Google bans root certificates owned by DarkMatter from Chrome and Android; Mozilla declined to include DarkMatter certificates in Firefox earlier this month
Context & Ripple Effects
Two weeks after Mozilla refused to ship DarkMatter's root certificates in Firefox over the UAE firm's alleged role in hacking citizens, Google has made the same call unilaterally for its own trust stores. The move strips DarkMatter-issued roots from Chrome and Android without waiting for consensus among root program operators.
The precedent here is Chrome's 2015 banishment of a Chinese certificate authority for breach of trust: Google has repeatedly shown it will act alone when it judges an operator unworthy of HTTPS trust, and Mozilla's parallel refusal signals the browser duopoly now moves as a bloc on surveillance-linked certificates.
First-order effects
- DarkMatter loses its path to trusted HTTPS interception on the world's largest browser and mobile OS overnight, and any site chaining to its certificates stops working in Chrome and on Android devices.
- Google absorbs the operational cost of an emergency trust-store revocation across Chrome and Android, reinforcing that its root program answers to its own threat model rather than to customer requests.
Second-order effects
- Apple and Microsoft face immediate pressure to match the exclusion in Safari, macOS, iOS, and Windows, since a certificate trusted anywhere undermines the block everywhere else.
- Certificate authorities serving government clients inherit stricter vetting: with Mozilla and Google both having rejected DarkMatter, resellers and subordinate CAs will distance themselves from surveillance-tied roots rather than risk the same fate.
Third-order effects
- Browser vendors are consolidating into de facto regulators of web encryption: state-linked interception certificates now die by browser veto, not by policy process, a pattern the corpus shows recurring from the Chinese CA ban through the Kazakhstan and TrustCor exclusions.
- Governments seeking lawful-intercept capability lose the commercial route to trusted certificates, pushing interception toward endpoint compromises and device-level exploits instead of the CA system.
The trend: Web trust is shifting from distributed certificate-authority governance to unilateral gatekeeping by browser makers, who increasingly block state-linked roots before formal processes catch up.