french-bulldog-5342008_1920

Episode 215 - Real security is boring

Josh and Kurt talk about attacking open source. How serious is the threat of developers being targeted or a git repo being watched for secret security fixes? The reality of it all is there are many layers in a security journey, the most important things you can do are also the least exciting. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_215_Real_security_is_boring.mp3 Show Notes Targeting developers XKCD Infrastructure comic Hiding security flaws in git Mossad vs Not-Mossad (PDF warning)

September 14, 2020
work-boots-4133813_1920

Episode 209 - Secure Boot isn't Secure

Josh and Kurt talk about Secure Boot. The conversation uses the recent “Boot Hole” vulnerability to frame a conversation about what Secure Boot is and isn’t. Why the Boot Hole flaw doesn’t really matter, and why Secure Boot was very scary for Linux users back when it came out. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_209_Secure_Boot_isnt_Secure.mp3 Show Notes Boot Hole

August 10, 2020