Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

131–140 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#131
post #53

Earlier quoted context omitted.

This is why I'm always advocating for political engagement for fighting these kind of issues. It's not exactly hard for a government to ban or forbid circumventing their monitoring. It does take time, but they're about to catch up.

It’s far harder if you have a major tech industry to push back and the whole massive security risk this exposes big corporations to. Which is something Kazakhstan must not have much of. This is also terrible for foreign investment and attracting business. It also makes foreign intelligence’s job easier.

Too bad EPIC is caught up with stupid issues relating to whether the census can ask if illegal invaders are citizens or not?

Re: MITM on HTTPS traffic in Kazakhstan

#132
Google, Mozilla, and Microsoft need to take a stand here and blacklist these certs. All of the efforts to move to HTTPS, and all of the rhetoric surrounding it, are just wasted time and empty words if we as a tech community allow this kind of behavior to go unchallenged. This sets such a dangerous precedent, and governments need to know that this kind of meddling will not be tolerated.

Re: MITM on HTTPS traffic in Kazakhstan

#134

Earlier quoted context omitted.

Steganography. With a good key and enough stuffing, it is undetectable

Do you mean steganography? Stenography is writing in shorthand (or typing on a stenotype, like court reporters do).

autocorrect strikes again :)

Re: MITM on HTTPS traffic in Kazakhstan

#135
post #21

I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…

> Now "us techies" have to find a new technical solution to a very social problem. Cert pinning does mitigate it for apps, doesn't it? The end-user doesn't need to really worry abt rouge root CAs, if my understanding is right. Traditional VPNs, P2P VPNs, Tor as a Proxy (decentralised net? dat/i2p/freenet/ipfs) could solve it generally across various use-cases, of which, VPNs are already mainstream.

Not necessarily. We have rolled out SSL inspection at my company and have to exclude certain apps (e.g. Dropbox, Google Drive) or else they won't work. The FW just blocks the connection and the user gets a SSL/TLS error.

Re: MITM on HTTPS traffic in Kazakhstan

#136
post #113
post #32

Earlier quoted context omitted.

This would be fantastic. Also, it would be great if there were a "red dot" style warning when you manually click "Proceed anyway" while viewing a https page with an invalid certificate (currently, the browser remembers the "Proceed anyway" decision and accepts the invalid cert after the initial acceptance of the warning)

There's the big red X over the HTTPS icon in the address bar in Chrome and I'm pretty sure there's something similar done to the padlock icon in Firefox, no?

Oops, you're absolutely right.

Re: MITM on HTTPS traffic in Kazakhstan

#137
post #21

I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…

Maybe this sort of interruption is manageable when half of your 18 million people are rural and the economy isn't heavily dependent on internet traffic. Try doing this in a more urban populated country and you will see a much different outcome.

You just start small, from small cities, so rest of people have enough time to prepare.

Re: MITM on HTTPS traffic in Kazakhstan

#138

Earlier quoted context omitted.

Corporations also do this so they can scan traffic for data exfil.

Which is, tbqh, a useless solution. Oh wow, now an attacker just has to include some obfuscated javascript encryption lib. Bam. Exfil detection completely bypassed.

For example corporations might want to make sure that worker is not sending e-mails with confidential data from its gmail. Sophisticated thief surely will circumvent that kind of protection, but a lot of thieves are stupid, so simple measures actually work.

Re: MITM on HTTPS traffic in Kazakhstan

#139

Earlier quoted context omitted.

Far too many people would be able to notice. Someone in one of the companies would whistleblow.

But would they? The Snowden leaks were 6 years ago. I am assuming the government didn't just throw up their hands and give up after that... edit: not to say they are specifically MITM'ing HTTPS widescale.

There are a lot easier ways to exfiltrate data than wholesale breaking TLS encryption and MITM'ing 295+ tbps of domestic traffic. That said, every super power is working on better decryption capabilities.

Re: MITM on HTTPS traffic in Kazakhstan

#140
post #97

Earlier quoted context omitted.

For mobile apps, though, you can bootstrap HPKP with a key built into the app. I worked on an app doing this, and it would certainly fail to connect in this scenario.

A lot of internal enterprise networks use MITM, so your app won't work there as well. It might be a good thing or not, depending on your use-case.

If the app is not for that particular corporation, then no harm done.
Post reply on HN