FINDING · DETECTION

Kazakhstan's interception system triggered solely on the TLS SNI header: a connection was intercepted only if the SNI contained one of 37 targeted domains AND the path passed through specific AS9198 hops; the server's actual certificate needed to be browser-trusted but did not need to match the SNI domain, and interception could be triggered bidirectionally — from outside the country connecting to TLS hosts inside Kazakhstan.

From 2020-raman-investigatingInvestigating Large Scale HTTPS Interception in Kazakhstan · §3.2, §4 · 2020 · Internet Measurement Conference

Implications

Tags

censors
kz
techniques
sni-blockingdpi

Extracted by claude-sonnet-4-6 — review before relying.