Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…
What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impac…
Kazakhstan to MitM all HTTPS traffic starting Jan 1
261–270 of 378 posts
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#262Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…
Well they could make using client certificates mandatory from Kazakhstanian ip addresses. Now the gov server can't connect and so can't MITM anything.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#263My first thought, any tech company to setup offices in this country are probably out the window. However, more importantly, they just made it really easy for other governments to spy on them. In their zeal to protect national security, they have done just the opposite.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#264http://www.wolframalpha.com/input/?i=number+of+internet+user...
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#265Wow, I feel really sorry for all Kzakhstan citizens. Also, this is a great example of 'rubber-hose cryptoanalysis' - who cares about 4096 RSA or whatnot if the government can just beat you until you oblige...
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#266Earlier quoted context omitted.
What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impac…
Certificate pinning does not work with certificates that are installed in the devices trusted certificate store.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#267Earlier quoted context omitted.
Certificate pinning does not work with certificates that are installed in the devices trusted certificate store.
You are confused. This is exactly what pinning defends against.
Chrome does not perform pin validation when the
certificate chain chains up to a private trust anchor.
A key result of this policy is that private trust
anchors can be used to proxy (or MITM) connections,
even to pinned sites.
-- https://www.chromium.org/Home/chromium-security/security-faq...Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#268Earlier quoted context omitted.
What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impac…
Certificate pinning does not work with certificates that are installed in the devices trusted certificate store.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#269Earlier quoted context omitted.
You are confused. This is exactly what pinning defends against.
Sorry, no: Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. -- https://www.chromium.org/Home/chromium-security/security-faq...
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#270Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…
- A life-long educational program for the people, starting with study of basic logic, rhetoric, and obscurantism. Consider collaborating with people trying to do the same in e.g. Russia.
- Joining the burgeoning autocratic bureaucracy and playing by its rules to bring change from within. If you don't feel like you have the energy or skills, consider supporting a like-minded, but more capable person in their career. It's never a crime to support a growing bureaucrat.
The biggest challenge you're going to face is defining a common idea to unite the people with whom you want to collaborate. "Like-minded" should mean something specific, or else. This idea should paint a picture compelling enough to motivate people to act, even if only a smallish number, and big enough to eclipse the lesser differences among the collaborators.
The only easy option is emigration.