{"id":11406,"date":"2019-07-19T09:30:06","date_gmt":"2019-07-19T16:30:06","guid":{"rendered":"https:\/\/www.privateinternetaccess.com\/blog\/?p=11406"},"modified":"2021-08-03T07:01:10","modified_gmt":"2021-08-03T14:01:10","slug":"kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation","status":"publish","type":"post","link":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/","title":{"rendered":"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation"},"content":{"rendered":"<p>On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the Kazakh government ordered all of the internet service providers (ISPs) to force their customers to install a government-issued root certificate by Qaznet Trust Network on all of their internet accessing devices. If installed, this MITM cert allows the government to intercept, decrypt, analyze, then re-encrypt all browser encrypted HTTPS traffic in a country wide man-in-the-middle (MITM) attack. Since Wednesday, Kazakh internet users have been redirected to instructional pages asking them to install the new certificate. Forcing all of Kazakhstan\u2019s internet through one government issued certificate is a gargantuan privacy issue, but it is also a security issue. Any hacker that gets control of the Quaznet domain will be able to view the supposedly encrypted personal information from Kazakh internet users. Passwords, usernames, credit card information, all of it would be available unencrypted in such a scenario.<\/p>\n<p>To their credit, a <a href=\"https:\/\/rus.azattyq.org\/a\/30064788.html\" target=\"_blank\" rel=\"noopener noreferrer\">Kazakh official clarified<\/a> on July 19th, 2019 that the installation of the certificate was voluntary and not a prerequisite to accessing the internet.<\/p>\n<p>Officials from the Ministry of Digital Development, Innovation and Aerospace <a href=\"https:\/\/www.zdnet.com\/article\/kazakhstan-government-is-now-intercepting-all-https-traffic\/\" target=\"_blank\" rel=\"noopener noreferrer\">stated<\/a> that the new rule was \u201caimed at enhancing the protection of citizens, government bodies and private companies from hacker attacks, Internet fraudsters and other types of cyber threats,\u201d but that clearly doesn\u2019t seem to be the case. Messaging on the MITM cert install page by one Kazakh service provider, Kcell, specified what some of those \u201cother types of cyber threats\u201d just might be:<\/p>\n<blockquote><p>\u201cA security certificate is a set of electronic digital symbols used to pass traffic that contains protocols that support encryption. Thus, it will allow Kazakhstani Internet users to be protected from hacker attacks and viewing illegal content.\u201d<\/p><\/blockquote>\n<p>The notice-to-be-mitm also specifies that Linux users are exempt from downloading this rogue cert:<\/p>\n<blockquote><p>\u201c[\u2026] the installation of a security certificate must be performed from each device that will be used to access the Internet (mobile phones and tablets based on iOS \/ Android, personal computers and laptops based on Windows \/ MacOS).\u201d<\/p><\/blockquote>\n<p>The privacy and cryptography community online has responded with a particular uproar. <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/comcast-still-uses-mitm-javascript-injection-serve-unwanted-ads-messages\/\">MITM attacks by ISPs<\/a> are bad enough when it\u2019s done by the ISP for economic gain reasons. When it\u2019s ordered by a government which overseas millions of citizens, it is a look into the future dystopia. If Kazakhstan succeeds in this, the country will join North Korea in a short list of countries that have more of an intranet than an internet. The real fear, which Dr. Green articulates concisely, is the thought of <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/australian-prime-minister-turnbull-laws-mathematics-dont-apply-australia\/\">tech-illiterate<\/a> politicians in democratic governments around the world salivating at the mouth while considering Kazakhstan\u2019s new internet policy as a good one.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">This is the future all those cypherpunks warned us about. Let\u2019s hope the West sees the danger, and doesn\u2019t look on with admiration.<\/p>\n<p>\u2014 Matthew Green (@matthew_d_green) <a href=\"https:\/\/twitter.com\/matthew_d_green\/status\/1152212992173453313?ref_src=twsrc%5Etfw\">July 19, 2019<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h2>A state entity is trying to MITM its citizens\u2026 How will internet browsers react?<\/h2>\n<p>Will browsers ban this certificate, even if it isn\u2019t mandatory, essentially disabling the ability for the Kazakh government and ISPs to spy on Kazakh citizens? Or will they allow this certificate to be and show some sort of persistent warning instead? Some believe that this is no different than internet access as exists in some managed, corporate settings.<\/p>\n<p>One<a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1567114#c16\" target=\"_blank\" rel=\"noopener noreferrer\"> commenter on the Mozilla (Firefox) bugthread<\/a> has a passionate plea to the former with the argument that only by taking the nuclear approach and blocking Kazakhstan\u2019s MITM cert will the wider internet community be able to stop Kazakhstan from achieving its goal of intercepting all HTTPS traffic within the country. Allegedly, the threat of this is what caused the government to back down on this same plan in 2016.<\/p>\n<blockquote><p>I am a citizen of Kazakhstan. If Mozilla\/Google Chrome developers see this message,I kindly ask you to consider blocking the above mentioned certificate and any access to your browsers for the certificate holders. If this certificate didn\u2019t pass Web trust audit, it can be the same as presented in 2016. So blocking it from the major world browsers is the only chance for kazakhs to avoid MITM attacks and keep at least some privacy rights (meaning that if blocked\/blacklisted, the government will have to call back the certificate as it was done in 2016). [\u2026] If the certificate is not blacklisted, but only the visual message will pop up warning users about untrusted certificate \u2013 it will not help since majority of citizens (especially elderly ones) simply will not pay enough attention to such [a] message.