<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>Root Causes: A PKI and Security Podcast</title><link>https://www.spreaker.com/podcast/root-causes-a-pki-and-security-podcast--3406724</link><description><![CDATA[Podcast by Tim Callan and Jason Soroko]]></description><atom:link href="https://www.spreaker.com/show/3406724/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Society &amp; Culture</category><copyright>Copyright Tim Callan</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ecacfe8353659a8c4d9ec597fd2e9467.jpg</url><title>Root Causes: A PKI and Security Podcast</title><link>https://www.spreaker.com/podcast/root-causes-a-pki-and-security-podcast--3406724</link></image><lastBuildDate>Fri, 04 Sep 2026 13:17:47 +0000</lastBuildDate><itunes:author>Tim Callan</itunes:author><itunes:owner><itunes:name>Tim Callan</itunes:name><itunes:email>feeds@spreaker.com</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ecacfe8353659a8c4d9ec597fd2e9467.jpg"/><itunes:subtitle>Podcast by Tim Callan and Jason Soroko</itunes:subtitle><itunes:summary><![CDATA[Podcast by Tim Callan and Jason Soroko]]></itunes:summary><itunes:category text="Society &amp; Culture"/><itunes:explicit>false</itunes:explicit><podcast:guid>387e8a22-20ba-536b-aaf6-7fe15047e705</podcast:guid><itunes:type>episodic</itunes:type><item><title>Root Causes 661: What Will Happen with eIDAS and MTC?</title><link>https://www.spreaker.com/episode/root-causes-661-what-will-happen-with-eidas-and-mtc--74898644</link><description><![CDATA[TLS certificates from CA/Browser Forum CAs are not the only server certificates in the WebPKI.  eIDAS QWACs are treated as server certificates by the major browsers. We see clear progress toward post quantum cryptography (PQC) for TLS by way of the Merkle Tree Certificate (MTC) architecture. But what is the path to PQC for eIDAS?  We examine this question.]]></description><guid isPermaLink="false">7bae9d28-8c3d-455b-9f35-3e2160baf33a</guid><pubDate>Fri, 04 Sep 2026 13:02:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74898644/128_default_tc.mp3" length="10408898" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>TLS certificates from CA/Browser Forum CAs are not the only server certificates in the WebPKI.  eIDAS QWACs are treated as server certificates by the major browsers. We see clear progress toward post quantum cryptography (PQC) for TLS by way of the...</itunes:subtitle><itunes:summary><![CDATA[TLS certificates from CA/Browser Forum CAs are not the only server certificates in the WebPKI.  eIDAS QWACs are treated as server certificates by the major browsers. We see clear progress toward post quantum cryptography (PQC) for TLS by way of the Merkle Tree Certificate (MTC) architecture. But what is the path to PQC for eIDAS?  We examine this question.]]></itunes:summary><itunes:duration>651</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/08425043d7fc3cc89da045119a9a8206.jpg"/><itunes:episode>662</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 660: What Are Delegated Credentials?</title><link>https://www.spreaker.com/episode/root-causes-660-what-are-delegated-credentials--74813067</link><description><![CDATA[As certificate lifespans become extremely short, new methods of delivery become functionally necessary.  We explain RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates.]]></description><guid isPermaLink="false">81f4df0f-c1bd-48fe-91d1-86b6b502e904</guid><pubDate>Wed, 02 Sep 2026 13:55:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74813067/128_default_tc.mp3" length="3006841" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As certificate lifespans become extremely short, new methods of delivery become functionally necessary.  We explain RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates.</itunes:subtitle><itunes:summary><![CDATA[As certificate lifespans become extremely short, new methods of delivery become functionally necessary.  We explain RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates.]]></itunes:summary><itunes:duration>188</itunes:duration><itunes:keywords>webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/411b27a623edf1d0f17361da23e19db8.jpg"/><itunes:episode>661</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 659: Should We Lengthen Certificate Lifespans?</title><link>https://www.spreaker.com/episode/root-causes-659-should-we-lengthen-certificate-lifespans--74768803</link><description><![CDATA[With certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again.  We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is generally a bad policy.]]></description><guid isPermaLink="false">7bc3da22-cb1b-4e02-8fcd-c592e3e6f879</guid><pubDate>Mon, 31 Aug 2026 13:53:42 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74768803/128_default_tc.mp3" length="11944062" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>With certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again.  We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is...</itunes:subtitle><itunes:summary><![CDATA[With certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again.  We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is generally a bad policy.]]></itunes:summary><itunes:duration>747</itunes:duration><itunes:keywords>webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/61de19676a8ce56c656bdb018ac95d55.jpg"/><itunes:episode>659</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 658: The Trouble with X9 Certificates</title><link>https://www.spreaker.com/episode/root-causes-658-the-trouble-with-x9-certificates--74700147</link><description><![CDATA[X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates.  We clarify why this is not the case.]]></description><guid isPermaLink="false">6e7e809f-8309-40c0-af52-f3c0bfa9428f</guid><pubDate>Wed, 26 Aug 2026 16:59:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74700147/128_default_tc.mp3" length="12481996" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates.  We clarify why this is not the case.</itunes:subtitle><itunes:summary><![CDATA[X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates.  We clarify why this is not the case.]]></itunes:summary><itunes:duration>781</itunes:duration><itunes:keywords>webpki,x9</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1d51ced6d1dae1420f6831bece2f31aa.jpg"/><itunes:episode>658</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 657: What Is Chaos Engineering?</title><link>https://www.spreaker.com/episode/root-causes-657-what-is-chaos-engineering--74650578</link><description><![CDATA["Chaos engineering" describes the practice of injecting faults into a system to see what happens.  This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.]]></description><guid isPermaLink="false">9d3f54c3-938e-4d2a-9cb6-1285740159d2</guid><pubDate>Mon, 24 Aug 2026 15:34:55 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74650578/128_default_tc.mp3" length="1822763" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>"Chaos engineering" describes the practice of injecting faults into a system to see what happens.  This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.</itunes:subtitle><itunes:summary><![CDATA["Chaos engineering" describes the practice of injecting faults into a system to see what happens.  This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.]]></itunes:summary><itunes:duration>114</itunes:duration><itunes:keywords>cybersecurity</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/09967795809a7053a31d714ad80c6aff.jpg"/><itunes:episode>657</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 656: The Trouble with Recursive AI Training</title><link>https://www.spreaker.com/episode/root-causes-656-the-trouble-with-recursive-ai-training--74460188</link><description><![CDATA[Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results.  As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results.  This ultimately can result in completely unusable information.]]></description><guid isPermaLink="false">6d9e5427-645c-4f82-b8ad-430849bae172</guid><pubDate>Fri, 21 Aug 2026 13:46:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74460188/128_default_tc.mp3" length="5909985" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results.  As more AI-generated slop finds its way onto the internet, this runs the risk of further...</itunes:subtitle><itunes:summary><![CDATA[Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results.  As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results.  This ultimately can result in completely unusable information.]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>ai (artificial intelligence)</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/67de584443ecaf53ba85cfed8c1c0742.jpg"/><itunes:episode>656</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 655: Why Not to Create Your Own Private CA</title><link>https://www.spreaker.com/episode/root-causes-655-why-not-to-create-your-own-private-ca--74340426</link><description><![CDATA[It is possible to use common tools like OpenSSL to create your own ML-DSA private CA.  This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.]]></description><guid isPermaLink="false">42bc65a9-036a-4888-a2ea-e8b94044ede2</guid><pubDate>Wed, 19 Aug 2026 20:42:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74340426/128_default_tc.mp3" length="5759938" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It is possible to use common tools like OpenSSL to create your own ML-DSA private CA.  This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.</itunes:subtitle><itunes:summary><![CDATA[It is possible to use common tools like OpenSSL to create your own ML-DSA private CA.  This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0dc9ef80901257ff08851b8df89a6687.jpg"/><itunes:episode>655</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 654: What's the Difference Between ML-DSA and ML-KEM?</title><link>https://www.spreaker.com/episode/root-causes-654-what-s-the-difference-between-ml-dsa-and-ml-kem--74208901</link><description><![CDATA[We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.]]></description><guid isPermaLink="false">13aa265c-cf17-4ed5-a556-aafdf84384d5</guid><pubDate>Mon, 17 Aug 2026 13:18:19 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74208901/128_default_tc.mp3" length="6747576" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.</itunes:subtitle><itunes:summary><![CDATA[We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.]]></itunes:summary><itunes:duration>422</itunes:duration><itunes:keywords>post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1a4d86a604406d14b2a91022cf2e3288.jpg"/><itunes:episode>654</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 653: Post Quantum Civilization</title><link>https://www.spreaker.com/episode/root-causes-653-post-quantum-civilization--73982225</link><description><![CDATA[Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.]]></description><guid isPermaLink="false">fd3d0e71-1a57-4eb4-8f00-83814f7ad3e3</guid><pubDate>Fri, 14 Aug 2026 12:17:51 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73982225/128_default_tc.mp3" length="7185597" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.</itunes:subtitle><itunes:summary><![CDATA[Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.]]></itunes:summary><itunes:duration>450</itunes:duration><itunes:keywords>post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/59aa100f697b2229be707df8383f7d18.jpg"/><itunes:episode>653</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 652: Choosing WebPKI Deprecation Dates</title><link>https://www.spreaker.com/episode/root-causes-652-choosing-webpki-deprecation-dates--73894874</link><description><![CDATA[There is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be.]]></description><guid isPermaLink="false">4d725213-eb9f-4082-8afe-58c7d8b13079</guid><pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73894874/128_default_tc.mp3" length="10235863" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>There is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be.</itunes:subtitle><itunes:summary><![CDATA[There is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be.]]></itunes:summary><itunes:duration>640</itunes:duration><itunes:keywords>webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6c00e0f76e2e0d32f82e2c2be928e31e.jpg"/><itunes:episode>652</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 651: Look at a Calendar</title><link>https://www.spreaker.com/episode/root-causes-651-look-at-a-calendar--73761406</link><description><![CDATA[It is surprising that we continue to see root expirations occur at the most inopportune times.  Weekends, public holidays, even New Year's Eve.  In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."]]></description><guid isPermaLink="false">1e2f7042-fd1d-4430-8f87-915c00ed235a</guid><pubDate>Mon, 10 Aug 2026 13:20:41 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73761406/128_default_tc.mp3" length="5298531" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It is surprising that we continue to see root expirations occur at the most inopportune times.  Weekends, public holidays, even New Year's Eve.  In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."</itunes:subtitle><itunes:summary><![CDATA[It is surprising that we continue to see root expirations occur at the most inopportune times.  Weekends, public holidays, even New Year's Eve.  In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."]]></itunes:summary><itunes:duration>332</itunes:duration><itunes:keywords>pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/57d8ab7c1c4610d82c0755712b9c9667.jpg"/><itunes:episode>651</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 650: Is It Time to Stop Saying SSL?</title><link>https://www.spreaker.com/episode/root-causes-650-is-it-time-to-stop-saying-ssl--73758915</link><description><![CDATA[SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.]]></description><guid isPermaLink="false">27fcfef3-511a-4aeb-9fb8-648f6598360a</guid><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73758915/128_default_tc.mp3" length="7454365" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.</itunes:subtitle><itunes:summary><![CDATA[SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.]]></itunes:summary><itunes:duration>466</itunes:duration><itunes:keywords>ssl / tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4e0dd209a180ba1cc55f05f7c9d9474a.jpg"/><itunes:episode>650</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 649: Client Authentication Certificate Use Cases</title><link>https://www.spreaker.com/episode/root-causes-649-client-authentication-certificate-use-cases--73508772</link><description><![CDATA[With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates.  We discuss the reasons public trust is often chosen and how to transition away from it.]]></description><guid isPermaLink="false">d0198c8d-002a-4ecf-a97f-4c105fffdaa4</guid><pubDate>Wed, 05 Aug 2026 17:36:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73508772/128_default_tc.mp3" length="10794256" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates.  We discuss the reasons public trust is often chosen and how to transition away from it.</itunes:subtitle><itunes:summary><![CDATA[With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates.  We discuss the reasons public trust is often chosen and how to transition away from it.]]></itunes:summary><itunes:duration>675</itunes:duration><itunes:keywords>pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9586c8bfb666adab47fb2535715a696d.jpg"/><itunes:episode>649</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 648: Claude Mythos Discovers New HAWK and AES Attacks</title><link>https://www.spreaker.com/episode/root-causes-648-claude-mythos-discovers-new-hawk-and-aes-attacks--73394007</link><description><![CDATA[Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments.]]></description><guid isPermaLink="false">8929269d-64a6-4720-8cea-9fc7d93f4435</guid><pubDate>Mon, 03 Aug 2026 15:53:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73394007/128_default_tc.mp3" length="20612954" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced...</itunes:subtitle><itunes:summary><![CDATA[Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments.]]></itunes:summary><itunes:duration>1289</itunes:duration><itunes:keywords>aes,ai (artificial intelligence),post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/47018b05729b73910ba1cb7ef0448761.jpg"/><itunes:episode>648</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 647: AD CS "Certighost" Flaw Highlights Agentic Identity Risks</title><link>https://www.spreaker.com/episode/root-causes-647-ad-cs-certighost-flaw-highlights-agentic-identity-risks--73283802</link><description><![CDATA[A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent.  We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.]]></description><guid isPermaLink="false">91d68806-2c79-46ca-9c6a-387090179965</guid><pubDate>Fri, 31 Jul 2026 13:19:32 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73283802/128_default_tc.mp3" length="18452523" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent.  We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI...</itunes:subtitle><itunes:summary><![CDATA[A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent.  We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.]]></itunes:summary><itunes:duration>1154</itunes:duration><itunes:keywords>agentic ai,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/8cde8e3989c621d5b9fdf485a903bbb9.jpg"/><itunes:episode>647</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 646: Clarifying the Dates for clientAuth Deprecation</title><link>https://www.spreaker.com/episode/root-causes-646-clarifying-the-dates-for-clientauth-deprecation--73237972</link><description><![CDATA[Because of a change in the drop-dead date, we have observed confusion in the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage.  In this episode we spell out these dates very clearly.]]></description><guid isPermaLink="false">c29a899f-2b3a-4b99-9e34-5af164a506fc</guid><pubDate>Wed, 29 Jul 2026 14:47:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73237972/128_default_tc.mp3" length="5455664" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Because of a change in the drop-dead date, we have observed confusion in the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage.  In...</itunes:subtitle><itunes:summary><![CDATA[Because of a change in the drop-dead date, we have observed confusion in the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage.  In this episode we spell out these dates very clearly.]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c797c687647b4375f93c77cf01cd41e7.jpg"/><itunes:episode>646</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 645: FAPI 2.0 Principles</title><link>https://www.spreaker.com/episode/root-causes-645-fapi-2-0-principles--73194355</link><description><![CDATA[In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.]]></description><guid isPermaLink="false">18a41217-5857-404a-99e1-ae5ddc035bf2</guid><pubDate>Mon, 27 Jul 2026 14:53:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73194355/128_default_tc.mp3" length="3529290" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.</itunes:subtitle><itunes:summary><![CDATA[In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.]]></itunes:summary><itunes:duration>221</itunes:duration><itunes:keywords>ai (artificial intelligence),digital identities</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cb1343521985c8c74e37e04ce9f04255.jpg"/><itunes:episode>645</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 644: Cryptographically Bound Tokens</title><link>https://www.spreaker.com/episode/root-causes-644-cryptographically-bound-tokens--73147523</link><description><![CDATA[In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication.  In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.]]></description><guid isPermaLink="false">8a9dc6c0-bc3f-42a3-9719-bf5ddd13a313</guid><pubDate>Fri, 24 Jul 2026 13:34:57 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73147523/128_default_tc.mp3" length="4882642" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication.  In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.</itunes:subtitle><itunes:summary><![CDATA[In our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication.  In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.]]></itunes:summary><itunes:duration>306</itunes:duration><itunes:keywords>ai (artificial intelligence),pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0c9fea84c8bc97ba8e65b8d94ba1dafb.jpg"/><itunes:episode>644</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 643: Certificates for Stronger Agent Authentication</title><link>https://www.spreaker.com/episode/root-causes-643-certificates-for-stronger-agent-authentication--73109655</link><description><![CDATA[We survey different strategies for securely authenticating agentic AI, including certificates and SPIFFE. We discuss Zero Trust and the Principle of Least Privileges as applied to agents.]]></description><guid isPermaLink="false">59290db8-184a-4026-b26a-20db1419a25d</guid><pubDate>Wed, 22 Jul 2026 15:04:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73109655/128_default_tc.mp3" length="10397195" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We survey different strategies for securely authenticating agentic AI, including certificates and SPIFFE. We discuss Zero Trust and the Principle of Least Privileges as applied to agents.</itunes:subtitle><itunes:summary><![CDATA[We survey different strategies for securely authenticating agentic AI, including certificates and SPIFFE. We discuss Zero Trust and the Principle of Least Privileges as applied to agents.]]></itunes:summary><itunes:duration>650</itunes:duration><itunes:keywords>agentic ai,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/06ff9195d21fc3883ae80873c2130e01.jpg"/><itunes:episode>643</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 642: Anthropic to Support SPIFFE/SPIRE</title><link>https://www.spreaker.com/episode/root-causes-642-anthropic-to-support-spiffe-spire--73068740</link><description><![CDATA[Anthropic has announced its intentions to support SPIFFE/SPIRE with the SPIRE server rooted in an "upstream authority," which will require a root private CA rather than allowing self-attestation for agentic AI.]]></description><guid isPermaLink="false">fba7f071-2502-499b-966e-38b4866ff53e</guid><pubDate>Mon, 20 Jul 2026 13:28:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73068740/128_default_tc.mp3" length="3640885" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Anthropic has announced its intentions to support SPIFFE/SPIRE with the SPIRE server rooted in an "upstream authority," which will require a root private CA rather than allowing self-attestation for agentic AI.</itunes:subtitle><itunes:summary><![CDATA[Anthropic has announced its intentions to support SPIFFE/SPIRE with the SPIRE server rooted in an "upstream authority," which will require a root private CA rather than allowing self-attestation for agentic AI.]]></itunes:summary><itunes:duration>228</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ecacfe8353659a8c4d9ec597fd2e9467.jpg"/><itunes:episode>642</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 641: What Is SPIRE?</title><link>https://www.spreaker.com/episode/root-causes-641-what-is-spire--73028259</link><description><![CDATA[In our episode 640 we defined SPIFFE, which provides digital identity for agentic workloads.  In this episode we explain SPIRE (SPIFFE Runtime Environment), the SPIFFE certificate provisioning protocol.]]></description><guid isPermaLink="false">1e523c8d-acf6-4598-a1f4-0471e4f829db</guid><pubDate>Fri, 17 Jul 2026 14:15:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73028259/128_default_tc.mp3" length="5621478" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our episode 640 we defined SPIFFE, which provides digital identity for agentic workloads.  In this episode we explain SPIRE (SPIFFE Runtime Environment), the SPIFFE certificate provisioning protocol.</itunes:subtitle><itunes:summary><![CDATA[In our episode 640 we defined SPIFFE, which provides digital identity for agentic workloads.  In this episode we explain SPIRE (SPIFFE Runtime Environment), the SPIFFE certificate provisioning protocol.]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>ai (artificial intelligence),pki,spiffe,spire</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b64d5a862143e3b627eb91d3a2e6c88e.jpg"/><itunes:episode>641</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 640: What is SPIFFE?</title><link>https://www.spreaker.com/episode/root-causes-640-what-is-spiffe--72991748</link><description><![CDATA[SPIFFE (Secure Production Identity Framework for Everyone) is a standard for digital identity for agentic workloads.  In this episode we explain.]]></description><guid isPermaLink="false">e5a41378-8a1f-48d6-8aa1-6f19631593e9</guid><pubDate>Wed, 15 Jul 2026 13:53:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72991748/128_default_tc.mp3" length="4508150" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>SPIFFE (Secure Production Identity Framework for Everyone) is a standard for digital identity for agentic workloads.  In this episode we explain.</itunes:subtitle><itunes:summary><![CDATA[SPIFFE (Secure Production Identity Framework for Everyone) is a standard for digital identity for agentic workloads.  In this episode we explain.]]></itunes:summary><itunes:duration>282</itunes:duration><itunes:keywords>pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f5335cc93793083b6eee0207ea2bce4.jpg"/><itunes:episode>640</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 639: Fighting Static API Key Spillage Is Like Fighting Gravity</title><link>https://www.spreaker.com/episode/root-causes-639-fighting-static-api-key-spillage-is-like-fighting-gravity--72914887</link><description><![CDATA[Static API keys are a common security practice.  In this episode we discuss the risk of these keys being revealed, including directly by the AIs that use them.]]></description><guid isPermaLink="false">b2ac46fa-2ce8-46d1-9874-7d93276ad6e4</guid><pubDate>Fri, 10 Jul 2026 13:23:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72914887/128_default_tc.mp3" length="8144395" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Static API keys are a common security practice.  In this episode we discuss the risk of these keys being revealed, including directly by the AIs that use them.</itunes:subtitle><itunes:summary><![CDATA[Static API keys are a common security practice.  In this episode we discuss the risk of these keys being revealed, including directly by the AIs that use them.]]></itunes:summary><itunes:duration>509</itunes:duration><itunes:keywords>ai,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45d79c7ac530b333dc1444b311377555.jpg"/><itunes:episode>639</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 638: Catfishing</title><link>https://www.spreaker.com/episode/root-causes-638-catfishing--72871190</link><description><![CDATA[Tim shares his very personal experience with would-be catfishers and we talk about how AI is set to change the catfishing attack.]]></description><guid isPermaLink="false">9acc608e-ed16-4576-a28c-f84a41e587e2</guid><pubDate>Wed, 08 Jul 2026 14:36:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72871190/128_default_tc.mp3" length="20410401" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Tim shares his very personal experience with would-be catfishers and we talk about how AI is set to change the catfishing attack.</itunes:subtitle><itunes:summary><![CDATA[Tim shares his very personal experience with would-be catfishers and we talk about how AI is set to change the catfishing attack.]]></itunes:summary><itunes:duration>1276</itunes:duration><itunes:keywords>pki,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/73c3e8c39eed8515052b29174446931c.jpg"/><itunes:episode>638</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 637: Is It Time to Get Rid of EV SSL?</title><link>https://www.spreaker.com/episode/root-causes-637-is-it-time-to-get-rid-of-ev-ssl--72840449</link><description><![CDATA[The Baseline Requirements, CT logs, the Bugzilla Bloodbath, shortening certificate lifespans, all these trends serve to enforce a high level of quality and predictability across WebPKI certificates.  Nearly twenty years after the introduction of EV SSL, we ask if it has served its purpose and should be retired.]]></description><guid isPermaLink="false">18bb94ab-ab58-414d-ac3d-222816ada802</guid><pubDate>Mon, 06 Jul 2026 14:10:19 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72840449/128_default_tc.mp3" length="10550651" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Baseline Requirements, CT logs, the Bugzilla Bloodbath, shortening certificate lifespans, all these trends serve to enforce a high level of quality and predictability across WebPKI certificates.  Nearly twenty years after the introduction of EV...</itunes:subtitle><itunes:summary><![CDATA[The Baseline Requirements, CT logs, the Bugzilla Bloodbath, shortening certificate lifespans, all these trends serve to enforce a high level of quality and predictability across WebPKI certificates.  Nearly twenty years after the introduction of EV SSL, we ask if it has served its purpose and should be retired.]]></itunes:summary><itunes:duration>660</itunes:duration><itunes:keywords>pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3d3ffaec90087f4ce72f30eeb330fe30.jpg"/><itunes:episode>637</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 636: The Future of Crypto Agility</title><link>https://www.spreaker.com/episode/root-causes-636-the-future-of-crypto-agility--72791451</link><description><![CDATA[Dustin Moody of NIST joins us to talk about the evolution of standardized cryptography beyond the current PQC efforts. Topics include maintaining visibility on cryptography presently in use, 50 years of RSA, and cryptographic heterogeny.]]></description><guid isPermaLink="false">713aff01-f230-4329-bdfc-e23e80d180b0</guid><pubDate>Thu, 02 Jul 2026 14:25:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72791451/128_default_tc.mp3" length="9115835" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Dustin Moody of NIST joins us to talk about the evolution of standardized cryptography beyond the current PQC efforts. Topics include maintaining visibility on cryptography presently in use, 50 years of RSA, and cryptographic heterogeny.</itunes:subtitle><itunes:summary><![CDATA[Dustin Moody of NIST joins us to talk about the evolution of standardized cryptography beyond the current PQC efforts. Topics include maintaining visibility on cryptography presently in use, 50 years of RSA, and cryptographic heterogeny.]]></itunes:summary><itunes:duration>570</itunes:duration><itunes:keywords>cryptography,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/296724cc9883859e2833257595850298.jpg"/><itunes:episode>636</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 635: Do We Need to Get Rid of ECC?</title><link>https://www.spreaker.com/episode/root-causes-635-do-we-need-to-get-rid-of-ecc--72744239</link><description><![CDATA[Bas Westerbaan of Cloudflare joins us to discuss recent information that heightens concerns about Elliptic Curve Cryptography (ECC) and its vulnerability to a cryptographically relevant quantum computer (CRQC). We pose the question do we need to deprecate ECC in advance of our migration to ML-DSA and other PQC algorithms.]]></description><guid isPermaLink="false">354cffc1-f530-4cff-ba60-d68b9535a13e</guid><pubDate>Mon, 29 Jun 2026 16:13:49 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72744239/128_default_tc.mp3" length="9180618" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Bas Westerbaan of Cloudflare joins us to discuss recent information that heightens concerns about Elliptic Curve Cryptography (ECC) and its vulnerability to a cryptographically relevant quantum computer (CRQC). We pose the question do we need to...</itunes:subtitle><itunes:summary><![CDATA[Bas Westerbaan of Cloudflare joins us to discuss recent information that heightens concerns about Elliptic Curve Cryptography (ECC) and its vulnerability to a cryptographically relevant quantum computer (CRQC). We pose the question do we need to deprecate ECC in advance of our migration to ML-DSA and other PQC algorithms.]]></itunes:summary><itunes:duration>574</itunes:duration><itunes:keywords>elliptic curve cryptography (e,post quantum cryptography (pqc,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/46c9cc5eecd21ab4c3dfce81eee85408.jpg"/><itunes:episode>635</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 634: White House Executive Order Accelerates PQC Deployment</title><link>https://www.spreaker.com/episode/root-causes-634-white-house-executive-order-accelerates-pqc-deployment--72704697</link><description><![CDATA[A new Executive Order (EO) moves the deadline for ML-DSA deployment up to 2031.  We talk about why this happened and its implications on government, the technology industry, and enterprises around the globe.]]></description><guid isPermaLink="false">768b42ac-6d72-4d66-96db-d928b1f61103</guid><pubDate>Fri, 26 Jun 2026 16:07:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72704697/128_default_tc.mp3" length="12206950" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new Executive Order (EO) moves the deadline for ML-DSA deployment up to 2031.  We talk about why this happened and its implications on government, the technology industry, and enterprises around the globe.</itunes:subtitle><itunes:summary><![CDATA[A new Executive Order (EO) moves the deadline for ML-DSA deployment up to 2031.  We talk about why this happened and its implications on government, the technology industry, and enterprises around the globe.]]></itunes:summary><itunes:duration>763</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/29d27f18f696bec2e0927c472a5a579f.jpg"/><itunes:episode>634</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 633: ETSI PQC Conference Wrap Up</title><link>https://www.spreaker.com/episode/root-causes-633-etsi-pqc-conference-wrap-up--72671952</link><description><![CDATA[We are freshly returned from the 2026 ETSI PQC Conference.  We give a debrief on the conference, including the difference between post quantum cryptography (PQC) and quantum key distribution (QKD), the algorithmic zoo, PQC for blockchain, the Dunning Kruger Effect, and cryptographic Frogger.]]></description><guid isPermaLink="false">c444087a-2810-4e05-a752-bbe332fa4129</guid><pubDate>Wed, 24 Jun 2026 13:36:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72671952/128_default_tc.mp3" length="15551459" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are freshly returned from the 2026 ETSI PQC Conference.  We give a debrief on the conference, including the difference between post quantum cryptography (PQC) and quantum key distribution (QKD), the algorithmic zoo, PQC for blockchain, the Dunning...</itunes:subtitle><itunes:summary><![CDATA[We are freshly returned from the 2026 ETSI PQC Conference.  We give a debrief on the conference, including the difference between post quantum cryptography (PQC) and quantum key distribution (QKD), the algorithmic zoo, PQC for blockchain, the Dunning Kruger Effect, and cryptographic Frogger.]]></itunes:summary><itunes:duration>972</itunes:duration><itunes:keywords>post quantum cryptography (pqc,quantum key distribution</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/699acf8ba62d5d483d0aca0d52da9991.jpg"/><itunes:episode>633</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 632: Gartner Risk and Security 2026 Wrapup</title><link>https://www.spreaker.com/episode/root-causes-632-gartner-risk-and-security-2026-wrapup--72635852</link><description><![CDATA[We recently attended the Gartner Risk and Security conference for 2026, where we observed a great deal of attention on not only AI but also post quantum cryptography (PQC). Join us as we share the key takeaways.]]></description><guid isPermaLink="false">fd25cc79-48f8-4573-a59b-936dfdd923c5</guid><pubDate>Mon, 22 Jun 2026 15:51:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72635852/128_default_tc.mp3" length="19125428" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We recently attended the Gartner Risk and Security conference for 2026, where we observed a great deal of attention on not only AI but also post quantum cryptography (PQC). Join us as we share the key takeaways.</itunes:subtitle><itunes:summary><![CDATA[We recently attended the Gartner Risk and Security conference for 2026, where we observed a great deal of attention on not only AI but also post quantum cryptography (PQC). Join us as we share the key takeaways.]]></itunes:summary><itunes:duration>1196</itunes:duration><itunes:keywords>ai,pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a4750fd91597fc70a2cb1bf8fae7c0fc.jpg"/><itunes:episode>632</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 631: Did the Bugzilla Bloodbath Change Anything?</title><link>https://www.spreaker.com/episode/root-causes-631-did-the-bugzilla-bloodbath-change-anything--72603513</link><description><![CDATA[2024 saw a flurry of high profile incidents for public CA, which we named the Bugzilla Bloodbath. We look back to see how the WebPKI has changed as a consequence.]]></description><guid isPermaLink="false">30104afe-eaa0-4b17-9af5-99eb6376d2af</guid><pubDate>Fri, 19 Jun 2026 17:47:43 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72603513/128_default_tc.mp3" length="12633853" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2024 saw a flurry of high profile incidents for public CA, which we named the Bugzilla Bloodbath. We look back to see how the WebPKI has changed as a consequence.</itunes:subtitle><itunes:summary><![CDATA[2024 saw a flurry of high profile incidents for public CA, which we named the Bugzilla Bloodbath. We look back to see how the WebPKI has changed as a consequence.]]></itunes:summary><itunes:duration>790</itunes:duration><itunes:keywords>webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d4d87c7e225ee7dd8b48d8f0feaa576e.jpg"/><itunes:episode>631</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 630: The PQC Physicality Crisis</title><link>https://www.spreaker.com/episode/root-causes-630-the-pqc-physicality-crisis--72566470</link><description><![CDATA[Resource-constrained devices may need to address PQC through real-time, seed-based, key generation. Unfortunately, this leaves the full key exposed very briefly in RAM. The potential consequences of this are far-reaching and scary. We go into the details.]]></description><guid isPermaLink="false">4959ecde-0bda-4f82-a28a-70135e16752d</guid><pubDate>Wed, 17 Jun 2026 17:31:58 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72566470/128_default_tc.mp3" length="6208566" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Resource-constrained devices may need to address PQC through real-time, seed-based, key generation. Unfortunately, this leaves the full key exposed very briefly in RAM. The potential consequences of this are far-reaching and scary. We go into the details.</itunes:subtitle><itunes:summary><![CDATA[Resource-constrained devices may need to address PQC through real-time, seed-based, key generation. Unfortunately, this leaves the full key exposed very briefly in RAM. The potential consequences of this are far-reaching and scary. We go into the details.]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9ed573fd4533d95d1a8aaf8d263dbf30.jpg"/><itunes:episode>630</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 629: Does the Evidence Support Moving PQC Deadlines to 2029?</title><link>https://www.spreaker.com/episode/root-causes-629-does-the-evidence-support-moving-pqc-deadlines-to-2029--72539025</link><description><![CDATA[Sam Jaques of the University of Waterloo returns to discuss his tracking of progress in quantum computers and offer a perspective on moving our PQC deadlines up to 2029.]]></description><guid isPermaLink="false">3c0e7b83-4ce7-4c33-9e2a-65741999ca22</guid><pubDate>Mon, 15 Jun 2026 17:48:40 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72539025/128_default_tc.mp3" length="15567927" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Sam Jaques of the University of Waterloo returns to discuss his tracking of progress in quantum computers and offer a perspective on moving our PQC deadlines up to 2029.</itunes:subtitle><itunes:summary><![CDATA[Sam Jaques of the University of Waterloo returns to discuss his tracking of progress in quantum computers and offer a perspective on moving our PQC deadlines up to 2029.]]></itunes:summary><itunes:duration>973</itunes:duration><itunes:keywords>post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ac65ffe8c571957f0033ed10a64afa1c.jpg"/><itunes:episode>629</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 628: PI-DOS (Prompt Injection-based Denial of Service)</title><link>https://www.spreaker.com/episode/root-causes-628-pi-dos-prompt-injection-based-denial-of-service--72498766</link><description><![CDATA[An emerging attack against AIs is to create a significantly complex and recursive prompt that will occupy the AI indefinitely or for a sufficiently long time that it acts as a Denial-of-Service (DoS) attack.  We describe how this works.]]></description><guid isPermaLink="false">e76e8f25-0809-4528-9a89-ad188cd92545</guid><pubDate>Fri, 12 Jun 2026 13:29:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72498766/128_default_tc.mp3" length="9282656" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>An emerging attack against AIs is to create a significantly complex and recursive prompt that will occupy the AI indefinitely or for a sufficiently long time that it acts as a Denial-of-Service (DoS) attack.  We describe how this works.</itunes:subtitle><itunes:summary><![CDATA[An emerging attack against AIs is to create a significantly complex and recursive prompt that will occupy the AI indefinitely or for a sufficiently long time that it acts as a Denial-of-Service (DoS) attack.  We describe how this works.]]></itunes:summary><itunes:duration>581</itunes:duration><itunes:keywords>ai (artificial intelligence)</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/63463b0769bfcfdb783b47db5c5eff0b.jpg"/><itunes:episode>628</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 627: UK vs Apple E2EE Backups</title><link>https://www.spreaker.com/episode/root-causes-627-uk-vs-apple-e2ee-backups--72465113</link><description><![CDATA[In the latest in our coverage of government versus encryption, the UK issued secret orders to Apple to give it a cryptographic backdoor to Apple's advanced data protection capability for iCloud.  Apple responded by eliminating encryption entirely for UK users.  We break it down.]]></description><guid isPermaLink="false">93710f87-229d-4a90-abed-e32ca39a4c65</guid><pubDate>Wed, 10 Jun 2026 19:20:59 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72465113/128_default_tc.mp3" length="4991887" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the latest in our coverage of government versus encryption, the UK issued secret orders to Apple to give it a cryptographic backdoor to Apple's advanced data protection capability for iCloud.  Apple responded by eliminating encryption entirely for...</itunes:subtitle><itunes:summary><![CDATA[In the latest in our coverage of government versus encryption, the UK issued secret orders to Apple to give it a cryptographic backdoor to Apple's advanced data protection capability for iCloud.  Apple responded by eliminating encryption entirely for UK users.  We break it down.]]></itunes:summary><itunes:duration>312</itunes:duration><itunes:keywords>government vs encryption</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/747fdb8ea09569924cc7108cf4d476c4.jpg"/><itunes:episode>627</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 626: TLS 1.3 Roadblock</title><link>https://www.spreaker.com/episode/root-causes-626-tls-1-3-roadblock--72418799</link><description><![CDATA[TLS 1.3 is required to take advantage of post quantum cryptography (PQC) algorithms. Yes, we still see a lot of TLS 1.2 or earlier in deployment. We examine why this is the case and what to do about it.]]></description><guid isPermaLink="false">f85dccda-7145-4dba-931c-2cdbb334446c</guid><pubDate>Mon, 08 Jun 2026 13:55:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72418799/128_default_tc.mp3" length="9841727" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>TLS 1.3 is required to take advantage of post quantum cryptography (PQC) algorithms. Yes, we still see a lot of TLS 1.2 or earlier in deployment. We examine why this is the case and what to do about it.</itunes:subtitle><itunes:summary><![CDATA[TLS 1.3 is required to take advantage of post quantum cryptography (PQC) algorithms. Yes, we still see a lot of TLS 1.2 or earlier in deployment. We examine why this is the case and what to do about it.]]></itunes:summary><itunes:duration>616</itunes:duration><itunes:keywords>post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cc8361fd59dce8728b875a37e65996f1.jpg"/><itunes:episode>626</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 625: AI in 1000 Days - Cyber Defense</title><link>https://www.spreaker.com/episode/root-causes-625-ai-in-1000-days-cyber-defense--72367443</link><description><![CDATA[Recent revelations about Mythos and its ability to expose vulnerabilities have forced us to rethink basic assumptions about cyber defense. In our "AI in 1000 Days" series, Jason Soroko and I examine the implications of these revelations three years from now.  This includes upping the overall pace of attack and changes to best practices in cyber security defense.]]></description><guid isPermaLink="false">1331b4a2-1540-42c6-9b03-3835c6b3b2ef</guid><pubDate>Fri, 05 Jun 2026 12:42:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72367443/128_default_tc.mp3" length="7788712" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent revelations about Mythos and its ability to expose vulnerabilities have forced us to rethink basic assumptions about cyber defense. In our "AI in 1000 Days" series, Jason Soroko and I examine the implications of these revelations three years...</itunes:subtitle><itunes:summary><![CDATA[Recent revelations about Mythos and its ability to expose vulnerabilities have forced us to rethink basic assumptions about cyber defense. In our "AI in 1000 Days" series, Jason Soroko and I examine the implications of these revelations three years from now.  This includes upping the overall pace of attack and changes to best practices in cyber security defense.]]></itunes:summary><itunes:duration>487</itunes:duration><itunes:keywords>ai (artificial intelligence),cybersecurity,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a510c2d87ac5085936cb8b72a7f10ac4.jpg"/><itunes:episode>625</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 624: Implications of Mythos</title><link>https://www.spreaker.com/episode/root-causes-624-implications-of-mythos--72321282</link><description><![CDATA[Anthropic has delayed its widespread release of Mythos to give major software providers a chance to close off the many vulnerabilities it has discovered.  We dig into the vast implications of Mythos and other AI models for the future of cybersecurity.]]></description><guid isPermaLink="false">538b2cc2-9a55-47d1-8c6f-b7b24f86733c</guid><pubDate>Wed, 03 Jun 2026 12:28:30 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72321282/128_default_tc.mp3" length="15319918" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Anthropic has delayed its widespread release of Mythos to give major software providers a chance to close off the many vulnerabilities it has discovered.  We dig into the vast implications of Mythos and other AI models for the future of cybersecurity.</itunes:subtitle><itunes:summary><![CDATA[Anthropic has delayed its widespread release of Mythos to give major software providers a chance to close off the many vulnerabilities it has discovered.  We dig into the vast implications of Mythos and other AI models for the future of cybersecurity.]]></itunes:summary><itunes:duration>958</itunes:duration><itunes:keywords>cybersecurity</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c4f8a35ea21fc087e1b37ed4ba4bb0d6.jpg"/><itunes:episode>624</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 623: Are PQC Key Sized Big Enough?</title><link>https://www.spreaker.com/episode/root-causes-623-are-pqc-key-sized-big-enough--72278676</link><description><![CDATA[We discuss the possibility that our standardized ML-DSA keys turn out to be too short for true confidence, why that might occur, and the implications for private PKI certificates.]]></description><guid isPermaLink="false">e6366d7d-15a9-49c2-91d6-cbb756686c22</guid><pubDate>Mon, 01 Jun 2026 13:30:55 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72278676/128_default_tc.mp3" length="8097976" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss the possibility that our standardized ML-DSA keys turn out to be too short for true confidence, why that might occur, and the implications for private PKI certificates.</itunes:subtitle><itunes:summary><![CDATA[We discuss the possibility that our standardized ML-DSA keys turn out to be too short for true confidence, why that might occur, and the implications for private PKI certificates.]]></itunes:summary><itunes:duration>506</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/69ea188dc9978297652e75bacaf75c24.jpg"/><itunes:episode>623</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 622: Modeling the Time to CRQC</title><link>https://www.spreaker.com/episode/root-causes-622-modeling-the-time-to-crqc--72226233</link><description><![CDATA[Sam Jaques joins us to explain his much-referenced chart mapping progress toward cryptographically relevant quantum computing (CRQC).]]></description><guid isPermaLink="false">5dcdfe67-dbf2-47bf-b49c-2607a7bbf095</guid><pubDate>Fri, 29 May 2026 13:50:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72226233/128_default_tc.mp3" length="14904885" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Sam Jaques joins us to explain his much-referenced chart mapping progress toward cryptographically relevant quantum computing (CRQC).</itunes:subtitle><itunes:summary><![CDATA[Sam Jaques joins us to explain his much-referenced chart mapping progress toward cryptographically relevant quantum computing (CRQC).]]></itunes:summary><itunes:duration>932</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc,pqrc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b081220614e8ec01aa87388f2614b7ed.jpg"/><itunes:episode>622</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 621: Simplicity at Scale</title><link>https://www.spreaker.com/episode/root-causes-621-simplicity-at-scale--72171530</link><description><![CDATA[We break down the phrase "Simplicity at Scale" to see what it means to us in the context of CAs and CLM.]]></description><guid isPermaLink="false">64875f38-7b5f-4388-be4e-ff3a89f2b104</guid><pubDate>Tue, 26 May 2026 15:44:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72171530/128_default_tc.mp3" length="4987105" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We break down the phrase "Simplicity at Scale" to see what it means to us in the context of CAs and CLM.</itunes:subtitle><itunes:summary><![CDATA[We break down the phrase "Simplicity at Scale" to see what it means to us in the context of CAs and CLM.]]></itunes:summary><itunes:duration>312</itunes:duration><itunes:keywords>clm,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/be24030a320c5cc76050c3126cb2cb30.jpg"/><itunes:episode>621</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 620: Will NIST Update Its PQC Timelines?</title><link>https://www.spreaker.com/episode/root-causes-620-will-nist-update-its-pqc-timelines--72118909</link><description><![CDATA[A few years ago NIST proposed deadlines for PQC deployment at 2030 and 2035. But recent announcements from Google and Cloudflare suggest 2029 as a better deprecation target.  We are joined by Dustin Moody to get the NIST perspective on these announcements.]]></description><guid isPermaLink="false">d9be8c81-94d0-425c-9288-6a81979418d5</guid><pubDate>Fri, 22 May 2026 18:06:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72118909/128_default_tc.mp3" length="9087832" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A few years ago NIST proposed deadlines for PQC deployment at 2030 and 2035. But recent announcements from Google and Cloudflare suggest 2029 as a better deprecation target.  We are joined by Dustin Moody to get the NIST perspective on these...</itunes:subtitle><itunes:summary><![CDATA[A few years ago NIST proposed deadlines for PQC deployment at 2030 and 2035. But recent announcements from Google and Cloudflare suggest 2029 as a better deprecation target.  We are joined by Dustin Moody to get the NIST perspective on these announcements.]]></itunes:summary><itunes:duration>568</itunes:duration><itunes:keywords>post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/db46f4ad4e7cde9116ce02b4197519d9.jpg"/><itunes:episode>620</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 619: Do We All Need to Adopt PQC by 2029?</title><link>https://www.spreaker.com/episode/root-causes-619-do-we-all-need-to-adopt-pqc-by-2029--72055469</link><description><![CDATA[Recent announcements from Google and Cloudflare have declared new 2029 deadlines for full post quantum cryptography (PQC) migration.  Bas Westerbaan explains the rationale behind Cloudflare's decision and discusses implications for other enterprises, asking "Are you a gambler?"]]></description><guid isPermaLink="false">cb0c3e22-a623-4145-a06f-1f3fc8274292</guid><pubDate>Mon, 18 May 2026 12:59:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72055469/128_default_tc.mp3" length="16364083" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent announcements from Google and Cloudflare have declared new 2029 deadlines for full post quantum cryptography (PQC) migration.  Bas Westerbaan explains the rationale behind Cloudflare's decision and discusses implications for other enterprises,...</itunes:subtitle><itunes:summary><![CDATA[Recent announcements from Google and Cloudflare have declared new 2029 deadlines for full post quantum cryptography (PQC) migration.  Bas Westerbaan explains the rationale behind Cloudflare's decision and discusses implications for other enterprises, asking "Are you a gambler?"]]></itunes:summary><itunes:duration>1023</itunes:duration><itunes:keywords>post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e167d9098033342e1dc450710e300881.jpg"/><itunes:episode>619</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 618: MTC and Private PKI</title><link>https://www.spreaker.com/episode/root-causes-618-mtc-and-private-pki--72023798</link><description><![CDATA[Repeat guest Bas Westerbaan of Cloudflare joins us to explore the role of Merkle Tree Certificates in private CA scenarios with an eye toward where they will be needed and where traditional PKI will be better suited.]]></description><guid isPermaLink="false">aa301fb1-708e-4065-938a-04c8cce3d621</guid><pubDate>Fri, 15 May 2026 17:43:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72023798/128_default_tc.mp3" length="15574140" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Bas Westerbaan of Cloudflare joins us to explore the role of Merkle Tree Certificates in private CA scenarios with an eye toward where they will be needed and where traditional PKI will be better suited.</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Bas Westerbaan of Cloudflare joins us to explore the role of Merkle Tree Certificates in private CA scenarios with an eye toward where they will be needed and where traditional PKI will be better suited.]]></itunes:summary><itunes:duration>974</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/53d003eaf8de0d95eda3d877987fe051.jpg"/><itunes:episode>618</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 617: What Are X9 Certificates?</title><link>https://www.spreaker.com/episode/root-causes-617-what-are-x9-certificates--71991316</link><description><![CDATA[The US-based X9 financial industry consortium has created a server certificate.  We explain what X9 certificates are and suitable use cases for this certificate type.]]></description><guid isPermaLink="false">b1fe59e4-2283-43d7-8151-ba991df33374</guid><pubDate>Wed, 13 May 2026 14:29:16 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71991316/128_default_tc.mp3" length="20685363" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The US-based X9 financial industry consortium has created a server certificate.  We explain what X9 certificates are and suitable use cases for this certificate type.</itunes:subtitle><itunes:summary><![CDATA[The US-based X9 financial industry consortium has created a server certificate.  We explain what X9 certificates are and suitable use cases for this certificate type.]]></itunes:summary><itunes:duration>1293</itunes:duration><itunes:keywords>x9 certificates</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3e8419c36bef8df4cbcf2b98381ae1b3.jpg"/><itunes:episode>617</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 616: NIST and Merkle Tree Certificates</title><link>https://www.spreaker.com/episode/root-causes-616-nist-and-merkle-tree-certificates--71956076</link><description><![CDATA[Dustin Moody of NIST joins us to discuss Merkle Tree Certificates (MTC) and the NIST position on them.]]></description><guid isPermaLink="false">cf91a97a-f03f-4c86-84ff-2c462b4f9ba8</guid><pubDate>Mon, 11 May 2026 12:04:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71956076/128_default_tc.mp3" length="6581330" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Dustin Moody of NIST joins us to discuss Merkle Tree Certificates (MTC) and the NIST position on them.</itunes:subtitle><itunes:summary><![CDATA[Dustin Moody of NIST joins us to discuss Merkle Tree Certificates (MTC) and the NIST position on them.]]></itunes:summary><itunes:duration>412</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b22f2a8ae71f53e21b8e5c6ee8b6dc0a.jpg"/><itunes:episode>616</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 615: What Is IETF PLANTS?</title><link>https://www.spreaker.com/episode/root-causes-615-what-is-ietf-plants--71922770</link><description><![CDATA[Repeat guest Bas Westerbaan of Cloudflare joins us to explain the PLANTS working group in IETF, which is driving standards around post quantum cryptography (PQC) and Merkle Tree Certificates (MTC). Bas explains the path to becoming a final standard, where we are in this process, and how you can get involved.]]></description><guid isPermaLink="false">c7cc4c4b-1fa5-4af6-b5f9-9c39fe4b9488</guid><pubDate>Fri, 08 May 2026 12:39:54 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71922770/128_default_tc.mp3" length="6314254" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Bas Westerbaan of Cloudflare joins us to explain the PLANTS working group in IETF, which is driving standards around post quantum cryptography (PQC) and Merkle Tree Certificates (MTC). Bas explains the path to becoming a final standard,...</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Bas Westerbaan of Cloudflare joins us to explain the PLANTS working group in IETF, which is driving standards around post quantum cryptography (PQC) and Merkle Tree Certificates (MTC). Bas explains the path to becoming a final standard, where we are in this process, and how you can get involved.]]></itunes:summary><itunes:duration>395</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e00f53078f8a23a3e04d9c150087a5a4.jpg"/><itunes:episode>615</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 614: MTC and Downgrade Attacks</title><link>https://www.spreaker.com/episode/root-causes-614-mtc-and-downgrade-attacks--71889453</link><description><![CDATA[It's reasonable to believe that Merkle Tree Certificates (MTC) and traditional RSA will co-exist on the same servers for years, if not decades, during the transition to post quantum cryptography (PQC). Bas Westerbaan of Cloudflare joins us in this episode to explore the possibility of quantum downgrade attacks and what we can do about them.]]></description><guid isPermaLink="false">14e542c3-ecce-4894-8c69-e57a4cd71490</guid><pubDate>Wed, 06 May 2026 12:09:30 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71889453/128_default_tc.mp3" length="11731841" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It's reasonable to believe that Merkle Tree Certificates (MTC) and traditional RSA will co-exist on the same servers for years, if not decades, during the transition to post quantum cryptography (PQC). Bas Westerbaan of Cloudflare joins us in this...</itunes:subtitle><itunes:summary><![CDATA[It's reasonable to believe that Merkle Tree Certificates (MTC) and traditional RSA will co-exist on the same servers for years, if not decades, during the transition to post quantum cryptography (PQC). Bas Westerbaan of Cloudflare joins us in this episode to explore the possibility of quantum downgrade attacks and what we can do about them.]]></itunes:summary><itunes:duration>733</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/fce3775547a8e44b3a6401f4d6a8b9ef.jpg"/><itunes:episode>614</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 613: Status of the NIST PQC Contests</title><link>https://www.spreaker.com/episode/root-causes-613-status-of-the-nist-pqc-contests--71856049</link><description><![CDATA[We are joined by Dustin Moody of NIST to go over the current state of the various post quantum cryptography (PQC) contests, including upcoming FIPS standards for Falcon (FN-DSA) and HQC, other Round 4 algorithms, the digital signing algorithm (DSA) On Ramp, isogeny, and future cryptographic exploration.]]></description><guid isPermaLink="false">d5af36fa-7db0-4a6a-8ba9-0709d1ff26ea</guid><pubDate>Mon, 04 May 2026 13:28:42 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71856049/128_default_tc.mp3" length="21669136" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are joined by Dustin Moody of NIST to go over the current state of the various post quantum cryptography (PQC) contests, including upcoming FIPS standards for Falcon (FN-DSA) and HQC, other Round 4 algorithms, the digital signing algorithm (DSA) On...</itunes:subtitle><itunes:summary><![CDATA[We are joined by Dustin Moody of NIST to go over the current state of the various post quantum cryptography (PQC) contests, including upcoming FIPS standards for Falcon (FN-DSA) and HQC, other Round 4 algorithms, the digital signing algorithm (DSA) On Ramp, isogeny, and future cryptographic exploration.]]></itunes:summary><itunes:duration>1355</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/18f227b4e27816d672a81891798b288b.jpg"/><itunes:episode>613</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 612: What Do Subscribers Need for MTC?</title><link>https://www.spreaker.com/episode/root-causes-612-what-do-subscribers-need-for-mtc--71814655</link><description><![CDATA[We are joined by Bas Westerbaan of Cloudflare to explain considerations and requirements for use of Merkle Tree Certificates (MTC). This includes full adoption of TLS 1.3, offering PQC and RSA at the same time, the imperative value of automation, and running production MTC in 2027.]]></description><guid isPermaLink="false">f1e6eacf-d762-4ee8-bcdd-44e58b0a152e</guid><pubDate>Fri, 01 May 2026 13:45:24 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71814655/128_default_tc.mp3" length="12225033" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are joined by Bas Westerbaan of Cloudflare to explain considerations and requirements for use of Merkle Tree Certificates (MTC). This includes full adoption of TLS 1.3, offering PQC and RSA at the same time, the imperative value of automation, and...</itunes:subtitle><itunes:summary><![CDATA[We are joined by Bas Westerbaan of Cloudflare to explain considerations and requirements for use of Merkle Tree Certificates (MTC). This includes full adoption of TLS 1.3, offering PQC and RSA at the same time, the imperative value of automation, and running production MTC in 2027.]]></itunes:summary><itunes:duration>764</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ab2792f93fd46d42e79d2a84bdeb7fcd.jpg"/><itunes:episode>612</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 611: Merkle Tree Certificates, What and Why</title><link>https://www.spreaker.com/episode/root-causes-611-merkle-tree-certificates-what-and-why--71733456</link><description><![CDATA[There are strong reasons to believe that the architecture of PQC TLS will take the form of Merkle Tree Certificates (MTC). We are joined by post quantum cryptography expert Bas Westerbaan of Cloudflare as he explains this new PKI architecture, how it works, and why we need it. We define new concepts like landmark certificates and log mirrors and discuss what's necessary to move to this new architecture.]]></description><guid isPermaLink="false">05207a23-8f97-4490-965b-48c954421b29</guid><pubDate>Wed, 29 Apr 2026 14:04:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71733456/128_default_tc.mp3" length="22683105" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>There are strong reasons to believe that the architecture of PQC TLS will take the form of Merkle Tree Certificates (MTC). We are joined by post quantum cryptography expert Bas Westerbaan of Cloudflare as he explains this new PKI architecture, how it...</itunes:subtitle><itunes:summary><![CDATA[There are strong reasons to believe that the architecture of PQC TLS will take the form of Merkle Tree Certificates (MTC). We are joined by post quantum cryptography expert Bas Westerbaan of Cloudflare as he explains this new PKI architecture, how it works, and why we need it. We define new concepts like landmark certificates and log mirrors and discuss what's necessary to move to this new architecture.]]></itunes:summary><itunes:duration>1418</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9925be219e9f02c4d35e7ee5fe7ff5bc.jpg"/><itunes:episode>611</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 610: Types of Logical Qubits</title><link>https://www.spreaker.com/episode/root-causes-610-types-of-logical-qubits--71671992</link><description><![CDATA[We describe three different kinds of logical qubits with their relative strengths and weaknesses.]]></description><guid isPermaLink="false">871cfe48-3379-4eef-ae44-3e082e7df4b3</guid><pubDate>Mon, 27 Apr 2026 12:53:21 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71671992/128_default_tc.mp3" length="9621463" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We describe three different kinds of logical qubits with their relative strengths and weaknesses.</itunes:subtitle><itunes:summary><![CDATA[We describe three different kinds of logical qubits with their relative strengths and weaknesses.]]></itunes:summary><itunes:duration>602</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f60d02efa610cdb8a866a48615ac0ecc.jpg"/><itunes:episode>610</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 609: Side Channel Apocalypse</title><link>https://www.spreaker.com/episode/root-causes-609-side-channel-apocalypse--71617069</link><description><![CDATA[Jason explains the extreme danger of side channel attacks in the new post quantum cryptography (PQC) era.]]></description><guid isPermaLink="false">333cf350-3a9f-4370-a982-7b9b96b00348</guid><pubDate>Fri, 24 Apr 2026 17:05:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71617069/128_default_tc.mp3" length="6556986" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason explains the extreme danger of side channel attacks in the new post quantum cryptography (PQC) era.</itunes:subtitle><itunes:summary><![CDATA[Jason explains the extreme danger of side channel attacks in the new post quantum cryptography (PQC) era.]]></itunes:summary><itunes:duration>410</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ab04ae8df898ca204e548663bd477ea5.jpg"/><itunes:episode>609</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 608: The Fragility of Formal Verification</title><link>https://www.spreaker.com/episode/root-causes-608-the-fragility-of-formal-verification--71560981</link><description><![CDATA[The reliability of cryptographic algorithms is largely a matter of conjecture based on track record. Proving security is impaired by the difficulty of formal verification, implementation weaknesses, and failure in randomness.]]></description><guid isPermaLink="false">fff123b7-2b5b-4392-a4ba-f8d3655a37b9</guid><pubDate>Wed, 22 Apr 2026 14:21:22 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71560981/128_default_tc.mp3" length="7551311" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The reliability of cryptographic algorithms is largely a matter of conjecture based on track record. Proving security is impaired by the difficulty of formal verification, implementation weaknesses, and failure in randomness.</itunes:subtitle><itunes:summary><![CDATA[The reliability of cryptographic algorithms is largely a matter of conjecture based on track record. Proving security is impaired by the difficulty of formal verification, implementation weaknesses, and failure in randomness.]]></itunes:summary><itunes:duration>472</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/080c2ea4462c3cdb5b4502bb9df5852e.jpg"/><itunes:episode>608</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 607: PKI That's Hard to Discover</title><link>https://www.spreaker.com/episode/root-causes-607-pki-that-s-hard-to-discover--71492598</link><description><![CDATA[The first of the five pillars of Certificate Lifecycle Management (CLM) is discovery.  While many of your certificates are easily discoverable, some difficult PKI remains.]]></description><guid isPermaLink="false">d763c100-eb37-4703-8e08-fd78750a7ecb</guid><pubDate>Mon, 20 Apr 2026 13:23:30 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71492598/128_default_tc.mp3" length="7669176" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The first of the five pillars of Certificate Lifecycle Management (CLM) is discovery.  While many of your certificates are easily discoverable, some difficult PKI remains.</itunes:subtitle><itunes:summary><![CDATA[The first of the five pillars of Certificate Lifecycle Management (CLM) is discovery.  While many of your certificates are easily discoverable, some difficult PKI remains.]]></itunes:summary><itunes:duration>480</itunes:duration><itunes:keywords>certificate lifecycle manageme,clm,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5fae8d8ebad7af7aca49b05ad506f590.jpg"/><itunes:episode>607</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 606: What Is the UK Online Safety Act?</title><link>https://www.spreaker.com/episode/root-causes-606-what-is-the-uk-online-safety-act--71411024</link><description><![CDATA[The UK Online Safety Act intends to force vendors who sell hardware and software to allow the government to scan end-to-end encrypted communication on end devices. We once again marvel at governments seeking to undermine the security of their own citizens.]]></description><guid isPermaLink="false">8af7c208-751c-4d47-8424-fc1b618fe840</guid><pubDate>Fri, 17 Apr 2026 15:16:16 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71411024/128_default_tc.mp3" length="5923778" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The UK Online Safety Act intends to force vendors who sell hardware and software to allow the government to scan end-to-end encrypted communication on end devices. We once again marvel at governments seeking to undermine the security of their own...</itunes:subtitle><itunes:summary><![CDATA[The UK Online Safety Act intends to force vendors who sell hardware and software to allow the government to scan end-to-end encrypted communication on end devices. We once again marvel at governments seeking to undermine the security of their own citizens.]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>encryption,pki,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/191b9279b14d3e52f7fbd345c9f63361.jpg"/><itunes:episode>606</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 605: Chrome Declares Its Support for Merkle Tree Certificates (MTC)</title><link>https://www.spreaker.com/episode/root-causes-605-chrome-declares-its-support-for-merkle-tree-certificates-mtc--71344436</link><description><![CDATA[Google has taken a strong position supporting Merkle Tree Certificates (MTC) as the PQC-enabled future for SSL / TLS. We unpack this extremely important position from the WebPKI's most influential organization.]]></description><guid isPermaLink="false">19e43b6c-effb-4576-9911-58620268a666</guid><pubDate>Wed, 15 Apr 2026 13:54:43 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71344436/128_default_tc.mp3" length="8917620" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Google has taken a strong position supporting Merkle Tree Certificates (MTC) as the PQC-enabled future for SSL / TLS. We unpack this extremely important position from the WebPKI's most influential organization.</itunes:subtitle><itunes:summary><![CDATA[Google has taken a strong position supporting Merkle Tree Certificates (MTC) as the PQC-enabled future for SSL / TLS. We unpack this extremely important position from the WebPKI's most influential organization.]]></itunes:summary><itunes:duration>558</itunes:duration><itunes:keywords>merkle tree certificates (mtc),post quantum cryptography (pqc,ssl / tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/47b4e37d22824a41f2e817555f1c3d7c.jpg"/><itunes:episode>605</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 604: Accelerated Timeline for Quantum Computers Breaking ECC in Crypto and Blockchain</title><link>https://www.spreaker.com/episode/root-causes-604-accelerated-timeline-for-quantum-computers-breaking-ecc-in-crypto-and-blockchain--71292335</link><description><![CDATA[A new paper from Google Quantum AI and others documents a new technique for breaking ECC, particularly the curve protecting crypto currencies, smart contracts, and blockchain.  This accelerates post quantum cryptography (PQC) timelines.]]></description><guid isPermaLink="false">d1a0f6e6-2acd-483a-bd99-776d3e58cded</guid><pubDate>Mon, 13 Apr 2026 14:56:56 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71292335/128_default_tc.mp3" length="10706903" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new paper from Google Quantum AI and others documents a new technique for breaking ECC, particularly the curve protecting crypto currencies, smart contracts, and blockchain.  This accelerates post quantum cryptography (PQC) timelines.</itunes:subtitle><itunes:summary><![CDATA[A new paper from Google Quantum AI and others documents a new technique for breaking ECC, particularly the curve protecting crypto currencies, smart contracts, and blockchain.  This accelerates post quantum cryptography (PQC) timelines.]]></itunes:summary><itunes:duration>670</itunes:duration><itunes:keywords>blockchain,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ec7d1026f8a2c7c63e9a77850f9aadbc.jpg"/><itunes:episode>604</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 603: Cryptographically Relevant Quantum Computing (CRQC) with Only 10,000 Qubits</title><link>https://www.spreaker.com/episode/root-causes-603-cryptographically-relevant-quantum-computing-crqc-with-only-10-000-qubits--71238950</link><description><![CDATA[New research suggests that a cryptographically relevant quantum computer is achievable with only 10,000 qubits. This was an important contributor to Google moving its PQC target to 2029.]]></description><guid isPermaLink="false">9593d1f8-dba2-4a6a-8f9d-930fefd5118d</guid><pubDate>Fri, 10 Apr 2026 19:09:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71238950/128_default_tc.mp3" length="9060562" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>New research suggests that a cryptographically relevant quantum computer is achievable with only 10,000 qubits. This was an important contributor to Google moving its PQC target to 2029.</itunes:subtitle><itunes:summary><![CDATA[New research suggests that a cryptographically relevant quantum computer is achievable with only 10,000 qubits. This was an important contributor to Google moving its PQC target to 2029.]]></itunes:summary><itunes:duration>567</itunes:duration><itunes:keywords>crqc,cryptography,pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d69c982931a34f88f3da4a4a91a0a532.jpg"/><itunes:episode>603</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 602: Google Moves the PQC Date Forward to 2029</title><link>https://www.spreaker.com/episode/root-causes-602-google-moves-the-pqc-date-forward-to-2029--71187936</link><description><![CDATA[Google has announced that it is moving its target for full PQC support to 2029.  This is a strong statement from one of the most knowledgeable PQC technology companies that the existing 2030 target is too late.]]></description><guid isPermaLink="false">5e22447c-2490-45df-bda4-828b6c4a3fb9</guid><pubDate>Wed, 08 Apr 2026 15:21:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71187936/128_default_tc.mp3" length="12474034" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Google has announced that it is moving its target for full PQC support to 2029.  This is a strong statement from one of the most knowledgeable PQC technology companies that the existing 2030 target is too late.</itunes:subtitle><itunes:summary><![CDATA[Google has announced that it is moving its target for full PQC support to 2029.  This is a strong statement from one of the most knowledgeable PQC technology companies that the existing 2030 target is too late.]]></itunes:summary><itunes:duration>780</itunes:duration><itunes:keywords>cryptography,pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4d8fd53c12d8230533574051ae65a3f4.jpg"/><itunes:episode>602</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 601: The Zombie in the Server Room</title><link>https://www.spreaker.com/episode/root-causes-601-the-zombie-in-the-server-room--71133100</link><description><![CDATA[Legacy PKI implementations in the enterprise are holding back technical progress and creating security risk.  We discuss reasons why, consequences, and what to do about it.]]></description><guid isPermaLink="false">5d702f2f-375c-4f5d-a8bd-876bc2607f8b</guid><pubDate>Mon, 06 Apr 2026 13:22:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71133100/128_default_tc.mp3" length="6573705" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Legacy PKI implementations in the enterprise are holding back technical progress and creating security risk.  We discuss reasons why, consequences, and what to do about it.</itunes:subtitle><itunes:summary><![CDATA[Legacy PKI implementations in the enterprise are holding back technical progress and creating security risk.  We discuss reasons why, consequences, and what to do about it.]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/539ba0917e89616a367dc2e84934beb4.jpg"/><itunes:episode>601</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 600: Cryptographic Design Is Not Neutral</title><link>https://www.spreaker.com/episode/root-causes-600-cryptographic-design-is-not-neutral--71082316</link><description><![CDATA[In our previous episode we defined cryptography as the new geopolitics.  Now in our 600th episode we follow up to explain how all cryptographic decisions reflect the social, political, and legal viewpoints of the cryptography's designers.]]></description><guid isPermaLink="false">b2264648-a5d2-48ef-a438-be700a32b123</guid><pubDate>Fri, 03 Apr 2026 12:11:41 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71082316/128_default_tc.mp3" length="9911527" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our previous episode we defined cryptography as the new geopolitics.  Now in our 600th episode we follow up to explain how all cryptographic decisions reflect the social, political, and legal viewpoints of the cryptography's designers.</itunes:subtitle><itunes:summary><![CDATA[In our previous episode we defined cryptography as the new geopolitics.  Now in our 600th episode we follow up to explain how all cryptographic decisions reflect the social, political, and legal viewpoints of the cryptography's designers.]]></itunes:summary><itunes:duration>620</itunes:duration><itunes:keywords>cryptography,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a80be94aeff882d40b660939b5228639.jpg"/><itunes:episode>600</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 599: Cryptography Is the New Geopolitics</title><link>https://www.spreaker.com/episode/root-causes-599-cryptography-is-the-new-geopolitics--71044417</link><description><![CDATA[In the last decade or so, nations around the world have become keenly determined to use cryptography for their own legal, economic, and military advantage.  We explore this concept.]]></description><guid isPermaLink="false">23f7d75b-929c-4323-992f-bf5b09d6185f</guid><pubDate>Wed, 01 Apr 2026 13:44:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71044417/128_default_tc.mp3" length="10231683" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the last decade or so, nations around the world have become keenly determined to use cryptography for their own legal, economic, and military advantage.  We explore this concept.</itunes:subtitle><itunes:summary><![CDATA[In the last decade or so, nations around the world have become keenly determined to use cryptography for their own legal, economic, and military advantage.  We explore this concept.]]></itunes:summary><itunes:duration>640</itunes:duration><itunes:keywords>cryptography,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/335cc07f020b41976bb00d43b131a448.jpg"/><itunes:episode>599</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 598: Why Johnny Can't authN in OT</title><link>https://www.spreaker.com/episode/root-causes-598-why-johnny-can-t-authn-in-ot--71003642</link><description><![CDATA[A recent CISA report declares that the nation's OT infrastructure is incapable of keeping up with the crypto agility and certificate management needs that modern security demands.  We examine this finding.]]></description><guid isPermaLink="false">950b1ea3-ded0-4bc7-a2d5-3b9af3f132ff</guid><pubDate>Mon, 30 Mar 2026 17:25:50 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71003642/128_default_tc.mp3" length="7602720" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent CISA report declares that the nation's OT infrastructure is incapable of keeping up with the crypto agility and certificate management needs that modern security demands.  We examine this finding.</itunes:subtitle><itunes:summary><![CDATA[A recent CISA report declares that the nation's OT infrastructure is incapable of keeping up with the crypto agility and certificate management needs that modern security demands.  We examine this finding.]]></itunes:summary><itunes:duration>476</itunes:duration><itunes:keywords>pki,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0836f4eea5d1ee7fad5233ac8d2a1128.jpg"/><itunes:episode>598</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 597: If You Don't Hold the Keys, You Don't Hold the Subpoenas</title><link>https://www.spreaker.com/episode/root-causes-597-if-you-don-t-hold-the-keys-you-don-t-hold-the-subpoenas--70928064</link><description><![CDATA[Microsoft has publicly stated that it will hand over Bitlocker keys to US law enforcement agencies without requiring a subpoena or court order. These keys can be held by users rather than Microsoft, at their option. We dive into this topic.]]></description><guid isPermaLink="false">b06362c5-f1d5-46f2-87f0-13ebda5dd3ef</guid><pubDate>Fri, 27 Mar 2026 14:47:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70928064/128_default_tc.mp3" length="7140875" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Microsoft has publicly stated that it will hand over Bitlocker keys to US law enforcement agencies without requiring a subpoena or court order. These keys can be held by users rather than Microsoft, at their option. We dive into this topic.</itunes:subtitle><itunes:summary><![CDATA[Microsoft has publicly stated that it will hand over Bitlocker keys to US law enforcement agencies without requiring a subpoena or court order. These keys can be held by users rather than Microsoft, at their option. We dive into this topic.]]></itunes:summary><itunes:duration>447</itunes:duration><itunes:keywords>encryption,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f3c1ee62176c177be4de6aea569408d8.jpg"/><itunes:episode>597</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 596: CLM and Operational Uptime</title><link>https://www.spreaker.com/episode/root-causes-596-clm-and-operational-uptime--70872627</link><description><![CDATA[We usually think of Certificate Lifecycle Management (CLM) as a security category. But we could equally well categorize it as an operations category that enables uptime. In this episode we make our case.]]></description><guid isPermaLink="false">5495476b-4373-4b34-9b55-b44c247b969c</guid><pubDate>Wed, 25 Mar 2026 13:21:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70872627/128_default_tc.mp3" length="6459184" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We usually think of Certificate Lifecycle Management (CLM) as a security category. But we could equally well categorize it as an operations category that enables uptime. In this episode we make our case.</itunes:subtitle><itunes:summary><![CDATA[We usually think of Certificate Lifecycle Management (CLM) as a security category. But we could equally well categorize it as an operations category that enables uptime. In this episode we make our case.]]></itunes:summary><itunes:duration>404</itunes:duration><itunes:keywords>certificate lifecycle manageme,clm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d513bbe6b6b3bcd2ca52d11db5685656.jpg"/><itunes:episode>596</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 595: What Is a Digital Parasite?</title><link>https://www.spreaker.com/episode/root-causes-595-what-is-a-digital-parasite--70829993</link><description><![CDATA[We introduce the concept of a "digital parasite," explaining why this attack philosophy appears to be on the rise.]]></description><guid isPermaLink="false">7d447100-dade-45d2-83f2-c269f12a6d6d</guid><pubDate>Mon, 23 Mar 2026 13:42:55 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70829993/128_default_tc.mp3" length="12002158" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We introduce the concept of a "digital parasite," explaining why this attack philosophy appears to be on the rise.</itunes:subtitle><itunes:summary><![CDATA[We introduce the concept of a "digital parasite," explaining why this attack philosophy appears to be on the rise.]]></itunes:summary><itunes:duration>751</itunes:duration><itunes:keywords>pki,ransomware,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4cdc6c7b4cbabbcea6c606ec0cea63a1.jpg"/><itunes:episode>595</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 594: Google's Five PQC Recommendations for Policy Makers</title><link>https://www.spreaker.com/episode/root-causes-594-google-s-five-pqc-recommendations-for-policy-makers--70725613</link><description><![CDATA[In a recent blog post Google made five recommendations for policy makers.  We walk down the list.]]></description><guid isPermaLink="false">6101dcb8-b004-45bc-8414-c46c22f2a4ae</guid><pubDate>Wed, 18 Mar 2026 21:04:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70725613/128_default_tc.mp3" length="16279971" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In a recent blog post Google made five recommendations for policy makers.  We walk down the list.</itunes:subtitle><itunes:summary><![CDATA[In a recent blog post Google made five recommendations for policy makers.  We walk down the list.]]></itunes:summary><itunes:duration>1018</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/fe2241a8c5452ea218ede24875165fc6.jpg"/><itunes:episode>594</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 592: When a CAA Record Outlives the CA</title><link>https://www.spreaker.com/episode/root-causes-592-when-a-caa-record-outlives-the-ca--70619663</link><description><![CDATA[CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out.]]></description><guid isPermaLink="false">8d58fda5-6e60-4f82-afc7-60a078a4b2ab</guid><pubDate>Fri, 13 Mar 2026 08:20:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70619663/128_default_tc.mp3" length="8391827" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out.</itunes:subtitle><itunes:summary><![CDATA[CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out.]]></itunes:summary><itunes:duration>525</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/dad080c083a5506182d1fb0c4642eb54.jpg"/><itunes:episode>592</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 593: New PQC Guidance from CISA</title><link>https://www.spreaker.com/episode/root-causes-593-new-pqc-guidance-from-cisa--70648618</link><guid isPermaLink="false">155af289-cf61-4459-85b8-0f910a201726</guid><pubDate>Wed, 11 Mar 2026 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70648618/128_default_tc.mp3" length="16279971" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:duration>1018</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7875aa53b3b6a11c98fa06f704181019.jpg"/><itunes:episode>593</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 591: Client Authentication Deprecation Date Moves Out</title><link>https://www.spreaker.com/episode/root-causes-591-client-authentication-deprecation-date-moves-out--70590333</link><guid isPermaLink="false">8d9586e7-7e6e-4cd8-979d-6d6923e3e79b</guid><pubDate>Wed, 11 Mar 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70590333/128_default_tc.mp3" length="11315008" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:duration>707</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/145663157923c8becc42063122680e47.jpg"/><itunes:episode>591</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 590: The Size of the CA Is Not the Size of the Risk</title><link>https://www.spreaker.com/episode/root-causes-590-the-size-of-the-ca-is-not-the-size-of-the-risk--70559028</link><description><![CDATA[It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has.  This is false, however.  In this episode we address this misconception.]]></description><guid isPermaLink="false">f061afd8-82ba-464a-9c5a-51d8e42dface</guid><pubDate>Tue, 10 Mar 2026 01:05:31 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70559028/128_default_tc.mp3" length="7031761" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has.  This is false, however.  In this episode we address this misconception.</itunes:subtitle><itunes:summary><![CDATA[It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has.  This is false, however.  In this episode we address this misconception.]]></itunes:summary><itunes:duration>440</itunes:duration><itunes:keywords>digital certificates,pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/fccc2acae2e91dba091881e6cbeada85.jpg"/><itunes:episode>590</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 589: Is a Cryptographically Relevant Quantum Computer Economically Viable?</title><link>https://www.spreaker.com/episode/root-causes-589-is-a-cryptographically-relevant-quantum-computer-economically-viable--70509798</link><description><![CDATA[We recently heard the argument that it's simply too expensive to develop a cryptographically relevant quantum computer. We vehemently disagree. In this episode we explain why.]]></description><guid isPermaLink="false">cbc77048-8288-4f54-9cdc-9335755a1506</guid><pubDate>Fri, 06 Mar 2026 16:45:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70509798/128_default_tc.mp3" length="9207683" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We recently heard the argument that it's simply too expensive to develop a cryptographically relevant quantum computer. We vehemently disagree. In this episode we explain why.</itunes:subtitle><itunes:summary><![CDATA[We recently heard the argument that it's simply too expensive to develop a cryptographically relevant quantum computer. We vehemently disagree. In this episode we explain why.]]></itunes:summary><itunes:duration>576</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f3c6edd3f3fb7df2e785367f42490d3c.jpg"/><itunes:episode>589</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 588: It's Cryptographic Frogger from Here on Out</title><link>https://www.spreaker.com/episode/root-causes-588-it-s-cryptographic-frogger-from-here-on-out--70447363</link><description><![CDATA[In this episode Tim explains that the transition to PQC is not just a change in cryptographic algorithms but also a fundamental shift in how we treat our cryptography.  From here on out, IT systems need to be fundamentally crypto agile in a way we've never had to be before.]]></description><guid isPermaLink="false">3dc4b1a2-4497-4b0b-9d8c-9d60ac1b3a61</guid><pubDate>Wed, 04 Mar 2026 17:49:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70447363/128_default_tc.mp3" length="9521153" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode Tim explains that the transition to PQC is not just a change in cryptographic algorithms but also a fundamental shift in how we treat our cryptography.  From here on out, IT systems need to be fundamentally crypto agile in a way we've...</itunes:subtitle><itunes:summary><![CDATA[In this episode Tim explains that the transition to PQC is not just a change in cryptographic algorithms but also a fundamental shift in how we treat our cryptography.  From here on out, IT systems need to be fundamentally crypto agile in a way we've never had to be before.]]></itunes:summary><itunes:duration>596</itunes:duration><itunes:keywords>cryptography,post quantum cryptography (pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f7afbafc5ebc69e4a82ceaa1f7e2e727.jpg"/><itunes:episode>588</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 587: AI Orchestration for Attackers</title><link>https://www.spreaker.com/episode/root-causes-587-ai-orchestration-for-attackers--70393038</link><description><![CDATA[Jason describes a recent intrusion almost entirely operated by off-the-shelf AI tools.  This is an important milestone in security.  We describe its potential consequences.]]></description><guid isPermaLink="false">19149935-822e-4ae4-89ad-c03712b9640b</guid><pubDate>Mon, 02 Mar 2026 17:47:58 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70393038/128_default_tc.mp3" length="10489982" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason describes a recent intrusion almost entirely operated by off-the-shelf AI tools.  This is an important milestone in security.  We describe its potential consequences.</itunes:subtitle><itunes:summary><![CDATA[Jason describes a recent intrusion almost entirely operated by off-the-shelf AI tools.  This is an important milestone in security.  We describe its potential consequences.]]></itunes:summary><itunes:duration>656</itunes:duration><itunes:keywords>ai</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f7afbafc5ebc69e4a82ceaa1f7e2e727.jpg"/><itunes:episode>587</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 586: Beyond Harvest Now Decrypt Later</title><link>https://www.spreaker.com/episode/root-causes-586-beyond-harvest-now-decrypt-later--70329970</link><description><![CDATA[We expand on the concept of trust-now-forge-later to list a whole bevy of additional attacks that eventually will be enabled by cryptographically relevant quantum computers.]]></description><guid isPermaLink="false">fe886c96-068e-47f4-85d4-18086b85fd81</guid><pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329970/128_default_tc.mp3" length="8317430" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We expand on the concept of trust-now-forge-later to list a whole bevy of additional attacks that eventually will be enabled by cryptographically relevant quantum computers.</itunes:subtitle><itunes:summary><![CDATA[We expand on the concept of trust-now-forge-later to list a whole bevy of additional attacks that eventually will be enabled by cryptographically relevant quantum computers.]]></itunes:summary><itunes:duration>520</itunes:duration><itunes:keywords>pki,post quantum cryptography (pqc,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f7afbafc5ebc69e4a82ceaa1f7e2e727.jpg"/><itunes:episode>586</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 585: The Cryptographic Inventory Manifesto</title><link>https://www.spreaker.com/episode/root-causes-585-the-cryptographic-inventory-manifesto--70329974</link><description><![CDATA[We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.]]></description><guid isPermaLink="false">ddafde8b-ad4b-42ae-9245-28c2fcc37993</guid><pubDate>Wed, 25 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329974/128_default_tc.mp3" length="8558593" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.</itunes:subtitle><itunes:summary><![CDATA[We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.]]></itunes:summary><itunes:duration>535</itunes:duration><itunes:keywords>cryptographic inventory,cryptography,cybersecurity,digital certificates,pqc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/15c061b1dc290c7ea7fc36197565e271.jpg"/><itunes:episode>585</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 585: The Cryptographic Inventory Manifesto</title><link>https://www.spreaker.com/episode/root-causes-585-the-cryptographic-inventory-manifesto--70271715</link><description><![CDATA[We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2273198534</guid><pubDate>Tue, 24 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70271715/2273198534_tim_callan_root_causes_585_the_cryptographic_inventory_manifesto.mp3" length="17117184" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.</itunes:subtitle><itunes:summary><![CDATA[We all love a good manifesto! Jason spells out the ten principles of the Cryptographic Inventory Manifesto, and we discuss.]]></itunes:summary><itunes:duration>535</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 584: Mapping DORA to CLM</title><link>https://www.spreaker.com/episode/root-causes-584-mapping-dora-to-clm--70329968</link><description><![CDATA[We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are.]]></description><guid isPermaLink="false">b2b5c67f-8c87-422c-859e-11733e3b3b83</guid><pubDate>Mon, 23 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329968/128_default_tc.mp3" length="19815044" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are.</itunes:subtitle><itunes:summary><![CDATA[We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are.]]></itunes:summary><itunes:duration>1239</itunes:duration><itunes:keywords>certificate lifecycle manageme,certificate lifespans,dora,european standard,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3e224fe4f9342f3cc752818bb6fb44e7.jpg"/><itunes:episode>584</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 584: Mapping DORA to CLM</title><link>https://www.spreaker.com/episode/root-causes-584-mapping-dora-to-clm--70237160</link><description><![CDATA[We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements.  You will be surprised how explicit these requirements are.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2272069802</guid><pubDate>Mon, 23 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70237160/2272069802_tim_callan_root_causes_584_mapping_dora.mp3" length="29722005" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements.  You will be surprised how explicit these requirements are.</itunes:subtitle><itunes:summary><![CDATA[We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements.  You will be surprised how explicit these requirements are.]]></itunes:summary><itunes:duration>1239</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 583: AI Versus ECC P 256</title><link>https://www.spreaker.com/episode/root-causes-583-ai-versus-ecc-p-256--70185749</link><description><![CDATA[In an innovative application, an AI has been used to find private keys for ECC (Elliptic Curve Cryptography) P 256.  We explain how.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2270589410</guid><pubDate>Sat, 21 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70185749/2270589410_tim_callan_root_causes_583_ai_versus_ecc.mp3" length="15644565" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In an innovative application, an AI has been used to find private keys for ECC (Elliptic Curve Cryptography) P 256.  We explain how.</itunes:subtitle><itunes:summary><![CDATA[In an innovative application, an AI has been used to find private keys for ECC (Elliptic Curve Cryptography) P 256.  We explain how.]]></itunes:summary><itunes:duration>652</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 583: AI Versus ECC P 256</title><link>https://www.spreaker.com/episode/root-causes-583-ai-versus-ecc-p-256--70329991</link><description><![CDATA[Recorded in Ottawa Ontario.]]></description><guid isPermaLink="false">3108d037-52b8-488a-9bd3-bf1c3c79e2e9</guid><pubDate>Fri, 20 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329991/128_default_tc.mp3" length="10426568" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recorded in Ottawa Ontario.</itunes:subtitle><itunes:summary><![CDATA[Recorded in Ottawa Ontario.]]></itunes:summary><itunes:duration>652</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>583</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 582: New Research Drastically Cuts Number of Qubits for Cryptographic Relevance</title><link>https://www.spreaker.com/episode/root-causes-582-new-research-drastically-cuts-number-of-qubits-for-cryptographic-relevance--70134740</link><description><![CDATA[New research indicates that the number of qubits necessary to achieve cryptographic relevance has reduced by two orders of magnitude.  We cover this breaking news and its implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2268884726</guid><pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70134740/2268884726_tim_callan_root_causes_582_research_cuts_qubits_cryptographic_relevance.mp3" length="20453431" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>New research indicates that the number of qubits necessary to achieve cryptographic relevance has reduced by two orders of magnitude.  We cover this breaking news and its implications.</itunes:subtitle><itunes:summary><![CDATA[New research indicates that the number of qubits necessary to achieve cryptographic relevance has reduced by two orders of magnitude.  We cover this breaking news and its implications.]]></itunes:summary><itunes:duration>852</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 581: A Timeline for Deprecation of Manual DCV Methods</title><link>https://www.spreaker.com/episode/root-causes-581-a-timeline-for-deprecation-of-manual-dcv-methods--70084135</link><description><![CDATA[By CABF ballot all manual methods of Domain Control Validation (DCV) will be deprecated by 2028.  We explain which methods are due for deprecation and when.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2267697077</guid><pubDate>Sun, 15 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70084135/2267697077_tim_callan_root_causes_581_a_timeline_for_deprecation_of_manual_dcv_methods.mp3" length="25249536" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>By CABF ballot all manual methods of Domain Control Validation (DCV) will be deprecated by 2028.  We explain which methods are due for deprecation and when.</itunes:subtitle><itunes:summary><![CDATA[By CABF ballot all manual methods of Domain Control Validation (DCV) will be deprecated by 2028.  We explain which methods are due for deprecation and when.]]></itunes:summary><itunes:duration>790</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 580: Top Use Cases for Hybrid Certificates</title><link>https://www.spreaker.com/episode/root-causes-580-top-use-cases-for-hybrid-certificates--70047880</link><description><![CDATA[We go over the qualities in abstract of a use case that strongly invites the use of hybrid certificates and then run down a list of specific use cases that meet these criteria.  This includes OT systems, code signing, secure boot, WiFi, enterprise S/MIME, and more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2266121072</guid><pubDate>Fri, 13 Feb 2026 20:01:25 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70047880/2266121072_tim_callan_root_causes_580_top_use_cases_for_hybrid_certificates.mp3" length="24570624" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We go over the qualities in abstract of a use case that strongly invites the use of hybrid certificates and then run down a list of specific use cases that meet these criteria.  This includes OT systems, code signing, secure boot, WiFi, enterprise...</itunes:subtitle><itunes:summary><![CDATA[We go over the qualities in abstract of a use case that strongly invites the use of hybrid certificates and then run down a list of specific use cases that meet these criteria.  This includes OT systems, code signing, secure boot, WiFi, enterprise S/MIME, and more.]]></itunes:summary><itunes:duration>768</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 579: Make Cryptography Boring Again</title><link>https://www.spreaker.com/episode/root-causes-579-make-cryptography-boring-again--69975138</link><description><![CDATA[In this episode Jason declares that we must make cryptography boring again.  We get into what that means and why it matters.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2264552567</guid><pubDate>Tue, 10 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69975138/2264552567_tim_callan_root_causes_579_make_cryptography_boring_again.mp3" length="34066176" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode Jason declares that we must make cryptography boring again.  We get into what that means and why it matters.</itunes:subtitle><itunes:summary><![CDATA[In this episode Jason declares that we must make cryptography boring again.  We get into what that means and why it matters.]]></itunes:summary><itunes:duration>1065</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 578: 200 Days Won't Actually Be 200 Days</title><link>https://www.spreaker.com/episode/root-causes-578-200-days-won-t-actually-be-200-days--69892400</link><description><![CDATA[We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days.  It happens that all those numbers are too large and the actual maxima will be less than that.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2263198439</guid><pubDate>Mon, 09 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69892400/2263198439_tim_callan_root_causes_578_200_days_wont.mp3" length="19541760" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days.  It happens that all those numbers are too large and the actual maxima will be less than that.  We explain.</itunes:subtitle><itunes:summary><![CDATA[We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days.  It happens that all those numbers are too large and the actual maxima will be less than that.  We explain.]]></itunes:summary><itunes:duration>611</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 577: All the Stuff That's Coming in March</title><link>https://www.spreaker.com/episode/root-causes-577-all-the-stuff-that-s-coming-in-march--69850440</link><description><![CDATA[March 2026 is due to be the most eventful month in the history of the WebPKI.  Join us as we go over all the many changes coming next month.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2261621081</guid><pubDate>Fri, 06 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69850440/2261621081_tim_callan_root_causes_577_all_the_stuff.mp3" length="19382016" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>March 2026 is due to be the most eventful month in the history of the WebPKI.  Join us as we go over all the many changes coming next month.</itunes:subtitle><itunes:summary><![CDATA[March 2026 is due to be the most eventful month in the history of the WebPKI.  Join us as we go over all the many changes coming next month.]]></itunes:summary><itunes:duration>606</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 576: Jeffries Dumps Bitcoin Due to the Quantum Threat</title><link>https://www.spreaker.com/episode/root-causes-576-jeffries-dumps-bitcoin-due-to-the-quantum-threat--69791987</link><description><![CDATA[A large investment firm divests from Bitcoin for fear of the quantum threat.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2260204532</guid><pubDate>Wed, 04 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69791987/2260204532_tim_callan_root_causes_576_jeffries_dumps_bitcoin_due_to_the_quantum_threat.mp3" length="13155072" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A large investment firm divests from Bitcoin for fear of the quantum threat.</itunes:subtitle><itunes:summary><![CDATA[A large investment firm divests from Bitcoin for fear of the quantum threat.]]></itunes:summary><itunes:duration>412</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 575: Shortening Certificate Term - All the Dates</title><link>https://www.spreaker.com/episode/root-causes-575-shortening-certificate-term-all-the-dates--69748306</link><description><![CDATA[Everybody knows about March 15 and the drop in maximum public TLS certificate term to 200 days.  But that only scratches the surface on key dates with this maximum term reduction.  Join us as we go over "all the dates" for TLS maximum term reduction.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2259001127</guid><pubDate>Mon, 02 Feb 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69748306/2259001127_tim_callan_root_causes_575_shortening_certificate_term_all_the_dates.mp3" length="39983616" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Everybody knows about March 15 and the drop in maximum public TLS certificate term to 200 days.  But that only scratches the surface on key dates with this maximum term reduction.  Join us as we go over "all the dates" for TLS maximum term reduction.</itunes:subtitle><itunes:summary><![CDATA[Everybody knows about March 15 and the drop in maximum public TLS certificate term to 200 days.  But that only scratches the surface on key dates with this maximum term reduction.  Join us as we go over "all the dates" for TLS maximum term reduction.]]></itunes:summary><itunes:duration>1250</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 574: 2025 Predictions Scorecard - Part 2</title><link>https://www.spreaker.com/episode/root-causes-574-2025-predictions-scorecard-part-2--69690740</link><description><![CDATA[We score our 2025 predictions in this second of two parts.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2257211948</guid><pubDate>Fri, 30 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69690740/2257211948_tim_callan_root_causes_574_2025_predictions_scorecard_part_2.mp3" length="37548288" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We score our 2025 predictions in this second of two parts.</itunes:subtitle><itunes:summary><![CDATA[We score our 2025 predictions in this second of two parts.]]></itunes:summary><itunes:duration>1174</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 573: 2025 Predictions Scorecard - Part 1</title><link>https://www.spreaker.com/episode/root-causes-573-2025-predictions-scorecard-part-1--69646075</link><description><![CDATA[Every new year we make predictions for the year to come, and every year we go back and see how we did.  This is the first of two parts scoring our 2025 predictions.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2255730848</guid><pubDate>Wed, 28 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69646075/2255730848_tim_callan_root_causes_573_2025_predictions_scorecard_part_1.mp3" length="44784384" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Every new year we make predictions for the year to come, and every year we go back and see how we did.  This is the first of two parts scoring our 2025 predictions.</itunes:subtitle><itunes:summary><![CDATA[Every new year we make predictions for the year to come, and every year we go back and see how we did.  This is the first of two parts scoring our 2025 predictions.]]></itunes:summary><itunes:duration>1400</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 572: Quality of Entropy</title><link>https://www.spreaker.com/episode/root-causes-572-quality-of-entropy--69591364</link><description><![CDATA[We discuss the idea that not all cryptographic entropy is equally "random" and potential consequences.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2254388483</guid><pubDate>Mon, 26 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69591364/2254388483_tim_callan_root_causes_572_quality_of_entropy.mp3" length="16781568" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss the idea that not all cryptographic entropy is equally "random" and potential consequences.</itunes:subtitle><itunes:summary><![CDATA[We discuss the idea that not all cryptographic entropy is equally "random" and potential consequences.]]></itunes:summary><itunes:duration>525</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 571: Will There Ever Be a Cryptographically Relevant Quantum Computer?</title><link>https://www.spreaker.com/episode/root-causes-571-will-there-ever-be-a-cryptographically-relevant-quantum-computer--69560062</link><description><![CDATA[We discuss the idea that it might be impossible to actually create a cryptographically relevant quantum computer and weigh in on this idea.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2252801873</guid><pubDate>Fri, 23 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69560062/2252801873_tim_callan_root_causes_571_will_there_ever_be_a_cryptographically_relevant_quantum_computer.mp3" length="17820672" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss the idea that it might be impossible to actually create a cryptographically relevant quantum computer and weigh in on this idea.</itunes:subtitle><itunes:summary><![CDATA[We discuss the idea that it might be impossible to actually create a cryptographically relevant quantum computer and weigh in on this idea.]]></itunes:summary><itunes:duration>557</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 570: PQC Readiness at the Boardroom Level</title><link>https://www.spreaker.com/episode/root-causes-570-pqc-readiness-at-the-boardroom-level--69537385</link><description><![CDATA[Repeat guest Chris McGrath shares what enterprises need to be doing now to stay on track for the NIST PQC deadline in 2030.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2251593371</guid><pubDate>Wed, 21 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69537385/2251593371_tim_callan_root_causes_570_pqc_readiness_at_the_boardroom_level.mp3" length="23331072" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Chris McGrath shares what enterprises need to be doing now to stay on track for the NIST PQC deadline in 2030.</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Chris McGrath shares what enterprises need to be doing now to stay on track for the NIST PQC deadline in 2030.]]></itunes:summary><itunes:duration>730</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 569: New Regulations Are Changing the PKI Landscape</title><link>https://www.spreaker.com/episode/root-causes-569-new-regulations-are-changing-the-pki-landscape--69510249</link><description><![CDATA[Repeat guest Chris McGrath joins us to discuss how increasingly strict regulations are requiring increased rigor, visibility, and auditability for enterprise digital certificates and PKI.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2250415505</guid><pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69510249/2250415505_tim_callan_root_causes_569_new_regulations_are_changing_the_pki_landscape.mp3" length="19159296" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Chris McGrath joins us to discuss how increasingly strict regulations are requiring increased rigor, visibility, and auditability for enterprise digital certificates and PKI.</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Chris McGrath joins us to discuss how increasingly strict regulations are requiring increased rigor, visibility, and auditability for enterprise digital certificates and PKI.]]></itunes:summary><itunes:duration>599</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 568: Upping Your Certificate Game for Better Security</title><link>https://www.spreaker.com/episode/root-causes-568-upping-your-certificate-game-for-better-security--69469185</link><description><![CDATA[Senior cyber security advisor Chris McGrath joins us to discuss redefining digital certificates and their role in your organizational security profile, increasing regulation of certificates, and how enterprises can up their certificate game.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2248686086</guid><pubDate>Fri, 16 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69469185/2248686086_tim_callan_root_causes_568_upping_your_certificate_game_for_better_security.mp3" length="24174336" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Senior cyber security advisor Chris McGrath joins us to discuss redefining digital certificates and their role in your organizational security profile, increasing regulation of certificates, and how enterprises can up their certificate game.</itunes:subtitle><itunes:summary><![CDATA[Senior cyber security advisor Chris McGrath joins us to discuss redefining digital certificates and their role in your organizational security profile, increasing regulation of certificates, and how enterprises can up their certificate game.]]></itunes:summary><itunes:duration>756</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 567: Top 10 PQC Laggards in the Enterprise</title><link>https://www.spreaker.com/episode/root-causes-567-top-10-pqc-laggards-in-the-enterprise--69437394</link><description><![CDATA[We name the ten enterprise environments and use cases that are most likely to be late adopters of post quantum cryptography (PQC).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2247308873</guid><pubDate>Wed, 14 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69437394/2247308873_tim_callan_root_causes_567_top_10_pqc_laggards_in_the_enterprise.mp3" length="39836928" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We name the ten enterprise environments and use cases that are most likely to be late adopters of post quantum cryptography (PQC).</itunes:subtitle><itunes:summary><![CDATA[We name the ten enterprise environments and use cases that are most likely to be late adopters of post quantum cryptography (PQC).]]></itunes:summary><itunes:duration>1245</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 566: Time Is a Security Primitive</title><link>https://www.spreaker.com/episode/root-causes-566-time-is-a-security-primitive--69406024</link><description><![CDATA[We discuss the foundational importance of time in PKI and security in general. This includes when things happen, the order in which things happen, and attacks based on time-spoofing.  We drill down on certificates, roots, timestamping, Certificate Transparency, patching, audits, and PQC.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2246257541</guid><pubDate>Mon, 12 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69406024/2246257541_tim_callan_root_causes_566_time_is_a_security_primitive.mp3" length="23642112" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss the foundational importance of time in PKI and security in general. This includes when things happen, the order in which things happen, and attacks based on time-spoofing.  We drill down on certificates, roots, timestamping, Certificate...</itunes:subtitle><itunes:summary><![CDATA[We discuss the foundational importance of time in PKI and security in general. This includes when things happen, the order in which things happen, and attacks based on time-spoofing.  We drill down on certificates, roots, timestamping, Certificate Transparency, patching, audits, and PQC.]]></itunes:summary><itunes:duration>739</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 565: Our Response to QWAC Arguments - Part 3</title><link>https://www.spreaker.com/episode/root-causes-565-our-response-to-qwac-arguments-part-3--69375257</link><description><![CDATA[In our concluding episode on the topic, we scrutinize arguments make for and against QWACs, this time focused on "compliance and interoperability."]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2244697532</guid><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69375257/2244697532_tim_callan_root_causes_565_our_response_to_qwac_arguments_part_3.mp3" length="22291968" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our concluding episode on the topic, we scrutinize arguments make for and against QWACs, this time focused on "compliance and interoperability."</itunes:subtitle><itunes:summary><![CDATA[In our concluding episode on the topic, we scrutinize arguments make for and against QWACs, this time focused on "compliance and interoperability."]]></itunes:summary><itunes:duration>697</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 564: Our Response to QWAC Arguments - Part 2</title><link>https://www.spreaker.com/episode/root-causes-564-our-response-to-qwac-arguments-part-2--69343775</link><description><![CDATA[In our second of three episodes on the topic, we scrutinize arguments make for and against QWAKs, this time focused on "governance and sovereignty."]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2243322119</guid><pubDate>Wed, 07 Jan 2026 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69343775/2243322119_tim_callan_root_causes_564_our_response_to_qwac_arguments_part_2.mp3" length="21816576" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our second of three episodes on the topic, we scrutinize arguments make for and against QWAKs, this time focused on "governance and sovereignty."</itunes:subtitle><itunes:summary><![CDATA[In our second of three episodes on the topic, we scrutinize arguments make for and against QWAKs, this time focused on "governance and sovereignty."]]></itunes:summary><itunes:duration>682</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 563: Our Response to QWAC Arguments - Part 1</title><link>https://www.spreaker.com/episode/root-causes-563-our-response-to-qwac-arguments-part-1--69310826</link><description><![CDATA[As a follow up to our episode 546, we break down the first of three sets of arguments about QWACs and examine their level of validity.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2242233683</guid><pubDate>Mon, 05 Jan 2026 21:07:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69310826/2242233683_tim_callan_root_causes_563_our_response_to_qwac_arguments_part_1.mp3" length="30688512" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As a follow up to our episode 546, we break down the first of three sets of arguments about QWACs and examine their level of validity.</itunes:subtitle><itunes:summary><![CDATA[As a follow up to our episode 546, we break down the first of three sets of arguments about QWACs and examine their level of validity.]]></itunes:summary><itunes:duration>959</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 562 : What Is a Side Oracle Attack?</title><link>https://www.spreaker.com/episode/root-causes-562-what-is-a-side-oracle-attack--69251442</link><description><![CDATA[You may have heard of side channel attacks. Now Jason explains what a side oracle attack is and how a side oracle attack in conjunction with AI could be effective against the HQC or Falcon PQC algorithms.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2238955376</guid><pubDate>Tue, 30 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69251442/2238955376_tim_callan_root_causes_562_what_is_a_side_oracle_attack.mp3" length="15270912" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>You may have heard of side channel attacks. Now Jason explains what a side oracle attack is and how a side oracle attack in conjunction with AI could be effective against the HQC or Falcon PQC algorithms.</itunes:subtitle><itunes:summary><![CDATA[You may have heard of side channel attacks. Now Jason explains what a side oracle attack is and how a side oracle attack in conjunction with AI could be effective against the HQC or Falcon PQC algorithms.]]></itunes:summary><itunes:duration>478</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/579a53659273239d92cf0e4712a866ef.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 561: What Is Classic McEliece?</title><link>https://www.spreaker.com/episode/root-causes-561-what-is-classic-mceliece--69186001</link><description><![CDATA[One of the NIST Round 3 PQC finalists that was never selected or eliminated is Classic McEliece. In this episode we explain in non-math terms how this algorithm works.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2235351191</guid><pubDate>Tue, 23 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69186001/2235351191_tim_callan_root_causes_561_what_is_classic_mceliece.mp3" length="15171072" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>One of the NIST Round 3 PQC finalists that was never selected or eliminated is Classic McEliece. In this episode we explain in non-math terms how this algorithm works.</itunes:subtitle><itunes:summary><![CDATA[One of the NIST Round 3 PQC finalists that was never selected or eliminated is Classic McEliece. In this episode we explain in non-math terms how this algorithm works.]]></itunes:summary><itunes:duration>475</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 560: AI in 1000 Days - Small Language Models</title><link>https://www.spreaker.com/episode/root-causes-560-ai-in-1000-days-small-language-models--69134599</link><description><![CDATA[Continuing our examination of AI in 1000 days, we discuss the use of finely tuned small language models for highly specific use cases.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2232817193</guid><pubDate>Thu, 18 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69134599/2232817193_tim_callan_root_causes_560_ai_in_1000_days_small_language_models.mp3" length="20927232" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Continuing our examination of AI in 1000 days, we discuss the use of finely tuned small language models for highly specific use cases.</itunes:subtitle><itunes:summary><![CDATA[Continuing our examination of AI in 1000 days, we discuss the use of finely tuned small language models for highly specific use cases.]]></itunes:summary><itunes:duration>654</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 559: AI 1000 days - Content Quality</title><link>https://www.spreaker.com/episode/root-causes-559-ai-1000-days-content-quality--69106212</link><description><![CDATA[We discuss what happens when the quality gap between AI-generated and human-generated content drops to zero.  We explore the consequences of this inevitable outcome.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2231545859</guid><pubDate>Wed, 17 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69106212/2231545859_tim_callan_root_causes_559_ai_1000_days_content_quality.mp3" length="24046080" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss what happens when the quality gap between AI-generated and human-generated content drops to zero.  We explore the consequences of this inevitable outcome.</itunes:subtitle><itunes:summary><![CDATA[We discuss what happens when the quality gap between AI-generated and human-generated content drops to zero.  We explore the consequences of this inevitable outcome.]]></itunes:summary><itunes:duration>752</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 558: AI in 1000 days - Human-in-the-loop Economy</title><link>https://www.spreaker.com/episode/root-causes-558-ai-in-1000-days-human-in-the-loop-economy--69060340</link><description><![CDATA[In our ongoing series on what AI will look like in 1000 days, we discuss the spread of a new business process, where AIs do the bulk of the work while humans sit in the loop for certain specific tasks and roles.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2230142717</guid><pubDate>Mon, 15 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69060340/2230142717_tim_callan_root_causes_558_ai_in_1000_days_human_in_the_loop_economy.mp3" length="14728704" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing series on what AI will look like in 1000 days, we discuss the spread of a new business process, where AIs do the bulk of the work while humans sit in the loop for certain specific tasks and roles.</itunes:subtitle><itunes:summary><![CDATA[In our ongoing series on what AI will look like in 1000 days, we discuss the spread of a new business process, where AIs do the bulk of the work while humans sit in the loop for certain specific tasks and roles.]]></itunes:summary><itunes:duration>461</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 557: Top 5 PQC Laggards</title><link>https://www.spreaker.com/episode/root-causes-557-top-5-pqc-laggards--69029913</link><description><![CDATA[Following up on our list of top 5 PQC vanguards, in this episode we detail the top 5 PQC laggards.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2228664827</guid><pubDate>Fri, 12 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69029913/2228664827_tim_callan_root_causes_557_top_5_pqc_laggards.mp3" length="18788352" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Following up on our list of top 5 PQC vanguards, in this episode we detail the top 5 PQC laggards.</itunes:subtitle><itunes:summary><![CDATA[Following up on our list of top 5 PQC vanguards, in this episode we detail the top 5 PQC laggards.]]></itunes:summary><itunes:duration>588</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 556: Top 5 PQC Vanguards</title><link>https://www.spreaker.com/episode/root-causes-556-top-5-pqc-vanguards--68980112</link><description><![CDATA[We describe the top five technology categories that are on the vanguard of driving PQC adoption.  We describe what these categories have in common and how that results in early adoption of post quantum cryptography.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2227371797</guid><pubDate>Wed, 10 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68980112/2227371797_tim_callan_root_causes_556_top_5_pqc_vanguards.mp3" length="19153152" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We describe the top five technology categories that are on the vanguard of driving PQC adoption.  We describe what these categories have in common and how that results in early adoption of post quantum cryptography.</itunes:subtitle><itunes:summary><![CDATA[We describe the top five technology categories that are on the vanguard of driving PQC adoption.  We describe what these categories have in common and how that results in early adoption of post quantum cryptography.]]></itunes:summary><itunes:duration>599</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 555: Perpretrators of Rogue Certificates</title><link>https://www.spreaker.com/episode/root-causes-555-perpretrators-of-rogue-certificates--68948474</link><description><![CDATA[We detail the top ten groups inside the organization who introduce rogue certificates into IT organizations.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2226274679</guid><pubDate>Mon, 08 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68948474/2226274679_tim_callan_root_causes_555_perpretrators_of_rogue_certificates.mp3" length="24402432" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We detail the top ten groups inside the organization who introduce rogue certificates into IT organizations.</itunes:subtitle><itunes:summary><![CDATA[We detail the top ten groups inside the organization who introduce rogue certificates into IT organizations.]]></itunes:summary><itunes:duration>763</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 554: Disentangling Quantum</title><link>https://www.spreaker.com/episode/root-causes-554-disentangling-quantum--68901910</link><description><![CDATA[Tech watchers tend to conflate the many quantum technologies under development right now.   In this episode we go through these technologies and explain how they connect.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2224617932</guid><pubDate>Fri, 05 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68901910/2224617932_tim_callan_root_causes_554_disentangling_quantum.mp3" length="19650048" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Tech watchers tend to conflate the many quantum technologies under development right now.   In this episode we go through these technologies and explain how they connect.</itunes:subtitle><itunes:summary><![CDATA[Tech watchers tend to conflate the many quantum technologies under development right now.   In this episode we go through these technologies and explain how they connect.]]></itunes:summary><itunes:duration>615</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 553: Connecting Quantum Clocks to Cryptography</title><link>https://www.spreaker.com/episode/root-causes-553-connecting-quantum-clocks-to-cryptography--68870218</link><description><![CDATA[We discuss quantum clocks and their potential role in cryptography.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2223613016</guid><pubDate>Wed, 03 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68870218/2223613016_tim_callan_root_causes_553_connecting_quantum_clocks_to_cryptography.mp3" length="11397208" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss quantum clocks and their potential role in cryptography.</itunes:subtitle><itunes:summary><![CDATA[We discuss quantum clocks and their potential role in cryptography.]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 552: 2026 Predictions</title><link>https://www.spreaker.com/episode/root-causes-552-2026-predictions--68822371</link><description><![CDATA[We share our PKI predictions for 2026. Topics include PQC, eIDAS 2, CT logging, ACME, passkeys, CA distrust, AI model poisoning, and new attack vectors.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2222251814</guid><pubDate>Mon, 01 Dec 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68822371/2222251814_tim_callan_root_causes_552_2026_predictions.mp3" length="62819328" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We share our PKI predictions for 2026. Topics include PQC, eIDAS 2, CT logging, ACME, passkeys, CA distrust, AI model poisoning, and new attack vectors.</itunes:subtitle><itunes:summary><![CDATA[We share our PKI predictions for 2026. Topics include PQC, eIDAS 2, CT logging, ACME, passkeys, CA distrust, AI model poisoning, and new attack vectors.]]></itunes:summary><itunes:duration>1964</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 551: PKI in a Swarm at 50 mph</title><link>https://www.spreaker.com/episode/root-causes-551-pki-in-a-swarm-at-50-mph--68728913</link><description><![CDATA[Jason explores the role cryptography and trust systems play in the command and control of groups of autonomous drone systems.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2218351724</guid><pubDate>Mon, 24 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68728913/2218351724_tim_callan_root_causes_551_pki_in_a_swarm_at_50_mph.mp3" length="18994176" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason explores the role cryptography and trust systems play in the command and control of groups of autonomous drone systems.</itunes:subtitle><itunes:summary><![CDATA[Jason explores the role cryptography and trust systems play in the command and control of groups of autonomous drone systems.]]></itunes:summary><itunes:duration>594</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 550: WebPKI Certificate Lifespan - How Low Can You Go?</title><link>https://www.spreaker.com/episode/root-causes-550-webpki-certificate-lifespan-how-low-can-you-go--68685132</link><description><![CDATA[Certificate maximum term is shrinking.  In this episode we examine exactly how short they could get.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2216773616</guid><pubDate>Fri, 21 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68685132/2216773616_tim_callan_root_causes_550_webpki_certificate_lifespan_how_low_can_you_go.mp3" length="22717555" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certificate maximum term is shrinking.  In this episode we examine exactly how short they could get.</itunes:subtitle><itunes:summary><![CDATA[Certificate maximum term is shrinking.  In this episode we examine exactly how short they could get.]]></itunes:summary><itunes:duration>947</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 549: AI 1000 Days from Now - the Defeat of Voice Authentication</title><link>https://www.spreaker.com/episode/root-causes-549-ai-1000-days-from-now-the-defeat-of-voice-authentication--68649667</link><description><![CDATA[In our ongoing series on AI in 1000 days, we describe the inevitable, complete distrust of voice printing as an authentication method, including why and what we think will happen.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2215654094</guid><pubDate>Wed, 19 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68649667/2215654094_tim_callan_root_causes_549_ai_1000_days_from_now_the_defeat_of_voice_authentication.mp3" length="34881792" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing series on AI in 1000 days, we describe the inevitable, complete distrust of voice printing as an authentication method, including why and what we think will happen.</itunes:subtitle><itunes:summary><![CDATA[In our ongoing series on AI in 1000 days, we describe the inevitable, complete distrust of voice printing as an authentication method, including why and what we think will happen.]]></itunes:summary><itunes:duration>1091</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 548: AI 1000 Days from Now - Emotional Intelligence</title><link>https://www.spreaker.com/episode/root-causes-548-ai-1000-days-from-now-emotional-intelligence--68604566</link><description><![CDATA[We begin a new series about what we expect from AI in the next three years.  In this episode we discuss AI emulating emotional intelligence and its benefits.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2214189182</guid><pubDate>Mon, 17 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68604566/2214189182_tim_callan_root_causes_548_ai_1000_days_from_now_emotional_intelligence.mp3" length="25530163" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We begin a new series about what we expect from AI in the next three years.  In this episode we discuss AI emulating emotional intelligence and its benefits.</itunes:subtitle><itunes:summary><![CDATA[We begin a new series about what we expect from AI in the next three years.  In this episode we discuss AI emulating emotional intelligence and its benefits.]]></itunes:summary><itunes:duration>1064</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 547: Should We Do Mass Revocation Fire Drills?</title><link>https://www.spreaker.com/episode/root-causes-547-should-we-do-mass-revocation-fire-drills--68571779</link><description><![CDATA[In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2212651718</guid><pubDate>Fri, 14 Nov 2025 18:19:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68571779/2212651718_tim_callan_root_causes_547_should_we_do_mass_revocation_fire_drills.mp3" length="18068083" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.</itunes:subtitle><itunes:summary><![CDATA[In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.]]></itunes:summary><itunes:duration>753</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 546: New Research Codifies Arguments for and Against QWACs</title><link>https://www.spreaker.com/episode/root-causes-546-new-research-codifies-arguments-for-and-against-qwacs--68544027</link><description><![CDATA[We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2211490553</guid><pubDate>Wed, 12 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68544027/2211490553_tim_callan_root_causes_546_new_research_codifies_arguments_for_and_against_qwacs.mp3" length="83392512" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates.</itunes:subtitle><itunes:summary><![CDATA[We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates.]]></itunes:summary><itunes:duration>2606</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 545: What Is MOSH?</title><link>https://www.spreaker.com/episode/root-causes-545-what-is-mosh--68498626</link><description><![CDATA[The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2210138207</guid><pubDate>Mon, 10 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68498626/2210138207_tim_callan_root_causes_545_what_is_mosh.mp3" length="15967488" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.</itunes:subtitle><itunes:summary><![CDATA[The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.]]></itunes:summary><itunes:duration>499</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 54: What Is Chain of Lure?</title><link>https://www.spreaker.com/episode/root-causes-54-what-is-chain-of-lure--68469039</link><description><![CDATA[Chain of lure is an attack method used to circumvent restrictions and boundaries places on AIs.  Jason explains this attack and its implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2208813338</guid><pubDate>Fri, 07 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68469039/2208813338_tim_callan_root_causes_54_what_is_chain_of_lure.mp3" length="19294464" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Chain of lure is an attack method used to circumvent restrictions and boundaries places on AIs.  Jason explains this attack and its implications.</itunes:subtitle><itunes:summary><![CDATA[Chain of lure is an attack method used to circumvent restrictions and boundaries places on AIs.  Jason explains this attack and its implications.]]></itunes:summary><itunes:duration>603</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 543: AI Finds a Zero Day</title><link>https://www.spreaker.com/episode/root-causes-543-ai-finds-a-zero-day--68442539</link><description><![CDATA[We have seen the first known instance of an AI tool discovering a zero-day vulnerability.  This could have vast implications on vulnerability detection and bug bounty programs.  We discuss the implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2207500515</guid><pubDate>Wed, 05 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68442539/2207500515_tim_callan_root_causes_543_ai_finds_a_zero_day.mp3" length="34096896" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We have seen the first known instance of an AI tool discovering a zero-day vulnerability.  This could have vast implications on vulnerability detection and bug bounty programs.  We discuss the implications.</itunes:subtitle><itunes:summary><![CDATA[We have seen the first known instance of an AI tool discovering a zero-day vulnerability.  This could have vast implications on vulnerability detection and bug bounty programs.  We discuss the implications.]]></itunes:summary><itunes:duration>1066</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 542: Use Cases for HQC</title><link>https://www.spreaker.com/episode/root-causes-542-use-cases-for-hqc--68403383</link><description><![CDATA[In this episode we go over some of the reasons one might choose HQC over ML-KEM as a PQC key exchange algorithm for specific circumstances. And we discuss the future diversity of cryptography.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2205649003</guid><pubDate>Sun, 02 Nov 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68403383/2205649003_tim_callan_root_causes_542_use_cases_for_hqc.mp3" length="20301312" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we go over some of the reasons one might choose HQC over ML-KEM as a PQC key exchange algorithm for specific circumstances. And we discuss the future diversity of cryptography.</itunes:subtitle><itunes:summary><![CDATA[In this episode we go over some of the reasons one might choose HQC over ML-KEM as a PQC key exchange algorithm for specific circumstances. And we discuss the future diversity of cryptography.]]></itunes:summary><itunes:duration>635</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 541: Introducing the HQC PQC Algorithm</title><link>https://www.spreaker.com/episode/root-causes-541-introducing-the-hqc-pqc-algorithm--68378318</link><description><![CDATA[NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC.  We explain this code-based algorithm.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2204032767</guid><pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68378318/2204032767_tim_callan_root_causes_541_introducing_the_hqc_pqc_algorithm.mp3" length="13185024" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC.  We explain this code-based algorithm.</itunes:subtitle><itunes:summary><![CDATA[NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC.  We explain this code-based algorithm.]]></itunes:summary><itunes:duration>413</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 540: Contextual CBOM</title><link>https://www.spreaker.com/episode/root-causes-540-contextual-cbom--68297712</link><description><![CDATA[We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2200012703</guid><pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68297712/2200012703_tim_callan_root_causes_540_contextual_cbom.mp3" length="21225984" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.</itunes:subtitle><itunes:summary><![CDATA[We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.]]></itunes:summary><itunes:duration>664</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 539: What Is the Two-QWAC Architecture?</title><link>https://www.spreaker.com/episode/root-causes-539-what-is-the-two-qwac-architecture--68246259</link><description><![CDATA[A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain.  We explain what's coming and why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2196556887</guid><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68246259/2196556887_tim_callan_root_causes_539_what_is_the_two_qwac_architecture.mp3" length="38489088" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of...</itunes:subtitle><itunes:summary><![CDATA[A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain.  We explain what's coming and why.]]></itunes:summary><itunes:duration>1203</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 538: What Is an Entropy Desert?</title><link>https://www.spreaker.com/episode/root-causes-538-what-is-an-entropy-desert--68215768</link><description><![CDATA[An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2194581507</guid><pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68215768/2194581507_tim_callan_root_causes_538_what_is_an_entropy_desert.mp3" length="13020380" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.</itunes:subtitle><itunes:summary><![CDATA[An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.]]></itunes:summary><itunes:duration>543</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 537: The Thermodynamics of Privacy</title><link>https://www.spreaker.com/episode/root-causes-537-the-thermodynamics-of-privacy--68175836</link><description><![CDATA[In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2192281667</guid><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68175836/2192281667_tim_callan_root_causes_537_the_thermodynamics_of_privacy.mp3" length="19560860" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.</itunes:subtitle><itunes:summary><![CDATA[In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.]]></itunes:summary><itunes:duration>815</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 536: Patent Blocker on ML-KEM</title><link>https://www.spreaker.com/episode/root-causes-536-patent-blocker-on-ml-kem--68151191</link><description><![CDATA[A patent dispute in 2024 nearly blocked ML-KEM.  But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2190819231</guid><pubDate>Wed, 15 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68151191/2190819231_tim_callan_root_causes_536_patent_blocker_on_ml_kem.mp3" length="22781952" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A patent dispute in 2024 nearly blocked ML-KEM.  But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations.  We explain.</itunes:subtitle><itunes:summary><![CDATA[A patent dispute in 2024 nearly blocked ML-KEM.  But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations.  We explain.]]></itunes:summary><itunes:duration>712</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 535: The CPS Is a Superset of Actual Practices</title><link>https://www.spreaker.com/episode/root-causes-535-the-cps-is-a-superset-of-actual-practices--68123907</link><description><![CDATA[The CPS must always be a superset of actual practices in a properly running CA.  We explain why this is a product of good design.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2189558243</guid><pubDate>Sun, 12 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68123907/2189558243_tim_callan_root_causes_535_the_cps_is_a_superset_of_actual_practices.mp3" length="14959767" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CPS must always be a superset of actual practices in a properly running CA.  We explain why this is a product of good design.</itunes:subtitle><itunes:summary><![CDATA[The CPS must always be a superset of actual practices in a properly running CA.  We explain why this is a product of good design.]]></itunes:summary><itunes:duration>623</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/579a53659273239d92cf0e4712a866ef.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 534: Signing the Machines That Think</title><link>https://www.spreaker.com/episode/root-causes-534-signing-the-machines-that-think--68093405</link><description><![CDATA[Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime.  How do you know?  Jason proposes that, the same way we sign our code, we should be signing our AI models as well.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2187354483</guid><pubDate>Fri, 10 Oct 2025 17:47:53 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68093405/2187354483_tim_callan_root_causes_534_signing_the_machines_that_think.mp3" length="12889052" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime.  How do you know?  Jason proposes that, the same way we sign our code, we should be signing our AI models as well.</itunes:subtitle><itunes:summary><![CDATA[Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime.  How do you know?  Jason proposes that, the same way we sign our code, we should be signing our AI models as well.]]></itunes:summary><itunes:duration>537</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 533: Flexibility Through Multi-CA Trust Models</title><link>https://www.spreaker.com/episode/root-causes-533-flexibility-through-multi-ca-trust-models--68048378</link><description><![CDATA[We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&amp;A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2184313987</guid><pubDate>Tue, 07 Oct 2025 14:37:29 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68048378/2184313987_tim_callan_root_causes_533_flexibilty_through_multi_ca_trust_models.mp3" length="13582195" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&amp;amp;A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.</itunes:subtitle><itunes:summary><![CDATA[We discuss how a static PKI structure can hurt corporate flexibility and resilience. Events like reorgs and M&amp;A activity can cause intractable problems with the wrong PKI setup. Plus, Jason coins the term PKI archeology.]]></itunes:summary><itunes:duration>566</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 532: Introducing Offline PKI</title><link>https://www.spreaker.com/episode/root-causes-532-introducing-offline-pki--68002444</link><description><![CDATA[In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2181721771</guid><pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68002444/2181721771_tim_callan_root_causes_532_introducing_offline_pki.mp3" length="15958771" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.</itunes:subtitle><itunes:summary><![CDATA[In this episode, Jason describes how we might use the principles of PKI in a purely offline scenario.]]></itunes:summary><itunes:duration>665</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 531: Benefits of Single-purpose Root Hierarchies</title><link>https://www.spreaker.com/episode/root-causes-531-benefits-of-single-purpose-root-hierarchies--67980801</link><description><![CDATA[Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones.  We discuss why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2180429579</guid><pubDate>Wed, 01 Oct 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67980801/2180429579_tim_callan_root_causes_531_benefits_of_single_purpose_root_heirarchies.mp3" length="23917741" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones.  We discuss why.</itunes:subtitle><itunes:summary><![CDATA[Public certificates are transitioning from multi-purpose root hierarchies to single-purpose ones.  We discuss why.]]></itunes:summary><itunes:duration>997</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 530: Introducing the AI Iceberg</title><link>https://www.spreaker.com/episode/root-causes-530-introducing-the-ai-iceberg--67943414</link><description><![CDATA[We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2178716436</guid><pubDate>Mon, 29 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67943414/2178716436_tim_callan_root_causes_530_introducing_the_ai_iceberg.mp3" length="27037257" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.</itunes:subtitle><itunes:summary><![CDATA[We compare AI in 2025 to Internet in 1995 and describe the AI iceberg, including the majority of applications which are below the waterline.]]></itunes:summary><itunes:duration>1127</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 529: What Is a Common Mark Certificate?</title><link>https://www.spreaker.com/episode/root-causes-529-what-is-a-common-mark-certificate--67880792</link><description><![CDATA[Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2175984219</guid><pubDate>Wed, 24 Sep 2025 18:30:27 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67880792/2175984219_tim_callan_root_causes_529_what_is_a_common_mark_certificate.mp3" length="10867309" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.</itunes:subtitle><itunes:summary><![CDATA[Verified Mark Certificates (VMC) now have a companion product for logos that are not registered trademarks, called a Common Mark Certificate (CMC). We explain the differences.]]></itunes:summary><itunes:duration>453</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 528: Misissued SSL Certificate for 1.1.1.1</title><link>https://www.spreaker.com/episode/root-causes-528-misissued-ssl-certificate-for-1-1-1-1--67811052</link><description><![CDATA[A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses.  We go into the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2172772287</guid><pubDate>Wed, 17 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67811052/2172772287_tim_callan_root_causes_528_missued_ssl_certificate_for_1111.mp3" length="33640704" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses.  We go into the details.</itunes:subtitle><itunes:summary><![CDATA[A CA has incorrectly issued TLS certificates for the 1.1.1.1 and 2.2.2.2 IP addresses.  We go into the details.]]></itunes:summary><itunes:duration>1052</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 527: Key Dates for the Deprecation of Public mTLS</title><link>https://www.spreaker.com/episode/root-causes-527-key-dates-for-the-deprecation-of-public-mtls--67768829</link><description><![CDATA[Client authentication using public TLS server certificates is on the deprecation path.  In this episode we go through the key dates in this deprecation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2170977132</guid><pubDate>Mon, 15 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67768829/2170977132_tim_callan_root_causes_527_key_dates_for_the_deprecation_of_public_mtls.mp3" length="15031213" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Client authentication using public TLS server certificates is on the deprecation path.  In this episode we go through the key dates in this deprecation.</itunes:subtitle><itunes:summary><![CDATA[Client authentication using public TLS server certificates is on the deprecation path.  In this episode we go through the key dates in this deprecation.]]></itunes:summary><itunes:duration>626</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 526: Voice Biometrics Are Worthless</title><link>https://www.spreaker.com/episode/root-causes-526-voice-biometrics-are-worthless--67738886</link><description><![CDATA[Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2169577398</guid><pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67738886/2169577398_tim_callan_root_causes_526_voice_biometrics_are_worthless.mp3" length="12299245" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.</itunes:subtitle><itunes:summary><![CDATA[Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.]]></itunes:summary><itunes:duration>513</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 525: The End of Email-based DCV</title><link>https://www.spreaker.com/episode/root-causes-525-the-end-of-email-based-dcv--67707399</link><description><![CDATA[A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years.  We go into the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2168322969</guid><pubDate>Wed, 10 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67707399/2168322969_tim_callan_root_causes_525_the_end_of_email_based_dcv.mp3" length="14499966" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years.  We go into the details.</itunes:subtitle><itunes:summary><![CDATA[A new CABF ballot proposal will eliminate all email- and phone-based DCV over the next few years.  We go into the details.]]></itunes:summary><itunes:duration>604</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 524: How to Kill Three Birds with One Stone</title><link>https://www.spreaker.com/episode/root-causes-524-how-to-kill-three-birds-with-one-stone--67675539</link><description><![CDATA[Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates.  These are 47-day SSL, PQC, and the deprecation of mTLS.  We describe the overlap between these efforts and how to combine them for better efficiency and project management.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2166952509</guid><pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67675539/2166952509_tim_callan_root_causes_524_how_to_kill_three_birds_with_one_stone.mp3" length="18304061" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates.  These are 47-day SSL, PQC, and the deprecation of mTLS.  We describe the overlap...</itunes:subtitle><itunes:summary><![CDATA[Three major changes are coming to the world of public certificates, all of which require major changes in how organizations deploy, renew, and manage their certificates.  These are 47-day SSL, PQC, and the deprecation of mTLS.  We describe the overlap between these efforts and how to combine them for better efficiency and project management.]]></itunes:summary><itunes:duration>763</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 523: Will Your Configuration Block MPIC DCV?</title><link>https://www.spreaker.com/episode/root-causes-523-will-your-configuration-block-mpic-dcv--67622635</link><description><![CDATA[MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you have a problem.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2164194417</guid><pubDate>Wed, 03 Sep 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67622635/2164194417_tim_callan_root_causes_523_will_your_configuration_block_mpic_dcv.mp3" length="16233754" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you have...</itunes:subtitle><itunes:summary><![CDATA[MPIC (Multi-perspective Issuance Corroboration) is soon to move into enforcement phase. In this episode we describe three configuration decisions that can force Domain Control Validation (DCV) to fail and tell you what to do about them before you have a problem.]]></itunes:summary><itunes:duration>677</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 522: How Prepared Are Enterprises for PQC? (Part 2)</title><link>https://www.spreaker.com/episode/root-causes-522-how-prepared-are-enterprises-for-pqc-part-2--67545147</link><description><![CDATA[We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2160975474</guid><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67545147/2160975474_tim_callan_root_causes_522_how_prepared_are_enteprises_for_pqc_part_2.mp3" length="48209223" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).</itunes:subtitle><itunes:summary><![CDATA[We complete our description and commentary on the results of Sectigo's survey of enterprise preparedness for Post Quantum Cryptography (PQC).]]></itunes:summary><itunes:duration>2009</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 521: How Prepared Are Enterprises for PQC? (Part 1)</title><link>https://www.spreaker.com/episode/root-causes-521-how-prepared-are-enterprises-for-pqc-part-1--67482464</link><description><![CDATA[We begin to go over the results of Sectigo's recent survey of enterprises and their preparedness and plans for adopting Post Quantum Cryptography (PQC).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2157705177</guid><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67482464/2157705177_tim_callan_root_causes_521_how_prepared_are_enterprises_for_pqc_part_1.mp3" length="46618893" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We begin to go over the results of Sectigo's recent survey of enterprises and their preparedness and plans for adopting Post Quantum Cryptography (PQC).</itunes:subtitle><itunes:summary><![CDATA[We begin to go over the results of Sectigo's recent survey of enterprises and their preparedness and plans for adopting Post Quantum Cryptography (PQC).]]></itunes:summary><itunes:duration>1943</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 520: How Prepared Are IT Teams for 47-day Certificates?</title><link>https://www.spreaker.com/episode/root-causes-520-how-prepared-are-it-teams-for-47-day-certificates--67457959</link><description><![CDATA[Sectigo has released the results of its survey of IT professionals in charge of certificates to measure their readiness and preparation for 47-day maximum certificate term.  We go over the results.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2156463075</guid><pubDate>Wed, 20 Aug 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67457959/2156463075_tim_callan_root_causes_520_how_prepared_are_it_teams_for_47_day_certificates.mp3" length="64940457" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Sectigo has released the results of its survey of IT professionals in charge of certificates to measure their readiness and preparation for 47-day maximum certificate term.  We go over the results.</itunes:subtitle><itunes:summary><![CDATA[Sectigo has released the results of its survey of IT professionals in charge of certificates to measure their readiness and preparation for 47-day maximum certificate term.  We go over the results.]]></itunes:summary><itunes:duration>2706</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 519: AI Is the Room</title><link>https://www.spreaker.com/episode/root-causes-519-ai-is-the-room--67422988</link><description><![CDATA[AI is not the elephant in the room. It is the room itself.  Jason explains what he means by that.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2155391607</guid><pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67422988/2155391607_tim_callan_root_causes_519_ai_is_the_room.mp3" length="26530842" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>AI is not the elephant in the room. It is the room itself.  Jason explains what he means by that.</itunes:subtitle><itunes:summary><![CDATA[AI is not the elephant in the room. It is the room itself.  Jason explains what he means by that.]]></itunes:summary><itunes:duration>1106</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 518: NCSC Lukewarm on FIDO WebAuthn</title><link>https://www.spreaker.com/episode/root-causes-518-ncsc-lukewarm-on-fido-webauthn--67358245</link><description><![CDATA[Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution.  We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of Linux support.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2152568520</guid><pubDate>Wed, 13 Aug 2025 16:39:38 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67358245/2152568520_tim_callan_root_causes_518_ncsc_lukewarm_on_fido_webauthn.mp3" length="15866983" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution.  We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of...</itunes:subtitle><itunes:summary><![CDATA[Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution.  We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of Linux support.]]></itunes:summary><itunes:duration>992</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 517: The Cost of Quantum Factoring</title><link>https://www.spreaker.com/episode/root-causes-517-the-cost-of-quantum-factoring--67116030</link><description><![CDATA[Jason walks us through an important recent paper from Google tracking the cost of quantum factoring.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2136524310</guid><pubDate>Fri, 25 Jul 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67116030/2136524310_tim_callan_root_causes_517_the_cost_of_quantum_factoring.mp3" length="7712352" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason walks us through an important recent paper from Google tracking the cost of quantum factoring.</itunes:subtitle><itunes:summary><![CDATA[Jason walks us through an important recent paper from Google tracking the cost of quantum factoring.]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 516: PQC for ADCS</title><link>https://www.spreaker.com/episode/root-causes-516-pqc-for-adcs--67056897</link><description><![CDATA[Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should be asking.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2133865932</guid><pubDate>Mon, 21 Jul 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67056897/2133865932_tim_callan_root_causes_516_pqc_for_adcs.mp3" length="19670105" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should...</itunes:subtitle><itunes:summary><![CDATA[Microsoft has finally announced that it will offer an update to Active Directory Certificate Services (ADCS, formerly MSCA) to support post quantum cryptography. We discuss Microsoft's checkered support for ADCS and offer some questions users should be asking.]]></itunes:summary><itunes:duration>820</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 515: What Is Entropy-aware Governance?</title><link>https://www.spreaker.com/episode/root-causes-515-what-is-entropy-aware-governance--67029927</link><description><![CDATA[Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and requirements.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2132474928</guid><pubDate>Fri, 18 Jul 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67029927/2132474928_tim_callan_root_causes_515_what_is_entropy_aware_governance.mp3" length="21410201" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and...</itunes:subtitle><itunes:summary><![CDATA[Jason coins the term "entropy-aware governance" to describe the idea of using the degree of entropy it contains to measure the strength of any given secret. This could be an objective, consistent metric that could be applied to standard practices and requirements.]]></itunes:summary><itunes:duration>892</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 514: Diary of an Online Firestorm</title><link>https://www.spreaker.com/episode/root-causes-514-diary-of-an-online-firestorm--67000917</link><description><![CDATA[Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread.  We discuss what a more functional response would have looked like.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2131171575</guid><pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67000917/2131171575_tim_callan_root_causes_514_diary_of_an_online_firestorm.mp3" length="18386201" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread.  We discuss what a more functional response would have looked like.</itunes:subtitle><itunes:summary><![CDATA[Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread.  We discuss what a more functional response would have looked like.]]></itunes:summary><itunes:duration>766</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 513: Is Revocation the Best Remedy for CPS Misalignment?</title><link>https://www.spreaker.com/episode/root-causes-513-is-revocation-the-best-remedy-for-cps-misalignment--66974491</link><description><![CDATA[We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2129716587</guid><pubDate>Mon, 14 Jul 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66974491/2129716587_tim_callan_root_causes_513_is_revocation_the_best_remedy_for_cps_misalignment.mp3" length="17817689" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.</itunes:subtitle><itunes:summary><![CDATA[We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.]]></itunes:summary><itunes:duration>742</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 512: CPS Versus Practices Misalignment</title><link>https://www.spreaker.com/episode/root-causes-512-cps-versus-practices-misalignment--66944074</link><description><![CDATA[We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2128329717</guid><pubDate>Fri, 11 Jul 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66944074/2128329717_tim_callan_root_causes_512_cps_versus_practices_misalignment.mp3" length="18295763" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation.</itunes:subtitle><itunes:summary><![CDATA[We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation.]]></itunes:summary><itunes:duration>762</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 511: The GoML Root Store</title><link>https://www.spreaker.com/episode/root-causes-511-the-goml-root-store--66870524</link><description><![CDATA[We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2125146465</guid><pubDate>Sat, 05 Jul 2025 18:45:33 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66870524/2125146465_tim_callan_root_causes_511_the_goml_root_store.mp3" length="22610010" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store.</itunes:subtitle><itunes:summary><![CDATA[We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store.]]></itunes:summary><itunes:duration>942</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 510: Introducing the GoML Browser</title><link>https://www.spreaker.com/episode/root-causes-510-introducing-the-goml-browser--66774118</link><description><![CDATA[We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2120637906</guid><pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66774118/2120637906_tim_callan_root_causes_510_introducing_the_goml_browser.mp3" length="14841335" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling.</itunes:subtitle><itunes:summary><![CDATA[We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling.]]></itunes:summary><itunes:duration>618</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 509: What Is a CPS?</title><link>https://www.spreaker.com/episode/root-causes-509-what-is-a-cps--66745864</link><description><![CDATA[We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2119335714</guid><pubDate>Wed, 25 Jun 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66745864/2119335714_tim_callan_root_causes_509_what_is_a_cps.mp3" length="10815836" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs.</itunes:subtitle><itunes:summary><![CDATA[We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs.]]></itunes:summary><itunes:duration>451</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 508: What Is Code Vibing?</title><link>https://www.spreaker.com/episode/root-causes-508-what-is-code-vibing--66711054</link><description><![CDATA["Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2118306795</guid><pubDate>Mon, 23 Jun 2025 18:49:44 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66711054/2118306795_tim_callan_root_causes_508_what_is_code_vibing.mp3" length="25526874" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>"Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser.</itunes:subtitle><itunes:summary><![CDATA["Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser.]]></itunes:summary><itunes:duration>1064</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 507: First Distrust of 2025</title><link>https://www.spreaker.com/episode/root-causes-507-first-distrust-of-2025--66638784</link><description><![CDATA[The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2116385109</guid><pubDate>Thu, 19 Jun 2025 21:36:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66638784/2116385109_tim_callan_root_causes_507_first_distrust_of_2025.mp3" length="13758837" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details.</itunes:subtitle><itunes:summary><![CDATA[The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details.]]></itunes:summary><itunes:duration>573</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 506: Recap of CABF Face-to-face #65</title><link>https://www.spreaker.com/episode/root-causes-506-recap-of-cabf-face-to-face-65--66592589</link><description><![CDATA[For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting.  We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2114941899</guid><pubDate>Tue, 17 Jun 2025 15:18:35 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66592589/2114941899_tim_callan_root_causes_506_recap_of_cabf_face_to_face_65.mp3" length="12813806" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting.  We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face.</itunes:subtitle><itunes:summary><![CDATA[For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting.  We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face.]]></itunes:summary><itunes:duration>534</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 505: Trust Now, Forge Later</title><link>https://www.spreaker.com/episode/root-causes-505-trust-now-forge-later--66549640</link><description><![CDATA[In this episode we explain the potential for future quantum computers to break files signed  today with RSA or ECC, called "Trust now, forge later."]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2112786915</guid><pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66549640/2112786915_tim_callan_root_causes_505_trust_now_forge_later.mp3" length="15207262" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain the potential for future quantum computers to break files signed  today with RSA or ECC, called "Trust now, forge later."</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain the potential for future quantum computers to break files signed  today with RSA or ECC, called "Trust now, forge later."]]></itunes:summary><itunes:duration>634</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 504: Jason Programs a Quantum Computer</title><link>https://www.spreaker.com/episode/root-causes-504-jason-programs-a-quantum-computer--66499654</link><description><![CDATA[Jason describes his recent experience using Amazon Braket.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2111162898</guid><pubDate>Tue, 10 Jun 2025 21:46:47 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66499654/2111162898_tim_callan_root_causes_504_jason_programs_a_quantum_computer.mp3" length="25645715" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason describes his recent experience using Amazon Braket.</itunes:subtitle><itunes:summary><![CDATA[Jason describes his recent experience using Amazon Braket.]]></itunes:summary><itunes:duration>1069</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 503: What Are Hybrid and Composite PQC?</title><link>https://www.spreaker.com/episode/root-causes-503-what-are-hybrid-and-composite-pqc--66423613</link><description><![CDATA[We explain the difference between two strategies of PQC implementation, which we call hybrid and composite.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2108972148</guid><pubDate>Fri, 06 Jun 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66423613/2108972148_tim_callan_root_causes_503_what_are_hybrid_and_composite_pqc.mp3" length="11605518" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We explain the difference between two strategies of PQC implementation, which we call hybrid and composite.</itunes:subtitle><itunes:summary><![CDATA[We explain the difference between two strategies of PQC implementation, which we call hybrid and composite.]]></itunes:summary><itunes:duration>484</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 502: The PQC Game of Chicken</title><link>https://www.spreaker.com/episode/root-causes-502-the-pqc-game-of-chicken--66400993</link><description><![CDATA[In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse.  We discuss stack ranking and "eyes open" PQC risk decisions.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2107796214</guid><pubDate>Wed, 04 Jun 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66400993/2107796214_tim_callan_root_causes_502_the_pqc_game_of_chicken.mp3" length="15825765" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse.  We discuss stack ranking and "eyes open" PQC risk decisions.</itunes:subtitle><itunes:summary><![CDATA[In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse.  We discuss stack ranking and "eyes open" PQC risk decisions.]]></itunes:summary><itunes:duration>660</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 501: Why Increasing RSA Key Size Won't Solve the Quantum Problem</title><link>https://www.spreaker.com/episode/root-causes-501-why-increasing-rsa-key-size-won-t-solve-the-quantum-problem--66370630</link><description><![CDATA[In this brief episode we explain why the problem that Shor's Algorithm poses to RSA and ECC can't be solved simply by increasing key size.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2106502629</guid><pubDate>Mon, 02 Jun 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66370630/2106502629_tim_callan_root_causes_501_why_increasing_rsa_key_size_wont_solve_the_quantum_problem.mp3" length="5175090" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this brief episode we explain why the problem that Shor's Algorithm poses to RSA and ECC can't be solved simply by increasing key size.</itunes:subtitle><itunes:summary><![CDATA[In this brief episode we explain why the problem that Shor's Algorithm poses to RSA and ECC can't be solved simply by increasing key size.]]></itunes:summary><itunes:duration>216</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 500: OMG! 500 Episodes of Root Causes!</title><link>https://www.spreaker.com/episode/root-causes-500-omg-500-episodes-of-root-causes--66340251</link><description><![CDATA[Wow. It's episode 500 of Root Causes. Jason and Tim talk about how the podcast has evolved in the past six years, how it remains consistent, and the updates we're making to keep being a valuable resource for our listeners.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2104868721</guid><pubDate>Thu, 29 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66340251/2104868721_tim_callan_root_causes_500_omg_500_episodes_of_root_causes.mp3" length="29937294" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Wow. It's episode 500 of Root Causes. Jason and Tim talk about how the podcast has evolved in the past six years, how it remains consistent, and the updates we're making to keep being a valuable resource for our listeners.</itunes:subtitle><itunes:summary><![CDATA[Wow. It's episode 500 of Root Causes. Jason and Tim talk about how the podcast has evolved in the past six years, how it remains consistent, and the updates we're making to keep being a valuable resource for our listeners.]]></itunes:summary><itunes:duration>1247</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 499: Don't Blame Signal</title><link>https://www.spreaker.com/episode/root-causes-499-don-t-blame-signal--66294306</link><description><![CDATA[The recent Signal controversy highlights the importance of understanding what protections an E2EE messaging app provides, and what it does not.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2103122133</guid><pubDate>Tue, 27 May 2025 14:21:21 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66294306/2103122133_tim_callan_root_causes_499_dont_blame_signal.mp3" length="12431510" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The recent Signal controversy highlights the importance of understanding what protections an E2EE messaging app provides, and what it does not.</itunes:subtitle><itunes:summary><![CDATA[The recent Signal controversy highlights the importance of understanding what protections an E2EE messaging app provides, and what it does not.]]></itunes:summary><itunes:duration>518</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 498: UK NCSC PQC Guidance</title><link>https://www.spreaker.com/episode/root-causes-498-uk-ncsc-pqc-guidance--66233547</link><description><![CDATA[The UK National Cyber Security Centre (NCSC) has released new PQC guidance. We take exception to the dates it gives and explain why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2101077546</guid><pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66233547/2101077546_tim_callan_root_causes_498_uk_ncsc_pqc_guidance.mp3" length="22358302" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The UK National Cyber Security Centre (NCSC) has released new PQC guidance. We take exception to the dates it gives and explain why.</itunes:subtitle><itunes:summary><![CDATA[The UK National Cyber Security Centre (NCSC) has released new PQC guidance. We take exception to the dates it gives and explain why.]]></itunes:summary><itunes:duration>932</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 497: PQC Update with Sofia Celi</title><link>https://www.spreaker.com/episode/root-causes-497-pqc-update-with-sofia-celi--66192928</link><description><![CDATA[Guest Sofia Celi (IETF, Brave) returns to talk about important developments in post quantum cryptography. Sofia tells us about her candidate algorithm MAYO and what is happening with the NIST PQC onramp.  We learn about KEM TLS and the status of PQC initiatives in IETF.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2099864202</guid><pubDate>Wed, 21 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66192928/2099864202_tim_callan_root_causes_497_pqc_update_with_sofia_celi.mp3" length="28577366" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Guest Sofia Celi (IETF, Brave) returns to talk about important developments in post quantum cryptography. Sofia tells us about her candidate algorithm MAYO and what is happening with the NIST PQC onramp.  We learn about KEM TLS and the status of PQC...</itunes:subtitle><itunes:summary><![CDATA[Guest Sofia Celi (IETF, Brave) returns to talk about important developments in post quantum cryptography. Sofia tells us about her candidate algorithm MAYO and what is happening with the NIST PQC onramp.  We learn about KEM TLS and the status of PQC initiatives in IETF.]]></itunes:summary><itunes:duration>1191</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 496: E2EE Gmail</title><link>https://www.spreaker.com/episode/root-causes-496-e2ee-gmail--66153718</link><description><![CDATA[Gmail is now end-to-end encrypted for all recipients, regardless of the receiving client. We explain how Gmail accomplishes this trick.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2098574670</guid><pubDate>Sun, 18 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66153718/2098574670_tim_callan_root_causes_496_gmail_e2ee.mp3" length="17921358" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Gmail is now end-to-end encrypted for all recipients, regardless of the receiving client. We explain how Gmail accomplishes this trick.</itunes:subtitle><itunes:summary><![CDATA[Gmail is now end-to-end encrypted for all recipients, regardless of the receiving client. We explain how Gmail accomplishes this trick.]]></itunes:summary><itunes:duration>747</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 495: Trust Models and Post Quantum Cryptography</title><link>https://www.spreaker.com/episode/root-causes-495-trust-models-and-post-quantum-cryptography--66122981</link><description><![CDATA[We build on our Trust Models discussion to explore how organizations can structure their PKI for the transition to post quantum cryptography (PQC).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2097060360</guid><pubDate>Fri, 16 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66122981/2097060360_tim_callan_root_causes_495_trust_models_and_post_quantum_cryptography.mp3" length="10099868" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We build on our Trust Models discussion to explore how organizations can structure their PKI for the transition to post quantum cryptography (PQC).</itunes:subtitle><itunes:summary><![CDATA[We build on our Trust Models discussion to explore how organizations can structure their PKI for the transition to post quantum cryptography (PQC).]]></itunes:summary><itunes:duration>421</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 494: Introduction to Trust Models</title><link>https://www.spreaker.com/episode/root-causes-494-introduction-to-trust-models--66076351</link><description><![CDATA[We explain the basics of trust models and compare various models including WebPKI, private CA, and consortium models.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2095150842</guid><pubDate>Tue, 13 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66076351/2095150842_tim_callan_root_causes_494_introduction_to_trust_models.mp3" length="30481789" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We explain the basics of trust models and compare various models including WebPKI, private CA, and consortium models.</itunes:subtitle><itunes:summary><![CDATA[We explain the basics of trust models and compare various models including WebPKI, private CA, and consortium models.]]></itunes:summary><itunes:duration>1270</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 49: Disentangling Public and Private Certificate Use Cases</title><link>https://www.spreaker.com/episode/root-causes-49-disentangling-public-and-private-certificate-use-cases--65996994</link><description><![CDATA[Changing root store requirements mean CAs must separate their root hierarchies for different certificate types. We explain why enterprises should consider private CA for some use cases.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2092120323</guid><pubDate>Thu, 08 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65996994/2092120323_tim_callan_root_causes_49_disentangling_public_and_private_certificate_use_cases.mp3" length="17549318" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Changing root store requirements mean CAs must separate their root hierarchies for different certificate types. We explain why enterprises should consider private CA for some use cases.</itunes:subtitle><itunes:summary><![CDATA[Changing root store requirements mean CAs must separate their root hierarchies for different certificate types. We explain why enterprises should consider private CA for some use cases.]]></itunes:summary><itunes:duration>731</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 492: When Mandatory Security Training Sucks</title><link>https://www.spreaker.com/episode/root-causes-492-when-mandatory-security-training-sucks--65933459</link><description><![CDATA[In this episode we get excited about errors we see in mandatory security trainings.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2090859687</guid><pubDate>Tue, 06 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65933459/2090859687_tim_callan_root_causes_492_when_mandatory_security_training_sucks.mp3" length="28243866" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we get excited about errors we see in mandatory security trainings.</itunes:subtitle><itunes:summary><![CDATA[In this episode we get excited about errors we see in mandatory security trainings.]]></itunes:summary><itunes:duration>1177</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 491: RSA's Non-quantum Threat</title><link>https://www.spreaker.com/episode/root-causes-491-rsa-s-non-quantum-threat--65829712</link><description><![CDATA[We are rejoined by Dr. Michele Mosca to explore the potential threat of RSA being broken even in the absence of a quantum computing attack.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2088408507</guid><pubDate>Thu, 01 May 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65829712/2088408507_tim_callan_root_causes_491_rsas_non_quantum_threat.mp3" length="45657502" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are rejoined by Dr. Michele Mosca to explore the potential threat of RSA being broken even in the absence of a quantum computing attack.</itunes:subtitle><itunes:summary><![CDATA[We are rejoined by Dr. Michele Mosca to explore the potential threat of RSA being broken even in the absence of a quantum computing attack.]]></itunes:summary><itunes:duration>1902</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 490: Chrome and Chromium</title><link>https://www.spreaker.com/episode/root-causes-490-chrome-and-chromium--65781597</link><description><![CDATA[We define Chrome versus Chromium, explaining what each is and the difference between the two.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2086592802</guid><pubDate>Mon, 28 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65781597/2086592802_tim_callan_root_causes_490_chrome_and_chromium.mp3" length="14458457" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We define Chrome versus Chromium, explaining what each is and the difference between the two.</itunes:subtitle><itunes:summary><![CDATA[We define Chrome versus Chromium, explaining what each is and the difference between the two.]]></itunes:summary><itunes:duration>603</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 489: Does AI Nullify E2EE?</title><link>https://www.spreaker.com/episode/root-causes-489-does-ai-nullify-e2ee--65703197</link><description><![CDATA[Does AI kill end-to-end encryption?  There is a contention that the presence of AI agents in the workstream will render your confidential information visible outside the encrypted communication channels and therefore that E2EE is pointless.  We explore this argument.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2084265159</guid><pubDate>Thu, 24 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65703197/2084265159_tim_callan_root_causes_489_does_ai_nullify_e2ee.mp3" length="17394329" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Does AI kill end-to-end encryption?  There is a contention that the presence of AI agents in the workstream will render your confidential information visible outside the encrypted communication channels and therefore that E2EE is pointless.  We...</itunes:subtitle><itunes:summary><![CDATA[Does AI kill end-to-end encryption?  There is a contention that the presence of AI agents in the workstream will render your confidential information visible outside the encrypted communication channels and therefore that E2EE is pointless.  We explore this argument.]]></itunes:summary><itunes:duration>725</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 488: CABF Face-to-Face Meeting Update</title><link>https://www.spreaker.com/episode/root-causes-488-cabf-face-to-face-meeting-update--65668352</link><description><![CDATA[We explain the major news items from the most recent CA/Browser Forum face-to-face meeting in Tokyo. Topics include MPIC, 47-day certificate term, and Temporary Restraining Orders.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2083237791</guid><pubDate>Tue, 22 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65668352/2083237791_tim_callan_root_causes_488_cabf_face_to_face_meeting_update.mp3" length="8098851" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We explain the major news items from the most recent CA/Browser Forum face-to-face meeting in Tokyo. Topics include MPIC, 47-day certificate term, and Temporary Restraining Orders.</itunes:subtitle><itunes:summary><![CDATA[We explain the major news items from the most recent CA/Browser Forum face-to-face meeting in Tokyo. Topics include MPIC, 47-day certificate term, and Temporary Restraining Orders.]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 487: Security 2030</title><link>https://www.spreaker.com/episode/root-causes-487-security-2030--65614773</link><description><![CDATA[Jason and I take a peek forward at what we imagine IT security looks like in 2030.  Topics include PQC, ZTNA, "green zones," deep fakes, IoT, connected cars, agentic AI, blockchain, and CLM.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2080599090</guid><pubDate>Wed, 16 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65614773/2080599090_tim_callan_root_causes_487_security_2030.mp3" length="67210841" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason and I take a peek forward at what we imagine IT security looks like in 2030.  Topics include PQC, ZTNA, "green zones," deep fakes, IoT, connected cars, agentic AI, blockchain, and CLM.</itunes:subtitle><itunes:summary><![CDATA[Jason and I take a peek forward at what we imagine IT security looks like in 2030.  Topics include PQC, ZTNA, "green zones," deep fakes, IoT, connected cars, agentic AI, blockchain, and CLM.]]></itunes:summary><itunes:duration>2801</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 486: 47-day Maximum Term Ballot Passes CABF</title><link>https://www.spreaker.com/episode/root-causes-486-47-day-maximum-term-ballot-passes-cabf--65569756</link><description><![CDATA[Apple's ballot to step the maximum term for public SSL certificates down to 47 days has passed in the CA/Browser Forum.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2078508100</guid><pubDate>Mon, 14 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65569756/2078508100_tim_callan_root_causes_486_47_day_maximum_term_ballot_passes_cabf.mp3" length="16130005" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple's ballot to step the maximum term for public SSL certificates down to 47 days has passed in the CA/Browser Forum.  We explain.</itunes:subtitle><itunes:summary><![CDATA[Apple's ballot to step the maximum term for public SSL certificates down to 47 days has passed in the CA/Browser Forum.  We explain.]]></itunes:summary><itunes:duration>672</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 485: What Is Open MPIC?</title><link>https://www.spreaker.com/episode/root-causes-485-what-is-open-mpic--65554045</link><description><![CDATA[Guest Dmitry Sharkov joins us to describe Open MPIC, the open-source project to help public CAs support MPIC.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2077377660</guid><pubDate>Sun, 13 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65554045/2077377660_tim_callan_root_causes_485_what_is_open_mpic.mp3" length="29485120" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Guest Dmitry Sharkov joins us to describe Open MPIC, the open-source project to help public CAs support MPIC.</itunes:subtitle><itunes:summary><![CDATA[Guest Dmitry Sharkov joins us to describe Open MPIC, the open-source project to help public CAs support MPIC.]]></itunes:summary><itunes:duration>1229</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 484: Multi Good Factor Authentication</title><link>https://www.spreaker.com/episode/root-causes-484-multi-good-factor-authentication--65485376</link><description><![CDATA[We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2074742832</guid><pubDate>Wed, 09 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65485376/2074742832_tim_callan_root_causes_484_multi_good_factor_authentication.mp3" length="18402893" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.</itunes:subtitle><itunes:summary><![CDATA[We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.]]></itunes:summary><itunes:duration>767</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 483: Introducing the PQC Sandbox</title><link>https://www.spreaker.com/episode/root-causes-483-introducing-the-pqc-sandbox--65410672</link><description><![CDATA[We are joined by repeat guest Bruno Coulliard of Crypto4A to introduce Sectigo's new post quantum cryptography (PQC) sandbox.  The PQC sandbox allows you to get quantum resistant certificates in your hands to understand how they work with your systems.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2073183752</guid><pubDate>Mon, 07 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65410672/2073183752_tim_callan_root_causes_483_introducing_the_pqc_sandbox.mp3" length="32653128" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are joined by repeat guest Bruno Coulliard of Crypto4A to introduce Sectigo's new post quantum cryptography (PQC) sandbox.  The PQC sandbox allows you to get quantum resistant certificates in your hands to understand how they work with your systems.</itunes:subtitle><itunes:summary><![CDATA[We are joined by repeat guest Bruno Coulliard of Crypto4A to introduce Sectigo's new post quantum cryptography (PQC) sandbox.  The PQC sandbox allows you to get quantum resistant certificates in your hands to understand how they work with your systems.]]></itunes:summary><itunes:duration>1361</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 482: Microsoft and PQC</title><link>https://www.spreaker.com/episode/root-causes-482-microsoft-and-pqc--65319041</link><description><![CDATA[In this episode we explore the potential PQC future for Microsoft Active Directory Certificate Services, aka MSCA.  We discuss potential paths for Microsoft to take and their consequences.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2069215320</guid><pubDate>Wed, 02 Apr 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65319041/2069215320_tim_callan_root_causes_482_microsoft_and_pqc.mp3" length="21103757" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explore the potential PQC future for Microsoft Active Directory Certificate Services, aka MSCA.  We discuss potential paths for Microsoft to take and their consequences.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explore the potential PQC future for Microsoft Active Directory Certificate Services, aka MSCA.  We discuss potential paths for Microsoft to take and their consequences.]]></itunes:summary><itunes:duration>879</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 481: What Is Protocol Ossification?</title><link>https://www.spreaker.com/episode/root-causes-481-what-is-protocol-ossification--65258232</link><description><![CDATA[Protocol ossification is the phenomenon whereby ecosystems fail to work correctly with the full range of options included in a protocol.  This occurs when individual software components only partially support the capabilities that should be available.  We define protocol ossification, explain how and why it occurs, give real world examples, and talk about potential remedies.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2067675776</guid><pubDate>Mon, 31 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65258232/2067675776_tim_callan_root_causes_481_what_is_protocol_ossification.mp3" length="17038361" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Protocol ossification is the phenomenon whereby ecosystems fail to work correctly with the full range of options included in a protocol.  This occurs when individual software components only partially support the capabilities that should be available....</itunes:subtitle><itunes:summary><![CDATA[Protocol ossification is the phenomenon whereby ecosystems fail to work correctly with the full range of options included in a protocol.  This occurs when individual software components only partially support the capabilities that should be available.  We define protocol ossification, explain how and why it occurs, give real world examples, and talk about potential remedies.]]></itunes:summary><itunes:duration>710</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 480: White House PQC Executive Order</title><link>https://www.spreaker.com/episode/root-causes-480-white-house-pqc-executive-order--65088723</link><description><![CDATA[Many people believe that the Trump White House rescinded an important cybersecurity executive order from late days of the Biden administration.  We set the record straight.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2062434016</guid><pubDate>Mon, 24 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65088723/2062434016_tim_callan_root_causes_480_white_house_pqc_executive_order.mp3" length="14942861" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Many people believe that the Trump White House rescinded an important cybersecurity executive order from late days of the Biden administration.  We set the record straight.</itunes:subtitle><itunes:summary><![CDATA[Many people believe that the Trump White House rescinded an important cybersecurity executive order from late days of the Biden administration.  We set the record straight.]]></itunes:summary><itunes:duration>623</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 479: AI Adversarial Machine Learning</title><link>https://www.spreaker.com/episode/root-causes-479-ai-adversarial-machine-learning--65018424</link><description><![CDATA[In this episode we discuss the thinking on how adversaries can exploit the flaws in AI models to achieve unexpected and dangerous results.  We explore some potential paths of defense against attacks of this sort.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2059993472</guid><pubDate>Fri, 21 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65018424/2059993472_tim_callan_root_causes_479_ai_adversarial_machine_learning.mp3" length="18981774" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we discuss the thinking on how adversaries can exploit the flaws in AI models to achieve unexpected and dangerous results.  We explore some potential paths of defense against attacks of this sort.</itunes:subtitle><itunes:summary><![CDATA[In this episode we discuss the thinking on how adversaries can exploit the flaws in AI models to achieve unexpected and dangerous results.  We explore some potential paths of defense against attacks of this sort.]]></itunes:summary><itunes:duration>791</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 478: Should We All Switch from RSA to ECC?</title><link>https://www.spreaker.com/episode/root-causes-478-should-we-all-switch-from-rsa-to-ecc--64939104</link><description><![CDATA[RSA is under attack.  Even without the quantum threat, we face the possibility of smart new exploits reducing the viable RSA key space and rendering it unsafe.  In this episode we discuss the merits of choosing ECC over RSA as soon as today.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2056487756</guid><pubDate>Mon, 17 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64939104/2056487756_tim_callan_root_causes_478_should_we_all_switch_from_rsa_to_ecc.mp3" length="23075426" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>RSA is under attack.  Even without the quantum threat, we face the possibility of smart new exploits reducing the viable RSA key space and rendering it unsafe.  In this episode we discuss the merits of choosing ECC over RSA as soon as today.</itunes:subtitle><itunes:summary><![CDATA[RSA is under attack.  Even without the quantum threat, we face the possibility of smart new exploits reducing the viable RSA key space and rendering it unsafe.  In this episode we discuss the merits of choosing ECC over RSA as soon as today.]]></itunes:summary><itunes:duration>962</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 477: Comparative Security Philosophies</title><link>https://www.spreaker.com/episode/root-causes-477-comparative-security-philosophies--64863266</link><description><![CDATA[We discuss how various popular computing platforms approach security and highlight the differences between them.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2053413672</guid><pubDate>Wed, 12 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64863266/2048313032_tim_callan_root_causes_475_can_your_ai_scheme_against_you.mp3" length="25730190" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss how various popular computing platforms approach security and highlight the differences between them.</itunes:subtitle><itunes:summary><![CDATA[We discuss how various popular computing platforms approach security and highlight the differences between them.]]></itunes:summary><itunes:duration>1072</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 476: The Need for Security KPIs</title><link>https://www.spreaker.com/episode/root-causes-476-the-need-for-security-kpis--64801697</link><description><![CDATA[Jason recounts a 2024 Black Hat talk about the need for objective measurements of our IT defenses and whether the good guys or bad guys are winning. Jason breaks down how to define and measure the impact of security measures.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2051426088</guid><pubDate>Mon, 10 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64801697/2051426088_tim_callan_root_causes_476_the_need_for_security_kpis.mp3" length="23865233" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason recounts a 2024 Black Hat talk about the need for objective measurements of our IT defenses and whether the good guys or bad guys are winning. Jason breaks down how to define and measure the impact of security measures.</itunes:subtitle><itunes:summary><![CDATA[Jason recounts a 2024 Black Hat talk about the need for objective measurements of our IT defenses and whether the good guys or bad guys are winning. Jason breaks down how to define and measure the impact of security measures.]]></itunes:summary><itunes:duration>995</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 475: Can Your AI Scheme Against You?</title><link>https://www.spreaker.com/episode/root-causes-475-can-your-ai-scheme-against-you--64734666</link><description><![CDATA[It's the stuff of science fiction! Interesting research shows how today's AI technology is capable of lying to and scheming against its human owners in service of its goals.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2048313032</guid><pubDate>Thu, 06 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64734666/2048313032_tim_callan_root_causes_475_can_your_ai_scheme_against_you.mp3" length="25730190" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It's the stuff of science fiction! Interesting research shows how today's AI technology is capable of lying to and scheming against its human owners in service of its goals.</itunes:subtitle><itunes:summary><![CDATA[It's the stuff of science fiction! Interesting research shows how today's AI technology is capable of lying to and scheming against its human owners in service of its goals.]]></itunes:summary><itunes:duration>1072</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 474: Explaining Shor's Algorithm</title><link>https://www.spreaker.com/episode/root-causes-474-explaining-shor-s-algorithm--64677070</link><description><![CDATA[We talk a lot about Shor's Algorithm in our discussion of post quantum cryptography (PQC). In this episode Jason explains Shor's algorithm for non-quantum physicists.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2046049128</guid><pubDate>Sun, 02 Mar 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64677070/2046049128_tim_callan_root_causes_474_explaining_shors_algorithm.mp3" length="30546108" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We talk a lot about Shor's Algorithm in our discussion of post quantum cryptography (PQC). In this episode Jason explains Shor's algorithm for non-quantum physicists.</itunes:subtitle><itunes:summary><![CDATA[We talk a lot about Shor's Algorithm in our discussion of post quantum cryptography (PQC). In this episode Jason explains Shor's algorithm for non-quantum physicists.]]></itunes:summary><itunes:duration>1273</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 473: Does Security Software Lack Creativity?</title><link>https://www.spreaker.com/episode/root-causes-473-does-security-software-lack-creativity--64632053</link><description><![CDATA[Jason reports on a 2024 Black Hat keynote about how modern software development practices inhibit innovation and invention.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2044298648</guid><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64632053/2044298648_tim_callan_root_causes_473_does_security_software_lack_creativity.mp3" length="14624951" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason reports on a 2024 Black Hat keynote about how modern software development practices inhibit innovation and invention.</itunes:subtitle><itunes:summary><![CDATA[Jason reports on a 2024 Black Hat keynote about how modern software development practices inhibit innovation and invention.]]></itunes:summary><itunes:duration>609</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 472: AI Offensive Modeling</title><link>https://www.spreaker.com/episode/root-causes-472-ai-offensive-modeling--64593213</link><description><![CDATA[AI tools are now available to perform red-teaming activity for DevSecOps. Such tools are soon to be table stakes in the constantly escalating IT security arms race. Join us to learn more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2042806264</guid><pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64593213/2042806264_tim_callan_root_causes_472_ai_offensive_modeling.mp3" length="16207758" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>AI tools are now available to perform red-teaming activity for DevSecOps. Such tools are soon to be table stakes in the constantly escalating IT security arms race. Join us to learn more.</itunes:subtitle><itunes:summary><![CDATA[AI tools are now available to perform red-teaming activity for DevSecOps. Such tools are soon to be table stakes in the constantly escalating IT security arms race. Join us to learn more.]]></itunes:summary><itunes:duration>675</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 471: ACME for PQC</title><link>https://www.spreaker.com/episode/root-causes-471-acme-for-pqc--64550176</link><description><![CDATA[In this episode, guest Alexandre Giron explains what is needed to support post quantum cryptography (PQC) with ACME.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2041444764</guid><pubDate>Sun, 23 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64550176/2041444764_tim_callan_root_causes_471_acme_for_pqc.mp3" length="30928600" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode, guest Alexandre Giron explains what is needed to support post quantum cryptography (PQC) with ACME.</itunes:subtitle><itunes:summary><![CDATA[In this episode, guest Alexandre Giron explains what is needed to support post quantum cryptography (PQC) with ACME.]]></itunes:summary><itunes:duration>1289</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 470: The MFA False Equivalency Fallacy</title><link>https://www.spreaker.com/episode/root-causes-470-the-mfa-false-equivalency-fallacy--64456394</link><description><![CDATA[Not all forms of MFA are equally secure. In this episode we describe the differences between the more secure and less secure forms of MFA.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2038025565</guid><pubDate>Wed, 19 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64456394/2038025565_tim_callan_root_causes_470_the_mfa_false_equivalency_fallacy.mp3" length="17132253" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Not all forms of MFA are equally secure. In this episode we describe the differences between the more secure and less secure forms of MFA.</itunes:subtitle><itunes:summary><![CDATA[Not all forms of MFA are equally secure. In this episode we describe the differences between the more secure and less secure forms of MFA.]]></itunes:summary><itunes:duration>714</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 469: The All or Nothing Fallacy in Cybersecurity</title><link>https://www.spreaker.com/episode/root-causes-469-the-all-or-nothing-fallacy-in-cybersecurity--64421810</link><description><![CDATA[In this episode we explain the all-or-nothing fallacy in cybersecurity and how it's affecting debate in the WebPKI right now.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2036696852</guid><pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64421810/2036696852_tim_callan_root_causes_469_the_all_or_nothing_fallacy_in_cybersecurity.mp3" length="10444243" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain the all-or-nothing fallacy in cybersecurity and how it's affecting debate in the WebPKI right now.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain the all-or-nothing fallacy in cybersecurity and how it's affecting debate in the WebPKI right now.]]></itunes:summary><itunes:duration>435</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 468: UK Demands New Backdoor from Apple</title><link>https://www.spreaker.com/episode/root-causes-468-uk-demands-new-backdoor-from-apple--64382866</link><description><![CDATA[A new demand from the UK seeks complete access to all Apple cloud data housed in the UK, regardless of the data owners' citizenship and residency. We unpack this latest development in Government versus Encryption.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2034665888</guid><pubDate>Fri, 14 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64382866/2034665888_tim_callan_root_causes_468_uk_demands_new_backdoor_from_apple.mp3" length="15033888" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new demand from the UK seeks complete access to all Apple cloud data housed in the UK, regardless of the data owners' citizenship and residency. We unpack this latest development in Government versus Encryption.</itunes:subtitle><itunes:summary><![CDATA[A new demand from the UK seeks complete access to all Apple cloud data housed in the UK, regardless of the data owners' citizenship and residency. We unpack this latest development in Government versus Encryption.]]></itunes:summary><itunes:duration>626</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 467: Decoupling Public from Private Use Cases</title><link>https://www.spreaker.com/episode/root-causes-467-decoupling-public-from-private-use-cases--64346856</link><description><![CDATA[The past year has seen a great deal of focus on the use of public TLS certificates where private root certificates are actually the appropriate solution. In this episode we discuss the differences between these two use cases and what IT organizations can do about it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2032792768</guid><pubDate>Wed, 12 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64346856/2032792768_tim_callan_root_causes_467_decoupling_public_from_private_use_cases.mp3" length="13955731" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The past year has seen a great deal of focus on the use of public TLS certificates where private root certificates are actually the appropriate solution. In this episode we discuss the differences between these two use cases and what IT organizations...</itunes:subtitle><itunes:summary><![CDATA[The past year has seen a great deal of focus on the use of public TLS certificates where private root certificates are actually the appropriate solution. In this episode we discuss the differences between these two use cases and what IT organizations can do about it.]]></itunes:summary><itunes:duration>582</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 466: Apple Moves 47-day Ballot to CABF Vote</title><link>https://www.spreaker.com/episode/root-causes-466-apple-moves-47-day-ballot-to-cabf-vote--64300053</link><description><![CDATA[Apple is proceeding with a ballot that eventually will shorten SSL certificate maximum term to 47 days.  Accompanying the ballot, Apple released a statement explaining its intent with the ballot.  In this episode we unpack its statements.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2030851460</guid><pubDate>Sun, 09 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64300053/2030851460_tim_callan_root_causes_466_apple_moves_47_day_ballot_to_cabf_vote.mp3" length="45162131" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple is proceeding with a ballot that eventually will shorten SSL certificate maximum term to 47 days.  Accompanying the ballot, Apple released a statement explaining its intent with the ballot.  In this episode we unpack its statements.</itunes:subtitle><itunes:summary><![CDATA[Apple is proceeding with a ballot that eventually will shorten SSL certificate maximum term to 47 days.  Accompanying the ballot, Apple released a statement explaining its intent with the ballot.  In this episode we unpack its statements.]]></itunes:summary><itunes:duration>1882</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 465: Twelve Bugzilla Sins for CAs to Avoid</title><link>https://www.spreaker.com/episode/root-causes-465-twelve-bugzilla-sins-for-cas-to-avoid--64255638</link><description><![CDATA[In the wake of the Bugzilla Bloodbath, we list and describe twelve sins CAs commit on Bugzilla and its like, why they're detrimental, and how CAs should avoid them.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2028856520</guid><pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64255638/2028856520_tim_callan_root_causes_465_twelve_bugzilla_sins_for_cas_to_avoid.mp3" length="61682969" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the wake of the Bugzilla Bloodbath, we list and describe twelve sins CAs commit on Bugzilla and its like, why they're detrimental, and how CAs should avoid them.</itunes:subtitle><itunes:summary><![CDATA[In the wake of the Bugzilla Bloodbath, we list and describe twelve sins CAs commit on Bugzilla and its like, why they're detrimental, and how CAs should avoid them.]]></itunes:summary><itunes:duration>2570</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 464: Defending Against Harvest and Decrypt</title><link>https://www.spreaker.com/episode/root-causes-464-defending-against-harvest-and-decrypt--64213190</link><description><![CDATA[Harvest and decrypt is a well-known attack vector against traditional cryptography prior to PQC. In this episode, we discuss what enterprises should be doing today to defend themselves against harvest and decrypt.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2026921772</guid><pubDate>Wed, 05 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64213190/2026921772_tim_callan_root_causes_464_defending_against_harvest_and_decrypt.mp3" length="14158481" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Harvest and decrypt is a well-known attack vector against traditional cryptography prior to PQC. In this episode, we discuss what enterprises should be doing today to defend themselves against harvest and decrypt.</itunes:subtitle><itunes:summary><![CDATA[Harvest and decrypt is a well-known attack vector against traditional cryptography prior to PQC. In this episode, we discuss what enterprises should be doing today to defend themselves against harvest and decrypt.]]></itunes:summary><itunes:duration>590</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 463: Cellular Networks Are Insecure</title><link>https://www.spreaker.com/episode/root-causes-463-cellular-networks-are-insecure--64181739</link><description><![CDATA[In this episode we explain that all cellular networks, contrary to popular belief, are fundamentally insecure.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2025470748</guid><pubDate>Mon, 03 Feb 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64181739/2025470748_tim_callan_root_causes_463_cellular_networks_are_insecure.mp3" length="17805581" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain that all cellular networks, contrary to popular belief, are fundamentally insecure.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain that all cellular networks, contrary to popular belief, are fundamentally insecure.]]></itunes:summary><itunes:duration>742</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 462: Crypto War 3.0</title><link>https://www.spreaker.com/episode/root-causes-462-crypto-war-3-0--64092284</link><description><![CDATA[In this episode we walk through the evolution of the war on cryptography, from the beginning up through today, terminating in what we call Crypto War 3.0.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2022889132</guid><pubDate>Fri, 31 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64092284/2022889132_tim_callan_root_causes_462_crypto_war_30.mp3" length="32110541" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we walk through the evolution of the war on cryptography, from the beginning up through today, terminating in what we call Crypto War 3.0.</itunes:subtitle><itunes:summary><![CDATA[In this episode we walk through the evolution of the war on cryptography, from the beginning up through today, terminating in what we call Crypto War 3.0.]]></itunes:summary><itunes:duration>1338</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 461: Sectigo Acquires Entrust Public CA Business</title><link>https://www.spreaker.com/episode/root-causes-461-sectigo-acquires-entrust-public-ca-business--64008433</link><description><![CDATA[Sectigo today announced the acquisition of the Entrust public CA business. Entrust will go forward as a Sectigo reseller. Join us to learn the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2021187861</guid><pubDate>Wed, 29 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64008433/2021187861_tim_callan_root_causes_461_sectigo_acquires_entrust_public_ca_business.mp3" length="15103593" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Sectigo today announced the acquisition of the Entrust public CA business. Entrust will go forward as a Sectigo reseller. Join us to learn the details.</itunes:subtitle><itunes:summary><![CDATA[Sectigo today announced the acquisition of the Entrust public CA business. Entrust will go forward as a Sectigo reseller. Join us to learn the details.]]></itunes:summary><itunes:duration>629</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 460: The State of PQC with Michele Mosca</title><link>https://www.spreaker.com/episode/root-causes-460-the-state-of-pqc-with-michele-mosca--63965177</link><description><![CDATA[In this episode we are joined by Dr. Michela Mosca. We discuss his pioneering work identifying the need for post-quantum cryptography, where PQC stands today, and what the future may hold.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2020337037</guid><pubDate>Tue, 28 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63965177/2020337037_tim_callan_root_causes_460_the_state_of_pqc_with_michele_mosca.mp3" length="45823285" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we are joined by Dr. Michela Mosca. We discuss his pioneering work identifying the need for post-quantum cryptography, where PQC stands today, and what the future may hold.</itunes:subtitle><itunes:summary><![CDATA[In this episode we are joined by Dr. Michela Mosca. We discuss his pioneering work identifying the need for post-quantum cryptography, where PQC stands today, and what the future may hold.]]></itunes:summary><itunes:duration>1909</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 459: 2024 Lookback - Shortening Certificate Lifespans &amp; DCV</title><link>https://www.spreaker.com/episode/root-causes-459-2024-lookback-shortening-certificate-lifespans-dcv--63880978</link><description><![CDATA[2024 set in motion major changes for certificate lifespans and DCV.  In this episode we discuss the Apple 47-day proposal, stepping down certificate term, public versus private CA use cases, DCV reuse periods, MPIC, WHOIS, and other topics.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2017418741</guid><pubDate>Fri, 24 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63880978/2017418741_tim_callan_root_causes_459_2024_lookback_shortening_certificate_lifespans_dcv.mp3" length="17776698" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2024 set in motion major changes for certificate lifespans and DCV.  In this episode we discuss the Apple 47-day proposal, stepping down certificate term, public versus private CA use cases, DCV reuse periods, MPIC, WHOIS, and other topics.</itunes:subtitle><itunes:summary><![CDATA[2024 set in motion major changes for certificate lifespans and DCV.  In this episode we discuss the Apple 47-day proposal, stepping down certificate term, public versus private CA use cases, DCV reuse periods, MPIC, WHOIS, and other topics.]]></itunes:summary><itunes:duration>741</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 458: Apple Extends Entrust Distrust to SMIME and VMC</title><link>https://www.spreaker.com/episode/root-causes-458-apple-extends-entrust-distrust-to-smime-and-vmc--63765187</link><description><![CDATA[Apple has added itself to the Entrust distrust and has extended this distrust to S/MIME and VMC.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2013232903</guid><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63765187/2013232903_tim_callan_root_causes_458_apple_extends_entrust_distrust_to_smime_and_vmc.mp3" length="12680334" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple has added itself to the Entrust distrust and has extended this distrust to S/MIME and VMC.  We explain.</itunes:subtitle><itunes:summary><![CDATA[Apple has added itself to the Entrust distrust and has extended this distrust to S/MIME and VMC.  We explain.]]></itunes:summary><itunes:duration>528</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 457: 2024 Lookback - Guests</title><link>https://www.spreaker.com/episode/root-causes-457-2024-lookback-guests--63727969</link><description><![CDATA[We had a remarkable year on the Root Causes podcast in terms of our guests. We look back at the extremely expert guests we were lucky to talk about in 2024.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2011271827</guid><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63727969/2011271827_tim_callan_root_causes_457_2024_lookback_guests.mp3" length="16498064" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We had a remarkable year on the Root Causes podcast in terms of our guests. We look back at the extremely expert guests we were lucky to talk about in 2024.</itunes:subtitle><itunes:summary><![CDATA[We had a remarkable year on the Root Causes podcast in terms of our guests. We look back at the extremely expert guests we were lucky to talk about in 2024.]]></itunes:summary><itunes:duration>687</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 456: 2024 Lookback - Bugzilla Bloodbath</title><link>https://www.spreaker.com/episode/root-causes-456-2024-lookback-bugzilla-bloodbath--63687542</link><description><![CDATA[In this 2024 lookback episode, we give an overview of the firestorm of Bugzilla incidents that we refer to as the Bugzilla Bloodbath. The Bugzilla Bloodbath affected actions around the Entrust distrust, delayed revocation reform, 47-day SSL certificate maximum term, linting, and more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2009041287</guid><pubDate>Tue, 14 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63687542/2009041287_tim_callan_root_causes_456_2024_lookback_bugzilla_bloodbath.mp3" length="16443341" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this 2024 lookback episode, we give an overview of the firestorm of Bugzilla incidents that we refer to as the Bugzilla Bloodbath. The Bugzilla Bloodbath affected actions around the Entrust distrust, delayed revocation reform, 47-day SSL...</itunes:subtitle><itunes:summary><![CDATA[In this 2024 lookback episode, we give an overview of the firestorm of Bugzilla incidents that we refer to as the Bugzilla Bloodbath. The Bugzilla Bloodbath affected actions around the Entrust distrust, delayed revocation reform, 47-day SSL certificate maximum term, linting, and more.]]></itunes:summary><itunes:duration>685</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 455: PQC Standardization in IETF</title><link>https://www.spreaker.com/episode/root-causes-455-pqc-standardization-in-ietf--63641712</link><description><![CDATA[We talk with guest Sofia Celi of Brave Browser, who leads the IETF PQC standardization effort, about the process of setting standards for PQC-compatible digital certificates. We learn about expected timelines, hybrid strategies, the NIST PQC onramp's role, and more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2006139379</guid><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63641712/2006139379_tim_callan_root_causes_458_pqc_standardization_in_ietf.mp3" length="51707785" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We talk with guest Sofia Celi of Brave Browser, who leads the IETF PQC standardization effort, about the process of setting standards for PQC-compatible digital certificates. We learn about expected timelines, hybrid strategies, the NIST PQC onramp's...</itunes:subtitle><itunes:summary><![CDATA[We talk with guest Sofia Celi of Brave Browser, who leads the IETF PQC standardization effort, about the process of setting standards for PQC-compatible digital certificates. We learn about expected timelines, hybrid strategies, the NIST PQC onramp's role, and more.]]></itunes:summary><itunes:duration>2155</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 454: 2024 Lookback - Post quantum cryptography (PQC)</title><link>https://www.spreaker.com/episode/root-causes-454-2024-lookback-post-quantum-cryptography-pqc--63593029</link><description><![CDATA[2024 was an eventful year for post quantum cryptography (PQC). This includes FIPS standards, the PQC onramp, and the dawn of widespread interest among IT professionals.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/2002529759</guid><pubDate>Thu, 02 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63593029/2002529759_tim_callan_root_causes_454_2024_lookback_post_quantum_cryptography_pqc.mp3" length="11173998" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2024 was an eventful year for post quantum cryptography (PQC). This includes FIPS standards, the PQC onramp, and the dawn of widespread interest among IT professionals.</itunes:subtitle><itunes:summary><![CDATA[2024 was an eventful year for post quantum cryptography (PQC). This includes FIPS standards, the PQC onramp, and the dawn of widespread interest among IT professionals.]]></itunes:summary><itunes:duration>466</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 453: It Turns Out Monkeys Couldn't Type Shakespeare After All</title><link>https://www.spreaker.com/episode/root-causes-453-it-turns-out-monkeys-couldn-t-type-shakespeare-after-all--63550137</link><description><![CDATA[The old adage states that a monkey in front of a keyboard, given enough time, could randomly type the works of Shakespeare. Apparently, someone ran the numbers and said not so much. We break it down and explain why we're discussing this on a PKI podcast.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1999604727</guid><pubDate>Thu, 02 Jan 2025 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63550137/1999604727_tim_callan_root_causes_453_it_turns_out_monkeys_couldnt_type_shakespeare_after_all.mp3" length="20472419" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The old adage states that a monkey in front of a keyboard, given enough time, could randomly type the works of Shakespeare. Apparently, someone ran the numbers and said not so much. We break it down and explain why we're discussing this on a PKI podcast.</itunes:subtitle><itunes:summary><![CDATA[The old adage states that a monkey in front of a keyboard, given enough time, could randomly type the works of Shakespeare. Apparently, someone ran the numbers and said not so much. We break it down and explain why we're discussing this on a PKI podcast.]]></itunes:summary><itunes:duration>853</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 452: 2024 Predictions Scorecard</title><link>https://www.spreaker.com/episode/root-causes-452-2024-predictions-scorecard--63523061</link><description><![CDATA[We go over our predictions for 2024 and score our ability as prognosticators.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1997604011</guid><pubDate>Thu, 26 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63523061/1997604011_tim_callan_root_causes_452_2024_predictions_scorecard.mp3" length="15344753" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We go over our predictions for 2024 and score our ability as prognosticators.</itunes:subtitle><itunes:summary><![CDATA[We go over our predictions for 2024 and score our ability as prognosticators.]]></itunes:summary><itunes:duration>639</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 451: A Year in CABF Ballots</title><link>https://www.spreaker.com/episode/root-causes-451-a-year-in-cabf-ballots--63477430</link><description><![CDATA[It was a crazy year for CA/Browser Forum activity, with nearly three times the normal number of ballots.  Guest Martijn Katerbarg goes over the 32 CABF ballots from 2024.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1994787347</guid><pubDate>Thu, 26 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63477430/1994787347_tim_callan_root_causes_451_a_year_in_cabf_ballots.mp3" length="50130708" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It was a crazy year for CA/Browser Forum activity, with nearly three times the normal number of ballots.  Guest Martijn Katerbarg goes over the 32 CABF ballots from 2024.</itunes:subtitle><itunes:summary><![CDATA[It was a crazy year for CA/Browser Forum activity, with nearly three times the normal number of ballots.  Guest Martijn Katerbarg goes over the 32 CABF ballots from 2024.]]></itunes:summary><itunes:duration>2089</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 450: 2025 Predictions</title><link>https://www.spreaker.com/episode/root-causes-450-2025-predictions--63450001</link><description><![CDATA[We make our 2025 predictions. Topics include maximum certificate term, AI, post-quantum cryptography (PQC), deep fakes, and more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1992842707</guid><pubDate>Mon, 23 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63450001/1992842707_tim_callan_root_causes_450_2025_predictions.mp3" length="69827027" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We make our 2025 predictions. Topics include maximum certificate term, AI, post-quantum cryptography (PQC), deep fakes, and more.</itunes:subtitle><itunes:summary><![CDATA[We make our 2025 predictions. Topics include maximum certificate term, AI, post-quantum cryptography (PQC), deep fakes, and more.]]></itunes:summary><itunes:duration>2910</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 449: What Is a Quantum-safe HSM?</title><link>https://www.spreaker.com/episode/root-causes-449-what-is-a-quantum-safe-hsm--63400476</link><description><![CDATA[Repeat guest Bruno Coulliard of Crypto4A joins us to define a quantum-safe (or PQC enabled) hardware security module.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1990147511</guid><pubDate>Wed, 18 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63400476/1990147511_tim_callan_root_causes_449_what_is_a_quantum_safe_hsm.mp3" length="34299336" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Bruno Coulliard of Crypto4A joins us to define a quantum-safe (or PQC enabled) hardware security module.</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Bruno Coulliard of Crypto4A joins us to define a quantum-safe (or PQC enabled) hardware security module.]]></itunes:summary><itunes:duration>1429</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 448: The Privilege of Being a Public CA</title><link>https://www.spreaker.com/episode/root-causes-448-the-privilege-of-being-a-public-ca--63357686</link><description><![CDATA[We go over Tim's September 2024 keynote speech at ENISA CA Day, "The Privilege of Being a Public CA."]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1988187447</guid><pubDate>Tue, 17 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63357686/1988187447_tim_callan_root_causes_448_the_privilege_of_being_a_public_ca.mp3" length="36969694" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We go over Tim's September 2024 keynote speech at ENISA CA Day, "The Privilege of Being a Public CA."</itunes:subtitle><itunes:summary><![CDATA[We go over Tim's September 2024 keynote speech at ENISA CA Day, "The Privilege of Being a Public CA."]]></itunes:summary><itunes:duration>1540</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 447: NIST Deprecates RSA-2048 and ECC 256</title><link>https://www.spreaker.com/episode/root-causes-447-nist-deprecates-rsa-2048-and-ecc-256--63321788</link><description><![CDATA[As part of its post-quantum cryptography (PQC) initiative NIST has released a draft deprecating RSA-2048 and ECC 256 by 2030 and disallowing them by 2035.  We get into the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1985034099</guid><pubDate>Fri, 13 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63321788/1985034099_tim_callan_root_causes_447_nist_deprecates_rsa_2048_and_ecc_256.mp3" length="19844642" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As part of its post-quantum cryptography (PQC) initiative NIST has released a draft deprecating RSA-2048 and ECC 256 by 2030 and disallowing them by 2035.  We get into the details.</itunes:subtitle><itunes:summary><![CDATA[As part of its post-quantum cryptography (PQC) initiative NIST has released a draft deprecating RSA-2048 and ECC 256 by 2030 and disallowing them by 2035.  We get into the details.]]></itunes:summary><itunes:duration>827</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 446: Sectigo Assumes Five CABF Offices</title><link>https://www.spreaker.com/episode/root-causes-446-sectigo-assumes-five-cabf-offices--63286017</link><description><![CDATA[Tim has stepped into the position of vice-chair of the CA/Browse Forum, and Sectigo now holds five chair or vice-chair positions in that body.  We explain how leadership is chosen, the offices Sectigo holds today, and some of our vision for CABF in the next two years.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1982042035</guid><pubDate>Thu, 12 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63286017/1982042035_tim_callan_root_causes_446_sectigo_assumes_five_cabf_offices.mp3" length="19223048" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Tim has stepped into the position of vice-chair of the CA/Browse Forum, and Sectigo now holds five chair or vice-chair positions in that body.  We explain how leadership is chosen, the offices Sectigo holds today, and some of our vision for CABF in...</itunes:subtitle><itunes:summary><![CDATA[Tim has stepped into the position of vice-chair of the CA/Browse Forum, and Sectigo now holds five chair or vice-chair positions in that body.  We explain how leadership is chosen, the offices Sectigo holds today, and some of our vision for CABF in the next two years.]]></itunes:summary><itunes:duration>801</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 445: Seven Reasons to Shorten Certificate Lifespans</title><link>https://www.spreaker.com/episode/root-causes-445-seven-reasons-to-shorten-certificate-lifespans--63241595</link><description><![CDATA[We take a deep dive into the seven reasons shorter certificate lifespans are better.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1977851671</guid><pubDate>Mon, 09 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63241595/1977851671_tim_callan_root_causes_445_seven_reasons_to_shorten_certificate_lifespans.mp3" length="40251756" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We take a deep dive into the seven reasons shorter certificate lifespans are better.</itunes:subtitle><itunes:summary><![CDATA[We take a deep dive into the seven reasons shorter certificate lifespans are better.]]></itunes:summary><itunes:duration>1677</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 444: What Happens to the WebPKI if Google Sells Chrome</title><link>https://www.spreaker.com/episode/root-causes-444-what-happens-to-the-webpki-if-google-sells-chrome--63189302</link><description><![CDATA[We discuss how a potential break of Chrome from Google would affect the WebPKI.  We look at product changes, resourcing, post-quantum cryptography (PQC), innovation, moonshot initiatives, and other public CAs.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1975298595</guid><pubDate>Fri, 06 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63189302/1975298595_tim_callan_root_causes_444_what_happens_to_the_webpki_if_google_sells_chrome.mp3" length="27993327" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss how a potential break of Chrome from Google would affect the WebPKI.  We look at product changes, resourcing, post-quantum cryptography (PQC), innovation, moonshot initiatives, and other public CAs.</itunes:subtitle><itunes:summary><![CDATA[We discuss how a potential break of Chrome from Google would affect the WebPKI.  We look at product changes, resourcing, post-quantum cryptography (PQC), innovation, moonshot initiatives, and other public CAs.]]></itunes:summary><itunes:duration>1166</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 443: Is MSCA Going Away?</title><link>https://www.spreaker.com/episode/root-causes-443-is-msca-going-away--63126558</link><description><![CDATA[In this episode we discuss the challenges for enterprises using Microsoft Active Directory Certificate Services (ADCS).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1972603803</guid><pubDate>Sun, 01 Dec 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63126558/1972603803_tim_callan_root_causes_443_is_msca_going_away.mp3" length="19270954" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we discuss the challenges for enterprises using Microsoft Active Directory Certificate Services (ADCS).</itunes:subtitle><itunes:summary><![CDATA[In this episode we discuss the challenges for enterprises using Microsoft Active Directory Certificate Services (ADCS).]]></itunes:summary><itunes:duration>803</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 442: Apple Proposal to Reduce SSL Lifespan Updated</title><link>https://www.spreaker.com/episode/root-causes-442-apple-proposal-to-reduce-ssl-lifespan-updated--63007147</link><description><![CDATA[Apple has published an updated draft to its proposal for shortening the lifespan of SSL certificates, including a final maximum term of 47 rather than 45 days.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1967062967</guid><pubDate>Mon, 25 Nov 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63007147/1967062967_tim_callan_root_causes_442_apple_proposal_to_reduce_ssl_lifespan_updated.mp3" length="32003434" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple has published an updated draft to its proposal for shortening the lifespan of SSL certificates, including a final maximum term of 47 rather than 45 days.  We explain.</itunes:subtitle><itunes:summary><![CDATA[Apple has published an updated draft to its proposal for shortening the lifespan of SSL certificates, including a final maximum term of 47 rather than 45 days.  We explain.]]></itunes:summary><itunes:duration>1334</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 441: New White House Initiative Targets BGP</title><link>https://www.spreaker.com/episode/root-causes-441-new-white-house-initiative-targets-bgp--62972261</link><description><![CDATA[A new White House initiative requires that federal agencies need to create plans to thwart BGP attacks. We discuss, including Resource PKI (RPKI) and Multi-Perspective Issuance Corroboration (MPIC).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1965001483</guid><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62972261/1965001483_tim_callan_root_causes_441_new_white_house_initative_targets_bgp.mp3" length="21440163" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new White House initiative requires that federal agencies need to create plans to thwart BGP attacks. We discuss, including Resource PKI (RPKI) and Multi-Perspective Issuance Corroboration (MPIC).</itunes:subtitle><itunes:summary><![CDATA[A new White House initiative requires that federal agencies need to create plans to thwart BGP attacks. We discuss, including Resource PKI (RPKI) and Multi-Perspective Issuance Corroboration (MPIC).]]></itunes:summary><itunes:duration>893</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 440: Public Key Directories</title><link>https://www.spreaker.com/episode/root-causes-440-public-key-directories--62793270</link><description><![CDATA[We talk about public key directories and complicating factors such as Tailscale, VPN, TOR, Cloudflare, and Zero Trust.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1961462419</guid><pubDate>Mon, 18 Nov 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62793270/1961462419_tim_callan_root_causes_440_public_key_directories.mp3" length="18678848" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We talk about public key directories and complicating factors such as Tailscale, VPN, TOR, Cloudflare, and Zero Trust.</itunes:subtitle><itunes:summary><![CDATA[We talk about public key directories and complicating factors such as Tailscale, VPN, TOR, Cloudflare, and Zero Trust.]]></itunes:summary><itunes:duration>778</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 439: PQC Onramp Narrowed Down to 15 Candidates</title><link>https://www.spreaker.com/episode/root-causes-439-pqc-onramp-narrowed-down-to-15-candidates--62758143</link><description><![CDATA[NIST has narrowed its PQC onramp contest to 15 candidates.  We go over who remains and the makeup of the remaining candidates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1959260607</guid><pubDate>Fri, 15 Nov 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62758143/1959260607_tim_callan_root_causes_439_pqc_onramp_narrowed_down_to_15_candidates.mp3" length="24809195" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST has narrowed its PQC onramp contest to 15 candidates.  We go over who remains and the makeup of the remaining candidates.</itunes:subtitle><itunes:summary><![CDATA[NIST has narrowed its PQC onramp contest to 15 candidates.  We go over who remains and the makeup of the remaining candidates.]]></itunes:summary><itunes:duration>1034</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 438: PQC Is an Existential Requirement</title><link>https://www.spreaker.com/episode/root-causes-438-pqc-is-an-existential-requirement--62710624</link><description><![CDATA[Repeat guest Bruno Couillard argues that cryptography is part of the foundational fabric of our lives and that the transition to PQC is an existential requirement.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1956475447</guid><pubDate>Tue, 12 Nov 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62710624/1956475447_tim_callan_root_causes_438_pqc_is_an_existential_requirement.mp3" length="40801800" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Bruno Couillard argues that cryptography is part of the foundational fabric of our lives and that the transition to PQC is an existential requirement.</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Bruno Couillard argues that cryptography is part of the foundational fabric of our lives and that the transition to PQC is an existential requirement.]]></itunes:summary><itunes:duration>1700</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 437: Don't Blame the Linter</title><link>https://www.spreaker.com/episode/root-causes-437-don-t-blame-the-linter--62623689</link><description><![CDATA[Linters are essential tools for maintaining quality of certificate issuance. Public open-source linters are available to help CAs assure compliance. As a result, CAs have begun attributing gaps in coverage by public linters as the root cause for misissuance events. We explain why this is faulty reasoning.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1950186751</guid><pubDate>Tue, 05 Nov 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62623689/1950186751_tim_callan_root_causes_437_dont_blame_the_linter.mp3" length="16370211" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Linters are essential tools for maintaining quality of certificate issuance. Public open-source linters are available to help CAs assure compliance. As a result, CAs have begun attributing gaps in coverage by public linters as the root cause for...</itunes:subtitle><itunes:summary><![CDATA[Linters are essential tools for maintaining quality of certificate issuance. Public open-source linters are available to help CAs assure compliance. As a result, CAs have begun attributing gaps in coverage by public linters as the root cause for misissuance events. We explain why this is faulty reasoning.]]></itunes:summary><itunes:duration>682</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 436: Formal Proofs</title><link>https://www.spreaker.com/episode/root-causes-436-formal-proofs--62546833</link><description><![CDATA[Formal proofs are critical to cryptography. We discuss how better processes and AI can accelerate formal proofs of cryptographic concepts.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1945040723</guid><pubDate>Tue, 29 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62546833/1945040723_tim_callan_root_causes_436_formal_proofs.mp3" length="14959589" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Formal proofs are critical to cryptography. We discuss how better processes and AI can accelerate formal proofs of cryptographic concepts.</itunes:subtitle><itunes:summary><![CDATA[Formal proofs are critical to cryptography. We discuss how better processes and AI can accelerate formal proofs of cryptographic concepts.]]></itunes:summary><itunes:duration>623</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9e714a676f7fb5fcc6867f7de8694899.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 435: The PQC "Q Day" Is Not That Simple</title><link>https://www.spreaker.com/episode/root-causes-435-the-pqc-q-day-is-not-that-simple--62503481</link><description><![CDATA[The PQC community likes to debate when crypto relevant quantum computers will be available, which is sometimes called "Q day." In this episode we explain how radically oversimplified this concept is and dive into the nuances of what a "cryptographically relevant quantum computer" really will be.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1941928931</guid><pubDate>Fri, 25 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62503481/1941928931_tim_callan_root_causes_435_the_pqc_q_day_is_not_that_simple.mp3" length="28472541" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The PQC community likes to debate when crypto relevant quantum computers will be available, which is sometimes called "Q day." In this episode we explain how radically oversimplified this concept is and dive into the nuances of what a...</itunes:subtitle><itunes:summary><![CDATA[The PQC community likes to debate when crypto relevant quantum computers will be available, which is sometimes called "Q day." In this episode we explain how radically oversimplified this concept is and dive into the nuances of what a "cryptographically relevant quantum computer" really will be.]]></itunes:summary><itunes:duration>1186</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 434: Did Researchers Break AES Using Quantum Annealing?</title><link>https://www.spreaker.com/episode/root-causes-434-did-researchers-break-aes-using-quantum-annealing--62466271</link><description><![CDATA[News reports claim Chinese researchers broke AES with a quantum annealing computer. We clarify the details and talk about the implications of this reported discovery.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1939617755</guid><pubDate>Tue, 22 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62466271/1939617755_tim_callan_root_causes_434_did_researchers_break_aes_using_quantum_annealing.mp3" length="16897263" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>News reports claim Chinese researchers broke AES with a quantum annealing computer. We clarify the details and talk about the implications of this reported discovery.</itunes:subtitle><itunes:summary><![CDATA[News reports claim Chinese researchers broke AES with a quantum annealing computer. We clarify the details and talk about the implications of this reported discovery.]]></itunes:summary><itunes:duration>704</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 433: Will AI Eat All the Electricity?</title><link>https://www.spreaker.com/episode/root-causes-433-will-ai-eat-all-the-electricity--62401294</link><description><![CDATA[We explore the question of whether or not we have enough electricity to fuel AI's expected growth.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1936652567</guid><pubDate>Thu, 17 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62401294/1936652567_tim_callan_root_causes_433_will_ai_eat_all_the_electricity.mp3" length="15097686" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We explore the question of whether or not we have enough electricity to fuel AI's expected growth.</itunes:subtitle><itunes:summary><![CDATA[We explore the question of whether or not we have enough electricity to fuel AI's expected growth.]]></itunes:summary><itunes:duration>629</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 432: Apple Floats New Short-lived Certificate Proposal</title><link>https://www.spreaker.com/episode/root-causes-432-apple-floats-new-short-lived-certificate-proposal--62362728</link><description><![CDATA[Apple recently floated a draft CABF ballot for commentary that steps down maximum term for SSL certificates starting next year and eventually landing at 45 days in 2027.  We share the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1934900699</guid><pubDate>Mon, 14 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62362728/1934900699_tim_callan_root_causes_432_apple_floats_new_short_lived_certificate_proposal.mp3" length="37942574" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple recently floated a draft CABF ballot for commentary that steps down maximum term for SSL certificates starting next year and eventually landing at 45 days in 2027.  We share the details.</itunes:subtitle><itunes:summary><![CDATA[Apple recently floated a draft CABF ballot for commentary that steps down maximum term for SSL certificates starting next year and eventually landing at 45 days in 2027.  We share the details.]]></itunes:summary><itunes:duration>1581</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 431: New Mozilla Proposal to Combat Delayed Revocation</title><link>https://www.spreaker.com/episode/root-causes-431-new-mozilla-proposal-to-combat-delayed-revocation--62334832</link><description><![CDATA[Deliberate delay of mandatory revocations has plagued the WebPKI in 2024. A new proposed policy from Mozilla stands to eliminate most of this behavior. In this episode we go over the proposal and explain its potential consequences.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1933401902</guid><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62334832/1933401902_tim_callan_root_causes_431_new_mozilla_proposal_to_combat_delayed_revocation.mp3" length="40584111" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Deliberate delay of mandatory revocations has plagued the WebPKI in 2024. A new proposed policy from Mozilla stands to eliminate most of this behavior. In this episode we go over the proposal and explain its potential consequences.</itunes:subtitle><itunes:summary><![CDATA[Deliberate delay of mandatory revocations has plagued the WebPKI in 2024. A new proposed policy from Mozilla stands to eliminate most of this behavior. In this episode we go over the proposal and explain its potential consequences.]]></itunes:summary><itunes:duration>1691</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 430: How Does a TLS Handshake Work?</title><link>https://www.spreaker.com/episode/root-causes-430-how-does-a-tls-handshake-work--62301469</link><description><![CDATA[In this episode we give a high-level explanation of what happens in a TLS 1.3 handshake and then discuss what will happen when PQC is included.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1931716754</guid><pubDate>Wed, 09 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62301469/1931716754_tim_callan_root_causes_430_how_does_a_tls_handshake_work.mp3" length="20937884" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we give a high-level explanation of what happens in a TLS 1.3 handshake and then discuss what will happen when PQC is included.</itunes:subtitle><itunes:summary><![CDATA[In this episode we give a high-level explanation of what happens in a TLS 1.3 handshake and then discuss what will happen when PQC is included.]]></itunes:summary><itunes:duration>872</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 429: ServiceNow Outage Due to Expired Root Certificate</title><link>https://www.spreaker.com/episode/root-causes-429-servicenow-outage-due-to-expired-root-certificate--62286325</link><description><![CDATA[A ServiceNow private CA root expired, creating outages across hundreds of enterprises. We explain what appears to have gone on.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1931100317</guid><pubDate>Tue, 08 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62286325/1931100317_tim_callan_root_causes_429_servicenow_outage_due_to_expired_root_certificate.mp3" length="10186863" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A ServiceNow private CA root expired, creating outages across hundreds of enterprises. We explain what appears to have gone on.</itunes:subtitle><itunes:summary><![CDATA[A ServiceNow private CA root expired, creating outages across hundreds of enterprises. We explain what appears to have gone on.]]></itunes:summary><itunes:duration>425</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 428: .MOBI Attack Puts WHOIS-based DCV into Question</title><link>https://www.spreaker.com/episode/root-causes-428-mobi-attack-puts-whois-based-dcv-into-question--62235735</link><description><![CDATA[White hat researchers managed to take over WHOIS for the .mobi TLD. Among other things, this discovery foretells the death of WHOIS as a valid email source for Domain Control Validation (DCV).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1928975426</guid><pubDate>Fri, 04 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62235735/1928975426_tim_callan_root_causes_428_mobi_attack_puts_whois_based_dcv_into_question.mp3" length="24738928" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>White hat researchers managed to take over WHOIS for the .mobi TLD. Among other things, this discovery foretells the death of WHOIS as a valid email source for Domain Control Validation (DCV).</itunes:subtitle><itunes:summary><![CDATA[White hat researchers managed to take over WHOIS for the .mobi TLD. Among other things, this discovery foretells the death of WHOIS as a valid email source for Domain Control Validation (DCV).]]></itunes:summary><itunes:duration>1031</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 427: Mapping CLM to NIST CSF 2.0</title><link>https://www.spreaker.com/episode/root-causes-427-mapping-clm-to-nist-csf-2-0--62199378</link><description><![CDATA[In this episode we map the contributions of Certificate Lifecycle Management into the new NIST Cybersecurity Framework 2.0.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1927650551</guid><pubDate>Tue, 01 Oct 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62199378/1927650551_tim_callan_root_causes_427_mapping_clm_to_nist_csf20.mp3" length="22728853" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we map the contributions of Certificate Lifecycle Management into the new NIST Cybersecurity Framework 2.0.</itunes:subtitle><itunes:summary><![CDATA[In this episode we map the contributions of Certificate Lifecycle Management into the new NIST Cybersecurity Framework 2.0.]]></itunes:summary><itunes:duration>947</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 426: Expired Certificate Takes Down Bank of England</title><link>https://www.spreaker.com/episode/root-causes-426-expired-certificate-takes-down-bank-of-england--62167759</link><description><![CDATA[A certificate expiration is now known to have created July's outage of Bank of England.  Join us as we shake our heads in amazement yet again.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1926367928</guid><pubDate>Mon, 30 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62167759/1926367928_tim_callan_root_causes_426_expired_certificate_takes_down_bank_of_england.mp3" length="11113644" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A certificate expiration is now known to have created July's outage of Bank of England.  Join us as we shake our heads in amazement yet again.</itunes:subtitle><itunes:summary><![CDATA[A certificate expiration is now known to have created July's outage of Bank of England.  Join us as we shake our heads in amazement yet again.]]></itunes:summary><itunes:duration>463</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 425: PQC Requirements for Voting Systems</title><link>https://www.spreaker.com/episode/root-causes-425-pqc-requirements-for-voting-systems--62131925</link><description><![CDATA[In honor of the upcoming US elections, we describe the six main requirements for a post-quantum voting system.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1924900076</guid><pubDate>Fri, 27 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62131925/1924900076_tim_callan_root_causes_425_pqc_requirements_for_voting_systems.mp3" length="15689953" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In honor of the upcoming US elections, we describe the six main requirements for a post-quantum voting system.</itunes:subtitle><itunes:summary><![CDATA[In honor of the upcoming US elections, we describe the six main requirements for a post-quantum voting system.]]></itunes:summary><itunes:duration>654</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 424: Using LoRA IoT Protocol for Clandestine Communications</title><link>https://www.spreaker.com/episode/root-causes-424-using-lora-iot-protocol-for-clandestine-communications--62099677</link><description><![CDATA[In this episode we describe the LoRA protocol, which allows IoT devices to communicate securely without using a cellular network, and how it can be used for secret communications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1923108524</guid><pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62099677/1923108524_tim_callan_root_causes_424_using_lora_iot_protocol_for_clandestine_communications.mp3" length="16905296" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe the LoRA protocol, which allows IoT devices to communicate securely without using a cellular network, and how it can be used for secret communications.</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe the LoRA protocol, which allows IoT devices to communicate securely without using a cellular network, and how it can be used for secret communications.]]></itunes:summary><itunes:duration>704</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 423: Is a Certificate Software or a Service?</title><link>https://www.spreaker.com/episode/root-causes-423-is-a-certificate-software-or-a-service--62043464</link><description><![CDATA[In this episode we discuss the dual nature of a public certificate as both a file and part of a holistic service that lasts until its expiration. We discuss revocation checking, CT logging, GAAP accounting, linters, certificate tracking tools, Certificate Lifecycle Management, standards bodies, post-quantum cryptography, and subscription models.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1920227681</guid><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62043464/1920227681_tim_callan_root_causes_423_is_a_certificate_software_or_a_service.mp3" length="26602882" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we discuss the dual nature of a public certificate as both a file and part of a holistic service that lasts until its expiration. We discuss revocation checking, CT logging, GAAP accounting, linters, certificate tracking tools,...</itunes:subtitle><itunes:summary><![CDATA[In this episode we discuss the dual nature of a public certificate as both a file and part of a holistic service that lasts until its expiration. We discuss revocation checking, CT logging, GAAP accounting, linters, certificate tracking tools, Certificate Lifecycle Management, standards bodies, post-quantum cryptography, and subscription models.]]></itunes:summary><itunes:duration>1109</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 422: New Date for Entrust Distrust</title><link>https://www.spreaker.com/episode/root-causes-422-new-date-for-entrust-distrust--62030439</link><description><![CDATA[The Chrome root program has changed the date for the Entrust distrust.  Join us to get the details.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1919415614</guid><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62030439/1919415614_tim_callan_root_causes_422_new_date_for_entrust_distrust.mp3" length="6435341" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Chrome root program has changed the date for the Entrust distrust.  Join us to get the details.</itunes:subtitle><itunes:summary><![CDATA[The Chrome root program has changed the date for the Entrust distrust.  Join us to get the details.]]></itunes:summary><itunes:duration>268</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 421: FIDO 2 Implementation Problems</title><link>https://www.spreaker.com/episode/root-causes-421-fido-2-implementation-problems--61850806</link><description><![CDATA[White hat researchers have raised concerns about FIDO 2 (AKA WebAuthn).  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1917684677</guid><pubDate>Mon, 16 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61850806/1917684677_tim_callan_root_causes_421_fido_2_implementation_problems.mp3" length="12193422" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>White hat researchers have raised concerns about FIDO 2 (AKA WebAuthn).  We explain.</itunes:subtitle><itunes:summary><![CDATA[White hat researchers have raised concerns about FIDO 2 (AKA WebAuthn).  We explain.]]></itunes:summary><itunes:duration>508</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 420: New Side Channel Attack Against YubiKeys</title><link>https://www.spreaker.com/episode/root-causes-420-new-side-channel-attack-against-yubikeys--61494751</link><description><![CDATA[EUCLEAK, a newly revealed side channel vulnerability, can clone the contents of a YubiKey.  We talk about the attack and its significance.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1916210366</guid><pubDate>Fri, 13 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61494751/1916210366_tim_callan_root_causes_420_new_side_channel_attack_against_yubikeys.mp3" length="18329190" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>EUCLEAK, a newly revealed side channel vulnerability, can clone the contents of a YubiKey.  We talk about the attack and its significance.</itunes:subtitle><itunes:summary><![CDATA[EUCLEAK, a newly revealed side channel vulnerability, can clone the contents of a YubiKey.  We talk about the attack and its significance.]]></itunes:summary><itunes:duration>764</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 419 - What Happens to Vendors Who Don't Support ACME When 90-day Certificates Come?</title><link>https://www.spreaker.com/episode/root-causes-419-what-happens-to-vendors-who-don-t-support-acme-when-90-day-certificates-come--61327279</link><description><![CDATA[Though it is the closest thing to an industry-standard API, there are still products and operating systems that don't support ACME. In this episode we explore what happens to these products once 90-day SSL certificates become the requirement.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1914084548</guid><pubDate>Mon, 09 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61327279/1914084548_tim_callan_root_causes_419_what_happens_to_vendors_that_dont_support_acme_when_90_day_certificates_come.mp3" length="23392592" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Though it is the closest thing to an industry-standard API, there are still products and operating systems that don't support ACME. In this episode we explore what happens to these products once 90-day SSL certificates become the requirement.</itunes:subtitle><itunes:summary><![CDATA[Though it is the closest thing to an industry-standard API, there are still products and operating systems that don't support ACME. In this episode we explore what happens to these products once 90-day SSL certificates become the requirement.]]></itunes:summary><itunes:duration>975</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 418: Moving from Cryptographic Homogeneity to Cryptographic Heterogeneity</title><link>https://www.spreaker.com/episode/root-causes-418-moving-from-cryptographic-homogeneity-to-cryptographic-heterogeneity--61285973</link><description><![CDATA[One seldom discussed consequence of quantum computers and PQC is the move from cryptographic homogeneity to cryptographic heterogeneity, with multiple KEMs and DSAs eventually expected as ongoing standards. We examine the consequences of this change.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1911607607</guid><pubDate>Fri, 06 Sep 2024 16:48:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61285973/1911607607_tim_callan_root_causes_418_moving_from_cryptographic_homogeneity_to_cryptographic_heterogeneity.mp3" length="26530851" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>One seldom discussed consequence of quantum computers and PQC is the move from cryptographic homogeneity to cryptographic heterogeneity, with multiple KEMs and DSAs eventually expected as ongoing standards. We examine the consequences of this change.</itunes:subtitle><itunes:summary><![CDATA[One seldom discussed consequence of quantum computers and PQC is the move from cryptographic homogeneity to cryptographic heterogeneity, with multiple KEMs and DSAs eventually expected as ongoing standards. We examine the consequences of this change.]]></itunes:summary><itunes:duration>1106</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 417: Introducing pkimetal the PKI Meta-linter</title><link>https://www.spreaker.com/episode/root-causes-417-introducing-pkimetal-the-pki-meta-linter--61255600</link><description><![CDATA[We introduce pkimetal, an open source project from Rob Stradling that allows CA to write to many popular linters with a single integration.  We explain the importance and pitfalls of linters and how pkimetal improves linter implementation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1909670810</guid><pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61255600/1909670810_tim_callan_root_causes_417_introducing_pkimetal_the_pki_meta_linter.mp3" length="12604239" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We introduce pkimetal, an open source project from Rob Stradling that allows CA to write to many popular linters with a single integration.  We explain the importance and pitfalls of linters and how pkimetal improves linter implementation.</itunes:subtitle><itunes:summary><![CDATA[We introduce pkimetal, an open source project from Rob Stradling that allows CA to write to many popular linters with a single integration.  We explain the importance and pitfalls of linters and how pkimetal improves linter implementation.]]></itunes:summary><itunes:duration>525</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 416: SSL Subscriber Uses a Restraining Order to Prevent Revocation</title><link>https://www.spreaker.com/episode/root-causes-416-ssl-subscriber-uses-a-restraining-order-to-prevent-revocation--61215107</link><description><![CDATA[An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain what happened, why it's deeply problematic, how the industry might consider responding.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1907262590</guid><pubDate>Thu, 29 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61215107/1907262590_tim_callan_root_causes_416_ssl_subscriber_uses_a_restraining_order_to_prevent_revocation.mp3" length="32627259" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain what happened, why it's deeply problematic, how the industry might consider responding.</itunes:subtitle><itunes:summary><![CDATA[An enterprise SSL subscriber recently used a Temporary Restraining Order to prevent the proper revocation of misissued certificates. We explain what happened, why it's deeply problematic, how the industry might consider responding.]]></itunes:summary><itunes:duration>1360</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 415: What Can I Do with These New FIPS PQC Standards?</title><link>https://www.spreaker.com/episode/root-causes-415-what-can-i-do-with-these-new-fips-pqc-standards--61175385</link><description><![CDATA[NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1905065672</guid><pubDate>Tue, 27 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61175385/1905065672_tim_callan_root_causes_415_what_can_i_do_with_these_new_fips_pqc_standards.mp3" length="28178836" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.</itunes:subtitle><itunes:summary><![CDATA[NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.]]></itunes:summary><itunes:duration>1174</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 414: What Are the Revocation Periods for Public Certificates?</title><link>https://www.spreaker.com/episode/root-causes-414-what-are-the-revocation-periods-for-public-certificates--61127722</link><description><![CDATA[In this episode we detail the mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1902812710</guid><pubDate>Fri, 23 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61127722/1902812710_tim_callan_root_causes_414_what_are_the_revocation_periods_for_public_certificates.mp3" length="17239413" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we detail the mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.</itunes:subtitle><itunes:summary><![CDATA[In this episode we detail the mandatory revocation periods for leaf certificates and intermediates and explain when a 24-hour versus a 120-hour revocation deadline applies.]]></itunes:summary><itunes:duration>718</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 413: NIST Releases Standards for First Three PQC Algorithms</title><link>https://www.spreaker.com/episode/root-causes-413-nist-releases-standards-for-first-three-pqc-algorithms--61054928</link><description><![CDATA[On August 13, 2024, NIST released its first three standards for PQC algorithms, ML-KEM, ML-DSA, and SLH-DSA.  We tell you where to find them and talk about what happens next.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1898656380</guid><pubDate>Fri, 16 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61054928/1898656380_tim_callan_root_causes_413_nist_releases_standards_for_first_three_pqc_algorithms.mp3" length="10469022" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On August 13, 2024, NIST released its first three standards for PQC algorithms, ML-KEM, ML-DSA, and SLH-DSA.  We tell you where to find them and talk about what happens next.</itunes:subtitle><itunes:summary><![CDATA[On August 13, 2024, NIST released its first three standards for PQC algorithms, ML-KEM, ML-DSA, and SLH-DSA.  We tell you where to find them and talk about what happens next.]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 412: Google Throws in the Towel on Eliminating Cookies</title><link>https://www.spreaker.com/episode/root-causes-412-google-throws-in-the-towel-on-eliminating-cookies--61016359</link><description><![CDATA[Cookies are incredibly useful but also pose grave privacy concerns. We have in the past covered Chrome's initiatives to replace cookies.  Now Chrome has announced that for the foreseeable future cookies will remain. We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1896617820</guid><pubDate>Tue, 13 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61016359/1896617820_tim_callan_root_causes_412_google_throws_in_the_towel_on_eliminating_cookies.mp3" length="14272995" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Cookies are incredibly useful but also pose grave privacy concerns. We have in the past covered Chrome's initiatives to replace cookies.  Now Chrome has announced that for the foreseeable future cookies will remain. We explain.</itunes:subtitle><itunes:summary><![CDATA[Cookies are incredibly useful but also pose grave privacy concerns. We have in the past covered Chrome's initiatives to replace cookies.  Now Chrome has announced that for the foreseeable future cookies will remain. We explain.]]></itunes:summary><itunes:duration>595</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 411: PQC Security Levels</title><link>https://www.spreaker.com/episode/root-causes-411-pqc-security-levels--60971595</link><description><![CDATA[A popular belief is that Grover's algorithm will require that we double our AES key sizes.  Repeat guest Bas Westerbaan of Cloudflare explains why this myth is incorrect and talks through the concept of "security levels" in post-quantum cryptography.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1893269022</guid><pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60971595/1893269022_tim_callan_root_causes_411_pqc_security_levels.mp3" length="29486287" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A popular belief is that Grover's algorithm will require that we double our AES key sizes.  Repeat guest Bas Westerbaan of Cloudflare explains why this myth is incorrect and talks through the concept of "security levels" in post-quantum cryptography.</itunes:subtitle><itunes:summary><![CDATA[A popular belief is that Grover's algorithm will require that we double our AES key sizes.  Repeat guest Bas Westerbaan of Cloudflare explains why this myth is incorrect and talks through the concept of "security levels" in post-quantum cryptography.]]></itunes:summary><itunes:duration>1229</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 410: CrowdStrike, Automatic Updates, and Walled Gardens</title><link>https://www.spreaker.com/episode/root-causes-410-crowdstrike-automatic-updates-and-walled-gardens--60940291</link><description><![CDATA[We examine one specific aspect of the recent CrowdStrike flaw. Microsoft blames the problem on the fact that it must, by European law, allow kernel updates to Windows. We unpack the challenges this poses.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1890673497</guid><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60940291/1890673497_tim_callan_root_causes_410_crowdstrike_automatic_updates_and_walled_gardens.mp3" length="22293808" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We examine one specific aspect of the recent CrowdStrike flaw. Microsoft blames the problem on the fact that it must, by European law, allow kernel updates to Windows. We unpack the challenges this poses.</itunes:subtitle><itunes:summary><![CDATA[We examine one specific aspect of the recent CrowdStrike flaw. Microsoft blames the problem on the fact that it must, by European law, allow kernel updates to Windows. We unpack the challenges this poses.]]></itunes:summary><itunes:duration>929</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 409: Mozilla Distrusts Entrust</title><link>https://www.spreaker.com/episode/root-causes-409-mozilla-distrusts-entrust--60904994</link><description><![CDATA[This week Mozilla chose to follow Chrome in deprecating the Entrust trusted roots.  We give you the details and explain why this action matters.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1887737583</guid><pubDate>Fri, 02 Aug 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60904994/1887737583_tim_callan_root_causes_409_mozilla_distrusts_entrust.mp3" length="21332157" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>This week Mozilla chose to follow Chrome in deprecating the Entrust trusted roots.  We give you the details and explain why this action matters.</itunes:subtitle><itunes:summary><![CDATA[This week Mozilla chose to follow Chrome in deprecating the Entrust trusted roots.  We give you the details and explain why this action matters.]]></itunes:summary><itunes:duration>889</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 408: Takeaways from Recent Conversations with PQC Experts</title><link>https://www.spreaker.com/episode/root-causes-408-takeaways-from-recent-conversations-with-pqc-experts--60862753</link><description><![CDATA[In the past three months we featured far-ranging conversations about post-quantum cryptography (PQC) with experts Bas Westerbaan of Cloudflare, Dustin Moody of NIST, and Bruno Coulliard of Crypto4A.  In this episode we recap important takeaways from these conversations.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1884629268</guid><pubDate>Mon, 29 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60862753/1884629268_tim_callan_root_causes_408_takeaways_from_recent_conversations_pqc_experts.mp3" length="18792129" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the past three months we featured far-ranging conversations about post-quantum cryptography (PQC) with experts Bas Westerbaan of Cloudflare, Dustin Moody of NIST, and Bruno Coulliard of Crypto4A.  In this episode we recap important takeaways from...</itunes:subtitle><itunes:summary><![CDATA[In the past three months we featured far-ranging conversations about post-quantum cryptography (PQC) with experts Bas Westerbaan of Cloudflare, Dustin Moody of NIST, and Bruno Coulliard of Crypto4A.  In this episode we recap important takeaways from these conversations.]]></itunes:summary><itunes:duration>783</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 407: Whatever Happened to Passkeys?</title><link>https://www.spreaker.com/episode/root-causes-407-whatever-happened-to-passkeys--60816894</link><description><![CDATA[WebAuthn arrived last year with great fanfare.  But here we are in the latter half of 2024, and they are rarely used.  In this episode we discuss why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1881695526</guid><pubDate>Thu, 25 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60816894/1881695526_tim_callan_root_causes_407_what_happened_to_passkeys.mp3" length="19344086" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>WebAuthn arrived last year with great fanfare.  But here we are in the latter half of 2024, and they are rarely used.  In this episode we discuss why.</itunes:subtitle><itunes:summary><![CDATA[WebAuthn arrived last year with great fanfare.  But here we are in the latter half of 2024, and they are rarely used.  In this episode we discuss why.]]></itunes:summary><itunes:duration>806</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 406: Certificate Discovery Is for Internal Certificates, Too</title><link>https://www.spreaker.com/episode/root-causes-406-certificate-discovery-is-for-internal-certificates-too--60781496</link><description><![CDATA[When we discuss certificate discovery in CLM platforms, there is a common assumption that we're talking about public certificates exclusively.  In this episode we explain the value of certificate discovery for internal PKI certificates also.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1879320669</guid><pubDate>Mon, 22 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60781496/1879320669_tim_callan_root_causes_406_certificate_discovery_is_for_internal_certificates_too.mp3" length="26305651" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>When we discuss certificate discovery in CLM platforms, there is a common assumption that we're talking about public certificates exclusively.  In this episode we explain the value of certificate discovery for internal PKI certificates also.</itunes:subtitle><itunes:summary><![CDATA[When we discuss certificate discovery in CLM platforms, there is a common assumption that we're talking about public certificates exclusively.  In this episode we explain the value of certificate discovery for internal PKI certificates also.]]></itunes:summary><itunes:duration>1096</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 405: What Is an Adversarial Self-replicating Prompt?</title><link>https://www.spreaker.com/episode/root-causes-405-what-is-an-adversarial-self-replicating-prompt--60745818</link><description><![CDATA[In this episode we explain what an adversarial, self-replicating prompt, otherwise known as a prompt worm.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1876016199</guid><pubDate>Fri, 19 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60745818/1876016199_tim_callan_root_causes_405_what_is_an_adversarial_self_replicating_prompt.mp3" length="36112971" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain what an adversarial, self-replicating prompt, otherwise known as a prompt worm.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain what an adversarial, self-replicating prompt, otherwise known as a prompt worm.]]></itunes:summary><itunes:duration>1505</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 404: SCOTUS Ruling Will Change IT Security Regulation</title><link>https://www.spreaker.com/episode/root-causes-404-scotus-ruling-will-change-it-security-regulation--60710460</link><description><![CDATA[The US Supreme Court has struck down the Chevron Deferment, which greatly expanded federal agencies' power to interpret and enforce statutes. This monumental ruling stands to shift power considerably from agencies to courts and will put more pressure on legislatures to determine precise laws around tech.  We explore the consequences of this ruling.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1873305657</guid><pubDate>Tue, 16 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60710460/1873305657_tim_callan_root_causes_404_scotus_ruling_will_change_it_security_regulation.mp3" length="23179117" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The US Supreme Court has struck down the Chevron Deferment, which greatly expanded federal agencies' power to interpret and enforce statutes. This monumental ruling stands to shift power considerably from agencies to courts and will put more pressure...</itunes:subtitle><itunes:summary><![CDATA[The US Supreme Court has struck down the Chevron Deferment, which greatly expanded federal agencies' power to interpret and enforce statutes. This monumental ruling stands to shift power considerably from agencies to courts and will put more pressure on legislatures to determine precise laws around tech.  We explore the consequences of this ruling.]]></itunes:summary><itunes:duration>966</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 403: NIST PQC Contest Round 4 and Onramp with Dustin Moody</title><link>https://www.spreaker.com/episode/root-causes-403-nist-pqc-contest-round-4-and-onramp-with-dustin-moody--60675948</link><description><![CDATA[We are joined again by Dustin Moody, who leads the NIST search for PQC algorithms.  In this episode Dustin describes going-forward efforts, including Round 4 of the NIST contest and the Onramp. We discuss some of the candidate algorithms and the consequences of having multiple algorithms available for use.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1870037571</guid><pubDate>Fri, 12 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60675948/1870037571_tim_callan_root_causes_403_nist_pqc_contest_round_4_and_onramp_with_dustin_moody.mp3" length="31060522" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are joined again by Dustin Moody, who leads the NIST search for PQC algorithms.  In this episode Dustin describes going-forward efforts, including Round 4 of the NIST contest and the Onramp. We discuss some of the candidate algorithms and the...</itunes:subtitle><itunes:summary><![CDATA[We are joined again by Dustin Moody, who leads the NIST search for PQC algorithms.  In this episode Dustin describes going-forward efforts, including Round 4 of the NIST contest and the Onramp. We discuss some of the candidate algorithms and the consequences of having multiple algorithms available for use.]]></itunes:summary><itunes:duration>1294</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 402: New Social Engineering Powershell Attack</title><link>https://www.spreaker.com/episode/root-causes-402-new-social-engineering-powershell-attack--60645077</link><description><![CDATA[A new social engineering exploit instructs victims to enter command line prompts to hack themselves on behalf of the hacker. We explain and discuss potential responses.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1867383906</guid><pubDate>Tue, 09 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60645077/1867383906_tim_callan_root_causes_402_new_social_engineering_powershell_attack.mp3" length="22110630" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new social engineering exploit instructs victims to enter command line prompts to hack themselves on behalf of the hacker. We explain and discuss potential responses.</itunes:subtitle><itunes:summary><![CDATA[A new social engineering exploit instructs victims to enter command line prompts to hack themselves on behalf of the hacker. We explain and discuss potential responses.]]></itunes:summary><itunes:duration>921</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 401: New SSH Remote Code Execution Vulnerability Revealed</title><link>https://www.spreaker.com/episode/root-causes-401-new-ssh-remote-code-execution-vulnerability-revealed--60612473</link><description><![CDATA[A newly revealed OpenSSH vulnerability can open enterprises to remote code execution.  We explain what is happening, why you should care, and what to do about it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1864018266</guid><pubDate>Fri, 05 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60612473/1864018266_tim_callan_root_causes_401_new_ssh_remote_code_execution_vulnerability_revealed.mp3" length="14878385" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A newly revealed OpenSSH vulnerability can open enterprises to remote code execution.  We explain what is happening, why you should care, and what to do about it.</itunes:subtitle><itunes:summary><![CDATA[A newly revealed OpenSSH vulnerability can open enterprises to remote code execution.  We explain what is happening, why you should care, and what to do about it.]]></itunes:summary><itunes:duration>620</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 400: French Court Orders DNS Poisoning</title><link>https://www.spreaker.com/episode/root-causes-400-french-court-orders-dns-poisoning--60581738</link><description><![CDATA[To combat piracy of sporting event transmissions, a French court has ordered major tech companies including Google and Cloudflare to poison DNS settings.  In this episode we provide some detail and generally marvel at this strange decision.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1861167417</guid><pubDate>Tue, 02 Jul 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60581738/1861167417_tim_callan_root_causes_400_french_court_orders_dns_poisoning.mp3" length="15302302" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>To combat piracy of sporting event transmissions, a French court has ordered major tech companies including Google and Cloudflare to poison DNS settings.  In this episode we provide some detail and generally marvel at this strange decision.</itunes:subtitle><itunes:summary><![CDATA[To combat piracy of sporting event transmissions, a French court has ordered major tech companies including Google and Cloudflare to poison DNS settings.  In this episode we provide some detail and generally marvel at this strange decision.]]></itunes:summary><itunes:duration>638</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 399: Entrust Distrusted</title><link>https://www.spreaker.com/episode/root-causes-399-entrust-distrusted--60540957</link><description><![CDATA[On June 27, 2024 Google Chrome announced it was distrusting Entrust as a public CA starting November 1, 2024. We explain what to expect, go over Google's stated reasons, and share some of what lead up to this.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1858655787</guid><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60540957/1858655787_tim_callan_root_causes_399_entrust_distrusted.mp3" length="28349174" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On June 27, 2024 Google Chrome announced it was distrusting Entrust as a public CA starting November 1, 2024. We explain what to expect, go over Google's stated reasons, and share some of what lead up to this.</itunes:subtitle><itunes:summary><![CDATA[On June 27, 2024 Google Chrome announced it was distrusting Entrust as a public CA starting November 1, 2024. We explain what to expect, go over Google's stated reasons, and share some of what lead up to this.]]></itunes:summary><itunes:duration>1181</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 398: History of the NIST PQC Contest with Dustin Moody</title><link>https://www.spreaker.com/episode/root-causes-398-history-of-the-nist-pqc-contest-with-dustin-moody--60529950</link><description><![CDATA[In this episode we are joined by Dr. Dustin Moody, leader of the NIST post-quantum cryptography contest. Dustin gives us an inside view of the background behind NIST's decision to run the contest and how we got to where we are today.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1857954651</guid><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60529950/1857954651_tim_callan_root_causes_398_history_of_the_nist_pqc_contest_with_dustin_moody.mp3" length="36813580" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we are joined by Dr. Dustin Moody, leader of the NIST post-quantum cryptography contest. Dustin gives us an inside view of the background behind NIST's decision to run the contest and how we got to where we are today.</itunes:subtitle><itunes:summary><![CDATA[In this episode we are joined by Dr. Dustin Moody, leader of the NIST post-quantum cryptography contest. Dustin gives us an inside view of the background behind NIST's decision to run the contest and how we got to where we are today.]]></itunes:summary><itunes:duration>1534</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 397: All Post Quantum Systems Are Terrible</title><link>https://www.spreaker.com/episode/root-causes-397-all-post-quantum-systems-are-terrible--60494755</link><description><![CDATA[In this new conversation with Bas Westerbaan of Cloudflare, we reveal that all existing PQC systems present significant problems for incorporation into our existing ecosystems. We explain the problems with existing systems and some options for what to do about it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1856025987</guid><pubDate>Mon, 24 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60494755/1856025987_tim_callan_root_causes_397_all_post_quantum_systems_are_terrible.mp3" length="40600770" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this new conversation with Bas Westerbaan of Cloudflare, we reveal that all existing PQC systems present significant problems for incorporation into our existing ecosystems. We explain the problems with existing systems and some options for what to...</itunes:subtitle><itunes:summary><![CDATA[In this new conversation with Bas Westerbaan of Cloudflare, we reveal that all existing PQC systems present significant problems for incorporation into our existing ecosystems. We explain the problems with existing systems and some options for what to do about it.]]></itunes:summary><itunes:duration>1692</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 396: The Trouble with Microsoft Recall</title><link>https://www.spreaker.com/episode/root-causes-396-the-trouble-with-microsoft-recall--60465281</link><description><![CDATA[Microsoft has proposed a feature called Recall that uses screen images to fuel AI-assisted capabilities.  This has raised fears about the security decisions around this capability.  We talk about why and how the proposed technology has resultingly changed.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1853894970</guid><pubDate>Fri, 21 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60465281/1853894970_tim_callan_root_causes_396_the_trouble_with_microsoft_recall.mp3" length="20322888" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Microsoft has proposed a feature called Recall that uses screen images to fuel AI-assisted capabilities.  This has raised fears about the security decisions around this capability.  We talk about why and how the proposed technology has resultingly...</itunes:subtitle><itunes:summary><![CDATA[Microsoft has proposed a feature called Recall that uses screen images to fuel AI-assisted capabilities.  This has raised fears about the security decisions around this capability.  We talk about why and how the proposed technology has resultingly changed.]]></itunes:summary><itunes:duration>847</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 395: Is Y2Q Like Y2K?</title><link>https://www.spreaker.com/episode/root-causes-395-is-y2q-like-y2k--60425118</link><description><![CDATA[In this episode we compare the advent of cryptography relevancy of quantum computers (somestimes called Y2Q) to Y2K.  We uncover similarities and differences and discuss how they govern decision making between now and Y2Q.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1851124068</guid><pubDate>Tue, 18 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60425118/1851124068_tim_callan_root_causes_395_is_y2q_like_y2k.mp3" length="35062458" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we compare the advent of cryptography relevancy of quantum computers (somestimes called Y2Q) to Y2K.  We uncover similarities and differences and discuss how they govern decision making between now and Y2Q.</itunes:subtitle><itunes:summary><![CDATA[In this episode we compare the advent of cryptography relevancy of quantum computers (somestimes called Y2Q) to Y2K.  We uncover similarities and differences and discuss how they govern decision making between now and Y2Q.]]></itunes:summary><itunes:duration>1461</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 394: Snowflake, Ticketmaster, and MFA</title><link>https://www.spreaker.com/episode/root-causes-394-snowflake-ticketmaster-and-mfa--60385199</link><description><![CDATA[In this episode we drill down on one aspect of the loss of more than 500 million Ticketmaster users' data, which is the use of MFA for access to the Snowflake platform.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1847409738</guid><pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60385199/1847409738_tim_callan_root_causes_394_snowflake_ticketmaster_and_mfa.mp3" length="16099479" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we drill down on one aspect of the loss of more than 500 million Ticketmaster users' data, which is the use of MFA for access to the Snowflake platform.</itunes:subtitle><itunes:summary><![CDATA[In this episode we drill down on one aspect of the loss of more than 500 million Ticketmaster users' data, which is the use of MFA for access to the Snowflake platform.]]></itunes:summary><itunes:duration>671</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 393: PQC-enabled Chrome Breaks Other Software</title><link>https://www.spreaker.com/episode/root-causes-393-pqc-enabled-chrome-breaks-other-software--60353229</link><description><![CDATA[Chrome's recent 124 release supports PQC algorithms from NIST. This has led to the discovery of software and systems that break under these circumstances. We explain what happened, why, and what to do about it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1845010083</guid><pubDate>Tue, 11 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60353229/1845010083_tim_callan_root_causes_393_pqc_enabled_chrome_breaks_other_software.mp3" length="17896612" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Chrome's recent 124 release supports PQC algorithms from NIST. This has led to the discovery of software and systems that break under these circumstances. We explain what happened, why, and what to do about it.</itunes:subtitle><itunes:summary><![CDATA[Chrome's recent 124 release supports PQC algorithms from NIST. This has led to the discovery of software and systems that break under these circumstances. We explain what happened, why, and what to do about it.]]></itunes:summary><itunes:duration>746</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 392: Chromium Issues a Quality Ultimatum</title><link>https://www.spreaker.com/episode/root-causes-392-chromium-issues-a-quality-ultimatum--60314291</link><description><![CDATA[In the most recent CA/Browser Forum face-to-face meeting, the Google Chrome root program gave a presentation clearly defining its expectations for quality of incident reporting from CAs with an eye to where many CAs have been failing.  We relate Chromium's statements and their significance.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1841274570</guid><pubDate>Fri, 07 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60314291/1841274570_tim_callan_root_causes_392_chromium_issues_a_quality_ultimatum.mp3" length="30658464" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the most recent CA/Browser Forum face-to-face meeting, the Google Chrome root program gave a presentation clearly defining its expectations for quality of incident reporting from CAs with an eye to where many CAs have been failing.  We relate...</itunes:subtitle><itunes:summary><![CDATA[In the most recent CA/Browser Forum face-to-face meeting, the Google Chrome root program gave a presentation clearly defining its expectations for quality of incident reporting from CAs with an eye to where many CAs have been failing.  We relate Chromium's statements and their significance.]]></itunes:summary><itunes:duration>1278</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 391: 20 Percent of Web Visits Are PQC Enabled Today</title><link>https://www.spreaker.com/episode/root-causes-391-20-percent-of-web-visits-are-pqc-enabled-today--60277943</link><description><![CDATA[Cloudflare research engineer Bas Westerbaan joins us to share his observations about post-quantum cryptography and what it does in the real world. We talk about the pragmatic needs of moving the internet for PQC and speculate about timelines for availability of PQC certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1837730097</guid><pubDate>Tue, 04 Jun 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60277943/1837730097_tim_callan_root_causes_391_20_percent_of_web_visits_are_pqc_enabled_today.mp3" length="32410074" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Cloudflare research engineer Bas Westerbaan joins us to share his observations about post-quantum cryptography and what it does in the real world. We talk about the pragmatic needs of moving the internet for PQC and speculate about timelines for...</itunes:subtitle><itunes:summary><![CDATA[Cloudflare research engineer Bas Westerbaan joins us to share his observations about post-quantum cryptography and what it does in the real world. We talk about the pragmatic needs of moving the internet for PQC and speculate about timelines for availability of PQC certificates.]]></itunes:summary><itunes:duration>1350</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 390: Chromium Boosts Its Distrust Agility with a New Root Trust Deprecation</title><link>https://www.spreaker.com/episode/root-causes-390-chromium-boosts-its-distrust-agility-with-a-new-root-trust-deprecation--60239681</link><description><![CDATA[A root trust deprecation highlights new Chrome functionality that enables more agile and less disruptive distrust events.  We explain the significant of this event.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1834714758</guid><pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60239681/1834714758_tim_callan_root_causes_390_chromium_boosts_its_distrust_agility_with_a_new_root_trust_deprecation.mp3" length="31535690" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A root trust deprecation highlights new Chrome functionality that enables more agile and less disruptive distrust events.  We explain the significant of this event.</itunes:subtitle><itunes:summary><![CDATA[A root trust deprecation highlights new Chrome functionality that enables more agile and less disruptive distrust events.  We explain the significant of this event.]]></itunes:summary><itunes:duration>1314</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 389: 2024 RSA Conference Wrap Up</title><link>https://www.spreaker.com/episode/root-causes-389-2024-rsa-conference-wrap-up--60201286</link><description><![CDATA[Jason and I do our annual RSA wrap-up.  Trending segments include AI, Trust Centers, MFA, PQC, and more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1832334870</guid><pubDate>Tue, 28 May 2024 19:00:40 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60201286/1832334870_tim_callan_root_causes_389_2024_rsa_conference_wrap_up.mp3" length="39445661" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason and I do our annual RSA wrap-up.  Trending segments include AI, Trust Centers, MFA, PQC, and more.</itunes:subtitle><itunes:summary><![CDATA[Jason and I do our annual RSA wrap-up.  Trending segments include AI, Trust Centers, MFA, PQC, and more.]]></itunes:summary><itunes:duration>1644</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 388: What Is the WebPKI?</title><link>https://www.spreaker.com/episode/root-causes-388-what-is-the-webpki--60129128</link><description><![CDATA[These days we frequently discuss "the WebPKI." But what does that really mean?  In this episode we define the term and explain how this definition evolved over time. We give an inventory of a main components of the WebPKI and discuss what's required to become a CA.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1827626145</guid><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60129128/1827626145_tim_callan_root_causes_388_what_is_the_webpki.mp3" length="37787598" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>These days we frequently discuss "the WebPKI." But what does that really mean?  In this episode we define the term and explain how this definition evolved over time. We give an inventory of a main components of the WebPKI and discuss what's required...</itunes:subtitle><itunes:summary><![CDATA[These days we frequently discuss "the WebPKI." But what does that really mean?  In this episode we define the term and explain how this definition evolved over time. We give an inventory of a main components of the WebPKI and discuss what's required to become a CA.]]></itunes:summary><itunes:duration>1575</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 387:  What Is the Post-quantum Readiness of HSMs?</title><link>https://www.spreaker.com/episode/root-causes-387-what-is-the-post-quantum-readiness-of-hsms--60066421</link><description><![CDATA[We take a deep dive with return guest Bruno Coulliard on HSMs and the role they play in post-quantum cryptography (PQC).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1823735208</guid><pubDate>Thu, 16 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60066421/1823735208_tim_callan_root_causes_387_what_is_the_post_quantum_readiness_of_hsms.mp3" length="45461036" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We take a deep dive with return guest Bruno Coulliard on HSMs and the role they play in post-quantum cryptography (PQC).</itunes:subtitle><itunes:summary><![CDATA[We take a deep dive with return guest Bruno Coulliard on HSMs and the role they play in post-quantum cryptography (PQC).]]></itunes:summary><itunes:duration>1894</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 386: Meta Commits MITM Attack On Its Users</title><link>https://www.spreaker.com/episode/root-causes-386-meta-commits-mitm-attack-on-its-users--60006654</link><description><![CDATA[Recent court documents reveal that in 2016 Meta (then Facebook) set up a system to get around encryption and spy on traffic between its users and competing social media platforms.  We explain what happened.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1820978577</guid><pubDate>Mon, 13 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60006654/1820978577_tim_callan_root_causes_386_meta_commits_mitm_attack_on_its_users.mp3" length="20724770" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent court documents reveal that in 2016 Meta (then Facebook) set up a system to get around encryption and spy on traffic between its users and competing social media platforms.  We explain what happened.</itunes:subtitle><itunes:summary><![CDATA[Recent court documents reveal that in 2016 Meta (then Facebook) set up a system to get around encryption and spy on traffic between its users and competing social media platforms.  We explain what happened.]]></itunes:summary><itunes:duration>864</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 385: Failed Revocation and Wildcard Certificates</title><link>https://www.spreaker.com/episode/root-causes-385-failed-revocation-and-wildcard-certificates--59969277</link><description><![CDATA[We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1819066581</guid><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59969277/1819066581_tim_callan_root_causes_385_failed_revocation_and_wildcard_certificates.mp3" length="17746855" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.</itunes:subtitle><itunes:summary><![CDATA[We discuss misuse of wildcard certificates, failure to revoke on time, and how these two failures magnify each other.]]></itunes:summary><itunes:duration>740</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 384: So What Is a Senior Fellow Anyway?</title><link>https://www.spreaker.com/episode/root-causes-384-so-what-is-a-senior-fellow-anyway--59891101</link><description><![CDATA[Jason has a new title, Senior Fellow. In this episode Jason explains what his new focus will be and how this will be good for Root Causes.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1816236660</guid><pubDate>Tue, 07 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59891101/1816236660_tim_callan_root_causes_384_so_what_is_a_senior_fellow_anyway.mp3" length="10636701" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Jason has a new title, Senior Fellow. In this episode Jason explains what his new focus will be and how this will be good for Root Causes.</itunes:subtitle><itunes:summary><![CDATA[Jason has a new title, Senior Fellow. In this episode Jason explains what his new focus will be and how this will be good for Root Causes.]]></itunes:summary><itunes:duration>443</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 383: Delayed Revocation Events by the Numbers</title><link>https://www.spreaker.com/episode/root-causes-383-delayed-revocation-events-by-the-numbers--59774949</link><description><![CDATA[An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021, examine the trend line, and discuss root causes.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1812635115</guid><pubDate>Thu, 02 May 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59774949/1812635115_tim_callan_root_causes_383_delayed_revocation_events_by_the_numbers.mp3" length="36685736" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021, examine the trend line, and discuss root causes.</itunes:subtitle><itunes:summary><![CDATA[An epidemic of delayed revocations has infected the public CA community. We track delayed revocations since the beginning of 2021, examine the trend line, and discuss root causes.]]></itunes:summary><itunes:duration>1529</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 382: Mobile Phone Malware Steals Faces for Access</title><link>https://www.spreaker.com/episode/root-causes-382-mobile-phone-malware-steals-faces-for-access--59704939</link><description><![CDATA[New malware photographs users' faces to defeat authentication mechanisms. We explain the that biometrics are not "secrets" and discuss the continuing progression of attacks to steal biometrics.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1810508940</guid><pubDate>Mon, 29 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59704939/1810508940_tim_callan_root_causes_382_mobile_phone_malware_steals_faces_for_access.mp3" length="16862130" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>New malware photographs users' faces to defeat authentication mechanisms. We explain the that biometrics are not "secrets" and discuss the continuing progression of attacks to steal biometrics.</itunes:subtitle><itunes:summary><![CDATA[New malware photographs users' faces to defeat authentication mechanisms. We explain the that biometrics are not "secrets" and discuss the continuing progression of attacks to steal biometrics.]]></itunes:summary><itunes:duration>703</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 381: Apple Chip Sideloading Attack Leaks Encryption Keys</title><link>https://www.spreaker.com/episode/root-causes-381-apple-chip-sideloading-attack-leaks-encryption-keys--59668018</link><description><![CDATA[A newly revealed side channel attack enables theft of private keys from M-series Apple chips.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1808605410</guid><pubDate>Fri, 26 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59668018/1808605410_tim_callan_root_causes_381_apple_chip_sideloading_attack_leaks_encryption_keys.mp3" length="10833136" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A newly revealed side channel attack enables theft of private keys from M-series Apple chips.  We explain.</itunes:subtitle><itunes:summary><![CDATA[A newly revealed side channel attack enables theft of private keys from M-series Apple chips.  We explain.]]></itunes:summary><itunes:duration>451</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 380: What If Quantum Supremacy Comes Earlier Than We Thought?</title><link>https://www.spreaker.com/episode/root-causes-380-what-if-quantum-supremacy-comes-earlier-than-we-thought--59614419</link><description><![CDATA[Repeat guest Bruno Coulliard gives us an update on the US government's migration to post-quantum cryptography (PQC). We talk about the challenges to migration, the possibility of a black swan event in achieving quantum supremacy, and what happens if we all respond by pressing the "panic button" at the same time.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1806091554</guid><pubDate>Mon, 22 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59614419/1806091554_tim_callan_root_causes_380_what_if_quantum_supremacy_comes_earlier_than_we_thought.mp3" length="42519980" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Bruno Coulliard gives us an update on the US government's migration to post-quantum cryptography (PQC). We talk about the challenges to migration, the possibility of a black swan event in achieving quantum supremacy, and what happens if...</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Bruno Coulliard gives us an update on the US government's migration to post-quantum cryptography (PQC). We talk about the challenges to migration, the possibility of a black swan event in achieving quantum supremacy, and what happens if we all respond by pressing the "panic button" at the same time.]]></itunes:summary><itunes:duration>1772</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 379: AI-generated Fake IDS for KYC</title><link>https://www.spreaker.com/episode/root-causes-379-ai-generated-fake-ids-for-kyc--59530775</link><description><![CDATA[Inexpensive and easily obtained deepfake photographs of IDs, generated by AI, are available online. These pose a problem for KYC initiatives.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1803042201</guid><pubDate>Thu, 18 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59530775/1803042201_tim_callan_root_causes_379_ai_generated_fake_ids_for_kyc.mp3" length="19412548" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Inexpensive and easily obtained deepfake photographs of IDs, generated by AI, are available online. These pose a problem for KYC initiatives.</itunes:subtitle><itunes:summary><![CDATA[Inexpensive and easily obtained deepfake photographs of IDs, generated by AI, are available online. These pose a problem for KYC initiatives.]]></itunes:summary><itunes:duration>809</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 378: Why Are Forced Revocations So Difficult?</title><link>https://www.spreaker.com/episode/root-causes-378-why-are-forced-revocations-so-difficult--59475960</link><description><![CDATA[In the latest in our ongoing series of discussions of the Bugzilla Bloodbath, we delve deep into the problem of failure to revoke on time and the multiple causes that lead to this ongoing failure. And what to do about them.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1801269930</guid><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59475960/1801269930_tim_callan_root_causes_378_why_are_forced_revocations_so_difficult.mp3" length="30440164" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the latest in our ongoing series of discussions of the Bugzilla Bloodbath, we delve deep into the problem of failure to revoke on time and the multiple causes that lead to this ongoing failure. And what to do about them.</itunes:subtitle><itunes:summary><![CDATA[In the latest in our ongoing series of discussions of the Bugzilla Bloodbath, we delve deep into the problem of failure to revoke on time and the multiple causes that lead to this ongoing failure. And what to do about them.]]></itunes:summary><itunes:duration>1268</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 377: Is CPS/Issuance Misalignment a Revocation Event?</title><link>https://www.spreaker.com/episode/root-causes-377-is-cps-issuance-misalignment-a-revocation-event--59423330</link><description><![CDATA[If you issue public certificates that are fully compliant except that they do not reflect what your CPS says, are they misissued? Do they require revocation? This is a question with real stakes as we see multiple current instances of a CA denying revocation for that reason. In this episode we explore this issue.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1798606657</guid><pubDate>Thu, 11 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59423330/1798606657_tim_callan_root_causes_377_is_cpsissuance_misalignment_a_revocation_event.mp3" length="24642655" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>If you issue public certificates that are fully compliant except that they do not reflect what your CPS says, are they misissued? Do they require revocation? This is a question with real stakes as we see multiple current instances of a CA denying...</itunes:subtitle><itunes:summary><![CDATA[If you issue public certificates that are fully compliant except that they do not reflect what your CPS says, are they misissued? Do they require revocation? This is a question with real stakes as we see multiple current instances of a CA denying revocation for that reason. In this episode we explore this issue.]]></itunes:summary><itunes:duration>1027</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 376: Gartner's New CLM Framework</title><link>https://www.spreaker.com/episode/root-causes-376-gartner-s-new-clm-framework--59355930</link><description><![CDATA[Gartner has released a new framework for Certificate Lifecycle Management, called the Seven Core Functions of Certificate Automation. We walk through this framework and answer how it fits in with our own Five Pillars of CLM.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1796481337</guid><pubDate>Mon, 08 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59355930/1796481337_tim_callan_root_causes_376_gartners_new_clm_framework.mp3" length="28079702" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Gartner has released a new framework for Certificate Lifecycle Management, called the Seven Core Functions of Certificate Automation. We walk through this framework and answer how it fits in with our own Five Pillars of CLM.</itunes:subtitle><itunes:summary><![CDATA[Gartner has released a new framework for Certificate Lifecycle Management, called the Seven Core Functions of Certificate Automation. We walk through this framework and answer how it fits in with our own Five Pillars of CLM.]]></itunes:summary><itunes:duration>1170</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 375: What Is Name Space Lifecycle Management?</title><link>https://www.spreaker.com/episode/root-causes-375-what-is-name-space-lifecycle-management--59314064</link><description><![CDATA[In this guest episode we discuss name space hygiene with Geir Rasmussen, founder of NodeZro. CNAMEs, SPF, DMARC, name server entries, and other DNS identifiers, left unattended, can expose companies to identity-based attacks. We lay out the steps in addressing name space cleanup.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1793965165</guid><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59314064/1793965165_tim_callan_root_causes_375_what_is_name_space_lifecycle_management.mp3" length="40315083" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this guest episode we discuss name space hygiene with Geir Rasmussen, founder of NodeZro. CNAMEs, SPF, DMARC, name server entries, and other DNS identifiers, left unattended, can expose companies to identity-based attacks. We lay out the steps in...</itunes:subtitle><itunes:summary><![CDATA[In this guest episode we discuss name space hygiene with Geir Rasmussen, founder of NodeZro. CNAMEs, SPF, DMARC, name server entries, and other DNS identifiers, left unattended, can expose companies to identity-based attacks. We lay out the steps in addressing name space cleanup.]]></itunes:summary><itunes:duration>1680</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 374: NIST Cyber Security Framework 2 Released</title><link>https://www.spreaker.com/episode/root-causes-374-nist-cyber-security-framework-2-released--59246861</link><description><![CDATA[NIST Cyber Security Framework version 2.0 is released. It includes guidance on identity management and authentication. In this first episode of a series, we describe this framework's basic structure and its effect on industry.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1789831396</guid><pubDate>Sun, 31 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59246861/1789831396_tim_callan_root_causes_374_nist_cyber_security_framework_2_released.mp3" length="20937893" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST Cyber Security Framework version 2.0 is released. It includes guidance on identity management and authentication. In this first episode of a series, we describe this framework's basic structure and its effect on industry.</itunes:subtitle><itunes:summary><![CDATA[NIST Cyber Security Framework version 2.0 is released. It includes guidance on identity management and authentication. In this first episode of a series, we describe this framework's basic structure and its effect on industry.]]></itunes:summary><itunes:duration>872</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 373: Massive Brand Hijack Subverts More Than 21,000 Domains and Subdomains</title><link>https://www.spreaker.com/episode/root-causes-373-massive-brand-hijack-subverts-more-than-21-000-domains-and-subdomains--59220125</link><description><![CDATA[A massive name space attack has hijacked more than 21,000 domains and subdomains, including a who's who list of major global brands. This huge and innovative attack takes advantage of inherited trust in abandoned domains.  We explain what is happening.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1787710111</guid><pubDate>Fri, 29 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59220125/1787710111_tim_callan_root_causes_373_massive_brand_hijack_subverts_more_than_21000_domains_and_subdomains.mp3" length="21151042" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A massive name space attack has hijacked more than 21,000 domains and subdomains, including a who's who list of major global brands. This huge and innovative attack takes advantage of inherited trust in abandoned domains.  We explain what is happening.</itunes:subtitle><itunes:summary><![CDATA[A massive name space attack has hijacked more than 21,000 domains and subdomains, including a who's who list of major global brands. This huge and innovative attack takes advantage of inherited trust in abandoned domains.  We explain what is happening.]]></itunes:summary><itunes:duration>881</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 372: Bugzilla Bloodbath</title><link>https://www.spreaker.com/episode/root-causes-372-bugzilla-bloodbath--59180689</link><description><![CDATA[It's a bloodbath on Bugzilla. Since March 9, more than 25 new Bugzilla bugs been written up, which is 10x the typical pace. And it's not over. In this episode we explain what is going on and why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1784895846</guid><pubDate>Tue, 26 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59180689/1784895846_tim_callan_root_causes_372_bugzilla_bloodbath.mp3" length="31813331" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It's a bloodbath on Bugzilla. Since March 9, more than 25 new Bugzilla bugs been written up, which is 10x the typical pace. And it's not over. In this episode we explain what is going on and why.</itunes:subtitle><itunes:summary><![CDATA[It's a bloodbath on Bugzilla. Since March 9, more than 25 new Bugzilla bugs been written up, which is 10x the typical pace. And it's not over. In this episode we explain what is going on and why.]]></itunes:summary><itunes:duration>1326</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 371: MPIC Rules Go to CABF Ballot</title><link>https://www.spreaker.com/episode/root-causes-371-mpic-rules-go-to-cabf-ballot--59140832</link><description><![CDATA[A ballot for Multi-perspective Issuance Corroboration (MPIC), formerly known as MPDV, has entered a discussion period in the CA/Browser Forum (CABF).  We explain the details of what it contains.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1781920632</guid><pubDate>Fri, 22 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59140832/1781920632_tim_callan_root_causes_371_mpic_rules_go_to_cabf_ballot.mp3" length="19487017" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A ballot for Multi-perspective Issuance Corroboration (MPIC), formerly known as MPDV, has entered a discussion period in the CA/Browser Forum (CABF).  We explain the details of what it contains.</itunes:subtitle><itunes:summary><![CDATA[A ballot for Multi-perspective Issuance Corroboration (MPIC), formerly known as MPDV, has entered a discussion period in the CA/Browser Forum (CABF).  We explain the details of what it contains.]]></itunes:summary><itunes:duration>1218</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 370: Drama on Bugzilla</title><link>https://www.spreaker.com/episode/root-causes-370-drama-on-bugzilla--59105764</link><description><![CDATA[An evolving incident on Bugzilla has garnered a lot of attention and touches several important issues in the WebPKI ecosystem. We report what went on and unpack the issues involved.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1779339657</guid><pubDate>Tue, 19 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59105764/1779339657_tim_callan_root_causes_370_drama_on_bugzilla.mp3" length="26542959" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>An evolving incident on Bugzilla has garnered a lot of attention and touches several important issues in the WebPKI ecosystem. We report what went on and unpack the issues involved.</itunes:subtitle><itunes:summary><![CDATA[An evolving incident on Bugzilla has garnered a lot of attention and touches several important issues in the WebPKI ecosystem. We report what went on and unpack the issues involved.]]></itunes:summary><itunes:duration>1659</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 369: IMessage to Be PQC Enabled</title><link>https://www.spreaker.com/episode/root-causes-369-imessage-to-be-pqc-enabled--59056299</link><description><![CDATA[Apple has announced that iMessage will employ post-quantum cryptography (PQC). We explain the implications of this announcement.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1775447613</guid><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59056299/1775447613_tim_callan_root_causes_369_imessage_to_be_pqc_enabled.mp3" length="21287511" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple has announced that iMessage will employ post-quantum cryptography (PQC). We explain the implications of this announcement.</itunes:subtitle><itunes:summary><![CDATA[Apple has announced that iMessage will employ post-quantum cryptography (PQC). We explain the implications of this announcement.]]></itunes:summary><itunes:duration>887</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 368: CRYSTALS-Kyber Is Now ML-KEM</title><link>https://www.spreaker.com/episode/root-causes-368-crystals-kyber-is-now-ml-kem--59033752</link><description><![CDATA[What has been known as CRYSTALS-Kyber now has the new official name of Module Lattice-based Key Encryption Module, or ML-KEM. We give an update on the state of the NIST round 3 winners.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1773561219</guid><pubDate>Wed, 13 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59033752/1773561219_tim_callan_root_causes_368_crystals_kyber_is_now_ml_kem.mp3" length="13157849" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>What has been known as CRYSTALS-Kyber now has the new official name of Module Lattice-based Key Encryption Module, or ML-KEM. We give an update on the state of the NIST round 3 winners.</itunes:subtitle><itunes:summary><![CDATA[What has been known as CRYSTALS-Kyber now has the new official name of Module Lattice-based Key Encryption Module, or ML-KEM. We give an update on the state of the NIST round 3 winners.]]></itunes:summary><itunes:duration>548</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 367: Did an IoT Toothbrush Botnet Perform DDoS Attacks?</title><link>https://www.spreaker.com/episode/root-causes-367-did-an-iot-toothbrush-botnet-perform-ddos-attacks--58957864</link><description><![CDATA[A story circulated earlier this year about a botnet composed of millions of IoT toothbrushes, which later was debunked. We tell you the whole tale.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1767953646</guid><pubDate>Thu, 07 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58957864/1767953646_tim_callan_root_causes_367_did_an_iot_toothbrush_botnet_perform_ddos_attacks.mp3" length="10878055" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A story circulated earlier this year about a botnet composed of millions of IoT toothbrushes, which later was debunked. We tell you the whole tale.</itunes:subtitle><itunes:summary><![CDATA[A story circulated earlier this year about a botnet composed of millions of IoT toothbrushes, which later was debunked. We tell you the whole tale.]]></itunes:summary><itunes:duration>453</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 366: What Is eIDAS?</title><link>https://www.spreaker.com/episode/root-causes-366-what-is-eidas--58924189</link><description><![CDATA[eIDAS 2.0 has been making headlines recently with its proposed expansion to the European digital identity ecosystem.  But what is eIDAS?  What does it do, and why does it exist?  In this episode we give you the basics.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1765059684</guid><pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58924189/1765059684_tim_callan_root_causes_366_what_is_eidas.mp3" length="39225290" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>eIDAS 2.0 has been making headlines recently with its proposed expansion to the European digital identity ecosystem.  But what is eIDAS?  What does it do, and why does it exist?  In this episode we give you the basics.</itunes:subtitle><itunes:summary><![CDATA[eIDAS 2.0 has been making headlines recently with its proposed expansion to the European digital identity ecosystem.  But what is eIDAS?  What does it do, and why does it exist?  In this episode we give you the basics.]]></itunes:summary><itunes:duration>1634</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 365: What Is Subdomain Hijacking?</title><link>https://www.spreaker.com/episode/root-causes-365-what-is-subdomain-hijacking--58821558</link><description><![CDATA[In this episode we explain subdomain hijacking, including dangling subdomains and how they can constitute vulnerabilities.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1758017310</guid><pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58821558/1758017310_tim_callan_root_causes_365_what_is_subdomain_hijacking.mp3" length="19488664" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain subdomain hijacking, including dangling subdomains and how they can constitute vulnerabilities.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain subdomain hijacking, including dangling subdomains and how they can constitute vulnerabilities.]]></itunes:summary><itunes:duration>812</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 364: Video Conference Deepfake Enables $25 Million Theft</title><link>https://www.spreaker.com/episode/root-causes-364-video-conference-deepfake-enables-25-million-theft--58777486</link><description><![CDATA[Deepfakes continue to show themselves as part of the standard criminal toolkit. A recent deepfake spear phish enabled a $25 million Business Email Compromise (BEC).  We explain what happened.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1754915097</guid><pubDate>Thu, 22 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58777486/1754915097_tim_callan_root_causes_364_video_conference_deepfake_enables_25_million_theft.mp3" length="12566889" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Deepfakes continue to show themselves as part of the standard criminal toolkit. A recent deepfake spear phish enabled a $25 million Business Email Compromise (BEC).  We explain what happened.</itunes:subtitle><itunes:summary><![CDATA[Deepfakes continue to show themselves as part of the standard criminal toolkit. A recent deepfake spear phish enabled a $25 million Business Email Compromise (BEC).  We explain what happened.]]></itunes:summary><itunes:duration>524</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 363: Defending Yourself Against Use of Stolen Privileges</title><link>https://www.spreaker.com/episode/root-causes-363-defending-yourself-against-use-of-stolen-privileges--58743927</link><description><![CDATA[CloudFlare recently published details of an attack it suffered as a downstream effect of a November 2023 breach against Okta and what it did to nullify its success. We discuss the steps enterprises can take to protect themselves against malicious use of stolen access credentials.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1751933661</guid><pubDate>Sun, 18 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58743927/1751933661_tim_callan_root_causes_363_defending_yourself_against_use_of_stolen_priveleges.mp3" length="11027812" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>CloudFlare recently published details of an attack it suffered as a downstream effect of a November 2023 breach against Okta and what it did to nullify its success. We discuss the steps enterprises can take to protect themselves against malicious use...</itunes:subtitle><itunes:summary><![CDATA[CloudFlare recently published details of an attack it suffered as a downstream effect of a November 2023 breach against Okta and what it did to nullify its success. We discuss the steps enterprises can take to protect themselves against malicious use of stolen access credentials.]]></itunes:summary><itunes:duration>460</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 362:  When You're Attacked by a State Actor</title><link>https://www.spreaker.com/episode/root-causes-362-when-you-re-attacked-by-a-state-actor--58675591</link><description><![CDATA[In this episode we share the details of a recent nation state actor attack on Microsoft and some of the lessons learned.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1746191091</guid><pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58675591/1746191091_tim_callan_root_causes_362_when_youre_attacked_by_a_nation_state_actor.mp3" length="14569638" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we share the details of a recent nation state actor attack on Microsoft and some of the lessons learned.</itunes:subtitle><itunes:summary><![CDATA[In this episode we share the details of a recent nation state actor attack on Microsoft and some of the lessons learned.]]></itunes:summary><itunes:duration>607</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 361: The Premise of on Premise</title><link>https://www.spreaker.com/episode/root-causes-361-the-premise-of-on-premise--58627691</link><description><![CDATA[In this episode we examine commonly held belief that on-premise systems give system administrators greater levels of control and that that is better for security or other reasons. We explore the pros and cons of extra control, to what degree it is a benefit, and if it's worth it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1742379576</guid><pubDate>Fri, 09 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58627691/1742379576_tim_callan_root_causes_361_the_premise_of_on_premise.mp3" length="53320512" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we examine commonly held belief that on-premise systems give system administrators greater levels of control and that that is better for security or other reasons. We explore the pros and cons of extra control, to what degree it is a...</itunes:subtitle><itunes:summary><![CDATA[In this episode we examine commonly held belief that on-premise systems give system administrators greater levels of control and that that is better for security or other reasons. We explore the pros and cons of extra control, to what degree it is a benefit, and if it's worth it.]]></itunes:summary><itunes:duration>2222</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 360: Joe Biden Deepfake Plays in New Hampshire Primary</title><link>https://www.spreaker.com/episode/root-causes-360-joe-biden-deepfake-plays-in-new-hampshire-primary--58588694</link><description><![CDATA[A deepfake of Joe Biden's voice made an appearance in robocalls leading up to the New Hampshire primary. We discuss this latest development and its implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1739495547</guid><pubDate>Tue, 06 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58588694/1739495547_tim_callan_root_causes_360_joe_biden_deepfake_plays_in_new_hampshire_primary.mp3" length="17108080" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A deepfake of Joe Biden's voice made an appearance in robocalls leading up to the New Hampshire primary. We discuss this latest development and its implications.</itunes:subtitle><itunes:summary><![CDATA[A deepfake of Joe Biden's voice made an appearance in robocalls leading up to the New Hampshire primary. We discuss this latest development and its implications.]]></itunes:summary><itunes:duration>713</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 359: 90-day SSL Won't Affect Organization Validation Periods</title><link>https://www.spreaker.com/episode/root-causes-359-90-day-ssl-won-t-affect-organization-validation-periods--58547807</link><description><![CDATA[With maximum 90-day term coming for public SSL certificates and DCV reuse also moving to 90 days, we explain why we do not expect a similar reduction in the reuse period for organization validation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1735840197</guid><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58547807/1735840197_tim_callan_root_causes_359_90_day_ssl_wont_affect_organization_validation_periods.mp3" length="22521331" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>With maximum 90-day term coming for public SSL certificates and DCV reuse also moving to 90 days, we explain why we do not expect a similar reduction in the reuse period for organization validation.</itunes:subtitle><itunes:summary><![CDATA[With maximum 90-day term coming for public SSL certificates and DCV reuse also moving to 90 days, we explain why we do not expect a similar reduction in the reuse period for organization validation.]]></itunes:summary><itunes:duration>938</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 358: Security Questionnaire Sins</title><link>https://www.spreaker.com/episode/root-causes-358-security-questionnaire-sins--58503547</link><description><![CDATA[In this episode we present a catalog of "security questionnaire sins," which are avoidable problems and errors that frequently occur in the security questionnaires enterprises send to vendors.  Categories include difficulty of access, poor technical implementation, poor policies, and poor questions.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1732277916</guid><pubDate>Tue, 30 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58503547/1732277916_tim_callan_root_causes_358_security_questionnaire_sins.mp3" length="47763353" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we present a catalog of "security questionnaire sins," which are avoidable problems and errors that frequently occur in the security questionnaires enterprises send to vendors.  Categories include difficulty of access, poor technical...</itunes:subtitle><itunes:summary><![CDATA[In this episode we present a catalog of "security questionnaire sins," which are avoidable problems and errors that frequently occur in the security questionnaires enterprises send to vendors.  Categories include difficulty of access, poor technical implementation, poor policies, and poor questions.]]></itunes:summary><itunes:duration>1990</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 357: Signed Digital Photographs</title><link>https://www.spreaker.com/episode/root-causes-357-signed-digital-photographs--58465251</link><description><![CDATA[Three major camera manufacturers have joined to create a standard for signed digital images from their cameras.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1728696624</guid><pubDate>Fri, 26 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58465251/1728696624_tim_callan_root_causes_357_signed_digital_photographs.mp3" length="16892610" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Three major camera manufacturers have joined to create a standard for signed digital images from their cameras.</itunes:subtitle><itunes:summary><![CDATA[Three major camera manufacturers have joined to create a standard for signed digital images from their cameras.]]></itunes:summary><itunes:duration>704</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 356: Will MPDV Eliminate Email-based DCV?</title><link>https://www.spreaker.com/episode/root-causes-356-will-mpdv-eliminate-email-based-dcv--58420582</link><description><![CDATA[Multi-perspective Domain Validation (MPDV) is a necessary evolution of Domain Control Validation (DCV) to protect against Border Gateway Protocol (BGP) attacks. We explore how MPDV may affect accepted DCV methods, especially the email method.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1725553281</guid><pubDate>Mon, 22 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58420582/1725553281_tim_callan_root_causes_355_will_mpdv_eliminate_email_based_dcv.mp3" length="23749920" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Multi-perspective Domain Validation (MPDV) is a necessary evolution of Domain Control Validation (DCV) to protect against Border Gateway Protocol (BGP) attacks. We explore how MPDV may affect accepted DCV methods, especially the email method.</itunes:subtitle><itunes:summary><![CDATA[Multi-perspective Domain Validation (MPDV) is a necessary evolution of Domain Control Validation (DCV) to protect against Border Gateway Protocol (BGP) attacks. We explore how MPDV may affect accepted DCV methods, especially the email method.]]></itunes:summary><itunes:duration>990</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 355: Should a Managed PKI Provider Do Whatever the Customer Wants?</title><link>https://www.spreaker.com/episode/root-causes-355-should-a-managed-pki-provider-do-whatever-the-customer-wants--58369653</link><description><![CDATA[In this episode we explore whether a managed PKI provider should give complete control over PKI decisions to the end customer or if it should enforce certain minimum standards and principles regardless of what the customer asks for.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1722094614</guid><pubDate>Fri, 19 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58369653/1722094614_tim_callan_root_causes_355_should_a_managed_pki_provider_do_whatever_the_customer_wants.mp3" length="32429689" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explore whether a managed PKI provider should give complete control over PKI decisions to the end customer or if it should enforce certain minimum standards and principles regardless of what the customer asks for.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explore whether a managed PKI provider should give complete control over PKI decisions to the end customer or if it should enforce certain minimum standards and principles regardless of what the customer asks for.]]></itunes:summary><itunes:duration>1351</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 354: CyberSlash Attack Against CRYSTALS-Kyber</title><link>https://www.spreaker.com/episode/root-causes-354-cyberslash-attack-against-crystals-kyber--58321387</link><description><![CDATA[A newly published attack against common implementations of CRYSTALS-Kyber illustrates how cryptographic implementations can be vulnerable even if the cyphers themselves remain sound.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1719235860</guid><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58321387/1719235860_tim_callan_root_causes_354_cyberslash_attack_against_crystals_kyber.mp3" length="17670245" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A newly published attack against common implementations of CRYSTALS-Kyber illustrates how cryptographic implementations can be vulnerable even if the cyphers themselves remain sound.</itunes:subtitle><itunes:summary><![CDATA[A newly published attack against common implementations of CRYSTALS-Kyber illustrates how cryptographic implementations can be vulnerable even if the cyphers themselves remain sound.]]></itunes:summary><itunes:duration>736</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 353: Why Isn't PKI Everywhere?</title><link>https://www.spreaker.com/episode/root-causes-353-why-isn-t-pki-everywhere--58256265</link><description><![CDATA[Our hosts firmly believe that PKI is a necessary component of all digital interactions.  And yet there are still gaps in PKI implementation.  We discuss these gaps and why they persist.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1713774612</guid><pubDate>Tue, 09 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58256265/1713774612_tim_callan_root_causes_353_why_isnt_pki_everywhere.mp3" length="34805076" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Our hosts firmly believe that PKI is a necessary component of all digital interactions.  And yet there are still gaps in PKI implementation.  We discuss these gaps and why they persist.</itunes:subtitle><itunes:summary><![CDATA[Our hosts firmly believe that PKI is a necessary component of all digital interactions.  And yet there are still gaps in PKI implementation.  We discuss these gaps and why they persist.]]></itunes:summary><itunes:duration>1450</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 352: FBI Vs. End-to-end Encryption in Meta Apps</title><link>https://www.spreaker.com/episode/root-causes-352-fbi-vs-end-to-end-encryption-in-meta-apps--58198247</link><description><![CDATA[Meta is finally rolling out end-to-end encryption across its messaging apps. This is the latest chapter in the long story of government versus encryption.  We rant a little about this.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1708200531</guid><pubDate>Thu, 04 Jan 2024 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58198247/1708200531_tim_callan_root_causes_352_fbi_vs_end_to_end_encryption_in_meta_apps.mp3" length="22109465" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Meta is finally rolling out end-to-end encryption across its messaging apps. This is the latest chapter in the long story of government versus encryption.  We rant a little about this.</itunes:subtitle><itunes:summary><![CDATA[Meta is finally rolling out end-to-end encryption across its messaging apps. This is the latest chapter in the long story of government versus encryption.  We rant a little about this.]]></itunes:summary><itunes:duration>921</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 351: 2024 Predictions</title><link>https://www.spreaker.com/episode/root-causes-351-2024-predictions--58131508</link><description><![CDATA[We look forward to 2024 and predict trends for PKI, certificates, and digital identity. We discuss shortening certificate lifespans, Multi-perspective Domain Validation (MPDV), eIDAS 2.0, OCSP, post-quantum cryptography (PQC), Certificate Lifecycle Management (CLM), passwords, root stores, and government versus encryption. Plus, will Jason be sent to the gulag for not being Canadian enough?]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1701117078</guid><pubDate>Wed, 27 Dec 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58131508/1701117078_tim_callan_root_causes_351_2024_predictions.mp3" length="26144909" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We look forward to 2024 and predict trends for PKI, certificates, and digital identity. We discuss shortening certificate lifespans, Multi-perspective Domain Validation (MPDV), eIDAS 2.0, OCSP, post-quantum cryptography (PQC), Certificate Lifecycle...</itunes:subtitle><itunes:summary><![CDATA[We look forward to 2024 and predict trends for PKI, certificates, and digital identity. We discuss shortening certificate lifespans, Multi-perspective Domain Validation (MPDV), eIDAS 2.0, OCSP, post-quantum cryptography (PQC), Certificate Lifecycle Management (CLM), passwords, root stores, and government versus encryption. Plus, will Jason be sent to the gulag for not being Canadian enough?]]></itunes:summary><itunes:duration>1089</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 350: Public Certificates and the GDPR Right to Be Forgotten</title><link>https://www.spreaker.com/episode/root-causes-350-public-certificates-and-the-gdpr-right-to-be-forgotten--58088602</link><description><![CDATA[GDPR provides a "right to be forgotten," whereby individuals can demand the removal of PII from IT systems. This can run directly contrary to the transparency and permanence built into the DNA of public PKI systems. We explore this conundrum.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1696295664</guid><pubDate>Thu, 21 Dec 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58088602/1696295664_tim_callan_root_causes_350_public_certificates_and_the_gdpr_right_to_be_forgotten.mp3" length="22248797" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>GDPR provides a "right to be forgotten," whereby individuals can demand the removal of PII from IT systems. This can run directly contrary to the transparency and permanence built into the DNA of public PKI systems. We explore this conundrum.</itunes:subtitle><itunes:summary><![CDATA[GDPR provides a "right to be forgotten," whereby individuals can demand the removal of PII from IT systems. This can run directly contrary to the transparency and permanence built into the DNA of public PKI systems. We explore this conundrum.]]></itunes:summary><itunes:duration>927</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 349: 2023 Lookback - Overall Trends</title><link>https://www.spreaker.com/episode/root-causes-349-2023-lookback-overall-trends--58047817</link><description><![CDATA[We look back at PKI in 2023. Trends include artificial intelligence, enterprise crypto agility, the fall of OCSP, PKI everywhere, the weakness of passwords, and government versus the internet. We also look at last year's predictions and compare them to the year's events.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1693405557</guid><pubDate>Mon, 18 Dec 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58047817/1693405557_tim_callan_root_causes_349_2023_lookback_overall_trends.mp3" length="32575956" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We look back at PKI in 2023. Trends include artificial intelligence, enterprise crypto agility, the fall of OCSP, PKI everywhere, the weakness of passwords, and government versus the internet. We also look at last year's predictions and compare them...</itunes:subtitle><itunes:summary><![CDATA[We look back at PKI in 2023. Trends include artificial intelligence, enterprise crypto agility, the fall of OCSP, PKI everywhere, the weakness of passwords, and government versus the internet. We also look at last year's predictions and compare them to the year's events.]]></itunes:summary><itunes:duration>1357</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 348: What Is a Merkle Tree?</title><link>https://www.spreaker.com/episode/root-causes-348-what-is-a-merkle-tree--58020717</link><description><![CDATA[One foundational element of modern cryptographic systems is the Merkle tree.  Merkle tree is an enabler of blockchain and CT logs, among other things. We explain this data structure, its properties, and its use cases.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1691294871</guid><pubDate>Fri, 15 Dec 2023 16:22:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58020717/1691294871_tim_callan_root_causes_348_what_is_a_merkle_tree.mp3" length="17417362" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>One foundational element of modern cryptographic systems is the Merkle tree.  Merkle tree is an enabler of blockchain and CT logs, among other things. We explain this data structure, its properties, and its use cases.</itunes:subtitle><itunes:summary><![CDATA[One foundational element of modern cryptographic systems is the Merkle tree.  Merkle tree is an enabler of blockchain and CT logs, among other things. We explain this data structure, its properties, and its use cases.]]></itunes:summary><itunes:duration>726</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 347: 2023 Lookback - Shortening Certificate Lifespans</title><link>https://www.spreaker.com/episode/root-causes-347-2023-lookback-shortening-certificate-lifespans--57978377</link><description><![CDATA[90-day SSL certificates is only part of it!  2023 has been a year of certificate lifespans getting shorter.  We review these trends.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1687927818</guid><pubDate>Mon, 11 Dec 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57978377/1687927818_tim_callan_root_causes_347_2023_lookback_shortening_certificate_lifespans.mp3" length="26969196" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>90-day SSL certificates is only part of it!  2023 has been a year of certificate lifespans getting shorter.  We review these trends.</itunes:subtitle><itunes:summary><![CDATA[90-day SSL certificates is only part of it!  2023 has been a year of certificate lifespans getting shorter.  We review these trends.]]></itunes:summary><itunes:duration>1124</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 346: Private Credentials In Public Code</title><link>https://www.spreaker.com/episode/root-causes-346-private-credentials-in-public-code--57955175</link><description><![CDATA[In this episode we uncover the epidemic of private credentials in public-facing code repositories, including why it occurs and what do to about it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1685920107</guid><pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57955175/1685920107_tim_callan_root_causes_346_private_credentials_in_public_code.mp3" length="22307615" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we uncover the epidemic of private credentials in public-facing code repositories, including why it occurs and what do to about it.</itunes:subtitle><itunes:summary><![CDATA[In this episode we uncover the epidemic of private credentials in public-facing code repositories, including why it occurs and what do to about it.]]></itunes:summary><itunes:duration>930</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 345: Apple Versus European Sideloading</title><link>https://www.spreaker.com/episode/root-causes-345-apple-versus-european-sideloading--57922679</link><description><![CDATA[The European Union is applying pressure to Apple to allow sideloading of applications. We go over why this is occurring, the potential dangers, and Apple's response.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1683182409</guid><pubDate>Tue, 05 Dec 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57922679/1683182409_tim_callan_root_causes_345_apple_versus_european_sideloading.mp3" length="18253144" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The European Union is applying pressure to Apple to allow sideloading of applications. We go over why this is occurring, the potential dangers, and Apple's response.</itunes:subtitle><itunes:summary><![CDATA[The European Union is applying pressure to Apple to allow sideloading of applications. We go over why this is occurring, the potential dangers, and Apple's response.]]></itunes:summary><itunes:duration>761</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 344: Introducing the PQC Onramp</title><link>https://www.spreaker.com/episode/root-causes-344-introducing-the-pqc-onramp--57853679</link><description><![CDATA[NIST's Round 3 competition has yielded winners for standardization. But NIST wants to continue finding additional potential algorithms, especially those using non-Lattice schemes. We explain the PQC "onramp" and what we should expect.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1677767325</guid><pubDate>Wed, 29 Nov 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57853679/1677767325_tim_callan_root_causes_344_introducing_the_pqc_onramp.mp3" length="24394455" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST's Round 3 competition has yielded winners for standardization. But NIST wants to continue finding additional potential algorithms, especially those using non-Lattice schemes. We explain the PQC "onramp" and what we should expect.</itunes:subtitle><itunes:summary><![CDATA[NIST's Round 3 competition has yielded winners for standardization. But NIST wants to continue finding additional potential algorithms, especially those using non-Lattice schemes. We explain the PQC "onramp" and what we should expect.]]></itunes:summary><itunes:duration>1017</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 343: The EIDAS 2.0 Controversy</title><link>https://www.spreaker.com/episode/root-causes-343-the-eidas-2-0-controversy--57769776</link><description><![CDATA[ETSI is preparing to release specifications for eIDAS 2.0. One controversial aspect of this new standard is that it limits browsers' ability to determine their own trusted roots. In this episode we explain this limitation and the concerns surrounding it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1671976164</guid><pubDate>Wed, 22 Nov 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57769776/1671976164_tim_callan_root_causes_343_the_eidas_20_controversy.mp3" length="37420692" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>ETSI is preparing to release specifications for eIDAS 2.0. One controversial aspect of this new standard is that it limits browsers' ability to determine their own trusted roots. In this episode we explain this limitation and the concerns surrounding it.</itunes:subtitle><itunes:summary><![CDATA[ETSI is preparing to release specifications for eIDAS 2.0. One controversial aspect of this new standard is that it limits browsers' ability to determine their own trusted roots. In this episode we explain this limitation and the concerns surrounding it.]]></itunes:summary><itunes:duration>1559</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 342: Don't Change Your Password for Two Years</title><link>https://www.spreaker.com/episode/root-causes-342-don-t-change-your-password-for-two-years--57682774</link><description><![CDATA[The CA/Browser Forum rules stipulate how often forced password changes for CA employees are to occur. They don't, however, specify a frequency at which these forced changes must occur. Rather, they set the MINIMUM time before forced password changes can happen. Join us to learn why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1667482446</guid><pubDate>Fri, 17 Nov 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57682774/1667482446_tim_callan_root_causes_342_dont_change_your_password_for_two_years.mp3" length="16389796" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CA/Browser Forum rules stipulate how often forced password changes for CA employees are to occur. They don't, however, specify a frequency at which these forced changes must occur. Rather, they set the MINIMUM time before forced password changes...</itunes:subtitle><itunes:summary><![CDATA[The CA/Browser Forum rules stipulate how often forced password changes for CA employees are to occur. They don't, however, specify a frequency at which these forced changes must occur. Rather, they set the MINIMUM time before forced password changes can happen. Join us to learn why.]]></itunes:summary><itunes:duration>683</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 341: The Trouble with Security Questionnaires</title><link>https://www.spreaker.com/episode/root-causes-341-the-trouble-with-security-questionnaires--57623165</link><description><![CDATA[The practice of sending security questionnaires to technology vendors is exploding, and with it dysfunctional behavior is on the rise. In this episode we describe how security questionnaires are changing and the pitfalls associated with this emerging practice.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1664111133</guid><pubDate>Mon, 13 Nov 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57623165/1664111133_tim_callan_root_causes_341_the_trouble_with_security_questionnaires.mp3" length="28019237" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The practice of sending security questionnaires to technology vendors is exploding, and with it dysfunctional behavior is on the rise. In this episode we describe how security questionnaires are changing and the pitfalls associated with this emerging...</itunes:subtitle><itunes:summary><![CDATA[The practice of sending security questionnaires to technology vendors is exploding, and with it dysfunctional behavior is on the rise. In this episode we describe how security questionnaires are changing and the pitfalls associated with this emerging practice.]]></itunes:summary><itunes:duration>1168</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 340: Is This Podcast Canadian Enough?</title><link>https://www.spreaker.com/episode/root-causes-340-is-this-podcast-canadian-enough--57528301</link><description><![CDATA[Canada's Online Streaming Act will require internet content providers to provide a minimum percentage of content produced by Canadians or face fines. We explore this latest episode in the theme of governments attempting to control the free flow of information on the internet.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1657740411</guid><pubDate>Mon, 06 Nov 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57528301/1657740411_tim_callan_root_causes_340_is_this_podcast_canadian_enough.mp3" length="20507036" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Canada's Online Streaming Act will require internet content providers to provide a minimum percentage of content produced by Canadians or face fines. We explore this latest episode in the theme of governments attempting to control the free flow of...</itunes:subtitle><itunes:summary><![CDATA[Canada's Online Streaming Act will require internet content providers to provide a minimum percentage of content produced by Canadians or face fines. We explore this latest episode in the theme of governments attempting to control the free flow of information on the internet.]]></itunes:summary><itunes:duration>855</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 339: The ROI of CLM</title><link>https://www.spreaker.com/episode/root-causes-339-the-roi-of-clm--57460343</link><description><![CDATA[In this episode we describe at a high level how to calculate the Total Cost of Ownership (TCO) of CLM as opposed to manual installation and management of certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1653613314</guid><pubDate>Tue, 31 Oct 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57460343/1653613314_tim_callan_root_causes_339_the_roi_of_clm.mp3" length="16376523" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe at a high level how to calculate the Total Cost of Ownership (TCO) of CLM as opposed to manual installation and management of certificates.</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe at a high level how to calculate the Total Cost of Ownership (TCO) of CLM as opposed to manual installation and management of certificates.]]></itunes:summary><itunes:duration>682</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 338: CLM and Your Career as an IT Professional</title><link>https://www.spreaker.com/episode/root-causes-338-clm-and-your-career-as-an-it-professional--57354831</link><description><![CDATA[In this follow up to our episode on CLM and the IT skills gap, we now discuss how CLM matters to individual IT professionals and can help progress careers and improve work life.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1647354646</guid><pubDate>Mon, 23 Oct 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57354831/1647354646_tim_callan_root_causes_338_clm_and_your_career_as_an_it_professional.mp3" length="27832528" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this follow up to our episode on CLM and the IT skills gap, we now discuss how CLM matters to individual IT professionals and can help progress careers and improve work life.</itunes:subtitle><itunes:summary><![CDATA[In this follow up to our episode on CLM and the IT skills gap, we now discuss how CLM matters to individual IT professionals and can help progress careers and improve work life.]]></itunes:summary><itunes:duration>1160</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 337: CLM and the IT Skills Gap</title><link>https://www.spreaker.com/episode/root-causes-337-clm-and-the-it-skills-gap--57183213</link><description><![CDATA[For decades industry has had more need for skilled IT employees than the workforce could provide. In this episode we discuss how Certificate Lifecycle Management and certificate automation can help mitigate the challenges posed by the IT skills gap.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1636843149</guid><pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57183213/1636843149_tim_callan_root_causes_337_clm_and_the_it_skills_gap.mp3" length="29638844" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>For decades industry has had more need for skilled IT employees than the workforce could provide. In this episode we discuss how Certificate Lifecycle Management and certificate automation can help mitigate the challenges posed by the IT skills gap.</itunes:subtitle><itunes:summary><![CDATA[For decades industry has had more need for skilled IT employees than the workforce could provide. In this episode we discuss how Certificate Lifecycle Management and certificate automation can help mitigate the challenges posed by the IT skills gap.]]></itunes:summary><itunes:duration>1235</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 336: Digitally Signing Images on Cameras</title><link>https://www.spreaker.com/episode/root-causes-336-digitally-signing-images-on-cameras--57051179</link><description><![CDATA[A recent press release discusses efforts of camera manufacturers and the digital imagery supply chain to create an ecosystem for digitally signed images. We describe what such an ecosystem would do, where it could do in the future, and the advantages and limitations of these schemes.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1631756766</guid><pubDate>Tue, 03 Oct 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57051179/1631756766_tim_callan_root_causes_336_digitally_signing_images_on_cameras.mp3" length="20480458" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent press release discusses efforts of camera manufacturers and the digital imagery supply chain to create an ecosystem for digitally signed images. We describe what such an ecosystem would do, where it could do in the future, and the advantages...</itunes:subtitle><itunes:summary><![CDATA[A recent press release discusses efforts of camera manufacturers and the digital imagery supply chain to create an ecosystem for digitally signed images. We describe what such an ecosystem would do, where it could do in the future, and the advantages and limitations of these schemes.]]></itunes:summary><itunes:duration>853</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 335: When MFA Is Not MFA</title><link>https://www.spreaker.com/episode/root-causes-335-when-mfa-is-not-mfa--56995967</link><description><![CDATA[In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach.  We explain.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1628679435</guid><pubDate>Fri, 29 Sep 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56995967/1628679435_tim_callan_root_causes_335_when_mfa_is_not_mfa.mp3" length="14156624" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach.  We explain.</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach.  We explain.]]></itunes:summary><itunes:duration>590</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 334: What Is Attestation on the Web?</title><link>https://www.spreaker.com/episode/root-causes-334-what-is-attestation-on-the-web--56962851</link><description><![CDATA[Most people hate dealing with CAPTCHA, but it offers great benefits for web site operators.  In this episode we discuss alternatives to CAPTCHA, how they work, and their pros and cons.  Plus, the Get-Off-My-Lawn! browser returns.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1626863355</guid><pubDate>Tue, 26 Sep 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56962851/1626863355_tim_callan_root_causes_334_what_is_attestation_on_the_web.mp3" length="25999195" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Most people hate dealing with CAPTCHA, but it offers great benefits for web site operators.  In this episode we discuss alternatives to CAPTCHA, how they work, and their pros and cons.  Plus, the Get-Off-My-Lawn! browser returns.</itunes:subtitle><itunes:summary><![CDATA[Most people hate dealing with CAPTCHA, but it offers great benefits for web site operators.  In this episode we discuss alternatives to CAPTCHA, how they work, and their pros and cons.  Plus, the Get-Off-My-Lawn! browser returns.]]></itunes:summary><itunes:duration>1083</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 333: Intel Side Channel Attack Steals Private Keys</title><link>https://www.spreaker.com/episode/root-causes-333-intel-side-channel-attack-steals-private-keys--56883244</link><description><![CDATA[A newly revealed side channel attack can capture AES encryption keys from Intel chips. We explain this significant and powerful attack.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1621729950</guid><pubDate>Wed, 20 Sep 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56883244/1621729950_tim_callan_root_causes_333_intel_side_channel_attack_steals_private_keys.mp3" length="24355306" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A newly revealed side channel attack can capture AES encryption keys from Intel chips. We explain this significant and powerful attack.</itunes:subtitle><itunes:summary><![CDATA[A newly revealed side channel attack can capture AES encryption keys from Intel chips. We explain this significant and powerful attack.]]></itunes:summary><itunes:duration>1015</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 332: Acoustic AI-based Key Logging Attack</title><link>https://www.spreaker.com/episode/root-causes-332-acoustic-ai-based-key-logging-attack--56815023</link><description><![CDATA[Researchers have built an AI model that can interpret keystrokes based on the sound of keyboard use over a phone or video call.  Among other things, this technique can be used to steal passwords when the sound of logging in can be overheard. Join us as we learn about this new breed of credential harvesting.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1617440298</guid><pubDate>Thu, 14 Sep 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56815023/1617440298_tim_callan_root_causes_332_accoustic_ai_based_key_logging_attack.mp3" length="15267743" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Researchers have built an AI model that can interpret keystrokes based on the sound of keyboard use over a phone or video call.  Among other things, this technique can be used to steal passwords when the sound of logging in can be overheard. Join us...</itunes:subtitle><itunes:summary><![CDATA[Researchers have built an AI model that can interpret keystrokes based on the sound of keyboard use over a phone or video call.  Among other things, this technique can be used to steal passwords when the sound of logging in can be overheard. Join us as we learn about this new breed of credential harvesting.]]></itunes:summary><itunes:duration>636</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 331: Microsoft Restores Trust to VeriSign Code Signing Root</title><link>https://www.spreaker.com/episode/root-causes-331-microsoft-restores-trust-to-verisign-code-signing-root--56790049</link><description><![CDATA[Recent erroneous behavior for certain applications on Windows has drawn attention to the Microsoft trusted root store.  It turns out that Microsoft removed - and then re-added - a legacy VeriSign root in its trusted roots list.  We give you the details of what went on and why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1615552317</guid><pubDate>Wed, 13 Sep 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56790049/1615552317_tim_callan_root_causes_331_microsoft_restores_trust_to_verisign_code_signing_root.mp3" length="20467881" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent erroneous behavior for certain applications on Windows has drawn attention to the Microsoft trusted root store.  It turns out that Microsoft removed - and then re-added - a legacy VeriSign root in its trusted roots list.  We give you the...</itunes:subtitle><itunes:summary><![CDATA[Recent erroneous behavior for certain applications on Windows has drawn attention to the Microsoft trusted root store.  It turns out that Microsoft removed - and then re-added - a legacy VeriSign root in its trusted roots list.  We give you the details of what went on and why.]]></itunes:summary><itunes:duration>853</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 330: End-to-end PQC in Use Today</title><link>https://www.spreaker.com/episode/root-causes-330-end-to-end-pqc-in-use-today--56702636</link><description><![CDATA[Our hosts are joined by IronCap CEO Andrew Cheung as he discusses commercially available PQC solutions today, including VPN, email, and crypto currency.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1609150458</guid><pubDate>Tue, 05 Sep 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56702636/1609150458_tim_callan_root_causes_330_end_to_end_pqc_in_use_today.mp3" length="31271320" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Our hosts are joined by IronCap CEO Andrew Cheung as he discusses commercially available PQC solutions today, including VPN, email, and crypto currency.</itunes:subtitle><itunes:summary><![CDATA[Our hosts are joined by IronCap CEO Andrew Cheung as he discusses commercially available PQC solutions today, including VPN, email, and crypto currency.]]></itunes:summary><itunes:duration>1303</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 329: What Is Messaging Layer Security?</title><link>https://www.spreaker.com/episode/root-causes-329-what-is-messaging-layer-security--56629744</link><description><![CDATA[The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1603819845</guid><pubDate>Tue, 29 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56629744/1603819845_tim_callan_root_causes_329_what_is_messaging_layer_security.mp3" length="15797076" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.</itunes:subtitle><itunes:summary><![CDATA[The recently published Messaging Layer Security (MLS) protocol establishes key exchange protocols for participants in a simultaneous communication session for three or more participants. We explain its significance and possible futures for this standard.]]></itunes:summary><itunes:duration>658</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 328: What Is the Debian Weak Key Flaw?</title><link>https://www.spreaker.com/episode/root-causes-328-what-is-the-debian-weak-key-flaw--56569685</link><description><![CDATA[In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1599597372</guid><pubDate>Wed, 23 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56569685/1599597372_tim_callan_root_causes_328_what_is_the_debian_weak_key_flaw.mp3" length="10061741" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.</itunes:subtitle><itunes:summary><![CDATA[In 2008 the world of SSL was shocked by the discovery of a flaw in a popular operating system that limited the total set of possible private keys on this OS to about 32,000. We explain what happened, industry response, and its consequences.]]></itunes:summary><itunes:duration>419</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 327: What Is Multi-perspective Domain Validation?</title><link>https://www.spreaker.com/episode/root-causes-327-what-is-multi-perspective-domain-validation--56512346</link><description><![CDATA[In this episode we explain Border Gateway Protocol (BGP) attacks and how multi-perspective domain validation (MPDV, also known as multi-vantage point domain validation) can defeat them.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1596047181</guid><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56512346/1596047181_tim_callan_root_causes_327_what_is_multi_perspective_domain_validation.mp3" length="24380616" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain Border Gateway Protocol (BGP) attacks and how multi-perspective domain validation (MPDV, also known as multi-vantage point domain validation) can defeat them.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain Border Gateway Protocol (BGP) attacks and how multi-perspective domain validation (MPDV, also known as multi-vantage point domain validation) can defeat them.]]></itunes:summary><itunes:duration>1016</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 326: The Difference Between .ml and .mil</title><link>https://www.spreaker.com/episode/root-causes-326-the-difference-between-ml-and-mil--56479515</link><description><![CDATA[A recent Financial Times article reveals that mistyped email addresses aimed at the US military frequently are sent to email addresses in Mali instead, to the tune of hundreds of thousands per year.  Some of this includes sensitive military content.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1593936705</guid><pubDate>Tue, 15 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56479515/1593936705_tim_callan_root_causes_326_the_difference_between_ml_and_mil.mp3" length="16769288" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent Financial Times article reveals that mistyped email addresses aimed at the US military frequently are sent to email addresses in Mali instead, to the tune of hundreds of thousands per year.  Some of this includes sensitive military content.</itunes:subtitle><itunes:summary><![CDATA[A recent Financial Times article reveals that mistyped email addresses aimed at the US military frequently are sent to email addresses in Mali instead, to the tune of hundreds of thousands per year.  Some of this includes sensitive military content.]]></itunes:summary><itunes:duration>699</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 325: Certificate Error Causes Sharepoint Outage</title><link>https://www.spreaker.com/episode/root-causes-325-certificate-error-causes-sharepoint-outage--56445117</link><description><![CDATA[A recent outage in Microsoft Sharepoint was caused by an error in certificate installation. We explain what happened and the lessons to be learned.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1590862407</guid><pubDate>Fri, 11 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56445117/1590862407_tim_callan_root_causes_325_certificate_error_causes_sharepoint_outage.mp3" length="18527238" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent outage in Microsoft Sharepoint was caused by an error in certificate installation. We explain what happened and the lessons to be learned.</itunes:subtitle><itunes:summary><![CDATA[A recent outage in Microsoft Sharepoint was caused by an error in certificate installation. We explain what happened and the lessons to be learned.]]></itunes:summary><itunes:duration>579</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 324: Apple Vs New UK Surveillance Bill</title><link>https://www.spreaker.com/episode/root-causes-324-apple-vs-new-uk-surveillance-bill--56393369</link><description><![CDATA[The battle between government and encryption continues. The UK is attempting to build secret back doors into end-to-end encrypted services. In response, Apple has threatened to remove Apple services from the UK, including FaceTime and iMessage.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1585817747</guid><pubDate>Mon, 07 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56393369/1585817747_tim_callan_root_causes_324_apple_vs_new_uk_surveillance_bill.mp3" length="22533516" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The battle between government and encryption continues. The UK is attempting to build secret back doors into end-to-end encrypted services. In response, Apple has threatened to remove Apple services from the UK, including FaceTime and iMessage.</itunes:subtitle><itunes:summary><![CDATA[The battle between government and encryption continues. The UK is attempting to build secret back doors into end-to-end encrypted services. In response, Apple has threatened to remove Apple services from the UK, including FaceTime and iMessage.]]></itunes:summary><itunes:duration>939</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 323: Update on Microsoft Key Compromise</title><link>https://www.spreaker.com/episode/root-causes-323-update-on-microsoft-key-compromise--56356806</link><description><![CDATA[In this follow up to our episode 320, we describe Microsoft's actions to mitigate this attack and explain new understanding that shows its impact to be broader than originally thought. Anyone using the Microsoft stack needs to understand this new threat.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1581989575</guid><pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56356806/1581989575_tim_callan_root_causes_323_update_on_microsoft_key_compromise.mp3" length="23511552" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this follow up to our episode 320, we describe Microsoft's actions to mitigate this attack and explain new understanding that shows its impact to be broader than originally thought. Anyone using the Microsoft stack needs to understand this new threat.</itunes:subtitle><itunes:summary><![CDATA[In this follow up to our episode 320, we describe Microsoft's actions to mitigate this attack and explain new understanding that shows its impact to be broader than originally thought. Anyone using the Microsoft stack needs to understand this new threat.]]></itunes:summary><itunes:duration>735</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 322: RIP Kevin Mitnick</title><link>https://www.spreaker.com/episode/root-causes-322-rip-kevin-mitnick--56325698</link><description><![CDATA[In July famous security researcher Kevin Mitnick passed away.  We briefly pay tribute to Kevin and talk about his contributions to white hat hacking as a practice.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1579312471</guid><pubDate>Mon, 31 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56325698/1579312471_tim_callan_root_causes_322_rip_kevin_mitnick.mp3" length="11254272" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In July famous security researcher Kevin Mitnick passed away.  We briefly pay tribute to Kevin and talk about his contributions to white hat hacking as a practice.</itunes:subtitle><itunes:summary><![CDATA[In July famous security researcher Kevin Mitnick passed away.  We briefly pay tribute to Kevin and talk about his contributions to white hat hacking as a practice.]]></itunes:summary><itunes:duration>352</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 321: CABF Moratorium on New Certificate Consumer Members</title><link>https://www.spreaker.com/episode/root-causes-321-cabf-moratorium-on-new-certificate-consumer-members--56249471</link><description><![CDATA[The CA/Browser Forum recently passed a temporary moratorium on new members of the Certificate Consumer class.  We explain how Certificate Consumers have been admittted in the past and the pros and cons of creating stricter rules for Certificate Consumers.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1575915868</guid><pubDate>Thu, 27 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56249471/1575915868_tim_callan_root_causes_321_cabf_moratorium_on_new_certificate_consumer_members.mp3" length="22523581" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CA/Browser Forum recently passed a temporary moratorium on new members of the Certificate Consumer class.  We explain how Certificate Consumers have been admittted in the past and the pros and cons of creating stricter rules for Certificate Consumers.</itunes:subtitle><itunes:summary><![CDATA[The CA/Browser Forum recently passed a temporary moratorium on new members of the Certificate Consumer class.  We explain how Certificate Consumers have been admittted in the past and the pros and cons of creating stricter rules for Certificate Consumers.]]></itunes:summary><itunes:duration>939</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 320: Microsoft-signed Root Kit Attack</title><link>https://www.spreaker.com/episode/root-causes-320-microsoft-signed-root-kit-attack--56199927</link><description><![CDATA[A new root kit attack in the wild is code signed by a Microsoft certificate. We explain kernel-level attacks, how powerful they are, and how this attack occurred.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1573320337</guid><pubDate>Mon, 24 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56199927/1573320337_tim_callan_root_causes_320_microsoft_signed_root_kit_attack.mp3" length="15908399" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new root kit attack in the wild is code signed by a Microsoft certificate. We explain kernel-level attacks, how powerful they are, and how this attack occurred.</itunes:subtitle><itunes:summary><![CDATA[A new root kit attack in the wild is code signed by a Microsoft certificate. We explain kernel-level attacks, how powerful they are, and how this attack occurred.]]></itunes:summary><itunes:duration>663</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 319: EU Digital Wallets</title><link>https://www.spreaker.com/episode/root-causes-319-eu-digital-wallets--56177258</link><description><![CDATA[A new agreement mandates that European countries will make digital wallets available to their citizens in 2024.  We explain what's coming and some of its implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1571229199</guid><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56177258/1571229199_tim_callan_root_causes_319_eu_digital_wallets.mp3" length="29292632" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new agreement mandates that European countries will make digital wallets available to their citizens in 2024.  We explain what's coming and some of its implications.</itunes:subtitle><itunes:summary><![CDATA[A new agreement mandates that European countries will make digital wallets available to their citizens in 2024.  We explain what's coming and some of its implications.]]></itunes:summary><itunes:duration>1221</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 318: What Is ACME Renewal Information (ARI)?</title><link>https://www.spreaker.com/episode/root-causes-318-what-is-acme-renewal-information-ari--56139908</link><description><![CDATA[ACME is a functional and widely supported protocol for certificate provisioning and installation. A new extension to the protocol will help automate renewals.  In this episode we explain ACME Renewal Information (ARI).]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1568302042</guid><pubDate>Tue, 18 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56139908/1568302042_tim_callan_root_causes_318_what_is_acme_renewal_information_ari.mp3" length="14604655" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>ACME is a functional and widely supported protocol for certificate provisioning and installation. A new extension to the protocol will help automate renewals.  In this episode we explain ACME Renewal Information (ARI).</itunes:subtitle><itunes:summary><![CDATA[ACME is a functional and widely supported protocol for certificate provisioning and installation. A new extension to the protocol will help automate renewals.  In this episode we explain ACME Renewal Information (ARI).]]></itunes:summary><itunes:duration>609</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 317: New Automotive CAN Bus Attacks Demand PKI</title><link>https://www.spreaker.com/episode/root-causes-317-new-automotive-can-bus-attacks-demand-pki--56090232</link><description><![CDATA[In this episode we describe how physically accessing the CAN bus wires in a modern automobile can allow a thief to take over key fob functionality to unlock the doors, start the engine, and ultimately steal the vehicle.  We explain how PKI can defeat this attack and what is necessary to get there.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1564140772</guid><pubDate>Thu, 13 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56090232/1564140772_tim_callan_root_causes_317_new_automotive_can_bus_attacks_demand_pki.mp3" length="29299574" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe how physically accessing the CAN bus wires in a modern automobile can allow a thief to take over key fob functionality to unlock the doors, start the engine, and ultimately steal the vehicle.  We explain how PKI can defeat...</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe how physically accessing the CAN bus wires in a modern automobile can allow a thief to take over key fob functionality to unlock the doors, start the engine, and ultimately steal the vehicle.  We explain how PKI can defeat this attack and what is necessary to get there.]]></itunes:summary><itunes:duration>1221</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 316: SquareSpace Acquires Google Domains</title><link>https://www.spreaker.com/episode/root-causes-316-squarespace-acquires-google-domains--56062288</link><description><![CDATA[SquareSpace recently acquired Google's domain registry business.  We discuss what this move says about large technology trends.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1561888303</guid><pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56062288/1561888303_tim_callan_root_causes_316_squarespace_acquires_google_domains.mp3" length="18566477" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>SquareSpace recently acquired Google's domain registry business.  We discuss what this move says about large technology trends.</itunes:subtitle><itunes:summary><![CDATA[SquareSpace recently acquired Google's domain registry business.  We discuss what this move says about large technology trends.]]></itunes:summary><itunes:duration>774</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 315: Will the SEC Sue SolarWinds Executives?</title><link>https://www.spreaker.com/episode/root-causes-315-will-the-sec-sue-solarwinds-executives--56028794</link><description><![CDATA[The SEC has sent "Wells notices" to two senior executives from SolarWinds, with regard to the 2019 supply chain attack.  In this episode we explain these notices and their implication.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1558516069</guid><pubDate>Fri, 07 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56028794/1558516069_tim_callan_root_causes_315_will_the_sec_sue_solarwinds_executives.mp3" length="22566814" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The SEC has sent "Wells notices" to two senior executives from SolarWinds, with regard to the 2019 supply chain attack.  In this episode we explain these notices and their implication.</itunes:subtitle><itunes:summary><![CDATA[The SEC has sent "Wells notices" to two senior executives from SolarWinds, with regard to the 2019 supply chain attack.  In this episode we explain these notices and their implication.]]></itunes:summary><itunes:duration>940</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 314: AI-based Deepfakes in Real Crimes</title><link>https://www.spreaker.com/episode/root-causes-314-ai-based-deepfakes-in-real-crimes--56002932</link><description><![CDATA[We have spoken in previous episodes about the potential for deepfakes in real-world crimes. In this episode we discuss a variety of real-world attacks in which deepfakes have played a role. These include fake kidnapping, "sextortion," and a range of spear phishing attacks and social media scams.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1556637772</guid><pubDate>Wed, 05 Jul 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56002932/1556637772_tim_callan_root_causes_314_ai_based_deepfakes_in_real_crimes.mp3" length="37830224" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We have spoken in previous episodes about the potential for deepfakes in real-world crimes. In this episode we discuss a variety of real-world attacks in which deepfakes have played a role. These include fake kidnapping, "sextortion," and a range of...</itunes:subtitle><itunes:summary><![CDATA[We have spoken in previous episodes about the potential for deepfakes in real-world crimes. In this episode we discuss a variety of real-world attacks in which deepfakes have played a role. These include fake kidnapping, "sextortion," and a range of spear phishing attacks and social media scams.]]></itunes:summary><itunes:duration>1576</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 313: SSL Revocation Reason Codes</title><link>https://www.spreaker.com/episode/root-causes-313-ssl-revocation-reason-codes--54841853</link><description><![CDATA[In 2022 Mozilla added a root program requirement that CAs include Reason Codes when revoking public TLS certificates.  In this episode we explain the reason codes, along with some explicitly forbidden reason codes, and go into the backstory behind this requirement.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1548273106</guid><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54841853/1548273106_tim_callan_root_causes_313_ssl_revocation_reason_codes.mp3" length="23142054" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In 2022 Mozilla added a root program requirement that CAs include Reason Codes when revoking public TLS certificates.  In this episode we explain the reason codes, along with some explicitly forbidden reason codes, and go into the backstory behind...</itunes:subtitle><itunes:summary><![CDATA[In 2022 Mozilla added a root program requirement that CAs include Reason Codes when revoking public TLS certificates.  In this episode we explain the reason codes, along with some explicitly forbidden reason codes, and go into the backstory behind this requirement.]]></itunes:summary><itunes:duration>964</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 312: You Shouldn't Roll Your Own Crypto</title><link>https://www.spreaker.com/episode/root-causes-312-you-shouldn-t-roll-your-own-crypto--54553611</link><description><![CDATA[Don't roll your own crypto. In this episode we describe the findings from 2021 research that investigating the root causes of problems in cryptographic systems.  The results may surprise you.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1545549694</guid><pubDate>Tue, 20 Jun 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54553611/1545549694_tim_callan_root_causes_312_you_shouldnt_roll_your_own_crypto.mp3" length="21482191" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Don't roll your own crypto. In this episode we describe the findings from 2021 research that investigating the root causes of problems in cryptographic systems.  The results may surprise you.</itunes:subtitle><itunes:summary><![CDATA[Don't roll your own crypto. In this episode we describe the findings from 2021 research that investigating the root causes of problems in cryptographic systems.  The results may surprise you.]]></itunes:summary><itunes:duration>895</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 311: What Is CCADB?</title><link>https://www.spreaker.com/episode/root-causes-311-what-is-ccadb--54464817</link><description><![CDATA[We describe CCADB, the Common CA Database. We explain the role of CCADB in the WebPKI and how this role is evolving.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1542373918</guid><pubDate>Fri, 16 Jun 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54464817/1542373918_tim_callan_root_causes_311_what_is_ccadb.mp3" length="20008197" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We describe CCADB, the Common CA Database. We explain the role of CCADB in the WebPKI and how this role is evolving.</itunes:subtitle><itunes:summary><![CDATA[We describe CCADB, the Common CA Database. We explain the role of CCADB in the WebPKI and how this role is evolving.]]></itunes:summary><itunes:duration>834</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 310: Another AI Episode</title><link>https://www.spreaker.com/episode/root-causes-310-another-ai-episode--54358599</link><description><![CDATA[In this episode we continue to explore the capabilities of AI to replicate known people in deep fakes with AI-generated content.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1538948491</guid><pubDate>Tue, 13 Jun 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54358599/1538948491_tim_callan_root_causes_310_another_ai_episode.mp3" length="36346935" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we continue to explore the capabilities of AI to replicate known people in deep fakes with AI-generated content.</itunes:subtitle><itunes:summary><![CDATA[In this episode we continue to explore the capabilities of AI to replicate known people in deep fakes with AI-generated content.]]></itunes:summary><itunes:duration>1515</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 309: What Is Key Attestation For Code Signing</title><link>https://www.spreaker.com/episode/root-causes-309-what-is-key-attestation-for-code-signing--54140676</link><description><![CDATA[On June 1, 2023 new rules for delivery of code signing certificates went into effect, requiring the certificate be delivered by secure HSM. In addition to shipping a token by mail, certificates can be electronically delivered to Subscriber-owned hardware that supports key attestation.  In this episode we explain key attestation, supporting hardware, and the pros and cons of this method.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1534284790</guid><pubDate>Thu, 08 Jun 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54140676/1534284790_tim_callan_root_causes_309_what_is_key_attestation_for_code_signing.mp3" length="16262474" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On June 1, 2023 new rules for delivery of code signing certificates went into effect, requiring the certificate be delivered by secure HSM. In addition to shipping a token by mail, certificates can be electronically delivered to Subscriber-owned...</itunes:subtitle><itunes:summary><![CDATA[On June 1, 2023 new rules for delivery of code signing certificates went into effect, requiring the certificate be delivered by secure HSM. In addition to shipping a token by mail, certificates can be electronically delivered to Subscriber-owned hardware that supports key attestation.  In this episode we explain key attestation, supporting hardware, and the pros and cons of this method.]]></itunes:summary><itunes:duration>678</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 308: E-Tugra Root Deprecation</title><link>https://www.spreaker.com/episode/root-causes-308-e-tugra-root-deprecation--54104931</link><description><![CDATA[For the second time in under twelve months, a major browser is deprecating a CA's public trust.  This time it's E-Tugra.  Learn about the concerns raised about this CA, investigation of these concerns, and the ultimate deprecation decision.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1531662517</guid><pubDate>Mon, 05 Jun 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54104931/1531662517_tim_callan_root_causes_308_e_tugra_root_deprecation.mp3" length="25873530" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>For the second time in under twelve months, a major browser is deprecating a CA's public trust.  This time it's E-Tugra.  Learn about the concerns raised about this CA, investigation of these concerns, and the ultimate deprecation decision.</itunes:subtitle><itunes:summary><![CDATA[For the second time in under twelve months, a major browser is deprecating a CA's public trust.  This time it's E-Tugra.  Learn about the concerns raised about this CA, investigation of these concerns, and the ultimate deprecation decision.]]></itunes:summary><itunes:duration>1078</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 307: OT Red Teaming Leads to Malware Attack</title><link>https://www.spreaker.com/episode/root-causes-307-ot-red-teaming-leads-to-malware-attack--54055514</link><description><![CDATA[In this episode we describe how tools from operational technology red team exercises are being repurposed for malware attacks.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1526999656</guid><pubDate>Wed, 31 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54055514/1526999656_tim_callan_root_causes_307_ot_red_teaming_leads_to_malware_attack.mp3" length="19560675" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe how tools from operational technology red team exercises are being repurposed for malware attacks.</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe how tools from operational technology red team exercises are being repurposed for malware attacks.]]></itunes:summary><itunes:duration>815</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 306: Certificate Transparency Logs and Privacy</title><link>https://www.spreaker.com/episode/root-causes-306-certificate-transparency-logs-and-privacy--54010022</link><description><![CDATA[Certificate Transparency (CT) logs do a lot of good for the WebPKI. They also, however, carry with them some privacy concerns.  In this episode we explain those concerns.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1523387233</guid><pubDate>Fri, 26 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/54010022/1523387233_tim_callan_root_causes_306_certificate_transparency_logs_and_privacy.mp3" length="19366568" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certificate Transparency (CT) logs do a lot of good for the WebPKI. They also, however, carry with them some privacy concerns.  In this episode we explain those concerns.</itunes:subtitle><itunes:summary><![CDATA[Certificate Transparency (CT) logs do a lot of good for the WebPKI. They also, however, carry with them some privacy concerns.  In this episode we explain those concerns.]]></itunes:summary><itunes:duration>807</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 305: The Fifth Pillar of Certificate Lifecycle Management</title><link>https://www.spreaker.com/episode/root-causes-305-the-fifth-pillar-of-certificate-lifecycle-management--53985962</link><description><![CDATA[In our episode 143 we introduced the Four Pillars of CLM.  Now, two years later, we introduce a fifth pillar of CLM.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1521513139</guid><pubDate>Tue, 23 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53985962/1521513139_tim_callan_root_causes_305_the_fifth_pillar_of_certificate_lifecycle_management.mp3" length="19752439" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our episode 143 we introduced the Four Pillars of CLM.  Now, two years later, we introduce a fifth pillar of CLM.</itunes:subtitle><itunes:summary><![CDATA[In our episode 143 we introduced the Four Pillars of CLM.  Now, two years later, we introduce a fifth pillar of CLM.]]></itunes:summary><itunes:duration>823</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 304: Your 90-day SSL Certificates Checklist</title><link>https://www.spreaker.com/episode/root-causes-304-your-90-day-ssl-certificates-checklist--53933034</link><description><![CDATA[90-day maximum term for SSL certificates is coming. In this episode expert guest Henry Lam details his four-point checklist for preparing enterprises for these shorter-lived certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1517870395</guid><pubDate>Thu, 18 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53933034/1517870395_tim_callan_root_causes_304_your_90_day_ssl_certificates_checklist.mp3" length="19787442" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>90-day maximum term for SSL certificates is coming. In this episode expert guest Henry Lam details his four-point checklist for preparing enterprises for these shorter-lived certificates.</itunes:subtitle><itunes:summary><![CDATA[90-day maximum term for SSL certificates is coming. In this episode expert guest Henry Lam details his four-point checklist for preparing enterprises for these shorter-lived certificates.]]></itunes:summary><itunes:duration>825</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 303: A Return to Chrome and the Address Bar</title><link>https://www.spreaker.com/episode/root-causes-303-a-return-to-chrome-and-the-address-bar--53894163</link><description><![CDATA[In our recent episode 300 we discussed Chrome's upcoming removal of the lock icon from its interface. In this follow up, we catch the listener up on Chrome's longstanding program to minimize the URL in its interface, even to the point of contemplating removing the address bar entirely.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1515519550</guid><pubDate>Tue, 16 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53894163/1515519550_tim_callan_root_causes_303_a_return_to_chrome_and_the_address_bar.mp3" length="27593000" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our recent episode 300 we discussed Chrome's upcoming removal of the lock icon from its interface. In this follow up, we catch the listener up on Chrome's longstanding program to minimize the URL in its interface, even to the point of contemplating...</itunes:subtitle><itunes:summary><![CDATA[In our recent episode 300 we discussed Chrome's upcoming removal of the lock icon from its interface. In this follow up, we catch the listener up on Chrome's longstanding program to minimize the URL in its interface, even to the point of contemplating removing the address bar entirely.]]></itunes:summary><itunes:duration>1150</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 302: Intel Secure Boot Private Key Leak</title><link>https://www.spreaker.com/episode/root-causes-302-intel-secure-boot-private-key-leak--53839298</link><description><![CDATA[Resulting from a recent ransomware attack, a private key from Intel has been exposed, affecting more than a hundred OEM components and an unknown number of end user products. We explain what happened and its possible implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1513014721</guid><pubDate>Fri, 12 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53839298/1513014721_tim_callan_root_causes_302_intel_secure_boot_private_key_leak.mp3" length="18066536" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Resulting from a recent ransomware attack, a private key from Intel has been exposed, affecting more than a hundred OEM components and an unknown number of end user products. We explain what happened and its possible implications.</itunes:subtitle><itunes:summary><![CDATA[Resulting from a recent ransomware attack, a private key from Intel has been exposed, affecting more than a hundred OEM components and an unknown number of end user products. We explain what happened and its possible implications.]]></itunes:summary><itunes:duration>753</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 301: The Difference Between Certificate Automation and CLM</title><link>https://www.spreaker.com/episode/root-causes-301-the-difference-between-certificate-automation-and-clm--53794082</link><description><![CDATA[This podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM).  In this episode we discuss how CLM does not always entail automation and vice versa -- along with where this distinction occurs and why it matters.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1510343599</guid><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53794082/1510343599_tim_callan_root_causes_301_the_difference_between_certificate_automation_and_clm.mp3" length="21498707" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>This podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM).  In this episode we discuss how CLM does not always entail automation and vice versa -- along with where this distinction occurs and...</itunes:subtitle><itunes:summary><![CDATA[This podcast frequently discusses the concepts of certificate automation and Certificate Lifecycle Management (CLM).  In this episode we discuss how CLM does not always entail automation and vice versa -- along with where this distinction occurs and why it matters.]]></itunes:summary><itunes:duration>896</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 300: Chrome Eliminates the Lock Icon</title><link>https://www.spreaker.com/episode/root-causes-300-chrome-eliminates-the-lock-icon--53752950</link><description><![CDATA[Google Chrome has announced that it will eliminate the lock icon in September. We explain what Google will be doing, its stated rationale, and the pros and cons of this decision.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1507288045</guid><pubDate>Thu, 04 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53752950/1507288045_tim_callan_root_causes_300_chrome_eliminates_the_lock_icon.mp3" length="26880360" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Google Chrome has announced that it will eliminate the lock icon in September. We explain what Google will be doing, its stated rationale, and the pros and cons of this decision.</itunes:subtitle><itunes:summary><![CDATA[Google Chrome has announced that it will eliminate the lock icon in September. We explain what Google will be doing, its stated rationale, and the pros and cons of this decision.]]></itunes:summary><itunes:duration>1120</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 299: 2023 RSA Recap</title><link>https://www.spreaker.com/episode/root-causes-299-2023-rsa-recap--53720773</link><description><![CDATA[The 2023 RSA Conference just concluded.  This week Tim recaps what he saw at the show and how it reflects on security industry trends. Our hosts discuss Zero Trust, PQC, blockchain, artificial intelligence, post-COVID tradeshow behavior, and more.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1504926001</guid><pubDate>Tue, 02 May 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53720773/1504926001_tim_callan_root_causes_299_2023_rsa_recap.mp3" length="44838967" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The 2023 RSA Conference just concluded.  This week Tim recaps what he saw at the show and how it reflects on security industry trends. Our hosts discuss Zero Trust, PQC, blockchain, artificial intelligence, post-COVID tradeshow behavior, and more.</itunes:subtitle><itunes:summary><![CDATA[The 2023 RSA Conference just concluded.  This week Tim recaps what he saw at the show and how it reflects on security industry trends. Our hosts discuss Zero Trust, PQC, blockchain, artificial intelligence, post-COVID tradeshow behavior, and more.]]></itunes:summary><itunes:duration>1868</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 298: Moving Forward, Together - Promoting Automation</title><link>https://www.spreaker.com/episode/root-causes-298-moving-forward-together-promoting-automation--53681158</link><description><![CDATA[The Google Chrome root store has communicated its plans for promoting automation.  In this episode we explain Chrome's public plans for this initiative, which is anchored around ACME.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1502395072</guid><pubDate>Fri, 28 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53681158/1502395072_tim_callan_root_causes_298_moving_forward_together_promoting_automation.mp3" length="17965117" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Google Chrome root store has communicated its plans for promoting automation.  In this episode we explain Chrome's public plans for this initiative, which is anchored around ACME.</itunes:subtitle><itunes:summary><![CDATA[The Google Chrome root store has communicated its plans for promoting automation.  In this episode we explain Chrome's public plans for this initiative, which is anchored around ACME.]]></itunes:summary><itunes:duration>749</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 297: Certificate Expiration Creates Starlink Outage</title><link>https://www.spreaker.com/episode/root-causes-297-certificate-expiration-creates-starlink-outage--53653500</link><description><![CDATA[A recent outage in the Starlink internet service was caused by an unexpected certificate expiration. We discuss this ongoing problem and how 90-day maximum certificate term will exacerbate it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1500747997</guid><pubDate>Wed, 26 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53653500/1500747997_tim_callan_root_causes_297_certificate_expiration_creates_starlink_outage.mp3" length="14331133" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent outage in the Starlink internet service was caused by an unexpected certificate expiration. We discuss this ongoing problem and how 90-day maximum certificate term will exacerbate it.</itunes:subtitle><itunes:summary><![CDATA[A recent outage in the Starlink internet service was caused by an unexpected certificate expiration. We discuss this ongoing problem and how 90-day maximum certificate term will exacerbate it.]]></itunes:summary><itunes:duration>597</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 296: SHOULD We or MUST We?</title><link>https://www.spreaker.com/episode/root-causes-296-should-we-or-must-we--53609547</link><description><![CDATA[The CA/Browser Forum guidelines contain many prescribed requirements, with language containing the word SHOULD or MUST. In this episode we explain the specifying power of these two words, why they are used, and what they signal about the intent behind a guideline and how the rules might evolve.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1497807655</guid><pubDate>Fri, 21 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53609547/1497807655_tim_callan_root_causes_296_should_we_or_must_we.mp3" length="18183998" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CA/Browser Forum guidelines contain many prescribed requirements, with language containing the word SHOULD or MUST. In this episode we explain the specifying power of these two words, why they are used, and what they signal about the intent behind...</itunes:subtitle><itunes:summary><![CDATA[The CA/Browser Forum guidelines contain many prescribed requirements, with language containing the word SHOULD or MUST. In this episode we explain the specifying power of these two words, why they are used, and what they signal about the intent behind a guideline and how the rules might evolve.]]></itunes:summary><itunes:duration>758</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 295: Genesis Criminal Marketplace Taken Down</title><link>https://www.spreaker.com/episode/root-causes-295-genesis-criminal-marketplace-taken-down--53565064</link><description><![CDATA[A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1494911086</guid><pubDate>Mon, 17 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53565064/1494911086_tim_callan_root_causes_295_genesis_criminal_marketplace_taken_down.mp3" length="15968715" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.</itunes:subtitle><itunes:summary><![CDATA[A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.]]></itunes:summary><itunes:duration>665</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 294: Root Causes Honored by Webby Awards</title><link>https://www.spreaker.com/episode/root-causes-294-root-causes-honored-by-webby-awards--53527332</link><description><![CDATA[The Root Causes podcast has received a Webby Honoree award.  Jason and Tim briefly celebrate and discuss the challenge of operating a niche, homemade podcast while being directly compared to professionally produced podcasts on mainstream topics from media companies. Plus, Tim's new Root Causes t-shirt.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1491689812</guid><pubDate>Thu, 13 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53527332/1491689812_tim_callan_root_causes_294_root_causes_honored_by_webby_awards.mp3" length="13201050" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Root Causes podcast has received a Webby Honoree award.  Jason and Tim briefly celebrate and discuss the challenge of operating a niche, homemade podcast while being directly compared to professionally produced podcasts on mainstream topics from...</itunes:subtitle><itunes:summary><![CDATA[The Root Causes podcast has received a Webby Honoree award.  Jason and Tim briefly celebrate and discuss the challenge of operating a niche, homemade podcast while being directly compared to professionally produced podcasts on mainstream topics from media companies. Plus, Tim's new Root Causes t-shirt.]]></itunes:summary><itunes:duration>550</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 293: What Is Certbot?</title><link>https://www.spreaker.com/episode/root-causes-293-what-is-certbot--53493664</link><description><![CDATA[Certbot is an important part of the ACME standard.  This open source tool makes it easier for many IT administrators to use ACME to automate provisioning and installation of SSL / TLS certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1489207144</guid><pubDate>Mon, 10 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53493664/1489207144_tim_callan_root_causes_293_what_is_certbot.mp3" length="18078476" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certbot is an important part of the ACME standard.  This open source tool makes it easier for many IT administrators to use ACME to automate provisioning and installation of SSL / TLS certificates.</itunes:subtitle><itunes:summary><![CDATA[Certbot is an important part of the ACME standard.  This open source tool makes it easier for many IT administrators to use ACME to automate provisioning and installation of SSL / TLS certificates.]]></itunes:summary><itunes:duration>753</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 292: Validation Data Reuse for 90-day Certificates</title><link>https://www.spreaker.com/episode/root-causes-292-validation-data-reuse-for-90-day-certificates--53466172</link><description><![CDATA[As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also.  We explain today's data reuse rules and what the evidence indicates will be required for both domain control validation (DCV) and organization information validation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1486921291</guid><pubDate>Thu, 06 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53466172/1486921291_tim_callan_root_causes_292_validation_data_reuse_for_90_day_certificates.mp3" length="22089728" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also.  We explain today's data reuse rules and what the evidence...</itunes:subtitle><itunes:summary><![CDATA[As the industry explores the expected consequences of 90-day maximum term for SSL / TLS certificates, some are wondering if the allowed validation data reuse period stands to go down also.  We explain today's data reuse rules and what the evidence indicates will be required for both domain control validation (DCV) and organization information validation.]]></itunes:summary><itunes:duration>921</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 291: CLM and SIEM</title><link>https://www.spreaker.com/episode/root-causes-291-clm-and-siem--53427824</link><description><![CDATA[We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee access. We talk about expected behaviors in the CLM and monitoring them.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1484037643</guid><pubDate>Mon, 03 Apr 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53427824/1484037643_tim_callan_root_causes_291_clm_and_siem.mp3" length="13908408" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee...</itunes:subtitle><itunes:summary><![CDATA[We discuss how Certificate Lifecycle Management (CLM) interacts with Security Incident and Event Management (SIEM). The certificate world is chock full of events such as renewals, revocations, admin logins, and provisioning and removal of employee access. We talk about expected behaviors in the CLM and monitoring them.]]></itunes:summary><itunes:duration>580</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 290: What Are QGIS and QIIS?</title><link>https://www.spreaker.com/episode/root-causes-290-what-are-qgis-and-qiis--53396790</link><description><![CDATA[In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation.  We explain how they fit into validation and the criteria for a reliable information source.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1481509357</guid><pubDate>Wed, 29 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53396790/1481509357_tim_callan_root_causes_290_what_are_qgis_and_qiis.mp3" length="18867722" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation.  We explain how they fit into validation and the criteria for a...</itunes:subtitle><itunes:summary><![CDATA[In this episode we define Qualified Government Information Source (QGIS) and Qualified Independent Information Source (QIIS), which are critical to CABF-compliant organization validation.  We explain how they fit into validation and the criteria for a reliable information source.]]></itunes:summary><itunes:duration>786</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 289: What Is a Cryptographic Center of Excellence?</title><link>https://www.spreaker.com/episode/root-causes-289-what-is-a-cryptographic-center-of-excellence--53355401</link><description><![CDATA[In this episode we dig into an emerging idea, which is the cryptographic center of excellence.  We discuss how such a center of excellence would work and the benefits it can bring to an enterprise.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1478675155</guid><pubDate>Mon, 27 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53355401/1478675155_tim_callan_root_causes_289_what_is_a_cryptographic_center_of_excellence.mp3" length="12248952" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we dig into an emerging idea, which is the cryptographic center of excellence.  We discuss how such a center of excellence would work and the benefits it can bring to an enterprise.</itunes:subtitle><itunes:summary><![CDATA[In this episode we dig into an emerging idea, which is the cryptographic center of excellence.  We discuss how such a center of excellence would work and the benefits it can bring to an enterprise.]]></itunes:summary><itunes:duration>510</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 288: ISARA Releases Patents on Hybrid Certificates</title><link>https://www.spreaker.com/episode/root-causes-288-isara-releases-patents-on-hybrid-certificates--53306891</link><description><![CDATA[In this episode we are joined by Atsushi Yamada, CEO of ISARA.  He explains how ISARA has put its patents on hybrid certificates into the public domain and why.  We explain the role of hybrid certificates in PQC and ongoing crypto agility.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1475542822</guid><pubDate>Thu, 23 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53306891/1475542822_tim_callan_root_causes_288_isara_releases_patents_on_hybrid_certificates.mp3" length="11838737" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we are joined by Atsushi Yamada, CEO of ISARA.  He explains how ISARA has put its patents on hybrid certificates into the public domain and why.  We explain the role of hybrid certificates in PQC and ongoing crypto agility.</itunes:subtitle><itunes:summary><![CDATA[In this episode we are joined by Atsushi Yamada, CEO of ISARA.  He explains how ISARA has put its patents on hybrid certificates into the public domain and why.  We explain the role of hybrid certificates in PQC and ongoing crypto agility.]]></itunes:summary><itunes:duration>740</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/df65c56f4766cb628b3a21e005094beb.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 287: GoDaddy Private Key Breach</title><link>https://www.spreaker.com/episode/root-causes-287-godaddy-private-key-breach--53277879</link><description><![CDATA[In this episode we describe an incident in which a GoDaddy breach exposed customer private keys.  We explain the expectations surrounding private key exposure and get into the interesting question of when an incident is or is not part of a large company's CA business.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1473894910</guid><pubDate>Mon, 20 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53277879/1473894910_tim_callan_root_causes_287_godaddy_private_key_breach.mp3" length="19864791" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe an incident in which a GoDaddy breach exposed customer private keys.  We explain the expectations surrounding private key exposure and get into the interesting question of when an incident is or is not part of a large...</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe an incident in which a GoDaddy breach exposed customer private keys.  We explain the expectations surrounding private key exposure and get into the interesting question of when an incident is or is not part of a large company's CA business.]]></itunes:summary><itunes:duration>828</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 286: PKI and PQC in New White House Cybersecurity Initiative</title><link>https://www.spreaker.com/episode/root-causes-286-pki-and-pqc-in-new-white-house-cybersecurity-initiative--53224635</link><description><![CDATA[A new White House cybersecurity initiative specifically calls out digital identity and post quantum cryptography (PQC) among its focal areas. We discuss what it says and the potential implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1470216301</guid><pubDate>Thu, 16 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53224635/1470216301_tim_callan_root_causes_286_pki_and_pqc_in_new_white_house_cybersecurity_initiative.mp3" length="14514885" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A new White House cybersecurity initiative specifically calls out digital identity and post quantum cryptography (PQC) among its focal areas. We discuss what it says and the potential implications.</itunes:subtitle><itunes:summary><![CDATA[A new White House cybersecurity initiative specifically calls out digital identity and post quantum cryptography (PQC) among its focal areas. We discuss what it says and the potential implications.]]></itunes:summary><itunes:duration>605</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 285: Can ChatGPT Write Malware?</title><link>https://www.spreaker.com/episode/root-causes-285-can-chatgpt-write-malware--53195020</link><description><![CDATA[In our ongoing exploration of the security implications of AI, in this episode we examine the suitability of ChatGPT as a malware-writing tool and possible future directions for AI in software creation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1468666618</guid><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53195020/1468666618_tim_callan_root_causes_285_can_chatgpt_write_malware.mp3" length="38785387" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing exploration of the security implications of AI, in this episode we examine the suitability of ChatGPT as a malware-writing tool and possible future directions for AI in software creation.</itunes:subtitle><itunes:summary><![CDATA[In our ongoing exploration of the security implications of AI, in this episode we examine the suitability of ChatGPT as a malware-writing tool and possible future directions for AI in software creation.]]></itunes:summary><itunes:duration>970</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 284: 90-day SSL Certificates Are on the Way</title><link>https://www.spreaker.com/episode/root-causes-284-90-day-ssl-certificates-are-on-the-way--53160843</link><description><![CDATA[The Google Chrome root program recently announced its intention to reduce the maximum term for public SSL certificates to 90 days.  In this episode we explain this announcement and its implications and speculate on timing for this reduction.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1466102515</guid><pubDate>Fri, 10 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53160843/1466102515_tim_callan_root_causes_284_90_day_ssl_certificates_are_on_the_way.mp3" length="22950182" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Google Chrome root program recently announced its intention to reduce the maximum term for public SSL certificates to 90 days.  In this episode we explain this announcement and its implications and speculate on timing for this reduction.</itunes:subtitle><itunes:summary><![CDATA[The Google Chrome root program recently announced its intention to reduce the maximum term for public SSL certificates to 90 days.  In this episode we explain this announcement and its implications and speculate on timing for this reduction.]]></itunes:summary><itunes:duration>1435</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 283: Google Optional OCSP Proposal Clarified</title><link>https://www.spreaker.com/episode/root-causes-283-google-optional-ocsp-proposal-clarified--53112429</link><description><![CDATA[In our episode 281 we reported on Google's proposal for optional OCSP. In this episode we correct some of our earlier reporting in that episode, including the use of CRL and the removal of any revocation requirement for SSL certificates of not more than ten days in term.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1462715416</guid><pubDate>Mon, 06 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53112429/1462715416_tim_callan_root_causes_283_google_optional_ocsp_proposal_clarified.mp3" length="16285560" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our episode 281 we reported on Google's proposal for optional OCSP. In this episode we correct some of our earlier reporting in that episode, including the use of CRL and the removal of any revocation requirement for SSL certificates of not more...</itunes:subtitle><itunes:summary><![CDATA[In our episode 281 we reported on Google's proposal for optional OCSP. In this episode we correct some of our earlier reporting in that episode, including the use of CRL and the removal of any revocation requirement for SSL certificates of not more than ten days in term.]]></itunes:summary><itunes:duration>679</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 282: HSMs and Post Quantum Cryptography</title><link>https://www.spreaker.com/episode/root-causes-282-hsms-and-post-quantum-cryptography--53073341</link><description><![CDATA[Repeat guest Bruno Couillard of Crypto4A joins us to explain where Hardware Secure Modules (HSMs) fit into the world of PQC. We discuss the issues surrounding how HSMs will work with post quantum algorithms and hybrid certificates and the process (and timelines) for defining how HSMs will incorporate PQC.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1459740211</guid><pubDate>Thu, 02 Mar 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53073341/1459740211_tim_callan_root_causes_282_hsms_and_post_quantum_cryptography.mp3" length="68664884" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest Bruno Couillard of Crypto4A joins us to explain where Hardware Secure Modules (HSMs) fit into the world of PQC. We discuss the issues surrounding how HSMs will work with post quantum algorithms and hybrid certificates and the process (and...</itunes:subtitle><itunes:summary><![CDATA[Repeat guest Bruno Couillard of Crypto4A joins us to explain where Hardware Secure Modules (HSMs) fit into the world of PQC. We discuss the issues surrounding how HSMs will work with post quantum algorithms and hybrid certificates and the process (and timelines) for defining how HSMs will incorporate PQC.]]></itunes:summary><itunes:duration>1717</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 281: Google Proposes Optional OCSP</title><link>https://www.spreaker.com/episode/root-causes-281-google-proposes-optional-ocsp--52927564</link><description><![CDATA[In response to concerns about OCSP and privacy, Google has proposed removing the requirement for OCSP revocation checking for public SSL certificates meeting certain specific conditions.  In this episode we go into the details of this proposal.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1457069434</guid><pubDate>Sun, 26 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927564/1457069434_tim_callan_root_causes_281_google_proposes_optional_ocsp.mp3" length="37980549" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In response to concerns about OCSP and privacy, Google has proposed removing the requirement for OCSP revocation checking for public SSL certificates meeting certain specific conditions.  In this episode we go into the details of this proposal.</itunes:subtitle><itunes:summary><![CDATA[In response to concerns about OCSP and privacy, Google has proposed removing the requirement for OCSP revocation checking for public SSL certificates meeting certain specific conditions.  In this episode we go into the details of this proposal.]]></itunes:summary><itunes:duration>1583</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 280: Did an AI Break CRYSTALS-Kyber?</title><link>https://www.spreaker.com/episode/root-causes-280-did-an-ai-break-crystals-kyber--52926729</link><description><![CDATA[Recent news reports might suggest that an AI-enhanced side attack has defeated the CRYSTALS-Kyber PQC algorithm.  In this episode we clarify that Kyber has not been defeated to date and exactly what did occur. We define side channel attack, discuss the broader implications of this attack, and speculate on what would happen if Kyber actually were broken.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1455102184</guid><pubDate>Fri, 24 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926729/1455102184_tim_callan_root_causes_280_did_an_ai_break_crystals_kyber.mp3" length="29014392" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent news reports might suggest that an AI-enhanced side attack has defeated the CRYSTALS-Kyber PQC algorithm.  In this episode we clarify that Kyber has not been defeated to date and exactly what did occur. We define side channel attack, discuss...</itunes:subtitle><itunes:summary><![CDATA[Recent news reports might suggest that an AI-enhanced side attack has defeated the CRYSTALS-Kyber PQC algorithm.  In this episode we clarify that Kyber has not been defeated to date and exactly what did occur. We define side channel attack, discuss the broader implications of this attack, and speculate on what would happen if Kyber actually were broken.]]></itunes:summary><itunes:duration>1209</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 279: ChatGPT Watermarking</title><link>https://www.spreaker.com/episode/root-causes-279-chatgpt-watermarking--52927542</link><description><![CDATA[ChatGPT presents the potential problem of ChatGPT content being used and attributed to another source, such as a professional writer or a student. In this episode we discuss the idea of "watermarking" ChatGPT content, including stenography, randomness, entropy, and how to destroy the watermarks.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1451544178</guid><pubDate>Sun, 19 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927542/1451544178_tim_callan_root_causes_279_chatgpt_watermarking.mp3" length="38195939" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>ChatGPT presents the potential problem of ChatGPT content being used and attributed to another source, such as a professional writer or a student. In this episode we discuss the idea of "watermarking" ChatGPT content, including stenography,...</itunes:subtitle><itunes:summary><![CDATA[ChatGPT presents the potential problem of ChatGPT content being used and attributed to another source, such as a professional writer or a student. In this episode we discuss the idea of "watermarking" ChatGPT content, including stenography, randomness, entropy, and how to destroy the watermarks.]]></itunes:summary><itunes:duration>955</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 278: Microsoft on Certificates and FIDO</title><link>https://www.spreaker.com/episode/root-causes-278-microsoft-on-certificates-and-fido--52926764</link><description><![CDATA[Recent public discussion of FIDO and digital certificates reveal details of Microsoft's approach to consumer digital authentication.  We discuss secure elements, Windows Hello, and the differences between B2C, B2B, and B2E.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1449414250</guid><pubDate>Fri, 17 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926764/1449414250_tim_callan_root_causes_278_microsoft_on_certificates_and_fido.mp3" length="27098809" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent public discussion of FIDO and digital certificates reveal details of Microsoft's approach to consumer digital authentication.  We discuss secure elements, Windows Hello, and the differences between B2C, B2B, and B2E.</itunes:subtitle><itunes:summary><![CDATA[Recent public discussion of FIDO and digital certificates reveal details of Microsoft's approach to consumer digital authentication.  We discuss secure elements, Windows Hello, and the differences between B2C, B2B, and B2E.]]></itunes:summary><itunes:duration>678</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/df65c56f4766cb628b3a21e005094beb.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 277: Privacy Sandbox</title><link>https://www.spreaker.com/episode/root-causes-277-privacy-sandbox--52926609</link><description><![CDATA[In the latest continuation of the effort to create better protections for consumer privacy while still enabling targeted advertising, Google has announced the Privacy Sandbox.  In this episode we describe this latest foray, including concepts like k-anonymity and differential privacy.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1446183160</guid><pubDate>Mon, 13 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926609/1446183160_tim_callan_root_causes_277_privacy_sandbox.mp3" length="21925601" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the latest continuation of the effort to create better protections for consumer privacy while still enabling targeted advertising, Google has announced the Privacy Sandbox.  In this episode we describe this latest foray, including concepts like...</itunes:subtitle><itunes:summary><![CDATA[In the latest continuation of the effort to create better protections for consumer privacy while still enabling targeted advertising, Google has announced the Privacy Sandbox.  In this episode we describe this latest foray, including concepts like k-anonymity and differential privacy.]]></itunes:summary><itunes:duration>914</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 276: ChatGPT and Identity Reputation</title><link>https://www.spreaker.com/episode/root-causes-276-chatgpt-and-identity-reputation--52926761</link><description><![CDATA[ChatGPT and similar AI tools are dominating the public's mind these days.  In this episode we discuss the potential for people to attempt to use ChatGPT as a source of reputational analysis, KYC, and other information about individuals, companies, and other entities.  These activities are potentially subject to both error and deliberate misdirection.  In this episode we explain why.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1443348508</guid><pubDate>Thu, 09 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926761/1443348508_tim_callan_root_causes_276_chatgpt_and_identity_reputation.mp3" length="19440870" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>ChatGPT and similar AI tools are dominating the public's mind these days.  In this episode we discuss the potential for people to attempt to use ChatGPT as a source of reputational analysis, KYC, and other information about individuals, companies, and...</itunes:subtitle><itunes:summary><![CDATA[ChatGPT and similar AI tools are dominating the public's mind these days.  In this episode we discuss the potential for people to attempt to use ChatGPT as a source of reputational analysis, KYC, and other information about individuals, companies, and other entities.  These activities are potentially subject to both error and deliberate misdirection.  In this episode we explain why.]]></itunes:summary><itunes:duration>486</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 275: No Fly List Stolen</title><link>https://www.spreaker.com/episode/root-causes-275-no-fly-list-stolen--52928406</link><description><![CDATA[In a recently revealed security breach, an attacker gained a copy of the full 2019 TSA No Fly list, including subject PII. This breach was enabled by failures in digital identity and encryption. Join us in unpacking what happened and the lessons to be learned.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1441249732</guid><pubDate>Mon, 06 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928406/1441249732_tim_callan_root_causes_275_no_fly_list_stolen.mp3" length="20311608" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In a recently revealed security breach, an attacker gained a copy of the full 2019 TSA No Fly list, including subject PII. This breach was enabled by failures in digital identity and encryption. Join us in unpacking what happened and the lessons to be...</itunes:subtitle><itunes:summary><![CDATA[In a recently revealed security breach, an attacker gained a copy of the full 2019 TSA No Fly list, including subject PII. This breach was enabled by failures in digital identity and encryption. Join us in unpacking what happened and the lessons to be learned.]]></itunes:summary><itunes:duration>508</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 274: New Quantum Readiness Law</title><link>https://www.spreaker.com/episode/root-causes-274-new-quantum-readiness-law--52927560</link><description><![CDATA[The U.S. government has a new law requiring that government agencies create plans for migrating to post-quantum cryptography in response to impending threats from quantum computers. In this episode we are joined by guest Bruno Couillard of Crypto4A to discuss the law and its implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1439270110</guid><pubDate>Fri, 03 Feb 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927560/1439270110_tim_callan_root_causes_274_new_quantum_readiness_law.mp3" length="33349857" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The U.S. government has a new law requiring that government agencies create plans for migrating to post-quantum cryptography in response to impending threats from quantum computers. In this episode we are joined by guest Bruno Couillard of Crypto4A to...</itunes:subtitle><itunes:summary><![CDATA[The U.S. government has a new law requiring that government agencies create plans for migrating to post-quantum cryptography in response to impending threats from quantum computers. In this episode we are joined by guest Bruno Couillard of Crypto4A to discuss the law and its implications.]]></itunes:summary><itunes:duration>834</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 273: A Deep Dive on CA Agnostic</title><link>https://www.spreaker.com/episode/root-causes-273-a-deep-dive-on-ca-agnostic--52928400</link><description><![CDATA[The industry is seeing more and more attention spent on the idea of CA agnosticism. As with any buzzy technology term, it can be used to mean a variety of things. Join us as we catalog the various ways a Certificate Lifecycle Management (CLM) system can be "CA agnostic."]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1436112121</guid><pubDate>Mon, 30 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928400/1436112121_tim_callan_root_causes_273_a_deep_dive_on_ca_agnostic.mp3" length="51112253" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The industry is seeing more and more attention spent on the idea of CA agnosticism. As with any buzzy technology term, it can be used to mean a variety of things. Join us as we catalog the various ways a Certificate Lifecycle Management (CLM) system...</itunes:subtitle><itunes:summary><![CDATA[The industry is seeing more and more attention spent on the idea of CA agnosticism. As with any buzzy technology term, it can be used to mean a variety of things. Join us as we catalog the various ways a Certificate Lifecycle Management (CLM) system can be "CA agnostic."]]></itunes:summary><itunes:duration>1278</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 272: OCSP's Privacy Problem</title><link>https://www.spreaker.com/episode/root-causes-272-ocsp-s-privacy-problem--52926576</link><description><![CDATA[Concerns recently have been raised about OCSP real-time certificate checking and its potential to violate privacy.  In this episode we unpack these concerns and discuss the alternatives to OCSP.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1433929948</guid><pubDate>Fri, 27 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926576/1433929948_tim_callan_root_causes_272_ocsps_privacy_problem.mp3" length="17630676" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Concerns recently have been raised about OCSP real-time certificate checking and its potential to violate privacy.  In this episode we unpack these concerns and discuss the alternatives to OCSP.</itunes:subtitle><itunes:summary><![CDATA[Concerns recently have been raised about OCSP real-time certificate checking and its potential to violate privacy.  In this episode we unpack these concerns and discuss the alternatives to OCSP.]]></itunes:summary><itunes:duration>736</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 271: A Whole Fleet of Identity-based Automotive Hacks</title><link>https://www.spreaker.com/episode/root-causes-271-a-whole-fleet-of-identity-based-automotive-hacks--52925895</link><description><![CDATA[A white hat security researcher recently revealed a large number of identity-based vulnerabilities across many automotive manufacturers. In this episode we explain how a group of white hats exploited these manufacturers' dependence on non-secret "secrets" such as VIN or email address to force a raft of unacceptable behaviors across a large number of automotive brands.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1430990041</guid><pubDate>Mon, 23 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925895/1430990041_tim_callan_root_causes_271_a_whole_fleet_of_identity_based_automotive_hacks.mp3" length="32185404" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A white hat security researcher recently revealed a large number of identity-based vulnerabilities across many automotive manufacturers. In this episode we explain how a group of white hats exploited these manufacturers' dependence on non-secret...</itunes:subtitle><itunes:summary><![CDATA[A white hat security researcher recently revealed a large number of identity-based vulnerabilities across many automotive manufacturers. In this episode we explain how a group of white hats exploited these manufacturers' dependence on non-secret "secrets" such as VIN or email address to force a raft of unacceptable behaviors across a large number of automotive brands.]]></itunes:summary><itunes:duration>1341</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 270: What Is the Difference Between KEM and PKE?</title><link>https://www.spreaker.com/episode/root-causes-270-what-is-the-difference-between-kem-and-pke--52925902</link><description><![CDATA[One of the little known changes that has come to the world of TLS is that the secret handshake and key exchange updated from Public Key Exchange (PKE) to Key Encapsulation Methods (KEM).  In this episode we explain the difference between the two methods and why this change is taking place.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1428793909</guid><pubDate>Fri, 20 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925902/1428793909_tim_callan_root_causes_270_what_is_the_difference_between_kem_and_pke.mp3" length="17129878" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>One of the little known changes that has come to the world of TLS is that the secret handshake and key exchange updated from Public Key Exchange (PKE) to Key Encapsulation Methods (KEM).  In this episode we explain the difference between the two...</itunes:subtitle><itunes:summary><![CDATA[One of the little known changes that has come to the world of TLS is that the secret handshake and key exchange updated from Public Key Exchange (PKE) to Key Encapsulation Methods (KEM).  In this episode we explain the difference between the two methods and why this change is taking place.]]></itunes:summary><itunes:duration>715</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 269: Did a Patent Dispute Nearly Derail Post Quantum Cryptography?</title><link>https://www.spreaker.com/episode/root-causes-269-did-a-patent-dispute-nearly-derail-post-quantum-cryptography--52926536</link><description><![CDATA[On July 5, 2022 NIST announced its Round 3 PQC winners. What most people don't realize is that same day, the interested parties cleared a patent dispute that had the potential to prevent several of the winning primitives from moving forward. Join us as we explain who held that patent, what the potential impediment was, and how everything was resolved.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1425686413</guid><pubDate>Mon, 16 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926536/1425686413_tim_callan_root_causes_269_did_a_patent_dispute_nearly_derail_post_quantum_cryptography.mp3" length="14202464" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On July 5, 2022 NIST announced its Round 3 PQC winners. What most people don't realize is that same day, the interested parties cleared a patent dispute that had the potential to prevent several of the winning primitives from moving forward. Join us...</itunes:subtitle><itunes:summary><![CDATA[On July 5, 2022 NIST announced its Round 3 PQC winners. What most people don't realize is that same day, the interested parties cleared a patent dispute that had the potential to prevent several of the winning primitives from moving forward. Join us as we explain who held that patent, what the potential impediment was, and how everything was resolved.]]></itunes:summary><itunes:duration>592</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 268: WAFs Subverted by JSON Bypass</title><link>https://www.spreaker.com/episode/root-causes-268-wafs-subverted-by-json-bypass--52926689</link><description><![CDATA[In this episode we discuss rising attacks that overcome the protections of Web Application Firewalls (WAF).  We explain these attacks, why this bypass might effective against you even if think it doesn't, and what you should do to ensure you're safe.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1422711448</guid><pubDate>Thu, 12 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926689/1422711448_tim_callan_root_causes_268_wafs_subverted_by_json_bypass.mp3" length="2141317" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we discuss rising attacks that overcome the protections of Web Application Firewalls (WAF).  We explain these attacks, why this bypass might effective against you even if think it doesn't, and what you should do to ensure you're safe.</itunes:subtitle><itunes:summary><![CDATA[In this episode we discuss rising attacks that overcome the protections of Web Application Firewalls (WAF).  We explain these attacks, why this bypass might effective against you even if think it doesn't, and what you should do to ensure you're safe.]]></itunes:summary><itunes:duration>533</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 267: Can Quantum Computers Break RSA Today?</title><link>https://www.spreaker.com/episode/root-causes-267-can-quantum-computers-break-rsa-today--52927150</link><description><![CDATA[Much has been made of Schor's algorithm and the inevitable defeat of RSA using quantum computers. But a new research paper suggests a quantum computer may be applied to the problem in a fundamentally different way, hastening RSA's demise beyond even our current expected timelines. In this episode we discuss this new research, reactions to it, and its potential implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1420009558</guid><pubDate>Mon, 09 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927150/1420009558_tim_callan_root_causes_267_can_quantum_computers_break_rsa_today.mp3" length="32905184" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Much has been made of Schor's algorithm and the inevitable defeat of RSA using quantum computers. But a new research paper suggests a quantum computer may be applied to the problem in a fundamentally different way, hastening RSA's demise beyond even...</itunes:subtitle><itunes:summary><![CDATA[Much has been made of Schor's algorithm and the inevitable defeat of RSA using quantum computers. But a new research paper suggests a quantum computer may be applied to the problem in a fundamentally different way, hastening RSA's demise beyond even our current expected timelines. In this episode we discuss this new research, reactions to it, and its potential implications.]]></itunes:summary><itunes:duration>1372</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 266: End-to-end Encryption in the Apple Technology Stack</title><link>https://www.spreaker.com/episode/root-causes-266-end-to-end-encryption-in-the-apple-technology-stack--52925903</link><description><![CDATA[Recent announcements from Apple lay out a set of expansions in the scope and capability of encryption throughout the Apple ecosystem. In this episode we detail the announced changes and some of their implications.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1416429175</guid><pubDate>Wed, 04 Jan 2023 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925903/1416429175_tim_callan_root_causes_266_end_to_end_encryption_in_the_apple_technology_stack.mp3" length="4314630" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent announcements from Apple lay out a set of expansions in the scope and capability of encryption throughout the Apple ecosystem. In this episode we detail the announced changes and some of their implications.</itunes:subtitle><itunes:summary><![CDATA[Recent announcements from Apple lay out a set of expansions in the scope and capability of encryption throughout the Apple ecosystem. In this episode we detail the announced changes and some of their implications.]]></itunes:summary><itunes:duration>1077</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 265: A Banner Year for Post-quantum Cryptography</title><link>https://www.spreaker.com/episode/root-causes-265-a-banner-year-for-post-quantum-cryptography--52925849</link><description><![CDATA[2022 was post-quantum cryptography's biggest year so far.  Our hosts are joined by guest Bruno Couillard, CEO and CTO of Crypto4A.  We go over many developments in PQC, including the announcement of the NIST round 3 winners, the defeat of several late candidate algorithms, isogeny-based cryptography, hybrid certificates, and the significance of April 14, 2030.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1411919035</guid><pubDate>Wed, 28 Dec 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925849/1411919035_tim_callan_root_causes_265_a_banner_year_for_post_quantum_cryptography.mp3" length="7978904" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2022 was post-quantum cryptography's biggest year so far.  Our hosts are joined by guest Bruno Couillard, CEO and CTO of Crypto4A.  We go over many developments in PQC, including the announcement of the NIST round 3 winners, the defeat of several late...</itunes:subtitle><itunes:summary><![CDATA[2022 was post-quantum cryptography's biggest year so far.  Our hosts are joined by guest Bruno Couillard, CEO and CTO of Crypto4A.  We go over many developments in PQC, including the announcement of the NIST round 3 winners, the defeat of several late candidate algorithms, isogeny-based cryptography, hybrid certificates, and the significance of April 14, 2030.]]></itunes:summary><itunes:duration>1993</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 264: Crypto Agility for 2023</title><link>https://www.spreaker.com/episode/root-causes-264-crypto-agility-for-2023--52927161</link><description><![CDATA[We define the important needs and initiatives that are changing the crypto agility landscape.  We discuss topics including CA independence, cryptography in public clouds, post-quantum cryptography (PQC) agility, hybrid certificates, and FIDO 2/WebAuthn.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1409087032</guid><pubDate>Fri, 23 Dec 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927161/1409087032_tim_callan_root_causes_264_crypto_agility_for_2023.mp3" length="4582227" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We define the important needs and initiatives that are changing the crypto agility landscape.  We discuss topics including CA independence, cryptography in public clouds, post-quantum cryptography (PQC) agility, hybrid certificates, and FIDO 2/WebAuthn.</itunes:subtitle><itunes:summary><![CDATA[We define the important needs and initiatives that are changing the crypto agility landscape.  We discuss topics including CA independence, cryptography in public clouds, post-quantum cryptography (PQC) agility, hybrid certificates, and FIDO 2/WebAuthn.]]></itunes:summary><itunes:duration>1143</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 263: Secure Connection Methods Roundup</title><link>https://www.spreaker.com/episode/root-causes-263-secure-connection-methods-roundup--52927553</link><description><![CDATA[In this episode we discuss the three methods a user might choose for secure remote communications: VPN, SSH, and TOR.  For each we discuss the reasons you might choose them and the pros and cons of each.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1406776609</guid><pubDate>Tue, 20 Dec 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927553/1406776609_tim_callan_root_causes_263_secure_connection_methods_roundup.mp3" length="6140195" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we discuss the three methods a user might choose for secure remote communications: VPN, SSH, and TOR.  For each we discuss the reasons you might choose them and the pros and cons of each.</itunes:subtitle><itunes:summary><![CDATA[In this episode we discuss the three methods a user might choose for secure remote communications: VPN, SSH, and TOR.  For each we discuss the reasons you might choose them and the pros and cons of each.]]></itunes:summary><itunes:duration>1533</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 262: The Continuing Erosion of Online Identity</title><link>https://www.spreaker.com/episode/root-causes-262-the-continuing-erosion-of-online-identity--52925878</link><description><![CDATA[In one of our 2022 wrap up episodes, we look back at the continued erosion of the idea of reliable online identity throughout the year. We discuss the rise of deep fakes, celebrity phishing, voice biometrics, AI-generated art, trust models, and the failure of Twitter blue check marks.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1402889653</guid><pubDate>Wed, 14 Dec 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925878/1402889653_tim_callan_root_causes_262_the_continuing_erosion_of_online_identity.mp3" length="5519569" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In one of our 2022 wrap up episodes, we look back at the continued erosion of the idea of reliable online identity throughout the year. We discuss the rise of deep fakes, celebrity phishing, voice biometrics, AI-generated art, trust models, and the...</itunes:subtitle><itunes:summary><![CDATA[In one of our 2022 wrap up episodes, we look back at the continued erosion of the idea of reliable online identity throughout the year. We discuss the rise of deep fakes, celebrity phishing, voice biometrics, AI-generated art, trust models, and the failure of Twitter blue check marks.]]></itunes:summary><itunes:duration>1378</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 261: Why I Don't Say Spoof</title><link>https://www.spreaker.com/episode/root-causes-261-why-i-don-t-say-spoof--52927182</link><description><![CDATA[The word spoof is a security industry term used in the context of social engineering attacks.  In this episode we explore the word's connotations in different walks of life and why its connotations may not serve us well when applied to security concerns.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1401876283</guid><pubDate>Mon, 12 Dec 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927182/1401876283_tim_callan_root_causes_261_why_i_dont_say_spoof.mp3" length="2439245" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The word spoof is a security industry term used in the context of social engineering attacks.  In this episode we explore the word's connotations in different walks of life and why its connotations may not serve us well when applied to security concerns.</itunes:subtitle><itunes:summary><![CDATA[The word spoof is a security industry term used in the context of social engineering attacks.  In this episode we explore the word's connotations in different walks of life and why its connotations may not serve us well when applied to security concerns.]]></itunes:summary><itunes:duration>608</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/df65c56f4766cb628b3a21e005094beb.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 260: CA TrustCor Deprecated</title><link>https://www.spreaker.com/episode/root-causes-260-ca-trustcor-deprecated--52927149</link><description><![CDATA[Public CA TrustCor has had its roots deprecated by Microsoft and Mozilla, following a public dialog about TrustCor's suitability as a public CA. This entire investigation was prompted by a Washington Post article articulating a series of connections between this CA and spyware purveyors.  In this episode we explain these connections, the public dialog and investigation that occurred, and the ultimate deprecation of TrustCor.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1398950962</guid><pubDate>Thu, 08 Dec 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927149/1398950962_tim_callan_root_causes_260_ca_trustcor_deprecated.mp3" length="7255756" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Public CA TrustCor has had its roots deprecated by Microsoft and Mozilla, following a public dialog about TrustCor's suitability as a public CA. This entire investigation was prompted by a Washington Post article articulating a series of connections...</itunes:subtitle><itunes:summary><![CDATA[Public CA TrustCor has had its roots deprecated by Microsoft and Mozilla, following a public dialog about TrustCor's suitability as a public CA. This entire investigation was prompted by a Washington Post article articulating a series of connections between this CA and spyware purveyors.  In this episode we explain these connections, the public dialog and investigation that occurred, and the ultimate deprecation of TrustCor.]]></itunes:summary><itunes:duration>1812</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 259: What Went Wrong with the Twitter Blue Check Marks</title><link>https://www.spreaker.com/episode/root-causes-259-what-went-wrong-with-the-twitter-blue-check-marks--52925809</link><description><![CDATA[The Twitter authenticated identity blue check marks made a big splash and then quickly went away.  In this episode we explore the intent of these check marks and why they failed.  In particular, we detail the challenges involved in authenticating and vouching for the identity of an individual or organization.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1393626763</guid><pubDate>Wed, 30 Nov 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925809/1393626763_tim_callan_root_causes_259_what_went_wrong_with_the_twitter_blue_check_marks.mp3" length="3435586" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Twitter authenticated identity blue check marks made a big splash and then quickly went away.  In this episode we explore the intent of these check marks and why they failed.  In particular, we detail the challenges involved in authenticating and...</itunes:subtitle><itunes:summary><![CDATA[The Twitter authenticated identity blue check marks made a big splash and then quickly went away.  In this episode we explore the intent of these check marks and why they failed.  In particular, we detail the challenges involved in authenticating and vouching for the identity of an individual or organization.]]></itunes:summary><itunes:duration>857</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 258: New S/MIME Baseline Requirements Ratified</title><link>https://www.spreaker.com/episode/root-causes-258-new-s-mime-baseline-requirements-ratified--52925916</link><description><![CDATA[The CA/Browser Forum has passed new Baseline Requirements for S/MIME certificates, in effect late 2023.  In this episode we explain the broad stipulations of the new S/MIME BRs, including the multiple available levels of authentication and use case profiles that will be allowed.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1388255815</guid><pubDate>Mon, 21 Nov 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925916/1388255815_tim_callan_root_causes_258_new_smime_baseline_requirements_ratified.mp3" length="4105601" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CA/Browser Forum has passed new Baseline Requirements for S/MIME certificates, in effect late 2023.  In this episode we explain the broad stipulations of the new S/MIME BRs, including the multiple available levels of authentication and use case...</itunes:subtitle><itunes:summary><![CDATA[The CA/Browser Forum has passed new Baseline Requirements for S/MIME certificates, in effect late 2023.  In this episode we explain the broad stipulations of the new S/MIME BRs, including the multiple available levels of authentication and use case profiles that will be allowed.]]></itunes:summary><itunes:duration>1025</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 257: FTX Crypto Exchange Collapses</title><link>https://www.spreaker.com/episode/root-causes-257-ftx-crypto-exchange-collapses--52928412</link><description><![CDATA["If you don't hold the keys, you don't hold the cheese." Crypto exchange giant FTX recently collapsed, causing ripples through the cryptocurrency world. In this episode we focus on the cryptographic difference between cryptocurrency exchanges and other exchanges and how specific FTX user experience decisions led to the loss of valuable digital assets for investors.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1385958775</guid><pubDate>Thu, 17 Nov 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928412/1385958775_tim_callan_root_causes_257_ftx_crypto_exchange_collapses.mp3" length="2748597" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>"If you don't hold the keys, you don't hold the cheese." Crypto exchange giant FTX recently collapsed, causing ripples through the cryptocurrency world. In this episode we focus on the cryptographic difference between cryptocurrency exchanges and...</itunes:subtitle><itunes:summary><![CDATA["If you don't hold the keys, you don't hold the cheese." Crypto exchange giant FTX recently collapsed, causing ripples through the cryptocurrency world. In this episode we focus on the cryptographic difference between cryptocurrency exchanges and other exchanges and how specific FTX user experience decisions led to the loss of valuable digital assets for investors.]]></itunes:summary><itunes:duration>685</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 256: What Is Harvest and Decrypt?</title><link>https://www.spreaker.com/episode/root-causes-256-what-is-harvest-and-decrypt--52927198</link><description><![CDATA[As we prepare for the reality of quantum computers breaking RSA and ECC, a keenly important concept to understand is "Harvest and Decrypt."  The practical impact of Harvest and Decrypt is that for secrets with a reasonable lifespan, the quantum computer threat is much closer than you might think, including as early as today. In this episode we explain why that's the case and how this attack is likely to roll out.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1384433785</guid><pubDate>Wed, 16 Nov 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927198/1384433785_tim_callan_root_causes_256_what_is_harvest_and_decrypt.mp3" length="4699331" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As we prepare for the reality of quantum computers breaking RSA and ECC, a keenly important concept to understand is "Harvest and Decrypt."  The practical impact of Harvest and Decrypt is that for secrets with a reasonable lifespan, the quantum...</itunes:subtitle><itunes:summary><![CDATA[As we prepare for the reality of quantum computers breaking RSA and ECC, a keenly important concept to understand is "Harvest and Decrypt."  The practical impact of Harvest and Decrypt is that for secrets with a reasonable lifespan, the quantum computer threat is much closer than you might think, including as early as today. In this episode we explain why that's the case and how this attack is likely to roll out.]]></itunes:summary><itunes:duration>1173</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 255: What Is a Privacy Browser?</title><link>https://www.spreaker.com/episode/root-causes-255-what-is-a-privacy-browser--52927566</link><description><![CDATA[In this episode we describe privacy browsers, which quite simply are browsers designed to pay special attention to the user's privacy, including some of the strategies they use to protect privacy and the pros and cons of this approach.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1380955333</guid><pubDate>Fri, 11 Nov 2022 15:02:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927566/1380955333_tim_callan_root_causes_255_what_is_a_privacy_browser.mp3" length="5479003" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe privacy browsers, which quite simply are browsers designed to pay special attention to the user's privacy, including some of the strategies they use to protect privacy and the pros and cons of this approach.</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe privacy browsers, which quite simply are browsers designed to pay special attention to the user's privacy, including some of the strategies they use to protect privacy and the pros and cons of this approach.]]></itunes:summary><itunes:duration>1368</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 254: Toyota Symmetric Key Exposed on GitHub</title><link>https://www.spreaker.com/episode/root-causes-254-toyota-symmetric-key-exposed-on-github--52926630</link><description><![CDATA[In a recently exposed error, key material for a popular automobile manufacturer's PKI has been discovered on GitHub, resulting in exposure of sensitive information.  In this episode we explain the dual errors that led to this breach.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1378819801</guid><pubDate>Tue, 08 Nov 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926630/1378819801_tim_callan_root_causes_254_toyota_symmetric_key_exposed_on_github.mp3" length="2623810" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In a recently exposed error, key material for a popular automobile manufacturer's PKI has been discovered on GitHub, resulting in exposure of sensitive information.  In this episode we explain the dual errors that led to this breach.</itunes:subtitle><itunes:summary><![CDATA[In a recently exposed error, key material for a popular automobile manufacturer's PKI has been discovered on GitHub, resulting in exposure of sensitive information.  In this episode we explain the dual errors that led to this breach.]]></itunes:summary><itunes:duration>654</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 253: OpenSSL Vulnerability Explained</title><link>https://www.spreaker.com/episode/root-causes-253-openssl-vulnerability-explained--52927534</link><description><![CDATA[Last week the OpenSSL project announced an upcoming critical patch, leading to a great deal of speculation about this flaw and its implications for SSL certificates.  We explain what the flaw was, what you should do, and why it is that certificates are unaffected.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1376617399</guid><pubDate>Fri, 04 Nov 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927534/1376617399_tim_callan_root_causes_253_openssl_vulnerability_explained.mp3" length="2239378" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Last week the OpenSSL project announced an upcoming critical patch, leading to a great deal of speculation about this flaw and its implications for SSL certificates.  We explain what the flaw was, what you should do, and why it is that certificates...</itunes:subtitle><itunes:summary><![CDATA[Last week the OpenSSL project announced an upcoming critical patch, leading to a great deal of speculation about this flaw and its implications for SSL certificates.  We explain what the flaw was, what you should do, and why it is that certificates are unaffected.]]></itunes:summary><itunes:duration>558</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 252: Sidestepping Microsoft Email Encryption</title><link>https://www.spreaker.com/episode/root-causes-252-sidestepping-microsoft-email-encryption--52925921</link><description><![CDATA[A recently revealed vulnerability in Microsoft Exchange encryption can be used potentially to break the encryption on stored emails. In this episode we explain ECB (Electronic Code Book encryption and how this attack can occur.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1374493801</guid><pubDate>Sun, 30 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925921/1374493801_tim_callan_root_causes_252_sidestepping_microsoft_email_encryption.mp3" length="3415353" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recently revealed vulnerability in Microsoft Exchange encryption can be used potentially to break the encryption on stored emails. In this episode we explain ECB (Electronic Code Book encryption and how this attack can occur.</itunes:subtitle><itunes:summary><![CDATA[A recently revealed vulnerability in Microsoft Exchange encryption can be used potentially to break the encryption on stored emails. In this episode we explain ECB (Electronic Code Book encryption and how this attack can occur.]]></itunes:summary><itunes:duration>852</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 251: What's Next for the NIST PQC Primitives?</title><link>https://www.spreaker.com/episode/root-causes-251-what-s-next-for-the-nist-pqc-primitives--52926713</link><description><![CDATA[NIST has announced its new post-quantum cryptography primitives. So now what? In this episode we discuss the next steps required by the technology industry for widespread adoption of these algorithms and what the enterprise can do starting today to ready itself for quantum-safe encryption.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1372032334</guid><pubDate>Thu, 27 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926713/1372032334_tim_callan_root_causes_251_whats_next_with_the_nist_pqc_primitives.mp3" length="4991541" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST has announced its new post-quantum cryptography primitives. So now what? In this episode we discuss the next steps required by the technology industry for widespread adoption of these algorithms and what the enterprise can do starting today to...</itunes:subtitle><itunes:summary><![CDATA[NIST has announced its new post-quantum cryptography primitives. So now what? In this episode we discuss the next steps required by the technology industry for widespread adoption of these algorithms and what the enterprise can do starting today to ready itself for quantum-safe encryption.]]></itunes:summary><itunes:duration>1246</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 250: 250 Episodes of Root Causes!</title><link>https://www.spreaker.com/episode/root-causes-250-250-episodes-of-root-causes--52928408</link><description><![CDATA[It's Root Causes episode 250! In this episode Tim and Jason indulge themselves in podcasting about podcasting.  Hear about setting up a podcast, choosing topics, why we don't rehearse, why we have so few guests, and how we reacted the first time someone asked us for a media kit.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1370410666</guid><pubDate>Wed, 26 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928408/1370410666_tim_callan_root_causes_250_250_episodes_of_root_causes.mp3" length="6383407" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It's Root Causes episode 250! In this episode Tim and Jason indulge themselves in podcasting about podcasting.  Hear about setting up a podcast, choosing topics, why we don't rehearse, why we have so few guests, and how we reacted the first time...</itunes:subtitle><itunes:summary><![CDATA[It's Root Causes episode 250! In this episode Tim and Jason indulge themselves in podcasting about podcasting.  Hear about setting up a podcast, choosing topics, why we don't rehearse, why we have so few guests, and how we reacted the first time someone asked us for a media kit.]]></itunes:summary><itunes:duration>1594</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 249:  What Is MFA Exhaustion?</title><link>https://www.spreaker.com/episode/root-causes-249-what-is-mfa-exhaustion--52928424</link><description><![CDATA[Recent months have seen several high profile attacks that were enabled by defeating the MFA accompanying user name and password login.  In this episode we explain the concept of MFA fatigue and why it is an enabler for these attacks.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1367719174</guid><pubDate>Fri, 21 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928424/1367719174_tim_callan_root_causes_249_what_is_mfa_exhaustion.mp3" length="2503384" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent months have seen several high profile attacks that were enabled by defeating the MFA accompanying user name and password login.  In this episode we explain the concept of MFA fatigue and why it is an enabler for these attacks.</itunes:subtitle><itunes:summary><![CDATA[Recent months have seen several high profile attacks that were enabled by defeating the MFA accompanying user name and password login.  In this episode we explain the concept of MFA fatigue and why it is an enabler for these attacks.]]></itunes:summary><itunes:duration>624</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 248: Azure Code Signing Announced</title><link>https://www.spreaker.com/episode/root-causes-248-azure-code-signing-announced--52926631</link><description><![CDATA[Microsoft has announced the upcoming availability of a Microsoft-run code signing solution inside the Azure platform. We explain this approach's advantages and what to expect from it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1365415801</guid><pubDate>Tue, 18 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926631/1365415801_tim_callan_root_causes_248_azure_code_signing_announced.mp3" length="2274142" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Microsoft has announced the upcoming availability of a Microsoft-run code signing solution inside the Azure platform. We explain this approach's advantages and what to expect from it.</itunes:subtitle><itunes:summary><![CDATA[Microsoft has announced the upcoming availability of a Microsoft-run code signing solution inside the Azure platform. We explain this approach's advantages and what to expect from it.]]></itunes:summary><itunes:duration>567</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 247: Uber Breach Unpacked</title><link>https://www.spreaker.com/episode/root-causes-247-uber-breach-unpacked--52925732</link><description><![CDATA[A recent high-profile breach of Uber's systems led to widespread data loss.  Join our experts as we unpack the specifics of how this attack came about.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1362421999</guid><pubDate>Thu, 13 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925732/1362421999_tim_callan_root_causes_247_uber_breach_unpacked.mp3" length="2896732" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent high-profile breach of Uber's systems led to widespread data loss.  Join our experts as we unpack the specifics of how this attack came about.</itunes:subtitle><itunes:summary><![CDATA[A recent high-profile breach of Uber's systems led to widespread data loss.  Join our experts as we unpack the specifics of how this attack came about.]]></itunes:summary><itunes:duration>722</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 246: Google Chrome Root Program Announced</title><link>https://www.spreaker.com/episode/root-causes-246-google-chrome-root-program-announced--52926625</link><description><![CDATA[Google Chrome recently announced the formation of its trusted root program. It may be surprising to learn that the world's most popular browser has existed for more than a decade without its own root program. In this episode we explain why that is the case, why Chrome is launching a root program now, and the implications of this announcement.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1356774772</guid><pubDate>Mon, 03 Oct 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926625/1356774772_tim_callan_root_causes_246_google_chrome_root_program_announced.mp3" length="2889961" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Google Chrome recently announced the formation of its trusted root program. It may be surprising to learn that the world's most popular browser has existed for more than a decade without its own root program. In this episode we explain why that is the...</itunes:subtitle><itunes:summary><![CDATA[Google Chrome recently announced the formation of its trusted root program. It may be surprising to learn that the world's most popular browser has existed for more than a decade without its own root program. In this episode we explain why that is the case, why Chrome is launching a root program now, and the implications of this announcement.]]></itunes:summary><itunes:duration>721</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 245: One Time Passcode as a Liability</title><link>https://www.spreaker.com/episode/root-causes-245-one-time-passcode-as-a-liability--52925957</link><description><![CDATA[A recent article from Brian Krebs advances the idea that using OTP MFA may actually be a liability to security.  In this episode we explain the reasoning behind this characterization.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1353681415</guid><pubDate>Thu, 29 Sep 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925957/1353681415_tim_callan_root_causes_245_one_time_passcode_as_a_liability.mp3" length="2450198" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent article from Brian Krebs advances the idea that using OTP MFA may actually be a liability to security.  In this episode we explain the reasoning behind this characterization.</itunes:subtitle><itunes:summary><![CDATA[A recent article from Brian Krebs advances the idea that using OTP MFA may actually be a liability to security.  In this episode we explain the reasoning behind this characterization.]]></itunes:summary><itunes:duration>611</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 244: PwC Survey Reports Cyber Security as Biggest Risk to Companies</title><link>https://www.spreaker.com/episode/root-causes-244-pwc-survey-reports-cyber-security-as-biggest-risk-to-companies--52928414</link><description><![CDATA[A recent survey from PwC reports that cyber threats are no longer solely the domain on the CISO but instead have become every senior executive's concern.  We dive deep into these survey results and talk about they correlate with our own experiences, IT skills gaps, and feeding the podcasting beast.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1351414354</guid><pubDate>Mon, 26 Sep 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928414/1351414354_tim_callan_root_causes_244_pwc_survey_reports_cyber_security_as_biggest_risk_to_companies.mp3" length="3766632" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent survey from PwC reports that cyber threats are no longer solely the domain on the CISO but instead have become every senior executive's concern.  We dive deep into these survey results and talk about they correlate with our own experiences,...</itunes:subtitle><itunes:summary><![CDATA[A recent survey from PwC reports that cyber threats are no longer solely the domain on the CISO but instead have become every senior executive's concern.  We dive deep into these survey results and talk about they correlate with our own experiences, IT skills gaps, and feeding the podcasting beast.]]></itunes:summary><itunes:duration>940</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 243: Which Came First, the BRs or the EVGs?</title><link>https://www.spreaker.com/episode/root-causes-243-which-came-first-the-brs-or-the-evgs--52926725</link><description><![CDATA[Many people don't realize that the CA/Browser Forum's Baseline Requirements actually came LATER THAN the Extended Validation Guidelines. In this episode we explain how this seemly backward turn of events came about and what it says about how online trust has evolved over the past few decades.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1347656671</guid><pubDate>Tue, 20 Sep 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926725/1347656671_tim_callan_root_causes_243_which_came_first_the_brs_or_the_evgs.mp3" length="2539542" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Many people don't realize that the CA/Browser Forum's Baseline Requirements actually came LATER THAN the Extended Validation Guidelines. In this episode we explain how this seemly backward turn of events came about and what it says about how online...</itunes:subtitle><itunes:summary><![CDATA[Many people don't realize that the CA/Browser Forum's Baseline Requirements actually came LATER THAN the Extended Validation Guidelines. In this episode we explain how this seemly backward turn of events came about and what it says about how online trust has evolved over the past few decades.]]></itunes:summary><itunes:duration>633</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 242: Let's Encrypt Founder Peter Eckersley Passes</title><link>https://www.spreaker.com/episode/root-causes-242-let-s-encrypt-founder-peter-eckersley-passes--52927220</link><description><![CDATA[Electronic Frontier Foundation member and Let's Encrypt co-founder Peter Eckersley passed away recently at a young age. In this episode we pay respect to Peter's memory and his many contributions, including ACME, Certbot, and Let's Encrypt.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1345249654</guid><pubDate>Fri, 16 Sep 2022 18:47:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927220/1345249654_tim_callan_root_causes_242_lets_encrypt_founder_peter_eckersley_passes.mp3" length="1708077" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Electronic Frontier Foundation member and Let's Encrypt co-founder Peter Eckersley passed away recently at a young age. In this episode we pay respect to Peter's memory and his many contributions, including ACME, Certbot, and Let's Encrypt.</itunes:subtitle><itunes:summary><![CDATA[Electronic Frontier Foundation member and Let's Encrypt co-founder Peter Eckersley passed away recently at a young age. In this episode we pay respect to Peter's memory and his many contributions, including ACME, Certbot, and Let's Encrypt.]]></itunes:summary><itunes:duration>425</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 241: Is China Outspending the West in Quantum Computing?</title><link>https://www.spreaker.com/episode/root-causes-241-is-china-outspending-the-west-in-quantum-computing--52927229</link><description><![CDATA[A December 2021 report appears to indicate that China as vastly outspending Western countries in quantum computing. In this episode we examine this claim, including the role of private industry as opposed to government funding, the importance of international cooperation, and the vast implications of winning the race for quantum computing.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1342572652</guid><pubDate>Mon, 12 Sep 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927229/1342572652_tim_callan_root_causes_241_is_china_outspending_the_west_in_quantum_computing.mp3" length="4888052" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A December 2021 report appears to indicate that China as vastly outspending Western countries in quantum computing. In this episode we examine this claim, including the role of private industry as opposed to government funding, the importance of...</itunes:subtitle><itunes:summary><![CDATA[A December 2021 report appears to indicate that China as vastly outspending Western countries in quantum computing. In this episode we examine this claim, including the role of private industry as opposed to government funding, the importance of international cooperation, and the vast implications of winning the race for quantum computing.]]></itunes:summary><itunes:duration>1220</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 240: Hyundai Production Private Key Found in How-to Manual</title><link>https://www.spreaker.com/episode/root-causes-240-hyundai-production-private-key-found-in-how-to-manual--52927472</link><description><![CDATA[A white hat researcher recently defeated a production automobile's PKI by searching for the private key on Google. Join us as we describe the implementation error making this possible and how it might have come about.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1339575196</guid><pubDate>Tue, 06 Sep 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927472/1339575196_tim_callan_root_causes_240_hyundai_production_private_key_found_in_how_to_manual.mp3" length="3767205" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A white hat researcher recently defeated a production automobile's PKI by searching for the private key on Google. Join us as we describe the implementation error making this possible and how it might have come about.</itunes:subtitle><itunes:summary><![CDATA[A white hat researcher recently defeated a production automobile's PKI by searching for the private key on Google. Join us as we describe the implementation error making this possible and how it might have come about.]]></itunes:summary><itunes:duration>940</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 239: Post-quantum Cryptography Candidate SIKE Defeated</title><link>https://www.spreaker.com/episode/root-causes-239-post-quantum-cryptography-candidate-sike-defeated--52927239</link><description><![CDATA[NIST's round four post-quantum crypto candidate SIKE (Supersingular Isogeny Key Encapsulation) has been defeated and is now out of consideration.  In this episode we explain isogeny cryptography, why NIST is seeking additional candidates, and why failures of this kind are expected and healthy for PQC.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1333538782</guid><pubDate>Sun, 28 Aug 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927239/1333538782_tim_callan_root_causes_239_post_quantum_cryptography_candidate_sike_defeated.mp3" length="4210726" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST's round four post-quantum crypto candidate SIKE (Supersingular Isogeny Key Encapsulation) has been defeated and is now out of consideration.  In this episode we explain isogeny cryptography, why NIST is seeking additional candidates, and why...</itunes:subtitle><itunes:summary><![CDATA[NIST's round four post-quantum crypto candidate SIKE (Supersingular Isogeny Key Encapsulation) has been defeated and is now out of consideration.  In this episode we explain isogeny cryptography, why NIST is seeking additional candidates, and why failures of this kind are expected and healthy for PQC.]]></itunes:summary><itunes:duration>1051</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 238: Tim's Big Phishing Adventure</title><link>https://www.spreaker.com/episode/root-causes-238-tim-s-big-phishing-adventure--52927141</link><description><![CDATA[In a personally unprecedented occurrence, Tim's identity as a Sectigo executive is being used in a "waterholing" phishing scam intended to raid job seekers' bank accounts. We describe what is going on, how we found out, and the challenges in combatting such an attack.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1324503661</guid><pubDate>Mon, 15 Aug 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927141/1324503661_tim_callan_root_causes_238_tims_big_phishing_adventure.mp3" length="4051389" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In a personally unprecedented occurrence, Tim's identity as a Sectigo executive is being used in a "waterholing" phishing scam intended to raid job seekers' bank accounts. We describe what is going on, how we found out, and the challenges in...</itunes:subtitle><itunes:summary><![CDATA[In a personally unprecedented occurrence, Tim's identity as a Sectigo executive is being used in a "waterholing" phishing scam intended to raid job seekers' bank accounts. We describe what is going on, how we found out, and the challenges in combatting such an attack.]]></itunes:summary><itunes:duration>1011</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 237: Why Mozilla Is So Important to CAs</title><link>https://www.spreaker.com/episode/root-causes-237-why-mozilla-is-so-important-to-cas--52926742</link><description><![CDATA[Mozilla is a highly important to the world of public certificates, with influence beyond what the Firefox browser market share would suggest.  In this episode we examine the historical reasons for this influence and the mechanisms that maintain that influence today.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1321683601</guid><pubDate>Wed, 10 Aug 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926742/1321683601_tim_callan_root_causes_237_why_mozilla_is_so_important_to_cas.mp3" length="2872383" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Mozilla is a highly important to the world of public certificates, with influence beyond what the Firefox browser market share would suggest.  In this episode we examine the historical reasons for this influence and the mechanisms that maintain that...</itunes:subtitle><itunes:summary><![CDATA[Mozilla is a highly important to the world of public certificates, with influence beyond what the Firefox browser market share would suggest.  In this episode we examine the historical reasons for this influence and the mechanisms that maintain that influence today.]]></itunes:summary><itunes:duration>716</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 236: Active Directory Patch Knocks Out Non-MS Identity Consumers</title><link>https://www.spreaker.com/episode/root-causes-236-active-directory-patch-knocks-out-non-ms-identity-consumers--52925965</link><description><![CDATA[A recently revealed vulnerability in Active Directory made it possible for an attacker to escalate privileges inappropriately.  Microsoft's responded with a patch in May 2022, which unfortunately has forced a difficult workaround for many common software components beyond Active Directory that will otherwise be incapable of working with AD identities. In this episode we explain what his happening, how it came about, and the broader lessons for PKI owners.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1318024705</guid><pubDate>Thu, 04 Aug 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925965/1318024705_tim_callan_root_causes_236_active_directory_patch_knocks_out_non_ms_identity_consumers.mp3" length="3040778" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recently revealed vulnerability in Active Directory made it possible for an attacker to escalate privileges inappropriately.  Microsoft's responded with a patch in May 2022, which unfortunately has forced a difficult workaround for many common...</itunes:subtitle><itunes:summary><![CDATA[A recently revealed vulnerability in Active Directory made it possible for an attacker to escalate privileges inappropriately.  Microsoft's responded with a patch in May 2022, which unfortunately has forced a difficult workaround for many common software components beyond Active Directory that will otherwise be incapable of working with AD identities. In this episode we explain what his happening, how it came about, and the broader lessons for PKI owners.]]></itunes:summary><itunes:duration>758</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 235: What Is Lattice-based Cryptography?</title><link>https://www.spreaker.com/episode/root-causes-235-what-is-lattice-based-cryptography--52926702</link><description><![CDATA[The recent winners of the NIST post-quantum cryptography contest are strongly focused on lattice-based encryption.  In this episode we explain at a high level what this cryptographic approach entails and why lattice-based algorithms fared so well in the NIST search.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1312923346</guid><pubDate>Tue, 26 Jul 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926702/1312923346_tim_callan_root_causes_235_what_is_lattice_based_cryptography.mp3" length="6344157" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The recent winners of the NIST post-quantum cryptography contest are strongly focused on lattice-based encryption.  In this episode we explain at a high level what this cryptographic approach entails and why lattice-based algorithms fared so well in...</itunes:subtitle><itunes:summary><![CDATA[The recent winners of the NIST post-quantum cryptography contest are strongly focused on lattice-based encryption.  In this episode we explain at a high level what this cryptographic approach entails and why lattice-based algorithms fared so well in the NIST search.]]></itunes:summary><itunes:duration>1584</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 234: Report from the 2022 RSA Conference</title><link>https://www.spreaker.com/episode/root-causes-234-report-from-the-2022-rsa-conference--52925930</link><description><![CDATA[The RSA Security Conference is back. In this episode we talk about what happened in 2020 and how the first post-COVID RSAC compared to earlier years, along with some of the major themes this year.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1310051782</guid><pubDate>Fri, 22 Jul 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52925930/1310051782_tim_callan_root_causes_234_report_from_2022_rsa_conference.mp3" length="2468190" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The RSA Security Conference is back. In this episode we talk about what happened in 2020 and how the first post-COVID RSAC compared to earlier years, along with some of the major themes this year.</itunes:subtitle><itunes:summary><![CDATA[The RSA Security Conference is back. In this episode we talk about what happened in 2020 and how the first post-COVID RSAC compared to earlier years, along with some of the major themes this year.]]></itunes:summary><itunes:duration>614</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 233: CISA Recommendations for Post-Quantum Crypto</title><link>https://www.spreaker.com/episode/root-causes-233-cisa-recommendations-for-post-quantum-crypto--52926541</link><description><![CDATA[In coordination with NIST's announcement of its new post-quantum cryptographic algorithm contest winners, the Cybersecurity and Infrastructure Security Agency released a bulletin listing six key actions for IT to commence now.  We read out these six actions and put them in context.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1304694235</guid><pubDate>Tue, 12 Jul 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926541/1304694235_tim_callan_root_causes_233_cisa_recommendations_for_post_quantum_crypto.mp3" length="6116634" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In coordination with NIST's announcement of its new post-quantum cryptographic algorithm contest winners, the Cybersecurity and Infrastructure Security Agency released a bulletin listing six key actions for IT to commence now.  We read out these six...</itunes:subtitle><itunes:summary><![CDATA[In coordination with NIST's announcement of its new post-quantum cryptographic algorithm contest winners, the Cybersecurity and Infrastructure Security Agency released a bulletin listing six key actions for IT to commence now.  We read out these six actions and put them in context.]]></itunes:summary><itunes:duration>1527</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 232: NIST Announces Post Quantum Crypto Selections</title><link>https://www.spreaker.com/episode/root-causes-232-nist-announces-post-quantum-crypto-selections--52926666</link><description><![CDATA[NIST has announced its winning algorithms for round 3 of its post-quantum cryptography "contest." Join us as we name the winning algorithms and why they were chosen.  We discuss the continuing effort to arrive at additional algorithms, and we talk about the next steps coming out of this announcement.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1301993602</guid><pubDate>Fri, 08 Jul 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926666/1301993602_tim_callan_root_causes_232_nist_announces_post_quantum_crypto_selections.mp3" length="4518774" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>NIST has announced its winning algorithms for round 3 of its post-quantum cryptography "contest." Join us as we name the winning algorithms and why they were chosen.  We discuss the continuing effort to arrive at additional algorithms, and we talk...</itunes:subtitle><itunes:summary><![CDATA[NIST has announced its winning algorithms for round 3 of its post-quantum cryptography "contest." Join us as we name the winning algorithms and why they were chosen.  We discuss the continuing effort to arrive at additional algorithms, and we talk about the next steps coming out of this announcement.]]></itunes:summary><itunes:duration>1128</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 231: What Is FIDO?</title><link>https://www.spreaker.com/episode/root-causes-231-what-is-fido--52928432</link><description><![CDATA[Recent announcements about consumer passwordless authentication build on standards like FIDO and WebAuthn.  In this episode we explain device-centric authentication, the FIDO Alliance, and how it all works.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1300771300</guid><pubDate>Wed, 06 Jul 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928432/1300771300_tim_callan_root_causes_231_what_is_fido.mp3" length="5812292" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent announcements about consumer passwordless authentication build on standards like FIDO and WebAuthn.  In this episode we explain device-centric authentication, the FIDO Alliance, and how it all works.</itunes:subtitle><itunes:summary><![CDATA[Recent announcements about consumer passwordless authentication build on standards like FIDO and WebAuthn.  In this episode we explain device-centric authentication, the FIDO Alliance, and how it all works.]]></itunes:summary><itunes:duration>1451</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 230: What Is Apple Passkey?</title><link>https://www.spreaker.com/episode/root-causes-230-what-is-apple-passkey--52926694</link><description><![CDATA[Apple recently announced its Passkey functionality, which will allow passwordless authentication between Apple devices and supporting web services through key exchange. In this episode we discuss how this works, the user experience, the significance of FIDO and WebAuthn, and implications for consumer-facing sites.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1297458274</guid><pubDate>Thu, 30 Jun 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926694/1297458274_tim_callan_root_causes_230_what_is_apple_passkey.mp3" length="3826983" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple recently announced its Passkey functionality, which will allow passwordless authentication between Apple devices and supporting web services through key exchange. In this episode we discuss how this works, the user experience, the significance...</itunes:subtitle><itunes:summary><![CDATA[Apple recently announced its Passkey functionality, which will allow passwordless authentication between Apple devices and supporting web services through key exchange. In this episode we discuss how this works, the user experience, the significance of FIDO and WebAuthn, and implications for consumer-facing sites.]]></itunes:summary><itunes:duration>955</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 229: Browsing Collectives and the 80/20 Rule of Browser Privacy</title><link>https://www.spreaker.com/episode/root-causes-229-browsing-collectives-and-the-80-20-rule-of-browser-privacy--52926026</link><description><![CDATA[In this follow-on to our two previous podcasts, we elucidate additional potential schemes for preserving consumer privacy. We discuss data aggregation, the power of the default, decentralized blockchain identities, the death of cookies, browsing collectives, privacy browsers, and the 80/20 rule of browser entropy.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1283772628</guid><pubDate>Wed, 08 Jun 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926026/1283772628_tim_callan_root_causes_229_browsing_collectives_and_the_8020_rule_of_browser_privacy.mp3" length="5212535" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this follow-on to our two previous podcasts, we elucidate additional potential schemes for preserving consumer privacy. We discuss data aggregation, the power of the default, decentralized blockchain identities, the death of cookies, browsing...</itunes:subtitle><itunes:summary><![CDATA[In this follow-on to our two previous podcasts, we elucidate additional potential schemes for preserving consumer privacy. We discuss data aggregation, the power of the default, decentralized blockchain identities, the death of cookies, browsing collectives, privacy browsers, and the 80/20 rule of browser entropy.]]></itunes:summary><itunes:duration>1301</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 228: Getting the FLoC out of Here</title><link>https://www.spreaker.com/episode/root-causes-228-getting-the-floc-out-of-here--52926802</link><description><![CDATA[In a follow-up to our recent episode on cookies and browser tracking, we discuss Google's Federated Learning of Cohorts (FLoC) initiative, why it failed as a response, and other directions the industry is looking in.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1279293649</guid><pubDate>Tue, 31 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926802/1279293649_tim_callan_root_causes_228_getting_the_floc_out_of_here.mp3" length="3456885" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In a follow-up to our recent episode on cookies and browser tracking, we discuss Google's Federated Learning of Cohorts (FLoC) initiative, why it failed as a response, and other directions the industry is looking in.</itunes:subtitle><itunes:summary><![CDATA[In a follow-up to our recent episode on cookies and browser tracking, we discuss Google's Federated Learning of Cohorts (FLoC) initiative, why it failed as a response, and other directions the industry is looking in.]]></itunes:summary><itunes:duration>862</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 227: Let's Talk About Cookies</title><link>https://www.spreaker.com/episode/root-causes-227-let-s-talk-about-cookies--52926707</link><description><![CDATA[In this episode we explain the fundamentals of cookies and why, despite their obvious benefits, they present troublesome privacy concerns. We discuss the many ways web users can be tracked including cross-site cookies, tracking pixels, and browser fingerprinting.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1276473097</guid><pubDate>Fri, 27 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926707/1276473097_tim_callan_root_causes_227_lets_talk_about_cookies.mp3" length="5661536" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain the fundamentals of cookies and why, despite their obvious benefits, they present troublesome privacy concerns. We discuss the many ways web users can be tracked including cross-site cookies, tracking pixels, and browser...</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain the fundamentals of cookies and why, despite their obvious benefits, they present troublesome privacy concerns. We discuss the many ways web users can be tracked including cross-site cookies, tracking pixels, and browser fingerprinting.]]></itunes:summary><itunes:duration>1414</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 226: The Six Benefits of SSH Certificates</title><link>https://www.spreaker.com/episode/root-causes-226-the-six-benefits-of-ssh-certificates--52927584</link><description><![CDATA[In this third episode in our series on SSH keys, we identify the six main benefits of SSH certificates and how they mitigate the problems with SSH identified in earlier episodes.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1274548675</guid><pubDate>Tue, 24 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927584/1274548675_tim_callan_root_causes_226_the_six_benefits_of_ssh_certificates.mp3" length="5163164" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this third episode in our series on SSH keys, we identify the six main benefits of SSH certificates and how they mitigate the problems with SSH identified in earlier episodes.</itunes:subtitle><itunes:summary><![CDATA[In this third episode in our series on SSH keys, we identify the six main benefits of SSH certificates and how they mitigate the problems with SSH identified in earlier episodes.]]></itunes:summary><itunes:duration>1289</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 225: The Difference Between Relying Parties and Certificate Consumers</title><link>https://www.spreaker.com/episode/root-causes-225-the-difference-between-relying-parties-and-certificate-consumers--52928429</link><description><![CDATA[Despite the similarity in their names, in the world of digital certificates a Relying Party and a Certificate Consumer are very different things.  In this episode we define the four main roles in the public trust ecosystem: CA, Subscriber, Certificate Consumer, and Relying Party, with real-world examples.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1272236584</guid><pubDate>Thu, 19 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928429/1272236584_tim_callan_root_causes_225_the_difference_between_relying_parties_and_certificate_consumers.mp3" length="3681693" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Despite the similarity in their names, in the world of digital certificates a Relying Party and a Certificate Consumer are very different things.  In this episode we define the four main roles in the public trust ecosystem: CA, Subscriber, Certificate...</itunes:subtitle><itunes:summary><![CDATA[Despite the similarity in their names, in the world of digital certificates a Relying Party and a Certificate Consumer are very different things.  In this episode we define the four main roles in the public trust ecosystem: CA, Subscriber, Certificate Consumer, and Relying Party, with real-world examples.]]></itunes:summary><itunes:duration>919</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 224: The Five Problems with SSH Keys</title><link>https://www.spreaker.com/episode/root-causes-224-the-five-problems-with-ssh-keys--52927572</link><description><![CDATA[In this follow-on to our earlier episode explaining SSH keys, we discuss the five problems SSH keys present to organizations using them. And we give a peek at how to solve these problems.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1270122652</guid><pubDate>Tue, 17 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927572/1270122652_tim_callan_root_causes_224_the_five_problems_with_ssh_keys.mp3" length="4632693" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this follow-on to our earlier episode explaining SSH keys, we discuss the five problems SSH keys present to organizations using them. And we give a peek at how to solve these problems.</itunes:subtitle><itunes:summary><![CDATA[In this follow-on to our earlier episode explaining SSH keys, we discuss the five problems SSH keys present to organizations using them. And we give a peek at how to solve these problems.]]></itunes:summary><itunes:duration>1156</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 223: CT Log-Enabled Attacks on WordPress Sites</title><link>https://www.spreaker.com/episode/root-causes-223-ct-log-enabled-attacks-on-wordpress-sites--52928437</link><description><![CDATA[Attackers are using CT logs to identify brand new WordPress sites and install malware before upcoming security measures are in place.  This attack is novel in how it exploits Certificate Transparency information to identify likely targets.  In this episode we explain what is happening and why it's noteworthy.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1267828354</guid><pubDate>Wed, 11 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928437/1267828354_tim_callan_root_causes_223_ct_log_enabled_attacks_on_wordpress_sites.mp3" length="3545675" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Attackers are using CT logs to identify brand new WordPress sites and install malware before upcoming security measures are in place.  This attack is novel in how it exploits Certificate Transparency information to identify likely targets.  In this...</itunes:subtitle><itunes:summary><![CDATA[Attackers are using CT logs to identify brand new WordPress sites and install malware before upcoming security measures are in place.  This attack is novel in how it exploits Certificate Transparency information to identify likely targets.  In this episode we explain what is happening and why it's noteworthy.]]></itunes:summary><itunes:duration>884</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 222: Consolidation and PKI Solutions</title><link>https://www.spreaker.com/episode/root-causes-222-consolidation-and-pki-solutions--52928401</link><description><![CDATA[Vendor consolidation is an important topic in IT security. As the scope and variety of threats continues to increase, we have seen a proliferation of point solutions and features, and a resulting desire to reduce that vendor footprint or at least facilitate using them together. In this episode we discuss this trend and how it specifically affects PKI and digital certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1266343156</guid><pubDate>Wed, 11 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928401/1266343156_tim_callan_root_causes_222_consolidation_and_pki_solutions.mp3" length="2488925" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Vendor consolidation is an important topic in IT security. As the scope and variety of threats continues to increase, we have seen a proliferation of point solutions and features, and a resulting desire to reduce that vendor footprint or at least...</itunes:subtitle><itunes:summary><![CDATA[Vendor consolidation is an important topic in IT security. As the scope and variety of threats continues to increase, we have seen a proliferation of point solutions and features, and a resulting desire to reduce that vendor footprint or at least facilitate using them together. In this episode we discuss this trend and how it specifically affects PKI and digital certificates.]]></itunes:summary><itunes:duration>620</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 221: What Are SSH Keys?</title><link>https://www.spreaker.com/episode/root-causes-221-what-are-ssh-keys--52926033</link><description><![CDATA[SSH (Secure Shell) keys are ubiquitous for authenticated access to Linux systems. In this first of three episodes we explain what these keys are and how they're used.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1262883439</guid><pubDate>Wed, 04 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926033/1262883439_tim_callan_root_causes_221_what_are_ssh_keys.mp3" length="3590723" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>SSH (Secure Shell) keys are ubiquitous for authenticated access to Linux systems. In this first of three episodes we explain what these keys are and how they're used.</itunes:subtitle><itunes:summary><![CDATA[SSH (Secure Shell) keys are ubiquitous for authenticated access to Linux systems. In this first of three episodes we explain what these keys are and how they're used.]]></itunes:summary><itunes:duration>896</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 220: The Difference Between OTP and Passwordless</title><link>https://www.spreaker.com/episode/root-causes-220-the-difference-between-otp-and-passwordless--52927617</link><description><![CDATA["Passwordless" is a hot term in the industry, and as a result many technology vendors are attaching their solutions to this term. In this episode we clarify the difference between OTP services and passwordless authentication.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1261038070</guid><pubDate>Mon, 02 May 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927617/1261038070_tim_callan_root_causes_220_the_difference_between_otp_and_passwordless.mp3" length="3387364" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>"Passwordless" is a hot term in the industry, and as a result many technology vendors are attaching their solutions to this term. In this episode we clarify the difference between OTP services and passwordless authentication.</itunes:subtitle><itunes:summary><![CDATA["Passwordless" is a hot term in the industry, and as a result many technology vendors are attaching their solutions to this term. In this episode we clarify the difference between OTP services and passwordless authentication.]]></itunes:summary><itunes:duration>845</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 219: New Quantum Cryptography Legislation Introduced</title><link>https://www.spreaker.com/episode/root-causes-219-new-quantum-cryptography-legislation-introduced--52926727</link><description><![CDATA[New proposed legislation in the US House of Representatives mandates that federal agencies must begin preparation for using the new quantum resistant cryptographic algorithms selected by NIST. This represents a major development in building a quantum safe digital world.  In this episode we explain the proposed legislation and it's consequences.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1258102672</guid><pubDate>Tue, 26 Apr 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926727/1258102672_tim_callan_root_causes_219_new_quantum_cryptography_legislation_introduced.mp3" length="2926711" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>New proposed legislation in the US House of Representatives mandates that federal agencies must begin preparation for using the new quantum resistant cryptographic algorithms selected by NIST. This represents a major development in building a quantum...</itunes:subtitle><itunes:summary><![CDATA[New proposed legislation in the US House of Representatives mandates that federal agencies must begin preparation for using the new quantum resistant cryptographic algorithms selected by NIST. This represents a major development in building a quantum safe digital world.  In this episode we explain the proposed legislation and it's consequences.]]></itunes:summary><itunes:duration>730</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 218: PKI Nomenclature Oddities</title><link>https://www.spreaker.com/episode/root-causes-218-pki-nomenclature-oddities--52926737</link><description><![CDATA[Every technology space has its jargon. In this episode we go over some of the interesting, ambiguous, or amusing terms that are specific to the PKI and digital certificates industry.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1253781097</guid><pubDate>Wed, 20 Apr 2022 17:47:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926737/1253781097_tim_callan_root_causes_218_pki_nomenclature_oddities.mp3" length="7272953" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Every technology space has its jargon. In this episode we go over some of the interesting, ambiguous, or amusing terms that are specific to the PKI and digital certificates industry.</itunes:subtitle><itunes:summary><![CDATA[Every technology space has its jargon. In this episode we go over some of the interesting, ambiguous, or amusing terms that are specific to the PKI and digital certificates industry.]]></itunes:summary><itunes:duration>1816</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 217: What's the Deal with the Recent Okta Security Breach?</title><link>https://www.spreaker.com/episode/root-causes-217-what-s-the-deal-with-the-recent-okta-security-breach--52926055</link><description><![CDATA[In March the LAPSIS$ hacking group convincingly announced a breach of Okta systems, potentially exposing Okta customers to additional compromise. Despite Okta's initial statements to the contrary, it ultimately turned out that up to 366 Okta customers may be affected. Our hosts walk through the events of the attack, how it unfolded over time, and how this breach was revealed.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1250269009</guid><pubDate>Thu, 14 Apr 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926055/1250269009_tim_callan_root_causes_217_whats_the_deal_with_the_recent_okta_security_breach.mp3" length="5885408" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In March the LAPSIS$ hacking group convincingly announced a breach of Okta systems, potentially exposing Okta customers to additional compromise. Despite Okta's initial statements to the contrary, it ultimately turned out that up to 366 Okta customers...</itunes:subtitle><itunes:summary><![CDATA[In March the LAPSIS$ hacking group convincingly announced a breach of Okta systems, potentially exposing Okta customers to additional compromise. Despite Okta's initial statements to the contrary, it ultimately turned out that up to 366 Okta customers may be affected. Our hosts walk through the events of the attack, how it unfolded over time, and how this breach was revealed.]]></itunes:summary><itunes:duration>1469</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 216: What Is crt.sh?</title><link>https://www.spreaker.com/episode/root-causes-216-what-is-crt-sh--52926789</link><description><![CDATA[One of the foundational tools for monitoring and understanding public SSL certificates is crt.sh, created and maintained by Sectigo's own Rob Stradling. In this episode our hosts explain what crt.sh does and why it is so popular among SSL industry watchers.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1248464884</guid><pubDate>Sun, 10 Apr 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926789/1248464884_tim_callan_root_causes_216_what_is_crt_sh.mp3" length="2609154" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>One of the foundational tools for monitoring and understanding public SSL certificates is crt.sh, created and maintained by Sectigo's own Rob Stradling. In this episode our hosts explain what crt.sh does and why it is so popular among SSL industry...</itunes:subtitle><itunes:summary><![CDATA[One of the foundational tools for monitoring and understanding public SSL certificates is crt.sh, created and maintained by Sectigo's own Rob Stradling. In this episode our hosts explain what crt.sh does and why it is so popular among SSL industry watchers.]]></itunes:summary><itunes:duration>650</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 215: Passwordless Authentication and Legacy Systems</title><link>https://www.spreaker.com/episode/root-causes-215-passwordless-authentication-and-legacy-systems--52926080</link><description><![CDATA[Organizations seeking to use passwordless authentication frequently must deal with legacy systems that cannot support this scheme. In this episode we explain why that occurs and detail the steps organizations can take to mitigate the effect of legacy systems.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1246752205</guid><pubDate>Fri, 08 Apr 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926080/1246752205_tim_callan_root_causes_215_passwordless_authentication_and_legacy_systems.mp3" length="5672545" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Organizations seeking to use passwordless authentication frequently must deal with legacy systems that cannot support this scheme. In this episode we explain why that occurs and detail the steps organizations can take to mitigate the effect of legacy...</itunes:subtitle><itunes:summary><![CDATA[Organizations seeking to use passwordless authentication frequently must deal with legacy systems that cannot support this scheme. In this episode we explain why that occurs and detail the steps organizations can take to mitigate the effect of legacy systems.]]></itunes:summary><itunes:duration>1416</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 214: New DUO MFA Flaw Explained</title><link>https://www.spreaker.com/episode/root-causes-214-new-duo-mfa-flaw-explained--52926811</link><description><![CDATA[A recent FBI warning cautions organizations about exploits based on misconfigured DUO MFA, which exploits weaknesses in Active Directory to provision credentials on DUO for malicious parties.  This is an unusual story in several ways, including the fact that the exploit is based on a configuration error and that it's specific to a single, popular SaaS offering.  Our hosts explain this exploit and why it is noteworthy.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1244783002</guid><pubDate>Tue, 05 Apr 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926811/1244783002_tim_callan_root_causes_214_new_duo_mfa_flaw_explained.mp3" length="2717012" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent FBI warning cautions organizations about exploits based on misconfigured DUO MFA, which exploits weaknesses in Active Directory to provision credentials on DUO for malicious parties.  This is an unusual story in several ways, including the...</itunes:subtitle><itunes:summary><![CDATA[A recent FBI warning cautions organizations about exploits based on misconfigured DUO MFA, which exploits weaknesses in Active Directory to provision credentials on DUO for malicious parties.  This is an unusual story in several ways, including the fact that the exploit is based on a configuration error and that it's specific to a single, popular SaaS offering.  Our hosts explain this exploit and why it is noteworthy.]]></itunes:summary><itunes:duration>677</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 212: S/MIME Limited to Three Years</title><link>https://www.spreaker.com/episode/root-causes-212-s-mime-limited-to-three-years--52927598</link><description><![CDATA[On April 1 new root program requirements from Apple for S/MIME certificates go into effect, including a limitation of the allowable term to three years.  This is contrary to Apple's stated intentions last year.  In this episode the explain this change in policy and what certificate users can expect for the future.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1240117351</guid><pubDate>Mon, 28 Mar 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927598/1240117351_tim_callan_root_causes_212_smime_limited_to_three_years.mp3" length="2575897" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On April 1 new root program requirements from Apple for S/MIME certificates go into effect, including a limitation of the allowable term to three years.  This is contrary to Apple's stated intentions last year.  In this episode the explain this change...</itunes:subtitle><itunes:summary><![CDATA[On April 1 new root program requirements from Apple for S/MIME certificates go into effect, including a limitation of the allowable term to three years.  This is contrary to Apple's stated intentions last year.  In this episode the explain this change in policy and what certificate users can expect for the future.]]></itunes:summary><itunes:duration>642</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 213: 600-domain Phishing Attack</title><link>https://www.spreaker.com/episode/root-causes-213-600-domain-phishing-attack--52927280</link><description><![CDATA[In this episode we describe a recent phishing campaign noteworthy for its scale, encompassing a total of 600 unique domains.  We discuss the implications of a campaign of this scale and high level of organization.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1241964406</guid><pubDate>Mon, 28 Mar 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927280/1241964406_tim_callan_root_causes_213_600_domain_phishing_attack.mp3" length="1946398" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we describe a recent phishing campaign noteworthy for its scale, encompassing a total of 600 unique domains.  We discuss the implications of a campaign of this scale and high level of organization.</itunes:subtitle><itunes:summary><![CDATA[In this episode we describe a recent phishing campaign noteworthy for its scale, encompassing a total of 600 unique domains.  We discuss the implications of a campaign of this scale and high level of organization.]]></itunes:summary><itunes:duration>485</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 211: Does CLM  Make Wildcard and MDC Irrelevant?</title><link>https://www.spreaker.com/episode/root-causes-211-does-clm-make-wildcard-and-mdc-irrelevant--52926783</link><description><![CDATA[Wildcard and multi-domain certificates have traditionally made administration easier for IT departments. In this episode we weigh the degree to which Certificate Lifecycle Management (CLM) renders these benefits obsolete and if these certificate types continue to be worth the increased risk they carry.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1232119597</guid><pubDate>Sat, 12 Mar 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926783/1232119597_tim_callan_root_causes_211_does_clm_make_wildcard_and_mcd_irrelevant.mp3" length="3423218" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Wildcard and multi-domain certificates have traditionally made administration easier for IT departments. In this episode we weigh the degree to which Certificate Lifecycle Management (CLM) renders these benefits obsolete and if these certificate types...</itunes:subtitle><itunes:summary><![CDATA[Wildcard and multi-domain certificates have traditionally made administration easier for IT departments. In this episode we weigh the degree to which Certificate Lifecycle Management (CLM) renders these benefits obsolete and if these certificate types continue to be worth the increased risk they carry.]]></itunes:summary><itunes:duration>854</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 210: Living off the Land</title><link>https://www.spreaker.com/episode/root-causes-210-living-off-the-land--52926090</link><description><![CDATA[Microsoft has deprecated support for the popular sysadmin tool WMIC. Join our hosts as they explain the security reasons behind this development and broader lessons we can learn.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1228718440</guid><pubDate>Mon, 07 Mar 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926090/1228718440_tim_callan_root_causes_210_living_off_the_land.mp3" length="1579051" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Microsoft has deprecated support for the popular sysadmin tool WMIC. Join our hosts as they explain the security reasons behind this development and broader lessons we can learn.</itunes:subtitle><itunes:summary><![CDATA[Microsoft has deprecated support for the popular sysadmin tool WMIC. Join our hosts as they explain the security reasons behind this development and broader lessons we can learn.]]></itunes:summary><itunes:duration>393</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 209: One-Day Deployment of Certificate Lifecycle Management (CLM) Platforms</title><link>https://www.spreaker.com/episode/root-causes-209-one-day-deployment-of-certificate-lifecycle-management-clm-platforms--52926856</link><description><![CDATA[For any Certificate Lifecycle Management platform to succeed, effective deployment is essential. Our hosts are joined by Sectigo SVP of Global Sales Jennifer Binet who describes the optimal onboarding process, step by step.  Jennifer discusses adding use cases over time, streamlining the contracting process, and getting to full automation for all certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1224660349</guid><pubDate>Mon, 28 Feb 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926856/1224660349_tim_callan_root_causes_209_one_day_deployment_of_certificate_lifecycle_management_clm_platforms.mp3" length="4944181" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>For any Certificate Lifecycle Management platform to succeed, effective deployment is essential. Our hosts are joined by Sectigo SVP of Global Sales Jennifer Binet who describes the optimal onboarding process, step by step.  Jennifer discusses adding...</itunes:subtitle><itunes:summary><![CDATA[For any Certificate Lifecycle Management platform to succeed, effective deployment is essential. Our hosts are joined by Sectigo SVP of Global Sales Jennifer Binet who describes the optimal onboarding process, step by step.  Jennifer discusses adding use cases over time, streamlining the contracting process, and getting to full automation for all certificates.]]></itunes:summary><itunes:duration>1234</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 208: Automotive Information Systems Bricked by HD Radio Error</title><link>https://www.spreaker.com/episode/root-causes-208-automotive-information-systems-bricked-by-hd-radio-error--52927622</link><description><![CDATA[A major automobile manufacturer recently had a problem where its infotainment systems were permanently "bricked" by a flaw in local HD radio broadcasts. Our hosts describe what happened and explore the lessons we can learn from this incident.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1221810958</guid><pubDate>Thu, 24 Feb 2022 17:59:42 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927622/1221810958_tim_callan_root_causes_208_automotive_information_systems_bricked_by_hd_radio_error.mp3" length="2340935" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A major automobile manufacturer recently had a problem where its infotainment systems were permanently "bricked" by a flaw in local HD radio broadcasts. Our hosts describe what happened and explore the lessons we can learn from this incident.</itunes:subtitle><itunes:summary><![CDATA[A major automobile manufacturer recently had a problem where its infotainment systems were permanently "bricked" by a flaw in local HD radio broadcasts. Our hosts describe what happened and explore the lessons we can learn from this incident.]]></itunes:summary><itunes:duration>583</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 207: Former Gartner Analyst David Mahdi Jumps on the Playing Field</title><link>https://www.spreaker.com/episode/root-causes-207-former-gartner-analyst-david-mahdi-jumps-on-the-playing-field--52927600</link><description><![CDATA[Gartner analyst David Mahdi recently left the analyst space for Sectigo. In this episode he joins our hosts to explain the reasons for his optimism about digital trust, including NFTs, Web3, blockchain, PKI, and Zero Trust.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1220037058</guid><pubDate>Mon, 21 Feb 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927600/1220037058_tim_callan_root_causes_207_former_gartner_analyst_david_mahdi_jumps_on_the_playing_field.mp3" length="4555315" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Gartner analyst David Mahdi recently left the analyst space for Sectigo. In this episode he joins our hosts to explain the reasons for his optimism about digital trust, including NFTs, Web3, blockchain, PKI, and Zero Trust.</itunes:subtitle><itunes:summary><![CDATA[Gartner analyst David Mahdi recently left the analyst space for Sectigo. In this episode he joins our hosts to explain the reasons for his optimism about digital trust, including NFTs, Web3, blockchain, PKI, and Zero Trust.]]></itunes:summary><itunes:duration>1137</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 206: What Is Web3?</title><link>https://www.spreaker.com/episode/root-causes-206-what-is-web3--52926075</link><description><![CDATA[Web3 refers to the concept that online content can be attributed to specific known publishers, regardless of web site or online channel. In this episode we discuss the fundamentals of Web3, including self-signing protocols, authorization of content, blockchain, definitive authorship, consensus algorithms, and meat from space.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1215762505</guid><pubDate>Sun, 13 Feb 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926075/1215762505_tim_callan_root_causes_206_what_is_web3.mp3" length="8051628" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Web3 refers to the concept that online content can be attributed to specific known publishers, regardless of web site or online channel. In this episode we discuss the fundamentals of Web3, including self-signing protocols, authorization of content,...</itunes:subtitle><itunes:summary><![CDATA[Web3 refers to the concept that online content can be attributed to specific known publishers, regardless of web site or online channel. In this episode we discuss the fundamentals of Web3, including self-signing protocols, authorization of content, blockchain, definitive authorship, consensus algorithms, and meat from space.]]></itunes:summary><itunes:duration>2011</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 205: Anatomy of an Encrypted Peer-to-Peer Mesh Network</title><link>https://www.spreaker.com/episode/root-causes-205-anatomy-of-an-encrypted-peer-to-peer-mesh-network--52926709</link><description><![CDATA[Secure online collaboration poses logistical and technical challenges under the best of circumstances.  Now imagine you have no designated IT staff, no designated hardware, a small budget, and remote participants who are not deeply technical. In this episode Jason Soroko explains how he was able to quickly and easily create an encrypted communications mesh for use by him and his collaboration team.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1212867211</guid><pubDate>Wed, 09 Feb 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926709/1212867211_tim_callan_root_causes_205_anatomy_of_an_encrypted_peer_to_peer_mesh_network.mp3" length="3007169" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Secure online collaboration poses logistical and technical challenges under the best of circumstances.  Now imagine you have no designated IT staff, no designated hardware, a small budget, and remote participants who are not deeply technical. In this...</itunes:subtitle><itunes:summary><![CDATA[Secure online collaboration poses logistical and technical challenges under the best of circumstances.  Now imagine you have no designated IT staff, no designated hardware, a small budget, and remote participants who are not deeply technical. In this episode Jason Soroko explains how he was able to quickly and easily create an encrypted communications mesh for use by him and his collaboration team.]]></itunes:summary><itunes:duration>750</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 204: PKI's Role in Passwordless</title><link>https://www.spreaker.com/episode/root-causes-204-pki-s-role-in-passwordless--52926065</link><description><![CDATA[In previous episodes we have defined passwordless identity authentication. In this episode our hosts explain PKI's specific role in passwordless authentication, along the way clarifying the difference between password-masking and true passwordless technologies.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1209217972</guid><pubDate>Wed, 02 Feb 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926065/1209217972_tim_callan_root_causes_204_pkis_role_in_passwordless.mp3" length="5510361" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In previous episodes we have defined passwordless identity authentication. In this episode our hosts explain PKI's specific role in passwordless authentication, along the way clarifying the difference between password-masking and true passwordless...</itunes:subtitle><itunes:summary><![CDATA[In previous episodes we have defined passwordless identity authentication. In this episode our hosts explain PKI's specific role in passwordless authentication, along the way clarifying the difference between password-masking and true passwordless technologies.]]></itunes:summary><itunes:duration>1376</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 203: What Is a Credential Vault?</title><link>https://www.spreaker.com/episode/root-causes-203-what-is-a-credential-vault--52927273</link><description><![CDATA[Credential vaults are necessary for secure and functional secrets management for automated systems like DevOps or Robotic Process Automation (RPA). This episode explains how credential vaults work and details their benefits.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1207239178</guid><pubDate>Mon, 31 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927273/1207239178_tim_callan_root_causes_203_what_is_a_credential_vault.mp3" length="2587714" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Credential vaults are necessary for secure and functional secrets management for automated systems like DevOps or Robotic Process Automation (RPA). This episode explains how credential vaults work and details their benefits.</itunes:subtitle><itunes:summary><![CDATA[Credential vaults are necessary for secure and functional secrets management for automated systems like DevOps or Robotic Process Automation (RPA). This episode explains how credential vaults work and details their benefits.]]></itunes:summary><itunes:duration>645</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 202 : What Is Certificate Transparency?</title><link>https://www.spreaker.com/episode/root-causes-202-what-is-certificate-transparency--52926101</link><description><![CDATA[Certificate Transparency (CT) is essential to monitoring the public SSL certificates that are issued. In this episode we explain what CT logs are, how they work, and the uses we can put them to.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1204793467</guid><pubDate>Thu, 27 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926101/1204793467_tim_callan_root_causes_202_what_is_certificate_transparency.mp3" length="3742650" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certificate Transparency (CT) is essential to monitoring the public SSL certificates that are issued. In this episode we explain what CT logs are, how they work, and the uses we can put them to.</itunes:subtitle><itunes:summary><![CDATA[Certificate Transparency (CT) is essential to monitoring the public SSL certificates that are issued. In this episode we explain what CT logs are, how they work, and the uses we can put them to.]]></itunes:summary><itunes:duration>934</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 201: What Are the Baseline Requirements?</title><link>https://www.spreaker.com/episode/root-causes-201-what-are-the-baseline-requirements--52928447</link><description><![CDATA[The CA/Browser Forum Baseline Requirements (BR) are hugely influential in the world of public-trust certificates. In this episode we explain what the Baseline Requirements are, how they are created, and why they matter.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1202854744</guid><pubDate>Mon, 24 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928447/1202854744_tim_callan_root_causes_201_what_are_the_baseline_requirements.mp3" length="3906676" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CA/Browser Forum Baseline Requirements (BR) are hugely influential in the world of public-trust certificates. In this episode we explain what the Baseline Requirements are, how they are created, and why they matter.</itunes:subtitle><itunes:summary><![CDATA[The CA/Browser Forum Baseline Requirements (BR) are hugely influential in the world of public-trust certificates. In this episode we explain what the Baseline Requirements are, how they are created, and why they matter.]]></itunes:summary><itunes:duration>975</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 200: Why Not to Copy and Paste Commands from Web Pages</title><link>https://www.spreaker.com/episode/root-causes-200-why-not-to-copy-and-paste-commands-from-web-pages--52928469</link><description><![CDATA[This episode describes newly revealed vulnerabilities where copying and pasting text from a web page can open the site visitor up to attack. Our hosts explain how this attack can occur and its potential consequences, along with how to defend yourself against this threat.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1199550412</guid><pubDate>Wed, 19 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928469/1199550412_tim_callan_root_causes_200_why_not_to_copy_and_paste_commands_from_web_pages.mp3" length="1719864" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>This episode describes newly revealed vulnerabilities where copying and pasting text from a web page can open the site visitor up to attack. Our hosts explain how this attack can occur and its potential consequences, along with how to defend yourself...</itunes:subtitle><itunes:summary><![CDATA[This episode describes newly revealed vulnerabilities where copying and pasting text from a web page can open the site visitor up to attack. Our hosts explain how this attack can occur and its potential consequences, along with how to defend yourself against this threat.]]></itunes:summary><itunes:duration>428</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 199: What Is Privileged Access Management?</title><link>https://www.spreaker.com/episode/root-causes-199-what-is-privileged-access-management--52927644</link><description><![CDATA[In this episode we explain Privileged Access Management (PAM). We go on to explain some of the ways that networks using these techniques are still vulnerable to attack and what to do about it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1196632735</guid><pubDate>Thu, 13 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927644/1196632735_tim_callan_root_causes_199_what_is_privileged_access_management.mp3" length="3852941" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explain Privileged Access Management (PAM). We go on to explain some of the ways that networks using these techniques are still vulnerable to attack and what to do about it.</itunes:subtitle><itunes:summary><![CDATA[In this episode we explain Privileged Access Management (PAM). We go on to explain some of the ways that networks using these techniques are still vulnerable to attack and what to do about it.]]></itunes:summary><itunes:duration>961</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 198: Deep Voice Fakes</title><link>https://www.spreaker.com/episode/root-causes-198-deep-voice-fakes--52928470</link><description><![CDATA[We are all familiar with phishing in its various forms. Many people feel that they can protect themselves from fraud by verbally confirming apparent commands from senior executes. In this episode our hosts explore deep voice fakes, computer generated audio that successfully passes for the voice of a known associate, and the risks they pose.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1194552067</guid><pubDate>Tue, 11 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928470/1194552067_tim_callan_root_causes_198_deep_voice_fakes.mp3" length="3579633" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We are all familiar with phishing in its various forms. Many people feel that they can protect themselves from fraud by verbally confirming apparent commands from senior executes. In this episode our hosts explore deep voice fakes, computer generated...</itunes:subtitle><itunes:summary><![CDATA[We are all familiar with phishing in its various forms. Many people feel that they can protect themselves from fraud by verbally confirming apparent commands from senior executes. In this episode our hosts explore deep voice fakes, computer generated audio that successfully passes for the voice of a known associate, and the risks they pose.]]></itunes:summary><itunes:duration>893</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 197: Tim's Digital Haircut</title><link>https://www.spreaker.com/episode/root-causes-197-tim-s-digital-haircut--52926125</link><description><![CDATA[In this episode our hosts describe the extreme degree to which all business has become digital business, even the most offline businesses you can think of, including food delivery, in-restaurant dining, bricks-and-mortar retail, and naturally, haircuts. We discuss the disparate, interconnected systems required to make this happen and the fragility of this new digital world.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1192362853</guid><pubDate>Fri, 07 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926125/1192362853_tim_callan_root_causes_197_tims_digital_haircut.mp3" length="17234413" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode our hosts describe the extreme degree to which all business has become digital business, even the most offline businesses you can think of, including food delivery, in-restaurant dining, bricks-and-mortar retail, and naturally,...</itunes:subtitle><itunes:summary><![CDATA[In this episode our hosts describe the extreme degree to which all business has become digital business, even the most offline businesses you can think of, including food delivery, in-restaurant dining, bricks-and-mortar retail, and naturally, haircuts. We discuss the disparate, interconnected systems required to make this happen and the fragility of this new digital world.]]></itunes:summary><itunes:duration>719</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 196: What Is Certificate Agnostic?</title><link>https://www.spreaker.com/episode/root-causes-196-what-is-certificate-agnostic--52927284</link><description><![CDATA[In 2021 the certificate industry saw the emergency of the concept of "CA agnostic." However, that is only part of the story.   In this episode our hosts build on this concept to define the idea of certificate automation platforms being "certificate agnostic," meaning these platforms should handle all certificates regardless of type, configuration, physical location, environment, use case, and origin.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1190249227</guid><pubDate>Mon, 03 Jan 2022 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927284/1190249227_tim_callan_root_causes_196_what_is_certificate_agnostic.mp3" length="15055932" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In 2021 the certificate industry saw the emergency of the concept of "CA agnostic." However, that is only part of the story.   In this episode our hosts build on this concept to define the idea of certificate automation platforms being "certificate...</itunes:subtitle><itunes:summary><![CDATA[In 2021 the certificate industry saw the emergency of the concept of "CA agnostic." However, that is only part of the story.   In this episode our hosts build on this concept to define the idea of certificate automation platforms being "certificate agnostic," meaning these platforms should handle all certificates regardless of type, configuration, physical location, environment, use case, and origin.]]></itunes:summary><itunes:duration>627</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 195: iOS App Privacy Audits</title><link>https://www.spreaker.com/episode/root-causes-195-ios-app-privacy-audits--52927656</link><description><![CDATA[The latest update of iOS includes new capabilities for app privacy auditing and permissions. Our hosts explain the controls available on iOS and Android and how a mobile device privacy audit can be beneficial.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1185847021</guid><pubDate>Mon, 27 Dec 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927656/1185847021_tim_callan_root_causes_195_ios_app_privacy_audits.mp3" length="8591996" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The latest update of iOS includes new capabilities for app privacy auditing and permissions. Our hosts explain the controls available on iOS and Android and how a mobile device privacy audit can be beneficial.</itunes:subtitle><itunes:summary><![CDATA[The latest update of iOS includes new capabilities for app privacy auditing and permissions. Our hosts explain the controls available on iOS and Android and how a mobile device privacy audit can be beneficial.]]></itunes:summary><itunes:duration>358</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 194: Crypto Versus Cryptocurrency</title><link>https://www.spreaker.com/episode/root-causes-194-crypto-versus-cryptocurrency--52926133</link><description><![CDATA[Exploding interest in cryptocurrency has caused the word crypto to take on new meanings that were not part of the public dialog even a few years ago. In this episode our hosts explore both the overlap and difference between today's cryptocurrency (and blockchain) and more venerable forms of cryptography.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1181372983</guid><pubDate>Mon, 20 Dec 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926133/1181372983_tim_callan_root_causes_194_crypto_versus_cryptocurrency.mp3" length="19909441" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Exploding interest in cryptocurrency has caused the word crypto to take on new meanings that were not part of the public dialog even a few years ago. In this episode our hosts explore both the overlap and difference between today's cryptocurrency (and...</itunes:subtitle><itunes:summary><![CDATA[Exploding interest in cryptocurrency has caused the word crypto to take on new meanings that were not part of the public dialog even a few years ago. In this episode our hosts explore both the overlap and difference between today's cryptocurrency (and blockchain) and more venerable forms of cryptography.]]></itunes:summary><itunes:duration>831</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 193: 4 Positive Security Trends for 2022</title><link>https://www.spreaker.com/episode/root-causes-193-4-positive-security-trends-for-2022--52927628</link><description><![CDATA[Our hosts look back at four positive security trends in 2021 that industry should continue in 2022.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1179263212</guid><pubDate>Thu, 16 Dec 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927628/1179263212_tim_callan_root_causes_193_4_positive_security_trends_for_2022.mp3" length="22870298" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Our hosts look back at four positive security trends in 2021 that industry should continue in 2022.</itunes:subtitle><itunes:summary><![CDATA[Our hosts look back at four positive security trends in 2021 that industry should continue in 2022.]]></itunes:summary><itunes:duration>954</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 192: 14 Security Fallacies We Still Have in 2021</title><link>https://www.spreaker.com/episode/root-causes-192-14-security-fallacies-we-still-have-in-2021--52926794</link><description><![CDATA[In this year-end lookback episode, our hosts describe 14 common fallacies that still haunt IT professionals in 2021 - and the negative effects those fallacies bring.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1177134874</guid><pubDate>Mon, 13 Dec 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926794/1177134874_tim_callan_root_causes_192_14_security_fallacies_we_still_have_in_2021.mp3" length="35231411" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this year-end lookback episode, our hosts describe 14 common fallacies that still haunt IT professionals in 2021 - and the negative effects those fallacies bring.</itunes:subtitle><itunes:summary><![CDATA[In this year-end lookback episode, our hosts describe 14 common fallacies that still haunt IT professionals in 2021 - and the negative effects those fallacies bring.]]></itunes:summary><itunes:duration>1470</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 191: What Is Robotic Process Automation (RPA)?</title><link>https://www.spreaker.com/episode/root-causes-191-what-is-robotic-process-automation-rpa--52926854</link><description><![CDATA[An important trend sweeping enterprise IT is Robotic Process Automation. Our hosts define RPA and explain the importance of cryptographically secured digital identity in safely implementing RPA.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1174241335</guid><pubDate>Wed, 08 Dec 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926854/1174241335_tim_callan_root_causes_191_what_is_robotic_process_automation_rpa.mp3" length="21372379" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>An important trend sweeping enterprise IT is Robotic Process Automation. Our hosts define RPA and explain the importance of cryptographically secured digital identity in safely implementing RPA.</itunes:subtitle><itunes:summary><![CDATA[An important trend sweeping enterprise IT is Robotic Process Automation. Our hosts define RPA and explain the importance of cryptographically secured digital identity in safely implementing RPA.]]></itunes:summary><itunes:duration>892</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 190: Phishing Coinbase</title><link>https://www.spreaker.com/episode/root-causes-190-phishing-coinbase--52927665</link><description><![CDATA[In continuation of our ongoing exploration of blockchain and cryptocurrency, our hosts describe a recently discovered exploit where attackers use weaknesses in one-time-password-based MFA to steal Coinbase accounts.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1168870915</guid><pubDate>Mon, 29 Nov 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927665/1168870915_tim_callan_root_causes_190_phishing_coinbase.mp3" length="12934969" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In continuation of our ongoing exploration of blockchain and cryptocurrency, our hosts describe a recently discovered exploit where attackers use weaknesses in one-time-password-based MFA to steal Coinbase accounts.</itunes:subtitle><itunes:summary><![CDATA[In continuation of our ongoing exploration of blockchain and cryptocurrency, our hosts describe a recently discovered exploit where attackers use weaknesses in one-time-password-based MFA to steal Coinbase accounts.]]></itunes:summary><itunes:duration>539</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 189: What Is CA Agnostic?</title><link>https://www.spreaker.com/episode/root-causes-189-what-is-ca-agnostic--52926121</link><description><![CDATA[Certificate Lifecycle Management (CLM) platforms can deal with certificates from a number of sources. A CLM that can provision certificates of all types from all CAs, private and public, would be described as "CA agnostic." In this episode we explain this idea and its significance along with the key criteria for choosing a CA agnostic CLM platform.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1161647932</guid><pubDate>Wed, 17 Nov 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926121/1161647932_tim_callan_root_causes_189_what_is_ca_agnostic.mp3" length="24348901" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certificate Lifecycle Management (CLM) platforms can deal with certificates from a number of sources. A CLM that can provision certificates of all types from all CAs, private and public, would be described as "CA agnostic." In this episode we explain...</itunes:subtitle><itunes:summary><![CDATA[Certificate Lifecycle Management (CLM) platforms can deal with certificates from a number of sources. A CLM that can provision certificates of all types from all CAs, private and public, would be described as "CA agnostic." In this episode we explain this idea and its significance along with the key criteria for choosing a CA agnostic CLM platform.]]></itunes:summary><itunes:duration>1015</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 188: Introduction to Web Security</title><link>https://www.spreaker.com/episode/root-causes-188-introduction-to-web-security--52927647</link><description><![CDATA[Malware and other web site attacks are a frequent problem for small businesses and can result in reputational damage and site access being blocked or hindered by end user software and services. We are joined by web site protection expert JP Armenta, who explains how these attacks occur, their effects, and how site operators can protect themselves.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1158833449</guid><pubDate>Thu, 11 Nov 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52927647/1158833449_tim_callan_root_causes_188_introduction_to_web_security.mp3" length="29277645" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Malware and other web site attacks are a frequent problem for small businesses and can result in reputational damage and site access being blocked or hindered by end user software and services. We are joined by web site protection expert JP Armenta,...</itunes:subtitle><itunes:summary><![CDATA[Malware and other web site attacks are a frequent problem for small businesses and can result in reputational damage and site access being blocked or hindered by end user software and services. We are joined by web site protection expert JP Armenta, who explains how these attacks occur, their effects, and how site operators can protect themselves.]]></itunes:summary><itunes:duration>1220</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 187: Apple Limits Term for S/MIME Certificates</title><link>https://www.spreaker.com/episode/root-causes-187-apple-limits-term-for-s-mime-certificates--52926755</link><description><![CDATA[Apple recently announced that it would be limiting the allowable term for public S/MIME certificates to 825 days. Our hosts explain the implications of this declaration.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1156387924</guid><pubDate>Sun, 07 Nov 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926755/1156387924_tim_callan_root_causes_187_apple_limits_term_for_smime_certificates.mp3" length="24343226" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Apple recently announced that it would be limiting the allowable term for public S/MIME certificates to 825 days. Our hosts explain the implications of this declaration.</itunes:subtitle><itunes:summary><![CDATA[Apple recently announced that it would be limiting the allowable term for public S/MIME certificates to 825 days. Our hosts explain the implications of this declaration.]]></itunes:summary><itunes:duration>1014</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 186: Digital Signature SNAFU Costs Swiss Company 3 Billion Euro Contract</title><link>https://www.spreaker.com/episode/root-causes-186-digital-signature-snafu-costs-swiss-company-3-billion-euro-contract--52928443</link><description><![CDATA[In this episode our hosts explain how an esoteric digital signature error rendered a 3 billion Euro manufacturing contract with the Austrian government invalid.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1154064493</guid><pubDate>Thu, 04 Nov 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928443/1154064493_tim_callan_root_causes_186_digital_signature_snafu_costs_swiss_company_3_billion_euro_contract.mp3" length="28885381" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode our hosts explain how an esoteric digital signature error rendered a 3 billion Euro manufacturing contract with the Austrian government invalid.</itunes:subtitle><itunes:summary><![CDATA[In this episode our hosts explain how an esoteric digital signature error rendered a 3 billion Euro manufacturing contract with the Austrian government invalid.]]></itunes:summary><itunes:duration>1204</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 185: EU Covid Passport Root Key Stolen</title><link>https://www.spreaker.com/episode/root-causes-185-eu-covid-passport-root-key-stolen--52926871</link><description><![CDATA[The root certificates of the EU's Covid Passport program have suffered a private key compromise and counterfeit passports are now for sale on the black market. We explain the implications of this shocking revelation.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1152632827</guid><pubDate>Mon, 01 Nov 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926871/1152632827_tim_callan_root_causes_185_eu_covid_passport_root_key_stolen.mp3" length="24480225" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The root certificates of the EU's Covid Passport program have suffered a private key compromise and counterfeit passports are now for sale on the black market. We explain the implications of this shocking revelation.</itunes:subtitle><itunes:summary><![CDATA[The root certificates of the EU's Covid Passport program have suffered a private key compromise and counterfeit passports are now for sale on the black market. We explain the implications of this shocking revelation.]]></itunes:summary><itunes:duration>1020</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 184: Popular College WiFi Vulnerability Revealed</title><link>https://www.spreaker.com/episode/root-causes-184-popular-college-wifi-vulnerability-revealed--52926870</link><description><![CDATA[Recent research reveals that certificate misconfiguration in a commonly used college WiFi platform that can lead to exposure and theft of users' login credentials. Our hosts discuss WiFi authentication and the EAP protocol and explain how this vulnerability occurs.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1149073429</guid><pubDate>Tue, 26 Oct 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926870/1149073429_tim_callan_root_causes_184_popular_college_wifi_vulnerability_revealed.mp3" length="17298563" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent research reveals that certificate misconfiguration in a commonly used college WiFi platform that can lead to exposure and theft of users' login credentials. Our hosts discuss WiFi authentication and the EAP protocol and explain how this...</itunes:subtitle><itunes:summary><![CDATA[Recent research reveals that certificate misconfiguration in a commonly used college WiFi platform that can lead to exposure and theft of users' login credentials. Our hosts discuss WiFi authentication and the EAP protocol and explain how this vulnerability occurs.]]></itunes:summary><itunes:duration>721</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 183: New MSCA Attack Toolkits</title><link>https://www.spreaker.com/episode/root-causes-183-new-msca-attack-toolkits--52926790</link><description><![CDATA[At this year's BlackHat, a talk and white paper detailed the threat of MSCA root key attacks, which can be used to create unauthorized certificates.  This release includes a pair of offensive toolkits and a defensive toolkit.  We explain the importance of this release and provide a clear action list for IT professionals in charge of Microsoft CA.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1145567782</guid><pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52926790/1145567782_tim_callan_root_causes_183_new_msca_attack_toolkits.mp3" length="20604975" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>At this year's BlackHat, a talk and white paper detailed the threat of MSCA root key attacks, which can be used to create unauthorized certificates.  This release includes a pair of offensive toolkits and a defensive toolkit.  We explain the...</itunes:subtitle><itunes:summary><![CDATA[At this year's BlackHat, a talk and white paper detailed the threat of MSCA root key attacks, which can be used to create unauthorized certificates.  This release includes a pair of offensive toolkits and a defensive toolkit.  We explain the importance of this release and provide a clear action list for IT professionals in charge of Microsoft CA.]]></itunes:summary><itunes:duration>859</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 182: Let's Encrypt Root Expiration</title><link>https://www.spreaker.com/episode/root-causes-182-let-s-encrypt-root-expiration--52928487</link><description><![CDATA[Let's Encrypt's recent root expiration caused widespread service outages and other hassles for online services and sites. Our hosts discuss this expiration, why so many problems resulted, and the recipe for avoiding these problems in the future.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1143877063</guid><pubDate>Mon, 18 Oct 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52928487/1143877063_tim_callan_root_causes_182_lets_encrypt_root_expiration.mp3" length="36697179" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Let's Encrypt's recent root expiration caused widespread service outages and other hassles for online services and sites. Our hosts discuss this expiration, why so many problems resulted, and the recipe for avoiding these problems in the future.</itunes:subtitle><itunes:summary><![CDATA[Let's Encrypt's recent root expiration caused widespread service outages and other hassles for online services and sites. Our hosts discuss this expiration, why so many problems resulted, and the recipe for avoiding these problems in the future.]]></itunes:summary><itunes:duration>1529</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/45547d9939db967a9df2ce47442a8245.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 179: Standards for Certificates Apart from SSL</title><link>https://www.spreaker.com/episode/root-causes-179-standards-for-certificates-apart-from-ssl--46456005</link><description><![CDATA[Regular followers of this podcast hear a great deal about SSL, the CA/Browser Forum, and the standards governing public SSL. But SSL is not the only regulated type of public digital certificate. There are also things like S/MIME, eIDAS, code signing, document signing, and SSH certificates.  In this episode our hosts discuss these "other" certificate types and the rules and regulations governing them.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1112042269</guid><pubDate>Mon, 23 Aug 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/46456005/1112042269_tim_callan_root_causes_179_standards_for_certificates_apart_from_ssl.mp3" length="20718964" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Regular followers of this podcast hear a great deal about SSL, the CA/Browser Forum, and the standards governing public SSL. But SSL is not the only regulated type of public digital certificate. There are also things like S/MIME, eIDAS, code signing,...</itunes:subtitle><itunes:summary><![CDATA[Regular followers of this podcast hear a great deal about SSL, the CA/Browser Forum, and the standards governing public SSL. But SSL is not the only regulated type of public digital certificate. There are also things like S/MIME, eIDAS, code signing, document signing, and SSH certificates.  In this episode our hosts discuss these "other" certificate types and the rules and regulations governing them.]]></itunes:summary><itunes:duration>863</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 155: What’s Good for Subscribers Is Good for Relying Parties</title><link>https://www.spreaker.com/episode/root-causes-155-what-s-good-for-subscribers-is-good-for-relying-parties--43877496</link><description><![CDATA[In this episode we explore the relationship between Relying Parties (aka users of online services) and Certificate Subscribers (aka providers of these services). We discuss the common attitude that certificate requirements that negatively impact Subscribers are inconsequential. We explain the downstream effects of certificate incidents and why unthinkingly forcing rules on service providers without considering the full consequences is detrimental to everyone.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1004942434</guid><pubDate>Thu, 11 Mar 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43877496/1004942434_tim_callan_root_causes_155_whats_good_for_subscribers_is_good_for_relying_parties.mp3" length="22085673" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In this episode we explore the relationship between Relying Parties (aka users of online services) and Certificate Subscribers (aka providers of these services). We discuss the common attitude that certificate requirements that negatively impact...</itunes:subtitle><itunes:summary><![CDATA[In this episode we explore the relationship between Relying Parties (aka users of online services) and Certificate Subscribers (aka providers of these services). We discuss the common attitude that certificate requirements that negatively impact Subscribers are inconsequential. We explain the downstream effects of certificate incidents and why unthinkingly forcing rules on service providers without considering the full consequences is detrimental to everyone.]]></itunes:summary><itunes:duration>922</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 154: Did Claus Peter Schnorr Just Break RSA?</title><link>https://www.spreaker.com/episode/root-causes-154-did-claus-peter-schnorr-just-break-rsa--43877499</link><description><![CDATA[A recently published paper by a reputable German mathematician and cryptographer has garnered widespread attention for its claim to have destroyed the RSA algorithm. However, many people are skeptical. Join us as we discuss the paper's content, the proposed methodology, and the public discussion it has generated.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/1001395021</guid><pubDate>Mon, 08 Mar 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43877499/1001395021_tim_callan_root_causes_154_did_claus_peter_schnorr_just_break_rsa.mp3" length="25542363" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recently published paper by a reputable German mathematician and cryptographer has garnered widespread attention for its claim to have destroyed the RSA algorithm. However, many people are skeptical. Join us as we discuss the paper's content, the...</itunes:subtitle><itunes:summary><![CDATA[A recently published paper by a reputable German mathematician and cryptographer has garnered widespread attention for its claim to have destroyed the RSA algorithm. However, many people are skeptical. Join us as we discuss the paper's content, the proposed methodology, and the public discussion it has generated.]]></itunes:summary><itunes:duration>1066</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 153: Too Many Roots</title><link>https://www.spreaker.com/episode/root-causes-153-too-many-roots--43877500</link><description><![CDATA[Trust models in multi-vendor environments can be particularly tricky. <br /> We are joined once again by Tom Tansy, Chairman of the SunSpec Alliance for a deep dive in the challenges and best practices in maintaining trusted roots in complex, global supply chain ecosystems.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/999359203</guid><pubDate>Fri, 05 Mar 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43877500/999359203_tim_callan_root_causes_153_too_many_roots.mp3" length="33605901" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Trust models in multi-vendor environments can be particularly tricky. 
 We are joined once again by Tom Tansy, Chairman of the SunSpec Alliance for a deep dive in the challenges and best practices in maintaining trusted roots in complex, global supply...</itunes:subtitle><itunes:summary><![CDATA[Trust models in multi-vendor environments can be particularly tricky. <br /> We are joined once again by Tom Tansy, Chairman of the SunSpec Alliance for a deep dive in the challenges and best practices in maintaining trusted roots in complex, global supply chain ecosystems.]]></itunes:summary><itunes:duration>1402</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 152: Digital Certificates and the SunSpec Alliance</title><link>https://www.spreaker.com/episode/root-causes-152-digital-certificates-and-the-sunspec-alliance--43877498</link><description><![CDATA[The SunSpec Alliance is an important source of standards for clean energy infrastructure including solar and electric vehicles. To protect our electrical infrastructure and ensure proper functioning, digital identity and certificates are a necessity. Join us and guest Tom Tansy as we discuss how SunSpec employs PKI to this end.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/997187194</guid><pubDate>Tue, 02 Mar 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43877498/997187194_tim_callan_root_causes_152_digital_certificates_and_the_sunspec_alliance.mp3" length="31216572" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The SunSpec Alliance is an important source of standards for clean energy infrastructure including solar and electric vehicles. To protect our electrical infrastructure and ensure proper functioning, digital identity and certificates are a necessity....</itunes:subtitle><itunes:summary><![CDATA[The SunSpec Alliance is an important source of standards for clean energy infrastructure including solar and electric vehicles. To protect our electrical infrastructure and ensure proper functioning, digital identity and certificates are a necessity. Join us and guest Tom Tansy as we discuss how SunSpec employs PKI to this end.]]></itunes:summary><itunes:duration>1303</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 150: This Podcast Is Not About Alan Turing</title><link>https://www.spreaker.com/episode/root-causes-150-this-podcast-is-not-about-alan-turing--43660412</link><description><![CDATA[Recent news of the discovery of abandoned Enigma machines on the ocean floor inspires our hosts to discuss history's most famous code system, how it was broken, and how that relates to cryptography today.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/986925886</guid><pubDate>Sun, 14 Feb 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43660412/986925886_tim_callan_root_causes_150_this_podcast_is_not_about_alan_turing.mp3" length="24025731" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent news of the discovery of abandoned Enigma machines on the ocean floor inspires our hosts to discuss history's most famous code system, how it was broken, and how that relates to cryptography today.</itunes:subtitle><itunes:summary><![CDATA[Recent news of the discovery of abandoned Enigma machines on the ocean floor inspires our hosts to discuss history's most famous code system, how it was broken, and how that relates to cryptography today.]]></itunes:summary><itunes:duration>1003</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 148: Can Australia Force Sites to Pay for Linking to Content?</title><link>https://www.spreaker.com/episode/root-causes-148-can-australia-force-sites-to-pay-for-linking-to-content--43414634</link><description><![CDATA[A proposed law in Australia would require sites linking to news articles to pay for the right to link to these articles. While this law appears to be aimed at Google and Facebook, it has implications that are much bigger than these two news aggregators. Google has upped the ante by offering to cease operations in Australia before doing so. In this episode we discuss this ongoing development and where things go from here.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/981539350</guid><pubDate>Mon, 08 Feb 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43414634/981539350_tim_callan_root_causes_148_can_australia_force_sites_to_pay_for_linking_to_content.mp3" length="23369675" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A proposed law in Australia would require sites linking to news articles to pay for the right to link to these articles. While this law appears to be aimed at Google and Facebook, it has implications that are much bigger than these two news...</itunes:subtitle><itunes:summary><![CDATA[A proposed law in Australia would require sites linking to news articles to pay for the right to link to these articles. While this law appears to be aimed at Google and Facebook, it has implications that are much bigger than these two news aggregators. Google has upped the ante by offering to cease operations in Australia before doing so. In this episode we discuss this ongoing development and where things go from here.]]></itunes:summary><itunes:duration>975</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 144: Whatever Happened to the Green Address Bar?</title><link>https://www.spreaker.com/episode/root-causes-144-whatever-happened-to-the-green-address-bar--43158417</link><description><![CDATA[For more than a decade browsers displayed the "green address bar" on sites that had undergone the high authentication required for EV SSL certificates. But in recent years the identity information in the browser has has shrunk, lost its color, and in some cases disappeared entirely. In this episode our hosts walk you through the history of how the green address bar came to be and how browsers gradually reduced and then removed it.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/973295860</guid><pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43158417/973295860_tim_callan_root_causes_144_whatever_happened_to_the_green_address_bar.mp3" length="19539816" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>For more than a decade browsers displayed the "green address bar" on sites that had undergone the high authentication required for EV SSL certificates. But in recent years the identity information in the browser has has shrunk, lost its color, and in...</itunes:subtitle><itunes:summary><![CDATA[For more than a decade browsers displayed the "green address bar" on sites that had undergone the high authentication required for EV SSL certificates. But in recent years the identity information in the browser has has shrunk, lost its color, and in some cases disappeared entirely. In this episode our hosts walk you through the history of how the green address bar came to be and how browsers gradually reduced and then removed it.]]></itunes:summary><itunes:duration>816</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 142: Removing Street Address and Postal Code from Public Certificates</title><link>https://www.spreaker.com/episode/root-causes-142-removing-street-address-and-postal-code-from-public-certificates--43158419</link><description><![CDATA[On March 1 Sectigo will remove street address and postal/zip code information from its public certificates of all types. Our hosts explain the reasons for and advantages of this upcoming change, along with answers to some of the common questions we receive.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/968048287</guid><pubDate>Mon, 18 Jan 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43158419/968048287_tim_callan_root_causes_142_removing_street_address_and_postal_code_from_public_certificates.mp3" length="17722516" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On March 1 Sectigo will remove street address and postal/zip code information from its public certificates of all types. Our hosts explain the reasons for and advantages of this upcoming change, along with answers to some of the common questions we...</itunes:subtitle><itunes:summary><![CDATA[On March 1 Sectigo will remove street address and postal/zip code information from its public certificates of all types. Our hosts explain the reasons for and advantages of this upcoming change, along with answers to some of the common questions we receive.]]></itunes:summary><itunes:duration>740</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 141: The Case for Shorter Certificate Lifespans</title><link>https://www.spreaker.com/episode/root-causes-141-the-case-for-shorter-certificate-lifespans--42912107</link><description><![CDATA[Recent years have seen multiple reductions in the maximum term for public SSL certificates. Our hosts are joined by guest Nick France to discuss the benefits of shorter certificate lifespans for both public and private CAs.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/963715132</guid><pubDate>Mon, 11 Jan 2021 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42912107/963715132_tim_callan_root_causes_141_the_case_for_shorter_certificate_lifespans.mp3" length="26748753" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent years have seen multiple reductions in the maximum term for public SSL certificates. Our hosts are joined by guest Nick France to discuss the benefits of shorter certificate lifespans for both public and private CAs.</itunes:subtitle><itunes:summary><![CDATA[Recent years have seen multiple reductions in the maximum term for public SSL certificates. Our hosts are joined by guest Nick France to discuss the benefits of shorter certificate lifespans for both public and private CAs.]]></itunes:summary><itunes:duration>1116</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 137: SolarWinds Supply Chain Attack and Digital Identity</title><link>https://www.spreaker.com/episode/root-causes-137-solarwinds-supply-chain-attack-and-digital-identity--42701941</link><description><![CDATA[The SolarWinds Orion supply chain attack is making headlines throughout the tech press. This sophisticated attack includes some unusual manipulations of digital identity and certificates. In this episode we explain how certificates, keys, and identity play into the SolarWinds exploit.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/951929677</guid><pubDate>Mon, 21 Dec 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42701941/951929677_tim_callan_root_causes_137_solarwinds_supply_chain_attack_and_digital_identity.mp3" length="44366057" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The SolarWinds Orion supply chain attack is making headlines throughout the tech press. This sophisticated attack includes some unusual manipulations of digital identity and certificates. In this episode we explain how certificates, keys, and identity...</itunes:subtitle><itunes:summary><![CDATA[The SolarWinds Orion supply chain attack is making headlines throughout the tech press. This sophisticated attack includes some unusual manipulations of digital identity and certificates. In this episode we explain how certificates, keys, and identity play into the SolarWinds exploit.]]></itunes:summary><itunes:duration>1851</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 136: 2020 Lookback - Quantum Safe Certificates</title><link>https://www.spreaker.com/episode/root-causes-136-2020-lookback-quantum-safe-certificates--42701940</link><description><![CDATA[In the third of our year-end lookback episodes, we discuss 2020's progress in the quest for quantum-safe encryption. This includes narrowing the NIST candidate list down to fifteen algorithms, the availability of test hybrid certificates, and the trouble with long-lived IoT devices. Our hosts predict what 2021 will look like for quantum-safe certificates.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/949649428</guid><pubDate>Thu, 17 Dec 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42701940/949649428_tim_callan_root_causes_136_2020_lookback_quantum_safe_certificates.mp3" length="20744844" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In the third of our year-end lookback episodes, we discuss 2020's progress in the quest for quantum-safe encryption. This includes narrowing the NIST candidate list down to fifteen algorithms, the availability of test hybrid certificates, and the...</itunes:subtitle><itunes:summary><![CDATA[In the third of our year-end lookback episodes, we discuss 2020's progress in the quest for quantum-safe encryption. This includes narrowing the NIST candidate list down to fifteen algorithms, the availability of test hybrid certificates, and the trouble with long-lived IoT devices. Our hosts predict what 2021 will look like for quantum-safe certificates.]]></itunes:summary><itunes:duration>866</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 135: The Heartbleed Vulnerability</title><link>https://www.spreaker.com/episode/root-causes-135-the-heartbleed-vulnerability--42701943</link><description><![CDATA[In April 2014 a software vulnerability called Heartbleed was discovered in OpenSSL. Heartbleed made it possible for attackers to send commands to web servers and steal their private keys. Certificate subscribers around the world had to scramble to patch their servers and replace certificates by the millions. Guest Nick France joins us to explain this vulnerability, its consequences, and whether or not a Heartbleed-like vulnerability could occur today.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/947491852</guid><pubDate>Mon, 14 Dec 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42701943/947491852_tim_callan_root_causes_135_the_heartbleed_vulnerability.mp3" length="35671060" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In April 2014 a software vulnerability called Heartbleed was discovered in OpenSSL. Heartbleed made it possible for attackers to send commands to web servers and steal their private keys. Certificate subscribers around the world had to scramble to...</itunes:subtitle><itunes:summary><![CDATA[In April 2014 a software vulnerability called Heartbleed was discovered in OpenSSL. Heartbleed made it possible for attackers to send commands to web servers and steal their private keys. Certificate subscribers around the world had to scramble to patch their servers and replace certificates by the millions. Guest Nick France joins us to explain this vulnerability, its consequences, and whether or not a Heartbleed-like vulnerability could occur today.]]></itunes:summary><itunes:duration>1489</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 132: Examining MFA Through Soft Tokens</title><link>https://www.spreaker.com/episode/root-causes-132-examining-mfa-through-soft-tokens--42476253</link><description><![CDATA[In our ongoing examination of MFA, our hosts examine authentication through soft-token OTP (one-time passcode). They go over the potential benefits and pitfalls of soft tokens, and compare them to SMS tokens and hard tokens.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/941507815</guid><pubDate>Fri, 04 Dec 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42476253/941507815_tim_callan_root_causes_132_examining_mfa_through_soft_tokens.mp3" length="24145274" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing examination of MFA, our hosts examine authentication through soft-token OTP (one-time passcode). They go over the potential benefits and pitfalls of soft tokens, and compare them to SMS tokens and hard tokens.</itunes:subtitle><itunes:summary><![CDATA[In our ongoing examination of MFA, our hosts examine authentication through soft-token OTP (one-time passcode). They go over the potential benefits and pitfalls of soft tokens, and compare them to SMS tokens and hard tokens.]]></itunes:summary><itunes:duration>1008</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 130: How to Get Rid of Password Breaches</title><link>https://www.spreaker.com/episode/root-causes-130-how-to-get-rid-of-password-breaches--42222527</link><description><![CDATA[Massive password breeches have been so repeatedly prevalent for so many years that as an industry and a society we've just started to accept them as a fact of life. In this episode we discuss the weaknesses of passwords as a strategy and why they nonetheless are so common even today. We describe the roadmap for eventually weeding out passwords from most systems.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/935180389</guid><pubDate>Tue, 24 Nov 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42222527/935180389_tim_callan_root_causes_130_how_to_get_rid_of_password_breaches.mp3" length="22991429" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Massive password breeches have been so repeatedly prevalent for so many years that as an industry and a society we've just started to accept them as a fact of life. In this episode we discuss the weaknesses of passwords as a strategy and why they...</itunes:subtitle><itunes:summary><![CDATA[Massive password breeches have been so repeatedly prevalent for so many years that as an industry and a society we've just started to accept them as a fact of life. In this episode we discuss the weaknesses of passwords as a strategy and why they nonetheless are so common even today. We describe the roadmap for eventually weeding out passwords from most systems.]]></itunes:summary><itunes:duration>960</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 129: Examining MFA Through Hard Tokens</title><link>https://www.spreaker.com/episode/root-causes-129-examining-mfa-through-hard-tokens--42222526</link><description><![CDATA[Hard tokens are one of the oldest multi-factor authentication (MFA) form factors there is, and still in use today. In the latest in our series of explorations of MFA strategies, we examine the strengths and weaknesses of hard tokens as an MFA strategy.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/932271430</guid><pubDate>Thu, 19 Nov 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42222526/932271430_tim_callan_root_causes_129_examining_mfa_through_hard_tokens.mp3" length="21946758" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Hard tokens are one of the oldest multi-factor authentication (MFA) form factors there is, and still in use today. In the latest in our series of explorations of MFA strategies, we examine the strengths and weaknesses of hard tokens as an MFA strategy.</itunes:subtitle><itunes:summary><![CDATA[Hard tokens are one of the oldest multi-factor authentication (MFA) form factors there is, and still in use today. In the latest in our series of explorations of MFA strategies, we examine the strengths and weaknesses of hard tokens as an MFA strategy.]]></itunes:summary><itunes:duration>916</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 127: What Does a Chief Compliance Officer at a Public CA Do?</title><link>https://www.spreaker.com/episode/root-causes-127-what-does-a-chief-compliance-officer-at-a-public-ca-do--41971114</link><description><![CDATA[Our co-host Tim Callan has changed his title to Chief Compliance Officer. Join him and co-host Jason Soroko as they discuss what compliance means at a public Certificate Authority (CA) like Sectigo and what the Chief Compliance Officer does.]]></description><guid isPermaLink="false">tag:soundcloud,2010:tracks/923830939</guid><pubDate>Thu, 05 Nov 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41971114/923830939_tim_callan_root_causes_127_what_does_a_chief_compliance_officer_at_a_public_ca_do.mp3" length="20341669" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Our co-host Tim Callan has changed his title to Chief Compliance Officer. Join him and co-host Jason Soroko as they discuss what compliance means at a public Certificate Authority (CA) like Sectigo and what the Chief Compliance Officer does.</itunes:subtitle><itunes:summary><![CDATA[Our co-host Tim Callan has changed his title to Chief Compliance Officer. Join him and co-host Jason Soroko as they discuss what compliance means at a public Certificate Authority (CA) like Sectigo and what the Chief Compliance Officer does.]]></itunes:summary><itunes:duration>849</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bc1f767264082656e76e10ba805517d5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 81: What Is Embedded Firewall?</title><link>https://www.spreaker.com/episode/root-causes-81-what-is-embedded-firewall--70329997</link><description><![CDATA[Security for IoT devices depends not only on establishing strong identity mechanisms for devices and the services they connect to but also in ensuring the ongoing integrity of device operations. In this episode our hosts are joined by guest Alan Grau to explain what an embedded firewall is and how it aids security for connected devices.]]></description><guid isPermaLink="false">91e24487-f013-49d5-8b2d-83638cc095c0</guid><pubDate>Mon, 06 Apr 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329997/128_default_tc.mp3" length="14014341" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Security for IoT devices depends not only on establishing strong identity mechanisms for devices and the services they connect to but also in ensuring the ongoing integrity of device operations. In this episode our hosts are joined by guest Alan Grau...</itunes:subtitle><itunes:summary><![CDATA[Security for IoT devices depends not only on establishing strong identity mechanisms for devices and the services they connect to but also in ensuring the ongoing integrity of device operations. In this episode our hosts are joined by guest Alan Grau to explain what an embedded firewall is and how it aids security for connected devices.]]></itunes:summary><itunes:duration>876</itunes:duration><itunes:keywords>cybersecurity,embedded,firewall,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e414de4028c44edfbf4ddf022483a3dc.jpg"/><itunes:episode>81</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 80: The Pros and Cons of VPNs</title><link>https://www.spreaker.com/episode/root-causes-80-the-pros-and-cons-of-vpns--70329978</link><description><![CDATA[With the sudden, meteoric increase in remote workers, many IT professionals are looking at VPN as a method of keeping them secure.  Join our hosts as they discuss the advantages and disadvantages of VPNs, and what to look out for.]]></description><guid isPermaLink="false">0ebed29c-9c40-4409-b928-bffb0571ffbf</guid><pubDate>Thu, 02 Apr 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329978/128_default_tc.mp3" length="15722958" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>With the sudden, meteoric increase in remote workers, many IT professionals are looking at VPN as a method of keeping them secure.  Join our hosts as they discuss the advantages and disadvantages of VPNs, and what to look out for.</itunes:subtitle><itunes:summary><![CDATA[With the sudden, meteoric increase in remote workers, many IT professionals are looking at VPN as a method of keeping them secure.  Join our hosts as they discuss the advantages and disadvantages of VPNs, and what to look out for.]]></itunes:summary><itunes:duration>983</itunes:duration><itunes:keywords>cybersecurity,pki,vpn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/302f36e2a592fde60920a0fb1f84d51b.jpg"/><itunes:episode>80</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 79: Firefox Reinstates Support for Deprecated TLS Versions</title><link>https://www.spreaker.com/episode/root-causes-79-firefox-reinstates-support-for-deprecated-tls-versions--70329996</link><description><![CDATA[To enable broadest possible access to valuable information about the COVID-19 epidemic, Firefox has chosen to reinstate support for web sites using TLS 1.0 and 1.1. Join us to learn about this move, why Firefox has made it, and what that says about the state of web site security today.]]></description><guid isPermaLink="false">b84743d1-92fc-4acb-9952-44ed5f2b0d93</guid><pubDate>Mon, 30 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329996/128_default_tc.mp3" length="10975349" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>To enable broadest possible access to valuable information about the COVID-19 epidemic, Firefox has chosen to reinstate support for web sites using TLS 1.0 and 1.1. Join us to learn about this move, why Firefox has made it, and what that says about...</itunes:subtitle><itunes:summary><![CDATA[To enable broadest possible access to valuable information about the COVID-19 epidemic, Firefox has chosen to reinstate support for web sites using TLS 1.0 and 1.1. Join us to learn about this move, why Firefox has made it, and what that says about the state of web site security today.]]></itunes:summary><itunes:duration>686</itunes:duration><itunes:keywords>firefox,pki,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>79</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 78: Extended Validation Certificates and the Dark Web</title><link>https://www.spreaker.com/episode/root-causes-78-extended-validation-certificates-and-the-dark-web--70329975</link><description><![CDATA[New research presented at RSA Security Expo indicates that at least one party is using online criminal marketplaces to sell a package of a newly-created business and at least one Extended Validation SSL certificate to go with it.  Join our hosts as they explain what the research says and talk about the potential criminal use cases for a bundle like this one.]]></description><guid isPermaLink="false">025533d3-5076-4c24-9a29-c8a4e89b93bd</guid><pubDate>Thu, 26 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329975/128_default_tc.mp3" length="14111308" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>New research presented at RSA Security Expo indicates that at least one party is using online criminal marketplaces to sell a package of a newly-created business and at least one Extended Validation SSL certificate to go with it.  Join our hosts as...</itunes:subtitle><itunes:summary><![CDATA[New research presented at RSA Security Expo indicates that at least one party is using online criminal marketplaces to sell a package of a newly-created business and at least one Extended Validation SSL certificate to go with it.  Join our hosts as they explain what the research says and talk about the potential criminal use cases for a bundle like this one.]]></itunes:summary><itunes:duration>882</itunes:duration><itunes:keywords>certificates,dark web,ev,pki,webpki,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>78</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 77: Certificates for Public Cloud</title><link>https://www.spreaker.com/episode/root-causes-77-certificates-for-public-cloud--70329976</link><description><![CDATA[As a convenience to customers and a competitive differentiator, public cloud services such as AWS offer TLS certificates for use in their environments. Join our hosts as they explain this practice, how these certificates can be used, and which use cases and environments will not work with TLS certificates from public cloud vendors.]]></description><guid isPermaLink="false">2b97cbef-dcc6-440d-85d3-e20f9de4bb60</guid><pubDate>Mon, 23 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329976/128_default_tc.mp3" length="8988800" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As a convenience to customers and a competitive differentiator, public cloud services such as AWS offer TLS certificates for use in their environments. Join our hosts as they explain this practice, how these certificates can be used, and which use...</itunes:subtitle><itunes:summary><![CDATA[As a convenience to customers and a competitive differentiator, public cloud services such as AWS offer TLS certificates for use in their environments. Join our hosts as they explain this practice, how these certificates can be used, and which use cases and environments will not work with TLS certificates from public cloud vendors.]]></itunes:summary><itunes:duration>562</itunes:duration><itunes:keywords>cloud,digital certificates,hyperscalers,pki,tls,webpki,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>77</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 76: Implications of COVID-19 for PKI</title><link>https://www.spreaker.com/episode/root-causes-76-implications-of-covid-19-for-pki--70329977</link><description><![CDATA[COVID-19 is rocking all aspects of our daily and business lives. So what are the implications of lock-downs, office closures, and high employee absenteeism on the PKI world? Our hosts explore the implications of our new post-pandemic work culture on business continuity and security, and how PKI fits into this new way of working]]></description><guid isPermaLink="false">84ee2046-4b92-416a-86e5-8d25d5b9b2da</guid><pubDate>Fri, 20 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329977/128_default_tc.mp3" length="25741440" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>COVID-19 is rocking all aspects of our daily and business lives. So what are the implications of lock-downs, office closures, and high employee absenteeism on the PKI world? Our hosts explore the implications of our new post-pandemic work culture on...</itunes:subtitle><itunes:summary><![CDATA[COVID-19 is rocking all aspects of our daily and business lives. So what are the implications of lock-downs, office closures, and high employee absenteeism on the PKI world? Our hosts explore the implications of our new post-pandemic work culture on business continuity and security, and how PKI fits into this new way of working]]></itunes:summary><itunes:duration>1609</itunes:duration><itunes:keywords>covid,pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>76</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 75: Sectigo's COVID-19 Readiness</title><link>https://www.spreaker.com/episode/root-causes-75-sectigo-s-covid-19-readiness--70329983</link><description><![CDATA[As measures move into place throughout society to flatten the curve of COVID-19's spread, it is important to understand the potential effects of lock downs, school closures, and work-from-home mandates on the critical systems that keep our digital world running.  Sectigo has conducted an internal audit of its business continuity and disaster recovery plans in light of the specifics of the ongoing pandemic, and we remain confident in our ongoing operation without material disruption through the present crisis. In this episode our hosts go over the results of Sectigo's COVID-19 readiness audit and what customers can expect in the months to come.]]></description><guid isPermaLink="false">7c67df27-5d47-4e5a-aefd-df735b531c2a</guid><pubDate>Wed, 18 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329983/128_default_tc.mp3" length="4494903" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>As measures move into place throughout society to flatten the curve of COVID-19's spread, it is important to understand the potential effects of lock downs, school closures, and work-from-home mandates on the critical systems that keep our digital...</itunes:subtitle><itunes:summary><![CDATA[As measures move into place throughout society to flatten the curve of COVID-19's spread, it is important to understand the potential effects of lock downs, school closures, and work-from-home mandates on the critical systems that keep our digital world running.  Sectigo has conducted an internal audit of its business continuity and disaster recovery plans in light of the specifics of the ongoing pandemic, and we remain confident in our ongoing operation without material disruption through the present crisis. In this episode our hosts go over the results of Sectigo's COVID-19 readiness audit and what customers can expect in the months to come.]]></itunes:summary><itunes:duration>281</itunes:duration><itunes:keywords>covid,readiness,sectigo</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>75</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 74: Device and Network Access</title><link>https://www.spreaker.com/episode/root-causes-74-device-and-network-access--70330004</link><description><![CDATA[Certificates can play a critical role in enabling and controlling access for users and devices to our sensitive business processes and data.  Our hosts are joined once again by David Colon as we explore the role certificates play in providing network access and permissions, including some best practices.]]></description><guid isPermaLink="false">ed51bdd9-fbfd-4ae5-bf69-205ad0946407</guid><pubDate>Tue, 17 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330004/128_default_tc.mp3" length="14153911" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certificates can play a critical role in enabling and controlling access for users and devices to our sensitive business processes and data.  Our hosts are joined once again by David Colon as we explore the role certificates play in providing network...</itunes:subtitle><itunes:summary><![CDATA[Certificates can play a critical role in enabling and controlling access for users and devices to our sensitive business processes and data.  Our hosts are joined once again by David Colon as we explore the role certificates play in providing network access and permissions, including some best practices.]]></itunes:summary><itunes:duration>885</itunes:duration><itunes:keywords>access control,device,network,pki,tls,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>74</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 73: Apple to Drop Support for Two-year SSL Certificates</title><link>https://www.spreaker.com/episode/root-causes-73-apple-to-drop-support-for-two-year-ssl-certificates--70329965</link><description><![CDATA[At the most recent Face-to-Face meeting of the CA/Browser Forum, Apple announced that as of September 1 it will distrust public TLS certificates issued with terms longer than thirteen months for all its technology products. Join our hosts as they discuss this change, its affect on the ecosystem, and what you need to do to prepare for one-year SSL certificates.]]></description><guid isPermaLink="false">2b19d9e7-e0a9-4bed-af76-90b48915281c</guid><pubDate>Fri, 13 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329965/128_default_tc.mp3" length="19822302" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>At the most recent Face-to-Face meeting of the CA/Browser Forum, Apple announced that as of September 1 it will distrust public TLS certificates issued with terms longer than thirteen months for all its technology products. Join our hosts as they...</itunes:subtitle><itunes:summary><![CDATA[At the most recent Face-to-Face meeting of the CA/Browser Forum, Apple announced that as of September 1 it will distrust public TLS certificates issued with terms longer than thirteen months for all its technology products. Join our hosts as they discuss this change, its affect on the ecosystem, and what you need to do to prepare for one-year SSL certificates.]]></itunes:summary><itunes:duration>1239</itunes:duration><itunes:keywords>apple,certificate lifecycle manageme,certificate lifespans,clm,pki,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>73</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 72: Future-proofing Your PKI</title><link>https://www.spreaker.com/episode/root-causes-72-future-proofing-your-pki--70329973</link><description><![CDATA[Former CableLabs CIO and Kyrio President and General Manager Mitch Ashley joins our hosts to discuss how to set up a PKI system that will meet your needs for many years to come. Mitch is now CEO of Accelerated Strategies Group, a disruptive analyst firm focused on cybersecurity, devops and cloud. We discuss the differing attitudes, pain points, and processes of device manufacturers versus service providers. Mitch explains how the overall qualities of the ecosystem affect PKI, ensuring extensibility and auditability, and how to project your PKI needs into the future ten or twenty years from today.]]></description><guid isPermaLink="false">921aab08-6c1b-4178-9c0c-80b44a391488</guid><pubDate>Tue, 10 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329973/128_default_tc.mp3" length="33100447" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Former CableLabs CIO and Kyrio President and General Manager Mitch Ashley joins our hosts to discuss how to set up a PKI system that will meet your needs for many years to come. Mitch is now CEO of Accelerated Strategies Group, a disruptive analyst...</itunes:subtitle><itunes:summary><![CDATA[Former CableLabs CIO and Kyrio President and General Manager Mitch Ashley joins our hosts to discuss how to set up a PKI system that will meet your needs for many years to come. Mitch is now CEO of Accelerated Strategies Group, a disruptive analyst firm focused on cybersecurity, devops and cloud. We discuss the differing attitudes, pain points, and processes of device manufacturers versus service providers. Mitch explains how the overall qualities of the ecosystem affect PKI, ensuring extensibility and auditability, and how to project your PKI needs into the future ten or twenty years from today.]]></itunes:summary><itunes:duration>2069</itunes:duration><itunes:keywords>cable labs,mitch ashley,pki,tls,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>72</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 71: Short Lived DevOps Certificates</title><link>https://www.spreaker.com/episode/root-causes-71-short-lived-devops-certificates--70329979</link><description><![CDATA[Repeat guest and DevOps expert David Colon joins us again to discuss identity for microservices, including the use of very short-lived TLS certificates. David and our hosts explore the unique properties of PKI in these environments and describe how to find the optimal term for a container certificate.]]></description><guid isPermaLink="false">9f858e45-9f3b-4164-adbf-1bf52b2863de</guid><pubDate>Fri, 06 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329979/128_default_tc.mp3" length="20173360" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Repeat guest and DevOps expert David Colon joins us again to discuss identity for microservices, including the use of very short-lived TLS certificates. David and our hosts explore the unique properties of PKI in these environments and describe how to...</itunes:subtitle><itunes:summary><![CDATA[Repeat guest and DevOps expert David Colon joins us again to discuss identity for microservices, including the use of very short-lived TLS certificates. David and our hosts explore the unique properties of PKI in these environments and describe how to find the optimal term for a container certificate.]]></itunes:summary><itunes:duration>1261</itunes:duration><itunes:keywords>certificate lifecycle manageme,certificate lifespans,david colon,devops,pki,tls,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>71</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 70: Identity Is the New Perimeter</title><link>https://www.spreaker.com/episode/root-causes-70-identity-is-the-new-perimeter--70329966</link><description><![CDATA[Modern architectures and development processes have shattered the old concept of an IT perimeter for the enterprise. In this world, attaching strong identity to every device, user, and process is essential to security. In this episode our hosts describe this challenge and discuss the pros and cons of various identity schemes.]]></description><guid isPermaLink="false">d8010fd5-a836-470a-b071-10a6eacb45fc</guid><pubDate>Wed, 04 Mar 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329966/128_default_tc.mp3" length="26309000" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Modern architectures and development processes have shattered the old concept of an IT perimeter for the enterprise. In this world, attaching strong identity to every device, user, and process is essential to security. In this episode our hosts...</itunes:subtitle><itunes:summary><![CDATA[Modern architectures and development processes have shattered the old concept of an IT perimeter for the enterprise. In this world, attaching strong identity to every device, user, and process is essential to security. In this episode our hosts describe this challenge and discuss the pros and cons of various identity schemes.]]></itunes:summary><itunes:duration>1645</itunes:duration><itunes:keywords>cybersecurity,digital identities,pki,tls,webpki,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>70</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 69: Fundamentals of DevOps and PKI</title><link>https://www.spreaker.com/episode/root-causes-69-fundamentals-of-devops-and-pki--70329986</link><description><![CDATA[In our ongoing series on DevOps and PKI, DevOps practitioner David Colon joins us to help describe the intersection of DevOps security and PKI. We explore how PKI fits in with orchestration engines like Kubernetes and some of the practical considerations in securely using keys in such environments.]]></description><guid isPermaLink="false">abc35835-7b62-4d07-af05-b49a58da47cf</guid><pubDate>Fri, 28 Feb 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329986/128_default_tc.mp3" length="21288893" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing series on DevOps and PKI, DevOps practitioner David Colon joins us to help describe the intersection of DevOps security and PKI. We explore how PKI fits in with orchestration engines like Kubernetes and some of the practical...</itunes:subtitle><itunes:summary><![CDATA[In our ongoing series on DevOps and PKI, DevOps practitioner David Colon joins us to help describe the intersection of DevOps security and PKI. We explore how PKI fits in with orchestration engines like Kubernetes and some of the practical considerations in securely using keys in such environments.]]></itunes:summary><itunes:duration>1331</itunes:duration><itunes:keywords>certificate lifecycle manageme,certificate lifespans,devops,pki,tls,webpki,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>69</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 68: Why SHA-1 Is No Longer Secure</title><link>https://www.spreaker.com/episode/root-causes-68-why-sha-1-is-no-longer-secure--70329989</link><description><![CDATA[SHA-1 was a cornerstone of the early secure web.  Now, 25 years later, this hashing function is no longer secure.  Join our hosts to hear the history of SHA-1, its common use cases, and the properties of an effective hashing function. Learn about collision attacks and why they matter. Find out the reasons SHA-1 is still in use and why it is no longer secure in today's computing world.]]></description><guid isPermaLink="false">6ad7e15f-5e71-49b6-9102-5eebe87203cb</guid><pubDate>Mon, 24 Feb 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329989/128_default_tc.mp3" length="30612754" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>SHA-1 was a cornerstone of the early secure web.  Now, 25 years later, this hashing function is no longer secure.  Join our hosts to hear the history of SHA-1, its common use cases, and the properties of an effective hashing function. Learn about...</itunes:subtitle><itunes:summary><![CDATA[SHA-1 was a cornerstone of the early secure web.  Now, 25 years later, this hashing function is no longer secure.  Join our hosts to hear the history of SHA-1, its common use cases, and the properties of an effective hashing function. Learn about collision attacks and why they matter. Find out the reasons SHA-1 is still in use and why it is no longer secure in today's computing world.]]></itunes:summary><itunes:duration>1914</itunes:duration><itunes:keywords>cryptographic primitive,cryptography,hashing algorithm,pki,sha-1,tls,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>68</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 67: Definition of DevOps and DevSecOps</title><link>https://www.spreaker.com/episode/root-causes-67-definition-of-devops-and-devsecops--70329981</link><description><![CDATA[Our hosts are joined by senior DevOps engineer David Colon to explore what DevOps means in today's enterprise. They cover diverse aspects of the DevOps phenomenon, including cultural implications, "configuration drift," definition of release velocity, and DevSecOps. Plus of course how DevSecOps intersects with PKI.]]></description><guid isPermaLink="false">c4fe3eff-7fd2-4be6-b6de-527c0a95d8ea</guid><pubDate>Fri, 21 Feb 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329981/128_default_tc.mp3" length="21305639" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Our hosts are joined by senior DevOps engineer David Colon to explore what DevOps means in today's enterprise. They cover diverse aspects of the DevOps phenomenon, including cultural implications, "configuration drift," definition of release velocity,...</itunes:subtitle><itunes:summary><![CDATA[Our hosts are joined by senior DevOps engineer David Colon to explore what DevOps means in today's enterprise. They cover diverse aspects of the DevOps phenomenon, including cultural implications, "configuration drift," definition of release velocity, and DevSecOps. Plus of course how DevSecOps intersects with PKI.]]></itunes:summary><itunes:duration>1332</itunes:duration><itunes:keywords>certificate lifecycle manageme,certificate lifespans,devops,devsecops,pki,tls,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>67</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 66: Functional Versus Homomorphic Encryption</title><link>https://www.spreaker.com/episode/root-causes-66-functional-versus-homomorphic-encryption--70329982</link><description><![CDATA[Traditionally, file encryption is an all-or-nothing affair where data cannot be gleaned from the encrypted file without fully decrypting its contents. A new brand of cryptography called homomorphic encryption makes it possible for specific types of data to be read from a file while the rest of it remains encrypted. Join our hosts as they explain this new technology approach and its possible implications and use cases.]]></description><guid isPermaLink="false">e2a3d59c-eec3-4229-8553-2f2a3f529dbe</guid><pubDate>Tue, 18 Feb 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329982/128_default_tc.mp3" length="15078437" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Traditionally, file encryption is an all-or-nothing affair where data cannot be gleaned from the encrypted file without fully decrypting its contents. A new brand of cryptography called homomorphic encryption makes it possible for specific types of...</itunes:subtitle><itunes:summary><![CDATA[Traditionally, file encryption is an all-or-nothing affair where data cannot be gleaned from the encrypted file without fully decrypting its contents. A new brand of cryptography called homomorphic encryption makes it possible for specific types of data to be read from a file while the rest of it remains encrypted. Join our hosts as they explain this new technology approach and its possible implications and use cases.]]></itunes:summary><itunes:duration>943</itunes:duration><itunes:keywords>cryptography,encryption,homomorphic,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>66</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 65: Quantum Key Distribution</title><link>https://www.spreaker.com/episode/root-causes-65-quantum-key-distribution--70329988</link><description><![CDATA[Quantum key distribution is a new technology that uses the principles of quantum physics to generate and distribute truly random keys for encrypted communication. Join us as we explain how quantum key distribution works, why it is not the same as quantum safe cryptography, and which cases it may be useful for.]]></description><guid isPermaLink="false">11111448-1759-44fe-8724-d5c53e4777ad</guid><pubDate>Mon, 10 Feb 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329988/128_default_tc.mp3" length="17294039" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Quantum key distribution is a new technology that uses the principles of quantum physics to generate and distribute truly random keys for encrypted communication. Join us as we explain how quantum key distribution works, why it is not the same as...</itunes:subtitle><itunes:summary><![CDATA[Quantum key distribution is a new technology that uses the principles of quantum physics to generate and distribute truly random keys for encrypted communication. Join us as we explain how quantum key distribution works, why it is not the same as quantum safe cryptography, and which cases it may be useful for.]]></itunes:summary><itunes:duration>1081</itunes:duration><itunes:keywords>pki,qkd,quantum,quantum key distribution</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>65</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 64: What Is Digital Identity?</title><link>https://www.spreaker.com/episode/root-causes-64-what-is-digital-identity--70330010</link><description><![CDATA[The phrase "identity is the new perimeter" has gained in use of late, reflecting the reality that today's modern enterprise architecture is a mix of traditional and cloud, owned and rented and BYOD, all together in a complex mix. Under those circumstances identity is key to determine which digital entities have which permissions.  But what do we mean when we say identity?  Join our hosts as they explain the concepts behind digital identity, how they compare to our offline ideas around identity, and how these ideas shape computer security.]]></description><guid isPermaLink="false">d5c905f7-1c25-4eb4-b509-029556c15527</guid><pubDate>Tue, 04 Feb 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330010/128_default_tc.mp3" length="28552187" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The phrase "identity is the new perimeter" has gained in use of late, reflecting the reality that today's modern enterprise architecture is a mix of traditional and cloud, owned and rented and BYOD, all together in a complex mix. Under those...</itunes:subtitle><itunes:summary><![CDATA[The phrase "identity is the new perimeter" has gained in use of late, reflecting the reality that today's modern enterprise architecture is a mix of traditional and cloud, owned and rented and BYOD, all together in a complex mix. Under those circumstances identity is key to determine which digital entities have which permissions.  But what do we mean when we say identity?  Join our hosts as they explain the concepts behind digital identity, how they compare to our offline ideas around identity, and how these ideas shape computer security.]]></itunes:summary><itunes:duration>1785</itunes:duration><itunes:keywords>identity,identity is the new perimeter,pki,tls,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>64</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 63: What Is CAA?</title><link>https://www.spreaker.com/episode/root-causes-63-what-is-caa--70330003</link><description><![CDATA[CAA, which stands for CA Authentication, is the capability for the domain name owner to specify in DNS which CAs are allowed to issue SSL certificates for a specific domain. Join us to learn more about CAA, including how it works and its potential benefits to businesses.]]></description><guid isPermaLink="false">2c35d72c-f115-4d2d-8ef5-44fec3c43047</guid><pubDate>Wed, 29 Jan 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330003/128_default_tc.mp3" length="9520834" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>CAA, which stands for CA Authentication, is the capability for the domain name owner to specify in DNS which CAs are allowed to issue SSL certificates for a specific domain. Join us to learn more about CAA, including how it works and its potential...</itunes:subtitle><itunes:summary><![CDATA[CAA, which stands for CA Authentication, is the capability for the domain name owner to specify in DNS which CAs are allowed to issue SSL certificates for a specific domain. Join us to learn more about CAA, including how it works and its potential benefits to businesses.]]></itunes:summary><itunes:duration>596</itunes:duration><itunes:keywords>caa,digital certificates,pki,webpki,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>63</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 62: Windows CryptoAPI Spoofing Vulnerability Explained</title><link>https://www.spreaker.com/episode/root-causes-62-windows-cryptoapi-spoofing-vulnerability-explained--70330005</link><description><![CDATA[On January 14 Microsoft announced a sweeping vulnerability that makes it possible to defeat the authentication of Elliptic Curve Cryptography (ECC) on Windows 10 and Windows Server systems, making it possible to create fake certificates on trusted roots that will fool these systems. Join our hosts and guest Nick France, CTO of SSL at Sectigo, as we explain this vulnerability, how it could be used in exploits, and what must be done to address it.]]></description><guid isPermaLink="false">0c9af701-0c22-4dff-afbb-3ac23699a9ee</guid><pubDate>Wed, 22 Jan 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330005/128_default_tc.mp3" length="17577833" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>On January 14 Microsoft announced a sweeping vulnerability that makes it possible to defeat the authentication of Elliptic Curve Cryptography (ECC) on Windows 10 and Windows Server systems, making it possible to create fake certificates on trusted...</itunes:subtitle><itunes:summary><![CDATA[On January 14 Microsoft announced a sweeping vulnerability that makes it possible to defeat the authentication of Elliptic Curve Cryptography (ECC) on Windows 10 and Windows Server systems, making it possible to create fake certificates on trusted roots that will fool these systems. Join our hosts and guest Nick France, CTO of SSL at Sectigo, as we explain this vulnerability, how it could be used in exploits, and what must be done to address it.]]></itunes:summary><itunes:duration>1099</itunes:duration><itunes:keywords>cryptography,elliptic curve,microsoft,pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>62</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 61: Anatomy of a Cryptocurrency</title><link>https://www.spreaker.com/episode/root-causes-61-anatomy-of-a-cryptocurrency--70330015</link><description><![CDATA[In our ongoing series about blockchain, we explore the technology, process, and ecosystem needs for a successful cryptocurrency. Join our hosts along with expert guest Alan Grau as we discuss the technology and ecosystem specifics of cryptocurrencies, including blockchain and PKI.]]></description><guid isPermaLink="false">5fadf7c0-9dfb-4ffd-afdc-25a95636d386</guid><pubDate>Fri, 10 Jan 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330015/128_default_tc.mp3" length="30188915" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our ongoing series about blockchain, we explore the technology, process, and ecosystem needs for a successful cryptocurrency. Join our hosts along with expert guest Alan Grau as we discuss the technology and ecosystem specifics of cryptocurrencies,...</itunes:subtitle><itunes:summary><![CDATA[In our ongoing series about blockchain, we explore the technology, process, and ecosystem needs for a successful cryptocurrency. Join our hosts along with expert guest Alan Grau as we discuss the technology and ecosystem specifics of cryptocurrencies, including blockchain and PKI.]]></itunes:summary><itunes:duration>1887</itunes:duration><itunes:keywords>crypto,cryptocurrency,crypto wallet,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>61</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 60: Fundamentals of Blockchain</title><link>https://www.spreaker.com/episode/root-causes-60-fundamentals-of-blockchain--70330006</link><description><![CDATA[Widely understood to be the technology behind popular crypto currencies, blockchain has become a household word. But what it blockchain really, and how does it work? Join our hosts and returning guest Alan Grau as they explain how blockchain functions, its strengths and weaknesses, and some of the other potential applications for this technology.]]></description><guid isPermaLink="false">0678187b-1554-4a3c-a25d-97b26647a63f</guid><pubDate>Mon, 06 Jan 2020 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330006/128_default_tc.mp3" length="20682434" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Widely understood to be the technology behind popular crypto currencies, blockchain has become a household word. But what it blockchain really, and how does it work? Join our hosts and returning guest Alan Grau as they explain how blockchain...</itunes:subtitle><itunes:summary><![CDATA[Widely understood to be the technology behind popular crypto currencies, blockchain has become a household word. But what it blockchain really, and how does it work? Join our hosts and returning guest Alan Grau as they explain how blockchain functions, its strengths and weaknesses, and some of the other potential applications for this technology.]]></itunes:summary><itunes:duration>1293</itunes:duration><itunes:keywords>blockchain,pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>60</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 59: What Is Certificate Transparency?</title><link>https://www.spreaker.com/episode/root-causes-59-what-is-certificate-transparency--70329969</link><description><![CDATA[Certificate Transparency (CT) is a recent and important development in  the world of SSL certificates. Popular browsers require trusted CAs to log all SSL certificates to publicly available CT Logs. Join our hosts to find out how various parties are using CT Logs to learn about CA behavior and SSL usage patterns and to improve the overall quality of public trust.]]></description><guid isPermaLink="false">b2008753-0d63-4ad7-9d46-a1876d5a1a59</guid><pubDate>Mon, 30 Dec 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329969/128_default_tc.mp3" length="20582124" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Certificate Transparency (CT) is a recent and important development in  the world of SSL certificates. Popular browsers require trusted CAs to log all SSL certificates to publicly available CT Logs. Join our hosts to find out how various parties are...</itunes:subtitle><itunes:summary><![CDATA[Certificate Transparency (CT) is a recent and important development in  the world of SSL certificates. Popular browsers require trusted CAs to log all SSL certificates to publicly available CT Logs. Join our hosts to find out how various parties are using CT Logs to learn about CA behavior and SSL usage patterns and to improve the overall quality of public trust.]]></itunes:summary><itunes:duration>1287</itunes:duration><itunes:keywords>certificate transparency,ct logs,pki,ssl,tls,webpki,x509</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>59</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 58: 2019 Lookback - One Year of Podcasting</title><link>https://www.spreaker.com/episode/root-causes-58-2019-lookback-one-year-of-podcasting--70330017</link><description><![CDATA[Nearly a year ago our hosts launched Root Causes to provide a forum for discussion of the issues surrounding the critically important PKI technology. Now at the end of 2019 we discuss how this podcast has taken shape, how that compares to our original expectations, and what we are looking forward to in 2020.]]></description><guid isPermaLink="false">acb83dc0-dff3-4766-9a55-5a76972d5214</guid><pubDate>Mon, 16 Dec 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330017/128_default_tc.mp3" length="13437947" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Nearly a year ago our hosts launched Root Causes to provide a forum for discussion of the issues surrounding the critically important PKI technology. Now at the end of 2019 we discuss how this podcast has taken shape, how that compares to our original...</itunes:subtitle><itunes:summary><![CDATA[Nearly a year ago our hosts launched Root Causes to provide a forum for discussion of the issues surrounding the critically important PKI technology. Now at the end of 2019 we discuss how this podcast has taken shape, how that compares to our original expectations, and what we are looking forward to in 2020.]]></itunes:summary><itunes:duration>840</itunes:duration><itunes:keywords>pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>58</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 57: Quantum Random Number Generation</title><link>https://www.spreaker.com/episode/root-causes-57-quantum-random-number-generation--70329992</link><description><![CDATA[Random number generation is an essential part of successful cryptography. Quantum computers offer to improve this niche technology industry. Join our hosts to learn what quantum random number generators (qRNGs) are, how they stand to improve cryptography and other computing functions, and how they tie into post-quantum cryptography (or don't).]]></description><guid isPermaLink="false">1844bb63-5c01-4612-8bec-737a3a1a61b2</guid><pubDate>Thu, 12 Dec 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329992/128_default_tc.mp3" length="18116582" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Random number generation is an essential part of successful cryptography. Quantum computers offer to improve this niche technology industry. Join our hosts to learn what quantum random number generators (qRNGs) are, how they stand to improve...</itunes:subtitle><itunes:summary><![CDATA[Random number generation is an essential part of successful cryptography. Quantum computers offer to improve this niche technology industry. Join our hosts to learn what quantum random number generators (qRNGs) are, how they stand to improve cryptography and other computing functions, and how they tie into post-quantum cryptography (or don't).]]></itunes:summary><itunes:duration>1133</itunes:duration><itunes:keywords>pki,qrng,quantum,quantum random number generati,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>57</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 56: 2019 Lookback - Evolving Cryptography</title><link>https://www.spreaker.com/episode/root-causes-56-2019-lookback-evolving-cryptography--70329990</link><description><![CDATA[2019 saw important changes in the world's cryptographic standards, including changes in browser treatment of SSL certificates, the removal of a public CA from trusted root stores, widespread serial number entropy problems across many CAs, and progress in building quantum-resistant PKI. Join our hosts as they detail these going-on and others and talk about what 2020 may hold in terms of evolving cryptography.]]></description><guid isPermaLink="false">310d9889-ff4b-40d3-86a8-ae6e96f9c3ae</guid><pubDate>Mon, 09 Dec 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329990/128_default_tc.mp3" length="22241840" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2019 saw important changes in the world's cryptographic standards, including changes in browser treatment of SSL certificates, the removal of a public CA from trusted root stores, widespread serial number entropy problems across many CAs, and progress...</itunes:subtitle><itunes:summary><![CDATA[2019 saw important changes in the world's cryptographic standards, including changes in browser treatment of SSL certificates, the removal of a public CA from trusted root stores, widespread serial number entropy problems across many CAs, and progress in building quantum-resistant PKI. Join our hosts as they detail these going-on and others and talk about what 2020 may hold in terms of evolving cryptography.]]></itunes:summary><itunes:duration>1391</itunes:duration><itunes:keywords>cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>56</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 55: California's New IoT Security Law</title><link>https://www.spreaker.com/episode/root-causes-55-california-s-new-iot-security-law--70329985</link><description><![CDATA[California Senate Bill 327 (SB-327) goes into effect January 1, 2020. This groundbreaking ordinance requires basic security measures for devices deployed in California. Join us to learn what SB-327 requires from device manufacturers, which threats it protects against, and how this ordinance is leading the way toward stronger IoT security practices.]]></description><guid isPermaLink="false">789b76f8-97ec-4413-bdc0-102330f1270c</guid><pubDate>Thu, 05 Dec 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329985/128_default_tc.mp3" length="21389203" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>California Senate Bill 327 (SB-327) goes into effect January 1, 2020. This groundbreaking ordinance requires basic security measures for devices deployed in California. Join us to learn what SB-327 requires from device manufacturers, which threats it...</itunes:subtitle><itunes:summary><![CDATA[California Senate Bill 327 (SB-327) goes into effect January 1, 2020. This groundbreaking ordinance requires basic security measures for devices deployed in California. Join us to learn what SB-327 requires from device manufacturers, which threats it protects against, and how this ordinance is leading the way toward stronger IoT security practices.]]></itunes:summary><itunes:duration>1337</itunes:duration><itunes:keywords>cryptography,encryption,iot,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>55</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 54: 2019 Lookback - Infrastructure and IoT Security</title><link>https://www.spreaker.com/episode/root-causes-54-2019-lookback-infrastructure-and-iot-security--70330025</link><description><![CDATA[2019 was a highly eventful year for infrastructure and IoT security. The year saw the emergence of wholesale attacks on the world's energy infrastructure, an epidemic of ransomware incidents against municipalities, heightened attention to automotive identity and security, and a number of legislative measures to try to secure this whole set of systems and devices. Join our hosts as they talk about the trends in IoT and infrastructure security in 2019 and where these trends may go in 2020.]]></description><guid isPermaLink="false">161934f7-19b2-4722-8e96-6156fe04103b</guid><pubDate>Tue, 03 Dec 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330025/128_default_tc.mp3" length="23595609" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2019 was a highly eventful year for infrastructure and IoT security. The year saw the emergence of wholesale attacks on the world's energy infrastructure, an epidemic of ransomware incidents against municipalities, heightened attention to automotive...</itunes:subtitle><itunes:summary><![CDATA[2019 was a highly eventful year for infrastructure and IoT security. The year saw the emergence of wholesale attacks on the world's energy infrastructure, an epidemic of ransomware incidents against municipalities, heightened attention to automotive identity and security, and a number of legislative measures to try to secure this whole set of systems and devices. Join our hosts as they talk about the trends in IoT and infrastructure security in 2019 and where these trends may go in 2020.]]></itunes:summary><itunes:duration>1475</itunes:duration><itunes:keywords>cryptography,encryption,iotpki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>54</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 53: 2019 Lookback - Governments Try to Control PKI</title><link>https://www.spreaker.com/episode/root-causes-53-2019-lookback-governments-try-to-control-pki--70329987</link><description><![CDATA[2019 has been an eventful year for PKI. In this episode, first in a series of four lookbacks at the year, our hosts discuss how governments sought to control encryption, certificates, and public trust in 2019.]]></description><guid isPermaLink="false">5003a248-5786-438f-98c7-12436a7e343f</guid><pubDate>Mon, 25 Nov 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329987/128_default_tc.mp3" length="18161304" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>2019 has been an eventful year for PKI. In this episode, first in a series of four lookbacks at the year, our hosts discuss how governments sought to control encryption, certificates, and public trust in 2019.</itunes:subtitle><itunes:summary><![CDATA[2019 has been an eventful year for PKI. In this episode, first in a series of four lookbacks at the year, our hosts discuss how governments sought to control encryption, certificates, and public trust in 2019.]]></itunes:summary><itunes:duration>1136</itunes:duration><itunes:keywords>cryptography,encryption,government,government vs encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>53</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 52: New TLS Certificate Incident Research</title><link>https://www.spreaker.com/episode/root-causes-52-new-tls-certificate-incident-research--70329999</link><description><![CDATA[New research out of Indiana University Bloomington reviews nearly 400 "incidents" with public SSL certificates over the course of more than a decade. Join us as we go through the main findings from this piece of original research, including methodology, incident types and causes, and rogue certificates.]]></description><guid isPermaLink="false">d26a65c5-2872-4575-ab42-3a584b3c26d4</guid><pubDate>Fri, 22 Nov 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329999/128_default_tc.mp3" length="23158006" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>New research out of Indiana University Bloomington reviews nearly 400 "incidents" with public SSL certificates over the course of more than a decade. Join us as we go through the main findings from this piece of original research, including...</itunes:subtitle><itunes:summary><![CDATA[New research out of Indiana University Bloomington reviews nearly 400 "incidents" with public SSL certificates over the course of more than a decade. Join us as we go through the main findings from this piece of original research, including methodology, incident types and causes, and rogue certificates.]]></itunes:summary><itunes:duration>1448</itunes:duration><itunes:keywords>cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>52</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 51: Blockchain vs. PKI</title><link>https://www.spreaker.com/episode/root-causes-51-blockchain-vs-pki--70329995</link><description><![CDATA[In our industry interactions we frequently run into questions about how PKI and blockchain compare with each other. How do they work similarly or differently? Are they surrogates for each other? Are they complimentary? Join us this episode as we explain the details of how blockchain and PKI work, similarities and differences between them, and what use cases are appropriate for each.]]></description><guid isPermaLink="false">cd51e97c-912e-4ca1-a378-7d90ac613b4d</guid><pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329995/128_default_tc.mp3" length="28377480" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In our industry interactions we frequently run into questions about how PKI and blockchain compare with each other. How do they work similarly or differently? Are they surrogates for each other? Are they complimentary? Join us this episode as we...</itunes:subtitle><itunes:summary><![CDATA[In our industry interactions we frequently run into questions about how PKI and blockchain compare with each other. How do they work similarly or differently? Are they surrogates for each other? Are they complimentary? Join us this episode as we explain the details of how blockchain and PKI work, similarities and differences between them, and what use cases are appropriate for each.]]></itunes:summary><itunes:duration>1774</itunes:duration><itunes:keywords>blockchain,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>51</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 50: Energy Infrastructure Cyber Attacks</title><link>https://www.spreaker.com/episode/root-causes-50-energy-infrastructure-cyber-attacks--70329994</link><description><![CDATA[Global energy infrastructure continues to find itself under cyber attack from Advanced Persistent Threats (APTs). Join our hosts as we discuss recent attacks on power plants, why these attacks persist, and possible responses.]]></description><guid isPermaLink="false">0ad62046-b7b5-43dc-9c70-9c08777df9a8</guid><pubDate>Fri, 08 Nov 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329994/128_default_tc.mp3" length="21554297" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Global energy infrastructure continues to find itself under cyber attack from Advanced Persistent Threats (APTs). Join our hosts as we discuss recent attacks on power plants, why these attacks persist, and possible responses.</itunes:subtitle><itunes:summary><![CDATA[Global energy infrastructure continues to find itself under cyber attack from Advanced Persistent Threats (APTs). Join our hosts as we discuss recent attacks on power plants, why these attacks persist, and possible responses.]]></itunes:summary><itunes:duration>1348</itunes:duration><itunes:keywords>critical infrastructure,cryptography,encryption,energy,iot,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>50</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 49: California Consumer Privacy Act</title><link>https://www.spreaker.com/episode/root-causes-49-california-consumer-privacy-act--70330000</link><description><![CDATA[The California Consumer Privacy Act (CCPA) has been described by some as California's GDPR. This act provides broad protections to consumers in California, and businesses must comply starting January 1, 2020. Join us as we discuss this act, what protections it provides, and what businesses must do to comply.]]></description><guid isPermaLink="false">e80a9d26-a4d6-4a59-a4e8-c7b578e9b305</guid><pubDate>Wed, 06 Nov 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330000/128_default_tc.mp3" length="13615998" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The California Consumer Privacy Act (CCPA) has been described by some as California's GDPR. This act provides broad protections to consumers in California, and businesses must comply starting January 1, 2020. Join us as we discuss this act, what...</itunes:subtitle><itunes:summary><![CDATA[The California Consumer Privacy Act (CCPA) has been described by some as California's GDPR. This act provides broad protections to consumers in California, and businesses must comply starting January 1, 2020. Join us as we discuss this act, what protections it provides, and what businesses must do to comply.]]></itunes:summary><itunes:duration>851</itunes:duration><itunes:keywords>ccpa,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>49</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 48: Weaknesses in MFA Authentication</title><link>https://www.spreaker.com/episode/root-causes-48-weaknesses-in-mfa-authentication--70330019</link><description><![CDATA[A recent FBI warning cautions of attacks that circumvent Multi-Factor Authentication (MFA). Join us as we describe contemporary attacks against MFA and how to defend against them.]]></description><guid isPermaLink="false">adf704cb-72c3-4624-a534-b0544ef61084</guid><pubDate>Thu, 31 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330019/128_default_tc.mp3" length="14967260" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent FBI warning cautions of attacks that circumvent Multi-Factor Authentication (MFA). Join us as we describe contemporary attacks against MFA and how to defend against them.</itunes:subtitle><itunes:summary><![CDATA[A recent FBI warning cautions of attacks that circumvent Multi-Factor Authentication (MFA). Join us as we describe contemporary attacks against MFA and how to defend against them.]]></itunes:summary><itunes:duration>936</itunes:duration><itunes:keywords>cybersecurity,mfa,multi factor authentication</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>48</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 47: Quantum Apocalypse - Quantum Resistant Cryptography for IoT</title><link>https://www.spreaker.com/episode/root-causes-47-quantum-apocalypse-quantum-resistant-cryptography-for-iot--70329998</link><description><![CDATA[Expert consensus states that we will need to update cryptography before quantum computers break our existing algorithms in the next ten or fifteen years.  But what do we do about IoT devices, which may lack updating mechanisms and live in the field for decades with little available access. Our hosts are joined by repeat guest Alan Grau as we explore how IoT has specific requirements and challenges for quantum resistant crypto.]]></description><guid isPermaLink="false">fffdd081-f3e0-44dd-8e51-5298b37e1029</guid><pubDate>Fri, 25 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329998/128_default_tc.mp3" length="16925817" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Expert consensus states that we will need to update cryptography before quantum computers break our existing algorithms in the next ten or fifteen years.  But what do we do about IoT devices, which may lack updating mechanisms and live in the field...</itunes:subtitle><itunes:summary><![CDATA[Expert consensus states that we will need to update cryptography before quantum computers break our existing algorithms in the next ten or fifteen years.  But what do we do about IoT devices, which may lack updating mechanisms and live in the field for decades with little available access. Our hosts are joined by repeat guest Alan Grau as we explore how IoT has specific requirements and challenges for quantum resistant crypto.]]></itunes:summary><itunes:duration>1058</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>47</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 46: Criminals Are Patching Browsers for TLS Fingerprinting Attacks</title><link>https://www.spreaker.com/episode/root-causes-46-criminals-are-patching-browsers-for-tls-fingerprinting-attacks--70330024</link><description><![CDATA[In a new variant on a known attack, a Russian Advanced Persistent Threat has begun applying patches to Chrome and Firefox to enable TLS fingerprinting even after the malware is removed from a system. To learn more about this new development, join our hosts as they explain how this attack works, its significance, and where the criminals may go from here.]]></description><guid isPermaLink="false">a7e4ab81-0e09-4122-a76d-a2b92d3a7177</guid><pubDate>Tue, 22 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330024/128_default_tc.mp3" length="13088115" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In a new variant on a known attack, a Russian Advanced Persistent Threat has begun applying patches to Chrome and Firefox to enable TLS fingerprinting even after the malware is removed from a system. To learn more about this new development, join our...</itunes:subtitle><itunes:summary><![CDATA[In a new variant on a known attack, a Russian Advanced Persistent Threat has begun applying patches to Chrome and Firefox to enable TLS fingerprinting even after the malware is removed from a system. To learn more about this new development, join our hosts as they explain how this attack works, its significance, and where the criminals may go from here.]]></itunes:summary><itunes:duration>818</itunes:duration><itunes:keywords>cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>46</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 45: What Is the CA/Browser Forum?</title><link>https://www.spreaker.com/episode/root-causes-45-what-is-the-ca-browser-forum--70330027</link><description><![CDATA[SSL certificate practices are governed by the rules of the CA/Browser Forum. But what is the CA/Browser Forum, who is in it, and where do they get their authority? If you've ever wondered about questions like these join our hosts as they describe the origins of the CA/Browser Forum and how it operates.]]></description><guid isPermaLink="false">a968ede9-aabd-4e15-8517-1467298971ff</guid><pubDate>Fri, 18 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330027/128_default_tc.mp3" length="22315417" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>SSL certificate practices are governed by the rules of the CA/Browser Forum. But what is the CA/Browser Forum, who is in it, and where do they get their authority? If you've ever wondered about questions like these join our hosts as they describe the...</itunes:subtitle><itunes:summary><![CDATA[SSL certificate practices are governed by the rules of the CA/Browser Forum. But what is the CA/Browser Forum, who is in it, and where do they get their authority? If you've ever wondered about questions like these join our hosts as they describe the origins of the CA/Browser Forum and how it operates.]]></itunes:summary><itunes:duration>1395</itunes:duration><itunes:keywords>pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>45</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 44: Automotive Device Security</title><link>https://www.spreaker.com/episode/root-causes-44-automotive-device-security--70330007</link><description><![CDATA[The automobile is undoubtedly among today's most complex, commonplace, and security-sensitive IoT devices. Our hosts describe the cyber threats facing connected cars, including real attacks that already have been proven, new challenges that will come with increasingly advanced capabilities, and what manufacturers can do to protect drivers from harm.]]></description><guid isPermaLink="false">7f67caf5-f703-44aa-868b-ca332afa1c5b</guid><pubDate>Tue, 15 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330007/128_default_tc.mp3" length="16452704" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The automobile is undoubtedly among today's most complex, commonplace, and security-sensitive IoT devices. Our hosts describe the cyber threats facing connected cars, including real attacks that already have been proven, new challenges that will come...</itunes:subtitle><itunes:summary><![CDATA[The automobile is undoubtedly among today's most complex, commonplace, and security-sensitive IoT devices. Our hosts describe the cyber threats facing connected cars, including real attacks that already have been proven, new challenges that will come with increasingly advanced capabilities, and what manufacturers can do to protect drivers from harm.]]></itunes:summary><itunes:duration>1029</itunes:duration><itunes:keywords>automobile,automotive,cars,cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>44</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 43: Quantum Apocalypse - More on Mosca's Inequality</title><link>https://www.spreaker.com/episode/root-causes-43-quantum-apocalypse-more-on-mosca-s-inequality--70329993</link><description><![CDATA[In episode 35 our hosts explained Mosca's Inequality, a formula for calculating when we need to have post-quantum encryption in place to prevent the Quantum Apocalypse. In this episode our hosts embark on a nuanced exploration of the factors influencing this calculation and test whether popular estimates are credible.]]></description><guid isPermaLink="false">bb48da1c-7324-4cbf-8a43-46d2e3a17008</guid><pubDate>Fri, 11 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70329993/128_default_tc.mp3" length="21577284" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In episode 35 our hosts explained Mosca's Inequality, a formula for calculating when we need to have post-quantum encryption in place to prevent the Quantum Apocalypse. In this episode our hosts embark on a nuanced exploration of the factors...</itunes:subtitle><itunes:summary><![CDATA[In episode 35 our hosts explained Mosca's Inequality, a formula for calculating when we need to have post-quantum encryption in place to prevent the Quantum Apocalypse. In this episode our hosts embark on a nuanced exploration of the factors influencing this calculation and test whether popular estimates are credible.]]></itunes:summary><itunes:duration>1349</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>43</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 42: Anatomy of a Botnet</title><link>https://www.spreaker.com/episode/root-causes-42-anatomy-of-a-botnet--70330001</link><description><![CDATA[We talk about botnets a lot, but not everyone understands how they are built and used by the criminals who control them or how headless IoT devices have greatly added to their power. Expert guest Alan Grau (VP of IoT and Embedded Security, Sectigo) joins us to help dissect today's botnets.]]></description><guid isPermaLink="false">9c904dee-43dd-4f82-9c7a-b6036ec2c360</guid><pubDate>Tue, 08 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330001/128_default_tc.mp3" length="23736044" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>We talk about botnets a lot, but not everyone understands how they are built and used by the criminals who control them or how headless IoT devices have greatly added to their power. Expert guest Alan Grau (VP of IoT and Embedded Security, Sectigo)...</itunes:subtitle><itunes:summary><![CDATA[We talk about botnets a lot, but not everyone understands how they are built and used by the criminals who control them or how headless IoT devices have greatly added to their power. Expert guest Alan Grau (VP of IoT and Embedded Security, Sectigo) joins us to help dissect today's botnets.]]></itunes:summary><itunes:duration>1484</itunes:duration><itunes:keywords>botnet,cybersecurity</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>42</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 41: What Is Blockchain's Killer App?</title><link>https://www.spreaker.com/episode/root-causes-41-what-is-blockchain-s-killer-app--70330028</link><description><![CDATA[Our hosts frequently run into the assumption that blockchain and PKI are extremely similar technologies and are possibly even competitive to each other. While the two approaches accomplish some related goals, they are very different in how they work and ultimately accomplish different ends. Join us as we explain what blockchain actually does and how it compares to PKI, including some examples of use cases that are appropriate for each of these technologies.]]></description><guid isPermaLink="false">59c5627b-e8ac-4819-8c19-a3c6c1f04da5</guid><pubDate>Thu, 03 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330028/128_default_tc.mp3" length="14051511" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Our hosts frequently run into the assumption that blockchain and PKI are extremely similar technologies and are possibly even competitive to each other. While the two approaches accomplish some related goals, they are very different in how they work...</itunes:subtitle><itunes:summary><![CDATA[Our hosts frequently run into the assumption that blockchain and PKI are extremely similar technologies and are possibly even competitive to each other. While the two approaches accomplish some related goals, they are very different in how they work and ultimately accomplish different ends. Join us as we explain what blockchain actually does and how it compares to PKI, including some examples of use cases that are appropriate for each of these technologies.]]></itunes:summary><itunes:duration>879</itunes:duration><itunes:keywords>blockchain,cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>41</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 40: The Reports of RSA's Death Are Greatly Exaggerated</title><link>https://www.spreaker.com/episode/root-causes-40-the-reports-of-rsa-s-death-are-greatly-exaggerated--70330013</link><description><![CDATA[Recently at Black Hat and on public YouTube videos security newcomer Crown Sterling has claimed to factor the RSA algorithm. It turns out the breathlessly discussed feats were already accomplished as early as 1999.  Join our hosts as they debunk this fundamentally misleading rumor and discuss the reality of RSA encryption today.]]></description><guid isPermaLink="false">1d7e6cc5-9ea6-4d94-831e-f129724609ee</guid><pubDate>Tue, 01 Oct 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330013/128_default_tc.mp3" length="8796946" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recently at Black Hat and on public YouTube videos security newcomer Crown Sterling has claimed to factor the RSA algorithm. It turns out the breathlessly discussed feats were already accomplished as early as 1999.  Join our hosts as they debunk this...</itunes:subtitle><itunes:summary><![CDATA[Recently at Black Hat and on public YouTube videos security newcomer Crown Sterling has claimed to factor the RSA algorithm. It turns out the breathlessly discussed feats were already accomplished as early as 1999.  Join our hosts as they debunk this fundamentally misleading rumor and discuss the reality of RSA encryption today.]]></itunes:summary><itunes:duration>550</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,rsa,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>40</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 39: New University Research on Phishing and Certificates</title><link>https://www.spreaker.com/episode/root-causes-39-new-university-research-on-phishing-and-certificates--70330037</link><description><![CDATA[The majority of all phishing sites now use SSL certificates to more closely imitate the behavior of legitimate sites. New research from RWTH Aachen, a large, German technical university, investigates the patterns behind this certificate usage. Join our hosts as we dig into the details of these findings to learn specifically which certificate types are more or less likely to appear on phishing sites - and some thoughts on why.]]></description><guid isPermaLink="false">56a07776-a7da-4da0-b533-68994a576797</guid><pubDate>Thu, 26 Sep 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330037/128_default_tc.mp3" length="19238803" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The majority of all phishing sites now use SSL certificates to more closely imitate the behavior of legitimate sites. New research from RWTH Aachen, a large, German technical university, investigates the patterns behind this certificate usage. Join...</itunes:subtitle><itunes:summary><![CDATA[The majority of all phishing sites now use SSL certificates to more closely imitate the behavior of legitimate sites. New research from RWTH Aachen, a large, German technical university, investigates the patterns behind this certificate usage. Join our hosts as we dig into the details of these findings to learn specifically which certificate types are more or less likely to appear on phishing sites - and some thoughts on why.]]></itunes:summary><itunes:duration>1203</itunes:duration><itunes:keywords>cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>39</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 38: Interesting Breaches in August</title><link>https://www.spreaker.com/episode/root-causes-38-interesting-breaches-in-august--70330011</link><description><![CDATA[The month of August saw some unusual criminal activity when it comes to PKI and malware. Our hosts explain four August news stories including a SHA-1 enabled breach, stolen certificates and keys, and some interesting developments with malware-driven botnets.]]></description><guid isPermaLink="false">dd08ecfb-4bfd-4efb-840a-fa52b3518ff8</guid><pubDate>Tue, 24 Sep 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330011/128_default_tc.mp3" length="27583358" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The month of August saw some unusual criminal activity when it comes to PKI and malware. Our hosts explain four August news stories including a SHA-1 enabled breach, stolen certificates and keys, and some interesting developments with malware-driven...</itunes:subtitle><itunes:summary><![CDATA[The month of August saw some unusual criminal activity when it comes to PKI and malware. Our hosts explain four August news stories including a SHA-1 enabled breach, stolen certificates and keys, and some interesting developments with malware-driven botnets.]]></itunes:summary><itunes:duration>1724</itunes:duration><itunes:keywords>cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>38</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 37: Quantum Apocalypse - Will Quantum Annealing Break Cryptography?</title><link>https://www.spreaker.com/episode/root-causes-37-quantum-apocalypse-will-quantum-annealing-break-cryptography--70330029</link><description><![CDATA[Quantum annealing is a special case of quantum computing for which the engineering challenges are lessened - and therefore we expect computers of this sort to achieve stability sooner. In this episode we examine the potential for the quantum annealing approach to break RSA-based cryptography sooner than most people have been expecting, and the difficulty of predicting the "Z date" at all.]]></description><guid isPermaLink="false">fccf8537-d355-4373-a889-696240a0fc48</guid><pubDate>Tue, 10 Sep 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330029/128_default_tc.mp3" length="19750385" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Quantum annealing is a special case of quantum computing for which the engineering challenges are lessened - and therefore we expect computers of this sort to achieve stability sooner. In this episode we examine the potential for the quantum annealing...</itunes:subtitle><itunes:summary><![CDATA[Quantum annealing is a special case of quantum computing for which the engineering challenges are lessened - and therefore we expect computers of this sort to achieve stability sooner. In this episode we examine the potential for the quantum annealing approach to break RSA-based cryptography sooner than most people have been expecting, and the difficulty of predicting the "Z date" at all.]]></itunes:summary><itunes:duration>1235</itunes:duration><itunes:keywords>annealing,cryptography,encryption,pki,quantum,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>37</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 36: Quantum Apocalypse - The Search for Quantum Resistant Crypto</title><link>https://www.spreaker.com/episode/root-causes-36-quantum-apocalypse-the-search-for-quantum-resistant-crypto--70330018</link><description><![CDATA[Finding the new quantum-resistant cryptography we will need to replace RSA and ECC is a difficult task requiring the coordinated effort of academics, industry, and government. NIST has stepped in to lead this volunteer community. Join us to learn about this project to discover and vet going-forward crypto candidates, where we stand in the process, and where we go from here.]]></description><guid isPermaLink="false">41d2d230-f453-4f7e-94a1-f3f972d074f5</guid><pubDate>Tue, 03 Sep 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330018/128_default_tc.mp3" length="20180047" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Finding the new quantum-resistant cryptography we will need to replace RSA and ECC is a difficult task requiring the coordinated effort of academics, industry, and government. NIST has stepped in to lead this volunteer community. Join us to learn...</itunes:subtitle><itunes:summary><![CDATA[Finding the new quantum-resistant cryptography we will need to replace RSA and ECC is a difficult task requiring the coordinated effort of academics, industry, and government. NIST has stepped in to lead this volunteer community. Join us to learn about this project to discover and vet going-forward crypto candidates, where we stand in the process, and where we go from here.]]></itunes:summary><itunes:duration>1262</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>36</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 35: Quantum Apocalypse - Mosca's Inequality, Mad Max, and Mohawks</title><link>https://www.spreaker.com/episode/root-causes-35-quantum-apocalypse-mosca-s-inequality-mad-max-and-mohawks--70330026</link><description><![CDATA[Quantum computers have the potential to defeat the RSA and ECC encryption underlying our digital world. We must swap out these algorithms before quantum computers reach that stage of maturity. But how long to we have? Join our hosts Tim Callan and Jason Soroko as they explain how to calculate the ominously named "Z date," the possible consequences of missing that deadline, and potential hairstyles for a post-apocalyptic world.]]></description><guid isPermaLink="false">1de724b5-d69c-4ab2-898a-1cdd8470ba59</guid><pubDate>Thu, 29 Aug 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330026/128_default_tc.mp3" length="18975923" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Quantum computers have the potential to defeat the RSA and ECC encryption underlying our digital world. We must swap out these algorithms before quantum computers reach that stage of maturity. But how long to we have? Join our hosts Tim Callan and...</itunes:subtitle><itunes:summary><![CDATA[Quantum computers have the potential to defeat the RSA and ECC encryption underlying our digital world. We must swap out these algorithms before quantum computers reach that stage of maturity. But how long to we have? Join our hosts Tim Callan and Jason Soroko as they explain how to calculate the ominously named "Z date," the possible consequences of missing that deadline, and potential hairstyles for a post-apocalyptic world.]]></itunes:summary><itunes:duration>1186</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>35</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 34: Shadow IT and PKI</title><link>https://www.spreaker.com/episode/root-causes-34-shadow-it-and-pki--70330047</link><description><![CDATA[Shadow IT has become a fact of the modern enterprise. SaaS, BYOD, outsourced development, embedded IT, DevOps, and public cloud have all chipped away at the CIO's ability to oversee and control the enterprise's technology systems. This fragmentation leads to identity and access challenges that can affect security, governance, auditability, and compliance. Join our hosts as they discuss these challenges and what IT departments can do to address them.]]></description><guid isPermaLink="false">30df85f1-c55a-4ca6-8d5d-b30f83a7ab2c</guid><pubDate>Mon, 26 Aug 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330047/128_default_tc.mp3" length="21944671" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Shadow IT has become a fact of the modern enterprise. SaaS, BYOD, outsourced development, embedded IT, DevOps, and public cloud have all chipped away at the CIO's ability to oversee and control the enterprise's technology systems. This fragmentation...</itunes:subtitle><itunes:summary><![CDATA[Shadow IT has become a fact of the modern enterprise. SaaS, BYOD, outsourced development, embedded IT, DevOps, and public cloud have all chipped away at the CIO's ability to oversee and control the enterprise's technology systems. This fragmentation leads to identity and access challenges that can affect security, governance, auditability, and compliance. Join our hosts as they discuss these challenges and what IT departments can do to address them.]]></itunes:summary><itunes:duration>1372</itunes:duration><itunes:keywords>certificate lifecycle manageme,cryptography,discovery,encryption,mosca,pki,q date,quantum,rogue certificates,shadow it,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>34</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 33: Prepare for One-year Limits on SSL Certificates</title><link>https://www.spreaker.com/episode/root-causes-33-prepare-for-one-year-limits-on-ssl-certificates--70330008</link><description><![CDATA[The CA/Browser Forum faces a proposed ballot to limit the maximum duration of an SSL certificate to 13 months. Even if this ballot fails, browsers such as Google Chrome have the ability to simply distrust certificates of longer duration, creating the same de facto situation. Our hosts discuss the trend to shorter certificates, the pluses and minuses of decreased maximum term, and automation as the only solution to fill the gap.]]></description><guid isPermaLink="false">bfdc1c83-b242-4048-a584-c93ea14c4cf4</guid><pubDate>Tue, 20 Aug 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330008/128_default_tc.mp3" length="16311417" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The CA/Browser Forum faces a proposed ballot to limit the maximum duration of an SSL certificate to 13 months. Even if this ballot fails, browsers such as Google Chrome have the ability to simply distrust certificates of longer duration, creating the...</itunes:subtitle><itunes:summary><![CDATA[The CA/Browser Forum faces a proposed ballot to limit the maximum duration of an SSL certificate to 13 months. Even if this ballot fails, browsers such as Google Chrome have the ability to simply distrust certificates of longer duration, creating the same de facto situation. Our hosts discuss the trend to shorter certificates, the pluses and minuses of decreased maximum term, and automation as the only solution to fill the gap.]]></itunes:summary><itunes:duration>1020</itunes:duration><itunes:keywords>certificate lifespans,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>33</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 32: Why Do Browsers and Academic Research Say Different Things About EV SSL?</title><link>https://www.spreaker.com/episode/root-causes-32-why-do-browsers-and-academic-research-say-different-things-about-ev-ssl--70330049</link><description><![CDATA[Breaking research from two esteemed universities shows that sites with Extended Validation SSL certificates are much less likely to be engaged in criminal behavior like malware and phishing. And yet, leading browsers are reducing or removing EV information from the interface. Join our hosts as they explore the research results, this paradoxical browser behavior, and the effect it's likely to have on consumer security.]]></description><guid isPermaLink="false">c51ef5ae-9b56-42cd-8be3-9789925da9fe</guid><pubDate>Thu, 15 Aug 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330049/128_default_tc.mp3" length="23782855" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Breaking research from two esteemed universities shows that sites with Extended Validation SSL certificates are much less likely to be engaged in criminal behavior like malware and phishing. And yet, leading browsers are reducing or removing EV...</itunes:subtitle><itunes:summary><![CDATA[Breaking research from two esteemed universities shows that sites with Extended Validation SSL certificates are much less likely to be engaged in criminal behavior like malware and phishing. And yet, leading browsers are reducing or removing EV information from the interface. Join our hosts as they explore the research results, this paradoxical browser behavior, and the effect it's likely to have on consumer security.]]></itunes:summary><itunes:duration>1487</itunes:duration><itunes:keywords>ev,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>32</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 31: Using PKI to Authenticate Phone Callers</title><link>https://www.spreaker.com/episode/root-causes-31-using-pki-to-authenticate-phone-callers--70330021</link><description><![CDATA[Few people know that caller ID numbers have no identity value as they are completely self-reported. This fact enables the plague of robocalling scams sweeping our society right now. Join our hosts as they discuss public telephony systems and other environments that suffer from this problem, where this situation creates vulnerabilities, and what can be done about it.]]></description><guid isPermaLink="false">b96c26cb-1a3b-4698-8829-8f35d0a49411</guid><pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330021/128_default_tc.mp3" length="10972016" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Few people know that caller ID numbers have no identity value as they are completely self-reported. This fact enables the plague of robocalling scams sweeping our society right now. Join our hosts as they discuss public telephony systems and other...</itunes:subtitle><itunes:summary><![CDATA[Few people know that caller ID numbers have no identity value as they are completely self-reported. This fact enables the plague of robocalling scams sweeping our society right now. Join our hosts as they discuss public telephony systems and other environments that suffer from this problem, where this situation creates vulnerabilities, and what can be done about it.]]></itunes:summary><itunes:duration>686</itunes:duration><itunes:keywords>pki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>31</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 30: When a Whole Country Has Its PII Stolen - Giant Breach Fines - Phishing with SSL</title><link>https://www.spreaker.com/episode/root-causes-30-when-a-whole-country-has-its-pii-stolen-giant-breach-fines-phishing-with-ssl--70330023</link><description><![CDATA[Recently we have seen major news items in some of the common Root Causes themes. Join our hosts as they discuss new whopping breach fines from GDPR and the FTC, what happens when an entire country has its PII stolen, and phishing sites with SSL.]]></description><guid isPermaLink="false">12bf9063-7b4c-4b2d-a071-c605f25889d6</guid><pubDate>Tue, 06 Aug 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330023/128_default_tc.mp3" length="15887188" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recently we have seen major news items in some of the common Root Causes themes. Join our hosts as they discuss new whopping breach fines from GDPR and the FTC, what happens when an entire country has its PII stolen, and phishing sites with SSL.</itunes:subtitle><itunes:summary><![CDATA[Recently we have seen major news items in some of the common Root Causes themes. Join our hosts as they discuss new whopping breach fines from GDPR and the FTC, what happens when an entire country has its PII stolen, and phishing sites with SSL.]]></itunes:summary><itunes:duration>993</itunes:duration><itunes:keywords>gdpr,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>30</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes Special Bulletin: Kazakhstan Weaponizes the Public CA</title><link>https://www.spreaker.com/episode/root-causes-special-bulletin-kazakhstan-weaponizes-the-public-ca--70330032</link><description><![CDATA[The Kazakhstan government is taking measures to force citizens to trust its own root, enabling the widespread persecution of dissidents, journalists, and human rights advocates. Join our hosts to learn the long history of Kazakhstan's weaponization of PKI, what its effects may be, and the opportunities and challenges the browser community faces in fighting it.]]></description><guid isPermaLink="false">fdae773b-25b7-4ef8-9d5c-3951e440701d</guid><pubDate>Wed, 31 Jul 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330032/128_default_tc.mp3" length="17003139" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The Kazakhstan government is taking measures to force citizens to trust its own root, enabling the widespread persecution of dissidents, journalists, and human rights advocates. Join our hosts to learn the long history of Kazakhstan's weaponization of...</itunes:subtitle><itunes:summary><![CDATA[The Kazakhstan government is taking measures to force citizens to trust its own root, enabling the widespread persecution of dissidents, journalists, and human rights advocates. Join our hosts to learn the long history of Kazakhstan's weaponization of PKI, what its effects may be, and the opportunities and challenges the browser community faces in fighting it.]]></itunes:summary><itunes:duration>1063</itunes:duration><itunes:keywords>e2ee,government vs encryption,pki,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episodeType>bonus</itunes:episodeType></item><item><title>Root Causes 29: Vulnerabilities in Cisco Routers and Other Device Integrity Controls</title><link>https://www.spreaker.com/episode/root-causes-29-vulnerabilities-in-cisco-routers-and-other-device-integrity-controls--70330012</link><description><![CDATA[Security flaws in the device integrity modules of Cisco routers and other devices have lately filled the headlines. Join our hosts and guest Alan Grau as they discuss what is happening with these flaws, why, and what to do about it.]]></description><guid isPermaLink="false">42f51380-b01e-4187-8e54-957c152fc405</guid><pubDate>Thu, 25 Jul 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330012/128_default_tc.mp3" length="21105826" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Security flaws in the device integrity modules of Cisco routers and other devices have lately filled the headlines. Join our hosts and guest Alan Grau as they discuss what is happening with these flaws, why, and what to do about it.</itunes:subtitle><itunes:summary><![CDATA[Security flaws in the device integrity modules of Cisco routers and other devices have lately filled the headlines. Join our hosts and guest Alan Grau as they discuss what is happening with these flaws, why, and what to do about it.]]></itunes:summary><itunes:duration>1320</itunes:duration><itunes:keywords>cisco,cybersecurity,routers</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>29</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 28: SSL Certificate Automation Through ACME</title><link>https://www.spreaker.com/episode/root-causes-28-ssl-certificate-automation-through-acme--70330038</link><description><![CDATA[ACME is a new SSL certificate automation standard that is taking the world by storm. With support by 150 million web sites and more than 130 open source tools, ACME is a key tool in your digital certificate bag. Join our hosts and guest Abul Salek as they discuss this ACME, why it's important, and what's next for this hugely popular standard.]]></description><guid isPermaLink="false">249e164f-1329-4d49-82a5-ccaf84a82ba5</guid><pubDate>Mon, 22 Jul 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330038/128_default_tc.mp3" length="22018649" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>ACME is a new SSL certificate automation standard that is taking the world by storm. With support by 150 million web sites and more than 130 open source tools, ACME is a key tool in your digital certificate bag. Join our hosts and guest Abul Salek as...</itunes:subtitle><itunes:summary><![CDATA[ACME is a new SSL certificate automation standard that is taking the world by storm. With support by 150 million web sites and more than 130 open source tools, ACME is a key tool in your digital certificate bag. Join our hosts and guest Abul Salek as they discuss this ACME, why it's important, and what's next for this hugely popular standard.]]></itunes:summary><itunes:duration>1377</itunes:duration><itunes:keywords>acme,certificate lifecycle manageme,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>28</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 27: Pending Safe Browser Guidelines from Germany</title><link>https://www.spreaker.com/episode/root-causes-27-pending-safe-browser-guidelines-from-germany--70330030</link><description><![CDATA[The German government has published a draft of its latest guidelines for safe browsers, which include requirements for how SSL certificates are supported and treated. Join our hosts as they discuss the German safer browser requirements and their potential impact on Germany, other governments, and industry worldwide.]]></description><guid isPermaLink="false">5d69659c-a686-46d1-baaa-1d443a98237a</guid><pubDate>Thu, 18 Jul 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330030/128_default_tc.mp3" length="16296370" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The German government has published a draft of its latest guidelines for safe browsers, which include requirements for how SSL certificates are supported and treated. Join our hosts as they discuss the German safer browser requirements and their...</itunes:subtitle><itunes:summary><![CDATA[The German government has published a draft of its latest guidelines for safe browsers, which include requirements for how SSL certificates are supported and treated. Join our hosts as they discuss the German safer browser requirements and their potential impact on Germany, other governments, and industry worldwide.]]></itunes:summary><itunes:duration>1019</itunes:duration><itunes:keywords>browser,germany,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>27</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 26: The White House Wants to Prohibit End-to-end Encryption</title><link>https://www.spreaker.com/episode/root-causes-26-the-white-house-wants-to-prohibit-end-to-end-encryption--70330031</link><description><![CDATA[The White House is the latest government entity seeking to defeat widespread encryption technology through legislated "back door" access. Join our hosts as they explain why such an idea is essentially unworkable and would endanger the confidential online business and personal services upon which we all depend.]]></description><guid isPermaLink="false">d4966291-a254-46e7-bb71-da6e1b0c8663</guid><pubDate>Sun, 14 Jul 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330031/128_default_tc.mp3" length="17768840" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The White House is the latest government entity seeking to defeat widespread encryption technology through legislated "back door" access. Join our hosts as they explain why such an idea is essentially unworkable and would endanger the confidential...</itunes:subtitle><itunes:summary><![CDATA[The White House is the latest government entity seeking to defeat widespread encryption technology through legislated "back door" access. Join our hosts as they explain why such an idea is essentially unworkable and would endanger the confidential online business and personal services upon which we all depend.]]></itunes:summary><itunes:duration>1111</itunes:duration><itunes:keywords>cryptography,e2ee,encryption,end to end encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>26</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 25: Entropy and Random Numbers</title><link>https://www.spreaker.com/episode/root-causes-25-entropy-and-random-numbers--70330036</link><description><![CDATA[One cornerstone of successful cryptography is entropy, or the ability to create genuinely unpredictable values. But it turns out that generating truly random numbers is harder than you might think. Join our hosts as they discuss the need for randomness, the lengths companies go to to generate random numbers, and the bad things that can happen when they fail.]]></description><guid isPermaLink="false">1a514ed3-305e-4d3b-97f0-efb5e797fc6c</guid><pubDate>Tue, 02 Jul 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330036/128_default_tc.mp3" length="18492328" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>One cornerstone of successful cryptography is entropy, or the ability to create genuinely unpredictable values. But it turns out that generating truly random numbers is harder than you might think. Join our hosts as they discuss the need for...</itunes:subtitle><itunes:summary><![CDATA[One cornerstone of successful cryptography is entropy, or the ability to create genuinely unpredictable values. But it turns out that generating truly random numbers is harder than you might think. Join our hosts as they discuss the need for randomness, the lengths companies go to to generate random numbers, and the bad things that can happen when they fail.]]></itunes:summary><itunes:duration>1156</itunes:duration><itunes:keywords>cryptography,encryption,entropy,pki,randomness,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>25</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 24: Certificate Revocation</title><link>https://www.spreaker.com/episode/root-causes-24-certificate-revocation--70330035</link><description><![CDATA[Occasional certificate revocation is an essential part of the digital certificate lifecycle and any secure PKI scheme. Not only do certificate owners need the revoke their own certificates, but also CAs sometimes need to revoke certificates to keep trust high. Join our hosts as they discuss the whys and wherefores of revocation by the CA, especially as it relates to code signing and malware.]]></description><guid isPermaLink="false">27a093ec-8dcc-4e10-bb8c-2459926995bf</guid><pubDate>Thu, 27 Jun 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330035/128_default_tc.mp3" length="14844380" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Occasional certificate revocation is an essential part of the digital certificate lifecycle and any secure PKI scheme. Not only do certificate owners need the revoke their own certificates, but also CAs sometimes need to revoke certificates to keep...</itunes:subtitle><itunes:summary><![CDATA[Occasional certificate revocation is an essential part of the digital certificate lifecycle and any secure PKI scheme. Not only do certificate owners need the revoke their own certificates, but also CAs sometimes need to revoke certificates to keep trust high. Join our hosts as they discuss the whys and wherefores of revocation by the CA, especially as it relates to code signing and malware.]]></itunes:summary><itunes:duration>928</itunes:duration><itunes:keywords>certificate lifecycle manageme,pki,revocation,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>24</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 23: Global Energy Grids Under Cyber Attack</title><link>https://www.spreaker.com/episode/root-causes-23-global-energy-grids-under-cyber-attack--70330033</link><description><![CDATA[The world's energy grids and other utilities have increasingly become targets for cyber attack, both state-sponsored and otherwise. Join our hosts as they discuss the latest developments, possible consequences of cyber war against energy grids, and what we can do about it.]]></description><guid isPermaLink="false">9ee2ae8a-a8cb-4a08-b8b6-40d1e0618780</guid><pubDate>Thu, 20 Jun 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330033/128_default_tc.mp3" length="15169552" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The world's energy grids and other utilities have increasingly become targets for cyber attack, both state-sponsored and otherwise. Join our hosts as they discuss the latest developments, possible consequences of cyber war against energy grids, and...</itunes:subtitle><itunes:summary><![CDATA[The world's energy grids and other utilities have increasingly become targets for cyber attack, both state-sponsored and otherwise. Join our hosts as they discuss the latest developments, possible consequences of cyber war against energy grids, and what we can do about it.]]></itunes:summary><itunes:duration>949</itunes:duration><itunes:keywords>critical infrastructure,cybersecurity,operational technology,ot,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ecacfe8353659a8c4d9ec597fd2e9467.jpg"/><itunes:episode>23</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 22: Attacks on US Cities with EternalBlue Cyber Weapon</title><link>https://www.spreaker.com/episode/root-causes-22-attacks-on-us-cities-with-eternalblue-cyber-weapon--70330051</link><description><![CDATA[A recent spate of ransomware attacks against US municipalities is noteworthy for being enabled by the stolen US cyber weapon EternalBlue. Join our hosts as we explain this attack, its similarities to earlier incidents, and the whole syndrome of government-sponsored cyber war.]]></description><guid isPermaLink="false">1a4c0f33-4bee-49e3-ad7d-0a4c12fd4af2</guid><pubDate>Fri, 07 Jun 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330051/128_default_tc.mp3" length="16980151" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recent spate of ransomware attacks against US municipalities is noteworthy for being enabled by the stolen US cyber weapon EternalBlue. Join our hosts as we explain this attack, its similarities to earlier incidents, and the whole syndrome of...</itunes:subtitle><itunes:summary><![CDATA[A recent spate of ransomware attacks against US municipalities is noteworthy for being enabled by the stolen US cyber weapon EternalBlue. Join our hosts as we explain this attack, its similarities to earlier incidents, and the whole syndrome of government-sponsored cyber war.]]></itunes:summary><itunes:duration>1062</itunes:duration><itunes:keywords>cybersecurity</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>22</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 21: New Texas Energy Grid Security Regulation</title><link>https://www.spreaker.com/episode/root-causes-21-new-texas-energy-grid-security-regulation--70330044</link><description><![CDATA[The state of Texas is leading the way with new legislation requiring cyber protections for its energy grid. Join our hosts as we explain this legislation, why it comes now, and its potential impact on the greater energy industry.]]></description><guid isPermaLink="false">ecfbf61d-1a7f-4e16-b3b3-44c06c5cbcd0</guid><pubDate>Wed, 05 Jun 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330044/128_default_tc.mp3" length="17628824" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The state of Texas is leading the way with new legislation requiring cyber protections for its energy grid. Join our hosts as we explain this legislation, why it comes now, and its potential impact on the greater energy industry.</itunes:subtitle><itunes:summary><![CDATA[The state of Texas is leading the way with new legislation requiring cyber protections for its energy grid. Join our hosts as we explain this legislation, why it comes now, and its potential impact on the greater energy industry.]]></itunes:summary><itunes:duration>1102</itunes:duration><itunes:keywords>cybersecurity,ot,regulation,texas energy grid</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>21</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 20: 885 Million First American Financial Customer Docs Exposed</title><link>https://www.spreaker.com/episode/root-causes-20-885-million-first-american-financial-customer-docs-exposed--70330052</link><description><![CDATA[It was recently revealed that First American Title Corporation had 885 million confidential customer financial documents discoverable in the clear on its online site. These documents contain all the most sensitive information necessary for identity theft, spear phishing, and other exploits against individuals. Join our hosts as they discuss the details of this exposure, how it may have come about, and its potential consequences.]]></description><guid isPermaLink="false">63860078-3332-456f-a514-25250b62839e</guid><pubDate>Fri, 31 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330052/128_default_tc.mp3" length="13504821" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It was recently revealed that First American Title Corporation had 885 million confidential customer financial documents discoverable in the clear on its online site. These documents contain all the most sensitive information necessary for identity...</itunes:subtitle><itunes:summary><![CDATA[It was recently revealed that First American Title Corporation had 885 million confidential customer financial documents discoverable in the clear on its online site. These documents contain all the most sensitive information necessary for identity theft, spear phishing, and other exploits against individuals. Join our hosts as they discuss the details of this exposure, how it may have come about, and its potential consequences.]]></itunes:summary><itunes:duration>845</itunes:duration><itunes:keywords>cybersecurity</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>20</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 19: Death of a Public CA</title><link>https://www.spreaker.com/episode/root-causes-19-death-of-a-public-ca--70330050</link><description><![CDATA[Mozilla has decided to remove a public CA from its trusted root store. By doing so Mozilla renders public certificates from this CA essentially valueless for almost all use cases. Join our hosts as the examine the reasons for this decision, how CA rules are made and maintained, and why an action like this one ultimately is healthy for the internet as a whole.]]></description><guid isPermaLink="false">10f25621-c108-4796-a13c-cd214dd2f6f9</guid><pubDate>Thu, 30 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330050/128_default_tc.mp3" length="13434604" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Mozilla has decided to remove a public CA from its trusted root store. By doing so Mozilla renders public certificates from this CA essentially valueless for almost all use cases. Join our hosts as the examine the reasons for this decision, how CA...</itunes:subtitle><itunes:summary><![CDATA[Mozilla has decided to remove a public CA from its trusted root store. By doing so Mozilla renders public certificates from this CA essentially valueless for almost all use cases. Join our hosts as the examine the reasons for this decision, how CA rules are made and maintained, and why an action like this one ultimately is healthy for the internet as a whole.]]></itunes:summary><itunes:duration>840</itunes:duration><itunes:keywords>distrust,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>19</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 18: SHA-1 Collisions - TLS Fingerprinting - Cisco Trust Anchor Flaw</title><link>https://www.spreaker.com/episode/root-causes-18-sha-1-collisions-tls-fingerprinting-cisco-trust-anchor-flaw--70330058</link><description><![CDATA[Recent news has revealed several important developments in PKI and cyber trust. Our hosts cover the latest SHA-1 collision attack and why it signals the inevitable death of this hashing algorithm. We explain TLS fingerprinting and how it enables malware to defeat firewall AI protections. And we walk through reports of a flaw in the implementation of secure elements on Cisco routers.]]></description><guid isPermaLink="false">7b7927f8-f2e1-4a1d-841f-85939f4f303b</guid><pubDate>Thu, 23 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330058/128_default_tc.mp3" length="20871351" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent news has revealed several important developments in PKI and cyber trust. Our hosts cover the latest SHA-1 collision attack and why it signals the inevitable death of this hashing algorithm. We explain TLS fingerprinting and how it enables...</itunes:subtitle><itunes:summary><![CDATA[Recent news has revealed several important developments in PKI and cyber trust. Our hosts cover the latest SHA-1 collision attack and why it signals the inevitable death of this hashing algorithm. We explain TLS fingerprinting and how it enables malware to defeat firewall AI protections. And we walk through reports of a flaw in the implementation of secure elements on Cisco routers.]]></itunes:summary><itunes:duration>1305</itunes:duration><itunes:keywords>cryptographic primitive,hashing,pki,sha-1,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>18</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 17: Sectigo Acquires Icon Labs</title><link>https://www.spreaker.com/episode/root-causes-17-sectigo-acquires-icon-labs--70330042</link><description><![CDATA[Sectigo's recent acquisition of Icon Labs expands the company's  capabilities in embedded OEM and device identity. Jason and Tim are joined by Icon Labs co-founder Alan Grau as our podcasters explore the needs and potential vulnerabilities for connected devices and the suite of technologies that can address these security requirements.]]></description><guid isPermaLink="false">f0bf4361-85b3-4f51-b4b4-0ccc7968129f</guid><pubDate>Thu, 16 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330042/128_default_tc.mp3" length="18934529" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Sectigo's recent acquisition of Icon Labs expands the company's  capabilities in embedded OEM and device identity. Jason and Tim are joined by Icon Labs co-founder Alan Grau as our podcasters explore the needs and potential vulnerabilities for...</itunes:subtitle><itunes:summary><![CDATA[Sectigo's recent acquisition of Icon Labs expands the company's  capabilities in embedded OEM and device identity. Jason and Tim are joined by Icon Labs co-founder Alan Grau as our podcasters explore the needs and potential vulnerabilities for connected devices and the suite of technologies that can address these security requirements.]]></itunes:summary><itunes:duration>1184</itunes:duration><itunes:keywords>cybersecurity,embedded,iot,pki,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>17</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 16: PKI for DevOps Environments</title><link>https://www.spreaker.com/episode/root-causes-16-pki-for-devops-environments--70330063</link><description><![CDATA[DevOps as a software development and deployment methodology has radically transformed enterprise computing. This approach brings with it new architectures and tools such as containerization, Kubernetes, and multi-cloud. Learn how PKI plays a critical role in DevOps environments and how enterprises can best use certificates to keep their platforms safe.]]></description><guid isPermaLink="false">61a1f179-7365-434e-afc3-c6c62be1fa5a</guid><pubDate>Tue, 14 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330063/128_default_tc.mp3" length="22376840" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>DevOps as a software development and deployment methodology has radically transformed enterprise computing. This approach brings with it new architectures and tools such as containerization, Kubernetes, and multi-cloud. Learn how PKI plays a critical...</itunes:subtitle><itunes:summary><![CDATA[DevOps as a software development and deployment methodology has radically transformed enterprise computing. This approach brings with it new architectures and tools such as containerization, Kubernetes, and multi-cloud. Learn how PKI plays a critical role in DevOps environments and how enterprises can best use certificates to keep their platforms safe.]]></itunes:summary><itunes:duration>1399</itunes:duration><itunes:keywords>devops,devsecops,mtls,pki,ssl,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>16</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 15: Architecture for Enterprise Certificate Automation</title><link>https://www.spreaker.com/episode/root-causes-15-architecture-for-enterprise-certificate-automation--70330064</link><description><![CDATA[Automation of certificate deployment and management is a must for today's enterprise. Complexity, changing environments, fast time to market, and simply scale all dictate that the old manual management methodology is dying away. Join our hosts as they detail the whys and hows of enterprise certificate automation. A must-listen for anyone seeking to understand this rapidly emerging technology space.]]></description><guid isPermaLink="false">7c822f94-8707-4ee7-a183-76dd5eb4c238</guid><pubDate>Tue, 07 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330064/128_default_tc.mp3" length="18486476" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Automation of certificate deployment and management is a must for today's enterprise. Complexity, changing environments, fast time to market, and simply scale all dictate that the old manual management methodology is dying away. Join our hosts as they...</itunes:subtitle><itunes:summary><![CDATA[Automation of certificate deployment and management is a must for today's enterprise. Complexity, changing environments, fast time to market, and simply scale all dictate that the old manual management methodology is dying away. Join our hosts as they detail the whys and hows of enterprise certificate automation. A must-listen for anyone seeking to understand this rapidly emerging technology space.]]></itunes:summary><itunes:duration>1156</itunes:duration><itunes:keywords>certificate lifecycle manageme,certificate lifespans,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>15</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 14: P2P Vulnerability in IoT Devices</title><link>https://www.spreaker.com/episode/root-causes-14-p2p-vulnerability-in-iot-devices--70330065</link><description><![CDATA[Recent research reveals millions of consumer IoT devices that lack any level of authentication or encryption at all. Join our hosts as we discuss the nature of IoT-based botnets and their negative consequences on enterprises, consumers, and the internet at large, including DDoS, phishing, and more.]]></description><guid isPermaLink="false">3884127a-f112-47b9-ac6e-c4a1ac060abe</guid><pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330065/128_default_tc.mp3" length="21150130" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Recent research reveals millions of consumer IoT devices that lack any level of authentication or encryption at all. Join our hosts as we discuss the nature of IoT-based botnets and their negative consequences on enterprises, consumers, and the...</itunes:subtitle><itunes:summary><![CDATA[Recent research reveals millions of consumer IoT devices that lack any level of authentication or encryption at all. Join our hosts as we discuss the nature of IoT-based botnets and their negative consequences on enterprises, consumers, and the internet at large, including DDoS, phishing, and more.]]></itunes:summary><itunes:duration>1322</itunes:duration><itunes:keywords>iot,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>14</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 13: PKI for IoT</title><link>https://www.spreaker.com/episode/root-causes-13-pki-for-iot--70330016</link><description><![CDATA[The proliferation of Internet of Things (IoT) devices in many cases has outpaced security for those devices, leaving enterprises, end users, and the general public exposed. Learn how identity is an essential part of protecting any service involving IoT devices and how PKI is positioned to provide that identity.]]></description><guid isPermaLink="false">5ffee02e-c2db-4cd9-99f7-48c404d61732</guid><pubDate>Thu, 25 Apr 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330016/128_default_tc.mp3" length="19428138" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The proliferation of Internet of Things (IoT) devices in many cases has outpaced security for those devices, leaving enterprises, end users, and the general public exposed. Learn how identity is an essential part of protecting any service involving...</itunes:subtitle><itunes:summary><![CDATA[The proliferation of Internet of Things (IoT) devices in many cases has outpaced security for those devices, leaving enterprises, end users, and the general public exposed. Learn how identity is an essential part of protecting any service involving IoT devices and how PKI is positioned to provide that identity.]]></itunes:summary><itunes:duration>1215</itunes:duration><itunes:keywords>cybersecurity,iot,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>13</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 12: PKI in the News</title><link>https://www.spreaker.com/episode/root-causes-12-pki-in-the-news--70330022</link><description><![CDATA[It was a busy news week for PKI and authenticated identity, and our hosts run through four current stories to clarify them. Tune in to learn the latest about the Dragonblood WPA3 vulnerability, Russian spoofing of GPS/GNSS navigation signals, Know Your Customer (KYC) for social media sites, and a Chinese national's apparent attempt to install a USB rootkit somewhere in Mar-a-Lago.]]></description><guid isPermaLink="false">01a8d7c6-5e4c-446f-b510-8ab4e46a557e</guid><pubDate>Tue, 16 Apr 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330022/128_default_tc.mp3" length="18400795" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>It was a busy news week for PKI and authenticated identity, and our hosts run through four current stories to clarify them. Tune in to learn the latest about the Dragonblood WPA3 vulnerability, Russian spoofing of GPS/GNSS navigation signals, Know...</itunes:subtitle><itunes:summary><![CDATA[It was a busy news week for PKI and authenticated identity, and our hosts run through four current stories to clarify them. Tune in to learn the latest about the Dragonblood WPA3 vulnerability, Russian spoofing of GPS/GNSS navigation signals, Know Your Customer (KYC) for social media sites, and a Chinese national's apparent attempt to install a USB rootkit somewhere in Mar-a-Lago.]]></itunes:summary><itunes:duration>1151</itunes:duration><itunes:keywords>pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>12</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 11: Authentication Is Not for the Authenticated</title><link>https://www.spreaker.com/episode/root-causes-11-authentication-is-not-for-the-authenticated--70330053</link><description><![CDATA[With so much debate about the role and importance of authentication in digital systems, it is important to remember the purpose of authenticated identity in our cyber interactions. Join us for a discussion of who benefits from known identity, what can go wrong when identity is obscured, and why ecosystems must include incentives for members to participate in identity authentication.]]></description><guid isPermaLink="false">a24ac683-c597-4ba7-a79d-15a795a54379</guid><pubDate>Thu, 11 Apr 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330053/128_default_tc.mp3" length="13599725" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>With so much debate about the role and importance of authentication in digital systems, it is important to remember the purpose of authenticated identity in our cyber interactions. Join us for a discussion of who benefits from known identity, what can...</itunes:subtitle><itunes:summary><![CDATA[With so much debate about the role and importance of authentication in digital systems, it is important to remember the purpose of authenticated identity in our cyber interactions. Join us for a discussion of who benefits from known identity, what can go wrong when identity is obscured, and why ecosystems must include incentives for members to participate in identity authentication.]]></itunes:summary><itunes:duration>850</itunes:duration><itunes:keywords>authentication,cryptography,encryption,pki,signing,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>11</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 10: S/MIME Automated Deployment</title><link>https://www.spreaker.com/episode/root-causes-10-s-mime-automated-deployment--70330067</link><description><![CDATA[S/MIME certificates indicate the authentic identity of the sender and enable encryption for message content and attachments - providing strong defenses against a variety of email-based attacks.  Nonetheless, adoption today is extremely small. Find out what the challenges to past adoption have been for this underutilized security technology and what the industry is doing to help enterprises secure their email today.]]></description><guid isPermaLink="false">75d8ad47-e138-42b1-8d10-ea0dc5645830</guid><pubDate>Wed, 03 Apr 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330067/128_default_tc.mp3" length="17928919" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>S/MIME certificates indicate the authentic identity of the sender and enable encryption for message content and attachments - providing strong defenses against a variety of email-based attacks.  Nonetheless, adoption today is extremely small. Find out...</itunes:subtitle><itunes:summary><![CDATA[S/MIME certificates indicate the authentic identity of the sender and enable encryption for message content and attachments - providing strong defenses against a variety of email-based attacks.  Nonetheless, adoption today is extremely small. Find out what the challenges to past adoption have been for this underutilized security technology and what the industry is doing to help enterprises secure their email today.]]></itunes:summary><itunes:duration>1121</itunes:duration><itunes:keywords>email,encryption,pki,signing,s/mime,ssl,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>10</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 09: 63-bit Serial Numbers</title><link>https://www.spreaker.com/episode/root-causes-09-63-bit-serial-numbers--70330039</link><description><![CDATA[A recently discovered flaw in common practices reveals that potentially millions of active SSL certificates fall short of cryptographic requirements.  Learn how it is that 64-bit certificate serial numbers might offer only 63 bits of entropy and what CAs have to do about it.]]></description><guid isPermaLink="false">b796eeb4-841c-4b2c-9f47-036d3487ef6b</guid><pubDate>Mon, 25 Mar 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330039/128_default_tc.mp3" length="14592351" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>A recently discovered flaw in common practices reveals that potentially millions of active SSL certificates fall short of cryptographic requirements.  Learn how it is that 64-bit certificate serial numbers might offer only 63 bits of entropy and what...</itunes:subtitle><itunes:summary><![CDATA[A recently discovered flaw in common practices reveals that potentially millions of active SSL certificates fall short of cryptographic requirements.  Learn how it is that 64-bit certificate serial numbers might offer only 63 bits of entropy and what CAs have to do about it.]]></itunes:summary><itunes:duration>912</itunes:duration><itunes:keywords>bit length,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>9</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 08: Free PKI Is Not Free</title><link>https://www.spreaker.com/episode/root-causes-08-free-pki-is-not-free--70330060</link><description><![CDATA[The promise of a "free" Microsoft CA was alluring to enterprises in the 2000s, but today's increasingly open computing architectures and agile development methodology have outgrown your old fashioned Microsoft CA. Learn about the seven common use cases where your traditional CA no longer does the job.]]></description><guid isPermaLink="false">f4a6dfed-40f1-4000-b760-92866a71afa5</guid><pubDate>Tue, 19 Mar 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330060/128_default_tc.mp3" length="18220654" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The promise of a "free" Microsoft CA was alluring to enterprises in the 2000s, but today's increasingly open computing architectures and agile development methodology have outgrown your old fashioned Microsoft CA. Learn about the seven common use...</itunes:subtitle><itunes:summary><![CDATA[The promise of a "free" Microsoft CA was alluring to enterprises in the 2000s, but today's increasingly open computing architectures and agile development methodology have outgrown your old fashioned Microsoft CA. Learn about the seven common use cases where your traditional CA no longer does the job.]]></itunes:summary><itunes:duration>1139</itunes:duration><itunes:keywords>microsoft adca,msca,pki,ssl,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>8</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 07: Russian Disconnection from the Internet</title><link>https://www.spreaker.com/episode/root-causes-07-russian-disconnection-from-the-internet--70330040</link><description><![CDATA[Russia has stated that it will disconnect from the internet as a trial exercise for full-blown cyber warfare. This idea presents many problems for Russian services, systems, and businesses, especially since they depend on global systems such as DNS and public Certificate Authorities. Join us to learn some of the problems facing Russia will face if indeed it disconnects.]]></description><guid isPermaLink="false">dbc9ce20-8cd0-4f5e-a6b2-0d008c2ada95</guid><pubDate>Sat, 09 Mar 2019 23:50:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330040/128_default_tc.mp3" length="11055162" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Russia has stated that it will disconnect from the internet as a trial exercise for full-blown cyber warfare. This idea presents many problems for Russian services, systems, and businesses, especially since they depend on global systems such as DNS...</itunes:subtitle><itunes:summary><![CDATA[Russia has stated that it will disconnect from the internet as a trial exercise for full-blown cyber warfare. This idea presents many problems for Russian services, systems, and businesses, especially since they depend on global systems such as DNS and public Certificate Authorities. Join us to learn some of the problems facing Russia will face if indeed it disconnects.]]></itunes:summary><itunes:duration>691</itunes:duration><itunes:keywords>sovereign internet</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>7</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 06: Quantum-Resistant Cryptography</title><link>https://www.spreaker.com/episode/root-causes-06-quantum-resistant-cryptography--70330043</link><description><![CDATA[The pending cryptographic Quantum Apocalypse requires that we replace the hashing and encryption algorithms used through the internet, enterprise networks, mobile service, and popular devices. Join our experts to learn more about the requirements for quantum-resistant algorithms to survive the Quantum Apocalypse.]]></description><guid isPermaLink="false">b9483238-8dad-4371-b40a-ba82ce09a6ca</guid><pubDate>Sat, 09 Mar 2019 23:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330043/128_default_tc.mp3" length="19899596" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The pending cryptographic Quantum Apocalypse requires that we replace the hashing and encryption algorithms used through the internet, enterprise networks, mobile service, and popular devices. Join our experts to learn more about the requirements for...</itunes:subtitle><itunes:summary><![CDATA[The pending cryptographic Quantum Apocalypse requires that we replace the hashing and encryption algorithms used through the internet, enterprise networks, mobile service, and popular devices. Join our experts to learn more about the requirements for quantum-resistant algorithms to survive the Quantum Apocalypse.]]></itunes:summary><itunes:duration>1244</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>6</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 05:  Cryptographic Quantum Apocalypse</title><link>https://www.spreaker.com/episode/root-causes-05-cryptographic-quantum-apocalypse--70330046</link><description><![CDATA[The pending cryptographic Quantum Apocalypse requires that we replace the hashing and encryption algorithms used through the internet, enterprise networks, mobile service, and popular devices. Join our experts to learn more about the requirements for quantum-resistant algorithms to survive the Quantum Apocalypse.]]></description><guid isPermaLink="false">52976ddf-4226-4968-806a-90269e54ab71</guid><pubDate>Sat, 09 Mar 2019 22:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330046/128_default_tc.mp3" length="18394943" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The pending cryptographic Quantum Apocalypse requires that we replace the hashing and encryption algorithms used through the internet, enterprise networks, mobile service, and popular devices. Join our experts to learn more about the requirements for...</itunes:subtitle><itunes:summary><![CDATA[The pending cryptographic Quantum Apocalypse requires that we replace the hashing and encryption algorithms used through the internet, enterprise networks, mobile service, and popular devices. Join our experts to learn more about the requirements for quantum-resistant algorithms to survive the Quantum Apocalypse.]]></itunes:summary><itunes:duration>1150</itunes:duration><itunes:keywords>cryptography,encryption,mosca,pki,q date,quantum,ssl,tls,webpki,z date</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>5</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 04:  Australia's New IT Security Back Door</title><link>https://www.spreaker.com/episode/root-causes-04-australia-s-new-it-security-back-door--70330056</link><description><![CDATA[Australia now requires a back door to IT systems. Our hosts are skeptical that this idea will work. Join our PKI experts to learn about the dangers and pitfalls of such a system - and why they have failed in the past.]]></description><guid isPermaLink="false">7106c3f8-7276-4480-b9e6-1c31936daf78</guid><pubDate>Fri, 08 Mar 2019 19:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330056/128_default_tc.mp3" length="24118476" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Australia now requires a back door to IT systems. Our hosts are skeptical that this idea will work. Join our PKI experts to learn about the dangers and pitfalls of such a system - and why they have failed in the past.</itunes:subtitle><itunes:summary><![CDATA[Australia now requires a back door to IT systems. Our hosts are skeptical that this idea will work. Join our PKI experts to learn about the dangers and pitfalls of such a system - and why they have failed in the past.]]></itunes:summary><itunes:duration>1508</itunes:duration><itunes:keywords>australia,e2ee,government vs encryption</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>4</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 03:  US Government Shutdown and Security Vulnerabilities</title><link>https://www.spreaker.com/episode/root-causes-03-us-government-shutdown-and-security-vulnerabilities--70330045</link><description><![CDATA[The US government shutdown has taken its toll on IT systems. Services are going offline, and we are ill equipped to deal with a major security or service crisis. Tune in to learn more about the risks of the ongoing shutdown to the government's technical infrastructure.]]></description><guid isPermaLink="false">8dc7f45a-2365-4f69-abea-33e82f4b20ee</guid><pubDate>Fri, 08 Mar 2019 15:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330045/128_default_tc.mp3" length="14756609" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>The US government shutdown has taken its toll on IT systems. Services are going offline, and we are ill equipped to deal with a major security or service crisis. Tune in to learn more about the risks of the ongoing shutdown to the government's...</itunes:subtitle><itunes:summary><![CDATA[The US government shutdown has taken its toll on IT systems. Services are going offline, and we are ill equipped to deal with a major security or service crisis. Tune in to learn more about the risks of the ongoing shutdown to the government's technical infrastructure.]]></itunes:summary><itunes:duration>923</itunes:duration><itunes:keywords>cryptography,encryption,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>3</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 02:  O2 Outage and Equifax Breach</title><link>https://www.spreaker.com/episode/root-causes-02-o2-outage-and-equifax-breach--70330057</link><description><![CDATA[In December users of O2, Softbank, and other mobile services experienced a day-long data outage affecting as many as 40 million people. In the summer of 2017 148 million Americans lost their personal data in the Equifax breach.  The common thread?  Both occurred due to certificate expirations. Join our hosts to learn more about this trending vulnerability.]]></description><guid isPermaLink="false">5cd325f2-a53b-42de-b745-91acae75fbae</guid><pubDate>Fri, 08 Mar 2019 14:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330057/128_default_tc.mp3" length="15137787" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>In December users of O2, Softbank, and other mobile services experienced a day-long data outage affecting as many as 40 million people. In the summer of 2017 148 million Americans lost their personal data in the Equifax breach.  The common thread?...</itunes:subtitle><itunes:summary><![CDATA[In December users of O2, Softbank, and other mobile services experienced a day-long data outage affecting as many as 40 million people. In the summer of 2017 148 million Americans lost their personal data in the Equifax breach.  The common thread?  Both occurred due to certificate expirations. Join our hosts to learn more about this trending vulnerability.]]></itunes:summary><itunes:duration>947</itunes:duration><itunes:keywords>breach,certificate lifecycle manageme,cryptography,encryption,outage,pki,ssl,tls,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>2</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Root Causes 01:  Introduction</title><link>https://www.spreaker.com/episode/root-causes-01-introduction--70330048</link><description><![CDATA[Intro to the leading PKI and security podcast. Learn your hosts' qualifications and reasons for creating this podcast.]]></description><guid isPermaLink="false">c1a4de7b-944c-4681-a0ec-1df0fa6ebb6b</guid><pubDate>Fri, 08 Mar 2019 00:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70330048/128_default_tc.mp3" length="8069262" type="audio/mpeg"/><itunes:author>Tim Callan</itunes:author><itunes:subtitle>Intro to the leading PKI and security podcast. Learn your hosts' qualifications and reasons for creating this podcast.</itunes:subtitle><itunes:summary><![CDATA[Intro to the leading PKI and security podcast. Learn your hosts' qualifications and reasons for creating this podcast.]]></itunes:summary><itunes:duration>505</itunes:duration><itunes:keywords>pki,root causes podcast,webpki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6cce06141d2d3767d9fe12672a5e718b.jpg"/><itunes:episode>1</itunes:episode><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
