Kazakhstan to MitM all HTTPS traffic starting Jan 1
311–320 of 378 posts
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#312Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…
Raise awareness, spread the word about Tor. If they start running attacks against Tor, start an uproar. And pitch Tor as an elementary security measure; say "do this to make your communications more secure." It isn't perfect, but maybe it's better than nothing?
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#313Earlier quoted context omitted.
the ddos was achieved by altering the contents of one of the script on a large chinese site (was it baidu? google it). Once every user on that site loaded the tampered script, it made sure to send many requests to github.
Was the large Chinese site serving traffic over HTTPS?
To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#314Earlier quoted context omitted.
Steganography needs vast quantities of cover data. You're increasing the bandwidth costs dramatically when you recommend steganography for everything.
Steganography needs vast quantities of cover data. Porn? Perhaps the world's smut peddlers will become beacons of freedom and civil disobedience? (Sounds like a Neal Stephenson book.)
The worst thing — they just ban sites without any explanation. Site just stopped to work and you don't know why. Even w3.org was banned for some time (probably because its validator could be used as web proxy).
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#315wait till private keys for the cert are leaked by some disgruntled telecom company employee.. Puts the whole country internet at risk.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#316Earlier quoted context omitted.
Was the large Chinese site serving traffic over HTTPS?
Sadly, they (Baidu) are not, which is why the script content was easily modified. To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#317Earlier quoted context omitted.
Down-right demand? With what authority? It sounds like you're confusing these corporations for governments, as if they had to enforce your human rights..
The authority of the free market. Did web PKI develop because of governments? No. In fact, quite the contrary. Similarly, if consumers are educated and aware of the weaknesses of current cryptography controls in light of new threats such as governments requiring the installation of their own root CA so they can middle the connection, maybe they'll drive demand for better controls, controls which already exist.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#318Earlier quoted context omitted.
Was the large Chinese site serving traffic over HTTPS?
Sadly, they (Baidu) are not, which is why the script content was easily modified. To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#319Earlier quoted context omitted.
Sorry, no: Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. -- https://www.chromium.org/Home/chromium-security/security-faq...
How would the telco get their Private Trust Anchor into the certificate store ? More social engineering, i suppose. At the app level though, a chain resolution like what you describe is not required.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#320I really appreciate how they're doing this. The Chinese built up an amazing infrastructure for the Great Firewall; the Kazakhs just say "install our cert!" The Chinese spend billions and have to stay ahead of all of their citizens' clever new ideas at all times; the Kazakhs spend a few hundred and just need to point guns at their citizens until they install a cert. Sure, it's going to be difficult to enforce, but it…