エピソード

  • Episode 446 - Researchers took over .MOBI TLD
    2024/09/16

    Josh and Kurt talk about some security researchers sort of taking over the .MOBI whois server. The story is a bit sensational, but we ask if it really matters? There are a lot of interesting possible attacks, but turning something like this into a good attack is really hard, maybe impossible. The researchers presented the findings in a very reasonable way.

    Show Notes
    • We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
    • Heinz says sorry for ketchup QR code that links to porn site
    続きを読む 一部表示
    33 分
  • Episode 445 - EPSS with Jay Jacobs
    2024/09/09

    Josh and Kurt talk to Jay Jacobs about Exploit Prediction Scoring System (EPSS). EPSS is a new way to view vulnerabilities. It's a metric for the likelyhood that a vulnerability will be exploited in the next 30 days. Jay explains how EPSS got to where it is today, how the scoring works, and how we can start to think about including it in our larger risk equations. It's a really fun discussion.

    Show Notes
    • Jay Jacobs on LinkedIn
    • EPSS
    • Jay's graph animation
    • Cyentia's A Visual Exploration of Exploits in the Wild
    続きを読む 一部表示
    41 分
  • Episode 444 - Open Source and End of Life
    2024/09/02

    Josh and Kurt talk about Chrome unexpectedly going EOL on Ubuntu 18. Keeping old things alive is really hard to do, and in open source it's becoming more common to just run the latest version rather than trying to keep old versions alive for long periods of time.

    Show Notes
    • Chrome dumped support for Ubuntu 18.04 – but it'll be back
    • Linus Torvalds talks AI, Rust adoption, and why the Linux kernel is 'the only thing that matters'
    • Pidgin backdoor
    続きを読む 一部表示
    38 分
  • Episode 443 - The Supply Chain Security Crisis
    2024/08/26

    Josh and Kurt talk about a story that discusses a story from Black Hat that references supply chains. There's a ton of doom and gloom around our software supply chains and much of the advice isn't realistic. If we want to take this seriously we need to stop obsessing over the little problems and focus on some big problems.

    Show Notes
    • Black Hat USA 2024: Key Takeaways from the Premier Cybersecurity Event
    • The Reason Train Design Changed After 1948
    続きを読む 一部表示
    34 分
  • Episode 442 - The foundation of society, TLS certificates are a mess
    2024/08/19

    Josh and Kurt talk about a few stories around the TLS CA certificate world. It's all pretty dire sounding. There's not a lot of organization or process in the space, and the root CAs are literally the foundation of modern society, everything needs them to function. There's not a lot of positive ideas here, it's mostly a show where Kurt explains to Josh what's going on, because Josh doesn't want to care (and will continue to ignore all of this going forward).

    Show Notes
    • Firefox's Mozilla follows Google in losing trust in Entrust's TLS certificates
    • DigiCert Revocation Incident (CNAME-Based Domain Validation)
    • List of Trust Lists
    続きを読む 一部表示
    41 分
  • Episode 441 - Is CWE useful?
    2024/08/12

    Josh and Kurt talk about CWE. What is it, and why does it matter. We cover some history, some shortcomings, and some ideas on how CWE could be used to make security a lot better. We frame the future discussion around the OWASP top 10 list. We should be putting more effort into removing removing entire classes of vulnerabilities.

    Show Notes
    • CWE
    • Episode 360 – Memory safety and the NSA
    • Inside 22,734 Steam games
    続きを読む 一部表示
    33 分
  • Episode 440 - "What is open source" talk Josh gave
    2024/08/05

    Josh and Kurt talk about a presentation Josh recently gave that was supposed to be about how open source works. The talk was the wrong topic for a security crowd, but there's a lot of interesting details in the questions and comments that emerged. It's clear a lot of security people don't really care about the fine details about what open source is, their primary goal is to help keep development secure.

    Show Notes
    • Grassr00tz
    • Pamela Chestek copyright paper
    • Josh's presentation
    続きを読む 一部表示
    35 分
  • Episode 439 - Where are all the youth in open source?
    2024/07/29

    Josh and Kurt talk about a story talking about the "graying" of open source. There doesn't seem to be many young people working on open source, but we don't really know why that is. There are many thoughts, but a better question is why should anyone get involved in open source anymore? The world has changed quite a lot since open source was created.

    Show Notes
    • The graying open source community needs fresh blood
    • OSPOs for Good 2024
      • Day 1 Part 1
      • Day 1 Part 2
      • Day 2 Part 1
      • Day 2 Part 2
    • FFmpeg bug
    • JSON Editor Online
    • https://rfc3339.com/
    続きを読む 一部表示
    29 分