Earlier quoted context omitted.
Capitulating to foreign censors for business reasons has something to do with censorship.
Amazon has a ton of customers, at least a few of which like https://preemptivelove.org/ are also doing good things in these countries. It's not just Amazon that suffers, but Amazon's customers and everyone else downstream.
Amazon threatens to suspend Signal's AWS account over censorship circumvention
411–420 of 519 posts
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#412Earlier quoted context omitted.
They would care if there are financial consequences. https://en.wikipedia.org/wiki/Collateral_freedom
One of the common characteristics of an oppressive regime is that they already suffer financial consequences for their actions; sanctions, overseas account seizures, trade embargoes. Hoping that they'll throw their hands in the air and give-up instead of blocking AWS etc is naive. The people making the decision don't suffer the consequences as do their subjects.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#413Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#414Earlier quoted context omitted.
Yes. It's called war. What's confusing here? If a citizen of a nation thinks that another nation is not behaving as they would like (whichever country or whatever behavior that is), the proper channels to enact change are through government action, either diplomatic or militarized. Asking a private corporation to be international police is not good for anyone, as well intentioned as it may seem.
Military (or state in general) may have other, softer and more covert means of influencing other countries besides war, like “persuading” home corporations to act on their behalf. Thats not unheard of nowadays
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#415Can someone explain how does one serve content on a domain they don't own, like in this case Souq.com? Do they shove their content to something like product reviews or what? EDIT: I realized they use souqcdn.com. Does this mean it works because their clients use "souqcdn.com" to resolve to CloudFront CDN's IP address and then they craft a different Host header (like "Host: api.signal.org"). Also how can they possibly…
This is a recent technique for censorship circumvention called "domain fronting." See https://en.wikipedia.org/wiki/Domain_fronting for details. Essentially when implementing encrypted channels with TLS, the domain name is still clear text in the SNI field, making the censorship circumvention scheme vulnerable to deep packet inspection. The technique is to modify the SNI field in TLS traffic to innocent domains. Majo…
Something which could have been fixed on TLS 1.3, but didn't happen. Very unfortunately.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#416Earlier quoted context omitted.
That doesn't make sense. Lots of places think in terms of dollars, in fact the West/capitalism is all about it, and yet we don't have the same issues.
You are literally posting on an article where Signal's attempt to aid people speaking out against authoritarian regimes are being quelled by entities due to protecting their bottom line.
What does that have to do with other nations and their laws? The censoring issue here is in a foreign state and not caused by capitalism but a lack of it. AWS is not international police so you should focus on government if you want to see political changes.
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#417Earlier quoted context omitted.
I wonder if that means AWS, Google, etc oppose measures like encrypted SNI, since it's more likely to get their entire IP range banned by authoritarian governments.
They are more likely to oppose encrypted SNI on the grounds it's not really possible. How do you encrypt SNI for cold start? For a future connection, I could see how, but at that point you may as well simply do a resumption.
... is the current state of work on this problem.
It's true that encryption (within the desirable parameters discussed in that ID) costs us a round trip, but it might be worth it for most of us most of the time.
Keep in mind the TLS you're using today for most sites has 2RTT setup, and we put up with that (if you have a modern browser and go to some major sites you end up using TLS 1.3 draft 23 and thus 1RTT)
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#418I feel like Amazon has a moral obligation to name the country that is forcing them to do this under penalty of having their entire IP block black-holed. I assume Amazon would not take this step unless that was going to happen otherwise, or at least I don't see why they would. They don't need to make a political statement about it, just say they did it to comply with law / order of 'X'. Russia
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#419Earlier quoted context omitted.
My first thought is "How is it in the interest of Amazon's stockholders to prevent censorship in countries ruled by dictatorial regimes?" and secondly, "How does consenting to being a front for services that are strictly forbidden in certain countries benefit our company?"
Shareholders still come first if they do the right thing here. Letting reputable people do good with your product rises the tide for the ecosystem. Good for the Internet is good for AWS.
Isn't it begging the question to parent's point?
Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention
#420Earlier quoted context omitted.
> simply using a domain name you dont own in the SNI header just because it is terminated at the same service as you want to use is something you cannot do Why not out of curiosity? I'm not disputing Amazon's right to disallow this (it's their service after all), but before that I don't see any objective reason why this is something they they "cannot" or even "should not" do. Also, unless Amazon put in a technical ba…
> Why not out of curiosity? Because you are lying about what domain you want to access. This is against the TOS, and simply something you should not do. I know it helps signal to get around censorship and blocks, and it's technically working, but one should not do that.
The only ones getting spoofed are the censors.