Chief Experience Officer at Sectigo (@SectigoHQ). Long time blogger about online security, branding, marketing, and technology.

Granger, Indiana
CAA records exist to restrict issuing CAs for a given domain to as few as one CA. But what happens when the CAA record outlives the CA to which it restricts issuance? Join us to find out. piped.video/watch?v=WbI3p2bp…
52
It would be easy to believe that the amount of risk posed to the WebPKI by any individual public CA is somehow proportional to the number of active certificates that CA has. This is false, however. In this episode we address this misconception. root-causes-a-pki-and-securi…
34
It's cryptographic Frogger from here on out. The transition to PQC is not just a change in cryptographic algorithms but also a fundamental shift in how we treat our cryptography. IT systems need to be fundamentally crypto agile as never before. root-causes-a-pki-and-securi…
24
Jason describes a recent intrusion almost entirely operated by off-the-shelf AI tools. This is an important milestone in security. We describe its potential consequences. root-causes-a-pki-and-securi…
15
We expand on the concept of trust-now-forge-later to list a whole bevy of additional attacks that eventually will be enabled by cryptographically relevant quantum computers. piped.video/watch?v=CRI8BzGJ…
25
We look at the new European DORA and NIS2 regulations and how Certificate Lifecycle Management is a key requirement to meet these requirements. You will be surprised how explicit these requirements are. soundcloud.com/tim-callan/ro…
1
79
We go over the qualities in abstract of a use case that strongly invites the use of hybrid certificates and then run down a list of specific use cases. This includes OT systems, code signing, secure boot, WiFi, enterprise S/MIME, and more. soundcloud.com/tim-callan/ro…
42
We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days. It happens that all those numbers are too large and the actual maxima will be less than that. We explain. soundcloud.com/tim-callan/ro…
42
Everybody knows about March 15 and the drop in maximum public TLS certificate term to 200 days. But that only scratches the surface on key dates with this maximum term reduction. Join us as we go over "all the dates" for TLS maximum term reduction. soundcloud.com/tim-callan/ro…
1
60
Every new year on the Root Causes Podcast we make predictions for the year to come, and every year we go back and see how we did. This is the first of two parts scoring our 2025 predictions. piped.video/watch?v=tpV_706P…
22