Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

241–250 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#241
post #199

Earlier quoted context omitted.

Well, in that case I'm just going to invent a TCP-over-cat-pictures VPN. Encode all the TCP packets in the subtle details of the fur and package everything up as innocent-looking HTTP GET requests. This realistically shouldn't be too hard to do with obfsproxy's already-built framework.

You're going to run out of cat pictures pretty quickly.

Just drop fresh meme text on 'em and Bob's your uncle!

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#242
post #224

Could this be used by the Kazakh government to sign malware/spying packages and install them on their citizens' machines? Sounds like a super easy way to open that backdoor. Or is this a different type of cert? I'm thinking along the lines of what Dell and Lenovo were yelled at for (although those were easy to rip off, but the government could possibly serve as the malicious actor here).

Only if the cert also has code signing EKU. Then, in case of code signing trust bit not disabled in the cert manager, signed EXEs will appear with "verified publisher".

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#244

Earlier quoted context omitted.

> Sure it will, just send another NSL to the blacklisting instance. Instances, plural, including both browsers and various cross-check mechanisms (pinning, certificate transparency, etc). Likely too many people required for operational security. Not saying it couldn't be done, but it certainly couldn't be done lightly or often, and even then it would produce significant risk of exposure. It certainly couldn't be effe…

warrant/subpoena != NSL

Yes, as I said in my original response, "not necessarily for NSLs".

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#245
post #213

Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…

>Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness?

Revolution or leaving the country are your only choices. There is no democracy so there is probably no way to resolve this grievance, and I doubt it would be anywhere near the top of list for most citizens.

You can speak english and probably have computer skills, so I hope it would be possible for you to get out.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#246

Earlier quoted context omitted.

Kazakhstan is not the US. We are highly unlikely to see a public uprising in Kazakhstan over this when the country has had the same president since 1991 and rubber-stamp parliament. Protests in 2011 were quelled by gunning down protestors (see below). Nazarbayev, re-elected in a barely contested election to a fifth term on Sunday, was born to a peasant family. He trained as an engineer before rising through the ranks…

There was no public uprising after Snowden in the US either ... Some will now say you can't compare this. They are right because what Kazakhstan is doing there looks amateurish.

Yes, because an overwhelming majority of Americans dislike Snowden. Not a slim majority, an overwhelming one. http://www.usnews.com/news/articles/2015/04/21/edward-snowde...

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#248
post #36

Earlier quoted context omitted.

That would make people in the US feel better, but it wouldn't make any difference. If a country can force residents to install software or reconfigure their machines, there's nothing browser vendors can do to make those residents secure. Essentially, Kazakhstan owns (in both senses) the Internet-connected computers of all its residents, and it can do whatever it wants with them. It's also well within Kazakhstan's bud…

Can you name some examples of what they can do? Because other than release some sort of virus, which will be found in a matter of months, I don't think they can infect the entire country.

They can target more specifically than that. Suspected activists get a keylogger bundled in their next windows update. Later on another update removes all traces of it. It might take decades before something like that was noticed.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#249
post #80
post #72

Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…

What should these companies responses be? And why should the kazach goverment care? They'd prefer if the poeple used russian (or kazach) copy cats like vkontakte anyway.

Simple. Immediately implement certificate pinning so that rogue CA's can't be used to MitM their application traffic. That should have happened long ago for these apps anyway. This will break those apps and the government, in the face of everything breaking for their citizens might re-think their plan and at a minimum, turn of TLS middling for the impacted domains.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#250
post #213

Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…

What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impact to citizens who will then hopefully wake up and pressure the government to roll-back the program or at least put exceptions in place. You continue this strategy with banks, etc., until it becomes clear to the government that this plan will not work. Note that cert pinning for mobile and desktop apps should have happened long ago & this might be the perfect opportunity to drive it to happen.
Post reply on HN