wide-robots

Episode 429 - The autonomy of open source developers

Josh and Kurt talk about open source and autonomy. This is even related to some recent return to office news. The conversation weaves between a few threads, but fundamentally there’s some questions about why do people do what they do, especially in the world of open source. This also is a problem we see in security, security people love to tell developers what to do. Developers don’t like being told what to do. ...

May 20, 2024
wide-wood-curl

Episode 399 - Curl, Security, and Daniel Stenberg

Josh and Kurt talk to Daniel Stenberg about curl. Daniel is the creator of curl, we chat with him about the security of curl. Daniel tells us how curl is kept secure, we learn about some of the historical reasons curl works the way it does. We hear the story about the curl CVE situation firsthand. We also touch on the importance of curating the community of a popular open source project. ...

October 30, 2023
wide-stones

Episode 397 - The curl and glibc vulnerabilities

Josh and Kurt talk about a curl and glibc bug. The bugs themselves aren’t super interesting, but there are other conversations around the bugs that are interesting. Why don’t we just rewrite everything in Rust? Why can’t we just train developers to stop writing insecure code. How can AI solve this problem? It’s a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won’t change. ...

October 16, 2023
pinocchio-1939779_1920

Episode 394 - The lie anyone can contribute to open source

Josh and Kurt talk about filing bugs for software. There’s the old saying that anyone can file bugs and submit patches for open source, but the reality is most people can’t. Filing bugs for both closed and open source is nearly impossible in many instances. Even if you want to file a bug for an open source project, there are a lot of hoops before it’s something that can be actionable. ...

September 25, 2023
wide-volcano

Episode 392 - Curl and the calamity of CVE

Josh and Kurt talk about why CVE is making the news lately. Things are not well in the CVE program, and it’s not looking like anything will get fixed anytime soon. Josh and Kurt have a unique set of knowledge around CVE. There’s a lot of confusion and difficulty in understanding how CVE works. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_392_Curl_and_the_calamity_of_CVE.mp3 Show Notes Curl blog post Now it’s PostgreSQL’s turn to have a bogus CVE GitHub Advisory Database Josh’s “CVE tried to get me fired” story

September 11, 2023