Josh Bressers
Open Source Security
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have...
Author
Josh Bressers
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 260 - Dave Jevans tells us what CipherTrace is up to 01.03.2021 29:20
Josh and Kurt talk with Dave Jevans CEO of CipherTrace and chairman of the anti-phishing working group about the challenges of keeping track of cryptocurrency in the modern age. Show Notes Dave's Twitter CipherTrace Anti Phishing Working Group
Episode 259 - What even is open source anymore? 22.02.2021 33:10
Josh and Kurt talk about the question "what is open source?" Why do we think it's broken today, and what sort of ideas about what should come next. Show Notes OSI Bruce Perens Post Open Source Josh's community blog post Corey Doctorow Uber Twitter thread
Episode 258 - Stop using C 15.02.2021 30:21
Josh and Kurt talk about the Google Project Zero report titled "A Year in Review of 0-days Exploited In-The-Wild in 2020". It's a cool report but we don't agree on the conclusion. The answer isn't to security harder, it's to stop using C. Show Notes Google Project Zero Year of 0-days Kurt's CUPS tweet
Episode 257 - The sudo and libgcrypt vulnerabilities 08.02.2021 31:42
Josh and Kurt talk about the recent sudo and libgcrypt security vulnerabilities. What's the deal with these buffer overflows and TOCTU bugs? Show Notes Sudo buffer overflow Sudo SELinux bug libgcrypt buffer overflow
Episode 256 - 9 bits of podcast, 8 bits of computing 01.02.2021 31:47
Josh and Kurt talk about 8 bit computing. What sort of security lessons can we learn from the 8 bit world? More than you think. Show Notes Legend of Zelda Random Number Generation Green rocket flame SR71 leaked fuel How do Namibian Himbas see colour? Suptuple meter music
Episode 255 - What if security wasn't joyless? 25.01.2021 30:19
Josh and Kurt talk about what we can stop doing. We take a position of asking "does it spark joy" for tools and infrastructure. Everyone is doing something they should stop. Show Notes Does it spark joy?
Episode 254 - Right to Repair Security 18.01.2021 30:56
Josh and Kurt talk about the new right to repair rules in the EU. There's a strange line between loving the idea of right to repair, but also being horrified as security people at the idea of a device being on the Internet for 30 years. Show Notes EU right to repair repair.eu
Episode 253 - Defenders only need to be right once 11.01.2021 32:22
Josh and Kurt talk about this idea that seems to exist in security of "attackers only need to be right once" which is silly. The reality is attackers have to get everything right, defenders really only need to get it right once. But "defenders only need to be right once" isn't going to sell any products. Show Notes Richard Feynman and manhole covers Richard Feynman on Why He Can't Tell You How Mag...
Episode 252 - Is open source dangerous? Open source won, who cares, shut up! 04.01.2021 28:56
Josh and Kurt talk about a report on open source security from the Canadian Centre for Cyber Security. The title pretty much sums it up. Show Notes Security Considerations for Open Source Build an 8 bit computer from scratch
Episode 251 - Communication is hard, security communication is more hard 28.12.2020 31:26
Josh and Kurt talk about communication. It's really hard to talk about a lot of what we do. How do we know if a device is secure? How do we know our knowledge is correct? Show Notes 90 percent of U.S. bills carry traces of cocaine Is the moon a star or planet? A mole of moles New homeowner 'freaked out' when stranger took control of her security system Coffee maker ransomware NIST Phish Scale The...
Episode 250 - Door 25: Why do we do the things we do? Question everything 25.12.2020 6:54
Josh and Kurt talk about why we do the things we do. Sometimes we have to question everything. Links SLAM missile
Episode 249 - Door 24: Information wants to be free 24.12.2020 5:44
Josh and Kurt talk about the idea of information wanting to be free. It's Christmas, we should give it what it wants! Links Hacker Manifesto
Episode 248 - Door 23: How to report 1000 security flaws 23.12.2020 5:25
Josh and Kurt talk about how to file 1000 security flaws. One is easy, scale is hard.
Episode 247 - Door 22: How to report one security flaw 22.12.2020 5:14
Josh and Kurt talk about how to report one security flaw
Episode 246 - Door 21: Bug bounties 21.12.2020 5:00
Josh and Kurt talk about bug bounties
Episode 245 - Door 20: Is SMS 2FA better than no 2FA? 20.12.2020 5:08
Josh and Kurt talk about if SMS 2 factor auth is better than no 2FA Links Cyber deepfaked their host
Episode 244 - Door 19: TLS certificate trust 19.12.2020 5:23
Josh and Kurt talk about modern TLS certificate trust
Episode 243 - Door 18: Don't roll your own crypto or auth 18.12.2020 5:01
Josh and Kurt talk about why it's a horrible idea to roll your own crypto or auth
Episode 242 - Door 17: Vulnerability response 17.12.2020 5:00
Josh and Kurt talk about vulnerability response. What is it, what does it mean, how does it work
Episode 241 - Door 16: 16 bits of change 16.12.2020 5:04
Josh and Kurt talk about the switch from 16 to 32 to 64 bit and even the changes from Intel to ARM
Episode 240 - Door 15: Supplier compliance 15.12.2020 5:10
Josh and Kurt talk about supplier compliance Links Annex A.15.1 of ISO 27001:2013 Episode 162 – SBOM with Allan Friedman
Episode 239 - Door 14: Backdoors 14.12.2020 5:06
Josh and Kurt talk about backdoors in open source software
Episode 238 - Door 13: Unlucky or survivor bias? 13.12.2020 4:59
Josh and Kurt talk about the unluckiest man in the world and survivor bias Links Unluckiest man in the world
Episode 237 - Door 12: Video game hacking 12.12.2020 4:54
Josh and Kurt talk about video game hacking. The speedrunners are doing the best security research today Links Super Mario World RCE
Episode 236 - Door 11: Should you get on a 737? 11.12.2020 5:04
Josh and Kurt talk about the safety of a 737 Links FAA says 737 is safe
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.