-
Listen Now
EPISODE 188
Broadcast Date:
November 11, 202120 minutes
Podcast Nov 11, 2021Root Causes 188: Introduction to Web Security
Malware and other web site attacks can result in reputational damage and site access being blocked or hindered by end user software and services.
-
Listen Now
EPISODE 187
Broadcast Date:
November 8, 202117 minutes
Podcast Nov 08, 2021Root Causes 187: Apple Limits Term for S/MIME Certificates
Apple recently announced that it would limit the allowable term for public S/MIME certificates to 825 days. We explain this declaration's implications.
-
Listen Now
EPISODE 186
Broadcast Date:
November 4, 202120 minutes
Podcast Nov 04, 2021Root Causes 186: Digital Signature SNAFU Costs 3 Billion Euro Contract
In this episode we explain how an esoteric digital signature error rendered a 3 billion Euro manufacturing contract with the Austrian government invalid.
-
Listen Now
EPISODE 185
Broadcast Date:
November 2, 202117 minutes
Podcast Nov 02, 2021Root Causes 185: EU Covid Passport Root Key Stolen
The root certificates of the EU's Covid Passport program have suffered a private key compromise and counterfeit passports are for sale on the black market.
-
Watch Now
Cloud or On-Premise: Updating Assumptions on Secure Certificate Management
A Webinar from Sectigo
Webinar Oct 28, 2021Cloud or On-Premise: Updating Assumptions on Secure Certificate Manage
Join Tim Callan and Jason Soroko explain the difference between Cloud and On-Premise and which is better for secure certificate management.
-
Watch Now
Cloud or On-Premise: Updating Assumptions on Secure Certificate Management
A Webinar from Sectigo
Webinar Oct 28, 2021Cloud or On-Premise: Updating Assumptions on Secure Certificate Manage
Join Tim Callan and Jason Soroko explain the difference between Cloud and On-Premise and which is better for secure certificate management.
-
Listen Now
EPISODE 184
Broadcast Date:
October 27, 202112 minutes
Podcast Oct 27, 2021Root Causes 184: Popular College WiFi Vulnerability Revealed
Certificate misconfiguration in commonly used college WiFi can expose logins. We discuss WiFi authentication, EAP, and how this vulnerability occurs.
-
Listen Now
EPISODE 183
Broadcast Date:
October 21, 202114 minutes
Podcast Oct 21, 2021Root Causes 183: New MSCA Attack Toolkits
A new white paper and set of toolkits illuminate MSCA root key attacks. We provide a clear action list for IT professionals in charge of Microsoft CA.
-
Learn More
A World Where SSL Certificates Do Not Allow Organizational Unit Fields
A Blog Post from Sectigo
Blog Post Oct 19, 2021There’s a healthy discussion in the world of public SSL certificates: the OU field. Standing for Organizational Unit and currently unrestricted in its use, many IT professionals feel the data often placed in this field leads to confusion. It is an unauthenticated field that may soon be greatly restricted in usage — or even eliminated altogether.
-
Listen Now
EPISODE 182
Broadcast Date:
October 18, 202125 minutes
Podcast Oct 18, 2021Root Causes 182: Let's Encrypt Root Expiration
Let's Encrypt's recent root expiration caused widespread service outages. We discuss this expiration and the recipe for avoiding problems in the future.
-
Listen Now
EPISODE 181
Broadcast Date:
August 30, 202113 minutes
Podcast Aug 30, 2021Root Causes 181: Limitation of DCV Through Web Site Changes
Domain Control Validation (DCV) for SSL certificates using the "change to web site" method will be changing late this year. We explain these changes.
-
Listen Now
EPISODE 180
Broadcast Date:
August 26, 202112 minutes
Podcast Aug 26, 2021Root Causes 180: PetitPotam MSCA Attack
WE describe the PetitPotam MSCA attack and related terms like Mimikatz, pass-the-hash, and NTLM Relay, including a mitigation roadmap and free resources.