Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
Koniecznie odwiedź stronę podcastu i wesprzyj twórcę: www.spreaker.com
Gdzie słuchać?
Podcasty w aplikacji Replaio Radio Już wkrótcePodcasty trafią do aplikacji już wkrótce. Zainstaluj teraz i jako pierwszy zobacz nowe podejście do podcastów
Odcinki
Root Causes 251: What's Next for the NIST PQC Primitives? 27.10.2022 20:46
NIST has announced its new post-quantum cryptography primitives. So now what? In this episode we discuss the next steps required by the technology industry for widespread adoption of these algorithms and what the enterprise can do starting today to ready itself for quantum-safe encryption.
Root Causes 250: 250 Episodes of Root Causes! 26.10.2022 26:34
It's Root Causes episode 250! In this episode Tim and Jason indulge themselves in podcasting about podcasting. Hear about setting up a podcast, choosing topics, why we don't rehearse, why we have so few guests, and how we reacted the first time someone asked us for a media kit.
Root Causes 249: What Is MFA Exhaustion? 21.10.2022 10:24
Recent months have seen several high profile attacks that were enabled by defeating the MFA accompanying user name and password login. In this episode we explain the concept of MFA fatigue and why it is an enabler for these attacks.
Root Causes 248: Azure Code Signing Announced 18.10.2022 9:27
Microsoft has announced the upcoming availability of a Microsoft-run code signing solution inside the Azure platform. We explain this approach's advantages and what to expect from it.
Root Causes 247: Uber Breach Unpacked 13.10.2022 12:02
A recent high-profile breach of Uber's systems led to widespread data loss. Join our experts as we unpack the specifics of how this attack came about.
Root Causes 246: Google Chrome Root Program Announced 03.10.2022 12:01
Google Chrome recently announced the formation of its trusted root program. It may be surprising to learn that the world's most popular browser has existed for more than a decade without its own root program. In this episode we explain why that is the case, why Chrome is launching a root program now, and the implications of this announcement.
Root Causes 245: One Time Passcode as a Liability 29.09.2022 10:11
A recent article from Brian Krebs advances the idea that using OTP MFA may actually be a liability to security. In this episode we explain the reasoning behind this characterization.
Root Causes 244: PwC Survey Reports Cyber Security as Biggest Risk to Companies 26.09.2022 15:40
A recent survey from PwC reports that cyber threats are no longer solely the domain on the CISO but instead have become every senior executive's concern. We dive deep into these survey results and talk about they correlate with our own experiences, IT skills gaps, and feeding the podcasting beast.
Root Causes 243: Which Came First, the BRs or the EVGs? 20.09.2022 10:33
Many people don't realize that the CA/Browser Forum's Baseline Requirements actually came LATER THAN the Extended Validation Guidelines. In this episode we explain how this seemly backward turn of events came about and what it says about how online trust has evolved over the past few decades.
Root Causes 242: Let's Encrypt Founder Peter Eckersley Passes 16.09.2022 7:05
Electronic Frontier Foundation member and Let's Encrypt co-founder Peter Eckersley passed away recently at a young age. In this episode we pay respect to Peter's memory and his many contributions, including ACME, Certbot, and Let's Encrypt.
Root Causes 241: Is China Outspending the West in Quantum Computing? 12.09.2022 20:20
A December 2021 report appears to indicate that China as vastly outspending Western countries in quantum computing. In this episode we examine this claim, including the role of private industry as opposed to government funding, the importance of international cooperation, and the vast implications of winning the race for quantum computing.
Root Causes 240: Hyundai Production Private Key Found in How-to Manual 06.09.2022 15:40
A white hat researcher recently defeated a production automobile's PKI by searching for the private key on Google. Join us as we describe the implementation error making this possible and how it might have come about.
Root Causes 239: Post-quantum Cryptography Candidate SIKE Defeated 28.08.2022 17:31
NIST's round four post-quantum crypto candidate SIKE (Supersingular Isogeny Key Encapsulation) has been defeated and is now out of consideration. In this episode we explain isogeny cryptography, why NIST is seeking additional candidates, and why failures of this kind are expected and healthy for PQC.
Root Causes 238: Tim's Big Phishing Adventure 15.08.2022 16:51
In a personally unprecedented occurrence, Tim's identity as a Sectigo executive is being used in a "waterholing" phishing scam intended to raid job seekers' bank accounts. We describe what is going on, how we found out, and the challenges in combatting such an attack.
Root Causes 237: Why Mozilla Is So Important to CAs 10.08.2022 11:56
Mozilla is a highly important to the world of public certificates, with influence beyond what the Firefox browser market share would suggest. In this episode we examine the historical reasons for this influence and the mechanisms that maintain that influence today.
Root Causes 236: Active Directory Patch Knocks Out Non-MS Identity Consumers 04.08.2022 12:38
A recently revealed vulnerability in Active Directory made it possible for an attacker to escalate privileges inappropriately. Microsoft's responded with a patch in May 2022, which unfortunately has forced a difficult workaround for many common software components beyond Active Directory that will otherwise be incapable of working with AD identities. In this episode we explain what his happening,...
Root Causes 235: What Is Lattice-based Cryptography? 26.07.2022 26:24
The recent winners of the NIST post-quantum cryptography contest are strongly focused on lattice-based encryption. In this episode we explain at a high level what this cryptographic approach entails and why lattice-based algorithms fared so well in the NIST search.
Root Causes 234: Report from the 2022 RSA Conference 22.07.2022 10:14
The RSA Security Conference is back. In this episode we talk about what happened in 2020 and how the first post-COVID RSAC compared to earlier years, along with some of the major themes this year.
Root Causes 233: CISA Recommendations for Post-Quantum Crypto 12.07.2022 25:27
In coordination with NIST's announcement of its new post-quantum cryptographic algorithm contest winners, the Cybersecurity and Infrastructure Security Agency released a bulletin listing six key actions for IT to commence now. We read out these six actions and put them in context.
Root Causes 232: NIST Announces Post Quantum Crypto Selections 08.07.2022 18:48
NIST has announced its winning algorithms for round 3 of its post-quantum cryptography "contest." Join us as we name the winning algorithms and why they were chosen. We discuss the continuing effort to arrive at additional algorithms, and we talk about the next steps coming out of this announcement.
Root Causes 231: What Is FIDO? 06.07.2022 24:11
Recent announcements about consumer passwordless authentication build on standards like FIDO and WebAuthn. In this episode we explain device-centric authentication, the FIDO Alliance, and how it all works.
Root Causes 230: What Is Apple Passkey? 30.06.2022 15:55
Apple recently announced its Passkey functionality, which will allow passwordless authentication between Apple devices and supporting web services through key exchange. In this episode we discuss how this works, the user experience, the significance of FIDO and WebAuthn, and implications for consumer-facing sites.
Root Causes 229: Browsing Collectives and the 80/20 Rule of Browser Privacy 08.06.2022 21:41
In this follow-on to our two previous podcasts, we elucidate additional potential schemes for preserving consumer privacy. We discuss data aggregation, the power of the default, decentralized blockchain identities, the death of cookies, browsing collectives, privacy browsers, and the 80/20 rule of browser entropy.
Root Causes 228: Getting the FLoC out of Here 31.05.2022 14:22
In a follow-up to our recent episode on cookies and browser tracking, we discuss Google's Federated Learning of Cohorts (FLoC) initiative, why it failed as a response, and other directions the industry is looking in.
Root Causes 227: Let's Talk About Cookies 27.05.2022 23:34
In this episode we explain the fundamentals of cookies and why, despite their obvious benefits, they present troublesome privacy concerns. We discuss the many ways web users can be tracked including cross-site cookies, tracking pixels, and browser fingerprinting.
Podobne podcasty
Replaio nie jest wydawcą podcastów; nazwy audycji, okładki i audio należą do ich autorów i są rozpowszechniane przez publiczne kanały RSS