
Advertise on podcast: Open Source Security
Rating
4.7from
This podcast has
525 episodes
Language
EnglishPublisher
Josh BressersExplicit
No
Date created
2016/09/07
Latest episode
2026/04/20
Average duration
38 min.
Release period
7 days
Description
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.
Unlock Open Source Security podcast Email contact info,
Listeners & Audience details
Email contact information
Direct podcast contact details

Listeners
Audience numbers & engagement insights

Audience details
Podcast Insights

Podcast episodes
Check latest episodes from Open Source Security podcast
Building a plan for disaster with David Bernstein
2026/04/20
Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are some great resources for this planning, but as David tells us, it's really not that hard to put some plans together. It's easy to over-plan, David gives some great tips on getting started with our planning for an eventual incident.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/
Open Source Malware with Paul McCarty
2026/04/13
Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We of course touch on AI and the malware in skills problems and challenges. It's a fun discussion with a lot of new and interesting problems we all have to deal with.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/
Package management challenges with Andrew Nesbitt
2026/04/06
Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who look at multiple ecosystems in the way Andrew does. He has thoughts on why it's so hard to create a new ecosystem as well as some of the reasons we don't see a C language ecosystem. Andrew has a ton of interesting ideas and insight for us about both existing, new, and nonexistent ecosystems.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-04-ecosystems-andrew/
Open Source Security at scale with Michael Winser
2026/03/30
Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we could fund some really big, really hard projects? It's not cheap or easy, but he's getting it done. We spend a lot of the time discussing package registries, which are a huge topic. Michael is doing some amazing work helping package registries which is the first step in a very long journey.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-03-michael-winser/
2026 State of the Software Supply Chain with Brian Fox
2026/03/23
Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/
MCP and Agent security with Luke Hinds
2026/03/16
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We explain what MCP and agents are doing as well as why it's so hard to secure them. It's not impossible, but it's not simple either. We end the show by discussing some of the more human aspects to security and how history may be repeating itself with security folks laughing at new users who don't know any better.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-03-mcp-agent-luke/
The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer
2026/03/09
Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statement and their relationship with OpenSSL. We chat about some of the current features in cryptography, as well as some of what's coming in the future. It's a fun conversation that hits on a lot of great points.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/
Rust coreutils with Sylvestre Ledru
2026/03/02
Josh talks to Sylvestre Ledru about the Rust coreutils project. We've been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason isn't security, it's to modernize the code and attract new contributors. Sylvestre discusses with quite pleasant relationship with the GNU coreutils developers, some of the challenges in the project. What Ubuntu using this by default meant, and also gives us some things to watch for in the future. It's a super fun discussion about why Rust is not only awesome, but also the future.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-03-rust-coreutils-sylvestre-ledru/
Goose and the Agentic AI Foundation with Brad Axen
2026/02/23
Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things are today and where we might see them head. Donating Goose to the AAIF is great news as well as seeing MCP and AGENTS.MD in the foundation. We discuss how to deal with the problem of raising up junior developers, challenges of AI PRs, and some thoughts on how to get started if you're interested in AI development.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-02-goose-aaif-brad-axen/
The Global Vulnerability Intelligence Platform with Olle E. Johansson
2026/02/16
Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It's no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few people with a long term vision instead of trying to just fix the short term problems. His GVIP ideas are very good, but it's a community effort and needs our help. Give it a listen and if it sounds interesting, come help us out!
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-02-GVIP-olle-johansson/
Digital Sovereignty and Nextcloud with Frank Karlitschek
2026/02/09
Josh talk to the founder and CEO of Nextcloud, Frank Karlitschek about digital sovereignty. There's a lot of attention lately around digital sovereignty and often that conversation also includes Nextcloud. Frank tells us all about how Nextcloud works, how it can be used to free your data, and has some great insight into what decentralization already looks like and what it could look like soon.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-02-nextcloud-frank-karlitschek/
The Art of Crisis Management with David Bernstein
2026/02/02
Josh talks to David Bernstein about the world of crisis management and business continuity. David is a certified emergency manager and tell us about preparing for both digital and physical disruptions. Everything is IT now, so the way we think about disaster preparedness is changing. We talk about understanding risks, creating plans, and the role of practice in the world of crisis management. This is a super interesting universe and Dave was very patient and kind. I learned a lot and can't wait for Dave to come back.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-02-crisis-management-david-bernstein/
WTF is a passkey with William Brown
2026/01/26
William Brown is back! This time Josh chats with him about Passkeys. WTF are they? A Passkey is a form of multi factor authentication, but it's not super obvious what that really means. William does a fantastic job explaining what a Passkey is, how we got to where we are today with Passkeys. He shares a ton of explanations about the whole world of authentication along the way. Some of this stuff is basically magic.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-01-passkey-william-brown/
All about Suricata with Victor Julien
2026/01/19
Josh discusses Suricata with Victor Julien, the founder and lead developer of the project. Victor explains the history of the project, its impact on cybersecurity, and the community that keeps it all running. Challenges like encrypted traffic and the evolution of open-source projects. Victor even gives us a glimpse into what he sees as the future of the project. There's a lot to learn about Suricata in this one.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-01-suricata-victor-julien/
Iocaine poisons bots with Gergely Nagy
2026/01/12
Josh talks to Gergely Nagy (algernon) about his tool Iocaine. Iocaine creates a maze to trap scraping bots in a world a fake pages they cannot escape. algernon tells us how Iocaine effectively traps bots by serving them endless loops of nonsensical URLs and web pages. It's an extremely clever tool that's designed to be completely hidden from normal users, but not hidden to the scrapers.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-01-iocaine-algernon/
Podcast reviews
Read Open Source Security podcast reviews
CornOnTheMacabre 2024/06/19
Great Podcast
I don't work in this field; I'm strictly a security hobbyist. Found this podcast through archive.org, incidentally. Listened to 5 minutes of one episo...
letitsnowman 2024/11/25
josh is insufferable
I really enjoy Kurt’s perspective on stuff. Josh is insufferable. Not sure what complex he suffers from, but he can never be wrong and is always steam...
ktkaffee 2022/12/28
Excellent
I listen every week - it’s great to hear from others in my field.
cspeckrun 2023/10/23
Most frustrating show I continue listening to
Like a meeting with no agenda it can be informative and entertaining and you’re never quite sure if you should attend again but usually you do.
unbleachedbit 2023/09/25
The banter is spot on
as of September 2023 be negative reviews may be from non-techs or squishy persons in general. I understand the humor, and every episode that I have li...
obacker19 2020/05/19
Entertaining, insightful and actionable! 🔥
Whether you’re well established as a cyber security innovator, or just getting started carving out your role as a change agent within your organizatio...
Monar G. 2020/01/06
Like a fun conversation!
This podcast is like a fun conversation
Daveyma 2017/07/08
Too much fluff
Should be retitled
Podcast sponsorship advertising
Start advertising on Open Source Security relevant audience podcasts
You may also like to advertise on these Podcasts

4.8188169
It’s F*cking Spiritual: Manifestation, Men, & Money
Rachel Gibler

4.8235202
The Adventures of Danny and Mike
Danny Tamberelli, Michael C. Maronna, Jeremy Balon

4.178441
SEQUESTERED Podcast
Road Trip Studios

4.993248
PowerTech Development Podcast
PowerTech Online

4.9261133
Les Chat Podcast - LGBTQ+ - Lesbian Latinas
LGBTQ+ Podcast by Jojo & Dayra

5190661
The Business Method: Interviewing Billionaires, Billion Dollar Founders & the World’s Most Successful People 🎧🔥
Chris Reynolds

4.814477
Nintendo Tonight
Switch Stop

4.9266124
It's Christmastown
Vigorous Marvin

4.8164218
Front End Happy Hour
Front End Happy Hour

4.516626
Learn Real Estate Investing | Lifestyles Unlimited
Professional Real Estate Investors