Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 429 - The autonomy of open source developers

    Josh and Kurt talk about open source and autonomy. This is even related to some recent return to office news. The conversation weaves between a few threads, but fundamentally there's some questions about why do people do what they do, especially in the world of open source. This also is a problem we see in security, security people love to tell developers what to do. Developers don't like being told what to do.

    Show Notes
    • pycurl issue
    • Apple, SpaceX, Microsoft return-to-office mandates drove senior talent away
    • RSA ANIMATE: Drive: The surprising truth about what motivates us
    • Sudo-rs dependencies: when less is better
    • phishing webcomic
    • Debian OpenSSL Bug (16 years)
    33 min
  • Episode 428 - GitHub artifact attestation

    Josh and Kurt talk about a new to sign artifacts on GitHub. It's in beta, it's not going to be easy to use, it will have bugs. But that's all OK. This is how we start. We need infrastructure like this to enable easier to use features in the future. Someday, everything will be signed by default.

    Show Notes
    • GitHub artifact attestation
    38 min
  • Episode 427 - Will run0 replace sudo?

    Josh and Kurt talk about a sudo replacement going into systemd called run0. It sounds like it'll get a lot right, but systemd is a pretty big attack surface and not everyone is a fan. We shall have to see if this ends up replacing sudo.

    Show Notes
    • Conan O'Brien on Hot Ones
    • Lennart's Mastodon thread
    • xkcd automation
    31 min
  • Episode 426 - Automatically exploiting CVEs with AI

    Josh and Kurt talk about a paper describing using a LLM to automatically create exploits for CVEs. The idea is probably already happening in many spaces such as pen testing and intelligence services. We can't keep up with the number of vulnerabilities we have, there's no way we can possibly keep up with a glut of LLM generated vulnerabilities. We really need to rethink how we handle vulnerabilities.

    Show Notes
    • OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories
    • paper: LLM Agents can Autonomously Exploit One-day Vulnerabilities
    • Cisco Fixes RV320/RV325 Vulnerability by Banning "curl" in User-Agent
    • Episode 219 – Chat with Larry Cashdollar
    • Cory Doctorow: What Kind of Bubble is AI?
    38 min
  • Episode 425 - Video game cheaters, also pretendo

    Josh and Kurt talk about a database of game cheaters. Cheating in games has many similarities to security problems. Anti cheat rootkits are also terrible. The clever thing however is using statistics to identify cheaters. Statistics don't lie. Also, we discuss the Pretendo project sitting on a vulnerability for a year, is this ethical?

    Show Notes
    • Hacker News searchable database

    • Benford's law

    • John Oliver Medicaid

    • Mario64 invisible walls

    • Pretendo

    • Pretendo exploit

    31 min
  • Episode 424 - The Notepad++ Parasite Website

    Josh and Kurt talk about a Notepad++ fake website. It's possibly not illegal, but it's certainly ethically wrong. We also end up discussing why it seems like all these weird and wild things keep happening. It's probably due to the massive size of open source (and everything) now. Things have gotten gigantic and we didn't really notice.

    Show Notes
    • Help us to take down the parasite website
    • Open Source is bigger than you can imagine
    • Toronto Pearson International Airport heist
    36 min
  • Episode 423 - FCC cybersecurity label for consumer devices

    Josh and Kurt talk about a new FCC program to provide a cybersecurity certification mark. Similar to other consumer safety marks such as UL or CE. We also tie this conversation into GrapheneOS, and what trying to claim a consumer device is secure really means. Some of our compute devices have an infinite number of possible states. It's a really weird and hard problem.

    Show Notes
    • GrapheneOS
    • FCC approves cybersecurity label for consumer devices
    • Cyber Trust Mark Logo
    33 min
  • XZ Bonus Spectacular Episode

    Josh and Kurt talk about the recent events around XZ. It's only been a few days, and it's amazing what we already know. We explain a lot of the basics we currently know with the attitude much of these details will change quickly over the coming week. We can't fix this problem as it stands, we don't know where to start yet. But that's not a reason to lose hope. We can fix this if we want to, but it won't be flashy, it'll be hard work.

    Show Notes
    • GossiTheDog's Blog Post
    • fr0gger diagram
    • OpenSSF Blog (archive)
    • stb library
    1 hr 2 min
  • Episode 422 - Do you have a security.txt file?

    Josh and Kurt talk about the security.txt file. It's not new, but it's not something we've discussed before. It's a great idea, an easy format, and well defined. It's not high on many of our todo lists, but it's something worth doing.

    Show Notes
    • RFC 9116
    31 min
  • Episode 421 - CISA's new SSDF attestation form

    Josh and Kurt talk about the new SSDF attestation form from CISA. The current form isn't very complicated, and the SSDF has a lot of room for interpretation. But this is the start of something big. It's going to take a long time to see big changes in supply chain security, but we're confident they will come.

    Show Notes
    • Secure Software Development Attestation Form
    • The U.S. Military Is Missing Six Nuclear Weapons
    • NIST 800-218
    42 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners