Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

151–160 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#151
post #118

Earlier quoted context omitted.

An aspiring censor could also "easily connect to the broader network" and masquerade as a federated server in order to discover others. This process could even be automated. Federated services also require an identifier, and this identifier usually indicates where the user's account is located and how to connect with them (e.g. user@domain.com). As people share these identifiers, the aspiring censor can just keep add…

At least in case of XMPP, the client doesn't need to be able to connect to other domains, so as long as you can connect to your own server outside of the censorship's reach (which could be accessible for c2s connections in a completely different way than for s2s), you should be fine.

How do you ensure the censor doesn't block the major c2s connections? I suspect most techniques are too technical for your average user.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#152

Earlier quoted context omitted.

I'm guessing you haven't spent much time looking into how oppressive regimes work. They aren't going "to realize that they are being an oppressive regime" and have an epiphany where they realize, "Hey maybe I'm an evil dictator?" If you are up for reading, I highly recommend Michael Malice's book, Dear Reader: The Unauthorized Autobiography of Kim Jong Il . After reading that you will completely understand why "see h…

> After reading that you will completely understand why "see how long it is until they protest or move" is a silly thing to say. I wonder if you could give TL;DR on this, assuming there is something else than the basic prisoner's dilemma going on?

I'd be happy to give a very brief TL;DR with the disclaimer that I recommend either the book for a full picture or the Michael Malice interview on Joe Rogan's podcast (WARNING: NSFW language) [1]

There are a few factors involved (and please bear in mind I'm leaving out a lot of detail here, and this is nowhere near a comprehensive list).

1. There is extensive "brainwashing" regarding the great leader. He is praised for everything. There's a famous story about a western optometrist that performs surgery routine every where else in the world, but rare in N Korea that restores eye sight. The first thing people often do after receiving their sight is not thank the doctor, but to praise a poster of the great leader, thanking him for restoring their sight (I think this was a Nat Geo thing but I don't remember exactly).

2. There is a culture of tattling that heavily incentivizes ratting out your friends and family to the authorities. You will be punished for even having unclean thoughts, let alone taking bad actions. The pervasiveness of this makes it such that people often self-report themselves for thought crimes due to feelings of guilt or concern over getting turned in by friends/family (you may do less time in the prison camp for self-reporting).

3. Families are harshly punished for actions taken by their family members. This means that if you escape, your family will be likely killed or sent to prison camp. If you die in camp, your son/daughter/father/mother will have to take your place to finish your sentence. Thus even suicide/death in prison camp is a betrayal of your family. There is no way out.

[1] https://www.youtube.com/watch?v=5B_idqiEoUE

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#153

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

Morally, it's still the right thing to do, even though I guess it's in amazon's best interests not to allow it.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#154

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

> The cause is noble

The cause is noble, but the mechanism is dubious: it can be viewed as, in effect, saying to oppressive regimes “to harm me, you must harm a bunch of innocent bystanders, too”.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#155
post #59

I'm thinking of a legislative, not technological solution to this, which seems to be pretty straightforward: make it unlawful for US companies to refuse service simply for Domain fronting. That way, none of the big companies could lawfully refuse service to Signal; neither could they be faulted by these other regimes for "letting Signal use their domain".

Couldn't the service providers simply counter by offering Domain fronting as a premium feature at $1M/GB transferred? Or are we going to over-legislate service providers to essentially place them under government control when they refuse service to a given customer out of rational self interest?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#156

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

> The cause is noble The cause is noble, but the mechanism is dubious: it can be viewed as, in effect, saying to oppressive regimes “to harm me, you must harm a bunch of innocent bystanders, too”.

[deleted]

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#157

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

>You can't use TLS and load balancing hacks to pretend to be us in oppresive countries

They're not pretending to be Amazon, they're pretending to initiate a connection to an Amazon domain. The "conversation" goes like so:

Clear text request: "Hello, I would like to speak TLS with souq.com"

Clear text response: "Why yes, let us do that with these parameters"

Encrypted request: "Please give me the page for signal.org/api/whatever"

etc...

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#158

Sorry, I'm not on board with using an Amazon owned domain for this. That's got the potential to get Amazon itself blacklisted in some places, so they're absolutely not going to be okay with it.

Or it forces oppressive regimes to realize that they are being an oppressive regime. Want to censor the internet, fine, send your citizens back to the dark ages; see how long it is until they protest or move.

What country are you from and how old are you? I find it incredible anyone could be so naive about how oppressive organizations operate.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#159

Earlier quoted context omitted.

At least in case of XMPP, the client doesn't need to be able to connect to other domains, so as long as you can connect to your own server outside of the censorship's reach (which could be accessible for c2s connections in a completely different way than for s2s), you should be fine.

How do you ensure the censor doesn't block the major c2s connections? I suspect most techniques are too technical for your average user.

Modern clients can connect via port 443. There is also support for XMPP via WebSockets, that looks like regular HTTPS traffic.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#160
post #131

This is nothing to do with censorship. AWS has many clients and does not want its network to be blocked because of a single customer. Tough for Signal but that's how it is when dealing with businesses (especially one that so many others rely on). The same thing just happened with Telegram in Russia which explains the preemptive messages: https://arstechnica.com/information-technology/2018/04/in-ef...

The loss of domain fronting as a viable strategy means that it will be possible to censor Signal in areas where the service was previously working.

It's a warning to not break terms of service. The strategy still works, but it's against TOS of most hosts so it was never really viable.

Time to look for another option then, like any other technical challenge. I support Signal's work here but unfortunately we can't just enlist every other business to help (otherwise censorship wouldn't be much of a problem in the first place).

Post reply on HN