Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject ...
…
continue reading

1
Root Causes 472: AI Offensive Modeling
11:14
11:14
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:14AI tools are now available to perform red-teaming activity for DevSecOps. Such tools are soon to be table stakes in the constantly escalating IT security arms race. Join us to learn more.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 471: ACME for PQC
21:28
21:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
21:28In this episode, guest Alexandre Giron explains what is needed to support post quantum cryptography (PQC) with ACME.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 470: The MFA False Equivalency Fallacy
11:53
11:53
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:53Not all forms of MFA are equally secure. In this episode we describe the differences between the more secure and less secure forms of MFA.Tim Callan and Jason Soroko által
…
continue reading
In this episode we explain the all-or-nothing fallacy in cybersecurity and how it's affecting debate in the WebPKI right now.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 468: UK Demands New Backdoor from Apple
10:25
10:25
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
10:25A new demand from the UK seeks complete access to all Apple cloud data housed in the UK, regardless of the data owners' citizenship and residency. We unpack this latest development in Government versus Encryption.Tim Callan and Jason Soroko által
…
continue reading
The past year has seen a great deal of focus on the use of public TLS certificates where private root certificates are actually the appropriate solution. In this episode we discuss the differences between these two use cases and what IT organizations can do about it.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 466: Apple Moves 47-day Ballot to CABF Vote
31:21
31:21
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
31:21Apple is proceeding with a ballot that eventually will shorten SSL certificate maximum term to 47 days. Accompanying the ballot, Apple released a statement explaining its intent with the ballot. In this episode we unpack its statements.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 465: Twelve Bugzilla Sins for CAs to Avoid
42:49
42:49
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
42:49In the wake of the Bugzilla Bloodbath, we list and describe twelve sins CAs commit on Bugzilla and its like, why they're detrimental, and how CAs should avoid them.Tim Callan and Jason Soroko által
…
continue reading
Harvest and decrypt is a well-known attack vector against traditional cryptography prior to PQC. In this episode, we discuss what enterprises should be doing today to defend themselves against harvest and decrypt.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 463: Cellular Networks Are Insecure
12:21
12:21
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
12:21In this episode we explain that all cellular networks, contrary to popular belief, are fundamentally insecure.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 462: Crypto War 3.0
22:17
22:17
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
22:17In this episode we walk through the evolution of the war on cryptography, from the beginning up through today, terminating in what we call Crypto War 3.0.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 461: Sectigo Acquires Entrust Public CA Business
10:28
10:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
10:28Sectigo today announced the acquisition of the Entrust public CA business. Entrust will go forward as a Sectigo reseller. Join us to learn the details.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 460: The State of PQC with Michele Mosca
31:48
31:48
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
31:48In this episode we are joined by Dr. Michela Mosca. We discuss his pioneering work identifying the need for post-quantum cryptography, where PQC stands today, and what the future may hold.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 459: 2024 Lookback - Shortening Certificate Lifespans & DCV
12:20
12:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
12:202024 set in motion major changes for certificate lifespans and DCV. In this episode we discuss the Apple 47-day proposal, stepping down certificate term, public versus private CA use cases, DCV reuse periods, MPIC, WHOIS, and other topics.Tim Callan and Jason Soroko által
…
continue reading
Apple has added itself to the Entrust distrust and has extended this distrust to S/MIME and VMC. We explain.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 457: 2024 Lookback - Guests
11:26
11:26
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:26We had a remarkable year on the Root Causes podcast in terms of our guests. We look back at the extremely expert guests we were lucky to talk about in 2024.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 456: 2024 Lookback - Bugzilla Bloodbath
11:24
11:24
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:24In this 2024 lookback episode, we give an overview of the firestorm of Bugzilla incidents that we refer to as the Bugzilla Bloodbath. The Bugzilla Bloodbath affected actions around the Entrust distrust, delayed revocation reform, 47-day SSL certificate maximum term, linting, and more.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 455: PQC Standardization in IETF
35:54
35:54
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
35:54We talk with guest Sofia Celi of Brave Browser, who leads the IETF PQC standardization effort, about the process of setting standards for PQC-compatible digital certificates. We learn about expected timelines, hybrid strategies, the NIST PQC onramp's role, and more.Tim Callan and Jason Soroko által
…
continue reading
2024 was an eventful year for post quantum cryptography (PQC). This includes FIPS standards, the PQC onramp, and the dawn of widespread interest among IT professionals.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 453: It Turns Out Monkeys Couldn't Type Shakespeare After All
14:12
14:12
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
14:12The old adage states that a monkey in front of a keyboard, given enough time, could randomly type the works of Shakespeare. Apparently, someone ran the numbers and said not so much. We break it down and explain why we're discussing this on a PKI podcast.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 452: 2024 Predictions Scorecard
10:38
10:38
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
10:38We go over our predictions for 2024 and score our ability as prognosticators.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 451: A Year in CABF Ballots
34:48
34:48
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
34:48It was a crazy year for CA/Browser Forum activity, with nearly three times the normal number of ballots. Guest Martijn Katerbarg goes over the 32 CABF ballots from 2024.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 450: 2025 Predictions
48:29
48:29
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
48:29We make our 2025 predictions. Topics include maximum certificate term, AI, post-quantum cryptography (PQC), deep fakes, and more.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 449: What Is a Quantum-safe HSM?
23:48
23:48
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
23:48Repeat guest Bruno Coulliard of Crypto4A joins us to define a quantum-safe (or PQC enabled) hardware security module.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 448: The Privilege of Being a Public CA
25:39
25:39
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:39We go over Tim's September 2024 keynote speech at ENISA CA Day, "The Privilege of Being a Public CA."Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 447: NIST Deprecates RSA-2048 and ECC 256
13:46
13:46
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
13:46As part of its post-quantum cryptography (PQC) initiative NIST has released a draft deprecating RSA-2048 and ECC 256 by 2030 and disallowing them by 2035. We get into the details.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 446: Sectigo Assumes Five CABF Offices
13:20
13:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
13:20Tim has stepped into the position of vice-chair of the CA/Browse Forum, and Sectigo now holds five chair or vice-chair positions in that body. We explain how leadership is chosen, the offices Sectigo holds today, and some of our vision for CABF in the next two years.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 445: Seven Reasons to Shorten Certificate Lifespans
27:56
27:56
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
27:56We take a deep dive into the seven reasons shorter certificate lifespans are better.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 444: What Happens to the WebPKI if Google Sells Chrome?
19:25
19:25
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
19:25We discuss how a potential break of Chrome from Google would affect the WebPKI. We look at product changes, resourcing, post-quantum cryptography (PQC), innovation, moonshot initiatives, and other public CAs.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 443: Is MSCA Going Away?
13:22
13:22
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
13:22In this episode we discuss the challenges for enterprises using Microsoft Active Directory Certificate Services (ADCS).Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 442: Apple Proposal to Reduce SSL Lifespan Updated
22:13
22:13
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
22:13Apple has published an updated draft to its proposal for shortening the lifespan of SSL certificates, including a final maximum term of 47 rather than 45 days. We explain.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 441: New White House Initiative Targets BGP
14:52
14:52
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
14:52A new White House initiative requires that federal agencies need to create plans to thwart BGP attacks. We discuss, including Resource PKI (RPKI) and Multi-Perspective Issuance Corroboration (MPIC).Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 440: Public Key Directories
12:57
12:57
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
12:57We talk about public key directories and complicating factors such as Tailscale, VPN, TOR, Cloudflare, and Zero Trust.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 439: PQC Onramp Narrowed Down to 15 Candidates
17:13
17:13
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
17:13NIST has narrowed its PQC onramp contest to 15 candidates. We go over who remains and the makeup of the remaining candidates.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 438: PQC Is an Existential Requirement
28:19
28:19
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
28:19Repeat guest Bruno Couillard argues that cryptography is part of the foundational fabric of our lives and that the transition to PQC is an existential requirement.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 437: Don't Blame the Linter
11:21
11:21
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:21Linters are essential tools for maintaining quality of certificate issuance. Public open-source linters are available to help CAs assure compliance. As a result, CAs have begun attributing gaps in coverage by public linters as the root cause for misissuance events. We explain why this is faulty reasoning.…
…
continue reading

1
Root Causes 436: Formal Proofs
10:22
10:22
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
10:22Formal proofs are critical to cryptography. We discuss how better processes and AI can accelerate formal proofs of cryptographic concepts.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 435: The PQC "Q Day" Is Not That Simple
19:45
19:45
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
19:45The PQC community likes to debate when crypto relevant quantum computers will be available, which is sometimes called "Q day." In this episode we explain how radically oversimplified this concept is and dive into the nuances of what a "cryptographically relevant quantum computer" really will be.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 434: Did Researchers Break AES Using Quantum Annealing?
11:43
11:43
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:43News reports claim Chinese researchers broke AES with a quantum annealing computer. We clarify the details and talk about the implications of this reported discovery.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 433: Will AI Eat All the Electricity?
10:28
10:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
10:28We explore the question of whether or not we have enough electricity to fuel AI's expected growth.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 432: Apple Floats New Short-lived Certificate Proposal
26:20
26:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:20Apple recently floated a draft CABF ballot for commentary that steps down maximum term for SSL certificates starting next year and eventually landing at 45 days in 2027. We share the details.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 431: New Mozilla Proposal to Combat Delayed Revocation
28:10
28:10
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
28:10Deliberate delay of mandatory revocations has plagued the WebPKI in 2024. A new proposed policy from Mozilla stands to eliminate most of this behavior. In this episode we go over the proposal and explain its potential consequences.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 430: How Does a TLS Handshake Work?
14:31
14:31
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
14:31In this episode we give a high-level explanation of what happens in a TLS 1.3 handshake and then discuss what will happen when PQC is included.Tim Callan and Jason Soroko által
…
continue reading
A ServiceNow private CA root expired, creating outages across hundreds of enterprises. We explain what appears to have gone on.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 428: .MOBI Attack Puts WHOIS-based DCV into Question
17:10
17:10
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
17:10White hat researchers managed to take over WHOIS for the .mobi TLD. Among other things, this discovery foretells the death of WHOIS as a valid email source for Domain Control Validation (DCV).Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 427: Mapping CLM to NIST CSF 2.0
15:46
15:46
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
15:46In this episode we map the contributions of Certificate Lifecycle Management into the new NIST Cybersecurity Framework 2.0.Tim Callan and Jason Soroko által
…
continue reading
A certificate expiration is now known to have created July's outage of Bank of England. Join us as we shake our heads in amazement yet again.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 425: PQC Requirements for Voting Systems
10:53
10:53
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
10:53In honor of the upcoming US elections, we describe the six main requirements for a post-quantum voting system.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 424: Using LoRA IoT Protocol for Clandestine Communications
11:43
11:43
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
11:43In this episode we describe the LoRA protocol, which allows IoT devices to communicate securely without using a cellular network, and how it can be used for secret communications.Tim Callan and Jason Soroko által
…
continue reading

1
Root Causes 423: Is a Certificate Software or a Service?
18:28
18:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
18:28In this episode we discuss the dual nature of a public certificate as both a file and part of a holistic service that lasts until its expiration. We discuss revocation checking, CT logging, GAAP accounting, linters, certificate tracking tools, Certificate Lifecycle Management, standards bodies, post-quantum cryptography, and subscription models.…
…
continue reading