Earlier quoted context omitted.
> government run > how this is legal even. The government writes and enforces the laws. They'll never self incriminate.
This is a false assumption. Governments (executive branch) can be prosecuted for illegal behavior.
MITM on HTTPS traffic in Kazakhstan
351–360 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#352Re: MITM on HTTPS traffic in Kazakhstan
#353Earlier quoted context omitted.
If a government mandates its citizens to install the government’s own root certificate, then it’s not that easy to find a long-term technological solution. The problem here is not a technical one, IMHO. The problem is that the government of Kazakhstan is not respecting the freedom of its people. Point in case: In 2018, Kazakhstan ranked #144 in the Economist Intelligence Unit’s Democracy Index. Countries such as Chin…
I don't agree. First off, no matter how you or me may be enraged by the incident, this is not (and shouldn't be!) a "moral problem" for the Firefox. And, by the way, if you are not living in the Kazakhstan, it's not for you to decide "what is needed first and foremost in Kazakhstan", it's their business entirely. From the point of view of the Firefox, this should be an extremely simple technical problem. There is CA…
Re: MITM on HTTPS traffic in Kazakhstan
#354Earlier quoted context omitted.
If an attacker can install a CA on the system, the attacker can probably also apply binary modifications to Firefox. Or replace it with a compromised version.
It can be an authoritarian government arm twisting you into installing it voluntarily, as the article proves.
Re: MITM on HTTPS traffic in Kazakhstan
#355Earlier quoted context omitted.
Corporations also do this so they can scan traffic for data exfil.
Which is, tbqh, a useless solution. Oh wow, now an attacker just has to include some obfuscated javascript encryption lib. Bam. Exfil detection completely bypassed.
Too much security is willing to give up on the 95% because they can't get the 100%.
Re: MITM on HTTPS traffic in Kazakhstan
#356What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…
Comcast used to do this to me about 6 or 7 years ago to tell me, or someone, about torrent use on the connection and something or other about copyright infringement. They'd inject their messages into the html of websites and you'd have to dismiss them to continue to use the site. Not their site. All sites.
Re: MITM on HTTPS traffic in Kazakhstan
#357How does this work technically? I understand that by making people install the government cert, any website with a cert signed by that government cert will happily speak TLS. But, how can they read data transmitted between websites they don't control? When the client asks for Facebook's cert, wouldn't the government have to sneak in and show a fake cert signed by them instead? How does that work?
Re: MITM on HTTPS traffic in Kazakhstan
#358I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…
Before we celebrate defeat, let's just acknowledge that these practices are not taking place in the US, EU, etc. And compromising HTTPS in places with a functional judicial system (and human rights) would probably be blocked by an end-less series of law suites.
Re: MITM on HTTPS traffic in Kazakhstan
#359Re: MITM on HTTPS traffic in Kazakhstan
#360I'm surprised at comments in the bug threads suggesting they do nothing. The idea being that fighting this would force governments to fork/change browsers, ultimately being a worse experience for users. Seems like betraying people's trust is a pretty bad user experience. There will always be a fight over privacy. Giving up to a foreign government is a terrible idea. It would absolutely just let the problem spread and…