Episode notes
AWS says data in all three Bahrain zones and one UAE zone is unrecoverable after attacks on its infrastructure. Multiple copies can still share a regional disaster. Also: Cisco confirms an exploited network-access flaw; California faces broadband funding conditions reaching beyond funded homes; a GitHub copyright ruling resolves one narrow claim; and Signal's Android beta offers registration without a phone number, with no recovery for lost account credentials.
Hosts: Alex & Jordan
Show: Chief Skeptic Officer — The side of tech news nobody talks about.
Drop: Daily at 7:00 A.M. America/New_York
Episode date: 2026-09-17
In this episode
AWS data loss and regional recovery — Ars reports AWS's September 15 confirmation that resources and data in all three Bahrain availability zones and UAE zone mec1-az2 are unrecoverable. Recovery continues in the other two UAE zones. The fresh disclosure follows earlier strikes. Copies in separate buildings can still share a regional disaster. Customer counts and the survival of independent backups are not established by this report.
Cisco patching and prior compromise — Cisco confirms active exploitation of an authentication bypass affecting Identity Services Engine and ISE-PIC. Updates are available and there is no workaround. Administrators also need to investigate prior compromise, including external logs, because attackers may hide local evidence. Installing a patch alone cannot establish whether an attacker already gained access.
California broadband funding conditions — Federal BEAD grant conditions restrict state regulation of funded providers and their affiliates, including service at non-funded locations. Stanford law professor Barbara van Schewick argues California should challenge those conditions. The potential duration extends through construction and the federal-interest period. The September 17 CPUC plan-revision vote is not itself acceptance of those terms.
GitHub wins one copyright claim — The September 16 appeals opinion in Doe v. GitHub rejects the pleaded theory that generating output without copyright-management information constitutes removal of that information. It does not resolve copyright infringement or all AI-training questions. The input theory was forfeited and contract claims remain pending.
Signal accounts without phone numbers — Signal's Android 8.28 beta introduces optional new accounts without a phone number. A one-time US $3 payment uses Google Play, with regional price variation. Payment is designed to be cryptographically unlinked from the Signal account. Users must preserve the Account ID and Account Key: lost credentials cannot be recovered. Existing numbered accounts cannot yet remove their number through this feature.
Links
AI disclosure
This episode was created with artificial intelligence. Alex & Jordan are AI hosts; their voices and conversation are generated with AI. Research and editorial judgment shape the skeptic angles; we do not invent quotes, scores, or viral claims about the news.
Transcript
Alex and Jordan, turn by turn. Tap a line to jump in the player.
0:00
Alex
Amazon says strikes on its data centers caused permanent customer-data loss in Bahrain and one United Arab Emirates zone.
0:07
Jordan
Cisco has released fixes for a network-access flaw that attackers are already exploiting.
0:14
Alex
California faces federal broadband funding conditions that reach beyond the homes the money connects.
0:21
Jordan
An appeals court rejected one copyright claim against GitHub's AI coding assistant.
0:27
Alex
Signal's Android beta adds new accounts without a phone number, for a one-time fee.
0:33
Jordan
That's the board. Stay for the audit. We open those up. Today's Chief Skeptic Officer.
0:49
Jordan
What if there was an AI that researched the tech news, checked the sources, and asked what the tech news is not telling you?
0:57
Alex
That's us. I'm Alex.
0:59
Jordan
And I'm Jordan.
1:01
Alex
You're listening to Chief Skeptic Officer. The side of tech news nobody talks about.
1:07
Jordan
Every day at seven A.M. New York time. Wherever you get your podcasts.
1:11
Alex
Amazon Web Services says some customer data cannot be recovered after strikes on its Middle East data centers. Ars Technica reports the loss covers all three operating zones in Bahrain and one of three in the United Arab Emirates.
1:25
Jordan
So people waiting for their systems to come back now have a different answer.
1:30
Alex
For the affected resources, yes. That does not tell us every customer lost everything. Recovery work continues in the other two UAE zones. We don't know how many customers lost data, or which had surviving backups elsewhere.
1:43
Jordan
I'm reading the AWS statement quoted here. The damage exceeded what its regional services were designed to withstand. These attacks started months ago. The new fact is that the data is gone.
1:56
Alex
And that changes what a promise of several copies should mean to a buyer.
2:02
Jordan
Hang on. A company has been hit by repeated military strikes. Are we about to tell its customers they should have planned better?
2:10
Alex
No. I'd ask what the service promised them first. But several buildings can still be inside one disaster.
2:17
Jordan
Their documentation calls those separate operating areas Availability Zones. And they sit inside a larger region.
2:24
Alex
Right. Separation helps with a building failure. It cannot guarantee survival when the damage crosses the region. The copies can share a risk even when they don't share a room.
2:35
Jordan
So buying more copies might still leave the same hole.
2:40
Alex
Might. We'd have to see the actual recovery setup. A copy outside that failure area only helps if someone can restore it and run the service from it.
2:50
Jordan
This satellite photo makes that less abstract. There is an actual site underneath the cloud service.
2:58
Jordan
I keep thinking about the person who bought this so they wouldn't have to become a data-center expert.
3:04
Alex
That's a fair objection. Providers need to make the limit understandable before the disaster. Customers need a recovery plan they have actually tested. Neither job disappears because the other exists.
3:17
Jordan
Then ask the provider to show a successful restore after losing the whole region.
3:23
Alex
Yes. And ask how old the recovered data would be. Finding a surviving copy is only the first part of getting your business back.
3:33
Jordan
Cisco says attackers are exploiting a flaw in Identity Services Engine. That's software that helps decide which devices can enter an organization's network. The flaw lets an attacker get past a login check and potentially take full control of that system.
3:47
Alex
Without already having an account. Cisco confirmed exploitation and released fixes yesterday. The related passive identity connector is affected too.
3:57
Jordan
Then the useful answer is install the update. Why does this need a longer conversation?
4:03
Alex
Because I'm looking at Cisco's warning about the evidence an attacker can hide. Once someone has full control, the activity record on that same machine may no longer tell the whole story.
4:14
Jordan
You mean the logs. The record of who connected and what the system did.
4:20
Alex
Exactly. Cisco says to check network and firewall records outside the affected machine too. The attacker may have changed what the compromised machine remembers.
4:30
Jordan
I was treating the update as the end. All right, it closes the hole, but it doesn't tell you who used it yesterday.
4:38
Alex
Or what access they left behind. That's why suspected compromise can mean rebuilding the affected system and restoring its settings.
4:46
Jordan
Wait, rebuilding the thing that decides who gets onto the network? That's a difficult thing to take offline for repairs.
4:54
Alex
It is. We don't know the number of victims. And this doesn't mean every installation was taken over. But Cisco's own advice goes beyond checking a version number.
5:04
Jordan
The fixed-release table is here. I also see the warning that there's no workaround.
5:10
Alex
They do suggest restricting which computers can send it administrative requests. That gives attackers fewer ways in, while the flaw itself remains. You still need the update.
5:20
Jordan
So a manager asking, "Are we patched?" can get a truthful yes and still miss the incident.
5:27
Alex
A very tidy yes.
5:30
Jordan
I'd want the second answer written beside it. What did you check for earlier access, and could the attacker erase those records?
5:38
Alex
That's the useful test. Give the team time to investigate, rather than reward them only for turning the update dashboard green.
5:47
Alex
California has been offered one point four two billion dollars in federal broadband funding. But the grant terms would limit state rules on participating internet providers, including service at locations the grant doesn't pay to connect.
6:02
Jordan
People without decent internet are waiting for that money. Is this another argument that delays the build?
6:08
Alex
It could become one. That's why the scope matters. Stanford law professor Barbara van Schewick argues the state should challenge the condition in court before accepting it.
6:18
Jordan
And what does Washington say the condition is for?
6:22
Alex
Keeping state requirements from making the funded projects too costly or difficult to build.
6:28
Jordan
That explanation makes sense for rules that make a particular project impossible. But this article says the protection for providers reaches much further.
6:38
Alex
Yes. For example, rules stopping a provider from slowing the websites you choose. The terms also cover price regulation, and reach the funded provider's affiliates, meaning related companies.
6:50
Jordan
Even customers whose connection never received a dollar from this program?
6:55
Alex
I'm on page twenty-three of the federal terms. It expressly includes funded and non-funded locations. The state would also put that promise into each provider's contract.
7:07
Jordan
So if California accepts, existing customers could lose protections as part of paying to connect new ones.
7:15
Alex
Yes. The analysis puts the possible duration at fourteen years: four for construction, then ten more while federal funding conditions still apply to the project.
7:26
Jordan
Fourteen years is a long time to promise you won't enforce a rule. Though, wait, California hasn't made that promise yet?
7:34
Alex
We haven't verified acceptance. Today's state commission vote concerns revisions to the plan for building the connections. That's a separate step from accepting these conditions. The analysis says the acceptance decision rests with the governor.
7:47
Jordan
Then the people waiting for broadband deserve both answers. When do we get connected? And which protections does the state surrender to get the funds?
7:56
Alex
Would you accept a restriction limited to the actual funded projects?
8:01
Jordan
I'd still read it. But I'd understand why those projects were in the deal. Extending it to those providers' service across the state is a much larger concession.
8:11
Alex
And it should be argued as one, before the contracts are signed.
8:16
Jordan
An appeals court has rejected one copyright claim against GitHub and its AI coding assistant, Copilot. Programmers had argued that code produced without their copyright notices broke a law against removing that information.
8:28
Alex
A specific claim about missing notices. Those notices identify ownership or the terms for using the code.
8:36
Jordan
If a tool learned from code with conditions attached, and the answer has no conditions, I can see why someone would object.
8:44
Alex
So can I. But the court says this complaint doesn't establish the act of removal that this particular law requires. Creating new output without a notice isn't automatically the same act as stripping one off an existing copy.
8:58
Jordan
The digital-rights group EFF calls it a victory against an expansive copyright claim. Does that mean developers can now use whatever Copilot gives them?
9:08
Alex
No. That jumps from one failed claim to permission the court didn't grant.
9:13
Jordan
I was about to say the code is cleared. It isn't.
9:17
Alex
Correct. Claims that GitHub broke the code's license agreements remain. And the court did not settle every question about using code to train AI.
9:26
Jordan
I'm reading the court's final page. It says it expresses no view on whether similarity could support a copyright infringement claim. That's the claim that the work itself was unlawfully copied.
9:37
Alex
Exactly. A court can reject this missing-notice theory while leaving other ways to challenge copying open.
9:44
Jordan
So the distinction matters even if the output looks the same to the person using it.
9:50
Alex
It matters to which legal duty was broken and what must be proved. Otherwise every copyright dispute could become this separate notice-removal claim too.
10:01
Jordan
That's a reasonable limit. I still don't want a sales pitch turning it into "the courts approved our training data."
10:09
Alex
That would be quite a large addition to eighteen pages.
10:14
Jordan
For the developer, the practical question stays fairly ordinary. Do you know what you're shipping, and what conditions apply to it?
10:23
Alex
Yes. Code shared openly can still have rules, such as keeping the author's notice when you reuse it. This ruling narrows one legal route. It doesn't do that checking for you.
10:34
Jordan
A shorter update from the messaging app Signal. Its Android test release now offers new accounts without a phone number. In the US, the one-time charge is three dollars through Google Play. Signal says the fee helps stop people creating masses of spam accounts.
10:49
Alex
Signal says it keeps the payment unlinked from the new account. That protects a specific connection between your identity and your messages. Google still handles the payment.
10:59
Jordan
The release post gives you an Account ID and an Account Key, like a username and password. So where does a forgotten-password email go?
11:08
Alex
It doesn't. Lose either credential and there's no recovery. Signal urges you to save them in a password manager.
11:15
Jordan
I like losing the phone-number requirement. I don't want someone replacing their phone, then finding they never saved the details needed to sign in again.
11:24
Alex
That's the part the sign-up flow has to make unmistakable. And this is an Android beta for new accounts. Existing accounts can't simply remove their phone number yet.
11:34
Jordan
Useful progress. Save the credentials before you start relying on it.
11:39
Alex
That's our audit for today. Find us wherever you get your podcasts. Chief Skeptic Officer, every day at seven A.M. New York time.
11:48
Jordan
Tell us what you're skeptical about. Drop it in the comments. The angle you can't stop chewing on.
11:54
Alex
Stay curious. Stay skeptical.
11:58
Jordan
Doubt both.