/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mozilla accuses Chinese certificate authority WoSign of back-dating SHA-1 certificates and other violations, proposes no longer trusting WoSign certificates

Michael Mimoso / Threatpost :

Threatpost Michael Mimoso

Context & Ripple Effects

Mozilla's distrust proposal is the escalation of a month-old incident: as documented earlier in September, WoSign issued a valid SSL certificate for GitHub's primary domain to a subdomain customer and declined to revoke it even after being alerted. Back-dated SHA-1 certificates are the second alleged violation stacked on top of that mis-issuance.

The stakes go beyond one CA: because browser vendors control the root trust stores, Mozilla's move effectively decides whether WoSign can sell TLS at all. The related coverage shows where this path leads — Google's Chrome 61 distrust of WoSign and StartCom and Microsoft joining Apple, Google, and Mozilla in disabling the CA's certificates.

First-order effects

  • If Mozilla's proposal ships, every site running a WoSign-issued certificate faces browser warnings in Firefox unless it reissues from another CA, hitting WoSign's paying customers first.
  • WoSign loses the credibility needed to contest the findings publicly, since the back-dating allegation implies deliberate concealment rather than an operational error like the GitHub mis-issuance.

Second-order effects

  • The other major browser vendors face pressure to match Mozilla's decision or explain why their trust stores still vouch for a CA Firefox rejects — a coordination dynamic the coverage confirms played out when Microsoft joined Apple, Google, and Mozilla in disabling WoSign and StartCom certificates.
  • StartCom, WoSign's subsidiary, inherits the penalty through shared ownership, collapsing two CAs' businesses into one enforcement action.

Third-order effects

  • Browser makers are consolidating de facto regulatory power over the global TLS supply chain: audit failures now end in commercial death rather than probation, a template later applied when Firefox and Edge moved against TrustCor over its defense-contractor ties.
  • Certificate buyers gain an argument for concentrating on a small set of heavily scrutinized CAs, accelerating consolidation of the CA market around vendors that survive multi-browser audits.

The trend: Web trust is shifting from self-regulated certificate authorities to browser vendors acting as the effective regulators, with mis-issuance scandals triggering coordinated cross-vendor distrust rather than fines or remediation.