Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

381–390 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#381
post #361

A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…

I wished that all individuals in all countries would have such an attitude towards their governments.

Re: MITM on HTTPS traffic in Kazakhstan

#382
post #361

A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…

Please do post this feedback in the bugzilla bug and the linked discussion thread; this is the kind of thing that helps developers make a more informed decision rather than just speculating on what would help people more.

Re: MITM on HTTPS traffic in Kazakhstan

#383
post #103

What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…

This is so bad. I'm from India and at my parents place we have the government run internet provider. They MITM and inject advertisements all the time showing annoying popups whenever you open an http link. I don't know how this is legal even.

Use a VPN and they won't be able to MITM or inject advertisements.

Re: MITM on HTTPS traffic in Kazakhstan

#384
post #360
post #142

I'm surprised at comments in the bug threads suggesting they do nothing. The idea being that fighting this would force governments to fork/change browsers, ultimately being a worse experience for users. Seems like betraying people's trust is a pretty bad user experience. There will always be a fight over privacy. Giving up to a foreign government is a terrible idea. It would absolutely just let the problem spread and…

I wonder if open source browser projects can have a license that prohibits forking for the purpose of mass (state) surveillance.

By definition, no. https://opensource.org/osd-annotated #6

Re: MITM on HTTPS traffic in Kazakhstan

#385
post #21

I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…

Will oscp stapling be able to be used to detect "something fishy" going on, because in that case the root ca wouldn't actually match. Do browsers compare the oscp root with the root of the current chain? Actually, if it's mitm it's "all bets are off" isn't it, because the KZ government can filter that it out the proxied response? Still, if oscp can assist at all, it's probably worth it that the browsers check for mis…

Would the firewall allow your package if you do not use Kazakh certificate as root certificate?

Re: MITM on HTTPS traffic in Kazakhstan

#386
Lets say you have this root CA installed on local machine and won't delete it. Can you protect yourself against https decryption by MITM in any way? Will VPN help or they will intercept VPN connection too?

Re: MITM on HTTPS traffic in Kazakhstan

#387
post #323
post #21

I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…

Before we celebrate defeat, let's just acknowledge that these practices are not taking place in the US, EU, etc. And compromising HTTPS in places with a functional judicial system (and human rights) would probably be blocked by an end-less series of law suites.

Aren't some US providers (Comcast, Verizon?) injecting nasty tracking/advertising into HTTP pages?

That's extremely worrying as well and it appears politics so far are unwilling to make it illegal. There needs to be more protest and more competition so consumers can vote with their wallets.

Re: MITM on HTTPS traffic in Kazakhstan

#388
post #260

Earlier quoted context omitted.

You're proposing that the penalty for being suspected of subverting the firewall is death . In those cases you're going to want a highly refined system for avoiding detection, and it's also very important that one exist, because regimes that oppressive deserve to be opposed. Fortunately the more typical case isn't kidnapping and execution but only having your connection blocked, which creates a helpful feedback loop…

No disagreement here. What's being done is despicable. Rather than death, if we look at the history of oppressive societies, the more likely outcome is a job offer, the kind they won't let you refuse but they'll make it so you don't want to refuse anyway. They find the clever people who are working around the filters and interception and hire them to be the watchers. They get perks like time to spend on a real privat…

1984 101

Re: MITM on HTTPS traffic in Kazakhstan

#389
post #386

Lets say you have this root CA installed on local machine and won't delete it. Can you protect yourself against https decryption by MITM in any way? Will VPN help or they will intercept VPN connection too?

Use a browser that doesn't use the CA list of the OS (such as Firefox) and tunnel all the traffic via a stealthy VPN.

It would probably be illegal and if the regime finds out they'll put you into jail etc.

Re: MITM on HTTPS traffic in Kazakhstan

#390
Just think about this for a minute.

The regime has just painted a huge "X" on their backs.

If you hack the governments servers and steal the certificate private key you can pretty much rob the entire country - all bank transactions, pins, passwords etc. will be in the clear for you, ripe for the picking.

This is yet another reason why backdoors are so dangerous, not just for the privacy of all citizens.

Post reply on HN