Tim Callan and Jason Soroko
Root Causes: A PKI and Security Podcast
Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new laws and regulations, cryptographic advances, and the evolution of our computing architectures to be more virtual, agile, ubiquitous, and cloud-based. Jason and Tim (and the occasional guest subject matter expert) will help you stay current on developments in this essential technology platform and to u...
Author
Tim Callan and Jason Soroko
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Root Causes 488: CABF Face-to-Face Meeting Update 22.04.2025 5:37
We explain the major news items from the most recent CA/Browser Forum face-to-face meeting in Tokyo. Topics include MPIC, 47-day certificate term, and Temporary Restraining Orders.
Root Causes 487: Security 2030 16.04.2025 46:40
Jason and I take a peek forward at what we imagine IT security looks like in 2030. Topics include PQC, ZTNA, "green zones," deep fakes, IoT, connected cars, agentic AI, blockchain, and CLM.
Root Causes 486: 47-day Maximum Term Ballot Passes CABF 14.04.2025 11:11
Apple's ballot to step the maximum term for public SSL certificates down to 47 days has passed in the CA/Browser Forum. We explain.
Root Causes 485: What Is Open MPIC? 13.04.2025 20:28
Guest Dmitry Sharkov joins us to describe Open MPIC, the open-source project to help public CAs support MPIC.
Root Causes 484: Multi Good Factor Authentication 09.04.2025 12:46
We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.
Root Causes 483: Introducing the PQC Sandbox 07.04.2025 22:40
We are joined by repeat guest Bruno Coulliard of Crypto4A to introduce Sectigo's new post quantum cryptography (PQC) sandbox. The PQC sandbox allows you to get quantum resistant certificates in your hands to understand how they work with your systems.
Root Causes 482: Microsoft and PQC 02.04.2025 14:38
In this episode we explore the potential PQC future for Microsoft Active Directory Certificate Services, aka MSCA. We discuss potential paths for Microsoft to take and their consequences.
Root Causes 481: What Is Protocol Ossification? 31.03.2025 11:49
Protocol ossification is the phenomenon whereby ecosystems fail to work correctly with the full range of options included in a protocol. This occurs when individual software components only partially support the capabilities that should be available. We define protocol ossification, explain how and why it occurs, give real world examples, and talk about potential remedies.
Root Causes 480: White House PQC Executive Order 24.03.2025 10:22
Many people believe that the Trump White House rescinded an important cybersecurity executive order from late days of the Biden administration. We set the record straight.
Root Causes 479: AI Adversarial Machine Learning 21.03.2025 13:10
In this episode we discuss the thinking on how adversaries can exploit the flaws in AI models to achieve unexpected and dangerous results. We explore some potential paths of defense against attacks of this sort.
Root Causes 478: Should We All Switch from RSA to ECC? 17.03.2025 16:01
RSA is under attack. Even without the quantum threat, we face the possibility of smart new exploits reducing the viable RSA key space and rendering it unsafe. In this episode we discuss the merits of choosing ECC over RSA as soon as today.
Root Causes 477: Comparative Security Philosophies 12.03.2025 17:51
We discuss how various popular computing platforms approach security and highlight the differences between them.
Root Causes 476: The Need for Security KPIs 10.03.2025 16:34
Jason recounts a 2024 Black Hat talk about the need for objective measurements of our IT defenses and whether the good guys or bad guys are winning. Jason breaks down how to define and measure the impact of security measures.
Root Causes 475: Can Your AI Scheme Against You? 05.03.2025 15:56
It's the stuff of science fiction! Interesting research shows how today's AI technology is capable of lying to and scheming against its human owners in service of its goals.
Root Causes 474: Explaining Shor's Algorithm 02.03.2025 21:12
We talk a lot about Shor's Algorithm in our discussion of post quantum cryptography (PQC). In this episode Jason explains Shor's algorithm for non-quantum physicists.
Root Causes 473: Does Security Software Lack Creativity? 28.02.2025 10:08
Jason reports on a 2024 Black Hat keynote about how modern software development practices inhibit innovation and invention.
Root Causes 472: AI Offensive Modeling 26.02.2025 11:14
AI tools are now available to perform red-teaming activity for DevSecOps. Such tools are soon to be table stakes in the constantly escalating IT security arms race. Join us to learn more.
Root Causes 471: ACME for PQC 23.02.2025 21:28
In this episode, guest Alexandre Giron explains what is needed to support post quantum cryptography (PQC) with ACME.
Root Causes 470: The MFA False Equivalency Fallacy 19.02.2025 11:53
Not all forms of MFA are equally secure. In this episode we describe the differences between the more secure and less secure forms of MFA.
Root Causes 469: The All or Nothing Fallacy in Cybersecurity 17.02.2025 7:14
In this episode we explain the all-or-nothing fallacy in cybersecurity and how it's affecting debate in the WebPKI right now.
Root Causes 468: UK Demands New Backdoor from Apple 14.02.2025 10:25
A new demand from the UK seeks complete access to all Apple cloud data housed in the UK, regardless of the data owners' citizenship and residency. We unpack this latest development in Government versus Encryption.
Root Causes 467: Decoupling Public from Private Use Cases 12.02.2025 9:41
The past year has seen a great deal of focus on the use of public TLS certificates where private root certificates are actually the appropriate solution. In this episode we discuss the differences between these two use cases and what IT organizations can do about it.
Root Causes 466: Apple Moves 47-day Ballot to CABF Vote 09.02.2025 31:21
Apple is proceeding with a ballot that eventually will shorten SSL certificate maximum term to 47 days. Accompanying the ballot, Apple released a statement explaining its intent with the ballot. In this episode we unpack its statements.
Root Causes 465: Twelve Bugzilla Sins for CAs to Avoid 07.02.2025 42:49
In the wake of the Bugzilla Bloodbath, we list and describe twelve sins CAs commit on Bugzilla and its like, why they're detrimental, and how CAs should avoid them.
Root Causes 464: Defending Against Harvest and Decrypt 05.02.2025 9:49
Harvest and decrypt is a well-known attack vector against traditional cryptography prior to PQC. In this episode, we discuss what enterprises should be doing today to defend themselves against harvest and decrypt.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.