In Kazakhstan, several major providers have implemented HTTPS traffic interception.

In accordance with the amendments effective in Kazakhstan since 2016, amendments to the law on "Communications," many Kazakh providers, including Kcell,
Beeline, Tele2 and Altel, as of today have launched systems for intercepting clients' HTTPS traffic by replacing the originally used certificate. The interception system was initially planned to be implemented in 2016, but this operation has been continuously postponed, and the law has become seen as more formal than functional. The interception is carried out under the guise of concern for user security and the desire to protect them from threatening content.

To disable browser warnings about the use of an incorrect certificate, users are required to install a “national security certificate”, which is used when transmitting secure traffic to foreign sites (for example, traffic to Facebook has already been reported as intercepted).

When establishing a TLS connection, the real certificate of the target site is replaced with a newly generated certificate created on-the-fly, which will be marked as valid by the browser if the "national security certificate" has been added by the user to the root certificate store, as the substituted certificate is trust-chained to the "national security certificate."

In essence, the protection provided by the HTTPS protocol in Kazakhstan is completely compromised, and all HTTPS requests, in terms of the potential for surveillance and traffic substitution by security agencies, are hardly different from HTTP. It is impossible to monitor abuses in such a scheme, especially if the encryption keys related to the "national security certificate" fall into other hands as a result of a leak.

Browser developers are considering proposal must add the root certificate used for interception to the list of revoked certificates (OneCRL), as Mozilla recently has done. with certificates from the DarkMatter certification authority. However, the rationale behind this operation is not entirely clear (it was deemed useless in previous discussions), as in the case of the 'national security certificate', this certificate is initially not covered by trust chains, and without user installation of the certificate, browsers display warnings by default. On the other hand, the lack of response from browser manufacturers may encourage the implementation of similar systems in other countries. Another option suggested is to implement a new indicator for locally installed certificates involved in MITM attacks.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster