A finance employee in Hong Kong suspected the email was a fraud. So he did what five centuries of good advice told him to do: he verified. He joined a video call and looked his colleagues in the face. The faces were right. The voices were right. Fifteen transfers later, twenty-five and a half million dollars were gone, and every person on that call except him had been synthetic.
Listen on YouTube or in any podcast app. The full transcript follows, in chapters.
Intro 0:00
The Pistomechanics podcast. This is not the show you've been waiting for. This is the programming already running you. Together, we built this clumsy civilization belief by belief. Now we take the reins, working with the sublime machine nobody taught you to drive your own mind. Welcome to the Pistomechanics Podcast. It has never been easier to lie. A voice, a face, a photograph, any of it can be made now by anyone. And because everyone knows it, something stranger is happening. Even the truth gets doubted. So how on earth do we protect ourselves? And I don't mean the government protecting us. I mean us protecting ourselves.
Welcome to episode four of the Pistomechanics Podcast. Today, we are looking through a stack of historical records, cybersecurity analyses, and media scholarship to try and answer one central question. Yes, we want to understand exactly how civilization builds beliefs when our oldest defenses against deception, when they just no longer work. Right. Specifically, we're examining what happens when the very act of checking the evidence, you know, doing your due diligence, actually becomes the trap itself.
We are. Because the tools that you rely on every day to navigate reality are fundamentally shifting.
A man who did everything right 1:42
And to see how that shift operates in practice, we really need to begin in January 2024 with a finance employee working in the Hong Kong office of Arup. Okay, Arup, that's. That's the major British engineering firm, right? It is. They're the firm that worked on the Sydney Opera House and the Bird's Nest Stadium in Beijing. Very established. So this employee received an email, and it appeared to come from the company's chief financial officer in London. The message described a confidential transaction, and it essentially asked for the employee's discretion in handling it.
Let me. Let me just stop you right there for a second, because if you are listening to this on your commute or at work, you're probably a busy person trying to make sound decisions all day, and it is incredibly easy to hear the setup of that story and just assume the person on the receiving end was careless. Yes, people often jump to that conclusion. But he wasn't careless at all. I mean, his instincts worked perfectly. He read the email, and he immediately suspected a phishing scam, which is exactly the correct rational response to an unexpected message asking for money. He did exactly what five centuries of literacy and probably a dozen modern corporate security trainings taught him to do. He verified he did.
He completely refused to act on the email alone. Instead, he joined a video conference call to check the request. Right. He looked for proof. Exactly. And on that video call, he saw the chief Financial Officer. He also saw several other colleagues he. Recognized from the firm just on the screen with him? Yes. Their faces matched the people he knew, their voices matched, and they discussed the confidential transaction with him in real time on the screen. And because the check had passed, his doubts dissolved.
I mean, of course they did. He trusted his eyes and his ears. He checked the evidence, and the evidence told him the request was real. It installed a completely false belief. Right. So following the instructions he received during that video call, he began moving the funds. Over the course of the Evening, he made 15 separate transfers to five different Hong Kong bank accounts. Fifteen transfers? Yes. The total transferred was 200 million Hong Kong dollars. That is about 25 and a half million US dollars.
Wow. The fraud only surfaced later when he eventually followed up with Arup's head office in London. And I'm guessing London had no idea what he was talking about? None. The head office had authorized no transaction. They had held no meeting. They knew of no video call. The Hong Kong police later determined that every single participant on that video call, apart from the victim himself, had been synthetic. Every single one. I just want to make sure the listener really processes the Mechanics of that. 15 Transfers. 25 And a half million dollars. Every participant on the screen, except the man moving the money was an absolute fabrication.
They were generated from publicly available video and audio of those specific executives. The attackers used earnings calls, conference panels. They just used the ordinary raw material that exists in the public domain for almost every senior corporate figure in the world today. The weight of that situation is just. It's difficult to process. I mean, think about what it means to be that employee. Here is a man whose verification was his downfall. At no point that night did the internal question, is this real? Help him? Because for roughly 500 years, civilization has had two cures for deception. And they worked. Look closer and gather more sources. What happens to a civilization when those two moves become the delivery route?
Five centuries of looking closer 5:08
Well, to answer that, we really have to look at where those two legacy cures actually came from in the first place. Okay, let's look at the history. Right. Because the instruction to look closer or to gather more sources was not a naive reaction. Those moves were engineered immune responses. When the printing press arrived in Europe, it didn't just bring the spread of knowledge. It brought a flood of forgery, fabricated pamphlets, printed libel. And the response to that flood, which built slowly over generations, was an immune system.
Right. Society adapted. Exactly. We developed publishers marks to track origin. We developed the habit of cross reference. The expectation grew that a claim could be checked against another printed copy or another edition to find the truth. So we built systems to manage the new technology. And I mean, we saw that exact same pattern repeat later. Right. When the technology changed again. We did. In the late 19th century, the yellow press turned newspaper circulation wars into outright invention wars. I mean, publishers printed whatever would sell papers. The engineered response to that environment was the creation of professional norms in journalism,.
Like checking facts and citing sources. Yes. We saw the rise of mandatory sourcing, the printing of corrections, the strict separation of news from opinion. And the foundational premise underneath all of those adaptations was that deception is exposed by more information. Right. A forged document is undone by an authentic one. The remedy for bad speech was more speech. Which means the baseline assumption, the one you and I have inherited, is that if someone introduces a new technology that can deceive people, the public eventually develops a method to spot the seam. We assume there will be a brief period of confusion and then we'll learn to look closer at the paper stock, or we'll gather more sources to sort of outvote the lie. We assume the truth will reassert itself.
We do. And we can observe exactly how that expectation was tested with the arrival of photography. Oh, this is the Boston story, right? Yes. In the 1860s, a Boston engraver named William Mumler began selling what he called spirit photographs. These were portraits in which a deceased relative appeared faintly in the background, standing behind the living sitter. You really have to picture the historical context here. The 1860s is the American Civil War era. The country is absolutely saturated in grief. And suddenly there's a man wielding this relatively new technology, a camera, which people understand to be a machine that perfectly captures reality and it appears to be capturing the dead.
I am assuming he built a rather serious clientele. Very serious. I mean, the desire to believe was high. Mary Todd Lincoln sat for him. She received a picture of herself with the late president's hands resting on her shoulders. And eventually the authorities intervened. In 1869, the state of New York tried Mumler for fraud, which is exactly. The natural question anyone listening would ask. Right. If a new technology arrives and people start using it to deceive the public, surely the step in to figure out how to spot a fake, you put technical experts on the stand, you examine the physical evidence under a microscope, and you establish the objective truth. The prosecution certainly tried to do exactly that. They understood how such pictures could be made using double exposure or pre prepared glass plates. To demonstrate this to the court, they actually brought P.T. Barnum to the stand to testify against Mumler.
Barnum, like the circus promoter? The very same. And to make his point. Barnum had a photographer manufacture a spirit photograph of Barnum himself, complete with a ghost. And he entered that fabricated photograph into evidence. So Barnum is acting as the debunker. He goes to court and proves the technology can be manipulated. He shows them the exact mechanism of the trick. He proved it could be done. But the case fell apart precisely on that distinction. Proving that a photograph could be faked proved nothing about whether these specific plates, Mumler's actual plates, were faked. The court examined the gl. The experts examined the content. But no expert could establish fraud from the content of the plates themselves. Mumler was not convicted.
Wait. He walked away? He did. The judge stated aloud in the courtroom that he was morally convinced there was deception. But he acquitted Mumler because the case simply could not be made from the physical evidence provided. Let's. Let's stop and digest that image for a moment. You have an 1869 courtroom. They are dealing with a technology that is barely one generation old, and they are already failing to use the content itself to prove reality. The experts are staring at the glass plate, trying to find the seam, and the seam isn't enough to secure a conviction. So even back then, the strategy of looking closer at the medium did not resolve the truth of the medium.
In 1869, with the technology one generation old, a courtroom already could not decide from the content alone what was real. What has changed since is not the question. It is the price of asking it and the number of people who can afford to. Okay, but if we're talking about new media fooling the public, there is one historical event that people always point to. Whenever you discuss technology hijacking beliefs, someone brings up the specific story to prove that human beings have always been gullible. When a new format arrives.
A panic that never happened 10:15
Yes, they bring up the radio broadcast of October 30, 1938. Orson Welles, dramatization of the War of the Worlds. Right. The production was formatted partly as breaking news bulletins, inter interrupting a normal music program. And the legend states that a nation panicked. Families reportedly fled their homes, roads were jammed, and a population was simply unable to tell theater from news. That is the story. I mean, that is what most of us were taught in school. We were taught that the public heard the authoritative tone of a news anchor. And because radio was relatively new and trusted, they abandoned all reason and ran into the streets. They absorbed, or rather the broadcast successfully installed a false belief instantly.
The historical scholarship says otherwise. Really? Yes. Media historians, specifically Jefferson Pooley and Michael Socolow, have examined the records and Shown that the panic essentially did not happen. Right. It didn't happen at all. The audience for that particular broadcast was actually modest. The overwhelming majority of the people who did listen understood perfectly well that it was a play. Later, researchers who chased down the era's rumors of shock deaths or reports of hospitals treating terrified listeners, they found none of them verified.
I. I need to push back on that because that contradicts a very established cultural memory. If the panic didn't happen, why do we all know it happened? Where did the numbers come from? Because I remember seeing estimates of a million people frightened in textbooks. The mass hysteria was manufactured after the fact that by newspapers in 1938, the print press was facing a severe economic threat. They were losing advertising revenue to radio, which was free in the living room and faster at delivering breaking news.
Ah, so there was a motive. A very clear financial motive. The morning after the Wells broadcast, newspapers from coast to coast ran the panic as a fact. They framed radio as a dangerous, uncontrollable new medium that had terrorized the nation and could not be trusted by advertisers or the public. They ran an operation in the register of alarm. They used their established position as the trusted information channel to install a belief about their competitor. Exactly. And two years later, that newspaper narrative was laundered into science. A Princeton researcher named Hadley Cantril published a study on the broadcast. He gathered letters, newspaper clippings, a mail survey of roughly a thousand people, and about 150 interviews. But he gathered this data long after the newspapers had already taught the country that a mass panic had occurred.
So by the time he is conducting his interviews, the well is already poisoned. The people he is talking to already know they are supposed to view this event as a national hysteria. It was. Furthermore, there was a mechanical flaw in his methodology. Which was Cantril counted as panicked anyone who reported having been frightened or disturbed or even simply excited by the broadcast. Yes, if you use that standard for measurement. Every effective thriller ever aired on television has caused a mass panic. But because of his institutional affiliation, he remains the only academically credentialed source ever to claim the panic was large.
Because he had the credentials, his flawed study entered the textbooks. And because it entered the textbooks, it entered every classroom. We have to look at the timeline of that Correction. It took 75 years for the historical scholarship to finally set the record straight. 75 Years for society to correct one rumor about one broadcast. That is the actual speed the old immune system ran at. Which means every time a new medium arrives, it triggers the incumbent medium to declare an epistemic apocalypse. The old format warns that the new format will destroy our ability to know the truth. We have to be very careful sitting here discussing the engineering of belief not to fall into the same pattern.
Right. We are examining synthetic media, but we cannot afford to fall into the register of alarm. That is exactly why we are relying strictly on the documented numbers in this hour. Even when those numbers cut against the alarmist narrative, we have to keep our heads. Because if you actually look at the mechanics of 1938, the lesson isn't about human gullibility to a new technology. Almost no one was fooled by the broadcast. The story that fooled people was the one about the broadcast. So if history shows us that we eventually adapt to new media and that the initial alarm is often manufactured, the real question is how we are adapting. Now. Let's go back to that first legacy cure. We discussed the instinct to simply examine the video or the audio or the document with your own eyes until the forgery shows its seam. What is actually happening to the strategy of looking closer?
Today, the published detection literature gives us a very clear empirical answer on that.
Detection science runs at chance 14:56
Researchers have conducted a Meta analysis of 56 different studies on human detection of synthetic media. That analysis places average human deepfake detection at about 55%. Okay, let me just. Let me make sure we calibrate that number correctly. For the listener, 55% is above chance, and saying so is the brand. We are not claiming that human beings are entirely blind. 55% Means that, on average, humans are detecting fakes at a rate slightly better than a coin flip. That is correct. But it is vital to understand that 55% is an average across various qualities of media. For still images of synthetic faces, multiple studies place human performance squarely at chance. And for video, the results vary dramatically with the quality of the generation.
Meaning the better the fake, the worse we do. Exactly. One study sorted deepfake videos by difficulty. When participants looked at the easy ones, the ones with obvious visual artifacts, they detected them at about 71%. But on the most difficult set of videos, human detection fell to 25%. 25%, That is below chance. That means people were looking at the best fakes, studying them closely and confidently, calling them real. But surely that is just an untrained baseline. I mean, if you train people, if you sit them down and teach them what to look for, like the way the lighting fails to hit the cheekbone correctly, or an unnatural skin texture, or the way the hair blends poorly into the background, doesn't that training improve the detection Rate.
The literature tests that hypothesis as well. In one specific study of more than 450 people, researchers tried to train the participants. Teaching the standard tells changed neither accuracy nor confidence. Not at all. Not at all. And that finding recurs across the literature. The most consistent finding in deepfake detection studies is overconfidence. People firmly believe they can tell the difference. Let's work that image. Think of it as a certainty light in your brain. When you look closely at something, your brain processes the details, and the certainty light turns green. You feel sure of your judgment. The problem is that the belief that you can tell a fake from reality is totally unrelated to your actual ability to tell. Your brain rewards you with a feeling of certainty just for having scrutinized the image. Which means that looking harder at a flawless fake doesn't expose the fake. It just gives you more time to study the details, rationalize what you're seeing, and convince yourself it is authentic.
The seam is gone at human resolution. Looking harder at a good fake does not expose it. It deepens conviction. If looking closely fails and the certainty light in our brain is lying to us, the rational person immediately turns to the second legacy cure. They look for corroboration. You don't just trust the document in front of you. You go out and find a second witness. You gather more sources. What happens to corroboration when the engineering of belief scales up? Well, corroboration worked for five centuries because it was a reliable proxy for something real. Independent testimony used to be expensive. Producing a second witness or publishing a second newspaper required money, logistics, and human time.
Right. It took effort. Yes. Therefore, agreement among multiple sources genuinely indicated that an event had occurred in the physical world. But that heuristic dies the moment testimony becomes free. And to show you exactly how free it has become, we have two highly documented dollar specific exhibits. Okay, let's look at the first one.
One dollar, twenty minutes 18:21
The first occurred in January 2024, two days before the New Hampshire presidential primary. Thousands of Democratic voters received a robocall. The call was in the voice of President Joe Biden. It included his familiar catchphrase, what a bunch of malarkey. And it urged the listeners not to vote in the upcoming primary, but to save their vote for the November general election. The voice on the phone was synthetic. And we aren't just guessing about where that audio came from. We know exactly how it was engineered and exactly what it cost.
We do. The audio was created by Paul Carpenter, a New Orleans street magician. He was hired over the payment app Venmo for $150 by a political consultant named Steve Kramer. $150. Yes. Carpenter later demonstrated the exact process he used for NBC News. Generating the audio took him under 20 minutes, and it required about $1 of computing power. Just let that sit for a moment. $150 Over Venmo. 20 Minutes of time and $1 of computing power. The Federal Communications Commission eventually fined Kramer $6 million for the operation. At his criminal trial, where he was acquitted of the state charges, Kramer testified that he commissioned the call as a public warning to demonstrate how easy this technology had become. Now, we make no claims here about whether the call actually affected the vote totals in New Hampshire. The exhibit is the arithmetic itself, impersonating the sitting President of the United States at precise electoral timing was produced by a street magician for the price of a dinner.
If audio is that cheap, the listener might say, fine. I won't trust a single phone call. I will look for published articles. I will look for multiple news sites reporting the same facts. What is your second exhibit regarding gathering more sources? It concerns the scale of independent sources.
Three thousand ghost newsrooms 20:07
NewsGuard is an organization that rates news reliability and tracks the spread of misinformation. They began tracking websites that publish substantially. AI generated news with minimal human oversight. In May 2023, they identified 49 such sites. Okay, 49. Three years later, that number swelled to over 3,700 across 16 different languages. 3,700 Entire websites producing automated news and. Growing by 3 to 500 new site a month. They carry ordinary, trustworthy sounding names like regional dailies or local bulletins. Given the economic collapse of genuine local journalism, NewsGuard noted that the odds of a newly encountered website claiming to cover local news being synthetic are now better than even the corroborating source you find when you search the Internet to check. A story has an even chance of being manufactured.
So the entire information ecosystem is filling up with synthetic sources, which exist merely to verify other synthetic sources. It is a hall of mirrors, and. A 2024 paper published in the journal Nature showed exactly what happens to that hall of mirrors. The researchers demonstrated that generative models trained on the output of other generative models mathematically degrade. The models need human variants to function without it. They collapse into a narrow band of probable text. The ecosystem begins eating its own product.
So corroboration is compromised at the level of text and at the level of recorded audio. But what about live synchronous communication? The sort of thing where you expect to see someone's mannerisms, where you can ask them a question and watch them answer the irup employee in Hong Kong fell for a live call. But surely that required a serious budget to pull off. We have a documented case showing that live environments are also compromised, and cheaply. In May 2024, someone built a RUTSAPP account using a public photograph of Mark Reed. He is the chief executive of wpp, which is the largest advertising group in the world. The attacker set up a Microsoft Teams meeting that appeared to include him and another senior executive.
How exactly did they execute a live meeting without the real executive? They ran a cloned voiceover footage taken from YouTube. During the meeting, the attackers typed as Red himself in the meeting chat, remaining off camera while the cloned audio played over the video feed. That's bold. It was. The target was an agency leader within the WPP group who was asked to set up a new business entity. It was the opening move of a request for money and corporate details. In this specific instance, the installation of belief did not work, and Red emailed his leadership afterwards to warn them. But notice the mechanics. None of that operation required access to anything private. They used a photograph anyone could download and footage anyone could watch.
Handed the telephone 22:52
Think about the oldest trick in the repertoire of the con man. The mark grows suspicious of the deal. The con man doesn't argue. He welcomes the suspicion. He says, you're right to be careful. Don't make my word for it. Call the bank yourself. And he hands you the telephone. But the person on the other end of the line is the con man's accomplice. The verification is supplied by the attacker,. Which maps concisely back to the man in Hong Kong at the start of our hour. The video call he joined did not exist despite his suspicion it existed for it.
He asked, in effect, to speak to the bank, and the attackers were ready for exactly that request. He didn't fail to verify. The verification is what got him. Now, if a person reaches this point in the understanding of the architecture, they often look for an escape hatch. If I can't look closer and I can't check sources, I will just be generally more careful. I will simply be more skeptical about everything I see.
Three comforts, examined 23:45
There are three comforts people turn to when they realize the legacy defenses are failing. The first comfort is simply observing that the apocalypse didn't happen. And we concede that completely. The year 2024 was widely predicted by pundits to be the year deepfakes broke democracy, given the sheer number of global elections on the calendar. But if you look at the data, less than 1% of fact checked misinformation in the 2024 election cycles was AI generated. The predicted apocalypse simply did not arrive in the form people warned about.
Even the most famous counter case falls apart. Upon inspection in September 2023, two days before Slovakia's parliamentary election, a fabricated audio recording spread online. It purported to capture a pro European candidate discussing vote rigging. His side lost the election and the event was reported globally as the first national election swung by a deepfake. But the data doesn't actually support that conclusion, right? It does not. Careful analysis points out that the pre election polls were likely off for independent well understood reasons regarding voter turnout and traditional campaign dynam. We explicitly decline the claim that the Slovakia election was swung by a deep fake.
But conceding the non apocalypse offers no actual comfort to the listener. Because the damage doesn't require a fake to succeed in swinging a national election. The damage happens at the margins in the daily navigation of truth. Which brings us to the listener's fallback position. The second comfort. I will just be more careful. That is exactly where the trap closes. In 2019, legal scholars Robert Chesney and Danielle Citron identified a concept they called the liar's dividend. In a world where everyone knows perfect fakes are possible, a person caught by genuine incriminating evidence gains an escape route. They can simply declare the true evidence to be fake. The defense arms the attacker.
So raising public awareness of fakes actually reduces belief in accurate information. But is there real world proof of this dividend being spent? Are people actually doing this? Yes. It has already entered the courtroom. In a wrongful death lawsuit involving Tesla's autopilot system, the company's lawyers argued that recorded public statements made by Elon Musk could not be taken as authentic evidence. They argued that because Musk is famous, he is a frequent target for deepfakes, and therefore the recordings might not be real.
They attempted to introduce doubt about real, historically recorded statements. Judge Yvette Pennypacker rejected the argument. She wrote that if the court accepted this theory, someone in the position of power can say whatever they like and then hide behind the potential of DeepFace to avoid taking ownership of what they actually said. She called the argument deeply troubling. And we saw the exact same move from two defendants involved in the January 6 riot who argued in court that video footage of them at the Capitol might be AI generated.
And politicians internationally are using the dividend too, aren't they? A politician in India dismissed an audio recording of himself criticizing his own party as synthetic, even though subsequent forensic analysis found it to be authentic. A candidate in Turkey said The same of a compromising tape release before an election. These claims largely have not succeeded in working courtrooms yet. But the sentence is now available for free to every public figure caught by genuine evidence. Think of evidence like currency. Counterfeiting doesn't just fool the person holding the fake hundred dollar bill. If counterfeiting happens at scale, it destroys the currency itself. People stop accepting the paper money altogether. The deepfake withdraws the credibility of true evidence. The goal isn't just to make you believe a lie. It's to create a world of deniable truths.
There is a historical parallel for this erasure of truth. The historian David King collected the before and after pairs of photographs from Stalin's Soviet Union. Oh, I've seen some of these, yes. There is a famous photograph from 1937 of Stalin strolling beside the Moscow Volga Canal. At his side is Nikolay Yezhov, the head of the secret police. After Yezhov fell out of favor and was executed in 1940, the state retouchers removed him from the photograph. They meticulously filled the space where he had been standing with canal water and the edge of the embankment.
There was an entire industry of erasure. They weren't just altering one image, they were altering reality retroactively. The goal of that regime was not necessarily to make the public believe that one specific picture was the absolute unvarnished truth. The goal was to teach the public that the historical record answers to power. Because once the record answers to power, checking the record is no longer a way out of allegiance, it becomes a form of allegiance. And this creates a void for you and me, because a human mind cannot run on. I don't know. You can't navigate a world or even choose what to do with your day in a permanent state of suspended judgment. So when verification dies, what happens to belief? Belief reverts to medieval settlement. You believe based on allegiance, by lord, by church, by guild, by tribe. You look at a piece of media and you don't ask, is this true? You ask, does someone like me believe this?
When evidence dies, belief doesn't die. It changes masters.
The platforms and the law 28:48
Which brings us to the final comfort people lean on when they hear all of this. Won't the platforms or the law fix this? Surely there are technological and legislative guardrails being built by smart people to stop the installation of false beliefs. Let us look at the law first. We return to the Slovakia case, not as a story about a swung election, but as a mechanical failure of the law. The fabricated audio dropped during A legally mandated 48 hour pre election moratorium. This is a silence period where media outlets and politicians must refrain from making campaign statements.
It is a law built for the legacy media era, designed to protect the final hours of an election from last minute mudslinging. And it became the exact attack window the fake could straight online, while the institutions built to debunk it were legally muted and the platforms failed. In a similarly backward facing way, the leading platforms manipulated media policy at the time the audio dropped covered video, but it did not cover audio. The fabrication slipped through a loophole in a rule written for the previous generation of fakes.
But what about technological solutions like cryptographic signing? I hear constant discussions about embedding a permanent, unforgeable record into the file itself, proving when and how a photo was taken. The effort is real. It is called C2PA. Leica shipped a camera in 2023 that signs photographs natively. At the hardware level, the Samsung Galaxy S25 and the Google Pixel 10 sign images natively. But look at what happens in ordinary use. Most platforms like WhatsApp or Facebook strip embedded metadata when they process an upload.
Why do they do that? They compress the file to save server space. And in doing so, they quietly discard the cryptographic seal. And even if the platform preserves the seal, a user looking at the image on their phone can just take a screenshot. The whole apparatus of cryptographic verification is defeated by the screenshot button. You produce a new file with no connection to the original record. Furthermore, trying to build automated detectors is an arms race where the detector trains the generator. In the research literature, a generator can be trained directly against a published detector. Every detector that ships hands the next fake a gradient to climb.
So if the law is too slow and the technology defeats itself, what actually holds?
Ferrari: the fake that lost 31:03
In July 2024, an executive at Ferrari began receiving WhatsApp messages from someone presenting as Benedetto Vigna, the company's chief executive. Then came a call. The voice on the phone was Vigna, perfectly matched down to the specific southern Italian accent. The pretext was a confidential acquisition wrapped in the authority of the CEO and the urgency of a closing deal. It required an immediate currency hedge. Why did this executive survive the attack when the Arup employee in Hong Kong did not? Did he have better audio detection software installed on his phone?
He did not. He thought he heard something faintly wrong in the intonations. But he did not interrogate the audio. He did not lean in and listen harder, which is what failed the man in Hong Kong. Instead, he asked the voice to name a book that Vigna had Recommended to him a few days earlier. The book was called Decalogue of Complexity,. And the fake couldn't answer. The call ended immediately. Let's work that image. Think of polymorphic malware. In the early days of computing, antivirus software used to work by looking at the content of a file. It looked for specific signatures, lines of bad code. But then viruses became polymorphic. They rewrote their own code as they spread, so no two copies looked alike. Security survived by moving to behavioral detection. They stopped looking at the file itself and started watching what the file tried to do. What permissions does it request? What is it trying to access? The Ferrari executive relied on behavioral detection. He relied on a piece of shared history living outside the channel.
A lie can wear any face. He cannot skip the door.
Watching the door 32:34
And that is the turn. That is the realization we have been building toward trying to answer the question, is, is this real? By examining the message itself is a lost war. The pixels, the audio frequencies, the corroborating sites, all of that is the content layer. And the content layer has fallen. But every message still must do something that cannot be automated. It must enter a human mind. It must install a belief. Which means you and I have to stop interrogating the face and start watching the door. This unveils the discipline for which our show is named, pistomechanics, the study of the engineering of belief.
When you apply pistomechanics, you replace the unanswerable question, is this real? With three behavioral questions. First, what is this trying to install in me? Second, through which door is it coming? Is it arriving through emotion, through authority, through repetition, through urgency, or through belonging? And third, why is it arriving now? Wait, let's try those three questions on our discussion right now. Let's look at this exact hour of audio. What is this hour trying to install in the listener? And through which door is it coming?
It is a fair test. We are definitely using authority. We present data, we cite judges and psychological studies. We use repetition. We are actively engineering a belief about the failure of the old media environment. We are structuring the conversation to make the listener accept that the old defenses are dead. Which is why observing these doors is the very first move a Pistomechanics student makes. You stop interrogating the pixels and you interrogate the mechanics of the delivery. Now, is this real? But what is it doing? The successor immune system is a literacy, not a technology. It is a fluency in the mechanics of installation. The human art. The first three hours of this series were not just diagnosis of the problem. They were basic training.
Anyone who sat through all four hours is by now a pistomechanics student. But there is an honest limit we have to state literacy is not invulnerability. Knowing how the doors work does not mean the doors disappear. A trained mind still has doors. The only difference is that a threshold is crossed in the light rather than the dark. Underneath every belief there is one that all the others pass through first. People will lie to themselves to protect it and change a whole life in an afternoon to keep it. It was installed before anyone asked their permission. The Ferrari fake had everything except that one.
Next week we open it up. What it is made of and who put it there. Because the doors are few and every one of them can be learned. Next week we go one layer deeper. This was the Pistomechanics podcast. What can be studied can be learned.