Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 339 - Is a network problem a security vulnerability

    Josh and Kurt talk about really weird networking bugs. Josh tells a story about his home network problems that made no sense. There was also a qt5 bug that affected wireless networks that made virtually no sense. What should count as a security vulnerability?

    Show Notes
    • Resolving an unusual wifi issue
    • Hacker News thread
    • Global Security Database
    • IdeaPad 5 14ARE05
    39 min
  • Episode 338 - The government didn't make vulnerabilities illegal. Yet.

    Josh and Kurt talk about the recent National Defense Authorization Act that requires security vulnerabilities to be fixed. What does this mean for us, is it as bad as some people are claiming it is? It's actually not a huge deal, for most of us it's really just time to deal with product security.

    Show Notes
    • The Hacker Mind
    • The Untold Stories of Open Source
    • H.R.7900 - National Defense Authorization Act for Fiscal Year 2023
    • Kurt's blog post
    37 min
  • Episode 337 - Security patches are getting worse - Dustin Childs from ZDI tells us why

    Josh and Kurt talk to Dustin Childs about the recent ZDI Black Hat talk where they discovered the current trend of security patches not actually fixing the security problem. We talk about what this problem means. Why is it happening, and what ZDI is doing to try nudge the industry in the right direction.

    Show Notes
    • Dustin Childs
    • ZDI
    • Sloppy Software Patches Are a 'Disturbing Trend'
    • Zero Day Initiative launches new bug disclosure timelines
    • ISO 28147
    32 min
  • Episode 336 - We don't have data, we have security biases

    Josh and Kurt talk about our lack of security and some of the data bias problems that can emerge. A lot of what we think is security data is really just biased data. This is OK as long as we understand the data is broken and know this is the first step in a longer journey.

    Show Notes
    • Tweet about data
    • The 6 most common types of bias when working with data
    • Syft and Grype stars graph
    • John Snow, Cholera, the Broad Street Pump
    • Bob Lord tweet
    34 min
  • Episode 335 - Bull*&$% security ideas

    Josh and Kurt talk about a tweet from @kmcquade3 asking the question "What's a concept in security that is generally accepted as true but is actually bull%$#*?" How many of the replies make sense? Most of them do. We go over some of the best replies as fast as we can.

    Show Notes
    • The tweet that started it all
    • Mark Loveless
    • Mark Manning
    • Richard (Dick) Brooks
    • @ImbecillicusRex
    • What Train Have We Got?
    • Dan
    • Alejo 🏳️‍🌈
    • postmodern
    • 🇺🇸 Robert C. Seacord 🇺🇦
    • Yip Wai Peng
    • Sachin Shahi
    39 min
  • Episode 334 - Leap seconds break everything

    Josh and Kurt talk about leap seconds. Every time there's a leap second, things break. Facebook wants to get rid of them because they break computers, but Google found a clever way to keep leap seconds without breaking anything. Corner cases are hard, security is often just one huge corner case. There are lessons we can learn here.

    Show Notes
    • How and why the leap second affected Cloudflare DNS
    • Facebook wants to get rid of leap seconds
    • Leap Smear
    • Falsehoods programmers believe about time
    33 min
  • Episode 333 - Open Source is unfair

    Josh and Kurt talk about Microsoft creating a policy of not allowing anyone to charge for open source in their app store. This policy was walked back quickly, but it raises some questions about how fair or unfair open source really is. It's mostly unfair to developers if you look at the big picture.

    Show Notes
    • Syft
    • Grype
    • Microsoft bans and unbans open source
    • Tidelift survey
    • Bruce Perens - What comes after open source
    35 min
  • Episode 332 - PyPI: 2FA or not 2FA, that is the question

    Josh and Kurt talk about PyPI mandating two factor authentication for the top 1% of projects. It feels like a simple idea, but it's not when you start to think about it. What problems does 2FA solve? How common are these attacks? What are the second and third order effects of mandating 2FA? This episode should have something for everyone on all sides of this discussion to violently disagree with.

    Show Notes
    • PyPI announcement
    • NPM expired domains
    • Morten Linderud Tweet
    • Congratulations: We Now Have Opinions on Your Open Source Contributions
    40 min
  • Episode 331 - GPG, but nothing makes sense

    Josh and Kurt talk about their very silly GPG key management from the past. This is sadly a very true story that details how both Kurt and Josh protected their GPG keys. Josh's setup is like something out of a very bad spy novel. It was very over the top for a key that really didn't matter.

    Show Notes
    • XKCD signed email
    • Shire calendar
    • Guardian editors destroy Snowden laptop
    36 min
  • Episode 330 - The sliding scale of risk: seeing the forest for the trees

    Josh and Kurt talk about the challenge of dealing with vulnerabilities at a large scale. We tend to treat every vulnerability equally when they are not equal at all. Some are trees we have to pay very close attention to, and some are part of a larger forest that can't be treated as individual vulnerabilities. We often treat risk as a binary measurement instead of a sliding scale.

    Show Notes
    • gsd.id
    • The Register OpenSSL story
    • OpenSSL bug
    39 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners