Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 389 - What would HashiCorp do?

    Josh and Kurt talk about the HashiCorp license change and copyright problems in open source. This isn't the first and won't be the last time we see this, but it's very likely open source developers and communities will view any project that has a contributor license agreement as a problem moving forward.

    Show Notes
    • Josh's BSidesLV talk
    • Hacker News marked site as malware
    • HashiCorp license change
    • A Theory of Joint Authorship for Free and Open Source Software Projects
    43 min
  • Episode 388 - Video game vulnerabilities

    Josh and Kurt ask the question what is a vulnerability, but in the framing of video games. Security loves to categorize all bugs as security vulnerabilities or not security vulnerabilities. But the reality nothing is so simple. Everything is a question of risk, not vulnerability. The discussion about video games can help us to better have this discussion.

    Show Notes
    • Colossus bug
    • Minecraft Heist
    33 min
  • Episode 387 - Enterprise open source is different

    Josh and Kurt talk about the difference between what we think of as traditional open source, and enterprise software projects that have an open source license. They are both technically open source, but how the projects work is very very different.

    Show Notes
    • CentOS Stream PR
    • The Most Prolific Packager For Alpine Linux Is Stepping Away
    35 min
  • Episode 386 - We are watching web 2.0 burn

    Josh and Kurt talk about a new Google proposal that would add DRM for the web. All the ad driven companies seem to be acting very strangely, there's probably a reason for this. The way ads used to pay for content is changing, but a lot of these giant companies don't know how to adapt. It's going to be very interesting times in the near future.

    Show Notes
    • Web Environment Integrity
    • Hacker News Thread
    • Island Browser
    • hunter2
    32 min
  • Episode 385 - Is open source an insider threat?

    Josh and Kurt talk about insider threats, but not quite in the way one would expect. The potential for insider threats is possibly higher than usual right now, but what about open source? Are open source developers insider threats for your organization? Have you ever thought about this before?

    Show Notes
    • CISA insider threats
    • hacks4pancakes toot
    • Don't Trust a Programmer Who Knows C++
    • CISA Insider Threat Mitigation
    34 min
  • Episode 384 - What's next for open source?

    Josh and Kurt talk about some of the efforts to measure and understand open source. There are projects like the OpenSSF Scorecard. We want to measure open source for some idea of quality. Is AI generated code better than a random open source project found on GitHub? Can we track the countries contributors are from? These are all interesting problems that everyone will have to deal with soon.

    Show Notes
    • OpenSSF Scorecard
    42 min
  • Episode 383 - Is open source dying?

    Josh and Kurt talk about the notion that open source is somehow dying. What's actually happening is corporate open source is changing, which some are trying to deform into something wrong with open source. Open source is doing great, probably better than ever.

    Show Notes
    • Open Source isn't sustainable anymore
    • VORON Design
    • Video of the first lathe
    • Plane Crazy
    • Evernote layoffs
    37 min
  • Episode 382 - Red Hat, you were the chosen one!

    Josh and Kurt talk about Red Hat closing up the RHEL source code. Kurt and Josh both worked at Red Hat in the past. This isn't a show that bashes Red Hat, and it's not a show praising them. We take an honest look at the past, present, and future of Linux. There's a lot to talk about in this one. TL;DR, Red Hat was the chosen on, and we all feel betrayed.

    Show Notes
    • Red Hat's first blog post
    • Red Hat's honest post
    • DeWitt clause
    38 min
  • Episode 381 - WTF Reddit, APIs and risk

    Josh and Kurt talk about the incredible Reddit debacle. At the center of it all is an API. What does it mean to be using an API and how does this relate itself back to our own risk. Many of us rely on APIs for countless things, and if a company decides to cut off that API somehow, it could create a mess.

    Show Notes
    • Grimace's Birthday
    • Reddit's new API pricing will kill off Apollo on June 30
    • Cory Doctorow enshitification
    • Wal Mart pickle story
    • Elon Musk and Mark Zuckerberg agree to hold cage fight
    37 min
  • Episode 380 - A new Sovereign Tech Fund program and the BBC on destroying hard drives

    Josh and Kurt talk about a new program from the Sovereign Tech Fund to fund open source work. It's a great looking program with an acceptable amount of money behind the program. We also talk about a story claiming millions of perfectly good hard drives are destroyed per year. They're probably not OK at all.

    Show Notes
    • Sovereign Tech Fund Challenges
    • Why millions of usable hard drives are being destroyed
    • LTT Buys Storage Array
    33 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners