simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

The latest episode of the appropriately named "XZ Bonus Spectacular Episode" was informative, and while they made it abundantly clear there is not currently (possibly never in the current state of "things") a fix-all be-all solution, it is always fun to hear my fave old married couple bicker about OSS. And I am not just saying this because of the shout-outs (including the cell phone story), but because it helped emphasize an important thing I didn't realize - Debian's response to this was absolutely spectacular. I dare any commercially sponsored distro to do the same.

Debian seriously just when up in my book, and if you know me, that's something.

Anyway... check out https://opensourcesecurity.io/

kurtseifried, to random

Episode 415 of the with @kurtseifried and @joshbressers in which we learn that reducing the attack surface too much can reduce security significantly https://opensourcesecurity.io/2024/02/11/episode-415-reducing-attack-surface-for-less-security/ TL;DR: In a truly minimized container nobody can hear your security tools screaming.

kurtseifried, to random

Do you know what you won't hear on the ? The wrong kind of silence.

This week we talk about building unrealistic expectations around builds of software. I don't know what the answer is, but you can find out more about this mess at https://opensourcesecurity.io/2024/02/04/episode-414-the-exploited-ecosystem-of-open-source/ TL;DR: as we level up, people expect more.

briankrebs, to random

There's a huge disconnect for me rn in the IT space. Companies love to talk about an increasing deficit of smart, talented and skillful people available to help defend the cybers. Welp, a lot of those people are somehow now seeking gainful employment bc they've been laid off. Which is just nuts to me given the sheer scale, resources and effort our adversaries are throwing at everything now.

p.s. AI isn't going to fix anyone's security problems. If anything, it's going to compound them by orders of magnitude (at least in terms of data governance).

kurtseifried,

@briankrebs to quote @joshbressers incorrectly from a recent episode: “if a company gets hacked it’s not the technical person‘s problem. It’s the business is problem.” I would extend that but most business people aren’t all that tightly aligned with their company, indeed, the whole nature of companies is to limit liability for the people working for them from the company does. Which are done by the people who have protection from the liability of what they’re doing. I’m sure it’ll work out fine.

kurtseifried, to random

Welcome to a late-night edition of the #osspodcast, in which @joshbressers picks all of you over his Games Done Quick, where a guy trained his dog to play Gyromite https://nintendo.fandom.com/wiki/Gyromite also we discuss the #PyTorch and why, ultimately, a lot of these security problems are due to efficiency and specialization. https://opensourcesecurity.io/2024/01/28/3303/ TL;DR: We get confused about some details but as usual it's probably mostly correct(ish).

kurtseifried, to random

Do you know who is to blame for bad passwords in the 23andme hack? Find out with @joshbressers and me on the #osspodcast https://opensourcesecurity.io/2024/01/21/episode-412-blame-the-users-for-bad-passwords/ TL;DR: It's complicated.

kurtseifried, to random

Good news: a new has dropped which talks about old security technology, some of which did not make it, some of which is still in use, and some of which spawned entire industries.

Weird news: @joshbressers has a high-pitched noise that some of you can hear (assuming you have nice speakers and such).

Bad news: mod_security is basically dead ("Trustwave is announcing the End-of-Life (EOL) of our support for ModSecurity effective July 1, 2024. We will then hand over the maintenance of ModSecurity code back to the open-source community.")

Find out more https://opensourcesecurity.io/2024/01/14/episode-411-the-security-tools-that-started-it-all/

TL;DR: as always it's a weird and wonderful journey and I'm not sure where we are, or where we're going, but I'm pretty sure we're not lost. At least not in a dangerous way.

kurtseifried, to random

To put it bluntly: barcodes are a miracle and underappreciated.

Software package identifiers are much harder, which is probably why everyone complains about every existing solution to some degree because they are all. in fact. not great. Because it's a really hard problem. Find out with @kurtseifried and @joshbressers on the #osspodcast https://opensourcesecurity.io/2024/01/07/episode-410-package-identifiers-are-really-hard/

TL;DR: CISA did a REALLY Interesting thought experiment about 4 possible outcomes and you should probably read the paper they produced talking about them.

P.S. I wish I could @cisa

b00ga,

@joshbressers @kurtseifried @carol As with almost every topic on the … it’s worse than that. Looking at that list, there’s a Sonatype entry, but maven central is Sonatype now (https://central.sonatype.com). And JCenter is JFrog, and they deprecated JCenter a few years ago.

kurtseifried, to random

What is your favorite 10-20+ year old open source security technology? I’m talking things like tripwire, SATAN, fail2ban and so on. This is totally for harvesting content for a future episode.

mariuxdeangelo, to random

@joshbressers @kurtseifried how in the world have I managed to listen to over 1500 minutes of #osspodcast this year 😳

image/jpeg

kurtseifried, (edited ) to random

Also I forgot the content warning, this holiday spectacular episode gets kind of real, especially around healthcare and houselessness/unhoused people and a bunch of other topics.

What happens when Santa uses AI to manage the naughty and nice list? As we all learned from "The good place" the points based system no longer works. Find out on the with @joshbressers at https://opensourcesecurity.io/2023/12/17/episode-407-should_santa-use-ai/ Also are elves people? What species are they? Are Santa's elves aquatic elves? Does everyone live on top of water? What about volcanoes? Also what's the maintenance cycle like for Santas sleigh? Is there a log book for this somewhere?

kurtseifried, to random

Good news: radios are getting really cheap and low power, heck we stuck one on the cats collar. Bad news: we're sticking radios in everything new, and relying on them, maybe too much? Also, it's amazing that things like GPS even work at all considering how weak the signals are. Find out more with @joshbressers on the https://opensourcesecurity.io/2023/12/10/episode-406-the-security-of-radio/ Also Kurt totally doesn't do illegal things with stuff that isn't legal to turn on, but he does know what happens when you turn on a GPS signal jammer.

kurtseifried, to random

Is cheating at video games bad? Is modding video games good? Is modding a game cheating? @kurtseifried and @joshbressers aren't sure, but it is security-related (obviously), find out more on the https://opensourcesecurity.io/2023/12/03/episode-405-modding-games-isnt-cheating-and-security-isnt-fair/ TL;DR: maybe try taint?

kurtseifried, to random

I’m just enriching the cat. With play, not like uranium. Once I’m done I’ll post this weeks .

kurtseifried, to random

Digital ID is probably not a bad idea long term but making the root certificate system more insecure is probably a bad idea. Find out more with @joshbressers on the https://opensourcesecurity.io/2023/11/19/episode-402-the-eus-eidas-regulation-is-a-terrible-idea/ tldr: forcing everyone to trust governments and bypassing basic security requirements is bad, mmmkay?

kurtseifried, to random

The #osspodcast should talk about (and this was a slow week!):

kurtseifried, to random

Join myself and @joshbressers in discussing the Dutch government proposing legilsation to hack hacking groups, and the hacked victims of the hacking groups, for you know, their own safety. Find out more on the https://opensourcesecurity.io/2023/11/05/episode-400-when-can-the-government-hack-a-victim/ TL;DR: I'm still not sure if I'm for aor against this even after listening to myself discuss it.

kurtseifried, to random

Good news, @joshbressers and I decided to do a show about #curl, and rather conveniently @bagder agreed to be on it and give us the inside scoop on many, many things (like ... the curl built into Windows isn't curl. Not even a little bit) find out more on the #osspodcast https://opensourcesecurity.io/2023/10/29/episode-399-curl-security-and-daniel-stenberg/ TL;DR: use curl (command line or library). and you'll benefit from the work of over (checks @bagder's account quickly) 1210 people.

kurtseifried, to random

Do we use only 10% of our brains? Do we maintain only 11% of Open Source? Can @joshbressers spell "maintained"? Find out the answer to at least one of these questions on the https://opensourcesecurity.io/2023/10/22/episode-398-is-only-11-of-open-source-mainted/ TL;DR: Do we really need more features? Maybe. Do we need hot buttered toast? Absolutely!

kurtseifried,

@joshbressers Also listening to the I realize I really love nails, screws, bolts, fasteners, tapes, solvents (for chemical welding), and glues.

kf,

Hi @kurtseifried and @joshbressers.

At least 1/6000th of the weekly listeners enjoys your podcast 👍.

Niche at it is, you talk about important bits and pieces of information security, and not only the tech parts, but also the human factor.

Your take on us, software developers, is correct. We're only human.

With there is at least one thing to look forward to on Mondays 😊.

Keep the bluntness and technically correct statements coming. Also, too few potholes in the previous shows!

joshbuker, to random

@joshbressers @kurtseifried

Not sure if you've changed something with syndication, but Google Podcasts has been having trouble syncing the lately. The oldest episodes all disappeared, and the newest one tends to phase in and out of existence. 🤷

https://podcasts.google.com/feed/aHR0cHM6Ly9vcGVuc291cmNlc2VjdXJpdHkuaW8vZmVlZC8

kurtseifried, to random

Instead of my usual patter about how intriging or awesome this weeks with myself and @joshbressers is I've opted instead to let AI DallE-3 describe it as an image, and honestly? It is pretty bang on, except I don't have hair. https://opensourcesecurity.io/2023/10/15/episode-397-the-curl-and-glibc-vulnerabilities/

joshbressers, to random

Today @kurtseifried and I recorded the next episode

We argue A LOT

But at the end we come to the conclusion that we currently have the level of security the market demands

And if we want to change that level of security, the market has to change

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • khanakhh
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • everett
  • ngwrru68w68
  • Durango
  • megavids
  • InstantRegret
  • cubers
  • GTA5RPClips
  • cisconetworking
  • ethstaker
  • osvaldo12
  • modclub
  • normalnudes
  • provamag3
  • tester
  • anitta
  • Leos
  • lostlight
  • All magazines