Earlier quoted context omitted.
> My assumption is that because wikipedia has a known plaintext and a known link graph it's plausible to identify pages with some accuracy At least in theory, the latest versions of TLS should not be vulnerable to a known plaintext attack. TLS also is capable of length-padding, which would reduce the attack surface here as well for an eavesdropper. My understanding is that HTTP/2 makes it even more difficult to const…
> In practice, governments will probably just MITM the connection If they routinely MITM connections they will quickly be found out, and the CA would be removed from browsers.
Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
101–110 of 126 posts
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#102Earlier quoted context omitted.
> TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, Or in other words it is vulnerable. China can (and probably does) issue a certificate that all Chinese browsers must install, they can then do MITM https using their certificate to sign the new versions. Companies do this routinely BTW. Since it's their equipment, it's considered just fine. (But be aware of it if y…
do you have any examples of China issuing a certificate that all browsers trust? I've never seen or heard of this (at least across all browsers), so I find this unlikely.
https://en.greatfire.org/blog/2014/oct/china-collecting-appl...
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#103Earlier quoted context omitted.
> In practice, governments will probably just MITM the connection If they routinely MITM connections they will quickly be found out, and the CA would be removed from browsers.
Except China has their own browser made by a state controlled company that a lot of people use. This browser is already demonstrated to accept the government CA and ordinary people in China don't care.
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#104Earlier quoted context omitted.
wut? everyone in China already use Baike instead of Wikipedia, nobody really understand why they are making another website
To compare Chinese Wikipedia has 940,000 articles, baike has 6 million articles.
With 6x the articles on baike I can't imagine that there is that level of quality control. Unless there are 6x as many things worth documenting in China vs rest of the world.
An interesting statistic none-the-less.
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#105Can an expert comment on side-channel attacks on HTTPS and whether they're less viable on HTTP/2? My assumption is that because wikipedia has a known plaintext and a known link graph it's plausible to identify pages with some accuracy and either block them or monitor who's reading what. I also assume that the traffic profile of editing looks different from viewing.
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#106Earlier quoted context omitted.
To compare Chinese Wikipedia has 940,000 articles, baike has 6 million articles.
Wikipedia editors are pretty strict about what gets to remain a page. Everyone knows they delete articles unless it has lots of sources and public interest. With 6x the articles on baike I can't imagine that there is that level of quality control. Unless there are 6x as many things worth documenting in China vs rest of the world. An interesting statistic none-the-less.
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#107Earlier quoted context omitted.
As well as forge an SSL certificate for *.wikipedia.org. Last time I checked, Wikipedia had HSTS enabled. So trying to forge their DNS without also forging their SSL certificate would be equivalent to total censorship for anybody who has previously visited Wikipedia.
Assuming the government in question has access to a root certificate this should be possible.
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#108Earlier quoted context omitted.
wut? everyone in China already use Baike instead of Wikipedia, nobody really understand why they are making another website
To compare Chinese Wikipedia has 940,000 articles, baike has 6 million articles.
Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#109Re: Wikipedia’s Switch to HTTPS Has Successfully Fought Government Censorship
#110Can an expert comment on side-channel attacks on HTTPS and whether they're less viable on HTTP/2? My assumption is that because wikipedia has a known plaintext and a known link graph it's plausible to identify pages with some accuracy and either block them or monitor who's reading what. I also assume that the traffic profile of editing looks different from viewing.
The government could force pc manufacturers to deploy a root CA that they control and then do a MITM proxy to read everything the user is doing, they could also redirect wikipedia domain to another domain that just acts as a reverse proxy and deploy a legit cert on that other site