Episode 180 - A Tale of Two Vulnerabilities

Josh and Kurt talk about two recent vulnerabilities that have had very different outcomes. One was the Citrix remote code execution flaw. While the flaw is bad, the handling of the flaw was possibly worse than the flaw itself. The other was the Microsoft ECC encryption flaw. It was well handled even though it was hard to understand and it is a pretty big deal. As all these things go, fixing and disclosing vulnerabilities is hard. ...

January 27, 2020

Episode 179 - Google Project Zero and the 90 day clock

Josh and Kurt talk about the updated Google Project Zero disclosure policy. What’s the new policy, what does it mean, and will it really matter? We suspect it will improve some things, but won’t drastically change much. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_179_Google_Project_Zero_and_the_90_day_clock.mp3 Show Notes Google and 90 day patch disclosure Upgrading all Windows versions Show Tags #GoogleProject0 #CoordinatedDisclosure #ResponsibleDisclosure Comment on Twitter with the #osspodcast hashtag

January 20, 2020

Episode 178 - Are CVEs important and will ransomware put you out of business?

Josh and Kurt talk about a discussion on Twitter about if discovering CVE IDs is important for a resume? We don’t think it is. We also discuss the idea of ransomware putting a company out of business. Did it really? Possibly but it probably won’t create any substantial change in the industry. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_178_Are_CVEs_important_and_will_ransomware_put_you_out_of_busines.mp3 Show Notes Games Done Quick Ransomware puts company out of business 1 in 5 companies shut down due to ransomware Laura Shin SIM Swap Podcast Comment on Twitter with the #osspodcast hashtag ...

January 13, 2020

Episode 177 - Fake or real? The security of counterfeit goods

Josh and Kurt talk about marketplace safety and security. Will we ever see an end to the constant flow of counterfeit goods? The security industry has the same problem the marketplace industry has, without substantial injury we don’t see movement towards meaningful change. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_177_Fake_or_real_The_security_of_counterfeit_goods.mp3 Show Notes BrickLink Cars in Canada lighting on fire President Roosevelt used Al Capone’s Limo Dangerous car seats Fake external hard drive Comment on Twitter with the #osspodcast hashtag ...

January 6, 2020

Episode 176 - The 'predictions are stupid' prediction episode

Josh and Kurt talk about security predictions for 2020. None of the predictions are even a bit controversial or unexpected. We’re in a state of slow change, without disruptive technology next year will look a lot like this year. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_176_The_predictions_are_stupid_prediction_episode.mp3 Show Notes The Rising Speed of Technological Adoption Slack Certified GDPR Fines and Notices Comment on Twitter with the #osspodcast hashtag

December 30, 2019

Episode 175 - Defenders will always be one step behind

Josh and Kurt talk about the opportunistic nature of crime. Defenders have to defend, which means the adversaries are by definition always a step ahead. We use the context of automobile crimes to frame the discussion. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_175_Defenders_will_always_be_one_step_behind.mp3 Show Notes Stealing cars with radio relays RTL Software Defined Radio Canada most stolen car Comment on Twitter with the #osspodcast hashtag

December 23, 2019

Episode 174 - GitHub turns security up to 11; A discussion with Rob Schultheis

Josh and Kurt talk to Rob Schultheis from GitHub about some of the amazing projects GitHub is working on. We discuss GitHub security advisories, getting a CVE from GitHub, and what the new GitHub Security Lab is doing. It’s a great conversation about how GitHub is working to make security better for all of us. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_174_GitHub_turns_security_up_to_11_A_discussion_with_Rob_Schultheis.mp3 Show Notes GitHub Security Advisories GitHub CVE requests GitHub Security Lab GitHub Security Lab Slack GitHub Security Lab Twitter Show Tags #CodeQL #GitHub Comment on Twitter with the #osspodcast hashtag ...

December 16, 2019

Episode 173 - Ho Ho Homeland Security

Josh Santa and Kurt talk the border nightmare Santa Clause has to deal with as he traverses the globe. Questions we explore include: Are the reindeer farm animals? Is the North Pole a farm? Is Santa an intellectual property thief? Does Krampus eat politicians? Does Santa have a passport? Does Santa have an emergency radio? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_173_Ho_Ho_Homeland_Security.mp3 Show Notes Pirate Joes Comment on Twitter with the #osspodcast hashtag

December 9, 2019

Episode 172 - The security of planned obsolescence

Josh and Kurt talk about the security implications of planned obsolescence. We use Intel’s recent decision to remove old drivers from their website as the start of the conversation. By the end we realize this is more of a decision society needs to understand and make more than anything. Is constantly throwing out technology OK? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_172_The_security_of_planned_obsolescence.mp3 Show Notes Intel removes old drivers Upgrading all versions of Windows Sniffing your Smart TV Comment on Twitter with the #osspodcast hashtag ...

December 2, 2019

Episode 171 - Measuring cybersecurity with Kathryn Waldron

Josh and Kurt talk to Kathryn Waldron of the R Street Institute about a paper she recently published that collects a number of cybersecurity measuring devices in one place. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_171_Measuring_cybersecurity_with_Kathryn_Waldron.mp3 Show Notes Kathryn Waldron Kathryn’s Twitter account Resources for Measuring Cybersecurity There are 14 standards Show Tags #Regulation Comment on Twitter with the #osspodcast hashtag

November 25, 2019