@firstyear talked about FIDO and specifically Bitwarden and passkeys on the latest #osspodcast with @joshbressers and mentioned an problem involving a single bit (the UV flag) and "falsely" setting it in certain circumstances. Is that documented anywhere? This is mainly for William and Josh but if anyone knows chime in. And is this the only known example of this, as in possibly other programs and their implementations? Great podcast btw.
Absolutely loved the Santa's supply chain episode of Open Source Security Podcast ๐Ÿ˜‚ #OSSPodcast
Monday and no #osspodcast ;(

Last episode of #osspodcast (about Santa) made me think..

- What sort of DB is Santa using?
- Does he store historical data or just overwrites "latest_niceness_status"?
- Does he accept GDPR download/delete requests?
- Does he send phishing test emails to elves?

Just listened to @joshbressers and @kurtseifried on the #osspodcast discussing the openness of open source in the context of security, and I must say that the idea of ever working for an employer that ships closed source software is something I could never do again. Going to work at GitLab was rather freeing - there is no "barely stating truth" when disclosing bugs because the source code tells the truth. Every employer before that, even many that shipped security software, were so strict in the wording of disclosures that they were basically exercises in "truthiness" more than anything else. Good episode, Josh and Kurt.

https://opensourcesecurity.io/category/podcast/

#infosec #security

Podcast

Open Source Security
Thanks @joshbressers and @kurtseifried for keeping me informed with the #OSSPodcast , I spoke to Emily after she gave this talk and asked about the likelihood whether our "tragedy of the commons" will be improved by something like the STF (something I learned about listening to your podcast) coming to the US and she seemed optimistic (though recent news may have changed that). Her answer referenced Tidelift, something I heard about on your podcast on my run the day before.
@joshbressers #osspodcast @kurtseifried @meshtastic I want one, actually I want 2...... Shame there doesn't seem to be an integration for a flipper.

@joshbressers Just finished listening to #osspodcast for this week and bought two Heltec LoRa 32(V3) Radio.

Now no promises, but uh, maybe we see a #meshtastic @pidgin plugin out of this ๐Ÿ˜„

Guess who has two wings and got mentioned on the #OSSPodcast this week... This BIRD! https://mastodon.social/@kurtseifried@infosec.exchange/113065242907764895
Holy cow, the #osspodcast by @joshbressers and @kurtseifried has a new episode. Perfect example: I had time to listen to it already. This is a tangent, but I'm not allowed to talk about pot holes. I'm ending this. Have a marvellous rest of your day.