Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…
Kazakhstan to MitM all HTTPS traffic starting Jan 1
151–160 of 378 posts
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#152Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…
Kazakhstan is not the US. We are highly unlikely to see a public uprising in Kazakhstan over this when the country has had the same president since 1991 and rubber-stamp parliament. Protests in 2011 were quelled by gunning down protestors (see below). Nazarbayev, re-elected in a barely contested election to a fifth term on Sunday, was born to a peasant family. He trained as an engineer before rising through the ranks…
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#153Why is Kazakhstan's cert any different than the hundreds of "trusted" root certificates that came preinstalled on my mac? Looking at my mac's cert keychain, there are 185 trusted root certs. I don't know what any of them are or who has the private key to them. My ISP could MITM my traffic whenever it wants to, if it has the private key of one of the hundreds of trusted root certs on my device.
These CAs have to follow specific rules and have external audit. MITM is prohibited by these rules: certificate authorities that participate or enable MITM are removed from root stores (example: https://en.wikipedia.org/wiki/DigiNotar ).
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#154Earlier quoted context omitted.
As an aside, this is one of the reasons why I believe locally installed certificates overriding pinning has a quickly eroding shelf life... At some point, something bad will happen like this (or malware-based) and Chrome will raise their hand and say, "sorry enterprises, no more MITM at all, even for locally installed certificates." After that, IE and Firefox will follow and crypto will no longer be so trivially subv…
Someone suggested using a special icon in the address bar to denote this kind of thing.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#155Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…
> The people of Kazakhstan can achieve the same outcome. Highly unlikely. From Wikipedia: In April 2015, Nazarbayev was re-elected with almost 98% of the vote. That kind of tells the whole story - people are "behind" this (or rather no-one dares contradict the authorities). That country is basically owned by the Family and resistance is pretty much futile.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#156Why is Kazakhstan's cert any different than the hundreds of "trusted" root certificates that came preinstalled on my mac? Looking at my mac's cert keychain, there are 185 trusted root certs. I don't know what any of them are or who has the private key to them. My ISP could MITM my traffic whenever it wants to, if it has the private key of one of the hundreds of trusted root certs on my device.
Those hundreds of trusted root certificates are, at least to some extent, held to operational and security standards. If your ISP used one of those certificates to MitM your traffic, there is a very real possibility of that certificate being blacklisted by browsers. Further, unlike the Kazakhstan certificate, those root certificates cannot bypass HTTPS public key pinning (HPKP).
1:
> there is a very real possibility of that certificate being blacklisted by browsers
Why would a browser blacklist a certificate? Is it possible for a browser to detect a MITM attack when the SSL traffic is all signed by the private key of a trusted root certificate?
2:
> Further, unlike the Kazakhstan certificate, those root certificates cannot bypass HTTPS public key pinning (HPKP).
You are saying that pre-installed root certificates behave differently than user-installed root certificates? Wouldn't that behavior be system-dependent? I was under the impression that no root certificates can bypass public key pinning... isn't that sort of the point of pinning? That it allows traffic encryption outside of the normal trust hierarchy? What makes the Kazakhstan cert special that allows it to break pinning?
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#157My prediction : Indian government takes up this idea in the next 12 months. If this works this idea will spread.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#158[1] http://egov.kz/wps/poc?uri=mjnpa:document&language=kk&docume... [2] http://egov.kz/wps/poc?uri=mjnpa:document&language=ru&docume...
Edit: I think I got them this time. They seem to be ministerial orders under Kazakhstan's 2004 telecoms law:
In Kazakh: http://info-con.mid.gov.kz/sites/default/files/pages/2_kaz.d... http://info-con.mid.gov.kz/sites/default/files/pages/6_kaz.d...
And Russian: http://info-con.mid.gov.kz/sites/default/files/pages/2_rus.d... http://info-con.mid.gov.kz/sites/default/files/pages/6_rus.d...
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#159Why is Kazakhstan's cert any different than the hundreds of "trusted" root certificates that came preinstalled on my mac? Looking at my mac's cert keychain, there are 185 trusted root certs. I don't know what any of them are or who has the private key to them. My ISP could MITM my traffic whenever it wants to, if it has the private key of one of the hundreds of trusted root certs on my device.
These CAs have to follow specific rules and have external audit. MITM is prohibited by these rules: certificate authorities that participate or enable MITM are removed from root stores (example: https://en.wikipedia.org/wiki/DigiNotar ).
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#160Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…
The only thing that Google et al. could do is refuse to provide service to Kazakhstan which would only harm the people even more, if you are a dissident you are already taking a huge risk denying people the ability to access information and to connect with others won't help to reduce that risk just only make it worse as it would only isolate them further.
China is doing the same, so do many Gulf nations to some extent or another, no one is arguing that we should not cooperate with China, cooperation is the only real way to effect change in those nations in the first place, or would you think China would be as open as it is today if we would have a technical and cultural embargo over it?