Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Autor
Tim Callan and Jason Soroko
Kategorie
Web podcastu
Nejnovější epizoda
10. čvc 2026
Kde poslouchat?
Podcasty v aplikaci Replaio Radio Už brzyPodcasty míří do aplikace už brzy. Nainstaluj si ji teď a jako první uvidíš úplně nový pohled na podcasty
Epizody
Root Causes 614: MTC and Downgrade Attacks 06.05.2026 12:12
It's reasonable to believe that Merkle Tree Certificates (MTC) and traditional RSA will co-exist on the same servers for years, if not decades, during the transition to post quantum cryptography (PQC). Bas Westerbaan of Cloudflare joins us in this episode to explore the possibility of quantum downgrade attacks and what we can do about them.
Root Causes 613: Status of the NIST PQC Contests 04.05.2026 22:34
We are joined by Dustin Moody of NIST to go over the current state of the various post quantum cryptography (PQC) contests, including upcoming FIPS standards for Falcon (FN-DSA) and HQC, other Round 4 algorithms, the digital signing algorithm (DSA) On Ramp, isogeny, and future cryptographic exploration.
Root Causes 612: What Do Subscribers Need for MTC? 01.05.2026 12:43
We are joined by Bas Westerbaan of Cloudflare to explain considerations and requirements for use of Merkle Tree Certificates (MTC). This includes full adoption of TLS 1.3, offering PQC and RSA at the same time, the imperative value of automation, and running production MTC in 2027.
Root Causes 611: Merkle Tree Certificates, What and Why 29.04.2026 23:37
There are strong reasons to believe that the architecture of PQC TLS will take the form of Merkle Tree Certificates (MTC). We are joined by post quantum cryptography expert Bas Westerbaan of Cloudflare as he explains this new PKI architecture, how it works, and why we need it. We define new concepts like landmark certificates and log mirrors and discuss what's necessary to move to this new archite...
Root Causes 610: Types of Logical Qubits 27.04.2026 10:01
We describe three different kinds of logical qubits with their relative strengths and weaknesses.
Root Causes 609: Side Channel Apocalypse 24.04.2026 6:49
Jason explains the extreme danger of side channel attacks in the new post quantum cryptography (PQC) era.
Root Causes 608: The Fragility of Formal Verification 22.04.2026 7:51
The reliability of cryptographic algorithms is largely a matter of conjecture based on track record. Proving security is impaired by the difficulty of formal verification, implementation weaknesses, and failure in randomness.
Root Causes 607: PKI That's Hard to Discover 20.04.2026 7:59
The first of the five pillars of Certificate Lifecycle Management (CLM) is discovery. While many of your certificates are easily discoverable, some difficult PKI remains.
Root Causes 606: What Is the UK Online Safety Act? 17.04.2026 6:10
The UK Online Safety Act intends to force vendors who sell hardware and software to allow the government to scan end-to-end encrypted communication on end devices. We once again marvel at governments seeking to undermine the security of their own citizens.
Root Causes 605: Chrome Declares Its Support for Merkle Tree Certificates (MTC) 15.04.2026 9:17
Google has taken a strong position supporting Merkle Tree Certificates (MTC) as the PQC-enabled future for SSL / TLS. We unpack this extremely important position from the WebPKI's most influential organization.
Root Causes 604: Accelerated Timeline for Quantum Computers Breaking ECC in Crypto and Blockchain 13.04.2026 11:09
A new paper from Google Quantum AI and others documents a new technique for breaking ECC, particularly the curve protecting crypto currencies, smart contracts, and blockchain. This accelerates post quantum cryptography (PQC) timelines.
Root Causes 603: Cryptographically Relevant Quantum Computing (CRQC) with Only 10,000 Qubits 10.04.2026 9:26
New research suggests that a cryptographically relevant quantum computer is achievable with only 10,000 qubits. This was an important contributor to Google moving its PQC target to 2029.
Root Causes 602: Google Moves the PQC Date Forward to 2029 08.04.2026 12:59
Google has announced that it is moving its target for full PQC support to 2029. This is a strong statement from one of the most knowledgeable PQC technology companies that the existing 2030 target is too late.
Root Causes 601: The Zombie in the Server Room 06.04.2026 6:50
Legacy PKI implementations in the enterprise are holding back technical progress and creating security risk. We discuss reasons why, consequences, and what to do about it.
Root Causes 600: Cryptographic Design Is Not Neutral 03.04.2026 10:19
In our previous episode we defined cryptography as the new geopolitics. Now in our 600th episode we follow up to explain how all cryptographic decisions reflect the social, political, and legal viewpoints of the cryptography's designers.
Root Causes 599: Cryptography Is the New Geopolitics 01.04.2026 10:39
In the last decade or so, nations around the world have become keenly determined to use cryptography for their own legal, economic, and military advantage. We explore this concept.
Root Causes 598: Why Johnny Can't authN in OT 30.03.2026 7:55
A recent CISA report declares that the nation's OT infrastructure is incapable of keeping up with the crypto agility and certificate management needs that modern security demands. We examine this finding.
Root Causes 597: If You Don't Hold the Keys, You Don't Hold the Subpoenas 27.03.2026 7:26
Microsoft has publicly stated that it will hand over Bitlocker keys to US law enforcement agencies without requiring a subpoena or court order. These keys can be held by users rather than Microsoft, at their option. We dive into this topic.
Root Causes 596: CLM and Operational Uptime 25.03.2026 6:43
We usually think of Certificate Lifecycle Management (CLM) as a security category. But we could equally well categorize it as an operations category that enables uptime. In this episode we make our case.
Root Causes 595: What Is a Digital Parasite? 23.03.2026 12:30
We introduce the concept of a "digital parasite," explaining why this attack philosophy appears to be on the rise.
Root Causes 594: Google's Five PQC Recommendations for Policy Makers 18.03.2026 16:57
In a recent blog post Google made five recommendations for policy makers. We walk down the list.
Root Causes 593: New PQC Guidance from CISA 16.03.2026 16:57
CISA (Cybersecurity and Infrastructure Security Agency) has released new guidance about post-quantum cryptography in critical infrastructure, including some very sobering warnings. We go into the details.
Root Causes 592: When a CAA Record Outlives the CA 13.03.2026 8:44
CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out.
Root Causes 591: Client Authentication Deprecation Date Moves Out 11.03.2026 11:46
Chrome's deadline for deprecation of the clientAuth EKU and mTLS in public certificates has moved out. We give you the what, when, and why.
Root Causes 590: The Size of the CA Is Not the Size of the Risk 10.03.2026 7:19
It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has. This is false, however. In this episode we address this misconception.
Podobné podcasty
Replaio není vydavatelem podcastů; názvy pořadů, obálky a audio patří jejich autorům a šíří se přes veřejné RSS kanály