Software Engineering Daily

Software Engineering Daily

By Software Engineering DailyNewsTechnologyTech News
Download on the App Store

Software Engineering Daily episodes

  • Let’s Encrypt with Josh Aas

    “If everyone is going to use TLS, people need to trust their certificate authority, and the way to gain trust is through openness.”

    Let’s Encrypt is a free, automated, and open certificate authority developed by the Internet Security Research Group (ISRG). The ISRG is a non-profit whose mission is to reduce financial, technological, and education barriers to secure communication over the Internet.

    Josh Aas is the Co-founder and Executive Director of the ISRG. He is also a Senior Technology Strategist at Mozilla.

    Questions
    • What is the Internet Research Security Group?
    • What is a certificate authority?
    • Prior to Let’s Encrypt, what were the steps to turn on https for a website?
    • Why is it important to focus on security specifically at the transport layer?
    • What are the major problems with modern network security?
    • What types of malware and phishing attacks do you see the most these days?
    • What are the bottlenecks to widespread adoption of lets encrypt?
    • Links
        • Transport Layer Security
        • Let’s Encrypt is Trusted
        • Hardware Security Module
        • We can’t let tech giants, like Facebook and Twitter, control our news values
        • Josh’s personal page
        • Sponsors

          Hired.com is the job marketplace for software engineers. Go to hired.com/softwareengineeringdaily to get a $600 bonus upon landing a job through Hired.

          Digital Ocean is the simplest cloud hosting provider. Use promo code SEDAILY for $10 in free credit.

          The post Let’s Encrypt with Josh Aas appeared first on Software Engineering Daily.

          45 min
        • Botnets and Cybercrime with Shuman Ghosemajumder

          Modern automated attacks using widespread botnets have evolved in sophistication, making cybercrime an increasingly relevant threat in today’s internet.

          Security researchers and organizations have to stay vigilant in this cat-and-mouse game.

          Shuman Ghosemajumder is the VP of Product at Shape Security, which defends applications from malware and bots. He is the former click fraud czar at Google, and he will be speaking at QCon San Francisco.

          Questions
          • What types of botnets exist?
          • How do public clouds like AWS and Azure affect the ability to spin up a botnet?
          • What is the malicious botnet developer community like?
          • How does ShapeShifter Botwall use polymorphic code to defend against bots?
          • What is a man-in-the-browser attack?
          • How does Google deal with ad fraud?
          • Links
            • Shape Security
            • Shuman Ghosemajumder (Wikipedia)
            • Click-Fraud Czar
            • Rising Attack Vector: Credential Stuffing
            • Credential Stuffing (YouTube)
            • The post Botnets and Cybercrime with Shuman Ghosemajumder appeared first on Software Engineering Daily.

              50 min
            • Intelligence and National Security with Adrián Lamo

              “If you don’t like what you see sometimes when you look at the world, it’s incumbent on you – you do something about it.”

              Adrián Lamo is a threat analyst, hacker, and writer. In the early 2000’s, Adrián was a hobbyist white-hat hacker, breaking into companies to expose vulnerabilities and fix them.

              In 2010, Adrian informed the US Army that Chelsea Manning had provided more than 260,000 documents to Wikileaks.

              This interview does not discuss the Manning case, because we covered that topic in our Quoracast interview several months ago.

              Questions
              • What are the responsibilities of the government towards its citizens on the internet?
              • Why is Keybase useful to you?
              • What is the significance of the Ashley Madison attack?
              • What is the nature of our conflict with ISIS?
              • Is security a purely defensive concept?
              • Links
                • Adrian Lamo on Quora
                • Adrian Lamo on Wikipedia
                • The Quoracast: Adrian Lamo
                • Blogs of War
                • The Homeless Hacker v. The New York Times
                • The post Intelligence and National Security with Adrián Lamo appeared first on Software Engineering Daily.

                  44 min
                • Identity and Encryption with Keybase Founder Max Krohn

                  Keybase is an open-source key directory that allows users to encrypt messages and verify identities.

                  Max Krohn is the co-founder of Keybase, and previously co-founded OKCupid and SparkNotes.

                  Questions
                  • How do you explain public key encryption to a non-programmer millennial?
                  • How does Keybase leverage the Bitcoin blockchain?
                  • Why is a Merkle tree a crucial data structure in Keybase?
                  • What are some use cases for Keybase?
                  • How did OKCupid approach the type of bot problem Ashley Madison encouraged?
                  • Why is Keybase written in Go?
                  • How does Keybase run Go code in iOS?
                  • Links
                    • Keybase
                    • Public Key Cryptography
                    • Merkle Signature Scheme
                    • Keybase Raises $10.8 Million (contains lots of technical/mission information)
                    • Ashley Madison bots
                    • The post Identity and Encryption with Keybase Founder Max Krohn appeared first on Software Engineering Daily.

                      51 min
                    • Security and Privacy with Bruce Schneier

                      “What we learn again and again is that security is less about what you think of, and more about what you didn’t think of.”

                      Bruce Schneier is a security researcher and author of Data and Goliath.

                      Questions
                      • In Data and Goliath, what are the motives of different goliaths?
                      • Why is the Ashley Madison case a watershed moment in security?
                      • Do you still feel we should break up the NSA?
                      • Will Google and Amazon become military contractors?
                      • How can we defend ourselves from DOS attacks from refrigerators?
                      • When we put processors in refrigerators, and cars, and thermostats, are we increasing the attack surface, and our vulnerabilities faster than we are improving our utility?
                      • Links
                        • Schneier on Security
                        • Data and Goliath
                        • Ashley Madison Case
                        • XKeyscore
                        • Stuxnet
                        • Aspen Security Forum Videos
                        • “It’s Time to Break Up the NSA”
                        • iPhone Ransomware
                        • The post Security and Privacy with Bruce Schneier appeared first on Software Engineering Daily.

                          47 min
                        • Car Hacking with Craig Smith

                          Automobiles are now computers with security vulnerabilities.

                          Reverse engineers have begun to dissect car security.

                          Craig Smith is the author of The Car Hacker’s Handbook and the founder of Theia Labs, a research and consulting firm.

                          Questions
                          • What parts of a car are susceptible to remote hacking?
                          • What operating systems does a car run?
                          • What is the communication model of a car?
                          • How are updates delivered to a car?
                          • Is there enough attention on the topic of car hacking?
                          • Can you virtualize a car and hack it?
                          • Links
                            • The Car Hacker’s Handbook
                            • I am the Cavalry: Automotive Cyber Safety Advocates
                            • Wired Jeep Hacking Incident
                            • The post Car Hacking with Craig Smith appeared first on Software Engineering Daily.

                              55 min

                            About Software Engineering Daily

                            From the publisher's feed

                            Technical interviews about software topics.