pplpod

pplpod

pplpod is a podcast about people, places and lots of other stuff. Each episode takes a deep dive into the lives, choices, and legacies of fascinating figures from history, culture, music, and beyond. From icons who shaped entire generations to hidden stories that deserve the spotlight, pplpod brings you closer to the people behind the headlines and the legends. Thoughtful, engaging, and story-driven, pplpod explores what makes these lives extraordinary—and what we can learn from them today.

  1. 1d ago

    Zero-Day Vulnerabilities: The Hidden Flaws Governments Pay Millions For

    You can use long passwords, multi-factor authentication, and prompt updates and still be exposed to a zero-day: a flaw the software vendor has known about for exactly zero days. This episode separates terms that are often blurred. A vulnerability is the opening, like a bank vault air vent built an inch too wide. An exploit is the specialized tool built to get through it. A 2017 RAND Corporation data set found exploits took an average of 22 days to develop and stayed usable for 6.9 years. Around these flaws sits a three-part economy. On the white market, researchers report bugs for bounties. On the black market, criminal groups buy working exploits. The largest buyers are in the gray market: governments and intelligence agencies, where a single zero-click exploit can fetch millions. That feeds the debate over disclosure versus stockpiling, which stopped being theoretical with Stuxnet in 2010 and the Shadow Brokers leak in 2016. The episode closes with defense in depth, the practice of making a breach too slow, costly, and noisy to pay off. Releasing a patch can raise risk for a time, since attackers compare old and new code to locate the flaw before users install the fix.Stuxnet used four zero-days at once, spread by USB drives into the air-gapped Natanz facility, and fed operators fake readings while centrifuges tore themselves apart.EternalBlue, an exploit stolen from the NSA, powered the 2017 WannaCry and NotPetya attacks, with damage estimated at $10 billion.Pegasus spyware from the NSO Group uses zero-click exploits against apps such as iMessage and WhatsApp, requiring no action from the target.A 2022 study of an exploit broker found a 44 percent annualized inflation rate in exploit prices.

  2. 1d ago

    Sir Clive Sinclair's C5: The Electric Trike That Sank a Tech Legend

    On January 10th, 1985, Sir Clive Sinclair, the knighted millionaire behind the pocket calculator and the ZX Spectrum, unveiled what he believed was the future of transport at Alexandra Palace in London. It was a three-wheeled, open-air electric vehicle that looked like a plastic bathtub. This episode follows the Sinclair C5 from his long obsession with electric vehicles, through his sale of about 8.3 million pounds in personal shares to fund a secretive new company, to a launch in snow and ice that journalists turned into a public humiliation. The root of the trouble was a 1983 UK legal category, the electrically assisted pedal cycle, which required no license, insurance, road tax, or helmet. To qualify, the C5 could weigh no more than 60 kilograms, use no more than a 250 watt motor, and travel no faster than 15 miles per hour. Sinclair designed for the loophole instead of the commuter, with almost no market research. The collapse took eight months, yet the unsold stock found a strange afterlife, and the idea itself now looks decades early. The C5 ran on a standard lead acid battery and a motor originally designed to drive a truck cooling fan, and it was assembled in a Hoover washing machine factory in Wales.At the launch, cold cut the advertised 20 mile range to around five, and racing driver Stirling Moss was reduced to pedaling uphill amid diesel fumes.The British Safety Council chairman said he was shattered that 14-year-olds could drive it in traffic without a license, insurance, or a helmet.Production ended by August 1985 with about 5,000 of 14,000 units sold, and Sinclair lost seven million pounds of his own fortune.Liquidated C5s bought for as little as 75 pounds became collector's items, and one modified example ran at 150 miles per hour.

  3. 1d ago

    The Conficker Worm: 15 Million Infected PCs and an Attack That Never Came

    Starting in November 2008, the Conficker worm, also known as Downadup or Kido, infiltrated somewhere between 9 and 15 million computers. It grounded French military aircraft that could not download flight plans, turned up on Royal Navy warships and submarines, and infected over 800 computers in Sheffield hospitals. Its entry point was a Windows flaw cataloged as MS08-067, which Microsoft had patched on October 23rd, 2008. By January 2009 an estimated 30 percent of Windows PCs were still unpatched, and a second variant spread through USB drives and the AutoRun feature. This episode follows the contest between the worm's authors and an industry coalition that came to be called the Conficker Cabal, which included Microsoft, Symantec, ICANN, and academic researchers. The malware blocked security tools, signed its updates with RSA cryptography, and generated 250 domains a day to look for orders. When defenders locked those domains down, it escalated. Then, with the world braced for catastrophe, the giant botnet delivered a payload so small that it changes how the whole story reads. The name Conficker is a near-perfect anagram of parts of trafficconverter.biz, a domain the worm contacted for updates, with an extra K added.Manchester City Council estimated 1.5 million pounds in disruption and banned all portable USB drives.Within weeks of academics publishing a corrected MD6 hashing algorithm, the worm's authors had built it into their code.Variant D raised the daily domain count from 250 to 50,000 across 110 top level domains and added a peer-to-peer update network.In April 2009, Variant E installed the Waledac spam bot and scareware called SpyProtect 2009, then deleted itself. Half a million machines were still infected in 2019.

  4. 1d ago

    The Blue Screen of Death: Why Windows Crashes in Blue and Who Chose It

    The blue screen of death was not designed by psychologists to calm anyone down. When Windows NT 3.1 introduced the first true critical error screen in 1993, Microsoft developer John Vert wrote it to match what he already stared at all day: a MIPS workstation and the SlickEdit text editor, which defaulted to white text on a blue background. This episode traces the screen from the garbled text of Windows 1.01 and 2.03, through the blue task manager summoned by Control-Alt-Delete in Windows 3.1, to the stop error that halts everything. That halt is a protective act. Windows 95, 98, and Millennium Edition let programs and the core system share memory and offered to continue after an error, which rarely ended well. Windows NT isolated the kernel and, when something went wrong inside it, stopped cold to keep corruption off the hard drive while dumping memory for engineers. The episode also covers the hexadecimal codes, the sad face introduced with Windows 8, the QR code of Windows 10, and the black screen announced for Windows 11 version 24H2 after the CrowdStrike outage of July 2024. In 2014, tech outlets misread a Raymond Chen blog post and credited Steve Ballmer with inventing the crash screen. Ballmer had only written the text for the Windows 3.1 task manager dialog.Chen clarified that he himself created the Windows 95 version of the error screen.At Comdex in 1998, a scanner plugged in by Chris Capossela crashed a Windows 98 beta in front of Bill Gates, who joked that this must be why it was not shipping yet.On Windows 95 and 98, a path using the reserved DOS device name con twice could crash the machine, and malicious websites hid it in their pages.Windows Insider builds crash to a green screen, and the Linux software suite systemd has added its own blue screen for critical boot failures.

  5. 1d ago

    Eternal September: When AOL Flooded Usenet and Net Culture Broke

    On certain legacy servers, the date is still counted as a day in September 1993. The joke commemorates Eternal September, the moment between late 1993 and early 1994 when the early internet lost its small town feel. This episode reconstructs Usenet before the flood: a network of newsgroups reached mostly through universities and tech companies, passed between machines over phone lines by UUCP, where every byte cost someone money. That expense produced netiquette, enforced by flaming, kill files, and complaints to a newcomer's system administrator. Each September a wave of college freshmen disrupted the newsgroups, and by November they had either learned the rules or left. Then commercial providers such as Delphi and America Online offered access to anyone with a modem and a credit card. AOL opened its Usenet gateway in March 1994, and the newcomers never stopped arriving. The veterans' own posts record the birth of the phrase, and the episode connects their dilemma to open source maintainers now swamped by AI-generated pull requests. Quoting an entire 50-line post just to agree was a cardinal sin, since it forced servers around the world to pay to transmit it.In January 1994, Joel Furr asked two folklore newsgroups whether Delphi had unleashed a staggering amount of weirdos on the net.On January 25, 1994, David Fisher wrote that September 1993 would go down in net history as the September that never ended.A Unix script called sdate reports the date as an ever-growing day count in September 1993, and a free public Usenet server runs at eternal-september.org.In 2026, GitHub invoked Eternal September to describe the flood of AI-assisted pull requests overwhelming volunteer maintainers.

  6. 1d ago

    The GIF: How a 1987 Dial-Up Hack Survived a Patent War and Went Viral

    Most of the looping clips people send today are not GIF files at all. They are silent video files wearing an old disguise. This episode tells the story of the real Graphics Interchange Format, released in June 1987 by a CompuServe team led by Steve Wilhite, when customers paid by the minute and a single color image could take minutes to arrive. The solution was a palette of 256 colors chosen from roughly 16.7 million, LZW compression that built a shared dictionary of patterns on the fly, and interlacing that let users see a rough image early and abort a wrong download. The 1989 update added transparency and multiple frames, and in 1995 Netscape Navigator 2.0 made those frames loop forever. Then Unisys realized the compression algorithm was covered by its patent and began demanding licensing fees, provoking protests and the creation of a free alternative. The format outlived the patents and a long fight over its pronunciation, even as social platforms quietly replaced the files themselves with far smaller video. Limiting images to 256 colors matched the hardware of 1987, when graphics cards rarely displayed more than that at once.A true color hack split photos into 16 by 16 pixel blocks, each a separate frame with its own palette, which some browsers then flashed tile by tile.In 1999, Unisys said some non-commercial site owners could owe $5,000 to $7,500, prompting Burn All GIFs Day.PNG was developed in 1995 with the open deflate algorithm to avoid the patent, which expired between 2003 and 2004.Wilhite used his 2013 Webby Awards lifetime achievement speech to flash a message that it is pronounced with a soft G, like the peanut butter.

  7. 1d ago

    The 1997 PalmPilot: The One-Megabyte PDA That IMAX Still Emulates

    Projectionists running 70 millimeter IMAX prints, some weighing over 600 pounds, control the film platters through software that imitates a handheld device from 1997. This episode explains how that came to be by going back to March 10, 1997, when Palm, then a subsidiary of U.S. Robotics, launched the PalmPilot Personal at $299 and the PalmPilot Professional at $399. Inside was a 16 megahertz Motorola processor, Palm OS 2.0, and either 512 kilobytes or one megabyte of memory, all running for weeks on two AAA batteries. Those limits forced ruthless efficiency. Where rivals poured money into natural handwriting recognition that slow chips could not handle, Palm asked users to learn Graffiti, a set of simplified single-stroke letters the device could read instantly. The company also treated early buyers with unusual respect, and by 1998 it had reportedly sold over a million units. The same static, predictable interface is why IMAX engineers later rebuilt it as a simulator for a job where a stray swipe on a modern touchscreen could be costly. The PalmPilot weighed 5.6 ounces, measured 4.7 by 3.1 inches, and had a monochrome screen of 160 by 160 pixels.Graffiti reversed the usual approach: it trained the human to write for the computer, as with an A drawn like an upside-down V.Syncing with the desktop meant an RS-232 serial connection, and getting online required a separate $129 modem running at 14.4 kilobits per second.Owners of the earlier Pilot 1000 and 5000 could buy a $199 upgrade kit, or $99 for registered users, with a new memory card, a ROM chip, and a plastic door that added infrared.IMAX quick turn reel units were originally operated with physical PalmPilots, and the simulator preserved the interface for releases like Oppenheimer.

  8. 1d ago

    Social Engineering: How One Scammer Took $100 Million from Tech Giants

    Google and Facebook spend fortunes on cybersecurity, yet a single Lithuanian fraudster took $100 million from the two of them over two years. He used no exploit at all. He impersonated a hardware supplier both companies worked with, mocked up official letterheads, sent fake invoices, and was paid. This episode treats that case as the entry point to social engineering, the practice of attacking the human instead of the code, and explains why it is cheaper, faster, and more reliable for an attacker than hunting for a software flaw. The tactics each press on a hardwired trait. Pretexting builds false legitimacy from scraped personal details. Scareware goes straight for panic. Tailgating turns politeness at a secure door into a breach, while baiting and waterholing let curiosity and habit do the work. The history runs from phone phreakers such as Kevin Mitnick and Susan Headley to the RSA breach, the Sony Pictures leak, and the phishing of John Podesta in 2016. The law has tried to catch up, but no statute can patch curiosity, empathy, or fear. In a 2016 University of Illinois study, 290 of 297 USB drives dropped around campus were picked up, and 135 were plugged in and opened.The Badir brothers, three siblings in Israel who were blind from birth, ran an extensive telecommunications fraud scheme in the 1990s using voice impersonation.The 2011 RSA hack began with emails to four employees carrying a spreadsheet titled 2011 recruitment plan.Ubiquiti Networks lost nearly $47 million in 2015 to a spear-phishing email posing as an executive, recovering about $8 million.Within 24 hours of Equifax launching its breach response site, attackers registered 194 lookalike domains built on typing errors.

1.3
out of 5
13 Ratings

About

pplpod is a podcast about people, places and lots of other stuff. Each episode takes a deep dive into the lives, choices, and legacies of fascinating figures from history, culture, music, and beyond. From icons who shaped entire generations to hidden stories that deserve the spotlight, pplpod brings you closer to the people behind the headlines and the legends. Thoughtful, engaging, and story-driven, pplpod explores what makes these lives extraordinary—and what we can learn from them today.

You Might Also Like