Episode 93 - Security flaws in beep and patch, how did we get here?

Josh and Kurt talk about security flaws in beep and patch. How on earth were there security flaws in beep and patch? https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_93-Security_flaws_in_beep_and_patch_how_did_we_get_here.mp3 Show Notes beep security flaw patch security flaw Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

April 23, 2018

Episode 92 - Chat with Rami Saas the CEO of WhiteSource

Josh and Kurt talk to Rami Saas, the CEO of WhiteSource about 3rd party open source security as well as open source licensing. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode-92_chat_with_rami_saas.mp3 Show Notes WhiteSource Rami Saas Open Source Licenses Mercedes C-Class 205 Open Source Licenses Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

April 15, 2018

Episode 91 - Security lessons from a 7 year old

Josh and Kurt talk to a 7 year old about security. We cover Minecraft security, passwords, hacking, and many many other nuggets of wisdom. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode-91_security_lessons_from_a_7_year_old.mp3 Show Notes Minecraft John Doe Roblox Roblox Join our Facebook Group Comment on Twitter with the #osspodcast hashtag Keywords: passwords, minecraft

April 8, 2018

Spend until you're secure

I was watching a few Twitter conversations about purchasing security last week and had yet another conversation about security ROI. This has me thinking about what we spend money on. In many industries we can spend our way out of problems, not all problems, but a lot of problems. With security if I gave you a blank check and said “fix it”, you couldn’t. Our problem isn’t money, it’s more fundamental than that. ...

April 5, 2018

Episode 90 - Humans and misinformation

Josh and Kurt talk about all the current misinformation, how humans react to it, and what it means for security. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode-90_humans_and_misinformation.mp3 Show Notes Virus infections during lent Wikipedia circular reporting Guccifer Bad Twitter VPN advice Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

April 2, 2018

Episode 89 - Short selling AMD security flaws

Josh and Kurt talk about the recent AMD flaws and the events surrounding the disclosure. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode-89_short_selling_amd_security_flaws.mp3 Show Notes AMD flaws Activist investing Microsoft side channel bounty Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 25, 2018

Episode 88 - Chat with Chris Rosen from IBM about Container Security

Josh and Kurt talk about container security with IBM’s Chris Rosen. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_88_chat_with_chris_rosen_from_ibm_about_container_security.mp3 Show Notes Chris Rosen Kubernetes Istio Grafeas Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 18, 2018

Episode 87 - Chat with Let's Encrypt co-founder Josh Aas

Josh and Kurt talk about Let’s Encrypt with co-founder Josh Aas. We discuss the past, present, and future of the project. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_87_Chat_with_lets_encrypt_co-founder_josh_aas.mp3 Show Notes Let’s Encrypt Josh Aas Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 11, 2018

But that's not my job!

This week I’ve been thinking about how security people and non security people interact. Various conversations I have often end up with someone suggesting everyone needs some sort of security responsibility. My suspicion is this will never work. First some background to think about. In any organization there are certain responsibilities everyone has. Without using security as our specific example just yet, let’s consider how a typical building functions. You have people who are tasked with keeping the electricity working, the plumbing, the heating and cooling. Some people keep the building clean, some take care of the elevators. Some work in the building to accomplish some other task. If the company that inhabits the building is a bank you can imagine the huge number of tasks that take place inside. ...

March 7, 2018

Episode 86 - What happens when 23 thousand certificates leak?

Josh and Kurt talk about the Trustico certificate incident and Let’s Encrypt. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_86_What_happens_when_23_thousand_certificates_leak.mp3 Show Notes Certificate revocation Trustico website incident Let’s Encrypt ACME v2 XKCD PGP verification FreeIPA Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 5, 2018