Still Cyber Podcast Ep 04 – Quantum Challenges & Certificate Overload: Certs, AI, and the Road to Post-Quantum Security
In this week’s Still Cyber, After All These Years, Alan Shimel sits down with Brian Trzupek, SVP of Product at DigiCert, for a wide-ranging conversation about the evolving complexities of digital trust — even as Mitchell contends with the aftermath of the “snow-pocalypse.” Alan and Brian unpack how AI is dramatically increasing certificate inventories, with many organizations now managing tens of thousands of unique certificates, and why that matters for risk and automation. They explore the industry’s transition to a 47-day certificate expiration cycle (seriously — who picked 47 days anyway?) and the implications for operations, outages, and governance.
From modern certificate management, the discussion moves to the future of cryptography: how prepared are we for post-quantum cryptography when Q-Day arrives? Alan and Brian also highlight an exciting initiative in the quantum security space — the Quantum Security 25, a joint venture between Techstrong Group and DigiCert to spotlight the top 25 most influential leaders shaping quantum-secure futures. Nominations are still open, so listeners who want to nominate quantum security leaders can do so via the official form here: Nominate for Quantum Security 25 (quantumsecurity25.com nomination form) (Quantum Security 25)
Tune in for candid insights on securing machine identities, navigating cryptographic change, and the human side of building trust in an increasingly automated and quantum-forward world.
Transcript
Hey everyone. Welcome to another episode of Still Cyber. After all these years, I'm Alan Chimo, and there is no Mitchell Ashley today.
Unfortunately, Mitchell is stuck in the snow. Cop snowpocalypse up. He's up in Colorado.
He has no power in his house, and we made the, we made the, uh, the decision Go. No, go. We're going.
So Mitchell will be on the next one, but I'm really happy to have someone else on here. Otherwise you'd have to listen to me talk for 25 minutes by myself. We've got Brian Pec.
Pec. That's right. You got it.
I've interviewed Brian before, but I'm just terrible with names. Brian is the SVP of product at our friends over at DigiCert. And, uh, we're gonna talk a little bit about some things that really revolve around digital certificates, post quantum encryption, and we're gonna talk about Quantum.
And as Welton, I wanna introduce you all to something we call Quantum Security 25, which is something we're doing with DigiCert, but we're gonna talk security and Quantum and everything else. Brian, welcome to Still Cyber. It's great to have you on.
Thank you. Um, you know, let me just, I think everyone, well, not everyone, people are not gonna know DigiCert, just real quick, let's get that out of the way. Who's DigiCert?
Why should they know you? Yeah, so DigiCert's been around for quite some time. We, uh, started out really as a ca a publicly trusted certificate authority, you know, providing trust between browsers and servers and connections and medical devices and everything that's on the internet, right?
Um, we have extended all of that to really provide an ecosystem around that digital trust where we could manage, you know, all the workflows, all the connections around documents, around, um, you know, networks around, uh, IOT devices against software, uh, and now even into ai, right? So there's some really interesting things that the foundations of what we do with PKI and DNS, um, you know, spreads out to even the, the things we're doing right now with AI that seemed quite new. So it's, uh, very interesting.
Absolutely. You know, we we're gonna come back to the AI piece first. I, I wanted to, I wanted to touch on a lot of my friends out here.
You know, digital certificates have been around, as you said, Brian, a long time. Um, primarily Google has been a big instigator, a mover in this about shortening the lifespans of digital certificates, right? It, and there's a lot of reasons for, it's not just to raise more money on certificate fees, right?
It's about security. The, you know, the longer that certificate's out there, the more of a chance there is that something could go wrong. Yeah.
Right? That something could be compromised. So, the latest, I, I think it's the latest sort of expiration date that's coming on fresh certificates is 47 day, first of all, why we pick 47 days anyway, Brian, That, that, I wish I, I wish I knew a succinct answer to that one.
The powers that be in these consortiums came up with, uh, with that date. But yeah, 47 days probably has some mathematical magic to it that I don't understand. Is that what you think is, I'm thinking think So.
I said 45. You said 50. I said, let's meet in the middle.
We can't do 47 and a half. Let's go 47. No, I want 48.
All right. I'm gonna let you have this one in 47. It, it feels like something like that.
Yeah. Yeah. I mean, it's just random, random stuff.
And maybe that is part of it, that it's random. Of course, we're not, or some players like Google don't wanna stop at 47. They wanna, they wanna get down to 30, they wanna get down to weekly.
I mean, you know, what, what holds us back? Why, why? Well, let's talk about, first of all, Brian, why do we want to make certificates, lifetimes, you know, more fungible, more ephemeral, if you will.
Yeah, I mean, I think it, it comes down to a couple kind of market driving initiatives, if you wanna think of it that way. You mentioned Quantum as we, we talked earlier, right? So anybody not aware, right?
The threat of quantum computing shores algorithm, the ability to reverse RSA algorithms and, uh, you know, be able to effectively kind of crack. Modern crypto is looming out there. And I think NIST has said by, uh, 2029 that, you know, they wanna deprecate RSA as a, as a major algorithm.
That's, that's a big thing, right? That's not even really what's driving 47 day. I mean, when you look at networks and, um, you know, some of the other things, right?
Before you even get that, the 47 day they've introduced, um, this kind of multi-point inspection that we've been deploying that looks at, uh, you know, from different DNS endpoints across the internet to ensure the routes to domains are validated. So there's no BGP attacks in between. We're concerned with things like that, right?
So we're layering all these things together to provide security around the certificate, the network, the identity of the operator of that website, 47 days, kind of the next thing, right? That looks at it and says, we don't want these long lived keys. We don't want the kind of harvest now decrypt later attacks that exist with Quantum to, to be sitting out there.
Um, we, we want to also advance automation, right? So if you have certificates that are currently 398, these is what's allowed. Um, you're not really incentive incentivized to make that thing automatic unless you're maybe in like a cloud workload environment or something that is already automated itself.
So you have this huge disparity between some customers who do a ton of automation, and then others who are like, well, you know, I get an email, I'm gonna renew a cert, and it's 398 days. Um, so I think that push towards greater automation on networks just makes the entire ecosystem more resilient. Because you gotta remember in the event that something happens where there's maybe, uh, a compromise in the chain or validation, you know, uh, compromise or even network like BGP, we talked about compromise or something like that.
If you can automate the replacement of those certificates, and, you know, very quickly the risk of that event has been reduced significantly. And so I think we really drive towards that automation and replacement and, you know, kind of good crypto hygiene around the networks. Absolutely.
Absolutely. You know, to me, the, the, it's two things. Number one is if, if my certificates are so long lived that I gotta worry about it once a year, once every year and a half, I don't have a strong incentive to, to, uh, automate it.
But, but here's the other thing that I think drives certificate automation. It's the amount of certificates. You know, there was a day when I had a company, I had one website, one domain, maybe two domains.
Yeah. You know, but today, you know, the average enterprise is managing, dare I say, hundreds if not thousands of certificates, right? Yeah.
And it, it's, and it's not just the digital, the SSL certificate on your website. It's the identifiable, you know, the certificate of authority, like the identity certificate, and it's not even people, I mean, I guess every person Yeah, right? Is is authenticated that way, but it's the machine certificates every That's right.
Container has a certificate. Every device has a unique certificate, every instance of a cloud, every server. And now, you know, with AI is a, it's every AI agent, every, every, uh, API.
Yep. They all have, you know, you may know this better than me, Brian, the average enterprise, how many certificates are they managing? Oh, it's, I mean, so step back one second.
So as you go into that number, what's fascinating is people, when they generally think about certificates, they're thinking about those kind of publicly trusted certificates, right? I think you were trying to outline there. So the things that they kind of pay for and that they issue, right?
So protect the outside of that network. That number has grown astronomically as services have scaled. But like you were alluding to, when you look inside that network, you look into Kubernetes or containers or cloud systems or things like this, that's where now you get to your question, enterprises typically have about, uh, 50,000 certificates that they're measuring or are managing on that internal network.
And that's kind of, you know, we've heard other enterprises that have many, many more than that, right? So, to your point about, um, scalability, um, you know, it's, this number has just grown, gone, grown so huge and, and out of control that when you take those external certificates and you take those internal certificates and you're interconnecting APIs and workloads and all these sorts of things, they're, you know, I, I always like to say it, and I maybe shouldn't 'cause I'm, you know, kind of in the ca world, but it's, it's like they're little ticking time bombs, right? They, they literally have a clock on them, and they will stop working at some point.
And if you don't have a way to know where they are, and you don't have a way to get to them and replace them, and you have an environment that has, you know, maybe 50,000 in these containers that are kind of ephemeral, it's an even harder problem to keep track of these things. And they're just ticking away, right? And, and we hear time and time again, unfortunately from customers where something will expire somewhere down deep in some deployed infrastructure.
And the chain of events of what it brought down were then felt by a customer externally. Um, and that's really, you know, kind of a, a mission of ours at Dig CER is just providing the tooling and technologies to, to add rich automation around this so we can prevent those outages for people. Absolutely.
So, you know, first was the, the length of the, the life of these certificates, right? Yeah. As they grow shorter, automation becomes more imperative, but that pales in comparison to having to manage 50,000 of these suckers, right?
Yeah. Yeah. Now, automation is no longer a nice to have automation's a must have.
Now, of course, the whole, our whole certificate world, our whole encryption world, which so much of the internet rides on, so much of our privacy is based on, is is based on sort of the RSA algorithms. Yeah. You know, 1 28, 2 even 256 bit encryptions.
And, and for those of you who don't know what that means, you can go look it up or ask your ai, they could explain it to you. But the real monster lurking on the horizon, or has been lurking, has been, you know, post quantum encryption. Because when quantum is real, what would take thousands of years of our best computers right now to, to crack will take maybe minutes.
Uh, of course, you know, for the last 15 years, I've always heard Quantum's five years out, Quantum's, five years Out, it's always right there. Yeah. And it's always five years out.
I go five years later and it's still five years out. But now, but now stuff's getting real, right? Q day.
Yeah. You know, IBM m swears it's gonna be 2028 maybe, but sometime in that timeframe, 20 28, 20 29, we're in 2026, right? Q days, Q days coming days is coming.
And, and the thing about Q Day is everything I've read is, you know, it's not gonna be like happy New Year where we watch the ball drop in Times Square or something. It's gonna be kind of sneaky, right? Well, all of a sudden you're gonna look around and say, holy mackerel, quantum computing is real.
People are really using it. Now we already have sort of models and there are a few folks who are, you know, have models of quantum computers that are working to a certain extent, quantum networking and you know, a lot of quantum technology. Yeah.
But, um, but when qj comes, all these certificates could be rendered obsolete. That's right. And I, I think if, if you, you maybe take a macro view of the whole situation.
The certificate is a very small part of the quantum equation, right? Yeah. So like you said, when, when the algorithms become compromised and you could basically, you know, run a certificate through a quantum computer and get the private key and get all the traffic, right?
That's kind of the promise of quantum. Um, that's the risk, right? But the mitigation for it, Alan, is, is complex, right?
When I talk to customers about this, they come to us and say, Hey, dig, sir, you guys understand certificates. How do I replace those certificates? Do I just need to automate everything on my network?
Well, that's a good start, and that'll help with the certificate. But that certificate is probably on a server. That server has a crypto stack, there's software on that server that's providing cryptography that needs to be updated.
It's probably working through some sort of network, maybe load balancers, maybe, you know, different network infrastructure. It also needs to support those algorithms and quantum the technology, uh, flowing through there, uh, post quantum algorithms flow flowing through there. Um, and then you start to, you go through that like are using, uh, accelerators, right?
There's RSA acceleration hardware that people use. Well, that isn't gonna work anymore when you're not using RSA. So now your whole network slows down.
So now you need to buy more stuff to scale, right? Like, this problem really starts to unpack. And, and I don't think people kind of get that.
There's a lot of depth there. You're replacing software, you're looking at networks, you're looking at your certificates, you're looking at automation, you're looking at, um, you know, the various components. And, and God forbid if the organization is running their own hardware security modules for encryption, those all need to be updated to support these algorithms, right?
And then any downstream technology supported on that. Um, you know, I was talking with a bank, uh, a a couple weeks ago, and they're using, um, you know, uh, smart card like UB tokens and things like this to authenticate those all need to support these algorithms. Yeah.
You look at your Mac, the Mac that maybe you're using right now, your desktop, it has the little touch ID thing. Well, you know, Macs that are, I think six months and older, none of them support post quantum algorithms with your touch id. Right?
You can't even store it in a key chain. So there's all sorts of hardware, there's all sorts of network, there's all sorts of ecosystem that needs to go the certificate. Yes, of course we gotta replace those and provide automation around those and do that.
But there's this infrastructure that needs to be supported that we're, you know, that's the one single biggest thing when we talk to customers is if they come to us and they think it's a cert problem, we're like, there's a lot more you guys are gonna have to do. And now when you're putting your CISO hat on, are you budgeting this? Are you planning for this?
Do you have time to even go endeavor to figure this stuff out? And and I think that's where, you know, maybe two and a half, three years ago, Alan, people kind of were like, well, it's always kind of coming. It's, you know, we're not gonna have to do anything.
But with this NIST announcement that said, Hey, you know, we're looking at 2029 to, uh, kind of correlate with the 47 day, uh, certificate lifetime for RSA to be, uh, effectively deprecated, that really got people to say, whoa, hold on. Now we need to figure this out. Let's get a plan together and let's figure out how we can address this quantum thing across the entirety of our network and infrastructure.
So Brian, I, I, look, I, I agree with you a a hundred percent over on this, but I'm an optimistic kind of guy, right? And so what I always, what I believe is that when it comes to this quantum cryptography, post quantum world, it's one of the few times where I've seen both the government and industry partnering together to get out ahead on this, right? Yeah.
And the fact that NIST did come out and, and the industry did come out and say, Hey, we're gonna deprecate RSA in 2020. They did approve, you know, post quantum algorithms that are, you know, theoretically quantum proof or whatever you want to call it. Um, you know, we w we didn't handle Y 2K that well, even though that turned out to be a bit of a nothing burger, but still remember what it was like back then.
Yeah. People were kind of freaking, um, I think, you know, there's reason to freak here that it's not just about post quantum algorithms. Yeah.
Quite frankly, yeah. As you say, there's a lot that goes into making sure all our equipment can handle these new algorithms, right? But we, we shouldn't be freaking out about it.
We should just be diligent about it, I think. Yeah. Yeah.
And, and I think, you know, to that point, like it's, it's, it's fascinating too 'cause that the, the way I just talked about it was kind of focused on the network, right? But when you look at cryptography and you look at a quantum computer being able to attack just generalized cryptography, cryptography is used everywhere, right? So we kind of dissected the network problem there just a moment ago.
But what about all your databases that have role level encryption? What about all your backups that are encrypted and stored somewhere? What, like all of these things as you look at trying to become quantum ready as an organization, well, you'll need to re-encrypt those things.
You'll need some new keys. You'll need to store them differently. Like there's a whole downstream piece there.
'cause when you look at, you know, the attacks right now that you can't prevent are harvest now decrypt later attacks. People are literally capturing network or traffic or backups or whatever hackers can get their hands on that are encrypted that they can't read right now, but is valuable enough to store, put it on a hard drive. And once a quantum computer is there, now I can get the contents of that.
And you can use your imagination for the kinds of things you could use if you knew in three years you can gain access to it. There's probably some things you'd want access. So I think that's why you'd have an organization and a collaboration between governments and institutions and, uh, you know, uh, commercial vendors to try and solve this.
Because the risk is, is so, so high across all of that plane of data that we use for commerce globally. I mean, imagine if the internet was all HTTP right now, you would never send a message to anybody. Certainly not a credit card.
Like, so there's no way any of these things in systems would function. And if you look at the global economy and how much is pinned on that, it's a pretty big deal that we make sure that keeps working, let alone anything else that goes into secrecy and privacy and all these. And I think, you know, you gotta measure that against you.
You know, you're not putting quantum back in the box like it, it's gonna happen and why is it gonna happen? We focus on the negatives here. But the positives are, there's huge supply chain problems.
There's huge, um, pharma problems, genome problems. There's all these kinds of computationally, um, intense tasks that would take hundreds of thousands of years to do with computers today that they're building these computers and these algorithms to do in moments, right? Yeah.
And so that's why this will happen is we're trying to solve incredible problems With These computers. It's gonna be change. Yeah.
And, and you know, not to mention that they say AI won't really hit its potential until it we're running quantum, right? And vice versa, AI will enable, you know, one, once you have functioning quantum technology, AI will enable breakthroughs. Breakthroughs using that quantum technology and quantum technology will enable breakthroughs on ai.
So it's kind of a very symbiotic, almost relationship. Yeah, definitely Crazy stuff. But, um, you know, I I wanted to mention Brian Wright DigiCert has been, I mentioned this and, and staying outta head, DigiCert's been one of these partners in that effort and has been a company that has really tried to take the lead as we move to a quantum future.
I don't know if I agree with the word post quantum Brian, right? It's quantum, it's not post Quantum. It's not like Q Day happens and, and then Quantum goes away.
It's from that day on, it's quantum. So it's not really, We're Not after Quantum. Yeah.
We're just trying to mark that there's a day when those computers and algorithms become real. Right? Right.
They, they attack all the things you just talked about. Yeah. Right.
But, you know, but DigiCert, as I mentioned, DigiCert has been taking the lead in this, and one of the initiatives they're working on that we're, we're actually working on, right? With, and in partnership with DigiCert is something we're all calling the Quantum Security 25, where we're get, we're trying to stay out ahead of this thing. We're trying to publicize, hey, who are the top 25 or so leaders in this quantum space?
And, you know, and it's still early, there's still time for people to make the top 25. But I, I will tell you here at, at Techstrong, we have been, you know, we've been talking about reporting on Quantum for a while. Um, you know, tech Strong's part of Futurum Group now, and I, I had the chance through FU to meet, um, well, was the former chairman of fu, but he had to step down when he became the CEO of a company called Ion QA guy named Nicolo, Nicolo, Dessi, Nicolo, you know, ion Q is a big company out there in Quantum.
Yeah. So, and then I live, we live in Palm Beach County here in Florida. That's where our offices are.
And you know, Palm Beach County itself has this big push on to be called, uh, quantum Beach. Okay. I know it sounds corny.
It sounds corny. It wasn't my idea. But nevertheless, that we, we've had some conferences down here around quantum technology, and they're, oh, they're putting together all kinds of incentives to get quantum companies to move down here.
Hey, at least we wouldn't have six degrees where you are in Austin. So I I Would love to be at the Quantum Beach right now. Yes.
Yeah, Exactly. Exactly. Austin, Texas is like six degrees right now, So Yeah.
And Austin's not known for its tough weather. It's usually too hot. But anyway, quantum Beach, go figure.
Um, but so, you know, it, there, there is this growing momentum across the industry, and it's not just security, it's not just the post quantum algorithm crowd, it's, it's quantum in general, all of, of what Quantum's gonna mean. I, I had a chance none of, actually, she lives in Miami. She's the CEO of Q Secure.
I don't know if you've ever heard of this company Q Secure, she's got a PhD in AI and now she's working on, on Quantum as well. There, there are amazing people. There's so many very, very IBMs and other companies been working on this, right.
These are all companies that we need to get involved in this Quantum Security 25. Yeah. Um, people that we need to get in here.
But Brian, if, if you can, and I don't know how much you're keyed into all this, I may even be more keyed into it than you, but once we pick the Quantum Security 25, what, what, what's the idea? What's the reasoning? Where do we go from there?
Yeah. I mean, I'm, to be honest with you, I'm not keyed into the whole Quantum 25 largely. I did sort Time.
All right. Let run with it then from the side. Yeah.
That's why I love doing these podcasts. Yeah. So the idea here is let's identify 25 or the top 25 leading personalities.
People, I don't think you can have an AI has to be a real human. Um, you know, who are, who are thought leaders who are pushing the, the, the rope here on, on, on quantum technology and quantum security. Right.
Because yeah. I think a thing we need to be clear on is you really can't let quantum computing out in the wild without quantum security. Right.
Without all hell breaking loose anyway. Yeah. So, um, you know, but who are the leaders in this?
And then I think for the rest of us, it gives us some people to follow, if nothing else. Yeah. People to follow on LinkedIn or X or wherever you follow your, your folks.
Yeah, yeah. As we watch the countdown acute day into a post quantum world, you know, come about. Yeah.
Um, so if you're watching this, listening to this, whatever, and you know, someone who you think is a quantum security 25, the Quantum 25, uh, personality, you can nominate them. Uh, I don't, I don't have the URL infirmary, but it'll be in the notes on, on our podcast, and you can get it off on Techstrong as well, uh, on tech, strong ai, tech, strong, it, any of the tech strong sites will have it as well. Um, but Brian, it's, it's because it's getting real now.
Yeah. We're running low on time, but let me bring it back full circle. Yeah.
Go. The 47 day certificate is, we want us to get into the habit of refreshing our certificates because as two day gets closer, and as this becomes real, we want everyone to be able to have muscle memory, if you will. But the 47 day, uh, standard goes into effect, I think just in another month and a half or so.
March four, 15th March, Yeah. The hides of March. Um, what could people do?
You know, I hope no one's sitting here saying, oh my God, I never heard of that. Right. I, I better get busy.
But there probably is. There probably are. Uh, yeah.
What, what should people do there? Well, I think there's, you know, some pragmatic things, right? So a lot of the customers we have, you know, it's January, what, 26th right now?
Yeah. They're, um, very much get, like, especially if you have a large fleet of certificates, I mean, even if you just got a, a few and you're short staffed, people are pre issuing now, right? So they're saying, Hey, I can still get 398 days for, you know, another month or so, let me just, you know, if I'm close to expiration or if I've got things, let me just get those Now.
Sure. Lemme buy some Time, load it up and buy some time on that network. Um, so I can sort out the harder problems, like how do I automate this stuff?
How do I make sure my DNS works properly with the automation? How do I make sure like all the kinda laddering of, of executing on it? So I think that's probably the most simple advice I give people right now is, you know, kind of preload, get yourself moving so you give yourself some time and then this is your last warning because the timelines are only gonna get shorter.
You know, this year 2026 we got down to 200 days. 20, 27 we got onto a hundred days. 20, 29 we go down, or I'm sorry, 20, 27, we go down a hundred days.
20, 29, we go down to 47 days. So it's only getting less time. You will have to automate.
Um, so this is really the last shot. Yeah. I mean, look, quite frankly, by 2029 we may have had Q Day already, right?
And yes, man, if you didn't change it, Go home, you're not automated by then. Oh, Goodnight. You got trouble.
Yeah, yeah, you Got trouble. That's gonna be trouble. Yeah, Absolutely.
Hey Brian, where can people find out more about all that stuff on DigiCert? com, we've got, you know, all the, the blogs, the events, we've got our World Quantum Readiness Day, which we didn't talk about. Uh oh.
Yes. It kind stitches into your 25. So we've been leading on that for the last, uh, couple years now.
And, and you know, we do awards in there for industry leading companies that not very similar to the Quantum 25 here. Um, you know, just trying to push that forward and get that thinking right. com.
Love it. Brian, I appreciate you coming on. Poor Mitchell stuck somewhere in Colorado in the snow with no power.
Yeah. But you and I, well you had six degrees in Austin, but you made lemonade outta lemons. You went tobogganing and sledding.
We did, Yes. One day your kids will grow up and say, you remember when we, we went sledding here in Austin? And they were like, no way.
Yeah. Yeah. They'll be like, who's the crazy guy that had a toboggan in Austin, Texas?
You know what, that's why you keep it there for 50 years for that once every 50 years thing, man. Um, but thanks for coming on still Cyber, appreciate it. Say hello to all my thanks having me, Alan, sir.
Alrighty, I will. Hey, you've just listened to still Cyber, it's Alan Shiel. No, Mitchell Ashley today, but he'll be back next time.
Until then, everyone take care.

