Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 299 - Experts From A World That No Longer Exists

    Josh and Kurt talk about an article about how expertise has a limited lifetime. We are all experts in something, but some of us will find our expert knowledge to be outdated eventually. We discuss what that means in the context of security and tech and disagree about how to best keep your skills up to date.

    Show Notes
    • Experts From A World That No Longer Exists
    • Neuroplasticity
    • Scotty and the mouse
    • Git 2.34
    • 4H Public Speaking
    35 min
  • Episode 298 - David A Wheeler discusses the OpenSSF

    Josh and Kurt talk to David A. Wheeler about everything OpenSSF. The Open Source Security Foundation is part of the Linux Foundation, and there are 6 OpenSSF working groups. David does a great job explaining how the OpenSSF works and what the 6 working groups are doing. The working group are (in no particular order): Identifying Security Threats, Security Tooling, Best Practices, Vulnerability Disclosures, Digital Identity Attestation, Securing Critical Projects.

    Show Notes
    • David A Wheeler
    • Episode 14 – David A Wheeler: CII Badges
    • Sigstore joins the OpenSSF
    • OpenSSF Technical Working Groups
    • NPM requires MFA
    • LISH
    • Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks
    39 min
  • Episode 297 - 25 years of smashing stacks, fun, and profit

    Josh and Kurt talk about the famous Phrack 49 article "Smashing the Stack for Fun and Profit" turning 25 years old. This paper created a massive amount of change in the industry, possibly more than any other paper ever written. Everything from making exploiting stack overflows easier, to defenders creating technologies such as stack canaries are the direct result of this work.

    Show Notes
    • Phrack 49
    • Kurt's Interview with Elias Levi aka Aleph One
    34 min
  • Episode 296 - Is Trojan Source a vulnerability?

    Josh and Kurt talk about the new Trojan Source bug. We don't always agree on if this is a vulnerability (it's not), but by the end we come to an agreement that ASCII is out, Unicode is in. We don't live in a world where you can make a realistic suggestion to return to using only ASCII. There are a lot of weird moving parts with this one.

    Show Notes
    • Trojan Source
    • oss-security message
    • GitHub example
    34 min
  • Episode 295 - Open source security isn't free

    Josh and Kurt talk about Josh's electric car and new job. We then talk about the recent UAParser.js malware incident. There have been a lot of calls to do more to secure open source, but nobody seems to have any concrete proposals or suggestions to fund any of these activities.

    Show Notes
    • UAParser.js
    • CISA announcement
    34 min
  • Episode 294 - Chris Wysopal on the state of security education

    Josh and Kurt talk to Chris Wysopal, AKA Weld Pond, about security education. We talk about the current state of how we are learning about security as students and developers. What the best way to get developers interested in learning more about security? We end the show with fantastic advice from Chris for anyone new to the field of technology or security.

    Show Notes
    • Chris Wysopal
    • Veracode
    • l0phtcrack
    33 min
  • Episode 293 - Scoring OpenSSF Security Scoring

    Josh and Kurt talk about the release of OpenSSF Security Scorecards version 3. This is a great project that will probably make a huge difference. Most of the things the scorecards are measuring are no brainier activities. We go through the list of metrics being measured. There are only a few that we don't think are fantastic.

    Show Notes
    • 4 of spades
    • OpenSSF
    • Chris Montgomery audio explanation
    • Scorecard 3.0.0
    • Scoring criteria
    • Python Skeleton
    35 min
  • Episode 292 - Apache RCE and Twitch epic pwn

    Josh and Kurt talk about the recent Twitch hack and how in the modern age leaking source code almost certainly doesn't matter. The leaked data however is a big deal. We also discuss a recent Apache httpd update. Some things went right, some things went wrong. Dealing with vulnerabilities is hard.

    Show Notes
    • Parasocial Relationship
    • Twitch Hack
    • Soviet B-29 Clone
    • Apache CVE
    • Apache Advisory
    • GossiTheDog Tweet
    • Hacker Fantastic exploit
    31 min
  • Episode 291 - Everyone sucks at vulnerability disclosure

    Josh and Kurt talk about recent events around Apple and Microsoft disclosing security vulnerabilities. Microsoft usually does a good job, but Apple has a long history of not having a great bug bounty or vulnerability disclosure policy. None of this is simple, but hopefully you'll have some fun and learn a bit about the whole vulnerability disclosure process.

    Show Notes
    • Apple 0days
    • Microsoft Exchange flaw
    • THIS IS HOW THEY TELL ME THE WORLD ENDS
    • Linux Foundation Vulnerability Disclosure
    • Timezone problem
    36 min
  • Episode 290 - The security of the Matrix

    Josh and Kurt talk about the security of the Matrix movie series. There was a new Matrix trailer that made us want to discuss some of the security themes. We talk about how the movie is very focused on computing in the 90s. How Neo probably ran Linux and they used a real ssh exploit. How a lot of the plot is a bit silly. It's a really fun episode.

    Show Notes
    • Matrix 4 trailer
    • nmap in the Matrix
    • VFX Artists react to the Mandalorian
    • Glasshouse
    • Universal Paperclips
    36 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners