What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…
MITM on HTTPS traffic in Kazakhstan
341–350 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#342Earlier quoted context omitted.
This is so bad. I'm from India and at my parents place we have the government run internet provider. They MITM and inject advertisements all the time showing annoying popups whenever you open an http link. I don't know how this is legal even.
> government run > how this is legal even. The government writes and enforces the laws. They'll never self incriminate.
Re: MITM on HTTPS traffic in Kazakhstan
#343Re: MITM on HTTPS traffic in Kazakhstan
#344I understand that by making people install the government cert, any website with a cert signed by that government cert will happily speak TLS.
But, how can they read data transmitted between websites they don't control? When the client asks for Facebook's cert, wouldn't the government have to sneak in and show a fake cert signed by them instead? How does that work?
Re: MITM on HTTPS traffic in Kazakhstan
#345So it took them only two weeks to take advantage of Firefox's new policy to automatically "fix"[1] man in the middle attacks through enterprise/antivirus CAs. As expected, this "convenience" will make us all less safe :(. [1] https://blog.mozilla.org/security/2019/07/01/fixing-antiviru...
If an attacker can install a CA on the system, the attacker can probably also apply binary modifications to Firefox. Or replace it with a compromised version.
Re: MITM on HTTPS traffic in Kazakhstan
#346Google, Mozilla, and Microsoft need to take a stand here and blacklist these certs. All of the efforts to move to HTTPS, and all of the rhetoric surrounding it, are just wasted time and empty words if we as a tech community allow this kind of behavior to go unchallenged. This sets such a dangerous precedent, and governments need to know that this kind of meddling will not be tolerated.
Re: MITM on HTTPS traffic in Kazakhstan
#347Earlier quoted context omitted.
If you want to put a stop to things like this, then you have to. Complaints from companies and the general population should be enough to fix the issue.
Mere collateral damage.
In fact, you're making it worse because you're giving legitimacy to a government that is conducting actions which we shouldn't consider acceptable. If the US government started doing the same thing, I would really hope that browsers would block those certificates too.
Re: MITM on HTTPS traffic in Kazakhstan
#348Earlier quoted context omitted.
If the NSA was using their own certificates to MITM all HTTPS traffic it would be easily noticed by security researchers. Its not like they obtain the private keys of every US company. They'd have to make their own replacement certain for every site they wish to intercept. That could easily be noticed by security professionals and targeted companies by monitoring.
What about just for the Alexa 100?
Re: MITM on HTTPS traffic in Kazakhstan
#349Re: MITM on HTTPS traffic in Kazakhstan
#350What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…
This is so bad. I'm from India and at my parents place we have the government run internet provider. They MITM and inject advertisements all the time showing annoying popups whenever you open an http link. I don't know how this is legal even.