Open Source Security Podcast show

Open Source Security Podcast

Summary: A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.

Join Now to Subscribe to this Podcast
  • Visit Website
  • RSS
  • Artist: Josh Bressers & Kurt Seifried
  • Copyright: Some rights reserved (CC BY-NC-SA 3.0)

Podcasts:

 Episode 168 - The draconian draconians of DRM | File Type: audio/mpeg | Duration: 30:55

Josh and Kurt talk about the social norms of security. We also discuss security coprocessors and the reasons behind adding them to hardware. Is DRM a draconian security measure or do we need it to secure the future? We also touch on the story of NordVPN getting hacked. The real story isn't they got hacked, the story is they responded like clowns. The actual problem was one of leadership, there are certain leadership skills you can't be taught, you can only learn.

 Episode 167 - Security is terrible because digital literacy is terrible | File Type: audio/mpeg | Duration: 35:19

Josh and Kurt talk about the horrid state of digital literacy in the US. We start out talking about broken Phillips Hue light bulbs, then discuss research from Pew on the digital literacy of Americans. We may have accidentally discovered a use for all the cookie warnings every web site has.

 Episode 166 - Every day should be cybersecurity awareness month! | File Type: audio/mpeg | Duration: 24:39

Josh and Kurt about cybersecurity awareness month. What's our actionable advice we can give out? There isn't much which is a fundamental part of the problem.

 Episode 165 - Grab Bag of Microsoft Security News | File Type: audio/mpeg | Duration: 27:45

osh and Kurt about a number of Microsoft security news items. They've changed how they are handling encrypted disks and are now forcing cloud logins on Windows users.

 Episode 164 - DNS over HTTPS: Probably not the end of the world | File Type: audio/mpeg | Duration: 30:03

Josh and Kurt about DNS over HTTPS and how it may or may not destroy civilization. We also discuss the disruption of cloud in the context of security and touch on the news that GitHub is now a CVE CNA!

 Episode 163 - Death to Python 2 | File Type: audio/mpeg | Duration: 33:22

Josh and Kurt about the upcoming Python 2 EOL. What does it mean, why does it matter, and what you can you do?

 Episode 162 - SBOM with Allan Friedman | File Type: audio/mpeg | Duration: 30:35

Josh and Kurt speak with Allan Friedman of the US National Telecommunications and Information Administration about Software Bill of Materials. Where are we today, where are things going, and how you can help.

 Episode 161 - Human nature and ad powered open source | File Type: audio/mpeg | Duration: 29:19

Josh and Kurt start out discussing human nature and how it affects how we view security. A lot of things that look easy are actually really hard. We also talk about the npm library Standard showing command line ads. Are ads part of the future of open source?

 Episode 160 - Disclosing security issues is insanely complicated: Part 2 | File Type: audio/mpeg | Duration: 31:11

Josh and Kurt talk about disclosing security flaws in open source. This is part two of a discussion around how to disclose security issues. This episode focuses on some expectations and behaviors for open source projects as well as researchers trying to disclose a problem to a project.

 Episode 159 - Disclosing security issues is insanely complicated: Part 1 | File Type: audio/mpeg | Duration: 29:23

Josh and Kurt talk about disclosing security flaws. It's a topic that's come up a few times in the last few weeks and it's more complicated than it's ever been. We certainly ask more questions than we answer in this episode, there will be a part 2 that focuses on open source disclosure.

 Episode 158 - The mess that we call credit agencies in the US | File Type: audio/mpeg | Duration: 27:48

Josh and Kurt talk about the current state of credit security freezes in the US. We recount a thrilling tale of all the things Josh had to do to get new Internet service. It was all quite silly really.

 Episode 157 - Backdoors and snake oil in our cryptography | File Type: audio/mpeg | Duration: 30:58

Josh and Kurt talk about snakeoil cryptography at Black Hat and the new backdoored cryptography fight. Both of these problems will be with us for a very long time. These are fights worth fighting because it's the right thing to do.

 Episode 156 - What if we MitM a whole country? | File Type: audio/mpeg | Duration: 29:57

Josh and Kurt talk about Kazakhstan requiring citizens to place a government controlled root CA certificate on their computers. How does this work. What does it mean for the citizens of Kazakhstan, and why we all should be paying attention.

 Episode 155 - Stealing cars and ransomware | File Type: audio/mpeg | Duration: 27:22

Josh and Kurt talk about a new way to steal cars because a service didn't do proper background checks. We also discuss how this relates to working with criminals, such as ransomware, and what it means for the future of the ransomware industry.

 Episode 154 - Chat with the authors of the book "The Fifth Domain" | File Type: audio/mpeg | Duration: 31:17

Josh and Kurt talk to the authors of a new book The Fifth Domain. Dick Clarke and Rob Knake join us to discuss the book, cybersecurity, US policy, how we got where we are today and what the future holds for cybersecurity.

Comments

Login or signup comment.