Player FM - Internet Radio Done Right
Checked 17h ago
Added forty weeks ago
Content provided by Tim Callan and Jason Soroko. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Tim Callan and Jason Soroko or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!
Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED
O
Our Skin: A Personal Discovery Podcast


1 You Are Your Longest Relationship: Artist DaQuane Cherry on Psoriasis, Art, and Self-Care 32:12
32:12
Play Later
Play Later
Lists
Like
Liked32:12
DaQuane Cherry was once the kid who wore a hoodie to hide skin flare-ups in school. Now he’s an artist and advocate helping others feel seen. He reflects on his psoriasis journey, the power of small joys, and why loving yourself first isn’t a cliché—it’s essential. Plus, a deep dive into the history of La Roche-Posay’s legendary spring. See omnystudio.com/listener for privacy information.…
Root Causes 484: Multi Good Factor Authentication
Manage episode 476074962 series 3608539
Content provided by Tim Callan and Jason Soroko. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Tim Callan and Jason Soroko or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.
…
continue reading
517 episodes
Manage episode 476074962 series 3608539
Content provided by Tim Callan and Jason Soroko. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Tim Callan and Jason Soroko or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.
…
continue reading
517 episodes
All episodes
×Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should be asking.

1 Root Causes 515: What Is Entropy-aware Governance? 14:51
14:51
Play Later
Play Later
Lists
Like
Liked14:51
Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and requirements.

1 Root Causes 514: Diary of an Online Firestorm 12:45
12:45
Play Later
Play Later
Lists
Like
Liked12:45
Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread. We discuss what a more functional response would have looked like.

1 Root Causes 513: Is Revocation the Best Remedy for CPS Misalignment? 12:21
12:21
Play Later
Play Later
Lists
Like
Liked12:21
We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.

1 Root Causes 512: CPS Versus Practices Misalignment 12:41
12:41
Play Later
Play Later
Lists
Like
Liked12:41
We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation.
We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store.

1 Root Causes 510: Introducing the GoML Browser 10:18
10:18
Play Later
Play Later
Lists
Like
Liked10:18
We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling.
We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs.
"Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser.
The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details.

1 Root Causes 506: Recap of CABF Face-to-face #65 8:53
8:53
Play Later
Play Later
Lists
Like
Liked8:53
For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting. We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face.
In this episode we explain the potential for future quantum computers to break files signed today with RSA or ECC, called "Trust now, forge later."

1 Root Causes 504: Jason Programs a Quantum Computer 17:48
17:48
Play Later
Play Later
Lists
Like
Liked17:48
Jason describes his recent experience using Amazon Braket.

1 Root Causes 503: What Are Hybrid and Composite PQC? 8:03
8:03
Play Later
Play Later
Lists
Like
Liked8:03
We explain the difference between two strategies of PQC implementation, which we call hybrid and composite.
In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse. We discuss stack ranking and "eyes open" PQC risk decisions.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 501: Why Increasing RSA Key Size Won't Solve the Quantum Problem 3:35
3:35
Play Later
Play Later
Lists
Like
Liked3:35
In this brief episode we explain why the problem that Shor's Algorithm poses to RSA and ECC can't be solved simply by increasing key size.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 500: OMG! 500 Episodes of Root Causes! 20:46
20:46
Play Later
Play Later
Lists
Like
Liked20:46
Wow. It's episode 500 of Root Causes. Jason and Tim talk about how the podcast has evolved in the past six years, how it remains consistent, and the updates we're making to keep being a valuable resource for our listeners.
R
Root Causes: A PKI and Security Podcast

The recent Signal controversy highlights the importance of understanding what protections an E2EE messaging app provides, and what it does not.
R
Root Causes: A PKI and Security Podcast

The UK National Cyber Security Centre (NCSC) has released new PQC guidance. We take exception to the dates it gives and explain why.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 497: PQC Update with Sofia Celi 19:50
19:50
Play Later
Play Later
Lists
Like
Liked19:50
Guest Sofia Celi (IETF, Brave) returns to talk about important developments in post quantum cryptography. Sofia tells us about her candidate algorithm MAYO and what is happening with the NIST PQC onramp. We learn about KEM TLS and the status of PQC initiatives in IETF.
R
Root Causes: A PKI and Security Podcast

Gmail is now end-to-end encrypted for all recipients, regardless of the receiving client. We explain how Gmail accomplishes this trick.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 495: Trust Models and Post Quantum Cryptography 7:00
7:00
Play Later
Play Later
Lists
Like
Liked7:00
We build on our Trust Models discussion to explore how organizations can structure their PKI for the transition to post quantum cryptography (PQC).
R
Root Causes: A PKI and Security Podcast

1 Root Causes 494: Introduction to Trust Models 21:09
21:09
Play Later
Play Later
Lists
Like
Liked21:09
We explain the basics of trust models and compare various models including WebPKI, private CA, and consortium models.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 493: Disentangling Public and Private Certificate Use Cases 12:10
12:10
Play Later
Play Later
Lists
Like
Liked12:10
Changing root store requirements mean CAs must separate their root hierarchies for different certificate types. We explain why enterprises should consider private CA for some use cases.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 492: When Mandatory Security Training Sucks 19:36
19:36
Play Later
Play Later
Lists
Like
Liked19:36
In this episode we get excited about errors we see in mandatory security trainings.
R
Root Causes: A PKI and Security Podcast

We are rejoined by Dr. Michele Mosca to explore the potential threat of RSA being broken even in the absence of a quantum computing attack.
R
Root Causes: A PKI and Security Podcast

We define Chrome versus Chromium, explaining what each is and the difference between the two.
R
Root Causes: A PKI and Security Podcast

Does AI kill end-to-end encryption? There is a contention that the presence of AI agents in the workstream will render your confidential information visible outside the encrypted communication channels and therefore that E2EE is pointless. We explore this argument.
R
Root Causes: A PKI and Security Podcast

1 Root Causes 488: CABF Face-to-Face Meeting Update 5:37
5:37
Play Later
Play Later
Lists
Like
Liked5:37
We explain the major news items from the most recent CA/Browser Forum face-to-face meeting in Tokyo. Topics include MPIC, 47-day certificate term, and Temporary Restraining Orders.
R
Root Causes: A PKI and Security Podcast

Jason and I take a peek forward at what we imagine IT security looks like in 2030. Topics include PQC, ZTNA, "green zones," deep fakes, IoT, connected cars, agentic AI, blockchain, and CLM.
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.