{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T18:36:23Z","timestamp":1773254183531,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,28]],"date-time":"2023-11-28T00:00:00Z","timestamp":1701129600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-1900996,CNS-1901325,CNS-2053363,CNS-2247306,CNS-1901047,CNS-1900879"],"award-info":[{"award-number":["CNS-1900996,CNS-1901325,CNS-2053363,CNS-2247306,CNS-1901047,CNS-1900879"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,28]]},"DOI":"10.1145\/3626111.3630268","type":"proceedings-article","created":{"date-parts":[[2023,11,13]],"date-time":"2023-11-13T12:11:20Z","timestamp":1699877480000},"page":"295-301","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["No Root Store Left Behind"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6279-5828","authenticated-orcid":false,"given":"James","family":"Larisch","sequence":"first","affiliation":[{"name":"Harvard University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-5656-5272","authenticated-orcid":false,"given":"Waqar","family":"Aqeel","sequence":"additional","affiliation":[{"name":"Duke University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4323-4080","authenticated-orcid":false,"given":"Taejoong","family":"Chung","sequence":"additional","affiliation":[{"name":"Virginia Tech"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2027-0035","authenticated-orcid":false,"given":"Eddie","family":"Kohler","sequence":"additional","affiliation":[{"name":"Harvard University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4957-5131","authenticated-orcid":false,"given":"Dave","family":"Levin","sequence":"additional","affiliation":[{"name":"University of Maryland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5692-7062","authenticated-orcid":false,"given":"Bruce M.","family":"Maggs","sequence":"additional","affiliation":[{"name":"Duke University &amp; Emerald Innovations"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9113-1684","authenticated-orcid":false,"given":"Bryan","family":"Parno","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5268-004X","authenticated-orcid":false,"given":"Christo","family":"Wilson","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,28]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. Bugzilla. ([n. d.]). https:\/\/bugzilla.mozilla.org\/home."},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. CA\/Symantec Issues. ([n. d.]). https:\/\/wiki.mozilla.org\/CA\/Symantec_Issues."},{"key":"e_1_3_2_1_3_1","unstructured":"[n. d.]. dev-security-policy@mozilla.org. ([n. d.]). https:\/\/groups.google.com\/a\/mozilla.org\/g\/dev-security-policy."},{"key":"e_1_3_2_1_4_1","unstructured":"[n. d.]. Harica is a member of the PKI Consortium. ([n. d.]). https:\/\/pkic.org\/members\/harica\/."},{"key":"e_1_3_2_1_5_1","volume-title":"Comodo Certificate Issue -- Follow Up. (March","year":"2011","unstructured":"2011. Comodo Certificate Issue -- Follow Up. (March 2011). https:\/\/blog.mozilla.org\/security\/2011\/03\/25\/comodo-certificate-issue-follow-up\/."},{"key":"e_1_3_2_1_6_1","unstructured":"2013. Hard code ANSSI(DCISS) to french gov dns space. (2013). https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=952572#c2."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"2014. Network Security Services. Mozilla Developer Network. (2014). http:\/\/mzl.la\/1DRKqGZ.","DOI":"10.1016\/S1353-4858(14)70036-4"},{"key":"e_1_3_2_1_8_1","unstructured":"2015. CRLSets. The Chromium Projects. (2015). http:\/\/bit.ly\/1JPsUeC."},{"key":"e_1_3_2_1_9_1","volume-title":"Revoking Trust in one CNNIC Intermediate Certificate. (March","year":"2015","unstructured":"2015. Revoking Trust in one CNNIC Intermediate Certificate. (March 2015). https:\/\/blog.mozilla.org\/security\/2015\/03\/23\/revoking-trust-in-one-cnnic-intermediate-certificate\/."},{"key":"e_1_3_2_1_10_1","volume-title":"Distrusting New WoSign and StartCom Certificates. (October","year":"2016","unstructured":"2016. Distrusting New WoSign and StartCom Certificates. (October 2016). https:\/\/blog.mozilla.org\/security\/2016\/10\/24\/distrusting-new-wosign-and-startcom-certificates\/."},{"key":"e_1_3_2_1_11_1","unstructured":"2016. TUBITAK Kamu Sertifikasyon Merkezi - New Root Certificate. (2016). https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1262809#c33."},{"key":"e_1_3_2_1_12_1","volume-title":"https:\/\/docs.google.com\/document\/d\/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ\/edit","author":"StartCom WoSign","year":"2016","unstructured":"2016. WoSign and StartCom. (2016). https:\/\/docs.google.com\/document\/d\/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ\/edit."},{"key":"e_1_3_2_1_13_1","volume-title":"Mozilla's Plan for Symantec Roots. (October","year":"2017","unstructured":"2017. Mozilla's Plan for Symantec Roots. (October 2017). https:\/\/groups.google.com\/g\/mozilla.dev.security.policy\/c\/FLHRT79e3XE."},{"key":"e_1_3_2_1_14_1","volume-title":"Distrust of Symantec TLS Certificates. (March","year":"2018","unstructured":"2018. Distrust of Symantec TLS Certificates. (March 2018). https:\/\/blog.mozilla.org\/security\/2018\/03\/12\/distrust-symantec-tls-certificates\/."},{"key":"e_1_3_2_1_15_1","unstructured":"2020. ca-certificates: Removal of GeoTrust Global CA requires investigation. (2020). https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=962596."},{"key":"e_1_3_2_1_16_1","volume-title":"Foundations of databases","author":"Abiteboul Serge","unstructured":"Serge Abiteboul, Richard Hull, and Victor Vianu. 1995. Foundations of databases. Vol. 8. Addison-Wesley Reading."},{"key":"e_1_3_2_1_17_1","volume-title":"Maintaining digital certificate security. (July","author":"Langley Adam","year":"2014","unstructured":"Adam Langley. 2014. Maintaining digital certificate security. (July 2014). https:\/\/security.googleblog.com\/2014\/07\/maintaining-digital-certificate-security.html."},{"key":"e_1_3_2_1_18_1","volume-title":"Maintaining digital certificate security. (March","author":"Langley Adam","year":"2015","unstructured":"Adam Langley. 2015. Maintaining digital certificate security. (March 2015). https:\/\/security.googleblog.com\/2015\/03\/maintaining-digital-certificate-security.html."},{"key":"e_1_3_2_1_19_1","volume-title":"Distrusting WoSign and StartCom Certificates. (October","author":"Whalley Andrew","year":"2016","unstructured":"Andrew Whalley. 2016. Distrusting WoSign and StartCom Certificates. (October 2016). https:\/\/security.googleblog.com\/2016\/10\/distrusting-wosign-and-startcom.html."},{"key":"e_1_3_2_1_20_1","volume-title":"State-sponsored hackers in China compromise certificate authority. (September","author":"Technica Ars","year":"2011","unstructured":"Ars Technica. 2011. State-sponsored hackers in China compromise certificate authority. (September 2011). https:\/\/arstechnica.com\/information-technology\/2011\/09\/comodo-hacker-i-hacked-diginotar-too-other-cas-breached\/."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2007.18"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2002.1004365"},{"key":"e_1_3_2_1_23_1","volume-title":"Chrome's Plan to Distrust Symantec Certificates. (September","author":"O'Brien Devon","year":"2017","unstructured":"Devon O'Brien, Ryan Sleevi, Andrew Whalley. 2017. Chrome's Plan to Distrust Symantec Certificates. (September 2017). https:\/\/security.googleblog.com\/2017\/09\/chromes-plan-to-distrust-symantec.html."},{"key":"e_1_3_2_1_24_1","unstructured":"Differences in openssl and nss interpretations of the leading dot [n. d.]. mozilla\/gecko-dev. Github. ([n. d.]). https:\/\/github.com\/mozilla\/gecko-dev\/blob\/f8087305eb1ebea329b838924627008713c5f56c\/security\/nss\/lib\/mozpkix\/lib\/pkixnames.cpp#L997."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/11814771_51"},{"key":"e_1_3_2_1_26_1","volume-title":"Thoth: Comprehensive Policy Compliance in Data Retrieval Systems. In 25th USENIX Security Symposium (USENIX Security 16)","author":"Elnikety Eslam","year":"2016","unstructured":"Eslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg, and Peter Druschel. 2016. Thoth: Comprehensive Policy Compliance in Data Retrieval Systems. In 25th USENIX Security Symposium (USENIX Security 16). 637--654."},{"key":"e_1_3_2_1_27_1","volume-title":"Chrome and Firefox Removing EV Certificate Indicators. (August","author":"Fisher Dennis","year":"2019","unstructured":"Dennis Fisher. 2019. Chrome and Firefox Removing EV Certificate Indicators. (August 2019). https:\/\/duo.com\/decipher\/chrome-and-firefox-removing-ev-certificate-indicators."},{"key":"e_1_3_2_1_28_1","volume-title":"French gov used fake Google certificate to read its workers' traffic. (December","author":"French","year":"2013","unstructured":"French gov used fake Google certificate to read its workers' traffic 2013. French gov used fake Google certificate to read its workers' traffic. (December 2013). https:\/\/www.theregister.co.uk\/2013\/12\/10\/french_gov_dodgy_ssl_cert_reprimand\/."},{"key":"e_1_3_2_1_29_1","volume-title":"Revoking Intermediate Certificates: Introducing OneCRL. Mozilla Security Blog. (March","author":"Goodwin Mark","year":"2015","unstructured":"Mark Goodwin. 2015. Revoking Intermediate Certificates: Introducing OneCRL. Mozilla Security Blog. (March 2015). http:\/\/mzl.la\/1zLFp7M."},{"key":"e_1_3_2_1_30_1","unstructured":"Jacob Hoffman-Andrews. 2020. (November 2020). https:\/\/letsencrypt.org\/2020\/11\/06\/own-two-feet.html."},{"key":"e_1_3_2_1_31_1","volume-title":"Internet Public Key Infrastructure. Part I: X.509 Certificate and CRL Profile. RFC 2459. (June","author":"Housley Russ","year":"1996","unstructured":"Russ Housley, Dr. Warwick S. Ford, and Dave Solo. 1996. Internet Public Key Infrastructure. Part I: X.509 Certificate and CRL Profile. RFC 2459. (June 1996). https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-pkix-ipki-part1-02"},{"key":"e_1_3_2_1_32_1","unstructured":"Ian Haken. 2017. (April 2017). https:\/\/netflixtechblog.com\/bettertls-c9915cd255c0."},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings 2001 IEEE Symposium on Security and Privacy. S&P","author":"Jim Trevor","year":"2000","unstructured":"Trevor Jim. 2000. SD3: A trust management system with certified evaluation. In Proceedings 2001 IEEE Symposium on Security and Privacy. S&P 2001. IEEE, 106--115."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39884-1_28"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190508.3190518"},{"key":"e_1_3_2_1_36_1","unstructured":"Adam Langley. 2013. Enhancing digital certificate security. (2013). https:\/\/security.googleblog.com\/2013\/01\/enhancing-digital-certificate-security.html."},{"key":"e_1_3_2_1_37_1","unstructured":"Adam Langley. 2013. Further improving digital certificate security. (2013). https:\/\/security.googleblog.com\/2013\/12\/further-improving-digital-certificate.html."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560594"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.17"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605438"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-005-0073-0"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830539"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815685"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487813"},{"key":"e_1_3_2_1_45_1","volume-title":"Exploring CA Certificate Control. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Ma Zane","year":"2021","unstructured":"Zane Ma, Joshua Mason, Manos Antonakakis, Zakir Durumeric, and Michael Bailey. 2021. What's in a Name? Exploring CA Certificate Control. In 30th USENIX Security Symposium (USENIX Security 21). 4383--4400."},{"key":"e_1_3_2_1_46_1","volume-title":"Web browsers dropm ysterious company with ties to U.S. military contractor. (November","author":"Menn Joseph","year":"2022","unstructured":"Joseph Menn.2022. Web browsers dropm ysterious company with ties to U.S. military contractor. (November 2022). https:\/\/www.washingtonpost.com\/technology\/2022\/11\/30\/trustcor-internet-authority-mozilla\/."},{"key":"e_1_3_2_1_47_1","unstructured":"Mozilla. [n. d.]. Revoking Trust in Two TurkTrust Certificates. ([n. d.]). https:\/\/blog.mozilla.org\/security\/2013\/01\/03\/revoking-trust-in-two-turktrust-certficates\/."},{"key":"e_1_3_2_1_48_1","unstructured":"Mozilla Root Store Policy [n. d.]. Mozilla Root Store Policy. ([n. d.]). https:\/\/www.mozilla.org\/en-US\/about\/governance\/policies\/security-group\/certs\/policy\/."},{"key":"e_1_3_2_1_49_1","unstructured":"Xinming Ou Sudhakar Govindavajhala Andrew W Appel et al. 2005. MulVAL: A Logic-based Network Security Analyzer.. In USENIX security symposium Vol. 8. Baltimore MD 113--128."},{"key":"e_1_3_2_1_50_1","volume-title":"concerns about Trustcor. (November","author":"Reardon Joel","year":"2022","unstructured":"Joel Reardon. 2022. concerns about Trustcor. (November 2022). https:\/\/groups.google.com\/a\/mozilla.org\/g\/dev-security-policy\/c\/oxX69KFvsm4\/m\/PKpJf5W6AQAJ."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278532.3278562"},{"key":"e_1_3_2_1_52_1","unstructured":"Jeffrey D Ullman. 1988. Database and knowledge-base systems. (1988)."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2741948.2741958"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484768"}],"event":{"name":"HotNets '23: The 22nd ACM Workshop on Hot Topics in Networks","location":"Cambridge MA USA","acronym":"HotNets '23","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication"]},"container-title":["Proceedings of the 22nd ACM Workshop on Hot Topics in Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3626111.3630268","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3626111.3630268","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:38:18Z","timestamp":1755891498000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3626111.3630268"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,28]]},"references-count":54,"alternative-id":["10.1145\/3626111.3630268","10.1145\/3626111"],"URL":"https:\/\/doi.org\/10.1145\/3626111.3630268","relation":{},"subject":[],"published":{"date-parts":[[2023,11,28]]},"assertion":[{"value":"2023-11-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}