Mozilla says it will not include root certificates of surveillance company DarkMatter, which has been accused of helping UAE hack its citizens, inside Firefox
Mozilla declines DarkMatter's application to have its root certificates included in Firefox's root store.
Context & Ripple Effects
Mozilla's rejection of DarkMatter is the latest move in a decade-long pattern of the Firefox root store being used as a conduct filter on certificate authorities. The precedent runs from Mozilla's accusations against Chinese CA WoSign over back-dated SHA-1 certificates in 2016, through the joint Google-Mozilla-Apple-Microsoft blocking of the Kazakhstan government's interception certificate in August 2019, to Firefox and Edge dropping TrustCor over its ties to a US defense contractor in 2022.
First-order effects
- DarkMatter, accused of helping the UAE hack its own citizens, is shut out of Firefox's trusted root store — its certificates will not validate for Firefox users regardless of their technical soundness.
Second-order effects
- Google followed within two weeks with a ban on DarkMatter certificates in Chrome and Android, extending the exclusion to the largest browser and mobile platform and leaving DarkMatter's CA business effectively unviable on mainstream clients.
Third-order effects
- Root program operators are now vetting certificate authorities for ownership and behavior rather than just technical compliance — a governance shift where Mozilla, Google, Apple, and Microsoft collectively decide which states and security firms can anchor web trust, with no formal regulatory oversight of that gatekeeping.
The trend: Browser root stores are evolving into the de facto trust regulator of the web, excluding certificate authorities over conduct and state ties rather than cryptographic failures alone.