Open Source Security cover art

All Episodes

Open Source Security — 546 episodes

#
Title
1

CRA vulnerability reporting with Daniel Thompson

2

Finding difficult vulnerabilities with Jaya Baloo from AISLE

3

Sovereign Tech Agency with Erik Möller

4

CVEs vs Advisories with Paul Asadoorian

5

Maintaining EOL Open Source with Commonhaus and HeroDevs

6

Cleanup, Speedup, Levelup open source at e18e

7

VulnCheck's State of Exploitation Report with Patrick Garrity

8

Securing critical infrastructure with Josh Corman

9

Abandoned open source with Josh Marpet

10

Red Hat's Project Lightwell with Mo Duffy

11

Rust Foundation Maintainers Fund with Lori and Niko

12

AIBOM, CBOM, and HBOM with Allan Friedman

13

Packagist and Composer security with Jordi Boggiano

14

Sustaining Open VSX with Mike and Thabang

15

Hacking your CI/CD with François Proulx

16

Open source verification with Sal Kimmich

17

Vulnerability disclosure with Casey Ellis

18

F-Droid the open app store with Hans

19

Open source is critical infrastructure with Kat Cosgrove

20

How to actually test a disaster plan with David Bernstein

21

Open Source Pledge with Vlad-Stefan Harbuz

22

Building a plan for disaster with David Bernstein

23

Open Source Malware with Paul McCarty

24

Package management challenges with Andrew Nesbitt

25

Open Source Security at scale with Michael Winser

26

2026 State of the Software Supply Chain with Brian Fox

27

MCP and Agent security with Luke Hinds

28

The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

29

Rust coreutils with Sylvestre Ledru

30

Goose and the Agentic AI Foundation with Brad Axen

31

The Global Vulnerability Intelligence Platform with Olle E. Johansson

32

Digital Sovereignty and Nextcloud with Frank Karlitschek

33

The Art of Crisis Management with David Bernstein

34

WTF is a passkey with William Brown

35

All about Suricata with Victor Julien

36

Iocaine poisons bots with Gergely Nagy

37

Anubis with Xe Iaso

38

Rustls with Dirkjan and Joe

39

Daniel Thompson answers: Does the CRA apply to Santa?

40

Linux Foundation Europe with Gabriele Columbro

41

Updating open source dependencies with Jamie Tanna

42

TARmageddon with Alex Zenla

43

Python Security with Seth Larson

44

Linux Vendor Firmware Service with Richard Hughes

45

NPM supply chain attacks with Charlie Eriksen

46

Detecting XZ in Debian with Otto Kekäläinen

47

Eclipse Foundation SBOMs with Mikael Barbero

48

Actually finding vulnerabilities using AI with Joshua Rogers

49

Sustaining Package Repositories with Brian Fox

50

Arch Linux Security with Foxboron and Anthraxx

51

OpenSSL with Hana Andersen and Anton Arapov

52

The Python Software Foundation with Deb Nicholson

53

Using Mercator to map assets with Didier Barzin

54

Talos Linux security with Andrey Smirnov

55

Discussing the Open Source, Open Threats? paper with Behzad and Ali

56

crates.io trusted publishing with Tobias Bieniek

57

CVE update with Patrick Garrity

58

GCVE with Cédric Bonhomme and Alexandre Dulaunoy

59

EU Regulations will change everything with Daniel Thompson

60

Open source microprocessors with Jan Pleskac

61

Package URLs with Philippe Ombredanne

62

Hobbyist Maintainers with Thomas DePierre

63

STIG automation with Aaron Lippold

64

Ecosyste.ms with Andrew Nesbitt

65

Curl vs AI with Daniel Stenberg

66

Repository signing with Kairo De Araujo

67

Securing GitHub Actions with William Woodruff

68

Embedded Security with Paul Asadoorian

69

tj-actions with Endor Lab's Dimitri Stiliadis

70

Syft, Grype, and Grant with Alan Pope

71

CVE for EOL with Aaron Frost

72

cargo-semver-checks with Predrag Gruevski

73

Distributed CI and Git with Lars Wirzenius

74

FIDO authentication with William Brown

75

CRA with Luis Villa

76

Open Source Malware with Brian Fox

77

Open Source Foundations with Kelley Misata of Suricata

78

Forking Open Source Projects with Sheogorath

79

Patching EOL Open Source with Aaron Frost

80

Why do we keep ignoring CI security with François Proulx

81

Modern day authentication with Marc Boorshtein

82

Open Source Maintenance with Gary Kramlich

83

Safety vs Security with Thomas Depierre

84

The Future of Open Source Security

85

Episode 461 - The new NIST password guidance

86

Episode 460 - Santa's Supply Chain Security

87

Episode 459 - CWE Top 25 List

88

Episode 458 - FBI endorses E2E encryption

89

Episode 457 - The D-Link D-bacle

90

Episode 456 - What if XZ happened to a company? The openness of open source

91

Episode 455 - Wordpress plugin security

92

Episode 454 - The state of open source with Brian Fox from Sonatype and Donald Fischer from Tidelift

93

Episode 453 - Software Liability

94

Episode 452 - All about Meshtastic

95

Episode 451 - Python security with Seth Larson

96

Episode 450 - What's Wrong With WordPress

97

Episode 449 - The CUPSpocalypse

98

Episode 448 - What's wrong with CISA?

99

Episode 447 - The Tidelift 2024 open source maintainer report

100

Episode 446 - Researchers took over .MOBI TLD

101

Episode 445 - EPSS with Jay Jacobs

102

Episode 444 - Open Source and End of Life

103

Episode 443 - The Supply Chain Security Crisis

104

Episode 442 - The foundation of society, TLS certificates are a mess

105

Episode 441 - Is CWE useful?

106

Episode 440 - "What is open source" talk Josh gave

107

Episode 439 - Where are all the youth in open source?

108

Episode 438 - CISA's bad OSS advice vs the Whitehouse good advice

109

Episode 437 - CocoPods and proper funding for open source

110

Episode 436 - OpenSSH and node-ip - it's all exponential growth

111

Episode 435 - polyfill.io - open source is too big to fix

112

Episode 434 - Unreported vulnerabilities and everyone is getting hacked

113

Episode 433 - Should OpenSSH block misbehaving clients?

114

Episode 432 - Flipper Zero with Alex Kulagin

115

Episode 431 - Redirecting HTTP to HTTPS

116

Episode 430 - Frozen kernel security

117

Episode 429 - The autonomy of open source developers

118

Episode 428 - GitHub artifact attestation

119

Episode 427 - Will run0 replace sudo?

120

Episode 426 - Automatically exploiting CVEs with AI

121

Episode 425 - Video game cheaters, also pretendo

122

Episode 424 - The Notepad++ Parasite Website

123

Episode 423 - FCC cybersecurity label for consumer devices

124

XZ Bonus Spectacular Episode

125

Episode 422 - Do you have a security.txt file?

126

Episode 421 - CISA's new SSDF attestation form

127

Episode 420 - What's going on at NVD

128

Episode 419 - Malicious GitHub repositories

129

Episode 418 - Being right all the time is hard

130

Episode 417 - Linux Kernel security with Greg K-H

131

Episode 416 - Thomas Depierre on open source in Europe

132

Episode 415 - Reducing attack surface for less security

133

Episode 414 - The exploited ecosystem of open source

134

Episode 413 - PyTorch and NPM get attacked, but it's OK

135

Episode 412 - Blame the users for bad passwords!

136

Episode 411 - The security tools that started it all

137

Episode 410 - Package identifiers are really hard

138

Episode 409 - You wouldn't hack a train?

139

Episode 408 - Does Kubernetes need long term support?

140

Episode 407 - Should Santa use AI?

141

Episode 406 - The security of radio

142

Episode 405 - Modding games isn't cheating and security isn't fair

143

Episode 403 - Does the government banning apps work?

144

Episode 402 - The EU's eIDAS regulation is a terrible idea

145

Episode 401 - Security skills shortage - We've tried nothing and the same thing keeps happening

146

Episode 400 - When can the government hack a victim?

