Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

481–490 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#481
post #241

Earlier quoted context omitted.

It is perfectly understandable why Amazon did that and siding with oppressive regimes is of course not unreasonable at all. Just unethical, hence the discussion.

Amazon isn’t nesessarily against censorship. They just don’t want to provide this sort of spoofing service. Regardless of whether the spoofers are good or bad.

I believe this is the fundamental issue, from Amazons PoV: this altruistic project with nice goals is abusing a network nuance, but most other actors using this capability are likely to be bad actors.

I don't think Amazons reasoning was "oh, lets help dictators dictate", but more "hey, isn't this a potential security hole ripe for abuse that would make us look incompetent?".

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#482

Earlier quoted context omitted.

Am I missing something, or is anyone using a CDN domain fronting?

An HTTPS connection sends the domain it wants to connect to in two layers: first unencrypted in the TLS headers, then encrypted in the HTTP header. In a regular connection (even using a CDN), those two will match. Using domain fronting, you put a popular domain in the unencrypted part, and the real domain in a encrypted HTTP header. Due to how they're implemented, the load balancers at Google and Amazon will ignore t…

> only a custom app like Signal can perform domain fronting.

Or curl, or openssl s_client. I'm still trying to understand domain fronting, and exactly what is being disallowed now. Do all of my CDN requests have to have identical Host headers and TLS server name indicators now? What if they're mismatched? Does the TLS handshake still succeed, and the traffic just doesn't get passed through the CDN server?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#483

Earlier quoted context omitted.

That would mean that Amazon was supplying Signals content as authentic Souq traffic, something that I doubt was happening.

Amazon was supplying Signal's content as souq.com but with the request making it clear it was for Signal. How might this be noticeable? Like so: - (irrelevant) the SNI and certificate presented by the server don't match the request -- only the hoster can see this, so what might they care? - (serious) metering: if the hoster uses SNI for metering... then Signal would be stealing the fronter's bandwidth - (mild) DNS me…

2 is hypothetical as none of the fronts are doing this, and even if a front "could" that doesn't matter as the fronts in question do not. We can agree that if this was happening then it would be an issue.

3 seems just wrong. Where does the DNS lookup take place? Why would the fronting server look up the SNI entry?

Are you 100% confirming that the encryption takes place using Souq's cert? Obviously it isn't going to display in a browser, but I'd wonder if there was something else you could do with it.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#484

Earlier quoted context omitted.

My first thought is "How is it in the interest of Amazon's stockholders to prevent censorship in countries ruled by dictatorial regimes?" and secondly, "How does consenting to being a front for services that are strictly forbidden in certain countries benefit our company?"

This an abhorrent chain of logic. By this rationale everything should be permissible if it’s profitable and legal in the country it’s done in. Ethics be damned. Slavery?[1] Fine. Assisting with genocide?[2] Ok. Human trafficking. Sure, as long as we’re making money. Now consider the likes of Facebook or Google. If Iran wanted to purge an ethnic minority from their country and offered a government contract to Facebook…

[deleted]

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#485

I feel like Amazon has a moral obligation to name the country that is forcing them to do this under penalty of having their entire IP block black-holed. I assume Amazon would not take this step unless that was going to happen otherwise, or at least I don't see why they would. They don't need to make a political statement about it, just say they did it to comply with law / order of 'X'. Russia

Why wouldn't they do this on their own? Keeping their reputation good with all countries(even the oppressive one's) is an important part of business. After all, amazon has stakeholders to answer to.

I don't see how it hurts their reputation to allow Signal to anonymize. They could even block domain fronting in general to block bad actors, and quietly whitelist Signal.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#486

Earlier quoted context omitted.

To put it bluntly: fuck the shareholders. The question being asked shouldn't be "are the capital owners getting paid", but "is this company improving lives and delivering benefit". It's after all, what they're here for, not just to make money. No matter how much money I can make selling heroin, they're not gonna let me because, you guessed it, I'm doing damage by doing it.

What about countless of other, not censored, services delivered from the same network? Do they not "improve lives" and "deliver benefit"? Collateral freedom is akin to placing your guerilla command center in a hospital, in a gamble that the other side will leave you alone instead of risking extra harm to innocent civilians. In this case, the hospital decided to disallow guerillas to use it as cover.

This.

People don't realize doing stuff like this is just going to make lives worse once these regimes block Amazon/Google/whatever.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#488

"Unfortunately, a TLS handshake fully exposes the target hostname in plaintext, since the hostname is included in the SNI header in the clear. This remains the case even in TLS 1.3, and it gives a censor all they need." Does this mean that endpoints that require SNI are potentially contributing to censorship? Facts: SNI is optional. Not all websites require it. For example, https://signal.org does not require SNI; cl…

s/send/& correct/

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#489

Earlier quoted context omitted.

Why wouldn't they do this on their own? Keeping their reputation good with all countries(even the oppressive one's) is an important part of business. After all, amazon has stakeholders to answer to.

I don't see how it hurts their reputation to allow Signal to anonymize. They could even block domain fronting in general to block bad actors, and quietly whitelist Signal.

It's not about anonymizing, it's about hiding under the mask of some other entity, without their(other entity's) permission. AWS's other customers and various governments won't be happy about aws allowing Signal to do so.

While they could white list Signal, I don't see why they would want to go through this trouble. It's not like any of these public companies care any more about supporting people under oppressive rules, than profit.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#490

Earlier quoted context omitted.

You're not wrong, it would certainly not be in shareholder's financial interest for amazon to take this stance. For the record, U.S. politicians have voted on sanctions on Russia for cyber crimes and brought representatives to the UN raising the issue of their human rights records.

> For the record, U.S. politicians have voted on sanctions on Russia Indeed, the US nearly destroyed Russia's largest aluminum company - Rusal - recently in a sanctions move against an oligarch close to Putin (Oleg Deripaska, who owns the majority of Rusal). The best way to deal with oppressive regimes, is generally to go through powerful political bodies/groups, whether the UN, G7, or US Congress. The impact a compa…

Actually, this has changed:

"On April 23, however, the US government gave Rusal's American customers "more time to comply with sanctions", even saying it would "consider lifting them if United Company Rusal Plc’s major shareholder, Russian tycoon Oleg Deripaska, ceded control of the company." Department of the Treasury gave these clients until October 23, 2018 to comply with (wind down business) the Rusal sanctions."

https://www.reuters.com/article/us-usa-russia-sanctions-rusa...

Post reply on HN