Open Source Security Podcast

Josh Bressers & Kurt Seifried

  • 26 minutes 17 seconds
    Modern day authentication with Marc Boorshtein

    In this discussion with Tremolo Security CTO Marc Boorshtein, we explore what modern day Single Sign-On (SSO) looks like. Everyone likes to talk about zero trust, but how does that work? We talk about some of the history of authentication that got us here, and some technical details on how you should be implementing authentication into your application. We finish up with some passkey details and realize every authentication discussion really just turns into complaining how hard identity is.

    The blog post for this episode can be found at

    https://opensourcesecurity.io/2025/2025-02-modern_day_authentication_with_marc_boorshtein/

    3 February 2025, 12:00 am
  • 19 minutes 44 seconds
    Government Security Requirements with Dick Brooks

    Dick Brooks from Business Cyber Guardian discusses the landscape of federal software security requirements, we discuss frameworks like CISA's Software Acquisition Guide, Secure Software Development Framework, and the EU's Cyber Resilience Act. These regulations impact open source projects differently from commercial vendors, Dick helps explain what that means for the vendors as well as open source developers.

    The accompaning blog can be found at

    https://opensourcesecurity.io/2025/01-government_security_requirements_with_dick_brooks

     

     

    CISA Software Acquisition Guide CISA SAG Reader Project NASA SSDF collaboration

    27 January 2025, 12:00 am
  • 27 minutes 18 seconds
    Open Source Maintenance with Gary Kramlich

    In this episode, Gary Kramlich, the lead developer of Pidgin discusses the challenges and strategies of maintaining a 26-year-old open source messaging client.Gary tell us all about how a small team manages technical debt, handles library dependencies, and makes decisions about rewrites versus incremental improvements while supporting a broader open source ecosystem.

    The accompaning blog can be found at

    https://opensourcesecurity.io/2025/01-open_source_maintenance_with_gary_kramlich/

    20 January 2025, 12:21 am
  • 21 minutes 23 seconds
    Safety vs Security with Thomas Depierre

    In this episode of Open Source Security, Josh welcomes Thomas Depierre, a Site Reliability Engineer and open source maintainer, to discuss the intersection of safety and security. Thomas explains why safety is broader than security. While security often views people as the problem, Thomas explains that people are paradoxically the solution. Nothing should work, but it does, mostly due to people keeping things working.

     

    The accompaning blog can be found at

    https://opensourcesecurity.io/2025/01-safety_vs_security_with_thomas_depierre/

    13 January 2025, 1:56 pm
  • 4 minutes 28 seconds
    The Future of Open Source Security

    It’s a new year and time for some changes to the opensourcesecurity.io website.

     

    It's time to retire the podcast, but that's to make way for something new and hopefully better. You can read the details in the blog post (the audio version is basically the same thing)

    https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/

    1 January 2025, 2:24 pm
  • 36 minutes 7 seconds
    Episode 461 - The new NIST password guidance

    Josh and Kurt talk about new NIST password guidance. There's some really good stuff in this new document. Ideas like usability and equity show up (which is amazing). There's more strict guidance against rotating passwords and complex passwords. This new guidance gives us a lot to look forward to.

    Show Notes
    30 December 2024, 12:00 am
  • 43 minutes 29 seconds
    Episode 460 - Santa's Supply Chain Security

    Josh and Kurt talk about the supply chain of Santa. Does he purchase all those things? Are they counterfeit goods? Are they acquired some other way? And once he has all the stuff, the logistics of getting it to the sleigh is mind boggling. It's all very complex

    Show Notes
    23 December 2024, 12:00 am
  • 36 minutes 1 second
    Episode 459 - CWE Top 25 List

    Josh and Kurt talk about a CWE Top 25 list from MITRE. The list itself is fine, but we discuss why the list looks the way it does (it's because of WordPress). We also discuss why Josh hates lists like this (because they never create any actions). We finish up running through the whole list with a few comments about the findings.

    Show Notes
    16 December 2024, 12:00 am
  • 33 minutes 43 seconds
    Episode 458 - FBI endorses E2E encryption

    Josh and Kurt talk about the FBI telling everyone to use end to end encrypted messengers. This is a pretty drastic deviation from messages in the past. The reason for this is it appears the US telephone networks are pwnt beyond repair at this point, which is concerning. The only real solution now is to treat the phone network as untrusted and encrypt all the traffic.

    Show Notes
    9 December 2024, 12:00 am
  • 41 minutes
    Episode 457 - The D-Link D-bacle

    Josh and Kurt talk about a serious D-Link security vulnerability in a bunch of end of life products. The crux of the discussion focuses on D-Link, but the reality is almost all consumer gear you plug into the internet is terrible. And there's little hope it will get better anytime soon.

    Show Notes
    2 December 2024, 12:00 am
  • 33 minutes 42 seconds
    Episode 456 - What if XZ happened to a company? The openness of open source

    Josh and Kurt embark on a thought experiment to discuss how a commercial entity would handle something like the xz incident. It was very specific and difficult to understand. It's easy to claim just because source code being available doesn't matter. But the reality is when source code is needed, it can make a huge difference for everyone working together, just like we saw with xz.

    Show Notes
    25 November 2024, 12:00 am
  • More Episodes? Get the App
© MoonFM 2025. All rights reserved.