Live data from Hacker News

Thai Database Leaks 8.3B Internet Records

rainbowtabl.es

41–50 of 79 posts

Re: Thai Database Leaks 8.3B Internet Records

#41
post #20

There is a special place in hell for software developers who write server software with no authentication by default.

I think you will find that place quite empty, today and in the future.

The other place, where "product owners" and pointy haired managers mingle - that place will be quite crowded when their TTL expires.

Re: Thai Database Leaks 8.3B Internet Records

#42
post #7

Solution for this is to tunnel the traffic through encrypted connection to servers in countries that respect persons privacy(if that is true nowadays). The easiest way is to use WireGuard, easy to set up uses only one port and have clients for many devices.

If you trust your vps dns, easiest way would be autossh -D and set your browser's socks5 proxy to localhost: and tell it to use remote dns when resolving domains. This requires no wireguard setup, no certificate generation or anything.

WireGuard doesn't use certificates it works similar way to SSH with keys, also they have open source clients for Android and iOS a few clicks configuration

Re: Thai Database Leaks 8.3B Internet Records

#43
post #40
post #25

Earlier quoted context omitted.

You don't even need that to be useful though. In my tinpot banana republic (Australia) ISP metadata retention is required by law, and warrantless access to that is granted to organisations involved in fighting terrorism, child abuse, and other serious crimes - and those agencies include local councils, animal control, the taxi commission, and various horse racing oversight organisations... :sigh: Even moving your met…

Isn't the official language in Belize is English? Aren't South America's routers accessible by the agencies collaborating with the US Govt.?

Maybe, and quite likely. I considered using Moldovia as my example jurisdiction instead, but Belize has some nice cachet and backstory to add appropriate colour and context to a rant.

Still gonna put off the local dog catcher who's trying to work out if I'm video chatting with his ex girlfriend...

(If _actual_ FVEY or equivalent national security agencies are curious about me, I'm pragmatic enough to know none of my tradecraft live action role playing is gonna make any difference at all. I could buy some magical amulets, fake my own death, and live in a submarine. I am still gonna be Mossad'ed upon... I'll avoid running shipping containers full of drugs/weapons/children across international borders, and try to keep my harshest criticism of the Saudi/Trump Royal families to myself...)

Re: Thai Database Leaks 8.3B Internet Records

#44
post #34
post #2

> To be clear: DoH and/or DoT would have stopped the gathering of DNS query data in this case. It's simple to set up, and it's just a smart thing to do for anyone concerned about their privacy. Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist. Unless this feature starts being turned on by default in routers and popular…

Most malicious ISPs disable DoH (ex: Verizon) so it likely wouldn’t have solved this. If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.

How can they disable DoH? That's Dns over HTTPS.

Re: Thai Database Leaks 8.3B Internet Records

#45
post #34

Earlier quoted context omitted.

Most malicious ISPs disable DoH (ex: Verizon) so it likely wouldn’t have solved this. If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.

How do they disable DoH? They block TLS over that port?

Thats DoT, DoH ist just a dns query over https(443)

Re: Thai Database Leaks 8.3B Internet Records

#46
post #42

Earlier quoted context omitted.

If you trust your vps dns, easiest way would be autossh -D and set your browser's socks5 proxy to localhost: and tell it to use remote dns when resolving domains. This requires no wireguard setup, no certificate generation or anything.

WireGuard doesn't use certificates it works similar way to SSH with keys, also they have open source clients for Android and iOS a few clicks configuration

You don't generate a key pair to share with the client? How does that even work when you want to disable a key or set a password?

Re: Thai Database Leaks 8.3B Internet Records

#47
post #42

Earlier quoted context omitted.

WireGuard doesn't use certificates it works similar way to SSH with keys, also they have open source clients for Android and iOS a few clicks configuration

You don't generate a key pair to share with the client? How does that even work when you want to disable a key or set a password?

What i meant generating keys is not equal to generating certificate in the common sense of this word, it only works with randomly generated keys , passwords are not save way to encrypt data unless you can remember random sequence of characters for every client you have. If look at WireGuard protocol will get all the answares.

Re: Thai Database Leaks 8.3B Internet Records

#48
post #11

Earlier quoted context omitted.

DoH just moves the logging from Thai telecom and moves it to Cloudflare (or, whoever you set up as your DoH server, but most likely Cloudflare), no? I trust CF much more than my ISP, but it makes the potential leak much worse... edit: On the other hand, DoH makes DNS requests independent of ISP, which is nice. ISPs are often monopoly by nature.

Cloudflare has a privacy policy https://developers.cloudflare.com/1.1.1.1/privacy/public-dns... Obviously, for Thai users this is a reasonable option, but I would understand why American users would not want to use Cloudflare, Google or even Quad9, as these are all US-based.

The netflow data from cloudflare, which is 0.05% of all traffic, is retained for 60 days according do the compliance report. 8.3B log entries is a lot, but I suspect that given how large market share cloudflare has, 0.05% over 60 days is also not a small data set. My intuition with probability calculus make me suspect that given normal internet usage over 60 days, a person is more likely than not to end up in cloudflares netflow log.

Re: Thai Database Leaks 8.3B Internet Records

#49
post #43
post #40

Earlier quoted context omitted.

Isn't the official language in Belize is English? Aren't South America's routers accessible by the agencies collaborating with the US Govt.?

Maybe, and quite likely. I considered using Moldovia as my example jurisdiction instead, but Belize has some nice cachet and backstory to add appropriate colour and context to a rant. Still gonna put off the local dog catcher who's trying to work out if I'm video chatting with his ex girlfriend... (If _actual_ FVEY or equivalent national security agencies are curious about me, I'm pragmatic enough to know none of my…

Oh. It's quite enough to express your opinions.
Post reply on HN