Clown Cast

Poisoned Potions: When Code Dependencies Turn Evil

17 min · 3 jun 2026
aflevering Poisoned Potions: When Code Dependencies Turn Evil artwork

Beschrijving

A deep dive into software supply chain attacks—where a single compromised package can infiltrate thousands of projects through invisible dependency chains. Explore how npm and PyPI became the internet's most dangerous potion shops, from the left-pad collapse to the event-stream backdoor, and the emerging 'slopsquatting' threat where AI hallucinations become actual security vulnerabilities. 00:00 - The Potion Shop Metaphor: How Package Registries Work 02:30 - Dependency Trees: Why You're Installing 1500 Packages Without Knowing It 06:00 - The Left-Pad Incident: When 11 Lines of Code Broke the Internet 09:30 - The Event-Stream Backdoor: A Trojan Horse in Plain Sight 13:00 - Slopsquatting: AI-Generated Package Names as Attack Vectors 17:00 - Defense Strategies: Can You Trust Your Dependencies? This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

Reacties

0

Wees de eerste die een reactie plaatst

Meld je nu aan en word lid van de Clown Cast community!

Probeer gratis

Probeer 14 dagen gratis

€ 9,99 / maand na proefperiode. · Elk moment opzegbaar.

  • Podcasts die je alleen op Podimo hoort
  • 20 uur luisterboeken / maand
  • Gratis podcasts

Alle afleveringen

78 afleveringen

aflevering Infinite Scroll: Why Your Attention Span Is Actually Fine artwork

Infinite Scroll: Why Your Attention Span Is Actually Fine

You've heard humans now have an 8-second attention span, shorter than a goldfish. It's everywhere—headlines, TED talks, marketing decks. It's also completely fabricated. This episode debunks the myth, traces its absurd origins, and explores what the actual neuroscience reveals about infinite scrolling, dopamine, and whether your brain is really changing. 00:00 - Cold open: Welcome to the scroll 01:20 - The 8-second goldfish myth debunked 03:45 - Tracing the false stat to its source 05:30 - What goldfish can actually do 07:00 - Research shows no decline in attention spans 09:15 - How infinite scroll weaponizes dopamine 12:00 - Headlines vs. what the research actually says 14:30 - Why it feels broken if it isn't 16:45 - Outro This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

5 jun 202616 min
aflevering The 1.5 Million Problem: Securing Enterprise MCP Gateways artwork

The 1.5 Million Problem: Securing Enterprise MCP Gateways

Shadow MCP servers are running wild in enterprises, connecting AI agents to critical systems with zero security oversight. This episode follows an AI-native engineer tasked with building the first governed MCP gateway—a security framework that brings registry management, identity enforcement, policy engines, and audit trails to enterprise tool integration. We break down why one-off integrations cost $670K extra per breach and how the Model Context Protocol became enterprise's biggest security blind spot. Key timestamps: 00:00 - Hook: 1.5 Million Unsecured AI Agents 02:15 - Shadow MCP: The New Shadow IT 05:30 - The Cost of Uncontrolled Integration 08:45 - Why MCP's Success Created the Problem 11:20 - Enter the Enterprise Gateway 13:40 - Building the Security Framework (Registry, Identity, Policy, Audit) 16:00 - Top-K Tool Pruning & Token Telemetry 17:30 - Closing Thoughts on Governance This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

Gisteren18 min
aflevering The Swerve and the Algorithm: Who Really Decides? artwork

The Swerve and the Algorithm: Who Really Decides?

Are your choices truly yours, or just the result of atoms, neurons, and algorithms following predetermined rules? In our philosophical deep dive into determinism and free will, we trace 2,300 years of thinking—from Epicurus's theory of cosmic swerves to modern neuroscience proving your brain decides before you're conscious of it. With AI algorithms now nudging our decisions daily, the ancient question of free will feels more urgent than ever. 00:00 - The Paradox of Choice 02:15 - Epicurus and the Swerve: Glitches in Reality 05:00 - The Stoic Response: Determinism and Virtue 08:10 - Neuroscience: Your Brain's Secret Decisions 11:30 - Algorithms as Modern Determinism 14:45 - Eastern Philosophy and Acceptance 17:00 - The Freedom We Can Keep This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

Gisteren18 min
aflevering The 2% Who Beat the Odds: Plus-EV Betting Exposed artwork

The 2% Who Beat the Odds: Plus-EV Betting Exposed

How do you make money when you lose more bets than you win? In this episode, we explore plus-EV betting—the mathematical framework that allows 2-3% of sharp bettors to consistently profit from sportsbooks in a $165 billion market. From understanding expected value to finding price edges, discover the difference between prediction and probability that separates the sharps from the house. 00:00:00 - Intro: Magic and Money (The Hook) 00:02:00 - Defining Plus-EV and Expected Value 00:04:00 - US Sports Betting by the Numbers (165B Processed, 10% House Take) 00:06:30 - The Sharps: Meet the 2-3% Who Beat the System 00:10:00 - The Price Edge: Why Prediction Doesn't Equal Profit 00:14:00 - Practical Deep Dive: Tools and Bankroll Tracking This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

Gisteren16 min
aflevering Poisoned Potions: When Code Dependencies Turn Evil artwork

Poisoned Potions: When Code Dependencies Turn Evil

A deep dive into software supply chain attacks—where a single compromised package can infiltrate thousands of projects through invisible dependency chains. Explore how npm and PyPI became the internet's most dangerous potion shops, from the left-pad collapse to the event-stream backdoor, and the emerging 'slopsquatting' threat where AI hallucinations become actual security vulnerabilities. 00:00 - The Potion Shop Metaphor: How Package Registries Work 02:30 - Dependency Trees: Why You're Installing 1500 Packages Without Knowing It 06:00 - The Left-Pad Incident: When 11 Lines of Code Broke the Internet 09:30 - The Event-Stream Backdoor: A Trojan Horse in Plain Sight 13:00 - Slopsquatting: AI-Generated Package Names as Attack Vectors 17:00 - Defense Strategies: Can You Trust Your Dependencies? This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

3 jun 202617 min