Would someone with network access in Kazakhstan check if Caddy's MITM detector catches this please? https://caddyserver.com/docs/mitm-detection - or https://mitm.watch (Cloudflare's unofficial deployment of the same tech). If it does not, could you file a bug report with a complete packet capture (and exact browser version - multiple browsers are preferred)? https://github.com/caddyserver/caddy/issues (Edit: Reported…
So uh, should I be concerned at all if my connection came back as a likely MITM from my home network in the US? Or is it most likely a false positive caused by my firewall or something? I tested it both off a VPN and on a VPN from my iPhone yet still had the same result both times.
MITM on HTTPS traffic in Kazakhstan
111–120 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#112Does such a certificate compromise non-browser traffic as well? Like SSH tunnels, mobile apps, Telegram etc.
Re: MITM on HTTPS traffic in Kazakhstan
#113They should just put a red dot on the browser bar somewhere indicating a non-normal root cert is being used (this would also help in dev / test scenarios).
This would be fantastic. Also, it would be great if there were a "red dot" style warning when you manually click "Proceed anyway" while viewing a https page with an invalid certificate (currently, the browser remembers the "Proceed anyway" decision and accepts the invalid cert after the initial acceptance of the warning)
Re: MITM on HTTPS traffic in Kazakhstan
#114> This will save privacy of all Internet users in Kazakhstan.
No. This will mean that users would simply switch to chrome, edge, brave, ... , n + 1.
In case all of them block this CA, the government will force people to install an older version or will patch any open source browser so that it works with their certificates.
IMO, this is also wrong from a philosophical point of view. Your browser should just be your browser and not take part in political disputes. It doesn't sit well with me that Firefox has anything to say in the politics of its users.
And finally, encryption doesn't solve violence.
Re: MITM on HTTPS traffic in Kazakhstan
#115I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…
But we are in a better place than before. Without HTTPS everywhere and governments needing to ask people to install new root certs, we would not have learned about this Kazakhstan MITM issue.
Re: MITM on HTTPS traffic in Kazakhstan
#116Earlier quoted context omitted.
We don’t want users to trust the green check, because it never meant you could trust a site. We do want users to distrust plaintext, because it means the café you’re visiting can steal your password. I don’t see how this is a good criticism of the push for HTTPS everywhere (which appears to be the context here).
because cafe can just ask people 'install this extension to navigate' and non-tech users being users will fall for it most of the time, because state actor can do even worse, and once we trained the users that non green check is dangerous they won't have the knowledge to distinguish between "insecure with no check" and "maybe secure with check but I've to control every time the details", people will shortcut that par…
Ever SSHed into a server and been told by your SSH client that, oh, by the way, the server is using the NULL cipher with no authentication, and network attackers can mess with your session arbitrarily? Probably not. That's what using plaintext HTTP should feel like.
Re: MITM on HTTPS traffic in Kazakhstan
#117hmm, certificate pinning will not allow this gov-ca to work for a lot of high profile web sites. i wonder if these sites with cert pins are whitelisted by the kz gov? -- somehow i missed that HPKP is dead and will be removed from chromium and all the derivative browsers. now google is focusing on Expect-CT
Although pinned certificates have gone out of favor on the web, they are still very frequently used by iOS and Android apps. Last time I checked, the Facebook Messenger app refused to work when being MitM'ed.
Re: MITM on HTTPS traffic in Kazakhstan
#118Earlier quoted context omitted.
Yep - without HTTPS everywhere, governments would have been silently able to snoop on Internet traffic without anyone knowing.
Sarcasm? Not sure. But all a government has to do is embed within the endpoint, post-decryption. "Or else."