Menu
Sign In Pricing Add Podcast
Podcast Image

How About Tomorrow?

Open Source Security Theater

Mon, 16 Dec 2024

Description

Dax kicks off an open source rant, plastics, TSA security theater and the connection to rich people getting murdered, Adam wonders if he can become a romantic or if he's stuck being a disconnected robot, and thoughts on building an API.Links:dax on X: “openauth beta is here you’re gonna wanna watch this video more info in threadOpenAuth Beta | SSTOpenAuthopenauthjs/openauth: ▦ Universal, standards-based auth provider.Byung-Chul Han PhilosophyComposable Web ArchitectureGenerate Best-in-Class SDKsSponsor: Terminal now offers a monthly box called Cron.Want to carry on the conversation? Join us in Discord. Or send us an email at [email protected]:(00:00) - This is not podcast content (00:28) - The annoyance of open source (10:40) - Recycling and plastic (13:20) - Mixed feelings about security theater (18:16) - Money and murder (27:45) - Are we romantics? (34:29) - Byung-Chul Han (41:59) - Is Twitter good for Adam? (47:08) - How's Adam's API going? ★ Support this podcast ★

Audio
Featured in this Episode
Transcription

Full Episode

0.249 - 5.016 Adam

this is not what we're getting into yeah this is not podcast content chris cut this out you know what i mean

0

28.706 - 51.73 Dax

i need to really badly do a rant perfect do it that's what this is for that's what this podcast is i like was writing out a tweet and i was like like a really ranty tweet and i was like holding myself back so i was like i should probably just like rant about this on the on the podcast um let's go so we released open off beta uh last week or not last week damn it's only been it's not monday it's only been a week

0

52.49 - 69.524 Dax

And it's been really cool. We've gotten like a lot of really great PRs, like a crazy amount of PR. Like every day I wake up to like five or six PRs that are definitely mergeable. And it's really great because that's kind of what we hoped for. Like we wanted to build a shell of something and the power of open source is to like cover the, like a long tail list of something.

0

69.924 - 93.335 Dax

And the community is actually doing that and helping us there, which is awesome. But I think it's general enough of a project that I'm getting like a much wider audience of people that are like looking at it. And so I'm attracting some of these like very annoying open source type situations. Uh, so it's not what people might imagine. It's not the person demanding a future.

0

93.415 - 114.54 Dax

I actually don't care about that. Like I'm like, I'm, I don't find that annoying. Like someone, I know that annoys some people and they're like, you don't pay for this. But for us, it's like a little bit different. Uh, I get like, Man, I've been struggling. The reason I didn't post a tweet is because I'm struggling to find the right insult for this type of person. Like, it's like a Karen.

114.56 - 132.086 Dax

It's like a Karen category of person. But I feel like it's more specific than that. A couple of days ago, I got two issues open being like, do not use JWTs. They're insecure. And there's a second one that was like, do not use local storage. They're insecure. And this person just like linked a bunch of like random ass security articles.

132.626 - 155.568 Dax

yeah and their view of things is so binary and whenever it comes to like i found this anytime you get in the category of like compliance or security or everything people are so proud to like know the know a rule they're so proud to know a rule you shouldn't do this and then whenever some situation comes up there's like blanket apply the rule uh the rule says you shouldn't do this

156.309 - 171.615 Dax

So he, you know, he wrote this thing about JWTs not being valid and they're like, you should never use them. But security is not like that. And compliance is also not like that. Anyone that actually works in these spaces knows that there's always a spectrum of insecure to extremely secure.

172.096 - 191.646 Dax

And then you pick somewhere on that spectrum that balances the security aspect of what you're trying to do with, there's always a good product trade-off. Okay. Yeah. So he wrote this in like, as it was a binary thing and he, It's wrong because I want to kind of appeal to authority. Like every single, like a bunch of office of service companies uses the exact same model.

Comments

There are no comments yet.

Please log in to write the first comment.