425 afleveringen

A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.

Open Source Security Podcast Josh Bressers & Kurt Seifried

    • Technologie
    • 4,7 • 3 beoordelingen

A security podcast geared towards those looking to better understand security topics of the day. Hosted by Kurt Seifried and Josh Bressers covering a wide range of topics including IoT, application security, operational security, cloud, devops, and security news of the day. There is a special open source twist to the discussion often giving a unique perspective on any given topic.

    The Notepad++ Parasite Website

    The Notepad++ Parasite Website

    Josh and Kurt talk about a Notepad++ fake website. It's possibly not illegal, but it's certainly ethically wrong. We also end up discussing why it seems like all these weird and wild things keep happening. It's probably due to the massive size of open source (and everything) now. Things have gotten gigantic and we didn't really notice.
    Show Notes Help us to take down the parasite website Open Source is bigger than you can imagine Toronto Pearson International Airport heist

    • 35 min.
    FCC cybersecurity label for consumer devices

    FCC cybersecurity label for consumer devices

    Josh and Kurt talk about a new FCC program to provide a cybersecurity certification mark. Similar to other consumer safety marks such as UL or CE. We also tie this conversation into GrapheneOS, and what trying to claim a consumer device is secure really means. Some of our compute devices have an infinite number of possible states. It's a really weird and hard problem.
    Show Notes GrapheneOS FCC approves cybersecurity label for consumer devices Cyber Trust Mark Logo

    • 32 min.
    XZ Bonus Spectacular Episode

    XZ Bonus Spectacular Episode

    Josh and Kurt talk about the recent events around XZ. It's only been a few days, and it's amazing what we already know. We explain a lot of the basics we currently know with the attitude much of these details will change quickly over the coming week. We can't fix this problem as it stands, we don't know where to start yet. But that's not a reason to lose hope. We can fix this if we want to, but it won't be flashy, it'll be hard work.
    Show Notes GossiTheDog's Blog Post fr0gger diagram OpenSSF Blog (archive) stb library

    • 1 u. 1 min.
    Do you have a security.txt file?

    Do you have a security.txt file?

    Josh and Kurt talk about the security.txt file. It's not new, but it's not something we've discussed before. It's a great idea, an easy format, and well defined. It's not high on many of our todo lists, but it's something worth doing.
    Show Notes RFC 9116

    • 30 min.
    CISA's new SSDF attestation form

    CISA's new SSDF attestation form

    Josh and Kurt talk about the new SSDF attestation form from CISA. The current form isn't very complicated, and the SSDF has a lot of room for interpretation. But this is the start of something big. It's going to take a long time to see big changes in supply chain security, but we're confident they will come.
    Show Notes Secure Software Development Attestation Form The U.S. Military Is Missing Six Nuclear Weapons NIST 800-218

    • 41 min.
    What's going on at NVD

    What's going on at NVD

    Josh and Kurt talk about what's going on at the National Vulnerability Database. NVD suddenly stopped enriching vulnerabilities, and it's sent shock-waves through the vulnerability management space. While there are many unknowns right now, the one thing we can count on is things won't go back to the way they were.
    Show Notes Anchore's Blog Grype Josh's Cyphercon Talk Ecosyste.ms Episode 266 – The future of security scanning with Debricked

    • 39 min.

Klantrecensies

4,7 van 5
3 beoordelingen

3 beoordelingen

Top-podcasts in Technologie

De Technoloog | BNR
BNR Nieuwsradio
✨Poki - Podcast over Kunstmatige Intelligentie AI
Alexander Klöpping & Wietse Hage
Bright Podcast
Bright B.V.
Lex Fridman Podcast
Lex Fridman
Cryptocast | BNR
BNR Nieuwsradio
Darknet Diaries
Jack Rhysider

Suggesties voor jou

LINUX Unplugged
Jupiter Broadcasting
Smashing Security
Graham Cluley & Carole Theriault
Defense in Depth
David Spark
Self-Hosted
Jupiter Broadcasting
Malicious Life
Malicious Life
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich