But who says these applications would just make up a root certificate, which would could not be verified? They just need to obtain a roof from a company who's certificate is verifiable and they can continue the chain to make the certificate for swap