Episode 101 - Our unregulated future is here to stay

Josh and Kurt talk about Bird scooters. The implications of the scooters on the city, segways, bicycles. The topic of how these vehicles interact with pedestrians on the road and trails. It’s an example of humans not wanting to follow the rules and generally making the situation annoying for everyone. It’s the old security story of new technology without clear rules. The show ends with some horrifying numbers behind how bad things get before people really care. ...

June 17, 2018

Episode 100 - You're bad at buying security, we can help!

Josh and Kurt talk about how to be a smart security buyer. We have guest Steve Mayzak walk us through how a the buying process works as well as giving out a ton of great advice. Even if you’re experienced with how to buy security technology you should give this a listen. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_100_your_bad_at_buying_solutions_we_can_help.mp3 Show Notes Buyer training Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

June 11, 2018

Security ROI isn't impossible, we suck at measuring

As of late I’ve been seeing a lot of grumbling that security return on investment (ROI) is impossible. This is of course nonsense. Understanding your ROI is one of the most important things you can do as a business leader. You have to understand if what you’re doing makes sense. By the very nature of business, some of the things we do have more value than other things. Some things even have negative value. If we don’t know which things are the most important, we’re just doing voodoo security. ...

June 5, 2018

Episode 99 - Consumer security is too broken to fix, and it doesn't matter

Josh and Kurt talk about a number of consumer security issues. The FBI told everyone to reboot their routers which they won’t do. The .app top level domain is a cesspool of malware. Everyone has a cell phone and won’t update them properly. None of this probably matters though. Unless there are real measurable tragedies caused by this tech, people tend not to really care. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_99_consumer_security_is_too_broken_to_fix_and_it_doesnt_matter.mp3 Show Notes FBI says reboot your routers .app cesspool Join our Facebook Group ...

June 4, 2018

Episode 98 - When IT decisions kill people

Josh and Kurt talk about the NTSB report from the fatal Uber crash and what happened with Amazon’s Alexa recording then emailing a private conversation. IT decisions now have real world consequences like never before. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_98_when_it_decisions_kill_people.mp3 Show Notes Uber NTSB report Powerpoint and the space shuttle Alexa secret recording Siri unlocks the door 911 operator hangs up Join our Facebook Group Comment on Twitter with the #osspodcast hashtag ...

May 28, 2018

Episode 97 - Automation: Humans are slow and dumb

Josh and Kurt talk about the security of automation as well as automating security. The only way automation will really work long term is full automation. Humans can’t be trusted enough to rely on them to do things right. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_97_automation_humans_are_slow_and_dumb.mp3 Show Notes Tesla hits a firetruck British Tesla passenger Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

May 20, 2018

Helicopter security

After my last post about security spending, I was thinking about how most security teams integrate into the overall business (hint: they don’t). As part of this thought experiment I decided to compare traditional security to something that in modern times has come to be called helicopter parenting. A helicopter parent is someone who won’t let their kids do anything on their own. These are the people you hear about who follow their child to college, to sports practice. They yell at teachers and coaches for not respecting how special the child is. The kids are never allowed to take any risks because risk is dangerous and bad. If they climb the tree, while it could be a life altering experience, they could also fall and get hurt. Skateboarding is possibly the most dangerous thing anyone could ever do! We better make sure nothing bad can ever happen. ...

May 17, 2018

Episode 96 - Are legal backdoors a good idea?

Josh and Kurt talk about backdoors in code and products that have been put there on purpose. We talk about unlocking phones. Encryption backdoors with a focus on why they won’t work. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_96_all_about_backdoors.mp3 Show Notes CALEA Cellebrite unlocking phones Schneier on Ray Ozzie’s proposal UK RIP act Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

May 14, 2018

Episode 95 - Twitter passwords and npm backdoors

Josh and Kurt talk about Twitter doing the right thing when they logged a lot of passwords, the npm malicious getcookies package, and how backdoors work in code. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_95_twitter_passwords_and_npm_backdoors.mp3 Show Notes Twitter password logging npm getcookies xkcd gluing things together Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

May 7, 2018

Episode 94 - DNSSEC, BGP, and reality

Josh and Kurt talk about the Amazon Route 53 incident and what it really means for the modern infrastructure. Complaining nobody is using DNSSEC or securing BGP aren’t the right conversations to be having. Reality must be considered in any honest conversation about these topics. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_94_dns_bgp_and_reality.mp3 Show Notes Route 53 attack Cloudflare’s 1.1.1.1 Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

April 30, 2018