TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Open Source Security

    Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

    There’s a lot of good work happening that doesn’t get attention because there’s no marketing department behind it, they don’t have a developer relations team posting on LinkedIn every two hours. Let’s focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what’s up, they have a lot to teach us. We just have to listen.

    Advertise

    Copyright: © This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 205 - The State of Open Source Security with Alyssa Miller from Snyk Jul 13, 2020
    Show notes

    Josh and Kurt talk to Alyssa Miller from Snyk about the State of Open Source Security 2020 report. Alyssa was the report author and has some great insight into the current trends we're seeing in open source security. Some of the challenges developers face. We discuss the difficulty static and composition analysis scanners face. It's a great conversation!

    Show Notes

    • The State of Open Source Security 2020
    • Alyssa's Twitter

    Episode 204 - What Would Apple Do? Jul 06, 2020
    Show notes

    Josh and Kurt talk about some recent security actions Apple has taken. Not all are good, but in general Apple is doing things to benefit their customers (their customers are not advertisers). We also discuss some of the challenges when your customers are advertisers.

    Show Notes

    • Apple one year certificates
    • Apple declines to implement 16 new APIs
    • Apple is tracking unsigned executables

    Episode 203 - Humans, conferences, and security: let me think and get back to you in a bit Jun 29, 2020
    Show notes

    Josh and Kurt talk about human behavior. The conversation makes its way to conferences and the perpetual question of if a conference is useful or not. We come to the agreement the big shows aren't what they used to be, but things like BSides are great experiences.

    Show Notes

    • Security and Human Behaviour
    • Josh's blog post
    • Mudge's Twitter thread

    Episode 202 - The convergence of application security Jun 22, 2020
    Show notes

    Josh and Kurt talk about the security of applications. We talk about the security of infrastructure all the time, but what happens when we combine infrastructure into an application or solution?

    Show Notes
    • Picture of Kurt's security check-up
    • Dragon controls

    Episode 201 - We broke CVSSv3, now how do we fix it? Jun 15, 2020
    Show notes

    Josh and Kurt talk about CVSSv3 and how it's broken. We started with a blog post to explain why the NVD CVSS scores are so wrong, and we ended up researching CVSSv3 and found out it's far more broken than any of us expected in ways we didn't expect. NVD isn't broken, CVSSv3 is. How did we get here? Are there any options that work today? Where should we go next?

    Show Notes
    • Josh's blog post
    • NVD
    • Red Hat security data
    • Josh's CVE data project
    • Microsoft security ratings scale

    Episode 200 - Talking Container Security with Liz Rice Jun 08, 2020
    Show notes

    Josh and Kurt talk to Liz Rice from Aqua Security about container security and her new book on the same topic. What does container security look like today? What are some things you can do now? What will container security look like in the future?

    Show Notes
    • Container Security download
    • Pictures of elephants
    • Kubernetes Security book
    • Starboard project
    • Dynamic threat analysis

    Episode 199 - Special cases are special: DNS, Websockets, and CSV Jun 01, 2020
    Show notes

    Josh and Kurt talk about a grab bag of topics. A DNS security flaw, port scanning your machine from a web browser, and CSV files running arbitrary code. All of these things end up being the result of corner cases. Letting a corner case be part of a default setup is always a mistake. Yes always, not even that one time.

    Show Notes

    • Bind advisory
    • Robustness Principal
    • eBay port scanning localhost
    • OWASP CSV injection

    Episode 198 - Good advice or bad advice? Hang up, look up, and call back May 25, 2020
    Show notes

    Josh and Kurt talk about the Krebs blog post titled "When in Doubt: Hang Up, Look Up, & Call Back". In the world of security there isn't a lot of actionable advice, it's worth discussing if something like this will work, or ever if it's the right way to handle these situations.

    Show notes

    • When in Doubt: Hang Up, Look Up, & Call Back
    • Tech Support Scam podcast: Part 1, Part 2
    • STIR/SHAKEN
    • Drill the wrong safe deposit box
    • 2009 Bank of Ireland robbery

    Episode 197 - Beer, security, and consistency; the newer, better, triad May 17, 2020
    Show notes

    Josh and Kurt talk about what beer and reproducible builds have in common. It's a lot more than you think, and it mostly comes down to quality control. If you can't reproduce what you do, you're not a mature organization and you need maturity to have quality.

    Show Notes
    • Reinheitsgebot
    • Josh's Blog Post
    • Ken Thompson's reflections on trusting trust
    • Tor Browser Deterministic Builds
    • One line package broke npm create
    • Donkey Kong 64 memory leak

    Episode 196 - Pounding square solutions into round holes: forced updates from Ubuntu May 11, 2020
    Show notes

    Josh and Kurt talk about automatic updates. Specifically we discuss a recent decision by Ubuntu to enable forced automatic updates. There are lessons here for the security community. We have a history of jumping to solutions rather than defining and understanding problems. Sometimes our solutions aren't the best. Also murder bees.

    Show Notes
    • The Oatmeal giant bee comic
    • Honeybees cook giant hornet
    • Ubuntu 20.04 LTS' snap obsession has snapped me off of it
    • Forum discussion

    Previous 1 33 34 35 36 37 55 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights