Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Author
Tim Callan and Jason Soroko
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 263: Secure Connection Methods Roundup 20.12.2022 25:32
In this episode we discuss the three methods a user might choose for secure remote communications: VPN, SSH, and TOR. For each we discuss the reasons you might choose them and the pros and cons of each.
Root Causes 262: The Continuing Erosion of Online Identity 14.12.2022 22:57
In one of our 2022 wrap up episodes, we look back at the continued erosion of the idea of reliable online identity throughout the year. We discuss the rise of deep fakes, celebrity phishing, voice biometrics, AI-generated art, trust models, and the failure of Twitter blue check marks.
Root Causes 261: Why I Don't Say Spoof 12.12.2022 10:07
The word spoof is a security industry term used in the context of social engineering attacks. In this episode we explore the word's connotations in different walks of life and why its connotations may not serve us well when applied to security concerns.
Root Causes 260: CA TrustCor Deprecated 08.12.2022 30:11
Public CA TrustCor has had its roots deprecated by Microsoft and Mozilla, following a public dialog about TrustCor's suitability as a public CA. This entire investigation was prompted by a Washington Post article articulating a series of connections between this CA and spyware purveyors. In this episode we explain these connections, the public dialog and investigation that occurred, and the ultima...
Root Causes 259: What Went Wrong with the Twitter Blue Check Marks 30.11.2022 14:16
The Twitter authenticated identity blue check marks made a big splash and then quickly went away. In this episode we explore the intent of these check marks and why they failed. In particular, we detail the challenges involved in authenticating and vouching for the identity of an individual or organization.
Root Causes 258: New S/MIME Baseline Requirements Ratified 21.11.2022 17:04
The CA/Browser Forum has passed new Baseline Requirements for S/MIME certificates, in effect late 2023. In this episode we explain the broad stipulations of the new S/MIME BRs, including the multiple available levels of authentication and use case profiles that will be allowed.
Root Causes 257: FTX Crypto Exchange Collapses 17.11.2022 11:24
"If you don't hold the keys, you don't hold the cheese." Crypto exchange giant FTX recently collapsed, causing ripples through the cryptocurrency world. In this episode we focus on the cryptographic difference between cryptocurrency exchanges and other exchanges and how specific FTX user experience decisions led to the loss of valuable digital assets for investors.
Root Causes 256: What Is Harvest and Decrypt? 16.11.2022 19:32
As we prepare for the reality of quantum computers breaking RSA and ECC, a keenly important concept to understand is "Harvest and Decrypt." The practical impact of Harvest and Decrypt is that for secrets with a reasonable lifespan, the quantum computer threat is much closer than you might think, including as early as today. In this episode we explain why that's the case and how this atta...
Root Causes 255: What Is a Privacy Browser? 11.11.2022 22:47
In this episode we describe privacy browsers, which quite simply are browsers designed to pay special attention to the user's privacy, including some of the strategies they use to protect privacy and the pros and cons of this approach.
Root Causes 254: Toyota Symmetric Key Exposed on GitHub 08.11.2022 10:53
In a recently exposed error, key material for a popular automobile manufacturer's PKI has been discovered on GitHub, resulting in exposure of sensitive information. In this episode we explain the dual errors that led to this breach.
Root Causes 253: OpenSSL Vulnerability Explained 04.11.2022 9:17
Last week the OpenSSL project announced an upcoming critical patch, leading to a great deal of speculation about this flaw and its implications for SSL certificates. We explain what the flaw was, what you should do, and why it is that certificates are unaffected.
Root Causes 252: Sidestepping Microsoft Email Encryption 30.10.2022 14:11
A recently revealed vulnerability in Microsoft Exchange encryption can be used potentially to break the encryption on stored emails. In this episode we explain ECB (Electronic Code Book encryption and how this attack can occur.
Root Causes 251: What's Next for the NIST PQC Primitives? 27.10.2022 20:45
NIST has announced its new post-quantum cryptography primitives. So now what? In this episode we discuss the next steps required by the technology industry for widespread adoption of these algorithms and what the enterprise can do starting today to ready itself for quantum-safe encryption.
Root Causes 250: 250 Episodes of Root Causes! 26.10.2022 26:33
It's Root Causes episode 250! In this episode Tim and Jason indulge themselves in podcasting about podcasting. Hear about setting up a podcast, choosing topics, why we don't rehearse, why we have so few guests, and how we reacted the first time someone asked us for a media kit.
Root Causes 249: What Is MFA Exhaustion? 21.10.2022 10:23
Recent months have seen several high profile attacks that were enabled by defeating the MFA accompanying user name and password login. In this episode we explain the concept of MFA fatigue and why it is an enabler for these attacks.
Root Causes 248: Azure Code Signing Announced 18.10.2022 9:26
Microsoft has announced the upcoming availability of a Microsoft-run code signing solution inside the Azure platform. We explain this approach's advantages and what to expect from it.
Root Causes 247: Uber Breach Unpacked 13.10.2022 12:01
A recent high-profile breach of Uber's systems led to widespread data loss. Join our experts as we unpack the specifics of how this attack came about.
Root Causes 246: Google Chrome Root Program Announced 03.10.2022 12:00
Google Chrome recently announced the formation of its trusted root program. It may be surprising to learn that the world's most popular browser has existed for more than a decade without its own root program. In this episode we explain why that is the case, why Chrome is launching a root program now, and the implications of this announcement.
Root Causes 245: One Time Passcode as a Liability 29.09.2022 10:10
A recent article from Brian Krebs advances the idea that using OTP MFA may actually be a liability to security. In this episode we explain the reasoning behind this characterization.
Root Causes 244: PwC Survey Reports Cyber Security as Biggest Risk to Companies 26.09.2022 15:39
A recent survey from PwC reports that cyber threats are no longer solely the domain on the CISO but instead have become every senior executive's concern. We dive deep into these survey results and talk about they correlate with our own experiences, IT skills gaps, and feeding the podcasting beast.
Root Causes 243: Which Came First, the BRs or the EVGs? 20.09.2022 10:32
Many people don't realize that the CA/Browser Forum's Baseline Requirements actually came LATER THAN the Extended Validation Guidelines. In this episode we explain how this seemly backward turn of events came about and what it says about how online trust has evolved over the past few decades.
Root Causes 242: Let's Encrypt Founder Peter Eckersley Passes 16.09.2022 7:04
Electronic Frontier Foundation member and Let's Encrypt co-founder Peter Eckersley passed away recently at a young age. In this episode we pay respect to Peter's memory and his many contributions, including ACME, Certbot, and Let's Encrypt.
Root Causes 241: Is China Outspending the West in Quantum Computing? 12.09.2022 20:19
A December 2021 report appears to indicate that China as vastly outspending Western countries in quantum computing. In this episode we examine this claim, including the role of private industry as opposed to government funding, the importance of international cooperation, and the vast implications of winning the race for quantum computing.
Root Causes 240: Hyundai Production Private Key Found in How-to Manual 06.09.2022 15:39
A white hat researcher recently defeated a production automobile's PKI by searching for the private key on Google. Join us as we describe the implementation error making this possible and how it might have come about.
Root Causes 239: Post-quantum Cryptography Candidate SIKE Defeated 28.08.2022 17:30
NIST's round four post-quantum crypto candidate SIKE (Supersingular Isogeny Key Encapsulation) has been defeated and is now out of consideration. In this episode we explain isogeny cryptography, why NIST is seeking additional candidates, and why failures of this kind are expected and healthy for PQC.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.