Skip to content
Droid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Trending:
Galaxy S26•Pixel 10•Android 16•Nothing OS•Gemini AI•Smartwatches•Tech Deals•Latest Reviews•How-to Guides
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/Android 14 may come with root certificates
News

Android 14 may come with root certificates

Robert Haba
Feb 14, 20235 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
Android 14 may come with root certificates
0%
Share on XFacebookBluesky
Follow on Google
Advertisement
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Key Takeaways

Automated Editorial Synthesis
AI Overview
  • The foundation of Public Key Infrastructure (PKI) is its root certificates, which are certified by reputable Certificate Authorities, or CAs.
  • A pre-packaged root store seen in browsers, apps, and other programs serves as a trust seal for these certificates.
  • A website that supports HTTPS but isn't using a certificate signed by a CA in the root store of your browser will be marked as insecure when you visit it.

The foundation of Public Key Infrastructure (PKI) is its root certificates, which are certified by reputable Certificate Authorities, or CAs. A pre-packaged root store seen in browsers, apps, and other programs serves as a trust seal for these certificates. A website that supports HTTPS but isn’t using a certificate signed by a CA in the root store of your browser will be marked as insecure when you visit it. Applications and browsers can frequently update their certificates, but unless you use an OTA update, your phone cannot. According to Esper, with Android 14, that might alter.

Due to our reliance on certificates as the foundation of a chain of trust when visiting websites, there have been a few scares involving them throughout the years. Let’s Encrypt, a nonprofit CA, has signed the certificate used here on XDA. Your connection to this website is safe and secure thanks to their certificate, which was signed by the Internet Security Research Group. The same holds true for any other HTTPS-enabled website you visit.

Advertisement

Every operating system has its own built-in root store, and Android is no different. You can actually view this root store on your Android smartphone by navigating to security and privacy in your device’s settings. From there, it will depend on the type of device you’re using, but the screenshots below show where it is on OneUI 5.

android 14 root certificates

But even this root shop isn’t the be-all and end-all, you know? In an effort to fend off Man-in-the-Middle (MITM) attacks, apps can choose to utilize and trust their own root store (like Firefox does) and they can accept only particular certificates (a practice known as certificate pinning). Users can install their own certificates, but since Android 7, app developers have had to agree to let their apps utilize these certificates.

Why having these root certificates is important

A large portion of the internet depends on the security of the Internet Security Research Group since Let’s Encrypt certificates are cross-signed by this organization. The ISRG would have to revoke the key if it lost control of its private key (should it be stolen, for instance). Depending on how businesses react, some portions of the internet may become inaccessible to hardware lacking an updateable root certificate. Even though it’s a completely improbable nightmare scenario, Google aims to prevent situations like that from happening. Because of this, what is happening with TrustCor right now might be telling Google that it’s time to give Android updatable root certificates.

Advertisement

As an example, academics have questioned TrustCor after discovering that company allegedly has close ties to a US military contractor. Although TrustCor still has access to its private key, many businesses that must choose which certificates to include in their root stores no longer trust the company. These researchers said that TrustCor, a contractor for the US military, had paid programmers to include malware that gathered data from smartphone apps. Faith is crucial in PKI, but after these claims surfaced, TrustCor lost that trust. Since then, TrustCor has been abandoned as a certificate authority by organizations like Google, Microsoft, and Mozilla. But even though the commit has already made, an OTA update will be necessary to remove TrustCor’s certificates from the Android root store.

You May Also Like
Recommended
1

Huawei Kirin 9050 Pro chipset: full specs and what’s new

kirin 9050
2

The 5 biggest phone launches to watch in September 2026

semptember 2026 phones
3

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

The upside is that you can disable TrustCor’s certificates on your device now by going to your certificates on your device, as we showed above, and then scrolling to TrustCor and disabling the three certificates that come with your device. According to developers from the GrapheneOS project, there should be “very little impact on web compatibility due to this CA barely being used by anyone other than a specific dynamic DNS provider.”

Solution: Project Mainline

If you’re familiar with Project Mainline, then you can already see how this can help solve the problem. Google makes use of Mainline modules which are delivered through the Google Play Services framework and the Google Play Store. Each Mainline module is delivered as either an APK file, an APEX file, or an APK-in-APEX. When a Mainline module is being updated, the user sees a “Google Play System Update” (GPSU) notification on their device. Effectively, to deliver updates to critical components, Google has bypassed the need to wait for an OEM to roll out an update, choosing to do the task itself. Bluetooth and Ultra-wideband are two essential Mainline modules handled by Google.

Conscrypt, a Mainline module that provides Android’s TLS implementation, will allow updatable root certificates in a future release, according to changes on the AOSP Gerrit (found by Esper). In the event that a situation similar to TrustCor (or worse) arises in the future, this would mean that certificates may be removed (or even added) via a Google Play System Update through Project Mainline, ensuring a considerably speedier process. It’s unclear when this will launch, but Android 14 is probably going to get it. Technically, Google could launch it with Android 13 QPR2, but it would only help Google Pixel users until Android 14 is released to the rest of the world next year. This is due to the fact that other OEMs usually do not release QPR updates.

Advertisement

The entire reason for this to exist would be so that Google can maintain control over another crucial aspect of device security without needing to rely on OEMs pushing updates instead. An OTA is currently required to update certificates, but in an emergency situation, every day where users don’t have an update could matter. Utilizing Project Mainline to ensure that users can get crucial certificate updates in time if they’re ever needed is certainly a welcome change.

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#android#certificates#root#security
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
✨DEAL!
Samsung Galaxy Watch Ultra (2025)

Samsung Galaxy Watch Ultra (2025)

5.0
$449.99$649.99-31%
Buy on Amazon
👑A good choice
Apple iPhone 17 Pro

Apple iPhone 17 Pro

4.8
$1,012.97$1,099.00-8%
Buy on Amazon
💎Best Android Device
Samsung Galaxy S26 Ultra

Samsung Galaxy S26 Ultra

4.9
$1,212.85$1,499.99-19%
Buy on Amazon
✨DEAL
Google Pixel 11 Pro

Google Pixel 11 Pro

5.0
1,099.00$1,299.00-15%
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Advertisement

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Advertisement

Latest Stories

01

Honor MagicOS 11 to debut with hidden Power Saving Suggestions feature

02

Galaxy Watch 4 and Watch 4 Classic reach end of software support

03

GrapheneOS merges Secure Paste to limit clipboard access

04

Android 17 quietly blocks apps from detecting Developer Mode status

Advertisement
Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare

Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon

Deal
Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon
Advertisement
Advertisement
Recommended stories

Continue reading

More from this category →
kirin 9050
NewsSep 11, 2026

Huawei Kirin 9050 Pro chipset: full specs and what’s new

Huawei has released its new high-performance Kirin 9050 Pro chipset, and details about the silicon's architecture are now available across CPU, GPU, NPU, modem, security, and cooling. CPU, GPU, and NPU upgrades The chip's LinxiCore CPU supports simultaneous multi-threading and delivers a 24% gain in peak single-core performance alongside a 52% gain in multi-core concurrent […]

By Robert Haba
semptember 2026 phones
NewsSep 8, 2026

The 5 biggest phone launches to watch in September 2026

September is usually iPhone season, but this year several Android brands are packing their very best hardware into the same four-week stretch, aiming to steal some of the spotlight. More than 20 phones are expected to launch this month alone, and here's a rundown of five of the biggest phone launches on the calendar for […]

By Luiza Mosneagu
NewsSep 4, 2026

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

Google's Scam Detection feature could be coming to Xiaomi phones next, according to a new APK teardown by Android Authority. The AI-powered scam-call warning tool debuted first on Pixel devices, has since expanded to Samsung's Galaxy S26 series, and has shown signs of heading to vivo phones as well, and Android Authority now says it's […]

By Robert Haba
android-trojan
NewsSep 4, 2026

New StreamRat Android banking trojan spreads via fake streaming ads

Cybersecurity researchers at ThreatFabric have disclosed a new Android banking trojan called StreamRat that was pushed to Spanish-speaking users through a fake television-streaming campaign on Meta and can hand its operators near-complete control of an infected device. According to ThreatFabric, the campaign's advertising focused on Spain and reached an estimated 570,950 Meta accounts in the […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.