Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com
Autor
Tim Callan
Categoría
Web del podcast
Último episodio
9 de oct. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Root Causes 351: 2024 Predictions 27.12.2023 18:09
We look forward to 2024 and predict trends for PKI, certificates, and digital identity. We discuss shortening certificate lifespans, Multi-perspective Domain Validation (MPDV), eIDAS 2.0, OCSP, post-quantum cryptography (PQC), Certificate Lifecycle Management (CLM), passwords, root stores, and government versus encryption. Plus, will Jason be sent to the gulag for not being Canadian enough?
Root Causes 350: Public Certificates and the GDPR Right to Be Forgotten 21.12.2023 15:27
GDPR provides a "right to be forgotten," whereby individuals can demand the removal of PII from IT systems. This can run directly contrary to the transparency and permanence built into the DNA of public PKI systems. We explore this conundrum.
Root Causes 349: 2023 Lookback - Overall Trends 18.12.2023 22:37
We look back at PKI in 2023. Trends include artificial intelligence, enterprise crypto agility, the fall of OCSP, PKI everywhere, the weakness of passwords, and government versus the internet. We also look at last year's predictions and compare them to the year's events.
Root Causes 348: What Is a Merkle Tree? 15.12.2023 12:06
One foundational element of modern cryptographic systems is the Merkle tree. Merkle tree is an enabler of blockchain and CT logs, among other things. We explain this data structure, its properties, and its use cases.
Root Causes 347: 2023 Lookback - Shortening Certificate Lifespans 11.12.2023 18:44
90-day SSL certificates is only part of it! 2023 has been a year of certificate lifespans getting shorter. We review these trends.
Root Causes 346: Private Credentials In Public Code 08.12.2023 15:30
In this episode we uncover the epidemic of private credentials in public-facing code repositories, including why it occurs and what do to about it.
Root Causes 345: Apple Versus European Sideloading 05.12.2023 12:41
The European Union is applying pressure to Apple to allow sideloading of applications. We go over why this is occurring, the potential dangers, and Apple's response.
Root Causes 344: Introducing the PQC Onramp 29.11.2023 16:57
NIST's Round 3 competition has yielded winners for standardization. But NIST wants to continue finding additional potential algorithms, especially those using non-Lattice schemes. We explain the PQC "onramp" and what we should expect.
Root Causes 343: The EIDAS 2.0 Controversy 22.11.2023 25:59
ETSI is preparing to release specifications for eIDAS 2.0. One controversial aspect of this new standard is that it limits browsers' ability to determine their own trusted roots. In this episode we explain this limitation and the concerns surrounding it.
Root Causes 342: Don't Change Your Password for Two Years 17.11.2023 11:23
The CA/Browser Forum rules stipulate how often forced password changes for CA employees are to occur. They don't, however, specify a frequency at which these forced changes must occur. Rather, they set the MINIMUM time before forced password changes can happen. Join us to learn why.
Root Causes 341: The Trouble with Security Questionnaires 13.11.2023 19:28
The practice of sending security questionnaires to technology vendors is exploding, and with it dysfunctional behavior is on the rise. In this episode we describe how security questionnaires are changing and the pitfalls associated with this emerging practice.
Root Causes 340: Is This Podcast Canadian Enough? 06.11.2023 14:15
Canada's Online Streaming Act will require internet content providers to provide a minimum percentage of content produced by Canadians or face fines. We explore this latest episode in the theme of governments attempting to control the free flow of information on the internet.
Root Causes 339: The ROI of CLM 31.10.2023 11:22
In this episode we describe at a high level how to calculate the Total Cost of Ownership (TCO) of CLM as opposed to manual installation and management of certificates.
Root Causes 338: CLM and Your Career as an IT Professional 23.10.2023 19:20
In this follow up to our episode on CLM and the IT skills gap, we now discuss how CLM matters to individual IT professionals and can help progress careers and improve work life.
Root Causes 337: CLM and the IT Skills Gap 10.10.2023 20:35
For decades industry has had more need for skilled IT employees than the workforce could provide. In this episode we discuss how Certificate Lifecycle Management and certificate automation can help mitigate the challenges posed by the IT skills gap.
Root Causes 336: Digitally Signing Images on Cameras 03.10.2023 14:13
A recent press release discusses efforts of camera manufacturers and the digital imagery supply chain to create an ecosystem for digitally signed images. We describe what such an ecosystem would do, where it could do in the future, and the advantages and limitations of these schemes.
Root Causes 335: When MFA Is Not MFA 29.09.2023 9:50
In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach. We explain.
Root Causes 334: What Is Attestation on the Web? 26.09.2023 18:03
Most people hate dealing with CAPTCHA, but it offers great benefits for web site operators. In this episode we discuss alternatives to CAPTCHA, how they work, and their pros and cons. Plus, the Get-Off-My-Lawn! browser returns.
Root Causes 333: Intel Side Channel Attack Steals Private Keys 20.09.2023 16:55
A newly revealed side channel attack can capture AES encryption keys from Intel chips. We explain this significant and powerful attack.
Root Causes 332: Acoustic AI-based Key Logging Attack 14.09.2023 10:36
Researchers have built an AI model that can interpret keystrokes based on the sound of keyboard use over a phone or video call. Among other things, this technique can be used to steal passwords when the sound of logging in can be overheard. Join us as we learn about this new breed of credential harvesting.
Root Causes 331: Microsoft Restores Trust to VeriSign Code Signing Root 13.09.2023 14:13
Recent erroneous behavior for certain applications on Windows has drawn attention to the Microsoft trusted root store. It turns out that Microsoft removed - and then re-added - a legacy VeriSign root in its trusted roots list. We give you the details of what went on and why.
Root Causes 330: End-to-end PQC in Use Today 05.09.2023 21:43
Our hosts are joined by IronCap CEO Andrew Cheung as he discusses commercially available PQC solutions today, including VPN, email, and crypto currency.
Root Causes 329: What Is Messaging Layer Security? 29.08.2023 10:58
The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.
Root Causes 328: What Is the Debian Weak Key Flaw? 23.08.2023 6:59
In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.
Root Causes 327: What Is Multi-perspective Domain Validation? 18.08.2023 16:56
In this episode we explain Border Gateway Protocol (BGP) attacks and how multi-perspective domain validation (MPDV, also known as multi-vantage point domain validation) can defeat them.
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos