wide-spiderweb

Episode 438 - CISA's bad OSS advice vs the Whitehouse good advice

Josh and Kurt talk about two documents from the US government that discuss open source in very different ways. The CISA document lays out a way to measure open source, but we take issue with the idea of trying to measure which open source projects are “good”. The Whitehouse on the other hand takes an approach that is very open source, get involved. Trying to measure open source isn’t producing anything actionable, but getting involved is very actionable, and very much how open source works. ...

July 22, 2024
wide-pump

Episode 435 - polyfill.io - open source is too big to fix

Josh and Kurt talk about the latest polyfill.io mess. Apparently someone took over a very popular project and started to serve malware. First XZ, now this. What does it mean for open source? We don’t have any answers, and it’s hard to even talk about this problem because it’s so big. The thing is though, even if we can’t fix open source, it’s here to stay. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_435_polyfill_io_open_source_is_too_big_to_fix.mp3 Show Notes Polyfill supply chain attack hits 100K+ sites OpenSSF Scorecard

July 1, 2024
wide-tree-chop

Episode 415 - Reducing attack surface for less security

Josh and Kurt talk about a blog post explaining how to create a very very small container image. Generally in the world of security less is more, but it’s possible to remove too much. A lot of today’s security tooling relies on certain things to exist in a container image, if we remove them we could actually result in worse security than leaving it in. It’s a weird topic, but probably pretty important. ...

February 12, 2024
score-g0045204f4_1920

Episode 293 - Scoring OpenSSF Security Scoring

Josh and Kurt talk about the release of OpenSSF Security Scorecards version 3. This is a great project that will probably make a huge difference. Most of the things the scorecards are measuring are no brainier activities. We go through the list of metrics being measured. There are only a few that we don’t think are fantastic. https://traffic.libsyn.com/secure/opensourcesecuritypodcast/Episode_293_Scoring_OpenSSF_Security_Scoring.mp3 Show Notes 4 of spades OpenSSF Chris Montgomery audio explanation Scorecard 3.0.0 Scoring criteria Python Skeleton

October 18, 2021