Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 359 - The NOTAM outage and other legacy technology

    Josh and Kurt talk about the recent FAA NOTAM outage. Keeping legacy things running for long periods of time is really hard to do, this system is no different. It's also really hard to upgrade many of these due to corner cases and institutional knowledge. There aren't any great answers here, but we do ask a lot of questions about long running tech.

    Show Notes
    • NOTAM outage
    • AIX is not dead
    • IBM Linux commercial
    • Apple A/UX
    • How NOT To Implement the POSIX Standard, Featuring Windows NT
    • iSH
    • Hand Made Vacuum Tubes
    35 min
  • Episode 358 - Furby vs Alexa

    Josh and Kurt talk about the Furby source code going public. This is an opportunity to discuss what's changed in our attitude in devices that record our audio? Our devices today are vastly more powerful and dangerous than a Furby, what does your risk appetite look like?

    Show Notes
    • Furby source code
    • Talking Toy Or Spy?
    • Adam Ruins Everything - Why Jaywalking Is a Crime
    32 min
  • Episode 357 - Is open source being overexploited?

    Josh and Kurt talk about how to think about open source in the context of society. Open source is more like a natural resource than a supplier. It's common to think of open source projects as delivered to us, but it's more like acquiring raw materials from the forest. The problem is we're harvesting the raw materials in an unsustainable manner at the moment.

    Show Notes
    • I am not a supplier
    • Josh's question about the environment
    • sjvn Gorilla toolkit article
    • Gorilla Web Toolkit
    • Awesome Games Done Quick GeoGuessr
    • Awesome Games Done Quick 2023
    34 min
  • Episode 356 - LastPass ducked up, now what?

    Josh and Kurt talk about the LastPass saga. There's a lot of great explanations about what happened, but there hasn't been a lot of info on how to start cleaning up this mess. We rehash some of the existing details then try to untangle what existing users can do to try to start recovering. The real problem is how LastPass is dealing with this, not the technical details.

    Show Notes
    • Great writeup of LastPass
    • Jeremi M Gosney Mastodon explanation
    • Tavis writeup on password managers
    • Use a Passphrase
    36 min
  • Episode 355 - Security Boxing Day

    Josh and Kurt talk about some security gifts for boxing day. We start out with the idea of the security poverty line and discuss a few ideas for how a low resource group can make their open source more secure. There are no simple answers unfortunately.

    Show Notes
    • Wendy Nather
    • Security Poverty Line
    • Boots Theory
    32 min
  • Episode 354 - Jerry Bell tells us why Mastodon is awesome and MFA is hard

    Josh and Kurt talk about how hard multi factor authentication is. This all starts from a Mastodon thread, and Jerry Bell, the administrator of infosec.exchange joins us to discuss password security and all things Mastodon. Infosec.exchange is an incredible story and Jerry weaves a thrilling tale.

    Show Notes
    • infosec.exchange MFA discussion
    • Jerry's 2FA advice
    • MalwareTech retracts Mastodon statements
    32 min
  • Episode 353 - Jill Moné-Corallo on GitHub's bug bounty program

    Josh and Kurt talk to Jill Moné-Corallo about GitHub's bug bounty and product security team. It's a treat to discuss bug bounties with someone who is managing a very large bug bounty for one of the most important web sites in the world of software today.

    Show Notes
    • Jill's Twitter
    • Jill's Mastodon
    • GitHub Bug Bounty
    • Bug bounty scope
    • Eight years of the GitHub Security Bug Bounty program
    • GitHub NPM bug bounty find
    27 min
  • Episode 352 - Stylometry removes anonymity

    Josh and Kurt talk about a new tool that can do Stylometry analysis of Hacker News authors. The availability of such tools makes anonymity much harder on the Internet, but it's also not unexpected. The amount of power and tooling available now is incredible. We also discuss some of the future challenges we will see from all this technology.

    Show Notes
    • Hacker News Stylometry Analyzer
    • FBI Profiler on the Unabomber
    • Impersonate Eli Lilly for $8
    • Shakespeare Stylometry
    33 min
  • Episode 351 - Is security or usability a law of the universe?

    Josh and Kurt talk about end to end encrypted messages. This has been a popular topic lately due to the Mastodon popularity. Mastodon has a uniquely insecure messaging system, but they aren't the only one. The eternal debate of can security and usability exist together? We suspect it can't be, but it's a very complicated topic.

    Show Notes
    • EFF on Mastodon DM privacy
    • Towards End-to-End Encryption for Direct Messages in the Fediverse
    • Pluralistic: 14 Nov 2022 Even if you're paying for the product, you're still the product
    34 min
  • Episode 350 - Spam, Email, Content Moderation, and Infrastructure Oh My

    Josh and Kurt talk about email security and the perils of trying to run your own mail infrastructure. We then get into discussing the value and danger of trying to run your own infrastructure, email, blogs, or most anything. There's a lot to juggle about all this these days, it's complicated.

    Show Notes
    • PowerDMARC
    • Will Dormann
    • GossiTheDog upgrades Exchange
    • lcamtuf's blog
    • I like Ice Cream
    32 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners