Tim Callan and Jason Soroko

Root Causes: A PKI and Security Podcast

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...

Author

Tim Callan and Jason Soroko

Category

Technology

Podcast website

soundcloud.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Root Causes 338: CLM and Your Career as an IT Professional 23.10.2023

In this follow up to our episode on CLM and the IT skills gap, we now discuss how CLM matters to individual IT professionals and can help progress careers and improve work life.

Root Causes 337: CLM and the IT Skills Gap 10.10.2023

For decades industry has had more need for skilled IT employees than the workforce could provide. In this episode we discuss how Certificate Lifecycle Management and certificate automation can help mitigate the challenges posed by the IT skills gap.

Root Causes 336: Digitally Signing Images on Cameras 03.10.2023

A recent press release discusses efforts of camera manufacturers and the digital imagery supply chain to create an ecosystem for digitally signed images. We describe what such an ecosystem would do, where it could do in the future, and the advantages and limitations of these schemes.

Root Causes 335: When MFA Is Not MFA 29.09.2023

In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach. We explain.

Root Causes 334: What Is Attestation on the Web? 26.09.2023

Most people hate dealing with CAPTCHA, but it offers great benefits for web site operators. In this episode we discuss alternatives to CAPTCHA, how they work, and their pros and cons. Plus, the Get-Off-My-Lawn! browser returns.

Root Causes 333: Intel Side Channel Attack Steals Private Keys 20.09.2023

A newly revealed side channel attack can capture AES encryption keys from Intel chips. We explain this significant and powerful attack.

Root Causes 332: Acoustic AI-based Key Logging Attack 14.09.2023

Researchers have built an AI model that can interpret keystrokes based on the sound of keyboard use over a phone or video call. Among other things, this technique can be used to steal passwords when the sound of logging in can be overheard. Join us as we learn about this new breed of credential harvesting.

Root Causes 331: Microsoft Restores Trust to VeriSign Code Signing Root 13.09.2023

Recent erroneous behavior for certain applications on Windows has drawn attention to the Microsoft trusted root store. It turns out that Microsoft removed - and then re-added - a legacy VeriSign root in its trusted roots list. We give you the details of what went on and why.

Root Causes 330: End-to-end PQC in Use Today 05.09.2023

Our hosts are joined by IronCap CEO Andrew Cheung as he discusses commercially available PQC solutions today, including VPN, email, and crypto currency.

Root Causes 329: What Is Messaging Layer Security? 29.08.2023

The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.

Root Causes 328: What Is the Debian Weak Key Flaw? 23.08.2023

In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.

Root Causes 327: What Is Multi-perspective Domain Validation? 18.08.2023

In this episode we explain Border Gateway Protocol (BGP) attacks and how multi-perspective domain validation (MPDV, also known as multi-vantage point domain validation) can defeat them.

Root Causes 326: The Difference Between .ml and .mil 15.08.2023

A recent Financial Times article reveals that mistyped email addresses aimed at the US military frequently are sent to email addresses in Mali instead, to the tune of hundreds of thousands per year. Some of this includes sensitive military content.

Root Causes 325: Certificate Error Causes Sharepoint Outage 11.08.2023

A recent outage in Microsoft Sharepoint was caused by an error in certificate installation. We explain what happened and the lessons to be learned.

Root Causes 324: Apple Vs New UK Surveillance Bill 07.08.2023

The battle between government and encryption continues. The UK is attempting to build secret back doors into end-to-end encrypted services. In response, Apple has threatened to remove Apple services from the UK, including FaceTime and iMessage.

Root Causes 323: Update on Microsoft Key Compromise 02.08.2023

In this follow up to our episode 320, we describe Microsoft's actions to mitigate this attack and explain new understanding that shows its impact to be broader than originally thought. Anyone using the Microsoft stack needs to understand this new threat.

Root Causes 322: RIP Kevin Mitnick 31.07.2023

In July famous security researcher Kevin Mitnick passed away. We briefly pay tribute to Kevin and talk about his contributions to white hat hacking as a practice.

Root Causes 321: CABF Moratorium on New Certificate Consumer Members 26.07.2023

The CA/Browser Forum recently passed a temporary moratorium on new members of the Certificate Consumer class. We explain how Certificate Consumers have been admitted in the past and the pros and cons of creating stricter rules for Certificate Consumers.

Root Causes 320: Microsoft-signed Root Kit Attack 24.07.2023

A new root kit attack in the wild is code signed by a Microsoft certificate. We explain kernel-level attacks, how powerful they are, and how this attack occurred.

Root Causes 319: EU Digital Wallets 21.07.2023

A new agreement mandates that European countries will make digital wallets available to their citizens in 2024. We explain what's coming and some of its implications.

Root Causes 318: What Is ACME Renewal Information (ARI)? 18.07.2023

ACME is a functional and widely supported protocol for certificate provisioning and installation. A new extension to the protocol will help automate renewals. In this episode we explain ACME Renewal Information (ARI).

Root Causes 317: New Automotive CAN Bus Attacks Demand PKI 13.07.2023

In this episode we describe how physically accessing the CAN bus wires in a modern automobile can allow a thief to take over key fob functionality to unlock the doors, start the engine, and ultimately steal the vehicle. We explain how PKI can defeat this attack and what is necessary to get there.

Root Causes 316: SquareSpace Acquires Google Domains 11.07.2023

SquareSpace recently acquired Google's domain registry business. We discuss what this move says about large technology trends.

Root Causes 315: Will the SEC Sue SolarWinds Executives? 07.07.2023

The SEC has sent "Wells notices" to two senior executives from SolarWinds, with regard to the 2019 supply chain attack. In this episode we explain these notices and their implication.

Root Causes 314: AI-based Deepfakes in Real Crimes 05.07.2023

We have spoken in previous episodes about the potential for deepfakes in real-world crimes. In this episode we discuss a variety of real-world attacks in which deepfakes have played a role. These include fake kidnapping, "sextortion," and a range of spear phishing attacks and social media scams.

Listen to the Root Causes: A PKI and Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.