Earlier quoted context omitted.
Are you willing to intentionally break your software (which is currently working) for an entire country?
If you want to put a stop to things like this, then you have to. Complaints from companies and the general population should be enough to fix the issue.
MITM on HTTPS traffic in Kazakhstan
331–340 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#332What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…
Re: MITM on HTTPS traffic in Kazakhstan
#333Earlier quoted context omitted.
Oh I agree 100%. It just makes me sad that governments keep trying to spy and we have to keep coming up with new technology to make that harder.
It's not a technology problem, it's a social one. If a society values it's privacy enough then it will change. The real issue is how abstract the consequences of loss of privacy are. It requires people to actually think beyond "I've got nothing to hide". No worries though. Greedy corporations and governments are greedy and they'll keep pushing the limits of societie's tolerance until it blows up in their face.
It's both, everyone can contribute to the solution or the problem.
Re: MITM on HTTPS traffic in Kazakhstan
#334Earlier quoted context omitted.
I'll be 40 years old later this year. I've been interested in communications and communications protocols since I was about 12. I've been a software developer with a focus on network communications for over 15 years. I'm well aware of all that you've said. My point was, they get TLS interception down, and they capture what they want from a target of interest. When they look closely at your traffic and decide all thes…
https://en.m.wikipedia.org/wiki/Rubber-hose_cryptanalysis
Re: MITM on HTTPS traffic in Kazakhstan
#335Earlier quoted context omitted.
You're proposing that the penalty for being suspected of subverting the firewall is death . In those cases you're going to want a highly refined system for avoiding detection, and it's also very important that one exist, because regimes that oppressive deserve to be opposed. Fortunately the more typical case isn't kidnapping and execution but only having your connection blocked, which creates a helpful feedback loop…
> You're proposing that the penalty for being suspected of subverting the firewall is death. no, he's being hyperbolic to make the point that in an extreme situation, a default-deny approach could facilitate mass suppression of 'undesirable' traffic without creating an insurmountable backlog of traffic for the 'bad actor state' to review in determining what to process further.
Only it doesn't, because as soon as they allow anything, everything else starts to look enough like whatever is still allowed to make it through, because that's the only way to make it through.
Slashing away more things only increases the resources people will put behind making arbitrary traffic look like allowed traffic. It trades not having to review everything for having to fight everyone instead of only the people they want to block.
Then some people win, everyone copies the winners' methods to get through, and you're back to square one only now everything looks even more like everything else than it did before.
Re: MITM on HTTPS traffic in Kazakhstan
#336Earlier quoted context omitted.
Hello, To continue using internet, you need to install our government-provided fork of Firefox that doesn't blacklist our government-provided root cert. regards, your Tele2
That's exactly what will happen if they all-out blacklist. The best near-term option may be a compromise: a special indicator in the browser UI that the connection has been set up in such a way that some organization may be monitoring.
Re: MITM on HTTPS traffic in Kazakhstan
#337Earlier quoted context omitted.
Oh I agree 100%. It just makes me sad that governments keep trying to spy and we have to keep coming up with new technology to make that harder.
It's not a technology problem, it's a social one. If a society values it's privacy enough then it will change. The real issue is how abstract the consequences of loss of privacy are. It requires people to actually think beyond "I've got nothing to hide". No worries though. Greedy corporations and governments are greedy and they'll keep pushing the limits of societie's tolerance until it blows up in their face.
Re: MITM on HTTPS traffic in Kazakhstan
#338They should just put a red dot on the browser bar somewhere indicating a non-normal root cert is being used (this would also help in dev / test scenarios).
This is actually the subject of some debate, believe it or not, there is a good argument against it. Here is the crux of the issue, many TLS middleware providers install their own root certificate for network monitoring, data loss prevention, security scanning and so on. I personally would like them to stop doing that or at least make it obvious to end users it's happening. However, in order to modify the root store,…
So what if they could, in theory, work around the indicator by asking users to install some dubious live-patching executable? Firstly, the users wouldn't have to do so - the enforcement mechanism here is ultimately the MITM itself, so as long as the users just installed the certificate they could continue to access sites (they would have to make the certificate available separately, for installation on iOS / Android / ChromeOS etc). Secondly, the security implications of live-patching the executable are mostly irrelevant, because the only people installing this have already lost the security game. Thirdly, there is a benefit in making the bastards work for it - keeping that live-patcher up-to-date and working against a range of target executable versions is going to be bitter work.
Re: MITM on HTTPS traffic in Kazakhstan
#339Does anyone have ideas, who is the tech vendor? Russians? Chinese?
Re: MITM on HTTPS traffic in Kazakhstan
#340Earlier quoted context omitted.
But we are in a better place than before. Without HTTPS everywhere and governments needing to ask people to install new root certs, we would not have learned about this Kazakhstan MITM issue.
No. we just feel better because it just sounds so obviously reasonable doesn't it? Kazakhstan's low-tech approach is just that, low-tech and low-effort. They could have used tons of vectors besides simply saying "install this cert." A tiny shred of effort would have been to package an "updater" that did the install without explicitly saying that's what it was for. Or better yet: Kazakhstan is committed to a greener m…
This seems a cynical and lazy evaluation of the situation. No solution is perfect, trade offs must be made everywhere. With the right precautions the average person can have his/her communications encrypted. This is a much better situation than the one we were on before.