Уровень 0 · материалов: 5
В кластер входят документы, описывающие технические риски и механизмы слежки через принудительную установку корневых сертификатов, и не входят документы об иных методах государственного контроля интернета.
Общие признаки: установка государственных корневых сертификатов, перехват HTTPS-трафика, атаки Man-in-the-Middle, государственная слежка
Группа выше: Защита данных от изъятия и государственного доступа
Смысл: The main idea is to warn about the dangers of installing government-mandated root certificates, which destroy the fundamental security of HTTPS and allow state actors to conduct total surveillance via Man-in-the-Middle attacks.
Kazakhstan's government attempted to force citizens to install a state root certificate to decrypt and monitor all HTTPS/TLS encrypted internet traffic.
Смысл: The text aims to warn users about the technical risks of installing government-mandated root certificates, explaining that doing so allows the state to intercept and decrypt encrypted internet traffic (HTTPS) without detection.
Installing the Ministry of Digital Development's security certificates enables state-sponsored Man-in-the-Middle attacks, allowing the decryption of all HTTPS traffic without browser warnings.
Смысл: The main idea is that installing state-issued root certificates bypasses critical browser security protections (like Certificate Transparency), making the average user vulnerable to effortless, large-scale state surveillance and potential legal persecution.
Installing Ministry of Digital Development certificates allows the state to easily decrypt your secure internet traffic without browser warnings, posing a far greater practical risk than foreign intelligence agencies.
Смысл: The main idea is that the Chinese government utilized a Man-in-the-Middle attack on GitHub to monitor and control users while avoiding a total ban that would harm their economy. It warns that trusting root certificates blindly can lead to state-sponsored surveillance.
China conducted a Man-in-the-Middle attack on GitHub users to bypass SSL and monitor activity, hinting at future risks via trusted root certificates.
Смысл: The main idea is that the silent installation of rogue root certificates undermines HTTPS security, and Yandex Browser has introduced proactive warnings to alert users when their encrypted traffic is being intercepted.
Yandex Browser implemented a system to detect and warn users about rogue root certificates that allow attackers to intercept supposedly secure HTTPS traffic.