Tim Callan

Root Causes: A PKI and Security Podcast

Society EN ↓ 560 episodes

Podcast by Tim Callan and Jason Soroko

Author

Tim Callan

Category

Society

Podcast website

www.spreaker.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Root Causes 417: Introducing pkimetal the PKI Meta-linter 03.09.2024

We introduce pkimetal, an open source project from Rob Stradling that allows CA to write to many popular linters with a single integration. We explain the importance and pitfalls of linters and how pkimetal improves linter implementation.

Root Causes 416: SSL Subscriber Uses a Restraining Order to Prevent Revocation 29.08.2024

An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain what happened, why it's deeply problematic, how the industry might consider responding.

Root Causes 415: What Can I Do with These New FIPS PQC Standards? 27.08.2024

NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.

Root Causes 414: What Are the Revocation Periods for Public Certificates? 23.08.2024

In this episode we detail the mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.

Root Causes 413: NIST Releases Standards for First Three PQC Algorithms 16.08.2024

On August 13, 2024, NIST released its first three standards for PQC algorithms, ML-KEM, ML-DSA, and SLH-DSA. We tell you where to find them and talk about what happens next.

Root Causes 412: Google Throws in the Towel on Eliminating Cookies 13.08.2024

Cookies are incredibly useful but also pose grave privacy concerns. We have in the past covered Chrome's initiatives to replace cookies. Now Chrome has announced that for the foreseeable future cookies will remain. We explain.

Root Causes 411: PQC Security Levels 09.08.2024

A popular belief is that Grover's algorithm will require that we double our AES key sizes. Repeat guest Bas Westerbaan of Cloudflare explains why this myth is incorrect and talks through the concept of "security levels" in post-quantum cryptography.

Root Causes 410: CrowdStrike, Automatic Updates, and Walled Gardens 06.08.2024

We examine one specific aspect of the recent CrowdStrike flaw. Microsoft blames the problem on the fact that it must, by European law, allow kernel updates to Windows. We unpack the challenges this poses.

Root Causes 409: Mozilla Distrusts Entrust 02.08.2024

This week Mozilla chose to follow Chrome in deprecating the Entrust trusted roots. We give you the details and explain why this action matters.

Root Causes 408: Takeaways from Recent Conversations with PQC Experts 29.07.2024

In the past three months we featured far-ranging conversations about post-quantum cryptography (PQC) with experts Bas Westerbaan of Cloudflare, Dustin Moody of NIST, and Bruno Coulliard of Crypto4A. In this episode we recap important takeaways from these conversations.

Root Causes 407: Whatever Happened to Passkeys? 25.07.2024

WebAuthn arrived last year with great fanfare. But here we are in the latter half of 2024, and they are rarely used. In this episode we discuss why.

Root Causes 406: Certificate Discovery Is for Internal Certificates, Too 22.07.2024

When we discuss certificate discovery in CLM platforms, there is a common assumption that we're talking about public certificates exclusively. In this episode we explain the value of certificate discovery for internal PKI certificates also.

Root Causes 405: What Is an Adversarial Self-replicating Prompt? 19.07.2024

In this episode we explain what an adversarial, self-replicating prompt, otherwise known as a prompt worm.

Root Causes 404: SCOTUS Ruling Will Change IT Security Regulation 16.07.2024

The US Supreme Court has struck down the Chevron Deferment, which greatly expanded federal agencies' power to interpret and enforce statutes. This monumental ruling stands to shift power considerably from agencies to courts and will put more pressure on legislatures to determine precise laws around tech. We explore the consequences of this ruling.

Root Causes 403: NIST PQC Contest Round 4 and Onramp with Dustin Moody 12.07.2024

We are joined again by Dustin Moody, who leads the NIST search for PQC algorithms. In this episode Dustin describes going-forward efforts, including Round 4 of the NIST contest and the Onramp. We discuss some of the candidate algorithms and the consequences of having multiple algorithms available for use.

Root Causes 402: New Social Engineering Powershell Attack 09.07.2024

A new social engineering exploit instructs victims to enter command line prompts to hack themselves on behalf of the hacker. We explain and discuss potential responses.

Root Causes 401: New SSH Remote Code Execution Vulnerability Revealed 05.07.2024

A newly revealed OpenSSH vulnerability can open enterprises to remote code execution. We explain what is happening, why you should care, and what to do about it.

Root Causes 400: French Court Orders DNS Poisoning 02.07.2024

To combat piracy of sporting event transmissions, a French court has ordered major tech companies including Google and Cloudflare to poison DNS settings. In this episode we provide some detail and generally marvel at this strange decision.

Root Causes 399: Entrust Distrusted 28.06.2024

On June 27, 2024 Google Chrome announced it was distrusting Entrust as a public CA starting November 1, 2024. We explain what to expect, go over Google's stated reasons, and share some of what lead up to this.

Root Causes 398: History of the NIST PQC Contest with Dustin Moody 27.06.2024

In this episode we are joined by Dr. Dustin Moody, leader of the NIST post-quantum cryptography contest. Dustin gives us an inside view of the background behind NIST's decision to run the contest and how we got to where we are today.

Root Causes 397: All Post Quantum Systems Are Terrible 24.06.2024

In this new conversation with Bas Westerbaan of Cloudflare, we reveal that all existing PQC systems present significant problems for incorporation into our existing ecosystems. We explain the problems with existing systems and some options for what to do about it.

Root Causes 396: The Trouble with Microsoft Recall 21.06.2024

Microsoft has proposed a feature called Recall that uses screen images to fuel AI-assisted capabilities. This has raised fears about the security decisions around this capability. We talk about why and how the proposed technology has resultingly changed.

Root Causes 395: Is Y2Q Like Y2K? 18.06.2024

In this episode we compare the advent of cryptography relevancy of quantum computers (somestimes called Y2Q) to Y2K. We uncover similarities and differences and discuss how they govern decision making between now and Y2Q.

Root Causes 394: Snowflake, Ticketmaster, and MFA 14.06.2024

In this episode we drill down on one aspect of the loss of more than 500 million Ticketmaster users' data, which is the use of MFA for access to the Snowflake platform.

Root Causes 393: PQC-enabled Chrome Breaks Other Software 11.06.2024

Chrome's recent 124 release supports PQC algorithms from NIST. This has led to the discovery of software and systems that break under these circumstances. We explain what happened, why, and what to do about it.

Listen to the Root Causes: A PKI and Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.