Live data from Hacker News

Identifying Airtel middleboxes that censor HTTPS traffic

iamkush.me

61–70 of 130 posts

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#61

Earlier quoted context omitted.

The Great Firewall does not block TLS 1.3. You may have seen headlines which claim it does, but they're based on a report that actually says it doesn't. Remember journalists probably know even less than you do about most things they write about! In this case the report says the Great Firewall was determined to block the following specific combination: * A ClientHello for TLS 1.3 that * Includes the 0xffce extension v…

While all of the above is correct, it doesn't stop the GFW from implementing per flow based DPI that drops traffic, or throttles it to a throughput that is so slow as to be unusable, based on detection of consistent encrypted flows between an IP that is outside of China, and domestically within China. The one thing TLS1.3 with ESNI is not is hard to detect. It's a consistent traffic pattern if you throw a sufficient…

They're already doing massive flow sampling at the GFW complexes today. They can police down to individual flows if they want to. They scale wide by distributing out traffic based upon src or dst IP.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#62

Earlier quoted context omitted.

All well and good, but are these kind of 'middleboxes' unequivocally unethical? For example, some ISPs might want to block highly illegal content - let's use the typical examples, e.g. child porn sites, malware domains, and so on. It's not inherently unethical (or, at least, there are plenty of reasonable people who would say it is ethical) to install a middlebox that will make it more difficult for users to access t…

> let's use the typical examples, e.g. child porn sites, malware domains a futile game of whack-a-mole that only serves to make politicians feel good, and so they can claim they're "doing something" about social threats. malware domains can be adequately addressed at the application level through things such as: https://www.google.com/search?channel=fs&client=ubuntu&q=goo...

Devil's advocate response: If these content blockers are just 'futile games of whack-a-mole', then why are you getting up-in-arms about their existence? Should be easy to avoid them if you truly believe what you say.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#63
post #60

Earlier quoted context omitted.

My job overlaps with microwave and millimeter wave RF engineering somewhat. R&S also has no qualms about selling high-end spectrum analysis equipment to authoritarian regimes. Probably done through middlemen. For instance, you can find the Iranian government using their equipment in Tehran to hunt down things they don't like. To be fair, there's probably less than ten manufacturers of their category of spectrum analy…

Interesting, so triangulating people forwarding "open" internet over consumer-grade microwave (like Ubiquiti or similar)? I assume they can't do much about Toosheh since it's "read only", multiplexed with legitimate TV channels on the same transponder, and uplinked from the UAE.

Things that transmit generally, in all sorts of bands, lots of countries where the government holds an armed monopoly on connections to the outside world.

Try setting up an independent two-way satellite based C or Ku band earth station in Ethiopia, offer service to your neighbours and armed men will come to dismantle it.

Commercial spectrum analysis tools are an essential and important things in the hands of network engineers, but also a tool to crack down on anything that transmits that an authoritarian regime doesn't like.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#64

Earlier quoted context omitted.

> let's use the typical examples, e.g. child porn sites, malware domains a futile game of whack-a-mole that only serves to make politicians feel good, and so they can claim they're "doing something" about social threats. malware domains can be adequately addressed at the application level through things such as: https://www.google.com/search?channel=fs&client=ubuntu&q=goo...

Devil's advocate response: If these content blockers are just 'futile games of whack-a-mole', then why are you getting up-in-arms about their existence? Should be easy to avoid them if you truly believe what you say.

Stuff like what the UK is trying to do with a DNS based "black list" of bad things on the internet? Futile game of whack a mole.

Authoritarian regime that forces all ISPs in a country to run networks funnelling all traffic through a government run central point where they do DPI and flow analysis on it (Chinese GFW for instance)? More of a real threat.

For instance there is one ASN in Iran that has transit connections to the outside world. All ISPs are forced to be downstream of it. https://bgp.he.net/AS12880

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#65

Earlier quoted context omitted.

> let's use the typical examples, e.g. child porn sites, malware domains a futile game of whack-a-mole that only serves to make politicians feel good, and so they can claim they're "doing something" about social threats. malware domains can be adequately addressed at the application level through things such as: https://www.google.com/search?channel=fs&client=ubuntu&q=goo...

Devil's advocate response: If these content blockers are just 'futile games of whack-a-mole', then why are you getting up-in-arms about their existence? Should be easy to avoid them if you truly believe what you say.

Because they create tools governments will use to restrict legitimate speech and freedoms. As history has shown they do.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#66

On a meta level, this is one of the reasons why I tell every junior/entry level person I encounter in the ISP business the following: Ethics is important in network engineering. You can and should refuse to do things that cause measurable harm to the Internet. You should understand why certain things are bad, and should make a conscious choice not to aid and abet them. It is regretful that organizations like NANOG, R…

All well and good, but are these kind of 'middleboxes' unequivocally unethical? For example, some ISPs might want to block highly illegal content - let's use the typical examples, e.g. child porn sites, malware domains, and so on. It's not inherently unethical (or, at least, there are plenty of reasonable people who would say it is ethical) to install a middlebox that will make it more difficult for users to access t…

> some ISPs might want to block highly illegal content

There is no way - not even a theoretical way - to allow blocking of illegal content (for any definition of illegal) that won't allow for blocking of any other arbitrary content. Censorship is binary. You can accept either none of it, or all of it.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#67

Earlier quoted context omitted.

Devil's advocate response: If these content blockers are just 'futile games of whack-a-mole', then why are you getting up-in-arms about their existence? Should be easy to avoid them if you truly believe what you say.

Because they create tools governments will use to restrict legitimate speech and freedoms. As history has shown they do.

...So, again, they can't be 'futile games of whack-a-mole', if they work, then?

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#68

Earlier quoted context omitted.

Devil's advocate response: If these content blockers are just 'futile games of whack-a-mole', then why are you getting up-in-arms about their existence? Should be easy to avoid them if you truly believe what you say.

Because they create tools governments will use to restrict legitimate speech and freedoms. As history has shown they do.

Create and normalize. "What's one more site to denylist?"

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#69

On a meta level, this is one of the reasons why I tell every junior/entry level person I encounter in the ISP business the following: Ethics is important in network engineering. You can and should refuse to do things that cause measurable harm to the Internet. You should understand why certain things are bad, and should make a conscious choice not to aid and abet them. It is regretful that organizations like NANOG, R…

It'd be nice if we could address some things like BCP38 (anti spoofing), RPKI, route filtering and folks who knowingly support infrastructure that's used for outbound ddos (c2s and regular hosts), spam and malware phishing. Plenty of hosting shops in US and Canada have these problems. That seems a bit more within our reach whereas an ISP in India is more than happy to pay a vendor to implement middlebox packet molesters.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#70

Earlier quoted context omitted.

All well and good, but are these kind of 'middleboxes' unequivocally unethical? For example, some ISPs might want to block highly illegal content - let's use the typical examples, e.g. child porn sites, malware domains, and so on. It's not inherently unethical (or, at least, there are plenty of reasonable people who would say it is ethical) to install a middlebox that will make it more difficult for users to access t…

> some ISPs might want to block highly illegal content There is no way - not even a theoretical way - to allow blocking of illegal content (for any definition of illegal) that won't allow for blocking of any other arbitrary content. Censorship is binary. You can accept either none of it, or all of it.

At some level, everywhere has some form of censorship. For any country you could name, there are, or could easily be, content in any kind of media - books, audio, video, games, whatever, that is so abhorrent that it would either not be published, or would be shut down as soon as possible.

So if you say censorship is binary, it's already here, and has been here for ever. But I would guess that few believe that censorship is truly binary like you say.

Post reply on HN