Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing
Podcast Image

Planet Money

Can computer hackers get inside your mind?

17 Jun 2026

Transcription

Transcript generated automatically by AI and may contain errors.

Chapter 1: What is the main topic discussed in this episode?

0.031 - 19.828 Tanya Mosley

This message comes from the podcast 5 Miles From Home. When a high school student disappears from a small Nevada town, a story of betrayal and shocking confessions emerges. Hosted by Dateline's Keith Morrison. Search 5 Miles From Home to follow now. This is Planet Money from NPR.

0

Chapter 2: What invisible conflict exists between the U.S. and Iran?

22.913 - 43.656 Erika Beras

On Friday, if all goes according to plan, representatives from the U.S. and Iran will meet in Geneva to sign another 60-day ceasefire agreement. But the two sides still have not come to an agreement on what's been at the heart of this war and decades of conflict, Iran's development of nuclear weapons.

0

43.754 - 68.513 Nick Fountain

Right. This conflict has been on again, off again for years. And while the most recent iteration has been very violent with bombs and blockades, there is a whole other almost entirely invisible war that the U.S. and allies have been waging with Iran using cyber espionage or more accurately, cyber sabotage, you know, computer viruses, malware.

0

69.488 - 94.189 Nick Fountain

Recently, we heard a story about a piece of malware that might have been used in this invisible war that was diabolically cunning. Because it exploited weaknesses in computers, yes, but also maybe in the human psyche. The more I think about it, the more I think, this must have driven people insane. But, It also might have saved the world from nuclear destruction.

0

94.75 - 101.304 Erika Beras

We heard about this hack from someone whose job it is to identify computer hacks that could be a threat to all of us.

0

101.885 - 108.439 Juan Andres Guerrero Saade (JAGS)

What's your name? What do you do? My name is Juan Andres Guerrero Saade, which is why everybody calls me Jags.

108.993 - 114.143 Erika Beras

J-A-G-S, JAGS. His initials are shorter and cooler.

114.644 - 122.22 Nick Fountain

Yeah, actually, he is a pretty cool guy. He's got a faux hawk, sleeves of tattoos. He was on track to go get a PhD in philosophy, but now?

122.24 - 128.773 Juan Andres Guerrero Saade (JAGS)

I'm a security researcher, what I think would be the simplest term. I think some folks would say cyber paleontologist.

129.023 - 144.781 Erika Beras

cyber paleontologist, like he digs for the remnants of cyber attacks. Jags works for a cybersecurity company called Sentinel-1. It helps big companies like Samsung and the Golden State Warriors and the government protect their computers and networks.

Chapter 3: What is the significance of cyber sabotage in modern warfare?

202.463 - 214.467 Erika Beras

We met up with Jags because we wanted to get a peek into the invisible war. Because Jags has made a stunning discovery of a highly specialized, highly sophisticated cyber weapon.

0

215.028 - 229.108 Nick Fountain

Often these weapons don't even get detected. If they do, it's not usually until years later when someone like Jags comes across an old fragment and tries to reconstruct what top secret mission the weapon was designed to carry out.

0

229.469 - 240.023 Erika Beras

For Jags, the fragment he found wasn't even a piece of code. It was just six words. It came from a leaked list of malware from the NSA.

0

240.403 - 257.488 Nick Fountain

Yeah, the list came from this tool the NSA had. meant to help NSA operators, while they were hacking into some computer in enemy territory, figure out whether some other hacker was already there. And if so, whether they were friends or foes.

0

257.928 - 272.65 Juan Andres Guerrero Saade (JAGS)

Essentially, it'll run all these checks and it's gonna give the operators, it's gonna give a list of instructions of saying, hey, look, suspicious thing here. We don't know what that is. Known malware, pull back. Like little warning signs.

272.967 - 292.512 Nick Fountain

And this was a budding cyber paleontologist's dream. Each piece of malware on that list had the potential to teach you so much about how the world's top hackers were getting the job done. And maybe one would turn out to be an incredibly sophisticated cyber weapon.

292.812 - 307.902 Erika Beras

Jags, with great excitement, got a hold of this list and started scouring it for something he should start digging into. And one item screamed, look here. There's one, just one line.

308.455 - 318.311 Juan Andres Guerrero Saade (JAGS)

That's like completely different to all the other ones. Okay. And it just says FAST-16, nothing to see here, carry on. In all caps. That's it.

319.272 - 333.695 Nick Fountain

There's nothing else like it. FAST-16 was what the NSA was calling the malware. And the cryptic instruction the agency was giving its operators, not seek help or pull back, simply don't. Nothing to see here.

Chapter 4: Who is Juan Andres Guerrero Saade and what does he do?

378.227 - 390.083 Erika Beras

And eventually, he was able to put together the pieces of the skeleton that is Fast 16. But still, when he tried to reverse engineer it to understand what its secret mission was, he couldn't.

0

390.35 - 411.919 Juan Andres Guerrero Saade (JAGS)

I worked these like cracked out nights and very often I'll run into something. I'm like, oh, my God, I found this amazing thing. And then by the morning, you're like, no, this doesn't work. We call this the Valley of Despair. Oh, yes. I have built a home in the Valley of Despair. I'm in the process of gentrifying the Valley of Despair. If any of you would like to join me there.

0

412.557 - 432.068 Nick Fountain

After many, many fruitless nights, weeks, months, Jags had to turn to other projects and had to put Fast 16 down. But to remind him of what was not solved, he inked Fast 16 on his skin forever.

0

432.959 - 436.954 Juan Andres Guerrero Saade (JAGS)

Fast 16 has been on the back of my arm for a while now. You got it tattooed? Oh, yeah.

0

436.994 - 437.937 Nick Fountain

Where is Fast 16?

438.62 - 441.309 Juan Andres Guerrero Saade (JAGS)

You can see Fast 16 and nothing to see here.

441.35 - 446.795 Nick Fountain

Nothing to see here. Carry on. Hello and welcome to Play The Money. I'm Nick Fountain.

447.055 - 450.663 Erika Beras

And I'm Erika Barris. Today on the show, nothing to see here.

451.043 - 463.168 Nick Fountain

Carry on. Yeah, Jag sets out to solve the mystery of Fast 16 and finds a cyber weapon with the potential to chip away at our very grasp of reality.

Chapter 5: What is the mysterious malware known as Fast16?

872.076 - 890.494 Juan Andres Guerrero Saade (JAGS)

Anybody in this industry is a lightning rod for like DMs from people clearly having like schizophrenic episodes about like the government spying on me. So you hear this kind of stuff all the time. When you hear it from Vitaly, who's a very measured person, it makes you take pause. You go, okay, what are you talking about? What do you mean?

0

890.828 - 910.761 Erika Beras

Vitaly explained they're from the same era, the mid-2000s, and even though they don't share any code, they seem to share similar architecture. But Vitaly couldn't figure out what exactly Fast16's mission was, only that it targeted the part of a computer that did complex math.

0

911.045 - 923.256 Juan Andres Guerrero Saade (JAGS)

Think of it as like floating point math, like the really, really details-based, hard calculation stuff that most of the time you never deal with. And I've never run into a piece of malware that does that.

0

923.817 - 939.972 Erika Beras

Jags says he's never seen malware that messed with high-precision math. Most spy malware is designed to steal data or, like in Stuxnet, make things go haywire. But this one was basically telling the computer 2 plus 2 equals 5.

0

940.289 - 958.922 Nick Fountain

So, at this point, Jags had found Fast16 buried in a cyber library based on a hunch that it was something to pay attention to. And Vitaly had confirmed it was. Because who messes with math? And maybe more importantly, whose math were they messing with?

959.358 - 990.645 Juan Andres Guerrero Saade (JAGS)

Who is running high precision calculations back in 2005 doing something so interesting that it got somebody to build a super specific custom piece of malware to modify and mess with their workloads? Everything about this thing screams special. Like it screams unique. It screams groundbreaking. And I think what's most excruciating about it is that the mystery won't yield.

990.926 - 994.231 Juan Andres Guerrero Saade (JAGS)

Like you're just kind of have to keep pushing and say, OK, why?

995.873 - 997.676 Erika Beras

After the break.

997.736 - 1002.744 Juan Andres Guerrero Saade (JAGS)

OK, I guess we're back to the trenches of like, OK, how do we nail this thing?

Chapter 6: How did Fast16 potentially interfere with nuclear calculations?

1352.604 - 1371.145 Juan Andres Guerrero Saade (JAGS)

The exact same wrong answer. Exactly. So the idea was to drive these people nuts, right? Like you go and like it's right math, wrong answer, right formula, wrong answer over and over everywhere you go. And you probably don't know that it's wrong until you then go and try to do another thing with it. And you go, damn it, this thing is not working.

0

1371.125 - 1371.586 Nick Fountain

Yeah.

0

1371.606 - 1388.83 Juan Andres Guerrero Saade (JAGS)

Right. Like it's devious. The cunning of this attack is truly fascinating because at some point, I think before you ever consider that the computers are wrong. Yeah. You almost certainly look at these scientists and go, maybe you guys are clowns. Maybe you guys don't know what the hell you're doing.

0

1388.962 - 1402.088 Erika Beras

Jags and Vitale were flabbergasted by the sophistication and the technical prowess of this malware from decades ago. Not just the Cody parts, but also the deep knowledge of nuclear physics.

0

1402.108 - 1426.804 Nick Fountain

And after so many late nights of being haunted by Fast 16... Jags and Vitale were finally able to announce in April of this year that FAS-16, which they'd started looking into on a hunch, was indeed a major cyber weapon. Whose mission seemed like it was to sabotage Iran's nuclear development program. Was it worth the wait?

1427.786 - 1432.772 Juan Andres Guerrero Saade (JAGS)

Absolutely. I mean, walking around with this like bag of open questions, right?

1432.904 - 1444.879 Erika Beras

Yeah, there are still some unknowns. Number one, we don't know definitively that this was targeting Iran. For example, North Korea also had nuclear ambitions at that time.

1445.2 - 1465.462 Juan Andres Guerrero Saade (JAGS)

You look back, you go, well, North Korea was having a whole lot of problems with their missile program back then. We don't know where all these things were being used. We just know of one target that they definitely used this kind of stuff against, which is Iran. You're that confident? Look, let's put it a different way, right?

1465.763 - 1482.607 Juan Andres Guerrero Saade (JAGS)

We've never, ever, ever, ever, ever, ever heard of anybody doing this kind of cyber sabotage anywhere for anything other than the Iranian nuclear program in the same era as when FAS-16 is developed.

Comments

There are no comments yet.

Please log in to write the first comment.