They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…
> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…
Amazon threatens to suspend Signal's AWS account over censorship circumvention
211–220 of 519 posts
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#212Earlier quoted context omitted.
They say it doesn't solve the problem - "Would adding federation to Signal help with users behind country-wide blocks? Seems like a distributed service would be harder to censor than a centralized one." - "It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. Only the users of that software wo…
It sounds like a hard thing, but in case of XMPP "rebuilding your social graph again" is very easy - it's just a matter of importing your roster and sending authorization requests where needed. Could be, and probably already is, easily automated with some user friendly tool.
If the more straightforward solution (VPN) isn't a panacea for censorship, then federation isn't either.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#213Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#214They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…
>You can't use TLS and load balancing hacks to pretend to be us in oppresive countries They're not pretending to be Amazon, they're pretending to initiate a connection to an Amazon domain. The "conversation" goes like so: Clear text request: "Hello, I would like to speak TLS with souq.com" Clear text response: "Why yes, let us do that with these parameters" Encrypted request: "Please give me the page for signal.org/a…
For the record, I'm of the opinion that the US should insist that American companies not help dictators abroad in their censorship efforts. But it's hardly unreasonable for Amazon to say, "this type of stuff is illegal in Egypt. We don't want any trouble, so please stop using us as a means of circumventing Egyptian law."
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#215Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#216They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…
Since the plain text has the fake address while the encryption has the true address, I see no issue with this.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#217Earlier quoted context omitted.
It sounds like a hard thing, but in case of XMPP "rebuilding your social graph again" is very easy - it's just a matter of importing your roster and sending authorization requests where needed. Could be, and probably already is, easily automated with some user friendly tool.
If the solution to censorship is to constantly switch to new hosts, it would be even easier to do this via a VPN (which wouldn't require you to rebuild your social graph at all, unlike a federated endpoint switch). If the more straightforward solution (VPN) isn't a panacea for censorship, then federation isn't either.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#218Earlier quoted context omitted.
What does "innocent" mean in this context? You seem to be using the word to distinguish between people who use the app and other people who don't, but that can't be right. Is it unethical to use a communications app?
> What does "innocent" mean in this context? Innocent of whatever violation if local law the regime is targeting the app for.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#219Earlier quoted context omitted.
There is no fiduciary duty to shareholders of a public company. This is known as the shareholder value myth -- myth because it is false.
Yeah if this were the case the private jet market would crater.
Further, the fiduciary myth is silly as a premise upon any inspection: legally who gets to decide what's the one right ideal path for optimizing shareholder value, such that if you don't follow The One True Path then you're failing shareholders. Any other path than the single best one, would be inherently defined as failing the fiduciary responsibility to maximize shareholder value (which is another way of saying: legally it's an impossible concept to implement; and logically it's stupid, it falls down instantly, no person could know the maximization path at all times). It doesn't pass even a minute of rational intellectual scrutiny.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#220I really dislike the way they put it in the title of this post. What they are doing is simply abusing the name/size of a totally unrelated company to mask signal traffic. While I am totally in favor of signal, simply using a domain name you dont own in the SNI header just because it is terminated at the same service as you want to use is something you cannot do. They could have simply have sent the question to the ow…
Why not out of curiosity? I'm not disputing Amazon's right to disallow this (it's their service after all), but before that I don't see any objective reason why this is something they they "cannot" or even "should not" do. Also, unless Amazon put in a technical barrier (which they are in the process of doing), then they can't stop a third party from doing it anyway (i.e. me personally sending a different domain in the SNI header than the one I actually end up communicating with), and on that level (ie me rather than Amazon's customer) I see no reason why I wouldn't do exactly that if my ISP was blocking the target domain.