Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Episode 187 - Wireguard vs IPsec: the OK Boomer of security

    Josh and Kurt talk about Wireguard. There have been a lot of recent conversations about it and if it's better or worse than other VPN solutions. It's safe to say in our modern age, less is usually more, especially when it comes to security. Wireguard has a lot going for it, it can't be ignored.

    Show Notes
    • Replacing a Nintendo Switch fan
    • WireGuard
    • Hacker News discussion
    31 min
  • Episode 186 - Endpoint security with Tony Meehan

    Josh and Kurt talk to Tony Meehan from Elastic (formerly Endgame) about endpoint detection, response, protection, and even SIEM. Tony has a great history coming from the NSA and has a number of great stories to help understand the topics.

    Show Notes
    • Tony Meehan
    • Rob Joyce on Disrupting Nation State Hackers
    • Bobby Filar living off the land blog
    • Dwell time graph
    • Snowboarder vs Tree
    31 min
  • Episode 185 - Is it even possible to fix open source security?

    Josh and Kurt talk about the Linux Foundation Census 2. There is a lot of talk around how to fix open source security, but the reality is we can't fix it. We need to stop trying to fix what isn't broken and engineering around the system we have, not the system we want.

    Show Notes
    • Linux Foundation Census 2
    • Core Infrastructure Initiative
    32 min
  • Episode 184 - It's DNS. It's always DNS

    Josh and Kurt talk about the sale of the corp.com domain. Is it going to be the end of the world, or a non event? We disagree on what should happen with it. Josh hopes an evildoer buys it, Kurt hopes for Microsoft. We also briefly discuss the CIA owning Crypto AG.

    Show Notes
    • corp.com is for sale
    • CIA owned Crypto AG
    34 min
  • Episode 183 - The great working from home experiment

    Josh and Kurt talk about a huge working from home experiment because of the the Coronavirus. We also discuss some of the advice going on around the outbreak, as well as how humans are incredibly good at ignoring good advice, often to their own peril. Also an airplane wheel falls off.

    Show Notes
    • Work from home Hacker News discussion
    • CDC advice
    • How to wash your hands
    • Air Canada flight without running wather
    • Airplane wheel falling off
    33 min
  • Episode 182 - Does open source owe us anything?

    Josh and Kurt talk about open source maintainers and building communities. While an open source maintainer doesn't owe anyone anything, there are some difficult conversations around holding back a community rather than letting it flourish.

    Show Notes
    • Actix-web story
    • Lodash
    • Possible Lodash security issue
    • Javascript libraries are almost never updated
    • Ularn
    29 min
  • Episode 181 - The security of SIM swapping

    Josh and Kurt talk about SIM swapping. What is it, how does it work. Why should you care? There's not a ton you can do to protect yourself, but we go over some of the basic concepts and what to watch out for. It's unfortunate this is still a problem.

    Show Notes
    • Five Major US Wireless Carriers Are Vulnerable to SIM Swapping
    • Edmonton Police SIM swap website
    33 min
  • Episode 180 - A Tale of Two Vulnerabilities

    Josh and Kurt talk about two recent vulnerabilities that have had very different outcomes. One was the Citrix remote code execution flaw. While the flaw is bad, the handling of the flaw was possibly worse than the flaw itself. The other was the Microsoft ECC encryption flaw. It was well handled even though it was hard to understand and it is a pretty big deal. As all these things go, fixing and disclosing vulnerabilities is hard.

    Show Notes
    • Microsoft flaw CVE-2020-0601
    • Citrix flaw CVE-2019-19781
    • Citrix mitigation instructions
    32 min
  • Episode 179 - Google Project Zero and the 90 day clock

    Josh and Kurt talk about the updated Google Project Zero disclosure policy. What's the new policy, what does it mean, and will it really matter? We suspect it will improve some things, but won't drastically change much.

    Show Notes
    • Google and 90 day patch disclosure
    • Upgrading all Windows versions
    32 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

191 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners