Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 420 - What's going on at NVD

    Josh and Kurt talk about what's going on at the National Vulnerability Database. NVD suddenly stopped enriching vulnerabilities, and it's sent shock-waves through the vulnerability management space. While there are many unknowns right now, the one thing we can count on is things won't go back to the way they were.

    Show Notes
    • Anchore's Blog
    • Grype
    • Josh's Cyphercon Talk
    • Ecosyste.ms
    • Episode 266 – The future of security scanning with Debricked
    40 min
  • Episode 419 - Malicious GitHub repositories

    Josh and Kurt talk about an attack against GitHub where attackers are creating malicious repositories then artificially inflating the number of stars and forks. This is really a discussion about how can we try to find signal in all the noise of a massive ecosystem like GitHub.

    Show Notes
    • GitHub besieged by millions of malicious repositories in ongoing attack
    35 min
  • Episode 418 - Being right all the time is hard

    Josh and Kurt talk about recent stories about data breaches, flipper zero banning, and realistic security. We have a lot of weird challenges in the world of security, but hard problems aren't impossible problems. Sometimes we forget that.

    Show Notes
    • Mon Dieu! Nearly half the French population have data nabbed in massive breach
    • Feds move to ban auto theft tech device 'Flipper Zero'
    • Gmail and Yahoo's 2024 inbox protections and what they mean for your email program
    • Vending machine error reveals secret face image database of college students
    31 min
  • Episode 417 - Linux Kernel security with Greg K-H

    Josh and Kurt talk to GregKH about Linux Kernel security. We most focus on the topic of vulnerabilities in the Linux Kernel, and what being a CNA will mean for the future of Linux Kernel security vulnerabilities. The future of Linux Kernel security vulnerabilities is going to be very interesting.

    Show Notes
    • Greg K-H
    • Linux Kernel is a CNA
    • Machine learning and stable kernels
    • Bug reporting for Linux
    43 min
  • Episode 416 - Thomas Depierre on open source in Europe

    Josh and Kurt talk to Thomas Depierre about some of the European efforts to secure software. We touch on the CRA, MDA, FOSDEM, and more. As expected Thomas drops a huge amount of knowledge on what's happening in open source. We close the show with a lot of ideas around how to move the needle for open source. It's not easy, but it is possible.

    Show Notes
    • Thomas Depierre
    • I am not a supplier
    • Open Source In The European Legislative Landscape devroom
    • Cyber Resilience Act
    • The 2023 Tidelift state of the open source maintainer report
    43 min
  • Episode 415 - Reducing attack surface for less security

    Josh and Kurt talk about a blog post explaining how to create a very very small container image. Generally in the world of security less is more, but it's possible to remove too much. A lot of today's security tooling relies on certain things to exist in a container image, if we remove them we could actually result in worse security than leaving it in. It's a weird topic, but probably pretty important.

    Show Notes
    • How I reduced the size of my very first published docker image by 40% - A lesson in dockerizing shell scripts
    • Hacker News Discussion
    • Episode 293 – Scoring OpenSSF Security Scoring
    32 min
  • Episode 414 - The exploited ecosystem of open source

    Josh and Kurt talk about open source projects proving builds, and things nobody wants to pay for in open source. It's easy to have unrealistic expectations for open source projects, but we have the open source capitalism demands.

    Show Notes
    • Open Source Doesn't Require Providing Builds
    • The things nobody wants to pay for
    • Audacity privacy policy update has caused an outcry
    • The History of X11
    33 min
  • Episode 413 - PyTorch and NPM get attacked, but it's OK

    Josh and Kurt talk about an attack against PyTorch and NPM. The PyTorch attack shows the difficulty of trying to operate a large open source project. The NPM problem is one of the difficulty in trying to backdoor open source. A lot of people are watching and it only takes one person to notice a problem and we all benefit.

    Show Notes
    • Peanut Butter the dog plays Gyromite
    • The Wizard movie
    • PyTorch supply chain attack
    • npm Package Found Delivering Sophisticated RAT
    • Deceptive Deprecation: The Truth About npm Deprecated Packages
    • Changing a lightbulb
    • Spelunking the Bitcoin Blockchain with Josh Bressers | CypherCon 4.0
    • Operation Triangulation - What You Get When Attack iPhones of Researchers
    • 9th Annual State of the Software Supply Chain
    36 min
  • Episode 412 - Blame the users for bad passwords!

    Josh and Kurt talk about the 23andMe compromise and how they are blaming the users. It's obviously the the fault of the users, but there's still a lot of things to discuss on this one. Every company has to care about cybersecurity now, even if they don't want to.

    Show Notes
    • Security leaders weigh in on 23andme hack
    • Don't need a gun when you have a Donk - Crocodile Dundee 2
    • Hackers can infect network-connected wrenches to install ransomware
    • My disappointment is immeasurable, and my day is ruined
    34 min
  • Episode 411 - The security tools that started it all

    Josh and Kurt talk about a grab bag of old technologies that defined the security industry. Technology like SELinux, SSH, Snort, ModSecurity and more all started with humble beginnings, and many of them created new security industries.

    Show Notes
    • SELinux
    • AppArmor
    • SSH
    • ModSecurity
    • Snort
    • Nmap
    • Nessus
    • What comes after open source
    30 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners