Skip to main content

Search

Items tagged with: OSSPodcast


The good news: WordPress still works.

The bad news: They did something bad enough that we talked about on the #osspodcast,

The good news: what they did probably isn't bad enough for you to have to worry about...

The bad news: But if they keep going in this direction you will probably have to care.

Find out more with @joshbressers and @kurtseifried on the osspodcast https://opensourcesecurity.io/2024/10/13/episode-450-whats-wrong-with-wordpress/

TL;DR: When ecosystems are controlled by someone, hopefully they are benevolent and don't violate the social contracts that we think are in place.

But we seem to be in an era where eroding of trust to make a buck, and normalization of deviancy https://en.wikipedia.org/wiki/Normalization_of_deviance is becoming more common, and we should probably worry about that.


Also I forgot the content warning, this holiday spectacular episode gets kind of real, especially around healthcare and houselessness/unhoused people and a bunch of other topics.

What happens when Santa uses AI to manage the naughty and nice list? As we all learned from "The good place" the points based system no longer works. Find out on the #osspodcast with @joshbressers at https://opensourcesecurity.io/2023/12/17/episode-407-should_santa-use-ai/ Also are elves people? What species are they? Are Santa's elves aquatic elves? Does everyone live on top of water? What about volcanoes? Also what's the maintenance cycle like for Santas sleigh? Is there a log book for this somewhere?


This #osspodcast episode @kurtseifried and I discuss the #RedHat news

The reality is they're still better than a lot of companies claiming to do #OpenSource but it feels like a betrayal because they were the hero of open source for so long

https://opensourcesecurity.io/2023/07/02/episode-382-red-hat-you-were-the-chosen-one/


This week on #OSSPodcast @kurtseifried and I discuss how mind boggling big open source is, and what that means for how we use it

https://opensourcesecurity.io/2023/04/09/episode-370-open-source-is-bigger-than-you-can-imagine/


Episode 364 of the #osspodcast in which Kurt had bad shwarma, @joshbressers agrees that good shwarma is great, and we learn that it's also hard to know what's in your software even if you do #SBOM https://opensourcesecurity.io/2023/02/26/episode-364-using-sboms-is-hard/ TL;DR: We got different kinds of SBOM, SBOM drift, services and APIs, and then there some complicated problems on top of all that. Also legal obligations.


#AIX isn't dead, it's just pining for the fjords, much like #NOTAM which probably wants to die and be replaced with something modern, which might happen now that it had a little nap. Find out more with @kurtseifried and @joshbressers on the #osspodcast https://opensourcesecurity.io/2023/01/22/episode-359-the-notam-outage-and-other-legacy-technology/ TL;DR: Remember the #SCO lawsuit? It's all related.
Crazy connections wall


How many companies are helping #opensource by putting eggs in the toaster? Find out on the #osspodcast https://opensourcesecurity.io/2023/01/08/episode-357-is-open-source-being-overexploited/ wit @kurtseifried and @joshbressers TL;DR: don't put eggs in your toaster, seriously. Also maybe companies and demanding users should stop strip mining OpenSource and burning our developers.


I think we can all agree that #lastpass ducked up seriously, but what happens now? Find out on the #osspodcast with @kurtseifried and @joshbressershttps://opensourcesecurity.io/2023/01/01/episode-356-lastpass-ducked-up-now-what/ TL;DR: #lastpass is a bag of weasels that still has a website that makes it sound like all your vault data is encrypted. It's not.


If you didn't have enough money to get someone a gift you can give them the gift of the #osspodcast for free from @kurtseifried and @joshbressershttps://opensourcesecurity.io/2022/12/25/episode-355-security-boxing-day/ TL;DR: we talk about the security poverty line and some practical things you can actually do with no or little budget if you're using OpenSource. And trust me, you're using OpenSource.


This week on #osspodcast @kurtseifried and I chat about #stylometry

There's a tool to look at #HackerNews authors and see if their writing is similar to another user (sock puppets anyone?)

This of course leads to larger discussions about #privacy, #cybersecurity, #impersonation, and of course, #shakespeare

https://opensourcesecurity.io/2022/12/04/episode-352-stylometry-removes-anonymity/


This week on the #osspodcast @joshbressers and @kurtseifried discuss #factorio and then #usability vs #security https://opensourcesecurity.io/2022/11/27/episode-351-is-security-or-usability-a-law-of-the-universe/ TL;DR: THE ADMINS CAN READ THESE TOOTS!!!! EVEN THE PRIVATE TOOTS!!!!

Also, we managed to avoid discussing CISA, Twitter, and all the other things on fire.


This week on #OSSPodcast @kurtseifried and I chat about the new UK plan to scan all the infrastructure in the country

This of course creates a lot more questions than it answers

Nothing makes sense anymore. Maybe it never did.

#cybersecurity

https://opensourcesecurity.io/2022/11/13/episode-349-the-cyber-is-coming-from-inside-the-house-the-uk-is-scanning-itself/