fr

Tim Callan

Root Causes: A PKI and Security Podcast

Podcast by Tim Callan and Jason Soroko

N'hésitez pas à visiter le site du podcast et à soutenir son créateur : www.spreaker.com

Auteur

Tim Callan

Catégorie

Society

Site du podcast

www.spreaker.com

Dernier épisode

9 oct. 2026

Où écouter ?

Les podcasts dans l'appli Replaio Radio Bientôt disponible

Les podcasts arrivent très bientôt dans l'appli. Installe-la dès maintenant et découvre en avant-première une toute nouvelle façon de vivre les podcasts

Télécharger sur Google Play Installe-la gratuitement Android près de 10 M de téléchargements · note de 4,8 iOS bientôt

Épisodes

Root Causes 673: Harvest Now, Decrypt 83 Years Later 09.10.2026
Root Causes 672: New AI-driven Attack on RSA 1024 Revealed 07.10.2026
Root Causes 671: IETF Releases MTC Draft 6 03.10.2026
Root Causes 670: Apple Announces Its MTC Root Program 01.10.2026

Apple has announced it will support Merkle Tree Certificates for PQC and has released a draft root store policy. We share some of the surprising requirements in this draft.

Root Causes 669: The clientAuth EKU Deprecation Is Coming 28.09.2026

Publicly trusted client authentication certificates have a hard deadline to be deprecated in Q1 2027. Not everyone is ready for that. We discuss some of the reasons why and what to do about it.

Root Causes 668: AI in 1000 Days - Ownership of IP 25.09.2026
Root Causes 667: South Korea Has a Parallel PQC Program with Separate Algorithms 23.09.2026

The NIST contest has not been the only government-led effort to discover qunatum-resistant algorithms. In this episode we describe South Korea's PQC contest, which is entirely independent of the NIST contest.

Root Causes 666: What Is a Scientifically Relevant Quantum Computer? Part 2 21.09.2026

In this second of two episodes, we finish our discussion of Scientifically Relevant Quantum Computers (SRQC) and their implications.

Root Causes 665: What is Quantum Security Posture Management (QSPM)? 18.09.2026

We define a new term, Quantum Security Posture Management (QSPM) and explain what it is and why it's important for PQC plans.

Root Causes 664: What Is a Scientifically Relevant Quantum Computer? Part 1 17.09.2026

Much ado has been made about quantum computers breaking traditional cryptography. But that's not the reason so much effort is going into their creation. In this first of two episodes, we discuss the expected scientific applications for quantum computing architecture and the idea of a Scientifically Relevant Quantum Computer (SRQC).

Root Causes 663: The Trouble with Quantum Key Distribution 11.09.2026

Quantum Key Distribution (QKD) is supposed to be this highly secure method of key exchange. But is it as secure as people say? We explore the potential weaknesses with QKD.

Root Causes 662: HAWK Eliminated from NIST Competition, FALCON Unaffected 09.09.2026

We follow up on the recent Mythos attack against PQC candidate HAWK. We discuss the impact of this attack on both HAWK and FALCON.

Root Causes 661: What Will Happen with eIDAS and MTC? 04.09.2026

TLS certificates from CA/Browser Forum CAs are not the only server certificates in the WebPKI. eIDAS QWACs are treated as server certificates by the major browsers. We see clear progress toward post quantum cryptography (PQC) for TLS by way of the Merkle Tree Certificate (MTC) architecture. But what is the path to PQC for eIDAS? We examine this question.

Root Causes 660: What Are Delegated Credentials? 02.09.2026

As certificate lifespans become extremely short, new methods of delivery become functionally necessary. We explain RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates.

Root Causes 659: Should We Lengthen Certificate Lifespans? 31.08.2026

With certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again. We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is generally a bad policy.

Root Causes 658: The Trouble with X9 Certificates 26.08.2026

X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates. We clarify why this is not the case.

Root Causes 657: What Is Chaos Engineering? 24.08.2026

"Chaos engineering" describes the practice of injecting faults into a system to see what happens. This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.

Root Causes 656: The Trouble with Recursive AI Training 21.08.2026

Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results. As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results. This ultimately can result in completely unusable information.

Root Causes 655: Why Not to Create Your Own Private CA 19.08.2026

It is possible to use common tools like OpenSSL to create your own ML-DSA private CA. This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.

Root Causes 654: What's the Difference Between ML-DSA and ML-KEM? 17.08.2026

We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.

Root Causes 653: Post Quantum Civilization 14.08.2026

Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.

Root Causes 652: Choosing WebPKI Deprecation Dates 12.08.2026

There is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be.

Root Causes 651: Look at a Calendar 10.08.2026

It is surprising that we continue to see root expirations occur at the most inopportune times. Weekends, public holidays, even New Year's Eve. In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."

Root Causes 650: Is It Time to Stop Saying SSL? 07.08.2026

SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.

Root Causes 649: Client Authentication Certificate Use Cases 05.08.2026

With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it.

Écoute le podcast Root Causes: A PKI and Security Podcast sur Replaio

La radio et les podcasts dans une seule appli - gratuite, sans inscription. Installe-la dès aujourd'hui et ne rate pas le lancement

Télécharger sur Google Play

Replaio n'est pas éditeur de podcasts ; les noms des émissions, les visuels et l'audio appartiennent à leurs auteurs et sont diffusés via des flux RSS publics