The company that verifies safe websites in your browser works for the US government

HTTPS in a browser address bar
(Image credit: Shutterstock)

A company that several major web browsers rely on to verify safe and secure websites has links to U.S intelligence agencies and law enforcement, new research has claimed.

An expose by the Washington Post (TWP) (paywall), which draws its conclusions from documentation, records, and interviews with security researchers.

TrustCor Systems’ Panamanian registration records reveal that it shares personnel with a spyware developer previously identified as having links to Arizona company Packet Forensics, which public records have previously unveiled to have sold “communication interception services” to US agencies “for more than a decade.”

Root certificate infrastructure

Google Chrome, Apple Safari, Mozilla’s supposedly secure browser Firefox, and several others all allow TrustCor to sign root certificates for websites it deems as safe and legitimate, directing users to them, instead of potentially convincing fakes.

TrustCor maintains that it has never cooperated with government information requests or monitored users on behalf of a third party. However, the Pentagon is refusing to comment, and Mozilla is demanding answers from TrustCor while threatening to remove its authority.

The revelations surrounding TrustCor pose a PR nightmare for browsers like Firefox who market themselves as privacy tools, but its own products can now also no longer be considered safe for its end users.

MsgSafe, an email provider from TrustCor that purports to offer end-to-end encryption, has been denounced by security experts speak to TWP, claiming that an early version of the software contained spyware developed by a company linked to Packet Forensics.

 An expert familiar with Packet Forensics’ work explicitly confirmed that it had used TrustCor’s certificate process and MsgSafe to intercept communications and “help the US government catch suspected terrorists”. 

He also claimed that TrustCor’s products and services were only being used to seek out these “high-profile targets”, and there have been  no reports of root certificates being used to vouch for impostor websites for purposes such as data collection.

However, the doubt seeded by the revelations may cause reputational damage to the web browsers involved, as there’s no way of knowing if TrustCor’s strategy will change.

Luke Hughes
Staff Writer

 Luke Hughes holds the role of Staff Writer at TechRadar Pro, producing news, features and deals content across topics ranging from computing to cloud services, cybersecurity, data privacy and business software.

Read more
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
A wall of data on a large screen.
“It's the same doors that the good guys use, that the bad guys can walk through” - former White House tech advisor on data-centric security in the wake of Salt Typhoon
An American flag flying outside the US Capitol building against a blue sky
White House unveils "US Cyber Trust Mark" to help determine if your devices are secure
Ransomware
QR codes can be used to crack this vital browser security tool
Criminals are abusing top-level government domains across multiple countries
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Latest in Software & Services
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
a laptop computer
Windows 11 vs ChromeOS for business: Is one better than the other for your needs?
a laptop computer
Windows 11 vs macOS for business: which side are you on?
Latest in News
Sam Altman and OpenAI
UK regulator clears Microsoft’s $13bn deal with OpenAI after lengthy delay
Google AI Mode
Google previews AI Mode for search, taking on the likes of ChatGPT search and Perplexity
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features