From Chains to Trees 0 ▲ UNMITIGATED RISK 3 hours ago · Tech · hide · 0 comments The WebPKI has two structures that are not the same shape. One is a cryptographic graph of signed bindings. Public keys, names, entitlements, and the keys that authorized them. The other is a governance hierarchy of accountability. It explains why a relying party accepts that authority at all, and when it stops accepting it. Nearly every interesting failure in the history of the system lives in the gap between them. Misissuance, compromise, distrust events, and the long struggle with revocation are all stories about that mismatch. I wrote two long-form pieces that try to make the distinction legible. The first walks through the classical system as it actually exists. What a certificate is, how trust is delegated, how root programs and policy actually work, and why the governance layer has always mattered more than the certificate chain itself. A Deep Dive on the Classical WebPKI The second examines the redesign now underway. Post-quantum signatures are simply too large for the… No comments yet. Log in to reply on the Fediverse. Comments will appear here.