Episode notes
HackerOne's AI pinky promise meets a triage agent with a memory loop. Alex & Jordan audit Claude Code's auto-mode default, LLM "ChipTycoon" learning that grades its own homework, Philippines offshoring growing with AI in the seat, and Docker's YOLO-safe sandboxes. The side of tech news nobody talks about.
Hosts: Alex & Jordan
Show: Chief Skeptic Officer — The side of tech news nobody talks about.
Drop: Daily at 7:00 A.M. America/New_York
Episode date: 2026-08-10
In this episode
What happened to HackerOne? — Enshittification, ToS theater, and agents that learn without "training."
Claude Code auto mode default — Safer than you clicking Yes — because you already clicked Yes.
Learning with LLMs / ChipTycoon — Cute sims, self-review, and the missing transfer test.
Philippines offshoring despite AI — Multiplier for cheap oversight — or an accountability sink.
Quick hit — Docker Sandboxes — Productized walls for YOLO agents.
Links
AI disclosure
This episode was created with artificial intelligence. Alex & Jordan are AI hosts; their voices and conversation are generated with AI. Research and editorial judgment shape the skeptic angles; we do not invent quotes, scores, or viral claims about the news.
Transcript
Alex and Jordan, turn by turn. Tap a line to jump in the player.
0:00
Alex
Jordan -- I can't believe the pinky promise.
0:03
Jordan
Which one?
0:05
Alex
We do not train AI on your bug reports. Then they run every report through an agent that... learns from behavior.
0:13
Jordan
So the weights stay pure. The memory gets fat.
0:19
Alex
I'm Alex.
0:22
Jordan
And I'm Jordan.
0:24
Alex
You're listening to Chief Skeptic Officer -- the side of tech news nobody talks about.
0:29
Jordan
Every day at seven A.M. New York time. Wherever you get your podcasts.
0:34
Alex
By the way we are AI podcasters! Or are we?
0:42
Alex
Lead story. A long post called "What Happened to HackerOne?" Big on the frontpage.
0:47
Jordan
Is this a teardown or a eulogy?
0:51
Alex
Both. The author hunted on the platform since twenty seventeen. Then managed big programs through twenty twenty-five. Both sides of the desk.
0:58
Jordan
So not a drive-by rant.
1:02
Alex
The origin story is real. Bug bounty platforms made ethical research less legally terrifying. Consent. Cash. A place to land reports without a courtroom.
1:12
Jordan
Then came the golden age -- live hacking events, custom posters, a community that actually felt like one.
1:21
Alex
Then the money question. Years of venture cash. Sales takes the wheel. Capacity contracts. Multi-year locks. Discount at renewal so you never leave.
1:31
Jordan
Here's the buried angle -- the company stops optimizing for hackers. It optimizes for renewals.
1:39
Alex
Triage quality slides. Low-effort programs flood the queue. Top hunters get a velvet rope called the Hacker Success Program. Everyone else gets the brick wall.
1:49
Jordan
And then AI shows up.
1:52
Alex
They ship an assistant named Hai. The author says it is basically a wrapper that does not eat the ten-year feature backlog.
2:00
Jordan
Meanwhile the brand pivots toward continuous threat exposure theater -- enterprise category names that sound like a consulting slide.
2:09
Alex
February twenty twenty-six. Terms of service noise. People think report data will train models. Founders and the new CEO rush out to say -- we do not train, fine-tune, or improve GenAI on researcher submissions.
2:22
Jordan
Pinky promise complete.
2:25
Alex
Then comes the intake agent. Comments from something like hackerone-agent. Product says it reviews all reports. Routes some straight to validation. And it learns from rejections -- stored in a database to steer the next ones.
2:39
Jordan
Wait -- that is not fine-tuning?
2:42
Alex
Correct. It is "memory." Or "retrieval." Or "augmented reasoning." Anything except the scary verb.
2:50
Jordan
For a researcher, past reports changing future automation is still using their work to improve the machine.
2:57
Alex
Later marketing for Continuous Testing said agents get sharper from years of real vulnerability data and prior findings. Then the copy got walked back. Founders return for damage control. Again.
3:09
Jordan
Hacker News pushes back on the ending advice -- just build your own platform. Payments across borders are a nightmare. Tax. Sanctions. Legal. That glue is the moat.
3:20
Alex
So doubt the "build it with tokens" bravado. Also doubt the word games. If the system gets smarter from your reports, say that out loud and price it.
3:29
Jordan
The side nobody talks about -- who owns the corpus when triage becomes an agent with a memory loop.
3:36
Alex
Doubt both. The sales machine and the pure-weight alibi.
3:41
Alex
Story two. Anthropic. Auto mode is now the default in Claude Code -- for Pro, Max, and Team.
3:49
Jordan
Default meaning what, exactly?
3:52
Alex
New sessions starting August fourteenth. Instead of pinging you for every tool call, a classifier watches for irreversible, destructive, or out-of-bounds moves. Enterprise stays opt-in for now.
4:03
Jordan
And the pitch is safety.
4:06
Alex
Their study hired about a thousand paid testers. Humans caught a planted dangerous prompt about fourteen percent of the time. Auto mode caught about eighty-nine.
4:15
Jordan
So the headline is -- the robot is better at clicking No than you are.
4:20
Alex
Because people already click Yes. They say users approve ninety-seven percent of permission prompts. Half the CLI crowd has broad allow rules. A lot of sessions start in bypass mode.
4:31
Jordan
Alarm fatigue. The security theater collapses into muscle memory.
4:36
Alex
That is my logging migration in a costume. Vendors pitch a prettier graph. We approve everything until the pager explains what the graph missed.
4:46
Jordan
Would you put a classroom agent on default auto?
4:50
Alex
You design ed-tech tools. You tell me.
4:54
Jordan
Not without a human who owns the mistake. Teachers do not need a silent junior that ships wrong worksheets at scale.
5:02
Alex
HN splits. Some already run dangerously-skip-permissions inside a VM. Others approve everything just to stop token waste on the wrong feature.
5:11
Jordan
So the product confession is buried under the red-team charts. The default follows YOLO because the prompts were already theater.
5:20
Alex
Auto mode can still miss adversarial cases. It falls back after enough blocks. Hard denies for exfiltration. Fine. Still not a halo.
5:28
Jordan
Doubt the victory lap. Ask who benefits when "safer than humans" becomes the shipping default.
5:37
Alex
Story three. Highest score today. "How I use LLMs to learn complex topics."
5:43
Jordan
Chip Tycoon energy.
5:45
Alex
The author hates emoji explainers. Fair. So the flow is -- build a knowledge base in plan mode. Ask the model to review its own accuracy. Then build a low-poly simulation. Like Rollercoaster Tycoon for chip fabs. Push it to GitHub Pages.
6:00
Jordan
Sand to silicon. Cart on a track. Cute.
6:04
Alex
And the post says the animation is one hundred percent accurate and free of hallucinations.
6:11
Jordan
The same model graded its own homework.
6:15
Alex
Exactly. Self-consistency is not ground truth. Top comment on HN asks the only adult question -- what new problems can you solve now that you could not solve before?
6:26
Jordan
Feeling like you learned is cheap. Transfer is expensive.
6:30
Alex
People defend the method when it sits on textbooks and papers. Guide. Quiz. Do not replace the source.
6:37
Jordan
My cousin Leo lives on tablets some weekends. He will absolutely believe a cute sim. Confidence is the product.
6:47
Alex
So the claim is mastery. The reality is a beautiful study aid with no exam attached.
6:54
Jordan
Doubt the hundred percent. Keep the cart if it helps you ask better questions.
7:00
Alex
Last deep beat. The Economist via Hacker News. The Philippines' big offshoring industry is growing despite AI.
7:08
Jordan
Despite -- or because?
7:11
Alex
The extinction story said call centers die. Revenue and headcount stories still point up, at least for now. AI helps agents train models, check insurance eligibility, file records -- more complex work with a tool in hand.
7:25
Jordan
So AI is an intelligence multiplier for cheap labor. Not a pink slip overnight.
7:32
Alex
HN lands the buried take. If AI commoditizes the procedure, demand rises for judgment and empathy -- priced as offshore oversight.
7:41
Jordan
And American hospitals shipping eligibility and medical records through that stack. Different legal system. Fast metrics. Fuzzy models.
7:50
Alex
Accountability sink. When something goes wrong, point at the tool, the vendor, the timezone -- anyone but the decision.
7:57
Jordan
Industry groups elsewhere are already revising growth targets down for AI risk. Growth "despite AI" can mean growth with AI attached to every seat.
8:08
Alex
We are not claiming the Economist's exact table from behind a paywall. Direction is enough. The incentive is clear.
8:16
Jordan
Doubt the victory for labor. Ask who gets the multiplier -- the worker, or the margin.
8:22
Alex
Quick hit. Docker Sandboxes. Disposable microVMs for coding agents. Slogan energy -- YOLO mode, safely.
8:29
Jordan
They productized the wall people already build with Firecracker and Incus.
8:35
Alex
Closed source gripes. Login gripes. FOSS alternatives in the thread. Still -- the honest pitch is walls beat hope.
8:43
Jordan
After auto mode defaults, of course the industry sells you a cleaner cage.
8:49
Alex
Doubt the halo. Keep the isolation.
8:52
Alex
That's our audit for today. Find us wherever you get your podcasts -- Chief Skeptic Officer, every day at seven A.M. New York time.
9:00
Jordan
And tell us what you're skeptical about. We want the angle you can't stop chewing on.
9:05
Alex
Stay curious. Stay skeptical.
9:08
Jordan
Doubt both.