They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…
But effectively that is the case. If major providers like AWS and Google ban domain fronting, it is effectively dead - nobody needs domain fronting when you have three domains, three domains can be banned the same way as one. AWS and Google could throw their considerable weight on the side of anti-censorship and openness. They instead chose - as businesses frequently do - to play along with oppressive dictatorial reg…
Amazon threatens to suspend Signal's AWS account over censorship circumvention
281–290 of 519 posts
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#282Earlier quoted context omitted.
I can imagine why someone cares if someone else pretend being that someone....
No, the trick works the other way around; they pretend they want to talk to someone, but then talk to someone else. They never pretend to be someone else.
Just imagine using that for a non noble cause....
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#283Earlier quoted context omitted.
> The cause is noble The cause is noble, but the mechanism is dubious: it can be viewed as, in effect, saying to oppressive regimes “to harm me, you must harm a bunch of innocent bystanders, too”.
That's the entire point of domain fronting and collateral freedom: to make censorship as expensive as possible for oppresive regimes.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#284Earlier quoted context omitted.
> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…
Exactly, free countries (or those who consider themselves as such) should make it fully illegal for private companies to aid in any kind of censorship in behalf of oppressive countries. But what we see in reality is the opposite, all companies trying to make it as cheap and as simple as possible to censor anything every government dislikes; meaning the liberal fantasy of allowing every private company to do as it ple…
Not sure what you mean, I didn't see Napster fighting for censorship nor Craigslist fighting for FOSTA.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#285They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…
I agree. The intent is noble, but this headline makes Amazon look like the bad guy for disapproving unauthorized use of one of their domains, which is quite reasonable.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#286Earlier quoted context omitted.
> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…
Exactly, free countries (or those who consider themselves as such) should make it fully illegal for private companies to aid in any kind of censorship in behalf of oppressive countries. But what we see in reality is the opposite, all companies trying to make it as cheap and as simple as possible to censor anything every government dislikes; meaning the liberal fantasy of allowing every private company to do as it ple…
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#287Earlier quoted context omitted.
You think oppressive regimes don't already realize what they are? They simply don't care.
They would care if there are financial consequences. https://en.wikipedia.org/wiki/Collateral_freedom
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#288They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…
This doesn't seem quite accurate to me. They are not making an assertion that they ARE Amazon or Cloudfront. They are avoiding making an assertion that they are anybody, by using a shared facility. It's a bit like using a public payphone to avoid being identified. When you use a public payphone, presumably the call originates from a line owned by the phone company, but nobody accuses you of attempting to impersonate the telephone company by doing that.
This may still be a violation of the TOS, but people should be clear about the actual intent of what is being done.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#289Earlier quoted context omitted.
But he got thousands of people censored. I hope he's happy.
This is not useful. The great thing about domain fronting when e.g. Google semi-officially supported it is that it is a non-secret technique which leverages the unique status of a large-scale technical operation that the citizenry demands access to. It allows the citizenry of an oppressive state to engage in collective action via the machinery of global capitalism. Google and Amazon should not only be supporting this…
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#290Couldn't they ask people to donate their AWS instances or a portion of their webserver (or domain) resources to running a small outward facing webserver as a dummy, making the domain look like its a real website (eCommerce etc) and then passing Signal data through a Shadowsocks (or something similar) proxy? Couldn't they develop an AMI that they hold the keys to that people could deploy with ease?
Those who wish to suppress Signal would just play whack-a-mole. They'd login to Signal, find what domains it was connecting to and then block those. To update Signal with new addresses constantly, you'd need a server hosting those updates- which would in turn be blocked immediately. The idea of using Souq.com or Google.com as the domain name in the TLS header was that even oppressive regimes won't block Google or Sou…
Which, at least in the case of Russia, seems to be false.