Josh Bressers

Open Source Security

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have...

Author

Josh Bressers

Category

Technology

Podcast website

opensourcesecurity.io

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 111 - The TLS 1.3 and DNS episode 27.08.2018

Josh  and  Kurt  talk about TLS 1.3 and DNS. What can we expect from the future for these, how are they related (or not related). We touch on DNSSEC and why it probably won't matter. DNS over TLS is looking pretty great though. There is also a guest appearance from quantum crypto.

Episode 110 - Review of Black Hat, Defcon, and the effect of security policies 19.08.2018

Josh  and  Kurt  talk about Black Hat and Defcon and how unexciting they have become. What happened with hotels at Defcon, and more importantly how many security policies have 2nd and 3rd level effects we often can't foresee. We end with important information about pizzza, bananas, and can openers.

Episode 109 - OSCon and actionable advice 13.08.2018

Josh  and  Kurt  talk about phishing training and how it doesn't really matter. Josh spoke at OSCon and comes back with some fun observations and advice. People want practical actionable advice and we're not good at that.

Episode 108 - Bluetooth, phishing, airgaps, and eating soup off the floor 06.08.2018

Josh  and  Kurt  talk about the latest attack on bluetooth and discuss phishing in the modern world. U2F is a great way to stop phishing, training is not. We also discuss airgaps in response to attacks on airgapped power utilities.

Episode 107 - The year of the Linux Desktop and other hardware stories 30.07.2018

Josh  and  Kurt  talk about modern hardware, how security relates to devices and actions. Everything from secure devices, to the cables we use, to thermal cameras and coat hangers. We end the conversation discussing the words we use and how they affect the way people see us and themselves.

Episode 106 - Data isn't oil, it's nuclear waste 23.07.2018

Josh  and  Kurt  talk about Cory Doctorow's piece on Facebook data privacy. It's common to call data the new oil but it's more like nuclear waste. How we fix the data problem in the future is going to require solutions we can't yet imagine as well as new ways of thinking about the problems.

Episode 105 - More backdoors in open source 16.07.2018

Josh  and  Kurt  talk about some recent backdoor problems in open source packages. We touch on is open source secure, how that security works, and what it should look like in the future. This problem is never going to go away or get better, and that's probably OK.

Episode 104 - The Gentoo security incident 09.07.2018

Josh  and  Kurt  talk about the Gentoo security incident. Gentoo did a really good job being open and dealing with the incident quickly. The basic takeaway from all this is make sure your organization is forcing users to use 2 factor authentication. The long term solution is going to be all identity providers forcing everyone to use 2FA.

Episode 103 - The Seven Properties of Highly Secure Devices 02.07.2018

Josh  and  Kurt  talk about a Microsoft Research paper titled "The Seven Properties of Highly Secure Devices". We take a real world view into how to secure our devices. What works, what doesn't work, and why this list is actually really good.

Episode 102 - Michael Feiertag from tCell 25.06.2018

Josh  and  Kurt  talk to Michael Feiertag, the CEO of tCell. We talk about what a Web Application Firewall is, what it does and doesn't do, and what the future of this technology looks like. We touch on how this affects a DevOps environment. Security has to fit into the existing model, not try to change it. 

Episode 101 - Our unregulated future is here to stay 17.06.2018

Josh  and  Kurt  talk about Bird scooters. The implications of the scooters on the city, segways, bicycles. The topic of how these vehicles interact with pedestrians on the road and trails. It's an example of humans not wanting to follow the rules and generally making the situation annoying for everyone. It's the old security story of new technology without clear rules. The show ends with some hor...

Episode 100 - You're bad at buying security, we can help! 11.06.2018

Josh  and  Kurt  talk about how to be a smart security buyer. We have guest  Steve Mayzak  walk us through how a the buying process works as well as giving out a ton of great advice. Even if you're experienced with how to buy security technology you should give this a listen.

Episode 99 - Consumer security is too broken to fix, and it doesn't matter 04.06.2018

Josh  and  Kurt  talk about a number of consumer security issues. The FBI told everyone to reboot their routers which they won't do. The .app top level domain is a cesspool of malware. Everyone has a cell phone and won't update them properly. None of this probably matters though. Unless there are real measurable tragedies caused by this tech, people tend not to really care.

Episode 98 - When IT decisions kill people 28.05.2018

Josh  and  Kurt  talk about the NTSB report from the fatal Uber crash and what happened with Amazon's Alexa recording then emailing a private conversation. IT decisions now have real world consequences like never before.

Episode 97 - Automation: Humans are slow and dumb 20.05.2018

Josh  and  Kurt  talk about the security of automation as well as automating security. The only way automation will really work long term is full automation. Humans can't be trusted enough to rely on them to do things right.

Episode 96 - Are legal backdoors a good idea? 11.05.2018

Josh  and  Kurt  talk about backdoors in code and products that have been put there on purpose. We talk about unlocking phones. Encryption backdoors with a focus on why they won't work.

Episode 95 - Twitter passwords and npm backdoors 07.05.2018

Josh  and  Kurt  talk about Twitter doing the right thing when they logged a lot of passwords and the npm malicious getcookies package and how backdoors work in code.

Episode 94 - DNSSEC, BGP, and reality 30.04.2018

Josh  and  Kurt  talk about the Amazon Route 53 incident and what it really means for the modern infrastructure. Complaining nobody is using DNSSEC or securing BGP aren't the right conversations to be having. Reality must be considered in any honest conversation about these topics.

Episode 93 - Security flaws in beep and patch, how did we get here? 15.04.2018

Josh  and  Kurt  talk about security flaws in beep and patch. How on earth were there security flaws in beep and patch?

Episode 92 - Chat with Rami Saas the CEO of WhiteSource 15.04.2018

Josh  and  Kurt  talk to Rami Saas, the CEO of WhiteSource about 3rd party open source security as well as open source licensing.

Episode 91 - Security lessons from a 7 year old 08.04.2018

Josh and Kurt talk to a 7 year old about security. We cover Minecraft security, passwords, hacking, and many many other nuggets of wisdom.

Episode 90 - Humans and misinformation 02.04.2018

Josh  and  Kurt  talk about all the current misinformation, how humans react to it, and what it means for security.

Episode 89 - Short selling AMD security flaws 25.03.2018

Josh  and  Kurt  talk about the recent AMD flaws and the events surrounding the disclosure.

Episode 88 - Chat with Chris Rosen from IBM about Container Security 18.03.2018

Josh  and  Kurt  talk about container security with IBM's Chris Rosen.

Episode 87 - Chat with Let's Encrypt co-founder Josh Aas 11.03.2018

Josh  and  Kurt  talk about Let's Encrypt with co-founder Josh Aas. We discuss the past, present, and future of the project.

Listen to the Open Source Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.