Today, any one of hundreds of certificate authorities can vouch for any website in the world — including yours. ConsensusPKI puts the website owner back in charge, checks every claim from many independent places, and keeps the public record honest. No single party to hack, bribe or coerce.
The padlock in your browser means a certificate authority vouched for the site. There are hundreds of them, and your browser trusts them all equally — for every site on the internet.
Any trusted authority can issue a certificate for any domain — your bank's, your government's, yours. The system's safety equals the safety of its weakest member.
In 2011 a hacked Dutch authority issued fake certificates for major services, used to spy on hundreds of thousands of people. Browsers accepted every one of them.
Modern transparency logs record every certificate so forgeries can be discovered — after the fact. Discovery is not prevention. The forged certificate still works.
Three changes, each simple to state: the owner's key is the only key that counts, every claim is checked from many places, and the public record cannot be quietly rewritten.
A certificate for your website only counts if it carries your own signature. Even if every authority in the world were compromised, none of them could speak for you.
Domain checks run from multiple, unpredictably chosen network locations at once. Fooling one vantage point achieves nothing; an attacker would have to fool most of the internet, visibly.
The public record is co-signed every hour by a majority of independent witnesses. Showing different versions to different people requires most of them to conspire — and leaves evidence.
Quantum computers will eventually break the signatures that secure today's internet. Most systems will bolt on fixes later — and pay for it on every connection. ConsensusPKI was designed for the transition from day one.
Classical and post-quantum signatures operate together, and every record can step up — but never down. Migration without a flag day.
Post-quantum signatures are big. ConsensusPKI moves the heavy material off the connection entirely, so a fully post-quantum proof stays no larger than today's certificates.
Built on the NIST-standardised post-quantum algorithms (ML-DSA) — the same ones governments and browsers are adopting.
Your validation expertise becomes more valuable, not less — while the liability of unilateral issuance disappears. A better role in a safer system.
Digital identity and eIDAS-era services need infrastructure no single party can subvert — and a credible post-quantum answer. This is both.
Your domains, your keys, your rules: opt out of remote takeover entirely, and get an audit trail that survives even a future quantum adversary.
The core guarantees are machine-verified with a formal prover, the wire formats are locked by public test vectors, and a full reference implementation exists with a growing test suite. A peer-reviewed paper is in preparation.
The full research paper will be published here once it has been submitted to peer review. Until then, the Research page tracks what exists today and what has been verified.