Certificate authorities

When your browser says a website is genuine, it is trusting a third party who vouched that this key belongs to this name. That third party is a certificate authority.

Your device ships with a list of authorities it trusts, and the awkward property is that in the public web any one of them can vouch for any name. So the system is only as strong as the least careful organisation on that list, which historically has not always been very careful. It works well enough to run the internet on, but it is worth understanding what is actually being trusted, which is a list somebody else curates.

Checked against the primary source.

More on Cryptography