Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
Koniecznie odwiedź stronę podcastu i wesprzyj twórcę: www.spreaker.com
Gdzie słuchać?
Podcasty w aplikacji Replaio Radio Już wkrótcePodcasty trafią do aplikacji już wkrótce. Zainstaluj teraz i jako pierwszy zobacz nowe podejście do podcastów
Odcinki
Root Causes 376: Gartner's New CLM Framework 08.04.2024 19:30
Gartner has released a new framework for Certificate Lifecycle Management, called the Seven Core Functions of Certificate Automation. We walk through this framework and answer how it fits in with our own Five Pillars of CLM.
Root Causes 375: What Is Name Space Lifecycle Management? 05.04.2024 28:00
In this guest episode we discuss name space hygiene with Geir Rasmussen, founder of NodeZro. CNAMEs, SPF, DMARC, name server entries, and other DNS identifiers, left unattended, can expose companies to identity-based attacks. We lay out the steps in addressing name space cleanup.
Root Causes 374: NIST Cyber Security Framework 2 Released 31.03.2024 14:32
NIST Cyber Security Framework version 2.0 is released. It includes guidance on identity management and authentication. In this first episode of a series, we describe this framework's basic structure and its effect on industry.
Root Causes 373: Massive Brand Hijack Subverts More Than 21,000 Domains and Subdomains 29.03.2024 14:41
A massive name space attack has hijacked more than 21,000 domains and subdomains, including a who's who list of major global brands. This huge and innovative attack takes advantage of inherited trust in abandoned domains. We explain what is happening.
Root Causes 372: Bugzilla Bloodbath 26.03.2024 22:06
It's a bloodbath on Bugzilla. Since March 9, more than 25 new Bugzilla bugs been written up, which is 10x the typical pace. And it's not over. In this episode we explain what is going on and why.
Root Causes 371: MPIC Rules Go to CABF Ballot 22.03.2024 20:18
A ballot for Multi-perspective Issuance Corroboration (MPIC), formerly known as MPDV, has entered a discussion period in the CA/Browser Forum (CABF). We explain the details of what it contains.
Root Causes 370: Drama on Bugzilla 19.03.2024 27:39
An evolving incident on Bugzilla has garnered a lot of attention and touches several important issues in the WebPKI ecosystem. We report what went on and unpack the issues involved.
Root Causes 369: IMessage to Be PQC Enabled 15.03.2024 14:47
Apple has announced that iMessage will employ post-quantum cryptography (PQC). We explain the implications of this announcement.
Root Causes 368: CRYSTALS-Kyber Is Now ML-KEM 13.03.2024 9:08
What has been known as CRYSTALS-Kyber now has the new official name of Module Lattice-based Key Encryption Module, or ML-KEM. We give an update on the state of the NIST round 3 winners.
Root Causes 367: Did an IoT Toothbrush Botnet Perform DDoS Attacks? 07.03.2024 7:33
A story circulated earlier this year about a botnet composed of millions of IoT toothbrushes, which later was debunked. We tell you the whole tale.
Root Causes 366: What Is eIDAS? 04.03.2024 27:14
eIDAS 2.0 has been making headlines recently with its proposed expansion to the European digital identity ecosystem. But what is eIDAS? What does it do, and why does it exist? In this episode we give you the basics.
Root Causes 365: What Is Subdomain Hijacking? 26.02.2024 13:32
In this episode we explain subdomain hijacking, including dangling subdomains and how they can constitute vulnerabilities.
Root Causes 364: Video Conference Deepfake Enables $25 Million Theft 22.02.2024 8:44
Deepfakes continue to show themselves as part of the standard criminal toolkit. A recent deepfake spear phish enabled a $25 million Business Email Compromise (BEC). We explain what happened.
Root Causes 363: Defending Yourself Against Use of Stolen Privileges 18.02.2024 7:40
CloudFlare recently published details of an attack it suffered as a downstream effect of a November 2023 breach against Okta and what it did to nullify its success. We discuss the steps enterprises can take to protect themselves against malicious use of stolen access credentials.
Root Causes 362: When You're Attacked by a State Actor 12.02.2024 10:07
In this episode we share the details of a recent nation state actor attack on Microsoft and some of the lessons learned.
Root Causes 361: The Premise of on Premise 09.02.2024 37:02
In this episode we examine commonly held belief that on-premise systems give system administrators greater levels of control and that that is better for security or other reasons. We explore the pros and cons of extra control, to what degree it is a benefit, and if it's worth it.
Root Causes 360: Joe Biden Deepfake Plays in New Hampshire Primary 06.02.2024 11:53
A deepfake of Joe Biden's voice made an appearance in robocalls leading up to the New Hampshire primary. We discuss this latest development and its implications.
Root Causes 359: 90-day SSL Won't Affect Organization Validation Periods 02.02.2024 15:38
With maximum 90-day term coming for public SSL certificates and DCV reuse also moving to 90 days, we explain why we do not expect a similar reduction in the reuse period for organization validation.
Root Causes 358: Security Questionnaire Sins 30.01.2024 33:10
In this episode we present a catalog of "security questionnaire sins," which are avoidable problems and errors that frequently occur in the security questionnaires enterprises send to vendors. Categories include difficulty of access, poor technical implementation, poor policies, and poor questions.
Root Causes 357: Signed Digital Photographs 26.01.2024 11:44
Three major camera manufacturers have joined to create a standard for signed digital images from their cameras.
Root Causes 356: Will MPDV Eliminate Email-based DCV? 22.01.2024 16:30
Multi-perspective Domain Validation (MPDV) is a necessary evolution of Domain Control Validation (DCV) to protect against Border Gateway Protocol (BGP) attacks. We explore how MPDV may affect accepted DCV methods, especially the email method.
Root Causes 355: Should a Managed PKI Provider Do Whatever the Customer Wants? 19.01.2024 22:31
In this episode we explore whether a managed PKI provider should give complete control over PKI decisions to the end customer or if it should enforce certain minimum standards and principles regardless of what the customer asks for.
Root Causes 354: CyberSlash Attack Against CRYSTALS-Kyber 16.01.2024 12:16
A newly published attack against common implementations of CRYSTALS-Kyber illustrates how cryptographic implementations can be vulnerable even if the cyphers themselves remain sound.
Root Causes 353: Why Isn't PKI Everywhere? 09.01.2024 24:10
Our hosts firmly believe that PKI is a necessary component of all digital interactions. And yet there are still gaps in PKI implementation. We discuss these gaps and why they persist.
Root Causes 352: FBI Vs. End-to-end Encryption in Meta Apps 04.01.2024 15:21
Meta is finally rolling out end-to-end encryption across its messaging apps. This is the latest chapter in the long story of government versus encryption. We rant a little about this.
Podobne podcasty
Replaio nie jest wydawcą podcastów; nazwy audycji, okładki i audio należą do ich autorów i są rozpowszechniane przez publiczne kanały RSS