Episode 22 - IoT Wild West

Josh and Kurt talk about planned obsolescence and IoT devices. Should manufacturers brick devices? We also have a crazy discussion about the ethics of hacking back. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/299448186-opensourcesecuritypodcast-episode-22-iot-wild-west.mp3 Show Notes First Uses of Coffee Did coffee cause the enlightenment? Nest bricks Revolv devices Phoebus Cartel Verizon will brick the Note 7 Trolley Problem Toaster toasts the weather 80% of medical device companies have less than 50 employees Passive wifi chips Crystal radio Great Seal Bug Moscow Embassy Comment on Twitter with the #osspodcast hashtag ...

December 25, 2016

Episode 21 - CVE 10K Extravaganza

Josh and Kurt talk about CVE 10K. CVE IDs have finally crossed the line, we need 5 digits to display them. This has never happened before now. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/298898472-opensourcesecuritypodcast-episode-21-cve-10k-extravaganza.mp3 Show Notes OpenSSH CVE10K assignments CVE-2016-10005 CVE syntax change CVE Numbering Authorities OpenSSH Security Advisory C to HDL Reboot Boeing Dreamliner One person writes most Linux video camera drivers Donald Becker China Airlines Flight 120 Comment on Twitter with the #osspodcast hashtag

December 21, 2016

Episode 20 - The Death of PGP

Josh and Kurt talk about the death of PGP, and how it’s not actually dead at all. It’s still really hard to use though. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/298557680-opensourcesecuritypodcast-episode-20-the-death-of-pgp.mp3 Show Notes I’m giving up on PGP Yubikey 4 Josh’s PGP setup blog post Kurt’s key with multiple signatures PGP short ID collisons Let’s Encrypt ICQ website from the late 90’s Signal Secure Messaging $2 million fraud at NorQuest College Scammers pose as company exec EV certificate requirements Comment on Twitter with the #osspodcast hashtag ...

December 19, 2016

Episode 19 - A field full of razor blades and monsters

Josh and Kurt talk about the bricking devices (on purpose). https://traffic.libsyn.com/secure/opensourcesecuritypodcast/297769068-opensourcesecuritypodcast-episode-19-a-field-full-of-razor-blades-and-monsters.mp3 Show Notes Samsung will brick the Note 7s Verizon won’t brick the phones Hoverboard imports banned Firestone tire recall Denmark Apple refurbished phone case Deprecating SHA1 South Korean Banking Encryption Canada’s Worst Driver Fitbit bought Pebble Comment on Twitter with the #osspodcast hashtag

December 14, 2016

Episode 18 - The Security of Santa

Josh and Kurt talk about the security concerns and logistics of Santa, elves, and the North Pole. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/297112068-opensourcesecuritypodcast-episode-18-the-security-of-santa.mp3 Show Notes Elf on the Shelf Furby without fur Norad Tracks Santa Futurama Xmas St. Nicholas David Sedaris on Santa US Senate Candy Desk You need 76 days to read all privacy statements Mona Lisa Theft Super Guppy LSST Data Management Back of the envelope 3589 x1.32large instances (1952 gigs ram) holds 7 petabytes of data in memory ...

December 11, 2016

Episode 17 - Cyphercon Interview with Korgo

Josh and Kurt talk to Michael Goetzman about Cyphercon https://traffic.libsyn.com/secure/opensourcesecuritypodcast/296503873-opensourcesecuritypodcast-episode-17-cyphercon-interview-with-korgo.mp3 Show Notes Cyphercon Cyphercon 2.0 Cyphercon 1.0 920 Sec Korgo Virus SafeHouse Spy Restaurant Discovery World Midwest Gaming Classic Summerfest: Cold War Battleground Nike Zeus Missile Poutine Ghost Fleet George Stroumboulopoulos Comment on Twitter

December 6, 2016

Episode 16 - Cat and mouse

Josh and Kurt talk about cybercrime and regulation. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/295920212-opensourcesecuritypodcast-episode-16-cat-and-mouse.mp3 Show Notes Avalanche Global Fraud Ring Spam King Rosendale Speed Trap Attacking Broadband Routers Spreadsheet of VPN providers DNSSEC Root Signing Ceremony Chicago Tylenol Murders Psychoactive Substances Act 2016 Computer Fraud and Abuse Act Calvinball CIH Virus Author Firefox 0day Comment on Twitter

December 2, 2016

Episode 15 - Cyber Black Monday

Josh and Kurt talk about Cyber Monday security tips. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/295266221-opensourcesecuritypodcast-episode-15-cyber-black-monday.mp3 Show Notes Edmonton Bus Accidents BeyondCorp: A New Approach to Enterprise Security Black Hat Cell Towers Google ranks https results first Domain Tasting GnuCash Tesla Credentials Tavis Ormandy strcpy pwsafe Is mashing the keyboard cryptographically secure? Comment on Twitter

November 29, 2016

Episode 14 - David A Wheeler: CII Badges

Josh and Kurt have a guest! David A. Wheeler talks about open source security and the CII Badges project. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/294303517-opensourcesecuritypodcast-episode-14-david-a-wheeler-cii-badges.mp3 Show Notes CII Badge Program Badges Project Database Badges GitHub Project Page Comment on Twitter

November 22, 2016

Episode 13 - CVE: The metric system of security

Josh and Kurt talk about CVE, DWF, and the future of flaw reporting. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/293693983-opensourcesecuritypodcast-episode-13-cve-the-metric-system-of-security.mp3 Show Notes CVE CVE Candidates (CAN) DWF NVD Open Source Security Mailing List Larry Cashdollar’s Defcon talk Metric Inch Comment on Twitter

November 18, 2016