Certificates bind keys to names through trust chains

A certificate links a cryptographic key to a name, and you believe it because something you already trust vouched for it.

That chain runs back to a list of authorities your device shipped with. Every link is a place the chain can break: an authority that issues carelessly, an intermediate that gets compromised, a device with an extra certificate quietly added. The cryptography is rarely the weak part. The trust chain is.

More on TLS and PKI