Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

351–360 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#351
post #342

Earlier quoted context omitted.

> government run > how this is legal even. The government writes and enforces the laws. They'll never self incriminate.

This is a false assumption. Governments (executive branch) can be prosecuted for illegal behavior.

Your statement only applies to the subset of countries where there is judicial independence.

Re: MITM on HTTPS traffic in Kazakhstan

#352
post #351
post #342

Earlier quoted context omitted.

This is a false assumption. Governments (executive branch) can be prosecuted for illegal behavior.

Your statement only applies to the subset of countries where there is judicial independence.

Which is true in case of India

Re: MITM on HTTPS traffic in Kazakhstan

#353
post #304
post #165

Earlier quoted context omitted.

If a government mandates its citizens to install the government’s own root certificate, then it’s not that easy to find a long-term technological solution. The problem here is not a technical one, IMHO. The problem is that the government of Kazakhstan is not respecting the freedom of its people. Point in case: In 2018, Kazakhstan ranked #144 in the Economist Intelligence Unit’s Democracy Index. Countries such as Chin…

I don't agree. First off, no matter how you or me may be enraged by the incident, this is not (and shouldn't be!) a "moral problem" for the Firefox. And, by the way, if you are not living in the Kazakhstan, it's not for you to decide "what is needed first and foremost in Kazakhstan", it's their business entirely. From the point of view of the Firefox, this should be an extremely simple technical problem. There is CA…

The certificate is not in the Firefox trust store. The government is requiring users to add it manually.

Re: MITM on HTTPS traffic in Kazakhstan

#354
post #345
post #321

Earlier quoted context omitted.

If an attacker can install a CA on the system, the attacker can probably also apply binary modifications to Firefox. Or replace it with a compromised version.

It can be an authoritarian government arm twisting you into installing it voluntarily, as the article proves.

Which they could also do with software, or even hardware via import controls.

Re: MITM on HTTPS traffic in Kazakhstan

#355

Earlier quoted context omitted.

Corporations also do this so they can scan traffic for data exfil.

Which is, tbqh, a useless solution. Oh wow, now an attacker just has to include some obfuscated javascript encryption lib. Bam. Exfil detection completely bypassed.

True, but Joe Dipseedoodle doesn't accidentally send out an HR report because he was logged into his personal email account.

Too much security is willing to give up on the 95% because they can't get the 100%.

Re: MITM on HTTPS traffic in Kazakhstan

#356
post #327
post #103

What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…

Comcast used to do this to me about 6 or 7 years ago to tell me, or someone, about torrent use on the connection and something or other about copyright infringement. They'd inject their messages into the html of websites and you'd have to dismiss them to continue to use the site. Not their site. All sites.

I've noticed Airtel doing something similar in India but to inform of approaching bill dates.

Re: MITM on HTTPS traffic in Kazakhstan

#357

How does this work technically? I understand that by making people install the government cert, any website with a cert signed by that government cert will happily speak TLS. But, how can they read data transmitted between websites they don't control? When the client asks for Facebook's cert, wouldn't the government have to sneak in and show a fake cert signed by them instead? How does that work?

It can probably work as MITM. The ISP or whoever controls your net traffic needs to generate a fake certificate(signed by a trusted root cert) for a site you are browsing. Refer example in: https://en.wikipedia.org/wiki/Man-in-the-middle_attack

Re: MITM on HTTPS traffic in Kazakhstan

#358
post #323
post #21

I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…

Before we celebrate defeat, let's just acknowledge that these practices are not taking place in the US, EU, etc. And compromising HTTPS in places with a functional judicial system (and human rights) would probably be blocked by an end-less series of law suites.

Everything can be justified by national security. You can't try and block something with "an end-less series of law suites" if the defending party doesn't even need to provide any kind of proof. "Why are we MTiMing HTTPS? This is un-constitutional! -- Because internet is a threat to national security which in turn has higher priority than your rights, Citizen!. Everything else is classified and will be discussed in a closed court." Take a wild guess what that court is going to decide...

Re: MITM on HTTPS traffic in Kazakhstan

#360
post #142

I'm surprised at comments in the bug threads suggesting they do nothing. The idea being that fighting this would force governments to fork/change browsers, ultimately being a worse experience for users. Seems like betraying people's trust is a pretty bad user experience. There will always be a fight over privacy. Giving up to a foreign government is a terrible idea. It would absolutely just let the problem spread and…

I wonder if open source browser projects can have a license that prohibits forking for the purpose of mass (state) surveillance.
Post reply on HN