Mozilla's Firefox and Microsoft's Edge plan to stop trusting new certificates from TrustCor, after a report revealed TrustCor's ties to a US defense contractor
Joseph Menn / Washington Post : Tweets: @reedmideke Tweets: Reed Mideke / @reedmideke : After providing wildly evasive answers to the people who decide whether the whole internet should trust them, @TrustCor appears to be entering the finding out stage https://www.washingtonpost.com/ ...
Context & Ripple Effects
The Washington Post's investigation into TrustCor Systems — a root certificate authority trusted by Chrome, Safari, and Firefox — revealed connections to US defense contractor Packet Forensics and US intelligence and law enforcement, with TrustCor giving what observers called evasive answers to the browser makers who decide whether the whole internet should trust it.
Mozilla has run this playbook before: it refused to include surveillance firm DarkMatter's roots in Firefox in 2019 over UAE hacking allegations, and it moved against China's WoSign in 2016 for back-dating SHA-1 certificates. The difference this time is that Microsoft is moving in lockstep, turning a Mozilla governance call into a cross-browser consensus.
First-order effects
- TrustCor's root program is effectively dead on arrival for new issuance: any new certificate it issues will be rejected by Firefox and Edge, cutting off its commercial web-PKI business at the source.
- Sites still holding existing TrustCor certificates face a forced migration window before browsers stop trusting them outright, pushing reissuance demand toward rival CAs.
Second-order effects
- Google followed within weeks, with Android and Chrome also dropping TrustCor — once Chrome, Firefox, and Edge align, Safari's continued trust becomes the outlier rather than the anchor, and Apple faces pressure to follow.
- Certificate buyers gain one more reason to concentrate on CAs with clean governance records, accelerating the consolidation of the web PKI around a shrinking set of trusted roots like Let's Encrypt, whose free certificates reached universal browser trust back in 2015.
Third-order effects
- If the pattern from WoSign through DarkMatter to TrustCor holds, root-program membership becomes contingent on ownership transparency, not just technical compliance — forcing every CA to disclose control structures or risk removal.
- Browser vendors are hardening their role as the internet's de facto trust regulators, with Mozilla's incident history functioning as precedent that other platforms cite when deciding whom to distrust.
The trend: Web trust is consolidating under browser-vendor governance, where investigative reporting on a certificate authority's ownership can end its business faster than any technical mis-issuance.