Episode 6

Stopping Scams for Consumers

with Tate Jarrow of Rebound

Show Notes

Tate Jarrow is the Founder and CEO of Rebound, a consumer anti-scam company. Before founding Rebound, Tate was an Army infantry officer and Airborne Ranger, and then a Special Agent at the U.S. Secret Service.

At Google, he helped start a company called Beacon through the Area 120 incubator, which was then acquired into Google One.

Key Highlights

  • What Rebound is building: "Antivirus but for scams" — software that sits on a user's device across macOS, Windows, iOS, and Android, sees what the user sees, and alerts when it detects an inbound scam. Currently in alpha, heading into paid beta within the month, with general availability targeted for summer.
  • Why now: Normal people have zero real defense against scams. Law enforcement don't have resources for individual cases, and platforms are hard to reach for recovery. Existing consumer cybersecurity is rooted in 20-year-old problems (antivirus, credit monitoring) and isn't built for AI-powered, personalized, scaled attacks.
  • "You can't arrest your way out of cybercrime": Cyber criminals run transnational organizations as businesses with P&Ls, so the real lever is changing the economics.
  • Google: Tate started in legal/investigations chasing cybercrime actors on Google platforms, got frustrated by the gap between business incentive and what could actually be done. Two of his Area 120 teammates are now on the Rebound team.
  • Scam overconfidence: Tate shares that a GASA study found the #1 predictor of being scammed is confidence that you can spot one — overconfidence is the actual risk factor. Every demographic gets hit.
  • Regulation and data: US regulation is 20 years behind. The real risk now is social engineering powered by leaked addresses, phones, emails, and contacts. He wants companies held accountable for the social engineering risk they create, not just PII in the narrow legacy sense.
  • "Caring guardians": People in tech are the de facto security help desk for their parents, friends, and families. Rebound is building features so a tech-savvy family member can have visibility into risk across the people they care about — plus in-app trust verification (one-click identity check) for the "is this actually my friend messaging me?" problem.

Chapter Timestamps

  • 00:00Introduction and Background
  • 01:26Rebound's Mission and Product Overview
  • 03:39Technical Implementation and Current Status
  • 04:45Motivation Behind Consumer Protection Focus
  • 07:45Google Journey and Area 120 Experience
  • 14:59Law Enforcement Perspective on Cybercrime
  • 18:30Evolution of Cybercriminal Organizations
  • 21:07Current State of Consumer Protection
  • 30:04Regulatory Environment and Government Role
  • 37:25Community Protection and Cross-Platform Challenges
  • 43:00Product Vision and Future Plans

Transcript

There may be transcription errors: we apologize for those in advance.

Rob: Hey everyone, welcome to Won't Fix. I'm excited to be talking to Tate Jarrow today. Tate and I worked together at Google, where we collaborated on the Google One VPN, which was also part of the Pixel phone. My team built that VPN.

Before Google, Tate was a West Point grad, Army Infantry Officer and Airborne Ranger, and then a Special Agent in the U.S. Secret Service, where he was named Special Agent of the Year for working on the Liberty Reserve money laundering case. At Google, he created a company called Beacon that was part of the internal incubator, which was then acquired — and that is how he ended up joining Google One. He's now Founder and CEO of a company called Rebound, a consumer anti-scam company focused on preventing scams and helping victims recover. So I'm excited to dig into that today. I think you'll enjoy the conversation, and as always, please give us your feedback. Thanks.

Rob: Hey Tate, how's it going?

Tate: Hey Rob, it's going well. Good to see you.

Rob: It's been a while since we were both at Google, but it hasn't been that long since we spoke, and we've kind of kept in touch a little bit since those days. Give us a bit of an introduction of what you're working on now, and then we're going to jump into some of your background and some of the very interesting things you've done.

Tate: Yeah, it's great to see you. Thanks for having me. Right now, I founded a startup and we're working on scam protection for individuals. The easiest way to think about what we're doing is it's antivirus, but for scams. How can we deploy software on people's devices that's paying attention, and when it identifies an inbound scam, it shoots up an alert — just like antivirus has done for decades? That early alert is really critical to protect users from accidentally falling into a scam. That's what I'm building out right now. We are in alpha. We have a product across all four major platforms, and we'll be doing paid beta within the month. So we're pretty excited.

Rob: That's awesome. We've talked about this topic a few times. For everyone, I know I have my own definitions and ways I think about it, but what do you think of scams? What is a scam? What's not a scam? What's in scope for the protection you're looking to offer?

Tate: It's a great question. The way I think about it is: any inbound communication where it's attempting to deceive the user and get them at some point to give up information or give up money as part of that communication. Communication is really broad, but the way I think about it is what does a user see, what does a user hear? From the user's perspective, it's a very broad category because they get exposed to many things. The technical approach we take is we see what the user sees. So it's really a wide range of things — it can be an email, but it could also be something you see on a website, because written communication in a browser is communication. It's a very broad answer, but that's how I think about it in my head.

Rob: You said you're in alpha. Practically speaking, what does it mean? What have you shipped and what are your plans, to the extent you can tell us where you're at in the process?

Tate: We've shipped a desktop app on macOS and Windows, and Android and iOS. Our desktop app is in alpha; our iOS and Android are working, we just haven't shipped them to external users yet. We're dogfooding them, to coin a Google term. Functionally, it's an app you install on your device. What we're doing is, like I said, seeing what the user is seeing. We get user permission to have visibility, and then we're scanning for scam indicators. When we identify them — it's cross-platform, cross-domain — we throw up an alert and explain to the user why we think something is suspicious or a scam threat.

Rob: That's awesome. I want to talk more about the product, but first: why choose to work on this space? What's the motivator? Then we can talk about the background and how you got to Google and how that experience was. Because I think you probably have a different experience of Google than some other folks — and we'll get into why that might be. You've had kind of an interesting experience there. Tell me a little more about the motivator for wanting to work on this pretty difficult but very important problem.

Tate: The fundamental answer is I think there's this huge gap where normal people just don't have the resources to protect themselves in this space. That's the perspective — how do we help normal people? My family, your family, my parents, my siblings, our friends. I always tell the story: when my mom gets scammed, nobody cares. You call the local police, they're like, "What do you want us to do about it? We don't have the resources." You call the FBI, you call the Secret Service, they're like, "Call me when it's a $10 million loss." And then good luck getting help from a platform for your individual problem. Some places you can't get a human. Instagram is famous for this — people have their accounts hacked and there's no one to talk to for recovery.

The normal person is really left out on their own with no resources. And the existing products in the consumer cybersecurity space are rooted in problems from 20 years ago. They're rooted in antivirus, or they're rooted in credit monitoring. But the products out there to help people in scam situations — especially now that we're seeing personalized, scaled, AI-powered attacks where you can no longer rely on a misspelling to warn you about a bad email — I think normal people really need this type of help. That's what motivates me and was really behind the founding of the company, approaching it from the individual's perspective, because I think it's been neglected for a long time. That's not to say this is the only solution in this space — we need multi-dimensional ways to approach the problem. But this is where I felt really passionate.

Rob: We're working on this more from the company's perspective and trying to see if we can cut it off at other points. But at the end of the day, I feel similarly that there's a lot of this kind of stuff that's just neglected. Folks haven't been focused on this necessarily. And also, with the kind of AI models and tools being used by the attackers, there should be so much that can be done by defenders as well, both on behalf of consumers and companies. So it's an important set of work.

You have a background where you worked at Google, but you came in — I think your company was acquired, or you worked on a product that was essentially acquired. Tell us more about your Google journey.

Tate: I was at Google a little over five years. I started at Google behind the scenes in legal, in this investigative capacity where we were looking at cybercrime actors that were either leveraging Google platforms or taking advantage of Google platforms. The idea was: let's identify the individuals. We weren't responsible for blocking the activity, which is what a lot of trust and safety does, but we were like, let's find the people and then try to cut them off from being able to do this, and also give them a real-world consequence, either through lawsuits or referrals to law enforcement.

I did that for about a year, and I got a little frustrated because there's always a gap in every business between the business incentive and how much could actually be done. That gap is frustrating. I felt like I was always pushing to do more, and the business incentive was like, "No, that doesn't make sense." So I decided the way I wanted to approach helping people at scale was to build things.

At the time, Google had this great internal incubator called Area 120, where anybody in the company could pitch and get funded to build a startup. I ended up pitching as a founder — we ended up calling it Beacon. The idea was similar to the approach we're taking now, from the user's perspective. Google does a great job of blocking — email spam is a great example. But even if you're 99.9% effective, 0.1% gets through. So how do you help the user with that 0.1% they're going to end up seeing? We built an app designed to help users improve their personal security and privacy. We analyzed what they were doing, told them the risk, and gave them the ways to improve it.

Built that company, and then we got acquired back into Google, into Google One. This is where you and I met the first time. Google One had "you pay for storage" — paid Google — but they also had this hypothesis that people would pay for advanced security. At the time, they had one product, which was the VPN, which your team was instrumental in building. Google One wanted to build in more features around advanced security and tell a story. That's where our app came in. Unfortunately, shortly thereafter, Google One got reorged into Photos. Photos didn't really care about security, yada yada yada, AI. Now Google One does storage and gates AI features. So yeah, that's my Google journey. I think that answered the question.

Rob: So I guess it's more accurate to say you were a Googler, you started a company within Google, Google acquired that company, and then shipped that, unshipped that — decided it was great, decided it wasn't great. It sounds like a very Googly story, to be honest.

Tate: Yeah, that is accurate. And that's really my introduction to entrepreneurship. Area 120 — it's too bad it got discontinued and rolled up into Google Labs, but it was a great place. Everyone who went there was self-selecting because they wanted to ship fast, they wanted to build something new without the constraints of shipping products at Google, which can be a very long and frustrating process. On my team right now, we have two people who were on my Area 120 team building with us. Pretty fun experience. That's really why I'm where I am now — because of that program.

Rob: It definitely was a very cool program. I'm sorry it doesn't exist in the same form anymore. I think you probably talk to folks like this all the time. I talk to folks all the time who are in big tech companies and they want to start something, or they wonder how to do it. I normally say two things. One: just be sure you're the person who has to make this thing exist, and there's no other way it could possibly exist without you, because starting stuff is really hard. But also, starting stuff is really fun. It's really hard and really fun. The other thing I say is: you really need to work on it with other people, in my opinion. It's really hard to be a solo founder. But if you have people you've worked with before, who you trust and enjoy working with, it's great. I feel very lucky about the co-founders I have, who we'll be meeting in our discussions in a future episode — they're great. It sounds like you have some good folks you're working with as well.

Tate: I do. And I think it's really important now, especially with how easy it is to build things because of Claude Code, basically. The things that used to differentiate and make companies win was software development, and now anybody can really build anything very cheaply. But the reason I bring this up is I think it's important to have people on the team who have different perspectives. A competitive advantage is going to have to come from different perspectives. Maybe it's go-to-market, maybe it's distribution, maybe it's a data play, maybe it's model development — but it's not necessarily just "I have an idea and I'm going to be the one to build it." You need more to have a defensible company, especially now. My co-founder is great. He's a former Googler as well. He was in trust and safety for a long time. Having people with different perspectives on the team is critical to survival for businesses, especially startups right now. I totally agree with you.

Rob: The other thing that's really interesting about your background — I want to talk a little bit about it — is you were in the military, in law enforcement, in the Secret Service. So I think you have a very important perspective for this subject area. I remember one time, maybe about two years ago, I was chatting with someone on a plane, and someone was trying to get me to go buy gift cards for a company I was an advisor to. They must have scraped LinkedIn and said, "Okay, Rob works for so-and-so," and they were like, "Go buy the gift cards at CVS or something." I was chatting on the side to a friend in law enforcement, saying, "Is there a law enforcement path for dealing with this?" And they were basically like, "Not really. There isn't really anything we could or would do in this case." I'd love to hear a little more about how your background working on that kind of stuff informs what you're doing, and how you think about the need here or the opportunity.

Tate: That's a good point, thanks for bringing it up. I did eight and a half years as a Special Agent in the Secret Service — six and a half in New York, which is where I'm based now, and then two in DC. When I was in New York, I was on the cybercrime squad, and that's how I got into this whole area.

Cybercrime is a tale of way too much bad guy volume and not enough resources at any level to even make a mediocre dent in it. Through my time, I was involved in some really big investigations. For example, very few people will remember this, but in 2013 we took down a digital currency called Liberty Reserve, which was a centralized digital currency made by criminals for criminals — I think that's what the DOJ press release said. We were able to take it down, and it took out the currency for an entire ecosystem. This is what carder forums were using, high-yield investment programs, all sorts of money laundering. There were six to eight billion dollars of transactions happening, and we took it all down. It evaporated overnight. All the criminals had to migrate to something, and they went to Bitcoin because you can't take down Bitcoin — it's not a centralized server.

That impact was amazing, but it was basically like one month of impact. Did it really change how cybercrime happened? When you arrest people, I'm arresting one person or five people, but there's another hundred thousand doing it. Over these experiences, what I really learned was: we're not going to arrest our way out of this problem. We're not going to prosecute our way out of this problem.

A great example — right now, a lot of people are touting that the US Attorney's Office in DC is going after these Cambodian scam compounds, which is a huge problem. But they're like three years too late. This has been a problem for years, and the amount of harm — I mean, billions of dollars, and of course the people in these compounds are human trafficking victims. That has been happening for years, and only now, three to five years later, is the US federal government finally catching up. And okay, so maybe now they're not in Cambodia, they're shifting to Indonesia, they're shifting into Africa or other countries.

All of this to say: law enforcement has a role to play, but the step change of reducing harm for normal people is not going to come through that path. It's going to come from platforms. It's going to come from societal change in what people are doing, how they're protecting themselves. This has framed my approach: I want to get on 300 million people's devices to reduce the harm 300 million people are seeing. If we can do that, we will change the ecosystem. We'll change the math for what it takes for a scammer to be successful.

The other thing I learned from that experience was about cyber criminals. For a long time we've had this stereotype of "it's a teenager in Czechoslovakia" — not even a country anymore, but the Czech Republic — or someone in their mom's basement. The real answer is that these are transnational criminal organizations that run like businesses. They have profits, they have costs, they have salaries, they have trust — they run it like a business. That's important because they think about the economics of a scam the way you would think about running a project at Google or Facebook or any company. If you have that perspective, then it changes how we think about the solves, because it's not about prosecuting criminals — it's about making the economics of the criminal activity not worthwhile anymore, or much more expensive, so they can do less harm. I know you think about this a lot as well. Fundamentally, my journey has led me to that realization. I'll stop talking because I can go on forever on this topic.

Rob: Maybe the cynical way to look at that — one of the other guests, a former Meta and Google friend, said that the goal of the trust and safety team is not to solve crime. You're not going to solve crime, but you want to really move it off of your platform so it goes somewhere else. So I think we always talk about raising the costs and making it less profitable, but the footnote on that is: asterisk, on our platform. And then hopefully we don't see it on our platform anymore. We know they're going to go somewhere, so they go to some other platform. How do you think about that? If you look at it from the consumer perspective, you don't want the people using your app or service to be scammed, but the bad guys are businesses and they're just going to go somewhere else. How do you think about the "where things move" aspect of this?

Tate: There's a very deep society-level question — really a global society question — which is: why are people turning to this type of criminal activity? What are the economic conditions where they live, where this is the more viable option, the lowest-risk, highest-reward option to survive? That's the global society problem we have to solve, but that's maybe out of scope for this conversation.

The way I think about it — and it's a really good point that people have to move somewhere — but if you think about scam protection, especially from an individual's perspective, we're basically at zero. We have zero defense. The best-in-class defense is literally an email from your bank saying "watch out for scams." That's what a consumer gets. That's best-in-class.

