Tyche Labs · trusted-list observatory

The map of published trust

A trusted list is a state saying, in machine-readable form, whom it vouches for. Everyone knows the European one. Almost nobody has looked at the shape of the whole thing — who points at whom, which pointers answer a strict client, and whether anybody is obliged to check. This is that graph, fetched rather than described.

01

One hub, thirty-one lists

The European Union publishes a list of lists. Each member state, plus Iceland, Liechtenstein, Norway and an archived United Kingdom entry, publishes its own — naming the providers it supervises and the services they are trusted for.

Nothing here is drawn from a document we did not retrieve. Every circle is a file that answered.

31 machine-processable national lists, from one hub.
02

Forty-three pointers is not forty-three countries

The hub carries 43 pointers, and that is the number usually quoted. It is not a count of countries. 11 of them point at a human-readable PDF of a list that is already there in machine-processable form, and one points at the hub itself.

The small squares are those PDFs. They matter for the arithmetic: a fault in one list out of forty-three sounds like a rounding error, and the same fault out of thirty-one does not.

43 pointers = 31 lists + 11 PDF copies + 1 self-reference.
03

One of them had never answered — until this morning

Ireland's trusted list is declared by the hub, and for twenty-five consecutive observations a strict client could not retrieve it. The server sent one certificate where two are needed: the intermediate linking it to a trusted root was missing, so verification failed before the file was ever read.

The operator was told. On the twenty-sixth observation the intermediate was there, the chain verified, and the list came down clean. That is the outcome this instrument exists to produce, and it is the reason a series matters more than a snapshot: the defect and its repair are both in the record, and neither is a screenshot.

Failed 25 of 26 observations, then fixed on 25 August 2026. All 31 European lists now answer.
04

One is published without transport security at all

Slovakia's pointer is declared over plain http://, and answers there. The same host over HTTPS presents a certificate for a different name, so the encrypted path is the one that fails.

This is not the scandal it first looks like. The list carries its own XAdES signature, so its integrity does not depend on the transport. But a client configured to refuse plain HTTP — an increasingly ordinary policy — cannot fetch a national trusted list at all.

The list is signed. The channel is not. Those are different guarantees, and only one of them is present.
05

There is a second hub, and no edge between them

The Americas publish a regional list of lists in the same ETSI format, under the same standard, covering Argentina, Brazil, Paraguay and Uruguay. Chile appears too — not through the regional hub, but through Argentina's own national list.

The two hubs do not mention each other. Not a broken link: no link. A client that knows how to read one has no path to the other.

But the disconnection is not symmetrical, and that took a second bloc to see. The Pacific Alliance — Chile, Colombia, Mexico, Peru — publishes four lists in the same format that do declare a pointer out, and it names an ec.europa.eu address as the list of lists for territory “AP”. It redirects to the European one. Four Latin American states have been declaring Brussels as their own regional hub since 2019, and Brussels has never pointed back.

0 edges between the EU and MERCOSUR hubs; four unreciprocated edges from the Pacific Alliance into the European one.
06

Four copies, three of them expired

The regional list is served from four addresses across three states. All four answer. All four carry a signature block. Three are byte-for-byte identical at sequence 7, whose declared next update passed 110 days ago; the fourth, in Brazil, is sequence 8 and current.

A signature proves who wrote a document. It does not say whether the document is still the one you should be reading. The only field that separates the current copy from the lapsed ones is the one no rule requires anybody to check.

Same standard, same signature check, 110 days apart.
07

And then the islands — and a hub nobody arrives at

Some states publish a trusted list that no hub points at: Switzerland, the United Kingdom's live list, Serbia, North Macedonia, and Ukraine's national list — which was reissued the day before this measurement and is the freshest list anywhere in the graph. They are reachable and structurally invisible: you find them only if you already know the address.

We had Moldova and Ukraine in that group, and we were wrong. The European Union publishes a second list of lists, for mutual-recognition agreements, and it points at both. The first list of lists does not mention the second, so a crawl that starts at the famous hub — which is every crawl — never arrives. Ukraine appears twice and the EU points at the other one: a separate, EU-facing list with ten providers rather than the national list's twenty-one.

Serbia and Montenegro point at each other; Montenegro reaches Brussels only through Belgrade. North Macedonia's list fails the same way Ireland's did until this morning — a chain that cannot be built.
08

What states publish when they publish no list

Most of the world does not publish a trusted list at all. What it publishes instead is a root certificate: the anchor itself, offered for download, with no statement about who else the state vouches for. Thirteen root distribution points from twelve states are drawn here as diamonds — from Argentina, India and Japan to Qatar, Russia, Taiwan and the United States — and two of them, Vietnam's and Bangladesh's, fail TLS validation to a strict client from both of our vantages. The defect that opened this page wearing a different flag.

They are deliberately joined to nothing. A trusted list is a claim about others; a root is a claim about yourself, and no pointer graph connects the two. Counting them together with the lists would produce a bigger number and a worse one.

One state sits between the two categories. South Korea publishes a genuine machine-readable national list — but as a sequence-numbered Microsoft-format certificate trust list and a JSON register, not as the European XML. It is drawn dashed, in its own population, because its register mixes test and development hierarchies in with the production ones — twelve of forty-two — and no status field marks which is which: only the names betray them.

The root and Korean labels are the only ones on this page we asserted ourselves: a certificate carries no SchemeTerritory to read.
09

 

Every one of these lists is somebody's legal obligation to publish. Not one of them is anybody's obligation to check.

That is the finding. The defects are individually small and mostly easy to fix — a missing intermediate, a stale mirror, an unencrypted pointer. What is not small is that they persisted long enough for a first look to find them, in infrastructure whose entire purpose is to be relied upon.

The instrument

Explore the whole graph

Every node is a published artefact that this instrument fetched. Hover any node for its country's name; click one for what was measured about it, and for whether its territory is something the publisher declared or something we asserted.

Show

The numbers, and where each one comes from

31 of 31
European machine-processable lists that answer a strict client, after Ireland's was repaired on 25 August. Stated first because an instrument that only reports problems is campaigning, not measuring.
3 of 4
National pointers in the MERCOSUR regional list that answer. Paraguay's cannot be chain-verified — the same class of fault as Ireland's, in a different hemisphere.
1 of 4
Copies of the MERCOSUR list that are current. The other three are identical to each other and 110 days past their declared next update.
0
Edges between the two regional hubs. Europe and the Americas each publish a list of lists, and neither has ever heard of the other.

The official monitor said it was fine

The European Commission publishes a live view of these same lists in its Digital Signature Services demonstration application. Throughout the twenty-five observations in which our strict client could not retrieve the Irish list, that dashboard reported it SYNCHRONIZED — downloaded, parsed and validated, with a recent successful download timestamp. On the morning of 25 August, while it still could not be retrieved here, the official view recorded a successful download at 10:38.

Both were correct. The dashboard runs a client that completes a chain by fetching the certificate the server omitted; ours trusts only what the server actually sent. Nothing was broken in the monitor and nothing was wrong in our measurement. The endpoint was simply retrievable by one kind of client and not by another, and the monitoring in place was of the kind that could not see it.

That is the finding underneath all the others, and it is not about Ireland. A defect invisible to the instrument watching for defects will persist for as long as nobody looks with a different instrument. It also means this page is not a competitor to that dashboard: it is a second reading, and the two are useful precisely where they disagree.

Stated carefully

We are not claiming the Commission's tooling is wrong, nor that anybody was negligent. Chain completion by fetching a missing intermediate is normal, permitted client behaviour. The observation is narrower and harder to dismiss: two competent clients disagreed about whether a published national trusted list could be retrieved, for at least twenty-five consecutive observations, and only one of them was being watched.

How we found the hub we had missed

For most of this measurement we reported Moldova and Ukraine as lists that nothing points at. That was wrong, and it was wrong in an instructive way: we had seeded the crawl at the European list of lists, and the European Union runs two. The second, for mutual-recognition agreements, currently declares exactly two territories — Ukraine and Moldova — and the first does not link to it. Every automated reading that begins at the well-known hub reproduces our error.

It surfaced only because an adversarial review of our own work went looking for what we had not measured. That is the argument for building the critic into the method rather than waiting for a reviewer: the correction cost an afternoon, and it would have cost a publication.

Then we asked the whole world

Two vantages are still not the world, so we asked it. The same strict TLS check, run from the RIPE Atlas measurement network against the endpoints in question, from a vantage in 177 countries — one probe in each, on all six inhabited continents. This is one moment rather than a series, and it measures the transport and the certificate presented, not the signature on the list.

Ireland's repaired endpoint validated cleanly from almost every one of them. One member state's endpoint did the opposite: it presented a valid certificate to not a single probe, on any continent — the same answer from Helsinki, São Paulo, Johannesburg and Sydney alike. That is no longer a question of where we stand to look. Its operator will be notified before the specifics are named here.

Each dot is one country the check ran from — 177 in all, on every inhabited continent. From every one, the repaired control validated and the one exception did not.

74 countries
National vantage points the check ran from, across all six inhabited continents. Stated as a number so that “from everywhere” is a measurement and not a flourish.
459 of 478
Probes that retrieved a valid certificate for the repaired control endpoint. The rest did not answer from the probe's own side; none saw an invalid certificate.
0 of 476
Probes that retrieved a valid certificate for the one exception — not one, anywhere. The endpoint and the operator we notified are withheld until a reasonable interval has passed.

Why the raw probe counts are not the finding

A bare TLS probe that omits the server name reports a content-delivery network's default certificate as though the list were misconfigured; even with the name sent, cloud hosting can hand a default certificate to some vantages and the real one to others. Every figure above reconciles the measurement network's result against a fetch of each pointer's actual URL. After that reconciliation exactly one endpoint fails from every vantage and every method; every other list validates when it is fetched the way software fetches it. The measurement that is easiest to run is the one most likely to invent a defect.

What this does not claim

It is not a security assessment

This measures whether a published endpoint answers a strict TLS client, and what each list says about its own currency. It is not signature validation, not supervision, not a legal determination, and not a vulnerability report. Nothing here is exploitable; several things here are simply not maintained.

A short series, and it says so

A run count is not a duration. This series is young, and that bounds what it can support: a pointer that failed every observation failed persistently within this window, which is not the same as a long-standing defect. Ireland's is the exception only because its repair happened inside the window and is therefore in the record. The classifier changed once, on 25 August, when refusals were separated from server errors; counts either side of that change are not the same measurement, and the analysis refuses to merge them.

Two vantage points, one moment

The series is measured from a single host in Estonia. Anything that fails there is asked once more from a second declared vantage on another network, because one host cannot tell “refuses everyone” from “refuses us”. Where the two disagree, the disagreement is the finding and both answers are published; we do not report the more convenient one. Two vantages are still not the world — so the one-moment worldwide check reported above was run separately; being a snapshot, it does not extend this window.

Labels are attributed

A node's territory comes from the list's own SchemeTerritory, or from the pointer that declares it. Ireland's list has never answered us; it is labelled IE because the European hub says so, not because we read it off a filename. Where we asserted a label ourselves, the panel says so.

Operators hear from us first

Where a named operator is involved we write to them before publishing, and a fix before publication is the outcome we would rather report. We do not route around a refusal. The second vantage identifies itself in its User-Agent, fetches only a fixed allowlist of the artefacts already measured here, and returns the observation rather than the document — it is an observation post, not a way to obtain something an operator has decided not to serve. A result gained by evading a block would not be a measurement of what a client sees.

Reproducing this

The instrument is three small programs and an append-only directory of dated runs. The classifier is declared in code before any percentage is computed, populations are never merged, and the page you are reading is generated from the run files rather than written by hand. Two defects the instrument found in itself — parallel workers manufacturing their own timeouts, and a namespace-blind parser misreading every prefixed list — are recorded in the README instead of quietly patched.

probe.pytransport: does the endpoint answer a strict client
freshness.pydeclared currency: issue date, next update, terminal lists
graph.pystructure: who declares a pointer to whom, followed transitively
export_web.pyassembles this page's data from the recorded runs
checks.yamlone card per check: the clause it rests on and its RFC 2119 level, or a written statement that it has no normative anchor and why — and, for every one, what it does not establish. The build refuses to publish a check without one.