In the early days of internet commercialization I thought issuing trusted certificates would ideally be provided by banks. Money transfers are all about trust and securing information, it seemed like a perfect fit. You get a smart card from your bank that holds their root certificates and pop that into any computer to authenticate an email or website. It also holds your private keys for authenticating yourself to others for online banking, voting, etc.
Of course I've since learned how awfully inertial the banking industry is and that the security of financial transactions is a lot of hand-waving and wishful thinking. On top of that, there's outright corruption of banks profiting from theft and always cooperate with governments.
So the answer is, you shouldn't have to trust anyone. The security infrastructure must be built assuming hostilities are everywhere. Any trust that is given should be limited to just what is necessary to accomplish the task at hand.
Of course I've since learned how awfully inertial the banking industry is and that the security of financial transactions is a lot of hand-waving and wishful thinking. On top of that, there's outright corruption of banks profiting from theft and always cooperate with governments.
So the answer is, you shouldn't have to trust anyone. The security infrastructure must be built assuming hostilities are everywhere. Any trust that is given should be limited to just what is necessary to accomplish the task at hand.