<\/p><\/blockquote>\n<p>Since 2016, the Kazakh officials have added language that allows for exceptions to their MITM plan that graciously \u201callows\u201d for encrypted traffic to bypass this MITM. The commenter also noted that the government does feel that they have bypassed the issues from their last rollout of their countrywide MITM attack:<\/p>\n<blockquote><p>The request to install the certificate is distributed via sms (as of now \u2013 only to the capital\u2019s citizens). The last change in the law that the officials are referring to was done in December 2017. Clause 3-1, subclause 4) says that \u201cProviders of international network are required to \u20264) to pass traffic using protocols that support encryption via security certificates, with the exception of traffic that was encrypted in Kazakhstan by cryptographic tools for data security\u201d.<\/p><\/blockquote>\n<p>If browsers blacklist the certificate, and in essence take the stance that they will not let the Kazakh government spy on its citizens using their software, it\u2019s possible that the Kazakh government will back down; however, it\u2019s also possible that the Kazakh government might just force Kazakh ISPs to encourage the use of a state run browser \u2013 which would likely be forked from Chromium or Firefox anyways. This issue, as articulated by Matthew Hardeman in the corresponding <a href=\"https:\/\/groups.google.com\/forum\/#!msg\/mozilla.dev.security.policy\/wnuKAhACo3E\/4m7w6P82DwAJ\">email listserv discussion<\/a>, leads to different a scenario where Kazakh citizens have both their privacy and security violated.<\/p>\n<p>What ends up happening at the browser level is still unclear \u2013 all the large industry stakeholders such as Microsoft, Mozilla, and Google are all discussing the <a href=\"https:\/\/groups.google.com\/forum\/#!msg\/mozilla.dev.security.policy\/wnuKAhACo3E\/cpsvHgcuDwAJ\" target=\"_blank\" rel=\"noopener noreferrer\">issue<\/a> in earnest but nothing has been decided as of yet. In the meantime, Kazakh internet users need to protect themselves by encrypting their internet traffic themselves and avoiding the installation of this certificate at all costs \u2013 possibly by switching to Linux. Even if the certificate isn\u2019t necessary to access the internet, many Kazakh internet users will get that impression from the language presented by their ISPs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the Kazakh government ordered all of the internet service providers (ISPs) to force their customers to install a government-issued root certificate by Qaznet Trust Network on all of their internet accessing devices. &hellip; <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation&#8221;<\/span><\/a><\/p>\n","protected":false},"author":12,"featured_media":11409,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_stopmodifiedupdate":false,"_modified_date":"","footnotes":""},"categories":[12,1,130],"tags":[1105,1501,1502,1503],"class_list":["post-11406","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-news","category-governments","tag-https","tag-kazakhstan","tag-mitm","tag-rogue-certificates"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation<\/title>\n<meta name=\"description\" content=\"On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation\" \/>\n<meta property=\"og:description\" content=\"On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\" \/>\n<meta property=\"og:site_name\" content=\"PIA\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/privateinternetaccess\/\" \/>\n<meta property=\"article:published_time\" content=\"2019-07-19T16:30:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-03T14:01:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Caleb Chen\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@http:\/\/twitter.com\/bitxbitxbitcoin\" \/>\n<meta name=\"twitter:site\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Caleb Chen\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\"},\"author\":{\"name\":\"Caleb Chen\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/0558caeb5ffc3548403d0391401d6bb7\"},\"headline\":\"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation\",\"datePublished\":\"2019-07-19T16:30:06+00:00\",\"dateModified\":\"2021-08-03T14:01:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\"},\"wordCount\":1076,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png\",\"keywords\":[\"https\",\"kazakhstan\",\"mitm\",\"rogue certificates\"],\"articleSection\":[\"Cybersecurity\",\"General Privacy News\",\"Governments\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\",\"name\":\"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png\",\"datePublished\":\"2019-07-19T16:30:06+00:00\",\"dateModified\":\"2021-08-03T14:01:10+00:00\",\"description\":\"On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the\",\"breadcrumb\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png\",\"width\":1000,\"height\":500,\"caption\":\"kazakhstan mitm rogue cert\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.privateinternetaccess.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"name\":\"PIA\",\"description\":\"Online privacy news from around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\",\"name\":\"Private Internet Access\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"width\":1200,\"height\":1200,\"caption\":\"Private Internet Access\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/privateinternetaccess\/\",\"https:\/\/x.com\/buyvpnservice\",\"https:\/\/www.instagram.com\/piavpn\/\",\"https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/0558caeb5ffc3548403d0391401d6bb7\",\"name\":\"Caleb Chen\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a15ee046ccff16b50a391b9ff430be47f70e80f9e7bfd4bd0b029339535ece67?