Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Andrew Nesbitt boosted
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 2 days ago

This week on #OpenSourceSecurity I chat with @djc and @ctz about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety

https://opensourcesecurity.io/2025/2025-12-rustls-dirkjan-joe/

#TLS #Rustls #Rust #MemorySafety

Open Source Security

Rustls with Dirkjan and Joe

Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many challenges in writing a TLS library (Rust or not). We also chat about some of what’s to come. Rustls has an OpenSSL compatibility layer which makes is a really interesting project. Episode Links Dirkjan Joe Rustls This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
  • Copy link
  • Flag this post
  • Block
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 2 days ago

This week on #OpenSourceSecurity I chat with @djc and @ctz about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety

https://opensourcesecurity.io/2025/2025-12-rustls-dirkjan-joe/

#TLS #Rustls #Rust #MemorySafety

Open Source Security

Rustls with Dirkjan and Joe

Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many challenges in writing a TLS library (Rust or not). We also chat about some of what’s to come. Rustls has an OpenSSL compatibility layer which makes is a really interesting project. Episode Links Dirkjan Joe Rustls This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
  • Copy link
  • Flag this post
  • Block
Andrew Nesbitt boosted
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 4 weeks ago

This episode of #OpenSourceSecurity I chat with Alex Zenla from Edera about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one. Alex fills us in on how it was found, what the coordination looked like, and some things to think about as we manage these incredibly complex supply chains

https://opensourcesecurity.io/2025/2025-12-tarmageddon-alex/

  • Copy link
  • Flag this post
  • Block
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 4 weeks ago

This episode of #OpenSourceSecurity I chat with Alex Zenla from Edera about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one. Alex fills us in on how it was found, what the coordination looked like, and some things to think about as we manage these incredibly complex supply chains

https://opensourcesecurity.io/2025/2025-12-tarmageddon-alex/

  • Copy link
  • Flag this post
  • Block
Andrew Nesbitt boosted
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp last month

On this episode of #OpenSourceSecurity I chat with @hughsie about the Linux Vendor Firmware Service (LVFS)

While it's amazing we can update firmware from Linux now, it was a ton of work to get us here

If you have gear that doesn't work with LVFS, make sure you ask the vendor why not (and support the hardware folks who do support LVFS)

https://opensourcesecurity.io/2025/2025-11-lvfs-richard-hughes/

  • Copy link
  • Flag this post
  • Block
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp last month

On this episode of #OpenSourceSecurity I chat with @hughsie about the Linux Vendor Firmware Service (LVFS)

While it's amazing we can update firmware from Linux now, it was a ton of work to get us here

If you have gear that doesn't work with LVFS, make sure you ask the vendor why not (and support the hardware folks who do support LVFS)

https://opensourcesecurity.io/2025/2025-11-lvfs-richard-hughes/

  • Copy link
  • Flag this post
  • Block
Andrew Nesbitt and 1 other boosted
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 2 months ago

This week on #OpenSourceSecurity I talk to @ottok about his blog post about detecting an attack like xz in Debian

It's a fascinating conversation about a very complicated topic

There are things that could be detected, but this one would have been very very difficult

https://opensourcesecurity.io/2025/2025-11-xz-debian-otto/

Open Source Security

Detecting XZ in Debian with Otto Kekäläinen

In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’s blog post about the XZ backdoor and how it’s a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. Episode Links Otto Could the XZ backdoor have been detected with better Git and Debian packaging practices? This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
  • Copy link
  • Flag this post
  • Block
Josh Bressers
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 2 months ago

This week on #OpenSourceSecurity I talk to @ottok about his blog post about detecting an attack like xz in Debian

It's a fascinating conversation about a very complicated topic

There are things that could be detected, but this one would have been very very difficult

https://opensourcesecurity.io/2025/2025-11-xz-debian-otto/

Open Source Security

Detecting XZ in Debian with Otto Kekäläinen

In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’s blog post about the XZ backdoor and how it’s a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. Episode Links Otto Could the XZ backdoor have been detected with better Git and Debian packaging practices? This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
FreeBSD Foundation
FreeBSD Foundation
@FreeBSDFoundation@mastodon.social  ·  activity timestamp 5 months ago

How do you secure thousands of open-source projects?

At the June 2025 FreeBSD Developer Summit, Michael Winser shared three years of lessons from the Alpha-Omega project—covering supply chain risk, rapid audits, and sustainable funding.

📺 Watch here: Lessons From Funding Open Source Security Over the Past 3 Years, What’s Ahead
https://youtu.be/6DoT-eFH6tY?si=M_zlAfXFrCrvj36_

#BSDCan2025#OpenSourceSecurity#AlphaOmega#FreeBSD

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
FreeBSD Foundation
FreeBSD Foundation
@FreeBSDFoundation@mastodon.social  ·  activity timestamp 5 months ago

How do you secure thousands of open-source projects?

At the June 2025 FreeBSD Developer Summit, Michael Winser shared three years of lessons from the Alpha-Omega project—covering supply chain risk, rapid audits, and sustainable funding.

📺 Watch here: Lessons From Funding Open Source Security Over the Past 3 Years, What’s Ahead
https://youtu.be/6DoT-eFH6tY?si=M_zlAfXFrCrvj36_

#BSDCan2025#OpenSourceSecurity#AlphaOmega#FreeBSD

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct