Episodes

  • OpenSSL with Hana Andersen and Anton Arapov
    Sep 22 2025

    I discuss all things OpenSSL with Hana Andersen and Anton Arapov from the OpenSSL Corporation. Discover the intricacies of organizing the first-ever OpenSSL conference in Prague, the importance of post-quantum cryptography, and the evolution of OpenSSL from a small team to a global community. Whether you're a seasoned cryptographer or just curious about the future of secure communications, this episode offers insights and stories. Don't miss out on learning how OpenSSL is still shaping the future of cryptography.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-openssl-hana-anton/

    Show More Show Less
    29 mins
  • The Python Software Foundation with Deb Nicholson
    Sep 15 2025

    In this episode I discuss the Python Software Foundation with Deb Nicholson. We discuss their contributions to the Python programming community. Learn how this dedicated organization supports the growth and innovation of Python, fostering an ecosystem for developers worldwide. Everything funding open-source projects to organizing community events, discover the initiatives that make the Python Software Foundation a force for positive change in the tech world.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-psf-deb-nicholson/

    Show More Show Less
    38 mins
  • Using Mercator to map assets with Didier Barzin
    Sep 8 2025

    In this episode, we the information system mapping tool Mercator with Didier Barzin, a CISO at a hospital in Luxembourg. Discover how Mercator revolutionizes the way organizations map their complex information systems. From hospitals to universities and even the banking sector. Mercator helps manage and protect vast networks by creating dynamic, comprehensive maps that replace outdated Excel sheets. Join us as we explore the challenges and innovations in information security and the impact of Mercator on various industries.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-mercator-didier-barzin/

    Show More Show Less
    26 mins
  • Talos Linux security with Andrey Smirnov
    Sep 1 2025

    In this episode, I discuss into the security features of Talos Linux with Andrey Smirnov. Andrey explains how Talos focuses on its immutability and minimal attack surface. Discover how these enhancements fortify your systems against vulnerabilities, ensuring a secure and resilient infrastructure. Join us as we explore the security advancements that make Talos Linux not only a super easy way to run Kubernetes, but also a very secure way.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-09-talos-andrey-smirnov/

    Show More Show Less
    38 mins
  • Discussing the Open Source, Open Threats? paper with Behzad and Ali
    Aug 25 2025

    In this episode I chat with the authors of a recent paper on open source security: Open Source, Open Threats? Investigating Security Challenges in Open-Source Software. I chat with Ali Akhavani and Behzad Ousat about their findings. There are interesting data points in the paper such as a 98% increase in reported vulnerabilities compared to a 25% growth in open source ecosystems. We discuss the challenges of maintaining security in a rapidly expanding digital landscape, and learn about the role of community engagement and automated tools in addressing these discrepancies. It's a great paper and a fantastic discussion.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-08-oss-threats-ali-behzad/

    Show More Show Less
    35 mins
  • crates.io trusted publishing with Tobias Bieniek
    Aug 18 2025

    In this episode we discuss crates.io trusted publishing with Tobias Bieniek. We cover the steps crates.io is taking to enhance supply chain security through trusted publishing, a method that leverages short-lived tokens and GitHub actions to safeguard against unauthorized access. Tobias shares insights into the challenges of managing a large-scale open-source repository, offering a glimpse into the future of secure software distribution. Tune in to learn how these advancements are shaping the landscape of open-source development.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-08-cratesio-trusted-publishing-tobias/

    Show More Show Less
    26 mins
  • CVE update with Patrick Garrity
    Aug 11 2025

    In this episode I chat with Patrick Garrity from VulnCheck. We discuss the chaos that has enveloped the CVE and NVD programs over the past two years. We cover some of the transparency and communication challenges with the existing program. What some of the new things that have started to emerge as well as why they seem to be struggling. We end on the note that the last 3 months haven't been confidence inspiring. It's likely in 6 months everyone will be scrambling to deal with a difficult situation.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025-08-cve-patrick-garrity/

    Show More Show Less
    32 mins
  • GCVE with Cédric Bonhomme and Alexandre Dulaunoy
    Aug 4 2025

    In this episode I discuss GCVE and Vulnerability-Lookup with Alex and Cedric from CIRCL. GCVE offers a decentralized approach, allowing organizations to assign their own IDs and publish vulnerabilities independently. Vulnerability-Lookup is the tool that makes GCVE a reality. The flexibility addresses many of the limitations we see today with a single centralized ID system. The work happening by CIRCL on GCVE is very impressive, with all the current CVE turmoil, this is a project we should all be paying attention to.

    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2025/2025/2025-08-gcve-cedric-alex/

    Show More Show Less
    32 mins