Episodes

  • Episode 454 - The state of open source with Brian Fix from Sonatype and Donald Fischer from Tidelift
    Nov 11 2024

    Josh and Kurt talk to Brian Fox from Sonatype and Donald Fischer from Tidelift about their recent reports as well as open source. There are really interesting connections between the two reports. The overall theme seems to be open source is huge, everywhere, and needs help. But all is no lost! There's some great ideas on what the future needs to look like.

    Show Notes
    • Donald Fischer
    • Brian Fox
    • Tidelift
    • Sonatype
    • The 2024 Tidelift state of the open source maintainer report
    • Sonatype State of the Software Supply Chain
    • Anchore 2024 Software Supply Chain Security Report
    • OpenSSF TAC issue 101
    Show More Show Less
    43 mins
  • Episode 453 - Software Liability
    Nov 4 2024

    Josh and Kurt talk about three government activities happening around security. CISA has a request for comment, and an international strategic plan around cybersecurity. These are both good ideas, and hopefully will help drive change. But we also discuss an EU proposal that brings liability rules to software which sounds like a great way to force change to happen.

    Show Notes
    • Request for Comment on Product Security Bad Practices Guidance
    • FY2025-2026 CISA International Strategic Plan
    • EU brings product liability rules in line with digital age and circular economy
    • CSA Cloud Controls Matrix
    Show More Show Less
    36 mins
  • Episode 452 - All about Meshtastic
    Oct 28 2024

    Josh and Kurt talk about the Meshtastic open source project. It's a really slick mesh radio system that runs on very cheap radio equipment. This episode isn't very security related (there are a few things), but it is very open source.

    Show Notes
    • Meshtastic
    • Heltec LoRa 32(V3) Radio
    • 465 Rutgers University Confirmed: Meshtastic and LoRa are dangerous
    • Meshtastic Routing Issues & Deployment Scenarios
    • TC2-BBS-mesh
    • The Comms Channel
    • Josh's BBS
    • Heltec T114 bug
    Show More Show Less
    39 mins
  • Episode 451 - Python security with Seth Larson
    Oct 21 2024

    Josh and Kurt talk to Seth Larson from the Python Software Foundation about security the Python ecosystem. Seth is an employee of the PSF and is doing some amazing work. Seth is showing what can be accomplished when we pay open source developers to do some of the tasks a volunteer might consider boring, but is super important work.

    Show Notes
    • Seth Larson
    • XKCD PGP Signature
    • Seth's Blog
    • Python and Sigstore
    • Deprecating PGP - PEP 761
    • Python SBOMs

    Show More Show Less
    36 mins
  • Episode 450 - What's Wrong With WordPress
    Oct 14 2024

    Josh and Kurt talk about the current Wordpress / WP Engine mess. In what is certainly a supply chain attack, the Advanced Custom Fields forking. This whole saga is weird and filled with chaos and stupidity. We have no idea how it will end, but we do know that the blog platform you use shouldn't be this exciting. The bad sort of exciting.

    Show Notes
    • WordPress.org’s latest move involves taking control of a WP Engine plugin
    • Wordpress / WP Engine timeline
    • Knorr German Recipes
    Show More Show Less
    39 mins
  • Episode 449 - The CUPSpocalypse
    Oct 7 2024

    Josh and Kurt talk about the recent CUPS issue. The vulnerability itself wasn't all that exciting, but the whole disclosure process was wild. There's a lot to talk about, many things didn't quite go as planned and it all leaked early. Let's talk about why and what it all means.

    Show Notes
    • CUPS vulnerability
    • Akamai report
    • Wil Wheaton: being a nerd is not about what you love; it’s about how you love it
    Show More Show Less
    38 mins
  • Episode 448 - What's wrong with CISA?
    Sep 30 2024

    Josh and Kurt talk about a few things that have recently come out of CISA. They seem to be blaming the vendors for a lot of the problems, but there's also not any actionable advice telling the vendors what they should be doing. This feels like the classic case of "just security harder". We need CISA to be leading the way funding and defining security, not blaming vendors for giving the market what it demands.

    Show Notes
    • iCloud Photos Downloader
    • CISA boss: Makers of insecure software must stop enabling today's cyber villains
    • A Security Market for Lemons
    • CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities
    • CISA Secure by Design Pledge
    • Railroad Newsletter
    • CISA Secure Software Development Attestation Form
    Show More Show Less
    35 mins
  • Episode 447 - The Tidelift 2024 open source maintainer report
    Sep 23 2024

    Josh and Kurt talk about the 2024 Tidelift maintainer report. The report is pretty big and covers a ton of ground. We focus in a few of the statistics that should worry anyone who uses open source. We've known for a while developers are struggling, and the numbers back that up. This one feels like the old "we've tried nothing and we're all out of ideas".

    Show Notes
    • THE 2024 TIDELIFT STATE OF THE OPEN SOURCE MAINTAINER REPORT
    • Canadian passport
    • Changelog Interviews #433
    • Pandas CVE
    Show More Show Less
    39 mins