Mozilla accuses Chinese certificate authority WoSign of back-dating SHA-1 certificates and other violations, proposes no longer trusting WoSign certificates
Context & Ripple Effects
This proposal is the escalation of a month-old scandal: in early September, researchers documented how WoSign issued a valid SSL certificate covering GitHub's primary domain to a subdomain customer and then declined to revoke it even after being alerted. Mozilla's accusation of back-dated SHA-1 certificates adds a second, deliberate-looking violation on top of the misissuance.
The significance is procedural as much as technical: Mozilla is moving to use its root-store authority — the power every browser holds over which certificate authorities the web trusts — against a major Chinese CA, setting up the enforcement sequence that Google and Microsoft would later join.
First-order effects
- Sites currently authenticated with WoSign-issued certificates face replacement or browser warnings if Mozilla's proposal to stop trusting the CA takes effect in Firefox.
Second-order effects
- Other browser vendors are forced to take positions on the same evidence — a coordination dynamic visible when Google moved to fully distrust WoSign and StartCom in Chrome 61 and Microsoft followed by disabling both CAs, leaving WoSign's subsidiary StartCom commercially dead-ended toward its eventual shutdown.
Third-order effects
- The episode hardens a template of browser-enforced CA accountability — root stores acting as the de facto regulator of certificate authorities — a pattern that recurs years later when Firefox and Edge move against TrustCor over its ties to a US defense contractor.
The trend: Browser vendors are consolidating de facto regulatory power over the web's public key infrastructure, increasingly willing to revoke trust in entire certificate authorities for misissuance.