TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Open Source Security

    Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

    There’s a lot of good work happening that doesn’t get attention because there’s no marketing department behind it, they don’t have a developer relations team posting on LinkedIn every two hours. Let’s focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what’s up, they have a lot to teach us. We just have to listen.

    Advertise

    Copyright: © This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 316 - You have to use open source Mar 28, 2022
    Show notes

    Josh and Kurt talk about the latest NPM backdoored package. It feels like this keeps happening. We talk about why this is and why it's probably OK. Kurt fixes Linus' Law, in open source the superpower isn't bugs are shallow (they're not), the superpower is security bugs in open source can't be ignored.

    Show Notes
    • node-ipc protestware

    Episode 315 - Who even makes all these terrible decisions? Mar 21, 2022
    Show notes

    Josh and Kurt talk about Microsoft accidentally letting us find out about ads in file explorer. Changing your clocks sucks. And touch on some of the security implications of the Russian invasion and sanctions. There are a lot of security lessons we can all learn. Mostly what not to do.

    Show Notes
    • Ads in Windows Filemanager
    • Russia running out of storage
    • Russia threatens to nationalize industry
    • Onagawa Nuclear Power Plant
    • Cockcroft's Follies
    • German government advises citizens to uninstall Kaspersky

    Episode 314 - The Linux Dirty Pipe vulnerability Mar 14, 2022
    Show notes

    Josh and Kurt talk about the Linux Kernel Dirty Pipe security vulnerability. This bug is an amazing combination of amazing complexity, incredible simplicity, and a little bit of luck. The discovery is amazing, the analysis is enlightening. There's almost no way a bug like this could be found outside of open source.

    Show Notes
    • Dirty Pipe Writeup

    Episode 313 - Insecurity at scale Mar 07, 2022
    Show notes

    Josh and Kurt talk about the challenges of security at scale. Specifically we focus on why a lot of security starts to fall apart once you have to do something more than a few times. There's a lot of new thinking we need to push security forward.

    Show Notes
    • Stable Linux Kernel and Machine Learning

    Episode 312 - The Legend of the SBOM Feb 28, 2022
    Show notes

    Josh and Kurt talk about SBOMs. Not what they are, there's plenty about that. We talk about why everyone keeps claiming they're super important, and why we're starting to see some people question if we really need them. SBOMs are part of a future that's still being invented.

    Show Notes
    • Questioning SBOMs
    • Rezilion Log4j diagram
    • David A Wheeler on CII Badges
    • Using open source is communism

    Episode 311 - Did you scan the QR code? Feb 21, 2022
    Show notes

    Josh and Kurt talk about the Coinbase Super Bowl ad. It was a QR code, lots of security people were aghast at how many people scanned the QR code. The reality is scanning QR codes isn't dangerous. What other security advice just won't go away?

    Show Notes
    • Coinbase Ad
    • Kurt's Twitter question
    • QR code parking scam
    • Mossad or not Mossad
    • Kurt's talk

    Episode 310 - Hayley Tsukayama from the EFF talks about privacy Feb 14, 2022
    Show notes

    Josh and Kurt talk to Hayley Tsukayama from the EFF about privacy. We all know privacy in the modern age is very complicated and difficult. Normal people don't have many allies when it comes to privacy. The EFF has been blazing the trail for digital rights for more than 30 years! This episode has a ton of amazing details, it's easy to see how the EFF became the jewel of the Internet.

    Show Notes
    • Hayley's Twitter
    • EFF
    • How to Fix the Internet
    • Episode 277 – Privacy and activism with Chris Weiland
    • Washington State privacy bill
    • Join the EFF (seriously, do this!)

    Episode 309 - The bright future of open source security Feb 07, 2022
    Show notes

    Josh and Kurt talk about NPM requiring 2FA for the top 100 packages. We discuss the new Alpha and Omega projects from the OpenSSF and what it could mean for the future of open source security. Then we end on a note about the new Samba critical vulnerability.

    Show Notes
    • NPM requires 2FA
    • OpenSSF Alpha and Omega
    • David A. Wheeler episode
    • Linux Foundation LFX
    • Samba Advisory

    Episode 308 - Welcome to the jungle - How to talk about open source security Jan 31, 2022
    Show notes

    Josh and Kurt talk about how to get attention for security problems. Recent research around Twitter credentials checked into GitHub showed us how to get a lot of attention when compared to a problem like Log4Shell which took years before anyone really picked up on the problem. It's hard to talk about security sometimes.

    Show Notes
    • Josh's computer vision code
    • Twitter secrets
    • Qualys pwnkit

    Episode 307 - Got vulnerabilities? Introducing GSD Jan 24, 2022
    Show notes

    Josh and Kurt talk about the Global Security Database (GSD) project. This is a Cloud Security Alliance (CSA) effort to build community around vulnerability identifiers.

    Show Notes
    • We rate dogs
    • Racoons that heal your sadness
    • Global Security Database
    • Episode 261 – DWF is back! Welcome to community powered CVE
    • GSD mailing list
    • GSD Circle group
    • GSD Database
    • GSD Project Plan

    Previous 1 22 23 24 25 26 55 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights