Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

21–30 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#21
post #7

Earlier quoted context omitted.

That makes it only more interesting. However, I assume, IP-based location isn't that granular?

It's very surprisingly granular. I logged dropped packets from my router's firewall for a week and looked up the origin locations with geoip for fun. Just plugging in the coordinates to google maps would zoom directly in on peoples' houses (sometimes in the middle of nowhere). I'm not sure it's 100% accurate, of course, but it sure seemed specific.

I tried checking my current ip. It points me to some hotel in Helsinki. I'm about 500 km away from there.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#24
post #7

Earlier quoted context omitted.

That makes it only more interesting. However, I assume, IP-based location isn't that granular?

It's very surprisingly granular. I logged dropped packets from my router's firewall for a week and looked up the origin locations with geoip for fun. Just plugging in the coordinates to google maps would zoom directly in on peoples' houses (sometimes in the middle of nowhere). I'm not sure it's 100% accurate, of course, but it sure seemed specific.

The actual data source will provide a country, state or sometimes even city and zipcode. Then whatever tool you're using to map drops a pin in the middle of that region. If you zoom in, you get whatever happens to be at the geographic center of whatever the mapping tool (probably Google Maps) thinks is the center. eg if it says "United States" and no other data, you get some random ass place in the middle of Kansas. Sometimes there can be more specific data, but just because you can keep zooming in doesn't mean that that's actually where it is

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#25
post #7
post #4

Earlier quoted context omitted.

Remember they have your location anyway from your IP address.

That makes it only more interesting. However, I assume, IP-based location isn't that granular?

Basically that and... I'd say when you don't share the location, they only have what's available publicly from GeoIP (via ISPs). Wen you do, your user agent actively tries to give them the best possible results (using GPS or anything else), that's the way I would put it.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#26
post #7

Earlier quoted context omitted.

That makes it only more interesting. However, I assume, IP-based location isn't that granular?

It's very surprisingly granular. I logged dropped packets from my router's firewall for a week and looked up the origin locations with geoip for fun. Just plugging in the coordinates to google maps would zoom directly in on peoples' houses (sometimes in the middle of nowhere). I'm not sure it's 100% accurate, of course, but it sure seemed specific.

This just means that it's precise, not necessarily accurate.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#27
post #2

> The national security certificate will secure protection of Kazakhstan users when using coded access protocols to foreign Internet resources. How is this protecting users? They are outright lying here, if I understand correctly. Also why are they asking for my location? http://i.imgur.com/fYKHRK1.png

At least they are honest - spying and not hiding it ;)

Well technically that's your browser blocking their location request and asking you if you want to let it go through. If they were honest they would say something like "we're about to request your location for x very useful thing that justifies giving up this piece of sensitive data"

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#28

I really appreciate how they're doing this. The Chinese built up an amazing infrastructure for the Great Firewall; the Kazakhs just say "install our cert!" The Chinese spend billions and have to stay ahead of all of their citizens' clever new ideas at all times; the Kazakhs spend a few hundred and just need to point guns at their citizens until they install a cert. Sure, it's going to be difficult to enforce, but it…

Chinese govt is also capable of doing this. Best part? We even have our trusted* root certificate!

Could this get any "better"? Sure! We can even MITM all the OUTGOING https traffic if we want! #GitHubDDoS

* Recently un-trusted by Apple and Mozilla. https://support.apple.com/en-us/HT204938

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#29

Google and Mozilla should blacklist the certificate once it's made public.

That would just stop their browsers from working in Kazakhstan on HTTPS sites, who would most likely respond by issuing a new certificate and/or recommending IE. It may also discourage websites from implementing HTTPS.

Not sure how this will work with certificate pinning, though. Will sites like Google become inaccessible?

Post reply on HN