Open Source Security Podcast  By  cover art

Open Source Security Podcast

By: Josh Bressers & Kurt Seifried
  • Summary

  • A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.
    This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.
    Show more Show less
activate_primeday_promo_in_buybox_DT
Episodes
  • Episode 437 - CocoPods and proper funding for open source
    Jul 15 2024

    Josh and Kurt talk about a pretty big bug found in CocoPods ownership. We also touch on a paper that discusses the technical debt that open source should have. We discuss what the long term sustainability of open source. There aren't any good solutions for open source today, but talking about these problems is important, we have to start to understand what's going on before we can plausibly discuss solutions. If you're an open source project that needs to put things on pause, or even walk way, that's OK.

    Show Notes
    • CocoaPods Vulnerabilities Could Hit Apple, Microsoft, Facebook, TikTok, Snap and More
    • The Expense of Unprotected Free Software
    • Long-term maintenance of PCRE2 #426
    Show more Show less
    37 mins
  • Episode 436 - OpenSSH and node-ip - it's all exponential growth
    Jul 8 2024

    Josh and Kurt talk about the recent OpenSSH vulnerability and the node-ip project owner taking their project private. They're quasi related in the context of two open source projects handled bugs very differently. The OpenSSH bug isn't really as serious as it seems, but you still want to patch.

    The node-ip bug is a very different story. The relationship between users and open source developers is one experiencing more strain now than we've ever seen. It's a weird conversation and we don't have good answers. Security in general is a collection of unsolvable problems.

    Show Notes
    • Qualys security advisory
    • Hacker News Discussion
    • Security Cryptography Whatever
    • Dev rejects CVE severity, makes his GitHub repo read-only
    Show more Show less
    32 mins
  • Episode 435 - polyfill.io - open source is too big to fix
    Jul 1 2024

    Josh and Kurt talk about the latest polyfill.io mess. Apparently someone took over a very popular project and started to serve malware. First XZ, now this. What does it mean for open source? We don't have any answers, and it's hard to even talk about this problem because it's so big. The thing is though, even if we can't fix open source, it's here to stay.

    Show Notes
    • Polyfill supply chain attack hits 100K+ sites
    • OpenSSF Scorecard
    Show more Show less
    39 mins

What listeners say about Open Source Security Podcast

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.