PodcastsTechnologyOpen Source Security

Open Source Security

Josh Bressers
Open Source Security
Latest episode

521 episodes

  • Open Source Security

    MCP and Agent security with Luke Hinds

    16/03/2026 | 35 mins.
    Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We explain what MCP and agents are doing as well as why it's so hard to secure them. It's not impossible, but it's not simple either. We end the show by discussing some of the more human aspects to security and how history may be repeating itself with security folks laughing at new users who don't know any better.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-03-mcp-agent-luke/
  • Open Source Security

    The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

    09/03/2026 | 33 mins.
    Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statement and their relationship with OpenSSL. We chat about some of the current features in cryptography, as well as some of what's coming in the future. It's a fun conversation that hits on a lot of great points.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/
  • Open Source Security

    Rust coreutils with Sylvestre Ledru

    02/03/2026 | 31 mins.
    Josh talks to Sylvestre Ledru about the Rust coreutils project. We've been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason isn't security, it's to modernize the code and attract new contributors. Sylvestre discusses with quite pleasant relationship with the GNU coreutils developers, some of the challenges in the project. What Ubuntu using this by default meant, and also gives us some things to watch for in the future. It's a super fun discussion about why Rust is not only awesome, but also the future.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-03-rust-coreutils-sylvestre-ledru/
  • Open Source Security

    Goose and the Agentic AI Foundation with Brad Axen

    23/02/2026 | 29 mins.
    Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things are today and where we might see them head. Donating Goose to the AAIF is great news as well as seeing MCP and AGENTS.MD in the foundation. We discuss how to deal with the problem of raising up junior developers, challenges of AI PRs, and some thoughts on how to get started if you're interested in AI development.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-02-goose-aaif-brad-axen/
  • Open Source Security

    The Global Vulnerability Intelligence Platform with Olle E. Johansson

    16/02/2026 | 34 mins.
    Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It's no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few people with a long term vision instead of trying to just fix the short term problems. His GVIP ideas are very good, but it's a community effort and needs our help. Give it a listen and if it sounds interesting, come help us out!
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-02-GVIP-olle-johansson/

More Technology podcasts

About Open Source Security

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.
Podcast website

Listen to Open Source Security, Darknet Diaries and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features

Open Source Security: Podcasts in Family