Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

281–290 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#281
post #263

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

But effectively that is the case. If major providers like AWS and Google ban domain fronting, it is effectively dead - nobody needs domain fronting when you have three domains, three domains can be banned the same way as one. AWS and Google could throw their considerable weight on the side of anti-censorship and openness. They instead chose - as businesses frequently do - to play along with oppressive dictatorial reg…

Russia had no problem whatsoever blocking both Amazon and Google when it was blocking Telegram a couple weeks ago. What makes you think this would be any different? In other words, why is Signal being able to operate more important than all of the other people who pay AWS and Google for services?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#282
post #76

Earlier quoted context omitted.

I can imagine why someone cares if someone else pretend being that someone....

No, the trick works the other way around; they pretend they want to talk to someone, but then talk to someone else. They never pretend to be someone else.

Right. Even so, don't you see problem in that too? Pretending doing one but in fact doing other?

Just imagine using that for a non noble cause....

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#283

Earlier quoted context omitted.

> The cause is noble The cause is noble, but the mechanism is dubious: it can be viewed as, in effect, saying to oppressive regimes “to harm me, you must harm a bunch of innocent bystanders, too”.

That's the entire point of domain fronting and collateral freedom: to make censorship as expensive as possible for oppresive regimes.

But Signal was doing all of this without Amazon's consent. I don't care how noble you think your cause is, dragging other people into your fight against their will is wrong, full stop.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#284

Earlier quoted context omitted.

> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…

Exactly, free countries (or those who consider themselves as such) should make it fully illegal for private companies to aid in any kind of censorship in behalf of oppressive countries. But what we see in reality is the opposite, all companies trying to make it as cheap and as simple as possible to censor anything every government dislikes; meaning the liberal fantasy of allowing every private company to do as it ple…

> all companies trying to make it as cheap and as simple as possible to censor anything every government dislikes

Not sure what you mean, I didn't see Napster fighting for censorship nor Craigslist fighting for FOSTA.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#285

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

I agree. The intent is noble, but this headline makes Amazon look like the bad guy for disapproving unauthorized use of one of their domains, which is quite reasonable.

Because they are the bad guy.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#286

Earlier quoted context omitted.

> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…

Exactly, free countries (or those who consider themselves as such) should make it fully illegal for private companies to aid in any kind of censorship in behalf of oppressive countries. But what we see in reality is the opposite, all companies trying to make it as cheap and as simple as possible to censor anything every government dislikes; meaning the liberal fantasy of allowing every private company to do as it ple…

As you note, private companies are typically free to do as they please in free countries...that's kinda the point. You have no right to use AWS, so this is not censorship in the legal sense. And free governments also tend to have strong laws respecting the sovereignty of other nations, whether or not their laws are similar. Your frustration is noble, but it's also internally inconsistent.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#287
post #79

Earlier quoted context omitted.

You think oppressive regimes don't already realize what they are? They simply don't care.

They would care if there are financial consequences. https://en.wikipedia.org/wiki/Collateral_freedom

Why should Amazon be dragged into Signal's fight without their consent?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#288

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

> They're spoofing identity

This doesn't seem quite accurate to me. They are not making an assertion that they ARE Amazon or Cloudfront. They are avoiding making an assertion that they are anybody, by using a shared facility. It's a bit like using a public payphone to avoid being identified. When you use a public payphone, presumably the call originates from a line owned by the phone company, but nobody accuses you of attempting to impersonate the telephone company by doing that.

This may still be a violation of the TOS, but people should be clear about the actual intent of what is being done.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#289
post #166

Earlier quoted context omitted.

But he got thousands of people censored. I hope he's happy.

This is not useful. The great thing about domain fronting when e.g. Google semi-officially supported it is that it is a non-secret technique which leverages the unique status of a large-scale technical operation that the citizenry demands access to. It allows the citizenry of an oppressive state to engage in collective action via the machinery of global capitalism. Google and Amazon should not only be supporting this…

More evil than cutting off all the other users of other services that chose to host with AWS/Google? Cause that's what happened when Russia banned Telegram, and Russia didn't show any problem with doing it again.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#290
post #116

Couldn't they ask people to donate their AWS instances or a portion of their webserver (or domain) resources to running a small outward facing webserver as a dummy, making the domain look like its a real website (eCommerce etc) and then passing Signal data through a Shadowsocks (or something similar) proxy? Couldn't they develop an AMI that they hold the keys to that people could deploy with ease?

Those who wish to suppress Signal would just play whack-a-mole. They'd login to Signal, find what domains it was connecting to and then block those. To update Signal with new addresses constantly, you'd need a server hosting those updates- which would in turn be blocked immediately. The idea of using Souq.com or Google.com as the domain name in the TLS header was that even oppressive regimes won't block Google or Sou…

>The idea of using Souq.com or Google.com as the domain name in the TLS header was that even oppressive regimes won't block Google or Souq for their entire country.

Which, at least in the case of Russia, seems to be false.

Post reply on HN