TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Open Source Security

    Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

    There’s a lot of good work happening that doesn’t get attention because there’s no marketing department behind it, they don’t have a developer relations team posting on LinkedIn every two hours. Let’s focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what’s up, they have a lot to teach us. We just have to listen.

    Advertise

    Copyright: © This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 296 - Is Trojan Source a vulnerability? Nov 08, 2021
    Show notes

    Josh and Kurt talk about the new Trojan Source bug. We don't always agree on if this is a vulnerability (it's not), but by the end we come to an agreement that ASCII is out, Unicode is in. We don't live in a world where you can make a realistic suggestion to return to using only ASCII. There are a lot of weird moving parts with this one.

    Show Notes
    • Trojan Source
    • oss-security message
    • GitHub example

    Episode 295 - Open source security isn't free Nov 01, 2021
    Show notes

    Josh and Kurt talk about Josh's electric car and new job. We then talk about the recent UAParser.js malware incident. There have been a lot of calls to do more to secure open source, but nobody seems to have any concrete proposals or suggestions to fund any of these activities.

    Show Notes
    • UAParser.js
    • CISA announcement

    Episode 294 - Chris Wysopal on the state of security education Oct 25, 2021
    Show notes

    Josh and Kurt talk to Chris Wysopal, AKA Weld Pond, about security education. We talk about the current state of how we are learning about security as students and developers. What the best way to get developers interested in learning more about security? We end the show with fantastic advice from Chris for anyone new to the field of technology or security.

    Show Notes
    • Chris Wysopal
    • Veracode
    • l0phtcrack

    Episode 293 - Scoring OpenSSF Security Scoring Oct 18, 2021
    Show notes

    Josh and Kurt talk about the release of OpenSSF Security Scorecards version 3. This is a great project that will probably make a huge difference. Most of the things the scorecards are measuring are no brainier activities. We go through the list of metrics being measured. There are only a few that we don't think are fantastic.

    Show Notes
    • 4 of spades
    • OpenSSF
    • Chris Montgomery audio explanation
    • Scorecard 3.0.0
    • Scoring criteria
    • Python Skeleton

    Episode 292 - Apache RCE and Twitch epic pwn Oct 11, 2021
    Show notes

    Josh and Kurt talk about the recent Twitch hack and how in the modern age leaking source code almost certainly doesn't matter. The leaked data however is a big deal. We also discuss a recent Apache httpd update. Some things went right, some things went wrong. Dealing with vulnerabilities is hard.

    Show Notes
    • Parasocial Relationship
    • Twitch Hack
    • Soviet B-29 Clone
    • Apache CVE
    • Apache Advisory
    • GossiTheDog Tweet
    • Hacker Fantastic exploit

    Episode 291 - Everyone sucks at vulnerability disclosure Oct 04, 2021
    Show notes

    Josh and Kurt talk about recent events around Apple and Microsoft disclosing security vulnerabilities. Microsoft usually does a good job, but Apple has a long history of not having a great bug bounty or vulnerability disclosure policy. None of this is simple, but hopefully you'll have some fun and learn a bit about the whole vulnerability disclosure process.

    Show Notes
    • Apple 0days
    • Microsoft Exchange flaw
    • THIS IS HOW THEY TELL ME THE WORLD ENDS
    • Linux Foundation Vulnerability Disclosure
    • Timezone problem

    Episode 290 - The security of the Matrix Sep 27, 2021
    Show notes

    Josh and Kurt talk about the security of the Matrix movie series. There was a new Matrix trailer that made us want to discuss some of the security themes. We talk about how the movie is very focused on computing in the 90s. How Neo probably ran Linux and they used a real ssh exploit. How a lot of the plot is a bit silly. It's a really fun episode.

    Show Notes
    • Matrix 4 trailer
    • nmap in the Matrix
    • VFX Artists react to the Mandalorian
    • Glasshouse
    • Universal Paperclips

    Episode 289 - Who left this 0day on the floor? Sep 20, 2021
    Show notes

    Josh and Kurt talk about an unusual number of really bad security updates. We even recorded this before the Azure OMIGOD vulnerability was disclosed. It's certainly been a wild week with Apple and Chrome 0days, and a Travis CI secret leak. Maybe this is the new normal.

    Show Notes
    • Matrix 4 trailer
    • Travis CI issue
    • Apple 0day patches
    • Chrome 0day patches
    • CGP Grey Where is the European Union

    Episode 288 - Linux Kernel compiler warnings considered dangerous Sep 13, 2021
    Show notes

    Josh and Kurt talk about some happenings in the Linux Kernel. There are some new rules around how to submit patches that goes against how GitHub works. They're also turning all compiler warnings into errors. It's really interesting to understand what these steps mean today, and what they could mean in the future.

    Show Notes
    • The Register Linux story
    • OpenSSL Release Notes

    Episode 287 - Is GitHub's Copilot the new Clippy? Sep 06, 2021
    Show notes

    Josh and Kurt talk about GitHub Copilot. What can we learn from a report claiming 40% of code generated by Copilot has security vulnerabilities? Is this the future or just some sort of strange new thing that will be gone as fast as it came?

    Show Notes
    • GitHub Copilot
    • Copilot research paper

    Previous 1 24 25 26 27 28 55 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights