Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 289 - Who left this 0day on the floor?

    Josh and Kurt talk about an unusual number of really bad security updates. We even recorded this before the Azure OMIGOD vulnerability was disclosed. It's certainly been a wild week with Apple and Chrome 0days, and a Travis CI secret leak. Maybe this is the new normal.

    Show Notes
    • Matrix 4 trailer
    • Travis CI issue
    • Apple 0day patches
    • Chrome 0day patches
    • CGP Grey Where is the European Union
    34 min
  • Episode 288 - Linux Kernel compiler warnings considered dangerous

    Josh and Kurt talk about some happenings in the Linux Kernel. There are some new rules around how to submit patches that goes against how GitHub works. They're also turning all compiler warnings into errors. It's really interesting to understand what these steps mean today, and what they could mean in the future.

    Show Notes
    • The Register Linux story
    • OpenSSL Release Notes
    36 min
  • Episode 287 - Is GitHub's Copilot the new Clippy?

    Josh and Kurt talk about GitHub Copilot. What can we learn from a report claiming 40% of code generated by Copilot has security vulnerabilities? Is this the future or just some sort of strange new thing that will be gone as fast as it came?

    Show Notes
    • GitHub Copilot
    • Copilot research paper
    32 min
  • Episode 285 - Open source owes you nothing!

    Josh and Kurt talk about open source bugs. What happens if a project decides to close most of their bugs? Nothing really. Bug trackers aren't a help desk.

    Show Notes
    • Emacs closes 45% of bugs
    • UVI
    • Tesla investigation
    • UK COVID spreadsheet
    33 min
  • Episode 284 - What happens when we DRM power tools?

    Josh and Kurt talk about a Home Depot plan to put DRM on power tools. Anyone can add a computer to anything for a few dollars now. How secure is any of this. What does it mean when the things we buy start to acquire DRM? There are a lot of new questions we don't have any real answers for.

    Show Notes
    • Home Depot power tools
    • Ray Ozzie's IoT board
    • First-sale doctrine
    36 min
  • Episode 283 - When vulnerability disclosure becomes dangerous

    Josh and Kurt talk about a very difficult disclosure problem. What happens when you have to report a vulnerability to an ethically questionable company? It's less simple than it sounds, many of the choices could end up harming victims.

    Show Notes
    • Disclosure Dilemmas
    • @evacide
    • Bob Diachenko
    • This Is How They Tell Me The World Ends
    35 min
  • Episode 282 - The security of Rust: who left all this awesome in here?

    Josh and Kurt talk about a story from Microsoft declaring Rust the future of safe programming, replacing C and C++. We discuss how tooling affects progress and why this isn't always obvious when you're in the middle of progress.

    Show Notes

    • Microsoft: Rust Is the Industry's 'Best Chance' at Safe Systems Programming
    • Josh's devopsdays talk
    • Microsoft moved font handling out of the kernel
    • Atari 2600 emulator in Minecraft
    • Rate of technology adoption
    31 min
  • Episode 281 - If you spy on journalists, you're the bad guys

    Josh and Kurt talk about the news that the NSO Group is widely distributing spyware onto a large number of devices. This news should be a wake up call for anyone creating devices and systems that could be attacked, it's time to segment services. There's not a lot individuals can do at this point, but we have some ideas at the end of the episode.

    Show Notes
    • NSO Group spying
    • Technical details Twitter thread
    • Are we the Baddies?
    33 min
  • Episode 280 - The perils of Single Sign On

    Josh and Kurt talk about what happens when you lose access to your Single Sign On provider. These providers have become critical to many of us, if we lose access to our SSO account we will lose access to many services.

    Show Notes
    • Postbank
    31 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners