Go offline with the Player FM app!
CVE for EOL with Aaron Frost
Manage episode 476867163 series 1502626
Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/
481 episodes
Manage episode 476867163 series 1502626
Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/
481 episodes
All episodes
×

1 Securing GitHub Actions with William Woodruff 31:50




1 tj-actions with Endor Lab's Dimitri Stiliadis 32:39














1 Open Source Foundations with Kelley Misata of Suricata 31:45


1 Forking Open Source Projects with Sheogorath 22:14




1 Why do we keep ignoring CI security with François Proulx 23:38


1 Modern day authentication with Marc Boorshtein 26:17
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.