Episode 18

Former FTC Chair Weighs in on Scams

with Jon Leibowitz

Show Notes

My guest Jon Leibowitz spent nearly a decade at the Federal Trade Commission, and four years running it — as Chairman from 2009 to 2013, right through the wreckage of the financial crisis.

During Jon's chairmanship (March 2009 to February 2013), the FTC's enforcement centered on "last dollar" frauds preying on Recession-battered consumers: coordinated national sweeps against mortgage-rescue and foreclosure-relief scams (leading to the 2010 MARS Rule banning advance fees), and a landmark $108 million settlement with Countrywide over mishandling struggling borrowers. It hit deceptive marketers hard — the roughly $359 million Jesse Willms "free trial" negative-option case, a $163 million scareware judgment against fake-virus-pop-up operators, the 2011 fake-news-site sweep over bogus acai-berry weight-loss claims and phony Oprah and Rachael Ray endorsements, and a 2012 international crackdown on India-based tech-support scam boiler rooms. On the robocall front, it brought cases like the Cash Grant Institute and the auto-warranty scheme (the telemarketer who surrendered his Mercedes) and launched the public Robocall Challenge contest. Beyond fraud, his FTC also built the agency's modern privacy agenda — landmark settlements with Google and Facebook and a record $22.5 million penalty against Google over Safari tracking — and stayed active on antitrust and competition alongside all of it.

After the FTC, he went into private practice at Davis Polk, testified before Congress more times than he can probably count, and today he chairs the National Consumers League — one of the oldest consumer advocacy groups in the country.

But here's what makes this conversation timely. The scams he chased fifteen years ago never died. They got faster, cheaper, and — thanks to AI — a whole lot more convincing.

Chapter Timestamps

  • 00:00Intro
  • 2:33FTC career and current work
  • 4:03Old scams, new technology, and the rise of AI-enabled fraud
  • 5:30From the “spam king” to large-scale online deception
  • 6:51Fraud supply chains, overseas actors, and cross-border enforcement
  • 9:52AI deepfakes and the persuasive power of modern scams
  • 11:21Affiliate marketing, robocalls, and weakened FTC monetary remedies
  • 14:42State attorneys general and platform cooperation
  • 17:48Shared intelligence and the multi-provider nature of scams
  • 18:23AI fraud's scale and fabricated “evidence”
  • 20:33Long-form fake media and recurring-subscription traps
  • 23:39Domain authentication and the failure of voluntary privacy standards
  • 27:03Reporting, independent evaluation, and regulatory balance
  • 33:02Trust in the internet and FTC rules against impersonation and fake reviews
  • 34:53Business verification and the trade-off between friction and safety
  • 37:14A $0 trial that becomes $34.90 per month
  • 39:58Closing: protecting reality while preserving innovation

Resources & Links

Cases from Jon's era

  • Sanford Wallace "Spam King" (CD-ROM tray) — FTC releaseThe FTC's 2004 complaint describes spyware that popped open CD-ROM trays and then flashed a "FINAL WARNING!!" pushing paid fixes. Nice follow-up detail: a court later ordered Wallace to give up $4,089,500, from selling the "fix" at roughly $30 a copy.
  • Scareware $163M judgment (Kristy Ross) — ftc.govUseful context for listeners: a co-defendant and his father had to give up $8.2 million under a 2011 settlement, which is a good contrast with the giant headline number.
  • 2012 international tech-support crackdown — FTC releaseThis is the press conference Jon describes; one of the six operations found victims by buying Google ads that appeared when people searched for their computer company's support number, which echoes the toll-free-number point.
  • Jesse Willms $359M settlement — FTC release
  • The Atlantic, "The Dark Lord of the Internet" (Willms profile, 2014)
  • Fake news sites / acai sweep (2011) — FTC release
  • Central Coast Nutraceuticals (fake Oprah / Rachael Ray endorsements) — FTC release
  • AMG Capital Management v. FTC (SCOTUSblog case page) — SCOTUSblogThe ruling came down April 22, 2021, unanimously, holding that the FTC can't get restitution or disgorgement under Section 13(b).
  • Impersonation Rule taking effect (FTC) — FTC releaseIt lets the FTC go straight to federal court to get money back for victims and seek civil penalties.
  • Fake reviews and testimonials rule (FTC, Aug 2024) — FTC releaseThis directly covers fake celebrity testimonials and AI-generated reviews.
  • Click-to-cancel vacated (law-firm explainer) — FenwickThe Eighth Circuit struck it down on July 8, 2025 because the FTC skipped a required preliminary regulatory analysis.

