Google plans to completely distrust certificates issued by WoSign and StartCom with its Chrome 61 release, following several instances of wrongly issued certs
Charlie Osborne / ZDNet :
Context & Ripple Effects
This is the second time Google has moved to expel a Chinese certificate authority from Chrome: back in 2015 it responded to unauthorized TLS certificates trusted by nearly every operating system by banishing the same CA over a breach of trust. The difference now is scale and process — WoSign and StartCom are being distrusted wholesale in Chrome 61 rather than case-by-case.
The move also extends a template Google built against a much bigger target: after misissued google.com certificates, it gave Symantec an ultimatum (account fully or Chrome flags your certificates), which later hardened into a full distrust plan starting with Chrome 66. WoSign and StartCom are smaller players facing the same escalating playbook.
First-order effects
- Any site still running a WoSign or StartCom certificate faces browser warnings once Chrome 61 ships, forcing operators to reissue from another authority before the release lands.
- WoSign and StartCom effectively lose the largest browser's trust pool overnight, collapsing their commercial value as issuing CAs.
Second-order effects
- Other platform vendors face pressure to match Chrome — and within weeks Microsoft did exactly that, disabling WoSign and StartCom certificates alongside Apple, Google, and Mozilla.
- The successful takedown of two CAs gives Google standing to apply the same treatment to larger ones, as its subsequent Symantec distrust schedule demonstrates.
Third-order effects
- Browser vendors are consolidating de facto regulatory power over the web PKI: unilateral distrust decisions, not industry-body censure, now determine whether a certificate authority survives — a trajectory that ends with StartCom shutting down and revoking all its certificates after blacklisting across every major browser.
- If the pattern holds, certificate authorities operate under a single effective regulator — whichever vendor controls the dominant browser — raising questions about due process and appeal that no current governance body answers.
The trend: Web trust enforcement is shifting from industry consensus bodies to unilateral browser-vendor distrust decisions, with Google's Chrome setting the terms a CA must meet to stay in business.