Open Source Security Podcast: Recent Episodes

Josh Bressers & Kurt Seifried

A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.

View Details

Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-e18e-james

View Details

Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation

View Details

Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It's not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman

View Details

Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet

View Details

Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that are overwhelming open source projects. Mo does a really good job of explaining why this is fundamentally a people problem, not a technology problem. But it's a people problem we can probably use technology to help. It will be interesting to see where Lightwell goes in the next few years.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-lightwell-mo-duffy

View Details

Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust Foundation has some great ideas.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko

View Details

Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-allan-omnibom

View Details

Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager for PHP. Recently the people behind these projects have added a number of security features that will improve the security of the entire ecosystem. Jordi explains it all to us and gives a glimpse of what's coming next.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-packagist-security-jordi

View Details

Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for large company users to help fund the registry. We discuss how we got here, what's actually going on, and why this commercial approach is working. Everyone knew this day would come, and it looks like the Eclipse Foundation got this one right.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-openvsx-mike-thabang/

View Details

Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke to François a year ago, the world was a very different place than it is today. François has a ton of knowledge about how we got here and what we can do moving forward. Boost Security has a bunch of amazing open source tools François built that can help keep CI/CD systems understood and locked down.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-françois-smoked-meat/

View Details

Josh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs and incidents. There are some new features we will need in both our hardware and software to ward off the state of things. Since those features are years away, what we need in the short term is shoring up our SDLC programs. Sal has some really good medical examples and analogies for this one. It's a huge problem but not insurmountable.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-verification-sal-kimmich/

View Details

Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight into how a security vulnerability should be handled, and why the explosion of AI is making all this much harder than it's ever been before. While finding vulnerabilities is easy, reporting them is still a lot of work. Casey is working on helping everyone better understand all this with his disclose.io project.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-vulnerability-disclosure-casey-ellis/

View Details

Josh talks to Hans-Christoph Steiner about F-Droid, the Free and Open Source Android App Repository. The way F-Droid works looks a lot like a Linux distribution which has some interesting security challenges, but also some great security benefits. Hans walks us through the current state of open app repositories and also what the future currently looks like. There are more open phones than ever before, but there are also more challenges than ever before. Hans breaks it all down in an easy to understand way.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-fdroid-hans-steiner/

View Details

Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open source communities can work well, or not work at all. Kat's time on the Kubernetes Release Team. We touch on how a project like Kubernetes is super successful, while another, Ingress NGINX, was not. It's a super insightful discussion with a ton of lessons and advice for everyone.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-open-source-infrastructure-kat/

View Details

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas in this one about how to test the process not the people. How to construct the plan, and even some tips to go from a plan to some actual real world testing. It's another episode filled with great and practical advice.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-testing-the-plan-david-bernstein/

View Details

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source maintainers. This ties into Vlad's FOSDEM talk which was all about the challenge of just knowing what open source you are using. The importance of trying to make open source sustainable is a really important topic, but it's also a really hard topic. Vlad helps explain all of this as well as some ideas for the solving this in the future.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-open-source-pledge-vlad/

View Details

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are some great resources for this planning, but as David tells us, it's really not that hard to put some plans together. It's easy to over-plan, David gives some great tips on getting started with our planning for an eventual incident.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/

View Details

Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We of course touch on AI and the malware in skills problems and challenges. It's a fun discussion with a lot of new and interesting problems we all have to deal with.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/

View Details

Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who look at multiple ecosystems in the way Andrew does. He has thoughts on why it's so hard to create a new ecosystem as well as some of the reasons we don't see a C language ecosystem. Andrew has a ton of interesting ideas and insight for us about both existing, new, and nonexistent ecosystems.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-ecosystems-andrew/

View Details

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we could fund some really big, really hard projects? It's not cheap or easy, but he's getting it done. We spend a lot of the time discussing package registries, which are a huge topic. Michael is doing some amazing work helping package registries which is the first step in a very long journey.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-michael-winser/

View Details

Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/

View Details

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We explain what MCP and agents are doing as well as why it's so hard to secure them. It's not impossible, but it's not simple either. We end the show by discussing some of the more human aspects to security and how history may be repeating itself with security folks laughing at new users who don't know any better.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-mcp-agent-luke/

View Details

Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statement and their relationship with OpenSSL. We chat about some of the current features in cryptography, as well as some of what's coming in the future. It's a fun conversation that hits on a lot of great points.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/

View Details

Josh talks to Sylvestre Ledru about the Rust coreutils project. We've been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason isn't security, it's to modernize the code and attract new contributors. Sylvestre discusses with quite pleasant relationship with the GNU coreutils developers, some of the challenges in the project. What Ubuntu using this by default meant, and also gives us some things to watch for in the future. It's a super fun discussion about why Rust is not only awesome, but also the future.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-rust-coreutils-sylvestre-ledru/

View Details

Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things are today and where we might see them head. Donating Goose to the AAIF is great news as well as seeing MCP and AGENTS.MD in the foundation. We discuss how to deal with the problem of raising up junior developers, challenges of AI PRs, and some thoughts on how to get started if you're interested in AI development.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-02-goose-aaif-brad-axen/

View Details

Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It's no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few people with a long term vision instead of trying to just fix the short term problems. His GVIP ideas are very good, but it's a community effort and needs our help. Give it a listen and if it sounds interesting, come help us out!

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-02-GVIP-olle-johansson/

View Details

Josh talk to the founder and CEO of Nextcloud, Frank Karlitschek about digital sovereignty. There's a lot of attention lately around digital sovereignty and often that conversation also includes Nextcloud. Frank tells us all about how Nextcloud works, how it can be used to free your data, and has some great insight into what decentralization already looks like and what it could look like soon.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-02-nextcloud-frank-karlitschek/

View Details

Josh talks to David Bernstein about the world of crisis management and business continuity. David is a certified emergency manager and tell us about preparing for both digital and physical disruptions. Everything is IT now, so the way we think about disaster preparedness is changing. We talk about understanding risks, creating plans, and the role of practice in the world of crisis management. This is a super interesting universe and Dave was very patient and kind. I learned a lot and can't wait for Dave to come back.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-02-crisis-management-david-bernstein/

View Details

William Brown is back! This time Josh chats with him about Passkeys. WTF are they? A Passkey is a form of multi factor authentication, but it's not super obvious what that really means. William does a fantastic job explaining what a Passkey is, how we got to where we are today with Passkeys. He shares a ton of explanations about the whole world of authentication along the way. Some of this stuff is basically magic.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-01-passkey-william-brown/

View Details

Josh discusses Suricata with Victor Julien, the founder and lead developer of the project. Victor explains the history of the project, its impact on cybersecurity, and the community that keeps it all running. Challenges like encrypted traffic and the evolution of open-source projects. Victor even gives us a glimpse into what he sees as the future of the project. There's a lot to learn about Suricata in this one.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-01-suricata-victor-julien/

View Details

Josh talks to Gergely Nagy (algernon) about his tool Iocaine. Iocaine creates a maze to trap scraping bots in a world a fake pages they cannot escape. algernon tells us how Iocaine effectively traps bots by serving them endless loops of nonsensical URLs and web pages. It's an extremely clever tool that's designed to be completely hidden from normal users, but not hidden to the scrapers.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-01-iocaine-algernon/

View Details

Josh chats with Xe Iaso, the creator of Anubis the web AI firewall. We discuss how Anubis is tackling bots and scrapers. The discussion around the scrapers is fascinating and challenging, these things are everywhere and don't behave very nicely. There's also discussion about running a successful open source project. Xe has a lot of experience to share with us, you're going to learn something new with this one.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-01-anubis-xe/

View Details

Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many challenges in writing a TLS library (Rust or not). We also chat about some of what's to come. Rustls has an OpenSSL compatibility layer which makes is a really interesting project.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-12-rustls-dirkjan-joe/

View Details

Josh welcomes back Daniel Thompson explore the rather silly question of whether Santa Claus needs to be compliant with the Cyber Resilience Act (CRA). This episode was intended to be silly, but it ended up being an incredibly interesting conversation. Daniel explained a great deal about how the CRA works and how it could apply to Santa Claus. The TL;DR is even if he's giving out free stuff, the CRA almost certainly applies. Daniel also fills us in on his book (you can email Josh to enter into a drawing for a copy), and his work on web browsers for the CRA. It's an incredibly informative discussion.

The show notes and blog post for this episode can be found at

https://opensourcesecurity.io/2025/2025-12-daniel-cra-santa/

View Details

Josh has a chat with Gabriele Columbro, Executive Director of the Fintech Open Source Foundation and General Manager of Linux Foundation Europe. We of course discuss the Cyber Resilience Act (CRA), the evolving landscape of open source regulation, and the collaborative efforts of major foundations. Open source is everywhere, but there's also a ton of work to do now. Gabriele has really good insight into where things are today and where they are heading in the future for open source and regulation.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-12-lfeu-gab/

View Details

Josh discusses updating open source dependencies with Jamie Tanna. Jamie works on Renovate which gives them a lot of insight into the challenges of keeping your open source updated. We discuss the challenges of semantic versioning, supply chain security, and AI-generated code. If you're new or old to the world of open source dependencies, there's something to learn from this chat.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-12-renovate-jamie

View Details

Josh discusses the TARmageddon vulnerability with Alex Zenla, CTO of Edera. In this episode, we explore the discovery of the TARmageddon vulnerability. It's especially interesting because it's Rust, but also involves multiple end of life crates. Alex shares the story of how Edera managed to figure all this out (it was not simple). Hard problems are still hard, but there's a lot of lessons in this one.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-12-tarmageddon-alex/

View Details

In this episode Seth Larson gives us a cornucopia of topics relating to Python security. Seth discusses the Python Software Foundation's decision to reject a significant grant NSF. Diversity is a big deal to python, so this was a no brainier. We discuss the upcoming PyCon US conference, featuring a new security track that fosters collaboration between developers and security experts. Josh is a huge fan of having a security track at developer conferences. And we close on a paper about zip and tar archives Seth wrote. It seems like we should have zip and tar security figured out by now, but we don't. Thankfully Seth is working on it.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-11-python-security-seth-larson/

View Details

Josh talks to Richard Hughes about the world of firmware. We cover how Richard's journey from developing the ColorHug led to the creation of the Linux Vendor Firmware Service (LVFS), changing how firmware updates are managed for nearly every Linux user. Updating firmware has always been dicey, and on Linux it used to be impossible. Richard helps us understand how this all works and how we can all help out.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-11-lvfs-richard-hughes/

View Details

Josh chats with Charlie Eriksen, a security researcher at Aikido Security. We discuss the recent NPM supply chain attacks that affect hundreds of packages. Charlie shares his experiences dealing with recent security breaches, the challenges of maintaining trust in open source software, and the importance of proactive measures to safeguard open source. The rapid pace of change is impacting our security practices and what steps can be taken to foster resilience in the face of evolving threats.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-11-npm-charlie/

View Details

In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto's blog post about the XZ backdoor and how it's a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-11-xz-debian-otto/

View Details

In this conversation, Josh speaks with Mikael Barbero, head of security at the Eclipse Foundation. They discuss the foundation's role in enhancing the security posture of open source projects, the importance of Software Bill of Materials (SBOMs), and the various security services provided to projects. Mikael explains the challenges and strategies involved in implementing security best practices across a diverse range of projects, as well as the foundation's proactive approach to navigating security regulations and compliance. This is some great security work happening for open source projects.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-10-eclipse-sbom-mikael-barbero/

View Details

I chat with Joshua Rogers about a blog post he wrote as well as some bugs he submitted to the curl project. Joshua explains how he went searching for some AI tools to help find security bugs, and found out they can work, if you're a competent human. We discuss the challenges of finding effective tools, the importance of human oversight in triaging vulnerabilities, and how to submit those bugs to open source projects responsibly. It's a very sane and realistic conversation about what AI tools can and can't do, and how humans should be interacting with these things.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-10-ai-joshua-rogers/

View Details

Brian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the importance of sustainable practices in the open source community. Brian tells us how organizations can reduce their footprint and contribute to a more balanced ecosystem. The package repositories cannot continue to be the world's CDN.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-10-sustaining-repos-brian-fox/

View Details

Join us for a conversation with Foxboron (Morten Linderud) and Anthraxx (Levente Polyak), members of the Arch Linux security team. We talk about the difficulties of maintaining a Linux distribution, the challenges of handling CVEs, and the dedication of volunteers who keep the open-source community working (and how overworked those volunteers are). We explain what makes Arch a little different, how they approach their security process, and what sort of help they would love to see in the future.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-09-arch-foxboron-anthraxx/

View Details

I discuss all things OpenSSL with Hana Andersen and Anton Arapov from the OpenSSL Corporation. Discover the intricacies of organizing the first-ever OpenSSL conference in Prague, the importance of post-quantum cryptography, and the evolution of OpenSSL from a small team to a global community. Whether you're a seasoned cryptographer or just curious about the future of secure communications, this episode offers insights and stories. Don't miss out on learning how OpenSSL is still shaping the future of cryptography.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-09-openssl-hana-anton/

View Details

In this episode I discuss the Python Software Foundation with Deb Nicholson. We discuss their contributions to the Python programming community. Learn how this dedicated organization supports the growth and innovation of Python, fostering an ecosystem for developers worldwide. Everything funding open-source projects to organizing community events, discover the initiatives that make the Python Software Foundation a force for positive change in the tech world.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-09-psf-deb-nicholson/

View Details

In this episode, we the information system mapping tool Mercator with Didier Barzin, a CISO at a hospital in Luxembourg. Discover how Mercator revolutionizes the way organizations map their complex information systems. From hospitals to universities and even the banking sector. Mercator helps manage and protect vast networks by creating dynamic, comprehensive maps that replace outdated Excel sheets. Join us as we explore the challenges and innovations in information security and the impact of Mercator on various industries.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-09-mercator-didier-barzin/

View Details

In this episode, I discuss into the security features of Talos Linux with Andrey Smirnov. Andrey explains how Talos focuses on its immutability and minimal attack surface. Discover how these enhancements fortify your systems against vulnerabilities, ensuring a secure and resilient infrastructure. Join us as we explore the security advancements that make Talos Linux not only a super easy way to run Kubernetes, but also a very secure way.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-09-talos-andrey-smirnov/

View Details

In this episode I chat with the authors of a recent paper on open source security: Open Source, Open Threats? Investigating Security Challenges in Open-Source Software. I chat with Ali Akhavani and Behzad Ousat about their findings. There are interesting data points in the paper such as a 98% increase in reported vulnerabilities compared to a 25% growth in open source ecosystems. We discuss the challenges of maintaining security in a rapidly expanding digital landscape, and learn about the role of community engagement and automated tools in addressing these discrepancies. It's a great paper and a fantastic discussion.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-08-oss-threats-ali-behzad/

View Details

In this episode we discuss crates.io trusted publishing with Tobias Bieniek. We cover the steps crates.io is taking to enhance supply chain security through trusted publishing, a method that leverages short-lived tokens and GitHub actions to safeguard against unauthorized access. Tobias shares insights into the challenges of managing a large-scale open-source repository, offering a glimpse into the future of secure software distribution. Tune in to learn how these advancements are shaping the landscape of open-source development.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-08-cratesio-trusted-publishing-tobias/

View Details

In this episode I chat with Patrick Garrity from VulnCheck. We discuss the chaos that has enveloped the CVE and NVD programs over the past two years. We cover some of the transparency and communication challenges with the existing program. What some of the new things that have started to emerge as well as why they seem to be struggling. We end on the note that the last 3 months haven't been confidence inspiring. It's likely in 6 months everyone will be scrambling to deal with a difficult situation.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-08-cve-patrick-garrity/

View Details

In this episode I discuss GCVE and Vulnerability-Lookup with Alex and Cedric from CIRCL. GCVE offers a decentralized approach, allowing organizations to assign their own IDs and publish vulnerabilities independently. Vulnerability-Lookup is the tool that makes GCVE a reality. The flexibility addresses many of the limitations we see today with a single centralized ID system. The work happening by CIRCL on GCVE is very impressive, with all the current CVE turmoil, this is a project we should all be paying attention to.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025/2025-08-gcve-cedric-alex/

View Details

In this episode, we dive into the Product Liability Directive and Cyber Resilience Act with Daniel Thompson, CEO of Crab Nebula. The EU's new legislative framework impacts manufacturers in ways we don't totally understand, but are going to bring substantial changes to how companies use and develop open source. Daniel explains the broader implications for software security and the future of digital products in the European market.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-07-eu-regulations-daniel-thompson/

View Details

In this episode Jan Pleskac, CEO and co-founder of Tropic Square, shares insights on the challenges and innovations in creating open and auditable hardware. While most hardware is very closed, Tropic Square is working to change this. WE discuss how open source can enhance security, the complexities of integrating third-party technologies, and the future of secure computing devices.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-07-open-source-microprocessors/

View Details

I'm joined by Philippe Ombredanne, creator of the Package URL (PURL), to discuss the surprisingly complex and messy problem of simply identifying open source software packages. We dive into how PURLs provide a universal, common-sense standard that is becoming essential for the future of SBOMs and securing the software supply chain.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-06-purl-philippe-ombredanne/

View Details

Thomas DePierre joins Open Source Security to discuss the central idea from his blog post, "You are all on the hobbyist maintainers turf now," exploring the massive disconnect between the corporate world that consumes open source and the hobbyist community that actually produces it. The conversation reveals this isn't a new problem, but a long-standing reality whose consequences for security, stability, and the future of software we are only now beginning to truly confront.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-06-hobbyist-thomas-depierre/

View Details

I chat with Aaron Lippold, creator of MITRE's Security Automation Framework (SAF), to discuss how to escape the pain of manual STIG compliance. We explore the technical details of open-source tools like InSpec, Heimdall, and Vulcan that automate validation, normalize diverse security data, and streamline the entire security authoring process.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-06-stig-automation-aaron-lippold/

View Details

I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is able to incredible insights into the world of open source. We chat all about how Ecosyste.ms works and how he manages to wrangle all this data.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-06-ecosystems_andrew_nesbitt/

View Details

Daniel Stenberg, the maintainer of Curl, discusses the increase in AI security reports that are wasting the time of maintainers. We discuss Curl's new policy of banning the bad actors while establishing some pretty sane AI usage guidelines. We chat about how this low-effort, high-impact abuse pattern is a denial-of-service attack on the curl project (and other open source projects too).

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-curl_vs_ai_with_daniel_stenberg/

View Details

I recently had a chat with Kairo about a project he maintains called Repository Service for TUF (RSTUF). We explain why TUF is tough (har har har), what RSTUF can do, and some of the challenges around securing repositories.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-rstuf-with-kairo-de-araujo/

View Details

William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent security risks in GitHub Actions, such as injection vulnerabilities, permission issues, and mutable tags, by providing static analysis and remediation guidance. Fresh off the heels of the tj-actions/changed-files backdoor, this is a great topic with some things everyone can do right away.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-securing-github-actions-william-woodruff/

View Details

Recently, I had the pleasure of chatting with Paul Asadoorian, Principal Security Researcher at Eclypsium and the host of the legendary Paul's Security Weekly podcast. Our conversation dove into the often-murky waters of embedded systems and the Internet of Things (IoT), sparked by a specific vulnerability discussion on Paul's show concerning reference code for the popular ESP32 microcontroller.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-embedded-security-with-paul-asadoorian/

View Details

Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with production-level security rigor instead of ignoring them.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-tjactions_with_dimitri_stiliadis/

View Details

I chat with Alan Pope about the open source security tools Syft, Grype, and Grant. These tools help create Software Bills of Materials (SBOMs) and scan for vulnerabilities. Learn why generating and storing SBOMs is crucial for understanding your software supply chain and quickly responding to new threats like Log4Shell.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-syft-grype-grant-alan-pope/

View Details

Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/

View Details

Cargo Semver Checks is a Rust tool by Predrag Gruevski that is tackling the problem of broken dependencies that cost developers time when trying to upgrade dependencies. Predrag's work shows how automated checks can catch breaking changes before they're released, potentially saving projects from unexpected failures and making dependency updates less painful across the entire Rust ecosystem.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cargo-semver-checks-predrag-gruevski/

View Details

Lars Wirzenius discusses his innovative CI/CD system Ambient, which uses isolated virtual machines without network access to enhance security, and his work on Radicle, a peer-to-peer Git collaboration platform. Together, these projects offer a glimpse into a more distributed future for software development, addressing key challenges in current CI/CD systems like long wait times, security vulnerabilities, and centralized infrastructure limitations.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-03-ambient-radicle-lars-wirzenius/

View Details

William Brown tells us all about how confusing and complicated the FIDO authentication universe is. He talks about WebAuthn implementation challenges to flaws in the FIDO metadata service that affect how hardware tokens are authenticated against. The conversation covers the spectrum of hardware security key quality, attestation mechanisms, and the barriers preventing open source developers from improving industry standards despite their expertise.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-03-fido_auth_william_brown/

View Details

In this episode, open source legal expert Luis Villa breaks down what the EU's Cyber Resilience Act means for developers and businesses, exploring carve-outs for individual contributors and the complex relationship between security and sustainability. Luis provides practical guidance on navigating this evolving regulatory landscape while explaining why the CRA represents both a challenge and an opportunity for the open source ecosystem.

