This transcript is generated with the help of AI and is lightly edited for clarity.
//
DOZIE:
You’re typing on your computer, and the AI is able to know what keys you’re hitting. The pitch from where the location of the key is on your keyboard can give away your password.
REID:
A finance employee joined a video call with people who looked and sounded like the company’s CFO and colleagues, and then transferred 25 million-ish dollars.
PARTH:
You should know, this is now the world we live in, where you can’t really trust real-time video. Someone can put your face on. Someone can wear your voice, kind of like a mask.
//
PARTH:
The token grantee program gives $1,000 a week in tokens to high-potential creators already deep in AI, across film, gaming, comics, print, and digital art. There are no tool restrictions. The freedom to choose is the point. Grantees also get access to my own custom fleet of agents and an ongoing collaboration with me. The goal? To close the gap between an idea and the world.
REID:
Part of this token program is showing how AI is kind of revolutionizing creativity building, and having a variety of folks who are using tokens—tokens to the future—in order to build and to show what they build, and to illustrate this for other folks and kind of help see the future. And so I’m doing this with Parth Patil. And Parth, I’ll hand it over to you to kick off the episode.
PARTH:
Awesome. Thanks, Reid. So, super excited to have you here today. Today we have a really good friend of mine. We have Dozie Anazia, and we’re really excited to have you on the token grantee program, especially because Dozie comes from a slightly different background from everyone else in the program. Dozie’s background is in cybersecurity, but we’ll get to that. I want to go back to how we met. I think it was five years ago now. I met Dozie on Clubhouse five years ago. Yeah, back in 2021. We were hanging out in rooms on Clubhouse, talking about games, talking about science fiction, nerd culture, and then just where the future was headed.
So why don’t we take people back? Introduce yourself, maybe where we were when we met, and then where we are today and what you’re up to.
DOZIE:
Yeah, I think that’s a pretty good description. We just randomly met on Clubhouse, as one does. It’s 2021, and I don’t actually remember exactly where we met. I think we just had the same group of friends and we were talking about software development, AI, data, all the tech stuff. And I think we just kind of serendipitously found each other because we both would use gaming as a metaphor or philosophy for just everything. Yeah, so I always found you interesting because you did that and I also did the same. So just describing life in gaming—gamify life—was kind of absolutely how we started having conversations with each other.
PARTH:
And I think especially as AI came online in 2020, ChatGPT in 2022, and then GPT-4 in 2023, we were pretty early. Like, there’s a huge early adopter community on Clubhouse, as you know, and we were early to playing with these tools and seeing what code generation was. And I was kind of like, oh my God, we need to unpack this together. I’m seeing what it does to data analysis. Dozie’s in school studying computer science. So clearly both of our fields are rapidly being transformed.
It’s like when you find these people, these teammates, and you start exploring the unknown, it’s so much better than doing it alone. And especially as agents and AI get more powerful, I find it really helpful to have someone like Dozie around, forcing me to reconsider how many permissions I’m giving my agents.
DOZIE:
Yeah, I was just going to say that. It’s funny you brought that up, because when I was in school—I think it was my second to last semester—I took an artificial intelligence class, and that was 2021. He was showcasing OpenAI, and OpenAI was basically giving you access to Atari games. And then you could basically put it in a Google Colab notebook or an Anaconda notebook and you just play Pong or something like that in a web interface. So yeah, I was on OpenAI like 2021, 2020. So that was my first rendition of it.
REID:
So, by the way, I totally get how you guys are like besties. I mean, it’s all the keywords that I associate with Parth. It’s gaming, Clubhouse, AI. It’s like, check, check, check, check. That’s totally fucking awesome.
I’m curious about how this also kind of connects to your current day with AI. There’s a whole breadth of projects you’ve worked on with tokens—gaming experiments, Star Collector, Letterboxd dupe—all the way to, you know, kind of like part of it is—and we’re going to only stay at fairly general and externally known examples. But also you do a bunch of stuff in security and you have a security expertise piece. And so I’m curious about kind of what your engagement with AI has been across this range. Cover some of them and then interrelate them some.
