Episode 17 - Cyphercon Interview with Korgo

Josh and Kurt talk to Michael Goetzman about Cyphercon https://traffic.libsyn.com/secure/opensourcesecuritypodcast/296503873-opensourcesecuritypodcast-episode-17-cyphercon-interview-with-korgo.mp3 Show Notes Cyphercon Cyphercon 2.0 Cyphercon 1.0 920 Sec Korgo Virus SafeHouse Spy Restaurant Discovery World Midwest Gaming Classic Summerfest: Cold War Battleground Nike Zeus Missile Poutine Ghost Fleet George Stroumboulopoulos Comment on Twitter

December 6, 2016

Episode 16 - Cat and mouse

Josh and Kurt talk about cybercrime and regulation. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/295920212-opensourcesecuritypodcast-episode-16-cat-and-mouse.mp3 Show Notes Avalanche Global Fraud Ring Spam King Rosendale Speed Trap Attacking Broadband Routers Spreadsheet of VPN providers DNSSEC Root Signing Ceremony Chicago Tylenol Murders Psychoactive Substances Act 2016 Computer Fraud and Abuse Act Calvinball CIH Virus Author Firefox 0day Comment on Twitter

December 2, 2016

Episode 15 - Cyber Black Monday

Josh and Kurt talk about Cyber Monday security tips. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/295266221-opensourcesecuritypodcast-episode-15-cyber-black-monday.mp3 Show Notes Edmonton Bus Accidents BeyondCorp: A New Approach to Enterprise Security Black Hat Cell Towers Google ranks https results first Domain Tasting GnuCash Tesla Credentials Tavis Ormandy strcpy pwsafe Is mashing the keyboard cryptographically secure? Comment on Twitter

November 29, 2016

Episode 14 - David A Wheeler: CII Badges

Josh and Kurt have a guest! David A. Wheeler talks about open source security and the CII Badges project. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/294303517-opensourcesecuritypodcast-episode-14-david-a-wheeler-cii-badges.mp3 Show Notes CII Badge Program Badges Project Database Badges GitHub Project Page Comment on Twitter

November 22, 2016

Episode 13 - CVE: The metric system of security

Josh and Kurt talk about CVE, DWF, and the future of flaw reporting. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/293693983-opensourcesecuritypodcast-episode-13-cve-the-metric-system-of-security.mp3 Show Notes CVE CVE Candidates (CAN) DWF NVD Open Source Security Mailing List Larry Cashdollar’s Defcon talk Metric Inch Comment on Twitter

November 18, 2016

Episode 12 - Security Trebuchet

Josh and special guest host Dave Sirrine talk about feedback, OpenSSL, OAuth2, Let’s Encrypt, disclosure, and locks. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/292434458-opensourcesecuritypodcast-episode-12-security-trebuchet.mp3 Show Notes coh’s feedback OpenSSL security advisory Red Hat CLI security API Shovel Knight Pumpkin OAuth2 bug Let’s Encrypt Half of all Chrome connections use https Google’s Windows Bug RichSec (Richmond VA Information Security Users Group) RVASec (Yearly conference in June held by RichSec) Schuyler Towne - “Why do you lock your door?” Comment on Twitter ...

November 10, 2016

Episode 11 - The Poison Candy Episode

Josh and special guest host Dave Sirrine talk about Halloween, passwords, hardware timing attacks, chip and pin, security economics, SSL/TLS, and Mozilla enabling TLS 1.3 by default. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/290834937-opensourcesecuritypodcast-episode-11-the-poison-candy-episode.mp3 Show Notes Risky Candy XKCD Password Strength Diceware Haswell Timing Attack Rowhammer on Android Eavesdropping keystrokes via VOIP SSL/TLS Timeline Comment on Twitter

October 31, 2016

Episode 10 - The super botnet that nobody can stop

Kurt and Josh discuss Dirty COW, the big IoT DDoS, and Josh can’t pronounce Mirai or Dyn. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/289791587-opensourcesecuritypodcast-episode-10-the-super-botnet-that-nobody-can-stop.mp3 Show Notes Dirty Cow Kees Cook Kernel Bug Lifetime Rowhammer Mirai botnet DDoS Law of truly large numbers Comment on Twitter

October 24, 2016

Episode 9 - Are bug bounties measuring the wrong things?

Kurt and Josh discuss responsible disclosure, irresponsible disclosure, bug bounties, measuring security, usability AND security, as well as quality of life. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/288890601-opensourcesecuritypodcast-episode-9-are-bug-bounties-measuring-the-wrong-things.mp3 Show Notes Responsible Disclosure OpenSSL Security Policy Rain Forest Puppy Policy ISO 29147 Facebook Bug Bounty Security Spending Security AND Usability Comment on Twitter

October 18, 2016

Episode 8 - The primality of prime numbers

Kurt and Josh discuss prime numbers (probably getting a lot of it wrong), Samsung, passwords, National Cyber Security Awareness Month, and bathroom scales. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/287233537-opensourcesecuritypodcast-episode-8-the-primality-of-prime-numbers.mp3 Show Notes New Prime Number Research Randomness testing Kurt’s Repo of Primes DNSSEC Signing Ceremony Magento Skimmer XKCD Wrench Comic Firesheep National Cyber Security Awareness Month Stop Trying to Fix the User Only Trust Food Delivered by Zebra Bathroom Scale Flaw Comment on Twitter

October 11, 2016