-
Podcast Oct 27, 2021
Root Causes 184: Popular College WiFi Vulnerability Revealed
Certificate misconfiguration in commonly used college WiFi can expose logins. We discuss WiFi authentication, EAP, and how this vulnerability occurs.
-
Podcast Oct 21, 2021
Root Causes 183: New MSCA Attack Toolkits
A new white paper and set of toolkits illuminate MSCA root key attacks. We provide a clear action list for IT professionals in charge of Microsoft CA.
-
Blog Post Oct 19, 2021
There’s a healthy discussion in the world of public SSL certificates: the OU field. Standing for Organizational Unit and currently unrestricted in its use, many IT professionals feel the data often placed in this field leads to confusion. It is an unauthenticated field that may soon be greatly restricted in usage — or even eliminated altogether.
-
Podcast Oct 18, 2021
Root Causes 182: Let's Encrypt Root Expiration
Let's Encrypt's recent root expiration caused widespread service outages. We discuss this expiration and the recipe for avoiding problems in the future.
-
Podcast Aug 30, 2021
Root Causes 181: Limitation of DCV Through Web Site Changes
Domain Control Validation (DCV) for SSL certificates using the "change to web site" method will be changing late this year. We explain these changes.
-
Podcast Aug 26, 2021
Root Causes 180: PetitPotam MSCA Attack
WE describe the PetitPotam MSCA attack and related terms like Mimikatz, pass-the-hash, and NTLM Relay, including a mitigation roadmap and free resources.
-
Podcast Aug 24, 2021
Root Causes 179: Standards for Certificates Apart from SSL
SSL is not the only regulated type of digital certificate. We discuss the rules for S/MIME, eIDAS, code signing, document signing, and SSH certificates.
-
Podcast Aug 20, 2021
Root Causes 178: Stealing Cryptocurrency
We describe the various ways in which cryptocurrency can be stolen, including private key compromise, broker security failure, and login credential theft.
-
Podcast Aug 09, 2021
Root Causes 177: What Is Passwordless?
Passwordless is a hot topic in identity. We explain credential form factors and offer a specific definition of passwordless.
-
Podcast Aug 05, 2021
Root Causes 176: Introducing State-Locality Exclusivity
Sectigo is implementing an important change to its public-facing SSL certificate business called State-Locality Exclusivity. We explain in this episode.
-
Podcast Aug 02, 2021
Root Causes 175: What Is a Linter?
Linters are a venerable coding tool has recently taken on new significant in the world of public certificates. Our hosts explain.
-
Podcast Jul 27, 2021
Root Causes 174: Windows 11 and TPMs
Microsoft has announced that its upcoming Windows 11 release will require TPM 2.0 support at a minimum. We discuss the implications of this announcement.