Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem
Yiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li, Haixin Duan, Jiachen Li, Zaifeng Zhang
Abstract
HTTPS secures communications in the web and heavily relies on the Web PKI for authentication. In the Web PKI, Certificate Authorities (CAs) are organizations that provide trust and issue digital certificates. Web clients rely on public root stores maintained by operating systems or browsers, with hundreds of audited CAs as trust anchors. However, as reported by security incidents, hidden root CAs beyond the public root programs have been imported into local root stores, which allows adversaries to gain trust from web clients. In this paper, we provide the first client-side, nation-wide view of hidden root CAs in the Web PKI ecosystem. Through cooperation with a leading browser vendor, we analyze certificate chains in web visits, together with their verification statuses, from volunteer users in 5 months. In total, over 1.17 million hidden root certificates are captured and they cause a profound impact from the angle of web clients and traffic. Further, we identify around 5 thousand organizations that hold hidden root certificates, including fake root CAs that impersonate large trusted ones. Finally, we highlight that the implementation of hidden root CAs and certificates is highly flawed, and issues such as weak keys and signature algorithms are prevalent. Our findings uncover that the ecosystem of hidden root CAs is massive and dynamic, and shed light on the landscape of Web PKI security. Finally, we call for immediate efforts from the community to review the integrity of local root stores.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c38919b2-762b-415b-8e79-46a4e9094792Cited by top-tier papers3
- TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersWei Xu, Xiang Li, Chaoyi Lu, Baojun Liu et al.CCS 2023 · 15 citations
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 2 citations
- The Maginot Line: Attacking the Boundary of DNS Caching ProtectionXiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang et al.USENIX Security 2023
Builds on9
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes et al.NDSS 2017 · 161 citations
- Killed by Proxy: Analyzing Client-end TLS Interception SoftwareXavier de Carné de Carnavalet, Mohammad MannanNDSS 2016 · 90 citations
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin et al.CCS 2016 · 89 citations
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson et al.S&P 2018 · 86 citations
Related papers
- S/MINE: Collecting and Analyzing S/MIME Certificates at ScaleGurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann et al.USENIX Security 2025
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- Where the Wild Warnings Are: Root Causes of Chrome HTTPS Certificate ErrorsMustafa Emre Acer, Emily Stark, Adrienne Porter Felt, Sascha Fahl et al.CCS 2017 · 53 citations
- The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice in Public Key InfrastructuresJens Hiller, Johanna Amann, Oliver HohlfeldCCS 2020 · 4 citations
- What's in a Name? Exploring CA Certificate ControlZane Ma, Joshua Mason, Manos Antonakakis, Zakir Durumeric et al.USENIX Security 2021 · 16 citations