The blog post for this episode can be found at

https://opensourcesecurity.io/2025/2025-03-CRA_luis_villa/

View Details

Brian Fox discusses findings from a recent Sonatype report about the growing challenge of malicious packages in open source repositories. At the time of recording there are now over 820,000 malware packages in public repositories. Brian explains why certain ecosystems are more vulnerable than others and how behavioral detection methods can identify suspicious packages, and the challenge in solving this problem.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-03-oss_malware_brian_fox/

View Details

In this episode Open Source Security talks to Dr. Kelly Masada about the Open Information Security Foundation (OISF). The way OISF is managing Suricata through a foundation is super interesting. There are a lot of lessons in this one for both open source projects and existing open source foundations.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-03-oss_foundations_kelley_misata/

View Details

In this episode Open Source Security chats with Sheogorath about HedgeDoc project's journey from HackMD to CodiMD and finally to HedgeDoc. We learn what forking a project looks like, including license changes (MIT to AGPL), security vulnerability management across different codebases, naming challenges, and infrastructure migrations. The conversation goes through to journey from HackMD to CodiMD and all the lessons learned along the way. And there are many lessons.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-02-fork_open_source_sheogorath/

View Details

In this episode, Open Source Security chats with Aaron Frost, CEO of Hero Devs about the world of maintaining end-of-life open source software. Aaron explains how EOL versions of open source work and how backporting security fixes can help maintaining compliance. In the discussion we cover the "just upgrade" mentality, how backporting works, why it's hard, and why it matters. We also cover some oddities the world of CVE brings to the discussion.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-02-patching_EOL_OSS_aaron_frost/

View Details

François Proulx, a supply chain security researcher at Boost Security, discusses how continuous integration (CI) and build pipeline security represents a critical and overlooked hole in our supply chain security. It seems like most supply chain compromises are actually from CI system breaches rather than direct code compromise, yet we seem to obsess over everything on either side of the CI system. François has a bunch of really good practical suggestions for how we can start to improve our CI security today.

The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-02-ignoring_ci_security_francois_proulx/

View Details

In this discussion with Tremolo Security CTO Marc Boorshtein, we explore what modern day Single Sign-On (SSO) looks like. Everyone likes to talk about zero trust, but how does that work? We talk about some of the history of authentication that got us here, and some technical details on how you should be implementing authentication into your application. We finish up with some passkey details and realize every authentication discussion really just turns into complaining how hard identity is.

The blog post for this episode can be found at

https://opensourcesecurity.io/2025/2025-02-modern_day_authentication_with_marc_boorshtein/

View Details

Dick Brooks from Business Cyber Guardian discusses the landscape of federal software security requirements, we discuss frameworks like CISA's Software Acquisition Guide, Secure Software Development Framework, and the EU's Cyber Resilience Act. These regulations impact open source projects differently from commercial vendors, Dick helps explain what that means for the vendors as well as open source developers.

The accompaning blog can be found at

https://opensourcesecurity.io/2025/01-government_security_requirements_with_dick_brooks

CISA Software Acquisition Guide CISA SAG Reader Project NASA SSDF collaboration

View Details

In this episode, Gary Kramlich, the lead developer of Pidgin discusses the challenges and strategies of maintaining a 26-year-old open source messaging client.Gary tell us all about how a small team manages technical debt, handles library dependencies, and makes decisions about rewrites versus incremental improvements while supporting a broader open source ecosystem.

The accompaning blog can be found at

https://opensourcesecurity.io/2025/01-open_source_maintenance_with_gary_kramlich/

View Details

In this episode of Open Source Security, Josh welcomes Thomas Depierre, a Site Reliability Engineer and open source maintainer, to discuss the intersection of safety and security. Thomas explains why safety is broader than security. While security often views people as the problem, Thomas explains that people are paradoxically the solution. Nothing should work, but it does, mostly due to people keeping things working.

The accompaning blog can be found at

https://opensourcesecurity.io/2025/01-safety_vs_security_with_thomas_depierre/

View Details

It’s a new year and time for some changes to the opensourcesecurity.io website.

It's time to retire the podcast, but that's to make way for something new and hopefully better. You can read the details in the blog post (the audio version is basically the same thing)

https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/

View Details

Josh and Kurt talk about new NIST password guidance. There's some really good stuff in this new document. Ideas like usability and equity show up (which is amazing). There's more strict guidance against rotating passwords and complex passwords. This new guidance gives us a lot to look forward to.

Show Notes * Usagi Electric * NIST proposes barring some of the most nonsensical password rules * NIST SP 800-63(B) * STRIDE threat model * PASTA threat model

View Details

Josh and Kurt talk about the supply chain of Santa. Does he purchase all those things? Are they counterfeit goods? Are they acquired some other way? And once he has all the stuff, the logistics of getting it to the sleigh is mind boggling. It's all very complex

Show Notes * Project Gunman

View Details

Josh and Kurt talk about a CWE Top 25 list from MITRE. The list itself is fine, but we discuss why the list looks the way it does (it's because of WordPress). We also discuss why Josh hates lists like this (because they never create any actions). We finish up running through the whole list with a few comments about the findings.

Show Notes * 2024 CWE Top 25 Most Dangerous Software Weaknesses * Set of 9 Unusual Odd Sided dice - D3, D5, D7, D9, D11, D13, D15, D17 & D19

View Details

Josh and Kurt talk about the FBI telling everyone to use end to end encrypted messengers. This is a pretty drastic deviation from messages in the past. The reason for this is it appears the US telephone networks are pwnt beyond repair at this point, which is concerning. The only real solution now is to treat the phone network as untrusted and encrypt all the traffic.

Show Notes * Salt Typhoon * U.S. officials urge Americans to use encrypted apps amid unprecedented cyberattack * LTT Hacked phone * Security Cryptography Whatever Telegram * Secure Messaging Apps Comparison

View Details

Josh and Kurt talk about a serious D-Link security vulnerability in a bunch of end of life products. The crux of the discussion focuses on D-Link, but the reality is almost all consumer gear you plug into the internet is terrible. And there's little hope it will get better anytime soon.

Show Notes * China has utterly pwned 'thousands and thousands' of devices at US telcos * D-Link tells users to trash old VPN routers over bug too dangerous to identify * D-Link YouTube explainer video

View Details

Josh and Kurt embark on a thought experiment to discuss how a commercial entity would handle something like the xz incident. It was very specific and difficult to understand. It's easy to claim just because source code being available doesn't matter. But the reality is when source code is needed, it can make a huge difference for everyone working together, just like we saw with xz.

Show Notes * Lindt admits chocolate may not be ‘expertly crafted’ in class-action lawsuit battle * Mitchell & Webb - Needlessly ambiguous terms

View Details

Josh and Kurt talk about the way Wordpress vets their plugins. While Wordpress has been in the news lately, they do some clever things to get plugins approved. There's a static analyzer that runs against new submissions. We discuss using static analysis, securing open source, contributing and more.

Show Notes * Linus Torvalds Lands A 2.6% Performance Improvement With Minor Linux Kernel Patch * Kurt's Plugin

View Details

Josh and Kurt talk to Brian Fox from Sonatype and Donald Fischer from Tidelift about their recent reports as well as open source. There are really interesting connections between the two reports. The overall theme seems to be open source is huge, everywhere, and needs help. But all is no lost! There's some great ideas on what the future needs to look like.

Show Notes * Donald Fischer * Brian Fox * Tidelift * Sonatype * The 2024 Tidelift state of the open source maintainer report * Sonatype State of the Software Supply Chain * Anchore 2024 Software Supply Chain Security Report * OpenSSF TAC issue 101

View Details

Josh and Kurt talk about three government activities happening around security. CISA has a request for comment, and an international strategic plan around cybersecurity. These are both good ideas, and hopefully will help drive change. But we also discuss an EU proposal that brings liability rules to software which sounds like a great way to force change to happen.

Show Notes * Request for Comment on Product Security Bad Practices Guidance * FY2025-2026 CISA International Strategic Plan * EU brings product liability rules in line with digital age and circular economy * CSA Cloud Controls Matrix

View Details

Josh and Kurt talk about the Meshtastic open source project. It's a really slick mesh radio system that runs on very cheap radio equipment. This episode isn't very security related (there are a few things), but it is very open source.

Show Notes * Meshtastic * Heltec LoRa 32(V3) Radio * 465 Rutgers University Confirmed: Meshtastic and LoRa are dangerous * Meshtastic Routing Issues & Deployment Scenarios * TC2-BBS-mesh * The Comms Channel * Josh's BBS * Heltec T114 bug

View Details

Josh and Kurt talk to Seth Larson from the Python Software Foundation about security the Python ecosystem. Seth is an employee of the PSF and is doing some amazing work. Seth is showing what can be accomplished when we pay open source developers to do some of the tasks a volunteer might consider boring, but is super important work.

Show Notes * Seth Larson * XKCD PGP Signature * Seth's Blog * Python and Sigstore * Deprecating PGP - PEP 761 * Python SBOMs

View Details

Josh and Kurt talk about the current Wordpress / WP Engine mess. In what is certainly a supply chain attack, the Advanced Custom Fields forking. This whole saga is weird and filled with chaos and stupidity. We have no idea how it will end, but we do know that the blog platform you use shouldn't be this exciting. The bad sort of exciting.

Show Notes * WordPress.org’s latest move involves taking control of a WP Engine plugin * Wordpress / WP Engine timeline * Knorr German Recipes

View Details

Josh and Kurt talk about the recent CUPS issue. The vulnerability itself wasn't all that exciting, but the whole disclosure process was wild. There's a lot to talk about, many things didn't quite go as planned and it all leaked early. Let's talk about why and what it all means.

Show Notes * CUPS vulnerability * Akamai report * Wil Wheaton: being a nerd is not about what you love; it’s about how you love it

View Details

Josh and Kurt talk about a few things that have recently come out of CISA. They seem to be blaming the vendors for a lot of the problems, but there's also not any actionable advice telling the vendors what they should be doing. This feels like the classic case of "just security harder". We need CISA to be leading the way funding and defining security, not blaming vendors for giving the market what it demands.

Show Notes * iCloud Photos Downloader * CISA boss: Makers of insecure software must stop enabling today's cyber villains * A Security Market for Lemons * CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities * CISA Secure by Design Pledge * Railroad Newsletter * CISA Secure Software Development Attestation Form

View Details

Josh and Kurt talk about the 2024 Tidelift maintainer report. The report is pretty big and covers a ton of ground. We focus in a few of the statistics that should worry anyone who uses open source. We've known for a while developers are struggling, and the numbers back that up. This one feels like the old "we've tried nothing and we're all out of ideas".

Show Notes * THE 2024 TIDELIFT STATE OF THE OPEN SOURCE MAINTAINER REPORT * Canadian passport * Changelog Interviews #433 * Pandas CVE

View Details

Josh and Kurt talk about some security researchers sort of taking over the .MOBI whois server. The story is a bit sensational, but we ask if it really matters? There are a lot of interesting possible attacks, but turning something like this into a good attack is really hard, maybe impossible. The researchers presented the findings in a very reasonable way.

Show Notes * We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI * Heinz says sorry for ketchup QR code that links to porn site

View Details

Josh and Kurt talk to Jay Jacobs about Exploit Prediction Scoring System (EPSS). EPSS is a new way to view vulnerabilities. It's a metric for the likelyhood that a vulnerability will be exploited in the next 30 days. Jay explains how EPSS got to where it is today, how the scoring works, and how we can start to think about including it in our larger risk equations. It's a really fun discussion.

Show Notes * Jay Jacobs on LinkedIn * EPSS * Jay's graph animation * Cyentia's A Visual Exploration of Exploits in the Wild

View Details

Josh and Kurt talk about Chrome unexpectedly going EOL on Ubuntu 18. Keeping old things alive is really hard to do, and in open source it's becoming more common to just run the latest version rather than trying to keep old versions alive for long periods of time.

Show Notes * Chrome dumped support for Ubuntu 18.04 – but it'll be back * Linus Torvalds talks AI, Rust adoption, and why the Linux kernel is 'the only thing that matters' * Pidgin backdoor

View Details

Josh and Kurt talk about a story that discusses a story from Black Hat that references supply chains. There's a ton of doom and gloom around our software supply chains and much of the advice isn't realistic. If we want to take this seriously we need to stop obsessing over the little problems and focus on some big problems.

Show Notes * Black Hat USA 2024: Key Takeaways from the Premier Cybersecurity Event * The Reason Train Design Changed After 1948

View Details

Josh and Kurt talk about a few stories around the TLS CA certificate world. It's all pretty dire sounding. There's not a lot of organization or process in the space, and the root CAs are literally the foundation of modern society, everything needs them to function. There's not a lot of positive ideas here, it's mostly a show where Kurt explains to Josh what's going on, because Josh doesn't want to care (and will continue to ignore all of this going forward).

Show Notes * Firefox's Mozilla follows Google in losing trust in Entrust's TLS certificates * DigiCert Revocation Incident (CNAME-Based Domain Validation) * List of Trust Lists

View Details

Josh and Kurt talk about CWE. What is it, and why does it matter. We cover some history, some shortcomings, and some ideas on how CWE could be used to make security a lot better. We frame the future discussion around the OWASP top 10 list. We should be putting more effort into removing removing entire classes of vulnerabilities.

Show Notes * CWE * Episode 360 – Memory safety and the NSA * Inside 22,734 Steam games

View Details

Josh and Kurt talk about a presentation Josh recently gave that was supposed to be about how open source works. The talk was the wrong topic for a security crowd, but there's a lot of interesting details in the questions and comments that emerged. It's clear a lot of security people don't really care about the fine details about what open source is, their primary goal is to help keep development secure.

Show Notes * Grassr00tz * Pamela Chestek copyright paper * Josh's presentation

View Details

Josh and Kurt talk about a story talking about the "graying" of open source. There doesn't seem to be many young people working on open source, but we don't really know why that is. There are many thoughts, but a better question is why should anyone get involved in open source anymore? The world has changed quite a lot since open source was created.

Show Notes * The graying open source community needs fresh blood * OSPOs for Good 2024 + Day 1 Part 1 + Day 1 Part 2 + Day 2 Part 1 + Day 2 Part 2 * FFmpeg bug * JSON Editor Online * https://rfc3339.com/

View Details

Josh and Kurt talk about two documents from the US government that discuss open source in very different ways. The CISA document lays out a way to measure open source, but we take issue with the idea of trying to measure which open source projects are "good". The Whitehouse on the other hand takes an approach that is very open source, get involved. Trying to measure open source isn't producing anything actionable, but getting involved is very actionable, and very much how open source works.

Show Notes * CISA: Continued Progress Towards a Secure Open Source Ecosystem * Whitehouse: Administration Cybersecurity Priorities for the FY 2026 Budget

View Details

Josh and Kurt talk about a pretty big bug found in CocoPods ownership. We also touch on a paper that discusses the technical debt that open source should have. We discuss what the long term sustainability of open source. There aren't any good solutions for open source today, but talking about these problems is important, we have to start to understand what's going on before we can plausibly discuss solutions. If you're an open source project that needs to put things on pause, or even walk way, that's OK.

Show Notes * CocoaPods Vulnerabilities Could Hit Apple, Microsoft, Facebook, TikTok, Snap and More * The Expense of Unprotected Free Software * Long-term maintenance of PCRE2 #426

View Details

Josh and Kurt talk about the recent OpenSSH vulnerability and the node-ip project owner taking their project private. They're quasi related in the context of two open source projects handled bugs very differently. The OpenSSH bug isn't really as serious as it seems, but you still want to patch.

The node-ip bug is a very different story. The relationship between users and open source developers is one experiencing more strain now than we've ever seen. It's a weird conversation and we don't have good answers. Security in general is a collection of unsolvable problems.

Show Notes * Qualys security advisory * Hacker News Discussion * Security Cryptography Whatever * Dev rejects CVE severity, makes his GitHub repo read-only

View Details

Josh and Kurt talk about the latest polyfill.io mess. Apparently someone took over a very popular project and started to serve malware. First XZ, now this. What does it mean for open source? We don't have any answers, and it's hard to even talk about this problem because it's so big. The thing is though, even if we can't fix open source, it's here to stay.

Show Notes * Polyfill supply chain attack hits 100K+ sites * OpenSSF Scorecard

View Details

Josh and Kurt talk about three wangles of responsibility. We start with a story about a bike theft ring, bike theft doesn't usually get any attention, but this one is special. Then we ask why it seems like everyone is getting hacked, it's because they have to tell us now. And finally we have a story about the huge number of unreported vulnerabilities in open source projects. This statistic probably affects all software, but there's some numbers for open source specifically.

Show Notes * The West Coast’s Fanciest Stolen Bikes Are Getting Trafficked by One Mastermind in Jalisco, Mexico * $5 million worth of stolen tools recovered thanks to Apple's AirTag — 12 secret storage facilities had around 15,000 construction tools * Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities

View Details

Josh and Kurt talk about a new proposal from OpenSSH to add a timeout to penalize clients misbehaving. But this then brings up the typical security conversation of "if it's not perfect we shouldn't do it". Trying new things is a good thing, even if something fails, we learn a lesson that we can use in the future.

Show Notes * OpenSSH introduces options to penalize undesirable behavior * Hacker News comments

View Details

Josh and Kurt talk to Alex Kulagin from Flipper about the Flipper Zero. It's one of the coolest hacker devices that exists on the market. We talk about what it is, how it started, what it can (and can't) do. It's a really fun conversation.

Show Notes * Flipper Zero Website * Headphone jack radio capture * Flipper Zero on Tik Tok

View Details

Josh and Kurt talk about a blog post titled "Your API Shouldn't Redirect HTTP to HTTPS". It's an interesting idea, and probably a good one. There is however a lot of baggage in this space as you'll hear in the discussion. There's no a simple solution, but this is certainly something to discuss.

Show Notes * Your API Shouldn't Redirect HTTP to HTTPS * Hacker News discussion * HSTS Section 5.1

View Details

Josh and Kurt talk about a blog post about frozen kernels being more secure. We cover some of the history and how a frozen kernel works and discuss why they would be less secure. A frozen kernel is from when things worked very differently. What sort of changes will we see in the future?

Show Notes * Kurt's strange coffee * Why a 'frozen' distribution Linux kernel isn't the safest choice for security

View Details

Josh and Kurt talk about open source and autonomy. This is even related to some recent return to office news. The conversation weaves between a few threads, but fundamentally there's some questions about why do people do what they do, especially in the world of open source. This also is a problem we see in security, security people love to tell developers what to do. Developers don't like being told what to do.

Show Notes * pycurl issue * Apple, SpaceX, Microsoft return-to-office mandates drove senior talent away * RSA ANIMATE: Drive: The surprising truth about what motivates us * Sudo-rs dependencies: when less is better * phishing webcomic * Debian OpenSSL Bug (16 years)

View Details

Josh and Kurt talk about a new to sign artifacts on GitHub. It's in beta, it's not going to be easy to use, it will have bugs. But that's all OK. This is how we start. We need infrastructure like this to enable easier to use features in the future. Someday, everything will be signed by default.

Show Notes * GitHub artifact attestation

View Details

Josh and Kurt talk about a sudo replacement going into systemd called run0. It sounds like it'll get a lot right, but systemd is a pretty big attack surface and not everyone is a fan. We shall have to see if this ends up replacing sudo.

Show Notes * Conan O'Brien on Hot Ones * Lennart's Mastodon thread * xkcd automation

View Details

Josh and Kurt talk about a paper describing using a LLM to automatically create exploits for CVEs. The idea is probably already happening in many spaces such as pen testing and intelligence services. We can't keep up with the number of vulnerabilities we have, there's no way we can possibly keep up with a glut of LLM generated vulnerabilities. We really need to rethink how we handle vulnerabilities.

Show Notes * OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories * paper: LLM Agents can Autonomously Exploit One-day Vulnerabilities * Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent * Episode 219 – Chat with Larry Cashdollar * Cory Doctorow: What Kind of Bubble is AI?

View Details

Josh and Kurt talk about a database of game cheaters. Cheating in games has many similarities to security problems. Anti cheat rootkits are also terrible. The clever thing however is using statistics to identify cheaters. Statistics don't lie. Also, we discuss the Pretendo project sitting on a vulnerability for a year, is this ethical?

Show Notes * Hacker News searchable database * Benford's law * John Oliver Medicaid * Mario64 invisible walls * Pretendo * Pretendo exploit

View Details

Josh and Kurt talk about a Notepad++ fake website. It's possibly not illegal, but it's certainly ethically wrong. We also end up discussing why it seems like all these weird and wild things keep happening. It's probably due to the massive size of open source (and everything) now. Things have gotten gigantic and we didn't really notice.

Show Notes * Help us to take down the parasite website * Open Source is bigger than you can imagine * Toronto Pearson International Airport heist

View Details

Josh and Kurt talk about a new FCC program to provide a cybersecurity certification mark. Similar to other consumer safety marks such as UL or CE. We also tie this conversation into GrapheneOS, and what trying to claim a consumer device is secure really means. Some of our compute devices have an infinite number of possible states. It's a really weird and hard problem.

Show Notes * GrapheneOS * FCC approves cybersecurity label for consumer devices * Cyber Trust Mark Logo

View Details

Josh and Kurt talk about the recent events around XZ. It's only been a few days, and it's amazing what we already know. We explain a lot of the basics we currently know with the attitude much of these details will change quickly over the coming week. We can't fix this problem as it stands, we don't know where to start yet. But that's not a reason to lose hope. We can fix this if we want to, but it won't be flashy, it'll be hard work.

Show Notes * GossiTheDog's Blog Post * fr0gger diagram * OpenSSF Blog (archive) * stb library

View Details

Josh and Kurt talk about the security.txt file. It's not new, but it's not something we've discussed before. It's a great idea, an easy format, and well defined. It's not high on many of our todo lists, but it's something worth doing.

Show Notes * RFC 9116

View Details

Josh and Kurt talk about the new SSDF attestation form from CISA. The current form isn't very complicated, and the SSDF has a lot of room for interpretation. But this is the start of something big. It's going to take a long time to see big changes in supply chain security, but we're confident they will come.

Show Notes * Secure Software Development Attestation Form * The U.S. Military Is Missing Six Nuclear Weapons * NIST 800-218

View Details

Josh and Kurt talk about what's going on at the National Vulnerability Database. NVD suddenly stopped enriching vulnerabilities, and it's sent shock-waves through the vulnerability management space. While there are many unknowns right now, the one thing we can count on is things won't go back to the way they were.

Show Notes * Anchore's Blog * Grype * Josh's Cyphercon Talk * Ecosyste.ms * Episode 266 – The future of security scanning with Debricked

View Details

Josh and Kurt talk about an attack against GitHub where attackers are creating malicious repositories then artificially inflating the number of stars and forks. This is really a discussion about how can we try to find signal in all the noise of a massive ecosystem like GitHub.

Show Notes * GitHub besieged by millions of malicious repositories in ongoing attack

View Details

Josh and Kurt talk about recent stories about data breaches, flipper zero banning, and realistic security. We have a lot of weird challenges in the world of security, but hard problems aren't impossible problems. Sometimes we forget that.

Show Notes * Mon Dieu! Nearly half the French population have data nabbed in massive breach * Feds move to ban auto theft tech device ‘Flipper Zero’ * Gmail and Yahoo’s 2024 inbox protections and what they mean for your email program * Vending machine error reveals secret face image database of college students

View Details

Josh and Kurt talk to GregKH about Linux Kernel security. We most focus on the topic of vulnerabilities in the Linux Kernel, and what being a CNA will mean for the future of Linux Kernel security vulnerabilities. The future of Linux Kernel security vulnerabilities is going to be very interesting.

Show Notes * Greg K-H * Linux Kernel is a CNA * Machine learning and stable kernels * Bug reporting for Linux

View Details

Josh and Kurt talk to Thomas Depierre about some of the European efforts to secure software. We touch on the CRA, MDA, FOSDEM, and more. As expected Thomas drops a huge amount of knowledge on what's happening in open source. We close the show with a lot of ideas around how to move the needle for open source. It's not easy, but it is possible.

Show Notes * Thomas Depierre * I am not a supplier * Open Source In The European Legislative Landscape devroom * Cyber Resilience Act * The 2023 Tidelift state of the open source maintainer report

View Details

Josh and Kurt talk about a blog post explaining how to create a very very small container image. Generally in the world of security less is more, but it's possible to remove too much. A lot of today's security tooling relies on certain things to exist in a container image, if we remove them we could actually result in worse security than leaving it in. It's a weird topic, but probably pretty important.

Show Notes * How I reduced the size of my very first published docker image by 40% - A lesson in dockerizing shell scripts * Hacker News Discussion * Episode 293 – Scoring OpenSSF Security Scoring

View Details

Josh and Kurt talk about open source projects proving builds, and things nobody wants to pay for in open source. It's easy to have unrealistic expectations for open source projects, but we have the open source capitalism demands.

Show Notes * Open Source Doesn't Require Providing Builds * The things nobody wants to pay for * Audacity privacy policy update has caused an outcry * The History of X11

View Details

Josh and Kurt talk about an attack against PyTorch and NPM. The PyTorch attack shows the difficulty of trying to operate a large open source project. The NPM problem is one of the difficulty in trying to backdoor open source. A lot of people are watching and it only takes one person to notice a problem and we all benefit.

Show Notes * Peanut Butter the dog plays Gyromite * The Wizard movie * PyTorch supply chain attack * npm Package Found Delivering Sophisticated RAT * Deceptive Deprecation: The Truth About npm Deprecated Packages * Changing a lightbulb * Spelunking the Bitcoin Blockchain with Josh Bressers | CypherCon 4.0 * Operation Triangulation - What You Get When Attack iPhones of Researchers * 9th Annual State of the Software Supply Chain

View Details

Josh and Kurt talk about the 23andMe compromise and how they are blaming the users. It's obviously the the fault of the users, but there's still a lot of things to discuss on this one. Every company has to care about cybersecurity now, even if they don't want to.

Show Notes * Security leaders weigh in on 23andme hack * Don't need a gun when you have a Donk - Crocodile Dundee 2 * Hackers can infect network-connected wrenches to install ransomware * My disappointment is immeasurable, and my day is ruined

View Details

Josh and Kurt talk about a grab bag of old technologies that defined the security industry. Technology like SELinux, SSH, Snort, ModSecurity and more all started with humble beginnings, and many of them created new security industries.

Show Notes * SELinux * AppArmor * SSH * ModSecurity * Snort * Nmap * Nessus * What comes after open source

View Details

Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.

Show Notes * OpenSSF CISA response * purl * CPE * OmniBOR * SWID

View Details

Josh and Kurt talk about how some hackers saved the day with a Polish train. We delve into a discussion about how we don't really own anything anymore if you look around. There's a great talk from the Blender Conference about this and how GPL makes a difference in the world of software ownership. It's sort of a dire conversation, but not all hope is lost.

Show Notes * Polish manufacturer accused of programming failures into its trains to gain more servicing business * Polish Hackers Repaired Trains the Manufacturer Artificially Bricked. Now The Train Company Is Threatening Them * Blender Conference Keynote * Corey Doctorow * Chicago has a problem until the year 2083 | Stand-up Maths * Chicago Doesn’t Own Its Own Streets | Climate Town

View Details

Josh and Kurt talk about a story asking for a Kubernetes LTS. Should open source projects have LTS versions? What does LTS even mean? Why is maintaining software so hard? It's a lively discussion all about the past, present, and future of open source LTS.

Show Notes * Why Kubernetes needs an LTS * Linux gives up on 6-year LTS kernels, says they’re too much work

View Details

It's the 2023 Christmas Spectacular! Josh and Kurt talk about what would happen if Santa starts using AI to judge which children are naughty and nice. There's some fun in this one, but it does get pretty real. While we tried to discuss Santa using AI, the reality is this sort of AI is coming for many of us. AI will be making decisions for all of us in the near future (if it isn't already). While less fun than we had hoped for, it's an important conversation.

Show Notes * Sea Elf * Ollama * UnitedHealth uses faulty AI to deny elderly patients medically necessary coverage, lawsuit claims * Stephen Fry on AI * Lawyer who cited cases concocted by AI asks judge to spare sanctions * Hugging Face

View Details

Josh and Kurt talk about a few security stories about radio. The TETRA:BURST attack on police radios, spoofing GPS for airplanes near Iran, and Apple including cellular radios in the macbooks. The common thread between all these stories is looking at the return on investment for security. Sometimes good enough security is fine, sometimes it's not worth fixing certain security problems because the risk vs reward doesn't work out.

Show Notes * TETRA:BURST * GPS spoofing attack * Apple MacBooks cellular radio * Mossad vs Not Mossad

View Details

Josh and Kurt talk about Capcom claiming modding a game is akin to cheating. The arguments used are fundamentally one of equity vs equality. Humans love to focus on equality instead of equity when we deal with most problems. This is especially true in the world of security. Rather than doing something that has a net positive, we ignore the details and focus on doing something that feels "right".

Show Notes * Why Capcom thinks PC game modding is akin to “cheating” * Ben Heck

View Details

Josh and Kurt talk about the Canadian Government banning WeChat and Kaspersky. There's a lot of weird little details in this conversation. It fundamentally comes down to a conversation about risk. It's easy to spout nonsense about risk, but having an honest discussion about it is REALLY complicated. But the government plays by a very different set of rules.

Show Notes * Canada bans WeChat, Kaspersky applications on government devices * Fitness tracking app Strava gives away location of secret US army bases * Phishing emails increase over 1,200 percent since ChatGPT launch * FedRAMP Rev 5 * FAIR Institute

View Details

Josh and Kurt talk about the new EU eIDAS regulation. This is a bill that will force web browsers to add root certificates based on law instead of technical merits, which is how it's currently done. This is concerning for a number of reasons that we discuss on the show. This proposal is not a good idea.

Show Notes * Mozilla site * Root CA mailing list * UK eIDAS regulation * EFF statement on eIDAS * Fixed XKCD comic

View Details

Josh and Kurt talk about security skills shortage. We start out on the topic of cybersecurity skills and weave our way around a number of human related problems in this space. The world of tech has a lot of weird problems and there's not a lot of movement to fix many of them. Tech is weird and hard, and with the almost complete lack of regulation creates some of these challenges. In the world of security we need a better talent pipeline, but that takes actual efforts, not just complaining on the internet.

Show Notes * Schneier on security skill shortage * British Airways flight smoke * The Password Game * Tesla accidents * Lawn darts

View Details

Josh and Kurt talk about a proposed Dutch proposal that would allow the intelligence services to hack victims of adversaries they are in the process of infiltrating. The purpose of this discussion isn't to focus on the Dutch specifically, but rather to discuss the larger topic of government oversight. These are all very new concepts and nobody knows how things should work.

Show Notes * Dutch hacking proposal * Give Me Toilet Paper! by Asuka424 in 9:54 - Summer Games Done Quick 2023 * Flipper Zero Smart Meter * Frequency Hopping * Teri Kanfield

View Details

Josh and Kurt talk to Daniel Stenberg about curl. Daniel is the creator of curl, we chat with him about the security of curl. Daniel tells us how curl is kept secure, we learn about some of the historical reasons curl works the way it does. We hear the story about the curl CVE situation firsthand. We also touch on the importance of curating the community of a popular open source project.

Show Notes * Daniel's Mastodon account * Curl * The curl CVE blog * Broken curl on PowerShell * wolfSSL

View Details

Josh and Kurt talk about Sonatype's 9th Annual State of the Software Supply Chain. There's a ton of data in the report, but the thing we want to talk about is the statistic that only 11% of open source is actually being maintained. Do we think that's true? Does it really matter?

Show Notes * Sonatype report * ecosyste.ms * GNOME libcue flaw * Reality 2.0 supply chain episode

View Details

Josh and Kurt talk about a curl and glibc bug. The bugs themselves aren't super interesting, but there are other conversations around the bugs that are interesting. Why don't we just rewrite everything in Rust? Why can't we just train developers to stop writing insecure code. How can AI solve this problem? It's a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won't change.

Show Notes * Curl vulnerability * glibc vulnerability * Josh's Badge Project * Bob Lord's phishing message

View Details

Josh and Kurt talk about contributor license agreements (CLAs). CLAs used to be seen as a necessary evil, but they're almost certainly bad now. We're seeing CLAs being abused, it's clear now anything controlled by a CLA won't be open source forever.

Show Notes * A Theory of Joint Authorship for Free and Open Source Software Projects * Bruce Perens: What Comes After Open Source

View Details

Josh and Kurt talk about uncertainty. There are a bunch of stories in the news lately that really just boil down to uncertainty. Uncertainty is incredibly dangerous for everyone. We are afraid of uncertainty, and often don't really understand why it is. Trust is like a currency and uncertainty erodes trust faster than almost anything else.

Show Notes * Unity's license mess * Godot * Meta and Salesforce want to re-hire people they fired earlier this year * U.S. Debt Credit Rating Downgraded, Only Second Time In Nation’s History

View Details

Josh and Kurt talk about filing bugs for software. There's the old saying that anyone can file bugs and submit patches for open source, but the reality is most people can't. Filing bugs for both closed and open source is nearly impossible in many instances. Even if you want to file a bug for an open source project, there are a lot of hoops before it's something that can be actionable.

Show Notes * Linux is a nightmare * Lodash just declared issue bankruptcy and closed every issue and open PR * Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges * Curl NULL pointer dereference

View Details

Josh and Kurt talk about the weird world we live in how where we can't control a lot of our hardware. We don't really have control over most devices we interact with on a daily basis. The conversation shifts into a question of how can we decide what to trust and where. It's a very strange problem we experience now.

Show Notes * Boots theory * MGM cybersecurity issue shuts down slot machines and ATMs in Las Vegas casinos * New York Fire Department Forcible Entry Reference Guide * Request for Information on Open-Source Software Security: Areas of Long-Term Focus and Prioritization

View Details

Josh and Kurt talk about why CVE is making the news lately. Things are not well in the CVE program, and it's not looking like anything will get fixed anytime soon. Josh and Kurt have a unique set of knowledge around CVE. There's a lot of confusion and difficulty in understanding how CVE works.

Show Notes * Curl blog post * Now it's PostgreSQL's turn to have a bogus CVE * GitHub Advisory Database * Josh's "CVE tried to get me fired" story

View Details

Josh and Kurt talk about wordpress selling web services with a 100 year lifespan. Will WordPress still be around in 100 years? What would 100 years of disaster recovery look like? Most of us will never need to think about 100 years of disaster recovery.

Show Notes * WordPress is now selling 100-year domains * Danish ransomware * 15-Minute City * The Year Without Pants

View Details

Josh and Kurt talk about a blog post that explains how C and C++ compilers prioritize performance over correctness. This is the class story of security vs usability. Security is never the primary goal. If a security requirement doesn't also enable other business goals it will fail. We also touch on the news of a Rust package containing binary files. It doesn't really have anything to do with security, it's all about convenience.

Show Notes * C and C++ Prioritize Performance over Correctness * Nisha's toot * Barry Marshall * Rust devs push back as Serde project ships precompiled binaries * Why DARPA Hopes To 'Distill' Old Binaries Into Readable Code * Mario 64 decompilation

View Details

Josh and Kurt talk about the HashiCorp license change and copyright problems in open source. This isn't the first and won't be the last time we see this, but it's very likely open source developers and communities will view any project that has a contributor license agreement as a problem moving forward.

Show Notes * Josh's BSidesLV talk * Hacker News marked site as malware * HashiCorp license change * A Theory of Joint Authorship for Free and Open Source Software Projects

View Details

Josh and Kurt ask the question what is a vulnerability, but in the framing of video games. Security loves to categorize all bugs as security vulnerabilities or not security vulnerabilities. But the reality nothing is so simple. Everything is a question of risk, not vulnerability. The discussion about video games can help us to better have this discussion.

Show Notes * Colossus bug * Minecraft Heist

View Details

Josh and Kurt talk about the difference between what we think of as traditional open source, and enterprise software projects that have an open source license. They are both technically open source, but how the projects work is very very different.

Show Notes * CentOS Stream PR * The Most Prolific Packager For Alpine Linux Is Stepping Away

View Details

Josh and Kurt talk about a new Google proposal that would add DRM for the web. All the ad driven companies seem to be acting very strangely, there's probably a reason for this. The way ads used to pay for content is changing, but a lot of these giant companies don't know how to adapt. It's going to be very interesting times in the near future.

Show Notes * Web Environment Integrity * Hacker News Thread * Island Browser * hunter2

View Details

Josh and Kurt talk about insider threats, but not quite in the way one would expect. The potential for insider threats is possibly higher than usual right now, but what about open source? Are open source developers insider threats for your organization? Have you ever thought about this before?

Show Notes * CISA insider threats * hacks4pancakes toot * Don’t Trust a Programmer Who Knows C++ * CISA Insider Threat Mitigation

View Details

Josh and Kurt talk about some of the efforts to measure and understand open source. There are projects like the OpenSSF Scorecard. We want to measure open source for some idea of quality. Is AI generated code better than a random open source project found on GitHub? Can we track the countries contributors are from? These are all interesting problems that everyone will have to deal with soon.

Show Notes * OpenSSF Scorecard

View Details

Josh and Kurt talk about the notion that open source is somehow dying. What's actually happening is corporate open source is changing, which some are trying to deform into something wrong with open source. Open source is doing great, probably better than ever.

Show Notes * Open Source isn't sustainable anymore * VORON Design * Video of the first lathe * Plane Crazy * Evernote layoffs

View Details

Josh and Kurt talk about Red Hat closing up the RHEL source code. Kurt and Josh both worked at Red Hat in the past. This isn't a show that bashes Red Hat, and it's not a show praising them. We take an honest look at the past, present, and future of Linux. There's a lot to talk about in this one. TL;DR, Red Hat was the chosen on, and we all feel betrayed.

Show Notes * Red Hat's first blog post * Red Hat's honest post * DeWitt clause

View Details

Josh and Kurt talk about the incredible Reddit debacle. At the center of it all is an API. What does it mean to be using an API and how does this relate itself back to our own risk. Many of us rely on APIs for countless things, and if a company decides to cut off that API somehow, it could create a mess.

Show Notes * Grimace's Birthday * Reddit’s new API pricing will kill off Apollo on June 30 * Cory Doctorow enshitification * Wal Mart pickle story * Elon Musk and Mark Zuckerberg agree to hold cage fight

View Details

Josh and Kurt talk about a new program from the Sovereign Tech Fund to fund open source work. It's a great looking program with an acceptable amount of money behind the program. We also talk about a story claiming millions of perfectly good hard drives are destroyed per year. They're probably not OK at all.

Show Notes * Sovereign Tech Fund Challenges * Why millions of usable hard drives are being destroyed * LTT Buys Storage Array

View Details

Josh and Kurt talk about some new open source projects that aim to start taking back some of our privacy and rights. It's a huge hill to climb, but it seems like there is some hope. Open source doesn't care about growth, or numbers, or anything really, so it can't ever lose.

Show Notes * Codeberg * Veilid * Hawkins Cheezies * Apollo's Reddit API costs

View Details

Josh and Kurt talk about namespaces. They were a topic in the last podcast, and resulted in a much much larger discussion for us. We decided to hash out some of our thinking in an episode. This is a much harder problem than either of us expected. We don't have any great answers, but we do have a lot of questions.

Show Notes * Not Red Hat * NPM hash package * Episode 129 – The EU bug bounty program

View Details

Josh and Kurt talk about PyPI suspending new accounts and packages for a day, and a 60 minutes story about deepfakes. The problems are mostly the same, but for very different reasons. The world is changing faster than we can keep up, so what is a human to do?

Show Notes * PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted](https://thehackernews.com/2023/05/pypi-repository-under-attack-user-sign.html) * 60 minutes reporter voice clone * Cooridor Crew deepfakes * Certificate bit flip * Candy is delicious

View Details

Josh and Kurt talk about the Open Source Summit in Vancouver. Josh was there and we pick on two observations. Firstly that security keeps trying to use fear as a feature, except it doesn't work. Secondly we discuss AI and how people are talking about it. It is changing things, how much is yet to be seen.

Show Notes * SLSA * FRSCA * S2C2F * MSI leak * Intel microcode * Tom Scott AI Video

View Details

Josh and Kurt finish up the leftpad discussion. We spent a lot of time talking about how the market will respond to these sort of events, and the market did indeed speak; very little has changed. There is an aspect of all these security events where we need to understand the cost vs benefit just isn't there. it may never be there. Rather than whine and complain, we need to work with our constraints.

Show Notes * Episode 77 – npm and the supply chain

View Details

Josh and Kurt revisit Episode 77, which was named "npm and the supply chain" but was a discussion about the incident we all know now as "leftpad". We didn't understand what was happening at the time, but this would become an event we talk about for years to come. It's shocking how many of the things we discuss are still completely valid five years later.

Show Notes * Episode 77 – npm and the supply chain

View Details

This is the second part of remastering Episode 42 which is all about the security in the Hitchhiker’s Guide to the Galaxy movie. It's a fun show and it's shocking how many of these security themes are still relevant today.

Show Notes * Original Episode 42 * Part 1

View Details

The podcast is on a hiatus for a little while due to some personal matters, but that creates an opportunity to remaster some fun old episodes. These shows are REALLY hard to listen to at the current quality (tools and talent has come a long way in the last few years).

This is a remaster of Episode 42 which is all about the security in the Hitchhiker’s Guide to the Galaxy movie. It's a fun show and it's shocking how many of these security themes are still relevant today.

Show Notes * Original Episode 42

View Details

Josh and Kurt talk about a blog post about pip and virtual environments. This eventually turns into a larger conversation around packaging tools and how we see incremental changes over time. The package ecosystems were what we needed a few years ago, but our needs have changed.

Show Notes * One Does Not Simply 'pip install' * Dag Wieers RPM * Webfinger GitHub repo

View Details

Josh and Kurt talk about some data on the size of NPM. Josh wrote a blog post and a report about the amount of SEO spam in NPM was released. Open source is enormous, and it's mostly one person. It's hard to imagine how this all works sometimes and this lack of understanding can create challenges.

Show Notes * Josh's blog on the size of NPM * One In Two New Npm Packages Is SEO Spam Right Now * Linux Kernel power distribution graph

View Details

Josh and Kurt talk about OpenAI having a bug in ChatGPT, then they tried to blame open source. It didn't go very well. In this episode Josh and Kurt argue a lot, maybe someday we'll know who was the least wrong.

Show Notes * ChatGPT Tweet * ChatGPT Blog * redis bug

View Details

Josh and Kurt talk to Fiona Krakenbürger about the Sovereign Tech Fund. This is a fund created by Germany to fund important open source projects. Fiona has amazing insight into how this fund was created, what it's doing today to help fund open source. She discusses where we go from here and what the future will look like. The Sovereign Tech Fund is a forward thinking program to fund open source across the world. This episode is a window into the future.

Show Notes * Fiona on Mastodon * Sovereign Tech Fund * Sovereign Tech Fund Feasibility Study * NJ Governor Requests Expertise of 6 People Who Still Know COBOL * OpenSSF Criticality Score * European critical open source software * OSTIF critical open source projects * Apply to the Sovereign Tech Fund

View Details

Josh and Kurt talk about GitHub enforcing sanctions against an open source developer and Docker changing how their registry works. There's a lot to unpack in this one. There's a lot of happenings going on in the world of open source. We are seeing governments paying attention to open source like never before, change is coming and everything is going to change.

Show Notes * ipmitool Repository Archived, Developer Suspended By GitHub * Elixir: Docker now charges open source orgs $300

View Details

Josh and Kurt talk about the number of dependencies that is now normal. Keeping track of thousands of dependencies used to be impressive, now it's normal. In what instances should we know everything about our open source? The days of being able to ignore your software liability is looking like it's coming to an end.

Show Notes * LTT millenial pause * The perverse incentive of vulnerability counting * National Cybersecurity Strategy

View Details

Josh and Kurt talk to Thomas Depierre about his "I am not a supplier" blog post. We drink from the firehose on this one. Thomas describes the realities and challenges of being an open source maintainer. What open source and society owe each other. How safety can help describe what we see. There's too many topics to even list. The whole episode is an epic adventure through modern open source.

Show Notes * Thomas on Mastodon * I am not a supplier * The Treachery of Images (Ceci n'est pas une pipe) * Atlantic Council report * The Field Guide to Understanding 'Human Error' * Google wants new rules for developers working on 'critical' projects * Roads and Bridges:The Unseen Labor Behind Our Digital Infrastructure * Sovereign Tech Fund

View Details

Josh and Kurt talk about SBOMs. Quite a bit has happened in the world of SBOMs in the last year or so. There are going to be different types of SBOMs, like build, source, or runtime. Each will tell us different things depending on what we need to know. We also cover some of the community efforts happening around SBOMs. They're still not easy to use, but it's better better.

Show Notes * SBOM Types draft * SBOM Drift * OpenSSF SBOM Everywhere

View Details

Josh and Kurt talk to Joylynn Kirui about DevSecOps in the Microsoft universe. Joylynn gives us an overview of the current state of devops and tells us about some of the tools Microsoft has made available to the open source universe.

Show Notes * Joylynn Kirui * Joylynn on DVT Tech Insights * Episode 174 - a chat with GitHub about CodeQL * S2C2F * Azure Open Source Day

View Details

Josh and Kurt talk to Carol Nichols about Rust. Carol is an authority on Rust and helps us understand how Rust works, why it's different. Why Rust doesn't have the same problems C and C++ have, and what the future of it all could look like. It's a really fun show with some great questions from Carol along the way.

Show Notes * Carol Nichols on Mastodon * The Rust Programming Language, 2nd Edition * Rust book online * Netflix tech blog on Java performance * Rust in the context of Railroad Brakes * Kees Cook blog - Bounded Flexible Arrays in C * Consumer Reports on memory safety * OSS-Fuzz and Rust

View Details

Josh and Kurt talk about the recent GitHub breach. It wasn't terribly exciting, but there are some interesting conversations to have around securing certificates, source code, and hardware security modules. In general GitHub did most things right on this one.

Show Notes * GitHub blog post * Hacker History Podcast episode with Robert * Super Mario 64 decompile * Mario 64 built without optimization * Link to the Past source code

View Details

Josh and Kurt talk about the NSA guidance on using memory safety issues. The TL;DR is to stop using C. We discuss why C has so many problem, why we can't fix C, and what some alternatives looks like. Even the alternatives have their own set of issues and there are many options, but the one thing we can agree on is we have to stop using C.

Show Notes * NSA Releases Guidance on How to Protect Against Software Memory Safety Issues * Drum memory and the story of Mel * Netflix performance * Discord Go vs Rust * NVIDIA switch to Spark

View Details

Josh and Kurt talk about the recent FAA NOTAM outage. Keeping legacy things running for long periods of time is really hard to do, this system is no different. It's also really hard to upgrade many of these due to corner cases and institutional knowledge. There aren't any great answers here, but we do ask a lot of questions about long running tech.

Show Notes * NOTAM outage * AIX is not dead * IBM Linux commercial * Apple A/UX * How NOT To Implement the POSIX Standard, Featuring Windows NT * iSH * Hand Made Vacuum Tubes

View Details

Josh and Kurt talk about the Furby source code going public. This is an opportunity to discuss what's changed in our attitude in devices that record our audio? Our devices today are vastly more powerful and dangerous than a Furby, what does your risk appetite look like?

Show Notes * Furby source code * Talking Toy Or Spy? * Adam Ruins Everything - Why Jaywalking Is a Crime

View Details

Josh and Kurt talk about how to think about open source in the context of society. Open source is more like a natural resource than a supplier. It's common to think of open source projects as delivered to us, but it's more like acquiring raw materials from the forest. The problem is we're harvesting the raw materials in an unsustainable manner at the moment.

Show Notes * I am not a supplier * Josh's question about the environment * sjvn Gorilla toolkit article * Gorilla Web Toolkit * Awesome Games Done Quick GeoGuessr * Awesome Games Done Quick 2023

View Details

Josh and Kurt talk about the LastPass saga. There's a lot of great explanations about what happened, but there hasn't been a lot of info on how to start cleaning up this mess. We rehash some of the existing details then try to untangle what existing users can do to try to start recovering. The real problem is how LastPass is dealing with this, not the technical details.

Show Notes * Great writeup of LastPass * Jeremi M Gosney Mastodon explanation * Tavis writeup on password managers * Use a Passphrase

View Details

Josh and Kurt talk about some security gifts for boxing day. We start out with the idea of the security poverty line and discuss a few ideas for how a low resource group can make their open source more secure. There are no simple answers unfortunately.

Show Notes * Wendy Nather * Security Poverty Line * Boots Theory

View Details

Josh and Kurt talk about how hard multi factor authentication is. This all starts from a Mastodon thread, and Jerry Bell, the administrator of infosec.exchange joins us to discuss password security and all things Mastodon. Infosec.exchange is an incredible story and Jerry weaves a thrilling tale.

Show Notes * infosec.exchange MFA discussion * Jerry's 2FA advice * MalwareTech retracts Mastodon statements

View Details

Josh and Kurt talk to Jill Moné-Corallo about GitHub's bug bounty and product security team. It's a treat to discuss bug bounties with someone who is managing a very large bug bounty for one of the most important web sites in the world of software today.

Show Notes * Jill's Twitter * Jill's Mastodon * GitHub Bug Bounty * Bug bounty scope * Eight years of the GitHub Security Bug Bounty program * GitHub NPM bug bounty find

View Details

Josh and Kurt talk about a new tool that can do Stylometry analysis of Hacker News authors. The availability of such tools makes anonymity much harder on the Internet, but it's also not unexpected. The amount of power and tooling available now is incredible. We also discuss some of the future challenges we will see from all this technology.

Show Notes * Hacker News Stylometry Analyzer * FBI Profiler on the Unabomber * Impersonate Eli Lilly for $8 * Shakespeare Stylometry

View Details

Josh and Kurt talk about end to end encrypted messages. This has been a popular topic lately due to the Mastodon popularity. Mastodon has a uniquely insecure messaging system, but they aren't the only one. The eternal debate of can security and usability exist together? We suspect it can't be, but it's a very complicated topic.

Show Notes * EFF on Mastodon DM privacy * Towards End-to-End Encryption for Direct Messages in the Fediverse * Pluralistic: 14 Nov 2022 Even if you're paying for the product, you're still the product

View Details

Josh and Kurt talk about email security and the perils of trying to run your own mail infrastructure. We then get into discussing the value and danger of trying to run your own infrastructure, email, blogs, or most anything. There's a lot to juggle about all this these days, it's complicated.

Show Notes * PowerDMARC * Will Dormann * GossiTheDog upgrades Exchange * lcamtuf's blog * I like Ice Cream

View Details

Josh and Kurt talk about the UK plan to scan their country's IP space. The purpose and outcome of this isn't completely clear at this point, but we are hopeful the data can be used as a positive force. We are only going to see more programs like this as all the governments are told they have to cyber harder.

Show Notes * NCSC Scanning information * Motherboard podcast about NCIS

View Details

Josh and Kurt talk about the recent OpenSSL nothingburger. OpenSSL got everyone whipped into a frenzy over a critical vulnerability, then changed the severity to high. The correct solution to this whole problem is to stop using a TLS library written in C, we need to be using memory safe languages. Don't migrate from OpenSSL 1 to 3, migrate from OpenSSL 1 to Rustls.

Show Notes * OpenSSL Blog Post * OpenSSL pre-announcement * Mark Cox Tweet 3.0 only affected * GossiTheDog NDA Tweet * Claims of a name and logo * Rustls

Image Credit

View Details

Josh and Kurt talk about Lufthansa trying to ban Airtags. This has a similar feel to all the security events where a company tries to hand waive away a security problem then having to walk back all their previous statements. There is almost always a massive imbalance between the large companies and consumers.

Show Notes * Lufthansa bans airtags * Airtag stalking problems * Lufthansa unbans airtags * Cult of the Dead Cow book * TV Typewriter * Andre the Giant on an airplane * Poison Squad

View Details

Josh and Kurt talk about Lufthansa trying to ban Airtags. This has a similar feel to all the security events where a company tries to hand waive away a security problem then having to walk back all their previous statements. There is almost always a massive imbalance between the large companies and consumers.

Show Notes * Lufthansa bans airtags * Airtag stalking problems * Lufthansa unbans airtags * Cult of the Dead Cow book * TV Typewriter * Andre the Giant on an airplane * Poison Squad

View Details

Josh and Kurt talk about stories detailing tech working with multiple jobs. This raises some questions about fairness, accountability, and the future of work. As an industry we are very bad at measuring what we do, which is a problem shared with many jobs currently working from home.

Show Notes * Equifax surveilled 1,000 remote workers, fired 24 found juggling two jobs * Business Insider 2 jobs story * Ken Thompson lines of code

View Details

Josh and Kurt talk about ineffective security from the past we still use today. There has been a great deal of progress in the last few decades bringing us amazing products like the Flipper Zero, cameras that can peer inside locks, and even software defined radio. A great deal of security relies on people not having easy access to these cheap devices. What does this mean for the future of security?

Show Notes * Cloning a Rare ISA Card to Use a Rare CD Drive * Vintage Tech YouTubers Discussion Panel | VCFMW 17 (2022) * Flipper Zero * Lock camera * HackRF One * The history of Hash * Reddit post-it notes in apartment

View Details

Josh and Kurt talk about a newly rediscovered old python vulnerability. It raises a lot of questions about what was OK in 2007 vs what's OK in 2022. The issue is very complicated and has a wild story surrounding it. There is no reason to not fix this in 2022.

Show Notes * CVE-2007-4559 * Red Hat Bug * Register story * Response from upstream * Upstream patch * ZippSlip * Current upstream bug * CSURF

View Details

Josh and Kurt talk about a blog post that explains there isn't really an open source software supply chain. The whole idea of open source being one thing is incorrect, open source is really a lot of little things put together. A lot of companies and organizations get this wrong.

Show Notes * Iliana's Twitter * There is no “software supply chain” * Google supply chain blog * GitHub ansi_term advisory * PyPI 2FA Dashboard * tarfile issue rediscovered in 2022

View Details

Josh and Kurt talk about programming language ecosystems tracking and publishing security advisory details. We are at a point in the language ecosystems where they are giving us services that have historically been reserved for operating systems.

Show Notes * Kelsey Hightower tweet * OSS-Fuzz

View Details

Josh and Kurt talk about the Time Till Open Source Alternative blog post. The numbers probably don't mean what we think they mean anymore. A lot of modern open source is really corporate controlled. Just because something carries an open source license doesn't mean you can contribute to it.

Show Notes * Time Till Open Source Alternative * GitHub Desktop issue 78 * The Reddit Safe

View Details

Josh and Kurt talk with Josh Aas from the Internet Security Research Group about Let's Encrypt, Prossimo, and Divvi Up. A lot has changed since the last time we spoke with Josh. Let's Encrypt won, and the ISG are working on some really cool new projects.

Show Notes * Josh Aas * Internet Security Research Group (ISRG) * Let's Encrypt * Episode 87 – Chat with Let’s Encrypt co-founder Josh Aas * New Major Funding from the Ford Foundation * ISRG annual reports * Peter Eckersley

View Details

Josh and Kurt talk about really weird networking bugs. Josh tells a story about his home network problems that made no sense. There was also a qt5 bug that affected wireless networks that made virtually no sense. What should count as a security vulnerability?

Show Notes * Resolving an unusual wifi issue * Hacker News thread * Global Security Database * IdeaPad 5 14ARE05

View Details

Josh and Kurt talk about really weird networking bugs. Josh tells a story about his home network problems that made no sense. There was also a qt5 bug that affected wireless networks that made virtually no sense. What should count as a security vulnerability?

Show Notes * Resolving an unusual wifi issue * Hacker News thread * Global Security Database * IdeaPad 5 14ARE05

View Details

Josh and Kurt talk about the recent National Defense Authorization Act that requires security vulnerabilities to be fixed. What does this mean for us, is it as bad as some people are claiming it is? It's actually not a huge deal, for most of us it's really just time to deal with product security.

Show Notes * The Hacker Mind * The Untold Stories of Open Source * H.R.7900 - National Defense Authorization Act for Fiscal Year 2023 * Kurt's blog post

View Details

Josh and Kurt talk to Dustin Childs about the recent ZDI Black Hat talk where they discovered the current trend of security patches not actually fixing the security problem. We talk about what this problem means. Why is it happening, and what ZDI is doing to try nudge the industry in the right direction.

Show Notes * Dustin Childs * ZDI * Sloppy Software Patches Are a ‘Disturbing Trend’ * Zero Day Initiative launches new bug disclosure timelines * ISO 28147

View Details

Josh and Kurt talk about our lack of security and some of the data bias problems that can emerge. A lot of what we think is security data is really just biased data. This is OK as long as we understand the data is broken and know this is the first step in a longer journey.

Show Notes * Tweet about data * The 6 most common types of bias when working with data * Syft and Grype stars graph * John Snow, Cholera, the Broad Street Pump * Bob Lord tweet

View Details

Josh and Kurt talk about a tweet from @kmcquade3 asking the question "What's a concept in security that is generally accepted as true but is actually bull%$#*?" How many of the replies make sense? Most of them do. We go over some of the best replies as fast as we can.

Show Notes * The tweet that started it all * Mark Loveless * Mark Manning * Richard (Dick) Brooks * @ImbecillicusRex * What Train Have We Got? * Dan * Alejo 🏳️‍🌈 * postmodern * 🇺🇸 Robert C. Seacord 🇺🇦 * Yip Wai Peng * Sachin Shahi

View Details

Josh and Kurt talk about leap seconds. Every time there's a leap second, things break. Facebook wants to get rid of them because they break computers, but Google found a clever way to keep leap seconds without breaking anything. Corner cases are hard, security is often just one huge corner case. There are lessons we can learn here.

Show Notes * How and why the leap second affected Cloudflare DNS * Facebook wants to get rid of leap seconds * Leap Smear * Falsehoods programmers believe about time

View Details

Josh and Kurt talk about Microsoft creating a policy of not allowing anyone to charge for open source in their app store. This policy was walked back quickly, but it raises some questions about how fair or unfair open source really is. It's mostly unfair to developers if you look at the big picture.

Show Notes * Syft * Grype * Microsoft bans and unbans open source * Tidelift survey * Bruce Perens - What comes after open source

View Details

Josh and Kurt talk about PyPI mandating two factor authentication for the top 1% of projects. It feels like a simple idea, but it's not when you start to think about it. What problems does 2FA solve? How common are these attacks? What are the second and third order effects of mandating 2FA? This episode should have something for everyone on all sides of this discussion to violently disagree with.

Show Notes * PyPI announcement * NPM expired domains * Morten Linderud Tweet * Congratulations: We Now Have Opinions on Your Open Source Contributions

View Details

Josh and Kurt talk about their very silly GPG key management from the past. This is sadly a very true story that details how both Kurt and Josh protected their GPG keys. Josh's setup is like something out of a very bad spy novel. It was very over the top for a key that really didn't matter.

Show Notes * XKCD signed email * Shire calendar * Guardian editors destroy Snowden laptop

View Details

Josh and Kurt talk about the challenge of dealing with vulnerabilities at a large scale. We tend to treat every vulnerability equally when they are not equal at all. Some are trees we have to pay very close attention to, and some are part of a larger forest that can't be treated as individual vulnerabilities. We often treat risk as a binary measurement instead of a sliding scale.

Show Notes * gsd.id * The Register OpenSSL story * OpenSSL bug

View Details

Josh and Kurt talk about what the actual purpose of signing artifacts is. This is one of those spaces where the chain of custody for signing content is a lot more complicated than it sometimes seems to be. Is delivering software over https just as good as using a detached signature? How did we end up here, what do we think the future looks like? This episode will have something for everyone to complain about!

Show Notes * Twitter thread * Kurt's security advisory page * Bug 998

View Details

Josh and Kurt talk about the security of employees leaving jobs. Be it a voluntary departure or in the context of the current layoffs we see, what are the security implications of having to remove access for one or more people departing their job?

Show Notes * Tesla Layoffs * Coinbase layoffs

View Details

Josh and Kurt talk about a funny GitHub reply that notified 400,000 people. It's fun to laugh at this, but it's an easy open to discussing alert fatigue and why it's important to be very mindful of our communications.

Show Notes * GitHub 400K notifications Hacker News thread * Reddit user TV Bluetooth

View Details

Josh and Kurt talk about containers. There are a lot of opinions around what type of containers is best. Back when it all started there were only huge distro sized containers. Now we have a world with many different container types and sizes. Is one better?

Show Notes * Programming in the Apocalypse * Bob Diachenko * Paranoids Podcast

View Details

Josh and Kurt talk about a recent OpenSSF issue that asks the question how many open source maintainers should a project have that's "healthy"? Josh did some research that shows the overwhelming majority of packages have one maintainer. What does that mean?

Show Notes * OpenSSF TAC Issue 101

View Details

Josh and Kurt talk about the whole work from home debate. It seems like there are a lot of very silly excuses why working from home is bad. We've both been working from home for a long time and have a chat about the topic. There's not much security in this one, but it is a fun discussion.

Show Notes * Boris Johnson blames cheese * Apple and WFH

View Details

Josh and Kurt talk about a fake 7-Zip security report. It's pretty clear that everyone is running open source all the time. We end on some thoughts around what SBOM is good for, and who should be responsible for them.

Show Notes * Probably fake 7-Zip

View Details

Josh and Kurt talk to Adam Shostack about his new book "Threats: What Every Engineer Should Learn From Star Wars". We discuss some of the lessons and threats in the Star Wars universe, it's an old code I hear. We also discuss if Star Wars is a better than Star Trek for teaching security (it probably is). It's a fun conversation and sounds like an amazing book.

Show Notes * Adam Shostack * Adam's Website * The book

View Details

Josh and Kurt talk about the Google Project Zero blog post about 0day vulnerabilities in 2021. There were a lot more than ever before, but why? Part of the challenge is the whole industry is expanding while a lot of our security technologies are not. When the universe around you is expanding but you're staying the same size, you are actually shrinking.

Show Notes * Google Project Zero blog post * Apple 0days * Joint cyber advisory

View Details

Josh and Kurt talk about a survey about a TuxCare patch management and vulnerability detection. Sometimes our security bubble makes us forget what it's like in the real world for the people who keep our infrastructure running. Patching isn't always immediate, automation doesn't fix everything, and accepting risk is very important.

Show Notes * State of Enterprise Vulnerability Detection and Patch Management * CISA Known Exploited Vulnerabilities Catalog * Google 0days

View Details

Josh and Kurt talk about a lot of security vulnerabilities in this month's Patch Tuesday. There's also a new Git vulnerability. This sparks the age old question of how fast to patch? The answer isn't binary, the right answer is whatever works best for you, not what someone tells you is best.

Show Notes * Patch Tuesday * Git security update

View Details

Josh and Kurt talk about hackers using emergency data requests to gain access to sensitive data. The argument that somehow backdoors can be protected falls under this problem. We don't yet have the technical or policy protections in place to actually protect this data. We also explain why this zlib issue got a 2018 CVE ID in 2022.

Show Notes * Hackers using fake emergency data requests * CVE-2018-25032 * Global Security Database

View Details

Josh and Kurt talk about the binary nature of security. Many of our ideas are yes or no, there's not much in the middle. The conversation ends up derailed due to a Twitter thread about pinning dependencies. This gives you an idea how contentious of a topic pinning is. The final takeaway is not to let security turn into your identity, it ends up making a mess.

Show Notes * Josh's Twitter thread * How to install week old npm packages

View Details

Josh and Kurt talk about the latest NPM backdoored package. It feels like this keeps happening. We talk about why this is and why it's probably OK. Kurt fixes Linus' Law, in open source the superpower isn't bugs are shallow (they're not), the superpower is security bugs in open source can't be ignored.

Show Notes * node-ipc protestware

View Details

Josh and Kurt talk about Microsoft accidentally letting us find out about ads in file explorer. Changing your clocks sucks. And touch on some of the security implications of the Russian invasion and sanctions. There are a lot of security lessons we can all learn. Mostly what not to do.

Show Notes * Ads in Windows Filemanager * Russia running out of storage * Russia threatens to nationalize industry * Onagawa Nuclear Power Plant * Cockcroft's Follies * German government advises citizens to uninstall Kaspersky

View Details

Josh and Kurt talk about the Linux Kernel Dirty Pipe security vulnerability. This bug is an amazing combination of amazing complexity, incredible simplicity, and a little bit of luck. The discovery is amazing, the analysis is enlightening. There's almost no way a bug like this could be found outside of open source.

Show Notes * Dirty Pipe Writeup

View Details

Josh and Kurt talk about the challenges of security at scale. Specifically we focus on why a lot of security starts to fall apart once you have to do something more than a few times. There's a lot of new thinking we need to push security forward.

Show Notes * Stable Linux Kernel and Machine Learning

View Details

Josh and Kurt talk about SBOMs. Not what they are, there's plenty about that. We talk about why everyone keeps claiming they're super important, and why we're starting to see some people question if we really need them. SBOMs are part of a future that's still being invented.

Show Notes * Questioning SBOMs * Rezilion Log4j diagram * David A Wheeler on CII Badges * Using open source is communism

View Details

Josh and Kurt talk about the Coinbase Super Bowl ad. It was a QR code, lots of security people were aghast at how many people scanned the QR code. The reality is scanning QR codes isn't dangerous. What other security advice just won't go away?

Show Notes * Coinbase Ad * Kurt's Twitter question * QR code parking scam * Mossad or not Mossad * Kurt's talk

View Details

Josh and Kurt talk to Hayley Tsukayama from the EFF about privacy. We all know privacy in the modern age is very complicated and difficult. Normal people don't have many allies when it comes to privacy. The EFF has been blazing the trail for digital rights for more than 30 years! This episode has a ton of amazing details, it's easy to see how the EFF became the jewel of the Internet.

Show Notes * Hayley's Twitter * EFF * How to Fix the Internet * Episode 277 – Privacy and activism with Chris Weiland * Washington State privacy bill * Join the EFF (seriously, do this!)

View Details

Josh and Kurt talk about NPM requiring 2FA for the top 100 packages. We discuss the new Alpha and Omega projects from the OpenSSF and what it could mean for the future of open source security. Then we end on a note about the new Samba critical vulnerability.

Show Notes * NPM requires 2FA * OpenSSF Alpha and Omega * David A. Wheeler episode * Linux Foundation LFX * Samba Advisory

View Details

Josh and Kurt talk about how to get attention for security problems. Recent research around Twitter credentials checked into GitHub showed us how to get a lot of attention when compared to a problem like Log4Shell which took years before anyone really picked up on the problem. It's hard to talk about security sometimes.

Show Notes * Josh's computer vision code * Twitter secrets * Qualys pwnkit

View Details

Josh and Kurt talk about the Global Security Database (GSD) project. This is a Cloud Security Alliance (CSA) effort to build community around vulnerability identifiers.

Show Notes * We rate dogs * Racoons that heal your sadness * Global Security Database * Episode 261 – DWF is back! Welcome to community powered CVE * GSD mailing list * GSD Circle group * GSD Database * GSD Project Plan

View Details

Josh and Kurt talk about the faker and colors NPM events. There is a lot of discussion around open source being broken or somehow failing because of these events. The real answer is open source is an experience. How we interact with our dependencies determines what the experience looks like.

Show Notes * Developer corrupts colors and faker * Will Wright Pee * Internet Anonymity

View Details

Josh and Kurt talk about Norton creating an Ethereum mining pool. This is almost certainly a bad idea, we explain why. We then discuss the reality of NFTs and the case of stolen apes. NFTs can be very confusing. The whole world of cryptocurrency is very confusing for normal people. None of this is new, there have always been con artists, there will always be con artists.

Show Notes * Norton Crypto FAQ * Stolen Ape * Smart contract to buy the constitution * YEAR token

View Details

Josh and Kurt talk about the question will we ever fix all the vulnerabilities? The question came from Reddit and is very reasonable, but it turns out this is REALLY hard to discuss. The answer is of course "no", but why it is no is very complicated. Far more complicated than either of us thought it would be.

Show Notes * Will cyber security vulnerabilities ever "stop existing" ?

View Details

Josh and Kurt start the show with the reading of a security themed Christmas poem. We then discuss some of the new happenings around Log4j. The basic theme is that even if we were over-investing in Log4j, it probably wouldn't have caught this. There are still a lot of things to unpack with this event, I'm sure we'll be talking about it well into the future.

Log before Christmas poem

'Twas the night before Christmas, when all through the stack
Not a scanner was scanning, not even a rack,

The SBOMs were uploaded to the portal with care,
In hopes that next year would be boring and bare

The interns were nestled all snug at their beds;
While visions of dashboards danced in their heads;

The CISO in their 'kerchief, and I in my cap,
Had just slept our laptops for a long winter's nap,

When all of a sudden the pager went ack ack
I sprang to my laptop with worries of attack

Away to the browser I flew like a flash,
Tore open the window and cleared out the cache

The red of the dashboard the glow of the screen
Gave a lustre of disaster my eyes rarely seen

When what to my wondering eyes did we appear,
But a new advisory and eight vulnerabilities to fear,

Like a little old hacker all ready to play,
I knew in a moment it must be Log4j

More rapid than gigabit its coursers they came,
And it whistled, and shouted, and called them by name:

"Now, Log4Shell! now CVE! now ASF and NVD!
On, CISA! on, LunaSec! on, GossiTheDog!

To the top of the HackerNews! to the top of the wall!
Now hack away! hack away! hack away all!"

Like the bits that before the wild CDN fly by
When they meet with a firewall, they mount to the sky;

So up to the cloud like bastards they flew
With tweets full of vulns, and Log4j too—

And then, in a twinkling, I read in the slack
The wailing and screaming of each analyst called back

As I drew in my head, and was turning around,
Down the network Log4j came with a bound.

It was dressed in a hoodie, black and zipped tight,
The clothes were all swag from a conference one night

A bundle of vulns it had checked in its git
And it looked like a pedler just being a twit

The changelog—how it twinkled! its features, how merry!
Its versions were like roses, its logo like a cherry!

Its droll little mouth was drawn up like an at,
And the beard on its chin made it look stupid and fat

The stump of a diff it held tight in its teeth,
And the bits, they encircled the repo like a wreath;

It had a flashy readme an annoying little fad
That shook when it downloaded, like a disk drive gone bad

It was chubby and plump, an annoying old package,
And I laughed when I saw it, in spite of the hackage

A wink of its bits and a twist of its head
Soon gave me to know I had everything to dread

It spoke not a word, but went straight to its work,
And pwnt all the servers; then turned with a jerk,

And laying its patches aside of its nose,
And giving a nod, up the network it rose;

It sprang to its packet, to its team gave them more,
And away they all fled leaving behind a back door

But I heard it exclaim, ere it drove out of sight—
“Merry Christmas you nerds, Log4j won tonight!”

View Details

Josh and Kurt talk about the same topic everyone is talking about, Log4j. This episode was recorded on the Wednesday after the first Log4j issue. We point out all the gaps and difficulties for the defenders. The situation has gotten worse since then.

Good luck to everyone dealign with this thing

Show Notes * Log4j GSD entry * Minecraft server discussion * Log4j GitHub issue 608

View Details

Josh and Kurt talk about the epic failure that was episode 300. But this ties nicely into the topic of the day which is new ways to do things. The example is a new way to hold a controller when playing Tetris. There are always new tools and new ideas in security. Sometimes we have to abandon the old way because the new way to too good to ignore.

Show Notes * Lawfare Apple NSO podcast * New way to play Tetris

View Details

the lawsuit is based on CFAA, not on copyright. We apologize for this enormous oversight.

Josh and Kurt talk about Apple suing NSO using a copyright claim as their vehicle. Copyright is often used as a reason to bring lawsuits, even when it doesn't always make sense. Copyright has been used by open source to expand rights, and many companies to restrict rights. It's a very odd law sometimes. At the end of the day it seems the only real path forward for a problem like NSO is up to governments to protect their citizens.

Show Notes * Apple sues NSO group * VMWare EULA

View Details

Josh and Kurt talk about an article about how expertise has a limited lifetime. We are all experts in something, but some of us will find our expert knowledge to be outdated eventually. We discuss what that means in the context of security and tech and disagree about how to best keep your skills up to date.

Show Notes * Experts From A World That No Longer Exists * Neuroplasticity * Scotty and the mouse * Git 2.34 * 4H Public Speaking

View Details

Josh and Kurt talk to David A. Wheeler about everything OpenSSF. The Open Source Security Foundation is part of the Linux Foundation, and there are 6 OpenSSF working groups. David does a great job explaining how the OpenSSF works and what the 6 working groups are doing. The working group are (in no particular order): Identifying Security Threats, Security Tooling, Best Practices, Vulnerability Disclosures, Digital Identity Attestation, Securing Critical Projects.

Show Notes * David A Wheeler * Episode 14 – David A Wheeler: CII Badges * Sigstore joins the OpenSSF * OpenSSF Technical Working Groups * NPM requires MFA * LISH * Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks

View Details

Josh and Kurt talk about the famous Phrack 49 article "Smashing the Stack for Fun and Profit" turning 25 years old. This paper created a massive amount of change in the industry, possibly more than any other paper ever written. Everything from making exploiting stack overflows easier, to defenders creating technologies such as stack canaries are the direct result of this work.

Show Notes * Phrack 49 * Kurt's Interview with Elias Levi aka Aleph One

View Details

Josh and Kurt talk about the new Trojan Source bug. We don't always agree on if this is a vulnerability (it's not), but by the end we come to an agreement that ASCII is out, Unicode is in. We don't live in a world where you can make a realistic suggestion to return to using only ASCII. There are a lot of weird moving parts with this one.

Show Notes * Trojan Source * oss-security message * GitHub example

View Details

Josh and Kurt talk about Josh's electric car and new job. We then talk about the recent UAParser.js malware incident. There have been a lot of calls to do more to secure open source, but nobody seems to have any concrete proposals or suggestions to fund any of these activities.

Show Notes * UAParser.js * CISA announcement

View Details

Josh and Kurt talk to Chris Wysopal, AKA Weld Pond, about security education. We talk about the current state of how we are learning about security as students and developers. What the best way to get developers interested in learning more about security? We end the show with fantastic advice from Chris for anyone new to the field of technology or security.

Show Notes * Chris Wysopal * Veracode * l0phtcrack

View Details

Josh and Kurt talk about the release of OpenSSF Security Scorecards version 3. This is a great project that will probably make a huge difference. Most of the things the scorecards are measuring are no brainier activities. We go through the list of metrics being measured. There are only a few that we don't think are fantastic.

Show Notes * 4 of spades * OpenSSF * Chris Montgomery audio explanation * Scorecard 3.0.0 * Scoring criteria * Python Skeleton

View Details

Josh and Kurt talk about the recent Twitch hack and how in the modern age leaking source code almost certainly doesn't matter. The leaked data however is a big deal. We also discuss a recent Apache httpd update. Some things went right, some things went wrong. Dealing with vulnerabilities is hard.

Show Notes * Parasocial Relationship * Twitch Hack * Soviet B-29 Clone * Apache CVE * Apache Advisory * GossiTheDog Tweet * Hacker Fantastic exploit

View Details

Josh and Kurt talk about recent events around Apple and Microsoft disclosing security vulnerabilities. Microsoft usually does a good job, but Apple has a long history of not having a great bug bounty or vulnerability disclosure policy. None of this is simple, but hopefully you'll have some fun and learn a bit about the whole vulnerability disclosure process.

Show Notes * Apple 0days * Microsoft Exchange flaw * THIS IS HOW THEY TELL ME THE WORLD ENDS * Linux Foundation Vulnerability Disclosure * Timezone problem

View Details

Josh and Kurt talk about the security of the Matrix movie series. There was a new Matrix trailer that made us want to discuss some of the security themes. We talk about how the movie is very focused on computing in the 90s. How Neo probably ran Linux and they used a real ssh exploit. How a lot of the plot is a bit silly. It's a really fun episode.

Show Notes * Matrix 4 trailer * nmap in the Matrix * VFX Artists react to the Mandalorian * Glasshouse * Universal Paperclips

View Details

Josh and Kurt talk about an unusual number of really bad security updates. We even recorded this before the Azure OMIGOD vulnerability was disclosed. It's certainly been a wild week with Apple and Chrome 0days, and a Travis CI secret leak. Maybe this is the new normal.

Show Notes * Matrix 4 trailer * Travis CI issue * Apple 0day patches * Chrome 0day patches * CGP Grey Where is the European Union

View Details

Josh and Kurt talk about some happenings in the Linux Kernel. There are some new rules around how to submit patches that goes against how GitHub works. They're also turning all compiler warnings into errors. It's really interesting to understand what these steps mean today, and what they could mean in the future.

Show Notes * The Register Linux story * OpenSSL Release Notes

View Details

Josh and Kurt talk about GitHub Copilot. What can we learn from a report claiming 40% of code generated by Copilot has security vulnerabilities? Is this the future or just some sort of strange new thing that will be gone as fast as it came?

Show Notes * GitHub Copilot * Copilot research paper

View Details

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes * Dan's Twitter * Sigstore * SLSA Framework

View Details

Josh and Kurt talk about open source bugs. What happens if a project decides to close most of their bugs? Nothing really. Bug trackers aren't a help desk.

Show Notes * Emacs closes 45% of bugs * UVI * Tesla investigation * UK COVID spreadsheet

View Details

Josh and Kurt talk about a Home Depot plan to put DRM on power tools. Anyone can add a computer to anything for a few dollars now. How secure is any of this. What does it mean when the things we buy start to acquire DRM? There are a lot of new questions we don't have any real answers for.

Show Notes * Home Depot power tools * Ray Ozzie's IoT board * First-sale doctrine

View Details

Josh and Kurt talk about a very difficult disclosure problem. What happens when you have to report a vulnerability to an ethically questionable company? It's less simple than it sounds, many of the choices could end up harming victims.

Show Notes * Disclosure Dilemmas * @evacide * Bob Diachenko * This Is How They Tell Me The World Ends

View Details

Josh and Kurt talk about a story from Microsoft declaring Rust the future of safe programming, replacing C and C++. We discuss how tooling affects progress and why this isn't always obvious when you're in the middle of progress.

