An investigation shows TrustCor Systems, used by Chrome, Safari, and Firefox as a root certificate authority, has connections to US intel and law enforcement
TrustCor Systems vouches for the legitimacy of websites. But its physical address is a UPS Store in Toronto. Tweets: @shashj , @josephmenn , @jvagle , @matthew_d_green , and @v0max Tweets: Shashank Joshi / @shashj : “An offshore company that is trusted by the major web browsers and other tech companies to vouch for the legitimacy of websites has connections to contractors for U.S. intelligence agencies and law enforcement” https://twitter.com/... Joseph Menn / @josephmenn : New by me at The Post: One of the powerful root certificate authorities trusted by big web browsers to vouch for websites operates from a UPS Store address and has ties to a U.S. intelligence contractor selling interception gear. https://www.washingtonpost.com/ ... Jeffrey Vagle / @jvagle : TrustCor Systems, a root cert authority with intelligence community ties that's registered in Panama and operates out of a UPS Store PO box in Toronto. Cool. (via @josephmenn) https://www.washingtonpost.com/ ... Matthew Green / @matthew_d_green : Oh look: a fake CA tied to a surveillance company. Nothing to see here. https://www.washingtonpost.com/ ... @v0max : One of their products, @msgsafeio, purports to offer end-to-end encrypted email...which isn't. Passwords and message contents are sent plaintext and/or base64 encoded over TLS to their servers. https://twitter.com/...
Context & Ripple Effects
The web's root-store system has been here before: when WoSign issued a valid SSL cert for GitHub's domain to an unrelated user, the major browsers demonstrated they can and will cut off a root certificate authority that loses their confidence. TrustCor is now under the same kind of scrutiny, but for a different reason — not misissuance, but who stands behind it.
The Washington Post investigation reports that TrustCor, registered in Panama and operating from a UPS Store PO box in Toronto despite being trusted as a root CA by Chrome, Safari, and Firefox, has connections to contractors for U.S. intelligence agencies and law enforcement. Related reporting also flags its msgsafeio email product as advertising end-to-end encryption while allegedly sending passwords and message contents in plaintext.
First-order effects
- Chrome, Safari, and Firefox each face an immediate decision on whether TrustCor stays in their root programs, since a root CA tied to intelligence contractors is hard to defend on governance grounds alone.
- Every site holding a TrustCor-issued certificate is exposed: if the roots are removed, those sites break for users until they reissue from another CA.
Second-order effects
- [[a:985404|Mozilla's Firefox and Microsoft's Edge are already planning to stop trusting new TrustCor certificates]], which pressures Google and Apple to match rather than remain the outliers still trusting the root.
- Other certificate authorities should expect intensified due diligence on ownership and physical operations, because the investigation's red flags — offshore registration, a mailbox address, undisclosed affiliations — are now a template reporters and auditors will apply across the ecosystem.
Third-order effects
- Trust in the web's public key infrastructure is becoming a governance question rather than a purely technical one: the WoSign case set the precedent for removal over misissuance, and TrustCor extends it to opaque ownership and state-contractor ties.
- If confidence in Western-rooted CAs keeps eroding through incidents like this, the fragmentation path is already visible in Russia standing up its own trusted TLS certificate authority after sanctions blocked Russian sites from renewing certificates — a split-root web where trust follows jurisdiction.
The trend: The certificate authority system is shifting from a technical trust layer into a contested governance arena, where browsers act as de facto regulators and states respond by building parallel trust hierarchies.