DOZIE:
Yeah, so it’s interesting because I’m working on the gaming projects. The gaming projects are fun because I’m just my own play tester for the game, and then whatever I don’t like, I prompt it again, and then I’m trying to figure out how to get to that X factor of playability. And my brain is just all over the place—ADHD. I can’t focus on anything to save my life, but I have so many ideas. And specifically, all of it does encompass security, because if you’re going to put any of these things on a website, you have to do some sort of sanitization of the code, and AI does that for you. Codex does that.
And the crazy thing right now is that the last project I’ve been working on—my recent project is called Breakfast, and I’m making a mobile breaking news aggregator.
PARTH:
Okay.
DOZIE:
And so when I finished the project, I do it in Claude and then I moved it to Codex to do the code review. Codex is like, this is very vulnerable, there’s a cross-site scripting vulnerability in it. So the last couple days I’ve just been trying to code it properly. And I was building a platform that just does a code review of the URL. But the AI is kind of already doing it. But if you don’t have the AI, then you could with the platform. The other platform I’m building is called Aegis. You can just throw in your URL and it kind of just scans it and tells you if there are any port vulnerabilities.
It does all the OWASP standards. So yeah, security encompasses everything. You’re never really going to get away from it. And it’s really important, especially right now, especially the way AI is going.
REID:
Well, we’ll come back to some of the interrelationship between the gaming and the cultural stuff, because it’s the breadth that’s also one thing. But since we’re on security, what scenario do you worry that many security folks—especially ones who are maybe not as deeply versed in AI yet—are still treating as science fiction, and that they should be thinking, actually the future’s already here, it may be unevenly distributed?
DOZIE:
So it’s funny that you use science fiction, because I feel like we’re living in the science fiction as we speak. We’re in real-time science fiction, because there are so many different attack surfaces now. And for example, I saw something with LED light. There’s a way—if you have an LED on your keyboard or something like that, there’s a way for you to view what’s happening from another surface, from another machine, through the LED light, which is crazy. Or if you’re typing on your computer, the AI is able to know what keys you’re hitting.
Which is insane to me, because if you can hear someone typing their password, then you have their password, which is unfathomable to me, how the AI can do that. It’s like if you were in the ’90s, you would mask the phone sounds from your—
PARTH:
Right. From when you’re typing.
DOZIE:
Right. So now it’s just literally the pitch from where the location of the key is on your keyboard can give away your password. That’s insane to me.
PARTH:
That is crazy. No, I feel the same way. I mean, we play—my favorite game is Cyberpunk. And I look around in Cyberpunk, I’m like, wait a minute, almost every single thing in this game is definitely doable in the real world. Just like the programs that we can talk to that can do a lot of the things that were previously manual, and then thinking like, oh, you can clone them. Okay, so now we have scale, we have parallelization, which is both a huge benefit and a negative. Right? So I can actually have a bunch of these agents looking at what I’m working on and adversarially critiquing the things that I’m making. Yes, it definitely feels like we’re living in a science fiction world.
DOZIE:
Yeah. I mean, and now it’s going to be autonomous pen testing, if anything. Because I think we were having this conversation before—I don’t know what’s going to happen with the defense aspect of it. Because now companies are employing third-party companies to do their pen testing. But now you’re just going to get an agent to do it for you.
PARTH:
Right.
DOZIE:
And then you really just need to get a third-party company to audit the agent. But at the same time, now you have malware that’s undetectable. It’s just endless possibilities of what can happen.
PARTH:
Well, actually it’s not endless, right? Because if you’re the one that’s making the software, you have an information advantage. You have the whole code base. So you know what the possible surface area is, where an attacker has to find the opening.
DOZIE:
Right. And then you have—I think the incentivization of this type of thing would just be, if you’re making that software, you just create a backdoor for it. And that’s where the disconnect comes from. When people are making these types of things, they’re doing it for the money, and if they make a backdoor for it, that’s where it’s going to go. That’s really what happens when we’re trying to find ways to break into some of this software. The backdoor is already there. It’s just you don’t have the knowledge yet, you know.
PARTH:
Right, right. This is something I noticed about all my friends in security: you kind of benefit from this assume-the-worst-is-already-possible mindset. Assume it’s not secure. Actually, it’s probably the best mindset in security—understand the blast radius, assume that it’s not secure, and then start looking for everything that could possibly go wrong and contain the possible blast radius. And that’s right, the attacker only needs to find one opening. And then once you have the speed of AI, they can move very quickly.
DOZIE:
Right. And that’s honestly the scariest part—the fact that, for example, if the attacker already has your information and they know what bank you bank with, they can clone—if you have AI, you can clone the login web page to your bank. And the velocity with which you can do that now is frightening. So you can just deepfake a page or, you know, vibe code—
PARTH:
You can fake a website. Yeah, it’s a deepfake website.
DOZIE:
You can vibe-code an attack, essentially.
PARTH:
Yeah.
REID:
By the way, I think we should linger on this a little bit, because the question is a changing surface of offense advantage, defense advantage. There’s a question of—you find only one thing, you create credentials, you’re able to do that. You only have to find one hole, whether it’s a clone bank or anything else. But say a little bit about, in this offense and defense side, there’s both the AI making individual attacks more sophisticated, but there’s also many, many different attacks and making it a lot cheaper to run. Those are all kind of things on the offense side, so go through some. And then also, what are the things that we need to be doing on defense given this too?
DOZIE:
Well, that’s the thing I’m not sure about, because when it comes to blue team—if you’re an attacker, you want to do it in a black box. You don’t give the attacker any information, and that’s how they have to figure out their way into the space. If they can do it, then okay, then the blue team does the research based on what the red team did. So I would say the best defense—or what’s the phrase? Your best defense is a good offense, or something like that. So I would essentially just assume that you would use autonomous agents to do better research for the blue team.
PARTH:
And break into your own stuff before anyone else does.
DOZIE:
Right. So that’s what I was saying before—instead of employing a third-party company to do pen testing, you employ an agent to do your pen testing, and then you have that company audit the agent. Or the other way around: you have the pen tester break into your company, and then you have the AI maybe work in tandem with the third party. So the defense part is really difficult, because at a certain point you’re never going to be able to—there’s always, apparently, a way in.
PARTH:
There is also the teamwork aspect of defense, where you and I can team up and share what we know about defensive tactics. Whereas banks, institutions, infrastructure—it’s not like they’re playing single-player when they’re trying to defend themselves. The tactics of the attackers are known, right? There’s a whole set of possible—well, you have a framework for this.
DOZIE:
You have the MITRE ATT&CK framework, which is just all of the different techniques that are used by the advanced persistent threat, the nation-state, like China or Russia—their techniques on how to get into companies, or just cyber red teaming. But then you have Common Vulnerabilities and Exposures, or CVEs. So as soon as a CVE comes out, I think that’s where the AI needs to come in. The AI needs to be able to—as soon as there’s a common vulnerability or a zero-day, you need to have an autonomous agent dedicated to defending against something like this.
REID:
Well, I think it’s worth—look, in the cybersecurity thing it’s both being highly concerned about—science fiction is now, and there’s a whole bunch of stuff where it amplifies the offense side. It’s cheaper. Multithreaded kinds of attacks, for sure. I think one defense is the multiplayer game side. The other one is the hope, maybe not yet reality, that we might be able to actually better arm defense with the best models, kind of compute from that. It’s part of what’s going on with Mythos: not only does it discover vulnerabilities very well, but it also suggests fixes, and is kind of at a higher-quality model of attack and defense. Red teaming through hiring agents, third parties, pen testing—you get more resilient to other than the absolute best attackers.
So what are some of the areas that you would say, hey, we have to adjust to an AI universe, but these are the things that we need to be thinking about, really making sure we’re doing, so that we’re not just swamped with successful, call it hostile AI cyber agents?
DOZIE:
I mean, honestly, that is the point where I’m hands-off. Because honestly, with Mythos—if Mythos is a purple team philosophy, then what exactly—
PARTH:
What does purple team mean?
DOZIE:
So purple team would be the mix between red and blue. So it’s both of them combined. Kind of like how gray hat is white hat, black hat—it’s in the middle. So you’re kind of employing both sides to understand what is the best way to attack, what’s the best way to defend. So if Mythos is—and I was assuming that Mythos was more of a red team thing, but if it’s defending and it’s doing both, right? So if it’s defending and if it’s self-healing and finding vulnerabilities and patching them up as you go, then I believe that would be the way to go.
But again, there’s also speed, right?
PARTH:
As the models get faster, speed is going to be a huge aspect to this.
DOZIE:
I was reading an article just earlier today on—as long as you can be the best at one of those aspects, whether it’s speed or you have the best hardware. It was Schneier on Security, and they were talking about how AI-assisted evolution is honestly the way to go. That’s what we’ve been talking about. But if you can find a way to implement—so I guess it’s like continuous integration or continuous deployment. The next phase of that would be continuous discovery. So as long as you are always looking for the vulnerabilities within the system and you are proactively—yeah, proactive AI. If you’re going that direction, then that’s honestly the way to go.
REID:
Well, so let’s go through a couple of the key areas that you know very well, Dozie, that it’s important to do. Kind of red, blue, and purple teaming, and having different models’ weaknesses—and obviously adversarial review is one of the key things here, because capabilities and blind spots even in just the amazing models, Fable, Sol, et cetera. So if we’re doing this huge surface of different models, is the only way to do that to have machines stress test machines? Does it give some really deep concerns about the limits of human review? What’s the way to pull this together, both in a way to solve the problem but also in understanding what’s going on?
DOZIE:
Yeah, I mean, I would say that you’re always going to have to have the human in the loop. AI is good, but AI is still not better than the best hacker. So again, it’s always going to be a combination of the two. And what I was saying before was, in order to excel in the space, you have to be the best in one of these different disciplines, whether it’s the speed, the scale, the scope, or the sophistication. So as long as you can be the first to get to the vulnerability, then sure. If you have the technology to scale as far as you need to, to brute force something—
PARTH:
Right, the search space. Yeah.
DOZIE:
So as long as you’re zeroing in on one of those disciplines, then that’s honestly where you need to be. Because you can just be a random script kiddie and deploy an autonomous agent, and it could take down a whole company.
PARTH:
Yeah, I’ve noticed that the script kiddie has never been this—it’s the same power that gives people vibe-coding superpowers. Now, casually, you’re able to break things on accident even if you don’t even know what’s going on. And I guess when you think about the power of the computer-equipped person, right, the parallelization—where do you think the human—my thing is, I like having an agent that just patrols my network.
REID:
Yeah.
PARTH:
While I’m asleep. And even if it’s just read-only, it’s not that it actually builds anything, but that it’s just reading everything and making sure that none of the agents on my network are going rogue, none of them are putting keys in the wrong places. And I like it, but I feel that it’s not enough for it to just be reading while I’m asleep, because I would actually want it to wake me up, or I would want it to actually mitigate when something goes wrong. I want it to mitigate the exposure that I have there. So I guess, what do you think about when we give our defensive agents more agency, more proactive—like, how proactive?
At what point are we going to start seeing them go find the issue and solve it immediately before you even wake up? Do you think about that, where we as a human in the loop, you actually want to not need to be in the loop to play defense?
DOZIE:
Yeah. I mean, I think it’s hard to say that you’re going to be able to ever just be completely autonomous. I don’t know if that’s the best idea, because if the agent starts malfunctioning, then it’s definitely a problem. And if you have a hallucinating, adversarial agent, that’s something that you don’t want.
PARTH:
Right.
DOZIE:
But honestly, I would say that you have the agent that patrols, but you just have a second agent that has that specific skill.
PARTH:
Different perspectives on playing defense. Playing at the same time.
DOZIE:
Right, exactly. But I guess the way to talk about that would be skills—and not human skills, I’m talking about AI skills.
PARTH:
Agent skills.
DOZIE:
Yeah. So I was in a cyber room earlier today and they were talking about the compounding of skills. There are several different GitHubs that are just autonomously pen testing. I think he called it super skills. So you just have several different skills on top of each other, and then you have an agent basically extract from those skills to make a super agent. I don’t know if that’s where he was going with it, but I think that’s where we’re going. You’re going to have to compound a bunch of skills together for an agent to do what you’re talking about.
Or you just have multiple agents with maybe a few sets of skills.
PARTH:
And slightly different theories of how you might want to play the defense.
DOZIE:
Right, exactly.
PARTH:
Yeah. So you don’t put everything into one bucket, right? So I guess that gets into the white hat space—people starting to deploy their own agents to look for vulnerabilities, look for impersonation. It’s basically fighting AI fraud with AI defense, which is a modern version of the old white hat game. Do you think that this turns security into an arms race between agents, where the side having a better model wins by default?
DOZIE:
Yeah. So when you say arms race, I’m thinking, who has the most expensive, who has the most hardware, who has the highest capability. And I don’t know if that’s necessarily the case, because you have instances with DeepSeek basically blowing it out of the water and spending a fraction of what OpenAI is spending. So I think it’s more of—whenever there’s a paradigm shift, it’s not an arms race, it’s just more of a new capability. It’s honestly hard to explain. I’m having a hard time expressing it.
PARTH:
But I think it’s not necessarily a better model, but better resourced, better in a couple of different ways.
DOZIE:
It’s like an optimization race, if you will. I think that would be the way to phrase that.
REID:
Well, let’s come back to one of the things we were talking about a little bit earlier, because I do think one of the really important things is to say, well, offense has an advantage on just finding the one angle that works, with now a broader computer surface, together with an ability to experiment with it and do things with AI. Defense has the multiplayer configuration. How do we get the incentives to work in defense, kind of coordination? Because there’s actually some—I don’t want to reveal my weaknesses, I don’t want to share my benefits with potential competitors, or once I share those, maybe those also leak to the offense. How do we get the kind of multiplayer defense incentivized the right way?
DOZIE:
I mean, the multiplayer defense—I would say that’s already what’s happening. If you have a company come in, like I said before, if you have a company come in to do pen testing, you would have to give them an NDA. They obviously can’t reveal your vulnerabilities or anything like that to anyone in the public, because that would be a security issue. So it’s more of—cybersecurity isn’t just the hard skills of coding and cracking passwords or anything like that. Policy is a big deal. Following the law, having a very rigid policy on how your company operates would be the way to go.
But I feel like the law has not caught up to AI yet. So I feel like that’s the advent that we’re very close to. There’s just going to be a loophole with AI in some aspect, where the AI that you purchased, that you basically put on your own company—like you said, they have ceded it over to you. So now if it malfunctions or hallucinates or something like that, it’s on you; it’s not on them.
PARTH:
So when things go south, you publish a report on what happened. And then, in order to incentivize people to publish anonymized reports—you don’t need to give up the customer information, user details, et cetera, but outlining the style of the attack, because there are going to be novel attack patterns that are emerging, novel or at a higher frequency than they were pre-AI. But when you can reward people for sharing the shape of the attack as it emerges, by rewarding them with access to frontier models, for example, or rewarding them with access to more defensive measures—then it’s like, we want a world where you’re not playing single-player defense, I’m not playing single-player defense.
And then both of us could have had overlapping defenses where we’re covering a wider set of strategies instead of individually trying to patch everything. And I think creating some kind of reward for sharing information about the new shapes of attacks that are coming online, so that the defenders have a way to—whether that’s access to frontier models that can play defense, access to compute to do that defense, fortifying our systems. Let’s say one bank notices an attack and then notifies the rest of the financial institutions of that shape of attack before it becomes a bigger problem in the ecosystem.
DOZIE:
Right. I think it’s tough to say, because there’s no way to tell what someone’s true intentions are. So, not everybody’s an altruist. Not everybody is just thinking that, okay, well, I have compute power, I’m going to—with great power comes great responsibility, I’m just going to do this for good. I don’t think it really works that way.
PARTH:
You could pay people to make playing defense more lucrative than playing offense.
DOZIE:
I wish that was the case.
REID:
Around the world, wish that was the case.
