Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

241–250 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#241
post #218
post #178

Earlier quoted context omitted.

If it ruins their economy, yes.

99% of the population will happily install the government cert, and life will move on. The 1% will either put up with it, stop using the internet, or leave. One thing will happen though - the economy will not be ruined. Generally speaking, since the Cold War ended, these sorts of countries don't mind troublemakers leaving. It's better international PR for them to have 'problem people' leave voluntarily, than to repre…

For example there's no way for my LG TV to install that root CA, so all that smartness basically rendered useless, unless LG would issue new firmware for that region and I'm not really sure that they would care enough. I bet that there are plenty of devices that would stop working. Think about all those IoT devices. I could imagine some kind of eye surgery laser device to stop working because it can't connect to its Zurich servers to check license. Yes, it won't cause revolution, but there will be a lot of issues.

Re: MITM on HTTPS traffic in Kazakhstan

#242
post #21

I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…

Unfortunately governments like that will continue to do low effort workarounds as long as they have police and military forces to respond to those who don't conform.

Re: MITM on HTTPS traffic in Kazakhstan

#243

Earlier quoted context omitted.

Except I look at the linked mailing list and you already get "us techies" arguing "uh yeah but uhm this isn't so different from the corporate CA intercept thing right so let's not blacklist it uhm". What the fuck.

"So do we make our flagship product useless for the entire country or not?" - The real question

Yes? This isn't that complicated. You break it, and when competitive browser X refuses to do so, you sell the idea that browser X is compromised for all users everywhere (not just in Kazakhstan)

Stop thinking about the country with literally less than 1% of world internet users and start thinking of the reputational damage a less than charitable presentation of your collaboration with a totalitarian state against your users would do to the other 99%+ of your market.

Re: MITM on HTTPS traffic in Kazakhstan

#244
post #15

Would someone with network access in Kazakhstan check if Caddy's MITM detector catches this please? https://caddyserver.com/docs/mitm-detection - or https://mitm.watch (Cloudflare's unofficial deployment of the same tech). If it does not, could you file a bug report with a complete packet capture (and exact browser version - multiple browsers are preferred)? https://github.com/caddyserver/caddy/issues (Edit: Reported…

For reference

The code is here: https://github.com/caddyserver/caddy/blob/master/caddyhttp/h...

The paper: https://jhalderm.com/pub/papers/interception-ndss17.pdf

Re: MITM on HTTPS traffic in Kazakhstan

#245

I blame, in part, TLS 1.3, E-SNI, and DoH for this. Previously, a government could monitor what site a user is visiting just by looking at the TLS session startup. Even if it is hosted on a cloud provider and 100 different sites are hosted from the same IP, they could look at the TLS-SNI data in the plain text to choose to interrupt and block the connection. A fallback would be to manipulate DNS queries and force all…

It's probably completely unrelated.

DoH is easy to block. They can look at SNI and cut DoH connections.

Being able to access all the content is far more valuable than hostnames.

Re: MITM on HTTPS traffic in Kazakhstan

#246
post #228

Earlier quoted context omitted.

I'd like that as well, for exactly the same purpose. To the best of my knowledge, no browser can do this today, and I don't know of any other software that can do that either. (I'd want to have it in the system certificate store with the same constraint, as well.) Name Constraints, as mentioned elsewhere in this thread, wouldn't solve the problem, for two reasons: most software doesn't support them (and silently igno…

> most software doesn't support [name constraints] (and silently ignores them rather than correctly failing closed) Could you elaborate on this? Specific examples? CVEs? My experience has been that most software will either honor them, or honor the "critical" flag, which is correct (if disappointing) behavior. If you want it to fail closed, use the critical flag. If you want it to fail open, clear the critical flag.

The last time I investigated this this, several years ago, I found that several SSL libraries simply ignored the extension entirely, whether it had "critical" or not. Older OpenSSL did so, for instance.

Doing some additional research, it looks like the situation has improved significantly now, and name constraints might actually work as designed if you don't care about older systems.

That still doesn't address the ability for a browser/administrator to apply such name constraints to a CA that didn't ship as part of its certificate, though.

Re: MITM on HTTPS traffic in Kazakhstan

#247
Absolute morons. They will break windows updates. You cannot easily mitm Windows updates. There is additional undocumented check that the CA is from Microsoft. One needs to hotpatch the windows update dll’s to enable it. That’s almost certainly one that won’t be intercepted.

Re: MITM on HTTPS traffic in Kazakhstan

#248
post #234

Earlier quoted context omitted.

No. we just feel better because it just sounds so obviously reasonable doesn't it? Kazakhstan's low-tech approach is just that, low-tech and low-effort. They could have used tons of vectors besides simply saying "install this cert." A tiny shred of effort would have been to package an "updater" that did the install without explicitly saying that's what it was for. Or better yet: Kazakhstan is committed to a greener m…

No, it's not pointless. This attack was detectable because of PKI. Without it the attack would not have been detectable. Being imperfect is different than being pointless. Even if you developed the perfect algorithm for global security infrastructure, the Kazakhstan government could still just break down your door and implant the backdoor into your hardware if they wanted. So by your logic should we just forget about…

An implant is not necessary. Intel ME is embedded with the CPU and has access to everything.

Re: MITM on HTTPS traffic in Kazakhstan

#249
post #229

Earlier quoted context omitted.

Ethernet can carry protocols other than IPv4. IPv6 is one of them, but there were at one time a whole slew of them, like IPX and Appletalk. But ISPs don't carry them, so they're effectively blocked and have largely died out, and everything uses IPv4 or IPv6. Even if you want to use Appletalk today, you encapsulate in IPv4 or IPv6. There are also a whole bunch of IP transport protocols other than TCP and UDP, but fire…

I'll be 40 years old later this year. I've been interested in communications and communications protocols since I was about 12. I've been a software developer with a focus on network communications for over 15 years. I'm well aware of all that you've said. My point was, they get TLS interception down, and they capture what they want from a target of interest. When they look closely at your traffic and decide all thes…

https://en.m.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Re: MITM on HTTPS traffic in Kazakhstan

#250
post #53

Earlier quoted context omitted.

This is why I'm always advocating for political engagement for fighting these kind of issues. It's not exactly hard for a government to ban or forbid circumventing their monitoring. It does take time, but they're about to catch up.

It’s far harder if you have a major tech industry to push back and the whole massive security risk this exposes big corporations to. Which is something Kazakhstan must not have much of. This is also terrible for foreign investment and attracting business. It also makes foreign intelligence’s job easier.

You’ve got their priorities mixed up. Staying in power is more important than foreign investment if you’re an authoritarian government. What’s the point of growing the economic pie if you’re not in a position to profit from it ?

Now if you’re a politician in a democracy, you know it may be all over in about 8 years, so it’s more your interest to cosy up to the companies

Post reply on HN