InfoHawk funding announcement

Transcript

There may be transcription errors: we apologize for those in advance.

Rob: My guest today is Jon Leibowitz. Jon was chairman of the Federal Trade Commission from March 2009 to February 2013, and he'd been a commissioner since 2004. Jon is also an investor in my company, InfoHawk, and we're grateful for his support of what we're doing to stop scams, fraud, and abuse. I was really excited to talk to Jon about how the things we're seeing today map against what the FTC and other regulators and litigators have historically taken on in consumer protection. During his time chairing the FTC, there were a number of cases that are still quite relevant to what we see today. One was the Jesse Willms free-trial case, filed in May 2011 and settled in February 2012. It ended with a $359 million judgment and a lifetime ban on negative-option billing, after Willms's operation allegedly took money from nearly 4 million people. There were also actions against what's known as scareware: fake virus pop-ups. That included a $163 million judgment against defendant Kristy Ross and a lifetime bar from selling security software. In 2011, the FTC went after fake news sites that used counterfeit ABC, CNN, and Fox logos to hawk acai berry diet pills. A related case, Central Coast Nutraceuticals, settled for $1.5 million over phony Oprah Winfrey and Rachael Ray endorsements. And in 2012, the FTC launched an international case against India-based tech support boiler rooms impersonating Microsoft, Dell, and Norton. Unfortunately, a lot of these kinds of scams, fraud, and abuse are still problems today. We'll get into it with Jon in just a minute. As always, thanks for joining us, and I always appreciate your feedback.

Rob: Jon, good to see you. How are you doing?

Jon: I'm doing great. How about yourself, Rob? It's good to be back with you.

Rob: Doing well. I've just been busy trying to find scams and fraud. Unfortunately, it's not that hard.

Jon: I know, I know. Hopefully you'll do a really good job of stopping them, and I know you will.

Rob: Thank you. It's a good segue for today's discussion.

Jon: Absolutely.

Rob: I thought it would be really interesting to talk about some of the things you've seen historically and how they're different from, or the same as, what we're seeing now. But to start off: what have you been doing since the FTC?

Jon: A variety of things. First of all, I worked at the FTC for eight and a half years: the first four as a commissioner, the last four-plus as chair. From a psychic-income perspective, it was the most wonderful job I've ever had and ever will have. It was a very bipartisan commission at the time. Everybody listened to each other. We didn't always agree, but we agreed most of the time, particularly when we were going after primitive, pre-AI fraud. Since then, I've practiced law, I'm running a small publicly traded AI company, and I do a little antitrust and consumer protection consulting. That's me in a nutshell.

Rob: And in fair disclosure, you also invested in InfoHawk. We announced that publicly. Thank you for that.

Jon: I was glad to. And I'm glad you disclosed it. The work you're doing is critically important, and we can talk about why.

Rob: I'd love to. It seems like a lot of what the FTC was going after when you were there still exists today, sometimes in similar forms and sometimes in somewhat different ones. Looking back, there's still the same scareware and tech support scams. Those are very much in operation today. We just sent a batch of them to a number of companies after we stumbled on them. So a lot of it seems to be just the evolution of the scammers' tactics.

Jon: I think that's exactly right. The scams haven't changed nearly as much as the technology has. When I was at the FTC, we brought cases against bogus free trials and recurring charges, and we actually wrote ROSCA, the Restore Online Shoppers' Confidence Act. We didn't get to use it, but my successors did. Fake news sites, scareware and phony tech support, overseas operators, shady payment processors: all of this is now on steroids with AI. That's what makes AI in some ways very beneficial and in other ways extremely troubling. AI fraud isn't quite the extinction event we've read about over the last few weeks, but it's really, really important. When I first came to the FTC as a commissioner in 2004, we brought a case that maybe illustrates the vast difference between then and now. It was against a guy named Sanford Wallace, the self-described "Spam King." His scheme was a kind of spyware-and-scareware operation: he injected consumers' computers with spyware. What I remember best is that it made the CD-ROM tray open and close, open and close. Then he'd send those consumers an email: "Is your CD-ROM tray opening and closing for no particular reason? If it is, you need our product" for $39.95. And indeed, if you paid them $39.95, they would stop the CD-ROM tray from opening and closing, which they had caused in the first place. It was a reminder, maybe quaint at the time, that a consumer's computer is the consumer's own, and yet people are constantly trespassing on it in very bad ways. Now, of course, we see dramatically different levels and scales of fraud.

Rob: We're also seeing them use AI to hide their tracks. In some recent tech support scams, we've seen obfuscation. We actually found an analytics dashboard one of these operators had built, and they hadn't put any authentication on it, so we could see people being scammed in real time. Obviously, we notify the authorities about all of this. There's also one set of actors buying software from another set of actors and using it. You can often tell from the way these kits are used that multiple entities are involved. Sometimes there's a security mechanism designed into the software that isn't being used properly. So you can tell they built in security, but the people who bought access didn't use it. There's definitely a large supply chain of fraudsters using software built by other people.

Jon: And Rob, when you see these malefactors now, do they often have an offshore presence? That makes them even harder to block or stop, and certainly harder to go after as a prosecutor.

Rob: Yes, for sure. There are often lots of clues about where they might be located. There might be Portuguese comments in the code, or instructions and other things that indicate they're overseas. And if you look further, you'll often find they're probably outside the normal reach of the law, unfortunately.

Jon: And it's much harder now, when you have multiple bad actors collaborating from different jurisdictions. In 2011 or 2012, we brought an international action with three or four of our counterparts from Canada, Australia, and New Zealand, involving scams mostly out of India. That was not easy to coordinate, but we did it, and we got some help from the Indian authorities at the time. We had started to see this, but not a huge amount of it. That's why we did a big press conference, to get the word out. It seems antiquated by today's standards. In 2012, most scams were phone-based. Now the majority, maybe not the vast majority, are internet-based.

Rob: Some of these tech support scams we've seen still use toll-free numbers. I think that gives people more confidence it's legit, because it seems like the kind of thing where a real company is paying to accept your call. In fact, nothing could be further from the truth.

Jon: That is exactly right. AI gives every malefactor an army. Old-fashioned fraud was labor-intensive. When I was there it was beginning to evolve, but it just wasn't as sophisticated. Now you can put words in Oprah's mouth, and it sounds like Oprah. We need to do everything we can in both the private and public sectors, including public enforcement and companies like InfoHawk, to confront this problem successfully.

Rob: Absolutely. I remember a lot of those celebrity deepfakes. Well, not really deepfakes; back then it was more like Photoshop manipulation. Implied or explicit endorsements from Rachael Ray or Oprah for weight-loss products, negative-option rebills, and so on.

Jon: Very often centered around acai berries. I remember one of my staffers coming in and saying, "We're bringing another acai berry case." And I said, "What's the matter with acai berries?" I'm not sure they're the miracle cure some people think they are. And he said, "No, no, no. It involves all sorts of other misrepresentations and deceptions."

Rob: I've had this conversation a few times on this podcast, about affiliates. One of my former colleagues said affiliates are kind of the root of all evil. Having spent a lot of time going after affiliate actors, do you think there's a place for affiliate marketing in the world? Or is it, by proportion, so badly run that it's generally scammy?

Jon: As someone who has probably gotten 100 robocalls over the last three weeks offering me a $50,000 loan at a wonderful interest rate, I have to say I've about had it with affiliates. Now, there are different kinds of affiliates. But it's a kind of Wild West out there with affiliate marketing. It's not policed. When I was at the FTC, and until the Supreme Court's decision, the agency had the ability to get equitable relief from malefactors. So you could really go after the hub. You wouldn't go after every affiliate marketer, though you could if they were particularly abusive, violating Do Not Call and so on. But you could go after some of the worst actors and extract their profits. Then there was often a follow-on private lawsuit, so you could really punish them. Then in the AMG case, the Supreme Court took away the FTC's equitable relief authority to get restitution for victims and disgorge profits from malefactors. That decision might have been right on the law. I always thought our authority there was on thin ice. But Congress has not yet restored that authority, and may never. Restoring it would make deterrence more effective. Coming back to affiliates, I've started thinking about this in the context of Do Not Call, too. If you could sanction those who give affiliates their information to reach out to consumers in violative ways, if you could go after that hub more effectively, I think there'd be more self-policing and it would be less of a problem. But it's a problem today at multiple levels: scams, nuisance, and various other things.

Rob: Part of the problem is that some affiliate network providers are very aware of what they're doing. They'll actually end up funding some of their own affiliates. They're not supposed to; that's part of what the whole structure is meant to avoid. But I heard stories back in the day of companies getting Centurion credit cards for affiliates so they could buy more media and drive more leads. They should not have been doing any of that, but a lot of it was going on.

Jon: That doesn't surprise me at all.

Rob: Where do you think the states are right now? Is there any ability for something to happen at the non-federal level on fraud or scams? I'm curious whether you think there's any action there.

Jon: State AGs and other state enforcement authorities can be exceedingly helpful. There's a lot of conversation about what they're doing in antitrust, which I think is more good than bad. The same is true in consumer protection and stopping fraud. Still, with the exception of California, New York, and maybe one or two other places, they have a very finite amount of resources. So on consumer protection and fraud matters, they'll bring a few cases, but they're mostly partnering with the FTC and others. It's important that they keep doing this work, but I don't know that they're a force multiplier at this point.

Rob: I've talked with a number of people about this, including some state AGs. There's a lot of good intention, but it has to be met with follow-through, and sometimes that's not all there. The other interesting thing: the big companies being targeted by these scams and bad actors talk about sharing data with each other. There's a lot of that discussion, but I feel there's more they can do, especially with international actors. When I was at Facebook, we sued various scammers, sometimes knowing we wouldn't necessarily be putting anyone in prison, depending on where they were in the world. But I think there's more these companies can do to protect their own platforms, frankly.

Jon: I agree. To the extent malefactors use their platforms, it's critically important that they share data with law enforcement. We had a lot of help from Microsoft, and I believe some from Facebook and Google, on various cases we brought when I was at the FTC. I'm sure that's true now. It's also probably a good idea to find a way to anonymize the data so it couldn't be treated or seen as anti-competitive. Since many malefactors use multiple platforms, sharing information about the bad guys creates efficiencies and a higher likelihood of stopping people trying to rip off consumers.

Rob: Exactly. Something that isn't always understood: if bad guys are on an ad platform, they're also hurting all the other advertisers, because they're using tactics that shouldn't be allowed on the platform. I don't think we've seen people go after that much yet, but I'm sure we will at some point.

Jon: I think so too. It's a tough world out there, Rob. What can we do about it?

Rob: It really is. From your vantage point, Jon, how do you see AI changing the way law enforcement and regulators think about the threat landscape? Have you talked to people who are seeing it accelerate things or change the landscape in a meaningful way?

Jon: Sure. With the bad guys, they're not just asserting things anymore. They're manufacturing evidence, in a sense. The presentations are much more sophisticated. And just as we use AI for so many good things, the scale is much greater. So I'd say law enforcement authorities are much more worried. Typically, the technology for stopping something bad lags behind the bad thing happening. So I think they're quite worried. The National Consumers League, where I'm on the board, is holding a conference starting tomorrow on AI and fraud and AI and healthcare. Healthcare is a promising scenario; fraud is a disastrous one. I saw a statistic that Sally Greenberg, NCL's president, is using: $196 billion in AI-related fraud last year. That seemed a little high to me, and I've seen lower estimates. But even if it's on the high end and sweeps in other types of fraud, that's a lot. Think about it: there are 350 million Americans, and if they're victims of $100 billion to almost $200 billion in fraud, that's a lot of extra zeros chalked up against every single American.

Rob: 100%. One thing I've seen recently is very long and complex workflows, or pieces of media, that really take someone down a path. I'll share some examples in the show notes so people can see what I mean. There are a bunch of these celebrity "Alzheimer's cure" scams. There are fake 60 Minutes videos with deepfaked celebrities, and the video itself is 60 to 65 minutes long. It doesn't get to the payoff, the thing they want you to do, until 30 or 35 minutes in. At first I thought, wait, is this really a scam? But they keep doing it, so people must be staying, consuming this nonsense, believing it, and eventually buying these $200 items, these recurring subscriptions, at the end. It's very similar to what we've seen before with negative-option rebill nutraceutical products. But it's really insidious.

Jon: I'm surprised, as you are, that they have such a long lead time into their pitch. I guess they've found it effective. It gives them more credibility as they're trying to scam people. I've seen some of those, actually. I haven't clicked on them for more than 30 seconds; I don't go the full 35 or 60 minutes. But it's amazing, the quality of the work and video you now see on the internet that you did not see 10, 15, or 20 years ago. At some point you ought to go see Lois Greisman, who heads the Division of Marketing Practices at the FTC. Her group brings all the fraud cases. I'm sure they'd be very interested in what you're seeing.

Rob: We're definitely sharing what we're seeing with some folks. Part of what we're also trying to figure out is the right way to structure sharing. My sense is that the quicker we can get this information to the affected parties, the better. Any one of these scams touches 20 or 30 different entities: whoever's hosting the domains, the images, the videos, the ads, everything. A lot of providers are probably unwittingly participating in these scams.

Jon: I think that's right. You mentioned domain names. We had a long-running battle with ICANN, the Internet Corporation for Assigned Names and Numbers. I don't know how much you know about ICANN. You probably know too much. It's mostly controlled by its members, who are in the domain name business. So they want cheap prices, and they don't care much about empirical evidence of bad actors. We could not get them to authenticate domain names in any way, and I don't think they do now, because it would cost an extra dollar or two and they just don't want to pay it. We tried for a while, and there were some congressional hearings. But sometimes, even if you keep hammering on things like that, they just take the blows and move on. There's a similar problem with Do Not Track, but that's for a different podcast.

Rob: A different podcast with you someday. Wait, tell me about the Do Not Track thing.

Jon: We came up with an idea at the FTC. Computers are the consumer's property. Some people disagree, but I believe strongly, and I think most people agree, that they're not the property of advertisers or corporations. You should be able to control your own data. So we believed consumers should be able to prevent tracking. In my last year at the FTC, we started an initiative to collaboratively work through a set of standards so consumers could prevent the collection of their information. We got the advertisers to make some very small concessions. But I think they thought it was one commissioner's idea, and he cared about it a lot. That would have been me. They figured when he left, the issue would go away, and they were entirely right. If I ever went back to the FTC, which I doubt I will, and I doubt anyone would want me to, we would simply start bringing unfairness cases against companies for collecting consumers' data. These companies would tell you there may be some pro-competitive benefits to collecting information. We worked through the W3C, the standards body for much of the web. Tim Berners-Lee, I think, just passed away. They wanted to be helpful, but they couldn't be that helpful either. Because if you don't have regulation, or punishment for violations, then every company, even the ones that probably believe what they're doing is wrong, will grab. You know this from working at some very important corporations that do some very good things: they gravitate to the lowest common denominator. They're not scammers like the ones we're talking about today. But they want to make profits, and they see competitors doing things they didn't necessarily want to do but feel they have to.

Rob: One thing I struggle with is what a reasonable way would be to require these companies to report on things correlated with safety and security outcomes, especially in a world of AI where it's easier to fake things. I doubt regulators will be able to keep up with everything all the time. But there should be something in between, where I can get a sense of how safe these platforms are, and companies can and should report some level of this to the public. Is there a way to make that a reality?

Jon: I think you'd probably need some degree of legislation to require that kind of reporting. It's the kind of thing companies are reluctant to do voluntarily, particularly if it's public. Some pieces of legislation have had safe harbors for beneficial acts; I'd have to think more about it, but maybe you could do something like that. Or you could require reporting data to some entity. I don't think my former agency has the capacity to do that unless it also becomes a data regulator. That was discussed a few years ago, but it's not really under discussion now. In front of the FTC's building, there's a statue of a man restraining a giant horse. We've all believed, though no one has told us exactly, that the horse is the dynamic energy of capitalism. The man is restraining the horse. He's not knocking it down, and he's not letting it run past. He's guiding it. That's a metaphor for what you want: the dynamism of capitalism and innovation, but also some hand of regulation, whether firm or gentle. Sometimes I thought the Biden administration's hand was a little too heavy and stifled innovation. In the Trump administration, it's like they're waving the little flag at the bull, saying, "Just go by here." So to your point, it would be better if we had that data, but I'm not sure we're capable of striking the right balance. Congress, of course, has struck so many right balances in the last 10 or 15 years.

Rob: It's been tricky these last years. I think consumers sense that more can be done, that these platforms can do more, and they're probably right. But there's also a lot of very good work being done by people at these companies. So part of my thinking is: what's the data, and how do you empower the people inside these companies to show what they're doing and argue for resources internally if they need them?

Jon: You were inside those companies, and now you're trying to get them to work together. What have you found?

Rob: There's a wide range of dispositions. I think more can be done to work together across companies than is being done, and there's a lot of room to create collaboration. Many people feel they're working as hard and doing as well as they ever have on these problems. Others see the writing on the wall with AI images, video, and so on, and they're very worried and want to do more. So it's about having more conversations and bringing these people together. It's not just sharing data and signals; it's sharing techniques and tools and facilitating those conversations. That's what needs to happen at this point.

Jon: The government is much more in a self-regulatory mode than a regulatory one now. But do you think the FTC or the administration can play a role in encouraging that? We're having that debate on AI and catastrophe right now. Maybe we could have it on AI and fraud, too.

Rob: I think so. If companies can share how well they're doing on certain things, and bring in objective third parties to help assess what's happening, those are all positive. They'll increase our understanding of what's going on. Completely grading your own homework is not okay. But I also don't think asking the government to grade your homework solves the problem. It's something in between, where you facilitate. I always use the example of the Insurance Institute for Highway Safety doing crash tests to help us understand car safety. They have a financial incentive to do it well. It's not exactly the government, but there are a bunch of government-style aspects of insurance that make it more than optional. Something like that could be an interesting way to go. And to your point, there could be some kind of safe harbor or liability shift if you do things a certain way, which would create more incentives for this to happen.

Jon: One other problem we've been seeing, a manifestation of all this AI and fraud, is a loss of trust in the internet by consumers. Polling was showing an increase in that, though I haven't looked at the most recent data. That's a bad thing for society.

Rob: I think that's right. I also look at the kinds of ads that show up on news websites, and they give me less confidence in the news source. I'm probably not normal; the average person isn't paying as much attention to these things as I am. But a lot of things are reducing our trust in the information environment, unfortunately.

