Tim Callan

Root Causes: A PKI and Security Podcast

Society EN ↓ 594 Folgen

Podcast by Tim Callan and Jason Soroko

Besuch unbedingt die Website des Podcasts und unterstütze die Macher: www.spreaker.com

Autor

Tim Callan

Kategorie

Society

Podcast-Website

www.spreaker.com

Neueste Folge

9. Okt 2026

Wo hören?

Podcasts in der App Replaio Radio Bald verfügbar

Podcasts kommen bald in die App. Installiere sie jetzt und erlebe als Erster einen ganz neuen Blick auf Podcasts

Bei Google Play herunterladen Kostenlos installieren Android fast 10 Mio. Downloads · Bewertung 4,8 iOS bald

Folgen

Root Causes 351: 2024 Predictions 27.12.2023

We look forward to 2024 and predict trends for PKI, certificates, and digital identity. We discuss shortening certificate lifespans, Multi-perspective Domain Validation (MPDV), eIDAS 2.0, OCSP, post-quantum cryptography (PQC), Certificate Lifecycle Management (CLM), passwords, root stores, and government versus encryption. Plus, will Jason be sent to the gulag for not being Canadian enough?

Root Causes 350: Public Certificates and the GDPR Right to Be Forgotten 21.12.2023

GDPR provides a "right to be forgotten," whereby individuals can demand the removal of PII from IT systems. This can run directly contrary to the transparency and permanence built into the DNA of public PKI systems. We explore this conundrum.

Root Causes 349: 2023 Lookback - Overall Trends 18.12.2023

We look back at PKI in 2023. Trends include artificial intelligence, enterprise crypto agility, the fall of OCSP, PKI everywhere, the weakness of passwords, and government versus the internet. We also look at last year's predictions and compare them to the year's events.

Root Causes 348: What Is a Merkle Tree? 15.12.2023

One foundational element of modern cryptographic systems is the Merkle tree. Merkle tree is an enabler of blockchain and CT logs, among other things. We explain this data structure, its properties, and its use cases.

Root Causes 347: 2023 Lookback - Shortening Certificate Lifespans 11.12.2023

90-day SSL certificates is only part of it! 2023 has been a year of certificate lifespans getting shorter. We review these trends.

Root Causes 346: Private Credentials In Public Code 08.12.2023

In this episode we uncover the epidemic of private credentials in public-facing code repositories, including why it occurs and what do to about it.

Root Causes 345: Apple Versus European Sideloading 05.12.2023

The European Union is applying pressure to Apple to allow sideloading of applications. We go over why this is occurring, the potential dangers, and Apple's response.

Root Causes 344: Introducing the PQC Onramp 29.11.2023

NIST's Round 3 competition has yielded winners for standardization. But NIST wants to continue finding additional potential algorithms, especially those using non-Lattice schemes. We explain the PQC "onramp" and what we should expect.

Root Causes 343: The EIDAS 2.0 Controversy 22.11.2023

ETSI is preparing to release specifications for eIDAS 2.0. One controversial aspect of this new standard is that it limits browsers' ability to determine their own trusted roots. In this episode we explain this limitation and the concerns surrounding it.

Root Causes 342: Don't Change Your Password for Two Years 17.11.2023

The CA/Browser Forum rules stipulate how often forced password changes for CA employees are to occur. They don't, however, specify a frequency at which these forced changes must occur. Rather, they set the MINIMUM time before forced password changes can happen. Join us to learn why.

Root Causes 341: The Trouble with Security Questionnaires 13.11.2023

The practice of sending security questionnaires to technology vendors is exploding, and with it dysfunctional behavior is on the rise. In this episode we describe how security questionnaires are changing and the pitfalls associated with this emerging practice.

Root Causes 340: Is This Podcast Canadian Enough? 06.11.2023

Canada's Online Streaming Act will require internet content providers to provide a minimum percentage of content produced by Canadians or face fines. We explore this latest episode in the theme of governments attempting to control the free flow of information on the internet.

Root Causes 339: The ROI of CLM 31.10.2023

In this episode we describe at a high level how to calculate the Total Cost of Ownership (TCO) of CLM as opposed to manual installation and management of certificates.

Root Causes 338: CLM and Your Career as an IT Professional 23.10.2023

In this follow up to our episode on CLM and the IT skills gap, we now discuss how CLM matters to individual IT professionals and can help progress careers and improve work life.

Root Causes 337: CLM and the IT Skills Gap 10.10.2023

For decades industry has had more need for skilled IT employees than the workforce could provide. In this episode we discuss how Certificate Lifecycle Management and certificate automation can help mitigate the challenges posed by the IT skills gap.

Root Causes 336: Digitally Signing Images on Cameras 03.10.2023

A recent press release discusses efforts of camera manufacturers and the digital imagery supply chain to create an ecosystem for digitally signed images. We describe what such an ecosystem would do, where it could do in the future, and the advantages and limitations of these schemes.

Root Causes 335: When MFA Is Not MFA 29.09.2023

In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach. We explain.

Root Causes 334: What Is Attestation on the Web? 26.09.2023

Most people hate dealing with CAPTCHA, but it offers great benefits for web site operators. In this episode we discuss alternatives to CAPTCHA, how they work, and their pros and cons. Plus, the Get-Off-My-Lawn! browser returns.

Root Causes 333: Intel Side Channel Attack Steals Private Keys 20.09.2023

A newly revealed side channel attack can capture AES encryption keys from Intel chips. We explain this significant and powerful attack.

Root Causes 332: Acoustic AI-based Key Logging Attack 14.09.2023

Researchers have built an AI model that can interpret keystrokes based on the sound of keyboard use over a phone or video call. Among other things, this technique can be used to steal passwords when the sound of logging in can be overheard. Join us as we learn about this new breed of credential harvesting.

Root Causes 331: Microsoft Restores Trust to VeriSign Code Signing Root 13.09.2023

Recent erroneous behavior for certain applications on Windows has drawn attention to the Microsoft trusted root store. It turns out that Microsoft removed - and then re-added - a legacy VeriSign root in its trusted roots list. We give you the details of what went on and why.

Root Causes 330: End-to-end PQC in Use Today 05.09.2023

Our hosts are joined by IronCap CEO Andrew Cheung as he discusses commercially available PQC solutions today, including VPN, email, and crypto currency.

Root Causes 329: What Is Messaging Layer Security? 29.08.2023

The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.

Root Causes 328: What Is the Debian Weak Key Flaw? 23.08.2023

In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.

Root Causes 327: What Is Multi-perspective Domain Validation? 18.08.2023

In this episode we explain Border Gateway Protocol (BGP) attacks and how multi-perspective domain validation (MPDV, also known as multi-vantage point domain validation) can defeat them.

Höre den Podcast Root Causes: A PKI and Security Podcast in Replaio

Radio und Podcasts in einer App - kostenlos und ohne Anmeldung. Installiere sie noch heute und verpasse den Start nicht

Bei Google Play herunterladen

Replaio ist kein Herausgeber von Podcasts; die Namen der Sendungen, Cover und Audioinhalte gehören ihren Autoren und werden über öffentliche RSS-Feeds verbreitet