wide-santa

Episode 407 - Should Santa use AI?

It’s the 2023 Christmas Spectacular! Josh and Kurt talk about what would happen if Santa starts using AI to judge which children are naughty and nice. There’s some fun in this one, but it does get pretty real. While we tried to discuss Santa using AI, the reality is this sort of AI is coming for many of us. AI will be making decisions for all of us in the near future (if it isn’t already). While less fun than we had hoped for, it’s an important conversation. ...

December 18, 2023
wide-radio

Episode 406 - The security of radio

Josh and Kurt talk about a few security stories about radio. The TETRA:BURST attack on police radios, spoofing GPS for airplanes near Iran, and Apple including cellular radios in the macbooks. The common thread between all these stories is looking at the return on investment for security. Sometimes good enough security is fine, sometimes it’s not worth fixing certain security problems because the risk vs reward doesn’t work out. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_406_The_security_of_radio.mp3 Show Notes TETRA:BURST GPS spoofing attack Apple MacBooks cellular radio Mossad vs Not Mossad

December 11, 2023
wide-game

Episode 405 - Modding games isn't cheating and security isn't fair

Josh and Kurt talk about Capcom claiming modding a game is akin to cheating. The arguments used are fundamentally one of equity vs equality. Humans love to focus on equality instead of equity when we deal with most problems. This is especially true in the world of security. Rather than doing something that has a net positive, we ignore the details and focus on doing something that feels “right”. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_405_Modding_games_isnt_cheating_and_security_isnt_fair.mp3 Show Notes Why Capcom thinks PC game modding is akin to “cheating” Ben Heck

December 4, 2023
wide-keep-out

Episode 403 - Does the government banning apps work?

Josh and Kurt talk about the Canadian Government banning WeChat and Kaspersky. There’s a lot of weird little details in this conversation. It fundamentally comes down to a conversation about risk. It’s easy to spout nonsense about risk, but having an honest discussion about it is REALLY complicated. But the government plays by a very different set of rules. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_403_Does_the_government_banning_apps_work.mp3 Show Notes Canada bans WeChat, Kaspersky applications on government devices Fitness tracking app Strava gives away location of secret US army bases Phishing emails increase over 1,200 percent since ChatGPT launch FedRAMP Rev 5 FAIR Institute

November 27, 2023
wide-factory

Episode 402 - The EU's eIDAS regulation is a terrible idea

Josh and Kurt talk about the new EU eIDAS regulation. This is a bill that will force web browsers to add root certificates based on law instead of technical merits, which is how it’s currently done. This is concerning for a number of reasons that we discuss on the show. This proposal is not a good idea. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_402_The_EUs_eIDAS_regulation_is_a_terrible_idea.mp3 Show Notes Mozilla site Root CA mailing list UK eIDAS regulation EFF statement on eIDAS Fixed XKCD comic

November 20, 2023
wide-old-classroom

Episode 401 - Security skills shortage - We've tried nothing and the same thing keeps happening

Josh and Kurt talk about security skills shortage. We start out on the topic of cybersecurity skills and weave our way around a number of human related problems in this space. The world of tech has a lot of weird problems and there’s not a lot of movement to fix many of them. Tech is weird and hard, and with the almost complete lack of regulation creates some of these challenges. In the world of security we need a better talent pipeline, but that takes actual efforts, not just complaining on the internet. ...

November 13, 2023
wide-gov-hack

Episode 400 - When can the government hack a victim?

Josh and Kurt talk about a proposed Dutch proposal that would allow the intelligence services to hack victims of adversaries they are in the process of infiltrating. The purpose of this discussion isn’t to focus on the Dutch specifically, but rather to discuss the larger topic of government oversight. These are all very new concepts and nobody knows how things should work. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_400_When_can_the_government_hack_a_victim.mp3 Show Notes Dutch hacking proposal Give Me Toilet Paper! by Asuka424 in 9:54 - Summer Games Done Quick 2023 Flipper Zero Smart Meter Frequency Hopping Teri Kanfield

November 6, 2023
wide-wood-curl

Episode 399 - Curl, Security, and Daniel Stenberg

Josh and Kurt talk to Daniel Stenberg about curl. Daniel is the creator of curl, we chat with him about the security of curl. Daniel tells us how curl is kept secure, we learn about some of the historical reasons curl works the way it does. We hear the story about the curl CVE situation firsthand. We also touch on the importance of curating the community of a popular open source project. ...

October 30, 2023
wide-angel

Episode 398 - Is only 11% of open source maintained?

Josh and Kurt talk about Sonatype’s 9th Annual State of the Software Supply Chain. There’s a ton of data in the report, but the thing we want to talk about is the statistic that only 11% of open source is actually being maintained. Do we think that’s true? Does it really matter? https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_398_Is_only_11_of_open_source_mainted.mp3 Show Notes Sonatype report ecosyste.ms GNOME libcue flaw Reality 2.0 supply chain episode

October 23, 2023
wide-stones

Episode 397 - The curl and glibc vulnerabilities

Josh and Kurt talk about a curl and glibc bug. The bugs themselves aren’t super interesting, but there are other conversations around the bugs that are interesting. Why don’t we just rewrite everything in Rust? Why can’t we just train developers to stop writing insecure code. How can AI solve this problem? It’s a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won’t change. ...

October 16, 2023