Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

61–70 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#61

Earlier quoted context omitted.

Backbones appear to be included.

Possibly, but it's much harder to intercept and mitm specific traffic at that level. On the ISP-side, that's different: they can with high certainty say that some traffic is coming from/to a specific suspect, much like a phone surveillance. This might also apply to individual service, e.g. an email provider.

I think you can collect a lot of good data for law enforcement purposes by tapping datacenter networks. Remember the NSA's "SSL added and removed here :-)" slide?

Raise your hand if you use TLS between your database server and your web frontend. Keep your hand up if you rotated that certificate in the last month. Keep your hand up if you know whether your database's certificate has been tampered with. (i.e. do you check that it's signed by your internal CA? Then who is signing it? Who maintains the ca-certs package? What does the certificate verification code even look like?)

No hands up? Good! The government thanks you for your service. Keep doing what you're doing, they'll keep you safe.

Re: New German law would force ISPs to allow secret service to install trojans

#62
post #4

"will" = "according to a proposed law", but sadly par for the course for our governments to push this kind of thing through, even if a good chunk of their surveillance laws get eaten by the constitutional court. (Maybe we should have a rule that you can't be in politics anymore if multiple of the laws you supported were found to be unconstitutional? ...)

Well in theory that's what elections are for. But majority of the population doesn't seem to bother that much about those things and elects conservatives again and again. Need to raise awareness on these topics ... but unfortunately our opposition is split between crazy wannabe populists, a green party trying hard not to loose momentum by bringing up "critical" topics and a weak liberal party with a leader who's mostly there for being joked about. (Yeah, yeah, ignorant and simplified classification)

Re: New German law would force ISPs to allow secret service to install trojans

#63
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

For many things there isn't really need to get the payload. Get the IP addresses, DNS lookups and TLS SNI information and correlate to information gathered from elsewhere and you can derive a lot.

Re: New German law would force ISPs to allow secret service to install trojans

#64
post #12

FYI: pervasive mass internet surveillance by the US military with the active cooperation of large US telcos AT&T, Verizon, and others already enables this capability in the US and much of the rest of the world. The surveillance allows them to read the TCP sequence numbers or DNS query IDs, and then spoof valid response packets. It’s called QUANTUMINSERT. https://blog.fox-it.com/2015/04/20/deep-dive-into-quantum-in...

Is this relevant since nearly everything is https these days?

Re: New German law would force ISPs to allow secret service to install trojans

#65

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

>Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. Because they're not necessarily contradictory. This doesn't just give secret services a blank cheque to spy on everyone, it just provides intelligence agencies with a tool. I'm German and I don't object in principle to the fact that intelligence, under supervision of the govern…

They can wiretap, sure, but they can’t practically compel you to give up your book cipher.

Re: New German law would force ISPs to allow secret service to install trojans

#66
post #29
post #26

Earlier quoted context omitted.

This has nothing to do with NetzDG. If he would have spewed something of that caliber openly on the street he would've had to expect the same thing (depending on where in Germany of course). That there is no "free speech" in Germany in respect to hatespeech has been the case pre-internet too. I'm not a big fan of NetzDG, but I also have to say that I expected much worse censorship-wise when it passed and I haven't he…

You can do many things: You can pass those laws, put people in jail, make up the term "hate speech" and condemn everyone who does that. But you can not say that we have internet (or any other) freedom in Germany. There is some nice english proverb about a cake and eating it too

There are more parts to freedom than just freedom of speech.

Re: New German law would force ISPs to allow secret service to install trojans

#67
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

For many things there isn't really need to get the payload. Get the IP addresses, DNS lookups and TLS SNI information and correlate to information gathered from elsewhere and you can derive a lot.

+1 Hopefully DNS over tls and new sni encryption standards will put an end to all this in next 5-10 years

Re: New German law would force ISPs to allow secret service to install trojans

#68
post #29

Earlier quoted context omitted.

You can do many things: You can pass those laws, put people in jail, make up the term "hate speech" and condemn everyone who does that. But you can not say that we have internet (or any other) freedom in Germany. There is some nice english proverb about a cake and eating it too

You can try to argue that certain things aren't "hate speech" but I don't understand how you can claim it to be a made up term. Hate is a real thing and if you channel that into certain language you get hate speech, plain and simple. Germany has an interesting history with regards to what various constituents view as protected speech. As someone who hasn't lived in Germany I freely admit that I have a limited view of…

hate itself is real - a word that has a negative connotation, but was never illegal in itself. You could always hate a person or a football club. That word was taken, rebranded to include among other things everything critical of government and made illegal. That's why hate speech is made up. What is called hate speech today was called a rant, "hot take", an insult or whatever just a couple of years ago. Today we literally have a law against "hate crime" - another doubleplusgood word. These things are not real, they're tools to oppress a critical population. Also note that even true things fall under those "crimes". It doesn't matter if what you say is true as long as it's "insulting" to someone.

Re: New German law would force ISPs to allow secret service to install trojans

#69

VPN service providers can expect a pretty good future for them (not only with this, but also the new EU copyright guidelines).

And Tor.

https://metrics.torproject.org/rs.html#search/country:de

This shows 1,648 relays potentially having their traffic monitored under this law. Out of 6,432 relays, that makes up more than 25% of all Tor relays.

Unfortunately, Tor's design doesn't really go far enough in protecting against adversaries with large swaths of visibility. Perhaps it's time for people to begin shifting to I2P, or some other overlay network with more resilience against these types of adversaries.

Edit: This page gives you a nice visual representation of how much that consists of. Germany is the big one. https://metrics.torproject.org/bubbles.html#country

Re: New German law would force ISPs to allow secret service to install trojans

#70
post #40
post #31

Earlier quoted context omitted.

They just have to hijack one existing CA that's within their jurisdiction and force it to issue MITM certs. Key pinning or certificate transparency may mitigate this. Or the MITM box could use some kind of HTTP downgrade attack and not worry about certificates at all.

That would "burn" the CA (it will be removed and/or blacklisted from every major browser and operating system once it's exposed, and exposing it gets much easier with the recent push towards certificate transparency), so it can only be done once per CA.

After first try all german CAs may get removed so probably once ever
Post reply on HN