subject of a legitimate smear campaign.

Ronan Farrow

Yeah.

Andrew Marantz

Oh, yeah.

Ronan Farrow

I think that's absolutely accurate. Andrew?

Andrew Marantz

We were trying not to go in with the naivete of, like, “Can you believe business titans are being mean to each other?” But the level of this really does seem shocking and unprecedented. It's consistent with people who think of this as, like, whoever gets the ring first will control the world. It just seems like all bets are off.

As a reporter, it's very challenging to ask: Do you bring up the scurrilous rumors to knock them down? We had months of conversations about how best to do that.

Ronan Farrow

Hmm.

Andrew Marantz

So there's been a lot of reporting on Sam Altman, especially around the board coup a few years ago. Could you maybe give us the 2 or 3 things that you think are new and important from your reporting that rise above the rest in terms of people's understanding of Sam Altman and OpenAI?

5. The Investigation Finds New Evidence

Ronan Farrow

So I think there are things here that put to rest some of the longstanding rumors.

Andrew Marantz

Altman has always said—and Paul Graham at Y Combinator has always said—he was not pushed out; he left of his own volition. It really seems from our reporting that that was not the case. They have talked a lot about their fundraising in the Gulf, in the Middle East, as innocuous: All businesses do this. It really seems from our reporting that the relationships Sam has cultivated with some Emirati and Saudi royals are deeper than was previously realized. Ronan, what am I missing? There are several things like this.

Ronan Farrow

We just didn't really know in full what was in the Ilya Sutskever memos. We didn't really have the detailed, multiple-sourced, heavily documented accounts of the individual proof points that were offered in those memos. We didn't have the contents of those Dario Amodei notes, and we didn't have a lot of these people on the record yet.

So I think, actually, in a way, that was a disservice not only to Sam's critics but also to Sam himself. There was a bit of a veil of mystery, and that wasn't purely accidental. One of the things we document that's new here is that, as a condition of the exit of the board members who had moved against Sam—whom he wanted out—they insisted on an outside investigation. What happened there is, in my view, quite extraordinary.

Kevin Roose

Mm-hmm.

Ronan Farrow

At private companies, sometimes reports of this type, when a law firm is brought in to restore legitimacy, can be kept out of writing. Often it's to limit liability, and often legal experts say it's a bit of a red flag. This is a different kind of case. This isn't just any private company. This is a high-profile scandal that engulfed Silicon Valley when Sam was fired.

Andrew Marantz

And ostensibly—

Ronan Farrow

And—

Andrew Marantz

At a nonprofit.

Ronan Farrow

At a 501(c)(3), exactly. And so there were stakeholders, not just in the public but within this company, for whom that would be the bare-minimum threshold, right? Senior executives thought, “Okay, we're going to get some kind of at least detailed summary of what this law firm investigation found when they invoke it to rubber-stamp Sam coming back.”

And instead, what happened was an 800-word press release that said there had vaguely been a breakdown in trust and offered very few other details. What we report in this piece for the first time is there wasn't a report.

For years, people were asking, “Where’s the report? Where’s the report?” There wasn’t a report because it was kept out of writing. This is no longer just a speculative supposition. One of the two board members whom Sam helped select, who oversaw this process, now explicitly says, “Well, a written report was not needed.” That’s now their line on this.

Casey Newton

Yeah. I’m glad you brought it up. It was actually my favorite detail in the piece because it was something I’d been curious about forever.

Andrew Marantz

Mm-hmm.

Casey Newton

The thing that I found most interesting in the piece was the people who spoke on the record, or at least gave you quotes—some of them unattributed—about Sam. These were people who, I think, might previously have supported him, or at least felt like there was no upside to talking about him negatively in public.

There was a Microsoft executive quoted in your piece as saying that there’s a small but real chance he’s eventually remembered as a Bernie Madoff- or Sam Bankman-Fried-level scammer. There’s another unnamed board member who said, quote, “He’s unconstrained by truth,” and said that he has, quote, “an almost sociopathic lack of concern for the consequences that may come from deceiving someone.” I haven’t been on a lot of corporate boards, but I think that is something that’s quite rare to hear a board member say about a CEO of a company. I’m curious: When you were weighing these statements, did you feel like there are people who used to be fans of Sam who have soured on him, or are these people who have really held a grudge against him for a long time?

Andrew Marantz

The thing that you point out about people changing their tune over time, I think, is an integral part of what we document in the piece. The fact that Sam Altman comes up through this Y Combinator world is not incidental. The fact that he has an investment portfolio in, by his own estimation, about 400 other tech companies, and that he has sat on everyone’s board and everyone has sat on his board, is also significant.

I think our line about this in the piece is that we spoke to people who are Sam’s friends, Sam’s enemies, and, given the mercenary nature of Silicon Valley, some people who have been both. Given that that’s the landscape, you’re going to have people who change their tune as the wind blows in different ways, and that’s a lot of how Altman’s been able to weather a lot of this stuff in the past.

Ronan Farrow

One thing that results from that spread of opinions is, to your question about evolving takes on Sam, that there’s definitely a class of nuts-and-bolts investors—prominent people in Silicon Valley who are really pragmatists, not just safetyists, and who are growth- and business-oriented—who told us that at the time of Sam’s firing, of the blip, they gave him the benefit of the doubt.

That was especially because of the factor we talked about before, where there was a dearth of clear information. In that void, a lot of prominent people gave him the benefit of the doubt and saw only upside in bringing him back and removing the board that tried to fire him. There are a number of those prominent people in that category now who say, “I don’t know that I would have given him the benefit of the doubt if I knew everything then that I now know.”

Kevin Roose

It just strikes me, though, that everyone who digs into this winds up coming back with essentially the same story. You know what I mean? There aren’t 17 versions of Sam Altman out there, depending on which reporter calls which different source. I feel like we now know the broad outlines of this person’s psychology.

Casey Newton

I don’t know. I want to challenge that. I do talk to people who are big fans of Sam, some of whom work for him and some of whom don’t. Clearly, this is a guy who has been able, at various points, to lead very important technology projects and rally people behind a vision. These people are not mindless sheep. They’re critical and discerning—

Kevin Roose

Hmm.

Casey Newton

—and thoughtful people. I don’t want to seem like I’m taking Sam’s side on anything, but I think that there are a lot of people with very strong feelings about Sam Altman, positive and negative. I think the positive side tends to be more people defending him in private, and the public side tends to be more people criticizing him.

But I don’t know. I guess, for Ronan and Andrew, do you feel like there are vocal supporters whom you came across in reporting this story who had no direct employment relationship with OpenAI or Sam, or weren’t leading companies that he had invested in, who were like, “Yeah, this guy seems pretty good and smart and talented”?

Kevin Roose

Yeah, it was an 11-year-old—

Casey Newton

Yeah.

Kevin Roose

—who used ChatGPT to pass sixth grade.

Casey Newton

Oh, my God.

Andrew Marantz

No, no, there were legitimate defenders of Sam on a number of these fronts whom we talked to, for sure. I think a lot of this has to do with what baseline expectation you’re starting from. If you think of this as a business, and you start from the premise that people who run giant, successful businesses have to say a lot of different things to a lot of different people, why is this even a story?

I think, though, there’s a kind of level-setting here. One of the things you can do when you take a big putting-everything-in-one-place narrative effort like this is start from the beginning and remember what the original pitch was. When you go back to what the original pitch was, the defense of “Why are you guys being so naive? This is a normal competitive business” starts to feel less convincing.

If you pitched this as a nonprofit, safety-focused research lab that would aggressively comply with all regulation, were the people who believed that naive to believe it at the time? That’s when the defenses start to feel a little more pressured to me.

Kevin Roose

Yeah. Also, for what it’s worth, is it really a story that this guy is telling different things to so many different groups? That’s not really a story that gets told about Satya Nadella. It’s not really a story that gets told about Sundar Pichai. It’s not really a story that gets told about Tim Cook. There does seem to be something really unusual here.

My question for you guys, now that you’ve spent so much time immersed in this company, is: What do you think it means for OpenAI?

Andrew Marantz

Well, luckily, we have a really robust independent tech media, so I was going to tune into TBPN and see what its independent journalistic take on this would be.

Casey Newton

Do you want to give listeners who may not be familiar with what you’re talking about some context here?

Andrew Marantz

I think the day after our piece closed—Ronan, or something, like late last week—OpenAI acquired TBPN, which is this big tech chat show. So that’s one aspect of this answer: As OpenAI expands and grows, they seem to be buying up more of the press infrastructure to tell their own story.

Ronan Farrow

Relatedly, by the way, a lot of announcements over there were concentrated around when they knew we were going to be running, and developed during the period when we were in these intensive conversations with them.

Kevin Roose

Hmm.

Ronan Farrow

Many of them pointed at the topics in the piece.

Andrew Marantz

Hmm.

Ronan Farrow

They announced this new safety fellowship that’s very AI-y. They announced this new governance plan that’s very AI-y and ethereal, but they’re meant to, I think, occupy space in the conversation on the same topics.

Andrew Marantz

And look, I mean—

Ronan Farrow

Andrew—

Andrew Marantz

... everyone, Ronan, you should say more about this, but everyone, including Altman and the OpenAI executives we spoke to, recognizes the economic pressures here. I think you guys were there when he said, “Oh, yeah, it’s definitely a bubble, and someone’s going to lose a phenomenal amount of money,” right?

Kevin Roose

Yeah.

Andrew Marantz

So even putting the sci-fi Skynet stuff aside, the economic pressures are unavoidable, and a lot of it has to do with this pitchman rhetoric, the exact thing we’re talking about. These things are contingent. It’s not, “Will it be a bubble or not?” It’s, “How hyped up will the cycle get?” That’s a byproduct of how people like Sam go around the world talking about it.

Casey Newton

Yeah. I want to ask a basic question that I think people have probably raised with you, which is: Why does it matter who Sam Altman is?

If what we’re talking about is a technology that could have profound implications for national security, the economy, and potentially the future of humanity, it doesn’t seem obvious to a lot of people why it matters who is running these companies. A very nice person who is very honest and transparent in all their dealings could still release a rogue superintelligence that blows up the world, and a very manipulative person could release a very aligned model.

So what we should be paying attention to are the models themselves, not the people running the companies that make the models. I’m not saying I believe that, but I’m curious: What do you make of that argument, that we are focusing too much on the humans and not enough on the technology?

Ronan Farrow

We probably both have thoughts on this.

I think I have two. The first is that it’s worth noting that, while reasonable minds could perhaps differ on the question you just posed, the answer provided by Sam Altman and the founders of OpenAI was very clear. It was actually part of the way the entire enterprise was structured when it was founded as a nonprofit: They talked a lot about avoiding an AGI dictatorship. They really believed that the person who gets there first and has the most power over this technology is pivotal. Individual integrity is formative to the way the technology goes, the way it’s controlled, and the way it’s used.

The other thought that I have is that, in my mind, you raise a valid point. More significant than any of this are the structures around these individuals. We have a technology emerging that could really affect us all in all of the existential ways you just mentioned, and we don’t have the regulatory guardrails to keep an eye on these folks. We are completely ceding the power to these individual companies and their whims, the mud fight between them, and the quality control that each of them has or lacks. I think that, to me, is the big question. The integrity of an individual figures in that, and it’s important, but it reveals the weaknesses in the system. If you have someone who potentially lies all the time and could, in the eyes of many critics, be a danger, the important thing is to have the structures that account for that.

Casey Newton

There’s a great quote that you guys have in the piece from one of his former co-workers, who talks about how Sam now has this track record of setting up these elaborate guardrails to keep him in check and then skillfully navigating around them. And it made me wonder if you had seen this piece in The Information this week about tensions that are being reported between Sam and his chief financial officer, Sarah Friar. She’s reportedly expressed doubts that OpenAI will be ready for an IPO this year. And according to the story, Sam has noticeably and awkwardly excluded her from some conversations related to the company’s financial plans and kept her out of some key meetings.

I read that and I was like, “Well, this is exactly what you guys are writing about in your piece,” right? You sort of bring in somebody whose job it is to look over the finances of the entire company and get it ready for an IPO, but then, for whatever reason, we’re going to sort of exclude her from some meetings. Anyway, I just feel like we really are seeing the exact pattern that you guys are writing about now repeating in real time.

Andrew Marantz

Yeah, and just to agree with all of this, I think the thing that Kevin’s bringing up—given the power of this, why are we focusing on one personality?—is very legit. I think that this is way beyond one person. This is way beyond one personality. It’s not like the point of the piece is “Sam shouldn’t be AGI dictator, so Elon should, or Demis should, or whatever,” right? It’s to point out the fact that we’re having a discussion about AGI dictators at all is insane. These guys know it’s insane, and yet this seems to be the race that they see themselves being in.

Casey Newton

When he was fired, he was brought back in part because I think no one could really imagine an OpenAI without Sam Altman. Do you think that’s still the case?

Andrew Marantz

I don’t think it’s unimaginable anymore. I think part of reaching the scale that they’ve reached is that you can have a Steve Jobs figure be replaced by a Tim Cook figure, right? It seems like it’s inseparable from reaching this scale that that becomes at least a possibility in people’s minds. Right, Ron? I mean, does that strike you that way?

Ronan Farrow

Absolutely. I think the landscape has changed substantially over the period of time we were reporting this story. The fact that gradually more and more people were talking openly about this critique is very telling. We report in the piece that there are periodic spasms of senior executives at OpenAI talking about succession again. Of course, the company denies this. But it’s also very interesting that, in recent forms of that discussion, there has been talk about Fiji Simo being sort of the first potential successor candidate who could slot into any ideas of that type that circulate.

Between our asking about that and the piece coming out, obviously, Simo has now gone on leave for medical reasons. There’s a lot of reshuffling. We see it in the Sarah Friar case. I think you’re right to link it to that quote that’s in the article about constraints being sidelined. And yet I think these doubts and questions persist and are now much more out in the open.

Casey Newton

Yeah, on the leadership question, it just strikes me that, for somebody who I assume wants to stay CEO for a long time, it’s interesting to me that he’s hired so many former public company CEOs to be his top lieutenants, right? It’s like he has the former CEO of Instacart there. He has the former CEO of Nextdoor there. He has the former CEO of Slack there. So you’re bringing a lot of really sharp and pointy elbows into the room when you do something like that. I’m trying to tell Sam that there’s danger here.

Ronan Farrow

Pro tip: If you’re listening, Sam.

Kevin Roose

Yeah.

Ronan Farrow

There are people in this piece talking about earlier chapters of Sam Altman’s career where they feel he was deliberately avoiding that.

Kevin Roose

Hmm.

Ronan Farrow

Actually, part of what underpinned the terrible fumbling of the firing effort was a feeling that Sam had stacked the board with, as one former member put it, JV people. Certainly, if we’re being more charitable than that, they were people who were unprepared for the ruthless corporate warfare that ensued. And I think one thing that has accompanied the emergence of this as a more openly discussed critique is that there are more people around this company, more stakeholders wanting professionalizing influences in the mix.

Casey Newton

I have to ask about one detail that I loved in the piece, which was that the first time that Sam Altman and Dario Amodei were scheduled to meet, they were going to meet at an Indian restaurant for dinner. This was back in, I guess, 2015. And Sam texted him and said that his Uber had gotten in a crash and he was going to be 10 minutes late to dinner.

Now, you did not editorialize on that piece, but knowing you both, I’m sure that you went back through the Uber FOIA requests and found the logs of Sam Altman’s Uber ride that night. Is it your belief that Sam Altman’s Uber actually got in a crash? I think we’re just going to leave that as non-editorialized and let it stand right there by itself. I mean, we also had this conversation and really liked just presenting that uninflected for consideration.

Kevin Roose

Okay, if you are the Uber driver who was driving Sam Altman to dinner with Dario Amodei and you’re listening to this show, we do want to hear from you. We do want to hear your side. hardfork@nytimes.com. We will get to the bottom of this.

Kevin Roose

We will.

Casey Newton

Well, it’s a great piece. People should go read it. Please do not investigate any other AI companies before my book comes out.

Kevin Roose

Yeah.

Kevin Roose

It was a very stressful week for me.

Casey Newton

Yeah. Why don’t you guys take a nice long summer break before you get back to it?

Kevin Roose

Yeah, look into some politicians or Hollywood executives or something.

Casey Newton

We’ll send you some names.

Kevin Roose

Yeah.

Casey Newton

Luckily, it takes us as long to write a piece as it takes you to write a book.

Kevin Roose

Exactly. You’ll beat us if we do anything else.

Casey Newton

There are two of you; it should be faster.

Kevin Roose

Totally.

Casey Newton

Ronan, Andrew, thanks so much for coming.

Casey Newton

Thanks, guys.

Ronan Farrow and Andrew Marantz

Thanks, guys.

Casey Newton

Thanks, guys.

Casey Newton

Your hats are in the mail. When we come back, what our Spanish-language friends would call una cosa buena.

Kevin Roose

Did you just Google that?

Casey Newton

No.

Kevin Roose

You Claude’d it?

Casey Newton

Yes.

Kevin Roose

Okay. Oh.

6. Artemis II Restores Wonder

Kevin Roose

Well, Casey, it's been a pretty heavy show today. So we thought we would end on a positive note with our segment called One Good Thing.

Casey Newton

Yeah.

Kevin Roose

Okay. Casey, I am in love with this space mission.

Casey Newton

Hmm. Yes.

Kevin Roose

The NASA Artemis II mission. I have been totally and earnestly obsessed. My wife was like, “You sure are talking about this space mission a lot.” I have been glued to this thing, and I have been filled with a childlike glee and wonder that I did not know I still had the capacity to feel.

Casey Newton

Now, what exactly are they doing on this mission?

Kevin Roose

Orbiting the Moon.

Casey Newton

Mm-hmm.

Kevin Roose

They are going farther than any humans have gone from Earth before: 252,756 miles from Earth. And if you're wondering how many miles that is, The New York Times had a helpful comparison list.

Casey Newton

And what did they find?

Kevin Roose

You would need a chain of 2.37 billion Nathan's Famous hot dogs to cover the distance that this spacecraft has gone from Earth.

Casey Newton

That's great. Something we can all easily visualize. Thank you for that comparison.

Kevin Roose

Casey, I am learning things that I never expected to learn. I've been watching this with my kid. I have become completely obsessed with concepts and terms that I did not know a week ago, including corona structure.

Casey Newton

Mm-hmm.

Kevin Roose

The terminator line.

Casey Newton

Ooh.

Kevin Roose

Which I know you're wondering: That sounds scary.

Casey Newton

Yeah.

Kevin Roose

It's actually the line that separates the sunlit side of the Moon from the side that is dark.

Casey Newton

Oh.

Kevin Roose

I also learned that we don't call it the dark side of the Moon. That's not the preferred—

Casey Newton

Nomenclature?

Kevin Roose

—astronomical term. It's—

Casey Newton

What do we call it?

Kevin Roose

The far side of the Moon.

Casey Newton

The far side of the Moon.

Kevin Roose

I'm obsessed with all of these astronauts. There are 4 of them up there: Victor, Christina, Jeremy, and Reid. This is my Mount Rushmore. I love these people, who I've never met. They are adorable, they are incredibly brave, and I think we should go to the Moon every single year. I think we should give NASA whatever budget it needs to do this, because this has reignited my faith in humanity.

Casey Newton

Absolutely. I also saw somebody on social media posting that because the mission specialist Christina Koch had communicated with Houston's Jenny Gibbons during the mission, this mission actually passed the Bechdel test—which you don't often see on these missions. So I thought that was cool. Also, somebody pointed out, they said, “You know, the coolest thing about going on one of these missions, Kevin, would be leaving Florida at 5,000 miles an hour.” So that resonated with me as well.

Kevin Roose

Okay. You're more—

Casey Newton

Yeah.

Kevin Roose

—interested in the jokes. I am filled with childlike wonder over here, and I just think this is the coolest thing imaginable.

Casey Newton

It is very cool. Recently, I had an opportunity to go stargazing. I'm not sure if you've been stargazing recently.

Kevin Roose

Mm.

Casey Newton

I was up on Mauna Kea on the island of Hawaii. We had a really cool telescope there with our guide, and I got to stare at the face of the Moon.

Kevin Roose

Mm.

Casey Newton

And it inspired a childlike sense of wonder in me as well, but it did not make me want to go there because it looked quite bleak, actually.

Kevin Roose

You wouldn't go to the Moon?

Casey Newton

No, there's no Wi-Fi.

Kevin Roose

Okay. Casey, what is your One Good Thing this week?

7. Acme Weather Revives Dark Sky

Casey Newton

Today, Kevin, I want to talk about the only thing that can compete with the Moon when it comes to inspiring childlike wonder in a person, and that is a weather app.

Kevin Roose

Okay, I'm listening.

Casey Newton

Recently, I was reading about these entrepreneurs, Adam Grossman, Josh Reyes, and Dan Bruton, and they are the team behind Acme Weather, which you probably have not heard of yet, but I bet you've heard of Dark Sky.

Kevin Roose

Yes.

Casey Newton

Dark Sky was, by consensus, the best weather app on iOS, and while it rained during the 2010s—and I'm using “rained” in the nonmeteorological sense—and now I am using it in the meteorological sense, it would tell you whenever it rained.

Kevin Roose

Very good app. All right, Steve.

Casey Newton

So this app was bought by Apple in 2020, which was a head-scratcher. Apple already had a weather app. It was fine. And then Apple sort of integrated some of its forecasts and some of its other features into its Weather app, and then shut Dark Sky down in 2022. This made people really sad because I think a lot of us feel, myself included, like the Apple Weather app has never lived up to what Dark Sky was in its heyday.

Kevin Roose

Yeah. It's like a prediction mark. It's like, you know, maybe it's going to rain.

Casey Newton

Exactly. Well, these guys get back together, and they say, “Frick it, we're doing weather apps again.” And they make Acme Weather. You can download this now for iOS. It is apparently coming later to Android. And I know what you're thinking, Kevin, which is: What could you possibly build in 2026 in a weather app that could differentiate it from all the other weather apps that are already on the market, right?

Kevin Roose

Yes.

Casey Newton

Are you wondering this?

Kevin Roose

I am wondering this.

Casey Newton

Well, let me tell you a few things. Number 1, they don't just tell you the weather; they show you a range of possibilities in a line chart. So most of the time it'll be like, “Yeah, it's going to be 63 degrees in San Francisco today,” but every once in a while there's a lot of volatility in all the different signals that they use to predict the weather. And then you say, “Okay, I don't actually know what I'm walking into today. I better bring a couple of layers.”

Kevin Roose

This is the weather app for rationalists and other believers in Bayesian statistics.

Casey Newton

Exactly. Some of the other things that this app does: They will send you a push notification if they think there's going to be lightning in your neighborhood.

Kevin Roose

Okay.

Casey Newton

They will also do that when they think a sunset is going to be beautiful wherever you happen to be.

Kevin Roose

Wow.

Casey Newton

They'll send you an umbrella reminder if it's going to precipitate in the next 12 hours, and they'll send you a sunscreen alert when the UV index is high. But I'm saving my last 2 favorites for the end. Number 1, they will send you an alert when the aurora borealis may be visible where you are.

Kevin Roose

That's beautiful.

Casey Newton

I haven't gotten that notification yet, but I wake up every day hoping I'm going to get my aurora borealis notification.

Kevin Roose

You have to go to Scandinavia, I think.

Casey Newton

Number 2, and this is just in time for Pride, they will tell you when there is a rainbow in your neighborhood.

Kevin Roose

Wow.

Casey Newton

Are you kidding me? This is such a good idea for a weather app.

Kevin Roose

Yes.

Casey Newton

Who does not want to be sitting at your wage-slave job? You haven't been outside in 7 and a half hours, and then Acme Weather tells you, “Hey, guess what? There's a rainbow in your neighborhood.” You're going to book it outdoors, and you are going to behold the majesty of creation, Kevin.

Kevin Roose

How are they possibly collecting that data?

Casey Newton

Well, interestingly, they're taking this Waze-like approach, where they're inviting their community to submit reports.

Kevin Roose

Hmm.

Casey Newton

And so if a bunch of people say, “Hey, rainbow in my neighborhood,” they're going to go out and send out a notification.

Kevin Roose

Wow.

Casey Newton

So now look, this app does cost $25 a year, and probably most people out there are perfectly content with the free weather app on their phone. That is fine for you. But as somebody who loves cool things, new ideas, and people having fun, I just wanted to shout out Acme Weather because I think it's a really cool thing.

Kevin Roose

Now, what is the likelihood that this app will be purchased by Apple and then shut down?

Casey Newton

I mean, if that happens, I hope these guys get paid again. Because somebody has to move the weather app industry forward, and these are the folks who are doing it.

Kevin Roose

I love that. “Grandpa, how did you make your fortune?” “Well, I built 17 weather apps that were identical and then sold them all to Apple.”

Casey Newton

I also think it's inspiring that at a time when some companies are like, “We're going to make a system that's going to force the world to rewrite all software,” there are other guys who are like, “What if there's a rainbow in my neighborhood? I want to find out about that.” And those are the people that I want to highlight on today's show, Kevin.

Kevin Roose

Okay. Well, download Acme Weather before the heat death of the universe renders weather irrelevant.

Casey Newton

And tell us whether you liked it.

Kevin Roose

That was a good thing.

Casey Newton

Thank you.

Kevin Roose

Thank you for alerting me to this wonderful rainbow detector.

Casey Newton

Well, thank you for alerting me to the existence of the Moon.

Kevin Roose

I know you weren't a big believer in the Moon before, but hopefully I've convinced you today.

Casey Newton

Well, somebody told me something about a soundstage and, you know, maybe the landing was faked, so I've just been curious.

Kevin Roose

I think we're the only podcasters who actually believe in the Moon landing.

Casey Newton

Yeah, that’s our competitive advantage.

Kevin Roose

Hard Fork, where we believe that people have been to the Moon.