Feed aggregator
The AI plot to scan and destroy books (Lock and Code S07E19)
This week on the Lock and Code podcast…
If you want AI to tell you a story, it will. If you want that story to sound like one of your favorite authors, it can. And if you’re one of the authors that AI can imitate, you might be a little upset at what feels like theft.
In 2024, the authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson sued Anthropic, the creator of Claude, alleging that the company had wrongfully digested millions of copyrighted works—including some of their very own—to train its AI models. The lawsuit grew to include more than 300,000 writers, and in September 2025, Anthropic agreed to pay $1.5 billion to settle the claims.
That headline-worthy payout, however, would eventually be paired with more startling news.
In January 2026, a district court judge unsealed thousands of documents related to the litigation. When The Washington Post investigated the documents, reporters found references to a secret project inside Anthropic called “Project Panama,” which Anthropic itself described as the company’s effort “to destructively scan all the books in the world.”
Anthropic is not alone in this.
On August 17, 404 Media co-founder and reporter Emanuel Maiberg revealed that Amazon is doing something similar inside a department it calls VGT3. By hiding an Apple AirTag in one book from a 1,000-book order, and then tracking the shipment across the country, 404 Media identified the book’s final destination to be a facility outside Las Vegas, where, according to employees, books are cut apart and scanned.
Today, on the Lock and Code podcast with host David Ruiz, we speak with Maiberg about Amazon’s VGT3 operation and the likely commonplace practice of AI companies purchasing, scanning, and destroying books in an effort to build “frontier” models.
“They’re buying a book, they’re scanning it, they’re mulching the book, and then the digital version of the book exists behind this wall where we don’t even know if they plan to sell it, right? It’s like they might keep it behind a wall, and the only way we see it come out again from behind that wall is in the form of an answer from a chatbot.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek.
A restored PDP-11/83 serving this page on 211BSD Unix
Article URL: http://pdp1173.com/
Comments URL: https://news.ycombinator.com/item?id=49788773
Points: 1
# Comments: 1
Show HN: All of FreeCAD 1.1.3, every workbench and FEM, running in the browser
Article URL: https://freecad.virtastic.app/
Comments URL: https://news.ycombinator.com/item?id=49788754
Points: 1
# Comments: 0
46% of Open-Source AI Agents dropped from rankings in 28 weeks
Article URL: https://www.theagenticleaderboard.com/
Comments URL: https://news.ycombinator.com/item?id=49788752
Points: 1
# Comments: 1
Goolsbee: The Fed Can't Keep Waiting Out Oil Shocks
Design Drought
Article URL: https://lmnt.me/blog/design-drought.html
Comments URL: https://news.ycombinator.com/item?id=49788708
Points: 1
# Comments: 0
Show HN: Timewaster – They waste your time. Return the favor
Article URL: https://timewasterapp.com/
Comments URL: https://news.ycombinator.com/item?id=49788699
Points: 1
# Comments: 0
IvoryOS – Orchestrate an Autonomous Lab
Article URL: https://ivoryos.ai/
Comments URL: https://news.ycombinator.com/item?id=49788691
Points: 1
# Comments: 0
The fake sites using a cheap toolkit to sell $2,000 AI subscriptions
We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another uses the name of Omegle, the chat service that shut down in 2023. Others promote unfamiliar brands with little verifiable information about who operates them.
The sites we examined did not use fake password forms or push malware downloads. Instead, they used polished product pages and genuine Google sign-in screens before directing visitors to paid plans. Someone visiting an imitation site could believe they were buying from the genuine provider. With the unfamiliar brands, it is difficult to establish who is selling the subscription or independently verify the claims being made.
Despite their different names and designs, the sites share identical underlying files and closely related developer email addresses. This suggests that a single operator, or closely connected group, is behind the network.
What the sites show youAt first glance, these sites don’t look suspicious. They use secure connections, professional designs, and the confident language you would expect from an established software company.
The secure connection and padlock only show that traffic between you and the site is encrypted. They do not confirm who operates it.
Some show performance comparisons, star ratings, and precise user numbers. One claimed to have more than 12 million users. Another displayed the names of well-known companies as customers, although we found no evidence that those businesses were connected to it.
A website owner can add any rating, customer number, testimonial, or test result to a page. None of these claims should be treated as independent evidence that a product is genuine or widely used.
Behind the Sign in or Get started button is a subscription service. Visitors are asked to sign in with Google and are then shown paid plans, usage credits, and payment histories. Prices range from less than $10 a month to more than $2,000 a year. Several sites also ask users to upload documents, recordings, or other files for the advertised service to process.
The fake GPT-6 Astra site offers plans costing $89, $169, or $249 a month.On the sites we examined, there was no way to test the advertised product before paying. Controls on the landing pages did nothing until we signed in, and signing in led to a pricing page rather than the tool itself.
Many legitimate services require payment before use, so that alone does not prove that a site is unsafe. The concern here is the lack of reliable information about the company selling the subscription. There are no independent reviews or official product listings to compare with the claims on the page.
Different brands, the same website kitThe sites advertise a wide range of products, including voice-cloning tools, video editors, study apps, and general-purpose AI assistants. Underneath their different designs, however, they use the same commercial website starter kit.
The kit is a legitimate product designed to help people launch online services quickly. It includes an account system, billing, file storage, and administrative tools. The buyer supplies the branding and the product being advertised.
This explains why apparently unrelated services have identical checkout pages and account settings. The underlying system is the same even when the colors, typefaces, and product names are different.
The kit costs $249 as a one-time purchase, while additional templates cost about $2 each. Its vendor advertises that customers can launch a product in an hour. Once the first site has been created, producing more versions requires relatively little time or money. Building another site may require little more than a new domain, design, and product description—which might explain how the network grew to this scale.
Several sites still contain demonstration material supplied with the starter kit. This includes the kit’s brand name, promotional banners, generic menu entries, and testimonials from named people and companies with no apparent connection to the advertised service.
One site had relabeled a demonstration list of businesses as its own customers. On another, the word “boilerplate,” a term for reusable starter code, remained in the name of a paid subscription plan.
Signing in with GoogleThese sites send visitors to a genuine Google sign-in page. The web address belongs to Google, and the password is entered on Google’s website rather than on the service being advertised.
The sites we examined requested basic information such as the user’s name, email address, and profile picture. They did not ask for access to Gmail or Google Drive.
The Google consent screen used by the fake GPT-6 Astra site requests a name, email address, and profile picture.However, a genuine Google sign-in page does not confirm that the service is official or connected to the brand it displays. It only confirms that Google is handling the login and passing the approved information to an outside application.
Google’s consent screen identifies the application requesting access and provides developer details. Check these against the website and product you intended to use. If those names don’t match, you may not be dealing with the company you thought you were.
You can also open the developer information shown by Google. On the sites we examined, the support contacts were free webmail addresses rather than addresses belonging to the brands displayed on the websites.
Google’s developer information shows a free Gmail support address behind one of the sites.A free email address is not proof of wrongdoing, but it should raise questions when a service claims to have millions of users or presents itself as an established company.
How the sites are connectedWebsites load files containing the code they need to work. The system used by these sites gives some of those files names based on their contents. When the contents change, the filenames generally change too.
Across the sites we examined, many of these filenames were identical. This indicates that the sites were running the same version of the same underlying software. On its own, this could simply mean that different people bought the same starter kit.
The Google developer details provide a stronger connection. The developer contacts use free webmail accounts containing the same name, with only small differences such as the numbers added to the address.
Because these addresses are provided when the applications are registered with Google, rather than being automatically supplied by the starter kit, they suggest that the sites are operated by one party or by closely connected people.
What you agree to when you subscribeThe sites provide little information about the business selling the subscription. We found no registered company names, business addresses, or other independently verifiable ownership details. In many cases, the only contact method was an email address using the site’s own domain.
This could make it difficult to request a refund, challenge a charge, or resolve a problem with the subscription.
Some of the subscriptions are substantial. Alongside monthly plans, the sites sell annual access charged as a single payment, with one plan costing more than $2,000. Some plans state that unused credits expire after a set period.
Depending on the payment system used, card details may be handled by a third-party payment provider rather than given directly to the website operator. Users may still share account information and potentially sensitive material with a service whose owner they cannot identify.
How to spot sites like theseA polished design, real Google sign-in page, and impressive-looking reviews do not prove that a service is trustworthy.
- Check the web address. Make sure it belongs to the company or product you intended to use. Don’t rely on the logo or product name alone.
- Find out who runs the site. Look for a company name, business address, privacy policy, terms, and reliable contact details that can be independently checked.
- Read the Google consent screen. Check the application name, domain, developer details, and information it wants to access before selecting Continue.
- Be cautious if you cannot test the product. A service that offers no trial or working demonstration is asking you to pay before you can confirm that it does what it claims.
- Check independent sources. Search for the product separately and look for an official website or app-store listing. Do not rely on ratings and testimonials displayed by the seller.
- Don’t upload sensitive files until you know who operates the service. Documents, photos, recordings, and prompts may contain private information.
- Check your statements after subscribing. Contact the payment provider or your bank promptly if you see a charge you do not recognize.
- Remove connections you no longer trust. Visit the connections page in your Google Account and remove services you do not recognize or use. This prevents future access, but it does not delete information already shared with the operator.
Malwarebytes Browser Guard blocks malicious, phishing, scam, and fraudulent websites, including pages reached through deceptive adverts or search results.
If you’re unsure about a site, Malwarebytes Scam Guard can assess its web address or a screenshot and help you identify warning signs.
These particular sites centred on accounts and subscriptions rather than phone calls. If a suspicious service directs you to a support number, you can check it with Malwarebytes Scam Number Check before calling.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Show HN: 7 Coder Words – A puzzle game for computer science nerds
Article URL: https://kenamick.itch.io/7-coder-words
Comments URL: https://news.ycombinator.com/item?id=49788677
Points: 1
# Comments: 0
I shipped 2,000 pull requests through production last month [video]
Article URL: https://twitter.com/poteto/status/2102050467505430555
Comments URL: https://news.ycombinator.com/item?id=49788670
Points: 1
# Comments: 0
You Can Detect If Code Is Being Run Inside a Terminal
Article URL: https://nelson.cloud/you-can-detect-if-code-is-being-run-inside-a-terminal/
Comments URL: https://news.ycombinator.com/item?id=49788668
Points: 1
# Comments: 0
We Have So Many Questions
Article URL: https://lab.cloud/news/we-have-so-many-questions/
Comments URL: https://news.ycombinator.com/item?id=49788667
Points: 2
# Comments: 0
Pinned-Value Goods
Article URL: https://arun.is/blog/pinned-value-goods/
Comments URL: https://news.ycombinator.com/item?id=49788654
Points: 2
# Comments: 0
Using TypeSafe AI in Bug Bounty
Article URL: https://www.lampysecurity.com/post/using-typesafe-ai-in-bug-bounty
Comments URL: https://news.ycombinator.com/item?id=49788625
Points: 1
# Comments: 0
Tobi: Persistent terminal sessions across your devices
Article URL: https://tangled.org/ptr.pet/tobi
Comments URL: https://news.ycombinator.com/item?id=49788612
Points: 1
# Comments: 0
Trump Says His Contested Arch Would House Drones and Snipers
Article URL: https://www.nytimes.com/2026/09/20/us/politics/trump-dc-arch-snipers-drones-military-complex.html
Comments URL: https://news.ycombinator.com/item?id=49788611
Points: 2
# Comments: 0
Bootstrap scripts for ML workloads on a few GPU cloud providers
Article URL: https://github.com/tudormunteanu/gpu-cloud-instance-boostraps
Comments URL: https://news.ycombinator.com/item?id=49788598
Points: 1
# Comments: 0
