Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Author
Tim Callan and Jason Soroko
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 363: Defending Yourself Against Use of Stolen Privileges 18.02.2024 7:39
CloudFlare recently published details of an attack it suffered as a downstream effect of a November 2023 breach against Okta and what it did to nullify its success. We discuss the steps enterprises can take to protect themselves against malicious use of stolen access credentials.
Root Causes 362: When You're Attacked by a State Actor 12.02.2024 10:06
In this episode we share the details of a recent nation state actor attack on Microsoft and some of the lessons learned.
Root Causes 361: The Premise of on Premise 09.02.2024 37:01
In this episode we examine commonly held belief that on-premise systems give system administrators greater levels of control and that that is better for security or other reasons. We explore the pros and cons of extra control, to what degree it is a benefit, and if it's worth it.
Root Causes 360: Joe Biden Deepfake Plays in New Hampshire Primary 06.02.2024 11:52
A deepfake of Joe Biden's voice made an appearance in robocalls leading up to the New Hampshire primary. We discuss this latest development and its implications.
Root Causes 359: 90-day SSL Won't Affect Organization Validation Periods 02.02.2024 15:37
With maximum 90-day term coming for public SSL certificates and DCV reuse also moving to 90 days, we explain why we do not expect a similar reduction in the reuse period for organization validation.
Root Causes 358: Security Questionnaire Sins 30.01.2024 33:09
In this episode we present a catalog of "security questionnaire sins," which are avoidable problems and errors that frequently occur in the security questionnaires enterprises send to vendors. Categories include difficulty of access, poor technical implementation, poor policies, and poor questions.
Root Causes 357: Signed Digital Photographs 26.01.2024 11:43
Three major camera manufacturers have joined to create a standard for signed digital images from their cameras.
Root Causes 356: Will MPDV Eliminate Email-based DCV? 22.01.2024 16:29
Multi-perspective Domain Validation (MPDV) is a necessary evolution of Domain Control Validation (DCV) to protect against Border Gateway Protocol (BGP) attacks. We explore how MPDV may affect accepted DCV methods, especially the email method.
Root Causes 355: Should a Managed PKI Provider Do Whatever the Customer Wants? 19.01.2024 22:30
In this episode we explore whether a managed PKI provider should give complete control over PKI decisions to the end customer or if it should enforce certain minimum standards and principles regardless of what the customer asks for.
Root Causes 354: CyberSlash Attack Against CRYSTALS-Kyber 16.01.2024 12:15
A newly published attack against common implementations of CRYSTALS-Kyber illustrates how cryptographic implementations can be vulnerable even if the cyphers themselves remain sound.
Root Causes 353: Why Isn't PKI Everywhere? 09.01.2024 24:09
Our hosts firmly believe that PKI is a necessary component of all digital interactions. And yet there are still gaps in PKI implementation. We discuss these gaps and why they persist.
Root Causes 352: FBI Vs. End-to-end Encryption in Meta Apps 04.01.2024 15:20
Meta is finally rolling out end-to-end encryption across its messaging apps. This is the latest chapter in the long story of government versus encryption. We rant a little about this.
Root Causes 351: 2024 Predictions 27.12.2023 18:08
We look forward to 2024 and predict trends for PKI, certificates, and digital identity. We discuss shortening certificate lifespans, Multi-perspective Domain Validation (MPDV), eIDAS 2.0, OCSP, post-quantum cryptography (PQC), Certificate Lifecycle Management (CLM), passwords, root stores, and government versus encryption. Plus, will Jason be sent to the gulag for not being Canadian enough?
Root Causes 350: Public Certificates and the GDPR Right to Be Forgotten 21.12.2023 15:26
GDPR provides a "right to be forgotten," whereby individuals can demand the removal of PII from IT systems. This can run directly contrary to the transparency and permanence built into the DNA of public PKI systems. We explore this conundrum.
Root Causes 349: 2023 Lookback - Overall Trends 18.12.2023 22:36
We look back at PKI in 2023. Trends include artificial intelligence, enterprise crypto agility, the fall of OCSP, PKI everywhere, the weakness of passwords, and government versus the internet. We also look at last year's predictions and compare them to the year's events.
Root Causes 348: What Is a Merkle Tree? 15.12.2023 12:05
One foundational element of modern cryptographic systems is the Merkle tree. Merkle tree is an enabler of blockchain and CT logs, among other things. We explain this data structure, its properties, and its use cases.
Root Causes 347: 2023 Lookback - Shortening Certificate Lifespans 11.12.2023 18:43
90-day SSL certificates is only part of it! 2023 has been a year of certificate lifespans getting shorter. We review these trends.
Root Causes 346: Private Credentials In Public Code 08.12.2023 15:29
In this episode we uncover the epidemic of private credentials in public-facing code repositories, including why it occurs and what do to about it.
Root Causes 345: Apple Versus European Sideloading 05.12.2023 12:40
The European Union is applying pressure to Apple to allow sideloading of applications. We go over why this is occurring, the potential dangers, and Apple's response.
Root Causes 344: Introducing the PQC Onramp 29.11.2023 16:56
NIST's Round 3 competition has yielded winners for standardization. But NIST wants to continue finding additional potential algorithms, especially those using non-Lattice schemes. We explain the PQC "onramp" and what we should expect.
Root Causes 343: The EIDAS 2.0 Controversy 22.11.2023 25:58
ETSI is preparing to release specifications for eIDAS 2.0. One controversial aspect of this new standard is that it limits browsers' ability to determine their own trusted roots. In this episode we explain this limitation and the concerns surrounding it.
Root Causes 342: Don't Change Your Password for Two Years 17.11.2023 11:22
The CA/Browser Forum rules stipulate how often forced password changes for CA employees are to occur. They don't, however, specify a frequency at which these forced changes must occur. Rather, they set the MINIMUM time before forced password changes can happen. Join us to learn why.
Root Causes 341: The Trouble with Security Questionnaires 13.11.2023 19:27
The practice of sending security questionnaires to technology vendors is exploding, and with it dysfunctional behavior is on the rise. In this episode we describe how security questionnaires are changing and the pitfalls associated with this emerging practice.
Root Causes 340: Is This Podcast Canadian Enough? 06.11.2023 14:14
Canada's Online Streaming Act will require internet content providers to provide a minimum percentage of content produced by Canadians or face fines. We explore this latest episode in the theme of governments attempting to control the free flow of information on the internet.
Root Causes 339: The ROI of CLM 31.10.2023 11:21
In this episode we describe at a high level how to calculate the Total Cost of Ownership (TCO) of CLM as opposed to manual installation and management of certificates.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.