Back
Explore every episode of the podcast Root Causes: A PKI and Security Podcast
Dive into the complete episode list for Root Causes: A PKI and Security Podcast. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Root Causes 517: The Cost of Quantum Factoring | 25 juil. 2025 | 00:05:20 | |
Jason walks us through an important recent paper from Google tracking the cost of quantum factoring. | |||
| Root Causes 516: PQC for ADCS | 21 juil. 2025 | 00:13:39 | |
Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should be asking. | |||
| Root Causes 515: What Is Entropy-aware Governance? | 18 juil. 2025 | 00:14:51 | |
Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and requirements. | |||
| Root Causes 514: Diary of an Online Firestorm | 16 juil. 2025 | 00:12:45 | |
Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread. We discuss what a more functional response would have looked like. | |||
| Root Causes 513: Is Revocation the Best Remedy for CPS Misalignment? | 14 juil. 2025 | 00:12:21 | |
We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost. | |||
| Root Causes 512: CPS Versus Practices Misalignment | 11 juil. 2025 | 00:12:41 | |
We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation. | |||
| Root Causes 511: The GoML Root Store | 05 juil. 2025 | 00:15:41 | |
We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store. | |||
| Root Causes 510: Introducing the GoML Browser | 26 juin 2025 | 00:10:18 | |
We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling. | |||
| Root Causes 509: What Is a CPS? | 25 juin 2025 | 00:07:30 | |
We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs. | |||
| Root Causes 508: What Is Code Vibing? | 23 juin 2025 | 00:17:43 | |
"Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser. | |||
| Root Causes 507: First Distrust of 2025 | 19 juin 2025 | 00:09:32 | |
The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details. | |||
| Root Causes 506: Recap of CABF Face-to-face #65 | 17 juin 2025 | 00:08:53 | |
For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting. We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face. | |||
| Root Causes 505: Trust Now, Forge Later | 13 juin 2025 | 00:10:33 | |
In this episode we explain the potential for future quantum computers to break files signed today with RSA or ECC, called "Trust now, forge later." | |||
| Root Causes 504: Jason Programs a Quantum Computer | 10 juin 2025 | 00:17:48 | |
Jason describes his recent experience using Amazon Braket. | |||
| Root Causes 502: The PQC Game of Chicken | 04 juin 2025 | 00:10:59 | |
In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse. We discuss stack ranking and "eyes open" PQC risk decisions. | |||
| Root Causes 501: Why Increasing RSA Key Size Won't Solve the Quantum Problem | 02 juin 2025 | 00:03:35 | |
In this brief episode we explain why the problem that Shor's Algorithm poses to RSA and ECC can't be solved simply by increasing key size. | |||
| Root Causes 500: OMG! 500 Episodes of Root Causes! | 29 mai 2025 | 00:20:46 | |
Wow. It's episode 500 of Root Causes. Jason and Tim talk about how the podcast has evolved in the past six years, how it remains consistent, and the updates we're making to keep being a valuable resource for our listeners. | |||
| Root Causes 499: Don't Blame Signal | 27 mai 2025 | 00:08:37 | |
The recent Signal controversy highlights the importance of understanding what protections an E2EE messaging app provides, and what it does not. | |||
| Root Causes 498: UK NCSC PQC Guidance | 23 mai 2025 | 00:15:31 | |
The UK National Cyber Security Centre (NCSC) has released new PQC guidance. We take exception to the dates it gives and explain why. | |||
| Root Causes 497: PQC Update with Sofia Celi | 21 mai 2025 | 00:19:50 | |
Guest Sofia Celi (IETF, Brave) returns to talk about important developments in post quantum cryptography. Sofia tells us about her candidate algorithm MAYO and what is happening with the NIST PQC onramp. We learn about KEM TLS and the status of PQC initiatives in IETF. | |||
| Root Causes 496: E2EE Gmail | 18 mai 2025 | 00:12:26 | |
Gmail is now end-to-end encrypted for all recipients, regardless of the receiving client. We explain how Gmail accomplishes this trick. | |||
| Root Causes 495: Trust Models and Post Quantum Cryptography | 16 mai 2025 | 00:07:00 | |
We build on our Trust Models discussion to explore how organizations can structure their PKI for the transition to post quantum cryptography (PQC). | |||
| Root Causes 494: Introduction to Trust Models | 13 mai 2025 | 00:21:09 | |
We explain the basics of trust models and compare various models including WebPKI, private CA, and consortium models. | |||
| Root Causes 493: Disentangling Public and Private Certificate Use Cases | 07 mai 2025 | 00:12:10 | |
Changing root store requirements mean CAs must separate their root hierarchies for different certificate types. We explain why enterprises should consider private CA for some use cases. | |||
| Root Causes 492: When Mandatory Security Training Sucks | 06 mai 2025 | 00:19:36 | |
In this episode we get excited about errors we see in mandatory security trainings. | |||
| Root Causes 491: RSA's Non-quantum Threat | 01 mai 2025 | 00:31:41 | |
We are rejoined by Dr. Michele Mosca to explore the potential threat of RSA being broken even in the absence of a quantum computing attack. | |||
| Root Causes 490: Chrome and Chromium | 28 avr. 2025 | 00:10:02 | |
We define Chrome versus Chromium, explaining what each is and the difference between the two. | |||
| Root Causes 489: Does AI Nullify E2EE? | 24 avr. 2025 | 00:12:04 | |
Does AI kill end-to-end encryption? There is a contention that the presence of AI agents in the workstream will render your confidential information visible outside the encrypted communication channels and therefore that E2EE is pointless. We explore this argument. | |||
| Root Causes 488: CABF Face-to-Face Meeting Update | 22 avr. 2025 | 00:05:37 | |
We explain the major news items from the most recent CA/Browser Forum face-to-face meeting in Tokyo. Topics include MPIC, 47-day certificate term, and Temporary Restraining Orders. | |||
| Root Causes 487: Security 2030 | 16 avr. 2025 | 00:46:40 | |
Jason and I take a peek forward at what we imagine IT security looks like in 2030. Topics include PQC, ZTNA, "green zones," deep fakes, IoT, connected cars, agentic AI, blockchain, and CLM. | |||
| Root Causes 486: 47-day Maximum Term Ballot Passes CABF | 14 avr. 2025 | 00:11:11 | |
Apple's ballot to step the maximum term for public SSL certificates down to 47 days has passed in the CA/Browser Forum. We explain. | |||
| Root Causes 485: What Is Open MPIC? | 13 avr. 2025 | 00:20:28 | |
Guest Dmitry Sharkov joins us to describe Open MPIC, the open-source project to help public CAs support MPIC. | |||
| Root Causes 484: Multi Good Factor Authentication | 09 avr. 2025 | 00:12:46 | |
We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust. | |||
| Root Causes 483: Introducing the PQC Sandbox | 07 avr. 2025 | 00:22:40 | |
We are joined by repeat guest Bruno Coulliard of Crypto4A to introduce Sectigo's new post quantum cryptography (PQC) sandbox. The PQC sandbox allows you to get quantum resistant certificates in your hands to understand how they work with your systems. | |||
| Root Causes 482: Microsoft and PQC | 02 avr. 2025 | 00:14:38 | |
In this episode we explore the potential PQC future for Microsoft Active Directory Certificate Services, aka MSCA. We discuss potential paths for Microsoft to take and their consequences. | |||
| Root Causes 481: What Is Protocol Ossification? | 31 mars 2025 | 00:11:49 | |
Protocol ossification is the phenomenon whereby ecosystems fail to work correctly with the full range of options included in a protocol. This occurs when individual software components only partially support the capabilities that should be available. We define protocol ossification, explain how and why it occurs, give real world examples, and talk about potential remedies. | |||
| Root Causes 480: White House PQC Executive Order | 24 mars 2025 | 00:10:22 | |
Many people believe that the Trump White House rescinded an important cybersecurity executive order from late days of the Biden administration. We set the record straight. | |||
| Root Causes 479: AI Adversarial Machine Learning | 21 mars 2025 | 00:13:10 | |
In this episode we discuss the thinking on how adversaries can exploit the flaws in AI models to achieve unexpected and dangerous results. We explore some potential paths of defense against attacks of this sort. | |||
| Root Causes 478: Should We All Switch from RSA to ECC? | 17 mars 2025 | 00:16:01 | |
RSA is under attack. Even without the quantum threat, we face the possibility of smart new exploits reducing the viable RSA key space and rendering it unsafe. In this episode we discuss the merits of choosing ECC over RSA as soon as today. | |||
| Root Causes 477: Comparative Security Philosophies | 12 mars 2025 | 00:17:51 | |
We discuss how various popular computing platforms approach security and highlight the differences between them. | |||
| Root Causes 476: The Need for Security KPIs | 10 mars 2025 | 00:16:34 | |
Jason recounts a 2024 Black Hat talk about the need for objective measurements of our IT defenses and whether the good guys or bad guys are winning. Jason breaks down how to define and measure the impact of security measures. | |||
| Root Causes 475: Can Your AI Scheme Against You? | 05 mars 2025 | 00:15:56 | |
It's the stuff of science fiction! Interesting research shows how today's AI technology is capable of lying to and scheming against its human owners in service of its goals. | |||
| Root Causes 474: Explaining Shor's Algorithm | 02 mars 2025 | 00:21:12 | |
We talk a lot about Shor's Algorithm in our discussion of post quantum cryptography (PQC). In this episode Jason explains Shor's algorithm for non-quantum physicists. | |||
| Root Causes 473: Does Security Software Lack Creativity? | 28 févr. 2025 | 00:10:08 | |
Jason reports on a 2024 Black Hat keynote about how modern software development practices inhibit innovation and invention. | |||
| Root Causes 472: AI Offensive Modeling | 26 févr. 2025 | 00:11:14 | |
AI tools are now available to perform red-teaming activity for DevSecOps. Such tools are soon to be table stakes in the constantly escalating IT security arms race. Join us to learn more. | |||
| Root Causes 471: ACME for PQC | 23 févr. 2025 | 00:21:28 | |
In this episode, guest Alexandre Giron explains what is needed to support post quantum cryptography (PQC) with ACME. | |||
| Root Causes 470: The MFA False Equivalency Fallacy | 19 févr. 2025 | 00:11:53 | |
Not all forms of MFA are equally secure. In this episode we describe the differences between the more secure and less secure forms of MFA. | |||
| Root Causes 469: The All or Nothing Fallacy in Cybersecurity | 17 févr. 2025 | 00:07:14 | |
In this episode we explain the all-or-nothing fallacy in cybersecurity and how it's affecting debate in the WebPKI right now. | |||
| Root Causes 468: UK Demands New Backdoor from Apple | 14 févr. 2025 | 00:10:25 | |
A new demand from the UK seeks complete access to all Apple cloud data housed in the UK, regardless of the data owners' citizenship and residency. We unpack this latest development in Government versus Encryption. | |||
| Root Causes 467: Decoupling Public from Private Use Cases | 12 févr. 2025 | 00:09:41 | |
The past year has seen a great deal of focus on the use of public TLS certificates where private root certificates are actually the appropriate solution. In this episode we discuss the differences between these two use cases and what IT organizations can do about it. | |||
© My Podcast Data · Independent project · Data from Apple & Spotify