
2 days ago
Episode 269 - Eighteen Billion and a Bedtime Meta Settlement, Claude Watermark Trace Buster Buster, Cookie Fort Knox
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
Meta buys its way out of the teen engagement lawsuit and writes the curfew into the settlement.
- Meta settled with 52 attorneys general for ~$18B over claims Facebook and Instagram were built to drive compulsive teen use, resolving a 2023 suit led by California AG Rob Bonta that also alleged illegal under-13 data collection under COPPA. The product terms are the real story: a default two-hour daily cap for under-18s that only a parent can lift, a midnight–6am blackout, notifications muted 10pm–7am and during school hours, hidden like counts, no cosmetic surgery filters, and expanded age verification to find under-18s and purge under-13s — locked in for ten years under an independent auditor. Only $12.7B goes to states now. The other $5.3B is held back until YouTube and TikTok adopt matching one-hour limits, nighttime restrictions and age assurance, and each makes a matching payment — at which point Meta's own cap drops to one hour. Meta openly framed this as driving industry-wide adoption. Read that again: Meta just put a $5.3B bounty on its competitors adopting mandatory age verification, and everyone's calling it a punishment. Meta books ~$10B in Q3 legal expenses; California takes $1.5–2.1B.
A watermark-removal industry sprang up overnight for a watermark nobody can detect.
- Days after Anthropic switched on invisible watermarking in everything Claude writes, a removal market appeared: a 4,500-star GitHub project, freshly registered domains like claudewatermark[.]rip and gptcleanup.com, and existing Turnitin-bypass shops (StealthGPT, Human Writes) bolting Claude onto their pitch. None of it is verifiable; Anthropic hasn't published the scheme or shipped a detector. The technical punchline: stripping zero-width characters and C2PA/EXIF metadata works, but it's trivial, since file metadata dies on a re-save or a screenshot. The real mark lives in which words the model picked, so the only known removal is a heavy rewrite through a second model. Guillaume Meyer, who wrote the biggest tool, says so himself, metadata only, for now. Tester Pasquale Pillitteri read the code instead of the READMEs and found one popular cleaner passed a hidden payload through intact. Driver is EU AI Act Article 50, enforceable since Aug 2, penalties to €15M or 3% of global turnover. And a detected mark only proves Claude touched the text, not that it wrote it. Defender angle: these ship as agent skills people wire into pipelines and feed documents through. That's a supply chain surface.
Chrome finally kills the infostealer's favorite trick: the stolen cookie that walks past your MFA.
- Chrome shipped device-bound session credentials, storing a key in the device's security chip: TPM on Windows, Secure Enclave on macOS and iOS and cryptographically binding session cookies to that hardware. A stolen cookie can't be replayed on the attacker's box to walk past MFA, because the private key never leaves the chip. This is the fix for the failure mode we keep covering: as users adopted 2FA and passkeys, infostealers stopped fighting the login and started lifting the post-auth session instead. Announced in 2024, beta in April, GA for Workspace on Chrome for Windows from May 25, on by default with no admin config, and binding events are visible in Admin console audit logs. Honest caveat: it kills one very popular path, not every takeover, and only where the server side implements it.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
No comments yet. Be the first to say something!