Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Author
Tim Callan and Jason Soroko
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 514: Diary of an Online Firestorm 16.07.2025 12:45
Tim describes how the addition of an item to the CABF face-to-face meeting agenda blew up into a panicked and outraged online thread. We discuss what a more functional response would have looked like.
Root Causes 513: Is Revocation the Best Remedy for CPS Misalignment? 14.07.2025 12:21
We continue our discussion of CPS misalignment by discussing the reasons for revocation as a remedy, its disadvantages, and the possibility of another solution that provides the same benefits at less cost.
Root Causes 512: CPS Versus Practices Misalignment 11.07.2025 12:41
We examine the circumstance where otherwise allowed practices are out of alignment with the stated practices in the relevant CPS. We discuss CA transparency and accountability, increased scrutiny of the CPS, and mass revocation.
Root Causes 511: The GoML Root Store 05.07.2025 15:41
We follow up on our discussion of the Get off My Lawn (GoTM) browser with Jason's adventure in creating his own custom root store.
Root Causes 510: Introducing the GoML Browser 26.06.2025 10:18
We discuss Jason's code vibing journey to create the Get Off My Lawn! (GoTM) browser. We discuss SSL certificate information, EV indicators, and cookie handling.
Root Causes 509: What Is a CPS? 25.06.2025 7:30
We define CPS (Certificate Practices Statement) and explain the role it plays in both the WebPKI and private CAs.
Root Causes 508: What Is Code Vibing? 23.06.2025 17:43
"Code vibing" is using generative AI to create or improve working code. We share Jason's adventure using code vibing to create his own web browser.
Root Causes 507: First Distrust of 2025 19.06.2025 9:32
The first CA distrust event of 2025 comes with two simultaneous CA distrusts. We give you the details.
Root Causes 506: Recap of CABF Face-to-face #65 17.06.2025 8:53
For the first time ever, Jason and I record an episode from the floor of the CA/Browser Forum face-to-face meeting. We recap the themes of this meeting, and Jason gives his first impressions of a CABF Face-to-face.
Root Causes 505: Trust Now, Forge Later 13.06.2025 10:33
In this episode we explain the potential for future quantum computers to break files signed today with RSA or ECC, called "Trust now, forge later."
Root Causes 504: Jason Programs a Quantum Computer 10.06.2025 17:48
Jason describes his recent experience using Amazon Braket.
Root Causes 502: The PQC Game of Chicken 04.06.2025 10:59
In this episode Jason explains the fallacy of "playing chicken" with the Quantum Apocalypse. We discuss stack ranking and "eyes open" PQC risk decisions.
Root Causes 501: Why Increasing RSA Key Size Won't Solve the Quantum Problem 02.06.2025 3:35
In this brief episode we explain why the problem that Shor's Algorithm poses to RSA and ECC can't be solved simply by increasing key size.
Root Causes 500: OMG! 500 Episodes of Root Causes! 29.05.2025 20:46
Wow. It's episode 500 of Root Causes. Jason and Tim talk about how the podcast has evolved in the past six years, how it remains consistent, and the updates we're making to keep being a valuable resource for our listeners.
Root Causes 499: Don't Blame Signal 27.05.2025 8:37
The recent Signal controversy highlights the importance of understanding what protections an E2EE messaging app provides, and what it does not.
Root Causes 498: UK NCSC PQC Guidance 23.05.2025 15:31
The UK National Cyber Security Centre (NCSC) has released new PQC guidance. We take exception to the dates it gives and explain why.
Root Causes 497: PQC Update with Sofia Celi 21.05.2025 19:50
Guest Sofia Celi (IETF, Brave) returns to talk about important developments in post quantum cryptography. Sofia tells us about her candidate algorithm MAYO and what is happening with the NIST PQC onramp. We learn about KEM TLS and the status of PQC initiatives in IETF.
Root Causes 496: E2EE Gmail 18.05.2025 12:26
Gmail is now end-to-end encrypted for all recipients, regardless of the receiving client. We explain how Gmail accomplishes this trick.
Root Causes 495: Trust Models and Post Quantum Cryptography 16.05.2025 7:00
We build on our Trust Models discussion to explore how organizations can structure their PKI for the transition to post quantum cryptography (PQC).
Root Causes 494: Introduction to Trust Models 13.05.2025 21:09
We explain the basics of trust models and compare various models including WebPKI, private CA, and consortium models.
Root Causes 493: Disentangling Public and Private Certificate Use Cases 07.05.2025 12:10
Changing root store requirements mean CAs must separate their root hierarchies for different certificate types. We explain why enterprises should consider private CA for some use cases.
Root Causes 492: When Mandatory Security Training Sucks 06.05.2025 19:36
In this episode we get excited about errors we see in mandatory security trainings.
Root Causes 491: RSA's Non-quantum Threat 01.05.2025 31:41
We are rejoined by Dr. Michele Mosca to explore the potential threat of RSA being broken even in the absence of a quantum computing attack.
Root Causes 490: Chrome and Chromium 28.04.2025 10:02
We define Chrome versus Chromium, explaining what each is and the difference between the two.
Root Causes 489: Does AI Nullify E2EE? 24.04.2025 12:04
Does AI kill end-to-end encryption? There is a contention that the presence of AI agents in the workstream will render your confidential information visible outside the encrypted communication channels and therefore that E2EE is pointless. We explore this argument.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.