source-code-583537_1920

Episode 258 - Stop using C

Josh and Kurt talk about the Google Project Zero report titled “A Year in Review of 0-days Exploited In-The-Wild in 2020”. It’s a cool report but we don’t agree on the conclusion. The answer isn’t to security harder, it’s to stop using C. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_258_Stop_using_C.mp3 Show Notes Google Project Zero Year of 0-days Kurt’s CUPS tweet

February 15, 2021
water-2438837_1920

Episode 257 - The sudo and libgcrypt vulnerabilities

Josh and Kurt talk about the recent sudo and libgcrypt security vulnerabilities. What’s the deal with these buffer overflows and TOCTU bugs? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_257_The_sudo_and_libgcrypt_vulnerabilities.mp3 Show Notes Sudo buffer overflow Sudo SELinux bug libgcrypt buffer overflow

February 8, 2021
Screenshot from 2021-01-31 14-06-42

Episode 256 - 9 bits of podcast, 8 bits of computing

Josh and Kurt talk about 8 bit computing. What sort of security lessons can we learn from the 8 bit world? More than you think. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_256_9_bits_of_podcast_8_bits_of_computing.mp3 Show Notes Legend of Zelda Random Number Generation Green rocket flame SR71 leaked fuel How do Namibian Himbas see colour? Suptuple meter music

February 1, 2021
hand-1549399_1920

Episode 255 - What if security wasn't joyless?

Josh and Kurt talk about what we can stop doing. We take a position of asking “does it spark joy” for tools and infrastructure. Everyone is doing something they should stop. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_255_What_if_security_wasnt_joyless.mp3 Show Notes Does it spark joy?

January 25, 2021
antique-1868726_1920

Episode 254 - Right to Repair Security

Josh and Kurt talk about the new right to repair rules in the EU. There’s a strange line between loving the idea of right to repair, but also being horrified as security people at the idea of a device being on the Internet for 30 years. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_254_Right_to_Repair_Security.mp3 Show Notes EU right to repair repair.eu

January 18, 2021
old-1220013_1920

Episode 253 - Defenders only need to be right once

Josh and Kurt talk about this idea that seems to exist in security of “attackers only need to be right once” which is silly. The reality is attackers have to get everything right, defenders really only need to get it right once. But “defenders only need to be right once” isn’t going to sell any products. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_253_Defenders_only_need_to_be_right_once.mp3 Show Notes Richard Feynman and manhole covers Richard Feynman on Why He Can’t Tell You How Magnets Work Israeli airport security FAA stolen sweater XKCD Is it worth the time CGP Grey The trouble with transporters

January 11, 2021
slip-up-709045_1920

Episode 252 - Is open source dangerous? Open source won, who cares, shut up!

Josh and Kurt talk about a report on open source security from the Canadian Centre for Cyber Security. The title pretty much sums it up. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_252_Is_open_source_dangerous_Open_source_won_who_cares_shut_up.mp3 Show Notes Security Considerations for Open Source Build an 8 bit computer from scratch

January 4, 2021
wire-1781581_1920

Episode 251 - Communication is hard, security communication is more hard

Josh and Kurt talk about communication. It’s really hard to talk about a lot of what we do. How do we know if a device is secure? How do we know our knowledge is correct? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_251_Communication_is_hard_security_communication_is_more_hard.mp3 Show Notes 90 percent of U.S. bills carry traces of cocaine Is the moon a star or planet? A mole of moles New homeowner ‘freaked out’ when stranger took control of her security system Coffee maker ransomware NIST Phish Scale The metric system Operation Paperclip

December 28, 2020
25

Episode 250 - Door 25: Why do we do the things we do? Question everything

Josh and Kurt talk about why we do the things we do. Sometimes we have to question everything https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_250_Door_25_Why_do_we_do_the_things_we_do_Question_everything.mp3 Links SLAM missile

December 25, 2020
24

Episode 249 - Door 24: Information wants to be free

Josh and Kurt talk about the idea of information wanting to be free. It’s Christmas, we should give it what it wants! https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_249_Door_24_Information_wants_to_be_free.mp3 Links Hacker Manifesto

December 24, 2020