Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

81–90 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#81

Well, this is what happens when countless startups go to a couple of web hosters in the name of outsourcing unsexy stuff like racking and stacking servers.

That's a real problem, but I don't think it's related to this situation. We have to assume that censors can inspect apps, and can inspect some app traffic before it gets encrypted. This means that they'll know all about your servers and their IP addresses.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#82

The title is a bit clickbaity. It makes complete sense why Amazon will not be happy with domain fronting. Side note, Not sure what the point of [Redacted] is as it's trivial to get name from > General Manager, Amazon CloudFront

To focus the attention on the role rather than the person, who is clearly just representing the company. It softens it.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#83
post #73
post #59

I'm thinking of a legislative, not technological solution to this, which seems to be pretty straightforward: make it unlawful for US companies to refuse service simply for Domain fronting. That way, none of the big companies could lawfully refuse service to Signal; neither could they be faulted by these other regimes for "letting Signal use their domain".

No, the solution is to solve the technical problem of leaking metadata during the TLS handshake. Should it also be unlawful to refuse service to someone who pretends to be you when they resell your widgets to the mob because they fear retaliation if the mob isn't happy with the goods?

[deleted]

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#85

Their AWS wasn't threatened, only their ability to use CloudFront. We will immediately suspend your use of CloudFront if you use third party domains without their permission to masquerade as that third party.

Please don’t use code formatting for quotes, it makes the content unreadable on mobile

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#86

Earlier quoted context omitted.

If they were self-hosted, it would be even easier for Iran to block them.

If they hosted on VMs they would simply hop from one place to the other. The problem is that all of this stuff is "difficult" and no one would be writing stories about how great signal is if it could switch between thousands of companies that provide VMs to masses. We do not have these thousands of companies because AWS/GCS/Azure are the go to. Well, guess what? That means that objectively there are three kings of th…

Iran is probably sophisticated enough to make some DNS queries...

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#89
post #66

It seems centralized solutions (Telegram, Signal) are under fire recently. I wonder what would happen if federated protocols (Matrix, XMPP, etc.) were more popular and, thus, also in spotlight.

They say it doesn't solve the problem - "Would adding federation to Signal help with users behind country-wide blocks? Seems like a distributed service would be harder to censor than a centralized one." - "It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. Only the users of that software wo…

I think it may depend on how well distributed would a service be: having several big servers would not help but if every family and company had their own mini server, located in a non-censoring country then the censors would be unable to do anything easily. These servers, in turn, would be able to easily connect to the broader network. Of course that wouldn't be as easy to setup as a simple installation of the Signal app.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#90

Earlier quoted context omitted.

If they were self-hosted, it would be even easier for Iran to block them.

If they hosted on VMs they would simply hop from one place to the other. The problem is that all of this stuff is "difficult" and no one would be writing stories about how great signal is if it could switch between thousands of companies that provide VMs to masses. We do not have these thousands of companies because AWS/GCS/Azure are the go to. Well, guess what? That means that objectively there are three kings of th…

Egypt and Iran block their domain, so they would have no method of directing users to the current IP.
Post reply on HN