Root Causes: A PKI and Security Podcast

Tim Callan and Jason Soroko

Digital certificate industry veterans Tim Callan …

  • 7 minutes 26 seconds
    Root Causes 597: If You Don't Hold the Keys, You Don't Hold the Subpoenas
    Microsoft has publicly stated that it will hand over Bitlocker keys to US law enforcement agencies without requiring a subpoena or court order. These keys can be held by users rather than Microsoft, at their option. We dive into this topic.
    27 March 2026, 2:47 pm
  • 6 minutes 43 seconds
    Root Causes 596: CLM and Operational Uptime
    We usually think of Certificate Lifecycle Management (CLM) as a security category. But we could equally well categorize it as an operations category that enables uptime. In this episode we make our case.
    25 March 2026, 1:21 pm
  • 12 minutes 30 seconds
    Root Causes 595: What Is a Digital Parasite?
    We introduce the concept of a "digital parasite," explaining why this attack philosophy appears to be on the rise.
    23 March 2026, 1:42 pm
  • 16 minutes 57 seconds
    Root Causes 594: Google's Five PQC Recommendations for Policy Makers
    In a recent blog post Google made five recommendations for policy makers. We walk down the list.
    18 March 2026, 9:04 pm
  • 16 minutes 57 seconds
    Root Causes 593: New PQC Guidance from CISA
    CISA (Cybersecurity and Infrastructure Security Agency) has released new guidance about post-quantum cryptography in critical infrastructure, including some very sobering warnings. We go into the details.
    16 March 2026, 9:00 am
  • 8 minutes 44 seconds
    Root Causes 592: When a CAA Record Outlives the CA
    CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out.
    13 March 2026, 8:20 am
  • 11 minutes 46 seconds
    Root Causes 591: Client Authentication Deprecation Date Moves Out
    Chrome's deadline for deprecation of the clientAuth EKU and mTLS in public certificates has moved out. We give you the what, when, and why.
    11 March 2026, 12:00 am
  • 7 minutes 19 seconds
    Root Causes 590: The Size of the CA Is Not the Size of the Risk
    It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has. This is false, however. In this episode we address this misconception.
    10 March 2026, 1:05 am
  • 9 minutes 35 seconds
    Root Causes 589: Is a Cryptographically Relevant Quantum Computer Economically Viable?
    We recently heard the argument that it's simply too expensive to develop a cryptographically relevant quantum computer. We vehemently disagree. In this episode we explain why.
    6 March 2026, 4:45 pm
  • 9 minutes 55 seconds
    Root Causes 588: It's Cryptographic Frogger from Here on Out
    In this episode Tim explains that the transition to PQC is not just a change in cryptographic algorithms but also a fundamental shift in how we treat our cryptography. From here on out, IT systems need to be fundamentally crypto agile in a way we've never had to be before. Cryptographic Agility is the key to solve this problem.
    4 March 2026, 5:49 pm
  • 10 minutes 55 seconds
    Root Causes 587: AI Orchestration for Attackers

    YouTube video version of this episode
    https://youtu.be/-wMy3rPV1Lg

    2 March 2026, 5:47 pm
  • More Episodes? Get the App