Who's going to pay to fix open source security?

Who's going to pay to fix open source security?

Will no one think of the maintainers? As The New Stack points out, watching millions of projects fail because of a bug in an open source library has become common enough that we shrug and reply, "Told you so." It's gotten so bad, big tech companies are visiting the White House to discuss the issue as a matter of national security.

There is a great post up on the Stack Overflow blog examining this issue, but it's not about color.js, it's about Log4J. Traffic to questions on this logging library grew more than 1000% percent after the recent revelations about a new vulnerability.

Also discussed in this episode: cryptographer and Signal creator Moxie Marlinspike stepped down from his role as CEO of the encrypted messaging service. That's news, but he actually made bigger waves in tech circles with an unrelated blog post detailing his first experience with Web3. Spoiler alert: it's not as decentralized or divorced from Web2 as you might have thought.

You can find Cassidy Williams on Twitter and her website.

Ben Popper can be found on Twitter here.

Ryan Donovan can be found on Twitter, or writing for the Stack Overflow blog.

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Episoder(926)

Prevent agentic identity theft

Prevent agentic identity theft

Ryan is joined by Nancy Wang, CTO of 1Password, to discuss the security challenges local agents present, how enterprises can create robust governance of credentials through zero-knowledge architecture...

27 Mar 25min

Multi-stage attacks are the Final Fantasy bosses of security

Multi-stage attacks are the Final Fantasy bosses of security

Ryan welcomes Gee Rittenhouse, VP of Security at AWS, to the show to discuss the complexities of multi-stage attacks in cybersecurity and how these attacks unfold, the challenges in detecting them, an...

24 Mar 30min

After all the hype, was 2025 really the year of AI agents?

After all the hype, was 2025 really the year of AI agents?

Ryan is joined by Stefan Weitz, CEO and co-founder of the HumanX Conference, for a conversation on how AI has evolved in the last year. They discuss whether “the year of the agent” came to fruition, w...

20 Mar 32min

Building a global engineering team (plus AI agents) with Netlify

Building a global engineering team (plus AI agents) with Netlify

In this episode of Leaders of Code, Stack Overflow’s Chief of Product and Technology, Jody Bailey, sits down with Dana Lawson, CTO at Netlify. Dana shares her insights on leading a lean, globally dist...

19 Mar 29s

Keeping the lights on for open source

Keeping the lights on for open source

Ryan sits down with Chainguard CEO Dan Lorenc to chat about how his team is keeping the foundation of the internet—open source projects—alive by forking archived but widely-used repos to provide secur...

17 Mar 29min

Open source for awkward robots

Open source for awkward robots

Ryan is joined by Jan Liphardt,  CEO and co-founder of OpenMind, to chat about the rapidly evolving world of humanoid robotics and what it means for humans, why OpenMind is building an open source ope...

13 Mar 30min

Even the chip makers are making LLMs

Even the chip makers are making LLMs

Ryan welcomes Kari Briski, NVIDIA’s VP of Generative AI Software for Enterprise, to the show to explore how a chip manufacturer got into the model development game. They discuss NVIDIA’s co-design fee...

10 Mar 26min

Building brains for bulldozers

Building brains for bulldozers

Ryan chats with Kevin Peterson, CTO of Bedrock Robotics, about the evolution of self-driving technology and why robotics is now advancing; how real data is still relevant but simulation becomes essent...

6 Mar 24min

Populært innen Business og økonomi

lydartikler-fra-aftenposten
stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
pengepodden-2
livet-pa-veien-med-jan-erik-larssen
finansredaksjonen
pengesnakk
tid-er-penger-en-podcast-med-peter-warren
utbytte
stormkast-med-valebrokk-stordalen
morgenkaffen-med-finansavisen
okonomiamatorene
liberal-halvtime
rss-politisk-preik
rss-markedspuls-2
lederpodden
rss-pa-konto