/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google creates Google Trust Services to operate its own Root Certification Authority

In the support of our work to implement HTTPS across all of our products (https://www.google.com/transparencyrep ort/ https/) we have been operating our own subordinate Certificate Authority (GIAG2), issued by a third-party.

Google Online Security Blog Ryan Hurst

Context & Ripple Effects

This move caps a two-year campaign in which Google shifted from complaining about certificate authorities to policing them. After warning in March 2015 about unauthorized TLS certificates trusted by nearly every operating system, it gave Symantec an ultimatum over misissued google.com certificates — account for them or Chrome would flag Symantec's TLS certs as unsafe.

Until now Google's own HTTPS rollout ran on GIAG2, a subordinate authority issued by a third party. Creating Google Trust Services with its own root means the company enforcing CA standards no longer sits downstream of one.

First-order effects

  • Google's HTTPS-everywhere program now runs on a root it controls end-to-end, removing dependence on third-party issuers whose missteps it has repeatedly had to punish.
  • Commercial CAs lose one of the web's largest certificate consumers as a customer, while gaining it as a direct competitor at the root level.

Second-order effects

Third-order effects

  • If platform companies keep vertically integrating into trust infrastructure, the CA industry restructures around browser vendors as de facto regulators — the entities that decide which roots survive are increasingly the ones issuing their own.
  • That concentration raises an unresolved governance question: who audits the auditor when the enforcer of certificate standards is itself a root operator.

The trend: Web trust infrastructure is consolidating under platform operators that both issue certificates and control the browsers deciding which roots to trust.