/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google, Mozilla, Apple to block root certificate issued by Kazakhstan which could be used to monitor users; Microsoft says cert not in its Trusted Root Program

Joseph Cox / VICE :

VICE Joseph Cox

Context & Ripple Effects

Kazakhstan has been running this playbook since its 2015 order requiring citizens to install a state-issued root certificate, which would let the government intercept HTTPS traffic. The day before this report, Google and Mozilla committed to blocking the newly issued certificate in Chrome and Firefox (coverage of that announcement); Apple joining — plus Microsoft confirming the cert is absent from its [[a:?|Trusted Root Program]] — closes off the remaining major browser paths.

First-order effects

  • Kazakhstan's surveillance mechanism fails at install-time enforcement: with all four browser makers refusing to honor the root, users who do install it lose the ability to reach mainstream sites over HTTPS rather than gain monitoring coverage.
  • Microsoft's statement that the cert was never in its Trusted Root Program means Windows users were never exposed through the platform default, narrowing the attack to manual installs.

Second-order effects

  • The coordinated response follows the WoSign/StartCom revocation template from 2017, where Microsoft joined an Apple-Google-Mozilla consensus — signaling to other state actors that a misused government-issued root gets every major vendor aligned against it within days.
  • The move sits alongside Google's recent ban of DarkMatter certificates from Chrome and Android, reinforcing that trust decisions are consolidating around a shared vendor bloc regardless of whether the applicant is a company or a state.

Third-order effects

  • If the pattern holds, browser vendors function as the de facto governing authority of web trust — state-issued certificates survive only at their pleasure, and governments seeking interception must either build parallel infrastructure or accept exclusion from the encrypted web.
  • The 2019 block proved durable enough that by late 2020 all four vendors had formalized a full ban on the same Kazakhstan certificate (the eventual four-vendor ban), suggesting one-off revocations are hardening into standing policy toward state CAs.

The trend: Web trust is consolidating into an informal cartel of browser vendors whose joint revocation decisions now override national certificate authorities.

Discussion

  • @mnot Mark Nottingham on x
    The next obvious step is for a government to fork a browser - and of course do it badly (eg not apply security updates). Beyond the 🍿 effect, this makes it even more clear that your choice of browser is important. https://blog.mozilla.org/...
  • @campuscodi Catalin Cimpanu on x
    Apple, Google, and Mozilla block Kazakhstan's HTTPS intercepting certificate in their respective browsers Measure comes a little too late, as the Kazakh government has stopped using it, but the ban will the root cert from ever being useful again https://www.zdnet.com/... https://…
  • @scott_helme Scott Helme on x
    Chrome nuked the Kazakhstan government's interception certificate with an entry in CRLset: https://security.googleblog.com/ ...
  • @josephfcox Joseph Cox on x
    Microsoft says “The Certificate Authority (CA) in question is not a trusted CA in our Trusted Root Program” https://www.vice.com/...
  • @kristofera @kristofera on x
    Meanwhile, there are plenty of other shady govt root CAs that are either directly trusted by MSFT, or implicitly trusted due to cross-signing unless you explicitly move them to the “untrusted"* bin. (* = Don't delete, make untrusted to avoid having them reinstalled) pic.twitter.c…
  • @danbo Dan Atkinson on x
    Someone really dropped the ball in Redmond with this. Is the money paid by Kazakhstan's government for Windows support really worth this silly stance?
  • @josephfcox Joseph Cox on x
    I followed up to make sure with Microsoft, hey, even if the Kazakhstan cert isn't from a trusted CA, people can still add it to the browser, right? So you haven't blocked it. Nothing to add, spokesperson says.
  • @gossithedog Kevin Beaumont on x
    Microsoft completely missing the point there, it isn't a trusted CA on Chrome, Mozilla, Apple etc either - the government requires people to install it. The rest blocked it by distrusting it, Microsoft didn't = enables spying.
  • @askhalid Amrita Khalid on x
    Update: Apple spox said Safari is blocking the root certificate as well. “We have taken action to ensure the certificate is not trusted by Safari and our users are protected from this issue.” https://twitter.com/...
  • @wired @wired on x
    Kazakhstan has implemented a new monitoring system that would offer the government access to all web traffic within the country, even encrypted data. Now, Google, Mozilla, and Apple are adding technical protections to their browsers to fight back. https://wired.trib.al/FyTwY3y