Open Source Security

Open Source Security

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.

Avsnitt(526)

Episode 445 - EPSS with Jay Jacobs

Episode 445 - EPSS with Jay Jacobs

Josh and Kurt talk to Jay Jacobs about Exploit Prediction Scoring System (EPSS). EPSS is a new way to view vulnerabilities. It's a metric for the likelyhood that a vulnerability will be exploited in t...

9 Sep 202441min

Episode 444 - Open Source and End of Life

Episode 444 - Open Source and End of Life

Josh and Kurt talk about Chrome unexpectedly going EOL on Ubuntu 18. Keeping old things alive is really hard to do, and in open source it's becoming more common to just run the latest version rather t...

2 Sep 202437min

Episode 443 - The Supply Chain Security Crisis

Episode 443 - The Supply Chain Security Crisis

Josh and Kurt talk about a story that discusses a story from Black Hat that references supply chains. There's a ton of doom and gloom around our software supply chains and much of the advice isn't rea...

26 Aug 202434min

Episode 442 - The foundation of society, TLS certificates are a mess

Episode 442 - The foundation of society, TLS certificates are a mess

Josh and Kurt talk about a few stories around the TLS CA certificate world. It's all pretty dire sounding. There's not a lot of organization or process in the space, and the root CAs are literally the...

19 Aug 202440min

Episode 441 - Is CWE useful?

Episode 441 - Is CWE useful?

Josh and Kurt talk about CWE. What is it, and why does it matter. We cover some history, some shortcomings, and some ideas on how CWE could be used to make security a lot better. We frame the future d...

12 Aug 202433min

Episode 440 - "What is open source" talk Josh gave

Episode 440 - "What is open source" talk Josh gave

Josh and Kurt talk about a presentation Josh recently gave that was supposed to be about how open source works. The talk was the wrong topic for a security crowd, but there's a lot of interesting deta...

5 Aug 202434min

Episode 439 - Where are all the youth in open source?

Episode 439 - Where are all the youth in open source?

Josh and Kurt talk about a story talking about the "graying" of open source. There doesn't seem to be many young people working on open source, but we don't really know why that is. There are many tho...

29 Juli 202429min

Episode 438 - CISA's bad OSS advice vs the Whitehouse good advice

Episode 438 - CISA's bad OSS advice vs the Whitehouse good advice

Josh and Kurt talk about two documents from the US government that discuss open source in very different ways. The CISA document lays out a way to measure open source, but we take issue with the idea ...

22 Juli 202434min

Populärt inom Teknik

natets-morka-sida
uppgang-och-fall
elbilsveckan
market-makers
rss-technokratin
bilar-med-sladd
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
bli-saker-podden
skogsforum-podcast
rss-veckans-ai
rss-powerboat-sverige-podcast
hej-bruksbil
rss-it-sakerhetspodden
rss-fabriken-2
har-vi-akt-till-mars-an
rss-snacka-om-ai
rss-uppgang-och-fall
rss-en-ai-till-kaffet
under-femton