/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple, Google, Microsoft, and Mozilla have banned a root certificate being used by the Kazakhstan government to intercept and decrypt HTTPS traffic

This marks the second time browsers makers had to intervene and block a certificate used by the Kazakhstan government to spy on its citizens.

ZDNet Catalin Cimpanu

Context & Ripple Effects

Kazakhstan has run this playbook twice before: a state-issued root certificate mandated in 2015, then again in 2019 when ISPs were ordered to push the certificate onto every device and browser to intercept HTTPS traffic. That 2019 attempt drew a coordinated response — Google and Mozilla announced blocks within days, Apple followed, and Microsoft noted the cert was never in its Trusted Root Program. The same four vendors have now banned the certificate a second time, meaning Kazakhstan reissued or redeployed it after the first block.

The pattern echoes other trust-breach interventions: Google's ban of DarkMatter certificates from Chrome and Android in mid-2019, and Chrome's earlier expulsion of a Chinese certificate authority for breach of trust. Browser makers are acting as the de facto enforcement layer for web PKI when state actors abuse it.

First-order effects

  • Users in Kazakhstan who installed the government certificate lose its interception capability in all four major browsers, breaking the state's HTTPS decryption path on those platforms.
  • Microsoft's inclusion alongside Google, Mozilla, and Apple closes the gap left in 2019, when it had only said the cert wasn't in its Trusted Root Program rather than announcing an active block.

Second-order effects

  • Kazakhstan's interception program is forced back to non-browser channels — system-level installs and apps that don't honor browser trust stores — raising the cost and lowering the reach of the surveillance effort.
  • The repeat offense strengthens the case inside root programs for pre-emptive distrust rules against government-issued certificates, the mechanism already used against DarkMatter and the Chinese CA.

Third-order effects

  • If states keep reissuing intercepted certificates, browser vendors' root stores harden into the primary check on state surveillance of HTTPS — a structural shift where four US-based companies effectively set the limits of lawful interception for entire countries.
  • Repeated vendor blocks push governments toward alternatives outside the CA system (client-side software, network appliances), fragmenting how national surveillance is implemented and making it harder for users to detect.

The trend: State attempts to hijack HTTPS via forced root certificates are being met with faster, broader, and more unified distrust actions from browser vendors, making the root store the decisive battleground between national surveillance programs and encrypted traffic.