Episodes

  • Won't Fix Episode 13: With Alan Chapell of The Monopoly Report
    Aug 18 2026

    Rob Leathern speaks to privacy attorney and host of The Monopoly Report Podcast, Alan Chapell, about residential proxies, privacy and podcasting. Hear how free smart TV apps might be sharing your home IP address with strangers, and see just how broken online consent forms really are.

    Alan explains why current data broker laws miss these proxy networks entirely and how coming age verification rules could rewrite the open web.

    In This Episode:

    • Free smart TV apps quietly bundle code that rents your home internet connection to strangers, creating vulnerabilities that look suspiciously like security exploits.
    • Online consent breaks down with bandwidth sharing, when endless disclaimers mean nothing as consumers may have no easy way to turn the access off.
    • State data broker laws miss the mark by hunting legacy data vendors while ignoring massive proxy networks, credit card companies, and telecom giants.
    • AI companies pushing to scrape the entire web without limits could accidentally hand ad verification firms the ultimate legal shield against platform lawsuits.
    • Strict age check laws could spark an arms race with clever teenagers that could end with governments requiring real ID just to browse the web.

    Chapter Timestamps:

    00:00 Introduction

    5:32 Residential Proxies: The "Ethically Sourced IP" Question and the LG TV Case

    9:48 Legitimate Uses vs. Harmful Behaviors of Residential Proxy Networks

    12:50 Data Broker Laws, Enforcement Gaps, and KYC

    14:40 Consent Problems: Revocation, Age Verification, and the LG TV Example

    16:56 Adware Parallels: History, Opt-Outs, and Financial Incentives

    23:31 Age Verification: A Looming Internet-Wide Challenge

    25:39 Scraping, Antitrust, and AI Companies

    29:40 Podcast Strategy, Guest Selection, and Speaking Recklessly

    41:53 Regulators, Historical Knowledge Gaps, and Industry Dynamics

    Resources & Links:

    Rob Leathern (https://www.linkedin.com/in/leathern/)

    Alan Chapell (https://www.linkedin.com/in/alan-chapell-90711b/)

    The Monopoly Report (https://monopoly-report.com/)

    The Chapell Regulatory Insider (https://chapellreport.substack.com/)

    Show More Show Less
    47 mins
  • Won't Fix Episode 12: With Jeff Allen Co-founder & CRO of the Integrity Institute
    Aug 7 2026

    Jeff Allen is the Co-founder and Chief Research Officer of the Integrity Institute, started in 2021. A physicist and astronomer by training, moved into data science in 2013, and has since worked all three sides of the platform-publisher relationship: for publishers chasing platform traffic, for the platforms themselves, and for political organizations navigating both.

    At Facebook he worked on systemic problems in the Facebook and Instagram public content ecosystems.

    Along with Spencer Gurley, Jeff Allen and the Institute recently published the July 2026 report which Ofcom commissioned — Fraudulent Advertising and Account Integrity: Expert Insights on Best Practice, which fed directly into Ofcom's draft Fraudulent Advertising Codes (published 10 July, consultation closes 2 October).

    In This Episode:

    • Short-term ad revenue pits platform profits against user safety, making external regulation necessary to preserve long-term industry trust.
    • Regulators need technical guidance from experts independent of Big Tech funding to build safety policies that can survive court challenges.
    • Bad actors are using generative AI to quickly spin up realistic, multi-step scam sites that slip right past standard automated filters.
    • Effective oversight requires a two-step system: platform self-reporting backed by independent audits from verified researchers.
    • Scammers actively reverse engineer enforcement limits, making off-site damage and delayed user reporting persistent challenges.

    Chapter Timestamps:

    00:00 Introduction to Jeff Allen and the Integrity Institute

    1:46 The Integrity Institute's Mission and Approach

    3:29 The Scale of Online Scams and Fraudulent Advertising

    4:54 Regulatory Landscape and Ofcom's Role

    6:15 Development of the Ofcom Report

    10:33 Congressional Understanding and Regulatory Progress

    12:04 Media Coverage Challenges in Advertising

    15:02 Incentive Alignment and Regulatory Approach

    18:52 Data Access Challenges and Solutions

    21:40 Internal vs External Research Challenges

    24:07 The Sales Challenge in Data Science

    28:50 Specific Transparency Metrics and Market Impact

    32:46 Guidelines Disclosure and Adversarial Dynamics

    35:15 The "Three Slide Rule" and Off-Platform Harm

    40:17 Evolution of Fraudulent Content Creation

    43:23 Researcher Access and Data Requests

    45:25 Educational Needs and Trust and Safety Curriculum

    Resources & Links:

    Integrity Institute (https://www.integrityinstitute.org/)

    Integrity Institute Report (https://www.integrityinstitute.org/research/response-to-ofcoms-request-for-research-on-fraudulent-advertising-and-account-integrity)

    Rob's Notes (https://robleathern.substack.com/p/robs-notes-47-on-ofcoms-fraudulent)

    Jeff Allen (https://www.linkedin.com/in/jeff-allen-scientist/)

    Ofcom (https://www.ofcom.org.uk/)

    Rob Leathern (https://www.linkedin.com/in/leathern/)

    Show More Show Less
    48 mins
  • Won't Fix Episode 11: With Independent Researcher & Consultant Ben Edelman
    Jul 24 2026

    Ben Edelman has spent two decades catching online fraud that hides in plain sight — combining software engineering, law, and economics to prove misconduct empirically rather than take companies at their word. In this conversation we get into the Phia shopping-plugin scandal, how it relates to Honey and Paypal that he covered after Megalag broke the issue on YouTube, the mechanics of affiliate fraud, and his recent investigation into AppLovin's apparent app install deals with mobile carriers.

    In This Episode:

    • How Ben got into fraud investigation, and what keeps him motivated
    • Phia's "cookie stuffing": how a browser extension can claim affiliate credit for sales it didn't drive
    • Whether Phia's "December bug" oopsy explanation holds up, and Phia's earlier 2025 privacy “mistake”
    • The Honey/Paypal parallels, typosquatting and the broader toolkit of affiliate-fraud techniques
    • MegaLag vs. the mainstream media: how independent investigators break stories now
    • AppLovin's nonconsensual install investigation he wants state AGs to look at
    • What meaningful accountability looks like, and his advice to founders building in this space

    Links & Resources:

    • Ben Edelman's AppLovin investigation: https://www.benedelman.org/applovin-nonconsensual-installs/
    • Ben Edelman's site (full archive of his research): https://www.benedelman.org
    • Ben's list of "Investors supporting spyware": https://www.benedelman.org/spyware/investors/
    • Edge Shopping Stand-Down Violations: https://www.benedelman.org/edge-shopping-standdown/
    • Phia forced clicks and stand-down violations: https://www.benedelman.org/phia-forced-clicks/
    • Honey stand-down violations and concealment: https://www.benedelman.org/honey-detecting-testers/
    • Adware investors page:https://www.benedelman.org/spyware/investors/
    • "Spontaneous Deregulation: How to Compete with Platforms that Ignore the Rules" (HBR article about intentional rule-breaking as a business strategy): https://www.benedelman.org/publications/hbr-spontaneous-deregulation-apr2016.pdf
    • Rob Leathern (https://www.linkedin.com/in/leathern/)

    Chapter Timestamps:

    00:00 Introduction and Background on Online Fraud Investigation

    1:36 The Origins: Gator Adware and Early Ad Fraud (2001)

    3:10 The Dark Chapter of VC-Funded Adware

    4:54 Transition to Independent Investigation Work

    6:07 FIA Investigation: Two Types of Violations

    7:31 Understanding Forced Clicks Through Analogies

    9:50 Debunking FIA's "Recent Bug" Defense

    12:50 FIA's Previous Screenshot Controversy

    14:18 The Current "Dumb Tech Cycle" and Screenshot Overuse

    16:20 Recurring Patterns: From Gator to Modern Shopping Plugins

    21:11 Startup vs. Public Company Misconduct Patterns

    24:40 PayPal's Due Diligence and Ongoing Modifications

    27:24 Media Resources and Technical Expertise

    30:17 Typo squatting and Google's Role

    31:36 The Ad Tech Attention Gap

    33:34 AppLovin Investigation: Install Helpers and Carrier Partnerships

    34:21 Wall Street Journal's Surprising Rejection

    40:28 Carrier Billing and Historical Context

    44:42 Advice for Founders: The Temptation and Risk of Cheating

    Show More Show Less
    48 mins
  • Won't Fix Episode 10: With Lindsay Kaye & Will Herbig of HUMAN Security
    Jul 17 2026

    On July 7, 2026, HUMAN’s Satori team exposed NewsJunkie, a massive, coordinated connected television (CTV) device-spoofing operation that generated up to two billion invalid bid requests per day, per seller.

    In this episode of Won’t Fix, we go inside the investigation with Lindsay Kaye (VP of Threat Intelligence) and Will Herbig (Senior Director of Media Research) from HUMAN Security to break down how this sophisticated fraud was uncovered.

    We then zoom out and the conversation to talk about the connected TV ecosystem in general and how AI and automation are changing the security threat landscape in general.

    Resources & Links:

    • HUMAN Security Website: https://www.humansecurity.com/
    • The Full NewsJunkie Report: https://www.humansecurity.com/learn/resources/human-disrupts-ctv-device-spoofing-newsjunkie/
    • Lindsay’s Book (Dissecting the Dark Web, No Starch Press): https://nostarch.com/dissecting-the-dark-web
    • Rob Leathern (https://www.linkedin.com/in/leathern/)

    Chapter Timestamps:

    00:00 Introduction

    1:13 Team Backgrounds and Roles at Human Security

    3:31 Understanding the News Junkie Operation Structure

    5:27 Key Anomalies That Exposed the Fraud

    8:32 Scale and Impact of Invalid Traffic

    10:14 Evolution and Persistence of the Operation

    14:15 Residential Proxies and Infrastructure Connections

    20:24 AI-Generated Fake Business Identities

    23:44 Disruption Strategies and Industry Response

    26:48 Systemic Gaps and Supply Chain Compliance Issues

    31:48 Device Attestation and Technical Solutions

    34:41 AI's Impact on the Security Landscape

    41:33 Investigation Methodology and Future Outlook

    Show More Show Less
    48 mins
  • Won't Fix Episode 9: With Juliet Shen, Cofounder & HOP at ROOST
    Jul 7 2026

    Juliet Shen is cofounder and Head of Product at ROOST (Robust Open Online Safety Tools), a nonprofit building open-source trust-and-safety infrastructure for platforms of every size. She has done anti-abuse product work at Google and Grindr, and was the first trust-and-safety product manager at Snap, where she helped launch early cross-platform efforts to combat child exploitation. ROOST's website is https://roost.tools.

    Across her career, Juliet kept running into the same maddening pattern: every trust-and-safety team, at every platform, quietly rebuilding the same rules engines, review queues, and reporting pipelines from scratch, behind closed doors, and at enormous cost. ROOST is a bet that online safety should be shared, open infrastructure rather than proprietary secret sauce, available free to any platform or site that needs it. We talk about that, and a lot more.

    Key Highlights:

    • Every tech company shouldn't have to build their trust and safety tools from scratch behind closed doors. It’s an expensive waste of time when open-source infrastructure could solve the exact same foundational problems for everyone.
    • PMs and engineers need to step up and lead in the trust and safety space. They are the ones who can actually bridge the gap and get policy, operations, engineering, and legal teams talking to each other.
    • AI is great for knocking out the easy, baseline moderation tasks. But when a situation is highly nuanced or something the AI hasn't seen in its training data, you still absolutely need human judgment.
    • As social media breaks apart into decentralized networks, a one-size-fits-all safety system won't work anymore. We need modular tools that let platforms look at who the user is, how they're behaving, and what they're posting as separate pieces of the puzzle.
    • Good moderation is often less about analyzing the post itself and more about knowing exactly who is behind the account or the app. Right now, our lack of solid identity verification is a massive blind spot for digital safety.

    Chapter Timestamps:

    00:00 Introduction

    1:34 Career Journey and the Problem of Redundant Tool Building

    5:30 The Role of Product Managers in Trust and Safety Teams

    7:34 Impact of LLMs on Trust and Safety Operations

    11:27 Focus Areas and Child Safety Priority

    12:55 The ABC Framework and Actor Trust Challenges

    16:54 Community Building and TrustCon Participation

    19:13 Signal Sharing vs Tool Sharing Philosophy

    22:43 Open Source Approach and Scaling Challenges

    23:59 Future Roadmap and Research Partnerships

    28:52 Reviewer Well-being and Mental Health Considerations

    32:00 Centralized vs Decentralized Moderation Models

    37:15 Government Role and Open Source Support

    39:52 Success Metrics and Measurement Challenges

    42:50 Standards, Testing, and Future Directions

    Resources & Links:

    Rob Leathern (https://www.linkedin.com/in/leathern/)

    Juliet Shen (https://www.linkedin.com/in/julietshen/)

    ROOST (https://roost.tools)

    Show More Show Less
    46 mins
  • Won't Fix Episode 8: With Dave Kleidermacher of Google
    Jun 30 2026

    Dave Kleidermacher is a vice president of engineering at Google, leading engineering for Android security and privacy. His scope encompasses Android and the Made-by-Google world — Pixel, Nest, Fitbit, and the Play Store.

    We talked about Android's answer to scams: smarter defenses that use AI as a shield (on-device detection that catches scams as they unfold), and a deeper structural pivot to "Actor Trust" — establishing provable, cryptographic confidence in who or what a source is rather than forever trying to detect bad things.

    Dave has been steeped in these topics for a long time so we get into a bunch of great territory, and I think you’ll really enjoy the conversation.

    Key Highlights:

    • Consumer platforms must pivot from traditional vulnerability exploitation defenses to fighting scams and fraud, which make up 99% of actual practical threats facing users today.
    • The future of mobile authentication lies in reversing security asymmetry through "actor trust" cryptographically verifying the source device rather than relying on human intuition.
    • Big Tech players like Apple and Google need to publish a transparent, accountability driven joint priority roadmap to accelerate cross-platform security for critical defenses like caller verification.
    • Mobile network operators remain a critical structural weak point in consumer safety due to privacy-invasive habits like silent third party app installations and outdated location-tracking protocols.

    Chapter Timestamps:

    00:00 Introduction and Background

    3:01 The Shift from Vulnerability Threats to Scam Prevention ‎

    6:01 Real-time Voice Spoofing Capabilities and Demonstrations ‎

    8:19 Platform Defense Strategies and the Whack-a-Mole Problem ‎

    11:00 Actor Trust and Cryptographic Verification Approach ‎

    15:37 Google's Security Key Success and Developer Ecosystem Verification ‎

    17:35 RCS Standards and Industry Collaboration Challenges ‎

    27:19 Business Caller Verification and Stir Shaken Limitations ‎

    31:59 Privacy-Security Balance and Binary Transparency ‎

    41:30 Consumer Role and Stakeholder Responsibilities ‎

    43:27 Future AI Landscape and Industry Recommendations ‎

    49:47 Advertising Technology and Platform Accountability ‎

    Resources & Links:

    Rob Leathern (https://www.linkedin.com/in/leathern/)

    Dave Kleidermacher (https://www.linkedin.com/in/davekleidermacher/)

    Show More Show Less
    54 mins
  • Won’t Fix Episode 7: With Jeremy Philip Galen of Charlemagne Labs
    Jun 19 2026

    My guest today is Jeremy Galen, founder of Charlemagne Labs. Jeremy spent twelve years at Meta working in privacy, safety, and security — most recently five years as a product manager in trust and safety, focused on machine-learning content enforcement, account access, impersonation, and plagiarism.

    He left to start Charlemagne Labs, a New York startup building what he calls a "digital bodyguard" — an on-device AI assistant, Agent Charley, that steps in before a worker clicks a dangerous link or pastes sensitive data into a chatbot.

    The company's research recently landed in Meta's safety report for its frontier model, Muse Spark, where Charlemagne's benchmark measured how capable leading AI models are at multi-turn social engineering. His core argument is that the old "think before you click" model of security is broken, and that risky digital behavior should be treated less like a moral failure and more like a public-health and system-design problem.

    Learn more about Jeremy and the company at https://charlemagnelabs.ai/

    Listeners who sign up for the Pro plan can get 6 months for free if they use the promo code ROB2026.

    Key Highlights:

    • Selling consumer security software is a non-viable market because consumers buy what they want, while businesses buy what they need.
    • The open internet operates as an active battlefield where users face direct threat vectors from sophisticated foreign adversaries.
    • Falling for social engineering scams is entirely situational, rather than a reflection of an individual's intelligence.
    • Real-time, automated AI interventions are far more effective at enforcing digital hygiene than relying on static digital literacy training.
    • Over 90% of modern cybersecurity incidents originate from human risk vectors where an individual is directly targeted or manipulated.

    Chapter Timestamps:

    00:00 Introduction and Guest Background

    1:02 Career Transition and Startup Journey

    2:33 Consumer vs. Business Security Market Analysis

    3:56 Personal Motivation and Scam Prevalence

    5:09 Social Engineering Sophistication and Victim Blaming

    8:01 Big Tech vs. Startup Challenges

    13:59 Fundraising Reality and Survivor Bias

    18:05 Digital Hygiene and AI-Powered Protection

    22:06 Privacy-First Architecture and Local Models

    28:18 Democratizing Security and Luxury Concerns

    31:59 Meta Collaboration and Industry Standards

    35:16 Founder Advice and Problem Selection

    38:08 Company Information and Target Market

    Resources & Links:

    Rob Leathern (https://www.linkedin.com/in/leathern/)

    Show More Show Less
    40 mins
  • Won't Fix Episode 6: With Tate Jarrow, Founder & CEO of Rebound
    Jun 5 2026

    Tate Jarrow is the Founder and CEO of Rebound (https://trustrebound.com), a consumer anti-scam company. Before founding Rebound, Tate was an Army infantry officer and Airborne Ranger, and then a Special Agent at the U.S. Secret Service.

    At Google, he helped start a company called Beacon through the Area 120 incubator, which was then acquired into Google One.

    Key Highlights:

    • What Rebound is building: "Antivirus but for scams" — software that sits on a user's device across macOS, Windows, iOS, and Android, sees what the user sees, and alerts when it detects an inbound scam. Currently in alpha, heading into paid beta within the month, with general availability targeted for summer.
    • Why now: Normal people have zero real defense against scams. Law enforcement don't have resources for individual cases, and platforms are hard to reach for recovery. Existing consumer cybersecurity is rooted in 20-year-old problems (antivirus, credit monitoring) and isn't built for AI-powered, personalized, scaled attacks.
    • “You can't arrest your way out of cybercrime”: Cyber criminals run transnational organizations as businesses with P&Ls, so the real lever is changing the economics.
    • Google: Tate started in legal/investigations chasing cybercrime actors on Google platforms, got frustrated by the gap between business incentive and what could actually be done. Two of his Area 120 teammates are now on the Rebound team.
    • Scam overconfidence: Tate shares that a GASA study found the #1 predictor of being scammed is confidence that you can spot one — overconfidence is the actual risk factor. Every demographic gets hit.
    • Regulation and data: US regulation is 20 years behind. The real risk now is social engineering powered by leaked addresses, phones, emails, and contacts. He wants companies held accountable for the social engineering risk they create, not just PII in the narrow legacy sense.
    • "Caring guardians": People in tech are the de facto security help desk for their parents, friends, and families. Rebound is building features so a tech-savvy family member can have visibility into risk across the people they care about — plus in-app trust verification (one-click identity check) for the "is this actually my friend messaging me?" problem.

    Chapter Timestamps:

    00:00 Introduction and Background

    1:26 Rebound's Mission and Product Overview

    3:39 Technical Implementation and Current Status

    4:45 Motivation Behind Consumer Protection Focus

    7:45 Google Journey and Area 120 Experience

    14:59 Law Enforcement Perspective on Cybercrime

    18:30 Evolution of Cybercriminal Organizations

    21:07 Current State of Consumer Protection

    30:04 Regulatory Environment and Government Role

    37:25 Community Protection and Cross-Platform Challenges

    43:00 Product Vision and Future Plans

    Resources & Links:

    Rebound (https://trustrebound.com)

    Tate Jarrow (https://www.linkedin.com/in/tatejarrow/)

    Rob Leathern (https://www.linkedin.com/in/leathern/)

    Show More Show Less
    48 mins