Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

31–40 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#31

Is it possible to modify HTTPS traffic? Wouldn't they have to replace the CA certs on the target machine first before being able to modify that traffic?

They just have to hijack one existing CA that's within their jurisdiction and force it to issue MITM certs. Key pinning or certificate transparency may mitigate this.

Or the MITM box could use some kind of HTTP downgrade attack and not worry about certificates at all.

Re: New German law would force ISPs to allow secret service to install trojans

#32

My guess is that Germany will lose its web hosts as no one will trust to host anything in that country if this passes.

It's primarily about ISPs, not data centers. Your servers are typically secured with SSL.

Backbones appear to be included.

Re: New German law would force ISPs to allow secret service to install trojans

#33
post #13
post #11

"Sollen" translates to "should" and not "will" That means there is a element of uncertainty there whether they actually will.

Actually it translated to "have to", not "should" (which would more properly be "sollten").

I'm learning German at a fairly low level so I ask this from the perspective of wanting to learn, not as a challenge.

Wouldn't "have to" be "müssen"? In what cases would you use "sollen" to have a similar meaning?

And "sollten" is either Präteritum or Konjunctive II, which as I understand it would both mean "should have", though in different senses. Why is that a more proper translation of "should"?

Re: New German law would force ISPs to allow secret service to install trojans

#34
post #6

Mods: This is an article about a proposed law, so "will" isn't really an accurate reflection (yet, or hopefully at all) and the title should be changed. My proposal: "New German law would force ISPs to redirect traffic to intelligence services for trojan install" (if that is not to long).

Yes, you are right, but the current title is just 2 chars under the limit and I couldn't think of a shorter one. Sorry for the somewhat misleading "will".

My somewhat lame excuse: The law will most probably pass, current govt is a coalition of the two largest parties with overwhelming majority and absolutely no clue about anything digital.

Edit: would "shall" work instead of "will"?

Re: New German law would force ISPs to allow secret service to install trojans

#36

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

By no means. The Stasi was active in the GDR (German Democratic Republic, "East Germany"), and it is not as if those from the east are particularly watchful for state-instigated surveillance.

This predates the wall, but the wall only confirmed what was going on beforehand.

Re: New German law would force ISPs to allow secret service to install trojans

#37
post #11

"Sollen" translates to "should" and not "will" That means there is a element of uncertainty there whether they actually will.

Yes, you are right, I'm sorry for the somewhat misleading translation. But I felt "should" instead of "must" would be more confusing, because that would sound somewhat like "the author would like that". Which he definitely doesn't. Anything longer wouldn't have fit the limit.

Re: New German law would force ISPs to allow secret service to install trojans

#38
post #5

"will" isn't the exact translation of the headline, the idea is written in an upcoming law that will be discussed (or rubber-stamped?) next Wednesday...

Probably rubber-stamped. But you are right, my translation is confusing. I'm very sorry.

Re: New German law would force ISPs to allow secret service to install trojans

#39
post #34
post #6

Mods: This is an article about a proposed law, so "will" isn't really an accurate reflection (yet, or hopefully at all) and the title should be changed. My proposal: "New German law would force ISPs to redirect traffic to intelligence services for trojan install" (if that is not to long).

Yes, you are right, but the current title is just 2 chars under the limit and I couldn't think of a shorter one. Sorry for the somewhat misleading "will". My somewhat lame excuse: The law will most probably pass, current govt is a coalition of the two largest parties with overwhelming majority and absolutely no clue about anything digital. Edit: would "shall" work instead of "will"?

What about "may"?

Re: New German law would force ISPs to allow secret service to install trojans

#40
post #31

Is it possible to modify HTTPS traffic? Wouldn't they have to replace the CA certs on the target machine first before being able to modify that traffic?

They just have to hijack one existing CA that's within their jurisdiction and force it to issue MITM certs. Key pinning or certificate transparency may mitigate this. Or the MITM box could use some kind of HTTP downgrade attack and not worry about certificates at all.

That would "burn" the CA (it will be removed and/or blacklisted from every major browser and operating system once it's exposed, and exposing it gets much easier with the recent push towards certificate transparency), so it can only be done once per CA.
Post reply on HN