Live data from Hacker News

MITM on HTTPS traffic in Kazakhstan

bugzilla.mozilla.org

441–450 of 471 posts

Re: MITM on HTTPS traffic in Kazakhstan

#441

Earlier quoted context omitted.

Why does such a certificate exist in the first place?

It exists to intercept https and potentially other TLS traffic. It exists because everybody can make such a certificate. I made such a CA certificate for my personal use, not to MITM myself, but to issue certificates for some internal services that are out of scope of letsencrypt. Every major desktop OS comes with tools that let you make a CA certificate, Windows does, macos does, linux distro usually ship openssl/gn…

[deleted]

Re: MITM on HTTPS traffic in Kazakhstan

#442

Earlier quoted context omitted.

I disagree that encryption is political. Fundamentally, it's a privacy and security mechanism and on its own it's no more political than locks, safes, paper shredders or curtains. Because of the complex, un-intuitive nature of encryption, it mixed particularly badly with politics, and we're still suffering from the fallout of that now. (crypto wars 1) Firefox and other application vendors who use those standards do e…

Privacy is political.

Privacy is apolitical. In fact, it is built into the very fabric of how the world works.

Does the grain of sand on a beach in Japan know whether or not I've just sat down in America? No.

Does the merging black hole/neutron star somewhere in the universe know that it will have consequences for small bags of carbon and water somewhere in the universe? No it does not.

Do you know what your child is actually thinking when you harangue them for the umpteenth time? No, you don't.

Lack of privacy/privileged access to information has always been the byproduct of active human effort. The natural state of things, is for information to only effect it's immediate locality. I.e. privacy.

Lack of privacy; therefore is the political subject. Subtle difference, granted, but that subtlety belies the consequences of letting things get out of hand.

Excessive "awareness" is a problem. There are those that relish the thought for the power such systems confer; they chant

"I can make you safer!" "You lose nothing!" "There is no danger in this!" "It is just the sacrifice a Good Citizen should be expected to make for the Greater Good!"

However, once the check is written, does the government ever relinquish it's right to privacy?

Nay. National Security. Just trust us.

Never mind that the assertion that led to the sacrifice of the initial liberty was that there were those amongst us who couldn't be trusted.

Nay, sir, I agree with GP. The breach of fundamental rights (or imposition of obligation) is the matter of politics, and very infrequently do I see any credible case made where something as fundamental as breaking the confidentiality of the most efficient means of communication anything but a power grab, and eventual tool of tyrannical oppression.

Re: MITM on HTTPS traffic in Kazakhstan

#443

Earlier quoted context omitted.

What is the extent of the MITM attack that you can do with this certificate? Can you intercept all https traffic?

If a user trusts this root CA (~ "installs the certificate") then someone who controls the root can now make their MITM look like the real deal, because it's trusted. After all you've said you trust them. Whether you _should_ trust the authoritarian government of Kazakhstan is a policy issue. On its own the root does not magically intercept the traffic, so Kazakh ISPs will need to do a bunch of (potentially quite exp…

How do I know that NSA does not have one root certificate pre-installed in my browser?

Re: MITM on HTTPS traffic in Kazakhstan

#444
post #416

Earlier quoted context omitted.

> I don't know how this is legal even. Legality is secondary when you are punching up in a 3rd world country. (I am from India)

1. Please stop self-generalizing. This only leads to hopelessness, which is unwarrented since there's a huge amount of Internet-related activism in India, even more than the Western countries. 2. Plese stop using the label "Third-world". You are your own "first-world". There's better labels to describe yourself, namely "developing".

Well third world just means the country did not align with the US or USSR during the cold war. Though the concept has kinda changed meaning lately.

Re: MITM on HTTPS traffic in Kazakhstan

#445
Many of us already trust certificates we shouldn't be.

It's not even this blatant in most cases. About 6 countries have issued certificates for Google, India being one of them. And they all made use of the fact that they were part of the trusted root certificates on our systems.

https://www.quora.com/Why-are-HTTPS-requests-not-cacheable-b...

Re: MITM on HTTPS traffic in Kazakhstan

#446
post #443

Earlier quoted context omitted.

If a user trusts this root CA (~ "installs the certificate") then someone who controls the root can now make their MITM look like the real deal, because it's trusted. After all you've said you trust them. Whether you _should_ trust the authoritarian government of Kazakhstan is a policy issue. On its own the root does not magically intercept the traffic, so Kazakh ISPs will need to do a bunch of (potentially quite exp…

How do I know that NSA does not have one root certificate pre-installed in my browser?

Review and compile the browser yourself, or just trust that someone would have found it by now and trust that your browser vendor knows that and would never do it in the first place unless they wanted to kill their browser instantly

Re: MITM on HTTPS traffic in Kazakhstan

#447

Earlier quoted context omitted.

There are plenty of clients for letsencrypt, including even Bash ones. That should not be a problem.

Letsencrypt only issues certs for publicly accessible hosts. If you've got a bunch of intranet servers / REST services / whatever that are firewalled from the public internet, you're out of luck.

Thats incorrect, you can verify using DNS zone records, so the server can be as firewalled or air gapped as you want.

Re: MITM on HTTPS traffic in Kazakhstan

#448
post #15

Would someone with network access in Kazakhstan check if Caddy's MITM detector catches this please? https://caddyserver.com/docs/mitm-detection - or https://mitm.watch (Cloudflare's unofficial deployment of the same tech). If it does not, could you file a bug report with a complete packet capture (and exact browser version - multiple browsers are preferred)? https://github.com/caddyserver/caddy/issues (Edit: Reported…

In Russia on attempt to open https://mitm.watch I get provider's page with message "Requested IP is blocked"

Re: MITM on HTTPS traffic in Kazakhstan

#449

Earlier quoted context omitted.

In the meanwhile consider using Tor https://www.torproject.org . It has different transports transport plugins available if that will make the traffic look like regular traffic and not Tor traffic.

Tor has been blocked here for the last 10 (or so) years. You have to find and add a couple of bridge servers to get it working, until they get blocked as well, of course.

This is correct, but there are a couple of caveats.

As a reference - relays https://metrics.torproject.org/userstats-relay-country.html?... - bridges https://metrics.torproject.org/userstats-bridge-combined.htm... - ticket https://trac.torproject.org/projects/tor/ticket/20348

Noteworthy "I messaged the user my unpublished obfs4 bridge whose OR port is firewalled and the bridge is working so far". Also, the boxes don't seem to perform a good job in inspecting for protocols tunnelled over HTTPS (https://gitweb.torproject.org/pluggable-transports/httpsprox...).

Re: MITM on HTTPS traffic in Kazakhstan

#450
post #396

Earlier quoted context omitted.

Not really. NSA requests are backed by LE either directly or... extortion style. https://www.wired.com/2007/10/nsa-asked-for-p/

Allright. But they didn’t do it for all ~300M citizens though, did they?

https://en.m.wikipedia.org/wiki/Room_641A

They did it to everyone whose traffic transited ATT's backbone

Post reply on HN