gun-2423391_1920

Episode 264 - DevSecOps with GitLab's Mark Loveless

Josh and Kurt talk to Mark Loveless from GitLab. We touch on DevSecOps, what GitLab is doing, threat modeling, and the time Mark tested positive for TNT at the airport. It’s a great conversation. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_264_DevSecOps_with_GitLabs_Mark_Loveless.mp3 Show Notes Mark Loveless Twitter GitLab GitLab Handbook How we approach open source security PASTA threat modeling GitLab security features Tales from the Past - “You Tested Positive for TNT”

March 29, 2021
signs-2799416_1920

Episode 263 - GitHub pulls exploits, LinuxFoundation sign all the things

Josh and Kurt talk about how terrible daylight savings is. GitHub yanking some exploit code. And the Linux Foundation new project to sign all the things. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_263_GitHub_pulls_exploits_LinuxFoundation_sign_all_the_things.mp3 Show Notes Researcher Publishes Code to Exploit Microsoft Exchange Vulnerabilities on Github GitHub content restrictions Reproducing the Microsoft Exchange Proxylogon Exploit Chain

March 22, 2021
sysdig_Horz_Color_Logo_RGB_lrg

Episode 262 - A discussion with Loris and Pop from Sysdig

Josh and Kurt talk to Loris Degioanni and Dan from Sysdig. Sysdig are the minds behind Falco, an amazing open source runtime security engine. We talk about where their technology came from, they huge code donation to the CNCF and what securing a modern infrastructure looks like today. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_262_A_discussion_with_Loris_and_Pop_from_Sysdig.mp3 Show Notes Sysdig Falco Loris’ Twitter Dan “Pop” Popandrea’s Twitter Sysdig contributes Falco’s kernel module, eBPF probe, and libraries to the CNCF pdig Sysdig 2021 container security and usage report: Shifting left is not enough

March 15, 2021
audience-945449_1920

Episode 261 - DWF is back! Welcome to community powered CVE

Josh and Kurt talk about DWF. It’s back and the intention is to have real community driven security identifiers! https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_261_DWF_is_back_Welcome_to_community_powered_CVE.mp3 Show Notes Committee vs Community dwflist repo dwf-request tooling repo dwf-workflow policy repo CVE plateua graph iwantacve.org

March 8, 2021
farm-2852024_1920

Episode 260 - Dave Jevans tells us what CipherTrace is up to

Josh and Kurt talk with Dave Jevans CEO of CipherTrace and chairman of the anti-phishing working group about the challenges of keeping track of cryptocurrency in the modern age. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_260_Dave_Jevans_tells_us_what_CipherTrace_is_up_to.mp3 Show Notes Dave’s Twitter CipherTrace Anti Phishing Working Group

March 1, 2021
door-sign-1607503_1920

Episode 259 - What even is open source anymore?

Josh and Kurt talk about the question “what is open source?” Why do we think it’s broken today, and what sort of ideas about what should come next. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_259_What_even_is_open_source_anymore.mp3 Show Notes OSI Bruce Perens Post Open Source Josh’s community blog post Corey Doctorow Uber Twitter thread

February 22, 2021
source-code-583537_1920

Episode 258 - Stop using C

Josh and Kurt talk about the Google Project Zero report titled “A Year in Review of 0-days Exploited In-The-Wild in 2020”. It’s a cool report but we don’t agree on the conclusion. The answer isn’t to security harder, it’s to stop using C. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_258_Stop_using_C.mp3 Show Notes Google Project Zero Year of 0-days Kurt’s CUPS tweet

February 15, 2021
water-2438837_1920

Episode 257 - The sudo and libgcrypt vulnerabilities

Josh and Kurt talk about the recent sudo and libgcrypt security vulnerabilities. What’s the deal with these buffer overflows and TOCTU bugs? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_257_The_sudo_and_libgcrypt_vulnerabilities.mp3 Show Notes Sudo buffer overflow Sudo SELinux bug libgcrypt buffer overflow

February 8, 2021
Screenshot from 2021-01-31 14-06-42

Episode 256 - 9 bits of podcast, 8 bits of computing

Josh and Kurt talk about 8 bit computing. What sort of security lessons can we learn from the 8 bit world? More than you think. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_256_9_bits_of_podcast_8_bits_of_computing.mp3 Show Notes Legend of Zelda Random Number Generation Green rocket flame SR71 leaked fuel How do Namibian Himbas see colour? Suptuple meter music

February 1, 2021
hand-1549399_1920

Episode 255 - What if security wasn't joyless?

Josh and Kurt talk about what we can stop doing. We take a position of asking “does it spark joy” for tools and infrastructure. Everyone is doing something they should stop. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_255_What_if_security_wasnt_joyless.mp3 Show Notes Does it spark joy?

January 25, 2021