A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.

Similar Podcasts

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Go Time: Golang, Software Engineering

Go Time: Golang, Software Engineering
Your source for diverse discussions from around the Go community. This show records LIVE every Tuesday at 3pm US Eastern. Join the Golang community and chat with us during the show in the #gotimefm channel of Gophers slack. Panelists include Mat Ryer, Jon Calhoun, Carmen Andoh, Johnny Boursiquot, Angelica Hill, Mark Bates, Kris Brandow, and Natalie Pistunovich. We discuss cloud infrastructure, distributed systems, microservices, Kubernetes, Docker… oh and also Go! Some people search for GoTime or GoTimeFM and can’t find the show, so now the strings GoTime and GoTimeFM are in our description too.

The FOSS Pod

The FOSS Pod
From the creative geniuses behind Brad & Will Made a Tech Pod, The FOSS Pod is a show about the free and open source software that’s changing the world, and the developers who are making it happen.

Episode 403 - Does the government banning apps work?

November 26, 2023 35:04 33.65 MB Downloads: 0

Josh and Kurt talk about the Canadian Government banning WeChat and Kaspersky. There's a lot of weird little details in this conversation. It fundamentally comes down to a conversation about risk. It's easy to spout nonsense about risk, but having an honest discussion about it is REALLY complicated. But the government plays by a very different set of rules. Show Notes Canada bans WeChat, Kaspersky applications on government devices Fitness tracking app Strava gives away location of secret US army bases Phishing emails increase over 1,200 percent since ChatGPT launch FedRAMP Rev 5 FAIR Institute

Episode 402 - The EU's eIDAS regulation is a terrible idea

November 19, 2023 30:29 29.25 MB Downloads: 0

Josh and Kurt talk about the new EU eIDAS regulation. This is a bill that will force web browsers to add root certificates based on law instead of technical merits, which is how it's currently done. This is concerning for a number of reasons that we discuss on the show. This proposal is not a good idea. Show Notes Mozilla site Root CA mailing list UK eIDAS regulation EFF statement on eIDAS Fixed XKCD comic

Episode 401 - Security skills shortage - We've tried nothing and the same thing keeps happening

November 12, 2023 40:09 38.54 MB Downloads: 0

Josh and Kurt talk about security skills shortage. We start out on the topic of cybersecurity skills and weave our way around a number of human related problems in this space. The world of tech has a lot of weird problems and there's not a lot of movement to fix many of them. Tech is weird and hard, and with the almost complete lack of regulation creates some of these challenges. In the world of security we need a better talent pipeline, but that takes actual efforts, not just complaining on the internet. Show Notes Schneier on security skill shortage British Airways flight smoke The Password Game Tesla accidents Lawn darts

Episode 400 - When can the government hack a victim?

November 05, 2023 32:17 30.97 MB Downloads: 0

Josh and Kurt talk about a proposed Dutch proposal that would allow the intelligence services to hack victims of adversaries they are in the process of infiltrating. The purpose of this discussion isn't to focus on the Dutch specifically, but rather to discuss the larger topic of government oversight. These are all very new concepts and nobody knows how things should work. Show Notes Dutch hacking proposal Give Me Toilet Paper! by Asuka424 in 9:54 - Summer Games Done Quick 2023 Flipper Zero Smart Meter Frequency Hopping Teri Kanfield

Episode 399 - Curl, Security, and Daniel Stenberg

October 29, 2023 37:53 36.36 MB Downloads: 0

Josh and Kurt talk to Daniel Stenberg about curl. Daniel is the creator of curl, we chat with him about the security of curl. Daniel tells us how curl is kept secure, we learn about some of the historical reasons curl works the way it does. We hear the story about the curl CVE situation firsthand. We also touch on the importance of curating the community of a popular open source project. Show Notes Daniel's Mastodon account Curl The curl CVE blog Broken curl on PowerShell wolfSSL

Episode 398 - Is only 11% of open source mainted?

October 22, 2023 36:49 35.33 MB Downloads: 0

Josh and Kurt talk about Sonatype's 9th Annual State of the Software Supply Chain. There's a ton of data in the report, but the thing we want to talk about is the statistic that only 11% of open source is actually being maintained. Do we think that's true? Does it really matter? Show Notes Sonatype report ecosyste.ms GNOME libcue flaw Reality 2.0 supply chain episode

Episode 397 - The curl and glibc vulnerabilities

October 15, 2023 34:25 33.04 MB Downloads: 0

Josh and Kurt talk about a curl and glibc bug. The bugs themselves aren't super interesting, but there are other conversations around the bugs that are interesting. Why don't we just rewrite everything in Rust? Why can't we just train developers to stop writing insecure code. How can AI solve this problem? It's a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won't change. Show Notes Curl vulnerability glibc vulnerability Josh's Badge Project Bob Lord's phishing message

Episode 396 - CLAs are bad, Mkay?

October 08, 2023 35:26 34.01 MB Downloads: 0

Josh and Kurt talk about contributor license agreements (CLAs). CLAs used to be seen as a necessary evil, but they're almost certainly bad now. We're seeing CLAs being abused, it's clear now anything controlled by a CLA won't be open source forever. Show Notes A Theory of Joint Authorship for Free and Open Source Software Projects Bruce Perens: What Comes After Open Source

Episode 395 - Uncertainty, trust, and security

October 01, 2023 33:47 32.41 MB Downloads: 0

Josh and Kurt talk about uncertainty. There are a bunch of stories in the news lately that really just boil down to uncertainty. Uncertainty is incredibly dangerous for everyone. We are afraid of uncertainty, and often don't really understand why it is. Trust is like a currency and uncertainty erodes trust faster than almost anything else. Show Notes Unity's license mess Godot Meta and Salesforce want to re-hire people they fired earlier this year U.S. Debt Credit Rating Downgraded, Only Second Time In Nation’s History

Episode 394 - The lie anyone can contribute to open source

September 24, 2023 35:48 34.35 MB Downloads: 0

Josh and Kurt talk about filing bugs for software. There's the old saying that anyone can file bugs and submit patches for open source, but the reality is most people can't. Filing bugs for both closed and open source is nearly impossible in many instances. Even if you want to file a bug for an open source project, there are a lot of hoops before it's something that can be actionable. Show Notes Linux is a nightmare Lodash just declared issue bankruptcy and closed every issue and open PR Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges Curl NULL pointer dereference

Episode 393 - Can you secure something you don't own?

September 17, 2023 33:47 32.42 MB Downloads: 0

Josh and Kurt talk about the weird world we live in how where we can't control a lot of our hardware. We don't really have control over most devices we interact with on a daily basis. The conversation shifts into a question of how can we decide what to trust and where. It's a very strange problem we experience now. Show Notes Boots theory MGM cybersecurity issue shuts down slot machines and ATMs in Las Vegas casinos New York Fire Department Forcible Entry Reference Guide Request for Information on Open-Source Software Security: Areas of Long-Term Focus and Prioritization

Episode 392 - Curl and the calamity of CVE

September 10, 2023 46:25 44.55 MB Downloads: 0

Josh and Kurt talk about why CVE is making the news lately. Things are not well in the CVE program, and it's not looking like anything will get fixed anytime soon. Josh and Kurt have a unique set of knowledge around CVE. There's a lot of confusion and difficulty in understanding how CVE works. Show Notes Curl blog post Now it's PostgreSQL's turn to have a bogus CVE GitHub Advisory Database Josh's "CVE tried to get me fired" story

Episode 391 - The Wordpress 100 year disaster recovery problem

September 03, 2023 39:11 37.6 MB Downloads: 0

Josh and Kurt talk about wordpress selling web services with a 100 year lifespan. Will WordPress still be around in 100 years? What would 100 years of disaster recovery look like? Most of us will never need to think about 100 years of disaster recovery. Show Notes WordPress is now selling 100-year domains Danish ransomware 15-Minute City The Year Without Pants

Episode 390 - Rust shipping binaries doesn't matter

August 27, 2023 39:19 37.74 MB Downloads: 0

Josh and Kurt talk about a blog post that explains how C and C++ compilers prioritize performance over correctness. This is the class story of security vs usability. Security is never the primary goal. If a security requirement doesn't also enable other business goals it will fail. We also touch on the news of a Rust package containing binary files. It doesn't really have anything to do with security, it's all about convenience. Show Notes C and C++ Prioritize Performance over Correctness Nisha's toot Barry Marshall Rust devs push back as Serde project ships precompiled binaries Why DARPA Hopes To 'Distill' Old Binaries Into Readable Code Mario 64 decompilation

Episode 389 - What would HashiCorp do?

August 20, 2023 42:16 40.57 MB Downloads: 0

Josh and Kurt talk about the HashiCorp license change and copyright problems in open source. This isn't the first and won't be the last time we see this, but it's very likely open source developers and communities will view any project that has a contributor license agreement as a problem moving forward. Show Notes Josh's BSidesLV talk Hacker News marked site as malware HashiCorp license change A Theory of Joint Authorship for Free and Open Source Software Projects