A scammer doesn't have to — I think about this attacker-defender dynamic we've lived in cybersecurity at the enterprise level for decades. As defenders develop technology to defend, attackers have to adapt. It's a constant cat-and-mouse game. If you think about scams, scammers haven't had to adapt ever. The Nigerian prince email scam has existed for like 20 years, and they still exist. EasyPass text message scams have been around for at least five years. Nobody's figured out how to block them, so scammers haven't had to evolve. We're really starting from scratch.

The amount of work we can do to start creating robust protections for as many people as possible — we have like 10 years before we even get to a point where it's like, "Okay, now what are the scammers going to do?" My dream is that we get to a place where we're protecting everyone who has a device. What it will mean is attackers will evolve. Instead of moving from "this person is protected, I'll move to someone who's not protected," they'll be like, "Everyone's protected. Now I need to change my tactic." What we're building as a company is a feedback loop. As the attackers change their tactics, we'll know first — I know you're thinking about this too from the ad perspective. If you know first and quickly, then you can get protection across the network quickly, and that forces a bad actor to evolve again.

Right now, again, it's like zero. Attackers have no incentive to really evolve. I want to get us from zero to one, and then we'll get from one to five, then from five to 10, then 10 to 100 — and then we'll see where we are. Almost anything we do is going to be improvement on the current state of affairs, which is really sad if you think about it, because people have been losing. This is the biggest crime in America. It's the biggest crime globally by far. If this were people's houses getting robbed, no politician would talk about anything else except how to solve the fact that 25% of Americans are getting their house robbed every year. But it's cyber, so nobody really talks about it. We certainly have not invested the resources you'd expect when a quarter of the country is getting scammed on a yearly basis.

Rob: Yeah, we're just not set up for this. And we're not even really set up to understand how computers work, frankly. Even people who are pretty tech-savvy don't really understand how all of this fits together — it's quite complicated. But then, our law enforcement is not set up, none of our laws are set up, to deal with extraterritorial folks who are reaching into your machine or sending you a message or an email.

The other thing that to me is worth debunking — I'll just use the EasyPass thing you mentioned. A friend of mine from college, smart, very at the top of their field, works in Hollywood, went to a great school, very smart — they got scammed by that. It just so happened they had just driven through some toll bridge or something, and they got this message, and they were busy, and they're like, "Oh my gosh, I should pay this." They said the scammer was stupid because they charged their credit card like $500 — they could have probably gotten away with $10. But I'm like, well, I don't know. They must have some sense that this works enough of the time to make it worthwhile than trying to make it work 50 times for $500.

But the thing that's also worth talking about, especially if you're working on a consumer product — this came up in my conversation with Tom Wright — he said that sometimes people seem to think that folks who are getting scammed are stupid, and I just think that's not necessarily true. Folks who maybe are unsophisticated in certain areas are disproportionately getting targeted, but I also feel like people don't talk about getting scammed as much, and that's something we need to open up the aperture for.

Tate: I totally agree. There's language we use when we talk about scams that puts it on the victim — like "tricked." There's an implication there. You don't say "you were tricked into getting your house robbed" — people don't insinuate that a victim of a physical crime is at fault in most cases.

That does matter, because one: shaming victims is bad — it stops reporting, it makes it harder for victims to get help. But the other thing, which is probably the worst consequence, is that it makes people think they are not at risk. If you can say, "Oh, it's somebody who was dumb or fooled or doesn't know tech," then you can justify that you don't have to worry about it because you're not dumb, you know tech. And that's wrong.

There's this great study the Global Anti-Scam Alliance did — they published it in the fall of 2025. It's a global survey, and they asked people how confident they are in identifying a scam. I think 76% of respondents said they are confident. Then they correlated it: the number one factor for being a victim of a scam is being in that group. If you think you can identify a scam, you are statistically more likely to be fooled because you're overconfident. That's the scary thing — or one of the very scary things — about insinuating that it's a victim's fault: it makes other people think it's not going to happen to them, and then their guard is down and they're more susceptible.

Look at the data: IC3, which is the FBI's report; FTC, the Federal Trade Commission in the US; GASA. Every demographic is hit by scams. The classic one is that young people are hit by scams much more frequently than old people, but older people lose more money. The entire demographic is susceptible to this. People understanding that is so critical — recognizing that you can't recognize these on your own. Everybody can be fooled, either by circumstance or because the scams are so realistic.

A great example are AI deepfake audio calls, which are devastating. For those who don't know: a bad actor has gotten a recording of a loved one's voice — either from an Instagram reel or your voicemail message — and then they replicate the voice in a situation that's scary, like the person was arrested or kidnapped. They call a loved one who hears the voice and is authenticating this person through the voice. Of course they're going to do whatever that person says. This is the type of scam we're going to see start happening more at scale as AI allows the scalability and the ability to get this information in ways that were more expensive before.

It's really scary. We need technology to step up and help people, which again is why I built this company. But it's at every level — it's at the platform level. We need technology to identify these things in ads. We need technology at the voice carriers, the phone carriers, to identify suspect phone calls early and stop them from coming in. All right, I'll pause there.

Rob: One of the questions I generally have about a lot of this stuff: the fact that most people have smart devices means that you could potentially count on the government, or local countries or municipalities, to provide some level of protection or service to their citizens in a way that maybe wasn't possible even a decade ago. What other stuff do you think is owed to citizens, versus should be something that private companies sell? Obviously it's important for private companies to have the ability to innovate. But what should actually just be part of the law, or the way in which carriers operate? Where's the line there, you think?

Tate: It's a great question. To me it goes back to: where does regulation play a role, and how valuable is that regulation? Is it actually solving the right problem? India, I think very recently, tried to mass deploy a scam protection app on people's devices against their will. I think it was India. There was huge outcry because people are very worried about government surveillance and government-installed things. In the United States, what we've seen in the last few years is an extreme increase in sentiment and concern around government surveillance. We're seeing this with people protesting Flock surveillance — the cameras and the automated license plate reading, just as a couple of examples.

Where government has a role to play is in the regulatory environment. But the United States, unfortunately, is a very poor example for a regulated environment in this space. We can't even pass comprehensive privacy legislation that protects people's data from being sold to track them, which is one of the core problems — data brokers and how easy it is to find information about you, which of course scammers can leverage to target you. You gave the example of someone finding where you worked and targeting you because of that affiliation.

The other thing I think about specifically is regulation around what companies are expected to do when there are compromises of information. Look at data breaches. About 20 years ago, as companies — Target was one of the biggest ones — were losing people's personal information because they'd been negligent in their security practices, the regulatory environment started mandating that these companies provide identity credit monitoring. Some of these companies, to avoid mass litigation, would provide identity theft monitoring services. The thing is, this playbook is 20 years old, just like our computer crimes playbook is like 40 years old at this point.

What regulation needs to do is catch up to: where are companies responsible, and what should they provide when (1) they make a mistake that leads people to be more likely to be scammed, or (2) they have control of a platform where they could intervene if they spent more money? This is like the Facebook — you know, 10% of the revenue from Meta was shown in a Reuters investigation to be due to malicious ads, and they knew it. That's like $16 billion. So that's where the government has a place to play.

But the idea of government-provided interventions, because of the lack of trust people generally have, I think is a challenge. Although New York City is publishing an app — they're paying for an app for other people. So there's a third-party model that could be interesting where the buyer is the government. There's probably more appetite for that.

Rob: If I had a nickel for every free credit monitoring offer I have because of data breaches... My co-founder is currently involved in a series of discussions about gift card provision as well, because apparently I need gift cards for a really important client presentation. That's interesting — that's a direct example of LinkedIn scraping. These things are connected: the privacy, data breaches, data brokers, being able to craft something that would be more likely to get people to engage on a scam or a scammy offer. That's certainly one of the drivers of this stuff, unfortunately.

Tate: Identity theft is something that Americans — I'll talk about America because that's where I have the best perspective — understand and are worried about. That's because of decades of these breaches and lawsuits and regulation. But that risk is basically: everyone has the same identity theft risk because all of our personal information for every single person in the United States is out there to be had. So identity theft as a risk — there's nothing you can do about it.

The real risk now is social engineering. Social engineering attacks — really, all scams are social engineering attacks — are more effective when they have accurate personal information about you or the people around you. That's the real danger in these data breaches. It's not that my Social Security number is exposed — you can find my SSN. I was in OPM. Every American's SSN is exposed. But when you expose my addresses, my phone number, my emails, my contacts — that is a gold mine for scammers to create a more effective, higher-payoff, personalized scam.

That's where we need to go from a regulatory perspective: hold companies accountable for creating more risk from a social engineering scam perspective, because identity theft is too late — the cat's out of the bag on that one. That's the future I'd like to see: hold companies accountable for losing — you know, what they say is, "Well, it's an email, it's no big deal." Well, an email and my name — that's a really big deal, because now a scammer has a way to contact me and fool me. Companies are like, "It's not PII, it's email." That thinking is 20 years old, and we haven't caught up. The knock-on effects of data protection, how we think about data privacy, how breaches are handled by regulators — none of that is caught up yet. That's creating more risk for all of us.

Rob: Coming back to the product side, I think there are some really interesting opportunities for consumer applications. One recent example: a friend of mine reached out to me on TikTok — sent me a TikTok DM. I'm like, "That's weird. I'm in a group chat with this person on WhatsApp. Why would they be sending me a TikTok DM?" Of course it wasn't them, it was someone pretending to be them. It started with "Hey bud." I'm like, "They don't normally greet me that way, either." Long story short, this person had tried repeatedly to get this account off of TikTok. Eventually I sent a message to someone I know over there. It came down, but then it went back up, then it came down again, then it went back up again.

My point isn't how robust the takedown mechanisms of the platforms are — we all have our own experiences with that. It's really just the fact that a lot of this is like a community effort. I'm reaching out to my friend, other people are reaching out to them, and we're letting them know they're getting impersonated. We're protecting ourselves, we're also protecting other people. By taking action — if they do get that taken off — they're helping everyone. How do you think about the community protection aspect of these kinds of consumer anti-scam products?

Tate: That's a really interesting point. We're designing some product functionality around this. The way we think about it: every individual has a community. Because of AI, your example is a great one — how do I know the person contacting me on TikTok is actually the person I believe? How do you verify somebody over the internet? How do you actually verify someone you know?

What you alluded to is: the way you did it, you had to go off-channel. You're like, "I've already verified them on WhatsApp or some other platform, I'm going to reach out to them and see if they're actually coming from TikTok." One of the things we're building is a way to do that within our app. If both people have our app and are authenticated, then with a one-click button you can get a trust check back and forth in the moment to verify someone's identity. The approach we're taking: let's build the communities where you can trust and have a mechanism to verify trust for your close community, then slowly expand out.

But what you're talking about is a broader issue around how do we share data across platforms, or how do we share data with companies. It's such a challenge because broader cybersecurity at the enterprise level has been struggling with this — with the ISACs and the sharing programs they put together — because companies are really nervous about sharing PII. In the cybersecurity community, regulators created these abilities, these free spaces where companies could do it without being worried about getting sued. They had the legal oversight or the legal protection to do it, but all they were sharing was IP addresses, or malware samples, or malware hashes — they're not sharing phone numbers, emails, handles, because they're worried about the PII.

From a scam perspective, this is the big challenge: scammers don't operate on IP addresses. I mean, they do, but the thing they have to cut off, to your point, is "this is a bad account. We need to kill this account." If JP Morgan learns that there's a bad account that forced somebody to lose money, they should be able to share that, and then everyone knows this account is bad — let's shut down its footprint on every platform. I always think about Gmail. If I know there's a bad Gmail account, they might have TikTok, Facebook, Venmo, a bank account. If everyone knew that email was bad, all of that infrastructure could get shut down instantaneously. The problem is nobody's willing to share that type of information.

Even GASA, the Global Anti-Scam Alliance, is trying to come up with an intelligence platform. Basically, the only things people are sharing are IP addresses or bad domains, which are basically IP addresses. That's not actually going to put a dent in scams, because scammers operate on phone numbers, emails — it's a different level of indicator of compromise. That needs to be solved. There's certainly a regulatory piece — companies are going to want legal protection before they share that information, because they don't want to get sued for giving up personal information. It's a really thorny problem, which works in the bad guys' favor.

Something else we know happens: bad actors, from the consumer perspective, come in on one channel and jump to another. Being able to see where these scammers are going — I come in on Facebook Marketplace and I jump over to Signal — platforms don't have that insight unless they can share. That's one of the advantages we have: because we're building the consumer-focused platform, we'll see that cross-platform. It'll empower us to have a different perspective than many companies have.

Rob: I think that's right. That's also another way for them to not burn all of their infrastructure — if you can connect those dots. If a scammer has a Verizon phone number, not just a VoIP number, or a WhatsApp account, or whatever — if you can connect the dots between those things. Sometimes these dots connect multiple entities, because scammers do lead gen for each other too. They've highly specialized their work, unfortunately. So all of this stuff, you need to be looking at not just from a single company's perspective, or even from multiple companies' perspectives — you also need to be able to look at it from a user perspective. That's a very important lens.

Tate, this has been a super interesting conversation. How can people find you and your team and your products, and what should they expect when they go there?

Tate: You can find me on LinkedIn. Tate Jarrow is pretty unique — until someone impersonates me. If you want to talk to me personally, happy to connect there. My company's called Rebound. We're at trustrebound.com. We're going through a rebrand, so that might change, but we'll auto-forward the domains, so it's fine. Trustrebound.com. Like I said, right now we're in an alpha release. When you go to our website, you can sign up, and if you're selected you can use our products for free and give us feedback so we can improve them. Our goal is to launch with a GA — general audience — launch this summer, so people can protect themselves and their families.

One thing we didn't really talk about — and Rob, I think you feel this as well — is this idea of what we call "caring guardians." We often have our own families, we have parents, we have people around us. We are tech-savvy. People know we're in the space and they look to us for guidance and help. My mom calls: "Hey, is this safe?" My friend calls me because her dad clicked on a link, and I have to give them advice on what to do. Part of what we're building into the product is: how can we help these caring guardians — these guardians of bigger units than just their immediate family — protect the people around them they care about, and give them insight so they have visibility on potential risk across their family? We're building that into our product because we think it's really important. It's not just you — everyone is worried about other people as well. So enabling that functionality in our product is one of our goals. I think that answered the question.

Rob: You really did answer the question. That's actually something people have approached me quite a few times about — "Is there a product you could build me, for my parents, so I can feel like they're not out there by themselves? I don't want to be watching what they're doing, but I want someone to be looking after what they're doing online in some way." So this is really a big need out there. We're obviously rooting for you, for lots of reasons. Really excited about it.

By the way, your antivirus example — and what you just said — reminded me of the first money I ever made with computers. I was 13 years old, and a friend of mine, his dad had some virus. I think it might have been a really long time ago. Basically, I took a copy of Norton Disk Doctor or Norton AntiVirus or something, went to my friend's machine, ran it, got rid of this virus, and the dad gave me 50 bucks. That was the first money I ever made with computers. So just knowing the tools to use can sometimes be helpful, even if you don't actually know anything. You obviously know a lot, so everyone's going to be in good hands — but I knew nothing back at age 13, except to know the right tool to reach for.

Tate: That's a great story. It's pretty amazing because Norton hasn't really changed very much since then. They're just hashing and matching a hash list.

Rob: It was really great chatting, Tate. I'm sure everyone is rooting for you, and we're looking forward to learning more and keeping in touch with how things are going with Rebound — or whatever you end up renaming the company to.

Tate: Thanks, Rob. It's my pleasure. If anyone made it through, they can tell I could talk about this forever. I will say: we need more companies in this space, we need more investment in this space, because the market is enormous, and as an industry — as a society — we're really failing at protecting people across every dimension: the platform perspective, the regulatory perspective, the consumer perspective. Smart people who are interested and want to build and work in this space — yes, we need more. The more the better. I'm always happy to chat and help anybody who's operating in this space.

Rob: That's awesome. That's why we're doing these conversations — because we want more people working on these problems, or at least thinking about them, being aware of them.

← All Won't Fix episodes