Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

341–350 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#341
post #103

What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…

I had ads injected by some European and UK ISPs on my own website. I pushed me to finally get LetsEncrypt implemented and switch everything over to https.

Re: MITM on HTTPS traffic in Kazakhstan

#342

Earlier quoted context omitted.

This is so bad. I'm from India and at my parents place we have the government run internet provider. They MITM and inject advertisements all the time showing annoying popups whenever you open an http link. I don't know how this is legal even.

> government run > how this is legal even. The government writes and enforces the laws. They'll never self incriminate.

This is a false assumption. Governments (executive branch) can be prosecuted for illegal behavior.

Re: MITM on HTTPS traffic in Kazakhstan

#344
How does this work technically?

I understand that by making people install the government cert, any website with a cert signed by that government cert will happily speak TLS.

But, how can they read data transmitted between websites they don't control? When the client asks for Facebook's cert, wouldn't the government have to sneak in and show a fake cert signed by them instead? How does that work?

Re: MITM on HTTPS traffic in Kazakhstan

#345
post #321
post #319

So it took them only two weeks to take advantage of Firefox's new policy to automatically "fix"[1] man in the middle attacks through enterprise/antivirus CAs. As expected, this "convenience" will make us all less safe :(. [1] https://blog.mozilla.org/security/2019/07/01/fixing-antiviru...

If an attacker can install a CA on the system, the attacker can probably also apply binary modifications to Firefox. Or replace it with a compromised version.

It can be an authoritarian government arm twisting you into installing it voluntarily, as the article proves.

Re: MITM on HTTPS traffic in Kazakhstan

#346

Google, Mozilla, and Microsoft need to take a stand here and blacklist these certs. All of the efforts to move to HTTPS, and all of the rhetoric surrounding it, are just wasted time and empty words if we as a tech community allow this kind of behavior to go unchallenged. This sets such a dangerous precedent, and governments need to know that this kind of meddling will not be tolerated.

Let's get Congress to do it - fix the collective action problem. Pass a law that says that all American companies are forbidden from serving traffic to countries which require their citizens to install compromised roots on their personal devices. Treat them like North Korea / Iran.

Re: MITM on HTTPS traffic in Kazakhstan

#347
post #272

Earlier quoted context omitted.

If you want to put a stop to things like this, then you have to. Complaints from companies and the general population should be enough to fix the issue.

Mere collateral damage.

Is it better to be complicit with an authoritarian regime that is actively spying on their people, in order to have a marginally larger user base? I don't think so.

In fact, you're making it worse because you're giving legitimacy to a government that is conducting actions which we shouldn't consider acceptable. If the US government started doing the same thing, I would really hope that browsers would block those certificates too.

Re: MITM on HTTPS traffic in Kazakhstan

#348

Earlier quoted context omitted.

If the NSA was using their own certificates to MITM all HTTPS traffic it would be easily noticed by security researchers. Its not like they obtain the private keys of every US company. They'd have to make their own replacement certain for every site they wish to intercept. That could easily be noticed by security professionals and targeted companies by monitoring.

What about just for the Alexa 100?

Event just a single site from the alexa 100 would be too obvious. I'm sure some security researchers and/or companies are already monitoring the certificates issued from major websites for abnormalities.

Re: MITM on HTTPS traffic in Kazakhstan

#349
I think everyone who is concerned with privacy in states like those, use ToR anyway all the time. I know people who only do meaningful stuff on the Internet through an RDP session on a server in Amsterdam, connected to through a VPN. The rest is just to watch cat videos.

Re: MITM on HTTPS traffic in Kazakhstan

#350
post #103

What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…

This is so bad. I'm from India and at my parents place we have the government run internet provider. They MITM and inject advertisements all the time showing annoying popups whenever you open an http link. I don't know how this is legal even.

Which provider is this? MTNL or BSNL?
Post reply on HN