<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module]]></title><description><![CDATA[<p>This week on <a href="https://infosec.exchange/tags/OpenSourceSecurity" rel="tag">#<span>OpenSourceSecurity</span></a> I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module</p><p>It was a super fun discussion, I learned a ton, and it highlights the open source question about what happens when one of your dependencies isn't a great fit anymore</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/" title="The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer">
<img src="https://opensourcesecurity.io/images/wide-single-lock.jpg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/">
The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer
</a>
</h5>
<p class="card-text line-clamp-3">Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statement and their relationship with OpenSSL. We chat about some of the current features in cryptography, as well as some of what’s coming in the future. It’s a fun conversation that hits on a lot of great points.
Episode Links

Alex
Paul
pyca/cryptography
The State of OpenSSL for pyca/cryptography
x509-limbo
Community Cryptography Specification Project

This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.</p>
</div>
<a href="https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://opensourcesecurity.io/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />









<p class="d-inline-block text-truncate mb-0">Open Source Security <span class="text-secondary">(opensourcesecurity.io)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/9e4423c4-01cd-4123-90c3-3398b0e7074a/this-week-on-opensourcesecurity-i-had-a-chat-with-paul-kehrer-and-alex-gaynor-about-the-statement-they-published-discussing-the-challenges-posed-by-modern-openssl-for-the-python-cryptography-module</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 22:26:55 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/9e4423c4-01cd-4123-90c3-3398b0e7074a.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 09 Mar 2026 15:12:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module on Mon, 09 Mar 2026 21:17:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange">@<span>joshbressers</span></a></span> related information for listeners of this episode: Details about the OpenSSL fork situation from the curl wiki: <a href="https://github.com/curl/curl/wiki/OpenSSL-forks" rel="nofollow noopener"><span>https://</span><span>github.com/curl/curl/wiki/Open</span><span>SSL-forks</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116201296628423079</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/bagder/statuses/116201296628423079</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Mon, 09 Mar 2026 21:17:54 GMT</pubDate></item><item><title><![CDATA[Reply to This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module on Mon, 09 Mar 2026 18:38:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange">@<span>joshbressers</span></a></span> I even sent the link to the statement in openSSL by cryptography to a few friends, to read if they are "nerd" enough.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/plexsheep/statuses/116200668495985349</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/plexsheep/statuses/116200668495985349</guid><dc:creator><![CDATA[plexsheep@infosec.exchange]]></dc:creator><pubDate>Mon, 09 Mar 2026 18:38:09 GMT</pubDate></item><item><title><![CDATA[Reply to This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module on Mon, 09 Mar 2026 18:36:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/plexsheep%40infosec.exchange">@<span>plexsheep</span></a></span> Thanks!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116200663207253320</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116200663207253320</guid><dc:creator><![CDATA[joshbressers@infosec.exchange]]></dc:creator><pubDate>Mon, 09 Mar 2026 18:36:48 GMT</pubDate></item><item><title><![CDATA[Reply to This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module on Mon, 09 Mar 2026 18:23:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange">@<span>joshbressers</span></a></span> This was an amazing show!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/plexsheep/statuses/116200612661374631</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/plexsheep/statuses/116200612661374631</guid><dc:creator><![CDATA[plexsheep@infosec.exchange]]></dc:creator><pubDate>Mon, 09 Mar 2026 18:23:57 GMT</pubDate></item></channel></rss>