Apple, Google, Microsoft, and Mozilla have banned a root certificate being used by the Kazakhstan government to intercept and decrypt HTTPS traffic
This marks the second time browsers makers had to intervene and block a certificate used by the Kazakhstan government to spy on its citizens.
Context & Ripple Effects
Kazakhstan has run this playbook twice before: a state-issued root certificate mandated in 2015, then again in 2019 when ISPs were ordered to push the certificate onto every device and browser to intercept HTTPS traffic. That 2019 attempt drew a coordinated response — Google and Mozilla announced blocks within days, Apple followed, and Microsoft noted the cert was never in its Trusted Root Program. The same four vendors have now banned the certificate a second time, meaning Kazakhstan reissued or redeployed it after the first block.
The pattern echoes other trust-breach interventions: Google's ban of DarkMatter certificates from Chrome and Android in mid-2019, and Chrome's earlier expulsion of a Chinese certificate authority for breach of trust. Browser makers are acting as the de facto enforcement layer for web PKI when state actors abuse it.
First-order effects
- Users in Kazakhstan who installed the government certificate lose its interception capability in all four major browsers, breaking the state's HTTPS decryption path on those platforms.
- Microsoft's inclusion alongside Google, Mozilla, and Apple closes the gap left in 2019, when it had only said the cert wasn't in its Trusted Root Program rather than announcing an active block.
Second-order effects
- Kazakhstan's interception program is forced back to non-browser channels — system-level installs and apps that don't honor browser trust stores — raising the cost and lowering the reach of the surveillance effort.
- The repeat offense strengthens the case inside root programs for pre-emptive distrust rules against government-issued certificates, the mechanism already used against DarkMatter and the Chinese CA.
Third-order effects
- If states keep reissuing intercepted certificates, browser vendors' root stores harden into the primary check on state surveillance of HTTPS — a structural shift where four US-based companies effectively set the limits of lawful interception for entire countries.
- Repeated vendor blocks push governments toward alternatives outside the CA system (client-side software, network appliances), fragmenting how national surveillance is implemented and making it harder for users to detect.
The trend: State attempts to hijack HTTPS via forced root certificates are being met with faster, broader, and more unified distrust actions from browser vendors, making the root store the decisive battleground between national surveillance programs and encrypted traffic.