The Morning After We Pull a Root of Trust, Nobody Owns It

The Morning After We Pull a Root of Trust, Nobody Owns It

Imagine waking up one morning to find that your bank’s online services have been severely disrupted. The reason? A trusted certificate authority (CA) has been distrusted by major browsers, causing widespread chaos in the financial sector. This scenario may sound like science fiction, but it’s a very real possibility in today’s interconnected world.

In June 2024, Google’s Chrome Root Program made the decision to stop trusting new Transport Layer Security (TLS) certificates from Entrust, citing years of compliance failures and technical issues. While this move was justified, what followed was a predictable outcome: someone else’s problem became everyone else’s responsibility. The reality is that when we pull a root of trust, nobody owns the morning after.

The Web Public Key Infrastructure (PKI) appears to be a decentralized system from the outside, but in reality, it relies on a small set of embedded roots that underwrite TLS, code signing, S/MIME, and machine-to-machine authentication. Remove one of these trust anchors, and the consequences are far-reaching. Every service is chained to it, making the impact not just limited to a single website, but felt across entire industries.

History has shown us what happens when trust continuity fails. DigiNotar in 2011 was breached, issuing over 500 fraudulent certificates that compromised user trust. Symantec, TrustCor, and Entrust have all faced similar issues, with the pain confined to IT teams until it became too late. We’ve been conditioned to think that these incidents are isolated events, but they’re not. The problem is that we haven’t forced a coordinated national response.

The conditions that made past events survivable are rapidly changing. Cryptography and AI are altering the landscape in two significant ways: the move towards post-quantum cryptography, driven by NIST’s standardized replacements (FIPS 203, 204, and 205), is forcing a migration of security primitives on an unpredictable schedule; and AI is lowering the cost for attackers to find weak keys, scale social engineering against CA staff, and probe signing pipelines.

Here lies the uncomfortable truth: no one owns the morning after. CISA coordinates cyber incidents but doesn’t own the trust decision. The CA/Browser Forum sets issuance rules, while NIST publishes guidance, and the Federal PKI governs government certificates. Each entity owns a slice of the pie, but none is responsible for cross-sector cleanup.

This leaves affected parties with no reliable channel to learn about an impending major CA distrust before it becomes public knowledge. The good news is that issuers are starting to move in the right direction. In July 2025, the CA/Browser Forum passed Ballot SC-089, requiring every publicly trusted TLS CA to maintain and annually test a mass revocation plan. However, this only binds the issuers and doesn’t address the issue at hand: enterprises and sectors must also plan, test, and align for trust continuity.

The takeaway is clear: we need to treat trust continuity with the same seriousness as electric-grid black-start or DNS recovery. These plans are named and rehearsed long before the bad day. Public-key trust deserves no less attention. To avoid the chaos that ensues when a root of trust is pulled, someone needs to coordinate at the national level, and playbooks must be in place before an event occurs. This requires a coordinated effort across industries and sectors, with clear roles and responsibilities.

By acknowledging this reality and working together, we can mitigate the risks associated with trust continuity and ensure that when a root of trust is pulled, nobody owns the morning after – because we’ve prepared for it.


Source: Dark Reading — 2026-07-31