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a15ee046ccff16b50a391b9ff430be47f70e80f9e7bfd4bd0b029339535ece67?s=96&d=mm&r=g\",\"caption\":\"Caleb Chen\"},\"description\":\"Caleb Chen is a digital currency and privacy advocate who believes we must #KeepOurNetFree, preferably through decentralization. Caleb holds a Master's in Digital Currency from the University of Nicosia as well as a Bachelor's from the University of Virginia. He feels that the world is moving towards a better tomorrow, bit by bit by Bitcoin.\",\"sameAs\":[\"https:\/\/x.com\/http:\/\/twitter.com\/bitxbitxbitcoin\"],\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/author\/caleb-chen\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation","description":"On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/","og_locale":"en_US","og_type":"article","og_title":"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation","og_description":"On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the","og_url":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/","og_site_name":"PIA","article_publisher":"https:\/\/www.facebook.com\/privateinternetaccess\/","article_published_time":"2019-07-19T16:30:06+00:00","article_modified_time":"2021-08-03T14:01:10+00:00","og_image":[{"width":1000,"height":500,"url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png","type":"image\/png"}],"author":"Caleb Chen","twitter_card":"summary_large_image","twitter_creator":"@http:\/\/twitter.com\/bitxbitxbitcoin","twitter_site":"@buyvpnservice","twitter_misc":{"Written by":"Caleb Chen","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#article","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/"},"author":{"name":"Caleb Chen","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/0558caeb5ffc3548403d0391401d6bb7"},"headline":"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation","datePublished":"2019-07-19T16:30:06+00:00","dateModified":"2021-08-03T14:01:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/"},"wordCount":1076,"commentCount":2,"publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png","keywords":["https","kazakhstan","mitm","rogue certificates"],"articleSection":["Cybersecurity","General Privacy News","Governments"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/","name":"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png","datePublished":"2019-07-19T16:30:06+00:00","dateModified":"2021-08-03T14:01:10+00:00","description":"On July 17th, 2019, the government of Kazakhstan enacted a new cybersecurity measure that aims to spy on its citizens\u2019 internet traffic. Specifically, the","breadcrumb":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#primaryimage","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2019\/07\/1000px-Flag_of_Kazakhstan.svg_.png","width":1000,"height":500,"caption":"kazakhstan mitm rogue cert"},{"@type":"BreadcrumbList","@id":"https:\/\/www.privateinternetaccess.com\/blog\/kazakhstan-tries-and-fails-to-mitm-all-of-its-internet-users-with-rogue-certificate-installation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.privateinternetaccess.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Kazakhstan tries and fails to MITM all of its internet users with rogue certificate installation"}]},{"@type":"WebSite","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website","url":"https:\/\/www.privateinternetaccess.com\/blog\/","name":"PIA","description":"Online privacy news from around the world.","publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization","name":"Private Internet Access","url":"https:\/\/www.privateinternetaccess.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","width":1200,"height":1200,"caption":"Private Internet Access"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/privateinternetaccess\/","https:\/\/x.com\/buyvpnservice","https:\/\/www.instagram.com\/piavpn\/","https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w"]},{"@type":"Person","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/0558caeb5ffc3548403d0391401d6bb7","name":"Caleb Chen","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a15ee046ccff16b50a391b9ff430be47f70e80f9e7bfd4bd0b029339535ece67?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a15ee046ccff16b50a391b9ff430be47f70e80f9e7bfd4bd0b029339535ece67?s=96&d=mm&r=g","caption":"Caleb Chen"},"description":"Caleb Chen is a digital currency and privacy advocate who believes we must #KeepOurNetFree, preferably through decentralization. Caleb holds a Master's in Digital Currency from the University of Nicosia as well as a Bachelor's from the University of Virginia. He feels that the world is moving towards a better tomorrow, bit by bit by Bitcoin.","sameAs":["https:\/\/x.com\/http:\/\/twitter.com\/bitxbitxbitcoin"],"url":"https:\/\/www.privateinternetaccess.com\/blog\/author\/caleb-chen\/"}]}},"_links":{"self":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/11406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/comments?post=11406"}],"version-history":[{"count":5,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/11406\/revisions"}],"predecessor-version":[{"id":17585,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/11406\/revisions\/17585"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media\/11409"}],"wp:attachment":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media?parent=11406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/categories?post=11406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/tags?post=11406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}