Earlier quoted context omitted.
Chinese govt is also capable of doing this. Best part? We even have our trusted* root certificate! Could this get any "better"? Sure! We can even MITM all the OUTGOING https traffic if we want! #GitHubDDoS * Recently un-trusted by Apple and Mozilla. https://support.apple.com/en-us/HT204938
Was that trusted root cert ever misused? IIRC, it was un-trusted because they did not do their due diligence on how an issued sub-cert was being used by an Egyptian company. What does the GitHub DDOS have to do with MITM attacks on https?
Kazakhstan to MitM all HTTPS traffic starting Jan 1
281–290 of 378 posts
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#282Earlier quoted context omitted.
The same way that Stuxnet destroying Iranian centrifuges was an act of war ?
Yes. Although I'd have thought that particular war would have started back with the hostage-taking in, what, 1979? I really don't understand relationships between States.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#283Earlier quoted context omitted.
> most people wouldn't understand the full implication So attack that. Tell a story. What does this allow the government to do? Could a jealous ex-lover who works for the government read their ex's messages? Could the local mayor find out if you've got a medical problem? Get an illustrator to draw these up as little comics. Make images that people can understand. This is a great example: http://www.wordstream.com/ima…
Thanks. That's a solid idea.
http://files.wcitleaks.org/public/WCIT12%20-%20ITRs%20and%20...
Check out the fifth to last page, which is basically identical to what I created, if presented a bit worse. Did anyone give a shit? Nope.
Is that a genuine logo of the fucking ITU, the international body probably most obliged to prevent this kind of shit globally, and was this put together by a "senior staff member of the ITU" rather than /u/quink on reddit? Yup.
Did anything of that presentation make it to the media or public discussion? Nope. Meanwhile, my PNG has been posted here on HN 6 years after I first created it.
Let me know if you need my help, but I'm not at all sure how to best broadcast that message. Keeping away the MITM (who is here employed by an "elected" government with executive powers and "judicial oversight" acting "in the interest of public security" rather than a bogeyman or a corporation) is harder than protecting the ability to consume. Maybe the answer lies in making people afraid for their money.
Anyone with access to the private key for the certificate, which includes anyone with access to the multitude of servers that relay traffic for the entire country, could technically drain everyone's bank accounts and give away your shares at their discretion, if you've ever used online banking or trading in Kazakhstan. A single bad memory or whatever bug in some software somewhere and the number that's the private key is in the open.
In all honesty, make investors and bankers afraid and any government will shut up. As for ordinary lives of people, PRISM has shown us that they don't really care about this security stuff.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#284Earlier quoted context omitted.
How would the telco get their Private Trust Anchor into the certificate store ? More social engineering, i suppose. At the app level though, a chain resolution like what you describe is not required.
I'll give you a hint: they run customs.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#285I really appreciate how they're doing this. The Chinese built up an amazing infrastructure for the Great Firewall; the Kazakhs just say "install our cert!" The Chinese spend billions and have to stay ahead of all of their citizens' clever new ideas at all times; the Kazakhs spend a few hundred and just need to point guns at their citizens until they install a cert. Sure, it's going to be difficult to enforce, but it…
> it's going to be difficult to enforce I guess it's just a matter of dropping every connection that you can't MITM, no?
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#286It is a very cheap and effective way to achieve this.
Spying on the population is not prevented by GeoTrust and Cie's loosy certificates, a lot of literature and real life examples already show that. This is a tragedy of the commons, until everybody has access to REAL security, then no country has interest in having foreign powers spying them while not even being to do what everybody else does.
In France, Germany, Italy, Japan, Korea, Australia, etc, all of your data is already analyzed and deciphered, they freaking work together to make it less obvious than Kazakhstan. Don't make any mistake and don't call for overthrowing the regime there, it makes no sense.
From a citizen PoV, they became almost as watched over as we are for WWW traffic, but their lives are still not as much tracked as ours since they do not have the means of our agencies. They are still better off than us.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#287Earlier quoted context omitted.
You're going to run out of cat pictures pretty quickly.
I've been thinking about this lately, and it seems that you could use something like a book code. Client and server use existing internet accessible images as the book and then your communication simply references bytes in those images: client requests a URL that encodes the bytes it wants to send, server returns HTML containing the urls of images containing the bytes it wants to send in response (and any extra conte…
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#288Earlier quoted context omitted.
You're going to run out of cat pictures pretty quickly.
I've been thinking about this lately, and it seems that you could use something like a book code. Client and server use existing internet accessible images as the book and then your communication simply references bytes in those images: client requests a URL that encodes the bytes it wants to send, server returns HTML containing the urls of images containing the bytes it wants to send in response (and any extra conte…
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#289"telecom.kz wants to use your location." NOPE
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#290Google should come up with cheap satellite internet. This is the only way to bypass unruly governments. But then you're on a mercy of Google Republic.