Discover
Zero Downtime
Zero Downtime
Author: John Hass
Subscribed: 0Played: 0Subscribe
Share
© Copyright 2025 All rights reserved.
Description
Zero Downtime brings together tech, business, and the everyday experiences of running an IT company. John and Logan discuss what’s going on in their world, the questions people ask them most, and talk with other business owners and professionals in conversations that are real, relaxed, and worth your time.
46 Episodes
Reverse
WinRAR may have finally figured out how to get people to give them money, and it only took three decades. The answer wasn't licensing enforcement. It was a $150 messenger bag shaped like the WinRAR icon. Meanwhile, there are credible reports of two actively exploited Citrix NetScaler zero-days, a 16-year-old typed "admin" into a Microsoft analytics platform and got access to 17 trillion rows of data, and Microsoft's Weekly Damage Report is back with another seven days of broken things. This week, John and Logan cover four stories from the strange corners of cybersecurity, software economics, and ongoing Microsoft reliability.
Stories in this episode:
WinRAR finally gets paid. The company that has spent three decades politely asking people to pay for a software license apparently discovered the actual monetization strategy was always merchandise. WinRAR partnered with fashion brand Tern to release a $150 messenger bag shaped like the WinRAR icon. A single-user license costs about $29. People who refused to pay $29 for the software are apparently willing to pay five times that amount to physically walk around dressed as WinRAR.
Citrix NetScaler zero-days hit. There are credible reports of two previously undisclosed remote code execution vulnerabilities in NetScaler ADC and Gateway appliances, and that they may already be under active exploitation. Security firm watchTowr says it has high confidence that multiple unpatched NetScaler RCE vulnerabilities are being exploited in the wild. Some administrators have reportedly been told to shut their NetScalers down, not patch them.
16-year-old owns Microsoft admin. A researcher named Faav found that Microsoft's internal Titan analytics platform validated JWT claims (tenant, audience, application ID, username) but did not actually verify the cryptographic signature. He created an unsigned JWT, changed the username field to "admin," and Titan mapped him to local user ID 1 with the Administrator role. That gave him SQL query access to analytics infrastructure containing an estimated 17 trillion rows across 17 ClickHouse databases, including Bing analytics. The bounty: $5,000.
Microsoft's Weekly Damage Report. Office 2016 and 2019 perpetual licenses forgot they were paid for. Teams had a 49 minute connectivity incident. Teams Rooms calls dropped after 30 seconds on certain Poly Android devices. Word saved PDFs to SharePoint by quietly saving them to a local cache instead. Exchange Online could not reply or reply-all to Microsoft 365 Group messages. Copilot could not Copilot. And School Data Sync had a nearly five day education services outage.
New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.
Flock Safety, the $8 billion license plate reader company, just launched a "voluntary" employee separation program while cities across the country cancel their contracts. Windows quietly assigns a persistent 64-bit device identifier even when you set up a local account. The FCC has accidentally started a civil war inside Meshtastic and MeshCore mesh networks. And Microsoft's second Weekly Damage Report covers what got fixed and what is still broken after Patch Tuesday. This week, John and Logan break down four stories covering surveillance, privacy, radio regulations, and the ongoing state of Windows.
Stories in this episode:
The Flock is getting smaller. WIRED reported that Flock has launched a voluntary employee separation program roughly twice as generous as previous severance offers. Communities are dropping the surveillance camera vendor faster than ever, with 93 city and county governments cutting ties in August alone. Boston abandoned Flock after a vendor error enabled nationwide data sharing that its contract had explicitly disabled. The Washington Post reported dozens of cases where officers were accused of misusing the system to search for wives, girlfriends, or former romantic partners.
Windows tracks you without an account. A new open-source project called deGDID documents Microsoft's server-assigned 64-bit Device PUID, which Windows can obtain from Microsoft's infrastructure even on machines set up with a local account. A 2026 court case revealed that Microsoft possessed information associating one of these identifiers with URLs, timestamps, and IP addresses. The project does not claim to make Windows anonymous. It documents what this identifier does and offers a tested way to block and remove it.
FCC starts a LoRa civil war. Meshtastic and MeshCore communities discovered that the default configurations most Americans use may not comply with FCC 47 CFR 15.247, which requires a minimum 6 dB bandwidth of 500 kHz. Meshtastic's Long Fast default is 250 kHz. MeshCore's default has been 62.5 kHz. Fixing this fractures the network effect that made the system useful in the first place.
Microsoft's Weekly Damage Report. Remote Desktop Services, Hyper-V Linux folder sharing, and Active Directory trust were broken by September's Patch Tuesday and are now marked resolved. USB Audio Class 1.0 devices are only partially fixed. File History quietly stopped creating and updating backups with no fix yet. And a false "Defender is turned off" warning got officially resolved even though Defender was actually running the whole time.
New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.
A China-based operation used Claude to power more than 20 fraudulent dating apps and fake 4,700 AI "soulmates" for at least 25,000 real people. German police are quietly connecting their computers to citizens' WhatsApp accounts through phones handed over voluntarily. Chess.com just had 7.3 million records show up online. And attackers are now phishing Microsoft 365 accounts by pretending to help you set up a passkey. This week, John and Logan break down nine stories covering AI abuse, surveillance, data breaches, and Microsoft's newest weekly reliability problem.
Stories in this episode:
Your soulmate is running in a data center. According to Anthropic, a China-based operation used AI to power more than 20 fraudulent dating apps with thousands of fake personas interacting with at least 25,000 people. Claude Code helped build the apps. Claude powered the conversations. Roughly one in four accounts was a paid human worker taking video calls and following users on social media. The system generated about 2.36 million messages over two weeks and explicitly tracked which users were getting suspicious.
German police add themselves to your chats. According to court records published by Netzpolitik, parents voluntarily handed over their phones so officers could read messages from their daughter. Officers also secretly connected the parents' WhatsApp accounts to a police computer. Returning the phones did not end the access. The capability became permanently available to investigative units in August 2025.
Chess.com data leaked. A dataset with 7.3 million records and roughly 4.6 million unique email addresses showed up online in August. Have I Been Pwned found that 99% of the email addresses had appeared in previous breaches, which supports the theory that scrapers matched existing lists against Chess.com accounts.
Microsoft 365 fake passkey phishing. Attackers are calling employees pretending to be IT support, claiming a passkey upgrade is required. In one observed approach, the attacker persuades the employee to enter a device code on Microsoft's real authentication page, which authorizes an attacker-controlled client. The passkey cryptography was not broken. The employee was.
Plus AI giants like Dario Amodei calling for slower development and who actually benefits, Blockstream refusing to pay ransom after 4,000 bitcoin was drained from Liquid, Revolut handing customer data to attackers who spoofed a legitimate government email domain, a four-year sentence for a Conti ransomware member, and the first Microsoft Weekly Damage Report covering September's Remote Desktop, VPN, and Excel breakage.
New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.
LG Ad Solutions actually tells advertisers they can "own the living room." European governments and militaries are actively migrating off Microsoft. Microsoft 365 suffered a multi-day outage that took down Exchange and authentication. And ChatGPT, Claude, and Grok all had overlapping outages on the same day. This week, John and Logan break down nine stories covering surveillance, cloud reliability, cybersecurity, and what happens when the tool you built your workflow around suddenly stops responding.
Stories in this episode:
Your TV is watching back. Gamers Nexus published an investigation into LG smart TVs, and the allegations go well beyond home screen ads. Automatic content recognition identifies what you're watching even when the TV is being used as an HDMI display. LG's own advertising describes reaching associated phones, tablets, and computers in the household. Independent research also demonstrated that a compromised TV can record room audio while its screen appears off. If a display only needs to show HDMI, keep it off your network entirely.
Europe is building the Microsoft exit. Austria's military moved 16,000 PCs from Microsoft Office to LibreOffice. Schleswig-Holstein reports nearly 80 percent of its administrative workstations on LibreOffice, with more than 15 million euros in license savings. France's DINUM is moving to Linux. The ICC switched to openDesk after American sanctions. These are tested alternatives with working software behind them.
Microsoft 365 down. On August 31, an authentication configuration incident took out Teams, SharePoint, OneDrive, Exchange, and Microsoft's security and compliance products. Recovery took several days. Then Friday brought a separate Exchange Online incident delaying external email. Email is one of the most basic services businesses buy from Microsoft.
Three chatbots down. On September 3, ChatGPT, Claude, and Grok experienced overlapping disruptions. The lesson is not that AI failed. It is that your project instructions, source documents, and current drafts sitting inside one AI service can become inaccessible when that service goes down. Keep your work somewhere you control.
Plus Australia proposing an algorithm off switch that would let you choose a following-only feed, Berlin's government hack turning into a fight over whether to let CrowdStrike investigate, Trezor's shipping partner exposing 67,000 more customers after previously confirming the data was deleted, ShinyHunters posting data attributed to McKesson and Jack Henry after voice phishing entry, and a Windows 11 preview update that broke mouse cursor and desktop settings on non-English installations.
New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.
Infostealer malware is quietly harvesting active Claude login sessions and burning through victims' AI quotas, and 2FA won't stop it. Google removed a key hardware security feature from the Pixel 11, and GrapheneOS is now telling people to buy a Motorola instead. The EU has officially decided ChatGPT is a "search engine." And a China-linked hacking group turned compromised Cisco routers into full-blown spy platforms that lie to the administrator looking at them. This week, John and Logan break down six stories covering AI security, phones, regulation, and one very uncomfortable question about your router.
Stories in this episode:
Malware steals Claude sessions. Anthropic is warning users that infostealer families like Vidar, LummaC2, StealC, RedLine, and Atomic Stealer are harvesting active Claude sessions from infected computers. The attackers don't need your password or 2FA code. They're stealing the session token that says you already authenticated. Some users noticed their Claude usage limit reset and then disappear again while they weren't using it. That's because somebody else was.
Google nerfs the Pixel 11. GrapheneOS spent about a week working on its Pixel 11 port before concluding that Google removed hardware Memory Tagging Extension. MTE existed on Pixel 8, 9, and 10, and GrapheneOS builds core exploit protection around it. GrapheneOS is now recommending users not buy the Pixel 11 and pointing instead to a new partnership with Motorola, whose 2027 flagship phones are expected to become the first officially supported non-Pixel devices.
EU calls ChatGPT a search engine. Under the Digital Services Act, ChatGPT crossed 45 million monthly EU users and got officially designated a Very Large Online Search Engine. The classification isn't just a label. It brings mandatory systemic risk assessments covering illegal content and child safety (reasonable) but also misinformation, electoral processes, and public discourse (much fuzzier). Non-compliance can trigger fines of up to 6% of worldwide annual turnover.
Chinese hackers turn Cisco routers into spy platforms. A China-linked group called Fire Ant compromised Cisco IOS XR routers, TACACS authentication servers, and Linux management systems. Custom router malware suppressed syslog messages, modified show command output, and turned routers into packet capture devices uploading traffic to external FTP servers. If you SSH into your router and everything looks fine, that may be the malware answering your questions.
Plus Proton's political neutrality problem (SSH keys in a synced password manager and a $100K donation into one of the most politically charged conflicts on Earth), and California accidentally giving Linux a pass on age verification through the AB 1856 open-source exemption.
New episodes weekly. Follow Zero Downtime for cybersecurity, AI, privacy, and the tech stories that actually matter.



