Kazakhstan claims ISPs asking customers to install government-issued encryption certificates on their devices was simply a test, says users can now remove them
Olzhas Auyezov / Reuters :
Context & Ripple Effects
Kazakhstan has run this play before: back in December 2015 it ordered every Internet user to install a state-issued root certificate, a move security researchers flagged as imperilling citizens' traffic. This summer it revived the scheme through ISPs, with users forced to install the government certificate on all devices and in every browser so HTTPS sessions could be intercepted.
The 'it was only a test' framing arrives after the plan hit a wall: [[a:945038|Google and Mozilla announced they would block the Kazakh root certificate outright in Chrome and Firefox]], removing the technical path the interception depended on. Telling users they can now remove the certificates is a retreat dressed as closure.
First-order effects
- Kazakh users who installed the government certificate at their ISP's request are now being told to uninstall it, ending — on paper — the state's ability to decrypt their HTTPS traffic via that route.
- Kazakhstan's ISPs stand down from distributing the certificate, after weeks of acting as the enforcement arm for the interception scheme.
Second-order effects
- Browser vendors have established that their root-certificate stores override national mandates: once Chrome and Firefox blacklisted the cert, the government's install push became technically inert regardless of what ISPs requested.
- The episode raises the reputational and operational cost for any vendor serving Kazakh users — Apple, Microsoft, Google, and Mozilla all ended up treating a sovereign certificate as malware-grade, a precedent other governments attempting similar schemes must now price in.
Third-order effects
- If the pattern holds, state attempts at lawful-intercept-by-certificate will keep colliding with the handful of companies controlling browser root stores, making global trust in certificates an effective veto over national surveillance architectures.
- Kazakhstan's demonstrated fallback when fine-grained interception fails is blunter: the country has since resorted to nationwide internet shutdowns during unrest, suggesting the certificate test was one layer of a broader control toolkit rather than an isolated experiment.
The trend: State HTTPS-interception schemes are being defeated not by domestic opposition but by browser vendors' control of root-certificate trust, forcing governments toward cruder shutdown tactics instead.