Episode 40 - Let's fork bitcoin, again

Josh and Kurt discuss Verizon spyware, FCC privacy, Smart TVs, Tor’s rewrite, Google’s new operating system, bitcoin, and NanoCore. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/315737179-opensourcesecuritypodcast-episode-40-lets-fork-bitcoin-again.mp3 Show Notes Verizon Spyware Story FCC Broadband Privacy Inserting tracking headers Smart TVs run Flash Tor rewrite in safer language Fuchsia Bitcoin fork NanoCore Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

April 2, 2017

Remember kids, if you're going to disclose, disclose responsibly!

If you pay any attention to the security universe, you’re aware that Tavis Ormandy is basically on fire right now with his security research. He found the Cloudflare data leak issue a few weeks back, and is currently going to town on LastPass. The LastPass crew seems to be dealing with this pretty well, I’m not seeing a lot of complaining, mostly just info and fixes which is the right way to do these things. ...

March 28, 2017

Episode 39 - Flash on your dishwasher

Josh and Kurt discuss certificates, OpenSSL, dishwashers, Flash, and laptop travel bans. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/314794586-opensourcesecuritypodcast-episode-39-flash-on-your-dishwasher.mp3 Show Notes SNES bluetooth remake Symantec vs Google OpenSSL license change Dishwasher directory traversal Fedex $5 for Flash Laptop and iPad airline ban Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 28, 2017

Inverse Law of CVEs

I’ve started a project to put the CVE data into Elasticsearch and see if there is anything clever we can learn about it. Ever if there isn’t anything overly clever, it’s fun to do. And I get to make pretty graphs, which everyone likes to look at. I stuck a few of my early results on Twitter because it seemed like a fun thing to do. One of the graphs I put up was comparing the 3 BSDs. The image is below. ...

March 23, 2017

Episode 38 - We Ruin Everything

Josh and Kurt discuss disclosing your password, pwn2own, wikileaks, Back Orifice, HTTPS inspection, and antivirus. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/313701429-opensourcesecuritypodcast-episode-38-we-ruin-everything.mp3 Show Notes xkcd comic Defendant refusing to give up password Prisoner ID Password Fraud Victim’s Google Warrant pwn2own VM escape pwn2own Mozilla 22 hour fix Wikileaks non disclosure Back Orifice HTTPS inspection tools may be unsafe Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 22, 2017

Security, Consumer Reports, and Failure

Last week there was a story about Consumer Reports doing security testing of products. Consumer Reports to Begin Evaluating Products, Services for Privacy and Data Security As one can imagine there were a fair number of “they’ll get it wrong” sort of comments. They will get it wrong, at first, but that’s not a reason to pick on these guys. They’re quite brave to take this task on, it’s nearly impossible if you think about the state of security (especially consumer security). But this is how things start. There is no industry that has gone from broken to perfect in one step. It’s a long hard road when you have to deal with systemic problems in an industry. Consumer product security problems may be larger and more complex than any other industry has ever had to solve thanks to things such as globalization and how inexpensive tiny computers have become. ...

March 12, 2017

Episode 37 - Your bathtub is more dangerous than a shark

Josh and Kurt discuss how the Vault 7 leaks shows we live in the Neuromancer world, and this is likely the new normal. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/311442678-opensourcesecuritypodcast-episode-37-your-bathtub-is-more-dangerous-than-a-shark.mp3 Show Notes Hacker News Writeup about Vault 7 SATAN RTL-SDR White House Reconstruction Baseband Hacking CGA Graphics Chromium Security Brag Sheet French Zoo Poacher Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 9, 2017

Episode 36 - A Good Enough Podcast

Josh and Kurt discuss an IoT bear, Alexa and Siri, Google’s E2Email and S/MIME. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/310851037-opensourcesecuritypodcast-episode-36-a-good-enough-podcast.mp3 Show Notes IoT Bear Alexa murder evidence Google E2Email Google S/MIME Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

March 5, 2017

What the Oscars can teach us about security

If you watched the 89th Academy Awards you saw a pretty big mistake at the end of the show, the short story is Warren Beatty was handed the wrong envelope, he opened it, looked at it, then gave it to Faye Dunaway to read, which she did. The wrong people came on stage and started giving speeches, confused scrambling happened, and the correct winner was brought on stage. No doubt this will be talked about for many years to come as one of the most interesting and exciting events in the history of the awards ceremony. ...

March 2, 2017

Episode 35 - Crazy Cosmic Accident

Josh and Kurt discuss SHA-1 and cloudbleed. Bug bounties come up, we compare security to the Higgs boson, and IPv6 comes up at the end. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/309898784-opensourcesecuritypodcast-episode-35-crazy-cosmic-accident.mp3 Show Notes SHA-1 attack Google Security Blog about SHA-1 Zcash hash algorithm analysis Webkit SVN Collision Google bug about cloudbleed Cloudflare Blog Known cloudbleed sites SHA-1 CVE-2005-4900 Whitewood Entropy Join our Facebook Group Comment on Twitter with the #osspodcast hashtag

February 28, 2017