Episode 185 - Is it even possible to fix open source security?

Josh and Kurt talk about the Linux Foundation Census 2. There is a lot of talk around how to fix open source security, but the reality is we can’t fix it. We need to stop trying to fix what isn’t broken and engineering around the system we have, not the system we want. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_185_Is_it_even_possible_to_fix_open_source_security.mp3 Show Notes Linux Foundation Census 2 Core Infrastructure Initiative Comment on Twitter with the #osspodcast hashtag ...

March 2, 2020

Episode 184 - It’s DNS. It's always DNS

Josh and Kurt talk about the sale of the corp.com domain. Is it going to be the end of the world, or a non event? We disagree on what should happen with it. Josh hopes an evildoer buys it, Kurt hopes for Microsoft. We also briefly discuss the CIA owning Crypto AG. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_184_Its_DNS_Its_always_DNS.mp3 Show Notes corp.com is for sale CIA owned Crypto AG Comment on Twitter with the #osspodcast hashtag ...

February 24, 2020

Episode 183 - The great working from home experiment

Josh and Kurt talk about a huge working from home experiment because of the the Coronavirus. We also discuss some of the advice going on around the outbreak, as well as how humans are incredibly good at ignoring good advice, often to their own peril. Also an airplane wheel falls off. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_183_The_great_working_from_home_experiment.mp3 Show Notes Work from home Hacker News discussion CDC advice How to wash your hands Air Canada flight without running wather Airplane wheel falling off Comment on Twitter with the #osspodcast hashtag ...

February 17, 2020

Episode 182 - Does open source owe us anything?

Josh and Kurt talk about open source maintainers and building communities. While an open source maintainer doesn’t owe anyone anything, there are some difficult conversations around holding back a community rather than letting it flourish. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_182_Does_open_source_owe_us_anything.mp3 Show Notes Actix-web story Lodash Possible Lodash security issue Javascript libraries are almost never updated Ularn Comment on Twitter with the #osspodcast hashtag

February 10, 2020

Episode 181 - The security of SIM swapping

Josh and Kurt talk about SIM swapping. What is it, how does it work. Why should you care? There’s not a ton you can do to protect yourself, but we go over some of the basic concepts and what to watch out for. It’s unfortunate this is still a problem. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_181_The_security_of_SIM_swapping.mp3 Show Notes Five Major US Wireless Carriers Are Vulnerable to SIM Swapping Edmonton Police SIM swap website Show Tags #SIMSwap Comment on Twitter with the #osspodcast hashtag ...

February 3, 2020

Episode 180 - A Tale of Two Vulnerabilities

Josh and Kurt talk about two recent vulnerabilities that have had very different outcomes. One was the Citrix remote code execution flaw. While the flaw is bad, the handling of the flaw was possibly worse than the flaw itself. The other was the Microsoft ECC encryption flaw. It was well handled even though it was hard to understand and it is a pretty big deal. As all these things go, fixing and disclosing vulnerabilities is hard. ...

January 27, 2020

Episode 179 - Google Project Zero and the 90 day clock

Josh and Kurt talk about the updated Google Project Zero disclosure policy. What’s the new policy, what does it mean, and will it really matter? We suspect it will improve some things, but won’t drastically change much. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_179_Google_Project_Zero_and_the_90_day_clock.mp3 Show Notes Google and 90 day patch disclosure Upgrading all Windows versions Show Tags #GoogleProject0 #CoordinatedDisclosure #ResponsibleDisclosure Comment on Twitter with the #osspodcast hashtag

January 20, 2020

Episode 178 - Are CVEs important and will ransomware put you out of business?

Josh and Kurt talk about a discussion on Twitter about if discovering CVE IDs is important for a resume? We don’t think it is. We also discuss the idea of ransomware putting a company out of business. Did it really? Possibly but it probably won’t create any substantial change in the industry. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_178_Are_CVEs_important_and_will_ransomware_put_you_out_of_busines.mp3 Show Notes Games Done Quick Ransomware puts company out of business 1 in 5 companies shut down due to ransomware Laura Shin SIM Swap Podcast Comment on Twitter with the #osspodcast hashtag ...

January 13, 2020

Episode 177 - Fake or real? The security of counterfeit goods

Josh and Kurt talk about marketplace safety and security. Will we ever see an end to the constant flow of counterfeit goods? The security industry has the same problem the marketplace industry has, without substantial injury we don’t see movement towards meaningful change. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_177_Fake_or_real_The_security_of_counterfeit_goods.mp3 Show Notes BrickLink Cars in Canada lighting on fire President Roosevelt used Al Capone’s Limo Dangerous car seats Fake external hard drive Comment on Twitter with the #osspodcast hashtag ...

January 6, 2020

Episode 176 - The 'predictions are stupid' prediction episode

Josh and Kurt talk about security predictions for 2020. None of the predictions are even a bit controversial or unexpected. We’re in a state of slow change, without disruptive technology next year will look a lot like this year. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_176_The_predictions_are_stupid_prediction_episode.mp3 Show Notes The Rising Speed of Technological Adoption Slack Certified GDPR Fines and Notices Comment on Twitter with the #osspodcast hashtag

December 30, 2019