{"id":1055,"date":"2025-06-16T09:50:46","date_gmt":"2025-06-16T17:50:46","guid":{"rendered":"https:\/\/unmitigatedrisk.com\/?p=1055"},"modified":"2025-06-16T10:23:23","modified_gmt":"2025-06-16T18:23:23","slug":"webpki-market-analysis-mozilla-telemetry-vs-certificate-transparency-data","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=1055","title":{"rendered":"WebPKI Market Analysis: Mozilla Telemetry vs Certificate Transparency Data"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In the past, I&#8217;ve written about<a href=\"https:\/\/unmitigatedrisk.com\/?p=673\"> how to measure the WebPKI<\/a>, and from time to time I post brief updates on how the market is evolving.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other day, <a href=\"https:\/\/www.linkedin.com\/posts\/mcpherrinm_mozilla-provides-public-data-from-firefoxs-activity-7339709576365174784-HYry?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAAAATzZIBefRfvyXw1L3P_jZZAXhwg-FoCDE\">Matthew McPherrin posted<\/a> a <a href=\"https:\/\/github.com\/mcpherrinm\/cert-count\">script<\/a> showing how to use Mozilla telemetry data to analyze which Certificate Authorities are more critical to the web. Specifically, <strong>what percentage of browsing relies on each CA<\/strong>. Mozilla provides public data from Firefox&#8217;s telemetry on how many times a CA is used to successfully validate certificates. This is a pretty good measure for how &#8220;big&#8221; a CA actually is. The data is pretty hard to view in Mozilla&#8217;s public systems though, so he made a script to combine a few data sources and graph it.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeaqwg6WC9DxetEP1gYn5KVxiuDEJetxESggB0ArilcsITPVWIoTcTMKID_M76aCb3Em2daJR46cBcyXbtQ5LvSQSv1Cc26JSlVcOK8WFo_5Lif5tM0x91LfDDl5hIxLaXrnqDe?key=GFLD9mPBe_Yu7doZu_bmcA\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I normally focus on total issuance numbers since they&#8217;re easier to obtain. That data comes from <strong>Certificate Transparency logs<\/strong>, which contain all publicly trusted certificates that you might encounter without seeing an interstitial warning about the certificate not being logged (like<a href=\"https:\/\/no-sct.badssl.com\/\"> this example<\/a>).<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcPtXllpT3xn3E4n2A_JAi9tAFjunASm5IiYLBUPLADxGJrmMxsiQW_1jY1mWiRCVAAoz3lqTTFIXrQl4h4dGi4m_UKfeTBMttTCzF5jdgrs9ZFgnvWtwdbOcXRcVhDv4hkgdhnOQ?key=GFLD9mPBe_Yu7doZu_bmcA\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/docs.google.com\/spreadsheets\/d\/1gshICFyR6dtql-oB9uogKEvb2HarjEVLkrqGxYzb1C4\/edit?gid=1219675187#gid=1219675187\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What the Data Reveals<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Both datasets feature many of the same major players. But there are some striking differences that reveal important insights about the WebPKI ecosystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Let&#8217;s Encrypt dominates certificate issuance at 46.1%<\/strong> of all certificates. But it ranks third in Firefox&#8217;s actual usage telemetry. This suggests Let&#8217;s Encrypt serves many lower-traffic sites. Meanwhile, <strong>Google Trust Services leads in Firefox usage<\/strong> while ranking second in certificate issuance volume. This shows how high-traffic sites can amplify a CA&#8217;s real-world impact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DigiCert ranks second in Firefox usage<\/strong> while placing fourth in certificate issuance volume at 8.3%. This reflects their focus on major enterprise customers. With clients like <strong>Meta<\/strong> (Facebook, Instagram, WhatsApp), they secure some of the world&#8217;s highest-traffic websites. This <strong>&#8220;fewer certificates, massive impact&#8221;<\/strong> approach drives them up the usage charts despite not competing on volume with Let&#8217;s Encrypt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Google&#8217;s dominance<\/strong> reflects more than just their own properties like Google.com, YouTube, and Gmail. Google Cloud offers arguably <strong>the best load balancer solution in the market<\/strong> (full disclosure I worked on this project). You get TLS by default for most configurations. Combined with their global network that delivers CDN-like benefits out of the gate, this attracts major platforms like Wix and many others to build on Google Cloud. When these platforms choose Google&#8217;s infrastructure, they automatically inherit Google Trust Services certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Looking at the usage data reveals other interesting patterns. <b>Deutsche Telekom Security, <\/b><s style=\"\"><b>Government of Turkey,<\/b><\/s> (<strong>UPDATE: <\/strong>turns out the Turkey entry is a Firefox bug: they\u2019re using bucket #1 for both locally installed roots and Kamu SM, apparently by accident) <strong>and SECOM Trust Systems<\/strong> all appear prominently in Firefox telemetry but barely register in issuance numbers. In some respects, it&#8217;s no surprise that government-issued certificates see disproportionate usage. <strong>Government websites are often mandated for use<\/strong>. Citizens have to visit them for taxes, permits, benefits, and other essential services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Microsoft Corporation<\/strong> appears significantly in issuance data (6.5%) but doesn&#8217;t register in the Firefox telemetry. This reflects their focus on enterprise and Windows-integrated scenarios rather than public web traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>GoDaddy<\/strong> shows strong issuance numbers (10.5%) but more modest representation in browsing telemetry. This reflects their <strong>massive domain parking operations<\/strong>. They issue certificates for countless parked domains that receive minimal actual user traffic.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why This Matters<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mozilla Firefox represents under 3%<\/strong> of <a href=\"https:\/\/gs.statcounter.com\/browser-market-share\">global browser market share<\/a>. This telemetry reflects a smaller segment of internet users. While this data provides valuable insights into actual CA usage patterns, <strong>it would be ideal if Chrome released similar telemetry data<\/strong>. Given Chrome&#8217;s dominant <strong>66.85% market share<\/strong>, their usage data would dramatically improve our understanding of what real WebPKI usage actually looks like across the broader internet population.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The contrast between certificate issuance volume and actual browsing impact reveals important truths about internet infrastructure. <strong><a href=\"https:\/\/merkle.town\/\">CT logs currently show over 450,000 certificates being issued per hour<\/a><\/strong> across all CAs. Yet as this Firefox telemetry data shows, much of that volume serves lower-traffic sites while a smaller number of high-traffic certificates drive the actual user experience. Some CAs focus on <strong>high-volume, automated issuance<\/strong> for parked domains and smaller sites. Others prioritize <strong>fewer certificates for high-traffic, essential destinations<\/strong>. Understanding both metrics helps us better assess the real-world criticality of different CAs for internet security and availability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Raw certificate counts don&#8217;t tell the whole story<\/strong>. The websites people actually visit, and sometimes must visit, matter just as much as the sheer number of certificates issued. Some certificates protect websites with &#8220;captive audiences&#8221; or essential services, while others protect optional destinations. A government tax portal or YouTube will always see more traffic than the average small business website, regardless of how many certificates each CA issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of how you count, <strong>I&#8217;ve had the pleasure of working closely with at least 7 of the CAs<\/strong> in the top 10 in their journeys to become publicly trusted CAs. Each of these CAs have had varying goals for their businesses and operations, and that&#8217;s exactly why you see different manifestations in the outcomes. Let&#8217;s Encrypt focused on automation and volume. DigiCert targeted enterprise customers. Google leveraged their cloud infrastructure. GoDaddy built around domain services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Either way, it&#8217;s valuable to compare and contrast these measurement approaches to see what the WebPKI really looks like beyond just raw certificate counts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the past, I&#8217;ve written about how to measure the WebPKI, and from time to time I post brief updates on how the market is evolving. The other day, Matthew McPherrin posted a script showing how to use Mozilla telemetry data to analyze which Certificate Authorities are more critical to the web. Specifically, what percentage [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[217,4,1],"tags":[],"class_list":["post-1055","post","type-post","status-publish","format-standard","hentry","category-certificates","category-thoughts","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/1055","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1055"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/1055\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1055"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1055"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1055"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}