Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

331–340 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#331
post #272

Earlier quoted context omitted.

Are you willing to intentionally break your software (which is currently working) for an entire country?

If you want to put a stop to things like this, then you have to. Complaints from companies and the general population should be enough to fix the issue.

Mere collateral damage.

Re: MITM on HTTPS traffic in Kazakhstan

#332
post #103

What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…

Be careful.

Re: MITM on HTTPS traffic in Kazakhstan

#333
post #232

Earlier quoted context omitted.

Oh I agree 100%. It just makes me sad that governments keep trying to spy and we have to keep coming up with new technology to make that harder.

It's not a technology problem, it's a social one. If a society values it's privacy enough then it will change. The real issue is how abstract the consequences of loss of privacy are. It requires people to actually think beyond "I've got nothing to hide". No worries though. Greedy corporations and governments are greedy and they'll keep pushing the limits of societie's tolerance until it blows up in their face.

> It's not a technology problem, it's a social one.

It's both, everyone can contribute to the solution or the problem.

Re: MITM on HTTPS traffic in Kazakhstan

#334

Earlier quoted context omitted.

I'll be 40 years old later this year. I've been interested in communications and communications protocols since I was about 12. I've been a software developer with a focus on network communications for over 15 years. I'm well aware of all that you've said. My point was, they get TLS interception down, and they capture what they want from a target of interest. When they look closely at your traffic and decide all thes…

https://en.m.wikipedia.org/wiki/Rubber-hose_cryptanalysis

In CIS states they prefer the term thermo-rectal cryptanalysis. A soldering iron in one's nether regions does wonders for extracting secrets.

Re: MITM on HTTPS traffic in Kazakhstan

#335
post #274
post #260

Earlier quoted context omitted.

You're proposing that the penalty for being suspected of subverting the firewall is death . In those cases you're going to want a highly refined system for avoiding detection, and it's also very important that one exist, because regimes that oppressive deserve to be opposed. Fortunately the more typical case isn't kidnapping and execution but only having your connection blocked, which creates a helpful feedback loop…

> You're proposing that the penalty for being suspected of subverting the firewall is death. no, he's being hyperbolic to make the point that in an extreme situation, a default-deny approach could facilitate mass suppression of 'undesirable' traffic without creating an insurmountable backlog of traffic for the 'bad actor state' to review in determining what to process further.

> no, he's being hyperbolic to make the point that in an extreme situation, a default-deny approach could facilitate mass suppression of 'undesirable' traffic without creating an insurmountable backlog of traffic for the 'bad actor state' to review in determining what to process further.

Only it doesn't, because as soon as they allow anything, everything else starts to look enough like whatever is still allowed to make it through, because that's the only way to make it through.

Slashing away more things only increases the resources people will put behind making arbitrary traffic look like allowed traffic. It trades not having to review everything for having to fight everyone instead of only the people they want to block.

Then some people win, everyone copies the winners' methods to get through, and you're back to square one only now everything looks even more like everything else than it did before.

Re: MITM on HTTPS traffic in Kazakhstan

#336

Earlier quoted context omitted.

Hello, To continue using internet, you need to install our government-provided fork of Firefox that doesn't blacklist our government-provided root cert. regards, your Tele2

That's exactly what will happen if they all-out blacklist. The best near-term option may be a compromise: a special indicator in the browser UI that the connection has been set up in such a way that some organization may be monitoring.

Yes, this kind of indicator should always have existed for the corporate and anti-virus local roots as well.

Re: MITM on HTTPS traffic in Kazakhstan

#337
post #232

Earlier quoted context omitted.

Oh I agree 100%. It just makes me sad that governments keep trying to spy and we have to keep coming up with new technology to make that harder.

It's not a technology problem, it's a social one. If a society values it's privacy enough then it will change. The real issue is how abstract the consequences of loss of privacy are. It requires people to actually think beyond "I've got nothing to hide". No worries though. Greedy corporations and governments are greedy and they'll keep pushing the limits of societie's tolerance until it blows up in their face.

Governments are way scarier though. I can decide not to use Google, people in third world countries need the internet.

Re: MITM on HTTPS traffic in Kazakhstan

#338
post #102

They should just put a red dot on the browser bar somewhere indicating a non-normal root cert is being used (this would also help in dev / test scenarios).

This is actually the subject of some debate, believe it or not, there is a good argument against it. Here is the crux of the issue, many TLS middleware providers install their own root certificate for network monitoring, data loss prevention, security scanning and so on. I personally would like them to stop doing that or at least make it obvious to end users it's happening. However, in order to modify the root store,…

This is a silly argument. You might as well say that Firefox should include an option to silently submit all your keystrokes to a designated endpoint, because after all if you have access to set that option you have access to install a keylogger.

So what if they could, in theory, work around the indicator by asking users to install some dubious live-patching executable? Firstly, the users wouldn't have to do so - the enforcement mechanism here is ultimately the MITM itself, so as long as the users just installed the certificate they could continue to access sites (they would have to make the certificate available separately, for installation on iOS / Android / ChromeOS etc). Secondly, the security implications of live-patching the executable are mostly irrelevant, because the only people installing this have already lost the security game. Thirdly, there is a benefit in making the bastards work for it - keeping that live-patcher up-to-date and working against a range of target executable versions is going to be bitter work.

Re: MITM on HTTPS traffic in Kazakhstan

#340

Earlier quoted context omitted.

But we are in a better place than before. Without HTTPS everywhere and governments needing to ask people to install new root certs, we would not have learned about this Kazakhstan MITM issue.

No. we just feel better because it just sounds so obviously reasonable doesn't it? Kazakhstan's low-tech approach is just that, low-tech and low-effort. They could have used tons of vectors besides simply saying "install this cert." A tiny shred of effort would have been to package an "updater" that did the install without explicitly saying that's what it was for. Or better yet: Kazakhstan is committed to a greener m…

> Public Key Infrastructure is fucking pointless when the infrastructure is precisely what you can't trust.

This seems a cynical and lazy evaluation of the situation. No solution is perfect, trade offs must be made everywhere. With the right precautions the average person can have his/her communications encrypted. This is a much better situation than the one we were on before.

Post reply on HN