2014's Heartbleed vulnerability made it possible to steal private keys directly from web servers, requiring certificate replacement by the millions.
Root Causes Podcast


Podcast Tags
Contributors
Showing 415 to 432 of 550 podcasts
December 10, 202024 min
By Tim Callan and Jason Soroko
2020 was a big year for SASE (Secure Access Service Edge). We define SASE, ZTNA (Zero Trust Network Architecture), and SDP (Software Defined Perimeter).
December 7, 202024 min
By Tim Callan and Jason Soroko
In 2020 COVID-19 changed the way we work. Our hosts dicsuss the affect on employee access, Zero Trust, retail IT, immunity passports, and more.
December 4, 202017 min
By Tim Callan and Jason Soroko
In our ongoing examination of MFA, we examine authentication through soft-token OTP (one-time passcode) and compare it to SMS tokens and hard tokens.
November 30, 202017 min
By Tim Callan, Jason Soroko, and Nick France
Apple's Big Sur OS rollout drove a slowdown in the company's OCSP responders, affecting all Apple operating systems. We explain what happened and why.
November 24, 202016 min
By Tim Callan and Jason Soroko
We discuss the weaknesses of passwords and why they nonetheless are still common. We describe the roadmap for weeding out passwords from most systems.
November 19, 202015 min
By Tim Callan and Jason Soroko
Hard tokens are an old multi-factor authentication (MFA) form factor, still in use today. We examine the strengths and weaknesses of hard tokens.
November 12, 202015 min
By Tim Callan and Jason Soroko
Certificate agility refers to building our systems so that all certificates are known, current, and immediately replaceable.
October 5, 202010 min
By Tim Callan and Jason Soroko
We explore biometric MFA, including strengths and weaknesses and the idea that biometrics are more about proof of possession than identity authentication.
October 1, 202022 min
By Tim Callan and Jason Soroko
PKI and digital certificates depend on asymmetric encryption. Learn the difference between asymmetric and symmetric secrets & how they fit into encryption.
September 28, 202033 min
By Tim Callan and Jason Soroko
A discussion of passwordless authentication and access for Apple platforms (with Joel Rennich of Jamf).
October 28, 202018 min
By Tim Callan, Jason Soroko, and Alan Grau
New research shows how ransomware attacks could be launched against IoT devices. Understand these attacks and what can be done to defend against them.
November 5, 202014 min
By Tim Callan and Jason Soroko
Our hosts discuss what compliance means at a public Certificate Authority (CA) like Sectigo and what the Chief Compliance Officer does.
October 8, 202011 min
By Tim Callan and Jason Soroko
Certificate-based digital identity and Identity and Access Management (IAM) platforms are entirely different things. How do they fit in with each other?
September 21, 202014 min
By Tim Callan, Jason Soroko, and Alan Grau
Our hosts explain terms like Hardware Security Module (HSM), Trusted Platform Module (TPM), Secure Enclave, TrustZone, and Hardware Secure Element (SE).
September 18, 202020 min
By Tim Callan and Jason Soroko
How do digital identity and certificates fit into the SASE (Secure Access Service Edge) paradigm?
September 14, 202018 min
By Tim Callan and Jason Soroko
Learn why crypto agility is more important than ever, why the pace of cryptographic change is going up, and you can do to improve crypto agility.
September 8, 202024 min
By Tim Callan, Jason Soroko, and Alan Grau
Sectigo's Quantum Safe Kit enables hybrid TLS certificates. Find out how hybrid certificates are essential to transitioning to quantum-safe crypto.