Google and Mozilla say they will block the root certificate issued by the Kazakhstan government, which could be used to monitor users, in Chrome and Firefox
Google and Mozilla are taking action against the government of Kazakhstan's efforts to launch a surveillance operation against its own citizens.
Context & Ripple Effects
Kazakhstan has run this play before: a state-issued root certificate requirement dating to 2015, then this summer's sharper version — ISPs forced to push the certificate onto every device and browser so the government could intercept HTTPS traffic in the middle. The difference now is that the trust-store owners are refusing at the source.
The move lands weeks after Google banned DarkMatter certificates from Chrome and Android while Mozilla kept them out of Firefox entirely ([[a:944086]]), establishing that root-program gatekeeping is actively enforced against surveillance-adjacent actors — not just maintained passively.
First-order effects
- Kazakh citizens' browsers will refuse to honor the government certificate even where ISPs install it, collapsing the interception mechanism's reach in Chrome and Firefox, which together cover most of the market.
- Microsoft's statement that the cert was never in its Trusted Root Program, per follow-up coverage, means the government's scheme only ever worked against users it could force onto non-standard trust settings.
Second-order effects
- The holdout vendors face immediate pressure to match: Apple joined the block within days and the full four-vendor ban was formalized by December 2020 ([[a:961232]]), turning an initial two-browser response into an industry-wide standard.
- Kazakhstan is pushed toward costlier, less scalable workarounds — manual trust-store installs or custom builds — shifting its surveillance program from passive infrastructure to per-user friction.
Third-order effects
- Trust stores become a de facto regulatory layer over state surveillance: a handful of US-headquartered browser and OS vendors now hold veto power over any government's man-in-the-middle capability, a role no law formally assigned them.
- If states keep testing root-level interception, expect the root programs to formalize surveillance as an explicit revocation criterion — the DarkMatter and Kazakhstan cases are the working precedents.
The trend: Browser and OS vendors are consolidating de facto governance of encryption trust, using root-program bans to override state-run HTTPS interception schemes.