Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 392: Chromium Issues a Quality Ultimatum 07.06.2024 21:18
In the most recent CA/Browser Forum face-to-face meeting, the Google Chrome root program gave a presentation clearly defining its expectations for quality of incident reporting from CAs with an eye to where many CAs have been failing. We relate Chromium's statements and their significance.
Root Causes 391: 20 Percent of Web Visits Are PQC Enabled Today 04.06.2024 22:30
Cloudflare research engineer Bas Westerbaan joins us to share his observations about post-quantum cryptography and what it does in the real world. We talk about the pragmatic needs of moving the internet for PQC and speculate about timelines for availability of PQC certificates.
Root Causes 390: Chromium Boosts Its Distrust Agility with a New Root Trust Deprecation 31.05.2024 21:54
A root trust deprecation highlights new Chrome functionality that enables more agile and less disruptive distrust events. We explain the significant of this event.
Root Causes 389: 2024 RSA Conference Wrap Up 28.05.2024 27:24
Jason and I do our annual RSA wrap-up. Trending segments include AI, Trust Centers, MFA, PQC, and more.
Root Causes 388: What Is the WebPKI? 22.05.2024 26:15
These days we frequently discuss "the WebPKI." But what does that really mean? In this episode we define the term and explain how this definition evolved over time. We give an inventory of a main components of the WebPKI and discuss what's required to become a CA.
Root Causes 387: What Is the Post-quantum Readiness of HSMs? 16.05.2024 31:34
We take a deep dive with return guest Bruno Coulliard on HSMs and the role they play in post-quantum cryptography (PQC).
Root Causes 386: Meta Commits MITM Attack On Its Users 13.05.2024 14:24
Recent court documents reveal that in 2016 Meta (then Facebook) set up a system to get around encryption and spy on traffic between its users and competing social media platforms. We explain what happened.
Root Causes 385: Failed Revocation and Wildcard Certificates 10.05.2024 12:20
We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.
Root Causes 384: So What Is a Senior Fellow Anyway? 07.05.2024 7:23
Jason has a new title, Senior Fellow. In this episode Jason explains what his new focus will be and how this will be good for Root Causes.
Root Causes 383: Delayed Revocation Events by the Numbers 02.05.2024 25:29
An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021, examine the trend line, and discuss root causes.
Root Causes 382: Mobile Phone Malware Steals Faces for Access 29.04.2024 11:43
New malware photographs users' faces to defeat authentication mechanisms. We explain the that biometrics are not "secrets" and discuss the continuing progression of attacks to steal biometrics.
Root Causes 381: Apple Chip Sideloading Attack Leaks Encryption Keys 26.04.2024 7:31
A newly revealed side channel attack enables theft of private keys from M-series Apple chips. We explain.
Root Causes 380: What If Quantum Supremacy Comes Earlier Than We Thought? 22.04.2024 29:32
Repeat guest Bruno Coulliard gives us an update on the US government's migration to post-quantum cryptography (PQC). We talk about the challenges to migration, the possibility of a black swan event in achieving quantum supremacy, and what happens if we all respond by pressing the "panic button" at the same time.
Root Causes 379: AI-generated Fake IDS for KYC 18.04.2024 13:29
Inexpensive and easily obtained deepfake photographs of IDs, generated by AI, are available online. These pose a problem for KYC initiatives.
Root Causes 378: Why Are Forced Revocations So Difficult? 15.04.2024 21:08
In the latest in our ongoing series of discussions of the Bugzilla Bloodbath, we delve deep into the problem of failure to revoke on time and the multiple causes that lead to this ongoing failure. And what to do about them.
Root Causes 377: Is CPS/Issuance Misalignment a Revocation Event? 11.04.2024 17:07
If you issue public certificates that are fully compliant except that they do not reflect what your CPS says, are they misissued? Do they require revocation? This is a question with real stakes as we see multiple current instances of a CA denying revocation for that reason. In this episode we explore this issue.
Root Causes 376: Gartner's New CLM Framework 08.04.2024 19:30
Gartner has released a new framework for Certificate Lifecycle Management, called the Seven Core Functions of Certificate Automation. We walk through this framework and answer how it fits in with our own Five Pillars of CLM.
Root Causes 375: What Is Name Space Lifecycle Management? 05.04.2024 28:00
In this guest episode we discuss name space hygiene with Geir Rasmussen, founder of NodeZro. CNAMEs, SPF, DMARC, name server entries, and other DNS identifiers, left unattended, can expose companies to identity-based attacks. We lay out the steps in addressing name space cleanup.
Root Causes 374: NIST Cyber Security Framework 2 Released 31.03.2024 14:32
NIST Cyber Security Framework version 2.0 is released. It includes guidance on identity management and authentication. In this first episode of a series, we describe this framework's basic structure and its effect on industry.
Root Causes 373: Massive Brand Hijack Subverts More Than 21,000 Domains and Subdomains 29.03.2024 14:41
A massive name space attack has hijacked more than 21,000 domains and subdomains, including a who's who list of major global brands. This huge and innovative attack takes advantage of inherited trust in abandoned domains. We explain what is happening.
Root Causes 372: Bugzilla Bloodbath 26.03.2024 22:06
It's a bloodbath on Bugzilla. Since March 9, more than 25 new Bugzilla bugs been written up, which is 10x the typical pace. And it's not over. In this episode we explain what is going on and why.
Root Causes 371: MPIC Rules Go to CABF Ballot 22.03.2024 20:18
A ballot for Multi-perspective Issuance Corroboration (MPIC), formerly known as MPDV, has entered a discussion period in the CA/Browser Forum (CABF). We explain the details of what it contains.
Root Causes 370: Drama on Bugzilla 19.03.2024 27:39
An evolving incident on Bugzilla has garnered a lot of attention and touches several important issues in the WebPKI ecosystem. We report what went on and unpack the issues involved.
Root Causes 369: IMessage to Be PQC Enabled 15.03.2024 14:47
Apple has announced that iMessage will employ post-quantum cryptography (PQC). We explain the implications of this announcement.
Root Causes 368: CRYSTALS-Kyber Is Now ML-KEM 13.03.2024 9:08
What has been known as CRYSTALS-Kyber now has the new official name of Module Lattice-based Key Encryption Module, or ML-KEM. We give an update on the state of the NIST round 3 winners.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.