Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

Cancel
7
  • 10
    I'm no expert on this, but want to clarify this sentiment: "Logically, it appears that a MITM attack is possible". It's not just possible, it's the entire point of them installing this onto your computer. So no need to be paranoid, just understand what it is they're doing so you can safely work within their rules. I worked at a company in the US which had us install their own certificates as well. Commented Dec 4 at 16:44
  • 3
    @aaaaaa The fact that the certificates do not set Name Constraints means that they're definitely not putting any effort into dispelling concerns... In this case, it probably is the point, but an organization making you install a root CA is not always done to make MITM possible. Commented Dec 5 at 5:54
  • 1
    @aaaaaa It's not necessarily the entire point of the install of the certs. They could have legitimate certificates for actual websites that track back to those certs. We can't rule out that they want those certs for MITM, but we can't infer that it is their goal. If OP can still access any site with a regular certificate without installing those root certs, it's unlikely there is (currently) any generalised MITM in operation. Commented 2 days ago
  • 1
    Resources disputing goverment decisions are easily blocked. In Russia, methods to circumvent blocks are outlawed, and sites disseminating them are blocked. Commented 2 days ago
  • 1
    Kazakhstan does this because Kazakhstan intercepts your traffic and modifies it - maybe not right now, but they can when they want to. I don't think the question nor the answer need to be very long. If you don't install the certificate, they will still intercept and modify your traffic when they want to, but your computer will know it's wrong and won't load the page. Commented yesterday