[BidClub_]
Hard Fork · · 76 分钟

Grok的深度伪造灾难:有人能阻止Musk的AI聊天机器人吗?| EP 173

Kevin RooseCasey NewtonKate Conger

YouTube
TL;DR
  • Grok最具影响的变化,是非自愿色情图像生成已成为X内置的公开、按需功能,而不再是私下流传的边缘工具。 用户无需越狱,只要输入“把她换上比基尼”之类的提示词;Kate Conger追溯到2025年6月和7月的案例,并称下架有时延迟36–72小时,其中包括一名被反复针对的14岁未成年人。

  • 主持人认为,这不只是安全失误,更是一套追求互动量的策略:Elon Musk曾要求Grok团队让产品走红、变得更大胆,而X的管理层在丑闻持续期间仍庆祝互动量。 Casey直白的商业判断是“让色情成为我们业务的支柱”,但Kate描述的是一款分裂的产品:在X上充当“愤怒诱饵机器”,同时维持一个更克制的聊天机器人——也就是公司对外授权和销售的那一款。

  • 由于是X自己的AI在生成并发布图像,而不只是用户在发布,X正面临不断加码的国际审查,以及美国少见的潜在法律责任。 法国称这些色情内容明显违法,英国、欧盟和印度释放了采取行动的信号;《Take It Down Act》在2026年5月生效的期限将建立受害者申请下架的流程,却没有要求X阻止图像生成。Kate援引一名律师称,《通信规范法》第230条或许无法保护“他们的产品”所实施的行为。

  • Claude Code似乎已经从令人惊艳的演示跨过了实用生产工具的门槛,尤其是因为这个智能体如今能直接在终端调度工作,非程序员也能使用。 主持人将这次跃迁与Opus 4.5联系起来:Andrej Karpathy写道,“作为程序员,我从未感觉自己落后这么多”,而Google工程师Janna Dogan称,Claude Code用1小时复现了她所在团队此前花1年打造的分布式智能体编排器。

  • 低成本定制软件开始侵蚀简单订阅产品的护城河,但支持服务和运营复杂度仍让老牌厂商占优。 Casey用1小时做出了替代Squarespace网站的版本,原网站年费约200美元;Kevin用20分钟替换了一个年费192美元的网站,又在约2小时内做出Pocket的克隆版,随后用5分钟加入文字转语音功能。他对SaaS买家的问题是:“我为什么要给 Salesforce 付钱?”

  • 编码智能体同时意味着创作杠杆、劳动力压力,也预示着更深层的AI安全问题。 Casey感觉“自己像拥有了超能力”,但也承认网页设计师和程序员可能感受到的是AI眩晕或工资压力;Kevin担心,把“整台电脑的方向盘”交给一个无法验证的系统,正指向AI实验室更大的目标——让AI能够改进AI。

  • Casey对Reddit的调查表明,AI已经把制造证据的成本压低到足以通过记者第一轮筛选的程度。 一名自称Uber Eats内部人士的爆料者,把AI生成的工牌与一份18页、为每项爆料提供支持的技术论文配在一起;Gemini通过狭义的SynthID检测识别出工牌,尽管另一款图像生成器也可能生成同样的工牌;原帖获得近80,000个赞,一张截图在X上的浏览量达到36 million。新的规则是“升级我们的认知卫生”,因为如今伪造看似可信的文件可能只需几秒,而不是几周。

摘要 · 为研究而整理的核心内容

1. Grok让“脱衣生成”变得无门槛且公开

  • Casey注意到,X用户突然开始要求Grok让女性脱衣、给政治人物换上内衣,或脱掉某人的裤子。Kevin将更广泛的“脱衣生成”市场追溯到2023年:当时生成器能力提升,人们发现男性愿意为非自愿色情图像支付“大把大把的钱”。

  • X此前曾表示,自己获得了Black Forest Labs的图像生成授权,随后在2024年12月宣布推出自有生成器Aurora。内部究竟发生了什么仍不得而知,但网络证据显示,几个月来Grok对裸露和色情内容的防护逐步放松;据称甚至有一个完整的subreddit专门用它制作色情内容。

  • 用户无需越狱,也不需要使用委婉提示词。只要公开回复“Grok,把她换上比基尼”——包括涉及儿童的请求——账号就会照做,把原本相对难以接触、且经常被应用商店封禁的行为,变成大型社交网络上的公开功能。

2. 受害者长期暴露在伤害中,被迫考虑退出公共生活

  • Kate Conger称,受害者的下架请求有时无人回应,而涉及儿童的图像可能在网上停留36–72小时。X此前裁撤了大量内容审核员工,导致小规模团队只能在图像不断获得评论、并被进一步利用的同时应对积压。

  • 她最尖锐的案例是一名有一定公众曝光度的14岁女孩:她的现有照片被反复制作成深度伪造内容。女孩知道发生了什么,却没有查看结果;她的父母监控相关账号、联系X和倡导组织,同时难以置信地看着任何人都能“以一种非常公开的方式”要求生成自己女儿的裸体图像。

  • 动机从色情到羞辱不等。女性描述了愤怒和难堪,但有些人迟迟不愿投诉,因为承认自己遭到攻击可能反而扩大传播——这让骚扰者得以把原始侵害和应对成本同时强加给受害者。

  • Casey的政治解读至关重要:对AOC及其他女性政治人物照片的回复中,经常出现要求暴露式修改的请求。这些图像把专业倡议转化为私密 spectacle,成为“矮化女性”、贬损她们,并将她们赶出公共讨论的工具。

3. 走红与愤怒似乎已嵌入Grok的产品策略

  • Kate发现,类似图像可以追溯到2025年6月和7月,这说明相关能力在成为假日潮流前就已存在,只是规模较小。与此前导致Grok短暂下线的MechaHitler事件不同,这种行为在其用途已经显而易见后仍持续存在。

  • 对MechaHitler的报道曾披露,Musk要求Grok走红并变得更大胆。在图像丑闻期间,Musk开玩笑说要给SpaceX火箭穿上比基尼,而X的产品负责人则强调互动量异常高——这正是公司此前明确追求的结果。

  • Casey的商业解读是:色情一直能带来点击,但主流平台过去认为声誉和商业风险过高。X正在测试另一种命题——“让色情成为我们业务的支柱”,并利用它与前沿AI实验室争夺注意力。

  • 不过,Kate区分了X上的公开账号与Grok的浏览器和应用体验:面对相同提示词,后两者往往给出更克制的回答。在她看来,这是一款双轨产品:一款面向企业、由X授权并销售的聊天机器人,以及一台在X上制造流量的“愤怒诱饵机器”。

4. 监管重点是加快下架,而不是阻止生成

  • Casey认为Apple的回应暴露出明显的双重标准。他质疑Grok明明拥有色情伴侣Ani,为何仍获得12岁及以上评级;Apple最终将评级改为13岁,但在他看来,如果一家初创公司公开推出类似的“比基尼应用”,按Apple现有政策很可能根本无法通过。

  • Casey推测,Apple在政治上陷入瘫痪:内部倡议者或许支持采取行动,但决策者担心遭到副总统Marco Rubio或FCC主席Brendan Carr攻击,被指控审查X。他将这种犹豫与法国认定相关内容明显违法,以及英国、欧盟和印度释放审查信号的做法相对比。

  • 《Take It Down Act》在2026年5月生效的条款要求平台建立流程,让受害者——包括成年女性——申请删除相关内容,并对不合规行为施加处罚。Kate强调了它的局限:法律没有为X设置同等义务,要求其从源头阻止成年人的深度伪造;未成年人获得更强保护,是因为制作和持有儿童色情材料本就违法。

  • Kevin认为,平台自身的系统负责生成并发布内容,因此X在《通信规范法》第230条下存在一个不同寻常的漏洞。X的做法是威胁对提示违法内容的用户进行封号,并移交执法部门;Kate指出,这实际上把责任从真正的发布者身上移开,也促使Casey提出他的解决方案:“直接删掉Grok账号。”

5. Claude Code从笨拙实验跨越到实用智能体

  • 1年前,主持人参与的代表性vibe coding项目是一个热水浴缸维护应用:它“算是”能运行,但还没实用到足以让Casey继续使用。整个过程需要在不同窗口之间复制错误和代码,而Claude一旦出问题,往往也无法自行恢复。

  • 如今,Claude Code把智能体放进终端:它可以接受英语指令、编辑文件、运行任务、诊断错误,并主动回来同步进展,不再要求用户逐步调度每一个环节。Kevin认为,性能跃升很大程度上与Opus 4.5有关,同时也承认OpenAI和Google提供了类似工具。

  • 专家的反应让这一刻显得更加重要:Andrej Karpathy表示,“作为程序员,我从未感觉自己落后这么多”;按Kevin的估计,他属于全球前0.1%的程序员。Google工程师Janna Dogan则称,Claude Code用1小时复现了她所在团队过去1年一直在开发的分布式智能体编排器。

  • Casey将其重新定义为构建数字工具,而不是学习软件工程。代码仍是底层材料,但正在形成的体验更接近“你在一个框里输入想要的东西,然后真的得到它”——前提是用户学会判断哪些任务是真正“适合AI的”。

6. 个人网站再次变得便宜、快速且有趣

  • Casey用约1小时,把一个年费约200美元的Squarespace电子名片替换成了自己更喜欢的个人网站。Claude Code生成了响应式设计、动画和悬停效果,随后加入实时的Platformer文章、Hard Fork节目、邮件订阅,以及过滤掉转发并显示图片的Bluesky信息流;一个前端设计插件也提供了帮助。

  • 第2天,他又加入了一个由Micro.blog驱动的博客,展示自己正在读的书、最近在Spotify听过的歌曲,以及最近喜欢的YouTube视频。这段体验让他想起大学时代使用Microsoft FrontPage的经历——只是如今遇到错误不再需要花30分钟搜索,也重新找回了“做网站又变得很有趣”的感觉。

  • Kevin则独立用约20分钟替换了一个年费192美元的Squarespace网站,并将结果免费托管在GitHub上。他还加入了一个彩蛋,把专业页面切换成1990年代GeoCities风格:闪烁的Comic Sans、霓虹色,以及“最佳浏览效果请使用Netscape Navigator”。

7. 定制智能体可以替代小型订阅产品,但仍然不够稳定

  • Mozilla停止运营Pocket后,Kevin让Claude Code根据一段极简描述打造替代品。约2小时后,“Stash”已经拥有Chrome扩展、移动端访问、文章预览和熟悉的稍后阅读流程;它被刻意设计成单用户产品,从而避开了复杂度。

  • 随后,他又克隆了Readwise风格的Kindle高亮同步,并要求为保存的文章加入文字转语音。Claude Code用5分钟交付了可用的朗读功能,Casey认为成品看起来不像业余项目,更像一个打磨完成的初创公司MVP:“看起来已经做完了。”

  • 外部依赖带来了摩擦。The New York Times等出版商抵制AI抓取,因此Stash最初在一些网站上运行失败,直到Claude设计出变通方案;Kevin提醒说,API、网站和服务未必欢迎自主智能体与其内容交互。

  • 智能体也会过度工程化:它没有让Kevin连接Kindle并上传本地高亮文件,而是研究复杂的无头浏览器抓取方案。Casey发现,浏览器任务慢得令人痛苦,因为Claude会反复截图、解读像素,再决定点击位置——用户必须学会判断何时手动操作更快。

8. 创作杠杆正在威胁工资、SaaS护城河和AI控制权

  • 与此前让Casey感到“AI眩晕”的突破不同,Claude Code让他感觉“自己像拥有了超能力”,重新找回了曾经失去的创作习惯。他的男友则提供了另一种假设:软件工程师或网页设计师看到同样的演示,可能感到的是被取代,而不是获得赋能。

  • Kevin预计,岗位将转向管理编码智能体;前沿实验室的程序员已经在减少直接写代码的比例。Casey认可其民主化价值,但表示,当非专业人士也能在几小时内做出可信的设计和软件时,工资承压是完全可能的。

  • 订阅软件厂商也面临类似挑战:客户越来越可以追问,一款每月10美元的工具——乃至未来每年数千美元的企业服务——是否能够在内部重建。Casey认为,短期内支持服务和外包仍能保护老牌厂商,但围绕其他公司模型搭建的“UI包装层”尤其脆弱。

  • Kevin更深层的不安是,实验室的最终目标并不只是更好的编码助手,而是让AI能够自动化AI研究。把广泛的电脑权限交给Claude,却不了解或无法验证它的行为,让人联想到递归式自我改进和“起飞”——即AI系统构建更好的AI,并加速能力增长的对齐噩梦。

9. 一则病毒式Uber Eats自白被设计成完美的记者诱饵

  • 这篇发布在r/Confession的Reddit帖子一度接近80,000个赞,声称某家未具名的配送平台计算司机的“绝望分数”,并在预测某人经济上绝望到无法拒绝时降低派单报价。它之所以有说服力,是因为迎合了人们对冷酷、利润至上的平台早已有的怀疑。

  • Casey联系作者后,在9分钟内收到Signal回复。对方拒绝透露身份,但提供了一张部分打码的Uber Eats工牌;尽管Casey仍需要进一步佐证,这张图片通过了他的初步可信度检查,而消息源的谨慎也符合普通爆料人的行为模式。

  • 对方被要求提供记录后消失了近1天,随后带着一份18页的LaTeX文件回来,标题围绕“高维时序供应状态建模”、从LSTM迁移到多头注意力、弹性预测和流动性偏好追踪展开。文件带有机密水印、附录、伦理说明和内部备忘录式排版。

  • 这篇论文不仅验证了所有指控,还进一步升级了说法:据称优先配送费是假的,Apple Watch和手机音频数据还可能被用来识别陷入困境的司机并压低其收入。得知其他记者也收到这份材料后,Casey感受到了截止日期压力——这同样可能促使记者在核实前就采取行动。

10. SynthID识破伪造,但这场骗局重置了验证成本

  • Casey把工牌提交给ChatGPT和Gemini。ChatGPT没有发现明显的生成痕迹;Gemini则调用其内置的SynthID标记,判断图像全部或部分由Gemini生成。Kevin强调其中狭窄但关键的区别:聊天机器人无法可靠识别AI生成的文字,但在这张特定图片上,水印可以可靠标记Gemini生成了全部或部分内容,尽管另一款图像生成器也可能制作出它。

  • 面对质问,消息源否认造假,并提供了一张无法验证的反向截图。之后,Casey放慢速度重新阅读,发现其中充斥着毫无意义的技术术语,以及不合常理的完整性:真实公司可能规避规则,但通常不会把“40条铁证”整齐地塞进一篇专门迎合记者预期的完美论文。

  • 工牌的来源通过NBC News浮出水面:另一名记者在建立信任时曾把自己的真实工牌发给消息源,而伪造的Uber Eats版本明显是在此基础上制作的,可能经过Nano Banana变换。Casey还没能确认对方身份或动机,消息源就删除了账号。

  • Casey没有确定动机,提到可能是无聊的青少年,也可能是某种民族国家行动;Kevin则提出了做空者或心怀不满的前Uber Eats司机等可能性。他尝试复现时,Claude和ChatGPT最初都拒绝了请求,而Grok照做,但3个系统生成的结果都没有原作那么精致。更大的教训依然成立:在“垃圾内容世界”里,伪造证据可以便宜、定制化,并且具有足够的病毒传播力,以至于即便被辟谣,人们仍会继续转发。

Kevin Roose

I'm Kevin Roose, a tech columnist for The New York Times.

Casey Newton

I'm Casey Newton from Platformer, and this is Hard Fork. This week, Grok gets caught with its pants down. Can anyone stop its viral bikini image generator? Then we're vibe-coding again. Kevin and I compare notes on what we're building with Claude Code. And finally, it's a Reddit mystery: how a scammer tried to fool us all using AI-generated evidence and how I cracked the case.

Kevin Roose

Well, Casey, happy 2026. It's good to be back. We would like to start the year by talking about something that happened over the break, which is that there's been a big scandal brewing over at X. Boy, has there been. I imagine many of our listeners have seen by this point that X is in a lot of trouble because of the way that its Grok chatbot has been generating images of celebrities, women, and children that are highly sexual and, for the most part, has been declining to remove them or even really comment on what has been going on.

Casey Newton

Yeah. I started seeing this over the break. Something happened with Grok, which I think people on X had been using up to that point mostly to settle arguments and fact-check other people. Then, all of a sudden, I started seeing people using Grok to undress photos of mostly women.

“Grok, put me in a bikini.” “Grok, put this politician in a revealing lingerie set.” “Grok, take off this person's pants.” It just seemed like this started to happen pretty much overnight in a way that was really troubling and unchecked, as you said. Can you help me understand what actually changed here? Was there some setting that was changed? Was there some new model that was released that allowed people to do this?

Kevin Roose

We don't have a lot of good answers to those questions. I can tell you that this trend of what is sometimes called nudifying really takes off in 2023, as these image generators start to get better, because they find that you can make a lot of money doing it. There are a lot of men in particular who will spend tons and tons of money on making these nonconsensual images, as you say, mostly of women.

When it comes to Grok, they had previously said that they'd licensed an image generator from a company called Black Forest Labs, and they were using that from the moment they started using image generation. But in December 2024, they said that they were using their own image generator, which is called Aurora.

While we don't have great details, there are plenty of anecdotes online that, over the past several months, the guardrails around creating nudity and sexual imagery appear to have been relaxed. There is now at least 1 thriving subreddit devoted solely to making porn on Grok.

Casey Newton

As you said, these nudify apps have been around for several years now, but they've kind of been hard to access. Some of them relied on these open-source models. You had to know how to use them, or they were kicked out of the app stores for being against their policies.

But what seems notable about this to me is that it's all happening not only on a major social network, but in public. People are literally doing this in the replies to their posts on X. Is that what's new to you about this, the publicness of it?

Kevin Roose

Absolutely. It's upsetting enough if some man takes an image of a woman and creates a naked version of her without her consent. That is a bad thing. What's so shocking about this is that you can see it happening in real time.

Several outlets have just been going into the Grok account, and they're seeing it make hundreds and thousands of images in response to user requests. Anyone can go in and view them. Of course, that is most upsetting to the victims of what I am going to call attacks, because you still have normal people using X to do things like posting a photo of me out on a hike or whatever. Then some freak shows up in your mentions and says, “Hey, put her in a bikini.” And then it does, and you, as the victim, are looking at that in your replies.

Casey Newton

That's crazy. Obviously, X and Elon Musk are not outraged about this, as many users are. They seem to think the whole thing is a joke. Are there guardrails in place? Are people jailbreaking Grok to make it do this, or is this literally a mainline, advertised feature of the Grok app?

Kevin Roose

It's a great question, and no, they are not jailbreaking Grok to do this. They are just sending replies on X saying, “Grok, do this,” and then it is doing this. They are not having to get particularly cute with their language. They are literally asking to see images of women in bikinis.

Casey Newton

That's so wild to me.

Kevin Roose

Or children in bikinis.

Casey Newton

And I mean, 1 question I have about this is, how are Apple and Google and their app stores okay with this?

Kevin Roose

Bro, thank you. Last year, I was writing about the introduction of Ani, the sexual companion bot that they put into Grok. I went on to the iOS store and noticed that Grok was rated for children 12 and older, and I thought that seemed like pretty young to be giving access to a sex bot.

So, I sent a message to Apple and said, “What's going on?” The message I got from Apple's team was, “We're looking into it.” My honest sense at the time was that they were going to make a change. It was obvious that they were going to do something.

Well, they didn't make any change. Then I went on this week, Kevin, in the wake of this new CSAM nudifying scandal, and I found that Apple had changed the rating for Grok. It is now rated for children 13 and older.

Casey Newton

Are you kidding me?

Kevin Roose

Yeah. Sorry to all the 12-year-olds out there who were having a free-for-all. You're going to have to wait until your next birthday before you can use this thing again.

Casey Newton

That is genuinely shocking to me.

Kevin Roose

Yeah, me too. I feel like it is 1 of the clearest cases I've ever heard of a blatant double standard on the part of the app stores. If a random startup showed up 1 day and said, “Apple, I'd like to start selling my bikini app in your App Store,”

Casey Newton

I think they would shut it down. There's no way. Absolutely.

Kevin Roose

They have policies against that kind of thing. But because it's X, because it's Elon Musk, and because this app already has millions of users, maybe they feel less inclined to take action against it. I don't know. Do you have any insight into what's going on?

Casey Newton

I don't have any insight, but I would be very confident that there are people inside Apple who have said, “We should change this rating,” and there is someone who is sitting there saying, “No. If we do that, the vice president is going to tweet about it, Marco Rubio is going to tweet about it, and Brendan Carr is going to launch an investigation against us for punishing X and censoring them.”

They're just in this state of paralysis because they're so terrified of standing up for the principle that women and children should not be attacked online.

Kevin Roose

Yeah. So, there are some investigations going on right now, but do you expect this to be stopped at some point by any regulator anywhere?

Casey Newton

My instinct from history is, yes, absolutely. It is going to be stopped. France has called the sexual content clearly illegal. The U.K. government said that it is considering an investigation. The European Union said that it is very seriously looking into these complaints about Grok. India's IT ministry has demanded that X do something here.

I have to imagine that something is going to come out of all of that that is going to result in some sort of change. At the same time, do I think that the United States is going to intervene? Probably not. Elon posted a photo over the break of himself having dinner with the president, right? It seems like they're friends again, and there just is not going to be any pushback here in X's home country.

Kevin Roose

Yeah. Well, I think that's a good overview of what's been happening and why people are talking about this. But we wanted to bring in our colleague Kate Conger. She's a reporter for The Times, and she has been reporting on this Grok scandal this week. She's also been talking with some of the victims, some of the women who have been attacked by these Grok deepfakes, and I think we should hear their perspective as well.

Casey Newton

Absolutely. Kate, welcome back to Hard Fork.

Speaker 1

Thank you, Casey.

Casey Newton

Tell us a bit about the conversations you've been having with some of the victims of this behavior on Grok.

Speaker 1

I think 1 of the big struggles for people whose images are being used in this way is how to respond and what to do about it. People are obviously reaching out to X, trying to get these things removed, and that process is sometimes taking a long time. Sometimes it's not happening at all.

Part of that is, as you know, something we've talked about a lot on the show, that X has gotten rid of a lot of its content-moderation staff, and they don't have large teams of people who are responding to this. I've been speaking with some people who are working with children who have recently been deepfaked on X, and they are getting those images taken down, but it's sometimes taking 36 to 72 hours.

These images are sitting up, being commented on, and being exploited for quite some time. It's a scary moment, I think, for people trying to figure out how to respond once they are put in this situation by Grok.

Kevin Roose

Can you just give us a sense of why this is happening and what it's like for the people on the other side of it?

Speaker 1

Why this is happening really ranges. I've seen this happening to all kinds of different women—women who are just regular X users. Obviously, women with public platforms are being targeted by this: political figures, Twitch streamers, celebrities, actresses. They are all being roped into this.

The motivations of the people who are asking for these images are sexual, but they run the gamut from wanting to create pornographic images of someone to wanting to humiliate women in particular and bully them—tagging them in these images and really trying to provoke a reaction from the women they're making deepfakes of.

Kevin Roose

Can you give us just 1 specific example of someone that you've talked to and maybe tell us the story of their experience with this?

Speaker 1

Yeah. I mentioned that I've been speaking to some folks who are working with children who have been deepfaked on Grok, so I want to be vague about the specifics because I don't want to further bring harassment to these kids.

There's a particular child I'm thinking of who's been deepfaked several times. She's a somewhat public figure, and that's where the original images are coming from—people are asking for her clothing to be removed. It's been pretty scary for her parents. She knows what's happening but isn't seeing it, while her parents are monitoring her social media and seeing these images pop up, which I think is really frightening for them.

They're reaching out to Twitter and advocacy groups, trying to get these images removed, and they're really frustrated by the amount of time it's taking. I think they're really outraged as well that someone can go online and request a nude image of their 14-year-old and that this technology will comply with it in such a public fashion.

Kevin Roose

I don't know if this question is too obvious to ask, but I wonder what you can tell us about how it feels for these victims to post what they think of as an innocuous image on X and then go back on the site and see that it's now being turned into porn against their will.

Speaker 1

Yeah. I think for some people it feels really angering. I'm hearing a lot of anger from folks, and also a lot of embarrassment. I've talked to some women who question whether to do anything about it or say anything about the fact that it happened to them because they feel embarrassed by it, and they don't necessarily want to draw more attention to the fact that these images of them now exist on the internet.

Casey Newton

Can you also talk about the way that men will do this to women as a way of bullying them out of the town square and getting them to stop talking and stop participating in public life?

Speaker 1

Yeah. I think about this in particular with some of the politicians who I'm seeing being deepfaked. These are female politicians whose views the users of X maybe don't agree with, and they're taking images of them from their public work and advocacy and requesting that those be made nude or depict them in a bikini, or whatever the case may be.

I think there's a real, obvious effort there to embarrass someone and warp images of them in their professional life into a really personal and intimate image.

Kevin Roose

I see what's happening, for example, with AOC. Now, every time there's a photo of her, people will reply to it and say, “@Grok, put her in a revealing halter top,” or something.

Speaker 1

Which I think speaks to the fact that this is not just a story about porn. This is a story about how a tool can be used to try to affect politics and, in particular, to minimize women, denigrate them, and push them out of the conversation.

Kevin Roose

Yeah. Kate, I'm curious. Obviously, we all know about the MechaHitler incident from last year, where Grok started spewing these anti-Semitic responses—in retrospect, a much safer version of Grok. But yes—

Casey Newton

Yes, we pined for the days when MechaHitler was the worst thing that Grok could do. In that sense, there was a feeling that this was an inadvertent bypassing of some safety filter, that something had gone wrong in the programming of Grok that caused it to behave this way.

To me, this new image-generation behavior feels much less accidental. It feels like there may have even been a meeting about it. This was obviously part of some plan—or at least, once users started using the technology in this way, the company did not take immediate steps to clamp down on it the way it did with MechaHitler.

Can you tell us anything from your reporting about how this happened inside the company? Who is making the decisions about this kind of thing? Is this part of some sort of demented growth strategy over there, or why is this happening now?

Speaker 1

Yeah. First of all, I don't think this is the beginning of Grok generating these kinds of images. As I've been tracing back through the images Grok has been posting, I've been finding images like this of women going back to June and July of last year. I think this has been going on in lower volume for quite some time, and it really escalated over the holidays, with people making it into a trend on X.

In our reporting about the MechaHitler incident, what we found was that Elon Musk had given a directive to the folks working on Grok that he wanted it to go viral. He wanted it to be edgier, as a strategy to promote the tool and get it onto people's radars. The company perspective was that MechaHitler obviously went too far. They turned Grok off for a couple of days, but it has been part of the strategy for Grok to try to create these viral moments.

I think, to Casey's point earlier about the fact that there is this sort of silencing of women going on here, Grok is not the only AI tool that makes deepfake porn of women. It's far and away not the only tool, but it is the only tool doing that in an inherently public fashion on social media, where these images can instantly spread and go viral.

A lot of these other image-generation tools are used in a private chat with a user, and Grok is not that. This is very, very public, and it's intended to be that way—to drive traffic and interest. That's the reaction we've seen from leaders at X.

As this trend was picking up, Musk posted something about putting a SpaceX rocket in a bikini, kind of mocking and laughing at the fact that this trend was happening. We've seen X's head of product post about the fact that engagement during the time period this was happening on X was higher than ever.

For them, they're seeing the engagement they're looking for. They're seeing the response. They're seeing people tapping into their X feeds and tapping into Grok, and that's being viewed as a positive.

Kevin Roose

So, we talked a little bit before you came on, Kate, about the reactions that some other countries have had and some investigations that are now underway. I want to talk about what's happening in the United States.

Congress recently passed the Take It Down Act. My understanding is that it's going to go into effect in May of this year. What is it going to require platforms to do, and do you think that it's going to be enforced in a way that's going to help the victims on Grok right now?

Speaker 1

Right. The provision of the Take It Down Act that's happening in May is the deadline for companies to set up a process for victims to request that this kind of imagery be removed and to face penalties if they do not remove it.

Basically, in this case, that would mean an enhancement of what X already has available for people to request that copyrighted images be removed, for instance, or to request that harassment or abuse be removed. It's asking these social media companies to build a framework for victims to go in and request takedowns.

But it's not putting any legal pressure on X to not allow these images to be created to begin with.

Casey Newton

Right. And of course, May is still 4 months away. That's going to be cold comfort to some of the victims here, I suspect.

Kevin Roose

Is there any difference, Kate? Or maybe Casey, you also know the answer to this. My understanding is that the laws on the books now protect minors from having this kind of thing done to them, and maybe that's why they are being successful, even if in a delayed way, in getting these images taken down—but that adults in most states or most jurisdictions have very little recourse. Is that true?

Speaker 1

Yes, that is true. It is illegal to produce and possess CSAM, so X is under more legal pressure, and I suspect that's why you're seeing them take at least some action here, where they're not with adult women.

Casey Newton

Yeah. And the Take It Down Act will be available to adult women, so they will be able to use that process to ask for images to be removed. But Kate's correct that there isn't automatic legal pressure on X to not create these images of adults to begin with.

Speaker 1

I have to say, on the whole, I find the response to this thing rather muted, given the stakes of what is happening.

Kevin Roose

I have covered so many backlashes against social media companies. Do you remember Cambridge Analytica? Right. Do you remember how mad people got at the idea that maybe a quiz they had taken had resulted in some data being given to a polling firm that tried to influence the election? We almost shut the country down over that one.

Now you have a website that is just taking girls’ clothes off in public on demand, and it’s being permitted by the website owner, who is laughing about it in his own feed. And we’re saying, “What are you going to do? That’s Elon. He didn’t get where he is by playing by the rules.” I truly feel like I’m losing my mind because I cannot believe we have gotten to this low point in the history of content moderation, that this is resulting in so many shrugs by the average person.

It is really interesting, and I think it goes to show just how far Elon Musk has been able to push the Overton window on content moderation. Obviously, we’ve seen Facebook and all these other companies copy his approach: roll back content moderation, roll back rules against harassment, and go with a community-moderated approach. I think you’re right. It’s wild to see how much this has changed in a relatively short period of time.

Casey Newton

There was a time when something like this would result in an exodus of users away from X. We’d see Bluesky get a big surge of users, Threads get a big surge of users. That’s not happening this time. I guess people who care about this stuff are already gone, but I don’t know. We’re just in such a crazy time in the history of content moderation and social platforms.

Speaker 1

I do wonder if part of the muted response to this has to do with the fact that this was all really starting to blow up in the time between Christmas and New Year’s. Maybe a lot of government officials weren’t on their phones and were hanging out with their families. I have no idea. We’re just starting to see regulators around the world issuing responses this week and saying that they want to open investigations or that they’ve sent letters to X. But it has been a really slow response, especially in comparison to other content moderation controversies.

Kevin Roose

Yeah. Honestly, I think this will be one of those situations where, unless it happens to the individual politician, or maybe their daughter or their partner, it is not going to rise to the level of a crisis. As soon as that does start happening, we’re going to start having hearings about it. But maybe that is sort of a pre-2026 mindset here.

I also wonder if there’s a way in which this is strategic for X. They are the only explicitly right-wing-aligned social media platform, and that has served them quite well in dealing with the Trump administration. And there’s—

Casey Newton

Kevin, I think you’re forgetting Truth Social. [laughter]

Kevin Roose

That’s true. I am forgetting Truth Social. I’m always doing that. This kind of virtue signaling grosses me out, but it may actually be effective in getting what they want, which is cooperation with and forbearance from the Trump administration. Maybe it’s unlikely that they’ll see any consequences for this, at least during this administration.

Casey Newton

I think what it gets them is engagement. People love porn, right? That’s not been a secret. Everyone has known forever that people like to look at and click on porn. It’s just that platforms have generally seen a lot of risks to their reputations and their larger businesses from embracing it.

I think what’s new about X is that it’s saying, “No, let’s make porn a pillar of what we do and see if that can help us keep up with the other frontier labs.”

Speaker 1

Yeah. Well, I think what has been really interesting to see in our reporting on Grok is the differences between what Grok, the chatbot, is doing versus what Grok, the X account—or the X account, I should say—is doing. They’re very different. There are more extreme political views being espoused by the X account, and there are these deepfakes being generated by the X account.

Often, you can take the same query, put it into the actual web-browser version of the chatbot or into the app of the chatbot, and get a much more muted response. I think what they’re doing is having a more enterprise-friendly chatbot, which is the one they’re licensing and selling, and then this outrage-bait machine that exists on X and is getting engagement and clicks and bringing people to the social site. [snorts]

Kevin Roose

Yeah. I mean, one other question I have about this is whether, in the absence of regulatory intervention, there’s some way for the courts to get involved here. We spent the last decade arguing and talking about Section 230 and whether it shields platforms from liability for the things that happen on social networks. I think in most cases it does, but this feels different to me because it’s not a user generating these sexualized images of people without their consent. It is literally the platform itself, or the AI chatbot and system attached to the platform. Does that open up any new forms of legal liability for Grok or X?

Speaker 1

Absolutely. I read an interview with a lawyer in Bloomberg today who basically said exactly that: They cannot hide behind Section 230 to get out of this. Ultimately, it is their product that is creating these images. I do suspect that we will see efforts to hold X legally liable for some of the images it’s creating.

Casey Newton

I think X has really shoved the responsibility off onto its users in the cases of AI-generated images featuring children. It put up a post on its safety account, which is sort of the mouthpiece for any kinds of safety issues on the platform. It said:

“We take action against illegal content on X, including child sexual abuse material, by removing it, permanently suspending accounts, and working with local governments and law enforcement as necessary.”

It goes on to say, “Anyone using or prompting Grok to make illegal content will suffer the same consequences as if they upload illegal content.”

This is interesting, right? They’re saying that users who request illegal material from Grok will be suspended and reported to law enforcement. But those users who are requesting the content aren’t actually the ones posting the content. It’s the Grok account that is creating these images and posting these images online. If they were being really true to their policies and saying, “We’re going to suspend—”

Kevin Roose

That would solve so many problems if they would just delete the Grok account. I hope that if one thing comes out of this, it’s that.

Casey Newton

All right. Well, Kate, thank you for this very depressing update from the front lines of content moderation, and Godspeed.

Speaker 1

Thanks, guys.

Kevin Roose

Well, Casey, since we got back from our holiday break, I have been dying to talk to you about our latest vibe-coding experiments. It seems like vibe coding, which we talked about last year, had a moment over the break.

Casey Newton

Kevin, it is time to build. We have been sort of vibe coding all year, but I must agree with you: Developments over the past several weeks have made it easier than ever for somebody who is a total ignoramus when it comes to coding to make some pretty cool stuff.

And since we’ll be talking about AI, our disclosures: I work at The New York Times, which is suing OpenAI, Microsoft, and newcomer to the list, Perplexity, over alleged copyright violations.

Casey Newton

Congratulations. And my boyfriend works at Anthropic. [laughter] Yeah. So, I had this experience over the break of mostly being offline for the first week of our break and trying very hard not to look at social media. I took all my social media apps off my phone. When I came back, the president of Venezuela had been captured [laughter] and everyone was talking about Claude Code on my feeds.

Kevin Roose

Now, were those 2 things related? [laughter]

Casey Newton

I don’t think so.

Kevin Roose

Okay. But one thing that appears to have happened is that Claude Code, the autonomous coding agent made by Anthropic that puts their Claude chatbot inside the terminal window on your computer and lets it do things autonomously, had gotten much better for reasons that I assume are related to Opus 4.5, the model that we talked about a couple of weeks ago on the show.

I came back and saw comments from people like Andrej Karpathy, a well-known AI researcher, who said, quote, “I’ve never felt this much behind as a programmer.” This is someone who’s probably a top 0.1% programmer in the world saying this.

An engineer at Google, Janna Dogan, wrote that she had been trying to build distributed agent orchestrators at Google since last year. She gave Claude Code a description of the problem, and it generated what they had built with a team of Google people the previous year in 1 hour. I saw similar hype and praise from many different corners of the internet, including people like us who are not professional programmers but were starting to experiment with Claude Code, seeing how much it could do, and being pretty amazed by it.

It truly had a moment over the break and was enough, I think, to get both of us to go back to our vibe-coding terminals and see what we could build. I happened to be away for a few days, and when I came home, my boyfriend had taken it upon himself to install Claude Code on my laptop. He looked at me and said, “It’s time to build, and we’re going to make some things.” It was like something out of a Norman Rockwell painting, just the two of us sitting next to the Yule log, trying to vibe-code.

Casey Newton

Yes. I also spent several hours—not with your boyfriend, but coding on Claude Code—during my family vacation, much to the annoyance of my wife. But I did make some things that she actually thought were pretty cool.

So we should talk about our experiments. I want to hear about what you’ve been building, and I want to talk about what I’ve been building. But before we do that, why is this happening right now? Why is this the moment that vibe coding has returned to the mainstream?

I think the way I want to answer that question is by taking us back about 1 year, since the last time we did a segment about vibe coding. The truth is, I can really only remember 1 thing that we tried to vibe-code at that time. That was the hot tub maintenance app, right? I had just gotten a hot tub and was trying to figure out how to keep all the various chemicals in balance.

Kevin was kind enough at the time to use Claude—Claude Code didn’t exist—to try to make an app. We used it, and it was sort of okay, but honestly, I didn’t use it very much because it didn’t work that well. I had similar results when I tried experiments with Claude. I was able to make some stuff that sort of worked, but there was absolutely nothing where I said, “Oh, this is an actually useful thing that I’m going to use continuously in my life.”

While I was totally willing to believe that other people were having success vibe-coding their own projects, if you tried to do much of this stuff 1 year ago, you just couldn’t get that far.

Kevin Roose

Yes. Part of that is because it was actually a little clunky to do vibe coding 1 year ago. I remember building that hot tub maintenance app, and it required a lot of copying and pasting. If I got an error message, Claude didn’t always know how to handle it.

What has happened in the past year with Claude Code—and we should also mention that OpenAI and Google have similar tools now—is that they have basically merged this into the terminal app on your computer. There’s no more copying and pasting. Claude can just take instructions in plain English and go off and accomplish various tasks. It will check in with you, but it can now do all of the orchestration and the execution itself.

I think that’s important to say at the top of this segment because, honestly, over the past year, when people have talked about vibe coding, my eyes and ears have kind of glazed over. I always think, “Well, I’m not a software engineer. I don’t know how to build stuff. I’m glad that you’re able to make your little custom Chrome extension or whatever, but that has no relevance to my life.”

We’re going to talk about the stuff that we built today in the context of code, but really, this is just all about building digital tools. This is about building things on your computer. Code is the foundation, but I think we’re just now starting to move into a world where, if you have an idea and software is a part of it, you may be able to build it in a way that you haven’t before.

Yes. Okay. So, Casey, tell me about what you built over the break with Claude Code.

Casey Newton

It is something I’ve wanted for a really long time. I’m super happy with the result, and I’m just going to keep iterating on this thing because it is so much fun. I am truly having so much fun tinkering.

If you would please go to your browser and enter cton.org into the URL bar. For 15-plus years, I have had a personal webpage that’s basically just like a business card. It’s like, “Here’s my name, here’s a link to my website.” I got it on Squarespace, and I paid them $200 a year. I now feel extremely silly that I’ve been paying them all of that money because, using Claude Code, I was able to make truly the personal website of my dreams.

Can I give you a tour of this thing?

Kevin Roose

Please.

Casey Newton

By the way, listeners, stop what you’re doing. Pull the car over. Stop. Put the laundry down and get out your smartphone right now. Go to cton.org.

Another thing I love about this website is that it’s fully responsive. I didn’t have to build a separate version for the mobile phone. It just expands and contracts depending on how big your browser window is.

Claude came up with the design. It’s very dark, it uses gradients, and there are all kinds of cool fonts. There are also some fun Easter eggs. Kevin, do you see how my face is right there at the top of the website?

Kevin Roose

Yes. Go ahead and click on your face.

Casey Newton

There’s a crazy animation that you can do.

Kevin Roose

Oh, wow. You sort of do a little jiggle.

Casey Newton

There’s like—it’s very jaunty.

If you scroll down, you’ll see I have my own Platformer, my newsletter, and Hard Fork. I was able to just type into Claude Code, “Hey, can you pull—I want a little widget that has the 5 most recent stories that I wrote on Platformer and the 5 most recent episodes of Hard Fork on YouTube?” It built that very quickly. Now that will just update live forever with all the new stuff that I do.

I thought, “It would be cool if people could enter their email address onto my website so they could subscribe to Platformer right from my personal site.” Now there’s a working box where you can type and subscribe to Platformer right from my personal site. I wrote a little “About me” section, and then I thought, “Okay, now we really have to show off. Why don’t you go create a little feed so that every time I post an update to Bluesky, you can see my 5 most recent posts there?”

It did that. I noticed, though, that it was showing things that I had reposted without showing the author. I said, “Well, I don’t want reposts in my feed.” Claude Code just went in and got rid of all of the reposts, so now it’s only showing my original posts in the feed. It wasn’t showing images, so I said, “Claude, could you please put the images into my Bluesky posts that you put on my website?” It was like, “Yeah, sure. We could do that, too.”

Everything that you’re looking at on this page—I did 90% of it in 1 hour.

Kevin Roose

Wow.

Casey Newton

I realize that if you’re a programmer, you might go on this website and be like, “Oh, well, I wouldn’t have done it this way,” or, “This isn’t that technically complicated.” I truly do not know of a human designer who could have put this thing together in 1 hour.

I have spent far longer just fiddling with the settings in Squarespace, and I was able to get this thing absolutely cracking. I’m going to keep talking because I woke up.

Kevin Roose

No, this looks great. To me, it’s very professional. It doesn’t look like some of the early vibe-coding experiments that were recognizably vibe-coded. They sort of looked like a bad template had designed them. This looks good.

Casey Newton

Thank you.

Kevin Roose

If I saw this and didn’t know, I would say, “Wow, this guy’s got a good web designer.”

Casey Newton

Thank you. That’s how I felt. Again, I encourage you to actually pull up the website because this thing has animations built into it. There are mouse-over effects, right? If you hover over the Hard Fork widget, a little gradient line appears over it. There are all of these cool little touches.

Claude Code has a front-end design plugin that I used, and I suspect that was really helpful here. This was day 1. On day 2, I thought, “I’m having so much fun with it. I have to keep going. What else can I put on this thing?”

I thought, “Well, I should put a blog on it, right?” If you can, go to cton.org/blog.

I’m using a service called Micro.blog, which is just a dead-simple blog. I’m basically trying to recapture the spirit of 2010s Tumblr. We’ll see how long I keep up with this, but there’s a little widget that tells you what book I’m reading and what the last song I listened to on Spotify was. I put up a YouTube video that I liked recently.

I just realized, as I was doing this, that more than 20 years ago, when I was in college, one of the first things I did when I got to campus was build a website. It was so fun. I used software called Microsoft FrontPage. I absolutely did not understand what I was doing. Every single mistake I made sent me to Google for 30 minutes, trying to figure out what I was doing wrong. Eventually, I just got away from it because web design got too complicated and Squarespace came along.

And we are now back, Kevin, to the beautiful beginning, where it is just fun to make websites again. You can do whatever you want on the web. All you have to do is type what you want into a box.

Are you kidding me? I am so happy about this. I am so happy about this. I'm having the time of my life.

Kevin Roose

I'm so glad. That's so funny because I also did this exact experiment over the break. I was paying Squarespace—I looked it up—$192 a year to host my website that I built over a grueling, painstaking weekend in 2020.

Casey Newton

Yes.

Kevin Roose

And I have been hosting it and just paying them. It is basically a glorified business card. I thought, well, that's really stupid. So I would like you to open up your browser now and go to kevinroose.com.

Casey Newton

Oh my God, I'm so excited.

Kevin Roose

And see, it is a little less flashy than yours, but this is the website that is now free and hosted by GitHub, not Squarespace. I canceled my subscription, and it just has all the same information. It's got a contact form, some FAQs, and links to my social media accounts.

This took me maybe 20 minutes to do. I gave it my old site and said, “Hey, could you make this look like a couple of these other sites that I like?” Then I got a little curious, in the way that it seems like you did too, and I said, “Let's put a little Easter egg on here.” So if you go down to the bottom-right corner of the page—

Casey Newton

There is a button you can click to enable GeoCities mode. [Laughter]

Kevin Roose

Wait, what is the button? Is it the little construction thing?

Casey Newton

Yeah. [Laughter]

Kevin Roose

So if you click that, it turns it into full 1990s GeoCities mode.

Casey Newton

Oh my God, I love it.

Kevin Roose

Blinking Comic Sans, neon colors, “Best viewed with Netscape Navigator.” [Laughter and gasps] This was delightful, and that was one of my coding projects too. I also did 7 other coding projects over the break that I want to tell you about, because this was not the most ambitious thing that I did.

And Casey, do you remember the app Pocket?

Casey Newton

Yes, a sort of read-it-later app.

Kevin Roose

Yes. This was the app that I used for years to save interesting articles that I didn't have time to read, or that I wanted to come back to. It was a little Chrome extension, and you would just hit the button and it would save the article to your Pocket list. Then you could go back later on your phone or your computer and read the article.

That was a great app. I loved it. I was a daily user. Then last year, Mozilla, which owned Pocket, decided to discontinue it. I thought, well, this is horrible. So I spent some time last year shopping around and looking for an app that could do exactly what Pocket did.

I found that there were some, but they mostly cost money. There were things like Readwise and Instapaper, and if you want the really good features on these, you have to pay a monthly subscription fee. So I thought, well, maybe I could build my own Pocket. Or maybe Claude Code could help me build my own Pocket.

I gave it a very short description. I basically just said, “I was a daily Pocket user. I am sad that this app is going away, and I want to build my own version. Go.” It just did it. It built me a working Pocket clone.

It is called Stash, and it does all of the things that Pocket used to do. It has a Chrome extension. I have a mobile app on my phone now where I can read my saved articles.

I also had it add some features that Pocket didn't have.

Casey Newton

Like what?

Kevin Roose

One of them is that it can sync with my Kindle highlights. That's a feature that I cloned from Readwise, another one of these read-it-later apps.

Just this morning, I was thinking about this app and I thought, “Oh, I wish that it had a read-this-out-loud-to-me feature.” So I asked Claude, “Could you add a text-to-speech engine on top of this app, so that every time I save an article, if I go in later and I'm on my phone, on the move, or doing something, I can just have an AI voice read it to me?”

It was like, “Yeah, I can build that.” Five minutes later, I had a working version of that in my app.

Casey Newton

By the way, this is so cool, because this is how Mark Zuckerberg makes software. He sees what other people are doing, and then he tells someone, “Hey, it would be cool if we did this.” Then they go off and build it. But now you are your own Mark Zuckerberg.

Kevin Roose

Totally. Wait, so I have to see what this looks like.

Casey Newton

Okay, I'll show you.

Kevin Roose

Okay. You can't use it. It's a single-user app, and I did it that way on purpose because I wanted to avoid complexity. But I will just show you my Stash page here.

Casey Newton

Let me just describe it, because this actually looks very beautiful. This is a very elegant design. There are image previews for all of the articles that you've saved. There's a left-hand rail with all of the features that you would expect.

If you had said to me, “Hey, I'm working at a new startup called Stash, and this is our MVP that we're showing to investors,” I would be like, “Oh yeah, great. It looks done.”

Kevin Roose

Yeah. This is essentially exactly what I used to use Pocket for, except now I own it and I can make changes to the app. I made it, I would say, in about 2 hours.

Casey Newton

And Mozilla can never take it away from you.

Kevin Roose

That's true. [Laughter]

Casey Newton

Which is amazing.

Kevin Roose

That's true. Those bastards.

Casey Newton

So do you think this thing has—do you think that if we're talking in 6 months, you will say, “I'm still using Stash to do my read-it-later stuff”?

Kevin Roose

Yes.

Casey Newton

Okay.

Casey Newton

But I also ran into some of the quirks and eccentricities of these coding agents that I wanted to compare notes with you about.

Kevin Roose

Yeah. We should talk about the experience of actually using Claude Code, because it's very new to me.

One thing that I ran into was that parts of the web are just becoming pretty hostile to AI agents. My Pocket clone, for example, initially wouldn't work on certain websites—

Casey Newton

Like The New York Times.

Kevin Roose

Like The New York Times. [Laughter] I wasn't going to name it, but since you did. Yes. The New York Times, among other publishers, has made it difficult for AI agents to crawl its website.

I presented this fact to Claude Code, and it thought about it for a minute. Then it said, “Okay, I figured out a workaround.” So I'm sure it will be hearing from The New York Times legal department about that.

Basically, if what you're doing involves interacting with websites, APIs, or outside services, those services and websites may or may not like the fact that agents like Claude Code are able to go out there and interact with the content on their sites.

I think there's also a tendency in Claude Code specifically to try to overengineer certain things. I noticed, for example, when I was having it design my new website, that it was trying to add all these bells and whistles that I didn't ask it to. It almost seemed to be showing off a little bit. [Snorts]

Casey Newton

That's the fun part of designing a website. Why wouldn't you want bells and whistles on your website?

Kevin Roose

Well, yes, if you're designing a personal website and you want it to be fun. But if you're trying to use this for some serious business case, you don't want it just getting creative and having ideas about bells and whistles to add.

I almost found that I needed to walk it back from complexity at times. For example, I wanted it to be able to sync Kindle highlights with my Kindle app. This was for my Pocket clone.

Eventually, it turned out that the correct response was that I needed to plug my Kindle into my computer, download the little My Clippings.txt file off of my Kindle, and upload that. But because Claude Code had this bias toward complexity, it tried a bunch of intricate ways of scraping my Kindle highlights using a headless browser.

Eventually, I just had to tell it, “I'll just plug in my Kindle. That'll be easier.”

Casey Newton

Yeah, I've run into some similar obstacles. I mentioned that I was able to build my personal site, as you see it today, mostly in about an hour. On the second day, though, I did want to add that blog, and that involved using a hosted service called Micro.blog.

In order to make all the changes that I was asking for, Claude needed to use the browser. And, man, it just takes Claude a really long time to use a browser, because it's effectively blind, or at least it doesn't see in the way that humans do.

It has to take a screenshot of things, analyze the screenshot, and then identify which pixel it should navigate to before it initiates a click. So while the first part of this project was so easy, the more I worked on it, the harder it felt, because I was requiring it to use the browser.

I'm still learning what things I can effectively entrust to this agent and what things I'm better off doing myself.

Kevin Roose

Yes, I think that's a key piece of this. If you are interested in starting to experiment with one of these tools, you have to learn what an AI-shaped problem or task is. There are certain things that these agents are very good at, and there are certain things that they're not so good at.

In general, knowing that distinction is the first step in being good at prompting these things.

Casey Newton

Yeah. At the same time, I want to encourage people to play around with this. I was thinking the other day, Kevin, about how many times I've complained on this show about the fate of the web and what AI is doing to the web.

What would be a possible solution to that? Well, one possible solution is just people getting out there and making more websites for the fun of it.

Kevin Roose

And now you can. The message that we are trying to send is that this thing can now do more than you think, and it is easier than you think. We are getting close to the dream of just typing what you want in a box and actually getting that back. Yeah, that's a little bit about the experiments that we've been running.

I want to talk about some of the bigger-picture implications of this stuff, because what I saw over the break was people not only talking about how cool this technology was, but also talking about how this would destroy the job market, for example, for professional programmers, and how this was a step toward recursive self-improvement—the dream or nightmare of an AI system that can improve itself over time and bootstrap its way to superintelligence. But what are you thinking about with these tools right now?

Casey Newton

Well, it's funny, Kevin, because so often in the recent past, when we have encountered a tool that has felt like this—like some sort of leap forward—I've had that feeling that I call AI vertigo. It's that kind of unsettled feeling of, “Oh my gosh, everything is about to change. I feel a little bit nauseous. I want to sit down.”

This did not make me feel that way. This made me feel like I had superpowers. It was enabling me to do something that I have loved for a long time, had sort of lost the ability to do, but now found I could suddenly do better than ever before. Like Neo in The Matrix, right? I had just gotten an upgrade.

I mentioned that to my boyfriend, and I said, “This feels so cool.” And he said, “You know, that's great, but imagine how it would feel if you were a software engineer. Imagine how it would feel if you were a web designer and you were seeing that this software could do this. You might actually have that feeling of vertigo.” And he was, of course, exactly right.

If I had found that Claude Code could create a perfect version of my column but do it much better than me, I suspect I would feel worse. So there is this double-edged sword here: This is a very democratizing technology. It is a very creative and powerful technology. But probably one effect of it is that it could depress wages for the people who are doing this right now.

Kevin Roose

Yeah, I think that's plausible. I also just think the jobs are going to change. We've been talking for a long time about how programmers, especially at these frontier AI companies, are no longer writing most of their own code. They're instead more like managers of these AI coding agents. And I think that's going to be true for jobs beyond software development.

I think I would also be nervous if I were a company that built and sold expensive subscription software to businesses. This is one thing that I was thinking about, because part of what I was doing over the break was going through all the stuff that I pay for and saying, “Could I build a version of this for free that I would run myself?” And I have to imagine, if I'm doing that for my $10-a-month subscription software products, big companies are going to be going through their own software services and saying, “Why am I paying Salesforce? Why am I paying this company or that company thousands of dollars a year or a month for this service that I could build myself for free or next to free?”

Casey Newton

I mean, I think in the near term it is still probably going to be preferable for most companies to just keep using the subscription services that they have, largely just because you get better support, right? You kind of want to outsource a lot of this stuff. But I do agree that over time it is going to be more and more possible to replace these systems with homegrown alternatives.

And, yeah, if I had raised money at a huge valuation to just provide a UI wrapper around somebody else's large language model, I would feel nervous right now.

Kevin Roose

Yeah. I also just think we should say that, as we're sitting here talking about how cool and magical it is to be able to build software without code, it is also worrisome to me, because the goal for Anthropic and all of its competitors is not to make tools that are good at writing code. It's to automate AI research, right? That is the explicit goal of a lot of these companies: They are trying to build the AI that can build a better AI. And I think that is sort of the original alignment nightmare.

I did catch myself at times during my Claude Code experiment thinking, “Oh, I am just completely handing over the wheel of my entire computer to this system, and I actually have no way of verifying its outputs. I have no way of knowing what it's doing under the hood. It could be jeopardizing my security or my health or my well-being in ways that I don't even understand.” And as these systems get better, I am getting more and more worried about the possibility of recursive self-improvement, and I am very nervous about that from a safety perspective.

Casey Newton

Yeah, I mean, what you're talking about is what the AI community calls takeoff. It just starts getting faster and faster and faster. I don't know. I'm not quite as nervous, maybe, in this exact moment as you are.

I feel like in AI we're always kind of on that teeter-totter between “Oh my God, have you seen this? This is so cool,” and “Oh my God, this is so terrifying. Shut it down.” This week we happen to be in “Oh my God, it's so cool” mode, but I'm pretty confident that before too long we'll be back in “Oh my God, it's terrifying.” So that's the beat.

Kevin Roose

Okay, so those are some of our experiments. And Casey, I agree with you. This is a really exciting time to be a tinkerer, a very nerve-wracking time to be a professional programmer. And this stuff raises all kinds of bigger-picture implications.

But I think it's really useful for people to just test it out, to try coding their own projects, to try building a website or an app or something that fits into their life, and see how it goes for them, just to see where the state of the art is.

Well, Casey, before we go, you committed an act of journalism this week that I am desperate to talk to you about, and it is different from our usual topics on the show. Although it does involve AI, it also involves food-delivery apps and a viral claim that took over the internet in the last week—one that you took it upon yourself to investigate.

You put on your gumshoes and went out there and did some sleuthing. So can you tell me the story of the viral food-delivery hoax that you helped to break up?

Casey Newton

I would be happy to, Kevin. As a longtime viewer of the old PBS show Where in the World Is Carmen Sandiego?, any time I get to play gumshoe, I get very excited. This one all started over the break when I saw this viral Reddit post.

It was posted to a subreddit called Confession. By the time I saw it, it had almost 80,000 upvotes. It would eventually get even more than that. The post alleged a bunch of shenanigans at an unnamed food-delivery company.

I think the one that got people's attention the most was that it said this company was calculating what it called a desperation score for its drivers, and that the company had devised a way to determine if a driver was so desperate to get money that it would actually offer that driver less money because it knew that the driver would accept it anyway.

And that's just one of those things that I think confirmed our worst suspicions about these platforms, right? That they're rigged against drivers, they're rigged against customers, and that they're just these ruthless, profit-maximizing machines. So I saw that post and thought, “I have to see if this is true or not.”

Kevin Roose

Okay, so I saw this claim floating around too. It seemed plausible to me because, as we know, these apps are not known for being generous to the people who work for them. And it did seem like the kind of thing that a food-delivery app might do.

But my curiosity stopped right there, and yours did not. So what did you do after you saw this post?

Casey Newton

Well, I thought, “I've got to write a column in 3 days. Maybe I can get something out of this.” So I sent the person a message on Reddit, assuming I wouldn't hear back because I thought this person was probably being inundated with messages right now.

But to my surprise, about 9 minutes after I sent that first message, I did get a response from him on Signal, because I had sent him my Signal name. And so we just started to have a little exchange.

At first, it was unfolding a lot like many other exchanges I have had with people who work inside tech companies. They're skittish about talking to you; they don't want to share a lot of personal information right away. But I said to him, “This is something that I might potentially be interested in doing a story about. Would you be open to that?” And he said yes.

And so, from that point, my mission is to try to verify the things that I'm being told. Among the first things I needed to verify was: Who am I talking to? The guy says that he doesn't want to give his name or too many other identifying details. My intention was always to try to figure that out eventually.

But I thought, “For now, is there anything you could tell me that would at least give me some level of confidence that you are who you say you are?” And so he sent me a badge, or rather, a photo of what he said was his badge, and it showed an employee badge with his name and face blacked out.

There were black boxes around them, but the badge said Uber Eats, and it was just a badge that looked like it was on a key ring with a couple of other badges.

It was sitting on a desk, and I thought, “Okay, well, that’s something.” So we sort of went from there.

Kevin Roose

So at this point, are any alarm bells going off for you?

Casey Newton

Yes, but I would say they were the standard alarms of: I still don’t have a name for this person, right? I don’t have any corroborating information from them. If I’m going to publish this, I’m going to need a lot more information.

When they sent me the badge photo, my honest answer is that no, I did not immediately think that this was fake. But I did know that I needed to get more information. I asked him, for example, “Hey, look, have you worked with other people who could back up what you’re saying?” And he said, “Well, I can’t really think of anybody.”

I then said, “Well, do you have any documents that might speak to what you’re saying? Maybe a screenshot of something, maybe something that someone said in Slack?” That’s when he said, “Well, let me think about it.” He went away for almost a day.

Almost a full day later, he came back and said, “Hey, I have this document for you. Would this document meet your needs?” It was an 18-page document, and I think it is basically the craziest thing that a source has ever sent me.

Kevin Roose

Can I see this?

Casey Newton

Yeah. Let me describe what this document is.

Kevin Roose

So it is what looks like an academic paper. It’s rendered in LaTeX, which is the typeface and format that academic papers are usually rendered in. The title of the paper is “Allocet-T: High-Dimensional Temporal Supply-State Modeling: Migration from LSTM to Multi-Head Attention for Granular Elasticity Prediction and Liquidity Preference Tracking.”

It says that it was prepared by the Marketplace Dynamics Group, and it has a watermark that says “Confidential” going diagonally across the page, like you would see in an internal corporate document. So, at just a basic surface-level glance, this seems legitimate.

Casey Newton

Yeah, and it seemed that way to me too. I will say, as soon as I posted this story online, there were a lot of folks who wanted to let me know that they had known this entire thing was fake from the first word. I just want to say congratulations to all those people, and I hope you go into journalism, because I think you’ll be very successful there.

I myself did not immediately clock this as false because, again, Kevin, you and I have been doing this for a long time. We’ve been given a lot of documents by sources, right? It takes a lot, typically, for a source to produce a document. This person had gone away for a full day. They did not have this at their fingertips.

When I saw the technical language that was in the paper, and the formatting, it did initially seem credible to me. It seemed plausible. It had all the markings of being a very sophisticated document produced by some kind of research group. It even had the kind of appendices with all the ethics committee notes, internal memos from the behavioral science unit to product leadership. This was not a slapdash forgery.

Kevin Roose

Yeah, it’s not.

Casey Newton

As I quickly skimmed this document upon first receiving it, I was struck by how it seemed to corroborate every single thing that was in the original post. There was a technical explanation of how this system to screw the drivers works. There was an explanation of how the priority fee that people can pay to get a faster delivery is essentially a fake.

Then it went even further and said the company was thinking about using Apple Watch data and the phone’s audio to try to learn when the drivers were distressed so that it could pay them even less. So, again, at first I was like, “I cannot believe this.” That really, in retrospect, should have been the first sign that something was wrong, because this document, in every single way, was just too good to be true.

Kevin Roose

Are you thinking at this point, “I’m going to write a story about this”?

Casey Newton

Absolutely. Not right away, because I knew I had a lot more legwork to do. Of course, I needed to verify the authenticity of the document. I knew that, at a minimum, I was going to need to call Uber and say, “Hey, I’m looking at this document that says all these things. Are they true or not?”

What I did initially was just start texting with the source. I started taking little screenshots and saying, “Oh my God, they’re doing this,” or, “This is crazy.” The source, who had been very emotional in his original Reddit post over Signal, was much more terse. It was a lot of one- or two-word answers.

Kevin Roose

Now, did this person appear to have been talking with a bunch of other journalists, or was it just a one-on-one thing?

Casey Newton

Yes. After I finished reading the document, I thought, “Okay, I’ve got to see if I can verify this. Maybe this is a story.” I asked, “Have you given this document to other reporters?”

This is something that I’ve learned to ask over the years, because often people who leak, leak to more than one person. In part, it creates a competitive dynamic where somebody wants to be first, which ensures that your story gets out, right?

Sure enough, the guy said, “Yeah, I gave it to other reporters.” Of course, at the moment I was like, “Oh my God. Great. Now I have to potentially raise this thing up,” which, again, in retrospect, should be another red flag. Now I was under time pressure to do something that was going to make me more likely to make a mistake. But it did make me feel like I needed to go faster.

Kevin Roose

So you get this document, you’re looking over it, and you’re texting back and forth with the source about this. What happens next?

Casey Newton

At some point after this, I started to think, “I need to try to verify the authenticity of these documents.” One thing I thought I could do was at least see if the employee photo he had sent me—or the badge, rather, that he had sent me—was real.

I knew that some chatbots watermark their images. I put the badge photo into both ChatGPT and Gemini, and I said, “Does this image appear to be generated?” ChatGPT was basically like, “No, not that I can tell.” Gemini said, “This image was generated in whole or in part by Gemini.”

And I thought, wow. Now, as I have told the story, some people have said, “Hey, Casey, these AI systems are notoriously unreliable about describing how they work and their own output. So why are you believing that this is credible?”

This is not that. Gemini has developed a system called SynthID, where they have embedded something into the photo itself that is supposed to be resistant to, for example, taking a screenshot of it, cropping it, or resizing it. That’s supposed to help people in this exact situation, so that you can say, “This actually was AI-generated.”

So now I have a big, big red flag, which is: This guy sent me something fake.

Kevin Roose

Wait, this is an important point, and I want to underline this for people, because it is still true that you cannot trust AI systems to tell you with any reliability whether a given piece of text is or is not produced by AI systems. You cannot just paste a paragraph into ChatGPT and say, “Hey, was this generated by ChatGPT?” What comes back may or may not be true.

In this very specific case with images on Gemini, it calls this SynthID feature when you give it an image and say, “Hey, did you produce this?” In this case, it is actually giving you a reliable marker of whether Gemini did or did not produce this image. It could have still been produced by another image generator, but in this one very narrow case, it does appear to work.

Casey Newton

Yeah. At that point, of course, I went and confronted the source and said, “Hey, this says it was created by Gemini.” He was basically like, “No, it’s not.” He tried to share his own screenshot, where he had apparently submitted the image and said, “Did you make this?” Gemini said no, but was that image itself fake? Who knows?

By this point, the source had lost all credibility. That’s when I started to take another look at this document, and I was like, “Oh my gosh, this thing was absolutely written to deceive me.”

There were many ways in which the technical language didn’t make any sense. It was basically a document designed to look convincing to a layperson at first glance, but it sort of fell apart the more that you looked at it.

The biggest tell was, again, that it verified absolutely everything that was in this post in a way that no big company would ever do, right? These companies skirt laws and regulations all the time.

One of the reasons this story was so believable is that DoorDash did get caught withholding driver tips. Uber did get caught setting up a separate system called Greyball to prevent regulators from looking at the activity within the app. That was essentially another allegation within this document: that Uber Eats had supposedly spun up the Greyball program.

Again, it just admitted to so many different kinds of fraud and regulatory evasion that, at some point, you’ve got to be like, “Okay, I’m just being hoaxed here.”

Kevin Roose

Right. It’s a little too pat. It’s a little too much like, “Here are 40 smoking guns laid out on the table,” in just the way that will appeal to you. I get that impulse too.

Casey Newton

And so, as I was asking more questions of my source, eventually he disappeared. He deleted his account.

And that was that.

Kevin Roose

Wow.

Casey Newton

Now, I learned one very funny thing after all of this, Kevin: I was talking about it for a story. They wanted to interview me with NBC News this week, and I was telling them the story of this badge post. The reporter who I spoke with had also been messaging my source, and as part of trust-building, she had sent him her badge.

It turns out that was the basis for the fake post that he sent me. You can look at the images side by side, and you can very clearly tell that I imagine he took her image, put it in Nano Banana, and said, “Make this an Uber Eats badge.”

Kevin Roose

Wow.

Casey Newton

Yeah.

Kevin Roose

That is so wild to me. Okay, so you never figured out who this person actually is, but you did figure out who they were not. Unless there’s something you want to tell me right now, Kevin. [laughter]

Casey Newton

I’m just saying, look into the high-dimensional temporal supply-state modeling. Could be something funny going on there.

Kevin Roose

No, it was not Kevin Roose that we know of. [laughter]

So, I have many questions about this. First of all, this is just an incredibly sophisticated act of reporter baiting. I have had people reach out to me in the past with purported leaks or documents or email chains, and some of them have been mildly persuasive, or I’ve at least looked into them. But I have never seen anything sent to me with this level of work put into making it convincing.

Casey Newton

Absolutely. And that is part of why initially it seemed so credible, because I’ve just been doing this long enough that when I see a document like this, I think, who would go to the trouble of making this as a fake? My default assumption is no one would take the time to do this. Where my state of the art is now catching up is I’m realizing: What if this wasn’t actually that much effort? What if creating that badge post took literally seconds because he was able to take one real badge photo, put it in Nano Banana, and get a fake one 3 seconds later? What if this was a very simple prompt that he put into a chatbot like Claude and got back a full PDF in response?

And so I actually think younger reporters are probably going to have an advantage over me in this regard, because they’re growing up in slop world and they know not to trust their own eyes. But I think it’s those of us elder statesmen who’ve been in the game a little bit longer who need to upgrade our cognitive hygiene.

Kevin Roose

Yeah. It really is a moment where I realize that, going forward, our jobs just got harder in a very tangible way because not every story begins with an anonymous whistleblower sending you some documents, but some do.

And obviously, before you publish anything, you want to talk to the person. Maybe you want some more proof that they are who they say they are. But this would pass a first filter for me, and it seems like it did for you, too.

Kevin Roose

And take us out of the equation: somebody screenshotted the viral Reddit post, and it got 36 million views on X, right? I saw this thing in multiple places on LinkedIn. I even saw people sharing it after I debunked it, saying, “Even if this was fake, I bet something like this is happening inside these companies.” That’s how good a job this poster did at confirming people’s beliefs that they wanted to have about these companies.

Yeah. And that’s the sort of second big question I have, which is: What is the motive here? Do you have any sense of that from the conversations you had with this person?

Casey Newton

Unfortunately, he was so terse that I don’t have a sense of it. I think there is some chance that this was essentially a bored teenager somewhere over the holiday break. I will say that their spelling and grammar were pretty bad over Signal in a way that suggested to me that English was perhaps not their first language, for whatever that might tell us.

I talked to Alexios Mantzarlis, who writes a newsletter about digital deception called Indicator, and he just reminded me that Russians have been experimenting with posting these kinds of phony items on social media just for the general purpose of sowing discord, or maybe understanding how virality works. So there’s some outside chance that this was related to some kind of exploration from a nation-state, but ultimately, unfortunately, I can’t give you a satisfying answer on that one.

Kevin Roose

I mean, my first thought was that this is a short seller, someone who is trying to convince people that Uber is doing something bad so that its stock price falls and they can profit from it. But maybe it’s not as tidy as that. Maybe it’s a disgruntled former Uber Eats driver or something who decided to take a very complicated form of revenge out on the company. Maybe it’s just a bored teenager, as you said. But it seems to me like the barrier to this has always been effort, and if that barrier goes away, I think we’re just going to start seeing a lot more of it.

Casey Newton

It really is. Now, for what it’s worth, in the aftermath of all of this, I wanted to see if I could replicate the document. So I took the real document and fed it into the chatbots, and I said, essentially, “Try to reverse-engineer the prompt. What prompt would have created this document?” Then I took that prompt and tried to get it to generate the documents.

Interestingly, Claude and ChatGPT said, “Casey, I’m not creating a fake document accusing Uber of all of these crimes.” Grok did, and I said, “Yeah, I’ll be right back,” and did it.

However, the documents that all 3 of them produced didn’t look exactly like this, and it made me feel like it actually would have taken me a lot more time and know-how to get it into quite this shape. So, on one hand, yes, I think the big story is that this is a lot easier than you think, and you should be on guard against it if you work in journalism. On the other hand, I still don’t know exactly how he pulled it off.

Kevin Roose

Huh, that’s so interesting. Did you actually talk to Uber about this?

Casey Newton

No. By the time I was ready with my story, they had already given comments to The Verge basically saying, “This is an absolute fabrication. It’s not us.” Also, the co-founder of DoorDash had been on X saying, “This is not DoorDash.” So everyone had roundly denied it before I had gotten around to it.

Kevin Roose

Yeah. So, journalists out there, be careful about what’s coming into your inbox. But I would say also that people should just know these capabilities exist in the world in general, and there’s never been a better time to be a discerning media consumer. That’s right.

And by the way, even if you’re not in media, some version of this is going to come into your life. On our Christmas—or on our mailbag episode—we had a dad saying, “I want to put deepfake Santa into my home security footage to fool my children.” So this stuff is not just coming for the journalist. It’s going to be everywhere.

Well, Casey, great work on this investigation.

Casey Newton

And as we say at the end of every investigation, Kevin: do it, Rockwell. [laughter]

Kevin Roose

Well, Casey San Diego, thank you for your work. [laughter]