PLAY PODCASTS
Open Source Security

Open Source Security

549 episodes — Page 10 of 11

Ep 99Episode 99 - Consumer security is too broken to fix, and it doesn't matter

Josh and Kurt talk about a number of consumer security issues. The FBI told everyone to reboot their routers which they won't do. The .app top level domain is a cesspool of malware. Everyone has a cell phone and won't update them properly. None of this probably matters though. Unless there are real measurable tragedies caused by this tech, people tend not to really care.

Jun 4, 201834 min

Ep 98Episode 98 - When IT decisions kill people

Josh and Kurt talk about the NTSB report from the fatal Uber crash and what happened with Amazon's Alexa recording then emailing a private conversation. IT decisions now have real world consequences like never before.

May 28, 201834 min

Ep 97Episode 97 - Automation: Humans are slow and dumb

Josh and Kurt talk about the security of automation as well as automating security. The only way automation will really work long term is full automation. Humans can't be trusted enough to rely on them to do things right.

May 20, 201833 min

Ep 96Episode 96 - Are legal backdoors a good idea?

Josh and Kurt talk about backdoors in code and products that have been put there on purpose. We talk about unlocking phones. Encryption backdoors with a focus on why they won't work.

May 11, 201832 min

Ep 95Episode 95 - Twitter passwords and npm backdoors

Josh and Kurt talk about Twitter doing the right thing when they logged a lot of passwords and the npm malicious getcookies package and how backdoors work in code.

May 7, 201829 min

Ep 94Episode 94 - DNSSEC, BGP, and reality

Josh and Kurt talk about the Amazon Route 53 incident and what it really means for the modern infrastructure. Complaining nobody is using DNSSEC or securing BGP aren't the right conversations to be having. Reality must be considered in any honest conversation about these topics.

Apr 30, 201828 min

Ep 93Episode 93 - Security flaws in beep and patch, how did we get here?

Josh and Kurt talk about security flaws in beep and patch. How on earth were there security flaws in beep and patch?

Apr 15, 201836 min

Ep 92Episode 92 - Chat with Rami Saas the CEO of WhiteSource

Josh and Kurt talk to Rami Saas, the CEO of WhiteSource about 3rd party open source security as well as open source licensing.

Apr 15, 201833 min

Ep 91Episode 91 - Security lessons from a 7 year old

Josh and Kurt talk to a 7 year old about security. We cover Minecraft security, passwords, hacking, and many many other nuggets of wisdom.

Apr 8, 201819 min

Ep 90Episode 90 - Humans and misinformation

Josh and Kurt talk about all the current misinformation, how humans react to it, and what it means for security.

Apr 2, 201836 min

Ep 89Episode 89 - Short selling AMD security flaws

Josh and Kurt talk about the recent AMD flaws and the events surrounding the disclosure.

Mar 25, 201834 min

Ep 88Episode 88 - Chat with Chris Rosen from IBM about Container Security

Josh and Kurt talk about container security with IBM's Chris Rosen.

Mar 18, 201832 min

Ep 87Episode 87 - Chat with Let's Encrypt co-founder Josh Aas

Josh and Kurt talk about Let's Encrypt with co-founder Josh Aas. We discuss the past, present, and future of the project.

Mar 11, 201838 min

Ep 86Episode 86 - What happens when 23 thousand certificates leak?

Josh and Kurt talk about the Trustico certificate incident and Let's Encrypt.

Mar 3, 201834 min

Ep 85Episode 85 - NPM ate my files

Josh and Kurt talk about the npm 5.7.0 debacle.

Feb 23, 201832 min

Ep 84Episode 84 - Have I been pwned?

Josh and Kurt talk about the new password data dump from Have I been pwned?

Feb 23, 201831 min

Ep 83Episode 83 - XKCD + CVE = XKCVE

Josh and Kurt talk about the XKCD CVE comic and a flight simulator stealing credentials.

Feb 21, 201831 min

Ep 82Episode 82 - RSA, TLS, Chrome HTTP, and PCI

Josh and Kurt talk about problems of textbook RSA implementations, the upcoming TLS changes in TLS, and the insecurity of http in Chrome.

Feb 13, 201829 min

Ep 81Episode 81 - Autosploit, bug bounties, and the future of security

Josh and Kurt talk about AutoSploit, bug bounties and fixing flaws, market forces in security, future expectations, and how humans perceive threats.

Feb 7, 201831 min

Ep 80Episode 80 - GPS tracking and jamming

Josh and Kurt talk about GPS metadata giving away military bases and GPS jamming as part of testing.

Jan 31, 201833 min

Ep 79Episode 79 - Skyfall: please don't yell 'fire'

Josh and Kurt talk about Skyfall, fake reports, risk, logging, and how a civilized society functions.

Jan 24, 201855 min

Ep 78Episode 78 - Risk lessons from Hawaii

Josh and Kurt talk about the accidental missile warning in Hawaii. We also discuss general preparedness and risk.

Jan 16, 201852 min

Ep 77Episode 77 - npm and the supply chain

Josh and Kurt talk about the recent npm happenings. What it means for the supply chain, and we end with some thoughts on how maybe none of this matters.

Jan 10, 20181h 0m

Ep 76Episode 76 - Meltdown aftermath

Josh and Kurt talk about the aftermath of Meltdown. The details of the flaw are probably less interesting than what happens now.

Jan 7, 201850 min

Ep 75Episode 75 - Security Planner review

Josh and Kurt talk about the Security Planner website. It's pretty good all things considered.

Dec 19, 20171h 3m

Ep 74Episode 74 - Facial recognition and physical security

Josh and Kurt talk about facial recognition, physical security, banking, and Amazon Alexa.

Dec 13, 201742 min

Ep 73Episode 73 - Security from Santa

Josh and Kurt talk about basic security metrics and security from Santa. Is Santa GDPR compliant?

Dec 6, 20171h 0m

Ep 72Episode 72 - Bitcoin: It's over 9000

Josh and Kurt talk about Bitcoin, blockchain, and other cryptocurrencies.

Nov 28, 201752 min

Ep 71Episode 71 - GitHub's Security Scanner

Josh and Kurt talk about GitHub's security scanner and Linus' security email. We clarify the esoteric difference between security bugs and non security bugs.

Nov 21, 201746 min

Ep 70Episode 70 - The security of Intel ME

Josh and Kurt talk about Intel ME, Equifax salary history, and IoT.

Nov 14, 201749 min

Ep 69Episode 69 - Actionable security advice

Josh and Kurt talk about Amazon Key and actionable advice.

Nov 7, 201746 min

Ep 68Episode 68 - Ruining the Internet

Josh and Kurt talk about Facebook listening to your microphone, Google Chrome certificate pinning, CAs, 152 ways to stay safe, and Kubernetes.

Nov 1, 201751 min

Ep 67Episode 67 - Cyber won

Josh and Kurt talk about hacking back, passwords, honeypots, and conspiracies.

Oct 24, 201738 min

Ep 66Episode 66 - Objects in mirror are less terrible than they appear

Josh and Kurt talk about Equifax again, Kaspersky, TLS CAs, coming change, social security numbers, and Minecraft.

Oct 15, 201745 min

Episode 65 - Will aliens overthrow us before AI?

Josh and Kurt talk about Apple, Equifax, passwords, AI, and aliens.

Oct 9, 201749 min

Episode 64 - Networks and Dnsmasq and IoT oh my

Josh and Kurt talk about networks, Dnsmasq, IoT, and our coming security dystopian future.

Oct 3, 201752 min

Ep 63Episode 63 - Shoot, Shovel, and Bury

Josh and Kurt talk about the Equifax breach (again) and what it will mean for all of us. Blueborne comes up, as well as #TrevorForget.

Sep 26, 201758 min

Ep 62Episode 62 - All about the Equifax hack

Josh and Kurt talk about the Equifax breach and what it will mean for all of us.

Sep 11, 20171h 5m

Ep 61Episode 61 - Market driven security

Josh and Kurt talk about our lack of progress in security, economics, and how to interact with peers.

Sep 5, 201751 min

Episode 60 - The official blockchain episode

Josh and Kurt talk about the eclipse and blockchain.

Aug 30, 201746 min

Episode 59 - The VPN Episode

Josh and Kurt talk about VPNs and the upcoming eclipse.

Aug 15, 201756 min

Ep 58Episode 58 - Backwards compatibility to the point of insanity

Josh and Kurt talk about MalwareTech, Debian killing off TLS 1.0 and 1.1, auto safety, HBO, and npm not typo squatting.

Aug 9, 201755 min

Ep 57Episode 57 - We may never see amazing security research ever again

Josh and Kurt talk about Black Hat and Defcon, safes, banks, voting machines, SMBv1 DoS attack, Flash, liability, and password masking.

Aug 1, 201753 min

Episode 56 - Devil's Advocate and other fuzzy topics

Josh and Kurt talk about forest fires, fuzzing, old time Internet, and Net Neutrality. Listen to Kurt play the Devil's Advocate and manage to change Josh's mind about net neutrality.

Jul 18, 201758 min

Episode 55 - Good Docs Ruin My Story

Josh and Kurt talk about Let's Encrypt, certificates, Kaspersky, A/V, code signing, Not Petya, self driving cars, and failures that become security problems.

Jul 12, 201750 min

Episode 54 - Turning Into An Old Person

Josh and Kurt talk about Canada Day, Not Petya, Interac goes down, Minecraft, airport security and books, then GDPR.

Jul 4, 201756 min

Episode 53 - A Plane Isn't Like A Car

Josh and Kurt talk about security through obscurity, airplanes, the FAA, the Windows source code leak, and chicken sandwiches.

Jun 28, 201748 min

Episode 52 - You Could Have Done It Right, But You Didn't

Josh and Kurt talk about the new StackClash flaw, Grenfell Tower, risk management, and backwards compatibility.

Jun 20, 201752 min

Episode 51 - All About CVE

Josh and Kurt talk to Dan Adinolfi about CVE. Most anything you ever wanted to know about CVE is discussed.

Jun 12, 201754 min

Episode 50 - This Is A Security Podcast After All

Josh and Kurt discuss Futurama, tornadoes, sudo, encryption, hacking back, and something called an ombudsman. Also episode 50!

Jun 6, 201749 min