PLAY PODCASTS
Open Source Security

Open Source Security

549 episodes — Page 9 of 11

Ep 147Episode 147 - Scams and operations as part of the supply chain

Josh and Kurt talk about a new type of lockbox scams. We also discuss Slack being a target for nation state attacks. Do you consider your operations part of your supply chain?It's totally part of your supply chain.

May 27, 201930 min

Ep 146Episode 146 - What the @#$% happened to Microsoft?

Josh and Kurt talk about Microsoft. They're probably not the bad guys anymore, which is pretty wild. They're adding a Linux kernel to Window. Can we declare open source the unquestionable winner now?

May 20, 201932 min

Ep 145Episode 145 - What do security and fire have in common?

Josh and Kurt talk about fire. We discuss the history of fire prevention and how it mirrors many of things we see in security. There are lessons there for us, we just hope it doesn't take 2000 years like it did for proper fire prevention to catch on.

May 13, 201934 min

Ep 144Episode 144 - The security of money, which one is best?

Josh and Kurt talk about the security of money. Not how to keep it secure, but the security issues around using cash, credit, and bitcoin. We also talk about Banksy's clever method for proving something is original.

May 6, 201933 min

Ep 143Episode 143 - Security lessons from the phone book

Josh and Kurt talk about the phone book (yeah, the big paper book people used to use). Kurt got one in the mail. While it's certainly a relic from another time, there were security tips in it among other wild things.

Apr 29, 201934 min

Ep 142Episode 142 - Hypothetical security: what if you find a USB flash drive?

Josh and Kurt talk about what one could do if you find a USB drive. The context is based on the story where the Secret Service was rumored to have plugged a malicious USB drive into a computer. The purpose of discussion is to explore how to handle a situation like this in the real world. We end the episode with a fantastic comparison of swim safety and security.

Apr 21, 201931 min

Ep 141Episode 141 - Timezones are hard, security is harder

Josh and Kurt talk about the difficulty of security. We look at the difficulty of the EU not observing daylight savings time, which is probably magnitudes easier than getting security right. We also hit on a discussion on Reddit about U2F that shows the difficulty. Security today is too hard, even for the experts.

Apr 15, 201936 min

Ep 140Episode 140 - Good enough security is a pretty high bar

Josh and Kurt talk about identity. It's a nice example we can generally understand in the context of how much security is enough security? When we deal with identity the idea of good enough is often acceptable for the vast majority of uses. Perfect identity tracking isn't really a thing nor is it practical.

Apr 8, 201934 min

Ep 139Episode 139 - Secure voting, firefox send, and toxic comments on the internet

Josh and Kurt talk about Brexit, voting, Firefox send, and toxic comments. Is there anything we can do to slow the current trend of conversation on the Internet always seeming to spiral out of control? The answer is maybe with a lot of asterisks.

Apr 1, 201930 min

Ep 138Episode 138 - Information wants to be free

Josh and Kurt talk about a prank gone wrong, the reality of when your data ends up public. Once it's public you can't ever put it back. We also discuss Notepad++ no longer signing releases and what signing releases means for the world in general.

Mar 25, 201932 min

Episode 137.5 - Holy cow Beto was in the cDc, this is awesome!

Josh and Kurt talk about Beto being in the Cult of the Dead Cow (cDc). This is a pretty big deal in a very good way. We hit on some history, why it's a great thing, what we can probably expect from opponents. There's even some advice at the end how we can all help. We need more politicians with backgrounds like this.

Mar 18, 201935 min

Ep 137Episode 137 - When the IoT attacks!

Josh and Kurt talk about when devices attack! It's not quite that exciting, but there have been a slew of news about physical devices causing problems for humans. We end on the note that we're getting closer to a point when lawyers and regulators will start to pay attention. We're not there yet, so we still have a horrible insecure future on the horizon.

Mar 11, 201930 min

Ep 136Episode 136 - How people feel is more important than being right

Josh and Kurt talk about github blocking the Deepfakes repository. There's a far bigger discussion about how people feel, and sometimes security fails to understand that making people feel happy or safer is more important than being right.

Mar 4, 201931 min

Ep 135Episode 135 - Passwords, AI, and cloud strategy

Josh and Kurt talk about change your password day (what a terrible day). Google's password checkup (not a terrible idea), an AI finding new spice flavors we expect will one day take over the world, and we finish up on a new DoD cloud strategy. Also Josh burnt his finger, but is going to be OK.

Feb 25, 201930 min

Ep 134Episode 134 - What's up with the container runc security flaw?

Josh and Kurt talk about the new runc container security flaw. How does the flaw work, what can you do about it, what should you do about it, and what the future of container security may look like.

Feb 18, 201928 min

Ep 133Episode 133 - Smart locks and the government hacking devices

Josh and Kurt talk about the fiasco hacks4pancakes described on Twitter and what the future of smart locks will look like. We then discuss what it means if the Japanese government starts hacking consumer IoT gear, is it ethical? Will it make anything better?

Feb 11, 201931 min

Ep 132Episode 132 - Bird Scooter: 0, Cory Doctorow: 1

Josh and Kurt talk about the Bird Scooter vs Corey Doctorow incident. We then get into some of the social norms around new technology and what lessons the security industry can take from something new like shared scooters.

Feb 4, 201930 min

Ep 131Episode 131 - Windows micropatches, Google's privacy fine, and Mastercard fixes trial abuse

Josh and Kurt talk about non-Microsoft Windows micropatches. The days of pretending closed source matters are long gone. Google gets hit with a privacy fine, that probably won't matter. And Mastercard makes it easier for consumers to not accidentally sign up for services they don't want.

Jan 28, 201933 min

Ep 130Episode 130 - Chat with Snyk co-founder Danny Grander

Josh and Kurt talk to Danny Grander one of the co-founders of Snyk about Zip Slip, what it is, how to fix it, and how they disclosed everything. We also touch on plenty of other open source security topics as Danny is involved in many aspects of open source security.

Jan 21, 201934 min

Ep 129Episode 129 - The EU bug bounty program

Josh and Kurt talk about the EU bug bounty program. There have been a fair number of people complaining it's solving the wrong problem, but it's the only way the EU has to spend money on open source today. If that doesn't change this program will fail.

Jan 14, 201933 min

Ep 128Episode 128 - Australia's encryption backdoor bill

Josh and Kurt talk about Australia's recently passed encryption bill. What is the law that was passed, what does it mean, and what are the possible outcomes? The show notes contain a flow chart of possible outcomes.

Jan 7, 201932 min

2018 Christmas Special - Is Santa GDPR compliant?

Josh and Kurt talk about which articles of the GDPR apply to Santa, and if he's following the rules the way he should be (spoiler, he's probably not). Should Santa be on his own naughty list? We also create a new holiday character - George the DPO Elf!

Dec 24, 201837 min

Ep 127Episode 127 - Walled gardens, appstores, and more

Josh and Kurt talk about Mozilla pulling a paywall bypassing extension. We then turn our attention to talking about walled gardens. Are they good, are they bad? Something in the middle? There is a lot of prior art to draw on here, everything from Windows, Android, iOS, even Linux distributions.

Dec 17, 201835 min

Ep 127Episode 126 - The not so dire future of supply chain security

Josh and Kurt continue the discussion from episode 125. We look at the possible future of software supply chains. It's far less dire than previously expected. It's likely there will be some change in the

Dec 10, 201833 min

Ep 125Episode 125 - Open Source, supply chains, npm, and you

Josh and Kurt talk about how open source deals with malicious events. It's probably impossible to stop these from happening, but the open source universe deals with it in its own unique way. We start to discuss what you can do, since everyone is using open source everywhere now. There will be a second part to this episode where we discuss what the future holds for these sort of problems.

Dec 3, 201831 min

Ep 124Episode 124 - Cloudflare's service workers and the economics of security

Josh and Kurt talk about Cloudflare's new Workers service. We spend a lot of time discussing how economics drives technology, not security. It's quite likely this new service is less secure than existing alternatives, but it will be cheaper and faster which will matter more than security.

Nov 26, 201834 min

Ep 123Episode 123 - Talking about Kubernetes and container security with Liz Rice

Josh and Kurt talk to Liz Rice about Kubernetes and container security. How did we get where we are today, what's new and exciting today, and where do we think things are going.

Nov 19, 201827 min

Ep 122Episode 122 - What will Apple's T2 chip mean for the rest of us?

Josh and Kurt talk about Apple's new T2 security chip. It's not open source but we expect it to change the security landscape in the coming years.

Nov 12, 201833 min

Ep 121Episode 121 - All about the security of voting

Josh and Kurt talk about voting security. What does it mean, how does it work. What works, what doesn't work, and most importantly why we may not see secure electronic voting anytime soon.

Nov 5, 201836 min

Ep 120Episode 120 - Bloomberg and hardware backdoors - it's already happening

Josh and Kurt talk about Bloomberg's story about backdoors and motherboards. The story is probably false, but this is almost certainly happening already with hardware. What does it mean if your hardware is already backdoored by one or more countries?

Oct 29, 201830 min

Ep 119Episode 119 - The Google+ and Facebook incidents, it's not your data anymore

Josh and Kurt talk about the Google+ and Facebook data incidents. We don't have any control over this data anymore. The incidents didn't really affect the users because we have no idea who has access to it. We also touch on GDPR and what it could mean in this context.

Oct 22, 201831 min

Ep 118Episode 118 - Cloudflare's IPFS and onion service

Josh and Kurt talk about Cloudflare's new IPFS and Onion services. One brings distributed blockchain files to the masses, the other lets you host your site on tor easily.

Oct 15, 201830 min

Ep 117Episode 117 - Will security follow Linus' lead on being nice?

Josh and Kurt talk about Linus' effort to work on his attitude. What will this mean for security and IT in general?

Oct 8, 201831 min

Ep 116Episode 116 - The future of the CISO with Michael Piacente

Josh and Kurt talk to Michael Piacente from Hitch Partners about the past, present, and future role of the CISO in the industry.

Oct 1, 201830 min

Ep 115Episode 115 - Discussion with Brian Hajost from SteelCloud

Josh and Kurt talk to Brian Hajost from SteelCloud about public sector compliance. The world of public sector compliance can be confusing and strange, but it's not that bad when it's explained by someone with experience.

Sep 24, 201830 min

Ep 114Episode 114 - Review of "Click Here to Kill Everybody"

Josh and Kurt review Bruce Schneier's new book Click Here to Kill Everybody. It's a book everyone could benefit from reading. It does a nice job explaining many existing security problems in a simple manner.

Sep 17, 201830 min

Ep 113Episode 113 - Actual real security advice

Josh and Kurt talk about actual real world advice. Based on a story about trying to secure political campaigns, if we had to give some security help what should it look like, who should we give it to?

Sep 10, 201830 min

Ep 112Episode 112 - Google's Titan Key and the latest Struts issue

Josh and Kurt talk about the new Google Titan security key. There are some in the industry uneasy about the supply chain for the devices. We also discuss the latest Struts security issue. Struts is old and scary now, stop using it.

Sep 3, 201829 min

Ep 111Episode 111 - The TLS 1.3 and DNS episode

Josh and Kurt talk about TLS 1.3 and DNS. What can we expect from the future for these, how are they related (or not related). We touch on DNSSEC and why it probably won't matter. DNS over TLS is looking pretty great though. There is also a guest appearance from quantum crypto.

Aug 27, 201832 min

Episode 110 - Review of Black Hat, Defcon, and the effect of security policies

Josh and Kurt talk about Black Hat and Defcon and how unexciting they have become. What happened with hotels at Defcon, and more importantly how many security policies have 2nd and 3rd level effects we often can't foresee. We end with important information about pizzza, bananas, and can openers.

Aug 19, 201834 min

Ep 109Episode 109 - OSCon and actionable advice

Josh and Kurt talk about phishing training and how it doesn't really matter. Josh spoke at OSCon and comes back with some fun observations and advice. People want practical actionable advice and we're not good at that.

Aug 13, 201834 min

Ep 108Episode 108 - Bluetooth, phishing, airgaps, and eating soup off the floor

Josh and Kurt talk about the latest attack on bluetooth and discuss phishing in the modern world. U2F is a great way to stop phishing, training is not. We also discuss airgaps in response to attacks on airgapped power utilities.

Aug 6, 201830 min

Ep 107Episode 107 - The year of the Linux Desktop and other hardware stories

Josh and Kurt talk about modern hardware, how security relates to devices and actions. Everything from secure devices, to the cables we use, to thermal cameras and coat hangers. We end the conversation discussing the words we use and how they affect the way people see us and themselves.

Jul 30, 201829 min

Ep 106Episode 106 - Data isn't oil, it's nuclear waste

Josh and Kurt talk about Cory Doctorow's piece on Facebook data privacy. It's common to call data the new oil but it's more like nuclear waste. How we fix the data problem in the future is going to require solutions we can't yet imagine as well as new ways of thinking about the problems.

Jul 23, 201829 min

Ep 105Episode 105 - More backdoors in open source

Josh and Kurt talk about some recent backdoor problems in open source packages. We touch on is open source secure, how that security works, and what it should look like in the future. This problem is never going to go away or get better, and that's probably OK.

Jul 16, 201831 min

Ep 104Episode 104 - The Gentoo security incident

Josh and Kurt talk about the Gentoo security incident. Gentoo did a really good job being open and dealing with the incident quickly. The basic takeaway from all this is make sure your organization is forcing users to use 2 factor authentication. The long term solution is going to be all identity providers forcing everyone to use 2FA.

Jul 9, 201833 min

Ep 103Episode 103 - The Seven Properties of Highly Secure Devices

Josh and Kurt talk about a Microsoft Research paper titled "The Seven Properties of Highly Secure Devices". We take a real world view into how to secure our devices. What works, what doesn't work, and why this list is actually really good.

Jul 2, 201833 min

Ep 102Episode 102 - Michael Feiertag from tCell

Josh and Kurt talk to Michael Feiertag, the CEO of tCell. We talk about what a Web Application Firewall is, what it does and doesn't do, and what the future of this technology looks like. We touch on how this affects a DevOps environment. Security has to fit into the existing model, not try to change it.

Jun 25, 201830 min

Ep 101Episode 101 - Our unregulated future is here to stay

Josh and Kurt talk about Bird scooters. The implications of the scooters on the city, segways, bicycles. The topic of how these vehicles interact with pedestrians on the road and trails. It's an example of humans not wanting to follow the rules and generally making the situation annoying for everyone. It's the old security story of new technology without clear rules. The show ends with some horrifying numbers behind how bad things can get before people really care.

Jun 17, 201832 min

Ep 100Episode 100 - You're bad at buying security, we can help!

Josh and Kurt talk about how to be a smart security buyer. We have guest Steve Mayzak walk us through how a the buying process works as well as giving out a ton of great advice. Even if you're experienced with how to buy security technology you should give this a listen.

Jun 11, 201835 min