TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Open Source Security

    Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

    There’s a lot of good work happening that doesn’t get attention because there’s no marketing department behind it, they don’t have a developer relations team posting on LinkedIn every two hours. Let’s focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what’s up, they have a lot to teach us. We just have to listen.

    Advertise

    Copyright: © This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 306 - Open source isn't broken, it's an experience Jan 17, 2022
    Show notes

    Josh and Kurt talk about the faker and colors NPM events. There is a lot of discussion around open source being broken or somehow failing because of these events. The real answer is open source is an experience. How we interact with our dependencies determines what the experience looks like.

    Show Notes
    • Developer corrupts colors and faker
    • Will Wright Pee
    • Internet Anonymity

    Episode 305 - Norton, Ethereum, NFT, and Apes Jan 10, 2022
    Show notes

    Josh and Kurt talk about Norton creating an Ethereum mining pool. This is almost certainly a bad idea, we explain why. We then discuss the reality of NFTs and the case of stolen apes. NFTs can be very confusing. The whole world of cryptocurrency is very confusing for normal people. None of this is new, there have always been con artists, there will always be con artists.

    Show Notes
    • Norton Crypto FAQ
    • Stolen Ape
    • Smart contract to buy the constitution
    • YEAR token

    Episode 304 - Will we ever fix all the vulnerabilities? Jan 03, 2022
    Show notes

    Josh and Kurt talk about the question will we ever fix all the vulnerabilities? The question came from Reddit and is very reasonable, but it turns out this is REALLY hard to discuss. The answer is of course "no", but why it is no is very complicated. Far more complicated than either of us thought it would be.

    Show Notes
    • Will cyber security vulnerabilities ever "stop existing" ?

    Episode 303 - Log4j Christmas Spectacular! Dec 27, 2021
    Show notes

    Josh and Kurt start the show with the reading of a security themed Christmas poem. We then discuss some of the new happenings around Log4j. The basic theme is that even if we were over-investing in Log4j, it probably wouldn't have caught this. There are still a lot of things to unpack with this event, I'm sure we'll be talking about it well into the future.

    Log before Christmas poem

    'Twas the night before Christmas, when all through the stack Not a scanner was scanning, not even a rack,

    The SBOMs were uploaded to the portal with care, In hopes that next year would be boring and bare

    The interns were nestled all snug at their beds; While visions of dashboards danced in their heads;

    The CISO in their 'kerchief, and I in my cap, Had just slept our laptops for a long winter's nap,

    When all of a sudden the pager went ack ack I sprang to my laptop with worries of attack

    Away to the browser I flew like a flash, Tore open the window and cleared out the cache

    The red of the dashboard the glow of the screen Gave a lustre of disaster my eyes rarely seen

    When what to my wondering eyes did we appear, But a new advisory and eight vulnerabilities to fear,

    Like a little old hacker all ready to play, I knew in a moment it must be Log4j

    More rapid than gigabit its coursers they came, And it whistled, and shouted, and called them by name:

    "Now, Log4Shell! now CVE! now ASF and NVD! On, CISA! on, LunaSec! on, GossiTheDog!

    To the top of the HackerNews! to the top of the wall! Now hack away! hack away! hack away all!"

    Like the bits that before the wild CDN fly by When they meet with a firewall, they mount to the sky;

    So up to the cloud like bastards they flew With tweets full of vulns, and Log4j too—

    And then, in a twinkling, I read in the slack The wailing and screaming of each analyst called back

    As I drew in my head, and was turning around, Down the network Log4j came with a bound.

    It was dressed in a hoodie, black and zipped tight, The clothes were all swag from a conference one night

    A bundle of vulns it had checked in its git And it looked like a pedler just being a twit

    The changelog—how it twinkled! its features, how merry! Its versions were like roses, its logo like a cherry!

    Its droll little mouth was drawn up like an at, And the beard on its chin made it look stupid and fat

    The stump of a diff it held tight in its teeth, And the bits, they encircled the repo like a wreath;

    It had a flashy readme an annoying little fad That shook when it downloaded, like a disk drive gone bad

    It was chubby and plump, an annoying old package, And I laughed when I saw it, in spite of the hackage

    A wink of its bits and a twist of its head Soon gave me to know I had everything to dread

    It spoke not a word, but went straight to its work, And pwnt all the servers; then turned with a jerk,

    And laying its patches aside of its nose, And giving a nod, up the network it rose;

    It sprang to its packet, to its team gave them more, And away they all fled leaving behind a back door

    But I heard it exclaim, ere it drove out of sight— "Merry Christmas you nerds, Log4j won tonight!"


    Episode 302 - Log4j is a mess Dec 20, 2021
    Show notes

    Josh and Kurt talk about the same topic everyone is talking about, Log4j. This episode was recorded on the Wednesday after the first Log4j issue. We point out all the gaps and difficulties for the defenders. The situation has gotten worse since then.

    Good luck to everyone dealign with this thing

    Show Notes
    • Log4j GSD entry
    • Minecraft server discussion
    • Log4j GitHub issue 608

    Episode 301 - You're holding it wrong: the importance of unlearning Dec 13, 2021
    Show notes

    Josh and Kurt talk about the epic failure that was episode 300. But this ties nicely into the topic of the day which is new ways to do things. The example is a new way to hold a controller when playing Tetris. There are always new tools and new ideas in security. Sometimes we have to abandon the old way because the new way to too good to ignore.

    Show Notes
    • Lawfare Apple NSO podcast
    • New way to play Tetris

    Episode 300 - Apple vs NSO: What can copyright do for you? Dec 06, 2021
    Show notes

    the lawsuit is based on CFAA, not on copyright. We apologize for this enormous oversight.

    Josh and Kurt talk about Apple suing NSO using a copyright claim as their vehicle. Copyright is often used as a reason to bring lawsuits, even when it doesn't always make sense. Copyright has been used by open source to expand rights, and many companies to restrict rights. It's a very odd law sometimes. At the end of the day it seems the only real path forward for a problem like NSO is up to governments to protect their citizens.

    Show Notes
    • Apple sues NSO group
    • VMWare EULA

    Episode 299 - Experts From A World That No Longer Exists Nov 29, 2021
    Show notes

    Josh and Kurt talk about an article about how expertise has a limited lifetime. We are all experts in something, but some of us will find our expert knowledge to be outdated eventually. We discuss what that means in the context of security and tech and disagree about how to best keep your skills up to date.

    Show Notes
    • Experts From A World That No Longer Exists
    • Neuroplasticity
    • Scotty and the mouse
    • Git 2.34
    • 4H Public Speaking

    Episode 298 - David A Wheeler discusses the OpenSSF Nov 22, 2021
    Show notes

    Josh and Kurt talk to David A. Wheeler about everything OpenSSF. The Open Source Security Foundation is part of the Linux Foundation, and there are 6 OpenSSF working groups. David does a great job explaining how the OpenSSF works and what the 6 working groups are doing. The working group are (in no particular order): Identifying Security Threats, Security Tooling, Best Practices, Vulnerability Disclosures, Digital Identity Attestation, Securing Critical Projects.

    Show Notes
    • David A Wheeler
    • Episode 14 – David A Wheeler: CII Badges
    • Sigstore joins the OpenSSF
    • OpenSSF Technical Working Groups
    • NPM requires MFA
    • LISH
    • Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks

    Episode 297 - 25 years of smashing stacks, fun, and profit Nov 15, 2021
    Show notes

    Josh and Kurt talk about the famous Phrack 49 article "Smashing the Stack for Fun and Profit" turning 25 years old. This paper created a massive amount of change in the industry, possibly more than any other paper ever written. Everything from making exploiting stack overflows easier, to defenders creating technologies such as stack canaries are the direct result of this work.

    Show Notes
    • Phrack 49
    • Kurt's Interview with Elias Levi aka Aleph One

    Previous 1 23 24 25 26 27 55 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights