CACrown ArchivesThe cinema collection
Menu
Research dossier · People & Ideas

Kazakhstan man-in-the-middle attack

state-actor security exploit by the government of Kazakhstan

Correspondence, annotated notebooks and portrait silhouettes prepared for research
People and ideasInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionSep 23, 2025
Entity authorityQ65665939 ↗
Source-derived summary

In 2015, the government of Kazakhstan created a root certificate which could have enabled a man-in-the-middle attack on HTTPS traffic from Internet users in Kazakhstan. The government described it as a "national security certificate". If installed on users' devices, the certificate would have allowed the Kazakh government to intercept, decrypt, and re-encrypt any traffic passing through systems it controlled.

In July 2019, Kazakh ISPs started messaging their users that the certificate, now called the Qaznet Trust Certificate, issued by the state certificate authority the Qaznet Trust Network, would now have to be installed by all users.

Sites operated by Google, Facebook and Twitter appeared to be among the Kazakh government's initial targets.

On August 21, 2019, Mozilla and Google simultaneously announced that their Firefox and Chrome web browsers would not accept the government-issued certificate, even if installed manually by users. Apple also announced that they would make similar changes to their Safari browser. As of August 2019, Microsoft has so far not made any changes to its browsers, but reiterated that the government-issued certificate was not in the trusted root store of any of its browsers, and would not have any effect unless a user manually installed it.

In December 2020, the Kazakh government attempted to re-introduce the government-issued root certificate for a third time. In response to this, browser vendors again announced that they would block any such attempt by invalidating the certificate in their browsers.

Editorial summary

The public source identifies “Kazakhstan man-in-the-middle attack” as state-actor security exploit by the government of Kazakhstan. This brief keeps that definition visible, then builds a research path around Kazakhstan, man-in-the-middle and attack.

Editorial reviewA useful biographical orientation record, particularly for establishing names, roles and a first chronology. The current lead gives the account dated anchors—2015, 2019, 2020—that can be checked directly. The selected authority fields contribute no independent date. Its value is orientation rather than verdict, with Kazakhstan, man-in-the-middle and attack providing the first useful test.
Editorial analysis

Why this record matters

A short description can identify a subject without explaining its stakes. For “Kazakhstan man-in-the-middle attack”, the useful work is to connect “state-actor security exploit by the government of Kazakhstan” to the records capable of establishing context and consequence.

Evidence profile

Biographical claims are most persuasive when dates, appointments and relationships can be traced to records created close to the events described. The source revision retrieved here is dated Sep 23, 2025. The linked authority identifier is Q65665939. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2015, 2019 and 2020.

Critical limits

Public reputation and documentary evidence do not always develop together; absence from a summary is not evidence of historical absence. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Read biographical claims against dates, named institutions and the cited references. Distinguish a subject’s later reputation from evidence produced during their lifetime.

Best used for
  • Establishing names and roles
  • Building a first chronology
  • Locating cited institutions
Verify next

Personal papers, civil or court records, institutional files and the scholarship cited by the source.

Three-step research path

  1. Establish the record: confirm the title “Kazakhstan man-in-the-middle attack”, its source revision and the description used here.
  2. Expand the search: follow Kazakhstan man-in-the-middle attack primary sources, Kazakhstan man-in-the-middle attack archive and Kazakhstan research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “Kazakhstan man-in-the-middle attack”?
  2. Which claims depend on a single source or contested interpretation?
  3. How has the subject’s reputation changed across later accounts?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from “Kazakhstan man-in-the-middle attack” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.