loader from loading.io

Episode 434 - Unreported vulnerabilities and everyone is getting hacked

Open Source Security

Release Date: 06/24/2024

The Future of Open Source Security show art The Future of Open Source Security

Open Source Security

It’s a new year and time for some changes to the opensourcesecurity.io website.   It's time to retire the podcast, but that's to make way for something new and hopefully better. You can read the details in the blog post (the audio version is basically the same thing) https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/

info_outline
Episode 461 - The new NIST password guidance show art Episode 461 - The new NIST password guidance

Open Source Security

and talk about new NIST password guidance. There's some really good stuff in this new document. Ideas like usability and equity show up (which is amazing). There's more strict guidance against rotating passwords and complex passwords. This new guidance gives us a lot to look forward to. Show Notes

info_outline
Episode 460 - Santa's Supply Chain Security show art Episode 460 - Santa's Supply Chain Security

Open Source Security

and talk about the supply chain of Santa. Does he purchase all those things? Are they counterfeit goods? Are they acquired some other way? And once he has all the stuff, the logistics of getting it to the sleigh is mind boggling. It's all very complex Show Notes

info_outline
Episode 459 - CWE Top 25 List show art Episode 459 - CWE Top 25 List

Open Source Security

and talk about a CWE Top 25 list from MITRE. The list itself is fine, but we discuss why the list looks the way it does (it's because of WordPress). We also discuss why Josh hates lists like this (because they never create any actions). We finish up running through the whole list with a few comments about the findings. Show Notes

info_outline
Episode 458 - FBI endorses E2E encryption show art Episode 458 - FBI endorses E2E encryption

Open Source Security

and talk about the FBI telling everyone to use end to end encrypted messengers. This is a pretty drastic deviation from messages in the past. The reason for this is it appears the US telephone networks are pwnt beyond repair at this point, which is concerning. The only real solution now is to treat the phone network as untrusted and encrypt all the traffic. Show Notes

info_outline
Episode 457 - The D-Link D-bacle show art Episode 457 - The D-Link D-bacle

Open Source Security

and talk about a serious D-Link security vulnerability in a bunch of end of life products. The crux of the discussion focuses on D-Link, but the reality is almost all consumer gear you plug into the internet is terrible. And there's little hope it will get better anytime soon. Show Notes

info_outline
Episode 456 - What if XZ happened to a company? The openness of open source show art Episode 456 - What if XZ happened to a company? The openness of open source

Open Source Security

and embark on a thought experiment to discuss how a commercial entity would handle something like the xz incident. It was very specific and difficult to understand. It's easy to claim just because source code being available doesn't matter. But the reality is when source code is needed, it can make a huge difference for everyone working together, just like we saw with xz. Show Notes

info_outline
Episode 455 - Wordpress plugin security show art Episode 455 - Wordpress plugin security

Open Source Security

and talk about the way Wordpress vets their plugins. While Wordpress has been in the news lately, they do some clever things to get plugins approved. There's a static analyzer that runs against new submissions. We discuss using static analysis, securing open source, contributing and more. Show Notes

info_outline
Episode 454 - The state of open source with Brian Fox from Sonatype and Donald Fischer from Tidelift show art Episode 454 - The state of open source with Brian Fox from Sonatype and Donald Fischer from Tidelift

Open Source Security

and talk to Brian Fox from Sonatype and Donald Fischer from Tidelift about their recent reports as well as open source. There are really interesting connections between the two reports. The overall theme seems to be open source is huge, everywhere, and needs help. But all is no lost! There's some great ideas on what the future needs to look like. Show Notes

info_outline
Episode 453 - Software Liability show art Episode 453 - Software Liability

Open Source Security

and talk about three government activities happening around security. CISA has a request for comment, and an international strategic plan around cybersecurity. These are both good ideas, and hopefully will help drive change. But we also discuss an EU proposal that brings liability rules to software which sounds like a great way to force change to happen. Show Notes

info_outline
 
More Episodes

Josh and Kurt talk about three wangles of responsibility. We start with a story about a bike theft ring, bike theft doesn't usually get any attention, but this one is special. Then we ask why it seems like everyone is getting hacked, it's because they have to tell us now. And finally we have a story about the huge number of unreported vulnerabilities in open source projects. This statistic probably affects all software, but there's some numbers for open source specifically.

Show Notes