Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 379 - Will open source save the world, again?

    Josh and Kurt talk about some new open source projects that aim to start taking back some of our privacy and rights. It's a huge hill to climb, but it seems like there is some hope. Open source doesn't care about growth, or numbers, or anything really, so it can't ever lose.

    Show Notes
    • Codeberg
    • Veilid
    • Hawkins Cheezies
    • Apollo's Reddit API costs
    35 min
  • Episode 378 - Naming things is harder than security

    Josh and Kurt talk about namespaces. They were a topic in the last podcast, and resulted in a much much larger discussion for us. We decided to hash out some of our thinking in an episode. This is a much harder problem than either of us expected. We don't have any great answers, but we do have a lot of questions.

    Show Notes
    • Not Red Hat
    • NPM hash package
    • Episode 129 – The EU bug bounty program
    32 min
  • Episode 377 - The world is changing too fast for humans to understand

    Josh and Kurt talk about PyPI suspending new accounts and packages for a day, and a 60 minutes story about deepfakes. The problems are mostly the same, but for very different reasons. The world is changing faster than we can keep up, so what is a human to do?

    Show Notes
    • PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted](https://thehackernews.com/2023/05/pypi-repository-under-attack-user-sign.html)
    • 60 minutes reporter voice clone
    • Cooridor Crew deepfakes
    • Certificate bit flip
    • Candy is delicious
    38 min
  • Episode 376 - Open Source Summit, who built your open source, and AI

    Josh and Kurt talk about the Open Source Summit in Vancouver. Josh was there and we pick on two observations. Firstly that security keeps trying to use fear as a feature, except it doesn't work. Secondly we discuss AI and how people are talking about it. It is changing things, how much is yet to be seen.

    Show Notes
    • SLSA
    • FRSCA
    • S2C2F
    • MSI leak
    • Intel microcode
    • Tom Scott AI Video
    37 min
  • Episode 375 - The market forces of left-pad, Episode 77 remaster part 2

    Josh and Kurt finish up the leftpad discussion. We spent a lot of time talking about how the market will respond to these sort of events, and the market did indeed speak; very little has changed. There is an aspect of all these security events where we need to understand the cost vs benefit just isn't there. it may never be there. Rather than whine and complain, we need to work with our constraints.

    Show Notes
    • Episode 77 – npm and the supply chain
    30 min
  • Episode 374 - The event we called left-pad, Episode 77 remaster part 1

    Josh and Kurt revisit Episode 77, which was named "npm and the supply chain" but was a discussion about the incident we all know now as "leftpad". We didn't understand what was happening at the time, but this would become an event we talk about for years to come. It's shocking how many of the things we discuss are still completely valid five years later.

    Show Notes
    • Episode 77 – npm and the supply chain
    30 min
  • Episode 372 - HHGG security, Episode 42 remaster part 1

    The podcast is on a hiatus for a little while due to some personal matters, but that creates an opportunity to remaster some fun old episodes. These shows are REALLY hard to listen to at the current quality (tools and talent has come a long way in the last few years).

    This is a remaster of Episode 42 which is all about the security in the Hitchhiker's Guide to the Galaxy movie. It's a fun show and it's shocking how many of these security themes are still relevant today.

    Show Notes
    • Original Episode 42
    31 min
  • Episode 371 - pip install is the tool we deserve but not the tool we need

    Josh and Kurt talk about a blog post about pip and virtual environments. This eventually turns into a larger conversation around packaging tools and how we see incremental changes over time. The package ecosystems were what we needed a few years ago, but our needs have changed.

    Show Notes
    • One Does Not Simply 'pip install'
    • Dag Wieers RPM
    • Webfinger GitHub repo
    35 min
  • Episode 370 - Open Source is bigger than you can imagine

    Josh and Kurt talk about some data on the size of NPM. Josh wrote a blog post and a report about the amount of SEO spam in NPM was released. Open source is enormous, and it's mostly one person. It's hard to imagine how this all works sometimes and this lack of understanding can create challenges.

    Show Notes
    • Josh's blog on the size of NPM
    • One In Two New Npm Packages Is SEO Spam Right Now
    • Linux Kernel power distribution graph
    34 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners