Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 319 - Patch Tuesday with a capital T

    Josh and Kurt talk about a lot of security vulnerabilities in this month's Patch Tuesday. There's also a new Git vulnerability. This sparks the age old question of how fast to patch? The answer isn't binary, the right answer is whatever works best for you, not what someone tells you is best.

    Show Notes
    • Patch Tuesday
    • Git security update
    31 min
  • Episode 318 - Social engineering and why zlib got a 2018 CVE ID

    Josh and Kurt talk about hackers using emergency data requests to gain access to sensitive data. The argument that somehow backdoors can be protected falls under this problem. We don't yet have the technical or policy protections in place to actually protect this data. We also explain why this zlib issue got a 2018 CVE ID in 2022.

    Show Notes
    • Hackers using fake emergency data requests
    • CVE-2018-25032
    • Global Security Database
    31 min
  • Episode 317 - The lack of compromise in security

    Josh and Kurt talk about the binary nature of security. Many of our ideas are yes or no, there's not much in the middle. The conversation ends up derailed due to a Twitter thread about pinning dependencies. This gives you an idea how contentious of a topic pinning is. The final takeaway is not to let security turn into your identity, it ends up making a mess.

    Show Notes
    • Josh's Twitter thread
    • How to install week old npm packages
    33 min
  • Episode 316 - You have to use open source

    Josh and Kurt talk about the latest NPM backdoored package. It feels like this keeps happening. We talk about why this is and why it's probably OK. Kurt fixes Linus' Law, in open source the superpower isn't bugs are shallow (they're not), the superpower is security bugs in open source can't be ignored.

    Show Notes
    • node-ipc protestware
    31 min
  • Episode 315 - Who even makes all these terrible decisions?

    Josh and Kurt talk about Microsoft accidentally letting us find out about ads in file explorer. Changing your clocks sucks. And touch on some of the security implications of the Russian invasion and sanctions. There are a lot of security lessons we can all learn. Mostly what not to do.

    Show Notes
    • Ads in Windows Filemanager
    • Russia running out of storage
    • Russia threatens to nationalize industry
    • Onagawa Nuclear Power Plant
    • Cockcroft's Follies
    • German government advises citizens to uninstall Kaspersky
    34 min
  • Episode 314 - The Linux Dirty Pipe vulnerability

    Josh and Kurt talk about the Linux Kernel Dirty Pipe security vulnerability. This bug is an amazing combination of amazing complexity, incredible simplicity, and a little bit of luck. The discovery is amazing, the analysis is enlightening. There's almost no way a bug like this could be found outside of open source.

    Show Notes
    • Dirty Pipe Writeup
    27 min
  • Episode 313 - Insecurity at scale

    Josh and Kurt talk about the challenges of security at scale. Specifically we focus on why a lot of security starts to fall apart once you have to do something more than a few times. There's a lot of new thinking we need to push security forward.

    Show Notes
    • Stable Linux Kernel and Machine Learning
    32 min
  • Episode 312 - The Legend of the SBOM

    Josh and Kurt talk about SBOMs. Not what they are, there's plenty about that. We talk about why everyone keeps claiming they're super important, and why we're starting to see some people question if we really need them. SBOMs are part of a future that's still being invented.

    Show Notes
    • Questioning SBOMs
    • Rezilion Log4j diagram
    • David A Wheeler on CII Badges
    • Using open source is communism
    35 min
  • Episode 311 - Did you scan the QR code?

    Josh and Kurt talk about the Coinbase Super Bowl ad. It was a QR code, lots of security people were aghast at how many people scanned the QR code. The reality is scanning QR codes isn't dangerous. What other security advice just won't go away?

    Show Notes
    • Coinbase Ad
    • Kurt's Twitter question
    • QR code parking scam
    • Mossad or not Mossad
    • Kurt's talk
    33 min
  • Episode 310 - Hayley Tsukayama from the EFF talks about privacy

    Josh and Kurt talk to Hayley Tsukayama from the EFF about privacy. We all know privacy in the modern age is very complicated and difficult. Normal people don't have many allies when it comes to privacy. The EFF has been blazing the trail for digital rights for more than 30 years! This episode has a ton of amazing details, it's easy to see how the EFF became the jewel of the Internet.

    Show Notes
    • Hayley's Twitter
    • EFF
    • How to Fix the Internet
    • Episode 277 – Privacy and activism with Chris Weiland
    • Washington State privacy bill
    • Join the EFF (seriously, do this!)
    38 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners