Tim Callan

Root Causes: A PKI and Security Podcast

Podcast by Tim Callan and Jason Soroko

No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com

Autor

Tim Callan

Categoría

Society

Web del podcast

www.spreaker.com

Último episodio

9 de oct. de 2026

¿Dónde escuchar?

Podcasts en la app Replaio Radio Muy pronto

Los podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts

Descárgala en Google Play Instálala gratis Android casi 10 M de descargas · valoración de 4,8 iOS muy pronto

Episodios

Root Causes 401: New SSH Remote Code Execution Vulnerability Revealed 05.07.2024

A newly revealed OpenSSH vulnerability can open enterprises to remote code execution. We explain what is happening, why you should care, and what to do about it.

Root Causes 400: French Court Orders DNS Poisoning 02.07.2024

To combat piracy of sporting event transmissions, a French court has ordered major tech companies including Google and Cloudflare to poison DNS settings. In this episode we provide some detail and generally marvel at this strange decision.

Root Causes 399: Entrust Distrusted 28.06.2024

On June 27, 2024 Google Chrome announced it was distrusting Entrust as a public CA starting November 1, 2024. We explain what to expect, go over Google's stated reasons, and share some of what lead up to this.

Root Causes 398: History of the NIST PQC Contest with Dustin Moody 27.06.2024

In this episode we are joined by Dr. Dustin Moody, leader of the NIST post-quantum cryptography contest. Dustin gives us an inside view of the background behind NIST's decision to run the contest and how we got to where we are today.

Root Causes 397: All Post Quantum Systems Are Terrible 24.06.2024

In this new conversation with Bas Westerbaan of Cloudflare, we reveal that all existing PQC systems present significant problems for incorporation into our existing ecosystems. We explain the problems with existing systems and some options for what to do about it.

Root Causes 396: The Trouble with Microsoft Recall 21.06.2024

Microsoft has proposed a feature called Recall that uses screen images to fuel AI-assisted capabilities. This has raised fears about the security decisions around this capability. We talk about why and how the proposed technology has resultingly changed.

Root Causes 395: Is Y2Q Like Y2K? 18.06.2024

In this episode we compare the advent of cryptography relevancy of quantum computers (somestimes called Y2Q) to Y2K. We uncover similarities and differences and discuss how they govern decision making between now and Y2Q.

Root Causes 394: Snowflake, Ticketmaster, and MFA 14.06.2024

In this episode we drill down on one aspect of the loss of more than 500 million Ticketmaster users' data, which is the use of MFA for access to the Snowflake platform.

Root Causes 393: PQC-enabled Chrome Breaks Other Software 11.06.2024

Chrome's recent 124 release supports PQC algorithms from NIST. This has led to the discovery of software and systems that break under these circumstances. We explain what happened, why, and what to do about it.

Root Causes 392: Chromium Issues a Quality Ultimatum 07.06.2024

In the most recent CA/Browser Forum face-to-face meeting, the Google Chrome root program gave a presentation clearly defining its expectations for quality of incident reporting from CAs with an eye to where many CAs have been failing. We relate Chromium's statements and their significance.

Root Causes 391: 20 Percent of Web Visits Are PQC Enabled Today 04.06.2024

Cloudflare research engineer Bas Westerbaan joins us to share his observations about post-quantum cryptography and what it does in the real world. We talk about the pragmatic needs of moving the internet for PQC and speculate about timelines for availability of PQC certificates.

Root Causes 390: Chromium Boosts Its Distrust Agility with a New Root Trust Deprecation 31.05.2024

A root trust deprecation highlights new Chrome functionality that enables more agile and less disruptive distrust events. We explain the significant of this event.

Root Causes 389: 2024 RSA Conference Wrap Up 28.05.2024

Jason and I do our annual RSA wrap-up. Trending segments include AI, Trust Centers, MFA, PQC, and more.

Root Causes 388: What Is the WebPKI? 22.05.2024

These days we frequently discuss "the WebPKI." But what does that really mean? In this episode we define the term and explain how this definition evolved over time. We give an inventory of a main components of the WebPKI and discuss what's required to become a CA.

Root Causes 387: What Is the Post-quantum Readiness of HSMs? 16.05.2024

We take a deep dive with return guest Bruno Coulliard on HSMs and the role they play in post-quantum cryptography (PQC).

Root Causes 386: Meta Commits MITM Attack On Its Users 13.05.2024

Recent court documents reveal that in 2016 Meta (then Facebook) set up a system to get around encryption and spy on traffic between its users and competing social media platforms. We explain what happened.

Root Causes 385: Failed Revocation and Wildcard Certificates 10.05.2024

We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.

Root Causes 384: So What Is a Senior Fellow Anyway? 07.05.2024

Jason has a new title, Senior Fellow. In this episode Jason explains what his new focus will be and how this will be good for Root Causes.

Root Causes 383: Delayed Revocation Events by the Numbers 02.05.2024

An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021, examine the trend line, and discuss root causes.

Root Causes 382: Mobile Phone Malware Steals Faces for Access 29.04.2024

New malware photographs users' faces to defeat authentication mechanisms. We explain the that biometrics are not "secrets" and discuss the continuing progression of attacks to steal biometrics.

Root Causes 381: Apple Chip Sideloading Attack Leaks Encryption Keys 26.04.2024

A newly revealed side channel attack enables theft of private keys from M-series Apple chips. We explain.

Root Causes 380: What If Quantum Supremacy Comes Earlier Than We Thought? 22.04.2024

Repeat guest Bruno Coulliard gives us an update on the US government's migration to post-quantum cryptography (PQC). We talk about the challenges to migration, the possibility of a black swan event in achieving quantum supremacy, and what happens if we all respond by pressing the "panic button" at the same time.

Root Causes 379: AI-generated Fake IDS for KYC 18.04.2024

Inexpensive and easily obtained deepfake photographs of IDs, generated by AI, are available online. These pose a problem for KYC initiatives.

Root Causes 378: Why Are Forced Revocations So Difficult? 15.04.2024

In the latest in our ongoing series of discussions of the Bugzilla Bloodbath, we delve deep into the problem of failure to revoke on time and the multiple causes that lead to this ongoing failure. And what to do about them.

Root Causes 377: Is CPS/Issuance Misalignment a Revocation Event? 11.04.2024

If you issue public certificates that are fully compliant except that they do not reflect what your CPS says, are they misissued? Do they require revocation? This is a question with real stakes as we see multiple current instances of a CA denying revocation for that reason. In this episode we explore this issue.

Escucha el podcast Root Causes: A PKI and Security Podcast en Replaio

Radio y podcasts en una sola app - gratis y sin registro. Instálala hoy y no te pierdas el estreno

Descárgala en Google Play

Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos