2026-tolley-beyond-os-trust
findings extracted from this paper
-
Application packaging and software supply chains in Russia's Android ecosystem can expand the effective TLS trust boundary beyond OS-level controls, enabling MITM attacks on TLS connections for apps that bundle or inherit Russian-controlled certificate authorities. This bypasses the assumption that the OS trust store constrains which CAs can intercept encrypted traffic.
-
RuStore provides a state-adjacent software supply chain through which APKs containing certificate material can reach Russian Android users at scale, creating a vector for expanding TLS trust anchors outside the OS trust store and outside Google's certificate governance. The 2022 sanctions that drove RuStore adoption also concentrated this distribution power in domestically controlled infrastructure.
-
A measurement study of RuStore — Russia's domestic Android marketplace promoted after 2022 sanctions isolated Russian users from Google Play — finds that APKs bundle certificate material and trust-configuration artifacts independently of the OS trust store. The study combines ecosystem-wide measurement with a weighted top-application analysis to characterize how this app-level certificate bundling expands the effective TLS trust boundary.
-
The paper directly challenges the assumption that TLS provides a sufficient security fallback against hostile networks, demonstrating that Russia's Android ecosystem enables trust-anchor expansion through app packaging that undermines OS trust store boundaries. The implication is that TLS interception in Russia may be feasible at the app level without requiring OS-level compromise or user consent.