Jon: There are some new tools. I give the Lina Khan FTC credit for some new regulations. Some were struck down, including one I liked very much, click-to-cancel. Others, like the government and business impersonation rule, are very smart. It allows penalties against people who impersonate government and businesses, though you've got to catch them. There's also a new rule against fake reviews and false testimonials. This is the way around the no-equitable-relief problem: if there's a rule violation, the commission can get equitable relief and fine malefactors. I'm sure when they bring more cases there'll be constitutional challenges, but hopefully those rules will be upheld, and that will be modestly helpful. But we need to do more. There's no doubt about that.

Rob: What's your take, Jon, on business verification, ID verification, know-your-customer requirements? They'd add friction for businesses transacting on platforms, but perhaps increase certainty about who the business on the other end is.

Jon: I'm generally supportive. You have to accept a little more business friction, maybe a slightly higher cost and slightly lower deal-completion rate, in exchange for more honesty and integrity. Stepping back, I think most legitimate companies would make that trade if their competitors had to do it too. You can see a bit of this with the Children's Online Privacy Protection Rule. Facebook and others don't want to verify consumers' ages, or index the databases they have against each other to get something like 90% certainty, because then they couldn't advertise to those people and would be liable for violations if they did. You have to understand the facts on the ground in a particular circumstance. But again, it's that notion of not stopping the dynamism of capitalism, while not letting it be unfettered. It's that sculpture in front of the FTC. We'd be a better society with less of this fraud. I get the notion that, with AI, we're competing against the Chinese and want to be the leaders. But you have to have some guardrails, and, to your point, a little more friction in identification across platforms. We worked on that in a couple of contexts: kids, ICANN, others. I think it would be very helpful for reducing fraud online, and at a modest cost, too.

Rob: This reminds me of one I saw a couple of days ago that I think I mentioned to you. There was an image with a fake play button, like a video. If you clicked it, it pulled up Apple Pay and charged you $0 for a one-day trial. After the one-day trial, it would charge you $34.90 a month. I thought, this is crazy.

Jon: Did it actually tell you that? Was it in tiny letters?

Rob: It did tell you, in tiny print at the bottom: a $34.90 monthly charge after your $0 one-day free trial.

Jon: Unbelievable. And yet responses to problems like that can happen. Let me tell you how Congress enacted ROSCA, because the FTC was very involved in writing the legislation. I'd been on a trip with my kids and got a discount coupon for a hotel, say 50% off. I clicked on it and stayed at the hotel. I believe I canceled the service, but either way, it got embedded in my credit card at $6.99 a month, and it changed its name to "City Shopper," so you wouldn't know it was a recurring charge. I probably should look at my credit card statements more. But I finally asked my wife, "What's this City Shopper thing for $6.99?" She didn't know. I called Citibank, my card at the time. I don't use Citibank anymore, possibly for that reason. It was a total scam where they'd changed their name. So I started asking members of Congress and my own staff, "Has this ever happened to you?" They said, "Yeah, it happens all the time." For one of them, it had gone on for a year before they caught it. We went to see the staff of Senator Rockefeller, who chaired the Commerce Committee at the time, and I think Senator McCain's staff. They loved the idea of legislation, and we wrote ROSCA. And much to my chagrin, the first time I saw ROSCA used was against one of my clients when I was practicing law, though very possibly deservedly so. So maybe there could be that kind of random, serendipitous piece of legislation that comes about in ways no one expected and turns out to be very helpful in the AI fraud space.

Rob: Hopefully we'll have more conversations about that whole side of things. There's definitely interest in figuring out how to protect reality and protect people. We'll see what the next version of this is.

Jon: Thank you very much for having me, and good luck with your endeavors at InfoHawk. We hope it'll be part of the solution.

Rob: Thanks, Jon. I really appreciate all your support. It was great to catch up and to get some historical comparisons for all of this.

Jon: It's great. What do they say when you take someone out of a crypt? Disinter me anytime you want for a discussion. I'm very happy to be here, and I do like fraud stuff at the FTC. Can I just say this? Long before I got there, long after I left, today, and long after the crew running it today leaves, the FTC will be doing some very good work in the anti-fraud space despite its limited resources.

Rob: Thank you.

Jon: Amen.

← All Won't Fix episodes