Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
Koniecznie odwiedź stronę podcastu i wesprzyj twórcę: www.spreaker.com
Gdzie słuchać?
Podcasty w aplikacji Replaio Radio Już wkrótcePodcasty trafią do aplikacji już wkrótce. Zainstaluj teraz i jako pierwszy zobacz nowe podejście do podcastów
Odcinki
Root Causes 551: PKI in a Swarm at 50 mph 24.11.2025 9:54
Jason explores the role cryptography and trust systems play in the command and control of groups of autonomous drone systems.
Root Causes 550: WebPKI Certificate Lifespan - How Low Can You Go? 21.11.2025 15:47
Certificate maximum term is shrinking. In this episode we examine exactly how short they could get.
Root Causes 549: AI 1000 Days from Now - the Defeat of Voice Authentication 19.11.2025 18:11
In our ongoing series on AI in 1000 days, we describe the inevitable, complete distrust of voice printing as an authentication method, including why and what we think will happen.
Root Causes 548: AI 1000 Days from Now - Emotional Intelligence 17.11.2025 17:44
We begin a new series about what we expect from AI in the next three years. In this episode we discuss AI emulating emotional intelligence and its benefits.
Root Causes 547: Should We Do Mass Revocation Fire Drills? 14.11.2025 12:33
In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.
Root Causes 546: New Research Codifies Arguments for and Against QWACs 12.11.2025 43:26
We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates.
Root Causes 545: What Is MOSH? 10.11.2025 8:19
The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.
Root Causes 54: What Is Chain of Lure? 07.11.2025 10:03
Chain of lure is an attack method used to circumvent restrictions and boundaries places on AIs. Jason explains this attack and its implications.
Root Causes 543: AI Finds a Zero Day 05.11.2025 17:46
We have seen the first known instance of an AI tool discovering a zero-day vulnerability. This could have vast implications on vulnerability detection and bug bounty programs. We discuss the implications.
Root Causes 542: Use Cases for HQC 02.11.2025 10:35
In this episode we go over some of the reasons one might choose HQC over ML-KEM as a PQC key exchange algorithm for specific circumstances. And we discuss the future diversity of cryptography.
Root Causes 541: Introducing the HQC PQC Algorithm 31.10.2025 6:53
NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC. We explain this code-based algorithm.
Root Causes 540: Contextual CBOM 27.10.2025 11:04
We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.
Root Causes 539: What Is the Two-QWAC Architecture? 22.10.2025 20:03
A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain. We explain what's coming and why.
Root Causes 538: What Is an Entropy Desert? 20.10.2025 9:03
An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.
Root Causes 537: The Thermodynamics of Privacy 17.10.2025 13:35
In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.
Root Causes 536: Patent Blocker on ML-KEM 15.10.2025 11:52
A patent dispute in 2024 nearly blocked ML-KEM. But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations. We explain.
Root Causes 535: The CPS Is a Superset of Actual Practices 12.10.2025 10:23
The CPS must always be a superset of actual practices in a properly running CA. We explain why this is a product of good design.
Root Causes 534: Signing the Machines That Think 10.10.2025 8:57
Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime. How do you know? Jason proposes that, the same way we sign our code, we should be signing our AI models as well.
Root Causes 533: Flexibility Through Multi-CA Trust Models 07.10.2025 9:26
We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.
Root Causes 532: Introducing Offline PKI 02.10.2025 11:05
In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.
Root Causes 531: Benefits of Single-purpose Root Hierarchies 01.10.2025 16:37
Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones. We discuss why.
Root Causes 530: Introducing the AI Iceberg 29.09.2025 18:47
We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.
Root Causes 529: What Is a Common Mark Certificate? 24.09.2025 7:33
Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.
Root Causes 528: Misissued SSL Certificate for 1.1.1.1 17.09.2025 17:32
A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses. We go into the details.
Root Causes 527: Key Dates for the Deprecation of Public mTLS 15.09.2025 10:26
Client authentication using public TLS server certificates is on the deprecation path. In this episode we go through the key dates in this deprecation.
Podobne podcasty
Replaio nie jest wydawcą podcastów; nazwy audycji, okładki i audio należą do ich autorów i są rozpowszechniane przez publiczne kanały RSS