Episode 286 - Open source supply chain with Google's Dan Lorenc

Episode 286 - Open source supply chain with Google's Dan Lorenc

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(527)

Episode 285 - Open source owes you nothing!

Episode 285 - Open source owes you nothing!

Josh and Kurt talk about open source bugs. What happens if a project decides to close most of their bugs? Nothing really. Bug trackers aren't a help desk. Show Notes Emacs closes 45% of bugs UVI Tesl...

23 Aug 202132min

Episode 284 - What happens when we DRM power tools?

Episode 284 - What happens when we DRM power tools?

Josh and Kurt talk about a Home Depot plan to put DRM on power tools. Anyone can add a computer to anything for a few dollars now. How secure is any of this. What does it mean when the things we buy s...

16 Aug 202135min

Episode 283 - When vulnerability disclosure becomes dangerous

Episode 283 - When vulnerability disclosure becomes dangerous

Josh and Kurt talk about a very difficult disclosure problem. What happens when you have to report a vulnerability to an ethically questionable company? It's less simple than it sounds, many of the ch...

9 Aug 202134min

Episode 282 - The security of Rust: who left all this awesome in here?

Episode 282 - The security of Rust: who left all this awesome in here?

Josh and Kurt talk about a story from Microsoft declaring Rust the future of safe programming, replacing C and C++. We discuss how tooling affects progress and why this isn't always obvious when you'r...

2 Aug 202130min

Episode 281 - If you spy on journalists, you're the bad guys

Episode 281 - If you spy on journalists, you're the bad guys

Josh and Kurt talk about the news that the NSO Group is widely distributing spyware onto a large number of devices. This news should be a wake up call for anyone creating devices and systems that coul...

26 Jul 202132min

Episode 280 - The perils of Single Sign On

Episode 280 - The perils of Single Sign On

Josh and Kurt talk about what happens when you lose access to your Single Sign On provider. These providers have become critical to many of us, if we lose access to our SSO account we will lose access...

19 Jul 202130min

Episode 279 - The audacity of Audacity: When open source goes rogue

Episode 279 - The audacity of Audacity: When open source goes rogue

Josh and Kurt talk about the events happening to the Audacity audio editor. What happens if a popular open source application is acquired by an unknown entity? Can this happen to other open source pro...

12 Jul 202131min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
rss-impressions-2
rss-heis
tomprat-med-gunnar-tjomlid
rss-ai-forklart
shifter
elektropodden
fornybaren
rss-alt-vi-kan
smart-forklart
kortslutning
teknologi-og-mennesker
rss-polypod
rss-praktisk-proptech
rss-ki-praten
rss-grenser-for-ki