Dmitri ☕️ · @analog_cafe
554 followers · 1370 posts · Server mas.to

An update to mas.to/@analog_cafe/1107875557

The person got back to me expecting a bounty payment between 300-600 Eur to his PayPal account for the information. He did not reveal his identity in that email, even though I've asked in my reply.

I feel like I'm being extorted here as he's coming from a position of power (he knows something about me, but I don't know anything about him), and I'm not sure what his next steps may be.

Any advice?

#OSSPodcast #security

Last updated 1 year ago

Dmitri ☕️ · @analog_cafe
548 followers · 1339 posts · Server mas.to

@joshbressers Thanks, Josh!

is my favourite podcast, I look forward to it every week.

#OSSPodcast

Last updated 1 year ago

Dmitri ☕️ · @analog_cafe
546 followers · 1334 posts · Server mas.to

Got an email from a security researcher. Can’t find his email or name anywhere online. Email seems to demonstrate a legit vulnerability. Would you say it’s safe to engage/reply?

#OSSPodcast #security

Last updated 1 year ago

Carol (Nichols || Goulding) ꙮ · @carol
149 followers · 615 posts · Server crabby.fyi

@joshbressers: I have a plan for this episode

@kurtseifried: Hold my diet soda.

#OSSPodcast

Last updated 1 year ago

Carol (Nichols || Goulding) ꙮ · @carol
149 followers · 615 posts · Server crabby.fyi

@joshbressers
@kurtseifried I would love for your listeners to know that we remove SEO spam from crates.io when we find/ are notified of it, and if there's anyone out there getting a bonus for the number of users or packages on crates.io, they owe me a cut 😝

#OSSPodcast #rustlang

Last updated 1 year ago

Kevin Chadwick · @kevlar700
21 followers · 23 posts · Server ioc.exchange

Enjoyed episode 360 on memory safety. Glad Rust is causing some waves. The kind of push back against basic facts that you get on Reddit when you mention better ways than C is unreal. Totally agree that legislatiin might be the way from the Rust episode.

One thing you appear to be in the dark about though is Ada. It recently got tooling on par with Rust.

"alire.ada.dev"

It is also easier to use than Rust and safer. It's type system helps you even catch some logic errors before compilation, during compilation and at runtime. Yet it is as low level as C when needed. Actually Ada has better bare metal features than C such as record memory overlays to avoid bit shifting and excellent fixed point support. From the sound of it. I think it might be right upn both of yours street.

You can check it out without installing the above alire here.

"learn.adacore.com"

@joshbressers
@kurtseifried

#OSSPodcast

Last updated 1 year ago

Kevin Chadwick · @kevlar700
20 followers · 20 posts · Server ioc.exchange

@joshbressers

Old but interesting Episode 209 secure boot.

Blacklisting individual shims shouldn't be the way to do it. Whichever expanded key was used for shims for certain years should be blacklisted and a new key rolled and used going forward.

Interesting about GPL if true and I wish Linux had taken examJple from OpenBSD and dropped kernel modules years ago.9

#OSSPodcast

Last updated 1 year ago

pi0neer · @pi0neer
1 followers · 7 posts · Server ioc.exchange

@joshbressers I’d be really interested in hearing about Nix and it’s implications for software supply chains on the . Do you guys have any plans for that?

#OSSPodcast

Last updated 1 year ago

Carol (Nichols || Goulding) ꙮ · @carol
149 followers · 615 posts · Server crabby.fyi

It was my honor to invite myself onto one of my favorite podcasts, , to chat with @joshbressers and @kurtseifried about and shopvac attachments 😄 opensourcesecurity.io/2023/02/

#OSSPodcast #rustlang

Last updated 1 year ago

Carol (Nichols || Goulding) ꙮ · @carol
149 followers · 615 posts · Server crabby.fyi

Can confirm that @joshbressers and @kurtseifried of are as pleasant to chat with as they are to listen to :)

#OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
571 followers · 677 posts · Server mastodon.social

When we ( @kurtseifried and @joshbressers) did the luggage tracking via airtags episode on opensourcesecurity.io/2022/10/ we had no idea it would get this insane:

blogto.com/travel/2023/01/onta

“They said they could hear AirTags beeping,” said Rees. “Cops are unimpressed [with] how Air Canada is handling this in that they are taking possession and ownership of our property and deciding what needs to be done with it and donating it.”

#OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
565 followers · 652 posts · Server mastodon.social

isn't dead, it's just pining for the fjords, much like which probably wants to die and be replaced with something modern, which might happen now that it had a little nap. Find out more with @kurtseifried and @joshbressers on the opensourcesecurity.io/2023/01/ TL;DR: Remember the lawsuit? It's all related.

#aix #notam #OSSPodcast #sco

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
564 followers · 627 posts · Server mastodon.social

Ok poll time. Tomorrow @kurtseifried and @joshbressers record an . Do you want:

#OSSPodcast

Last updated 2 years ago

Josh Bressers · @joshbressers
994 followers · 724 posts · Server mastodon.social

This week's was fueled by @Di4na article "I am not a supplier"

We discuss open source in the context of being a natural resource that suffers from pollution and mismanagement (a bit like a forest or river)

We're probably currently a path to unsustainability

opensourcesecurity.io/2023/01/

#OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
555 followers · 602 posts · Server mastodon.social

How many companies are helping by putting eggs in the toaster? Find out on the opensourcesecurity.io/2023/01/ wit @kurtseifried and @joshbressers TL;DR: don't put eggs in your toaster, seriously. Also maybe companies and demanding users should stop strip mining OpenSource and burning our developers.

#opensource #OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
555 followers · 602 posts · Server mastodon.social

@bookwar So this came up on the Boxing day episode opensourcesecurity.io/2022/12/ TL;DR: most people don't have the spare resources, so they can't to preventative work until it catches fire. In fairness, most people have infinite other piles of fire to put out right now as well like that printer on the third floor that keeps jamming.

#OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
555 followers · 602 posts · Server mastodon.social

I think we can all agree that ducked up seriously, but what happens now? Find out on the with @kurtseifried and @joshbressers opensourcesecurity.io/2023/01/ TL;DR: is a bag of weasels that still has a website that makes it sound like all your vault data is encrypted. It's not.

#lastpass #OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
555 followers · 602 posts · Server mastodon.social

@hacks4pancakes For many of us with kids, especially kids with asthma or other medical conditions... yeah. I have a duty of care to my kids (both in that I want to avoid sickness, and I want to avoid making them sick). It would be a very different risk calculation if it were just me. The upside of conferences is also much lower for most of us. We actually covered the value of conferences on the opensourcesecurity.io/2020/06/ TL;DR: it's not what most people think

#OSSPodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
555 followers · 602 posts · Server mastodon.social

If you didn't have enough money to get someone a gift you can give them the gift of the for free from @kurtseifried and @joshbressers opensourcesecurity.io/2022/12/ TL;DR: we talk about the security poverty line and some practical things you can actually do with no or little budget if you're using OpenSource. And trust me, you're using OpenSource.

#OSSPodcast

Last updated 2 years ago

Josh Bressers · @joshbressers
952 followers · 660 posts · Server mastodon.social

I just remembered I wrote a parody poem based on The Night Before Christmas for last year. It was certainly a wild time a year ago. Thank goodness this year is way more boring

opensourcesecurity.io/2021/12/

#Log4Shell #OSSPodcast

Last updated 2 years ago