A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.

Episode 397 - The curl and glibc vulnerabilities

October 15, 2023 34:25 33.04 MB Downloads: 0

Josh and Kurt talk about a curl and glibc bug. The bugs themselves aren't super interesting, but there are other conversations around the bugs that are interesting. Why don't we just rewrite everything in Rust? Why can't we just train developers to stop writing insecure code. How can AI solve this problem? It's a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won't change. Show Notes Curl vulnerability glibc vulnerability Josh's Badge Project Bob Lord's phishing message

Episode 396 - CLAs are bad, Mkay?

October 08, 2023 35:26 34.01 MB Downloads: 0

Josh and Kurt talk about contributor license agreements (CLAs). CLAs used to be seen as a necessary evil, but they're almost certainly bad now. We're seeing CLAs being abused, it's clear now anything controlled by a CLA won't be open source forever. Show Notes A Theory of Joint Authorship for Free and Open Source Software Projects Bruce Perens: What Comes After Open Source

Episode 395 - Uncertainty, trust, and security

October 01, 2023 33:47 32.41 MB Downloads: 0

Josh and Kurt talk about uncertainty. There are a bunch of stories in the news lately that really just boil down to uncertainty. Uncertainty is incredibly dangerous for everyone. We are afraid of uncertainty, and often don't really understand why it is. Trust is like a currency and uncertainty erodes trust faster than almost anything else. Show Notes Unity's license mess Godot Meta and Salesforce want to re-hire people they fired earlier this year U.S. Debt Credit Rating Downgraded, Only Second Time In Nation’s History

Episode 394 - The lie anyone can contribute to open source

September 24, 2023 35:48 34.35 MB Downloads: 0

Josh and Kurt talk about filing bugs for software. There's the old saying that anyone can file bugs and submit patches for open source, but the reality is most people can't. Filing bugs for both closed and open source is nearly impossible in many instances. Even if you want to file a bug for an open source project, there are a lot of hoops before it's something that can be actionable. Show Notes Linux is a nightmare Lodash just declared issue bankruptcy and closed every issue and open PR Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges Curl NULL pointer dereference

Episode 393 - Can you secure something you don't own?

September 17, 2023 33:47 32.42 MB Downloads: 0

Josh and Kurt talk about the weird world we live in how where we can't control a lot of our hardware. We don't really have control over most devices we interact with on a daily basis. The conversation shifts into a question of how can we decide what to trust and where. It's a very strange problem we experience now. Show Notes Boots theory MGM cybersecurity issue shuts down slot machines and ATMs in Las Vegas casinos New York Fire Department Forcible Entry Reference Guide Request for Information on Open-Source Software Security: Areas of Long-Term Focus and Prioritization

Episode 392 - Curl and the calamity of CVE

September 10, 2023 46:25 44.55 MB Downloads: 0

Josh and Kurt talk about why CVE is making the news lately. Things are not well in the CVE program, and it's not looking like anything will get fixed anytime soon. Josh and Kurt have a unique set of knowledge around CVE. There's a lot of confusion and difficulty in understanding how CVE works. Show Notes Curl blog post Now it's PostgreSQL's turn to have a bogus CVE GitHub Advisory Database Josh's "CVE tried to get me fired" story

Episode 391 - The Wordpress 100 year disaster recovery problem

September 03, 2023 39:11 37.6 MB Downloads: 0

Josh and Kurt talk about wordpress selling web services with a 100 year lifespan. Will WordPress still be around in 100 years? What would 100 years of disaster recovery look like? Most of us will never need to think about 100 years of disaster recovery. Show Notes WordPress is now selling 100-year domains Danish ransomware 15-Minute City The Year Without Pants

Episode 390 - Rust shipping binaries doesn't matter

August 27, 2023 39:19 37.74 MB Downloads: 0

Josh and Kurt talk about a blog post that explains how C and C++ compilers prioritize performance over correctness. This is the class story of security vs usability. Security is never the primary goal. If a security requirement doesn't also enable other business goals it will fail. We also touch on the news of a Rust package containing binary files. It doesn't really have anything to do with security, it's all about convenience. Show Notes C and C++ Prioritize Performance over Correctness Nisha's toot Barry Marshall Rust devs push back as Serde project ships precompiled binaries Why DARPA Hopes To 'Distill' Old Binaries Into Readable Code Mario 64 decompilation

Episode 389 - What would HashiCorp do?

August 20, 2023 42:16 40.57 MB Downloads: 0

Josh and Kurt talk about the HashiCorp license change and copyright problems in open source. This isn't the first and won't be the last time we see this, but it's very likely open source developers and communities will view any project that has a contributor license agreement as a problem moving forward. Show Notes Josh's BSidesLV talk Hacker News marked site as malware HashiCorp license change A Theory of Joint Authorship for Free and Open Source Software Projects

Episode 388 - Video game vulnerabilities

August 13, 2023 32:40 31.35 MB Downloads: 0

Josh and Kurt ask the question what is a vulnerability, but in the framing of video games. Security loves to categorize all bugs as security vulnerabilities or not security vulnerabilities. But the reality nothing is so simple. Everything is a question of risk, not vulnerability. The discussion about video games can help us to better have this discussion. Show Notes Colossus bug Minecraft Heist

Episode 387 - Enterprise open source is different

August 06, 2023 34:04 32.7 MB Downloads: 0

Josh and Kurt talk about the difference between what we think of as traditional open source, and enterprise software projects that have an open source license. They are both technically open source, but how the projects work is very very different. Show Notes CentOS Stream PR The Most Prolific Packager For Alpine Linux Is Stepping Away

Episode 386 - We are watching web 2.0 burn

July 30, 2023 31:41 30.41 MB Downloads: 0

Josh and Kurt talk about a new Google proposal that would add DRM for the web. All the ad driven companies seem to be acting very strangely, there's probably a reason for this. The way ads used to pay for content is changing, but a lot of these giant companies don't know how to adapt. It's going to be very interesting times in the near future. Show Notes Web Environment Integrity Hacker News Thread Island Browser hunter2

Episode 385 - Is open source an insider threat?

July 23, 2023 33:23 32.03 MB Downloads: 0

Josh and Kurt talk about insider threats, but not quite in the way one would expect. The potential for insider threats is possibly higher than usual right now, but what about open source? Are open source developers insider threats for your organization? Have you ever thought about this before? Show Notes CISA insider threats hacks4pancakes toot Don’t Trust a Programmer Who Knows C++ CISA Insider Threat Mitigation

Episode 384 - What's next for open source?

July 16, 2023 41:08 39.47 MB Downloads: 0

Josh and Kurt talk about some of the efforts to measure and understand open source. There are projects like the OpenSSF Scorecard. We want to measure open source for some idea of quality. Is AI generated code better than a random open source project found on GitHub? Can we track the countries contributors are from? These are all interesting problems that everyone will have to deal with soon. Show Notes OpenSSF Scorecard

Episode 383 - Is open source dying?

July 09, 2023 36:40 35.2 MB Downloads: 0

Josh and Kurt talk about the notion that open source is somehow dying. What's actually happening is corporate open source is changing, which some are trying to deform into something wrong with open source. Open source is doing great, probably better than ever. Show Notes Open Source isn't sustainable anymore VORON Design Video of the first lathe Plane Crazy Evernote layoffs