Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 439 - Where are all the youth in open source?

    Josh and Kurt talk about a story talking about the "graying" of open source. There doesn't seem to be many young people working on open source, but we don't really know why that is. There are many thoughts, but a better question is why should anyone get involved in open source anymore? The world has changed quite a lot since open source was created.

    Show Notes
    • The graying open source community needs fresh blood
    • OSPOs for Good 2024
      • Day 1 Part 1
      • Day 1 Part 2
      • Day 2 Part 1
      • Day 2 Part 2
    • FFmpeg bug
    • JSON Editor Online
    • https://rfc3339.com/
    30 min
  • Episode 438 - CISA's bad OSS advice vs the Whitehouse good advice

    Josh and Kurt talk about two documents from the US government that discuss open source in very different ways. The CISA document lays out a way to measure open source, but we take issue with the idea of trying to measure which open source projects are "good". The Whitehouse on the other hand takes an approach that is very open source, get involved. Trying to measure open source isn't producing anything actionable, but getting involved is very actionable, and very much how open source works.

    Show Notes
    • CISA: Continued Progress Towards a Secure Open Source Ecosystem
    • Whitehouse: Administration Cybersecurity Priorities for the FY 2026 Budget
    35 min
  • Episode 437 - CocoPods and proper funding for open source

    Josh and Kurt talk about a pretty big bug found in CocoPods ownership. We also touch on a paper that discusses the technical debt that open source should have. We discuss what the long term sustainability of open source. There aren't any good solutions for open source today, but talking about these problems is important, we have to start to understand what's going on before we can plausibly discuss solutions. If you're an open source project that needs to put things on pause, or even walk way, that's OK.

    Show Notes
    • CocoaPods Vulnerabilities Could Hit Apple, Microsoft, Facebook, TikTok, Snap and More
    • The Expense of Unprotected Free Software
    • Long-term maintenance of PCRE2 #426
    37 min
  • Episode 436 - OpenSSH and node-ip - it's all exponential growth

    Josh and Kurt talk about the recent OpenSSH vulnerability and the node-ip project owner taking their project private. They're quasi related in the context of two open source projects handled bugs very differently. The OpenSSH bug isn't really as serious as it seems, but you still want to patch.

    The node-ip bug is a very different story. The relationship between users and open source developers is one experiencing more strain now than we've ever seen. It's a weird conversation and we don't have good answers. Security in general is a collection of unsolvable problems.

    Show Notes
    • Qualys security advisory
    • Hacker News Discussion
    • Security Cryptography Whatever
    • Dev rejects CVE severity, makes his GitHub repo read-only
    33 min
  • Episode 435 - polyfill.io - open source is too big to fix

    Josh and Kurt talk about the latest polyfill.io mess. Apparently someone took over a very popular project and started to serve malware. First XZ, now this. What does it mean for open source? We don't have any answers, and it's hard to even talk about this problem because it's so big. The thing is though, even if we can't fix open source, it's here to stay.

    Show Notes
    • Polyfill supply chain attack hits 100K+ sites
    • OpenSSF Scorecard
    39 min
  • Episode 434 - Unreported vulnerabilities and everyone is getting hacked

    Josh and Kurt talk about three wangles of responsibility. We start with a story about a bike theft ring, bike theft doesn't usually get any attention, but this one is special. Then we ask why it seems like everyone is getting hacked, it's because they have to tell us now. And finally we have a story about the huge number of unreported vulnerabilities in open source projects. This statistic probably affects all software, but there's some numbers for open source specifically.

    Show Notes
    • The West Coast's Fanciest Stolen Bikes Are Getting Trafficked by One Mastermind in Jalisco, Mexico
    • $5 million worth of stolen tools recovered thanks to Apple's AirTag — 12 secret storage facilities had around 15,000 construction tools
    • Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities
    32 min
  • Episode 433 - Should OpenSSH block misbehaving clients?

    Josh and Kurt talk about a new proposal from OpenSSH to add a timeout to penalize clients misbehaving. But this then brings up the typical security conversation of "if it's not perfect we shouldn't do it". Trying new things is a good thing, even if something fails, we learn a lesson that we can use in the future.

    Show Notes
    • OpenSSH introduces options to penalize undesirable behavior
    • Hacker News comments
    32 min
  • Episode 432 - Flipper Zero with Alex Kulagin

    Josh and Kurt talk to Alex Kulagin from Flipper about the Flipper Zero. It's one of the coolest hacker devices that exists on the market. We talk about what it is, how it started, what it can (and can't) do. It's a really fun conversation.

    Show Notes
    • Flipper Zero Website
    • Headphone jack radio capture
    • Flipper Zero on Tik Tok
    34 min
  • Episode 431 - Redirecting HTTP to HTTPS

    Josh and Kurt talk about a blog post titled "Your API Shouldn't Redirect HTTP to HTTPS". It's an interesting idea, and probably a good one. There is however a lot of baggage in this space as you'll hear in the discussion. There's no a simple solution, but this is certainly something to discuss.

    Show Notes
    • Your API Shouldn't Redirect HTTP to HTTPS
    • Hacker News discussion
    • HSTS Section 5.1
    33 min
  • Episode 430 - Frozen kernel security

    Josh and Kurt talk about a blog post about frozen kernels being more secure. We cover some of the history and how a frozen kernel works and discuss why they would be less secure. A frozen kernel is from when things worked very differently. What sort of changes will we see in the future?

    Show Notes
    • Kurt's strange coffee
    • Why a 'frozen' distribution Linux kernel isn't the safest choice for security
    35 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners