Episode 286 - Open source supply chain with Google's Dan Lorenc

Episode 286 - Open source supply chain with Google's Dan Lorenc

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(528)

Episode 255 - What if security wasn't joyless?

Episode 255 - What if security wasn't joyless?

Josh and Kurt talk about what we can stop doing. We take a position of asking "does it spark joy" for tools and infrastructure. Everyone is doing something they should stop. Show Notes Does it spark ...

25 Tammi 202130min

Episode 254 - Right to Repair Security

Episode 254 - Right to Repair Security

Josh and Kurt talk about the new right to repair rules in the EU. There's a strange line between loving the idea of right to repair, but also being horrified as security people at the idea of a device...

18 Tammi 202130min

Episode 253 - Defenders only need to be right once

Episode 253 - Defenders only need to be right once

Josh and Kurt talk about this idea that seems to exist in security of "attackers only need to be right once" which is silly. The reality is attackers have to get everything right, defenders really onl...

11 Tammi 202132min

Episode 252 - Is open source dangerous? Open source won, who cares, shut up!

Episode 252 - Is open source dangerous? Open source won, who cares, shut up!

Josh and Kurt talk about a report on open source security from the Canadian Centre for Cyber Security. The title pretty much sums it up. Show Notes Security Considerations for Open Source Build an 8 ...

4 Tammi 202128min

Episode 251 - Communication is hard, security communication is more hard

Episode 251 - Communication is hard, security communication is more hard

Josh and Kurt talk about communication. It's really hard to talk about a lot of what we do. How do we know if a device is secure? How do we know our knowledge is correct? Show Notes 90 percent of U.S...

28 Joulu 202031min

Episode 250 - Door 25: Why do we do the things we do? Question everything

Episode 250 - Door 25: Why do we do the things we do? Question everything

Josh and Kurt talk about why we do the things we do. Sometimes we have to question everything. Links SLAM missile

25 Joulu 20206min

Episode 249 - Door 24: Information wants to be free

Episode 249 - Door 24: Information wants to be free

Josh and Kurt talk about the idea of information wanting to be free. It's Christmas, we should give it what it wants! Links Hacker Manifesto

24 Joulu 20205min

Episode 248 - Door 23: How to report 1000 security flaws

Episode 248 - Door 23: How to report 1000 security flaws

Josh and Kurt talk about how to file 1000 security flaws. One is easy, scale is hard.

23 Joulu 20205min