Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com
Autor
Tim Callan
Categoría
Web del podcast
Último episodio
9 de oct. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Root Causes 648: Claude Mythos Discovers New HAWK and AES Attacks 03.08.2026 21:29
Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these de...
Root Causes 647: AD CS "Certighost" Flaw Highlights Agentic Identity Risks 31.07.2026 19:14
A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.
Root Causes 646: Clarifying the Dates for clientAuth Deprecation 29.07.2026 5:41
Because of a change in the drop-dead date, we have observed confusion in the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage. In this episode we spell out these dates very clearly.
Root Causes 645: FAPI 2.0 Principles 27.07.2026 3:41
In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.
Root Causes 644: Cryptographically Bound Tokens 24.07.2026 5:06
In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication. In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.
Root Causes 643: Certificates for Stronger Agent Authentication 22.07.2026 10:50
We survey different strategies for securely authenticating agentic AI, including certificates and SPIFFE. We discuss Zero Trust and the Principle of Least Privileges as applied to agents.
Root Causes 642: Anthropic to Support SPIFFE/SPIRE 20.07.2026 3:48
Anthropic has announced its intentions to support SPIFFE/SPIRE with the SPIRE server rooted in an "upstream authority," which will require a root private CA rather than allowing self-attestation for agentic AI.
Root Causes 641: What Is SPIRE? 17.07.2026 5:51
In our episode 640 we defined SPIFFE, which provides digital identity for agentic workloads. In this episode we explain SPIRE (SPIFFE Runtime Environment), the SPIFFE certificate provisioning protocol.
Root Causes 640: What is SPIFFE? 15.07.2026 4:42
SPIFFE (Secure Production Identity Framework for Everyone) is a standard for digital identity for agentic workloads. In this episode we explain.
Root Causes 639: Fighting Static API Key Spillage Is Like Fighting Gravity 10.07.2026 8:29
Static API keys are a common security practice. In this episode we discuss the risk of these keys being revealed, including directly by the AIs that use them.
Root Causes 638: Catfishing 08.07.2026 21:16
Tim shares his very personal experience with would-be catfishers and we talk about how AI is set to change the catfishing attack.
Root Causes 637: Is It Time to Get Rid of EV SSL? 06.07.2026 11:00
The Baseline Requirements, CT logs, the Bugzilla Bloodbath, shortening certificate lifespans, all these trends serve to enforce a high level of quality and predictability across WebPKI certificates. Nearly twenty years after the introduction of EV SSL, we ask if it has served its purpose and should be retired.
Root Causes 636: The Future of Crypto Agility 02.07.2026 9:30
Dustin Moody of NIST joins us to talk about the evolution of standardized cryptography beyond the current PQC efforts. Topics include maintaining visibility on cryptography presently in use, 50 years of RSA, and cryptographic heterogeny.
Root Causes 635: Do We Need to Get Rid of ECC? 29.06.2026 9:34
Bas Westerbaan of Cloudflare joins us to discuss recent information that heightens concerns about Elliptic Curve Cryptography (ECC) and its vulnerability to a cryptographically relevant quantum computer (CRQC). We pose the question do we need to deprecate ECC in advance of our migration to ML-DSA and other PQC algorithms.
Root Causes 634: White House Executive Order Accelerates PQC Deployment 26.06.2026 12:43
A new Executive Order (EO) moves the deadline for ML-DSA deployment up to 2031. We talk about why this happened and its implications on government, the technology industry, and enterprises around the globe.
Root Causes 633: ETSI PQC Conference Wrap Up 24.06.2026 16:12
We are freshly returned from the 2026 ETSI PQC Conference. We give a debrief on the conference, including the difference between post quantum cryptography (PQC) and quantum key distribution (QKD), the algorithmic zoo, PQC for blockchain, the Dunning Kruger Effect, and cryptographic Frogger.
Root Causes 632: Gartner Risk and Security 2026 Wrapup 22.06.2026 19:56
We recently attended the Gartner Risk and Security conference for 2026, where we observed a great deal of attention on not only AI but also post quantum cryptography (PQC). Join us as we share the key takeaways.
Root Causes 631: Did the Bugzilla Bloodbath Change Anything? 19.06.2026 13:10
2024 saw a flurry of high profile incidents for public CA, which we named the Bugzilla Bloodbath. We look back to see how the WebPKI has changed as a consequence.
Root Causes 630: The PQC Physicality Crisis 17.06.2026 6:28
Resource-constrained devices may need to address PQC through real-time, seed-based, key generation. Unfortunately, this leaves the full key exposed very briefly in RAM. The potential consequences of this are far-reaching and scary. We go into the details.
Root Causes 629: Does the Evidence Support Moving PQC Deadlines to 2029? 15.06.2026 16:13
Sam Jaques of the University of Waterloo returns to discuss his tracking of progress in quantum computers and offer a perspective on moving our PQC deadlines up to 2029.
Root Causes 628: PI-DOS (Prompt Injection-based Denial of Service) 12.06.2026 9:41
An emerging attack against AIs is to create a significantly complex and recursive prompt that will occupy the AI indefinitely or for a sufficiently long time that it acts as a Denial-of-Service (DoS) attack. We describe how this works.
Root Causes 627: UK vs Apple E2EE Backups 10.06.2026 5:12
In the latest in our coverage of government versus encryption, the UK issued secret orders to Apple to give it a cryptographic backdoor to Apple's advanced data protection capability for iCloud. Apple responded by eliminating encryption entirely for UK users. We break it down.
Root Causes 626: TLS 1.3 Roadblock 08.06.2026 10:16
TLS 1.3 is required to take advantage of post quantum cryptography (PQC) algorithms. Yes, we still see a lot of TLS 1.2 or earlier in deployment. We examine why this is the case and what to do about it.
Root Causes 625: AI in 1000 Days - Cyber Defense 05.06.2026 8:07
Recent revelations about Mythos and its ability to expose vulnerabilities have forced us to rethink basic assumptions about cyber defense. In our "AI in 1000 Days" series, Jason Soroko and I examine the implications of these revelations three years from now. This includes upping the overall pace of attack and changes to best practices in cyber security defense.
Root Causes 624: Implications of Mythos 03.06.2026 15:58
Anthropic has delayed its widespread release of Mythos to give major software providers a chance to close off the many vulnerabilities it has discovered. We dig into the vast implications of Mythos and other AI models for the future of cybersecurity.
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos