Live data from Hacker News

Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

motherboard.vice.com

41–50 of 126 posts

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#41
post #32
post #20

Earlier quoted context omitted.

No, TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, or b) the attacker successfully forges the certificate of the website you are trying to visit. That is, assuming you don't click away your browser's security warning. https://security.stackexchange.com/questions/8145/does-https...

> TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, Or in other words it is vulnerable. China can (and probably does) issue a certificate that all Chinese browsers must install, they can then do MITM https using their certificate to sign the new versions. Companies do this routinely BTW. Since it's their equipment, it's considered just fine. (But be aware of it if y…

do you have any examples of China issuing a certificate that all browsers trust?

I've never seen or heard of this (at least across all browsers), so I find this unlikely.

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#42

Can an expert comment on side-channel attacks on HTTPS and whether they're less viable on HTTP/2? My assumption is that because wikipedia has a known plaintext and a known link graph it's plausible to identify pages with some accuracy and either block them or monitor who's reading what. I also assume that the traffic profile of editing looks different from viewing.

And one thing to note is that people generally don't randomly pad the length of articles, so it's not _very_ difficult to figure out what articles you might be reading -- even over TLS.

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#43
post #30

Earlier quoted context omitted.

Yes, I understand that. I mean, why don't these censors block the whole wikipedia.org access then? If they don't want their population to access a Wikipedia topic/article and can't block/determine if someone is accessing it, the easiest thing to do would be just block it right away. So why they won't do it? (PS: I'm in no way in favor of censorship, I'm just trying to understand such mindset)

If you censor too much people may be pissed. It's much easier to decide "we censor specific articles about specific subjects" than "we censor all of wikipedia". Censoring a popular mainstream webpage may cause too much opposition. Maybe even the politicians who make the decision and their families like to look up things on wikipedia.

But can't they just download the Wikipedia backup, purge the articles they don't like, and redirect the DNS lookup to a local copy?

To the average citizen, it won't look much different than going to actual Wikipedia.

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#44
post #30

Earlier quoted context omitted.

If you censor too much people may be pissed. It's much easier to decide "we censor specific articles about specific subjects" than "we censor all of wikipedia". Censoring a popular mainstream webpage may cause too much opposition. Maybe even the politicians who make the decision and their families like to look up things on wikipedia.

But can't they just download the Wikipedia backup, purge the articles they don't like, and redirect the DNS lookup to a local copy? To the average citizen, it won't look much different than going to actual Wikipedia.

This is feasible, assuming the government is willing to pay for the hosting.

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#45
post #30

Earlier quoted context omitted.

Yes, I understand that. I mean, why don't these censors block the whole wikipedia.org access then? If they don't want their population to access a Wikipedia topic/article and can't block/determine if someone is accessing it, the easiest thing to do would be just block it right away. So why they won't do it? (PS: I'm in no way in favor of censorship, I'm just trying to understand such mindset)

If you censor too much people may be pissed. It's much easier to decide "we censor specific articles about specific subjects" than "we censor all of wikipedia". Censoring a popular mainstream webpage may cause too much opposition. Maybe even the politicians who make the decision and their families like to look up things on wikipedia.

Then https will force them to either extreme which I think is a good thing. No option to slowly raise the temperature so the frogs won't jump out of the pot.

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#46

Earlier quoted context omitted.

If a censor can't tell which specific parts of wikipedia someone is trying to access, then they will be more likely to simply block the entire site. HTTPS encrypts the URL and the content, but does not mask the DNS lookup nor the server being connected to.

Yes, I understand that. I mean, why don't these censors block the whole wikipedia.org access then? If they don't want their population to access a Wikipedia topic/article and can't block/determine if someone is accessing it, the easiest thing to do would be just block it right away. So why they won't do it? (PS: I'm in no way in favor of censorship, I'm just trying to understand such mindset)

They are currently creating a Wikipedia clone in China so I'm guessing they are allowing wikipedia only on a temporary basis.

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#49
post #41
post #32

Earlier quoted context omitted.

> TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, Or in other words it is vulnerable. China can (and probably does) issue a certificate that all Chinese browsers must install, they can then do MITM https using their certificate to sign the new versions. Companies do this routinely BTW. Since it's their equipment, it's considered just fine. (But be aware of it if y…

do you have any examples of China issuing a certificate that all browsers trust? I've never seen or heard of this (at least across all browsers), so I find this unlikely.

https://security.googleblog.com/2015/03/maintaining-digital-...

"On Friday, March 20th, we became aware of unauthorized digital certificates for several Google domains. The certificates were issued by an intermediate certificate authority apparently held by a company called MCS Holdings. This intermediate certificate was issued by CNNIC."

Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship

#50
post #22
post #20

Earlier quoted context omitted.

No, TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, or b) the attacker successfully forges the certificate of the website you are trying to visit. That is, assuming you don't click away your browser's security warning. https://security.stackexchange.com/questions/8145/does-https...

It isn't but if you live in China and want to use the internet, you'll likely be forced to use a proxy that MITMs and serves its own certificate....My point is that TLS is not a solution to prevent government interference when the user has to rely on the government infrastructure for access.

This is not how the great firewall works, check the facts known, not just baseless speculatation.
Post reply on HN