/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An investigation shows TrustCor Systems, used by Chrome, Safari, and Firefox as a root certificate authority, has connections to US intel and law enforcement

TrustCor Systems vouches for the legitimacy of websites.  But its physical address is a UPS Store in Toronto. Tweets: @shashj , @josephmenn , @jvagle , @matthew_d_green , and @v0max Tweets: Shashank Joshi / @shashj : “An offshore company that is trusted by the major web browsers and other tech companies to vouch for the legitimacy of websites has connections to contractors for U.S. intelligence agencies and law enforcement” https://twitter.com/... Joseph Menn / @josephmenn : New by me at The Post: One of the powerful root certificate authorities trusted by big web browsers to vouch for websites operates from a UPS Store address and has ties to a U.S. intelligence contractor selling interception gear. https://www.washingtonpost.com/ ... Jeffrey Vagle / @jvagle : TrustCor Systems, a root cert authority with intelligence community ties that's registered in Panama and operates out of a UPS Store PO box in Toronto. Cool. (via @josephmenn) https://www.washingtonpost.com/ ... Matthew Green / @matthew_d_green : Oh look: a fake CA tied to a surveillance company. Nothing to see here. https://www.washingtonpost.com/ ... @v0max : One of their products, @msgsafeio, purports to offer end-to-end encrypted email...which isn't. Passwords and message contents are sent plaintext and/or base64 encoded over TLS to their servers. https://twitter.com/...

Washington Post Joseph Menn

Context & Ripple Effects

The web's root-store system has been here before: when WoSign issued a valid SSL cert for GitHub's domain to an unrelated user, the major browsers demonstrated they can and will cut off a root certificate authority that loses their confidence. TrustCor is now under the same kind of scrutiny, but for a different reason — not misissuance, but who stands behind it.

The Washington Post investigation reports that TrustCor, registered in Panama and operating from a UPS Store PO box in Toronto despite being trusted as a root CA by Chrome, Safari, and Firefox, has connections to contractors for U.S. intelligence agencies and law enforcement. Related reporting also flags its msgsafeio email product as advertising end-to-end encryption while allegedly sending passwords and message contents in plaintext.

First-order effects

  • Chrome, Safari, and Firefox each face an immediate decision on whether TrustCor stays in their root programs, since a root CA tied to intelligence contractors is hard to defend on governance grounds alone.
  • Every site holding a TrustCor-issued certificate is exposed: if the roots are removed, those sites break for users until they reissue from another CA.

Second-order effects

  • [[a:985404|Mozilla's Firefox and Microsoft's Edge are already planning to stop trusting new TrustCor certificates]], which pressures Google and Apple to match rather than remain the outliers still trusting the root.
  • Other certificate authorities should expect intensified due diligence on ownership and physical operations, because the investigation's red flags — offshore registration, a mailbox address, undisclosed affiliations — are now a template reporters and auditors will apply across the ecosystem.

Third-order effects

  • Trust in the web's public key infrastructure is becoming a governance question rather than a purely technical one: the WoSign case set the precedent for removal over misissuance, and TrustCor extends it to opaque ownership and state-contractor ties.
  • If confidence in Western-rooted CAs keeps eroding through incidents like this, the fragmentation path is already visible in Russia standing up its own trusted TLS certificate authority after sanctions blocked Russian sites from renewing certificates — a split-root web where trust follows jurisdiction.

The trend: The certificate authority system is shifting from a technical trust layer into a contested governance arena, where browsers act as de facto regulators and states respond by building parallel trust hierarchies.

Discussion

  • @pauldokas Paul Dokas on x
    🧵 😬 https://twitter.com/...
  • @v0max @v0max on x
    So remember 6+ months when Joel and I outed a shady defense contractor for distributing a malware SDK in the US Play Store by lying to app developers about what it did? https://twitter.com/...
  • @v0max @v0max on x
    A decade ago, @rsingel and @csoghoian found these devices for sale, which purported to break TLS for lawful intercept purposes: https://www.wired.com/... But until now, *how* they were doing it was largely a mystery. The answer seems to be that they simply set up their own CA!
  • @v0max @v0max on x
    One of their products, @msgsafeio, purports to offer end-to-end encrypted email...which isn't. Passwords and message contents are sent plaintext and/or base64 encoded over TLS to their servers. https://twitter.com/...
  • @v0max Serge Egelman on x
    It turns out they also own a certificate authority! Their roots are everywhere. (Seriously, you should delete them in the off-chance they don't get pulled this week.) https://www.washingtonpost.com/ ...