Closed Bug 1863944 Opened 2 years ago Closed 2 years ago

MITM in Kazakhstan

Categories

(Core :: Security: PSM, enhancement)

enhancement

Tracking

()

RESOLVED WONTFIX

People

(Reporter: 7ln2itkob, Unassigned)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

3.16 KB, application/x-x509-ca-cert
Details
Attached file tsargrad-tv-chain.pem —

Steps to reproduce:

Visit https://tsargrad.tv while being located in Kazakhstan.

Actual results:

Website provided expired certificate verified by "Information Security Certification Authority".
Firefox showed error code SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE but offered to "accept risk and continue".

Expected results:

I think Mozilla must blacklist the certificate without allowing to continue since it is clearly malicious.

The Bugbug bot thinks this bug should belong to the 'Core::Security: PSM' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Security: PSM
Product: Firefox → Core

Is there a root certificate the government had you download and install in order to be able to view websites in Kazakhstan?

Flags: needinfo?(7ln2itkob)

Definitely not.

The ISCA CA certificate is only valid between 2023-08-09 and 2023-10-23. If I had their government certificate installed, they wouldn't need this weird outdated certificate to try to see what I'm doing.

To rule out any issues with my Firefox installation, I checked Chromium and had the same result. Chromium also allowed to continue, but provided a more explicit message indicating that the communication is being intercepted, whereas Firefox simply suggested that "the website is likely misconfigured or your computer clock is set to the wrong time", which is pretty far away from the real reason the certificate is invalid.

Until recently, the website was simply blocked. However, in the past couple weeks, internet connection quality in Kazakhstan has decreased without any meaningful explanation from government-owned ISP. Eventually, connection quality restored, and the website suddenly became accessible again, but with this new certificate.

Flags: needinfo?(7ln2itkob)

The website is misconfigured. Regardless, if it used an intermediate that wasn't expired, you'd see an unknown issuer error (since according to comment 3, you haven't installed the MITM CA from the government). This error would also be overridable, since in general there's no way to know that the certificate could have chained to a government MITM cert. In short, there's no effective action Firefox can take here.

Status: UNCONFIRMED → RESOLVED
Closed: 2 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: