Root Causes: A PKI and Security Podcast
Tim Callan and Jason Soroko
0
Digital certificate industry veterans Tim Callan and Jason Soroko explore issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic computing world. They discuss best practices in digital certificates under pressure from technology trends, new laws, cryptographic advances, and evolving computing architectures. The podcast helps listeners stay current on developments in this essential technology platform and understand the whys and wherefores of popular Public Key Infrastructures.
Epizode
-
Root Causes 663: The Trouble with Quantum Key Distribution 11.09.2026 22minQuantum Key Distribution (QKD) is supposed to be this highly secure method of key exchange. But is it as secure as people say? We explore the potential weaknesses with QKD. -
Root Causes 662: HAWK Eliminated from NIST Competition, FALCON Unaffected 09.09.2026 5minWe follow up on the recent Mythos attack against PQC candidate HAWK. We discuss the impact of this attack on both HAWK and FALCON. -
Root Causes 661: What Will Happen with eIDAS and MTC? 04.09.2026 10minTLS certificates from CA/Browser Forum CAs are not the only server certificates in the WebPKI. eIDAS QWACs are treated as server certificates by the major browsers. We see clear progress toward post quantum cryptography (PQC) for TLS by way of the Merkle Tree Certificate (MTC) architecture. But what is the path to PQC for eIDAS? We examine this question. -
Root Causes 660: What Are Delegated Credentials? 02.09.2026 3minAs certificate lifespans become extremely short, new methods of delivery become functionally necessary. We explain RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates. -
Root Causes 659: Should We Lengthen Certificate Lifespans? 31.08.2026 12minWith certificate lifespans shortening, we occasionally run into those who disagree with this trend and seek to lengthen maximum term once again. We examine regressive attitudes in PKI, why they occur, and the reasons that lessening security is generally a bad policy. -
Root Causes 658: The Trouble with X9 Certificates 26.08.2026 13minX9 is a consortium certificate for interbanking applications. There is a common misunderstanding that X9 certificates are a public-trust surrogate for mTLS using WebPKI certificates. We clarify why this is not the case. -
Root Causes 657: What Is Chaos Engineering? 24.08.2026 1min"Chaos engineering" describes the practice of injecting faults into a system to see what happens. This is a known strategy for deterministic systems, but with the advent of non-deterministic AI systems, chaos engineering has taken on greater importance. -
Root Causes 656: The Trouble with Recursive AI Training 21.08.2026 6minSince frontier-model AIs have been trained on a large portion of published human knowledge, widespread publication of incorrect information can taint AI results. As more AI-generated slop finds its way onto the internet, this runs the risk of further poisoning AI results. This ultimately can result in completely unusable information. -
Root Causes 655: Why Not to Create Your Own Private CA 19.08.2026 5minIt is possible to use common tools like OpenSSL to create your own ML-DSA private CA. This is a great tool for development and research projects, but Jason explains the pitfalls with trying to do this for production systems. -
Root Causes 654: What's the Difference Between ML-DSA and ML-KEM? 17.08.2026 7minWe are replacing RSA with the combination of ML-DSA and ML-KEM. We explain the naming convention and specifically what these two algorithms do. -
Root Causes 653: Post Quantum Civilization 14.08.2026 7minJason explains de-quantization, which is the practice of using our knowledge of how to use a quantum computer to reframe problems for processing using traditional computing architecture. -
Root Causes 652: Choosing WebPKI Deprecation Dates 12.08.2026 10minThere is no CABF or root program rule preventing public CAs from implementing new requirements earlier than their assigned due dates. We discuss reasons to implement a rule early and how early it should be. -
Root Causes 651: Look at a Calendar 10.08.2026 5minIt is surprising that we continue to see root expirations occur at the most inopportune times. Weekends, public holidays, even New Year's Eve. In this episode we have simple advice to anybody setting up a new root, which is "look at a calendar." -
Root Causes 650: Is It Time to Stop Saying SSL? 07.08.2026 7minSSL hasn't been a standard in use for nearly thirty years, but we still use the word. We discuss why that is, what else we might say, and the expected effect of Merkle Tree Certificates (MTC) on our technical vocabulary. -
Root Causes 649: Client Authentication Certificate Use Cases 05.08.2026 11minWith the upcoming deprecation of client authentication using publicly trusted TLS certificates, we go over the common use cases for these certificates. We discuss the reasons public trust is often chosen and how to transition away from it. -
Root Causes 648: Claude Mythos Discovers New HAWK and AES Attacks 03.08.2026 21minAnthropic recently announced that Mythos has found mathematical weakness in the core algorithm for the third-round NIST PQC candidate HAWK, effectively halving its effective key strength. Mythos also developed a faster attack on a round-reduced version of AES-128. These are not implementation attacks but mathematical attacks on the core cryptography. We discuss the massive implications of these developments. -
Root Causes 647: AD CS "Certighost" Flaw Highlights Agentic Identity Risks 31.07.2026 19minA newly revealed flaw in Active Directory Certificate Services (AD CS) allows an attacker to improperly obtain cryptographic credentials for an agent. We discuss the implications that this flaw Certighost (pronounced sert-uh-GHOST) has for agentic AI at large. -
Root Causes 646: Clarifying the Dates for clientAuth Deprecation 29.07.2026 5minBecause of a change in the drop-dead date, we have observed confusion in the timeline for deprecation of client authentication and mTLS for public TLS certificates. This is an inflexible deadline, and enterprises that are not ready risk outage. In this episode we spell out these dates very clearly. -
Root Causes 645: FAPI 2.0 Principles 27.07.2026 3minIn our series on digital identity for AI agents, we discuss FAPI 2.0 as an option. -
Root Causes 644: Cryptographically Bound Tokens 24.07.2026 5minIn our ongoing series on digital identity for agents, we have previous discussed use of certificates for authentication. In this episode we describe how cryptographic proof of possession can enable secure authentication using tokens.
Popularan u
Ovaj podcast se pojavljuje i u podcast listama ovih zemalja.