Tim Callan and Jason Soroko

Root Causes: A PKI and Security Podcast

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...

Author

Tim Callan and Jason Soroko

Category

Technology

Podcast website

soundcloud.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Root Causes 388: What Is the WebPKI? 22.05.2024

These days we frequently discuss "the WebPKI." But what does that really mean? In this episode we define the term and explain how this definition evolved over time. We give an inventory of a main components of the WebPKI and discuss what's required to become a CA.

Root Causes 387: What Is the Post-quantum Readiness of HSMs? 16.05.2024

We take a deep dive with return guest Bruno Coulliard on HSMs and the role they play in post-quantum cryptography (PQC).

Root Causes 386: Meta Commits MITM Attack On Its Users 13.05.2024

Recent court documents reveal that in 2016 Meta (then Facebook) set up a system to get around encryption and spy on traffic between its users and competing social media platforms. We explain what happened.

Root Causes 385: Failed Revocation and Wildcard Certificates 10.05.2024

We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.

Root Causes 384: So What Is a Senior Fellow Anyway? 07.05.2024

Jason has a new title, Senior Fellow. In this episode Jason explains what his new focus will be and how this will be good for Root Causes.

Root Causes 383: Delayed Revocation Events by the Numbers 02.05.2024

An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021, examine the trend line, and discuss root causes.

Root Causes 382: Mobile Phone Malware Steals Faces for Access 29.04.2024

New malware photographs users' faces to defeat authentication mechanisms. We explain the that biometrics are not "secrets" and discuss the continuing progression of attacks to steal biometrics.

Root Causes 381: Apple Chip Sideloading Attack Leaks Encryption Keys 26.04.2024

A newly revealed side channel attack enables theft of private keys from M-series Apple chips. We explain.

Root Causes 380: What If Quantum Supremacy Comes Earlier Than We Thought? 22.04.2024

Repeat guest Bruno Coulliard gives us an update on the US government's migration to post-quantum cryptography (PQC). We talk about the challenges to migration, the possibility of a black swan event in achieving quantum supremacy, and what happens if we all respond by pressing the "panic button" at the same time.

Root Causes 379: AI-generated Fake IDS for KYC 18.04.2024

Inexpensive and easily obtained deepfake photographs of IDs, generated by AI, are available online. These pose a problem for KYC initiatives.

Root Causes 378: Why Are Forced Revocations So Difficult? 15.04.2024

In the latest in our ongoing series of discussions of the Bugzilla Bloodbath, we delve deep into the problem of failure to revoke on time and the multiple causes that lead to this ongoing failure. And what to do about them.

Root Causes 377: Is CPS/Issuance Misalignment a Revocation Event? 11.04.2024

If you issue public certificates that are fully compliant except that they do not reflect what your CPS says, are they misissued? Do they require revocation? This is a question with real stakes as we see multiple current instances of a CA denying revocation for that reason. In this episode we explore this issue.

Root Causes 376: Gartner's New CLM Framework 08.04.2024

Gartner has released a new framework for Certificate Lifecycle Management, called the Seven Core Functions of Certificate Automation. We walk through this framework and answer how it fits in with our own Five Pillars of CLM.

Root Causes 375: What Is Name Space Lifecycle Management? 05.04.2024

In this guest episode we discuss name space hygiene with Geir Rasmussen, founder of NodeZro. CNAMEs, SPF, DMARC, name server entries, and other DNS identifiers, left unattended, can expose companies to identity-based attacks. We lay out the steps in addressing name space cleanup.

Root Causes 374: NIST Cyber Security Framework 2 Released 31.03.2024

NIST Cyber Security Framework version 2.0 is released. It includes guidance on identity management and authentication. In this first episode of a series, we describe this framework's basic structure and its effect on industry.

Root Causes 373: Massive Brand Hijack Subverts More Than 21,000 Domains and Subdomains 29.03.2024

A massive name space attack has hijacked more than 21,000 domains and subdomains, including a who's who list of major global brands. This huge and innovative attack takes advantage of inherited trust in abandoned domains. We explain what is happening.

Root Causes 372: Bugzilla Bloodbath 26.03.2024

It's a bloodbath on Bugzilla. Since March 9, more than 25 new Bugzilla bugs been written up, which is 10x the typical pace. And it's not over. In this episode we explain what is going on and why.

Root Causes 371: MPIC Rules Go to CABF Ballot 22.03.2024

A ballot for Multi-perspective Issuance Corroboration (MPIC), formerly known as MPDV, has entered a discussion period in the CA/Browser Forum (CABF). We explain the details of what it contains.

Root Causes 370: Drama on Bugzilla 19.03.2024

An evolving incident on Bugzilla has garnered a lot of attention and touches several important issues in the WebPKI ecosystem. We report what went on and unpack the issues involved.

Root Causes 369: iMessage to Be PQC Enabled 14.03.2024

Apple has announced that iMessage will employ post-quantum cryptography (PQC). We explain the implications of this announcement.

Root Causes 368: CRYSTALS-Kyber Is Now ML-KEM 13.03.2024

What has been known as CRYSTALS-Kyber now has the new official name of Module Lattice-based Key Encryption Module, or ML-KEM. We give an update on the state of the NIST round 3 winners.

Root Causes 367: Did an IoT Toothbrush Botnet Perform DDoS Attacks? 07.03.2024

A story circulated earlier this year about a botnet composed of millions of IoT toothbrushes, which later was debunked. We tell you the whole tale.

Root Causes 366: What Is eIDAS? 04.03.2024

eIDAS 2.0 has been making headlines recently with its proposed expansion to the European digital identity ecosystem. But what is eIDAS? What does it do, and why does it exist? In this episode we give you the basics.

Root Causes 365: What Is Subdomain Hijacking? 26.02.2024

In this episode we explain subdomain hijacking, including dangling subdomains and how they can constitute vulnerabilities.

Root Causes 364: Video Conference Deepfake Enables $25 Million Theft 22.02.2024

Deepfakes continue to show themselves as part of the standard criminal toolkit. A recent deepfake spear phish enabled a $25 million Business Email Compromise (BEC). We explain what happened.

Listen to the Root Causes: A PKI and Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.