Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

171–180 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#172

Does it mean that using SSL the normal way will become impossible? I can't imagine this. How this can be enforced?

1) The only TLS connections that are let through are all MITM'd.

2) Every other TCP/UDP flow is checked for conformance with plain-text protocols (like HTTP), or far worse, simply for the level of entropy in the data.

3) A threat of legal action is made against anyone caught using secure crypto.

Good luck beating that. The key here is that the "entropy detector" doesn't "really" need to work. It only needs to work well enough to scare people into submission.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#173

If we could rebuild the internet from scratch knowing that someone would try to do this, what measures could be put in place to make it impossible to MITM traffic (in other words, make it so the only option is to install monitoring software directly on the user's machine)? Is this something which even can be defeated with current cryptographic theory?

It's not only can be done in theory, it's already implemented in both TOR and I2P. You can't MITM traffic when it's encrypted end2end.

Issue is that cryptography won't help when there is some government that decide to enforce censorship country-wide.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#174
post #164

Earlier quoted context omitted.

At my last job, my manager tasked me with finding a way to defeat Chrome's update mechanism for all of our employees because a new version had introduced a bug that broke our internal web applications. I disregarded his plan and just introduced a workaround for the bug, but the point remains that enterprise customers already consider it a value-add to freeze their software in time for perpetuity. Hell, my workstation…

Sorry, I meant that from the perspective of the Chromium team.

Indeed, I agree with the policy that if someone can control what's installed locally, they've already won.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#175
post #128
post #60

Earlier quoted context omitted.

Pretty sure that Netflix loads a Flash client (or some other trusted code module) to prevent this. But you're right; the browser isn't secure enough to enable client-side encryption over HTTP as it would be trivial to MITM and sideload JS code to defeat it.

That's the problem with "client-side encryption". It doesn't work because the provider also has the power to replace the code with no say from you. And it's not very detectible because they do it all the time.

It’s the same reason why any DRM is completely pointless: It only provides inconvenience for the legitimate user.

I own Anno 2070 (as can be seen on my steam profile), but can only play with RELOADED crack under wine because UPlay refuses to run.

Same with this type of encryption: Kazahstan can easily defeat it, but it makes it harder for people trying to debug why they can’t use Netflix (for example, in case that Kazahstan MitM's everything, and encrypts with a different certificate than your Netflix client is using).

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#176

Earlier quoted context omitted.

Kazakhstan is not the US. We are highly unlikely to see a public uprising in Kazakhstan over this when the country has had the same president since 1991 and rubber-stamp parliament. Protests in 2011 were quelled by gunning down protestors (see below). Nazarbayev, re-elected in a barely contested election to a fifth term on Sunday, was born to a peasant family. He trained as an engineer before rising through the ranks…

There was no public uprising after Snowden in the US either ... Some will now say you can't compare this. They are right because what Kazakhstan is doing there looks amateurish.

For a while, I've been in the camp that the Snowden leaks were intentional and that he still works for the US. A rich work from home government contractor, with a smoking hot girlfriend, takes off with secrets and hides in Russia. His hot girlfriend is even allowed to join him.

I think it's more likely the Snowden leaks were to show just how little Americans care. They're using that spy network to track reactions.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#177
post #39

Earlier quoted context omitted.

I guess VPN is the only way to avoid it. Or sshuttle or something over port 80. But then again, how long will it take before they can detect that and then block it?! Or you can use non-standard ports, and change them continuously.

They can just block everything by default and only enable what they can decrypt. Maybe you could try tunelling encrypted data over HTTP, but heuristics could probably pick that up too.

If I had the free time, I'd create a cryptographic protocol running on top of telnet that looked like someone playing a MUD.

For email, you'd encrypt data to have it look like regular prose. So you'd only get a few bits per English word, but that would be sufficient for short messages. Could also make use of extra spaces in between words.

The real trick with that would be to take an existing document, and alter it to encode a message. So you'd be doing things like using synonym choice to get your bits.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#178
post #72

Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…

It's unlikely that the Kazakh government would be able to do that much with it. Kazakhstan has a population of about 18M and internet penetration of about 35% if they would really want to sift through all that traffic they are more than welcome to do so, just keep in mind that even the US would probably not be able to do so with any degree of effectiveness. The only thing that Google et al. could do is refuse to prov…

How is China doing the same?

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#179

Earlier quoted context omitted.

> The people of Kazakhstan can achieve the same outcome. Highly unlikely. From Wikipedia: In April 2015, Nazarbayev was re-elected with almost 98% of the vote. That kind of tells the whole story - people are "behind" this (or rather no-one dares contradict the authorities). That country is basically owned by the Family and resistance is pretty much futile.

In other words: it doesn't matter who is voting, what matters is who is counting the votes.

Given the highly volatile ethnic mix of Kazakhstan and the lurking destabilizing effect of foreign interests longing for abundant mineral resources, a strong majority for stability over freedom is hardly surprising. Nonetheless, 98% seems very much out of this world. But with the "right" mix of fearmongering and early divide-and-conquer intervention when a moderate opposition ist starting to organize? Certainly not unthinkable. There's so much more to a healthy democracy than not miscounting the votes.
Post reply on HN