Épisodes

  • Arch Linux Security with Foxboron and Anthraxx
    Sep 29 2025

    Join us for a conversation with Foxboron (Morten Linderud) and Anthraxx (Levente Polyak), members of the Arch Linux security team. We talk about the difficulties of maintaining a Linux distribution, the challenges of handling CVEs, and the dedication of volunteers who keep the open-source community working (and how overworked those volunteers are). We explain what makes Arch a little different, how they approach their security process, and what sort of help they would love to see in the future.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-arch-foxboron-anthraxx/

    Voir plus Voir moins
    38 min
  • OpenSSL with Hana Andersen and Anton Arapov
    Sep 22 2025

    I discuss all things OpenSSL with Hana Andersen and Anton Arapov from the OpenSSL Corporation. Discover the intricacies of organizing the first-ever OpenSSL conference in Prague, the importance of post-quantum cryptography, and the evolution of OpenSSL from a small team to a global community. Whether you're a seasoned cryptographer or just curious about the future of secure communications, this episode offers insights and stories. Don't miss out on learning how OpenSSL is still shaping the future of cryptography.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-openssl-hana-anton/

    Voir plus Voir moins
    29 min
  • The Python Software Foundation with Deb Nicholson
    Sep 15 2025

    In this episode I discuss the Python Software Foundation with Deb Nicholson. We discuss their contributions to the Python programming community. Learn how this dedicated organization supports the growth and innovation of Python, fostering an ecosystem for developers worldwide. Everything funding open-source projects to organizing community events, discover the initiatives that make the Python Software Foundation a force for positive change in the tech world.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-psf-deb-nicholson/

    Voir plus Voir moins
    38 min
  • Using Mercator to map assets with Didier Barzin
    Sep 8 2025

    In this episode, we the information system mapping tool Mercator with Didier Barzin, a CISO at a hospital in Luxembourg. Discover how Mercator revolutionizes the way organizations map their complex information systems. From hospitals to universities and even the banking sector. Mercator helps manage and protect vast networks by creating dynamic, comprehensive maps that replace outdated Excel sheets. Join us as we explore the challenges and innovations in information security and the impact of Mercator on various industries.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-mercator-didier-barzin/

    Voir plus Voir moins
    26 min
  • Talos Linux security with Andrey Smirnov
    Sep 1 2025

    In this episode, I discuss into the security features of Talos Linux with Andrey Smirnov. Andrey explains how Talos focuses on its immutability and minimal attack surface. Discover how these enhancements fortify your systems against vulnerabilities, ensuring a secure and resilient infrastructure. Join us as we explore the security advancements that make Talos Linux not only a super easy way to run Kubernetes, but also a very secure way.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-talos-andrey-smirnov/

    Voir plus Voir moins
    38 min
  • Discussing the Open Source, Open Threats? paper with Behzad and Ali
    Aug 25 2025

    In this episode I chat with the authors of a recent paper on open source security: Open Source, Open Threats? Investigating Security Challenges in Open-Source Software. I chat with Ali Akhavani and Behzad Ousat about their findings. There are interesting data points in the paper such as a 98% increase in reported vulnerabilities compared to a 25% growth in open source ecosystems. We discuss the challenges of maintaining security in a rapidly expanding digital landscape, and learn about the role of community engagement and automated tools in addressing these discrepancies. It's a great paper and a fantastic discussion.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-08-oss-threats-ali-behzad/

    Voir plus Voir moins
    35 min
  • crates.io trusted publishing with Tobias Bieniek
    Aug 18 2025

    In this episode we discuss crates.io trusted publishing with Tobias Bieniek. We cover the steps crates.io is taking to enhance supply chain security through trusted publishing, a method that leverages short-lived tokens and GitHub actions to safeguard against unauthorized access. Tobias shares insights into the challenges of managing a large-scale open-source repository, offering a glimpse into the future of secure software distribution. Tune in to learn how these advancements are shaping the landscape of open-source development.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-08-cratesio-trusted-publishing-tobias/

    Voir plus Voir moins
    26 min
  • CVE update with Patrick Garrity
    Aug 11 2025

    In this episode I chat with Patrick Garrity from VulnCheck. We discuss the chaos that has enveloped the CVE and NVD programs over the past two years. We cover some of the transparency and communication challenges with the existing program. What some of the new things that have started to emerge as well as why they seem to be struggling. We end on the note that the last 3 months haven't been confidence inspiring. It's likely in 6 months everyone will be scrambling to deal with a difficult situation.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-08-cve-patrick-garrity/

    Voir plus Voir moins
    32 min