Security News

Cybersecurity news aggregator

INFO News Dark Reading

The Morning After We Pull a Root of Trust, Nobody Owns It

  • What: Opinion piece on managing trust in digital certificates
  • Impact: Highlights importance of certificate inventory for security teams
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK CYBERSECURITY ANALYTICS CYBERSECURITY OPERATIONS COMMENTARY The Morning After We Pull a Root of Trust, Nobody Owns It The most valuable move any security team can make is building a certificate and key inventory. Rajeev Mohindra,Independent Researcher July 31, 2026 4 Min Read SOURCE: YUSNIZAM VIA GETTY IMAGES OPINION In June 2024, Google's Chrome Root Program said it would stop trusting new Transport Layer Security (TLS) certificates from Entrust. Behind the decision, years of compliance failures and a clear technical call. The decision was right. The fallout became someone else's responsibility. That is the part we keep getting wrong. We are good at the technical decision to remove a trust anchor. Root programs at Chrome, Mozilla, Microsoft, and Apple make that call well. What we lack is a way to coordinate what happens the morning after. Trust continuity is a national readiness problem hiding inside a browser setting. Web PKI appears distributed from the outside. It is not. A small set of embedded roots underwrites TLS, code signing, S/MIME, and the machine-to-machine auth that runs the economy. Pull one, and the blast radius is not one website. Every service is chained to it. The record is direct. DigiNotar in 2011, breached more than 500 fraudulent certificates; the certificate authority (CA) did not survive. Symantec in 2017 wound down after years of misuse. TrustCor in 2022. Entrust in 2024. Every one was handled. No one forced a coordinated national response, because it was unnecessary. The pain stayed inside IT teams, which swapped a certificate before customers noticed. Related:Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms That is the trap. We read four clean recoveries and think the issue is solved. It isn't. It just hasn't been tested at scale. Picture the scaled version. A regional bank's only CA is distrusted. It cannot process transactions or authenticate systems. Its team scrambles, but the CA is overwhelmed. Within hours, customers are locked out and regulators want answers. Competitors who issued from a second CA do not miss a beat. And the conditions that made the past events survivable are eroding. Two forces are changing the math. Cryptography & AI Alter the Situation First, the cryptography under every trust anchor is on a clock. The National Institute of Standards and Technology (NIST) has standardized the post-quantum replacements, FIPS 203, 204, and 205. That is a forced migration of the primitives that sign and secure everything, on a schedule you do not control. Second, AI lowers the attacker's cost to find weak keys, scale social engineering against CA staff, and probe signing pipelines for the one gap. Rare events get more plausible. Planned migrations get interrupted by sudden ones. Here is the uncomfortable part. No one owns the morning after. The Cybersecurity and Infrastructure Security Agency (CISA) coordinates cyber incidents but does not own the trust decision. The CA/Browser Forum sets issuance rules, not national response. NIST publishes guidance. The Federal PKI governs the government's own certificates. Each owns a slice. None owns the cross-sector cleanup. Today, people about to be affected have no reliable channel to learn that a major CA will be distrusted before the public does. Related:Thousands of Data Center Controllers Open to Takeover The issuers have started to move. In July 2025, the CA/Browser Forum passed Ballot SC-089, which now requires every publicly trusted TLS CA to maintain and annually test a mass revocation plan. That is the right idea, made mandatory. But it binds the issuers, not the rest of us. The enterprises and sectors that have to absorb a mass revocation still have no matching duty to plan, test, or align. We should treat trust continuity the same way we treat electric-grid black-start or DNS recovery. Those plans are named and rehearsed long before the bad day. Public-key trust deserves the same standing. Two things have to be true. Someone should coordinate at the national level, not a new agency whose only job is to connect the people making the distrust call with the sectors who live with it. And the playbooks must be in place before the event. Emergency root removal, intermediate CA compromise, a stolen code-signing key, a forced algorithm sunset, a cross-sector cascade: Each can be written and tested while everyone is calm. Related:Attackers Are Learning to Live Off the AI Toolchain You do not need to wait for any of that. Make three moves this quarter. Build a certificate and key inventory. You can only rotate what you can see. It is the highest-value move most teams are still missing. Name your liaison. One owner must run trust continuity and have the authority to pull people in. Run the tabletop. "Our primary CA gets distrusted in 30 days." Walk it end-to-end and write down where it breaks. Then run it again against the post-quantum migration, because that one is already on the calendar. And issue from more than one CA, so a distrust event is a switch, not a rebuild. The technical decision is not the problem. The morning after is ours to own. When the next root is pulled, the silence will be the sound of your sector scrambling. Break it now. Read more about: Opinion About the Author Rajeev Mohindra Independent Researcher Rajeev Mohindra is a public-key infrastructure specialist who works on certificate-lifecycle security and trust-anchor operations. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like CYBER RISK Claude Mythos Fears Startle Japan's Financial Services Sector by Nate Nelson APR 30, 2026 CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Editor's Choice CYBERATTACKS & DATA BREACHES Hugging Face Hack: Lessons for Cyber Defenders byDark Reading Editorial Team JUL 29, 2026 CYBERSECURITY OPERATIONS Europe's Multilingual Reality Exposes AI Security Gaps byAlexander Culafi JUL 24, 2026 7 MIN READ CYBERSECURITY OPERATIONS Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation byRobert Lemos JUL 24, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article