Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

141–150 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#141

To not even be sure whether a website you visit, or a file you download is actually what its creator says it is, is like picking up an orange but the government secretly replaces it with an apple that contains almost no vitamin C in it at all. You have the right to seek out and eat an orange for your immune system and survival, and no government should have the right to interfere with that, at any time. This law is a…

> Whoever proposed it should be ashamed of themselves

Name and shame: Interior Minister Horst Seehofer of the conservative-authoritarian CSU. He and his party friends are who want this.

We have the chance to kick them out of office in 2021, it's time for the stranglehold of Conservative internet-printers (Internetausdrucker, a German word for tech illiterates) as Interior Ministers to end once and for all.

Re: New German law would force ISPs to allow secret service to install trojans

#142

Earlier quoted context omitted.

Google, Mozilla, et al. should make a commitment to revoke the trust of any CA that is found to partake in behavior like that. Even retroactive revocation of existing certificates shouldn't be off the table if the offense is egregious enough. It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me…

Browsers blacklisted Kazakhstan government certificate used for MITM which was not even trusted. It is absurd to expect anything less than blacklisting such a CA immediately. Certificate transparency is required for all certificates since April, 2018, so you can't really issue rogue certificate.

Here's the Bugzilla report where they actually request their root be added to Firefox:

https://bugzilla.mozilla.org/show_bug.cgi?id=1232689

The answer is basically "no".

Re: New German law would force ISPs to allow secret service to install trojans

#143
post #73

My guess is that Germany will lose its web hosts as no one will trust to host anything in that country if this passes.

Snowden uncovered astonishing breaches of Trust in the US, has there been a major loss of Hosts here?

Nope, everyone happily shovels all of their data, as well as all of the data their customers provide them, into AWS, which is very cosy with the US military.

You can be reasonably certain that anything in AWS is available to US military intelligence without judicial oversight.

Re: New German law would force ISPs to allow secret service to install trojans

#144
post #124
post #107

Earlier quoted context omitted.

DNS usually isn’t, and TLS still runs over TCP, which is vulnerable to this type of hijacking, so yes, it is indeed still relevant due to both resolution as well as transport layer. NSA would be very bad at their job indeed if they couldn’t issue valid TLS certificates for any domain to themselves.

>NSA would be very bad at their job indeed if they couldn’t issue valid TLS certificates for any domain to themselves. Is there any evidence of this? With certificate transparency being mandatory a few years ago, you'd think that the NSA would be caught at least once.

The NSA released a who-knows-how-many-day in crypto32.dll to Microsoft recently that allows one to bypass app/driver EC certificate verification. It’s called CVE-2020-0601.

My assumption is that they had it for years and released it for patching the moment they detected anyone else using it.

https://www.cbronline.com/cybersecurity/crypt32-dll-vulnerab...

It’s not TLS, but it’s close. I still think they’d be bad at their job if they didn’t have some method of getting valid certs, and I don’t think they are bad at their job. With bulk collection they may be able to spoof replies to LE DNS verification. There are lots of avenues.

Re: New German law would force ISPs to allow secret service to install trojans

#145
post #129
post #110

Earlier quoted context omitted.

> It does not matter if Germany is not ruled by an autocratic regime at the moment I totally get the appeal of that argument, but it completely breaks down once I ask myself how much that autocratic bogeyman regime, once it got into power, would feel bound by privacy protections put in place by their predecessors.

The question is rather: can they use preestablished structures and machinery or do they need to build it from the ground up. Surveilance also needs work, and its less work if everything is prepared.

my point was more: any liberal social democratic society that subjects itself to every increasing censorship and surveillance will devolve towards totalitarianism.

Re: New German law would force ISPs to allow secret service to install trojans

#147
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

For many things there isn't really need to get the payload. Get the IP addresses, DNS lookups and TLS SNI information and correlate to information gathered from elsewhere and you can derive a lot.

You can derive a lot just from the set of IP addresses accessed, even if those IPs are cloud/CDN providers:

"What can you learn from an IP?" https://irtf.org/anrw/2019/slides-anrw19-final44.pdf

Re: New German law would force ISPs to allow secret service to install trojans

#148

Earlier quoted context omitted.

+1 Hopefully DNS over tls and new sni encryption standards will put an end to all this in next 5-10 years

+1 for the optimism, but unfortunately even with those mitigations it is not enough. Using a VPN in combination with DoT/H is currently best practice I believe.

Even multi-layer VPNs or Tor leak data via global correlation attacks. We need VPNs and Tor to start doing network bandwidth padding.

Re: New German law would force ISPs to allow secret service to install trojans

#149

Earlier quoted context omitted.

Well, as far as I know, all of these countries have political systems in which representatives are supposed to act on the behalf of the people. Basically, we can't all work full time to understand every political thing, and vote on them all, so we have someone do it for us: a representative. Representatives very rarely represent themselves, and are almost always representing either powerful people ( often through lob…

Why they are so scared of citizenry though? Anyone that is criminal or really needs security will just use Faraday Cages with disconnected computers. Literally there is nothing they can do against big league criminals with this much mass surveillance, so only logical conclusion is that this is only intended for use on citizenry.

I've tried to explain my thoughts on this before, so I'll give it the ol college try again.

I propose that the decentralized anarchistic, freedom of thought nature of the internet has essentially forced an acceleration the timetables for the totalitarian dystopian system.

The internet caught the oligarchs off guard, in the big scheme of things (the oligarchs make plans that their grandchildren execute)... and it took them a bit to catch up, and they now see it as the primary threat to their otherwise nearly total control of the mass consciousness. Think of every medium of communication, and see how it was more or less captured and controlled, whether it be print, radio, or television, and see that although heavily under attack, the internet is still very free, at least at it's core.

This creates a sort of arms race where the oligarchs must corrupt, control and compromise it faster than it can respond in a way that reveals enough of the truth to the masses that they risk some sort of neo-peasants revolt. In that goal they will use their already long tendrils into government and corporate ownership networks et al to accomplish the task. I could get into the nitty gritty, but that's the meta summary.

Surveillance is about control, not about security, but they have gotten very good at the Oxford debate posing that it is. (lamentations about the end of the nation state actor security threat for one)

Re: New German law would force ISPs to allow secret service to install trojans

#150
post #148

Earlier quoted context omitted.

+1 for the optimism, but unfortunately even with those mitigations it is not enough. Using a VPN in combination with DoT/H is currently best practice I believe.

Even multi-layer VPNs or Tor leak data via global correlation attacks. We need VPNs and Tor to start doing network bandwidth padding.

Yes, I agree. Is there anything we can do in the meantime?
Post reply on HN