Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

161–170 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#161
post #138

Earlier quoted context omitted.

Those hundreds of trusted root certificates are, at least to some extent, held to operational and security standards. If your ISP used one of those certificates to MitM your traffic, there is a very real possibility of that certificate being blacklisted by browsers. Further, unlike the Kazakhstan certificate, those root certificates cannot bypass HTTPS public key pinning (HPKP).

Thanks for the info! I didn't know some of this. Two questions: 1: > there is a very real possibility of that certificate being blacklisted by browsers Why would a browser blacklist a certificate? Is it possible for a browser to detect a MITM attack when the SSL traffic is all signed by the private key of a trusted root certificate? 2: > Further, unlike the Kazakhstan certificate, those root certificates cannot bypas…

1: A server using HPKP with the reporting feature turned on will receive reports from browsers when the certificate does not match what was expected (provided HPKP is being honored).

2: Browsers ignore HPKP when the server certificate is trusted through a user or administrator installed root CA. All mainstream browsers on all platforms behave in this way. This is by design specifically to allow enterprises to do the sort of traffic interception that Kazakhstan is implementing. The rationale is that if an attacker is able to get as far as installing their own CA on your system, you're screwed anyway.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#162
post #151
post #72

Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…

As I know from my Kazakhstan-born friend, Twitter and LiveJournal are banned in Kazakhstan for years, nobody cares.

Both are available in Kazakhstan. I don't remember twitter being blocked here. LJ was blocked due to former high-profile official's blog.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#163
post #158

I think I found the law, anyone read Kazakh[1] or Russian[2]? [1] http://egov.kz/wps/poc?uri=mjnpa:document&language=kk&docume... [2] http://egov.kz/wps/poc?uri=mjnpa:document&language=ru&docume... Edit: I think I got them this time. They seem to be ministerial orders under Kazakhstan's 2004 telecoms law: In Kazakh: http://info-con.mid.gov.kz/sites/default/files/pages/2_kaz.d... http://info-con.mid.gov.kz/sites/defau…

There are zero "cert" mentions.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#164
post #110

Earlier quoted context omitted.

Or someone just forks Chromium and releases Chromium For Enterprise.

Which again helps nobody, because forks of Chromium will inevitably lag on security fixes.

At my last job, my manager tasked me with finding a way to defeat Chrome's update mechanism for all of our employees because a new version had introduced a bug that broke our internal web applications. I disregarded his plan and just introduced a workaround for the bug, but the point remains that enterprise customers already consider it a value-add to freeze their software in time for perpetuity. Hell, my workstation was running XP until I needled IT to grant me a "premature" upgrade to Win 7.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#165
post #125

Earlier quoted context omitted.

Google, Facebook, Yahoo, etc tried this in China and failed. It inconvenienced the people, but it's not going to cause a popular uprising. In the west, you forget that guns and the threat of raw violence by the government are a very real deterrent Kazakhstan isn't going to produce a Baidu, but I'm sure Yandex and VK would be happy to fill a void and play along with their rules. And in the end, people just have less a…

And BlackBerry tried in Pakistan and "succeeded" - at least in delaying the shutdown of its servers by another month. It's easier to do it in countries where "freedom" was the status quo and then the government decides to do something like that. China isn't exactly a free country to begin with, and the Great Firewall was older than Google in China.

Blackberry caved and gave the Saudi's and other gulf nation the ability to decrypt the traffic, as usual money plays a bigger role than morals. Not that morals played anything in the decision to begin with BB calculated that it would cost them more to cave than to resist in terms of because it could sway existing customers to switch away from their platform, that was true for Pakistan but since Saudi Arabia and the Gulf states have money it wasn't true in that case. And if you are implying that Kazakhstan was "free" to begin with that's utterly wrong, you are also wrong about China the "Great Firewall" didn't came online until 2003, and they still do not implement wide scale SSL MITM attacks (I've used Internet in China that wasn't a special line for foreigners or was routed through HK and many sites like wikipedia for example were blocked over HTTP but not over HTTPS). That said fighting such activity by boycotting only aggravates the situation as you are doing even more harm to the people of the country, it's bad enough being monitored 24/7 but at least you have access to information and people from all over the world.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#166
post #78
post #57

While there are probably 100 different ways to avoid this and retain secure traffic, I would venture to guess that the average Internet savvy-ness of Kazakhstan is pretty low, so using any of them would single you out for additional government attention (whether you're actually doing anything illegal or not). That said, there's a remarkable tendency in countries as corrupt as Kazakhstan for a "shadow" telecom network…

Kazakhstan is possibly more democratic than all its neighbours save maybe Kirghizstan (I'm not up do date on the current government position). More democratic as in I can't make up who's more of a despot between Putin and Nazarbayev, after all they both win open elections, albeit with an iron grip on medias... But then Kirghizstan is likely depending on its neighbours for connectivity (also landlocked). The other nei…

Russia is also corrupt enough (especially in the rural areas) that you could probably find an Internet connection that wasn't actively monitored by Moscow authorities. I'm not saying it would be cheap, but it's definitely doable.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#167
post #68

This sounds pretty bad and we can just hope that this doesn't become the new norm. What makes me kinda angry is however where this originates from: There are countless so-called "IT security" products that had this idea of MitM-ing all traffic before. Basically it's just the same idea on a bigger level.

Indeed. This is already the norm in the Western world, as long as we're talking about the workplace.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#169
post #164

Earlier quoted context omitted.

Which again helps nobody, because forks of Chromium will inevitably lag on security fixes.

At my last job, my manager tasked me with finding a way to defeat Chrome's update mechanism for all of our employees because a new version had introduced a bug that broke our internal web applications. I disregarded his plan and just introduced a workaround for the bug, but the point remains that enterprise customers already consider it a value-add to freeze their software in time for perpetuity. Hell, my workstation…

Sorry, I meant that from the perspective of the Chromium team.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#170
post #139

Why is Kazakhstan's cert any different than the hundreds of "trusted" root certificates that came preinstalled on my mac? Looking at my mac's cert keychain, there are 185 trusted root certs. I don't know what any of them are or who has the private key to them. My ISP could MITM my traffic whenever it wants to, if it has the private key of one of the hundreds of trusted root certs on my device.

These CAs have to follow specific rules and have external audit. MITM is prohibited by these rules: certificate authorities that participate or enable MITM are removed from root stores (example: https://en.wikipedia.org/wiki/DigiNotar ).

DigiNotar was used for MITM after getting hacked. If talking about CAs caught intentionally issuing intermediates for MITM purposes, we should at least mention TrustWave (SecureTrust CA): https://en.wikipedia.org/wiki/Trustwave_Holdings#Unrestricte...
Post reply on HN