Podcast Episodes
Back to Search
The sliding scale of risk: seeing the forest for the trees
Episode 330
Josh and Kurt talk about the challenge of dealing with vulnerabilities at a large scale. We tend to treat every vulnerability equally when they are n…
3 years, 8 months ago
Signing (What is it good for)
Season 329
Josh and Kurt talk about what the actual purpose of signing artifacts is. This is one of those spaces where the chain of custody for signing content …
3 years, 8 months ago
The Security of Jobs or Job Security
Episode 328
Josh and Kurt talk about the security of employees leaving jobs. Be it a voluntary departure or in the context of the current layoffs we see, what ar…
3 years, 8 months ago
The security of alert fatigue
Episode 327
Josh and Kurt talk about a funny GitHub reply that notified 400,000 people. It's fun to laugh at this, but it's an easy open to discussing alert fati…
3 years, 9 months ago
Big fat containers
Josh and Kurt talk about containers. There are a lot of opinions around what type of containers is best. Back when it all started there were only hug…
3 years, 9 months ago
Is one open source maintainer enough?
Episode 325
Josh and Kurt talk about a recent OpenSSF issue that asks the question how many open source maintainers should a project have that's "healthy"? Josh …
3 years, 9 months ago
Episode 324 - WTF is up with WFH
Episode 324
Josh and Kurt talk about the whole work from home debate. It seems like there are a lot of very silly excuses why working from home is bad. We've bot…
3 years, 9 months ago
The fake 7-Zip vulnerability and SBOM
Episode 323
Josh and Kurt talk about a fake 7-Zip security report. It's pretty clear that everyone is running open source all the time. We end on some thoughts a…
3 years, 10 months ago
Adam Shostack on the security of Star Wars
Episode 322
Josh and Kurt talk to Adam Shostack about his new book "Threats: What Every Engineer Should Learn From Star Wars". We discuss some of the lessons and…
3 years, 10 months ago
Relativistic Security: Project Zero on 0day
Episode 321
Josh and Kurt talk about the Google Project Zero blog post about 0day vulnerabilities in 2021. There were a lot more than ever before, but why? Part …
3 years, 10 months ago