Ask HN: Why aren't Google, Facebook or Twitter CAs?
It would seem to me that their graphs are stronger predictors of authenticity then government sanctioned ID or financial payments.
Or they could just invest some of the vast pile of cash that some of them (I'm looking at you, Google) have lying around, and buy an existing, widely trusted CA, which would probably be lower-risk than investing in infrastructure and licensing; they still end up with full control of how the CA works going forward either way.
Because gaining control of an existing trusted CAs (and, consequently, existing widely trusted root certificates) gives them built-in reach that doesn't have to be be grown.
What licensing is involved? How is the day-to-day management even a thing? Didn't Shuttleworth make his money this way?
I would think a graph-backed cert would be an ideal way to authenticate service providers.