Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 399 - Curl, Security, and Daniel Stenberg

    Josh and Kurt talk to Daniel Stenberg about curl. Daniel is the creator of curl, we chat with him about the security of curl. Daniel tells us how curl is kept secure, we learn about some of the historical reasons curl works the way it does. We hear the story about the curl CVE situation firsthand. We also touch on the importance of curating the community of a popular open source project.

    Show Notes
    • Daniel's Mastodon account
    • Curl
    • The curl CVE blog
    • Broken curl on PowerShell
    • wolfSSL
    38 min
  • Episode 398 - Is only 11% of open source maintained?

    Josh and Kurt talk about Sonatype's 9th Annual State of the Software Supply Chain. There's a ton of data in the report, but the thing we want to talk about is the statistic that only 11% of open source is actually being maintained. Do we think that's true? Does it really matter?

    Show Notes
    • Sonatype report
    • ecosyste.ms
    • GNOME libcue flaw
    • Reality 2.0 supply chain episode
    37 min
  • Episode 397 - The curl and glibc vulnerabilities

    Josh and Kurt talk about a curl and glibc bug. The bugs themselves aren't super interesting, but there are other conversations around the bugs that are interesting. Why don't we just rewrite everything in Rust? Why can't we just train developers to stop writing insecure code. How can AI solve this problem? It's a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won't change.

    Show Notes
    • Curl vulnerability
    • glibc vulnerability
    • Josh's Badge Project
    • Bob Lord's phishing message
    35 min
  • Episode 396 - CLAs are bad, Mkay?

    Josh and Kurt talk about contributor license agreements (CLAs). CLAs used to be seen as a necessary evil, but they're almost certainly bad now. We're seeing CLAs being abused, it's clear now anything controlled by a CLA won't be open source forever.

    Show Notes
    • A Theory of Joint Authorship for Free and Open Source Software Projects
    • Bruce Perens: What Comes After Open Source
    36 min
  • Episode 395 - Uncertainty, trust, and security

    Josh and Kurt talk about uncertainty. There are a bunch of stories in the news lately that really just boil down to uncertainty. Uncertainty is incredibly dangerous for everyone. We are afraid of uncertainty, and often don't really understand why it is. Trust is like a currency and uncertainty erodes trust faster than almost anything else.

    Show Notes
    • Unity's license mess
    • Godot
    • Meta and Salesforce want to re-hire people they fired earlier this year
    • U.S. Debt Credit Rating Downgraded, Only Second Time In Nation's History
    34 min
  • Episode 394 - The lie anyone can contribute to open source

    Josh and Kurt talk about filing bugs for software. There's the old saying that anyone can file bugs and submit patches for open source, but the reality is most people can't. Filing bugs for both closed and open source is nearly impossible in many instances. Even if you want to file a bug for an open source project, there are a lot of hoops before it's something that can be actionable.

    Show Notes
    • Linux is a nightmare
    • Lodash just declared issue bankruptcy and closed every issue and open PR
    • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges
    • Curl NULL pointer dereference
    36 min
  • Episode 393 - Can you secure something you don't own?

    Josh and Kurt talk about the weird world we live in how where we can't control a lot of our hardware. We don't really have control over most devices we interact with on a daily basis. The conversation shifts into a question of how can we decide what to trust and where. It's a very strange problem we experience now.

    Show Notes
    • Boots theory
    • MGM cybersecurity issue shuts down slot machines and ATMs in Las Vegas casinos
    • New York Fire Department Forcible Entry Reference Guide
    • Request for Information on Open-Source Software Security: Areas of Long-Term Focus and Prioritization
    34 min
  • Episode 392 - Curl and the calamity of CVE

    Josh and Kurt talk about why CVE is making the news lately. Things are not well in the CVE program, and it's not looking like anything will get fixed anytime soon. Josh and Kurt have a unique set of knowledge around CVE. There's a lot of confusion and difficulty in understanding how CVE works.

    Show Notes
    • Curl blog post
    • Now it's PostgreSQL's turn to have a bogus CVE
    • GitHub Advisory Database
    • Josh's "CVE tried to get me fired" story
    47 min
  • Episode 391 - The Wordpress 100 year disaster recovery problem

    Josh and Kurt talk about wordpress selling web services with a 100 year lifespan. Will WordPress still be around in 100 years? What would 100 years of disaster recovery look like? Most of us will never need to think about 100 years of disaster recovery.

    Show Notes
    • WordPress is now selling 100-year domains
    • Danish ransomware
    • 15-Minute City
    • The Year Without Pants
    40 min
  • Episode 390 - Rust shipping binaries doesn't matter

    Josh and Kurt talk about a blog post that explains how C and C++ compilers prioritize performance over correctness. This is the class story of security vs usability. Security is never the primary goal. If a security requirement doesn't also enable other business goals it will fail. We also touch on the news of a Rust package containing binary files. It doesn't really have anything to do with security, it's all about convenience.

    Show Notes
    • C and C++ Prioritize Performance over Correctness
    • Nisha's toot
    • Barry Marshall
    • Rust devs push back as Serde project ships precompiled binaries
    • Why DARPA Hopes To 'Distill' Old Binaries Into Readable Code
    • Mario 64 decompilation
    40 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners