L. Jean Camp is the Bank of America Distinguished Professor in Cyber Analytics at the University of North Carolina at Charlotte. Her work has focused on what makes a public key certificate trustworthy, looking at both traditional strength measures as well as contextual and socio-technical issues.
Camp’s research has discovered that PKI failures aren’t primarily about cryptography. Her paper, A Complete Study of P.K.I. (PKI’s Known Incidents), examines over 1300 documented PKI failures and the factors behind them. She’s observed many PKI failures are organizational rather than mathematical.
In this condensed Q&A, she explains where PKI goes wrong, why trust needs to be evaluated in context, and how organizations should be thinking about trust as PKI expands to devices, machines, and AI agents.
So what a certificate actually proves is that you have a 3rd party running a product (maybe it’s a browser product, it’s Google, Apple, or it’s an app on your phone) and they have said, “Hey, these people, you can give them money to provide a method for encrypting your traffic.” When the public key infrastructure was first developed, and if you go back to the IETF mailing list and arguments at conferences, the idea was that it really would prove identity. If you connected to www.Coca-Cola.com you knew you were connecting to Coca-Cola. The domain name system was like signposts or street signs. The original National Academies book was even called “Signposts in Cyberspace: The Domain Name System and Internet Navigation.”
But if the public key infrastructure actually verified identity in a meaningful way, we would not have phishing, because people would not get tricked into logging into the wrong banking website. So what a certificate provides is information about the entity you’re connected with, who they have been certified by, and provides a way to encrypt your communications.
A public key provides not identification, but confidentiality of communications. Now, if you’re connecting to somebody you’ve connected to before, so that you’re really familiar with their domain name, then it is telling you that it is the same entity it was before.
But if it’s a confusing domain name, it’s not giving you identity information. In fact, the existence of the lock icon on a browser can provide confusion about identity, and we can see that PKI-enabled phishing is more effective than phishing without TLS.
So the dominant failure modes we found was misissued public keys, which means the public keys were not compliant with requirements, and that’s due to the business practices of the companies.
There is an inherent conflict in the whole public key business. So if you look at the people who run it on the web, it’s the Certificate Authority Browser Forum. There’s not any user representation there. The rules are defined by people who want to sell you certificates. They want more certificates.
Early on, there were these extended validity keys. The idea was that the CAs would sell public keys so that your kid’s high school website, or my dog’s Instagram account, or whatever, can have a public key certificate. But those companies that wanted to engage in finance or commerce would have an extended validation key. But that never worked, and it never worked because the certificate authorities did not do any additional verification. They did not increase their protection of the customer or end user who was trusting the certificate. They just charged more for EV certificates. So that was a complete failure, although it was theoretically promising.
The incentives were all messed up. The CA Browser incentives are to sell more certificates for more money. They’re not to ensure that end users are not confused. The keys weren’t compliant. There was a hash function that turned out to be mathematically broken. So what happened was this certificate authority, instead of having people just get new certificates with a decent hash function, they were like, we’ll sell you lousier certificates backdated, so the dates were wrong.
And that was a business decision. And so it wasn’t the keys cryptographically, the certificate was weak. For a modern certificate, it was completely broken.
I’m going to answer that with a big “YES”. They’re trusting the subject of the certificate to have represented themselves honestly to the certificate issuer. They’re trusting the certificate issuer to have correctly validated the claims of the subject, which is the most consistent source of failure. They’re trusting the software that they’re using to validate the certificate. And that is one of the most strongly audited parts of the system, and one of the strongest. They’re trusting the open cryptographic standards that are used. Which, again, the binding code, the checking code and the cryptography are all public and all very well audited. And they’re checking the entity that’s running the platform.
You’re not just trusting Google, Mozilla, Brave, and Microsoft, you’re trusting that their confidence in the certificate authority is well placed.
We talked to a series of policy experts, and many of them were intimidated by the mathematics. A lot of policy experts are experts in law. They’re experts in policy. Law is complicated. If you want to write laws, you should understand history, law and government. So that is not a bad thing by any means.
And the technological experts, they understand the math and that’s where they’re going to look for flaws. They understand the math and the coding. So they’re going to harden the crypto. They’re going to build strong code. And then there’s this kind of silent dependence on the larger government’s infrastructure.
We interviewed tech policy professionals who worked in a high level industry in applied crypto, and about the equivalent number of people in DC. The left coast people were like, “Man, those policy people better get this policy right.” And one of those people in DC literally said, “Well, those cryptographers have to be careful.”
And it sort of made me laugh because it illustrates the complexity of the issue. There’s this famous book on organizational decision failures. It’s called Essence of Decision by Graham Allison, and he goes through classic terrible decision making failures. And he says, if the State Department thinks you need a military solution and the DOD wants a State Department solution, you know you have a hairy problem.
The technologists are saying, “We’ve got the math right, but this is a hairy organizational problem, and we really need policymakers to do something,” and the policymakers are saying, “Hey, this technology is really complicated, you better be careful.” Each of them recognizes the limits of their own skill set in solving this incredibly difficult, nuanced problem of global remote trust.
That is one of the reasons I think the policymakers have such a hard time is that it really matters what your goals are. There are rogue certificates, which are rare, which are where people have subverted a certificate authority rather than a certificate authority being careless, or subverted keys.
But if you’re a bank customer, and you want to do online banking, all you have to do is to be able to differentiate the private keys that belong to your bank. But you also want to go shopping. Temu is in China, but their stuff is cheap. You want to buy it. You want to watch this video of somebody else’s dog, because dogs and cats are great. So it’s all about the risk decision. But if you’re sitting in the finance team at work, and you have hundreds of millions of dollars that can be accessed by your account, well, you need to have a little more guidance about what to trust.
It’s not reasonable to ask a human being to have all this knowledge about finance and compliance and risk, and nuclear plants, or the grid, or how the banking system works, and also expect them to have nuanced information about the PKI infrastructure and the organizational, social, and cryptographic risk. People need more guidance than just a little icon.
A lot of the risk can be mitigated by lifecycle. Shorter key lifespan certainly decreases the risk of a subverted key, but it doesn’t decrease the systematic risk of the incentive misalignment that’s endemic to the PKI ecosystem. So I think you need some customization that is risk aware and task aware.
Humans need to understand the implications of their decisions. And that is not something AI can do yet, and we also don’t really understand how AI is making a decision.
The problem with AI is we don’t know what it’s memorized. We don’t know when an AI, if it’s not completely transparent, is saying, “Hey, I’ve seen a certificate like this before. This looks great,” or if it’s genuinely doing weighted decision tree analysis on the contents of the certificate and the relationship between the fields in the certificate.
The other thing AI is terrible at is change. When there’s a big jump, a big change in the world, AI doesn’t immediately become aware of that change. AI is reinforcement learning. So you’ve got to have a human at the very least tell the AI explicitly, and then some other human or some other agents to make sure that that AI actually changed.
Most people and most companies don’t need very many trust anchors. There has been a trend in industry to decrease trust anchors. But the thing is, if you are shipping a browser or a device, you don’t want to get on a plane to Europe or across the Canadian border and suddenly everything breaks. There needs to be contextual human autonomy for control of trust anchors per device.
I feel like there’s a big space between what people who are producing technology for everybody to use to make sure it’s not broken for anyone. Which means that you have to be very open and accepting about what policymakers can do, which means it applies to everybody, and what individual companies need to do to manage their own root risk.
There’s a huge amount of investment in cyber security. But this is one area where there is I think actually a lack of services and customization. There aren’t that many companies that will filter your device routes on all your employees’ mobile and work devices to make sure nobody malicious is phoning home, because it’s a very hard and contextual problem.
I’m going to add AI agents in there because we don’t talk about verifying AI agents yet. We’re just like, “Yeah, open my browser. It’s totally fine. Nobody would ever use AI in an attack.” That was sarcasm.
It means that in theory, when you have a web interaction or you have an app installation, the human being can examine the certificate. They almost never do, but in theory, they could. When you start moving to machines, IoT, and other types, it’s very difficult to get the human in the loop. We simultaneously need human judgment and a stronger layer of some type of machine intelligence.
I think the kind of automatization and level of intelligence varies between applications.
- The Web PKI doesn’t give you meaningful identity information. It provides confidentiality in your connection.
- Audit new certificates in an intelligent way.
- Block all code signing certificates that you are not already trusting. So if you have a relationship with a software provider, they have issued a bunch of code signing certificates so people whose products embed their software can update their products. You don’t need to trust all of those. Understand the limits of your trust, limit your roots of trust, and make these roots of trust part of regular risk audits.
- Treat it like a critical business asset. Look at the history of misissuance. See what companies you can choose to do business with at no cost to yourself.
- Make sure they’re highly trustworthy. Consider the certificate authorities that you trust in all contexts.
- And when those certificate authorities approve second-level entities, when a new one shows up. don’t just automatically trust it.
When somebody comes into your company and sticks a mouse into your computer because it’s a cool new mouse, now they have a code signing key for your computer. And this code signing key was issued in China. So maybe you don’t let them use that mouse.
This Q&A is condensed and lightly edited from a phone interview with L. Jean Camp. Camp’s views are her own and do not represent the position of SecureW2.
SecureW2 is a leader in modern cloud PKI and certificate-based agentic AI security. Through its Signal blog, SecureW2 works with real human technology journalists to interview a range of top industry subject matter experts and thought leaders.