Tim Callan

Root Causes: A PKI and Security Podcast

Podcast by Tim Callan and Jason Soroko

No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com

Autor

Tim Callan

Categoría

Society

Web del podcast

www.spreaker.com

Último episodio

9 de oct. de 2026

¿Dónde escuchar?

Podcasts en la app Replaio Radio Muy pronto

Los podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts

Descárgala en Google Play Instálala gratis Android casi 10 M de descargas · valoración de 4,8 iOS muy pronto

Episodios

Root Causes 326: The Difference Between .ml and .mil 15.08.2023

A recent Financial Times article reveals that mistyped email addresses aimed at the US military frequently are sent to email addresses in Mali instead, to the tune of hundreds of thousands per year. Some of this includes sensitive military content.

Root Causes 325: Certificate Error Causes Sharepoint Outage 11.08.2023

A recent outage in Microsoft Sharepoint was caused by an error in certificate installation. We explain what happened and the lessons to be learned.

Root Causes 324: Apple Vs New UK Surveillance Bill 07.08.2023

The battle between government and encryption continues. The UK is attempting to build secret back doors into end-to-end encrypted services. In response, Apple has threatened to remove Apple services from the UK, including FaceTime and iMessage.

Root Causes 323: Update on Microsoft Key Compromise 02.08.2023

In this follow up to our episode 320, we describe Microsoft's actions to mitigate this attack and explain new understanding that shows its impact to be broader than originally thought. Anyone using the Microsoft stack needs to understand this new threat.

Root Causes 322: RIP Kevin Mitnick 31.07.2023

In July famous security researcher Kevin Mitnick passed away. We briefly pay tribute to Kevin and talk about his contributions to white hat hacking as a practice.

Root Causes 321: CABF Moratorium on New Certificate Consumer Members 27.07.2023

The CA/Browser Forum recently passed a temporary moratorium on new members of the Certificate Consumer class. We explain how Certificate Consumers have been admittted in the past and the pros and cons of creating stricter rules for Certificate Consumers.

Root Causes 320: Microsoft-signed Root Kit Attack 24.07.2023

A new root kit attack in the wild is code signed by a Microsoft certificate. We explain kernel-level attacks, how powerful they are, and how this attack occurred.

Root Causes 319: EU Digital Wallets 21.07.2023

A new agreement mandates that European countries will make digital wallets available to their citizens in 2024. We explain what's coming and some of its implications.

Root Causes 318: What Is ACME Renewal Information (ARI)? 18.07.2023

ACME is a functional and widely supported protocol for certificate provisioning and installation. A new extension to the protocol will help automate renewals. In this episode we explain ACME Renewal Information (ARI).

Root Causes 317: New Automotive CAN Bus Attacks Demand PKI 13.07.2023

In this episode we describe how physically accessing the CAN bus wires in a modern automobile can allow a thief to take over key fob functionality to unlock the doors, start the engine, and ultimately steal the vehicle. We explain how PKI can defeat this attack and what is necessary to get there.

Root Causes 316: SquareSpace Acquires Google Domains 11.07.2023

SquareSpace recently acquired Google's domain registry business. We discuss what this move says about large technology trends.

Root Causes 315: Will the SEC Sue SolarWinds Executives? 07.07.2023

The SEC has sent "Wells notices" to two senior executives from SolarWinds, with regard to the 2019 supply chain attack. In this episode we explain these notices and their implication.

Root Causes 314: AI-based Deepfakes in Real Crimes 05.07.2023

We have spoken in previous episodes about the potential for deepfakes in real-world crimes. In this episode we discuss a variety of real-world attacks in which deepfakes have played a role. These include fake kidnapping, "sextortion," and a range of spear phishing attacks and social media scams.

Root Causes 313: SSL Revocation Reason Codes 22.06.2023

In 2022 Mozilla added a root program requirement that CAs include Reason Codes when revoking public TLS certificates. In this episode we explain the reason codes, along with some explicitly forbidden reason codes, and go into the backstory behind this requirement.

Root Causes 312: You Shouldn't Roll Your Own Crypto 20.06.2023

Don't roll your own crypto. In this episode we describe the findings from 2021 research that investigating the root causes of problems in cryptographic systems. The results may surprise you.

Root Causes 311: What Is CCADB? 16.06.2023

We describe CCADB, the Common CA Database. We explain the role of CCADB in the WebPKI and how this role is evolving.

Root Causes 310: Another AI Episode 13.06.2023

In this episode we continue to explore the capabilities of AI to replicate known people in deep fakes with AI-generated content.

Root Causes 309: What Is Key Attestation For Code Signing 08.06.2023

On June 1, 2023 new rules for delivery of code signing certificates went into effect, requiring the certificate be delivered by secure HSM. In addition to shipping a token by mail, certificates can be electronically delivered to Subscriber-owned hardware that supports key attestation. In this episode we explain key attestation, supporting hardware, and the pros and cons of this method.

Root Causes 308: E-Tugra Root Deprecation 05.06.2023

For the second time in under twelve months, a major browser is deprecating a CA's public trust. This time it's E-Tugra. Learn about the concerns raised about this CA, investigation of these concerns, and the ultimate deprecation decision.

Root Causes 307: OT Red Teaming Leads to Malware Attack 31.05.2023

In this episode we describe how tools from operational technology red team exercises are being repurposed for malware attacks.

Root Causes 306: Certificate Transparency Logs and Privacy 26.05.2023

Certificate Transparency (CT) logs do a lot of good for the WebPKI. They also, however, carry with them some privacy concerns. In this episode we explain those concerns.

Root Causes 305: The Fifth Pillar of Certificate Lifecycle Management 23.05.2023

In our episode 143 we introduced the Four Pillars of CLM. Now, two years later, we introduce a fifth pillar of CLM.

Root Causes 304: Your 90-day SSL Certificates Checklist 18.05.2023

90-day maximum term for SSL certificates is coming. In this episode expert guest Henry Lam details his four-point checklist for preparing enterprises for these shorter-lived certificates.

Root Causes 303: A Return to Chrome and the Address Bar 16.05.2023

In our recent episode 300 we discussed Chrome's upcoming removal of the lock icon from its interface. In this follow up, we catch the listener up on Chrome's longstanding program to minimize the URL in its interface, even to the point of contemplating removing the address bar entirely.

Root Causes 302: Intel Secure Boot Private Key Leak 12.05.2023

Resulting from a recent ransomware attack, a private key from Intel has been exposed, affecting more than a hundred OEM components and an unknown number of end user products. We explain what happened and its possible implications.

Escucha el podcast Root Causes: A PKI and Security Podcast en Replaio

Radio y podcasts en una sola app - gratis y sin registro. Instálala hoy y no te pierdas el estreno

Descárgala en Google Play

Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos