Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 348 - OpenSSL is the new lead paint

    Josh and Kurt talk about the recent OpenSSL nothingburger. OpenSSL got everyone whipped into a frenzy over a critical vulnerability, then changed the severity to high. The correct solution to this whole problem is to stop using a TLS library written in C, we need to be using memory safe languages. Don't migrate from OpenSSL 1 to 3, migrate from OpenSSL 1 to Rustls.

    Show Notes
    • OpenSSL Blog Post
    • OpenSSL pre-announcement
    • Mark Cox Tweet 3.0 only affected
    • GossiTheDog NDA Tweet
    • Claims of a name and logo
    • Rustls

    Image Credit

    34 min
  • Episode 347 - Airtags in luggage and weasel security - two peas in a suitcase

    Josh and Kurt talk about Lufthansa trying to ban Airtags. This has a similar feel to all the security events where a company tries to hand waive away a security problem then having to walk back all their previous statements. There is almost always a massive imbalance between the large companies and consumers.

    Show Notes
    • Lufthansa bans airtags
    • Airtag stalking problems
    • Lufthansa unbans airtags
    • Cult of the Dead Cow book
    • TV Typewriter
    • Andre the Giant on an airplane
    • Poison Squad
    34 min
  • Episode 346 - Security and working from home have terrible things in common

    Josh and Kurt talk about stories detailing tech working with multiple jobs. This raises some questions about fairness, accountability, and the future of work. As an industry we are very bad at measuring what we do, which is a problem shared with many jobs currently working from home.

    Show Notes
    • Equifax surveilled 1,000 remote workers, fired 24 found juggling two jobs
    • Business Insider 2 jobs story
    • Ken Thompson lines of code
    33 min
  • Episode 345 - Cheap hacking devices turn security upside down

    Josh and Kurt talk about ineffective security from the past we still use today. There has been a great deal of progress in the last few decades bringing us amazing products like the Flipper Zero, cameras that can peer inside locks, and even software defined radio. A great deal of security relies on people not having easy access to these cheap devices. What does this mean for the future of security?

    Show Notes
    • Cloning a Rare ISA Card to Use a Rare CD Drive
    • Vintage Tech YouTubers Discussion Panel | VCFMW 17 (2022)
    • Flipper Zero
    • Lock camera
    • HackRF One
    • The history of Hash
    • Reddit post-it notes in apartment
    31 min
  • Episode 344 - Python tarfile - 2022 is nothing like 2007

    Josh and Kurt talk about a newly rediscovered old python vulnerability. It raises a lot of questions about what was OK in 2007 vs what's OK in 2022. The issue is very complicated and has a wild story surrounding it. There is no reason to not fix this in 2022.

    Show Notes
    • CVE-2007-4559
    • Red Hat Bug
    • Register story
    • Response from upstream
    • Upstream patch
    • ZippSlip
    • Current upstream bug
    • CSURF
    35 min
  • Episode 343 - Stop trying to fix the open source software supply chain

    Josh and Kurt talk about a blog post that explains there isn't really an open source software supply chain. The whole idea of open source being one thing is incorrect, open source is really a lot of little things put together. A lot of companies and organizations get this wrong.

    Show Notes
    • Iliana's Twitter
    • There is no "software supply chain"
    • Google supply chain blog
    • GitHub ansi_term advisory
    • PyPI 2FA Dashboard
    • tarfile issue rediscovered in 2022
    33 min
  • Episode 341 - Time till open source alternative

    Josh and Kurt talk about the Time Till Open Source Alternative blog post. The numbers probably don't mean what we think they mean anymore. A lot of modern open source is really corporate controlled. Just because something carries an open source license doesn't mean you can contribute to it.

    Show Notes
    • Time Till Open Source Alternative
    • GitHub Desktop issue 78
    • The Reddit Safe
    36 min
  • Episode 340 - Let's chat about Let's Encrypt with Josh Aas

    Josh and Kurt talk with Josh Aas from the Internet Security Research Group about Let's Encrypt, Prossimo, and Divvi Up. A lot has changed since the last time we spoke with Josh. Let's Encrypt won, and the ISG are working on some really cool new projects.

    Show Notes
    • Josh Aas
    • Internet Security Research Group (ISRG)
    • Let's Encrypt
    • Episode 87 – Chat with Let's Encrypt co-founder Josh Aas
    • New Major Funding from the Ford Foundation
    • ISRG annual reports
    • Peter Eckersley
    34 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners