Live data from Hacker News

Thai Database Leaks 8.3B Internet Records

rainbowtabl.es

61–70 of 79 posts

Re: Thai Database Leaks 8.3B Internet Records

#61
post #19

Earlier quoted context omitted.

(Disclosure: I'm Thai) Especially in Thailand, where free speech is almost non-existent. Few months ago there were Twitter user who goes by the name "Anonymous" ("นิรนาม" in Thai) who have been arrested for spreading fake news and being a threat to the country. The Twitter user mainly tweets about topics subjected to lèse-majesté law. He never leave any traces, which leaves question on how officials managed to track…

But aren't all the URLs in the messages/notifications "shortened" to a t.co/. So he would have had to click on the link.

This was also why everyone believed it's unlikely. Also I don't think Twitter even has DNS prefetching turned on. However now it's revealed that logging is real, us Thais should be worried.

Re: Thai Database Leaks 8.3B Internet Records

#62
post #48

Earlier quoted context omitted.

The netflow data from cloudflare, which is 0.05% of all traffic, is retained for 60 days according do the compliance report. 8.3B log entries is a lot, but I suspect that given how large market share cloudflare has, 0.05% over 60 days is also not a small data set. My intuition with probability calculus make me suspect that given normal internet usage over 60 days, a person is more likely than not to end up in cloudfl…

> a person is more likely than not to end up in cloudflares netflow log. They are, but because this is all Cloudflare's 1.1.1.1 service does, that log only tells you that the IP address used Cloudflare's service. So whereas this Thai data more or less says e.g. You watched Netflix between 18:40 and 19:26 and then again 21:33 to 22:09 the Cloudflare data says you own a device that uses Cloudflare's 1.1.1.1 DNS service…

If the attacker also have access to the anonymized data set which is stored for 25hrs they should be able to deanonymize quite a bit of the data by just comparing time stamps and finding patterns.

It is much better than just having normal logs laying around, and since the data is split in two data set, there is a possibility that having access to one does not automatic result in having access to the other. The dilution is also helpful, through I am uncertain to the extent given the amount of traffic generated.

Re: Thai Database Leaks 8.3B Internet Records

#63
post #45

Earlier quoted context omitted.

Thats DoT, DoH ist just a dns query over https(443)

Alright, I repeat my question, since it's almost identical: how do they block that? HTTPS starts with opening a TLS socket, how do they reliably determine that they can drop that traffic?

I don't think they do that.

Re: Thai Database Leaks 8.3B Internet Records

#64
post #55

Earlier quoted context omitted.

Alright, I repeat my question, since it's almost identical: how do they block that? HTTPS starts with opening a TLS socket, how do they reliably determine that they can drop that traffic?

I don't know if Verizon is actively doing it, but since most providers that offer DoH have well-known IPs, like 8.8.8.8, 1.1.1.1, 9.9.9.9, they could easily just block traffic heading in that direction.

[deleted]

Re: Thai Database Leaks 8.3B Internet Records

#65
post #11

Earlier quoted context omitted.

DoH just moves the logging from Thai telecom and moves it to Cloudflare (or, whoever you set up as your DoH server, but most likely Cloudflare), no? I trust CF much more than my ISP, but it makes the potential leak much worse... edit: On the other hand, DoH makes DNS requests independent of ISP, which is nice. ISPs are often monopoly by nature.

Cloudflare has a privacy policy https://developers.cloudflare.com/1.1.1.1/privacy/public-dns... Obviously, for Thai users this is a reasonable option, but I would understand why American users would not want to use Cloudflare, Google or even Quad9, as these are all US-based.

Is a privacy policy worth anything? Genuinely wondering, can they be sued, etc, if they violate it and claim "Oops, we made a mistake and our data got leaked".

For example Facebook probably said they would keep your data secure, but their system to prevent abuse from 3rd party "Quiz" developers was "Developer, by clicking here you agree not to abuse the data you can access."...

Re: Thai Database Leaks 8.3B Internet Records

#66
post #9
post #4

Earlier quoted context omitted.

I recently set up a dns-over-https (doh) proxy on my router to forward dns requests to 5 resolvers, that also use dnssec. I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server). I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.

Have you been able to find a trustworthy public DoT resolver? I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?

OpenNIC has a few servers supporting either DoH or DoT or both.

Re: Thai Database Leaks 8.3B Internet Records

#67
> Interestingly enough AWN had this DNS dashboard saved with a filter specifically looking at Facebook traffic. It's unclear why they would be particularly interested in who was going to Facebook.

One likely non-malicious explanation is that the telco is offering some plan with data caps based on social media such as instagram, facebook, etc. Searching around, I found the offering below for unlimited data on 9 social media apps http://www.ais.co.th/one-2-call/simcard/en/super_social.html...

I'm guessing one way the telco implements the selective cap is by tracking user's DNS, and is probably interested to know traffic to facebook

Re: Thai Database Leaks 8.3B Internet Records

#68
post #39
post #33

Earlier quoted context omitted.

Yes, well i trust this one: DoT: dns.digitale-gesellschaft.ch DoH: dns.digitale-gesellschaft.ch/dns-query Source: https://de.wikipedia.org/wiki/DNS_over_HTTPS https://de.wikipedia.org/wiki/DNS_over_TLS https://www.digitale-gesellschaft.ch/dns/ Sorry, for not being available in the en-wiki

Hadn't seem them before, very interesting. Vielen dank.

Just a year old and located in Zurich,

Re: Thai Database Leaks 8.3B Internet Records

#70
post #55

Earlier quoted context omitted.

Alright, I repeat my question, since it's almost identical: how do they block that? HTTPS starts with opening a TLS socket, how do they reliably determine that they can drop that traffic?

I don't know if Verizon is actively doing it, but since most providers that offer DoH have well-known IPs, like 8.8.8.8, 1.1.1.1, 9.9.9.9, they could easily just block traffic heading in that direction.

This follows along with what I read, at first it’s easy to block but it’s a losing proposition because anyone can stand up a doh server (which is also a network security nightmare)
Post reply on HN