Tim Callan

Root Causes: A PKI and Security Podcast

Podcast by Tim Callan and Jason Soroko

No dejes de visitar la web del podcast y apoyar a su creador: www.spreaker.com

Autor

Tim Callan

Categoría

Society

Web del podcast

www.spreaker.com

Último episodio

9 de oct. de 2026

¿Dónde escuchar?

Podcasts en la app Replaio Radio Muy pronto

Los podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts

Descárgala en Google Play Instálala gratis Android casi 10 M de descargas · valoración de 4,8 iOS muy pronto

Episodios

Root Causes 526: Voice Biometrics Are Worthless 12.09.2025

Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.

Root Causes 525: The End of Email-based DCV 10.09.2025

A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years. We go into the details.

Root Causes 524: How to Kill Three Birds with One Stone 08.09.2025

Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates. These are 47-day SSL, PQC, and the deprecation of mTLS. We describe the overlap between these efforts and how to combine them for better efficiency and project management.

Root Causes 523: Will Your Configuration Block MPIC DCV? 03.09.2025

MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you have a problem.

Root Causes 522: How Prepared Are Enterprises for PQC? (Part 2) 27.08.2025

We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).

Root Causes 521: How Prepared Are Enterprises for PQC? (Part 1) 22.08.2025

We begin to go over the results of Sectigo's recent survey of enterprises and their preparedness and plans for adopting Post Quantum Cryptography (PQC).

Root Causes 520: How Prepared Are IT Teams for 47-day Certificates? 20.08.2025

Sectigo has released the results of its survey of IT professionals in charge of certificates to measure their readiness and preparation for 47-day maximum certificate term. We go over the results.

Root Causes 519: AI Is the Room 18.08.2025

AI is not the elephant in the room. It is the room itself. Jason explains what he means by that.

Root Causes 518: NCSC Lukewarm on FIDO WebAuthn 13.08.2025

Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution. We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of Linux support.

Root Causes 517: The Cost of Quantum Factoring 25.07.2025

Jason walks us through an important recent paper from Google tracking the cost of quantum factoring.

Root Causes 516: PQC for ADCS 21.07.2025

Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should be asking.

Root Causes 515: What Is Entropy-aware Governance? 18.07.2025

Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and requirements.

Root Causes 514: Diary of an Online Firestorm 16.07.2025

Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread. We discuss what a more functional response would have looked like.

Root Causes 513: Is Revocation the Best Remedy for CPS Misalignment? 14.07.2025

We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.

Root Causes 512: CPS Versus Practices Misalignment 11.07.2025

We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation.

Root Causes 511: The GoML Root Store 05.07.2025

We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store.

Root Causes 510: Introducing the GoML Browser 26.06.2025

We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling.

Root Causes 509: What Is a CPS? 25.06.2025

We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs.

Root Causes 508: What Is Code Vibing? 23.06.2025

"Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser.

Root Causes 507: First Distrust of 2025 19.06.2025

The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details.

Root Causes 506: Recap of CABF Face-to-face #65 17.06.2025

For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting. We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face.

Root Causes 505: Trust Now, Forge Later 13.06.2025

In this episode we explain the potential for future quantum computers to break files signed today with RSA or ECC, called "Trust now, forge later."

Root Causes 504: Jason Programs a Quantum Computer 10.06.2025

Jason describes his recent experience using Amazon Braket.

Root Causes 503: What Are Hybrid and Composite PQC? 06.06.2025

We explain the difference between two strategies of PQC implementation, which we call hybrid and composite.

Root Causes 502: The PQC Game of Chicken 04.06.2025

In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse. We discuss stack ranking and "eyes open" PQC risk decisions.

Escucha el podcast Root Causes: A PKI and Security Podcast en Replaio

Radio y podcasts en una sola app - gratis y sin registro. Instálala hoy y no te pierdas el estreno

Descárgala en Google Play

Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos