Open Source Security

Episode 436 - OpenSSH and node-ip - it's all exponential growth


Listen Later

Josh and Kurt talk about the recent OpenSSH vulnerability and the node-ip project owner taking their project private. They're quasi related in the context of two open source projects handled bugs very differently. The OpenSSH bug isn't really as serious as it seems, but you still want to patch.

The node-ip bug is a very different story. The relationship between users and open source developers is one experiencing more strain now than we've ever seen. It's a weird conversation and we don't have good answers. Security in general is a collection of unsolvable problems.

Show Notes
  • Qualys security advisory
  • Hacker News Discussion
  • Security Cryptography Whatever
  • Dev rejects CVE severity, makes his GitHub repo read-only
...more
View all episodesView all episodes
Download on the App Store

Open Source SecurityBy Josh Bressers

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

40 ratings


More shows like Open Source Security

View all
Hacked by Hacked

Hacked

189 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

289 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,005 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

369 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

648 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,034 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

168 Listeners

Smashing Security by Graham Cluley

Smashing Security

322 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,113 Listeners

Hacking Humans by N2K Networks

Hacking Humans

316 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

97 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners