Root Causes: A PKI and Security Podcast - podcast cover

Root Causes: A PKI and Security Podcast

Tim Callan and Jason Sorokosoundcloud.com
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to understand the whys and wherefores of popular Public Key Infrastructures.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Root Causes 209: One-Day Deployment of Certificate Lifecycle Management (CLM) Platforms

For any Certificate Lifecycle Management platform to succeed, effective deployment is essential. Our hosts are joined by Sectigo SVP of Global Sales Jennifer Binet who describes the optimal onboarding process, step by step. Jennifer discusses adding use cases over time, streamlining the contracting process, and getting to full automation for all certificates.

Feb 28, 202221 min

Root Causes 206: What Is Web3?

Web3 refers to the concept that online content can be attributed to specific known publishers, regardless of web site or online channel. In this episode we discuss the fundamentals of Web3, including self-signing protocols, authorization of content, blockchain, definitive authorship, consensus algorithms, and meat from space.

Feb 13, 202234 min

Root Causes 205: Anatomy of an Encrypted Peer-to-Peer Mesh Network

Secure online collaboration poses logistical and technical challenges under the best of circumstances. Now imagine you have no designated IT staff, no designated hardware, a small budget, and remote participants who are not deeply technical. In this episode Jason Soroko explains how he was able to quickly and easily create an encrypted communications mesh for use by him and his collaboration team.

Feb 09, 202212 min

Root Causes 204: PKI's Role in Passwordless

In previous episodes we have defined passwordless identity authentication. In this episode our hosts explain PKI's specific role in passwordless authentication, along the way clarifying the difference between password-masking and true passwordless technologies.

Feb 02, 202223 min

Root Causes 203: What Is a Credential Vault?

Credential vaults are necessary for secure and functional secrets management for automated systems like DevOps or Robotic Process Automation (RPA). This episode explains how credential vaults work and details their benefits.

Jan 31, 202211 min

Root Causes 202 : What Is Certificate Transparency?

Certificate Transparency (CT) is essential to monitoring the public SSL certificates that are issued. In this episode we explain what CT logs are, how they work, and the uses we can put them to.

Jan 27, 202216 min

Root Causes 201: What Are the Baseline Requirements?

The CA/Browser Forum Baseline Requirements (BR) are hugely influential in the world of public-trust certificates. In this episode we explain what the Baseline Requirements are, how they are created, and why they matter.

Jan 24, 202216 min

Root Causes 200: Why Not to Copy and Paste Commands from Web Pages

This episode describes newly revealed vulnerabilities where copying and pasting text from a web page can open the site visitor up to attack. Our hosts explain how this attack can occur and its potential consequences, along with how to defend yourself against this threat.

Jan 19, 20227 min

Root Causes 198: Deep Voice Fakes

We are all familiar with phishing in its various forms. Many people feel that they can protect themselves from fraud by verbally confirming apparent commands from senior executes. In this episode our hosts explore deep voice fakes, computer generated audio that successfully passes for the voice of a known associate, and the risks they pose.

Jan 11, 202215 min

Root Causes 197: Tim's Digital Haircut

In this episode our hosts describe the extreme degree to which all business has become digital business, even the most offline businesses you can think of, including food delivery, in-restaurant dining, bricks-and-mortar retail, and naturally, haircuts. We discuss the disparate, interconnected systems required to make this happen and the fragility of this new digital world.

Jan 07, 202212 min

Root Causes 196: What Is Certificate Agnostic?

In 2021 the certificate industry saw the emergency of the concept of "CA agnostic." However, that is only part of the story. In this episode our hosts build on this concept to define the idea of certificate automation platforms being "certificate agnostic," meaning these platforms should handle all certificates regardless of type, configuration, physical location, environment, use case, and origin.

Jan 03, 202210 min

Root Causes 195: iOS App Privacy Audits

The latest update of iOS includes new capabilities for app privacy auditing and permissions. Our hosts explain the controls available on iOS and Android and how a mobile device privacy audit can be beneficial.

Dec 27, 20216 min

Root Causes 194: Crypto Versus Cryptocurrency

Exploding interest in cryptocurrency has caused the word crypto to take on new meanings that were not part of the public dialog even a few years ago. In this episode our hosts explore both the overlap and difference between today's cryptocurrency (and blockchain) and more venerable forms of cryptography.

Dec 20, 202114 min

Root Causes 190: Phishing Coinbase

In continuation of our ongoing exploration of blockchain and cryptocurrency, our hosts describe a recently discovered exploit where attackers use weaknesses in one-time-password-based MFA to steal Coinbase accounts.

Nov 29, 20219 min

Root Causes 189: What Is CA Agnostic?

Certificate Lifecycle Management (CLM) platforms can deal with certificates from a number of sources. A CLM that can provision certificates of all types from all CAs, private and public, would be described as "CA agnostic." In this episode we explain this idea and its significance along with the key criteria for choosing a CA agnostic CLM platform.

Nov 17, 202117 min

Root Causes 188: Introduction to Web Security

Malware and other web site attacks are a frequent problem for small businesses and can result in reputational damage and site access being blocked or hindered by end user software and services. We are joined by web site protection expert JP Armenta, who explains how these attacks occur, their effects, and how site operators can protect themselves.

Nov 11, 202120 min

Root Causes 185: EU Covid Passport Root Key Stolen

The root certificates of the EU's Covid Passport program have suffered a private key compromise and counterfeit passports are now for sale on the black market. We explain the implications of this shocking revelation.

Nov 01, 202117 min

Root Causes 184: Popular College WiFi Vulnerability Revealed

Recent research reveals that certificate misconfiguration in a commonly used college WiFi platform that can lead to exposure and theft of users' login credentials. Our hosts discuss WiFi authentication and the EAP protocol and explain how this vulnerability occurs.

Oct 26, 202112 min

Root Causes 183: New MSCA Attack Toolkits

At this year's BlackHat, a talk and white paper detailed the threat of MSCA root key attacks, which can be used to create unauthorized certificates. This release includes a pair of offensive toolkits and a defensive toolkit. We explain the importance of this release and provide a clear action list for IT professionals in charge of Microsoft CA.

Oct 21, 202114 min

Root Causes 182: Let's Encrypt Root Expiration

Let's Encrypt's recent root expiration caused widespread service outages and other hassles for online services and sites. Our hosts discuss this expiration, why so many problems resulted, and the recipe for avoiding these problems in the future.

Oct 18, 202125 min

Root Causes 181: Limitation of DCV Through Web Site Changes

This December will see a meaningful change in how CAs are allowed to conduct Domain Control Validation (DCV) using the method known as https token or file authentication or agreed up on change to web site. This method will be removed as an option for "domain spaces" including wildcards and subdomains. Join our hosts as they explain how DCV works and how the rules are changing and why. And we clarify the available options for those changing their preferred DCV methods.

Aug 29, 202113 min

Root Causes 180: PetitPotam MSCA Attack

The PetitPotam attack against Microsoft CA has garnered a lot of attention. Our hosts describe this attack and define related terms like Mimikatz, pass-the-hash, and NTLM Relay. The episode goes on to give a roadmap for mitigating this attack , including free resources available to help defend against PetitPotam.

Aug 26, 202112 min
For the best experience, listen in Metacast app for iOS or Android