147

Episode 399 - Curl, Security, and Daniel Stenberg

148

Episode 398 - Is only 11% of open source maintained?

149

Episode 397 - The curl and glibc vulnerabilities

150

Episode 396 - CLAs are bad, Mkay?

151

Episode 395 - Uncertainty, trust, and security

152

Episode 394 - The lie anyone can contribute to open source

153

Episode 393 - Can you secure something you don't own?

154

Episode 392 - Curl and the calamity of CVE

155

Episode 391 - The Wordpress 100 year disaster recovery problem

156

Episode 390 - Rust shipping binaries doesn't matter

157

Episode 389 - What would HashiCorp do?

158

Episode 388 - Video game vulnerabilities

159

Episode 387 - Enterprise open source is different

160

Episode 386 - We are watching web 2.0 burn

161

Episode 385 - Is open source an insider threat?

162

Episode 384 - What's next for open source?

163

Episode 383 - Is open source dying?

164

Episode 382 - Red Hat, you were the chosen one!

165

Episode 381 - WTF Reddit, APIs and risk

166

Episode 380 - A new Sovereign Tech Fund program and the BBC on destroying hard drives

167

Episode 379 - Will open source save the world, again?

168

Episode 378 - Naming things is harder than security

169

Episode 377 - The world is changing too fast for humans to understand

170

Episode 376 - Open Source Summit, who built your open source, and AI

171

Episode 375 - The market forces of left-pad, Episode 77 remaster part 2

172

Episode 374 - The event we called left-pad, Episode 77 remaster part 1

173

Episode 373 – HHGG security, Episode 42 remaster part 2

174

Episode 372 - HHGG security, Episode 42 remaster part 1

175

Episode 371 - pip install is the tool we deserve but not the tool we need

176

Episode 370 - Open Source is bigger than you can imagine

177

Episode 369 - OpenAI broke ChatGPT then tried to blame open source

178

Episode 368 - The Sovereign Tech Fund with Fiona Krakenbürger

179

Episode 367 - Open source will never be the same

180

Episode 366 - Software liability is coming

181

Episode 365 - "I am not your supplier" with Thomas Depierre

182

Episode 364 - Using SBOMs is hard

183

Episode 363 - Joylynn Kirui from Microsoft on DevSecOps

184

Episode 362 - A lesson in Rust from Carol Nichols

185

Episode 361 - GitHub got pwnt, but it wasn't very exciting

186

Episode 360 - Memory safety and the NSA

187

Episode 359 - The NOTAM outage and other legacy technology

188

Episode 358 - Furby vs Alexa

189

Episode 357 - Is open source being overexploited?

190

Episode 356 - LastPass ducked up, now what?

191

Episode 355 - Security Boxing Day

192

Episode 354 - Jerry Bell tells us why Mastodon is awesome and MFA is hard

193

Episode 353 - Jill Moné-Corallo on GitHub's bug bounty program

194

Episode 352 - Stylometry removes anonymity

195

Episode 351 - Is security or usability a law of the universe?

196

Episode 350 - Spam, Email, Content Moderation, and Infrastructure Oh My

197

Episode 349 - The cyber is coming from inside the house - the UK is scanning itself

198

Episode 348 - OpenSSL is the new lead paint

199

Episode 347 - Airtags in luggage and weasel security - two peas in a suitcase

200

Episode 346 - Security and working from home have terrible things in common

201

Episode 345 - Cheap hacking devices turn security upside down

202

Episode 344 - Python tarfile - 2022 is nothing like 2007

203

Episode 343 - Stop trying to fix the open source software supply chain

204

Episode 342 - Programming languages are the new operating system

205

Episode 341 - Time till open source alternative

206

Episode 340 - Let's chat about Let's Encrypt with Josh Aas

207

Episode 339 - Is a network problem a security vulnerability

208

Episode 338 - The government didn't make vulnerabilities illegal. Yet.

209

Episode 337 - Security patches are getting worse - Dustin Childs from ZDI tells us why

210

Episode 336 - We don't have data, we have security biases

211

Episode 335 - Bull*&$% security ideas

212

Episode 334 - Leap seconds break everything

213

Episode 333 - Open Source is unfair

214

Episode 332 - PyPI: 2FA or not 2FA, that is the question

215

Episode 331 - GPG, but nothing makes sense

216

Episode 330 - The sliding scale of risk: seeing the forest for the trees

217

Episode 329 - Signing (What is it good for)

218

Episode 328 - The Security of Jobs or Job Security

219

Episode 327 - The security of alert fatigue

220

Episode 326 - Big fat containers

221

Episode 325 - Is one open source maintainer enough?

222

Episode 324 - WTF is up with WFH

223

Episode 323 - The fake 7-Zip vulnerability and SBOM

224

Episode 322 - Adam Shostack on the security of Star Wars

225

Episode 321 - Relativistic Security: Project Zero on 0day

226

Episode 320 - Security Twitter is not the real world

227

Episode 319 - Patch Tuesday with a capital T

228

Episode 318 - Social engineering and why zlib got a 2018 CVE ID

229

Episode 317 - The lack of compromise in security

230

Episode 316 - You have to use open source

231

Episode 315 - Who even makes all these terrible decisions?

232

Episode 314 - The Linux Dirty Pipe vulnerability

233

Episode 313 - Insecurity at scale

234

Episode 312 - The Legend of the SBOM

235

Episode 311 - Did you scan the QR code?

236

Episode 310 - Hayley Tsukayama from the EFF talks about privacy

237

Episode 309 - The bright future of open source security

238

Episode 308 - Welcome to the jungle - How to talk about open source security

239

Episode 307 - Got vulnerabilities? Introducing GSD

240

Episode 306 - Open source isn't broken, it's an experience

241

Episode 305 - Norton, Ethereum, NFT, and Apes

242

Episode 304 - Will we ever fix all the vulnerabilities?

243

Episode 303 - Log4j Christmas Spectacular!

244

Episode 302 - Log4j is a mess

245

Episode 301 - You're holding it wrong: the importance of unlearning

246

Episode 300 - Apple vs NSO: What can copyright do for you?

247

Episode 299 - Experts From A World That No Longer Exists

248

Episode 298 - David A Wheeler discusses the OpenSSF

249

Episode 297 - 25 years of smashing stacks, fun, and profit

250

Episode 296 - Is Trojan Source a vulnerability?

251

Episode 295 - Open source security isn't free

252

Episode 294 - Chris Wysopal on the state of security education

253

Episode 293 - Scoring OpenSSF Security Scoring

254

Episode 292 - Apache RCE and Twitch epic pwn

255

Episode 291 - Everyone sucks at vulnerability disclosure

256

Episode 290 - The security of the Matrix

257

Episode 289 - Who left this 0day on the floor?

258

Episode 288 - Linux Kernel compiler warnings considered dangerous

259

Episode 287 - Is GitHub's Copilot the new Clippy?

260

Episode 286 - Open source supply chain with Google's Dan Lorenc

261

Episode 285 - Open source owes you nothing!

262

Episode 284 - What happens when we DRM power tools?

263

Episode 283 - When vulnerability disclosure becomes dangerous

264

Episode 282 - The security of Rust: who left all this awesome in here?

265

Episode 281 - If you spy on journalists, you're the bad guys

266

Episode 280 - The perils of Single Sign On

267

Episode 279 - The audacity of Audacity: When open source goes rogue

268

Episode 278 - Could SELinux have stopped SolarWinds?

269

Episode 277 - Privacy and activism with Chris Weiland

270

Episode 276 - Security, behavior, and the environment

271

Episode 275 - What in the @#$% is going on with ransomware?

272

Episode 274 - Mr. Amazon's Neighborhood

273

Episode 273 - Can we stop the coming artificial unintelligence deluge?

274

Episode 272 - The Biden Cybersecurity Executive Order

275

Episode 271 - Pipeline security: There is no problem humans can't make worse

276

Episode 270 - Hello dark patterns my old friend

277

Episode 269 - Do not experiment on the Linux Kernel

278

Episode 268 - Can we trust any 3rd parties?

279

Episode 267 - Does 0day still mean 0day?

280

Episode 266 - The future of security scanning with Debricked

281

Episode 265 - The lies closed source can tell, open source can't

282

Episode 264 - DevSecOps with GitLab's Mark Loveless

283

Episode 263 - GitHub pulls exploits, LinuxFoundation sign all the things

284

Episode 262 - A discussion with Loris and Pop from Sysdig

285

Episode 261 - DWF is back! Welcome to community powered CVE

286

Episode 260 - Dave Jevans tells us what CipherTrace is up to

287

Episode 259 - What even is open source anymore?

288

Episode 258 - Stop using C

289

Episode 257 - The sudo and libgcrypt vulnerabilities

290

Episode 256 - 9 bits of podcast, 8 bits of computing

291

Episode 255 - What if security wasn't joyless?

292

Episode 254 - Right to Repair Security

293

Episode 253 - Defenders only need to be right once

294

Episode 252 - Is open source dangerous? Open source won, who cares, shut up!

295

Episode 251 - Communication is hard, security communication is more hard

296

Episode 250 - Door 25: Why do we do the things we do? Question everything

297

Episode 249 - Door 24: Information wants to be free

298

Episode 248 - Door 23: How to report 1000 security flaws

299

Episode 247 - Door 22: How to report one security flaw

300

Episode 246 - Door 21: Bug bounties

301

Episode 245 - Door 20: Is SMS 2FA better than no 2FA?

302

Episode 244 - Door 19: TLS certificate trust

303

Episode 243 - Door 18: Don't roll your own crypto or auth

304

Episode 242 - Door 17: Vulnerability response

305

Episode 241 - Door 16: 16 bits of change

306

Episode 240 - Door 15: Supplier compliance

307

Episode 239 - Door 14: Backdoors

308

Episode 238 - Door 13: Unlucky or survivor bias?

309

Episode 237 - Door 12: Video game hacking

310

Episode 236 - Door 11: Should you get on a 737?

311

Episode 235 - Door 10: Deciding what information matters

312

Episode 234 - Door 09: public key cryptography

313

Episode 233 - Door 08: man 8 security

314

Episode 232 - Door 07: 7 is the best prime, 2 is the dumbest

315

Episode 231 - Door 06: 6 wifi risks ... that don't actually matter

316

Episode 230 - Door 05: 5 reasons you need 24/7 robot monitoring

317

Episode 229 - Door 04: EFF's Cover Your Tracks

318

Episode 228 - Door 03: Do all vulnerabilities matter equally?

319

Episode 227 - Door 02: Marketing department or selection bias?

320

Episode 226 - Door 01: Advent calendars

321

Episode 225 - Who is responsible if IoT burns down your house?

322

Episode 224 - Are old Android devices dangerous?

323

Episode 223 - Full disclosure won, deal with it

324

Episode 222 - HashiCorp Boundary with Jeff Mitchell

325

Episode 221 - Security, magic, and FaceID

326

Episode 220 - Securing network time and IoT

327

Episode 219 - Chat with Larry Cashdollar

328

Episode 218 - The past was a terrible place

329

Episode 217 - How to tell your story with Travis Murdock

330

Episode 216 - Security didn't find life on Venus

331

Episode 215 - Real security is boring

332

Episode 213 - Security Signals: What are you telling the world

333

Episode 212 - Grab Bag: The Security We Deserve Edition

334

Episode 211 - The only thing harder than signing files is managing users

335

Episode 210 - Cult of Information Security

336

Episode 209 - Secure Boot isn't Secure

337

Episode 208 - Passwords are pollution

338

Episode 207 - Weaponized attention

339

Episode 206 - Confidential Virtual Machines; The future of cloud computing

340

Episode 205 - The State of Open Source Security with Alyssa Miller from Snyk

341

Episode 204 - What Would Apple Do?

342

Episode 203 - Humans, conferences, and security: let me think and get back to you in a bit

343

Episode 202 - The convergence of application security

344

Episode 201 - We broke CVSSv3, now how do we fix it?

