Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 218 - The past was a terrible place

    Josh and Kurt talk about change. Specifically we discuss how the past was a terrible place. Never believe anyone who tells you it was better. Part of a career now is learning how to learn. The things you learn today won't be useful skills in a few years. The future is is always better than the past. Even in 2020.

    Show Notes

    • I no longer build software
    • Temple OS
    • Top Gear electric car
    • 1959 Bel Air crash test
    30 min
  • Episode 216 - Security didn't find life on Venus

    Josh and Kurt talk about how we talk about what we do in the context of life on Venus. We didn't really discover life on Venus, we discovered a gas that could be created by life on Venus. The world didn't hear that though. We have a similar communication problem in security. How often are your words misunderstood?

    Show Notes

    • Phosphine on Venus
    • GPS and relativity
    32 min
  • Episode 215 - Real security is boring

    Josh and Kurt talk about attacking open source. How serious is the threat of developers being targeted or a git repo being watched for secret security fixes? The reality of it all is there are many layers in a security journey, the most important things you can do are also the least exciting.

    Show Notes

    • Targeting developers
    • XKCD Infrastructure comic
    • Hiding security flaws in git
    • Mossad vs Not-Mossad (PDF warning)
    31 min
  • Episode 213 - Security Signals: What are you telling the world

    Josh and Kurt talk about how your actions can tell the world if you actually take security seriously. We frame the discussion in the context of Slack paying a very low bug bounty and discover some ways we can look at Slack and decide if they do indeed take our security very seriously.

    Show Notes

    • Reddit carbon monoxide Part 1 Part 2
    • GCP Grey minus infinity
    • Josh's blog post
    33 min
  • Episode 212 - Grab Bag: The Security We Deserve Edition

    Josh and Kurt talk about Chromium sending traffic to root DNS servers. Telemetry watching what we do. Cryptocurrency scams and a few other random topics. Also pandas.

    Show Notes

    • Blanket rack
    • Chromium DNS traffic
    • Ubuntu MOTD
    • Microsoft telemetry
    • YAM coin implodes
    • Panda Cubs
    30 min
  • Episode 211 - The only thing harder than signing files is managing users

    Josh and Kurt talk about the Microsoft 2 year old signature bug and Github no longer processing MFA resets for free users. Signing things is hard, but trying to manage users and infrastructure at scale is even harder.

    Show Notes

    • Microsoft signed jar bug
    • GitLab Support is no longer processing MFA resets for free users
    • Someone Is Hijacking Tor Exit Nodes to Conduct MITM Attacks
    30 min
  • Episode 210 - Cult of Information Security

    Josh and Kurt talk about the current state of information security. There are aspects that resemble a cult more than we would like. It's not all bad though, there are some things we can do to help move things forward. This episode shouldn't be taken too seriously.

    Show Notes

    • "cult of information security"
    • How to start a cult
    29 min
  • Episode 209 - Secure Boot isn't Secure

    Josh and Kurt talk about Secure Boot. The conversation uses the recent "Boot Hole" vulnerability to frame a conversation about what Secure Boot is and isn't. Why the Boot Hole flaw doesn't really matter, and why Secure Boot was very scary for Linux users back when it came out.

    Show Notes

    • Boot Hole
    34 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners