Josh Bressers

Open Source Security

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have...

Author

Josh Bressers

Category

Technology

Podcast website

opensourcesecurity.io

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 135 - Passwords, AI, and cloud strategy 25.02.2019

Josh  and  Kurt  talk about change your password day (what a terrible day). Google's password checkup (not a terrible idea), an AI finding new spice flavors we expect will one day take over the world, and we finish up on a new DoD cloud strategy. Also Josh burnt his finger, but is going to be OK.

Episode 134 - What's up with the container runc security flaw? 18.02.2019

Josh  and  Kurt  talk about the new runc container security flaw. How does the flaw work, what can you do about it, what should you do about it, and what the future of container security may look like.

Episode 133 - Smart locks and the government hacking devices 11.02.2019

Josh  and  Kurt  talk about the fiasco hacks4pancakes described on Twitter and what the future of smart locks will look like. We then discuss what it means if the Japanese government starts hacking consumer IoT gear, is it ethical? Will it make anything better?

Episode 132 - Bird Scooter: 0, Cory Doctorow: 1 04.02.2019

Josh  and  Kurt  talk about the Bird Scooter vs Corey Doctorow incident. We then get into some of the social norms around new technology and what lessons the security industry can take from something new like shared scooters.

Episode 131 - Windows micropatches, Google's privacy fine, and Mastercard fixes trial abuse 28.01.2019

Josh  and  Kurt  talk about non-Microsoft Windows micropatches. The days of pretending closed source matters are long gone. Google gets hit with a privacy fine, that probably won't matter. And Mastercard makes it easier for consumers to not accidentally sign up for services they don't want.

Episode 130 - Chat with Snyk co-founder Danny Grander 21.01.2019

Josh  and  Kurt  talk to Danny Grander one of the co-founders of Snyk about Zip Slip, what it is, how to fix it, and how they disclosed everything. We also touch on plenty of other open source security topics as Danny is involved in many aspects of open source security.

Episode 129 - The EU bug bounty program 14.01.2019

Josh  and  Kurt  talk about the EU bug bounty program. There have been a fair number of people complaining it's solving the wrong problem, but it's the only way the EU has to spend money on open source today. If that doesn't change this program will fail.

Episode 128 - Australia's encryption backdoor bill 07.01.2019

Josh  and  Kurt  talk about Australia's recently passed encryption bill. What is the law that was passed, what does it mean, and what are the possible outcomes? The show notes contain a flow chart of possible outcomes.

2018 Christmas Special - Is Santa GDPR compliant? 24.12.2018

Josh  and  Kurt  talk about which articles of the GDPR apply to Santa, and if he's following the rules the way he should be (spoiler, he's probably not). Should Santa be on his own naughty list? We also create a new holiday character - George the DPO Elf!

Episode 127 - Walled gardens, appstores, and more 17.12.2018

Josh  and  Kurt  talk about Mozilla pulling a paywall bypassing extension. We then turn our attention to talking about walled gardens. Are they good, are they bad? Something in the middle? There is a lot of prior art to draw on here, everything from Windows, Android, iOS, even Linux distributions.

Episode 126 - The not so dire future of supply chain security 10.12.2018

Josh  and  Kurt  continue the discussion from episode 125. We look at the possible future of software supply chains. It's far less dire than previously expected. It's likely there will be some change in the

Episode 125 - Open Source, supply chains, npm, and you 03.12.2018

Josh  and  Kurt  talk about how open source deals with malicious events. It's probably impossible to stop these from happening, but the open source universe deals with it in its own unique way. We start to discuss what you can do, since everyone is using open source everywhere now. There will be a second part to this episode where we discuss what the future holds for these sort of problems.

Episode 124 - Cloudflare's service workers and the economics of security 26.11.2018

Josh  and  Kurt  talk about Cloudflare's new Workers service. We spend a lot of time discussing how economics drives technology, not security. It's quite likely this new service is less secure than existing alternatives, but it will be cheaper and faster which will matter more than security.

Episode 123 - Talking about Kubernetes and container security with Liz Rice 19.11.2018

Josh  and  Kurt  talk to  Liz Rice  about Kubernetes and container security. How did we get where we are today, what's new and exciting today, and where do we think things are going.

Episode 122 - What will Apple's T2 chip mean for the rest of us? 12.11.2018

Josh  and  Kurt  talk about Apple's new T2 security chip. It's not open source but we expect it to change the security landscape in the coming years.

Episode 121 - All about the security of voting 05.11.2018

Josh  and  Kurt  talk about voting security. What does it mean, how does it work. What works, what doesn't work, and most importantly why we may not see secure electronic voting anytime soon.

Episode 120 - Bloomberg and hardware backdoors - it's already happening 29.10.2018

Josh  and  Kurt  talk about Bloomberg's story about backdoors and motherboards. The story is probably false, but this is almost certainly happening already with hardware. What does it mean if your hardware is already backdoored by one or more countries?

Episode 119 - The Google+ and Facebook incidents, it's not your data anymore 22.10.2018

Josh  and  Kurt  talk about the Google+ and Facebook data incidents. We don't have any control over this data anymore. The incidents didn't really affect the users because we have no idea who has access to it. We also touch on GDPR and what it could mean in this context.

Episode 118 - Cloudflare's IPFS and onion service 15.10.2018

Josh  and Kurt  talk about Cloudflare's new IPFS and Onion services. One brings distributed blockchain files to the masses, the other lets you host your site on tor easily.

Episode 117 - Will security follow Linus' lead on being nice? 08.10.2018

Josh  and  Kurt  talk about Linus' effort to work on his attitude. What will this mean for security and IT in general?

Episode 116 - The future of the CISO with Michael Piacente 01.10.2018

Josh  and  Kurt  talk to Michael Piacente from Hitch Partners about the past, present, and future role of the CISO in the industry.

Episode 115 - Discussion with Brian Hajost from SteelCloud 24.09.2018

Josh  and  Kurt  talk to Brian Hajost from SteelCloud about public sector compliance. The world of public sector compliance can be confusing and strange, but it's not that bad when it's explained by someone with experience.

Episode 114 - Review of "Click Here to Kill Everybody" 17.09.2018

Josh  and  Kurt  review Bruce Schneier's new book Click Here to Kill Everybody. It's a book everyone could benefit from reading. It does a nice job explaining many existing security problems in a simple manner.

Episode 113 - Actual real security advice 10.09.2018

Josh  and  Kurt  talk about actual real world advice. Based on a story about trying to secure political campaigns, if we had to give some security help what should it look like, who should we give it to?

Episode 112 - Google's Titan Key and the latest Struts issue 03.09.2018

Josh  and  Kurt  talk about the new Google Titan security key. There are some in the industry uneasy about the supply chain for the devices. We also discuss the latest Struts security issue. Struts is old and scary now, stop using it.

Listen to the Open Source Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.