Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

211–220 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#211

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…

Exactly, free countries (or those who consider themselves as such) should make it fully illegal for private companies to aid in any kind of censorship in behalf of oppressive countries. But what we see in reality is the opposite, all companies trying to make it as cheap and as simple as possible to censor anything every government dislikes; meaning the liberal fantasy of allowing every private company to do as it pleases is not going to cut it in a world where every important event you can't find in Google for all practical matters never happened.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#212
post #66

Earlier quoted context omitted.

They say it doesn't solve the problem - "Would adding federation to Signal help with users behind country-wide blocks? Seems like a distributed service would be harder to censor than a centralized one." - "It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. Only the users of that software wo…

It sounds like a hard thing, but in case of XMPP "rebuilding your social graph again" is very easy - it's just a matter of importing your roster and sending authorization requests where needed. Could be, and probably already is, easily automated with some user friendly tool.

If the solution to censorship is to constantly switch to new hosts, it would be even easier to do this via a VPN (which wouldn't require you to rebuild your social graph at all, unlike a federated endpoint switch).

If the more straightforward solution (VPN) isn't a panacea for censorship, then federation isn't either.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#214
post #157

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

>You can't use TLS and load balancing hacks to pretend to be us in oppresive countries They're not pretending to be Amazon, they're pretending to initiate a connection to an Amazon domain. The "conversation" goes like so: Clear text request: "Hello, I would like to speak TLS with souq.com" Clear text response: "Why yes, let us do that with these parameters" Encrypted request: "Please give me the page for signal.org/a…

They may not be impersonating Amazon, but they are using Amazon's services to circumvent the intent of policies (laws) that Amazon wants to comply with. Amazon has decided to stop be an unwitting participant in this particular mechanism of circumventing oppression.

For the record, I'm of the opinion that the US should insist that American companies not help dictators abroad in their censorship efforts. But it's hardly unreasonable for Amazon to say, "this type of stuff is illegal in Egypt. We don't want any trouble, so please stop using us as a means of circumventing Egyptian law."

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#216

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

Real work example would be a re-mailer. Outside of the envelope shows one address it goes to but inside where others cannot look actually has the true address?

Since the plain text has the fake address while the encryption has the true address, I see no issue with this.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#217
post #212

Earlier quoted context omitted.

It sounds like a hard thing, but in case of XMPP "rebuilding your social graph again" is very easy - it's just a matter of importing your roster and sending authorization requests where needed. Could be, and probably already is, easily automated with some user friendly tool.

If the solution to censorship is to constantly switch to new hosts, it would be even easier to do this via a VPN (which wouldn't require you to rebuild your social graph at all, unlike a federated endpoint switch). If the more straightforward solution (VPN) isn't a panacea for censorship, then federation isn't either.

Of course it's not a "panacea". It just makes some situations easier to handle, including server operator going rogue or broken by government. It doesn't magically provide answer to everything, but it's definitely an improvement when compared to purely centralized networks.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#218

Earlier quoted context omitted.

What does "innocent" mean in this context? You seem to be using the word to distinguish between people who use the app and other people who don't, but that can't be right. Is it unethical to use a communications app?

> What does "innocent" mean in this context? Innocent of whatever violation if local law the regime is targeting the app for.

It would be a very particular sort of autocratic state, which could censor communications apps on a blanket basis, but would have to go through some sort of charade with laws and courts for each particular app. Still, the app and its users are different parties.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#219

Earlier quoted context omitted.

There is no fiduciary duty to shareholders of a public company. This is known as the shareholder value myth -- myth because it is false.

Yeah if this were the case the private jet market would crater.

Berkshire Hathaway could have never existed if it were actually a legal requirement. For decades they've constantly passed on doing things that could have easily juiced shareholder value, including hostile actions in regards to takeovers. It's why nearly all of their acquisitions come to them instead: an extraordinary reputation.

Further, the fiduciary myth is silly as a premise upon any inspection: legally who gets to decide what's the one right ideal path for optimizing shareholder value, such that if you don't follow The One True Path then you're failing shareholders. Any other path than the single best one, would be inherently defined as failing the fiduciary responsibility to maximize shareholder value (which is another way of saying: legally it's an impossible concept to implement; and logically it's stupid, it falls down instantly, no person could know the maximization path at all times). It doesn't pass even a minute of rational intellectual scrutiny.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#220

I really dislike the way they put it in the title of this post. What they are doing is simply abusing the name/size of a totally unrelated company to mask signal traffic. While I am totally in favor of signal, simply using a domain name you dont own in the SNI header just because it is terminated at the same service as you want to use is something you cannot do. They could have simply have sent the question to the ow…

> simply using a domain name you dont own in the SNI header just because it is terminated at the same service as you want to use is something you cannot do

Why not out of curiosity? I'm not disputing Amazon's right to disallow this (it's their service after all), but before that I don't see any objective reason why this is something they they "cannot" or even "should not" do. Also, unless Amazon put in a technical barrier (which they are in the process of doing), then they can't stop a third party from doing it anyway (i.e. me personally sending a different domain in the SNI header than the one I actually end up communicating with), and on that level (ie me rather than Amazon's customer) I see no reason why I wouldn't do exactly that if my ISP was blocking the target domain.

Post reply on HN