Think about the last time you handed your ID to a bouncer. He glanced at it, saw the right hologram in the right corner, and waved you in. He didn’t call your hometown DMV. He didn’t verify your address. He trusted the sticker.
That’s roughly how trust works on the internet, and it’s why a story about counterfeit TLS certificates matters to anyone who uses a browser, an app, or an AI assistant that fetches things from the web on their behalf.
What that little padlock actually promises
When you see “https” and a padlock in your address bar, your browser is telling you two things. First, the connection is encrypted, so someone sitting on the same coffee shop Wi-Fi can’t read what you send. Second, the site presented a TLS certificate issued by a Certificate Authority, or CA, a company whose entire job is to confirm that a website belongs to who it claims to belong to.
Browsers ship with a built-in list of CAs they trust. If a certificate traces back to one of those names, the padlock appears and you relax. The padlock is the hologram on the ID. The CA is the agency that printed it.
The part that should make you uncomfortable
Researchers at Recorded Future documented darknet vendors selling counterfeit TLS certificates obtained from legitimate CAs, including Comodo, Symantec, and Thawte. These aren’t crude forgeries that browsers reject. They’re real certificates, issued through real processes, intended for phishing scams and man-in-the-middle attacks.
The cheapest ones start at $299.
The trick is in the paperwork. Vendors fraudulently use the details of actual companies to register the certificates. Real business names, real registration data, borrowed and submitted as if the applicant were the legitimate owner. The business owners generally have no idea their information is being used this way. There’s no breach notification for this, no alert email. Your company’s identity gets rented out and you find out never.
Google and Symantec had a long-running dispute over exactly this kind of weakness, with Google alleging that loose security controls on Symantec’s side let bad actors obtain certificates they shouldn’t have had.
Why I’m writing about this on an AI site
Because the way we browse is changing, and that changes who gets fooled.
When a human visits a fake login page, there are small chances to catch it. The logo looks slightly off. The URL has an extra hyphen. The copy sounds odd. We’re bad at spotting these things, but we’re not hopeless at it.
AI agents are a different story. An agent that books your travel, checks your invoices, or monitors a supplier portal does the same thing a browser does: it opens a connection, checks that the certificate is valid and trusted, and proceeds. A valid certificate is a green light. The agent has no instinct that says “this page feels weird.” It has no memory of what the real site looked like last Tuesday. It isn’t squinting at the logo.
So a paid-for, properly issued certificate used for deception removes the one signal an automated system relies on most. The padlock was never a promise that a site is honest. It only ever meant the connection is private and someone, somewhere, signed off on the identity. Humans learned to over-read that symbol. Software was built to over-read it too.
What this means in practice
I’m not telling you to distrust encryption. Encrypted connections are good and you want them. What’s worth adjusting is how much weight you put on the padlock alone, especially as more of your digital errands get handed to software.
- Treat the padlock as plumbing, not a reputation score. It tells you the pipe is sealed. It doesn’t tell you who’s on the other end.
- Check the name, not the symbol. Read the full domain carefully. A valid certificate on a lookalike domain is still a valid certificate.
- Be skeptical of how your agent got there. If an AI assistant lands on a login page because it followed a link from an email, a search result, or a document, that path deserves more suspicion than the destination’s padlock deserves credit.
- Keep credentials out of agent reach where you can. The less an automated helper can hand over, the less a convincing fake page can collect.
- Ask vendors how their agents verify identity. “We use HTTPS” is an answer about encryption, not about trust.
The cheap-forgery problem is an old one
Identity systems fail the same way across centuries. Someone figures out that the verification step is softer than the symbol it produces, and then the symbol becomes a commodity. A few hundred dollars buys the hologram, and everyone downstream keeps trusting it because trusting it is faster than checking.
The useful shift isn’t paranoia. It’s recognizing that the internet’s trust signals were designed for human judgment to sit alongside them. As we hand more browsing over to agents that don’t have judgment, the gaps in those signals stop being theoretical and start being operational. Knowing the padlock costs $299 is a reasonable place to begin.
đź•’ Published: