Episode 286 - Open source supply chain with Google's Dan Lorenc

Episode 286 - Open source supply chain with Google's Dan Lorenc

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(527)

Episode 285 - Open source owes you nothing!

Episode 285 - Open source owes you nothing!

Josh and Kurt talk about open source bugs. What happens if a project decides to close most of their bugs? Nothing really. Bug trackers aren't a help desk. Show Notes Emacs closes 45% of bugs UVI Tesl...

23 Aug 202132min

Episode 284 - What happens when we DRM power tools?

Episode 284 - What happens when we DRM power tools?

Josh and Kurt talk about a Home Depot plan to put DRM on power tools. Anyone can add a computer to anything for a few dollars now. How secure is any of this. What does it mean when the things we buy s...

16 Aug 202135min

Episode 283 - When vulnerability disclosure becomes dangerous

Episode 283 - When vulnerability disclosure becomes dangerous

Josh and Kurt talk about a very difficult disclosure problem. What happens when you have to report a vulnerability to an ethically questionable company? It's less simple than it sounds, many of the ch...

9 Aug 202134min

Episode 282 - The security of Rust: who left all this awesome in here?

Episode 282 - The security of Rust: who left all this awesome in here?

Josh and Kurt talk about a story from Microsoft declaring Rust the future of safe programming, replacing C and C++. We discuss how tooling affects progress and why this isn't always obvious when you'r...

2 Aug 202130min

Episode 281 - If you spy on journalists, you're the bad guys

Episode 281 - If you spy on journalists, you're the bad guys

Josh and Kurt talk about the news that the NSO Group is widely distributing spyware onto a large number of devices. This news should be a wake up call for anyone creating devices and systems that coul...

26 Juli 202132min

Episode 280 - The perils of Single Sign On

Episode 280 - The perils of Single Sign On

Josh and Kurt talk about what happens when you lose access to your Single Sign On provider. These providers have become critical to many of us, if we lose access to our SSO account we will lose access...

19 Juli 202130min

Episode 279 - The audacity of Audacity: When open source goes rogue

Episode 279 - The audacity of Audacity: When open source goes rogue

Josh and Kurt talk about the events happening to the Audacity audio editor. What happens if a popular open source application is acquired by an unknown entity? Can this happen to other open source pro...

12 Juli 202131min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
natets-morka-sida
rss-laddstationen-med-elbilen-i-sverige
bli-saker-podden
rss-elektrikerpodden
gubbar-som-tjotar-om-bilar
rss-technokratin
skogsforum-podcast
rss-uppgang-och-fall
developers-mer-an-bara-kod
rss-sakerhetspodcasten
rss-veckans-ai
rss-powerboat-sverige-podcast
rss-digitala-influencer-podden
rss-en-ai-till-kaffet
rss-upplyst-entreprenordirektor
rss-fabriken-2