Tim Callan

Root Causes: A PKI and Security Podcast

Society EN ↓ 594 Folgen

Podcast by Tim Callan and Jason Soroko

Besuch unbedingt die Website des Podcasts und unterstütze die Macher: www.spreaker.com

Autor

Tim Callan

Kategorie

Society

Podcast-Website

www.spreaker.com

Neueste Folge

9. Okt 2026

Wo hören?

Podcasts in der App Replaio Radio Bald verfügbar

Podcasts kommen bald in die App. Installiere sie jetzt und erlebe als Erster einen ganz neuen Blick auf Podcasts

Bei Google Play herunterladen Kostenlos installieren Android fast 10 Mio. Downloads · Bewertung 4,8 iOS bald

Folgen

Root Causes 551: PKI in a Swarm at 50 mph 24.11.2025

Jason explores the role cryptography and trust systems play in the command and control of groups of autonomous drone systems.

Root Causes 550: WebPKI Certificate Lifespan - How Low Can You Go? 21.11.2025

Certificate maximum term is shrinking. In this episode we examine exactly how short they could get.

Root Causes 549: AI 1000 Days from Now - the Defeat of Voice Authentication 19.11.2025

In our ongoing series on AI in 1000 days, we describe the inevitable, complete distrust of voice printing as an authentication method, including why and what we think will happen.

Root Causes 548: AI 1000 Days from Now - Emotional Intelligence 17.11.2025

We begin a new series about what we expect from AI in the next three years. In this episode we discuss AI emulating emotional intelligence and its benefits.

Root Causes 547: Should We Do Mass Revocation Fire Drills? 14.11.2025

In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.

Root Causes 546: New Research Codifies Arguments for and Against QWACs 12.11.2025

We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates.

Root Causes 545: What Is MOSH? 10.11.2025

The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.

Root Causes 54: What Is Chain of Lure? 07.11.2025

Chain of lure is an attack method used to circumvent restrictions and boundaries places on AIs. Jason explains this attack and its implications.

Root Causes 543: AI Finds a Zero Day 05.11.2025

We have seen the first known instance of an AI tool discovering a zero-day vulnerability. This could have vast implications on vulnerability detection and bug bounty programs. We discuss the implications.

Root Causes 542: Use Cases for HQC 02.11.2025

In this episode we go over some of the reasons one might choose HQC over ML-KEM as a PQC key exchange algorithm for specific circumstances. And we discuss the future diversity of cryptography.

Root Causes 541: Introducing the HQC PQC Algorithm 31.10.2025

NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC. We explain this code-based algorithm.

Root Causes 540: Contextual CBOM 27.10.2025

We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.

Root Causes 539: What Is the Two-QWAC Architecture? 22.10.2025

A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain. We explain what's coming and why.

Root Causes 538: What Is an Entropy Desert? 20.10.2025

An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.

Root Causes 537: The Thermodynamics of Privacy 17.10.2025

In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.

Root Causes 536: Patent Blocker on ML-KEM 15.10.2025

A patent dispute in 2024 nearly blocked ML-KEM. But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations. We explain.

Root Causes 535: The CPS Is a Superset of Actual Practices 12.10.2025

The CPS must always be a superset of actual practices in a properly running CA. We explain why this is a product of good design.

Root Causes 534: Signing the Machines That Think 10.10.2025

Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime. How do you know? Jason proposes that, the same way we sign our code, we should be signing our AI models as well.

Root Causes 533: Flexibility Through Multi-CA Trust Models 07.10.2025

We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.

Root Causes 532: Introducing Offline PKI 02.10.2025

In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.

Root Causes 531: Benefits of Single-purpose Root Hierarchies 01.10.2025

Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones. We discuss why.

Root Causes 530: Introducing the AI Iceberg 29.09.2025

We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.

Root Causes 529: What Is a Common Mark Certificate? 24.09.2025

Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.

Root Causes 528: Misissued SSL Certificate for 1.1.1.1 17.09.2025

A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses. We go into the details.

Root Causes 527: Key Dates for the Deprecation of Public mTLS 15.09.2025

Client authentication using public TLS server certificates is on the deprecation path. In this episode we go through the key dates in this deprecation.

Höre den Podcast Root Causes: A PKI and Security Podcast in Replaio

Radio und Podcasts in einer App - kostenlos und ohne Anmeldung. Installiere sie noch heute und verpasse den Start nicht

Bei Google Play herunterladen

Replaio ist kein Herausgeber von Podcasts; die Namen der Sendungen, Cover und Audioinhalte gehören ihren Autoren und werden über öffentliche RSS-Feeds verbreitet