Tyche Labs · measurement · 25 August 2026
The map of published trust
A trusted list is a state saying, in machine-readable form, whom it vouches for. The European Union publishes a list of those lists, and that document is well known. What is less known is the shape of the whole thing: who points at whom, which pointers answer a strict client, and whether anyone is obliged to check.
Open the interactive graph → — the full instrument, with every node clickable for what was measured about it.
What the numbers say
The European hub carries 43 pointers, and that is the figure usually quoted. It is not a count of countries. Eleven of them point at a human-readable PDF of a list that is already present in machine-processable form, and one points at the hub itself. The denominator that matters is 31.
| measurement | result | reading |
|---|---|---|
| European machine-processable lists that answer | 31 of 31 | after Ireland's was repaired on 25 August |
| European pointers published without TLS | 1 of 31 | signed list, unencrypted channel |
| MERCOSUR national pointers that answer | 3 of 4 | same standard, same fault class as Ireland's |
| Copies of the MERCOSUR list that are current | 1 of 4 | the other three identical, 110 days lapsed |
| Edges between the two hubs | 0 | the regions do not know about each other |
Four things worth saying plainly
The European list is in good health, and one fault was repaired while we watched. Ireland's list could not be retrieved by a strict client for twenty-five consecutive observations: the server sent the leaf certificate without the intermediate that links it to a trusted root. The operator was notified. On the twenty-sixth observation the intermediate was present and the list came down clean. All thirty-one machine-processable European lists now answer. A fix before publication is the outcome we would rather report, and it is the argument for a series over a snapshot — the defect and its repair are both in the record.
The official monitor never saw it. Throughout those twenty-five observations, the European Commission's own Digital Signature Services dashboard reported the same Irish list as synchronised — downloaded, parsed and validated. Both readings were correct: that client completes a chain by fetching the certificate the server omitted, and ours trusts only what the server sent. Nothing was broken in the monitor. The defect was simply invisible to the instrument watching for defects, which is the finding underneath all the others.
That health is a property of that list, not of the idea. The Americas publish a regional list in the same format under the same standard. One of its four national pointers cannot be chain-verified — the same class of fault as Ireland's, in a different hemisphere — and Chile appears in the graph only through Argentina's national list, not through the regional hub at all.
Signatures do not carry freshness. The regional list is served from four addresses across three states. All four answer, all four carry a signature block, and three are byte-for-byte identical at a sequence whose declared next update passed 110 days ago. The only field separating the current copy from the lapsed ones is the one no rule requires anybody to read.
A third bloc points into Europe, and Europe has never pointed back.
Chile, Colombia, Mexico and Peru publish trust lists for the Pacific Alliance in the
same ETSI format — as zip attachments on a ministry page, with no hub anything can
follow. Each declares exactly one pointer, and it names an ec.europa.eu
address as the list of lists for territory “AP”; it redirects to the
European one. All four lists are more than six years past their own declared next
update. Four states have been declaring Brussels as their regional hub since 2019, and
nothing in Brussels knows it.
Some lists are structurally invisible. Switzerland, Ukraine, the United Kingdom's live list, Moldova and Serbia publish trusted lists that no hub points at. Ukraine's was reissued the day before this measurement — the freshest list anywhere in the graph, and one nothing references. Moldova's carries no trust-service-provider section at all; its single pointer goes back to Brussels. Montenegro is reachable only through Serbia.
And then we asked the past
A state must publish its trusted list. Nobody must keep the earlier versions, and no public archive of them is maintained — so the questions that make these documents interesting, like when a provider entered supervision or how long a lapsed list stayed lapsed, are usually unanswerable. We asked whether they are answerable at all, for seven countries, and recovered 202 distinct signed versions from public web archives.
| country | recovered | of its own history |
|---|---|---|
| Iceland | 28 of 40 | 70% |
| Switzerland | 8 of 12 | 67% |
| Estonia | 32 of 73 | 44% |
| Denmark | 19 of 45 | 42% |
| Slovakia | 52 of 145 | 36% |
| Portugal | 41 of 119 | 35% |
| Germany | 22 of 159 | 14% |
Provenance, stated plainly: of the seven countries above, only Iceland's twenty-eight versions exist as files we recovered and hold. The other six rows come from an earlier assisted pass whose artefacts were not retained, and are shown here as pending reproduction rather than as measurements. A deterministic re-derivation that writes every recovered version to disk is running. Iceland is why we are cautious: there the assisted figure was right and our own correction to it was the error.
Archived copies of signed documents are usable as evidence. Iceland is the corpus we hold as files, and all twenty-eight of its recovered versions recompute to the digest their own signature covers. We saw no case of an archive returning altered bytes. That is an observation, not a proof of absence — with twenty-eight documents it bounds an alteration rate we could have missed at roughly one in nine, and the literature is explicit that archives can alter what they return. The claim that survives is narrower and more useful: for a document carrying a signature over its own content, alteration is detectable, and we detected none. The structural reason to expect few is that archiving fails by truncation, and a truncated document does not parse, so it never enters the record to be mistaken for a good copy.
How much survived depends on the checker, and that is the finding. On one fixed corpus, with no document changing, the measured survival rate moved from 11% to 100% according to which tool asked.
| what was asked of the same 28 documents | answer |
|---|---|
| a signature library at its default policy, against today's clock | 3 of 28 |
| the same library, evaluating as at each document's own issue date | 26 of 28 |
reference digests and the signature over SignedInfo, recomputed directly | 28 of 28 |
An earlier version of this page reported the middle row as the result, and described one
Icelandic version as an archived copy whose bytes differed from what was signed.
That accusation was ours, not the archive's. The document uses the XPath
filter not(ancestor-or-self::ds:Signature) — the enveloped-signature
transform written the older way, which the library does not apply, so it digested the
document including its own signature and correctly reported a mismatch against a digest
that never covered it. Removing the subtree by hand reproduces the signed digest to the
byte. The other exception was signed by a named individual at the supervisory body, and
the objection was to the certificate rather than the bytes. A checker that reports
broken when it means unsupported manufactures false accusations against
public infrastructure, and ours did.
Germany's last place belongs to the archive, not to Germany. Its list is 5.36 MB, the only one in the corpus over five, and every Internet Archive capture from 2020 to September 2023 comes back cut at exactly one mebibyte, while every capture from January 2024 onward is complete. The archive raised a limit, and Germany's knowable history begins there. Measured only inside the era where captures actually work, Germany recovers 65% — next to Iceland rather than last. What can be known about the history of public infrastructure is decided by an archive's technical policy, and no document anywhere announces it.
The obvious explanation was wrong. We expected national deposit libraries to be the difference, since nine Icelandic versions survive only in the National and University Library's archive. They are not: Portugal has the technically best national archive in the set and it yielded three versions of forty-one, Estonia's open archive yielded none, and the four countries with no reachable national archive span the whole range of outcomes. The Icelandic windfall is a fact about what one archive chose to crawl. Common Crawl, which nobody thinks of as a deposit library, contributed more than Estonia's did.
Then we asked the whole world
Two vantage points are not the world, so we asked it. The same strict TLS check, run from the RIPE Atlas measurement network from a probe in each of 177 countries, on all six inhabited continents. Ireland's repaired endpoint validated cleanly from almost every one of them. One member state's endpoint did the opposite: it presented a valid certificate to not a single probe, anywhere — the same answer from Helsinki, São Paulo, Johannesburg and Sydney alike. That is no longer a question of where we stand to look. Its operator will be notified before it is named here.
The measurement that is easiest to run is the one most likely to invent a defect. A bare TLS probe that omits the server name reports a content-delivery network's default certificate as though a national list were misconfigured; even with the name sent, cloud hosting can hand a default certificate to some vantages and the real one to others. Every figure here reconciles the measurement network's result against a fetch of each pointer's real address. After that reconciliation exactly one endpoint fails from every country and every method; every other list validates when it is fetched the way software fetches it.
What states publish when they publish no list
Most of the world does not publish a trusted list at all. What it publishes instead is a root certificate: the anchor itself, offered for download, with no statement about whom else the state vouches for. Argentina, India, Japan, Kazakhstan, Mexico, Qatar, Russia, Taiwan and the United States each publish one, and the map draws them apart from the lists, joined to nothing — because a trusted list is a claim about others and a root is a claim about yourself, and counting the two together would produce a bigger number and a worse one. Their country labels are the only ones on the map we asserted ourselves: a certificate carries no scheme territory to read.
Two of those distribution points cannot be read by a strict client. In two more hemispheres, a national root host serves the wrong intermediate certificate and another serves none at all — the same fault as Ireland's — and the measurement network found each defect identical from every probe, so it is not a quirk of where we stand. Their operators, too, will hear from us before either is named.
One state sits between the two categories. South Korea publishes a genuine machine-readable national list, but as a sequence-numbered Microsoft-format certificate trust list and a JSON register rather than the European XML. Its cycle is twenty-eight days, the shortest anywhere in the map, so it is the list most likely to fall out of date — which is why its currency is read out of the certificate itself rather than assumed from a successful download. Its register of forty-two accredited authorities carries twelve test and development hierarchies in among the production ones, told apart by nothing but their names.
What this is not
This measures whether a published endpoint answers a strict client, and what each list says about its own currency. It is not signature validation, not supervision, not a legal determination, and not a vulnerability assessment. A failing pointer means an artefact could not be retrieved from one vantage point at one moment; where an endpoint refused us specifically, it is recorded as refusing us rather than as broken, because a single vantage cannot tell those apart. Where a named operator is involved we write to them before we publish, and a fix before publication is the outcome we prefer to report. We do not route around a refusal: a result obtained by evading a block would no longer be a measurement of what a client sees.