Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

191–200 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#191
post #83

Woah, it can't be stressed how bad this is. If this succeeds, other countries will definitely follow! If it can be shown to work, it will be demanded that this be implemented by pretty much everyone for difficult to deny political reasons (terrorists, children, crime, etc) This feels like the first bullet in a new war that will occur in every parliament world wide.

I can't say that I agree with you. Kazakstan has never really been much of a leader in world politics.

Not following the politics; following the technological "innovation". "Appropriate technology" for "developing" dictatorships.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#192
post #145

Correct me if I'm wrong, but doesn't android display a rather ennerving "someone might be spying on you" warning when custom root certs are installed? I'm looking forward to the reactions when every (android-using) citizen of the country student gets that warning.

Why? They would have already installed the root cert themselves and they'd know perfectly well that they are being spied on. It'd just be another annoying warning bar for them.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#194
post #72

Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…

> The people of Kazakhstan can achieve the same outcome. Highly unlikely. From Wikipedia: In April 2015, Nazarbayev was re-elected with almost 98% of the vote. That kind of tells the whole story - people are "behind" this (or rather no-one dares contradict the authorities). That country is basically owned by the Family and resistance is pretty much futile.

Uh...that's not what I read into a 98% election result!

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#196
post #158

I think I found the law, anyone read Kazakh[1] or Russian[2]? [1] http://egov.kz/wps/poc?uri=mjnpa:document&language=kk&docume... [2] http://egov.kz/wps/poc?uri=mjnpa:document&language=ru&docume... Edit: I think I got them this time. They seem to be ministerial orders under Kazakhstan's 2004 telecoms law: In Kazakh: http://info-con.mid.gov.kz/sites/default/files/pages/2_kaz.d... http://info-con.mid.gov.kz/sites/defau…

Interesting. In 6_*.doc I can read this: "Long-distance and international operators perform transmission of traffic that uses protocols with encryption support using security certificate, except traffic encrypted by means of cryptographic protection on the territory of the Republic of Kazakhstan."

So, if encrypted by such means on the country's territory, shouldn't be intercepted? Ha!

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#197

Earlier quoted context omitted.

And sometimes the CAs might receive National Security Letters insisting on National Securtiy Certificates.

A National Security Letter will not prevent the certificate authority from being blacklisted when detected, and there are at least some legal precedents for warrants (though not necessarily for NSLs) that could challenge a warrant if complying with it would effectively destroy the business (given that the business itself is not the subject of the warrant). If that isn't the definition of an "unreasonable burden", not…

"A National Security Letter will not prevent the certificate authority from being blacklisted " Sure it will, just send another NSL to the blacklisting instance.

And I do not understand that going to jail instantly is a smaller burden for you than living with the small risk getting caught.

Do you really believe the NSA or any of those other patriots do not have a few of the private keys for the certificates you trust?

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#198
post #72

Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…

> The people of Kazakhstan can achieve the same outcome. Highly unlikely. From Wikipedia: In April 2015, Nazarbayev was re-elected with almost 98% of the vote. That kind of tells the whole story - people are "behind" this (or rather no-one dares contradict the authorities). That country is basically owned by the Family and resistance is pretty much futile.

You aren't the least bit suspicious about a 98% election result?

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#199
post #39

Earlier quoted context omitted.

I guess VPN is the only way to avoid it. Or sshuttle or something over port 80. But then again, how long will it take before they can detect that and then block it?! Or you can use non-standard ports, and change them continuously.

They can just block everything by default and only enable what they can decrypt. Maybe you could try tunelling encrypted data over HTTP, but heuristics could probably pick that up too.

Well, in that case I'm just going to invent a TCP-over-cat-pictures VPN. Encode all the TCP packets in the subtle details of the fur and package everything up as innocent-looking HTTP GET requests.

This realistically shouldn't be too hard to do with obfsproxy's already-built framework.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#200
post #83

Woah, it can't be stressed how bad this is. If this succeeds, other countries will definitely follow! If it can be shown to work, it will be demanded that this be implemented by pretty much everyone for difficult to deny political reasons (terrorists, children, crime, etc) This feels like the first bullet in a new war that will occur in every parliament world wide.

> If it can be shown to work

Work for who? This breaks SSL encryption, a technology which the modern internet relies on.

Post reply on HN