Tim Callan
Root Causes: A PKI and Security Podcast
Podcast by Tim Callan and Jason Soroko
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 292: Validation Data Reuse for 90-day Certificates 06.04.2023 15:21
As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also. We explain today's data reuse rules and what the evidence indicates will be required for both domain control validation (DCV) and organization information validation.
Root Causes 291: CLM and SIEM 03.04.2023 9:40
We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee access. We talk about expected behaviors in the CLM and monitoring them.
Root Causes 290: What Are QGIS and QIIS? 29.03.2023 13:06
In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation. We explain how they fit into validation and the criteria for a reliable information source.
Root Causes 289: What Is a Cryptographic Center of Excellence? 27.03.2023 8:30
In this episode we dig into an emerging idea, which is the cryptographic center of excellence. We discuss how such a center of excellence would work and the benefits it can bring to an enterprise.
Root Causes 288: ISARA Releases Patents on Hybrid Certificates 23.03.2023 12:20
In this episode we are joined by Atsushi Yamada, CEO of ISARA. He explains how ISARA has put its patents on hybrid certificates into the public domain and why. We explain the role of hybrid certificates in PQC and ongoing crypto agility.
Root Causes 287: GoDaddy Private Key Breach 20.03.2023 13:48
In this episode we describe an incident in which a GoDaddy breach exposed customer private keys. We explain the expectations surrounding private key exposure and get into the interesting question of when an incident is or is not part of a large company's CA business.
Root Causes 286: PKI and PQC in New White House Cybersecurity Initiative 16.03.2023 10:05
A new White House cybersecurity initiative specifically calls out digital identity and post quantum cryptography (PQC) among its focal areas. We discuss what it says and the potential implications.
Root Causes 285: Can ChatGPT Write Malware? 14.03.2023 16:10
In our ongoing exploration of the security implications of AI, in this episode we examine the suitability of ChatGPT as a malware-writing tool and possible future directions for AI in software creation.
Root Causes 284: 90-day SSL Certificates Are on the Way 10.03.2023 23:55
The Google Chrome root program recently announced its intention to reduce the maximum term for public SSL certificates to 90 days. In this episode we explain this announcement and its implications and speculate on timing for this reduction.
Root Causes 283: Google Optional OCSP Proposal Clarified 06.03.2023 11:19
In our episode 281 we reported on Google's proposal for optional OCSP. In this episode we correct some of our earlier reporting in that episode, including the use of CRL and the removal of any revocation requirement for SSL certificates of not more than ten days in term.
Root Causes 282: HSMs and Post Quantum Cryptography 02.03.2023 28:37
Repeat guest Bruno Couillard of Crypto4A joins us to explain where Hardware Secure Modules (HSMs) fit into the world of PQC. We discuss the issues surrounding how HSMs will work with post quantum algorithms and hybrid certificates and the process (and timelines) for defining how HSMs will incorporate PQC.
Root Causes 281: Google Proposes Optional OCSP 26.02.2023 26:23
In response to concerns about OCSP and privacy, Google has proposed removing the requirement for OCSP revocation checking for public SSL certificates meeting certain specific conditions. In this episode we go into the details of this proposal.
Root Causes 280: Did an AI Break CRYSTALS-Kyber? 24.02.2023 20:09
Recent news reports might suggest that an AI-enhanced side attack has defeated the CRYSTALS-Kyber PQC algorithm. In this episode we clarify that Kyber has not been defeated to date and exactly what did occur. We define side channel attack, discuss the broader implications of this attack, and speculate on what would happen if Kyber actually were broken.
Root Causes 279: ChatGPT Watermarking 19.02.2023 15:55
ChatGPT presents the potential problem of ChatGPT content being used and attributed to another source, such as a professional writer or a student. In this episode we discuss the idea of "watermarking" ChatGPT content, including stenography, randomness, entropy, and how to destroy the watermarks.
Root Causes 278: Microsoft on Certificates and FIDO 17.02.2023 11:18
Recent public discussion of FIDO and digital certificates reveal details of Microsoft's approach to consumer digital authentication. We discuss secure elements, Windows Hello, and the differences between B2C, B2B, and B2E.
Root Causes 277: Privacy Sandbox 13.02.2023 15:14
In the latest continuation of the effort to create better protections for consumer privacy while still enabling targeted advertising, Google has announced the Privacy Sandbox. In this episode we describe this latest foray, including concepts like k-anonymity and differential privacy.
Root Causes 276: ChatGPT and Identity Reputation 09.02.2023 8:06
ChatGPT and similar AI tools are dominating the public's mind these days. In this episode we discuss the potential for people to attempt to use ChatGPT as a source of reputational analysis, KYC, and other information about individuals, companies, and other entities. These activities are potentially subject to both error and deliberate misdirection. In this episode we explain why.
Root Causes 275: No Fly List Stolen 06.02.2023 8:28
In a recently revealed security breach, an attacker gained a copy of the full 2019 TSA No Fly list, including subject PII. This breach was enabled by failures in digital identity and encryption. Join us in unpacking what happened and the lessons to be learned.
Root Causes 274: New Quantum Readiness Law 03.02.2023 13:54
The U.S. government has a new law requiring that government agencies create plans for migrating to post-quantum cryptography in response to impending threats from quantum computers. In this episode we are joined by guest Bruno Couillard of Crypto4A to discuss the law and its implications.
Root Causes 273: A Deep Dive on CA Agnostic 30.01.2023 21:18
The industry is seeing more and more attention spent on the idea of CA agnosticism. As with any buzzy technology term, it can be used to mean a variety of things. Join us as we catalog the various ways a Certificate Lifecycle Management (CLM) system can be "CA agnostic."
Root Causes 272: OCSP's Privacy Problem 27.01.2023 12:16
Concerns recently have been raised about OCSP real-time certificate checking and its potential to violate privacy. In this episode we unpack these concerns and discuss the alternatives to OCSP.
Root Causes 271: A Whole Fleet of Identity-based Automotive Hacks 23.01.2023 22:21
A white hat security researcher recently revealed a large number of identity-based vulnerabilities across many automotive manufacturers. In this episode we explain how a group of white hats exploited these manufacturers' dependence on non-secret "secrets" such as VIN or email address to force a raft of unacceptable behaviors across a large number of automotive brands.
Root Causes 270: What Is the Difference Between KEM and PKE? 20.01.2023 11:55
One of the little known changes that has come to the world of TLS is that the secret handshake and key exchange updated from Public Key Exchange (PKE) to Key Encapsulation Methods (KEM). In this episode we explain the difference between the two methods and why this change is taking place.
Root Causes 269: Did a Patent Dispute Nearly Derail Post Quantum Cryptography? 16.01.2023 9:52
On July 5, 2022 NIST announced its Round 3 PQC winners. What most people don't realize is that same day, the interested parties cleared a patent dispute that had the potential to prevent several of the winning primitives from moving forward. Join us as we explain who held that patent, what the potential impediment was, and how everything was resolved.
Root Causes 268: WAFs Subverted by JSON Bypass 12.01.2023 8:53
In this episode we discuss rising attacks that overcome the protections of Web Application Firewalls (WAF). We explain these attacks, why this bypass might effective against you even if think it doesn't, and what you should do to ensure you're safe.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.