Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com
Autor
Tim Callan
Categoría
Web del podcast
Último episodio
9 de oct. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Root Causes 598: Why Johnny Can't authN in OT 30.03.2026 7:56
A recent CISA report declares that the nation's OT infrastructure is incapable of keeping up with the crypto agility and certificate management needs that modern security demands. We examine this finding.
Root Causes 597: If You Don't Hold the Keys, You Don't Hold the Subpoenas 27.03.2026 7:27
Microsoft has publicly stated that it will hand over Bitlocker keys to US law enforcement agencies without requiring a subpoena or court order. These keys can be held by users rather than Microsoft, at their option. We dive into this topic.
Root Causes 596: CLM and Operational Uptime 25.03.2026 6:44
We usually think of Certificate Lifecycle Management (CLM) as a security category. But we could equally well categorize it as an operations category that enables uptime. In this episode we make our case.
Root Causes 595: What Is a Digital Parasite? 23.03.2026 12:31
We introduce the concept of a "digital parasite," explaining why this attack philosophy appears to be on the rise.
Root Causes 594: Google's Five PQC Recommendations for Policy Makers 18.03.2026 16:58
In a recent blog post Google made five recommendations for policy makers. We walk down the list.
Root Causes 592: When a CAA Record Outlives the CA 13.03.2026 8:45
CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out.
Root Causes 590: The Size of the CA Is Not the Size of the Risk 10.03.2026 7:20
It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has. This is false, however. In this episode we address this misconception.
Root Causes 589: Is a Cryptographically Relevant Quantum Computer Economically Viable? 06.03.2026 9:36
We recently heard the argument that it's simply too expensive to develop a cryptographically relevant quantum computer. We vehemently disagree. In this episode we explain why.
Root Causes 588: It's Cryptographic Frogger from Here on Out 04.03.2026 9:56
In this episode Tim explains that the transition to PQC is not just a change in cryptographic algorithms but also a fundamental shift in how we treat our cryptography. From here on out, IT systems need to be fundamentally crypto agile in a way we've never had to be before.
Root Causes 587: AI Orchestration for Attackers 02.03.2026 10:56
Jason describes a recent intrusion almost entirely operated by off-the-shelf AI tools. This is an important milestone in security. We describe its potential consequences.
Root Causes 586: Beyond Harvest Now Decrypt Later 27.02.2026 8:40
We expand on the concept of trust-now-forge-later to list a whole bevy of additional attacks that eventually will be enabled by cryptographically relevant quantum computers.
Root Causes 585: The Cryptographic Inventory Manifesto 25.02.2026 8:55
We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.
Root Causes 585: The Cryptographic Inventory Manifesto 24.02.2026 8:55
We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.
Root Causes 584: Mapping DORA to CLM 23.02.2026 20:39
We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are.
Root Causes 584: Mapping DORA to CLM 23.02.2026 20:39
We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are.
Root Causes 583: AI Versus ECC P 256 21.02.2026 10:52
In an innovative application, an AI has been used to find private keys for ECC (Elliptic Curve Cryptography) P 256. We explain how.
Root Causes 583: AI Versus ECC P 256 20.02.2026 10:52
Recorded in Ottawa Ontario.
Root Causes 582: New Research Drastically Cuts Number of Qubits for Cryptographic Relevance 17.02.2026 14:12
New research indicates that the number of qubits necessary to achieve cryptographic relevance has reduced by two orders of magnitude. We cover this breaking news and its implications.
Root Causes 581: A Timeline for Deprecation of Manual DCV Methods 15.02.2026 13:10
By CABF ballot all manual methods of Domain Control Validation (DCV) will be deprecated by 2028. We explain which methods are due for deprecation and when.
Root Causes 580: Top Use Cases for Hybrid Certificates 13.02.2026 12:48
We go over the qualities in abstract of a use case that strongly invites the use of hybrid certificates and then run down a list of specific use cases that meet these criteria. This includes OT systems, code signing, secure boot, WiFi, enterprise S/MIME, and more.
Root Causes 579: Make Cryptography Boring Again 10.02.2026 17:45
In this episode Jason declares that we must make cryptography boring again. We get into what that means and why it matters.
Root Causes 578: 200 Days Won't Actually Be 200 Days 09.02.2026 10:11
We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days. It happens that all those numbers are too large and the actual maxima will be less than that. We explain.
Root Causes 577: All the Stuff That's Coming in March 06.02.2026 10:06
March 2026 is due to be the most eventful month in the history of the WebPKI. Join us as we go over all the many changes coming next month.
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos