RSS Amplifier

Podcast

Root Causes: A PKI and Security Podcast

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject…

soundcloud.comSource feed ↗14 episodes

Live Last read · last published · next check

Latest episodes

Saves to your Listen queue, to pick up on another day or another device.

Root Causes 658: The Trouble with X9 Certificates

X9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates. We clarify why this is not the case.

Play

Root Causes 657: What Is Chaos Engineering?

"Chaos engineering" describes the practice of injecting faults into a system to see what happens. This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance.

Play

Root Causes 656: The Trouble with Recursive AI Training

Since frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results. As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results. This ultimately can result in completely unusable information.

Play

Root Causes 655: Why Not to Create Your Own Private CA

It is possible to use common tools like OpenSSL to create your own ML-DSA private CA. This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems.

Play

Root Causes 654: What's the Difference Between ML-DSA and ML-KEM?

We are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do.

Play

Root Causes 653: Post Quantum Civilization

Jason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture.

Play

Root Causes 652: Choosing WebPKI Deprecation Dates

There is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be.

Play

Root Causes 651: Look at a Calendar

It is surprising that we continue to see root expirations occur at the most inopportune times. Weekends, public holidays, even New Year's Eve. In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar."

Play

Root Causes 650: Is It Time to Stop Saying SSL?

SSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary.

Play

Root Causes 649: Client Authentication Certificate Use Cases

With the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it.

Play

Root Causes 648: Claude Mythos Discovers New HAWK and AES Attacks

Anthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these…

Play

Root Causes 647: AD CS "Certighost" Flaw Highlights Agentic Identity Risks

A newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large.

Play

Root Causes 646: Clarifying the Dates for clientAuth Deprecation

Because of a change in the drop-dead date, we have observed confusion in the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage. In this episode we spell out these dates very clearly.

Play

Root Causes 645: FAPI 2.0 Principles

In our series on digital identity for AI agents, we discuss FAPI 2.0 as an option.

Play