Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com
Autor
Tim Callan
Categoría
Web del podcast
Último episodio
9 de oct. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Root Causes 426: Expired Certificate Takes Down Bank of England 30.09.2024 7:43
A certificate expiration is now known to have created July's outage of Bank of England. Join us as we shake our heads in amazement yet again.
Root Causes 425: PQC Requirements for Voting Systems 27.09.2024 10:54
In honor of the upcoming US elections, we describe the six main requirements for a post-quantum voting system.
Root Causes 424: Using LoRA IoT Protocol for Clandestine Communications 25.09.2024 11:44
In this episode we describe the LoRA protocol, which allows IoT devices to communicate securely without using a cellular network, and how it can be used for secret communications.
Root Causes 423: Is a Certificate Software or a Service? 20.09.2024 18:29
In this episode we discuss the dual nature of a public certificate as both a file and part of a holistic service that lasts until its expiration. We discuss revocation checking, CT logging, GAAP accounting, linters, certificate tracking tools, Certificate Lifecycle Management, standards bodies, post-quantum cryptography, and subscription models.
Root Causes 422: New Date for Entrust Distrust 19.09.2024 4:28
The Chrome root program has changed the date for the Entrust distrust. Join us to get the details.
Root Causes 421: FIDO 2 Implementation Problems 16.09.2024 8:28
White hat researchers have raised concerns about FIDO 2 (AKA WebAuthn). We explain.
Root Causes 420: New Side Channel Attack Against YubiKeys 13.09.2024 12:44
EUCLEAK, a newly revealed side channel vulnerability, can clone the contents of a YubiKey. We talk about the attack and its significance.
Root Causes 419 - What Happens to Vendors Who Don't Support ACME When 90-day Certificates Come? 09.09.2024 16:15
Though it is the closest thing to an industry-standard API, there are still products and operating systems that don't support ACME. In this episode we explore what happens to these products once 90-day SSL certificates become the requirement.
Root Causes 418: Moving from Cryptographic Homogeneity to Cryptographic Heterogeneity 06.09.2024 18:26
One seldom discussed consequence of quantum computers and PQC is the move from cryptographic homogeneity to cryptographic heterogeneity, with multiple KEMs and DSAs eventually expected as ongoing standards. We examine the consequences of this change.
Root Causes 417: Introducing pkimetal the PKI Meta-linter 03.09.2024 8:45
We introduce pkimetal, an open source project from Rob Stradling that allows CA to write to many popular linters with a single integration. We explain the importance and pitfalls of linters and how pkimetal improves linter implementation.
Root Causes 416: SSL Subscriber Uses a Restraining Order to Prevent Revocation 29.08.2024 22:40
An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain what happened, why it's deeply problematic, how the industry might consider responding.
Root Causes 415: What Can I Do with These New FIPS PQC Standards? 27.08.2024 19:34
NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.
Root Causes 414: What Are the Revocation Periods for Public Certificates? 23.08.2024 11:58
In this episode we detail the mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.
Root Causes 413: NIST Releases Standards for First Three PQC Algorithms 16.08.2024 7:16
On August 13, 2024, NIST released its first three standards for PQC algorithms, ML-KEM, ML-DSA, and SLH-DSA. We tell you where to find them and talk about what happens next.
Root Causes 412: Google Throws in the Towel on Eliminating Cookies 13.08.2024 9:55
Cookies are incredibly useful but also pose grave privacy concerns. We have in the past covered Chrome's initiatives to replace cookies. Now Chrome has announced that for the foreseeable future cookies will remain. We explain.
Root Causes 411: PQC Security Levels 09.08.2024 20:29
A popular belief is that Grover's algorithm will require that we double our AES key sizes. Repeat guest Bas Westerbaan of Cloudflare explains why this myth is incorrect and talks through the concept of "security levels" in post-quantum cryptography.
Root Causes 410: CrowdStrike, Automatic Updates, and Walled Gardens 06.08.2024 15:29
We examine one specific aspect of the recent CrowdStrike flaw. Microsoft blames the problem on the fact that it must, by European law, allow kernel updates to Windows. We unpack the challenges this poses.
Root Causes 409: Mozilla Distrusts Entrust 02.08.2024 14:49
This week Mozilla chose to follow Chrome in deprecating the Entrust trusted roots. We give you the details and explain why this action matters.
Root Causes 408: Takeaways from Recent Conversations with PQC Experts 29.07.2024 13:03
In the past three months we featured far-ranging conversations about post-quantum cryptography (PQC) with experts Bas Westerbaan of Cloudflare, Dustin Moody of NIST, and Bruno Coulliard of Crypto4A. In this episode we recap important takeaways from these conversations.
Root Causes 407: Whatever Happened to Passkeys? 25.07.2024 13:26
WebAuthn arrived last year with great fanfare. But here we are in the latter half of 2024, and they are rarely used. In this episode we discuss why.
Root Causes 406: Certificate Discovery Is for Internal Certificates, Too 22.07.2024 18:16
When we discuss certificate discovery in CLM platforms, there is a common assumption that we're talking about public certificates exclusively. In this episode we explain the value of certificate discovery for internal PKI certificates also.
Root Causes 405: What Is an Adversarial Self-replicating Prompt? 19.07.2024 25:05
In this episode we explain what an adversarial, self-replicating prompt, otherwise known as a prompt worm.
Root Causes 404: SCOTUS Ruling Will Change IT Security Regulation 16.07.2024 16:06
The US Supreme Court has struck down the Chevron Deferment, which greatly expanded federal agencies' power to interpret and enforce statutes. This monumental ruling stands to shift power considerably from agencies to courts and will put more pressure on legislatures to determine precise laws around tech. We explore the consequences of this ruling.
Root Causes 403: NIST PQC Contest Round 4 and Onramp with Dustin Moody 12.07.2024 21:34
We are joined again by Dustin Moody, who leads the NIST search for PQC algorithms. In this episode Dustin describes going-forward efforts, including Round 4 of the NIST contest and the Onramp. We discuss some of the candidate algorithms and the consequences of having multiple algorithms available for use.
Root Causes 402: New Social Engineering Powershell Attack 09.07.2024 15:21
A new social engineering exploit instructs victims to enter command line prompts to hack themselves on behalf of the hacker. We explain and discuss potential responses.
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos