loader from loading.io

Episode 450 - What's Wrong With WordPress

Open Source Security

Release Date: 10/14/2024

The Future of Open Source Security show art The Future of Open Source Security

Open Source Security

It’s a new year and time for some changes to the opensourcesecurity.io website.   It's time to retire the podcast, but that's to make way for something new and hopefully better. You can read the details in the blog post (the audio version is basically the same thing) https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/

info_outline
Episode 461 - The new NIST password guidance show art Episode 461 - The new NIST password guidance

Open Source Security

and talk about new NIST password guidance. There's some really good stuff in this new document. Ideas like usability and equity show up (which is amazing). There's more strict guidance against rotating passwords and complex passwords. This new guidance gives us a lot to look forward to. Show Notes

info_outline
Episode 460 - Santa's Supply Chain Security show art Episode 460 - Santa's Supply Chain Security

Open Source Security

and talk about the supply chain of Santa. Does he purchase all those things? Are they counterfeit goods? Are they acquired some other way? And once he has all the stuff, the logistics of getting it to the sleigh is mind boggling. It's all very complex Show Notes

info_outline
Episode 459 - CWE Top 25 List show art Episode 459 - CWE Top 25 List

Open Source Security

and talk about a CWE Top 25 list from MITRE. The list itself is fine, but we discuss why the list looks the way it does (it's because of WordPress). We also discuss why Josh hates lists like this (because they never create any actions). We finish up running through the whole list with a few comments about the findings. Show Notes

info_outline
Episode 458 - FBI endorses E2E encryption show art Episode 458 - FBI endorses E2E encryption

Open Source Security

and talk about the FBI telling everyone to use end to end encrypted messengers. This is a pretty drastic deviation from messages in the past. The reason for this is it appears the US telephone networks are pwnt beyond repair at this point, which is concerning. The only real solution now is to treat the phone network as untrusted and encrypt all the traffic. Show Notes

info_outline
Episode 457 - The D-Link D-bacle show art Episode 457 - The D-Link D-bacle

Open Source Security

and talk about a serious D-Link security vulnerability in a bunch of end of life products. The crux of the discussion focuses on D-Link, but the reality is almost all consumer gear you plug into the internet is terrible. And there's little hope it will get better anytime soon. Show Notes

info_outline
Episode 456 - What if XZ happened to a company? The openness of open source show art Episode 456 - What if XZ happened to a company? The openness of open source

Open Source Security

and embark on a thought experiment to discuss how a commercial entity would handle something like the xz incident. It was very specific and difficult to understand. It's easy to claim just because source code being available doesn't matter. But the reality is when source code is needed, it can make a huge difference for everyone working together, just like we saw with xz. Show Notes

info_outline
Episode 455 - Wordpress plugin security show art Episode 455 - Wordpress plugin security

Open Source Security

and talk about the way Wordpress vets their plugins. While Wordpress has been in the news lately, they do some clever things to get plugins approved. There's a static analyzer that runs against new submissions. We discuss using static analysis, securing open source, contributing and more. Show Notes

info_outline
Episode 454 - The state of open source with Brian Fox from Sonatype and Donald Fischer from Tidelift show art Episode 454 - The state of open source with Brian Fox from Sonatype and Donald Fischer from Tidelift

Open Source Security

and talk to Brian Fox from Sonatype and Donald Fischer from Tidelift about their recent reports as well as open source. There are really interesting connections between the two reports. The overall theme seems to be open source is huge, everywhere, and needs help. But all is no lost! There's some great ideas on what the future needs to look like. Show Notes

info_outline
Episode 453 - Software Liability show art Episode 453 - Software Liability

Open Source Security

and talk about three government activities happening around security. CISA has a request for comment, and an international strategic plan around cybersecurity. These are both good ideas, and hopefully will help drive change. But we also discuss an EU proposal that brings liability rules to software which sounds like a great way to force change to happen. Show Notes

info_outline
 
More Episodes

Josh and Kurt talk about the current Wordpress / WP Engine mess. In what is certainly a supply chain attack, the Advanced Custom Fields forking. This whole saga is weird and filled with chaos and stupidity. We have no idea how it will end, but we do know that the blog platform you use shouldn't be this exciting. The bad sort of exciting.

Show Notes