Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com
Autor
Tim Callan
Categoría
Web del podcast
Último episodio
9 de oct. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Root Causes 452: 2024 Predictions Scorecard 26.12.2024 10:39
We go over our predictions for 2024 and score our ability as prognosticators.
Root Causes 450: 2025 Predictions 23.12.2024 48:30
We make our 2025 predictions. Topics include maximum certificate term, AI, post-quantum cryptography (PQC), deep fakes, and more.
Root Causes 449: What Is a Quantum-safe HSM? 18.12.2024 23:49
Repeat guest Bruno Coulliard of Crypto4A joins us to define a quantum-safe (or PQC enabled) hardware security module.
Root Causes 448: The Privilege of Being a Public CA 17.12.2024 25:40
We go over Tim's September 2024 keynote speech at ENISA CA Day, "The Privilege of Being a Public CA."
Root Causes 447: NIST Deprecates RSA-2048 and ECC 256 13.12.2024 13:47
As part of its post-quantum cryptography (PQC) initiative NIST has released a draft deprecating RSA-2048 and ECC 256 by 2030 and disallowing them by 2035. We get into the details.
Root Causes 446: Sectigo Assumes Five CABF Offices 12.12.2024 13:21
Tim has stepped into the position of vice-chair of the CA/Browse Forum, and Sectigo now holds five chair or vice-chair positions in that body. We explain how leadership is chosen, the offices Sectigo holds today, and some of our vision for CABF in the next two years.
Root Causes 445: Seven Reasons to Shorten Certificate Lifespans 09.12.2024 27:57
We take a deep dive into the seven reasons shorter certificate lifespans are better.
Root Causes 444: What Happens to the WebPKI if Google Sells Chrome 06.12.2024 19:26
We discuss how a potential break of Chrome from Google would affect the WebPKI. We look at product changes, resourcing, post-quantum cryptography (PQC), innovation, moonshot initiatives, and other public CAs.
Root Causes 443: Is MSCA Going Away? 01.12.2024 13:23
In this episode we discuss the challenges for enterprises using Microsoft Active Directory Certificate Services (ADCS).
Root Causes 442: Apple Proposal to Reduce SSL Lifespan Updated 25.11.2024 22:14
Apple has published an updated draft to its proposal for shortening the lifespan of SSL certificates, including a final maximum term of 47 rather than 45 days. We explain.
Root Causes 441: New White House Initiative Targets BGP 22.11.2024 14:53
A new White House initiative requires that federal agencies need to create plans to thwart BGP attacks. We discuss, including Resource PKI (RPKI) and Multi-Perspective Issuance Corroboration (MPIC).
Root Causes 440: Public Key Directories 18.11.2024 12:58
We talk about public key directories and complicating factors such as Tailscale, VPN, TOR, Cloudflare, and Zero Trust.
Root Causes 439: PQC Onramp Narrowed Down to 15 Candidates 15.11.2024 17:14
NIST has narrowed its PQC onramp contest to 15 candidates. We go over who remains and the makeup of the remaining candidates.
Root Causes 438: PQC Is an Existential Requirement 12.11.2024 28:20
Repeat guest Bruno Couillard argues that cryptography is part of the foundational fabric of our lives and that the transition to PQC is an existential requirement.
Root Causes 437: Don't Blame the Linter 05.11.2024 11:22
Linters are essential tools for maintaining quality of certificate issuance. Public open-source linters are available to help CAs assure compliance. As a result, CAs have begun attributing gaps in coverage by public linters as the root cause for misissuance events. We explain why this is faulty reasoning.
Root Causes 436: Formal Proofs 29.10.2024 10:23
Formal proofs are critical to cryptography. We discuss how better processes and AI can accelerate formal proofs of cryptographic concepts.
Root Causes 435: The PQC "Q Day" Is Not That Simple 25.10.2024 19:46
The PQC community likes to debate when crypto relevant quantum computers will be available, which is sometimes called "Q day." In this episode we explain how radically oversimplified this concept is and dive into the nuances of what a "cryptographically relevant quantum computer" really will be.
Root Causes 434: Did Researchers Break AES Using Quantum Annealing? 22.10.2024 11:44
News reports claim Chinese researchers broke AES with a quantum annealing computer. We clarify the details and talk about the implications of this reported discovery.
Root Causes 433: Will AI Eat All the Electricity? 17.10.2024 10:29
We explore the question of whether or not we have enough electricity to fuel AI's expected growth.
Root Causes 432: Apple Floats New Short-lived Certificate Proposal 14.10.2024 26:21
Apple recently floated a draft CABF ballot for commentary that steps down maximum term for SSL certificates starting next year and eventually landing at 45 days in 2027. We share the details.
Root Causes 431: New Mozilla Proposal to Combat Delayed Revocation 11.10.2024 28:11
Deliberate delay of mandatory revocations has plagued the WebPKI in 2024. A new proposed policy from Mozilla stands to eliminate most of this behavior. In this episode we go over the proposal and explain its potential consequences.
Root Causes 430: How Does a TLS Handshake Work? 09.10.2024 14:32
In this episode we give a high-level explanation of what happens in a TLS 1.3 handshake and then discuss what will happen when PQC is included.
Root Causes 429: ServiceNow Outage Due to Expired Root Certificate 08.10.2024 7:05
A ServiceNow private CA root expired, creating outages across hundreds of enterprises. We explain what appears to have gone on.
Root Causes 428: .MOBI Attack Puts WHOIS-based DCV into Question 04.10.2024 17:11
White hat researchers managed to take over WHOIS for the .mobi TLD. Among other things, this discovery foretells the death of WHOIS as a valid email source for Domain Control Validation (DCV).
Root Causes 427: Mapping CLM to NIST CSF 2.0 01.10.2024 15:47
In this episode we map the contributions of Certificate Lifecycle Management into the new NIST Cybersecurity Framework 2.0.
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos