Episode 119 - The Google+ and Facebook incidents, it's not your data anymore

Josh and Kurt talk about the Google+ and Facebook data incidents. We don’t have any control over this data anymore. The incidents didn’t really affect the users because we have no idea who has access to it. We also touch on GDPR and what it could mean in this context. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_119_the_google_and_facebook_incidents_its_not_your_data_anymore.mp3 Show Notes Facebook hack Google+ hack Comment on Twitter with the #osspodcast hashtag

October 22, 2018

Episode 118 - Cloudflare's IPFS and onion service

Josh and Kurt talk about Cloudflare’s new IPFS and Onion services. One brings distributed blockchain files to the masses, the other lets you host your site on tor easily. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_118_cloudflares_ipfs_and_onion_service.mp3 Show Notes IPFS Onion service Comment on Twitter with the #osspodcast hashtag

October 15, 2018

Episode 117 - Will security follow Linus' lead on being nice?

Josh and Kurt talk about Linus’ effort to work on his attitude. What will this mean for security and IT in general? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_117_Will_security_follow_Linus_lead_on_being_nice.mp3 Show Notes Linus steps aside Contributor Covenant Comment on Twitter with the #osspodcast hashtag

October 8, 2018

Episode 116 - The future of the CISO with Michael Piacente

Josh and Kurt talk to Michael Piacente from Hitch Partners about the past, present, and future role of the CISO in the industry. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_116_The_future_of_the_CISO_with_Michael_Piacente.mp3 Show Notes Hitch Partners Michael Piacente Comment on Twitter with the #osspodcast hashtag

October 1, 2018

Episode 115 - Discussion with Brian Hajost from SteelCloud

Josh and Kurt talk to Brian Hajost from SteelCloud about public sector compliance. The world of public sector compliance can be confusing and strange, but it’s not that bad when it’s explained by someone with experience. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_115_Discussion_with_Brian_Hajost_from_SteelCloud.mp3 Show Notes SteelCloud DISA STIG Comment on Twitter with the #osspodcast hashtag

September 24, 2018

Episode 114 - Review of "Click Here to Kill Everybody"

Josh and Kurt review Bruce Schneier’s new book Click Here to Kill Everybody. It’s a book everyone could benefit from reading. It does a nice job explaining many existing security problems in a simple manner. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_114_review_of_click_here_to_kill_everybody.mp3 Show Notes Click Here to Kill Everybody There Will Be Cyberwar Reddit OSHA Comment on Twitter with the #osspodcast hashtag

September 17, 2018

Episode 113 - Actual real security advice

Josh and Kurt talk about actual real world advice. Based on a story about trying to secure political campaigns, if we had to give some security help what should it look like, who should we give it to? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_113_actual_real_security_advice.mp3 Show Notes Security advice to Democrats Our actual advice Don’t run your own services Email - Google or Microsoft Don’t’ use GPG Use a trusted device Use a password manager on a secure device Use 2FA Backups Comment on Twitter with the #osspodcast hashtag ...

September 10, 2018

Episode 112 - Google's Titan Key and the latest Struts issue

Josh and Kurt talk about the new Google Titan security key. There are some in the industry uneasy about the supply chain for the devices. We also discuss the latest Struts security issue. Struts is old and scary now, stop using it. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode-112_googles_titan_key_and_the_latest_struts_issue.mp3 Show Notes Google’s security key security questions Struts security issue Comment on Twitter with the #osspodcast hashtag

September 3, 2018

Episode 111 - The TLS 1.3 and DNS episode

Josh and Kurt talk about TLS 1.3 and DNS. What can we expect from the future for these, how are they related (or not related). We touch on DNSSEC and why it probably won’t matter. DNS over TLS is looking pretty great though. There is also a guest appearance from quantum crypto. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_111_The_TLS_1_3_and_DNS_episode.mp3 Show Notes Cloudflare TLS 1.3 blog NIST post quantum crypto Comment on Twitter with the #osspodcast hashtag ...

August 27, 2018

Episode 110 - Review of Black Hat, Defcon, and the effect of security policies

Josh and Kurt talk about Black Hat and Defcon and how unexciting they have become. What happened with hotels at Defcon, and more importantly how many security policies have 2nd and 3rd level effects we often can’t foresee. We end with important information about pizza, bananas, and can openers. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_110_review_of_black_hat_defcon_and_the_effect_of_security_policies.mp3 Show Notes Kids hacking voting machines Black Hat plaintext email Defcon hotel shenanigans International Pizza Expo How to use a can opener How to open a banana Join our Facebook Group ...

August 20, 2018