Episode 286 - Open source supply chain with Google's Dan Lorenc

Episode 286 - Open source supply chain with Google's Dan Lorenc

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(527)

Episode 302 - Log4j is a mess

Episode 302 - Log4j is a mess

Josh and Kurt talk about the same topic everyone is talking about, Log4j. This episode was recorded on the Wednesday after the first Log4j issue. We point out all the gaps and difficulties for the def...

20 Des 202133min

Episode 301 - You're holding it wrong: the importance of unlearning

Episode 301 - You're holding it wrong: the importance of unlearning

Josh and Kurt talk about the epic failure that was episode 300. But this ties nicely into the topic of the day which is new ways to do things. The example is a new way to hold a controller when playin...

13 Des 202131min

Episode 300 - Apple vs NSO: What can copyright do for you?

Episode 300 - Apple vs NSO: What can copyright do for you?

the lawsuit is based on CFAA, not on copyright. We apologize for this enormous oversight. Josh and Kurt talk about Apple suing NSO using a copyright claim as their vehicle. Copyright is often used as ...

6 Des 202131min

Episode 299 - Experts From A World That No Longer Exists

Episode 299 - Experts From A World That No Longer Exists

Josh and Kurt talk about an article about how expertise has a limited lifetime. We are all experts in something, but some of us will find our expert knowledge to be outdated eventually. We discuss wha...

29 Nov 202134min

Episode 298 - David A Wheeler discusses the OpenSSF

Episode 298 - David A Wheeler discusses the OpenSSF

Josh and Kurt talk to David A. Wheeler about everything OpenSSF. The Open Source Security Foundation is part of the Linux Foundation, and there are 6 OpenSSF working groups. David does a great job exp...

22 Nov 202138min

Episode 297 - 25 years of smashing stacks, fun, and profit

Episode 297 - 25 years of smashing stacks, fun, and profit

Josh and Kurt talk about the famous Phrack 49 article "Smashing the Stack for Fun and Profit" turning 25 years old. This paper created a massive amount of change in the industry, possibly more than an...

15 Nov 202133min

Episode 296 - Is Trojan Source a vulnerability?

Episode 296 - Is Trojan Source a vulnerability?

Josh and Kurt talk about the new Trojan Source bug. We don't always agree on if this is a vulnerability (it's not), but by the end we come to an agreement that ASCII is out, Unicode is in. We don't li...

8 Nov 202133min

Episode 295 - Open source security isn't free

Episode 295 - Open source security isn't free

Josh and Kurt talk about Josh's electric car and new job. We then talk about the recent UAParser.js malware incident. There have been a lot of calls to do more to secure open source, but nobody seems ...

1 Nov 202133min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
rss-impressions-2
rss-heis
tomprat-med-gunnar-tjomlid
rss-ai-forklart
shifter
elektropodden
fornybaren
rss-alt-vi-kan
smart-forklart
kortslutning
teknologi-og-mennesker
rss-polypod
rss-praktisk-proptech
rss-ki-praten
rss-grenser-for-ki