Randy Barlow · @bowlofeggs
4 followers · 8 posts · Server fosstodon.org

I have now set the TCP evil bit to 1 for all outbound traffic from my home router.

#osspodcast

Last updated 1 year ago

Sire :arch: :i3wm: :terminal: · @Sire
89 followers · 1015 posts · Server fosstodon.org

I don't think I can, in good faith, recommend the anymore. There was no mention of curl OR potholes in the latest episode. My disappointment is immeasurable and my day is ruined. @joshbressers @kurtseifried

#osspodcast

Last updated 1 year ago

kurtseifried (he/him) · @kurtseifried
605 followers · 159 posts · Server infosec.exchange

In the olden days if you had a 1000+ software packages to manage you were a fully fledged operating system with software, nowadays we call this a "web app."

Find out some hard lessons learned over the year from @kurtseifried and @joshbressers on the opensourcesecurity.io/2023/03/ TL;DR: counting vulnerabilities is both completely stupid, and completely neccesary. The trick is to think about them the right way (hint: statistics, not pets. Except when they are pets like . Who's a good vulnerability? You are!).

#osspodcast #log4j

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
595 followers · 127 posts · Server infosec.exchange

Ok so @kurtseifried and @joshbressers were lucky enough to have @Di4na on the aka the "I am not a supplier" person. TL;DR:... normally we cut the episode to 30 minutes. This one is 52 minutes. It's good. Really good. Suggestion: first go read softwaremaxims.com/blog/not-a- and then stare at the image below for a few minutes and think about what you just read, and then load the podcast up at opensourcesecurity.io/2023/03/ and listen to the author clarify it, and explain several other things. TL;DR You need to listen to Thomas. He's sharp.

#osspodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
588 followers · 115 posts · Server infosec.exchange

Episode 364 of the in which Kurt had bad shwarma, @joshbressers agrees that good shwarma is great, and we learn that it's also hard to know what's in your software even if you do opensourcesecurity.io/2023/02/ TL;DR: We got different kinds of SBOM, SBOM drift, services and APIs, and then there some complicated problems on top of all that. Also legal obligations.

#osspodcast #SBOM

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
579 followers · 34 posts · Server infosec.exchange

Episode 362 of the in which @carol not only teaches @kurtseifried and @joshbressers about , both at a high level (catching things at compile time makes for some magic) and some very clever low-level things (like borrowing and lending) but also asks one of the best guest questions I've ever heard, find out at the opensourcesecurity.io/2023/02/ TL;DR: the crevice tool is good, but if you live in Canada and have a garage you want the water on floor cleaning tool for your garage.

#osspodcast #rust

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
568 followers · 11 posts · Server infosec.exchange

In last week's news discussed after the fact by @kurtseifried ad @joshbressers on the opensourcesecurity.io/2023/02/ @github got hacked a little bit and it was mostly boring. In exciting news, it's also clear that @githubsecurity is staying on top of things and not only noticed themselves getting a little bit hacked, but then checked and noticed others getting hacked the same way and fixed them, and notified them. At least that's what we speculate (with reasonable evidence and a bit of Occam's Razor).

#osspodcast

Last updated 2 years ago

GitHub · @github
306 followers · 2660 posts · Server hello.2heng.xin

RT GitHub Security
Tune into this week's to hear @thejillboss chat about GitHub’s bug bounty program, including what’s in scope and why we love partnering with researchers
opensourcesecurity.io/2022/12/

:sys_twitter: twitter.com/GitHubSecurity/sta

#osspodcast

Last updated 2 years ago

GitHub (UNOFFICIAL) · @github
1 followers · 30 posts · Server secluded.ch

RT by @github: Tune into this week's to hear @thejillboss chat about GitHub’s bug bounty program, including what’s in scope and why we love partnering with researchers opensourcesecurity.io/2022/12/

#osspodcast

Last updated 2 years ago

Tune into this week's to hear @thejillboss chat about GitHub’s bug bounty program, including what’s in scope and why we love partnering with researchers opensourcesecurity.io/2022/12/

#osspodcast

Last updated 2 years ago

kurtseifried (he/him) · @kurtseifried
568 followers · 11 posts · Server infosec.exchange

@malanalysis @jerry @fuzztech @boblord Another observation: the term "password manager" never occurs in this thread (at least not that I saw). How many people are using a password manager to generate very entropic, secure passwords, that the password manager then manages securely, and only allows you to put into the correct website, or manually into an app (thus reducing a lot of the phishing attack surface/mistake potential).

Also, it's wild to see the value people assign to Mastodon accounts, "2fa is table stakes", ignoring the fact they're on a completely random service hosted by someone they may have never heard of, and the account really may not be that valuable/important to them... For all we know 70% of accounts on infosec.exchange are idle/moved/bots which means over 50% of active accounts use MFA...

This isn't 0 or 1. This is a rich nuanced world. Heck we covered this ages ago on the opensourcesecurity.io/2022/07/

#osspodcast

Last updated 2 years ago

Newk · @Newk
175 followers · 213 posts · Server infosec.exchange

@akselmo You may like the open source security podcast!

#osspodcast

Last updated 2 years ago

mlbiam · @mlbiam
101 followers · 190 posts · Server fosstodon.org

Listening to , @joshbressers "people complain."

#osspodcast

Last updated 2 years ago

Matt Owens · @brokenintuition
36 followers · 83 posts · Server fosstodon.org

My favorite podcast moment recently is @joshbressers somehow being aware of real-life NCIS, but being blown away by the existence of the multiple very popular TV shows based on it

#osspodcast

Last updated 2 years ago

Matt Owens · @brokenintuition
35 followers · 91 posts · Server fosstodon.org

My favorite podcast moment recently is @joshbressers somehow being aware of real-life NCIS, but being blown away by the existence of the multiple very popular TV shows based on it

#osspodcast

Last updated 2 years ago