Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
Besuch unbedingt die Website des Podcasts und unterstütze die Macher: www.spreaker.com
Wo hören?
Podcasts in der App Replaio Radio Bald verfügbarPodcasts kommen bald in die App. Installiere sie jetzt und erlebe als Erster einen ganz neuen Blick auf Podcasts
Folgen
Root Causes 301: The Difference Between Certificate Automation and CLM 09.05.2023 14:56
This podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM). In this episode we discuss how CLM does not always entail automation and vice versa -- along with where this distinction occurs and why it matters.
Root Causes 300: Chrome Eliminates the Lock Icon 04.05.2023 18:40
Google Chrome has announced that it will eliminate the lock icon in September. We explain what Google will be doing, its stated rationale, and the pros and cons of this decision.
Root Causes 299: 2023 RSA Recap 02.05.2023 31:08
The 2023 RSA Conference just concluded. This week Tim recaps what he saw at the show and how it reflects on security industry trends. Our hosts discuss Zero Trust, PQC, blockchain, artificial intelligence, post-COVID tradeshow behavior, and more.
Root Causes 298: Moving Forward, Together - Promoting Automation 28.04.2023 12:29
The Google Chrome root store has communicated its plans for promoting automation. In this episode we explain Chrome's public plans for this initiative, which is anchored around ACME.
Root Causes 297: Certificate Expiration Creates Starlink Outage 26.04.2023 9:57
A recent outage in the Starlink internet service was caused by an unexpected certificate expiration. We discuss this ongoing problem and how 90-day maximum certificate term will exacerbate it.
Root Causes 296: SHOULD We or MUST We? 21.04.2023 12:38
The CA/Browser Forum guidelines contain many prescribed requirements, with language containing the word SHOULD or MUST. In this episode we explain the specifying power of these two words, why they are used, and what they signal about the intent behind a guideline and how the rules might evolve.
Root Causes 295: Genesis Criminal Marketplace Taken Down 17.04.2023 11:05
A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.
Root Causes 294: Root Causes Honored by Webby Awards 13.04.2023 9:10
The Root Causes podcast has received a Webby Honoree award. Jason and Tim briefly celebrate and discuss the challenge of operating a niche, homemade podcast while being directly compared to professionally produced podcasts on mainstream topics from media companies. Plus, Tim's new Root Causes t-shirt.
Root Causes 293: What Is Certbot? 10.04.2023 12:33
Certbot is an important part of the ACME standard. This open source tool makes it easier for many IT administrators to use ACME to automate provisioning and installation of SSL / TLS certificates.
Root Causes 292: Validation Data Reuse for 90-day Certificates 06.04.2023 15:21
As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also. We explain today's data reuse rules and what the evidence indicates will be required for both domain control validation (DCV) and organization information validation.
Root Causes 291: CLM and SIEM 03.04.2023 9:40
We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee access. We talk about expected behaviors in the CLM and monitoring them.
Root Causes 290: What Are QGIS and QIIS? 29.03.2023 13:06
In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation. We explain how they fit into validation and the criteria for a reliable information source.
Root Causes 289: What Is a Cryptographic Center of Excellence? 27.03.2023 8:30
In this episode we dig into an emerging idea, which is the cryptographic center of excellence. We discuss how such a center of excellence would work and the benefits it can bring to an enterprise.
Root Causes 288: ISARA Releases Patents on Hybrid Certificates 23.03.2023 12:20
In this episode we are joined by Atsushi Yamada, CEO of ISARA. He explains how ISARA has put its patents on hybrid certificates into the public domain and why. We explain the role of hybrid certificates in PQC and ongoing crypto agility.
Root Causes 287: GoDaddy Private Key Breach 20.03.2023 13:48
In this episode we describe an incident in which a GoDaddy breach exposed customer private keys. We explain the expectations surrounding private key exposure and get into the interesting question of when an incident is or is not part of a large company's CA business.
Root Causes 286: PKI and PQC in New White House Cybersecurity Initiative 16.03.2023 10:05
A new White House cybersecurity initiative specifically calls out digital identity and post quantum cryptography (PQC) among its focal areas. We discuss what it says and the potential implications.
Root Causes 285: Can ChatGPT Write Malware? 14.03.2023 16:10
In our ongoing exploration of the security implications of AI, in this episode we examine the suitability of ChatGPT as a malware-writing tool and possible future directions for AI in software creation.
Root Causes 284: 90-day SSL Certificates Are on the Way 10.03.2023 23:55
The Google Chrome root program recently announced its intention to reduce the maximum term for public SSL certificates to 90 days. In this episode we explain this announcement and its implications and speculate on timing for this reduction.
Root Causes 283: Google Optional OCSP Proposal Clarified 06.03.2023 11:19
In our episode 281 we reported on Google's proposal for optional OCSP. In this episode we correct some of our earlier reporting in that episode, including the use of CRL and the removal of any revocation requirement for SSL certificates of not more than ten days in term.
Root Causes 282: HSMs and Post Quantum Cryptography 02.03.2023 28:37
Repeat guest Bruno Couillard of Crypto4A joins us to explain where Hardware Secure Modules (HSMs) fit into the world of PQC. We discuss the issues surrounding how HSMs will work with post quantum algorithms and hybrid certificates and the process (and timelines) for defining how HSMs will incorporate PQC.
Root Causes 281: Google Proposes Optional OCSP 26.02.2023 26:23
In response to concerns about OCSP and privacy, Google has proposed removing the requirement for OCSP revocation checking for public SSL certificates meeting certain specific conditions. In this episode we go into the details of this proposal.
Root Causes 280: Did an AI Break CRYSTALS-Kyber? 24.02.2023 20:09
Recent news reports might suggest that an AI-enhanced side attack has defeated the CRYSTALS-Kyber PQC algorithm. In this episode we clarify that Kyber has not been defeated to date and exactly what did occur. We define side channel attack, discuss the broader implications of this attack, and speculate on what would happen if Kyber actually were broken.
Root Causes 279: ChatGPT Watermarking 19.02.2023 15:55
ChatGPT presents the potential problem of ChatGPT content being used and attributed to another source, such as a professional writer or a student. In this episode we discuss the idea of "watermarking" ChatGPT content, including stenography, randomness, entropy, and how to destroy the watermarks.
Root Causes 278: Microsoft on Certificates and FIDO 17.02.2023 11:18
Recent public discussion of FIDO and digital certificates reveal details of Microsoft's approach to consumer digital authentication. We discuss secure elements, Windows Hello, and the differences between B2C, B2B, and B2E.
Root Causes 277: Privacy Sandbox 13.02.2023 15:14
In the latest continuation of the effort to create better protections for consumer privacy while still enabling targeted advertising, Google has announced the Privacy Sandbox. In this episode we describe this latest foray, including concepts like k-anonymity and differential privacy.
Ähnliche Podcasts
Replaio ist kein Herausgeber von Podcasts; die Namen der Sendungen, Cover und Audioinhalte gehören ihren Autoren und werden über öffentliche RSS-Feeds verbreitet