Episode 110 - Review of Black Hat, Defcon, and the effect of security policies

Josh and Kurt talk about Black Hat and Defcon and how unexciting they have become. What happened with hotels at Defcon, and more importantly how many security policies have 2nd and 3rd level effects we often can’t foresee. We end with important information about pizza, bananas, and can openers. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_110_review_of_black_hat_defcon_and_the_effect_of_security_policies.mp3 Show Notes Kids hacking voting machines Black Hat plaintext email Defcon hotel shenanigans International Pizza Expo How to use a can opener How to open a banana Join our Facebook Group ...

August 20, 2018

Episode 109 - OSCon and actionable advice

Josh and Kurt talk about phishing training and how it doesn’t really matter. Josh spoke at OSCon and comes back with some fun observations and advice. People want practical actionable advice and we’re not good at that. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_109_OSCon_and_actionable_advice.mp3 Show Notes Traffic cone costume Azure Linux Masterlock Speed Dial Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

August 13, 2018

Episode 108 - Bluetooth, phishing, airgaps, and eating soup off the floor

Josh and Kurt talk about the latest attack on bluetooth and discuss phishing in the modern world. U2F is a great way to stop phishing, training is not. We also discuss airgaps in response to attacks on airgapped power utilities. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_108_bluetooth_phishing_airgaps_and_eating_soup_off_the_floor.mp3 Show Notes ECDH in Bluetooth Diffie-Hellman with paint Google Phishing Hackers jumped air gaps Portable secure data center Join our Facebook Group Comment on Twitter with the #osspodcast hashtag ...

August 6, 2018

Episode 107 - The year of the Linux Desktop and other hardware stories

Josh and Kurt talk about modern hardware, how security relates to devices and actions. Everything from secure devices, to the cables we use, to thermal cameras and coat hangers. We end the conversation discussing the words we use and how they affect the way people see us and themselves. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_107_the_year_of_the_linux_desktop_and_other_hardware_stories.mp3 Show Notes Linux on Chromebooks Touchscreen and secrets Coat hanger vs Monster cables Build a toaster Join our Facebook Group ...

July 30, 2018

Episode 106 - Data isn't oil, it's nuclear waste

Josh and Kurt talk about Cory Doctorow’s piece on Facebook data privacy. It’s common to call data the new oil but it’s more like nuclear waste. How we fix the data problem in the future is going to require solutions we can’t yet imagine as well as new ways of thinking about the problems. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_106_data_isnt_oil_its_nuclear_waste.mp3 Show Notes Mark Zuckerberg and his empire of oily rags Fitness app leak Operation Mincemeat Bancor cryptocurrency theft CryptoKitties Join our Facebook Group ...

July 23, 2018

Episode 105 - More backdoors in open source

Josh and Kurt talk about some recent backdoor problems in open source packages. We touch on is open source secure, how that security works, and what it should look like in the future. This problem is never going to go away or get better, and that’s probably OK. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_105_more_backdoors_in_open_source.mp3 Show Notes eslint-scope issue Arch Linux Acrobat Reader issue Join our Facebook Group Comment on Twitter with the #osspodcast hashtag ...

July 16, 2018

The father of modern security: B. F. Skinner

A lot of what we call security is voodoo. Most of it actually. What I mean with that statement is our security process is often based on ideas that don’t really work. As an industry we have built up a lot of ideas and processes that aren’t actually grounded in facts and science. We don’t understand why we do certain things, but we know that if we don’t do those things something bad will happen! Will it really happen? I heard something will happen. I suspect the answer is no, but it’s very difficult to explain this concept sometimes. ...

July 11, 2018

Episode 104 - The Gentoo security incident

Josh and Kurt talk about the Gentoo security incident. Gentoo did a really good job being open and dealing with the incident quickly. The basic takeaway from all this is make sure your organization is forcing users to use 2 factor authentication. The long term solution is going to be all identity providers forcing everyone to use 2FA. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_104_the_gentoo_security_incident.mp3 Show Notes Gentoo incident timeline Have I Been Pwned Cloudflare Join our Facebook Group ...

July 9, 2018

Episode 103 - The Seven Properties of Highly Secure Devices

Josh and Kurt talk about a Microsoft Research paper titled “The Seven Properties of Highly Secure Devices”. We take a real world view into how to secure our devices. What works, what doesn’t work, and why this list is actually really good. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_103_the_seven_properties_of_highly_secure_devices.mp3 Show Notes 7 Properties of Highly Secure Devices Pwn2Own Kurt’s dryer vent tweet Mars rover filesystem bug The Update Framework (TUF) Join our Facebook Group Comment on Twitter with the #osspodcast hashtag ...

July 2, 2018

Episode 102 - Michael Feiertag from tCell

Josh and Kurt talk to Michael Feiertag, the CEO of tCell. We talk about what a Web Application Firewall is, what it does and doesn’t do, and what the future of this technology looks like. We touch on how this affects a DevOps environment. Security has to fit into the existing model, not try to change it. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_102_michael_feiertag_from_tcell.mp3 Show Notes Michael’s LinkedIn Michael’s Twitter tCell Web Application Firewall (WAF) Runtime Application Self Protection (RASP) Join our Facebook Group ...

June 25, 2018