Episode 141 - Timezones are hard, security is harder

Josh and Kurt talk about the difficulty of security. We look at the difficulty of the EU not observing daylight savings time, which is probably magnitudes easier than getting security right. We also hit on a discussion on Reddit about U2F that shows the difficulty. Security today is too hard, even for the experts. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_141_Timezones_are_hard_security_is_harder.mp3 Show Notes Storing time in UTC is hard How strong are nails and screws? Reddit U2F comments Comment on Twitter with the #osspodcast hashtag ...

April 15, 2019
city-walls-164825

The security of dependencies

So you’ve written some software. It’s full of open source dependencies. These days all software is full of open source, there’s no way around it at this point. I explain the background in my previous post. Now that we have all this open source, how do we keep up with it? If you’re using a lot of open source in your code there could be one or more updated dependencies per day! ...

April 10, 2019

Episode 140 - Good enough security is a pretty high bar

Josh and Kurt talk about identity. It’s a nice example we can generally understand in the context of how much security is enough security? When we deal with identity the idea of good enough is often acceptable for the vast majority of uses. Perfect identity tracking isn’t really a thing nor is it practical. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_140_Good_enough_security_is_a_pretty_high_bar.mp3 Show Notes Firefighters breaking through a door Fake engineer at the Berlin Airport Comment on Twitter with the #osspodcast hashtag ...

April 8, 2019
chain-109302

Supplying the supply chain

A long time ago Marc Andreessen said “software is eating the world”. This statement ended up being quite profound in hindsight, as most profound statements are. At the time nobody really understood what he meant and it probably wasn’t until the public cloud caught on that it became something nobody could ignore. The future of technology was less about selling hardware as it is about building software. We’re at a point now where it’s time to rethink software. Well, the rethinking happened quite some time ago, now everyone has to catch up. Today it’s a pretty safe statement to declare open source is eating the world. Open source won, it’s everywhere, you can’t not use it. It’s not always well understood. And it’s powering your supply chain, even if you don’t know it. ...

April 2, 2019

Episode 139 - Secure voting, firefox send, and toxic comments on the internet

Josh and Kurt talk about Brexit, voting, Firefox send, and toxic comments. Is there anything we can do to slow the current trend of conversation on the Internet always seeming to spiral out of control? The answer is maybe with a lot of asterisks. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_139_secure_voting_firefox_send_and_toxic_comments_on_the_internet.mp3 Show Notes Swiss evoting Darpa $10 million secure voting Firefox Send Jigsaw and toxic comments Comment on Twitter with the #osspodcast hashtag

April 1, 2019

Episode 138 - Information wants to be free

Josh and Kurt talk about a prank gone wrong, the reality of when your data ends up public. Once it’s public you can’t ever put it back. We also discuss Notepad++ no longer signing releases and what signing releases means for the world in general. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_138_Information_wants_to_be_free.mp3 Show Notes Japanese girl arrested Publish package to the npm registry University study on developers and passwords Kurt’s blockchain project - OpenCPEs Notepad++ stops signing releases What is a photocopier? TASBot Comment on Twitter with the #osspodcast hashtag ...

March 25, 2019

Episode 137.5 - Holy cow Beto was in the cDc, this is awesome!

Josh and Kurt talk about Beto being in the Cult of the Dead Cow (cDc). This is a pretty big deal in a very good way. We hit on some history, why it’s a great thing, what we can probably expect from opponents. There’s even some advice at the end how we can all help. We need more politicians with backgrounds like this. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_137_5_Holy_cow_Beto_was_in_the_cDc_this_is_awesome.mp3 Show Notes Cult of the Dead Cow Phrack Beto in the cDc 2600 Off the Hook Stallman Hacker Song Comment on Twitter with the #osspodcast hashtag ...

March 18, 2019

Episode 137 - When the IoT attacks!

Josh and Kurt talk about when devices attack! It’s not quite that exciting, but there have been a slew of news about physical devices causing problems for humans. We end on the note that we’re getting closer to a point when lawyers and regulators will start to pay attention. We’re not there yet, so we still have a horrible insecure future on the horizon. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_137_When_the_IoT_attacks.mp3 Show Notes Bricking a shoe Lime scooters throwing passengers off Malicious USB cables Comment on Twitter with the #osspodcast hashtag ...

March 11, 2019

Episode 136 - How people feel is more important than being right

Josh and Kurt talk about github blocking the Deepfakes repository. There’s a far bigger discussion about how people feel, and sometimes security fails to understand that making people feel happy or safer is more important than being right. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_136_How_people_feel_is_more_important_than_being_right.mp3 Show Notes Github Deepfakes discussion Cloudflare’s SOCKMAP blog Comment on Twitter with the #osspodcast hashtag

March 4, 2019

Episode 135 - Passwords, AI, and cloud strategy

Josh and Kurt talk about change your password day (what a terrible day). Google’s password checkup (not a terrible idea), an AI finding new spice flavors we expect will one day take over the world, and we finish up on a new DoD cloud strategy. Also Josh burnt his finger, but is going to be OK. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_135_Passwords_AI_and_cloud_strategy.mp3 Show Notes Change your password day Google password checkup AI finds new flavors DoD cloud strategy Comment on Twitter with the #osspodcast hashtag ...

February 25, 2019