keep-out-2638901_1920

Episode 281 - If you spy on journalists, you're the bad guys

Josh and Kurt talk about the news that the NSO Group is widely distributing spyware onto a large number of devices. This news should be a wake up call for anyone creating devices and systems that could be attacked, it’s time to segment services. There’s not a lot individuals can do at this point, but we have some ideas at the end of the episode. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_281_If_you_spy_on_journalists_youre_the_bad_guys.mp3 Show Notes NSO Group spying Technical details Twitter thread Are we the Baddies?

July 26, 2021
danger-851895_1920

Episode 280 - The perils of Single Sign On

Josh and Kurt talk about what happens when you lose access to your Single Sign On provider. These providers have become critical to many of us, if we lose access to our SSO account we will lose access to many services. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_280_The_perils_of_Single_Sign_On.mp3 Show Notes Postbank

July 19, 2021
microphone-338481_1920

Episode 279 - The audacity of Audacity: When open source goes rogue

Josh and Kurt talk about the events happening to the Audacity audio editor. What happens if a popular open source application is acquired by an unknown entity? Can this happen to other open source projects? What can we do about it? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_279_The_audacity_of_Audacity_When_open_source_goes_rogue.mp3 Show Notes SGDQ Paper Mario Paper Mario Arbitrary Code Execution explained Freenode Audacity acquired by Muse Group Audacity fork

July 12, 2021
signpost-5274077_1920

Episode 278 - Could SELinux have stopped SolarWinds?

Josh and Kurt talk about a listener provided question. Could SELinux have stopped the SolarWinds attack? Given what we know, the answer is technically yes, but practically no. SELinux is awesome, but it’s very difficult to sandbox something like a build system. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_278_Could_SELinux_have_stopped_SolarWinds.mp3 Show Notes Gone in 60 milliseconds

July 5, 2021
billofrights

Episode 277 - Privacy and activism with Chris Weiland

Josh and Kurt talk to Chris Weiland from Restore the Fourth Minnesota. Restore The Fourth Minnesota is nonprofit dedicated to restoring the Fourth Amendment to the U.S. Constitution and ending unconstitutional mass government surveillance. Chris drops a ton of knowledge about how to be an effective tech activist, what his group is doing, and most importantly we get actionable advice! https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_277_Privacy_and_activism_with_Chris_Weiland.mp3 Show Notes Restore the Fourth Minnesota Restore the Fourth Minnesota on Twitter Writ of assistance Carpenter vs United States How many US federal laws are there? Restore the Fourth Episode 114 – Review of “Click Here to Kill Everybody” EFF EFA ACLU affiliates Glenn Greenwald TED talk

June 28, 2021
city-2462053_1920

Episode 276 - Security, behavior, and the environment

Josh and Kurt talk about how our environment affects our behavior, and in turn our level of security. We often ignore what’s happening around us when everything is related. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_276_Security_behavior_and_the_environment.mp3 Show Notes Judges more lenient after a break Dungeons and Data Poverty changes your DNA

June 21, 2021
typewriter-407695_1920

Episode 275 - What in the @#$% is going on with ransomware?

Josh and Kurt talk about why it seems like the world of ransomware has gotten out of control in the last few weeks. Every day there’s some new and more bizarre ransomware story than we had yesterday. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_275_What_in_the_is_going_on_with_ransomware.mp3 Show Notes Spurious Correlations Ransom recovered Adam Shostack Ransomware is not the problem Latvian Woman charged for writing ransomware

June 14, 2021
street-690826_1920

Episode 274 - Mr. Amazon's Neighborhood

Josh and Kurt talk about Amazon sidewalk. There is a lot of attention, but how is this any different than the surveillance networks Apple and Google have built? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_274_Mr_Amazons_Neighborhood.mp3 Show Notes Amazon Sidewalk Ads and toothpaste Airtags and stalking

June 7, 2021
conversation-3513843_1920

Episode 273 - Can we stop the coming artificial unintelligence deluge?

Josh and Kurt talk about AI driven comments. We live in a world of massive confusion and disruption where what is true and false, real and fake, are often widely debated. As AI grows and evolves what does it mean for this future? We don’t really have any answers, but we ask a lot of questions. This isn’t easy, nor will it be solved quickly, but solving it is not optional. ...

May 31, 2021
cyber-4188727_1920

Episode 272 - The Biden Cybersecurity Executive Order

Josh and Kurt talk about the Biden Administration new cybersecurity executive order. There are some good ideas in there, but at the end of the day it’s an unfunded mandate. Unfunded mandates are difficult to implement. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_272_The_Biden_Cybersecurity_Executive_Order.mp3 Show Notes Biden Executive Order Fact Sheet Obama’s cyber EO

May 24, 2021