DOZIE:
Right.
REID:
Unfortunately, because lots and lots of surface. Speaking of surfaces to go after, I think we only have time for one more question before we turn to our closing motions. But I know one of the things that you have done some in-depth thought on, and because we’ve talked to you about it before, is one of the most famous deepfake scams that happened in Hong Kong a few years ago, where a finance employee joined a video call with people who looked and sounded like the company’s CFO and colleagues, and then transferred 25 million-ish dollars. Tell a little bit about that. And then, if seeing and hearing someone is no longer verification, what replaces it? Where are the vulnerabilities and the fixes?
DOZIE:
Well, yeah, so the thing about that case is that it happened in 2024. So that was pretty early within AI. That speaks to the speed aspect of attacks. If you have new technology like this and you’re the first to deploy it, then—think about having a model, or having Sora, in 2023. You can’t even tell. No one’s thinking about that type of thing. No one’s thinking about deepfakes. I mean, deepfakes have been going on for a minute, but the way to spin up a deepfake that quickly, with people that you know, that you see in everyday life—
You’ve been snowed so quickly. There’s no way to—it’s insane.
PARTH:
So I’ve been playing with a lot of these tools and I wanted to see what the best one of these was that you could run on a consumer GPU, my own gaming graphics GPU. I downloaded—I think it was an open-source library, and it was called Deep-Live-Cam. It’s the trending open source library on GitHub Trending. And I downloaded it, and I realized with one picture of your face, I could put your face on in a live video call. And then immediately I just told my family about it.
Because I was like, I am wearing my cousin’s face right now, and I put his face on in a video call. I was like, guys, you should know, this is now the world we live in, where you can’t really trust real-time video. Someone can put your face on; someone can wear your voice, kind of like a mask. And all I knew to do was to tell everyone that I want to protect that this is now a capability that could run on a graphics card that just anyone has. It’s not that it’s an expensive thing, or that it costs any money at all.
And that was two years ago. An open-source model runs on an at-home GPU. So that’s the video streaming. We get that with voice. We get that—I mean, we have Reid AI, which is hopefully trying to be a positive example of what digital avatars can be.
DOZIE:
Yeah.
PARTH:
This is a new form of social engineering, right?
DOZIE:
That case was everything that was social engineering. That was phishing. That was deepfake. That was a bank heist. It had literally everything you could think of. It was whale phishing. If you know what whale phishing is—it had so much in it. So it’s a good lesson for the world to understand what we’re up against.
And then as far as vishing—if someone steals your voice—I think you just need to—and it’s so easy to steal something.
PARTH:
That’s what vishing means. Voice phishing.
DOZIE:
Yeah. But again, it was vishing, it was a deepfake, it took everything. But I hate to say it, you might need safe words for people in your life. Like, you need “pineapple” or something like that. You need to really—
PARTH:
Interrogate. You need some way for the other person to reveal that they are who they say they are.
DOZIE:
Right.
PARTH:
Say something that only Dozie would know. Based on your interaction with me, based on how you know me. It’s like, who’s your favorite Marvel superhero?
DOZIE:
The new Lanterns show—there’s this clip going around of this guy revealing that he’s an alien. The guy’s talking about voting for Obama at the time, but then he asked him what school Harry Potter went to and he couldn’t answer, so that gave it away.
PARTH:
So you’re obviously not from Earth if you haven’t seen Harry Potter.
REID:
Well, Dozie, thank you very much. It’s been awesome. I look forward to future conversations.
DOZIE:
Reid, it was an absolute pleasure to meet you. Thank you for having me.
REID:
Possible is produced by Palette Media. It’s hosted by Aria Finger and me, Reid Hoffman. Our showrunner is Shaun Young. Possible is produced by Thanasi Dilos, Katie Sanders, Spencer Strasmore, Yimu Xiu, Aman Suri, Danny Garrison, Trent Barboza, and Tafadzwa Nemarundwe.
PARTH:
Special thanks to Surya Yalamanchili, Saida Sapieva, Ian Alas, Greg Beato, Parth Patil, and Ben Relles.

