/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mozilla's Firefox and Microsoft's Edge plan to stop trusting new certificates from TrustCor, after a report revealed TrustCor's ties to a US defense contractor

Joseph Menn / Washington Post : Tweets: @reedmideke Tweets: Reed Mideke / @reedmideke : After providing wildly evasive answers to the people who decide whether the whole internet should trust them, @TrustCor appears to be entering the finding out stage https://www.washingtonpost.com/ ...

Washington Post Joseph Menn

Context & Ripple Effects

The Washington Post's investigation into TrustCor Systems — a root certificate authority trusted by Chrome, Safari, and Firefox — revealed connections to US defense contractor Packet Forensics and US intelligence and law enforcement, with TrustCor giving what observers called evasive answers to the browser makers who decide whether the whole internet should trust it.

Mozilla has run this playbook before: it refused to include surveillance firm DarkMatter's roots in Firefox in 2019 over UAE hacking allegations, and it moved against China's WoSign in 2016 for back-dating SHA-1 certificates. The difference this time is that Microsoft is moving in lockstep, turning a Mozilla governance call into a cross-browser consensus.

First-order effects

  • TrustCor's root program is effectively dead on arrival for new issuance: any new certificate it issues will be rejected by Firefox and Edge, cutting off its commercial web-PKI business at the source.
  • Sites still holding existing TrustCor certificates face a forced migration window before browsers stop trusting them outright, pushing reissuance demand toward rival CAs.

Second-order effects

  • Google followed within weeks, with Android and Chrome also dropping TrustCor — once Chrome, Firefox, and Edge align, Safari's continued trust becomes the outlier rather than the anchor, and Apple faces pressure to follow.
  • Certificate buyers gain one more reason to concentrate on CAs with clean governance records, accelerating the consolidation of the web PKI around a shrinking set of trusted roots like Let's Encrypt, whose free certificates reached universal browser trust back in 2015.

Third-order effects

  • If the pattern from WoSign through DarkMatter to TrustCor holds, root-program membership becomes contingent on ownership transparency, not just technical compliance — forcing every CA to disclose control structures or risk removal.
  • Browser vendors are hardening their role as the internet's de facto trust regulators, with Mozilla's incident history functioning as precedent that other platforms cite when deciding whom to distrust.

The trend: Web trust is consolidating under browser-vendor governance, where investigative reporting on a certificate authority's ownership can end its business faster than any technical mis-issuance.

Discussion

  • @reedmideke Reed Mideke on x
    After providing wildly evasive answers to the people who decide whether the whole internet should trust them, @TrustCor appears to be entering the finding out stage https://www.washingtonpost.com/ ...
  • @designative Itamar Medeiros on x
    TrustCor Systems was a #rootcertificate authority, a key position in #internet infrastructure. But details about the company raised questions about where it is based and who it works with. https://www.washingtonpost.com/ ... #datasecurity #dataprivacy #internet #browser