Root Causes: A PKI and Security Podcast - podcast cover

Root Causes: A PKI and Security Podcast

Tim Callan and Jason Sorokosoundcloud.com
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to understand the whys and wherefores of popular Public Key Infrastructures.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Root Causes 299: 2023 RSA Recap

The 2023 RSA Conference just concluded. This week Tim recaps what he saw at the show and how it reflects on security industry trends. Our hosts discuss Zero Trust, PQC, blockchain, artificial intelligence, post-COVID tradeshow behavior, and more.

May 02, 202331 min

Root Causes 296: SHOULD We or MUST We?

The CA/Browser Forum guidelines contain many prescribed requirements, with language containing the word SHOULD or MUST. In this episode we explain the specifying power of these two words, why they are used, and what they signal about the intent behind a guideline and how the rules might evolve.

Apr 21, 202313 min

Root Causes 295: Genesis Criminal Marketplace Taken Down

A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.

Apr 17, 202311 min

Root Causes 294: Root Causes Honored by Webby Awards

The Root Causes podcast has received a Webby Honoree award. Jason and Tim briefly celebrate and discuss the challenge of operating a niche, homemade podcast while being directly compared to professionally produced podcasts on mainstream topics from media companies. Plus, Tim's new Root Causes t-shirt.

Apr 13, 20239 min

Root Causes 293: What Is Certbot?

Certbot is an important part of the ACME standard. This open source tool makes it easier for many IT administrators to use ACME to automate provisioning and installation of SSL / TLS certificates.

Apr 10, 202313 min

Root Causes 292: Validation Data Reuse for 90-day Certificates

As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also. We explain today's data reuse rules and what the evidence indicates will be required for both domain control validation (DCV) and organization information validation.

Apr 06, 202315 min

Root Causes 291: CLM and SIEM

We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee access. We talk about expected behaviors in the CLM and monitoring them.

Apr 03, 202310 min

Root Causes 290: What Are QGIS and QIIS?

In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation. We explain how they fit into validation and the criteria for a reliable information source.

Mar 29, 202313 min

Root Causes 288: ISARA Releases Patents on Hybrid Certificates

In this episode we are joined by Atsushi Yamada, CEO of ISARA. He explains how ISARA has put its patents on hybrid certificates into the public domain and why. We explain the role of hybrid certificates in PQC and ongoing crypto agility.

Mar 22, 202312 min

Root Causes 287: GoDaddy Private Key Breach

In this episode we describe an incident in which a GoDaddy breach exposed customer private keys. We explain the expectations surrounding private key exposure and get into the interesting question of when an incident is or is not part of a large company's CA business.

Mar 20, 202314 min

Root Causes 285: Can ChatGPT Write Malware?

In our ongoing exploration of the security implications of AI, in this episode we examine the suitability of ChatGPT as a malware-writing tool and possible future directions for AI in software creation.

Mar 14, 202316 min

Root Causes 284: 90-day SSL Certificates Are on the Way

The Google Chrome root program recently announced its intention to reduce the maximum term for public SSL certificates to 90 days. In this episode we explain this announcement and its implications and speculate on timing for this reduction.

Mar 10, 202324 min

Root Causes 283: Google Optional OCSP Proposal Clarified

In our episode 281 we reported on Google's proposal for optional OCSP. In this episode we correct some of our earlier reporting in that episode, including the use of CRL and the removal of any revocation requirement for SSL certificates of not more than ten days in term.

Mar 06, 202311 min

Root Causes 282: HSMs and Post Quantum Cryptography

Repeat guest Bruno Couillard of Crypto4A joins us to explain where Hardware Secure Modules (HSMs) fit into the world of PQC. We discuss the issues surrounding how HSMs will work with post quantum algorithms and hybrid certificates and the process (and timelines) for defining how HSMs will incorporate PQC.

Mar 02, 202329 min

Root Causes 281: Google Proposes Optional OCSP

In response to concerns about OCSP and privacy, Google has proposed removing the requirement for OCSP revocation checking for public SSL certificates meeting certain specific conditions. In this episode we go into the details of this proposal.

Feb 26, 202326 min

Root Causes 280: Did an AI Break CRYSTALS-Kyber?

Recent news reports might suggest that an AI-enhanced side attack has defeated the CRYSTALS-Kyber PQC algorithm. In this episode we clarify that Kyber has not been defeated to date and exactly what did occur. We define side channel attack, discuss the broader implications of this attack, and speculate on what would happen if Kyber actually were broken.

Feb 24, 202320 min

Root Causes 279: ChatGPT Watermarking

ChatGPT presents the potential problem of ChatGPT content being used and attributed to another source, such as a professional writer or a student. In this episode we discuss the idea of "watermarking" ChatGPT content, including stenography, randomness, entropy, and how to destroy the watermarks.

Feb 19, 202316 min

Root Causes 278: Microsoft on Certificates and FIDO

Recent public discussion of FIDO and digital certificates reveal details of Microsoft's approach to consumer digital authentication. We discuss secure elements, Windows Hello, and the differences between B2C, B2B, and B2E.

Feb 17, 202311 min

Root Causes 277: Privacy Sandbox

In the latest continuation of the effort to create better protections for consumer privacy while still enabling targeted advertising, Google has announced the Privacy Sandbox. In this episode we describe this latest foray, including concepts like k-anonymity and differential privacy.

Feb 13, 202315 min

Root Causes 276: ChatGPT and Identity Reputation

ChatGPT and similar AI tools are dominating the public's mind these days. In this episode we discuss the potential for people to attempt to use ChatGPT as a source of reputational analysis, KYC, and other information about individuals, companies, and other entities. These activities are potentially subject to both error and deliberate misdirection. In this episode we explain why.

Feb 09, 20238 min

Root Causes 275: No Fly List Stolen

In a recently revealed security breach, an attacker gained a copy of the full 2019 TSA No Fly list, including subject PII. This breach was enabled by failures in digital identity and encryption. Join us in unpacking what happened and the lessons to be learned.

Feb 06, 20238 min

Root Causes 274: New Quantum Readiness Law

The U.S. government has a new law requiring that government agencies create plans for migrating to post-quantum cryptography in response to impending threats from quantum computers. In this episode we are joined by guest Bruno Couillard of Crypto4A to discuss the law and its implications.

Feb 03, 202314 min

Root Causes 273: A Deep Dive on CA Agnostic

The industry is seeing more and more attention spent on the idea of CA agnosticism. As with any buzzy technology term, it can be used to mean a variety of things. Join us as we catalog the various ways a Certificate Lifecycle Management (CLM) system can be "CA agnostic."

Jan 30, 202321 min

Root Causes 272: OCSP's Privacy Problem

Concerns recently have been raised about OCSP real-time certificate checking and its potential to violate privacy. In this episode we unpack these concerns and discuss the alternatives to OCSP.

Jan 27, 202312 min

Root Causes 271: A Whole Fleet of Identity-based Automotive Hacks

A white hat security researcher recently revealed a large number of identity-based vulnerabilities across many automotive manufacturers. In this episode we explain how a group of white hats exploited these manufacturers' dependence on non-secret "secrets" such as VIN or email address to force a raft of unacceptable behaviors across a large number of automotive brands.

Jan 23, 202322 min

Root Causes 270: What Is the Difference Between KEM and PKE?

One of the little known changes that has come to the world of TLS is that the secret handshake and key exchange updated from Public Key Exchange (PKE) to Key Encapsulation Methods (KEM). In this episode we explain the difference between the two methods and why this change is taking place.

Jan 20, 202312 min
For the best experience, listen in Metacast app for iOS or Android