Live data from Hacker News

Does the UK Think It Can Police the Internet?

theengineeringmanager.com

41–50 of 65 posts

Re: Does the UK Think It Can Police the Internet?

#41
post #9

Earlier quoted context omitted.

What censorship are they doing that cannot be easily circumvented?

For piracy sites they first blocked the dns, dumb easily circumvented use the ip. Then they blocked the ip, dumb easily circumvented spawn multiple versions. They made linking to pirate sites illegal so they could block alternative versions. They used to sniff all plaintext looking for tracker announces which look really distinctive. But their latest methods are scarily effective. They now do a man in the middle atta…

I've not seen any evidence of MITM attacks by ISPs since snowden.

Have there been any evidence of HTTPS and/or VPNs being MITM'd by UK ISPs?

Unless the UK government has cracked all the ciphers used by HTTPS + VPNs and have backdoored every CA, I think we'd already know about widespread systematic MITM attacks in UK users. If they have done all of that, then you can bet others have too then the whole world is screwed

Please cite your sources of actual evidence. Talking about mysterious black boxes doesn't count - they could be pollution sensors for all we know.

Re: Does the UK Think It Can Police the Internet?

#42
post #19

Earlier quoted context omitted.

> They now do a man in the middle attack to decrypt ssl, and store all of it, if you use openvpn as a proxy without accounting for this they own you. Is there any evidence of this?

Yes in 2012 GCHQ installed black boxes in every uk isp that all internet must be routed through[1]. While no one knows what these boxes do, it was thought that they decrypt https requests and log the request header, which seems to be confirmed by snowden[2]. In 2016 the investigatory powers act is what gives them the legal authority to do it[3]. They have never claimed they send fake ssl packets to drop the stream bu…

I thought the point of SSL was that a MITM couldn’t decrypt it? Unless they have the private key(s). (Or the ability to substitute their own keys, but that seems to get noticed fairly quickly and the relevant certificate authority gets rapidly shunned).

Re: Does the UK Think It Can Police the Internet?

#43
post #20

The lesson of Brexit is that all attempts at asking difficult questions like "how will this work" and "will it achieve the stated purpose" have been abandoned, and we're governed by pure short-term sloganeering. But the restriction of free speech in the UK in the name of anti-terrorism has a long history. I'm old enough to remember when the Sinn Fein MPs were prohibited from speaking on television: https://en.wikiped…

Gerry Adams didn't have the voice I'd expected after all those years. I had in my head more of an Irish Joe Pasquale.

It was pretty disappointing.

Re: Does the UK Think It Can Police the Internet?

#44

Earlier quoted context omitted.

Why they can't just implement the measures that seem to have worked in Scotland to address knife crime seems a mystery - NIH at a political level? https://www.bbc.co.uk/news/uk-scotland-45572691

Scotland? That's in the distant colonies to the north of Watford Gap isn't it? (And near me) As far as Westminster governments are concerned we don't exist, have good ideas or get infrastructure. Just somewhere to park nuclear things and fracking.

It's not only that you don't exist it's that doing what worked for you would require that these people London has been marginalizing since forever are right and their current approach is wrong. That's a non-starter.

Re: Does the UK Think It Can Police the Internet?

#45
post #29

Earlier quoted context omitted.

The most comical part was the words were still spoken by an actor trying to lip sync. Which made a mockery of the intent to deny terrorists the oxygen of publicity - in every news broadcast. They didn't think that one through too far. :) > asking difficult questions like "how will this work" and "will it achieve the stated purpose" I think that's been steadily dying since the mid and later Thatcher years, and acceler…

It is a good thing that it made thugs like Martin McGuinness and Gerry Adams look ridiculous as they attempted to represent themselves as peaceful politicians rather than the terrorists they actually were.

When it comes to groups like the IRA one man's terrorist is another man's freedom fighter. You necessarily need to act in a way that makes you a terrorist in the eyes of the government if you want to get your freedom.

Re: Does the UK Think It Can Police the Internet?

#46
post #24

Earlier quoted context omitted.

I'm in the UK with BT as my ISP. I've not had a problem accessing blocked sites.

Good to know, im on virgin and they block ip not dns.

So that sounds like a Virgin block and not a UK government one.

Re: Does the UK Think It Can Police the Internet?

#47
post #20

The lesson of Brexit is that all attempts at asking difficult questions like "how will this work" and "will it achieve the stated purpose" have been abandoned, and we're governed by pure short-term sloganeering. But the restriction of free speech in the UK in the name of anti-terrorism has a long history. I'm old enough to remember when the Sinn Fein MPs were prohibited from speaking on television: https://en.wikiped…

The most comical part was the words were still spoken by an actor trying to lip sync. Which made a mockery of the intent to deny terrorists the oxygen of publicity - in every news broadcast. They didn't think that one through too far. :) > asking difficult questions like "how will this work" and "will it achieve the stated purpose" I think that's been steadily dying since the mid and later Thatcher years, and acceler…

>The most comical part was the words were still spoken by an actor trying to lip sync.

As brilliantly parodied by The Day Today:

https://www.youtube.com/watch?v=w6UhXivPyw4

Re: Does the UK Think It Can Police the Internet?

#48
post #42

Earlier quoted context omitted.

Yes in 2012 GCHQ installed black boxes in every uk isp that all internet must be routed through[1]. While no one knows what these boxes do, it was thought that they decrypt https requests and log the request header, which seems to be confirmed by snowden[2]. In 2016 the investigatory powers act is what gives them the legal authority to do it[3]. They have never claimed they send fake ssl packets to drop the stream bu…

I thought the point of SSL was that a MITM couldn’t decrypt it? Unless they have the private key(s). (Or the ability to substitute their own keys, but that seems to get noticed fairly quickly and the relevant certificate authority gets rapidly shunned).

Yea but as you point out SSL is only as safe as the public key infrastructure it runs on. Backwards compatibilty is also an issue, afaik default setups below tls 1.2 can be degraded to the point where its only ~70bit encryption which can be broken by state actors.

I was told they have intermediate keys for certificate authorities(probably done legally with the ca permission), generate a new key signed with the real intermediate. This would be detectable as the cert fingerprint would be different from the legit legit one, while SSH checks for this by default SSL does not.

I have tried to detect the above and as far as I can tell they are not doing it, but I believe the people I heard more than I believe my ability to detect it.

Re: Does the UK Think It Can Police the Internet?

#50
post #29

Earlier quoted context omitted.

It is a good thing that it made thugs like Martin McGuinness and Gerry Adams look ridiculous as they attempted to represent themselves as peaceful politicians rather than the terrorists they actually were.

When it comes to groups like the IRA one man's terrorist is another man's freedom fighter. You necessarily need to act in a way that makes you a terrorist in the eyes of the government if you want to get your freedom.

No. The people who murdered innocent families in pubs and on busy shopping streets are terrorists. Are you really saying that the murder of hundreds of British civilians was a price worth paying?
Post reply on HN