Fake Google Certificates Just Proved Why Thin Blog Posts Are Dead
A Certificate Problem Nobody Saw Coming
On October 6, Google disclosed that hackers hijacked three ccTLD registries, .gh, .sl, and .as, and used that access to pull unauthorized TLS certificates for several Google domains and other major brands. Chrome caught the known counterfeits and blocked them. Crisis handled, technically.
But sit with what actually happened. Attackers didn't breach Google's servers. They didn't need to. They found a weaker link in the chain of trust, a registry most people have never heard of, and used it to manufacture something that looked legitimate to every browser checking for a padlock icon.
That's not a server security story. That's a trust architecture story.
For twenty years, the padlock told you a site was who it claimed to be. One hijacked registry proved that assumption was never bulletproof, just reliable enough that nobody questioned it.
Here's why this matters if you write content for a living. AI systems deciding what to cite are running the same calculation browsers run for certificates: does this look trustworthy enough to vouch for. A generic blog post summarizing what everyone else already said is the content equivalent of a certificate issued by a registry nobody audits. It might render fine. It won't get trusted. And when trust becomes the actual currency, surface-level content has nothing to trade.
Why Trust Signals Decide What Gets Cited
The numbers back this up more plainly than the certificate story does. Similarweb and Ahrefs data from December 2025 found AI Overviews cut organic CTR for the top-ranking result by an average of 58 percent. Ranking first used to mean something close to guaranteed traffic. Now it means Google might just answer the question itself and keep the visitor on its own page.
What's more interesting is who still gets cited inside those Overviews. Search Engine Land reported that overlap between AI Overview citations and traditional organic rankings climbed from 32.3 percent in May 2024 to 54.5 percent by September 2025. Read that the other way around: nearly half of what AI cites was never in the top ten to begin with. Rank position stopped being the predictor. Something else is doing the selecting.
That something is attribution. An AI system generating an answer needs a source it can point to without embarrassing itself later, the same way a browser needs a certificate it can verify without a user ever seeing the chain behind it. Google even said outright, in documentation from May 2026, that there's no special schema or markup required to show up in Overviews. No trick, no file format, no workaround.
Which means the filtering is happening on the content itself. Specifically, whether it has anything in it worth attributing.
What Still Earns A Click
Zero-click searches went from 56 percent to 69 percent between May 2024 and May 2025. AI Overviews now show up on most informational queries. That part of the story is settled and it is not coming back.
But settled doesn't mean dead. It means the content that survives has to do something a summary cannot do for itself.
Original data survives. If you ran a test, pulled numbers nobody else has, or surveyed your own customers, an AI system has nowhere else to pull that fact from except you. First-hand experience survives the same way. "I tried this and here's what broke" cannot be generated by a model synthesizing ten other articles about the same topic.
Decision-oriented posts survive too, the ones that actually resolve a choice instead of describing the choice in more detail. A reader comparing two tools wants the comparison finished, not restated.
The data backs this up. Long-form posts over 2,000 words that include original, attributable facts showed 2.5x higher odds of ranking and earning backlinks in 2025 analyses. Length by itself buys nothing. Length stuffed with extractable, citable facts buys trust, and trust is the only currency an AI system knows how to spend when it decides who to quote.
Fixing The Misconceptions Holding Teams Back
Two misconceptions keep teams stuck, and both are costing them time they could spend on actual content.
The first is the llms.txt panic. Someone on the team heard that AI systems need a special file, a markdown version, some new schema nobody's implemented yet, and now there's a project brief for it. Google already answered this directly in documentation from May 2026: no special schema, no markup, no formatting requirement. Overviews pull from the same index as classic search. There is no secret file that gets you cited. There is only whether the content has something worth citing.
The second misconception is bigger and harder to unwind. Someone sees the zero-click numbers, the 69 percent figure, and concludes blogging is over, so why bother writing anything long-form at all. That conclusion skips over what the overlap data actually shows. Nearly half of AI citations in 2025 came from pages that never ranked in the traditional top ten. Those pages got picked because they had something extractable in them. Readers who click through from a citation already know the summary. They're arriving because they want more, which means they convert at a higher rate than someone skimming a generic result.