Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 459 - CWE Top 25 List

    Josh and Kurt talk about a CWE Top 25 list from MITRE. The list itself is fine, but we discuss why the list looks the way it does (it's because of WordPress). We also discuss why Josh hates lists like this (because they never create any actions). We finish up running through the whole list with a few comments about the findings.

    Show Notes
    • 2024 CWE Top 25 Most Dangerous Software Weaknesses
    • Set of 9 Unusual Odd Sided dice - D3, D5, D7, D9, D11, D13, D15, D17 & D19
    37 min
  • Episode 458 - FBI endorses E2E encryption

    Josh and Kurt talk about the FBI telling everyone to use end to end encrypted messengers. This is a pretty drastic deviation from messages in the past. The reason for this is it appears the US telephone networks are pwnt beyond repair at this point, which is concerning. The only real solution now is to treat the phone network as untrusted and encrypt all the traffic.

    Show Notes
    • Salt Typhoon
    • U.S. officials urge Americans to use encrypted apps amid unprecedented cyberattack
    • LTT Hacked phone
    • Security Cryptography Whatever Telegram
    • Secure Messaging Apps Comparison
    34 min
  • Episode 457 - The D-Link D-bacle

    Josh and Kurt talk about a serious D-Link security vulnerability in a bunch of end of life products. The crux of the discussion focuses on D-Link, but the reality is almost all consumer gear you plug into the internet is terrible. And there's little hope it will get better anytime soon.

    Show Notes
    • China has utterly pwned 'thousands and thousands' of devices at US telcos
    • D-Link tells users to trash old VPN routers over bug too dangerous to identify
    • D-Link YouTube explainer video
    41 min
  • Episode 456 - What if XZ happened to a company? The openness of open source

    Josh and Kurt embark on a thought experiment to discuss how a commercial entity would handle something like the xz incident. It was very specific and difficult to understand. It's easy to claim just because source code being available doesn't matter. But the reality is when source code is needed, it can make a huge difference for everyone working together, just like we saw with xz.

    Show Notes
    • Lindt admits chocolate may not be 'expertly crafted' in class-action lawsuit battle
    • Mitchell & Webb - Needlessly ambiguous terms
    34 min
  • Episode 455 - Wordpress plugin security

    Josh and Kurt talk about the way Wordpress vets their plugins. While Wordpress has been in the news lately, they do some clever things to get plugins approved. There's a static analyzer that runs against new submissions. We discuss using static analysis, securing open source, contributing and more.

    Show Notes
    • Linus Torvalds Lands A 2.6% Performance Improvement With Minor Linux Kernel Patch
    • Kurt's Plugin
    36 min
  • Episode 454 - The state of open source with Brian Fox from Sonatype and Donald Fischer from Tidelift

    Josh and Kurt talk to Brian Fox from Sonatype and Donald Fischer from Tidelift about their recent reports as well as open source. There are really interesting connections between the two reports. The overall theme seems to be open source is huge, everywhere, and needs help. But all is no lost! There's some great ideas on what the future needs to look like.

    Show Notes
    • Donald Fischer
    • Brian Fox
    • Tidelift
    • Sonatype
    • The 2024 Tidelift state of the open source maintainer report
    • Sonatype State of the Software Supply Chain
    • Anchore 2024 Software Supply Chain Security Report
    • OpenSSF TAC issue 101
    44 min
  • Episode 453 - Software Liability

    Josh and Kurt talk about three government activities happening around security. CISA has a request for comment, and an international strategic plan around cybersecurity. These are both good ideas, and hopefully will help drive change. But we also discuss an EU proposal that brings liability rules to software which sounds like a great way to force change to happen.

    Show Notes
    • Request for Comment on Product Security Bad Practices Guidance
    • FY2025-2026 CISA International Strategic Plan
    • EU brings product liability rules in line with digital age and circular economy
    • CSA Cloud Controls Matrix
    37 min
  • Episode 452 - All about Meshtastic

    Josh and Kurt talk about the Meshtastic open source project. It's a really slick mesh radio system that runs on very cheap radio equipment. This episode isn't very security related (there are a few things), but it is very open source.

    Show Notes
    • Meshtastic
    • Heltec LoRa 32(V3) Radio
    • 465 Rutgers University Confirmed: Meshtastic and LoRa are dangerous
    • Meshtastic Routing Issues & Deployment Scenarios
    • TC2-BBS-mesh
    • The Comms Channel
    • Josh's BBS
    • Heltec T114 bug
    40 min
  • Episode 451 - Python security with Seth Larson

    Josh and Kurt talk to Seth Larson from the Python Software Foundation about security the Python ecosystem. Seth is an employee of the PSF and is doing some amazing work. Seth is showing what can be accomplished when we pay open source developers to do some of the tasks a volunteer might consider boring, but is super important work.

    Show Notes
    • Seth Larson
    • XKCD PGP Signature
    • Seth's Blog
    • Python and Sigstore
    • Deprecating PGP - PEP 761
    • Python SBOMs

    37 min
  • Episode 450 - What's Wrong With WordPress

    Josh and Kurt talk about the current Wordpress / WP Engine mess. In what is certainly a supply chain attack, the Advanced Custom Fields forking. This whole saga is weird and filled with chaos and stupidity. We have no idea how it will end, but we do know that the blog platform you use shouldn't be this exciting. The bad sort of exciting.

    Show Notes
    • WordPress.org's latest move involves taking control of a WP Engine plugin
    • Wordpress / WP Engine timeline
    • Knorr German Recipes
    40 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners