Let's Encrypt warns phones running Android 7.1 or older won't connect to many secure websites starting in 2021 as they will no longer trust its root certificate
It took a long time, but most of the web now uses HTTPS to securely transmit information, partially thanks to a push by Google.
Context & Ripple Effects
The HTTPS transition Google accelerated with Chrome's 2018 decision to mark all HTTP sites "not secure" made certificates issued by the nonprofit Let's Encrypt a default part of the web's plumbing — its free certs are what let millions of sites switch at all. That reach is exactly why the trust-store problem matters: when Let's Encrypt rotates its root, any device whose vendor never shipped the update stops trusting much of the secure web.
Android is the exposure point because of its long support tail — by 2017 Google reported 64% of Chrome traffic on Android already ran over HTTPS, meaning the encryption push succeeded on devices that now can't follow the root rotation.
First-order effects
- Owners of Android 7.1-or-older phones face broken connections to sites using Let's Encrypt certificates starting in 2021 — errors that look like site outages but are actually stale trust stores on the device.
- Sites using Let's Encrypt certs must either accept losing those visitors or switch certificate authorities, adding cost and migration work precisely where budgets are thinnest.
Second-order effects
- Competing certificate authorities gain an argument for paid migration among operators who discover their audiences include legacy-Android users.
- Google faces pressure on the update pipeline itself: root-store maintenance becomes another reason unpatched Android devices degrade faster than Apple's, sharpening the fragmentation critique.
Third-order effects
- Web compatibility increasingly depends on OS vendors shipping root-certificate updates for the life of a device, turning certificate-authority rotations into de facto hardware retirement dates — a structural issue that recurs with every future root change, as later revocation episodes like the TrustCor distrust showed.
- The episode foreshadows certificate authorities building cross-signed intermediaries and other compatibility bridges as standard practice, since a single root expiry can silently cut off a large installed base.
The trend: As the web completes its HTTPS transition, certificate trust is becoming a function of device-update lifecycles, letting OS support policies quietly decide which hardware can still reach the modern web.