PNG_Aqua Logo Color

Episode 200 - Talking Container Security with Liz Rice

Josh and Kurt talk to Liz Rice from Aqua Security about container security and her new book on the same topic. What does container security look like today? What are some things you can do now? What will container security look like in the future? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_200_Talking_Container_Security_with_Liz_Rice.mp3 Show Notes Container Security download Pictures of elephants Kubernetes Security book Starboard project Dynamic threat analysis

June 8, 2020
aditya-vyas-ZtrahFp1pjA-unsplash

Episode 199 - Special cases are special: DNS, Websockets, and CSV

Josh and Kurt talk about a grab bag of topics. A DNS security flaw, port scanning your machine from a web browser, and CSV files running arbitrary code. All of these things end up being the result of corner cases. Letting a corner case be part of a default setup is always a mistake. Yes always, not even that one time. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_199_Special_cases_are_special_DNS_Websockets_and_CSV.mp3 Show Notes Bind advisory Robustness Principal eBay port scanning localhost OWASP CSV injection

June 1, 2020
phone-booth-203492

Episode 198 - Good advice or bad advice? Hang up, look up, and call back

Josh and Kurt talk about the Krebs blog post titled “When in Doubt: Hang Up, Look Up, & Call Back”. In the world of security there isn’t a lot of actionable advice, it’s worth discussing if something like this will work, or ever if it’s the right way to handle these situations. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_198_-_Good_advice_or_bad_advice_Hang_up_look_up_and_call_back.mp3 Show Notes When in Doubt: Hang Up, Look Up, & Call Back Tech Support Scam podcast: Part 1, Part 2 STIR/SHAKEN Drill the wrong safe deposit box 2009 Bank of Ireland robbery Comment on Twitter with the #osspodcast hashtag ...

May 25, 2020
barrel-52934.jpg

Episode 197 - Beer, security, and consistency; the newer, better, triad

Josh and Kurt talk about what beer and reproducible builds have in common. It’s a lot more than you think, and it mostly comes down to quality control. If you can’t reproduce what you do, you’re not a mature organization and you need maturity to have quality. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_197_Beer_security_and_consistency_the_newer_better_triad.mp3 Show Notes Reinheitsgebot Josh’s Blog Post Ken Thompson’s reflections on trusting trust Tor Browser Deterministic Builds One line package broke npm create Donkey Kong 64 memory leak Comment on Twitter with the #osspodcast hashtag ...

May 17, 2020

Episode 196 - Pounding square solutions into round holes: forced updates from Ubuntu

Josh and Kurt talk about automatic updates. Specifically we discuss a recent decision by Ubuntu to enable forced automatic updates. There are lessons here for the security community. We have a history of jumping to solutions rather than defining and understanding problems. Sometimes our solutions aren’t the best. Also murder bees. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_196_Pounding_square_solutions_into_round_holes_forced_updates_from_Ubuntu.mp3 Show Notes The Oatmeal giant bee comic Honeybees cook giant hornet Ubuntu 20.04 LTS’ snap obsession has snapped me off of it Forum discussion Comment on Twitter with the #osspodcast hashtag ...

May 11, 2020

Episode 195 - Is BGP actually insecure?

Josh and Kurt talk about the uproar around Cloudflare’s “Is BGP safe yet” site. It’s always interesting watching how much people will push back on new things, even if the new things is probably a step in the right direction. The clever thing Cloudflare is doing in this instance is they are making the BGP problem something anyone can understand. Also send us your funny dog stories. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_195_Is_BGP_actually_insecure.mp3 Show Notes Is BGP safe yet? Reddit BGP conversation Hacker News BGP conversation Stealing cryptocurrency with BGP Show Tags #BGP Comment on Twitter with the #osspodcast hashtag ...

May 4, 2020

Episode 194 - Working from home security: resistance is futile

Josh and Kurt talk about the new normal that’s working away from an office. It’s not exactly working from home as there are some unforeseen challenges that we just took for granted in the past. There are a lot of new and strange security problems we have to adapt to, everyone is doing amazing work with very little right now. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_194_Working_from_home_security_resistance_is_futile.mp3 Show Notes Microsoft buys corp.com Hijack computer network traffic with a Pi Zero Comment on Twitter with the #osspodcast hashtag ...

April 27, 2020

Episode 193 - Security lessons from space: Apollo 13 edition

Josh and Kurt talk about space. We intended to focus on Apollo 13 but as usual we have no ability to stay on topic. There is a lot of fun space discussions in this one though. Do you think you can hack Voyager 1? Only if you have a big enough satellite dish. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_193_Security_lessons_from_space_Apollo_13_edition.mp3 Show Notes Eavesdropping on Apollo 11 Apollo 11 classified weather satellite The pen that saved Apollo 11 Comment on Twitter with the #osspodcast hashtag ...

April 20, 2020

Episode 192 - Work without progress - what Infosec can learn from treadmills

Josh and Kurt talk about Kurt’s recent treadmill purchase and the lessons we can lean in security from the consumer market. The consumer market has learned a lot about how to interact with their customers in the last few decades, the security industry is certainly behind in this space today. Once again we display our ability to tie even the seemingly mundane things back to a discussion about security. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_192_Work_without_progress_what_Infosec_can_learn_from_treadmills.mp3 Show Notes Eating goldfish off the treadmill Comment on Twitter with the #osspodcast hashtag ...

April 13, 2020

Episode 191 - Security scanners are all terrible

Josh and Kurt talk about security scanners. They’re all pretty bad today, but there are some things we can do to make them better. Step one is to understand the problem. Do you know why you’re running the scanner and what the reports mean? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_191_Security_scanners_are_all_terrible.mp3 Show Notes Edmonton freeze thaw cycles Josh’s security scanner blog series Comment on Twitter with the #osspodcast hashtag

April 8, 2020