Tim shares his very personal experience with would-be catfishers and we talk about how AI is set to change the catfishing attack.
Tim Callan
Tim Callan has over 20 years of experience in the SSL and PKI technology spaces. Tim leads Sectigo's conformance with industry and regulatory requirements including browser root programs, WebTrust, CA/Browser Forum, and more. Tim is instrumental in driving initiatives to improve certificate agility and successful issuance. A founding member of the CA/Browser Forum and current vice-chair for one of its working groups, Tim is creator and co-host of Root Causes: A PKI and Security Podcast, the world’s most popular podcast dedicated to digital certificates. With 400+ episodes published, Tim is on the forefront of explaining trends that will be essential to the IT professionals, including shortening certificate lifespans and the coming change to post-quantum cryptography.
Recent posts by Tim Callan
The Baseline Requirements, CT logs, the Bugzilla Bloodbath, shortening certificate lifespans, all these trends serve to enforce a high level of quality and predictability across WebPKI certificates. Nearly twenty years after the introduction of EV SSL, we ask if it has served its purpose and should be retired.
Upcoming Webinar
Visibility first: Why discovery is the foundation of your certificate infrastructure
Join Sectigo for a practical look at what real certificate visibility looks like: how automated discovery works across mixed environments and issuing CAs, why it's the prerequisite for crypto agility and PQC readiness, and how teams are replacing manual tracking with continuous, centralized inventory.
Dustin Moody of NIST joins us to talk about the evolution of standardized cryptography beyond the current PQC efforts. Topics include maintaining visibility on cryptography presently in use, 50 years of RSA, and cryptographic heterogeny.
Bas Westerbaan of Cloudflare joins us to discuss recent information that heightens concerns about Elliptic Curve Cryptography (ECC) and its vulnerability to a cryptographically relevant quantum computer (CRQC). We pose the question do we need to deprecate ECC in advance of our migration to ML-DSA and other PQC algorithms.
Join this webinar to learn how modern private Certificate Authorities provide the foundation for authenticating agentic actors at scale, while giving you the visibility, control, and automation required for today’s infrastructure.
We are freshly returned from the 2026 ETSI PQC Conference. We give a debrief on the conference, including the difference between post quantum cryptography (PQC) and quantum key distribution (QKD), the algorithmic zoo, PQC for blockchain, the Dunning Kruger Effect, and cryptographic Frogger.
The session covers NIST’s published PQC standards and ongoing work around Falcon, HQC, and the post-quantum “onramp,” along with migration timelines, the NCCoE Migration to PQC project, and key considerations for the U.S. government’s transition to quantum-resistant cryptography.
This session focuses on how engineering, DevOps, and cloud teams can prepare now by building crypto‑agile infrastructure, enabling automated renewal and bulk‑replace workflows, and updating CI/CD pipelines to support rapid cryptographic change.
