Root Causes: A PKI and Security Podcast

Follow Root Causes: A PKI and Security Podcast
Share on
Copy link to clipboard

Digital certificate industry veterans Tim Callan and Jason Soroko explore the issues surrounding digital identity, PKI, and cryptographic connections in today's dynamic and evolving computing world. Best practices in digital certificates are continually under pressure from technology trends, new law…

Tim Callan and Jason Soroko


    • Feb 23, 2026 LATEST EPISODE
    • weekdays NEW EPISODES
    • 16m AVG DURATION
    • 585 EPISODES


    Search for episodes from Root Causes: A PKI and Security Podcast with a specific topic:

    Latest episodes from Root Causes: A PKI and Security Podcast

    Root Causes 584: Mapping DORA to CLM

    Play Episode Listen Later Feb 23, 2026 20:38


    We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are.

    Root Causes 583: AI Versus ECC P 256

    Play Episode Listen Later Feb 21, 2026 10:51


    In an innovative application, an AI has been used to find private keys for ECC (Elliptic Curve Cryptography) P 256. We explain how.

    Root Causes 582: New Research Drastically Cuts Number of Qubits for Cryptographic Relevance

    Play Episode Listen Later Feb 17, 2026 14:11


    New research indicates that the number of qubits necessary to achieve cryptographic relevance has reduced by two orders of magnitude. We cover this breaking news and its implications.

    Root Causes 581: A Timeline for Deprecation of Manual DCV Methods

    Play Episode Listen Later Feb 15, 2026 13:09


    By CABF ballot all manual methods of Domain Control Validation (DCV) will be deprecated by 2028. We explain which methods are due for deprecation and when.

    Root Causes 580: Top Use Cases for Hybrid Certificates

    Play Episode Listen Later Feb 13, 2026 12:47


    We go over the qualities in abstract of a use case that strongly invites the use of hybrid certificates and then run down a list of specific use cases that meet these criteria. This includes OT systems, code signing, secure boot, WiFi, enterprise S/MIME, and more.

    Root Causes 579: Make Cryptography Boring Again

    Play Episode Listen Later Feb 10, 2026 17:44


    In this episode Jason declares that we must make cryptography boring again. We get into what that means and why it matters.

    Root Causes 578: 200 Days Won't Actually Be 200 Days

    Play Episode Listen Later Feb 9, 2026 10:10


    We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days. It happens that all those numbers are too large and the actual maxima will be less than that. We explain.

    Root Causes 577: All the Stuff That's Coming in March

    Play Episode Listen Later Feb 6, 2026 10:05


    March 2026 is due to be the most eventful month in the history of the WebPKI. Join us as we go over all the many changes coming next month.

    Root Causes 576: Jeffries Dumps Bitcoin Due to the Quantum Threat

    Play Episode Listen Later Feb 4, 2026 6:51


    A large investment firm divests from Bitcoin for fear of the quantum threat.

    Root Causes 575: Shortening Certificate Term - All the Dates

    Play Episode Listen Later Feb 2, 2026 20:49


    Everybody knows about March 15 and the drop in maximum public TLS certificate term to 200 days. But that only scratches the surface on key dates with this maximum term reduction. Join us as we go over "all the dates" for TLS maximum term reduction.

    Root Causes 574: 2025 Predictions Scorecard - Part 2

    Play Episode Listen Later Jan 30, 2026 19:33


    We score our 2025 predictions in this second of two parts.

    Root Causes 573: 2025 Predictions Scorecard - Part 1

    Play Episode Listen Later Jan 28, 2026 23:19


    Every new year we make predictions for the year to come, and every year we go back and see how we did. This is the first of two parts scoring our 2025 predictions.

    Root Causes 572: Quality of Entropy

    Play Episode Listen Later Jan 26, 2026 8:44


    We discuss the idea that not all cryptographic entropy is equally "random" and potential consequences.

    Root Causes 571: Will There Ever Be a Cryptographically Relevant Quantum Computer?

    Play Episode Listen Later Jan 23, 2026 9:16


    We discuss the idea that it might be impossible to actually create a cryptographically relevant quantum computer and weigh in on this idea.

    Root Causes 570: PQC Readiness at the Boardroom Level

    Play Episode Listen Later Jan 21, 2026 12:09


    Repeat guest Chris McGrath shares what enterprises need to be doing now to stay on track for the NIST PQC deadline in 2030.

    Root Causes 569: New Regulations Are Changing the PKI Landscape

    Play Episode Listen Later Jan 19, 2026 9:58


    Repeat guest Chris McGrath joins us to discuss how increasingly strict regulations are requiring increased rigor, visibility, and auditability for enterprise digital certificates and PKI.

