Coop's Corner is a twice-weekly analysis of the hot stories affecting the technology industry by CNET News.com's executive editor Charles Cooper.
…
continue reading
Intel Chip Chat is a recurring podcast series of informal interviews with some of the brightest minds in the industry, striving to bring listeners closer to the innovations and inspirations of the people shaping the future of computing, and in the process share a little bit about the technologists themselves.
…
continue reading
Join Seth O’Brien, CP, FAAOP(D), as he dissects clinical care topics with leaders of the American Academy of Orthotists and Prosthetists Scientific Societies and the O&P profession. During these 30-minute podcasts, guests will discuss their area of clinical care and share personal experiences as professionals in that specialty and beyond, offering a relaxed journey into the professional lives of those that focus on a specific area of O&P patient care.
…
continue reading
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There’s a lot of good work happening that doesn’t get attention because there’s no marketing department behind it, they don’t have a developer relations team posting on LinkedIn every two hours. Let’s focus on those people and teams then learn what they do and how they do it. The goal is ...
…
continue reading
…
continue reading
Indian Genes is committed to bringing in ideas and thoughts from Global leaders in their field to every listener and home, with the intention of providing free and easy access to this information to all that would want to continue their quest for continuous learning. We also are very focused on our young talent that would benefit from this exposure as they plan and move ahead in the careers and life path, hopefully inspiring them to greater heights and clarity in thought that builds both cha ...
…
continue reading
Whether you are working hard or hardly working, join AEI Resident Fellow Brent Orrell as he explores national trends and public policies affecting the vitality of the American workforce and how to prepare yourself for success in our rapidly-changing economy. And whatever else happens, we promise it will take your mind off of your job.
…
continue reading
In this episode, we're flipping the script on our usual host Seth O’Brien, CP, FAAOP(D), as our guest host Abbey Senczyszyn, CPO, of Bremer Prosthetic Design, leads the conversation. We're getting Seth's take on how artificial intelligence is making its way into clinical practice, from patient care and documentation to gait analysis. Together, they…
…
continue reading

1
Using Mercator to map assets with Didier Barzin
25:48
25:48
Play later
Play later
Lists
Like
Liked
25:48In this episode, we the information system mapping tool Mercator with Didier Barzin, a CISO at a hospital in Luxembourg. Discover how Mercator revolutionizes the way organizations map their complex information systems. From hospitals to universities and even the banking sector. Mercator helps manage and protect vast networks by creating dynamic, co…
…
continue reading
In this episode, I discuss into the security features of Talos Linux with Andrey Smirnov. Andrey explains how Talos focuses on its immutability and minimal attack surface. Discover how these enhancements fortify your systems against vulnerabilities, ensuring a secure and resilient infrastructure. Join us as we explore the security advancements that…
…
continue reading

1
Discussing the Open Source, Open Threats? paper with Behzad and Ali
34:59
34:59
Play later
Play later
Lists
Like
Liked
34:59In this episode I chat with the authors of a recent paper on open source security: Open Source, Open Threats? Investigating Security Challenges in Open-Source Software. I chat with Ali Akhavani and Behzad Ousat about their findings. There are interesting data points in the paper such as a 98% increase in reported vulnerabilities compared to a 25% g…
…
continue reading

1
crates.io trusted publishing with Tobias Bieniek
25:39
25:39
Play later
Play later
Lists
Like
Liked
25:39In this episode we discuss crates.io trusted publishing with Tobias Bieniek. We cover the steps crates.io is taking to enhance supply chain security through trusted publishing, a method that leverages short-lived tokens and GitHub actions to safeguard against unauthorized access. Tobias shares insights into the challenges of managing a large-scale …
…
continue reading

1
Tackling Challenges in Upper-Limb Prostheses
31:15
31:15
Play later
Play later
Lists
Like
Liked
31:15In this episode, host Seth O’Brien, CP, FAAOP(D), is joined by Shane Grubbs, CPO/L, FAAOP, director at Ottobock.care and chair of the Academy’s Upper-Limb Prosthetics Scientific Society. Together, they unpack Shane’s top five challenges in upper limb prosthetics—from building patient confidence to creating supportive environments, improving educati…
…
continue reading

1
Adam Zeman - Neurologist / Shape Of Things Unseen
1:14:05
1:14:05
Play later
Play later
Lists
Like
Liked
1:14:05What does it mean to see with the mind’s eye — or not see at all? Do YOU see pictures in your mind? What if you couldn’t? In this mind-blowing episode, we sit down with Professor Adam Zeman, the world-renowned neurologist who discovered and coined the term “aphantasia” — a condition where people cannot form mental images. Zeman shares the fascinati…
…
continue reading
In this episode I chat with Patrick Garrity from VulnCheck. We discuss the chaos that has enveloped the CVE and NVD programs over the past two years. We cover some of the transparency and communication challenges with the existing program. What some of the new things that have started to emerge as well as why they seem to be struggling. We end on t…
…
continue reading

1
GCVE with Cédric Bonhomme and Alexandre Dulaunoy
31:38
31:38
Play later
Play later
Lists
Like
Liked
31:38In this episode I discuss GCVE and Vulnerability-Lookup with Alex and Cedric from CIRCL. GCVE offers a decentralized approach, allowing organizations to assign their own IDs and publish vulnerabilities independently. Vulnerability-Lookup is the tool that makes GCVE a reality. The flexibility addresses many of the limitations we see today with a sin…
…
continue reading

1
EU Regulations will change everything with Daniel Thompson
31:57
31:57
Play later
Play later
Lists
Like
Liked
31:57In this episode, we dive into the Product Liability Directive and Cyber Resilience Act with Daniel Thompson, CEO of Crab Nebula. The EU's new legislative framework impacts manufacturers in ways we don't totally understand, but are going to bring substantial changes to how companies use and develop open source. Daniel explains the broader implicatio…
…
continue reading

1
Open source microprocessors with Jan Pleskac
30:51
30:51
Play later
Play later
Lists
Like
Liked
30:51In this episode Jan Pleskac, CEO and co-founder of Tropic Square, shares insights on the challenges and innovations in creating open and auditable hardware. While most hardware is very closed, Tropic Square is working to change this. WE discuss how open source can enhance security, the complexities of integrating third-party technologies, and the f…
…
continue reading

1
Sara Seager - MIT/NASA In Search of New Worlds
33:44
33:44
Play later
Play later
Lists
Like
Liked
33:44Professor Sara Seager is an astrophysicist and a Professor of Physics, Professor of Planetary Science, and a Professor of Aeronautics and Astronautics at the Massachusetts Institute of Technology where she holds the Class of 1941 Professor Chair. She has been a pioneer in the vast and unknown world of exoplanets, planets that orbit stars other than…
…
continue reading

1
Evaluating Patient Outcomes with the C-Brace
26:54
26:54
Play later
Play later
Lists
Like
Liked
26:54In this episode, recorded live at the 51st Academy Annual Meeting and Scientific Symposium in Atlanta, host Seth O’Brien, CP, FAAOP(D), welcomes Russ Lundstrom, Director of Clinical Research and Services at Ottobock and recipient of the Thranhardt Lecture Series Award. Lundstrom shares insights from his research on goal attainment and reduced relia…
…
continue reading

1
Confidence in Every Step: Innovations in Microprocessor Knees
33:29
33:29
Play later
Play later
Lists
Like
Liked
33:29In this episode of O&P Clinical Care Insiders: Industry Partners Edition, host Seth O'Brien, CP, FAAOP(D), speaks with Breanne Logan, MSOP, CPO, senior clinical manager at BrainRobotics, to explore the transformative impact of emerging prosthetic technologies. They dive into the features and development of the Kneuro microprocessor knee, discuss ho…
…
continue reading
I'm joined by Philippe Ombredanne, creator of the Package URL (PURL), to discuss the surprisingly complex and messy problem of simply identifying open source software packages. We dive into how PURLs provide a universal, common-sense standard that is becoming essential for the future of SBOMs and securing the software supply chain. The show notes a…
…
continue reading

1
Hobbyist Maintainers with Thomas DePierre
49:03
49:03
Play later
Play later
Lists
Like
Liked
49:03Thomas DePierre joins Open Source Security to discuss the central idea from his blog post, "You are all on the hobbyist maintainers turf now," exploring the massive disconnect between the corporate world that consumes open source and the hobbyist community that actually produces it. The conversation reveals this isn't a new problem, but a long-stan…
…
continue reading

1
Addressing the Psychosocial Impact of Scoliosis
30:05
30:05
Play later
Play later
Lists
Like
Liked
30:05In this episode, recorded live at the 51st Academy Annual Meeting and Scientific Symposium in Atlanta, host Seth O'Brien, CP, FAAOP(D), explores the psychosocial impact of scoliosis with two leading voices in the field: Megan Glahn Castille, MS, CPO/LPO, assistant professor at Baylor College of Medicine and founder of the nonprofit Scolios-us, and …
…
continue reading
I chat with Aaron Lippold, creator of MITRE's Security Automation Framework (SAF), to discuss how to escape the pain of manual STIG compliance. We explore the technical details of open-source tools like InSpec, Heimdall, and Vulcan that automate validation, normalize diverse security data, and streamline the entire security authoring process. The s…
…
continue reading
I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is able to incredible insights into the world of open source. We chat all about how Ecosyste.ms works and how he manages to wrangle all this data. The s…
…
continue reading
Daniel Stenberg, the maintainer of Curl, discusses the increase in AI security reports that are wasting the time of maintainers. We discuss Curl's new policy of banning the bad actors while establishing some pretty sane AI usage guidelines. We chat about how this low-effort, high-impact abuse pattern is a denial-of-service attack on the curl projec…
…
continue reading
I recently had a chat with Kairo about a project he maintains called Repository Service for TUF (RSTUF). We explain why TUF is tough (har har har), what RSTUF can do, and some of the challenges around securing repositories. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-rstuf-with-kairo-de-a…
…
continue reading
In this episode, recorded live at the 51st Academy Annual Meeting and Scientific Symposium in Atlanta, host Seth O'Brien, CP, FAAOP(D), sits down with Tara Wright, CPO, FAAOP, a prosthetist-orthotist at Gillette Children's Specialty Healthcare in St Paul, Minnesota. Together, they dive into the evolving role of additive manufacturing in orthotics a…
…
continue reading

1
Securing GitHub Actions with William Woodruff
31:50
31:50
Play later
Play later
Lists
Like
Liked
31:50William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent security risks in GitHub Actions, such as injection vulnerabilities, permission issues, and mutable tags, by providing static analysis and remediation guid…
…
continue reading
Recently, I had the pleasure of chatting with Paul Asadoorian, Principal Security Researcher at Eclypsium and the host of the legendary Paul's Security Weekly podcast. Our conversation dove into the often-murky waters of embedded systems and the Internet of Things (IoT), sparked by a specific vulnerability discussion on Paul's show concerning refer…
…
continue reading

1
MAAJHI - Empowering people to Humanize Loss, Grief, & find Meaning with Krittika Sharma
2:01:12
2:01:12
Play later
Play later
Lists
Like
Liked
2:01:12Maajhi Link - www.maajhi.com Krittika’s passion for end-of-life care was sparked by a deeply personal experience & a lifelong relationship with loss. Driven by this profound connection, she is committed to bringing dignity, grace & wellbeing into aging, loss, end-of-life care, & the broader healthcare ecosystem. Krittika is a death meditation facil…
…
continue reading

1
tj-actions with Endor Lab's Dimitri Stiliadis
32:39
32:39
Play later
Play later
Lists
Like
Liked
32:39Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with produc…
…
continue reading
I chat with Alan Pope about the open source security tools Syft, Grype, and Grant. These tools help create Software Bills of Materials (SBOMs) and scan for vulnerabilities. Learn why generating and storing SBOMs is crucial for understanding your software supply chain and quickly responding to new threats like Log4Shell. The show notes and blog post…
…
continue reading
Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable unti…
…
continue reading

1
Elevating Excellence: The Value of the Academy’s Fellow Designation
29:22
29:22
Play later
Play later
Lists
Like
Liked
29:22In this episode, host Seth O'Brien, CP, FAAOP(D), sits down with Keith Smith, CO, LO, FAAOP, and David Wilson, MPO, CPO, LPO, FAAOP, to discuss the value of the Academy’s Fellow designation. Together, they explore why this credential matters, not just for individual recognition, but for advancing the entire O&P profession. From the history and purp…
…
continue reading

1
cargo-semver-checks with Predrag Gruevski
33:35
33:35
Play later
Play later
Lists
Like
Liked
33:35Cargo Semver Checks is a Rust tool by Predrag Gruevski that is tackling the problem of broken dependencies that cost developers time when trying to upgrade dependencies. Predrag's work shows how automated checks can catch breaking changes before they're released, potentially saving projects from unexpected failures and making dependency updates les…
…
continue reading
In this episode of O&P Clinical Care Insiders: Industry Partners Edition, host Seth O'Brien, CP, FAAOP(D), speaks with Lindsay E. Ryback, director of lymphology & phlebology at Thuasne, and Lesleigh Sisson, CFo, CFm, vice president and general manager of O&P Insight. Recorded live at the 51st Academy Annual Meeting in Atlanta, the conversation expl…
…
continue reading

1
Distributed CI and Git with Lars Wirzenius
27:27
27:27
Play later
Play later
Lists
Like
Liked
27:27Lars Wirzenius discusses his innovative CI/CD system Ambient, which uses isolated virtual machines without network access to enhance security, and his work on Radicle, a peer-to-peer Git collaboration platform. Together, these projects offer a glimpse into a more distributed future for software development, addressing key challenges in current CI/C…
…
continue reading
William Brown tells us all about how confusing and complicated the FIDO authentication universe is. He talks about WebAuthn implementation challenges to flaws in the FIDO metadata service that affect how hardware tokens are authenticated against. The conversation covers the spectrum of hardware security key quality, attestation mechanisms, and the …
…
continue reading
In this episode, open source legal expert Luis Villa breaks down what the EU's Cyber Resilience Act means for developers and businesses, exploring carve-outs for individual contributors and the complex relationship between security and sustainability. Luis provides practical guidance on navigating this evolving regulatory landscape while explaining…
…
continue reading

1
Growth, Community Engagement, and the Impact of the O&P Foundation: A Conversation with Fanny Schultea
23:50
23:50
Play later
Play later
Lists
Like
Liked
23:50In this episode, recorded live at the 51st Academy Annual Meeting and Scientific Symposium in Atlanta, host Seth O'Brien, CP, FAAOP(D), sits down with Fanny Schultea, MS, MSED, CPO/L, FAAOP(D), executive director of the Orthotics and Prosthetics Foundation for Education and Research. They dive into the remarkable growth of the O&P Foundation over t…
…
continue reading
Brian Fox discusses findings from a recent Sonatype report about the growing challenge of malicious packages in open source repositories. At the time of recording there are now over 820,000 malware packages in public repositories. Brian explains why certain ecosystems are more vulnerable than others and how behavioral detection methods can identify…
…
continue reading

1
Open Source Foundations with Kelley Misata of Suricata
31:45
31:45
Play later
Play later
Lists
Like
Liked
31:45In this episode Open Source Security talks to Dr. Kelly Masada about the Open Information Security Foundation (OISF). The way OISF is managing Suricata through a foundation is super interesting. There are a lot of lessons in this one for both open source projects and existing open source foundations. The blog post for this episode can be found at h…
…
continue reading

1
Forking Open Source Projects with Sheogorath
22:14
22:14
Play later
Play later
Lists
Like
Liked
22:14In this episode Open Source Security chats with Sheogorath about HedgeDoc project's journey from HackMD to CodiMD and finally to HedgeDoc. We learn what forking a project looks like, including license changes (MIT to AGPL), security vulnerability management across different codebases, naming challenges, and infrastructure migrations. The conversati…
…
continue reading

1
Patching EOL Open Source with Aaron Frost
22:53
22:53
Play later
Play later
Lists
Like
Liked
22:53In this episode, Open Source Security chats with Aaron Frost, CEO of Hero Devs about the world of maintaining end-of-life open source software. Aaron explains how EOL versions of open source work and how backporting security fixes can help maintaining compliance. In the discussion we cover the "just upgrade" mentality, how backporting works, why it…
…
continue reading
*A Special interview with Joginder Tanikella - CEO T-Works *Featuring a guided & detailed tour by Sahaj Sandhu - Start Up Manager Indian Genes was proud to visit the T-Works space and here bring to you never before seen footage & insight into this amazing initiative. If You are an Engineer, Start Up of just a Curious Mind....this is the episode you…
…
continue reading

1
Pain Science, Assessment, and the Future of Patient Care: A Conversation with Samantha Stauffer
28:53
28:53
Play later
Play later
Lists
Like
Liked
28:53In this episode, host Seth O'Brien, CP, FAAOP(D), sits down with Samantha Stauffer, MSOP, CPO, FAAOP, director of research at Independence Prosthetics-Orthotics, to discuss her groundbreaking research on pain and performance in post-amputation patients, featured as a Thranhardt Lecture Award at the 51st Academy Annual Meeting. Samantha shares her j…
…
continue reading

1
Why do we keep ignoring CI security with François Proulx
23:38
23:38
Play later
Play later
Lists
Like
Liked
23:38François Proulx, a supply chain security researcher at Boost Security, discusses how continuous integration (CI) and build pipeline security represents a critical and overlooked hole in our supply chain security. It seems like most supply chain compromises are actually from CI system breaches rather than direct code compromise, yet we seem to obses…
…
continue reading

1
Modern day authentication with Marc Boorshtein
26:17
26:17
Play later
Play later
Lists
Like
Liked
26:17In this discussion with Tremolo Security CTO Marc Boorshtein, we explore what modern day Single Sign-On (SSO) looks like. Everyone likes to talk about zero trust, but how does that work? We talk about some of the history of authentication that got us here, and some technical details on how you should be implementing authentication into your applica…
…
continue reading

1
Government Security Requirements with Dick Brooks
19:44
19:44
Play later
Play later
Lists
Like
Liked
19:44Dick Brooks from Business Cyber Guardian discusses the landscape of federal software security requirements, we discuss frameworks like CISA's Software Acquisition Guide, Secure Software Development Framework, and the EU's Cyber Resilience Act. These regulations impact open source projects differently from commercial vendors, Dick helps explain what…
…
continue reading

1
Open Source Maintenance with Gary Kramlich
27:18
27:18
Play later
Play later
Lists
Like
Liked
27:18In this episode, Gary Kramlich, the lead developer of Pidgin discusses the challenges and strategies of maintaining a 26-year-old open source messaging client.Gary tell us all about how a small team manages technical debt, handles library dependencies, and makes decisions about rewrites versus incremental improvements while supporting a broader ope…
…
continue reading
In this episode of Open Source Security, Josh welcomes Thomas Depierre, a Site Reliability Engineer and open source maintainer, to discuss the intersection of safety and security. Thomas explains why safety is broader than security. While security often views people as the problem, Thomas explains that people are paradoxically the solution. Nothing…
…
continue reading

1
Ben Wildavsky on the German Model of Dual-Studies
50:23
50:23
Play later
Play later
Lists
Like
Liked
50:23Ben Wildavsky is a veteran higher education strategist and writer, and host of the Higher Ed Spotlight podcast. He brings decades of experience in journalism and education policy, including leadership roles at Strada Education Network, the College Board, and US News & World Report. He is the author of The Career Arts: Making the Most of College, Cr…
…
continue reading

1
Mistakes, Clinical Insights, and the Pursuit of Excellence in Prosthetic Care: A Conversation with Dr. Gerald Stark
28:54
28:54
Play later
Play later
Lists
Like
Liked
28:54In our season 3 premiere episode, host Seth O'Brien, CP, FAAOP(D), talks with Gerald Stark, PhD, MSEM, CPO/L FAAOP(D), a certified prosthetist orthotist and director of clinical and technical operations for BionIT Labs. They discuss the importance of learning from mistakes for continual improvement in clinical care. Dr. Stark outlines five common e…
…
continue reading
In the inaugural episode of our quarterly podcast, O&P Clinical Care Insiders: Industry Partners Edition, host Seth O'Brien, CP, FAAOP(D), chats with Jonathan Taylor, director of clinical development and education at Spinal Technology. They explore the complexities of scoliosis bracing, comparing various brace types. Taylor emphasizes the lack of a…
…
continue reading
It’s a new year and time for some changes to the opensourcesecurity.io website. It's time to retire the podcast, but that's to make way for something new and hopefully better. You can read the details in the blog post (the audio version is basically the same thing) https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/…
…
continue reading