Root Causes: A PKI and Security Podcast - podcast cover

Root Causes: A PKI and Security Podcast

Tim Callan and Jason Sorokosoundcloud.com
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to understand the whys and wherefores of popular Public Key Infrastructures.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Root Causes 329: What Is Messaging Layer Security?

The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.

Aug 29, 202311 min

Root Causes 328: What Is the Debian Weak Key Flaw?

In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.

Aug 23, 20237 min

Root Causes 326: The Difference Between .ml and .mil

A recent Financial Times article reveals that mistyped email addresses aimed at the US military frequently are sent to email addresses in Mali instead, to the tune of hundreds of thousands per year. Some of this includes sensitive military content.

Aug 15, 202312 min

Root Causes 324: Apple Vs New UK Surveillance Bill

The battle between government and encryption continues. The UK is attempting to build secret back doors into end-to-end encrypted services. In response, Apple has threatened to remove Apple services from the UK, including FaceTime and iMessage.

Aug 07, 202316 min

Root Causes 323: Update on Microsoft Key Compromise

In this follow up to our episode 320, we describe Microsoft's actions to mitigate this attack and explain new understanding that shows its impact to be broader than originally thought. Anyone using the Microsoft stack needs to understand this new threat.

Aug 02, 202312 min

Root Causes 322: RIP Kevin Mitnick

In July famous security researcher Kevin Mitnick passed away. We briefly pay tribute to Kevin and talk about his contributions to white hat hacking as a practice.

Jul 31, 20236 min

Root Causes 321: CABF Moratorium on New Certificate Consumer Members

The CA/Browser Forum recently passed a temporary moratorium on new members of the Certificate Consumer class. We explain how Certificate Consumers have been admitted in the past and the pros and cons of creating stricter rules for Certificate Consumers.

Jul 26, 202316 min

Root Causes 319: EU Digital Wallets

A new agreement mandates that European countries will make digital wallets available to their citizens in 2024. We explain what's coming and some of its implications.

Jul 21, 202320 min

Root Causes 318: What Is ACME Renewal Information (ARI)?

ACME is a functional and widely supported protocol for certificate provisioning and installation. A new extension to the protocol will help automate renewals. In this episode we explain ACME Renewal Information (ARI).

Jul 18, 202310 min

Root Causes 317: New Automotive CAN Bus Attacks Demand PKI

In this episode we describe how physically accessing the CAN bus wires in a modern automobile can allow a thief to take over key fob functionality to unlock the doors, start the engine, and ultimately steal the vehicle. We explain how PKI can defeat this attack and what is necessary to get there.

Jul 13, 202320 min

Root Causes 314: AI-based Deepfakes in Real Crimes

We have spoken in previous episodes about the potential for deepfakes in real-world crimes. In this episode we discuss a variety of real-world attacks in which deepfakes have played a role. These include fake kidnapping, "sextortion," and a range of spear phishing attacks and social media scams.

Jul 05, 202326 min

Root Causes 313: SSL Revocation Reason Codes

In 2022 Mozilla added a root program requirement that CAs include Reason Codes when revoking public TLS certificates. In this episode we explain the reason codes, along with some explicitly forbidden reason codes, and go into the backstory behind this requirement.

Jun 22, 202316 min

Root Causes 312: You Shouldn't Roll Your Own Crypto

Don't roll your own crypto. In this episode we describe the findings from 2021 research that investigating the root causes of problems in cryptographic systems. The results may surprise you.

Jun 20, 202315 min

Root Causes 311: What Is CCADB?

We describe CCADB, the Common CA Database. We explain the role of CCADB in the WebPKI and how this role is evolving.

Jun 16, 202314 min

Root Causes 310: Another AI Episode

In this episode we continue to explore the capabilities of AI to replicate known people in deep fakes with AI-generated content.

Jun 13, 202325 min

Root Causes 309: What Is Key Attestation for Code Signing?

On June 1, 2023 new rules for delivery of code signing certificates went into effect, requiring the certificate be delivered by secure HSM. In addition to shipping a token by mail, certificates can be electronically delivered to Subscriber-owned hardware that supports key attestation. In this episode we explain key attestation, supporting hardware, and the pros and cons of this method.

Jun 07, 202311 min

Root Causes 308: E-Tugra Root Deprecation

For the second time in under twelve months, a major browser is deprecating a CA's public trust. This time it's E-Tugra. Learn about the concerns raised about this CA, investigation of these concerns, and the ultimate deprecation decision.

Jun 05, 202318 min

Root Causes 303: A Return to Chrome and the Address Bar

In our recent episode 300 we discussed Chrome's upcoming removal of the lock icon from its interface. In this follow up, we catch the listener up on Chrome's longstanding program to minimize the URL in its interface, even to the point of contemplating removing the address bar entirely.

May 16, 202319 min

Root Causes 302: Intel Secure Boot Private Key Leak

Resulting from a recent ransomware attack, a private key from Intel has been exposed, affecting more than a hundred OEM components and an unknown number of end user products. We explain what happened and its possible implications.

May 12, 202313 min

Root Causes 301: The Difference Between Certificate Automation and CLM

This podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM). In this episode we discuss how CLM does not always entail automation and vice versa -- along with where this distinction occurs and why it matters.

May 09, 202315 min

Root Causes 300: Chrome Eliminates the Lock Icon

Google Chrome has announced that it will eliminate the lock icon in September. We explain what Google will be doing, its stated rationale, and the pros and cons of this decision.

May 04, 202319 min
For the best experience, listen in Metacast app for iOS or Android