Ga naar de inhoud
PodcastsTechnologieWhat's in the SOSS? An OpenSSF Podcast

What's in the SOSS? An OpenSSF Podcast

OpenSSF
What's in the SOSS? An OpenSSF Podcast
Nieuwste aflevering

69 afleveringen

  • What's in the SOSS? An OpenSSF Podcast

    CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight

    11-08-2026 | 16 Min.
    In this episode of What's in the SOSS, host Sally sits down with Megan Knight, Director of Software Communities at ARM, OpenSSF Board Member, and Chair of the Awareness SIG within the Global Cyber Policy Working Group. Together, they break down the upcoming European Union Cyber Resilience Act (CRA) and address the persistent gap in ecosystem awareness. Megan outlines concrete, practical strategies for maintainers and organizations, highlights the vital role of community collaboration across working groups like ORBIT and ORC, and shares key resources to help lower the barrier to compliance. Stick around for a fun rapid-fire round where favorite open source mascots steal the spotlight! 

    Chapters:
    00:24 - Introduction and Welcome 
    01:44 - The current CRA landscape and key findings from recent LF Research reports.  
    04:23 - Actionable compliance steps for maintainers and organizations  
    07:16 - The mission of the OpenSSF Global Cyber Policy Working Group  
    10:28 - How to get involved  
    13:25 - Rapid-fire 
    15:12 - Key takeaways and resources for a deeper dive into CRA readiness

    Episode links:
    Megan Knight’s LinkedIn page
    Cyber Resilience Act - Implementation
    Global Cyber Policy Working Group (policy.openssf.org)
    Linux Foundation 2025 CRA Awareness and Readiness Report
    Linux Foundation 2026 CRA Awareness and Readiness Report
    Open Regulatory Compliance Working Group
    Open Resources for Baselines, Interoperability and Tooling (ORBIT) Working Group
    Open Source Project Security (OSPS) Baseline
    OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page
    LF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)
    Global Cyber Policy GitHub Repository
    Add any other applicable links related to the episode
    OpenSSF Community Calendar
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou

    04-08-2026 | 38 Min.
    Join host Yesenia as she sits down with Mila Zhou, Open Source Program Manager at AWS, to explore the fascinating intersection of finance, strategy, and security in the open source ecosystem. Mila shares her unique journey from forensic auditing to spearheading AWS funding initiatives, breaking down how strategic financial backing transforms vulnerable "long tail" projects and empowers dedicated security champions. Discover how full-time security engineers at foundations are securing critical repositories like PyPI, why community-driven forks like Valkey represent the true spirit of collaboration, and how the OpenSSF Ambassador Program is helping close the gap between developers and security experts. 

    Chapters:
    00:25 - Welcome & Introductions
    01:03 - From Accounting to AWS OSPO
    06:26 - A Day in the Life of an OSPO Program Manager
    09:53 - Navigating Critical Funding & The Long Tail
    13:25 - Valkey and Community-Driven Innovation
    15:29 - The Invisible Power of Dedicated Security Engineers
    28:46 - Marketing, Non-Code Contributions, and the Ambassador Program
    36:25 - Rapid Fire Fun
    37:05 - Final Thoughts & Closing

    Episode links:
    Miaolai (Mila) Zhou’s LinkedIn page
    Alpha-Omega Website
    Alpha-Omega Public Repository
    Valkey
    Mike Fiedler’s LinkedIn
    Seth Larson’s LinkedIn
    Yesenia’s Blog on Building a Team of Open Source Security Engineers in Residence
    The Hidden Heroes: How Non-Code Contributors Find Their Place in Open Source Communities - Miaolai Zhou & Lahari Chowtoori, AWS
    OpenSSF Ambassador Program
    Get involved with the OpenSSF
    Subscribe to the OpenSSF Newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    Turning AI into the Ultimate Open Source Maintainer Power Tool with Michael Winser

    28-07-2026 | 33 Min.
    In this episode of What’s in the SOSS?, host CRob welcomes back open source security champion Michael Winser to reflect on Alpha-Omega’s spectacular milestone of surpassing $20 million in security grants. Michael breaks down how their mission has evolved from simply chasing bugs to acting as a catalyst for sustainable, long-term security culture across critical projects. The two dive deep into the unsustainable economics of package repositories—the "app stores" of software development —and address how a massive partnership with frontier AI model providers is aiming to flip the script on AI. Instead of fueling endless, low-context vulnerability "slop," Alpha-Omega is working to put AI assists directly into the hands of maintainers as their ultimate defensive power tool. 

    Chapters:
    00:24 - Welcome Back, Michael Winser!
    01:10 - The Origin Story of a $20 Million Milestone
    04:54 - Evolving Beyond Audits to "Sustainable Security"
    11:18 - The Messy Economics of Package Registries
    20:28 - Turning AI into the Maintainer’s Power Tool
    29:01 - Vision for 2026: The Security Trust Graph

    Episode links:
    Michael Winser’s LinkedIn page
    Alpha-Omega Website
    Alpha-Omega Public Repository
    Learn more about the Security Engineers in Residence (SEIR) Roles 
    Andrew Nesbitt 
    OpenSSF Securing Software Repositories Working Group
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    Signing the Future: Securing AI and ML Artifacts with Mihai Maruseac

    14-07-2026 | 21 Min.
    In this episode of What’s in the SOSS?, host Yesenia Yser sits down with Mihai Maruseac, the lead of the OpenSSF AI/ML Working Group and Security and Privacy expert at OpenAI, to dive deep into the unique security challenges facing artificial intelligence. Unlike traditional software packages, AI models cannot simply be inspected for malware by looking at their weights – malicious code only exposes itself upon execution. Mihai outlines how the community is answering this threat through the evolution of the OpenSSF Model Signing (OMS) specification. Discover how OMS creates an unshakeable chain of custody for models, data sets, and agent workflows, the structural shift toward implementation-agnostic toolchains, and what the future looks like for a fully realized, end-to-end secure AI supply chain.
    Chapters:
    00:22 – Welcome: Yesenia introduces AI/ML Working Group lead Mihai Maruseac.
    00:51 – From TensorFlow to OpenAI: Mihai’s journey navigating open source security and AI.
    01:47 – Core Risks of Model Tampering: A look at hidden risks inside uninspectable model weights.
    03:27 – Establishing Chain of Custody: How cryptographic signatures verify file integrity from training to deployment.
    05:04 – Evolution of the OMS Spec: Why the community standardized on forward-compatible, framework-agnostic formats.
    07:17 – Tracking Iteration (v1.1 & v1.2): An overview of newly introduced security keys and community features.
    08:26 – Choosing Your PKI Tooling: Why the OMS specification remains highly flexible for users.
    10:22 – Real-World Integration: Early success stories with Kaggle, NVIDIA, and the path to PyTorch.
    12:42 – Looking Ahead to Version 2: Overcoming "attestation sprawl" by unifying multiple security claims.
    15:29 – The Ideal AI Supply Chain: Using signed artifacts with GUAC to automatically map vulnerabilities.
    17:09 – How to Get Involved: Immediate opportunities to contribute to signature format convergence.
    18:11 – Rapid Fire Segment: Mihai shares his favorite retro games, hiking, and love for Vim.
    19:37 – Final Words of Advice: Why contributors of all skill levels are welcome to join.
    Episode links:
    Mihai Maruseac’s LinkedIn Page
    OpenSSF Model Signing (OMS)
    OpenSSF Model Signing Spec GitHub Repo
    OpenSSF AI/ML Working Group
    OpenSSF Guide: Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline Security
    Graph for Understanding Artifact Composition (GUAC)
    Sigstore
    In-toto
    Ollama
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
  • What's in the SOSS? An OpenSSF Podcast

    The Heartbeat of the Kernel: Why Upstream is the Ultimate Security Strategy with Greg Kroah-Hartman

    30-06-2026 | 34 Min.
    What does it feel like to wake up and realize your weekend passion project is now the critical infrastructure powering the planet? In this episode of What’s in the SOSS?, CRob sits down with Linux kernel maintainer and open source icon Greg Kroah-Hartman. Greg takes us on a journey from his early days writing firmware for printer and hospital ATMs to managing the relentless, everyday engineering task of maintaining the Linux kernel over decades. He breaks down the realities of modern kernel security, dismantles the myth that maintainers know every single vulnerability exploit , and details how looming global regulations like the EU's Cyber Resilience Act (CRA) are shifting the compliance burden onto vendors. If your organization uses Linux, Greg has a simple, urgent message for you: stop fearing change, build your testing infrastructure, and update your systems. 
    Chapters:
    00:03 - Welcome: Host CRob introduces Linux kernel legend Greg Kroah-Hartman.
    01:04 - From Printers to Richard Stallman: Greg shares his origin story in embedded engineering and his introduction to free software.  
    02:00 - The Weekend Driver and the Dopamine Hit: How a quick weekend project turned Greg into a lifelong kernel contributor.
    04:20 - Realizing Linux is Critical Infrastructure: The moment the telcos and banks moved in, signaling that Linux was everywhere.
    05:28 - 2005: The Year the Kernel Grew Up: Implementing stable releases, the security team, and the rule to never break user space.
    07:05 - What People Get Wrong About Kernel Security: Linus's mantra that "a bug is a bug," and the reality of handling 35 fixes a day.
    09:32 - The Historic Fear of Updating: Why lagging behind for "stability" is actually incurring massive risk.
    12:17 - Global Regulation and the Cyber Resilience Act (CRA): How upcoming laws are changing vendor responsibility and why the open source community is exempt.
    13:51 - How OpenSSF is Reducing the Burden: Applauding the cross-ecosystem collaboration that protected maintainers from onerous drafts.
    17:05 - Pay Your Employees to Contribute: Greg’s best piece of advice for downstream enterprises relying on open source.
    18:39 - Inside the Kernel Security Alias: How the ad-hoc security team handles triage and assigns CVEs.
    21:11 - The CVE Numbers Game: Why the kernel ranks #2 in CVE creation and the trouble with automated severity scores.
    25:39 - We are Already There: AI Slop and Static Analysis: Greg addresses the recent surge of AI-generated bug reports and patches.
    31:20 - Rapid Fire Round: Spicy food, coffee, Star Wars, and the ultimate call to action. 
    Episode links:
    Greg Kroah-Hartman’s LinkedIn page
    The Linux Foundation CRA Stewards Playbook
    OpenSSF Global Cyber Policy Working Group
    The Linux Kernel Archive (Keep your systems current with the latest stable kernel releases)
    The Value of Open Source Software
    Additional Resources
    Get involved with the OpenSSF
    Subscribe to the OpenSSF newsletter
    Follow the OpenSSF on LinkedIn
Meer Technologie podcasts
Over What's in the SOSS? An OpenSSF Podcast
What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.About Christopher Robinson (aka CRob), hostCRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.
Podcast website

Luister naar What's in the SOSS? An OpenSSF Podcast, De Technoloog | BNR en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies