Artwork

Content provided by Open Source Security and Josh Bressers. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Open Source Security and Josh Bressers or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ro.player.fm/legal.
Player FM - Aplicație Podcast
Treceți offline cu aplicația Player FM !

CVE for EOL with Aaron Frost

30:00
 
Distribuie
 

Manage episode 476867163 series 1502626
Content provided by Open Source Security and Josh Bressers. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Open Source Security and Josh Bressers or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ro.player.fm/legal.

Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/

  continue reading

506 episoade

Artwork

CVE for EOL with Aaron Frost

Open Source Security

277 subscribers

published

iconDistribuie
 
Manage episode 476867163 series 1502626
Content provided by Open Source Security and Josh Bressers. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Open Source Security and Josh Bressers or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ro.player.fm/legal.

Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/

  continue reading

506 episoade

Tutti gli episodi

×
 
Loading …

Bun venit la Player FM!

Player FM scanează web-ul pentru podcast-uri de înaltă calitate pentru a vă putea bucura acum. Este cea mai bună aplicație pentru podcast și funcționează pe Android, iPhone și pe web. Înscrieți-vă pentru a sincroniza abonamentele pe toate dispozitivele.

 

Ghid rapid de referință

Listen to this show while you explore
Play