345

Episode 200 - Talking Container Security with Liz Rice

346

Episode 199 - Special cases are special: DNS, Websockets, and CSV

347

Episode 198 - Good advice or bad advice? Hang up, look up, and call back

348

Episode 197 - Beer, security, and consistency; the newer, better, triad

349

Episode 196 - Pounding square solutions into round holes: forced updates from Ubuntu

350

Episode 195 - Is BGP actually insecure?

351

Episode 194 - Working from home security: resistance is futile

352

Episode 193 - Security lessons from space: Apollo 13 edition

353

Episode 192 - Work without progress - what Infosec can learn from treadmills

354

Episode 191 - Security scanners are all terrible

355

Episode 190 - Building a talent "ecosystem"

356

Episode 189 - Video game hackers - speedrunning

357

Episode 188 - Depressing news sucks, we're talking about cheating in video games

358

Episode 187 - Wireguard vs IPsec: the OK Boomer of security

359

Episode 186 - Endpoint security with Tony Meehan

360

Episode 185 - Is it even possible to fix open source security?

361

Episode 184 - It's DNS. It's always DNS

362

Episode 183 - The great working from home experiment

363

Episode 182 - Does open source owe us anything?

364

Episode 181 - The security of SIM swapping

365

Episode 180 - A Tale of Two Vulnerabilities

366

Episode 179 - Google Project Zero and the 90 day clock

367

Episode 178 - Are CVEs important and will ransomware put you out of business?

368

Episode 177 - Fake or real? The security of counterfeit goods

369

Episode 176 - The 'predictions are stupid' prediction episode

370

Episode 175 - Defenders will always be one step behind

371

Episode 174 - GitHub turns security up to 11; A discussion with Rob Schultheis

372

Episode 173 - Ho Ho Homeland Security

373

Episode 172 - The security of planned obsolescence

374

Episode 171 - Measuring cybersecurity with Kathryn Waldron

375

Episode 170 - Until that quantum computer is cracking RSA keys, go sit back down!

376

Episode 169 - What happens when leadership doesn't care about security?

377

Episode 168 - The draconian draconians of DRM

378

Episode 167 - Security is terrible because digital literacy is terrible

379

Episode 166 - Every day should be cybersecurity awareness month!

380

Episode 165 - Grab Bag of Microsoft Security News

381

Episode 164 - DNS over HTTPS: Probably not the end of the world

382

Episode 163 - Death to Python 2

383

Episode 162 - SBOM with Allan Friedman

384

Episode 161 - Human nature and ad powered open source

385

Episode 160 - Disclosing security issues is insanely complicated: Part 2

386

Episode 159 - Disclosing security issues is insanely complicated: Part 1

387

Episode 158 - The mess that we call credit agencies in the US

388

Episode 157 - Backdoors and snake oil in our cryptography

389

Episode 156 - What if we MitM a whole country?

390

Episode 155 - Stealing cars and ransomware

391

Episode 154 - Chat with the authors of the book "The Fifth Domain"

392

Episode 153 - The unexpected security of AI, photographs, and VPN

393

Episode 152 - Tavis breaks the world ... again

394

Episode 151 - The DARPA Cyber Grand Challenge with David Brumley

395

Episode 150 - Our ad funded dystopian present

396

Episode 149 - Chat with Michael Coates about data security

397

Episode 148 - You just got pwnt, what now?

398

Episode 147 - Scams and operations as part of the supply chain

399

Episode 146 - What the @#$% happened to Microsoft?

400

Episode 145 - What do security and fire have in common?

401

Episode 144 - The security of money, which one is best?

402

Episode 143 - Security lessons from the phone book

403

Episode 142 - Hypothetical security: what if you find a USB flash drive?

404

Episode 141 - Timezones are hard, security is harder

405

Episode 140 - Good enough security is a pretty high bar

406

Episode 139 - Secure voting, firefox send, and toxic comments on the internet

407

Episode 138 - Information wants to be free

408

Episode 137.5 - Holy cow Beto was in the cDc, this is awesome!

409

Episode 137 - When the IoT attacks!

410

Episode 136 - How people feel is more important than being right

411

Episode 135 - Passwords, AI, and cloud strategy

412

Episode 134 - What's up with the container runc security flaw?

413

Episode 133 - Smart locks and the government hacking devices

414

Episode 132 - Bird Scooter: 0, Cory Doctorow: 1

415

Episode 131 - Windows micropatches, Google's privacy fine, and Mastercard fixes trial abuse

416

Episode 130 - Chat with Snyk co-founder Danny Grander

417

Episode 129 - The EU bug bounty program

418

Episode 128 - Australia's encryption backdoor bill

419

2018 Christmas Special - Is Santa GDPR compliant?

420

Episode 127 - Walled gardens, appstores, and more

421

Episode 126 - The not so dire future of supply chain security

422

Episode 125 - Open Source, supply chains, npm, and you

423

Episode 124 - Cloudflare's service workers and the economics of security

424

Episode 123 - Talking about Kubernetes and container security with Liz Rice

425

Episode 122 - What will Apple's T2 chip mean for the rest of us?

426

Episode 121 - All about the security of voting

427

Episode 120 - Bloomberg and hardware backdoors - it's already happening

428

Episode 119 - The Google+ and Facebook incidents, it's not your data anymore

429

Episode 118 - Cloudflare's IPFS and onion service

430

Episode 117 - Will security follow Linus' lead on being nice?

431

Episode 116 - The future of the CISO with Michael Piacente

432

Episode 115 - Discussion with Brian Hajost from SteelCloud

433

Episode 114 - Review of "Click Here to Kill Everybody"

434

Episode 113 - Actual real security advice

435

Episode 112 - Google's Titan Key and the latest Struts issue

436

Episode 111 - The TLS 1.3 and DNS episode

437

Episode 110 - Review of Black Hat, Defcon, and the effect of security policies

438

Episode 109 - OSCon and actionable advice

439

Episode 108 - Bluetooth, phishing, airgaps, and eating soup off the floor

440

Episode 107 - The year of the Linux Desktop and other hardware stories

441

Episode 106 - Data isn't oil, it's nuclear waste

442

Episode 105 - More backdoors in open source

443

Episode 104 - The Gentoo security incident

444

Episode 103 - The Seven Properties of Highly Secure Devices

445

Episode 102 - Michael Feiertag from tCell

446

Episode 101 - Our unregulated future is here to stay

447

Episode 100 - You're bad at buying security, we can help!

448

Episode 99 - Consumer security is too broken to fix, and it doesn't matter

449

Episode 98 - When IT decisions kill people

450

Episode 97 - Automation: Humans are slow and dumb

451

Episode 96 - Are legal backdoors a good idea?

452

Episode 95 - Twitter passwords and npm backdoors

453

Episode 94 - DNSSEC, BGP, and reality

454

Episode 93 - Security flaws in beep and patch, how did we get here?

455

Episode 92 - Chat with Rami Saas the CEO of WhiteSource

456

Episode 91 - Security lessons from a 7 year old

457

Episode 90 - Humans and misinformation

458

Episode 89 - Short selling AMD security flaws

459

Episode 88 - Chat with Chris Rosen from IBM about Container Security

460

Episode 87 - Chat with Let's Encrypt co-founder Josh Aas

461

Episode 86 - What happens when 23 thousand certificates leak?

462

Episode 85 - NPM ate my files

463

Episode 84 - Have I been pwned?

464

Episode 83 - XKCD + CVE = XKCVE

465

Episode 82 - RSA, TLS, Chrome HTTP, and PCI

466

Episode 81 - Autosploit, bug bounties, and the future of security

467

Episode 80 - GPS tracking and jamming

468

Episode 79 - Skyfall: please don't yell 'fire'

469

Episode 78 - Risk lessons from Hawaii

470

Episode 77 - npm and the supply chain

471

Episode 76 - Meltdown aftermath

472

Episode 75 - Security Planner review

473

Episode 74 - Facial recognition and physical security

474

Episode 73 - Security from Santa

475

Episode 72 - Bitcoin: It's over 9000

476

Episode 71 - GitHub's Security Scanner

477

Episode 70 - The security of Intel ME

478

Episode 69 - Actionable security advice

479

Episode 68 - Ruining the Internet

480

Episode 67 - Cyber won

481

Episode 66 - Objects in mirror are less terrible than they appear

482

Episode 65 - Will aliens overthrow us before AI?

483

Episode 64 - Networks and Dnsmasq and IoT oh my

484

Episode 63 - Shoot, Shovel, and Bury

485

Episode 62 - All about the Equifax hack

486

Episode 61 - Market driven security

487

Episode 60 - The official blockchain episode

488

Episode 59 - The VPN Episode

489

Episode 58 - Backwards compatibility to the point of insanity

490

Episode 57 - We may never see amazing security research ever again

491

Episode 56 - Devil's Advocate and other fuzzy topics

492

Episode 55 - Good Docs Ruin My Story

493

Episode 54 - Turning Into An Old Person

494

Episode 53 - A Plane Isn't Like A Car

495

Episode 52 - You Could Have Done It Right, But You Didn't

496

Episode 51 - All About CVE

497

Episode 50 - This Is A Security Podcast After All

498

Episode 49 - Testing Software Is Impossible

499

Episode 48 - Machine Learning: Not Actually Magic

500

Episode 47 - WannaCry: Everything Is Basically Broken

501

Episode 46 - Turns Out I'm Not A Bad Guy

502

Episode 45 - Trust Is More Important Now Than The Truth

503

Episode 44 - Bug Bounties Vs Pen Testing

504

Episode 43 - We Are Totally Immature

505

Episode 42 - Hitchhiker's Guide To Security

506

Episode 41 - All Your Money Are Belong To Us

507

Episode 40 - Let's Fork Bitcoin, Again

508

Episode 39 - Flash On Your Dishwasher

509

Episode 38 - We Ruin Everything

510

Episode 37 - Your Bathtub Is More Dangerous Than A Shark

511

Episode 36 - A Good Enough Podcast

512

Episode 35 - Crazy Cosmic Accident

513

Episode 34 - Bathing In Ebola Virus

514

Episode 33 - Everybody Who Went To The Circus Is In The Circus (RSA 2017)

515

Episode 32 - Gambling As A Service

516

Episode 31 - XML Is Never The Solution

517

Episode 30 - I'm Not An Expert But I've Been Yelled At By Experts

518

Episode 29 - The Security Of Rogue One

519

Episode 28 - RSA Conference 2017

520

Episode 27 - Prove To Me You Are Human

521

Episode 26 - Tell Your Sister, Stallman Was Right

522

Episode 25 - The Future Is Now

523

Episode 24 - The 2016 Prediction Edition

524

Episode 23 - We Can't Patch People

525

Episode 22 - IoT Wild West

526

Episode 21 - CVE 10K Extravaganza

527

Episode 20 - The Death Of PGP

528

Episode 19 - A Field Full Of Razor Blades And Monsters

529

Episode 18 - The Security Of Santa

530

Episode 17 - Cyphercon Interview With Korgo

531

Episode 16 - Cat And Mouse

532

Episode 15 - Cyber Black Monday

533

Episode 14 - David A Wheeler: CII Badges

534

Episode 13 - CVE: The Metric System Of Security

535

Episode 12 - Security Trebuchet

536

Episode 11 - The Poison Candy Episode

537

Episode 10 - The Super Botnet That Nobody Can Stop

538

Episode 9 - Are Bug Bounties Measuring The Wrong Things

539

Episode 8 - The Primality Of Prime Numbers

540

Episode 7 - More Powerful Than Root

541

Episode 6 - Foundational Knowledge Of Security

542

Episode 5 - OpenSSL: The Library We Deserve

543

Episode 4 - Dead Squirrel In A Box

544

Episode - 3 The Lockpicking Sewing Circle

545

Episode 2 - Instills The Proper Amount Of Fear

546

Episode 1 - Rich History Of Security Flaws