Open Source Security Podcast

By: Josh Bressers & Kurt Seifried
  • Summary

  • A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.
    This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.
    Show More Show Less
activate_samplebutton_t1
Episodes
  • Episode 448 - What's wrong with CISA?
    Sep 30 2024

    Josh and Kurt talk about a few things that have recently come out of CISA. They seem to be blaming the vendors for a lot of the problems, but there's also not any actionable advice telling the vendors what they should be doing. This feels like the classic case of "just security harder". We need CISA to be leading the way funding and defining security, not blaming vendors for giving the market what it demands.

    Show Notes
    • iCloud Photos Downloader
    • CISA boss: Makers of insecure software must stop enabling today's cyber villains
    • A Security Market for Lemons
    • CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities
    • CISA Secure by Design Pledge
    • Railroad Newsletter
    • CISA Secure Software Development Attestation Form
    Show More Show Less
    35 mins
  • Episode 447 - The Tidelift 2024 open source maintainer report
    Sep 23 2024

    Josh and Kurt talk about the 2024 Tidelift maintainer report. The report is pretty big and covers a ton of ground. We focus in a few of the statistics that should worry anyone who uses open source. We've known for a while developers are struggling, and the numbers back that up. This one feels like the old "we've tried nothing and we're all out of ideas".

    Show Notes
    • THE 2024 TIDELIFT STATE OF THE OPEN SOURCE MAINTAINER REPORT
    • Canadian passport
    • Changelog Interviews #433
    • Pandas CVE
    Show More Show Less
    39 mins
  • Episode 446 - Researchers took over .MOBI TLD
    Sep 16 2024

    Josh and Kurt talk about some security researchers sort of taking over the .MOBI whois server. The story is a bit sensational, but we ask if it really matters? There are a lot of interesting possible attacks, but turning something like this into a good attack is really hard, maybe impossible. The researchers presented the findings in a very reasonable way.

    Show Notes
    • We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
    • Heinz says sorry for ketchup QR code that links to porn site
    Show More Show Less
    33 mins

What listeners say about Open Source Security Podcast

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.

In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.