Live data from Hacker News

Help users in Iran reconnect to Signal

signal.org

391–400 of 417 posts

Re: Help users in Iran reconnect to Signal

#391

Earlier quoted context omitted.

What makes you think that it’s hard to block Tor? Even Kazakhstan blocked Tor many years ago. They’re using DPI: connection opens, client can write data, but can’t read anything which is frustrating from user PoV.

> What makes you think that it’s hard to block Tor? The fact that it is? There are secret bridges and Tor is able to disguise its traffic as other 'legitimate' protocols.

The bridges don't remain secret forever. All it takes is a government agency to ask the mailing list for one and then it's compromised. Once they're discovered, you can get into deep shit for trying to connect to that address.

My ex moved to China, and she told me that the only people who say Tor can't be blocked are people who have never lived in a country where the government is actively trying to block it. Just because you can connect to it doesn't mean you won't get a knock on the door in a month asking why.

Re: Help users in Iran reconnect to Signal

#392
post #147

Earlier quoted context omitted.

> can they break whatsapp encryption They don’t have to, they just need Facebook to cooperate.

I think you mean the phone vendors, as they are the ones holding the unencrypted chat history in the users cloud storage. Facebook themselves do not have access to the chat logs (unless they are compelled to inject keys).

Terms and conditions were updated a few weeks ago. The fact that the key will only remain on your phone has been removed from them.

Re: Help users in Iran reconnect to Signal

#393
post #339

Earlier quoted context omitted.

The "proprietary Google code" is a library with a well defined API, you can see what it has access to. I agree that Signal should take it out, but it's not an especially big deal from a security perspective. The auto update functionality just tells you that an update is available, you can choose not to install it. You can also independently verify that the sha256 sum matches the one given on the website, and that the…

> you can choose not to install it There is a time bomb in there and servers will kick you out regularly unless you have updated. If you get a patched client running you could probably change whatever string is required but some sort of action is required on the client side.

Sure, but that's an unrelated phenomenon to the security implications being discussed. The argument against auto-updates is "it's running code without my permission or ability to audit first"; putting a recency requirement for client-server communication doesn't impact that concern, and I don't see any reason why it would be considered a bad thing.

Re: Help users in Iran reconnect to Signal

#394

Earlier quoted context omitted.

Am honestly not trolling here although it will sound like it: Can someone please explain to me why it's a OK to reconnect Iranians to Signal, but not Trump supporters to Twitter (the ones censored and banned by Twitter)?

Hi, glad to help. The answer is that it depends on what your values are. If you want to reconnect people to twitter (a publishing platform) who have been banned for racist hate speech or inciting violence, and the laws in your jurisdiction permit you to do that. Then you can do that without going to jail. If you want to reconnect people to signal (a personal communications tool) who have been disconnected from it due…

[deleted]

Re: Help users in Iran reconnect to Signal

#395
As much as I admire the cause, I can't ignore the irony:

First Signal doesn't want to build a federated service because it is too complicated to build (for the guys who brought us a new class of encryption) and now they are asking us for proxy servers because their centralized network can be censored...

But since Signal is probably the best option for private communication right now, I don't want anybody to discourage to run a proxy right now.

Re: Help users in Iran reconnect to Signal

#396

Earlier quoted context omitted.

The header will appear in plaintext between the user and the proxy (easy to detect/log/drop for their ISP/government), and still appear in plaintext between the proxy and Signal (which is less of a problem). The SNI header is not dropped to upstream because it's used whether the reverse proxy is operated by the intended recipient (Signal) or not (the proxy). That's precisely the reason why people have been promoting…

It is not true that Signal domains are visible in plaintext on the wire between the user and the proxy. You can spin up the proxy and check yourself. Alternatively, you can ask yourself "why go through the trouble of setting up a legitimate ca-signed certificate if Signal domains are already leaking in plaintext"? The whole point of the ca-signed cert is to make the traffic blend in. Why go through that trouble when…

> You can spin up the proxy and check yourself.

I just did, and you are right. I stand corrected, sorry for spreading FUD. Other criticism of Signal still applies. I would edit my original message to reflect that, however i can't because it's been posted a while ago.

An attacker (such as the government) may not drop connections in real-time to Signal proxies without considerable efforts (i.e. for every HTTPS stream, verifying whether the remote server is a Signal proxy). However, after passively recording SNI headers, the attacker check those remote servers to figure out whether they are Signal proxies. As a conclusion, this Signal proxy is an effective censorship-circumvention tool, but does not protect users from the consequences of circumventing government censorship (which may be harsh).

A possible mitigation would be to have the virtualhost terminating the outer TLS connection serve the reverse proxy only from a specific folder/location, which cannot be well-known. So the attacker would see you are connecting to https://proxy.example, but as long as https://proxy.example serves legit-looking pages on /, and the Signal proxy is served from https://proxy.example/foobar, the attacker may not passively discover the actual reverse proxy. Of course, every Signal proxy would need to use a different subfolder.

Re: Help users in Iran reconnect to Signal

#397

Earlier quoted context omitted.

> Hackers usually are not in favor of censorship or information restriction. So who do you mean, with "you"? There are many comments on previous HN threads defending censorship and information restriction, precisely as the GP has described it. https://news.ycombinator.com/item?id=25693742 https://news.ycombinator.com/item?id=25691631 https://news.ycombinator.com/item?id=25706993 https://news.ycombinator.com/item?id=2…

What you call “defending censorship” is perhaps better described as “defending free speech”. Forced speech is not free speech.

Censorship is the suppression of speech, public communication, or other information, on the basis that such material is considered objectionable, harmful, sensitive, or "inconvenient." Censorship can be conducted by governments, private institutions, and other controlling bodies.

Amazon, Apple, Google, Twitter, Facebook, etc. are multibillion-dollar corporations that control a colossal share of online communications.

Let's not play pretend here.

Re: Help users in Iran reconnect to Signal

#398

Earlier quoted context omitted.

"I would like to see your supportive reaction if an Iranian company offers hosting to Parler. " This is a hacker forum and not a US foreign ministry praise board, even though it is mainly US based. In other words, I doubt the reaction here would be rage, if a iranian company would do that. Hackers usually are not in favor of censorship or information restriction. So who do you mean, with "you"?

> Hackers usually are not in favor of censorship or information restriction. So who do you mean, with "you"? There are many comments on previous HN threads defending censorship and information restriction, precisely as the GP has described it. https://news.ycombinator.com/item?id=25693742 https://news.ycombinator.com/item?id=25691631 https://news.ycombinator.com/item?id=25706993 https://news.ycombinator.com/item?id=2…

There are certainly peoole here defending censorship, but the parent poster spoke like "we" would follow US geopolicy in general. And in general I don't see the majority here in favor of kicking out parler etc.

Rather the contrary. Anyway, by my tautological definition of hacker, no hacker would be in favor of banning a communication app, anyway, so ...

Re: Help users in Iran reconnect to Signal

#399
post #276

Earlier quoted context omitted.

That does not resolve for me. Neither do any of the news sites. I even tried government ministries, such as en.mop.ir. simple$ ping president.ir/en ping: cannot resolve president.ir/en: Unknown host simple$ ping en.mop.ir ping: cannot resolve en.mop.ir: Unknown host simple$ ping tehrantimes.com ping: cannot resolve tehrantimes.com: Unknown host simple$ ping presstv.com ping: cannot resolve presstv.com: Unknown host

That might be something your ISP is doing. Try dig www.president.ir @8.8.8.8

Thanks. That got me the ip but browser won’t connect to it. So it’s blocked at the ip level. (Why would an ISP do this? Mine is one of the majors. Curious.)

Re: Help users in Iran reconnect to Signal

#400
post #3

I'm a big fan of the idea of independently-run proxy servers. Caddy has a secure forward proxy plugin born out of a research project at Google that does something similar, but works with any clients that let you configure HTTP proxies, and doesn't terminate TLS: instead it tunnels it over TLS. The proxy server itself can also be probe-resistant, i.e. difficult to detect that a website is acting as a proxy. I'm hoping…

how does something like this work against DPI? i guess not great? >Don't use this in situations where your personal safety or freedom could be at risk https://theintercept.com/2020/12/06/kashmir-social-media-pol... https://thewire.in/media/kashmir-journalist-auqib-javeed-pol... reason why i have a general disregard for technologies that are based on some sort of "link" AFK, phone number or the stupid facebook real na…

> how does something like this work against DPI? i guess not great?

No, it's pretty good. Think about it: all DPIs can see is an ordinary https connection. Since the traffic itself is encrypted, to discriminate this from normal web browsing the DPI device can only depend on metadata. Classic moves are:

1. Packet length pattern for TLS-in-TLS. 2. TLS fingerprinting.

The first could be defeated by adding padding to the first few packets of each of your connections. [1]

The second.. someone built a socks5 https CONNECT proxy client [2] out of Chrome's codebase, which means it shares all the fingerprint with Chrome and you really can't tell.

[1] https://github.com/klzgrad/forwardproxy/commit/2350f380f8db2... [2] https://github.com/klzgrad/naiveproxy

Post reply on HN