Kazakhstan man-in-the-middle attack
state-actor security exploit by the government of Kazakhstan

In 2015, the government of Kazakhstan created a root certificate which could have enabled a man-in-the-middle attack on HTTPS traffic from Internet users in Kazakhstan. The government described it as a "national security certificate". If installed on users' devices, the certificate would have allowed the Kazakh government to intercept, decrypt, and re-encrypt any traffic passing through systems it controlled.
In July 2019, Kazakh ISPs started messaging their users that the certificate, now called the Qaznet Trust Certificate, issued by the state certificate authority the Qaznet Trust Network, would now have to be installed by all users.
Sites operated by Google, Facebook and Twitter appeared to be among the Kazakh government's initial targets.
On August 21, 2019, Mozilla and Google simultaneously announced that their Firefox and Chrome web browsers would not accept the government-issued certificate, even if installed manually by users. Apple also announced that they would make similar changes to their Safari browser. As of August 2019, Microsoft has so far not made any changes to its browsers, but reiterated that the government-issued certificate was not in the trusted root store of any of its browsers, and would not have any effect unless a user manually installed it.
In December 2020, the Kazakh government attempted to re-introduce the government-issued root certificate for a third time. In response to this, browser vendors again announced that they would block any such attempt by invalidating the certificate in their browsers.
The public source identifies “Kazakhstan man-in-the-middle attack” as state-actor security exploit by the government of Kazakhstan. This brief keeps that definition visible, then builds a research path around Kazakhstan, man-in-the-middle and attack.
Why this record matters
A short description can identify a subject without explaining its stakes. For “Kazakhstan man-in-the-middle attack”, the useful work is to connect “state-actor security exploit by the government of Kazakhstan” to the records capable of establishing context and consequence.
Biographical claims are most persuasive when dates, appointments and relationships can be traced to records created close to the events described. The source revision retrieved here is dated Sep 23, 2025. The linked authority identifier is Q65665939. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2015, 2019 and 2020.
Public reputation and documentary evidence do not always develop together; absence from a summary is not evidence of historical absence. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Read biographical claims against dates, named institutions and the cited references. Distinguish a subject’s later reputation from evidence produced during their lifetime.
- Establishing names and roles
- Building a first chronology
- Locating cited institutions
Personal papers, civil or court records, institutional files and the scholarship cited by the source.
Three-step research path
- Establish the record: confirm the title “Kazakhstan man-in-the-middle attack”, its source revision and the description used here.
- Expand the search: follow Kazakhstan man-in-the-middle attack primary sources, Kazakhstan man-in-the-middle attack archive and Kazakhstan research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Kazakhstan man-in-the-middle attack”?
- Which claims depend on a single source or contested interpretation?
- How has the subject’s reputation changed across later accounts?
Search terms from this dossier
This entry incorporates text from “Kazakhstan man-in-the-middle attack” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.