Show Notes

  • Microsoft: Rust Is the Industry’s ‘Best Chance’ at Safe Systems Programming
  • Josh's devopsdays talk
  • Microsoft moved font handling out of the kernel
  • Atari 2600 emulator in Minecraft
  • Rate of technology adoption

View Details

Josh and Kurt talk about the news that the NSO Group is widely distributing spyware onto a large number of devices. This news should be a wake up call for anyone creating devices and systems that could be attacked, it's time to segment services. There's not a lot individuals can do at this point, but we have some ideas at the end of the episode.

Show Notes * NSO Group spying * Technical details Twitter thread * Are we the Baddies?

View Details

Josh and Kurt talk about what happens when you lose access to your Single Sign On provider. These providers have become critical to many of us, if we lose access to our SSO account we will lose access to many services.

Show Notes * Postbank

View Details

Josh and Kurt talk about the events happening to the Audacity audio editor. What happens if a popular open source application is acquired by an unknown entity? Can this happen to other open source projects? What can we do about it?

Show Notes * SGDQ Paper Mario * Paper Mario Arbitrary Code Execution explained * Freenode * Audacity acquired by Muse Group * Audacity fork

View Details

Josh and Kurt talk about a listener provided question. Could SELinux have stopped the SolarWinds attack? Given what we know, the answer is technically yes, but practically no. SELinux is awesome, but it's very difficult to sandbox something like a build system.

Show Notes * Gone in 60 milliseconds

View Details

Josh and Kurt talk to Chris Weiland from Restore the Fourth Minnesota. Restore The Fourth Minnesota is nonprofit dedicated to restoring the Fourth Amendment to the U.S. Constitution and ending unconstitutional mass government surveillance. Chris drops a ton of knowledge about how to be an effective tech activist, what his group is doing, and most importantly we get actionable advice!

Show Notes * Restore the Fourth Minnesota * Restore the Fourth Minnesota on Twitter * Writ of assistance * Carpenter vs United States * How many US federal laws are there? * Restore the Fourth * Episode 114 – Review of "Click Here to Kill Everybody" * EFF EFA * ACLU affiliates * Glenn Greenwald TED talk

View Details

Josh and Kurt talk about how our environment affects our behavior, and in turn our level of security. We often ignore what's happening around us when everything is related.

Show Notes * Judges more lenient after a break * Dungeons and Data * Poverty changes your DNA

View Details

Josh and Kurt talk about why it seems like the world of ransomware has gotten out of control in the last few weeks. Every day there's some new and more bizarre ransomware story than we had yesterday.

Show Notes * Spurious Correlations * Ransom recovered * Adam Shostack Ransomware is not the problem * Latvian Woman charged for writing ransomware

View Details

Josh and Kurt talk about Amazon sidewalk. There is a lot of attention, but how is this any different than the surveillance networks Apple and Google have built?

Show Notes * Amazon Sidewalk * Ads and toothpaste * Airtags and stalking

View Details

Josh and Kurt talk about AI driven comments. We live in a world of massive confusion and disruption where what is true and false, real and fake, are often widely debated. As AI grows and evolves what does it mean for this future? We don't really have any answers, but we ask a lot of questions. This isn't easy, nor will it be solved quickly, but solving it is not optional.

Show Notes * AIs and Fake Comments * ACLU AMA * Cloudflare Cryptographic Attestation of Personhood * Evil bit * Boris Johnson Painting Buses

View Details

Josh and Kurt talk about the Biden Administration new cybersecurity executive order. There are some good ideas in there, but at the end of the day it's an unfunded mandate. Unfunded mandates are difficult to implement.

Show Notes * Biden Executive Order * Fact Sheet * Obama's cyber EO

View Details

Josh and Kurt talk about how people handle problems. We open with the story of the Colonial Pipeline hack, but then go into some of the ways people tend to make problems worse.

Show Notes * Male vs Female trees * Pipeline hack * XKCD Pipelines * TSA Pipeline Security

View Details

Josh and Kurt talk about dark patterns. A dark pattern is when a service tries to confuse a user into doing something they don't want to, like unknowingly purchasing a monthly subscription to something you don't need or want. The US Federal Trade Commission is starting to discuss dark patterns in webs sites and apps.

Show Notes * Dark Patterns * Types of Dark Patterns * FTC Bringing Dark Patterns to Light * LTT Dell Warranty

View Details

Josh and Kurt talk about the University of Minnesota experimenting on the Linux Kernel. There's a lot to unpack in this one, but the TL;DR is you probably don't want to experiment on the kernel.

Show Notes * Linux Bans University of Minnesota for Sending Buggy Patches in the Name of Research * University of Minnesota security researchers apologize for deliberately buggy Linux patches * The International Obfuscated C Code Contest

View Details

Josh and Kurt talk about what 3rd party means in the current world. From 5G suppliers, to the Codecov and Solarwinds breaches. Is there anyone we can trust?

Show Notes * Europe and 5G * Codecov * Codecov Reuters story * Red Hat OpenSSH advisory

View Details

Josh and Kurt talk about 0day security vulnerabilities. What are they? What were they? And why the name has taken on a new meaning, and that's OK.

Show Notes * Hacker History Podcast * Chrome 0day * NTFS Documentation

View Details

Josh and Kurt talk to Emil Wåreus from Debricked about the future of security scanners. Debricked is doing some incredibly cool things to avoid relying on humans for vulnerability identification and cataloging. Learn what the future of security scanning is going to look like.

Show Notes

  • Debricked
  • Emil's Linkedin

View Details

Josh and Kurt talk about the PHP backdoor and the Ubiquity whistleblower. The key takeaway is to note how an open source project cannot cover up an incident, but closed source can and will cover up damaging information.

Show Notes * PHP backdoor * Ubiquity coverup * 3D printed TSA keys * LockPickingLaywer * Determining Key Shape from Sound * Lock camera

View Details

Josh and Kurt talk to Mark Loveless from GitLab. We touch on DevSecOps, what GitLab is doing, threat modeling, and the time Mark tested positive for TNT at the airport. It's a great conversation.

Show Notes

  • Mark Loveless Twitter
  • GitLab
  • GitLab Handbook
  • How we approach open source security
  • PASTA threat modeling
  • GitLab security features
  • Tales from the Past - "You Tested Positive for TNT"

View Details

Josh and Kurt talk about how terrible daylight savings is. GitHub yanking some exploit code. And the Linux Foundation new project to sign all the things.

Show Notes * Researcher Publishes Code to Exploit Microsoft Exchange Vulnerabilities on Github * GitHub content restrictions * Reproducing the Microsoft Exchange Proxylogon Exploit Chain

View Details

Josh and Kurt talk to Loris Degioanni and Dan from Sysdig. Sysdig are the minds behind Falco, an amazing open source runtime security engine. We talk about where their technology came from, they huge code donation to the CNCF and what securing a modern infrastructure looks like today.

Show Notes * Sysdig * Falco * Loris' Twitter * Dan "Pop" Popandrea's Twitter * Sysdig contributes Falco’s kernel module, eBPF probe, and libraries to the CNCF * pdig * Sysdig 2021 container security and usage report: Shifting left is not enough

View Details

Josh and Kurt talk about DWF. It's back and the intention is to have real community driven security identifiers!

Show Notes

  • Committee vs Community
  • dwflist repo
  • dwf-request tooling repo
  • dwf-workflow policy repo
  • CVE plateua graph
  • iwantacve.org

View Details

Josh and Kurt talk with Dave Jevans CEO of CipherTrace and chairman of the anti-phishing working group about the challenges of keeping track of cryptocurrency in the modern age.

Show Notes

  • Dave's Twitter
  • CipherTrace
  • Anti Phishing Working Group

View Details

Josh and Kurt talk about the question "what is open source?" Why do we think it's broken today, and what sort of ideas about what should come next.

Show Notes

  • OSI
  • Bruce Perens Post Open Source
  • Josh's community blog post
  • Corey Doctorow Uber Twitter thread

View Details

Josh and Kurt talk about the Google Project Zero report titled "A Year in Review of 0-days Exploited In-The-Wild in 2020". It's a cool report but we don't agree on the conclusion. The answer isn't to security harder, it's to stop using C.

Show Notes

  • Google Project Zero Year of 0-days
  • Kurt's CUPS tweet

View Details

Josh and Kurt talk about the recent sudo and libgcrypt security vulnerabilities. What's the deal with these buffer overflows and TOCTU bugs?

Show Notes

  • Sudo buffer overflow
  • Sudo SELinux bug
  • libgcrypt buffer overflow

View Details

Josh and Kurt talk about 8 bit computing. What sort of security lessons can we learn from the 8 bit world? More than you think.

Show Notes

  • Legend of Zelda Random Number Generation
  • Green rocket flame
  • SR71 leaked fuel
  • How do Namibian Himbas see colour?
  • Suptuple meter music

View Details

Josh and Kurt talk about what we can stop doing. We take a position of asking "does it spark joy" for tools and infrastructure. Everyone is doing something they should stop.

Show Notes

  • Does it spark joy?

View Details

Josh and Kurt talk about the new right to repair rules in the EU. There's a strange line between loving the idea of right to repair, but also being horrified as security people at the idea of a device being on the Internet for 30 years.

Show Notes

  • EU right to repair
  • repair.eu

View Details

Josh and Kurt talk about this idea that seems to exist in security of "attackers only need to be right once" which is silly. The reality is attackers have to get everything right, defenders really only need to get it right once. But "defenders only need to be right once" isn't going to sell any products.

Show Notes

  • Richard Feynman and manhole covers
  • Richard Feynman on Why He Can't Tell You How Magnets Work
  • Israeli airport security
  • FAA stolen sweater
  • XKCD Is it worth the time
  • CGP Grey The trouble with transporters

View Details

Josh and Kurt talk about a report on open source security from the Canadian Centre for Cyber Security. The title pretty much sums it up.

Show Notes

  • Security Considerations for Open Source
  • Build an 8 bit computer from scratch

View Details

Josh and Kurt talk about communication. It's really hard to talk about a lot of what we do. How do we know if a device is secure? How do we know our knowledge is correct?

Show Notes

  • 90 percent of U.S. bills carry traces of cocaine
  • Is the moon a star or planet?
  • A mole of moles
  • New homeowner 'freaked out' when stranger took control of her security system
  • Coffee maker ransomware
  • NIST Phish Scale
  • The metric system
  • Operation Paperclip

View Details

Josh and Kurt talk about why we do the things we do. Sometimes we have to question everything.

Links * SLAM missile

View Details

Josh and Kurt talk about the idea of information wanting to be free. It's Christmas, we should give it what it wants!

Links * Hacker Manifesto

View Details

Josh and Kurt talk about how to file 1000 security flaws. One is easy, scale is hard.

View Details

Josh and Kurt talk about how to report one security flaw

View Details

Josh and Kurt talk about bug bounties

View Details

Josh and Kurt talk about if SMS 2 factor auth is better than no 2FA

Links * Cyber deepfaked their host

View Details

Josh and Kurt talk about modern TLS certificate trust

View Details

Josh and Kurt talk about why it's a horrible idea to roll your own crypto or auth

View Details

Josh and Kurt talk about vulnerability response. What is it, what does it mean, how does it work

View Details

Josh and Kurt talk about the switch from 16 to 32 to 64 bit and even the changes from Intel to ARM

View Details

Josh and Kurt talk about supplier compliance

Links * Annex A.15.1 of ISO 27001:2013 * Episode 162 – SBOM with Allan Friedman

View Details

Josh and Kurt talk about backdoors in open source software

View Details

Josh and Kurt talk about the unluckiest man in the world and survivor bias

Links * Unluckiest man in the world

View Details

Josh and Kurt talk about video game hacking. The speedrunners are doing the best security research today

Links * Super Mario World RCE

View Details

Josh and Kurt talk about the safety of a 737

Links * FAA says 737 is safe

View Details

Josh and Kurt talk about Apple leaking internal IP addresses. Sometimes we create our own emergencies over things that don't matter.

Links * Apple's internal IP addresses

View Details

Josh and Kurt talk about public key cryptography

View Details

Josh and Kurt talk about the OpenBSD security(8) man page and the importance of automating security

Links * OpenBSD security(8) page

View Details

Josh and Kurt talk about prime numbers

View Details

Josh and Kurt talk about the non problems with public wifi we love to pretend matter

Links * The Half Dozen Risks of Using Dirty Public Wi-Fi Networks

View Details

Josh and Kurt talk about why you need 24/7 monitoring of all the things

Links * Swiss air force office hours * DC-10 cargo door

View Details

Josh and Kurt talk about how the EFF is helping us prevent Internet tracking

Links * EFF Cover Your Tracks

View Details

Josh and Kurt talk about how many security vulnerabilities matter enough to fix?

Links * A Third of Known Computer Security Flaws Have No Solution * Episode 162 – SBOM with Allan Friedman

View Details

Josh and Kurt talk about cybersecurity statistics and the value of the data we have.

Links * 24 Cybersecurity Statistics That Matter In 2020

View Details

Josh and Kurt talk about advent calendars. We are publishing 25 5 minute episodes in 25 days. Also portable X-ray machines.

View Details

Josh and Kurt talk about the safety and liability of new devices. What happens when your doorbell can burn down your house? What if it's your fault the doorbell burned down your house? There isn't really any prior art for where our devices are taking us, who knows what the future will look like.

Show Notes

  • Ring Doorbell recall
  • Ring incorrect screw diagram
  • Punctured battery
  • Episode 145 – What do security and fire have in common?
  • Phillips vs Robertson screws
  • wendy knox everette
  • Wendy's presentation on legal liability
  • Tim Burners-Lee privacy company

View Details

Josh and Kurt talk about what happens when important root certificates expire on old Android devices? Who should be responsible? How can we fix this? Is this even something we can or should fix? How devices should age is a really hard problem that needs a lot of discussion.

Show Notes

  • Unboxing coins
  • Old Android devices certificate store
  • Steve1989MREInfo

View Details

Josh and Kurt talk about the idea behind the full disclosure of security vulnerability details. There have been discussions about this topic for decades with many people on all sides of the issue. The reality is however, if you look at the current state of things, this discussion is settled, full disclosure won.

Show Notes

  • Hacker One 100 million payout
  • Project Zero bug
  • Remington gun trigger class action lawsuit
  • Square windows on a plane

View Details

Josh and Kurt talk to Jeff Mitchell about the new HashiCorp project Boundary. We discuss what Boundary is, why it's cooler than a VPN, and how you can get involved.

Show Notes

  • Jeff Mitchell
  • HashiCorp Boundary announcement
  • Discuss forum
  • Boundary Project
  • Boundary GitHub

View Details

Josh and Kurt talk about how to get started in security. It's like the hero's journey, but with security instead of magic. We then talk about what Webkit bringing Face ID and Touch ID to the browsers will mean.

Show Notes

  • Hero's Journey
  • Mudge's Tweet
  • L0pht at Congress
  • Bob Ross
  • Webkit Face ID and Touch ID for the Web

View Details

Josh and Kurt talk about Network Time Security (NTS) how it works and what it means for the world (probably not very much). We also talk about Singapore's Cybersecurity Labelling Scheme (CLS). It probably won't do a lot in the short term, but we hope it's a beacon of hope for the future.

Show Notes

  • Network Time Security
  • NTP and the University of Wisconsin
  • Cybersecurity Labelling Scheme (CLS)

View Details

Josh and Kurt have a chat with Larry Cashdollar. The three of us go way back. Larry has done some amazing things and he tells us all about it!

Show Notes

  • Akamai
  • Larry's website
  • Larry's First CVE

View Details

Josh and Kurt talk about change. Specifically we discuss how the past was a terrible place. Never believe anyone who tells you it was better. Part of a career now is learning how to learn. The things you learn today won't be useful skills in a few years. The future is is always better than the past. Even in 2020.

Show Notes

  • I no longer build software
  • Temple OS
  • Top Gear electric car
  • 1959 Bel Air crash test

View Details

Josh and Kurt talk to Travis Murdock about how to tell your story. Travis explains how to talk to the press and how to tell our story in a way that helps get our message across and lets the reporter do their job better.

Show Notes

  • Ruder Finn
  • CVE-2009-3555
  • Heartbleed

View Details

Josh and Kurt talk about how we talk about what we do in the context of life on Venus. We didn't really discover life on Venus, we discovered a gas that could be created by life on Venus. The world didn't hear that though. We have a similar communication problem in security. How often are your words misunderstood?

Show Notes

  • Phosphine on Venus
  • GPS and relativity

View Details

Josh and Kurt talk about attacking open source. How serious is the threat of developers being targeted or a git repo being watched for secret security fixes? The reality of it all is there are many layers in a security journey, the most important things you can do are also the least exciting.

Show Notes

  • Targeting developers
  • XKCD Infrastructure comic
  • Hiding security flaws in git
  • Mossad vs Not-Mossad (PDF warning)

View Details

Josh and Kurt talk about how your actions can tell the world if you actually take security seriously. We frame the discussion in the context of Slack paying a very low bug bounty and discover some ways we can look at Slack and decide if they do indeed take our security very seriously.

Show Notes

  • Reddit carbon monoxide Part 1 Part 2
  • GCP Grey minus infinity
  • Josh's blog post

View Details

Josh and Kurt talk about Chromium sending traffic to root DNS servers. Telemetry watching what we do. Cryptocurrency scams and a few other random topics. Also pandas.

Show Notes

  • Blanket rack
  • Chromium DNS traffic
  • Ubuntu MOTD
  • Microsoft telemetry
  • YAM coin implodes
  • Panda Cubs

View Details

Josh and Kurt talk about the Microsoft 2 year old signature bug and Github no longer processing MFA resets for free users. Signing things is hard, but trying to manage users and infrastructure at scale is even harder.

Show Notes

  • Microsoft signed jar bug
  • GitLab Support is no longer processing MFA resets for free users
  • Someone Is Hijacking Tor Exit Nodes to Conduct MITM Attacks

View Details

Josh and Kurt talk about the current state of information security. There are aspects that resemble a cult more than we would like. It's not all bad though, there are some things we can do to help move things forward. This episode shouldn't be taken too seriously.

Show Notes

  • "cult of information security"
  • How to start a cult

View Details

Josh and Kurt talk about Secure Boot. The conversation uses the recent "Boot Hole" vulnerability to frame a conversation about what Secure Boot is and isn't. Why the Boot Hole flaw doesn't really matter, and why Secure Boot was very scary for Linux users back when it came out.

Show Notes

  • Boot Hole

View Details

Josh and Kurt talk about some of the necessary evils of security. There are challenges we face like passwords and resource management. Sometimes the problem is old ideas, sometimes it's we don't have metrics. Can you measure not getting hacked?

Show Notes

  • Clearing checks
  • FAIR Institute
  • Factorio

View Details

Josh and Kurt start this one by explaining how the Twitter hacker was just a dumb criminal (most criminals are dumb). We then discuss the new GPT-3 AI that can create text. How we create, and how social media is doing everything it can to weaponize our attention. It's not a fight humanity is winning.

Show Notes

  • GPT-3 AI
  • Blipverts

View Details

Josh and Kurt talk about Google's new confidential VMs. The AMD Secure Encrypted Virtualization is the technology that makes it all possible. What is SEV, how does it work, and why should you care? This technology is going to be the future of the cloud.

Show Notes

  • Google confidential VMs
  • AMD SEV
  • SEV vs SGX

View Details

Josh and Kurt talk to Alyssa Miller from Snyk about the State of Open Source Security 2020 report. Alyssa was the report author and has some great insight into the current trends we're seeing in open source security. Some of the challenges developers face. We discuss the difficulty static and composition analysis scanners face. It's a great conversation!

Show Notes

  • The State of Open Source Security 2020
  • Alyssa's Twitter

View Details

Josh and Kurt talk about some recent security actions Apple has taken. Not all are good, but in general Apple is doing things to benefit their customers (their customers are not advertisers). We also discuss some of the challenges when your customers are advertisers.

Show Notes

  • Apple one year certificates
  • Apple declines to implement 16 new APIs
  • Apple is tracking unsigned executables

View Details

Josh and Kurt talk about human behavior. The conversation makes its way to conferences and the perpetual question of if a conference is useful or not. We come to the agreement the big shows aren't what they used to be, but things like BSides are great experiences.

Show Notes

  • Security and Human Behaviour
  • Josh's blog post
  • Mudge's Twitter thread

View Details

Josh and Kurt talk about the security of applications. We talk about the security of infrastructure all the time, but what happens when we combine infrastructure into an application or solution?

Show Notes * Picture of Kurt's security check-up * Dragon controls

View Details

Josh and Kurt talk about CVSSv3 and how it's broken. We started with a blog post to explain why the NVD CVSS scores are so wrong, and we ended up researching CVSSv3 and found out it's far more broken than any of us expected in ways we didn't expect. NVD isn't broken, CVSSv3 is. How did we get here? Are there any options that work today? Where should we go next?

Show Notes * Josh's blog post * NVD * Red Hat security data * Josh's CVE data project * Microsoft security ratings scale

View Details

Josh and Kurt talk to Liz Rice from Aqua Security about container security and her new book on the same topic. What does container security look like today? What are some things you can do now? What will container security look like in the future?

Show Notes * Container Security download * Pictures of elephants * Kubernetes Security book * Starboard project * Dynamic threat analysis

View Details

Josh and Kurt talk about a grab bag of topics. A DNS security flaw, port scanning your machine from a web browser, and CSV files running arbitrary code. All of these things end up being the result of corner cases. Letting a corner case be part of a default setup is always a mistake. Yes always, not even that one time.

Show Notes

  • Bind advisory
  • Robustness Principal
  • eBay port scanning localhost
  • OWASP CSV injection

View Details

Josh and Kurt talk about the Krebs blog post titled "When in Doubt: Hang Up, Look Up, & Call Back". In the world of security there isn't a lot of actionable advice, it's worth discussing if something like this will work, or ever if it's the right way to handle these situations.

Show notes

  • When in Doubt: Hang Up, Look Up, & Call Back
  • Tech Support Scam podcast: Part 1, Part 2
  • STIR/SHAKEN
  • Drill the wrong safe deposit box
  • 2009 Bank of Ireland robbery

View Details

Josh and Kurt talk about what beer and reproducible builds have in common. It's a lot more than you think, and it mostly comes down to quality control. If you can't reproduce what you do, you're not a mature organization and you need maturity to have quality.

Show Notes * Reinheitsgebot * Josh's Blog Post * Ken Thompson's reflections on trusting trust * Tor Browser Deterministic Builds * One line package broke npm create * Donkey Kong 64 memory leak

View Details

Josh and Kurt talk about automatic updates. Specifically we discuss a recent decision by Ubuntu to enable forced automatic updates. There are lessons here for the security community. We have a history of jumping to solutions rather than defining and understanding problems. Sometimes our solutions aren't the best. Also murder bees.

Show Notes * The Oatmeal giant bee comic * Honeybees cook giant hornet * Ubuntu 20.04 LTS’ snap obsession has snapped me off of it * Forum discussion

View Details

Josh and Kurt talk about the uproar around Cloudflare's "Is BGP safe yet" site. It's always interesting watching how much people will push back on new things, even if the new things is probably a step in the right direction. The clever thing Cloudflare is doing in this instance is they are making the BGP problem something anyone can understand. Also send us your funny dog stories.

Show Notes * Is BGP safe yet? * Reddit BGP conversation * Hacker News BGP conversation * Stealing cryptocurrency with BGP

View Details

Josh and Kurt talk about the new normal that's working away from an office. It's not exactly working from home as there are some unforeseen challenges that we just took for granted in the past. There are a lot of new and strange security problems we have to adapt to, everyone is doing amazing work with very little right now.

Show Notes * Microsoft buys corp.com * Hijack computer network traffic with a Pi Zero

View Details

Josh and Kurt talk about space. We intended to focus on Apollo 13 but as usual we have no ability to stay on topic. There is a lot of fun space discussions in this one though. Do you think you can hack Voyager 1? Only if you have a big enough satellite dish.

Show Notes * Eavesdropping on Apollo 11 * Apollo 11 classified weather satellite * The pen that saved Apollo 11

View Details

Josh and Kurt talk about Kurt's recent treadmill purchase and the lessons we can lean in security from the consumer market. The consumer market has learned a lot about how to interact with their customers in the last few decades, the security industry is certainly behind in this space today. Once again we display our ability to tie even the seemingly mundane things back to a discussion about security.

Show Notes * Eating goldfish off the treadmill

View Details

Josh and Kurt talk about security scanners. They're all pretty bad today, but there are some things we can do to make them better. Step one is to understand the problem. Do you know why you're running the scanner and what the reports mean?

Show Notes * Edmonton freeze thaw cycles * Josh's security scanner blog series

View Details

Josh and Kurt talk about building a talent ecosystem. What starts out as an attempt by Kurt to talk about Canada evolves into a discussion about how talent can evolve, or be purposely grown. Canada's entertainment industry and Unit 8200 are good examples of this.

Show Notes * SCTV * Red Team Project * Moon Shot book * AvE channel * Turning a tree root into a bowl * Mailing the Hope Diamond * The Ecosystem

View Details

Josh and Kurt talk about video games and hacking. Specifically how speed runners are really just video game hackers.

Show Notes * Developer speedrun commentary * Super Mario World end credits glitch explained * Mario 3 RCE * Breath of the Wild speedrun * Super Metroid reverse boss order * TMR beats every NES game

View Details

Josh and Kurt talk about video games. Yeah, video games. Specifically about cheating in video games. There's a lot of other security themes in the discussion. With the news being horrible these days, we needed to talk about something fun.

Show Notes * Penny Arcade * Banned from Fortnite * Apollo Robbins, world's best pickpocket

View Details

Josh and Kurt talk about Wireguard. There have been a lot of recent conversations about it and if it's better or worse than other VPN solutions. It's safe to say in our modern age, less is usually more, especially when it comes to security. Wireguard has a lot going for it, it can't be ignored.

Show Notes * Replacing a Nintendo Switch fan * WireGuard * Hacker News discussion

View Details

Josh and Kurt talk to Tony Meehan from Elastic (formerly Endgame) about endpoint detection, response, protection, and even SIEM. Tony has a great history coming from the NSA and has a number of great stories to help understand the topics.

Show Notes * Tony Meehan * Rob Joyce on Disrupting Nation State Hackers * Bobby Filar living off the land blog * Dwell time graph * Snowboarder vs Tree

View Details

Josh and Kurt talk about the Linux Foundation Census 2. There is a lot of talk around how to fix open source security, but the reality is we can't fix it. We need to stop trying to fix what isn't broken and engineering around the system we have, not the system we want.

Show Notes * Linux Foundation Census 2 * Core Infrastructure Initiative

View Details

Josh and Kurt talk about the sale of the corp.com domain. Is it going to be the end of the world, or a non event? We disagree on what should happen with it. Josh hopes an evildoer buys it, Kurt hopes for Microsoft. We also briefly discuss the CIA owning Crypto AG.

Show Notes * corp.com is for sale * CIA owned Crypto AG

View Details

Josh and Kurt talk about a huge working from home experiment because of the the Coronavirus. We also discuss some of the advice going on around the outbreak, as well as how humans are incredibly good at ignoring good advice, often to their own peril. Also an airplane wheel falls off.

Show Notes * Work from home Hacker News discussion * CDC advice * How to wash your hands * Air Canada flight without running wather * Airplane wheel falling off

View Details

Josh and Kurt talk about open source maintainers and building communities. While an open source maintainer doesn't owe anyone anything, there are some difficult conversations around holding back a community rather than letting it flourish.

Show Notes * Actix-web story * Lodash * Possible Lodash security issue * Javascript libraries are almost never updated * Ularn

View Details

Josh and Kurt talk about SIM swapping. What is it, how does it work. Why should you care? There's not a ton you can do to protect yourself, but we go over some of the basic concepts and what to watch out for. It's unfortunate this is still a problem.

Show Notes * Five Major US Wireless Carriers Are Vulnerable to SIM Swapping * Edmonton Police SIM swap website

View Details

Josh and Kurt talk about two recent vulnerabilities that have had very different outcomes. One was the Citrix remote code execution flaw. While the flaw is bad, the handling of the flaw was possibly worse than the flaw itself. The other was the Microsoft ECC encryption flaw. It was well handled even though it was hard to understand and it is a pretty big deal. As all these things go, fixing and disclosing vulnerabilities is hard.

Show Notes * Microsoft flaw CVE-2020-0601 * Citrix flaw CVE-2019-19781 * Citrix mitigation instructions

View Details

Josh and Kurt talk about the updated Google Project Zero disclosure policy. What's the new policy, what does it mean, and will it really matter? We suspect it will improve some things, but won't drastically change much.

Show Notes * Google and 90 day patch disclosure * Upgrading all Windows versions

View Details

Josh and Kurt talk about a discussion on Twitter about if discovering CVE IDs is important for a resume? We don't think it is. We also discuss the idea of ransomware putting a company out of business. Did it really? Possibly but it probably won't create any substantial change in the industry.

Show Notes * Games Done Quick * Ransomware puts company out of business * 1 in 5 companies shut down due to ransomware * Laura Shin SIM Swap Podcast

View Details

Josh and Kurt talk about marketplace safety and security. Will we ever see an end to the constant flow of counterfeit goods? The security industry has the same problem the marketplace industry has, without substantial injury we don't see movement towards meaningful change.

Show Notes * BrickLink * Cars in Canada lighting on fire * President Roosevelt used Al Capone's Limo * Dangerous car seats * Fake external hard drive

View Details

Josh and Kurt talk about security predictions for 2020. None of the predictions are even a bit controversial or unexpected. We're in a state of slow change, without disruptive technology next year will look a lot like this year.

Show Notes * The Rising Speed of Technological Adoption * Slack Certified * GDPR Fines and Notices

View Details

Josh and Kurt talk about the opportunistic nature of crime. Defenders have to defend, which means the adversaries are by definition always a step ahead. We use the context of automobile crimes to frame the discussion.

Show Notes * Stealing cars with radio relays * RTL Software Defined Radio * Canada most stolen car

View Details

Josh and Kurt talk to Rob Schultheis from GitHub about some of the amazing projects GitHub is working on. We discuss GitHub security advisories, getting a CVE from GitHub, and what the new GitHub Security Lab is doing. It's a great conversation about how GitHub is working to make security better for all of us.

Show Notes * GitHub Security Advisories * GitHub CVE requests * GitHub Security Lab * GitHub Security Lab Slack * GitHub Security Lab Twitter

View Details

Josh Santa and Kurt talk the border nightmare Santa Clause has to deal with as he traverses the globe. Questions we explore include: Are the reindeer farm animals? Is the North Pole a farm? Is Santa an intellectual property thief? Does Krampus eat politicians? Does Santa have a passport? Does Santa have an emergency radio?

Show Notes * Pirate Joes

View Details

Josh and Kurt talk about the security implications of planned obsolescence. We use Intel's recent decision to remove old drivers from their website as the start of the conversation. By the end we realize this is more of a decision society needs to understand and make more than anything. Is constantly throwing out technology OK?

Show Notes * Intel removes old drivers * Upgrading all versions of Windows * Sniffing your Smart TV

View Details

Josh and Kurt talk to Kathryn Waldron of the R Street Institute about a paper she recently published that collects a number of cybersecurity measuring devices in one place.

Show Notes * Kathryn Waldron * Kathryn's Twitter account * Resources for Measuring Cybersecurity * There are 14 standards

View Details

Josh and Kurt talk about banking and privacy. It's very likely nothing will get better anytime soon, humans will continue to be terrible at understanding certain risks. We also discuss what quantum supremacy means (or doesn't mean) for security.

Show Notes * National Bank Privacy Issues * Quantum Supremecy Claims * Hype Cycle * Scottish person talking to Siri * SMBC Quantum Comic

View Details

Josh and Kurt talk about government security incidents. The security concerns at the government level often have real life and death consequences. What happens when the leadership knowingly disregards security policy?

Show Notes * Breaking into a SCIF * Whitehouse cybersecurity team * Bugged typewriter

View Details

Josh and Kurt talk about the social norms of security. We also discuss security coprocessors and the reasons behind adding them to hardware. Is DRM a draconian security measure or do we need it to secure the future? We also touch on the story of NordVPN getting hacked. The real story isn't they got hacked, the story is they responded like clowns. The actual problem was one of leadership, there are certain leadership skills you can't be taught, you can only learn.

Show Notes * Before Windows boots protections

View Details

Josh and Kurt talk about the horrid state of digital literacy in the US. We start out talking about broken Phillips Hue light bulbs, then discuss research from Pew on the digital literacy of Americans. We may have accidentally discovered a use for all the cookie warnings every web site has.

Show Notes * Pew Research on American's Digitcal Literacy

View Details

Josh and Kurt about cybersecurity awareness month. What's our actionable advice we can give out? There isn't much which is a fundamental part of the problem.

Show Notes * Cybersecurity awareness month * Polar bear sized pigs

View Details

Josh and Kurt about a number of Microsoft security news items. They've changed how they are handling encrypted disks and are now forcing cloud logins on Windows users.

Show Notes * Microsoft KB 4516071 * A Security Market for Lemons * Kurt's file wiping advisory * Lock Picking Lawyer vs Consumer Reports * Sun Ray * Linux Gamers: <0.1% of sales but >20% of auto reported crashes

View Details

Josh and Kurt about DNS over HTTPS and how it may or may not destroy civilization. We also discuss the disruption of cloud in the context of security and touch on the news that GitHub is now a CVE CNA!

Show Notes * DNS over HTTPS * California Privacy Law * Defensive Security Podcast * GitHub is a CNA

View Details

Josh and Kurt about the upcoming Python 2 EOL. What does it mean, why does it matter, and what you can you do?

Show Notes * Python Clock * Python's statement about sunsetting Python 2 * wifi 6

View Details

Josh and Kurt speak with Allan Friedman of the US National Telecommunications and Information Administration about Software Bill of Materials. Where are we today, where are things going, and how you can help. 

Show Notes * Allan Friedman * NTIA * NTIA Software Component Transparency

View Details

Josh and Kurt start out discussing human nature and how it affects how we view security. A lot of things that look easy are actually really hard. We also talk about the npm library Standard showing command line ads. Are ads part of the future of open source?

Show Notes * thegrugq secure android * DoD JEDI program * Firefox privacy settings * Standard ads * Max Headroom

View Details

Josh and Kurt talk about disclosing security flaws in open source. This is part two of a discussion around how to disclose security issues. This episode focuses on some expectations and behaviors for open source projects as well as researchers trying to disclose a problem to a project.

Show Notes * webmin backdoor * Github security advisories

View Details

Josh and Kurt talk about disclosing security flaws. It's a topic that's come up a few times in the last few weeks and it's more complicated than it's ever been. We certainly ask more questions than we answer in this episode, there will be a part 2 that focuses on open source disclosure.

Show Notes * Lock Picking Lawyer * Tavis' Windows flaw

View Details

Josh and Kurt talk about the current state of credit security freezes in the US. We recount a thrilling tale of all the things Josh had to do to get new Internet service. It was all quite silly really.

Show Notes * Weak security freeze pins * 'null' license plate

View Details

Josh and Kurt talk about snakeoil cryptography at Black Hat and the new backdoored cryptography fight. Both of these problems will be with us for a very long time. These are fights worth fighting because it's the right thing to do.

Show Notes * Time AI video * Kurt's Tweet about technical explanations * Josh's blog post about bug training * Schneier on Barr's encryption discussion

View Details

Josh and Kurt talk about Kazakhstan requiring citizens to place a government controlled root CA certificate on their computers. How does this work. What does it mean for the citizens of Kazakhstan, and why we all should be paying attention.

Show Notes * Kazakhstan MitM all TLS traffic * Mozilla bug

View Details

Josh and Kurt talk about a new way to steal cars because a service didn't do proper background checks. We also discuss how this relates to working with criminals, such as ransomware, and what it means for the future of the ransomware industry.

Show Notes * Car2go theft * Alberta driver's license security * Albertosaurus * Las Vegas won't pay a ransom

View Details

Josh and Kurt talk to the authors of a new book The Fifth Domain. Dick Clarke and Rob Knake join us to discuss the book, cybersecurity, US policy, how we got where we are today and what the future holds for cybersecurity.

Show Notes * The Fifth Domain * Dick Clarke * Rob Knake * Future State Podcast

View Details

Josh and Kurt talk about user expectations around Facebook's AI. Normal people are starting to see the capabilities and potential risk with all these services. We also cover the topic of China owning a number of VPN services.

View Details

Josh and Kurt talk about the disclosure of security vulnerabilities. It's still not a settled topic, we frame the conversation around a recent disclosure from Tavis Ormandy of Google Project Zero.

View Details

Josh and Kurt talk to David Brumley. The CEO of ForAllSecure and professor at CMU. We discuss when David's team won the Cyber Grand Challenge, what the future of automated security looks like, and what ForAllSecure is doing. It's a fascinating window into the future of the industry.

View Details

Josh and Kurt talk about the future Chrome and ad blockers. There is a lot of nuance to unpack around this one. There are two versions of the Internet today. One with an ad blocker and one without. The Internet without an ad blocker is a dystopian nightmare. The actionable advice at the end of this one is to use Firefox.

View Details

Josh and Kurt have a chat with Michael Coates from Altitude Networks. We cover what Altitude is up to as well as general trends we're seeing around data security in the cloud. Michael lays out his vision for "data first security".

View Details

Josh and Kurt talk about public disclosure. We start out with a story about Canva, then discuss what do you do if you have a security incident? Who do you tell, what do you tell them. How do you tell your story? It's a really hard problem even if it's something you've done many times in the past.

View Details

Josh and Kurt talk about a new type of lockbox scams. We also discuss Slack being a target for nation state attacks. Do you consider your operations part of your supply chain?It's totally part of your supply chain.

View Details

Josh and Kurt talk about Microsoft. They're probably not the bad guys anymore, which is pretty wild. They're adding a Linux kernel to Window. Can we declare open source the unquestionable winner now?

View Details

Josh and Kurt talk about fire. We discuss the history of fire prevention and how it mirrors many of things we see in security. There are lessons there for us, we just hope it doesn't take 2000 years like it did for proper fire prevention to catch on.

View Details

Josh and Kurt talk about the security of money. Not how to keep it secure, but the security issues around using cash, credit, and bitcoin. We also talk about Banksy's clever method for proving something is original.

View Details

Josh and Kurt talk about the phone book (yeah, the big paper book people used to use). Kurt got one in the mail. While it's certainly a relic from another time, there were security tips in it among other wild things.

View Details

Josh and Kurt talk about what one could do if you find a USB drive. The context is based on the story where the Secret Service was rumored to have plugged a malicious USB drive into a computer. The purpose of discussion is to explore how to handle a situation like this in the real world. We end the episode with a fantastic comparison of swim safety and security.

View Details

Josh and Kurt talk about the difficulty of security. We look at the difficulty of the EU not observing daylight savings time, which is probably magnitudes easier than getting security right. We also hit on a discussion on Reddit about U2F that shows the difficulty. Security today is too hard, even for the experts.

View Details

Josh and Kurt talk about identity. It's a nice example we can generally understand in the context of how much security is enough security? When we deal with identity the idea of good enough is often acceptable for the vast majority of uses. Perfect identity tracking isn't really a thing nor is it practical.

View Details

Josh and Kurt talk about Brexit, voting, Firefox send, and toxic comments. Is there anything we can do to slow the current trend of conversation on the Internet always seeming to spiral out of control? The answer is maybe with a lot of asterisks.

View Details

Josh and Kurt talk about a prank gone wrong, the reality of when your data ends up public. Once it's public you can't ever put it back. We also discuss Notepad++ no longer signing releases and what signing releases means for the world in general.

View Details

Josh and Kurt talk about Beto being in the Cult of the Dead Cow (cDc). This is a pretty big deal in a very good way. We hit on some history, why it's a great thing, what we can probably expect from opponents. There's even some advice at the end how we can all help. We need more politicians with backgrounds like this.

View Details

Josh and Kurt talk about when devices attack! It's not quite that exciting, but there have been a slew of news about physical devices causing problems for humans. We end on the note that we're getting closer to a point when lawyers and regulators will start to pay attention. We're not there yet, so we still have a horrible insecure future on the horizon.

View Details

Josh and Kurt talk about github blocking the Deepfakes repository. There's a far bigger discussion about how people feel, and sometimes security fails to understand that making people feel happy or safer is more important than being right.

View Details

Josh and Kurt talk about change your password day (what a terrible day). Google's password checkup (not a terrible idea), an AI finding new spice flavors we expect will one day take over the world, and we finish up on a new DoD cloud strategy. Also Josh burnt his finger, but is going to be OK.

View Details

Josh and Kurt talk about the new runc container security flaw. How does the flaw work, what can you do about it, what should you do about it, and what the future of container security may look like.

View Details

Josh and Kurt talk about the fiasco hacks4pancakes described on Twitter and what the future of smart locks will look like. We then discuss what it means if the Japanese government starts hacking consumer IoT gear, is it ethical? Will it make anything better?

View Details

Josh and Kurt talk about the Bird Scooter vs Corey Doctorow incident. We then get into some of the social norms around new technology and what lessons the security industry can take from something new like shared scooters.

View Details

Josh and Kurt talk about non-Microsoft Windows micropatches. The days of pretending closed source matters are long gone. Google gets hit with a privacy fine, that probably won't matter. And Mastercard makes it easier for consumers to not accidentally sign up for services they don't want.

View Details

Josh and Kurt talk to Danny Grander one of the co-founders of Snyk about Zip Slip, what it is, how to fix it, and how they disclosed everything. We also touch on plenty of other open source security topics as Danny is involved in many aspects of open source security.

View Details

Josh and Kurt talk about the EU bug bounty program. There have been a fair number of people complaining it's solving the wrong problem, but it's the only way the EU has to spend money on open source today. If that doesn't change this program will fail.

View Details

Josh and Kurt talk about Australia's recently passed encryption bill. What is the law that was passed, what does it mean, and what are the possible outcomes? The show notes contain a flow chart of possible outcomes.

View Details

Josh and Kurt talk about which articles of the GDPR apply to Santa, and if he's following the rules the way he should be (spoiler, he's probably not). Should Santa be on his own naughty list? We also create a new holiday character - George the DPO Elf!

View Details

Josh and Kurt talk about Mozilla pulling a paywall bypassing extension. We then turn our attention to talking about walled gardens. Are they good, are they bad? Something in the middle? There is a lot of prior art to draw on here, everything from Windows, Android, iOS, even Linux distributions.

View Details

Josh and Kurt continue the discussion from episode 125. We look at the possible future of software supply chains. It's far less dire than previously expected. It's likely there will be some change in the

View Details

Josh and Kurt talk about how open source deals with malicious events. It's probably impossible to stop these from happening, but the open source universe deals with it in its own unique way. We start to discuss what you can do, since everyone is using open source everywhere now. There will be a second part to this episode where we discuss what the future holds for these sort of problems.

View Details

Josh and Kurt talk about Cloudflare's new Workers service. We spend a lot of time discussing how economics drives technology, not security. It's quite likely this new service is less secure than existing alternatives, but it will be cheaper and faster which will matter more than security.

View Details

Josh and Kurt talk to Liz Rice about Kubernetes and container security. How did we get where we are today, what's new and exciting today, and where do we think things are going.

View Details

Josh and Kurt talk about Apple's new T2 security chip. It's not open source but we expect it to change the security landscape in the coming years.

View Details

Josh and Kurt talk about voting security. What does it mean, how does it work. What works, what doesn't work, and most importantly why we may not see secure electronic voting anytime soon.

View Details

Josh and Kurt talk about Bloomberg's story about backdoors and motherboards. The story is probably false, but this is almost certainly happening already with hardware. What does it mean if your hardware is already backdoored by one or more countries?

View Details

Josh and Kurt talk about the Google+ and Facebook data incidents. We don't have any control over this data anymore. The incidents didn't really affect the users because we have no idea who has access to it. We also touch on GDPR and what it could mean in this context.

View Details

Josh and Kurt talk about Cloudflare's new IPFS and Onion services. One brings distributed blockchain files to the masses, the other lets you host your site on tor easily.

View Details

Josh and Kurt talk about Linus' effort to work on his attitude. What will this mean for security and IT in general?

View Details

Josh and Kurt talk to Michael Piacente from Hitch Partners about the past, present, and future role of the CISO in the industry.

View Details

Josh and Kurt talk to Brian Hajost from SteelCloud about public sector compliance. The world of public sector compliance can be confusing and strange, but it's not that bad when it's explained by someone with experience.

View Details

Josh and Kurt review Bruce Schneier's new book Click Here to Kill Everybody. It's a book everyone could benefit from reading. It does a nice job explaining many existing security problems in a simple manner.

View Details

Josh and Kurt talk about actual real world advice. Based on a story about trying to secure political campaigns, if we had to give some security help what should it look like, who should we give it to?

View Details

Josh and Kurt talk about the new Google Titan security key. There are some in the industry uneasy about the supply chain for the devices. We also discuss the latest Struts security issue. Struts is old and scary now, stop using it.

View Details

Josh and Kurt talk about TLS 1.3 and DNS. What can we expect from the future for these, how are they related (or not related). We touch on DNSSEC and why it probably won't matter. DNS over TLS is looking pretty great though. There is also a guest appearance from quantum crypto.

View Details

Josh and Kurt talk about Black Hat and Defcon and how unexciting they have become. What happened with hotels at Defcon, and more importantly how many security policies have 2nd and 3rd level effects we often can't foresee. We end with important information about pizzza, bananas, and can openers.

View Details

Josh and Kurt talk about phishing training and how it doesn't really matter. Josh spoke at OSCon and comes back with some fun observations and advice. People want practical actionable advice and we're not good at that.

View Details

Josh and Kurt talk about the latest attack on bluetooth and discuss phishing in the modern world. U2F is a great way to stop phishing, training is not. We also discuss airgaps in response to attacks on airgapped power utilities.

View Details

Josh and Kurt talk about modern hardware, how security relates to devices and actions. Everything from secure devices, to the cables we use, to thermal cameras and coat hangers. We end the conversation discussing the words we use and how they affect the way people see us and themselves.

View Details

Josh and Kurt talk about Cory Doctorow's piece on Facebook data privacy. It's common to call data the new oil but it's more like nuclear waste. How we fix the data problem in the future is going to require solutions we can't yet imagine as well as new ways of thinking about the problems.

View Details

Josh and Kurt talk about some recent backdoor problems in open source packages. We touch on is open source secure, how that security works, and what it should look like in the future. This problem is never going to go away or get better, and that's probably OK.

View Details

Josh and Kurt talk about the Gentoo security incident. Gentoo did a really good job being open and dealing with the incident quickly. The basic takeaway from all this is make sure your organization is forcing users to use 2 factor authentication. The long term solution is going to be all identity providers forcing everyone to use 2FA.

View Details

Josh and Kurt talk about a Microsoft Research paper titled "The Seven Properties of Highly Secure Devices". We take a real world view into how to secure our devices. What works, what doesn't work, and why this list is actually really good.

View Details

Josh and Kurt talk to Michael Feiertag, the CEO of tCell. We talk about what a Web Application Firewall is, what it does and doesn't do, and what the future of this technology looks like. We touch on how this affects a DevOps environment. Security has to fit into the existing model, not try to change it.

View Details

Josh and Kurt talk about Bird scooters. The implications of the scooters on the city, segways, bicycles. The topic of how these vehicles interact with pedestrians on the road and trails. It's an example of humans not wanting to follow the rules and generally making the situation annoying for everyone. It's the old security story of new technology without clear rules. The show ends with some horrifying numbers behind how bad things can get before people really care.

View Details

Josh and Kurt talk about how to be a smart security buyer. We have guest Steve Mayzak walk us through how a the buying process works as well as giving out a ton of great advice. Even if you're experienced with how to buy security technology you should give this a listen.

View Details

Josh and Kurt talk about a number of consumer security issues. The FBI told everyone to reboot their routers which they won't do. The .app top level domain is a cesspool of malware. Everyone has a cell phone and won't update them properly. None of this probably matters though. Unless there are real measurable tragedies caused by this tech, people tend not to really care.

View Details

Josh and Kurt talk about the NTSB report from the fatal Uber crash and what happened with Amazon's Alexa recording then emailing a private conversation. IT decisions now have real world consequences like never before.

View Details

Josh and Kurt talk about the security of automation as well as automating security. The only way automation will really work long term is full automation. Humans can't be trusted enough to rely on them to do things right.

View Details

Josh and Kurt talk about backdoors in code and products that have been put there on purpose. We talk about unlocking phones. Encryption backdoors with a focus on why they won't work.

View Details

Josh and Kurt talk about Twitter doing the right thing when they logged a lot of passwords and the npm malicious getcookies package and how backdoors work in code.

View Details

Josh and Kurt talk about the Amazon Route 53 incident and what it really means for the modern infrastructure. Complaining nobody is using DNSSEC or securing BGP aren't the right conversations to be having. Reality must be considered in any honest conversation about these topics.

View Details

Josh and Kurt talk about security flaws in beep and patch. How on earth were there security flaws in beep and patch?

View Details

Josh and Kurt talk to Rami Saas, the CEO of WhiteSource about 3rd party open source security as well as open source licensing.

View Details

Josh and Kurt talk to a 7 year old about security. We cover Minecraft security, passwords, hacking, and many many other nuggets of wisdom.

View Details

Josh and Kurt talk about all the current misinformation, how humans react to it, and what it means for security.

View Details

Josh and Kurt talk about the recent AMD flaws and the events surrounding the disclosure.

View Details

Josh and Kurt talk about container security with IBM's Chris Rosen.

View Details

Josh and Kurt talk about Let's Encrypt with co-founder Josh Aas. We discuss the past, present, and future of the project.

View Details

Josh and Kurt talk about the Trustico certificate incident and Let's Encrypt.

View Details

Josh and Kurt talk about the npm 5.7.0 debacle.

View Details

Josh and Kurt talk about the new password data dump from Have I been pwned?

View Details

Josh and Kurt talk about the XKCD CVE comic and a flight simulator stealing credentials.

View Details

Josh and Kurt talk about problems of textbook RSA implementations, the upcoming TLS changes in TLS, and the insecurity of http in Chrome.

View Details

Josh and Kurt talk about AutoSploit, bug bounties and fixing flaws, market forces in security, future expectations, and how humans perceive threats.

View Details

Josh and Kurt talk about GPS metadata giving away military bases and GPS jamming as part of testing.

View Details

Josh and Kurt talk about Skyfall, fake reports, risk, logging, and how a civilized society functions.

View Details

Josh and Kurt talk about the accidental missile warning in Hawaii. We also discuss general preparedness and risk.

View Details

Josh and Kurt talk about the recent npm happenings. What it means for the supply chain, and we end with some thoughts on how maybe none of this matters.

View Details

Josh and Kurt talk about the aftermath of Meltdown. The details of the flaw are probably less interesting than what happens now.

View Details

Josh and Kurt talk about the Security Planner website. It's pretty good all things considered.

View Details

Josh and Kurt talk about facial recognition, physical security, banking, and Amazon Alexa.

View Details

Josh and Kurt talk about basic security metrics and security from Santa. Is Santa GDPR compliant?

View Details

Josh and Kurt talk about Bitcoin, blockchain, and other cryptocurrencies.

View Details

Josh and Kurt talk about GitHub's security scanner and Linus' security email. We clarify the esoteric difference between security bugs and non security bugs.

View Details

Josh and Kurt talk about Intel ME, Equifax salary history, and IoT.

View Details

Josh and Kurt talk about Amazon Key and actionable advice.

View Details

Josh and Kurt talk about Facebook listening to your microphone, Google Chrome certificate pinning, CAs, 152 ways to stay safe, and Kubernetes.

View Details

Josh and Kurt talk about hacking back, passwords, honeypots, and conspiracies.

View Details

Josh and Kurt talk about Equifax again, Kaspersky, TLS CAs, coming change, social security numbers, and Minecraft.

View Details

Josh and Kurt talk about Apple, Equifax, passwords, AI, and aliens.

View Details

Josh and Kurt talk about networks, Dnsmasq, IoT, and our coming security dystopian future.

View Details

Josh and Kurt talk about the Equifax breach (again) and what it will mean for all of us. Blueborne comes up, as well as #TrevorForget.

View Details

Josh and Kurt talk about the Equifax breach and what it will mean for all of us.

View Details

Josh and Kurt talk about our lack of progress in security, economics, and how to interact with peers.

View Details

Josh and Kurt talk about the eclipse and blockchain.

View Details

Josh and Kurt talk about VPNs and the upcoming eclipse.

View Details

Josh and Kurt talk about MalwareTech, Debian killing off TLS 1.0 and 1.1, auto safety, HBO, and npm not typo squatting.

View Details

Josh and Kurt talk about Black Hat and Defcon, safes, banks, voting machines, SMBv1 DoS attack, Flash, liability, and password masking.

View Details

Josh and Kurt talk about forest fires, fuzzing, old time Internet, and Net Neutrality. Listen to Kurt play the Devil's Advocate and manage to change Josh's mind about net neutrality.

View Details

Josh and Kurt talk about Let's Encrypt, certificates, Kaspersky, A/V, code signing, Not Petya, self driving cars, and failures that become security problems.

View Details

Josh and Kurt talk about Canada Day, Not Petya, Interac goes down, Minecraft, airport security and books, then GDPR.

View Details

Josh and Kurt talk about security through obscurity, airplanes, the FAA, the Windows source code leak, and chicken sandwiches.

View Details

Josh and Kurt talk about the new StackClash flaw, Grenfell Tower, risk management, and backwards compatibility.

View Details

Josh and Kurt talk to Dan Adinolfi about CVE. Most anything you ever wanted to know about CVE is discussed.

View Details

Josh and Kurt discuss Futurama, tornadoes, sudo, encryption, hacking back, and something called an ombudsman. Also episode 50!

View Details

Josh and Kurt discuss Samba, FTP sites, MSDOS, regulation, and the airplane laptop travel ban.

View Details

Josh and Kurt have a guest! Mike Paquette from Elastic discusses the fundamentals and basics of Machine Learning. We also discuss how ML could have helped with WannaCry.

View Details

Josh and Kurt discuss the WannaCry worm.

View Details

Josh and Kurt discuss the recent Google phish attack.

View Details

Josh and Kurt discuss not-counterfeit MTG cards, antivirus, squirrelmail, unroll.me, grsecurity, baby monitors, and trust.

View Details

Josh and Kurt discuss Lego, bug bounties, pen testing, thought leadership, cars, lemons, entropy, and CVE.

View Details

Josh and Kurt discuss Shadow Brokers, pronouncing GIF, Atlanta's road problems, browser phishing, warning sirens, IoT, and fake Magic the Gathering cards.

View Details

Josh and Kurt discuss the security themes and events in the context of the HHGG movie.

View Details

Josh and Kurt discuss airplane laptop bans, ATM hacking, pointing at things, and Certificate Authorities.

View Details

Josh and Kurt discuss Verizon spyware, FCC privacy, Smart TVs, Tor's rewrite, Google's new operating system, bitcoin, and NanoCore.

View Details

Josh and Kurt discuss certificates, OpenSSL, dishwashers, Flash, and laptop travel bans.

View Details

Josh and Kurt discuss disclosing your password, pwn2own, wikileaks, Back Orifice, HTTPS inspection, and antivirus.

View Details

Josh and Kurt discuss how the Vault 7 leaks shows we live in the Neuromancer world, and this is likely the new normal.

View Details

Josh and Kurt discuss an IoT bear, Alexa and Siri, Google's E2Email and S/MIME.

View Details

Josh and Kurt discuss SHA-1 and cloudbleed. Bug bounties come up, and we compare security to the Higgs boson. We also discuss IPv6 at the end.

View Details

Josh and Kurt discuss RSA, the cryptographer's panel and of course, AI.

View Details

Josh and Kurt are at the same place at the same time! We discuss our RSA sessions and how things went. Talk of CVE IDs, open source libraries, Wordpress, and early morning sessions.

View Details

Josh and Kurt discuss random numbers, a lot. Also slot machines, gambling, and dice.

View Details

Josh and Kurt discuss door locks, Ikea, chair testing sounds, electrical safety, autonomous cars, and XML vs JSON.

View Details

Josh and Kurt discuss security automation. Machine learning, AI, and a bunch of moral and philosophical boundaries that new future will bring. You've been warned.

View Details

Josh and Kurt discuss the security of the movie Rogue One! Spoiler: Security in the Star Wars universe is worse than security in our universe.

View Details

Josh and Kurt discuss their involvement in the upcoming 2017 RSA conference: Open Source, CVEs, and Open Source CVE. Of course IoT and encryption manage to come up as topics.

View Details

Josh and Kurt discuss NTP, authentication issues, network security, airplane security, AI, and Minecraft.

View Details

Josh and Kurt end up discussing video game speed running, which is really just hacking. We also end up discussing the pitfalls of the modern world, you don't own your software or services. Stallman was right!

View Details

Josh and Kurt end up discussing CES, IoT, WiFi everywhere, and the future.

View Details

Josh and Kurt discuss 2016 predictions in 2017, what they got right, what they got wrong, and a bunch of other random things.

View Details

Josh and Kurt talk about scareware, malware, and how hard this stuff is to stop, and how the answer isn't fixing people.

View Details

Josh and Kurt talk about planned obsolescence and IoT devices. Should manufacturers brick devices? We also have a crazy discussion about the ethics of hacking back.

View Details

Josh and Kurt talk about CVE 10K. CVE IDs have finally crossed the line, we need 5 digits to display them. This has never happened before now.

View Details

Josh and Kurt talk about the death of PGP, and how it's not actually dead at all. It's still really hard to use though.

View Details

Josh and Kurt talk about the bricking devices (on purpose).

View Details

Josh and Kurt talk about the security concerns and logistics of Santa, elves, and the North Pole.

View Details

Josh and Kurt talk to Michael Goetzman about Cyphercon

View Details

Josh and Kurt talk about cybercrime and regulation.

View Details

Josh and Kurt talk about Cyber Monday security tips.

View Details

Josh and Kurt have a guest! David A. Wheeler talks about open source security and the CII Badges project.

View Details

Josh and Kurt talk about CVE, DWF, and the future of flaw reporting.

View Details

Josh and special guest host Dave Sirrine talk about feedback, OpenSSL, OAuth2, Let's Encrypt, disclosure, and locks.

View Details

Josh and special guest host Dave Sirrine talk about Halloween, passwords, hardware timing attacks, chip and pin, security economics, SSL/TLS, and Mozilla enabling TLS 1.3 by default.

View Details

Kurt and Josh discuss Dirty COW, the big IoT DDoS, and Josh can't pronounce Mirai or Dyn.

View Details

Kurt and Josh discuss responsible disclosure, irresponsible disclosure, bug bounties, measuring security, usability AND security, as well as quality of life.

View Details

Kurt and Josh discuss prime numbers (probably getting a lot of it wrong), Samsung, passwords, National Cyber Security Awareness Month, and bathroom scales.

View Details

Kurt and Josh discuss the ORWL computer, crashing systemd with one line, NIST, and a security journal.

View Details

Kurt and Josh discuss interesting news stories

View Details

Kurt and Josh discuss the recent OpenSSL update(s)

View Details

Josh and Kurt discuss news of the day, shipping, and container security

View Details

Josh and Kurt discuss news of the day, banks, 3D printing, and lockpicking.

View Details

Episode 2 of the Open Source Security Podcast

View Details

Episode 1 of the Open Source Security Podcast