    Root Causes 568: Upping Your Certificate Game for Better Security

    Play Episode Listen Later Jan 16, 2026 12:35


    Senior cyber security advisor Chris McGrath joins us to discuss redefining digital certificates and their role in your organizational security profile, increasing regulation of certificates, and how enterprises can up their certificate game.

    Root Causes 567: Top 10 PQC Laggards in the Enterprise

    Play Episode Listen Later Jan 14, 2026 20:44


    We name the ten enterprise environments and use cases that are most likely to be late adopters of post quantum cryptography (PQC).

    Root Causes 566: Time Is a Security Primitive

    Play Episode Listen Later Jan 12, 2026 12:18


    We discuss the foundational importance of time in PKI and security in general. This includes when things happen, the order in which things happen, and attacks based on time-spoofing. We drill down on certificates, roots, timestamping, Certificate Transparency, patching, audits, and PQC.

    Root Causes 565: Our Response to QWAC Arguments - Part 3

    Play Episode Listen Later Jan 9, 2026 11:36


    In our concluding episode on the topic, we scrutinize arguments make for and against QWACs, this time focused on "compliance and interoperability."

    Root Causes 564: Our Response to QWAC Arguments - Part 2

    Play Episode Listen Later Jan 6, 2026 11:21


    In our second of three episodes on the topic, we scrutinize arguments make for and against QWACs, this time focused on "governance and sovereignty."

    Root Causes 563: Our Response to QWAC Arguments - Part 1

    Play Episode Listen Later Jan 5, 2026 15:58


    As a follow up to our episode 546, we break down the first of three sets of arguments about QWACs and examine their level of validity.

    Root Causes 562 : What Is a Side Oracle Attack?

    Play Episode Listen Later Dec 30, 2025 7:57


    You may have heard of side channel attacks. Now Jason explains what a side oracle attack is and how a side oracle attack in conjunction with AI could be effective against the HQC or Falcon PQC algorithms.

    Root Causes 561: What Is Classic McEliece?

    Play Episode Listen Later Dec 23, 2025 7:54


    One of the NIST Round 3 PQC finalists that was never selected or eliminated is Classic McEliece. In this episode we explain in non-math terms how this algorithm works.

    Root Causes 560: AI in 1000 Days - Small Language Models

    Play Episode Listen Later Dec 18, 2025 10:53


    Continuing our examination of AI in 1000 days, we discuss the use of finely tuned small language models for highly specific use cases.

    Root Causes 559: AI 1000 days - Content Quality

    Play Episode Listen Later Dec 17, 2025 12:31


    We discuss what happens when the quality gap between AI-generated and human-generated content drops to zero. We explore the consequences of this inevitable outcome.

    Root Causes 558: AI in 1000 days - Human-in-the-loop Economy

    Play Episode Listen Later Dec 15, 2025 7:40


    In our ongoing series on what AI will look like in 1000 days, we discuss the spread of a new business process, where AIs do the bulk of the work while humans sit in the loop for certain specific tasks and roles.

    Root Causes 557: Top 5 PQC Laggards

    Play Episode Listen Later Dec 12, 2025 9:47


    Following up on our list of top 5 PQC vanguards, in this episode we detail the top 5 PQC laggards.

    Root Causes 556: Top 5 PQC Vanguards

    Play Episode Listen Later Dec 10, 2025 9:58


    We describe the top five technology categories that are on the vanguard of driving PQC adoption. We describe what these categories have in common and how that results in early adoption of post quantum cryptography.

    Root Causes 555: Perpretrators of Rogue Certificates

    Play Episode Listen Later Dec 8, 2025 12:42


    We detail the top ten groups inside the organization who introduce rogue certificates into IT organizations.

    Root Causes 554: Disentangling Quantum

    Play Episode Listen Later Dec 5, 2025 10:14


    Tech watchers tend to conflate the many quantum technologies under development right now. In this episode we go through these technologies and explain how they connect.

    Root Causes 553: Connecting Quantum Clocks to Cryptography

    Play Episode Listen Later Dec 3, 2025 5:55


    We discuss quantum clocks and their potential role in cryptography.

    Root Causes 552: 2026 Predictions

    Play Episode Listen Later Dec 1, 2025 32:43


    We share our PKI predictions for 2026. Topics include PQC, eIDAS 2, CT logging, ACME, passkeys, CA distrust, AI model poisoning, and new attack vectors.

    Root Causes 551: PKI in a Swarm at 50 mph

    Play Episode Listen Later Nov 24, 2025 9:53


    Jason explores the role cryptography and trust systems play in the command and control of groups of autonomous drone systems.

    Root Causes 550: WebPKI Certificate Lifespan - How Low Can You Go?

    Play Episode Listen Later Nov 21, 2025 15:46


    Certificate maximum term is shrinking. In this episode we examine exactly how short they could get.

    Root Causes 549: AI 1000 Days from Now - the Defeat of Voice Authentication

    Play Episode Listen Later Nov 19, 2025 18:10


    In our ongoing series on AI in 1000 days, we describe the inevitable, complete distrust of voice printing as an authentication method, including why and what we think will happen.

    Root Causes 548: AI 1000 Days from Now - Emotional Intelligence

    Play Episode Listen Later Nov 17, 2025 17:43


    We begin a new series about what we expect from AI in the next three years. In this episode we discuss AI emulating emotional intelligence and its benefits.

    Root Causes 547: Should We Do Mass Revocation Fire Drills?

    Play Episode Listen Later Nov 14, 2025 12:32


    In this episode we discuss the value for enterprises in running mass revocation drills and compare the merits of tabletop exercises versus voluntary revocation events.

    Root Causes 546: New Research Codifies Arguments for and Against QWACs

    Play Episode Listen Later Nov 12, 2025 43:26


    We are joined by guests Pol Holzmer and Johannes Sedlmeir to describe their recent research that documents and organizes public arguments made about QWAC certificates.

    Root Causes 545: What Is MOSH?

    Play Episode Listen Later Nov 10, 2025 8:18


    The MOSH tool aids the use of SSH-secured sessions, especially across different systems. Jason unpacks the security of this system and how it uses encryption and shared secrets.

    Root Causes 54: What Is Chain of Lure?

    Play Episode Listen Later Nov 7, 2025 10:02


    Chain of lure is an attack method used to circumvent restrictions and boundaries places on AIs. Jason explains this attack and its implications.

    Root Causes 543: AI Finds a Zero Day

    Play Episode Listen Later Nov 5, 2025 17:45


    We have seen the first known instance of an AI tool discovering a zero-day vulnerability. This could have vast implications on vulnerability detection and bug bounty programs. We discuss the implications.

    Root Causes 542: Use Cases for HQC

    Play Episode Listen Later Nov 2, 2025 10:34


    In this episode we go over some of the reasons one might choose HQC over ML-KEM as a PQC key exchange algorithm for specific circumstances. And we discuss the future diversity of cryptography.

    Root Causes 541: Introducing the HQC PQC Algorithm

    Play Episode Listen Later Oct 31, 2025 6:52


    NIST recently selected a second Key Exchange Module (KEM) among the PQC algorithms, HQC. We explain this code-based algorithm.

    Root Causes 540: Contextual CBOM

    Play Episode Listen Later Oct 27, 2025 11:03


    We define Cryptographic Bill of Materials (CBOM), which is more than a list of your cryptography and where it is. A CBOM need also include information about the PQC readiness of environments, availability of updates, and the importance of secrets.

    Root Causes 539: What Is the Two-QWAC Architecture?

    Play Episode Listen Later Oct 22, 2025 20:02


    A new kind of eIDAS QWAC (Qualifieid Website Authentication Certificate) is on the way. The "two-QWAC architecture" introduces a second certificate containing organization information to be displayed by the browser, to sit alongside but independent of the certificate that authenticates a domain. We explain what's coming and why.

    Root Causes 538: What Is an Entropy Desert?

    Play Episode Listen Later Oct 20, 2025 9:02


    An environment in which credentials are extremely predictable could be described as an entropy desert. There are occurring at a global scale. We discuss concepts like measurable entropy availability and entropy by design.

    Root Causes 537: The Thermodynamics of Privacy

    Play Episode Listen Later Oct 17, 2025 13:34


    In this episode we build on our concept of entropy-aware guidance to explain how we might quantify privacy. We touch on GDPR, proof of work, and Landaur's principle.

    Root Causes 536: Patent Blocker on ML-KEM

    Play Episode Listen Later Oct 15, 2025 11:51


    A patent dispute in 2024 nearly blocked ML-KEM. But emerging thinking raises concern that the 2024 resolution did not guarantee full, clear access to all ML-KEM implementations. We explain.

    Root Causes 535: The CPS Is a Superset of Actual Practices

    Play Episode Listen Later Oct 12, 2025 10:22


    The CPS must always be a superset of actual practices in a properly running CA. We explain why this is a product of good design.

    Root Causes 534: Signing the Machines That Think

    Play Episode Listen Later Oct 10, 2025 8:56


    Imagine what happens if you use the wrong LLM, including a malicious model placed there to create mischief or crime. How do you know? Jason proposes that, the same way we sign our code, we should be signing our AI models as well.

    Claim Root Causes: A PKI and Security Podcast

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel