Google, Mozilla, Apple to block root certificate issued by Kazakhstan which could be used to monitor users; Microsoft says cert not in its Trusted Root Program
Kazakhstan's surveillance mechanism fails at install-time enforcement: with all four browser makers refusing to honor the root, users who do install it lose the ability to reach mainstream sites over HTTPS rather than gain monitoring coverage.
Microsoft's statement that the cert was never in its Trusted Root Program means Windows users were never exposed through the platform default, narrowing the attack to manual installs.
Second-order effects
The coordinated response follows the WoSign/StartCom revocation template from 2017, where Microsoft joined an Apple-Google-Mozilla consensus — signaling to other state actors that a misused government-issued root gets every major vendor aligned against it within days.
The move sits alongside Google's recent ban of DarkMatter certificates from Chrome and Android, reinforcing that trust decisions are consolidating around a shared vendor bloc regardless of whether the applicant is a company or a state.
Third-order effects
If the pattern holds, browser vendors function as the de facto governing authority of web trust — state-issued certificates survive only at their pleasure, and governments seeking interception must either build parallel infrastructure or accept exclusion from the encrypted web.
The 2019 block proved durable enough that by late 2020 all four vendors had formalized a full ban on the same Kazakhstan certificate (the eventual four-vendor ban), suggesting one-off revocations are hardening into standing policy toward state CAs.
The trend: Web trust is consolidating into an informal cartel of browser vendors whose joint revocation decisions now override national certificate authorities.
The next obvious step is for a government to fork a browser - and of course do it badly (eg not apply security updates). Beyond the 🍿 effect, this makes it even more clear that your choice of browser is important. https://blog.mozilla.org/...
Apple, Google, and Mozilla block Kazakhstan's HTTPS intercepting certificate in their respective browsers Measure comes a little too late, as the Kazakh government has stopped using it, but the ban will the root cert from ever being useful again https://www.zdnet.com/... https://…
Meanwhile, there are plenty of other shady govt root CAs that are either directly trusted by MSFT, or implicitly trusted due to cross-signing unless you explicitly move them to the “untrusted"* bin. (* = Don't delete, make untrusted to avoid having them reinstalled) pic.twitter.c…
I followed up to make sure with Microsoft, hey, even if the Kazakhstan cert isn't from a trusted CA, people can still add it to the browser, right? So you haven't blocked it. Nothing to add, spokesperson says.
Microsoft completely missing the point there, it isn't a trusted CA on Chrome, Mozilla, Apple etc either - the government requires people to install it. The rest blocked it by distrusting it, Microsoft didn't = enables spying.
Update: Apple spox said Safari is blocking the root certificate as well. “We have taken action to ensure the certificate is not trusted by Safari and our users are protected from this issue.” https://twitter.com/...
Kazakhstan has implemented a new monitoring system that would offer the government access to all web traffic within the country, even encrypted data. Now, Google, Mozilla, and Apple are adding technical protections to their browsers to fight back. https://wired.trib.al/FyTwY3y