Episode 416 – Thomas Depierre on open source in Europe

Josh and Kurt talk to Thomas Depierre about some of the European efforts to secure software. We touch on the CRA, MDA, FOSDEM, and more. As expected Thomas drops a huge amount of knowledge on what’s happening in open source. We close the show with a lot of ideas around how to move the needleContinue reading “Episode 416 – Thomas Depierre on open source in Europe”

Episode 415 – Reducing attack surface for less security

Josh and Kurt talk about a blog post explaining how to create a very very small container image. Generally in the world of security less is more, but it’s possible to remove too much. A lot of today’s security tooling relies on certain things to exist in a container image, if we remove them weContinue reading “Episode 415 – Reducing attack surface for less security”

Episode 413 – PyTorch and NPM get attacked, but it’s OK

Josh and Kurt talk about an attack against PyTorch and NPM. The PyTorch attack shows the difficulty of operating a large open source project. The NPM situation continues to show the difficulty in trying to backdoor open source. Many people are watching, and it only takes one person to notice a problem and report it,Continue reading “Episode 413 – PyTorch and NPM get attacked, but it’s OK”