Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

461–470 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#461

Earlier quoted context omitted.

> For the record, U.S. politicians have voted on sanctions on Russia Indeed, the US nearly destroyed Russia's largest aluminum company - Rusal - recently in a sanctions move against an oligarch close to Putin (Oleg Deripaska, who owns the majority of Rusal). The best way to deal with oppressive regimes, is generally to go through powerful political bodies/groups, whether the UN, G7, or US Congress. The impact a compa…

> oligarch close to Putin (Oleg Deripaska ...) For the record, Deripaska is no friend of Putin, who forced him to start paying tax and stay out of politics. Look at how Putin humiliated him several years ago during an industrial dispute, when Putin took the side of workers against Deripaska. [0] - https://www.youtube.com/watch?v=0XfbWnDXCx8

For the record -- OF COURSE he's a friend/loyal to Putin, because in the Russian state all of the oligarchs owe fealty to the leader.

Look to Mikhail Khodorkovsky to see what happens to those that aren't Putin's friends.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#462

Earlier quoted context omitted.

The ethical choice is for AWS and Google to collude and both allow signal to continue to using domain fronting.

Russia had no problem whatsoever blocking both of them when blocking Tether a couple weeks ago.

No problem? They crippled their own use of the internet, at huge financial cost.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#463

Earlier quoted context omitted.

I don't know, was it moral for IBM to work with the Nazis to build their concentration camp databases? (yes, this happened) I mean, that made the shareholders money, right?

They sold them mechanical calculators (?) IIRC. "Databases" is maybe not the right word? Not a historian.

It was their punchcard technology, which is more akin to databases than calculators.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#464

Earlier quoted context omitted.

Then it's even worse, because the picture you're trying to paint implies that it's either leave guerillas alone, or nuke the entire city . A ban of a cloud service affects everything else that depends on it. The more popular a service, the more damage. That's the point of "collateral freedom". (Note the name of the term. It's no accident. It comes from "collateral damage".)

Block the road, not nuke the city. But if they were going to nuke the city? Fuck them, don't negotiate, it is absolutely not the fault of any group that is merely located somewhere inside the city.

I feel we're talking past each other because of a spatial analogy.

My point is - by employing domain fronting against censorship, you bet that the adversary will not ban the service you're using as a front. But they very well might just do that. At this point, everyone else using the service suffers. So that service, by refusing to be used as a domain front, is not just protecting its own interest - it's protecting interests of all the others who depend on it. You, on the other hand, are unilaterally putting those other people at risk. This does not make you a hero, it makes you a villain (even if a lesser one).

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#465

Earlier quoted context omitted.

Amazon servers are an entire city. There is a vast gulf between the equivalent of "being in a city that has a hospital" and the equivalent of "locating a base inside a hospital".

Then it's even worse, because the picture you're trying to paint implies that it's either leave guerillas alone, or nuke the entire city . A ban of a cloud service affects everything else that depends on it. The more popular a service, the more damage. That's the point of "collateral freedom". (Note the name of the term. It's no accident. It comes from "collateral damage".)

The mistake here is that they are not guerrillas and are not hurting anyone. It's censors that do. It's collateral damage only from the point of view of censors.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#466

Earlier quoted context omitted.

Block the road, not nuke the city. But if they were going to nuke the city? Fuck them, don't negotiate, it is absolutely not the fault of any group that is merely located somewhere inside the city.

I feel we're talking past each other because of a spatial analogy. My point is - by employing domain fronting against censorship, you bet that the adversary will not ban the service you're using as a front. But they very well might just do that. At this point, everyone else using the service suffers. So that service, by refusing to be used as a domain front, is not just protecting its own interest - it's protecting i…

"Putting them at risk" not by doing anything to them, but by being near them.

The domain fronting could be set up in a way that doesn't spoof domains, and the risks would be exactly the same. The spoofing is a red herring. The issue is the mere idea that a censor would be unable to tell what domain a connection is for. The actual thing that puts people at risk is ridiculous to attack on a moral basis. It's the same as just existing in a crowd. Not grabbing someone to be your shield.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#467

Earlier quoted context omitted.

So AWS finally lost enough money to the Russian blockade that they caved. Sad.

Russian economy is very very small. Whatever Amazon's reason is it's not that they lost some Russian banks for a week.

The same technique is being used to prevent censorship in a host of countries, like UAE, that have giant piles of cash and influence, and where blocking AWS/Google would have unacceptable consequences. No one gives a damn about a few Russians.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#468

Earlier quoted context omitted.

I feel we're talking past each other because of a spatial analogy. My point is - by employing domain fronting against censorship, you bet that the adversary will not ban the service you're using as a front. But they very well might just do that. At this point, everyone else using the service suffers. So that service, by refusing to be used as a domain front, is not just protecting its own interest - it's protecting i…

"Putting them at risk" not by doing anything to them, but by being near them. The domain fronting could be set up in a way that doesn't spoof domains, and the risks would be exactly the same. The spoofing is a red herring. The issue is the mere idea that a censor would be unable to tell what domain a connection is for. The actual thing that puts people at risk is ridiculous to attack on a moral basis. It's the same a…

In other words it's Amazon and Google who are willingly help censors to avoid a bit of collateral damage during strikes.

It's like helping Assad to find targets where people with opposing views live.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#469

Earlier quoted context omitted.

Are you? It looks like the Amazon load balancers don't actually care what your SNI domain is when routing traffic. They terminate your TLS connection, and then use the domain in your actual HTTP request to route it, which is not Amazon's domain. Amazon's ability to allow these two domains to differ, and to mostly ignore the former, is the crux of this whole trick.

Does this mean that Cloudfront does not actually require (correct) SNI? Example: Sending HTTP request for signal.org over TLS to Cloudfront IP address with SNI as "allergan.com" returns signal.org web page, not allergan.com web page.

Yes, this is the premise of domain fronting.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#470

Kinda a misleading headline. Amazon is stating the don't want their domain name used as a circumvention measure. I think that's reasonable. Signal is the one hijacking it and Amazon is taking the risk if it gets blocked.

No, the fact that Amazon owns the souq.com domain is irrelevant here.
Post reply on HN