Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 368 - The Sovereign Tech Fund with Fiona Krakenbürger

    Josh and Kurt talk to Fiona Krakenbürger about the Sovereign Tech Fund. This is a fund created by Germany to fund important open source projects. Fiona has amazing insight into how this fund was created, what it's doing today to help fund open source. She discusses where we go from here and what the future will look like. The Sovereign Tech Fund is a forward thinking program to fund open source across the world. This episode is a window into the future.

    Show Notes
    • Fiona on Mastodon
    • Sovereign Tech Fund
    • Sovereign Tech Fund Feasibility Study
    • NJ Governor Requests Expertise of 6 People Who Still Know COBOL
    • OpenSSF Criticality Score
    • European critical open source software
    • OSTIF critical open source projects
    • Apply to the Sovereign Tech Fund
    40 min
  • Episode 367 - Open source will never be the same

    Josh and Kurt talk about GitHub enforcing sanctions against an open source developer and Docker changing how their registry works. There's a lot to unpack in this one. There's a lot of happenings going on in the world of open source. We are seeing governments paying attention to open source like never before, change is coming and everything is going to change.

    Show Notes
    • ipmitool Repository Archived, Developer Suspended By GitHub
    • Elixir: Docker now charges open source orgs $300
    33 min
  • Episode 366 - Software liability is coming

    Josh and Kurt talk about the number of dependencies that is now normal. Keeping track of thousands of dependencies used to be impressive, now it's normal. In what instances should we know everything about our open source? The days of being able to ignore your software liability is looking like it's coming to an end.

    Show Notes
    • LTT millenial pause
    • The perverse incentive of vulnerability counting
    • National Cybersecurity Strategy
    35 min
  • Episode 365 - "I am not your supplier" with Thomas Depierre

    Josh and Kurt talk to Thomas Depierre about his "I am not a supplier" blog post. We drink from the firehose on this one. Thomas describes the realities and challenges of being an open source maintainer. What open source and society owe each other. How safety can help describe what we see. There's too many topics to even list. The whole episode is an epic adventure through modern open source.

    Show Notes
    • Thomas on Mastodon
    • I am not a supplier
    • The Treachery of Images (Ceci n'est pas une pipe)
    • Atlantic Council report
    • The Field Guide to Understanding 'Human Error'
    • Google wants new rules for developers working on 'critical' projects
    • Roads and Bridges:The Unseen Labor Behind Our Digital Infrastructure
    • Sovereign Tech Fund
    53 min
  • Episode 364 - Using SBOMs is hard

    Josh and Kurt talk about SBOMs. Quite a bit has happened in the world of SBOMs in the last year or so. There are going to be different types of SBOMs, like build, source, or runtime. Each will tell us different things depending on what we need to know. We also cover some of the community efforts happening around SBOMs. They're still not easy to use, but it's better better.

    Show Notes
    • SBOM Types draft
    • SBOM Drift
    • OpenSSF SBOM Everywhere
    37 min
  • Episode 363 - Joylynn Kirui from Microsoft on DevSecOps

    Josh and Kurt talk to Joylynn Kirui about DevSecOps in the Microsoft universe. Joylynn gives us an overview of the current state of devops and tells us about some of the tools Microsoft has made available to the open source universe.

    Show Notes
    • Joylynn Kirui
    • Joylynn on DVT Tech Insights
    • Episode 174 - a chat with GitHub about CodeQL
    • S2C2F
    • Azure Open Source Day
    32 min
  • Episode 362 - A lesson in Rust from Carol Nichols

    Josh and Kurt talk to Carol Nichols about Rust. Carol is an authority on Rust and helps us understand how Rust works, why it's different. Why Rust doesn't have the same problems C and C++ have, and what the future of it all could look like. It's a really fun show with some great questions from Carol along the way.

    Show Notes
    • Carol Nichols on Mastodon
    • The Rust Programming Language, 2nd Edition
    • Rust book online
    • Netflix tech blog on Java performance
    • Rust in the context of Railroad Brakes
    • Kees Cook blog - Bounded Flexible Arrays in C
    • Consumer Reports on memory safety
    • OSS-Fuzz and Rust
    42 min
  • Episode 361 - GitHub got pwnt, but it wasn't very exciting

    Josh and Kurt talk about the recent GitHub breach. It wasn't terribly exciting, but there are some interesting conversations to have around securing certificates, source code, and hardware security modules. In general GitHub did most things right on this one.

    Show Notes
    • GitHub blog post
    • Hacker History Podcast episode with Robert
    • Super Mario 64 decompile
    • Mario 64 built without optimization
    • Link to the Past source code
    34 min
  • Episode 360 - Memory safety and the NSA

    Josh and Kurt talk about the NSA guidance on using memory safety issues. The TL;DR is to stop using C. We discuss why C has so many problem, why we can't fix C, and what some alternatives looks like. Even the alternatives have their own set of issues and there are many options, but the one thing we can agree on is we have to stop using C.

    Show Notes
    • NSA Releases Guidance on How to Protect Against Software Memory Safety Issues
    • Drum memory and the story of Mel
    • Netflix performance
    • Discord Go vs Rust
    • NVIDIA switch to Spark
    35 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners