Certificates bind keys to names through trust chains
A certificate links a cryptographic key to a name, and you believe it because something you already trust vouched for it.
That chain runs back to a list of authorities your device shipped with. Every link is a place the chain can break: an authority that issues carelessly, an intermediate that gets compromised, a device with an extra certificate quietly added. The cryptography is rarely the weak part. The trust chain is.
More on TLS and PKI
- TLS encrypts a connection, not endpoint intentionsA sealed pipe to a stranger
- Certificate expiry creates operational pressureEvery one of them runs out
- Private-key compromise survives a valid certificateThe certificate is fine
- HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit tooThe turning that stops existing
- OCSP stapling moves status evidence closerThe proof comes stapled on
- Mutual TLS authenticates both endsBoth of you show papers
