Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

371–380 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#371
post #361

A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…

Couldn't agree more.

Re: MITM on HTTPS traffic in Kazakhstan

#372
post #352
post #351

Earlier quoted context omitted.

Your statement only applies to the subset of countries where there is judicial independence.

Which is true in case of India

The present judiciary in India lacks spine, on one hand they say privacy is fundamental right on other hand they drag their feet to stop the project aadhaar which required collecting biometric dataset on whole population.

And their defense claims US has SSN which is equivalent of Aadhaar why anyone can see ludicrous

And still Aadhar requirement is not removed for filing income tax return (which results in massive penalities)

Re: MITM on HTTPS traffic in Kazakhstan

#373
post #327
post #103

What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…

Comcast used to do this to me about 6 or 7 years ago to tell me, or someone, about torrent use on the connection and something or other about copyright infringement. They'd inject their messages into the html of websites and you'd have to dismiss them to continue to use the site. Not their site. All sites.

Ok, I begin to understand the idea behind HTTPS everywhere..

Re: MITM on HTTPS traffic in Kazakhstan

#374
I'm in Kazakhstan atm, the only solution I can see is to reach Google, Mozilla, Firefox, Apple, banks and all the other popular platforms and social media apps and ask them to ban connections with the government-issued certificate.

This will immediately block their services in the country and will raise awareness at scale.

https://renatello.com/mitm-in-kazakhstan/

Re: MITM on HTTPS traffic in Kazakhstan

#375

Earlier quoted context omitted.

Not only that but they can happily MITM HTTPS as well. Not all the HTTPS sites use certificate pinning or HSTS.

It's a tough problem because certificate pinning kills a lot of legitimate use patterns; it's not something I'd like to see being the default everywhere.

Yes but this is how many companies protect their HTTPS traffic (including one financial institution I work for).

Re: MITM on HTTPS traffic in Kazakhstan

#376
post #361

A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…

What is the extent of the MITM attack that you can do with this certificate? Can you intercept all https traffic?

Re: MITM on HTTPS traffic in Kazakhstan

#377
post #174

Earlier quoted context omitted.

Not only that but they can happily MITM HTTPS as well. Not all the HTTPS sites use certificate pinning or HSTS.

What root cert would they us for that?

You mean CA? There are many options depending on which agency and which target you are talking about. They have few options from stealing a CA from a legitimate CA user if the want anonymity or use one that is built in to your browsers or systems somebody else already pointed out in the thread.

Re: MITM on HTTPS traffic in Kazakhstan

#378
post #361

A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…

What is the extent of the MITM attack that you can do with this certificate? Can you intercept all https traffic?

Yes

Re: MITM on HTTPS traffic in Kazakhstan

#379
post #361

A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…

What is the extent of the MITM attack that you can do with this certificate? Can you intercept all https traffic?

Yes, having a root CA certificate like this installed in a client allows the certificate issuer (so in this case KZ government and anything they authorize ISPs to do) to impersonate any and every other domain. So yes, ALL https traffic to and from that client to be subject to intercept.

Re: MITM on HTTPS traffic in Kazakhstan

#380
post #214

Earlier quoted context omitted.

The government of my country has at least one certificate that's trusted by Mozilla (and I guess Chrome and Windows too) by default.

It won't stay trusted if it is actively used for MITM attacks. At least that's the idea.

https://security.stackexchange.com/questions/71171/is-there-...
Post reply on HN