Logo
    Search

    Episode 360 - Memory safety and the NSA

    enJanuary 30, 2023

    About this Episode

    Josh and Kurt talk about the NSA guidance on using memory safety issues. The TL;DR is to stop using C. We discuss why C has so many problem, why we can't fix C, and what some alternatives looks like. Even the alternatives have their own set of issues and there are many options, but the one thing we can agree on is we have to stop using C.

    Show Notes

    Recent Episodes from Open Source Security Podcast

    Episode 418 - Being right all the time is hard

    Episode 418 - Being right all the time is hard

    Josh and Kurt talk about recent stories about data breaches, flipper zero banning, and realistic security. We have a lot of weird challenges in the world of security, but hard problems aren't impossible problems. Sometimes we forget that.

    Show Notes

    Episode 417 - Linux Kernel security with Greg K-H

    Episode 417 - Linux Kernel security with Greg K-H

    Josh and Kurt talk to GregKH about Linux Kernel security. We most focus on the topic of vulnerabilities in the Linux Kernel, and what being a CNA will mean for the future of Linux Kernel security vulnerabilities. The future of Linux Kernel security vulnerabilities is going to be very interesting.

    Show Notes

    Episode 416 - Thomas Depierre on open source in Europe

    Episode 416 - Thomas Depierre on open source in Europe

    Josh and Kurt talk to Thomas Depierre about some of the European efforts to secure software. We touch on the CRA, MDA, FOSDEM, and more. As expected Thomas drops a huge amount of knowledge on what's happening in open source. We close the show with a lot of ideas around how to move the needle for open source. It's not easy, but it is possible.

    Show Notes

    Episode 415 - Reducing attack surface for less security

    Episode 415 - Reducing attack surface for less security

    Josh and Kurt talk about a blog post explaining how to create a very very small container image. Generally in the world of security less is more, but it's possible to remove too much. A lot of today's security tooling relies on certain things to exist in a container image, if we remove them we could actually result in worse security than leaving it in. It's a weird topic, but probably pretty important.

    Show Notes

    Episode 414 - The exploited ecosystem of open source

    Episode 414 - The exploited ecosystem of open source

    Josh and Kurt talk about open source projects proving builds, and things nobody wants to pay for in open source. It's easy to have unrealistic expectations for open source projects, but we have the open source capitalism demands.

    Show Notes

    Episode 413 - PyTorch and NPM get attacked, but it's OK

    Episode 413 - PyTorch and NPM get attacked, but it's OK

    Josh and Kurt talk about an attack against PyTorch and NPM. The PyTorch attack shows the difficulty of trying to operate a large open source project. The NPM problem is one of the difficulty in trying to backdoor open source. A lot of people are watching and it only takes one person to notice a problem and we all benefit.

    Show Notes

    Episode 412 - Blame the users for bad passwords!

    Episode 412 - Blame the users for bad passwords!

    Josh and Kurt talk about the 23andMe compromise and how they are blaming the users. It's obviously the the fault of the users, but there's still a lot of things to discuss on this one. Every company has to care about cybersecurity now, even if they don't want to.

    Show Notes