Live data from Hacker News

Identifying Airtel middleboxes that censor HTTPS traffic

iamkush.me

121–130 of 130 posts

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#121

Earlier quoted context omitted.

> let's use the typical examples, e.g. child porn sites, malware domains a futile game of whack-a-mole that only serves to make politicians feel good, and so they can claim they're "doing something" about social threats. malware domains can be adequately addressed at the application level through things such as: https://www.google.com/search?channel=fs&client=ubuntu&q=goo...

Devil's advocate response: If these content blockers are just 'futile games of whack-a-mole', then why are you getting up-in-arms about their existence? Should be easy to avoid them if you truly believe what you say.

Because whacking even 5% of moles looking for ways around government[0] censorship is a unconscionable travesty.

0: eg, China, Iran, etc; if you don't think people getting caught is a problem then I question your basic human decency; if you don't think 5% of people getting caught is a problem then I question your sense of scale and/or ability to multiply numbers by other numbers.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#122
post #99
post #69

Earlier quoted context omitted.

It'd be nice if we could address some things like BCP38 (anti spoofing), RPKI, route filtering and folks who knowingly support infrastructure that's used for outbound ddos (c2s and regular hosts), spam and malware phishing. Plenty of hosting shops in US and Canada have these problems. That seems a bit more within our reach whereas an ISP in India is more than happy to pay a vendor to implement middlebox packet molest…

I've been dealing with a ban evader/forum shock image spammer for months now, and the place he is buying proxies from is actively doing BGP hijacking on resources owned by AT&T, Windstream, hospitals and universities - for the primary purpose of carding and fraud. I haven't managed to get anyone knowledgeable at those companies to figure out how to pressure the small upstreams (that are not those T1s) to stop it.

Could you drop some IP prefixes you believe are hijacked and timestamps? I can probably help out and bring this to folks who can take action.

(I have to deal with hijacks frequently and part of our investigation is beating on folks who have permissive filters and pressuring their peers to improve things)

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#123

Earlier quoted context omitted.

Censorship is fine if it's opt in. I don't use facebook and censor myself from it. I opt in to use a pihole and adblocker. It filters many things I otherwise would see. You can't often choose your ISP so this makes it extra important for censorship of any kind of to be opt in rather than forced.

My kids will not opt-in to censoring "Thomas the Train" videos when they should be doing their school work. I think I just got everyone to take a step down the slippery slope.

> I think I just got everyone to take a step down the slippery slope.

Hi! Counterexample here!

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#124
post #99

Earlier quoted context omitted.

I've been dealing with a ban evader/forum shock image spammer for months now, and the place he is buying proxies from is actively doing BGP hijacking on resources owned by AT&T, Windstream, hospitals and universities - for the primary purpose of carding and fraud. I haven't managed to get anyone knowledgeable at those companies to figure out how to pressure the small upstreams (that are not those T1s) to stop it.

I'm about to start down a road that might lead to where you are, but my target audience is a bit more mature and laid back so it might not be an issue. But what you said reminded me of a conversation we had here a month ago. I think it may be that I reserve image upload functionality for users who have proven their humanness (and their humanity). In my case image quality matters much more than quantity, so I can affo…

One forum that almost entirely eliminated trolling is the (now 20 year old!) Metafilter, which requires a one time 5 dollar payment to sign up.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#125
post #110

Earlier quoted context omitted.

What strike-through?

All links have a thin red line through them: https://pasteimg.com/images/2020/09/29/strika.png

Weird, I have that neither in Chrome nor FF:

https://pasteimg.com/images/2020/09/30/image.png

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#126

Earlier quoted context omitted.

I'm about to start down a road that might lead to where you are, but my target audience is a bit more mature and laid back so it might not be an issue. But what you said reminded me of a conversation we had here a month ago. I think it may be that I reserve image upload functionality for users who have proven their humanness (and their humanity). In my case image quality matters much more than quantity, so I can affo…

One forum that almost entirely eliminated trolling is the (now 20 year old!) Metafilter, which requires a one time 5 dollar payment to sign up.

That depends on perspective, and what you consider trolling. Yeah...the 5 dollars is a great filter for the vast majority of the Greater Internet Fuckwad Theory[1] posters, but that just narrowed posters and moderation down to a particular echo chamber (not unlike HN, fwiw). If you are down with the content/tone of the majority of MF posts, you prolly think it's great. But just like HN, there are posters with 'cred' who can say most anything (things I would definitely consider a troll), the 'little people' who can say things, including trolling, as long as they don't deviate to far from orthodoxy, and the unclean who get moderated away (hey...they paid 5 bucks so can't just punt them). They have done a remarkable job at maintaining the illusion that they're some moderation utopia for a long time.

[1] https://www.penny-arcade.com/comic/2004/03/19

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#127
post #122
post #99

Earlier quoted context omitted.

I've been dealing with a ban evader/forum shock image spammer for months now, and the place he is buying proxies from is actively doing BGP hijacking on resources owned by AT&T, Windstream, hospitals and universities - for the primary purpose of carding and fraud. I haven't managed to get anyone knowledgeable at those companies to figure out how to pressure the small upstreams (that are not those T1s) to stop it.

Could you drop some IP prefixes you believe are hijacked and timestamps? I can probably help out and bring this to folks who can take action. (I have to deal with hijacks frequently and part of our investigation is beating on folks who have permissive filters and pressuring their peers to improve things)

Got an email? It's a bit more complex than some prefixes

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#128
post #126

Earlier quoted context omitted.

One forum that almost entirely eliminated trolling is the (now 20 year old!) Metafilter, which requires a one time 5 dollar payment to sign up.

That depends on perspective, and what you consider trolling. Yeah...the 5 dollars is a great filter for the vast majority of the Greater Internet Fuckwad Theory[1] posters, but that just narrowed posters and moderation down to a particular echo chamber (not unlike HN, fwiw). If you are down with the content/tone of the majority of MF posts, you prolly think it's great. But just like HN, there are posters with 'cred'…

Sounds like you have an axe to grind with some of the political or ideological positions of the people who run Metafilter. I never said it was run as a user-administered democracy, it's run by a core group of about five people who also own the servers. It's their pet project.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#129
post #103

Earlier quoted context omitted.

Oh so A and B are describing the same scenario, okay.

Yeah, I'm not sure what the parent was getting at separating them out since from the clients perspective they're the same. I guess they mean that getting a tcpcrypt connection on your server isn't a guarantee that there isn't a middlebox either.

They were alternative ways to prevent a MITM, but they both have solutions solved by existing TLS.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#130
post #126

Earlier quoted context omitted.

That depends on perspective, and what you consider trolling. Yeah...the 5 dollars is a great filter for the vast majority of the Greater Internet Fuckwad Theory[1] posters, but that just narrowed posters and moderation down to a particular echo chamber (not unlike HN, fwiw). If you are down with the content/tone of the majority of MF posts, you prolly think it's great. But just like HN, there are posters with 'cred'…

Sounds like you have an axe to grind with some of the political or ideological positions of the people who run Metafilter. I never said it was run as a user-administered democracy, it's run by a core group of about five people who also own the servers. It's their pet project.

It's their pet project with their pet axe to grind. I said as much. If you disagree specifically with the points I made about moderation, which was all I commented on, then cite where I'm wrong. Otherwise, accept it's just as much an echo chamber as all the others and not some magical moderation utopia is made out to be by it's uncritical fanbois. But "you just don't agree with their politics", which mostly I do, is just sad, lame apologist crap.
Post reply on HN