monkey-20182

Appsec isn't people

Recently there was a thread on Twitter I stuck my nose into about appsec and why it doesn’t work. I have a response in there that I believe is a nice way to explain my biggest problem with appsec. I would sum it up as “Appsec isn’t people”. Here is a clever image to help. You know you can take it seriously because the text is green. The best way to think about this is to ask a different but related question. Why don’t we have training for developers to write code with fewer bugs? Even the suggestion of this would be ridiculed by every single person in the software world. I can only imagine the university course “CS 107: Error free development”. Everyone would fail the course. It would probably be a blast to teach, you could spend the whole semester yelling at the students for being stupid and not just writing code with fewer bugs. You don’t even have to grade anything, just fail them all because you know the projects have bugs. ...

August 13, 2019

Episode 156 - What if we MitM a whole country?

Josh and Kurt talk about Kazakhstan requiring citizens to place a government controlled root CA certificate on their computers. How does this work. What does it mean for the citizens of Kazakhstan, and why we all should be paying attention. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_156_What_if_we_MitM_a_whole_country.mp3 Show Notes Kazakhstan MitM all TLS traffic Mozilla bug Comment on Twitter with the #osspodcast hashtag

July 29, 2019
space-2519836

Why you can't backdoor cryptography

Once again the topic of backdooring cryptography is in the news. The same people will fight the same fight. Again. So far sanity has prevailed every time we do this, but that doesn’t mean anyone should sit this one out. Make sure you tell everyone to pay attention and care. Trustworthy cryptography is too important. Given the language used it sounds a lot like what’s really being discussed is having the ability to view chat apps, view emails, and unlock phones. All things with a consumer focus. They’ve lost this fight more times than we can count now, no doubt this direction change is an attempt to spread confusion. ...

July 26, 2019

Episode 155 - Stealing cars and ransomware

Josh and Kurt talk about a new way to steal cars because a service didn’t do proper background checks. We also discuss how this relates to working with criminals, such as ransomware, and what it means for the future of the ransomware industry. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_155_Stealing_cars_and_ransomware.mp3 Show Notes Car2go theft Alberta driver’s license security Albertosaurus Las Vegas won’t pay a ransom Comment on Twitter with the #osspodcast hashtag

July 22, 2019

Episode 154 - Chat with the authors of the book "The Fifth Domain"

Josh and Kurt talk to the authors of a new book The Fifth Domain. Dick Clarke and Rob Knake join us to discuss the book, cybersecurity, US policy, how we got where we are today and what the future holds for cybersecurity. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_154_Chat_with_the_authors_of_the_book_The_Fifth_Domain.mp3 Show Notes The Fifth Domain Dick Clarke Rob Knake Future State Podcast Show Tags #FifthDomain #Cybersecurity Comment on Twitter with the #osspodcast hashtag

July 16, 2019

Episode 153 - The unexpected security of AI, photographs, and VPN

Josh and Kurt talk about user expectations around Facebook’s AI. Normal people are starting to see the capabilities and potential risk with all these services. We also cover the topic of China owning a number of VPN services. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_153_The_unexpected_security_of_AI_photographs_and_VPN.mp3 Show Notes Facebook’s AI descriptions China owns a lot of VPNs VPN comparison Comment on Twitter with the #osspodcast hashtag

July 8, 2019

Episode 152 - Tavis breaks the world ... again

Josh and Kurt talk about the disclosure of security vulnerabilities. It’s still not a settled topic, we frame the conversation around a recent disclosure from Tavis Ormandy of Google Project Zero. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_152_Tavis_breaks_the_world_again.mp3 Show Notes Tavis Tavis ruins everything cDc book France Bans Judge Analytics Elastic Source Code Comment on Twitter with the #osspodcast hashtag

July 1, 2019

Episode 151 - The DARPA Cyber Grand Challenge with David Brumley

Josh and Kurt talk to David Brumley. The CEO of ForAllSecure and professor at CMU. We discuss when David’s team won the Cyber Grand Challenge, what the future of automated security looks like, and what ForAllSecure is doing. It’s a fascinating window into the future of the industry. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_151_The_Darpa_Cyber_Grand_Challenge_with_David_Brumley.mp3 Show Notes David Brumley ForAllSecure Cyber Grand Challenge Comment on Twitter with the #osspodcast hashtag

June 24, 2019

Episode 150 - Our ad funded dystopian present

Josh and Kurt talk about the future Chrome and ad blockers. There is a lot of nuance to unpack around this one. There are two versions of the Internet today. One with an ad blocker and one without. The Internet without an ad blocker is a dystopian nightmare. The actionable advice at the end of this one is to use Firefox. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_150_Our_ad_funded_dystopian_present.mp3 Show Notes Chrome ad blocking Firefox Mozilla funding Donate to Firefox Comment on Twitter with the #osspodcast hashtag ...

June 17, 2019

Episode 149 - Chat with Michael Coates about data security

Josh and Kurt have a chat with Michael Coates from Altitude Networks. We cover what Altitude is up to as well as general trends we’re seeing around data security in the cloud. Michael lays out his vision for “data first security”. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_149_Chat_with_Michael_Coates_about_data_security.mp3 Show Notes Michael Coates Altitude Networks Michael’s Keynote Comment on Twitter with the #osspodcast hashtag

June 10, 2019