The Talk Show with John Gruber
The Talk Show with John Gruber

243: ‘The God Awful Truth’ With Rich Mogull

Special guest Rich Mogull joins the show. Topics cover a range of security and privacy-related issues: the Jeff Bezos/National Enquirer saga, laptop webcams, abuse of Apple’s enterprise developer program to enable sideloading of iOS apps, Amazon’s acquisition of Eero, and more.

Featured Speakers

John Gruber HostJohn Gruber GuestRich Mogull Guest

Topics Discussed

Episode Summary

Executive Summary: John Gruber and security expert Rich Mogull discuss the Bezos/National Enquirer extortion allegations, why iMessage is far safer than SMS, and how modern device/security architecture changes what’s actually possible. They also cover webcam paranoia, app/privacy abuses, Apple’s bug bounty and FaceTime bug, and Amazon’s purchase of Eero as a privacy concern.

Main Topics: Bezos, the National Enquirer, and messaging forensics (Priority: 5/5): The hosts dissect Bezos’ public accusation of extortion by AMI/National Enquirer, the political context around Trump, Pecker, and Saudi links, and how the messages/photos may have been obtained. Mogull explains why the key technical question is whether the communications were SMS, iMessage, or another channel. iMessage vs SMS/MMS security (Priority: 5/5): A major thread is the difference between end-to-end encrypted iMessage and insecure carrier-based SMS/MMS. Mogull stresses that a breach path could involve device compromise, account takeover, forwarding, screenshots, or carrier-level interception, but the attack surface differs dramatically by medium. Webcam and microphone paranoia on modern Macs (Priority: 4/5): They debate whether webcam covers are necessary, with Mogull arguing modern Macs are substantially safer due to hardware/software integration, T2-related protections, and permission prompts. He still acknowledges microphone privacy is different because there is no equivalent indicator light. Privacy, app-store abuse, and side-loading on iOS (Priority: 5/5): The conversation expands to Facebook/Google enterprise certificate abuse, side-loaded apps, and screen-recording frameworks used by apps without clear disclosure. Mogull argues Apple’s sandbox and review process are valuable, but the ecosystem needs stronger anti-fraud policing and better privacy disclosures. Password hygiene and two-factor authentication (Priority: 4/5): The speakers discuss real-world account security practices: using unique passwords, avoiding SMS as 2FA, relying on OTP apps, and the dangers of SIM-swap/carrier attacks. Mogull describes how SMS-based two-factor and careless account setup can be catastrophic when targeted. Apple’s security posture and bug bounty gaps (Priority: 4/5): They cover Apple’s response to the FaceTime group-call bug, the limits of its Mac bug bounty, and how post-exploitation techniques differ from true OS vulnerabilities. Mogull says Apple is much better than it used to be, but still leaves gaps in researcher incentives and platform coverage. Amazon’s acquisition of Eero and smart-home privacy (Priority: 4/5): They close with the privacy implications of Amazon buying Eero, especially because Wi‑Fi infrastructure sees all network traffic. Mogull notes there are legal and reputational constraints, but the acquisition still feels like a loss for consumers who trusted Eero as an independent privacy-conscious networking brand.

Key Arguments: The central question in the Bezos story is not just the gossip; it’s the communication medium and access path. If the messages were iMessage, compromise likely required device access or cloud/account compromise; if SMS/MMS, interception is far easier. National Enquirer coverage is not fiction in the way many assume; it has historically published real, consequential stories and is often used for strategic political or personal leverage. Modern Mac security makes covert webcam access much harder than many people assume, especially with Apple’s hardware-software integration and permission prompts, but microphone privacy remains more fragile because there is no indicator light. Covering a webcam may be a reasonable personal comfort choice, but journalists and readers should not extrapolate a rare stunt-hack demonstration into a general claim that cameras are broadly unsafe. App and enterprise-certificate misuse is a serious privacy problem: Apple’s platform security is only as good as its enforcement against side-loaded apps, tracking frameworks, and misleading data collection. SMS should not be trusted for authentication or sensitive communication; OTP/authenticator apps or device-based approvals are better, and SMS-based 2FA remains vulnerable to carrier and social-engineering attacks. Data collection itself is a liability: companies should avoid collecting behavioral data unless they truly need it, because every retained dataset can be breached, abused, or regulated. Apple’s security culture has improved substantially, but gaps remain in bug bounty coverage, researcher relations, and response speed for issues that are more operational than exploit-based. Amazon owning Eero is especially sensitive because home-network hardware can observe everything traversing the network, making trust in the router/base station a major privacy boundary.

Data Points: Years in security for Rich Mogull: ~20 years - Mogull describes his background in security advisory services and startup work. WWDC 2009 date guess in transcript: June 3–7 - The hosts discuss a MacRumors prediction for WWDC timing in San Jose. Hotel rates near Moscone: $700–$1,000/night - Used to illustrate the cost of conferences in San Francisco near Moscone. San Jose hotel rates: $450–$550/night - Compared with San Francisco, still expensive but somewhat lower. LinkedIn job-posting offer: $50 off - Ad read offering a discount for posting jobs via linkedin.com/talk. Away suitcase offer: $20 off - Ad read for Away luggage with promo code Talk Show 20. iMessage announcement date: June 6, 2011 - Mogull and Gruber verify iMessage launch timing via Wikipedia during the discussion. Unique passwords stored by Gruber in 1Password: 1,358 - Gruber checks his password manager while discussing password hygiene. Passwords stored in Yojimbo: 637 - Gruber mentions additional passwords kept outside Keychain in a note app. Kids’ ages mentioned: 9, 8, and 5 - Mogull references his younger children when discussing device-based socialization. Time window for FaceTime bug response: within about an hour - Apple reportedly disabled the relevant servers quickly after the group FaceTime bug surfaced.

Pivotal Quotes: "Take Apple at its word, it's usually the truth." — John Gruber: Used to argue that Apple’s product descriptions, like HomePod as a speaker first, are generally accurate. "What more? I don't know, but it's not a simple, here's some embarrassing images of a famous person in their extramarital affair." — Rich Mogull: Mogull explains why the Bezos/National Enquirer case likely involves deeper security and political dimensions. "It really does come down to do you trust the software running on your device?" — Rich Mogull: His core framing for webcam, microphone, and platform privacy risks.

Implications: Listeners should treat SMS, weak passwords, and lax device/account hygiene as real security risks, while recognizing that platform trust, vendor incentives, and enforcement matter as much as raw technical defenses. The industry is moving toward privacy by architecture—but only unevenly.

🔓 Sign Up for Unlimited Episode Search

About The Talk Show with John Gruber

The director’s commentary track for Daring Fireball. Long digressions on Apple, technology, design, movies, and more.

View all episodes from The Talk Show with John Gruber