Earlier quoted context omitted.
Hence the desire to backdoor all encryption to see the full juicy details. Also the reason DNS over HTTPS exists and is spreading.
Does DNS over HTTPS allow the dns provider to see beyond the domain name?
The UK Is Trying to Stop Facebook's End-to-End Encryption
31–40 of 60 posts
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#32Earlier quoted context omitted.
yes, but it'd be the ISPs storing the internet history
Backbones have the reputation of being filled with intercepting devices from various entities, including gov's own.
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#33They want to compromise entire country security, just to make it easy for LE. Problem is that I doubt it will help in any way because criminals will still be able to communicate with e2e if they will be encrypting traffic themselves and then disguise it as normal text etc. It will be a cat and mouse game. Not sure why they don't sack people coming with such stupid, totalitarian and abusive ideas.
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#34Is there any co-ordinated political response to this in the UK? Where do I sign up?
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#35Earlier quoted context omitted.
i assume in days of https, most of the history they would be able to obtain are only domain names, not specific URLs, right?
Except if you have a root certificate, then you can MITM you heart away. Which govs probably have.
So first of all this hypothetical government would have to issue itself certificates for any sites it was interested in intercepting, and intercept the traffic to impose a MITM. It has to do this live or it won't work. Every time it does this, it provides the other participant a smoking gun, which is to say evidence - in the form of these bogus certificates.
But wait, if you run Chrome, Safari or similar browsers, these certificates just won't work. To be functional the government has to obtain proof they were logged for everybody to see - in the Certificate Transparency system. Without that the user just gets an error telling them the certificate isn't logged and can't be trusted.
If they were logged, we all get to see them. Do you see them? No, because this isn't actually a thing. It's a paranoid fantasy.
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#36Earlier quoted context omitted.
yes, but it'd be the ISPs storing the internet history
Backbones have the reputation of being filled with intercepting devices from various entities, including gov's own.
Right now they get a good idea which sites are visited (because of Server Name Indication) by web browsers, and they get some portion of email (sent in the clear) plus a small fraction of web traffic (HTTP-only) and numerous older unencrypted protocols.
In particular they also get most of DNS. DPRIVE work (DNS over TLS, DNS over HTTPS, and eventually DNS over QUIC) reduces that considerably. Future DPRIVE work also includes oblivious transfer (you ask say Google to do a DNS lookup on your behalf, they learn who you are and which DNS server was asked but not what you asked it, the DNS server learns what was asked but not who you are, you get your answer).
Or of course, if you're particularly worried, you use Tor and everything on the snoops' screens dissolves into noise.
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#37It's always either "Think of the children!" or "X will only be used to investigate the most serious of crimes like terrorism, rape and murder" which shortly afterwards is then (quietly) forgotten about when something like browsing history etc. can be downloaded by basically anyone in government(s). Maybe there is a restriction snort where such an action requires a warrant but considering that "judges" and "courts" fo…
> In German there is a nice idiom for that kind of thought pattern: "Nach mir die Sintflut" Interestingly this is originally a French saying by Louis XV, Après moi, le déluge [0]. From wiki: > It is generally regarded as a nihilistic expression of indifference to whatever happens after one is gone, though it may also express a more literal forecasting of ruination. Its meaning is translated by Brewer in the forms "Wh…
TIL.
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#38Earlier quoted context omitted.
Hence the desire to backdoor all encryption to see the full juicy details. Also the reason DNS over HTTPS exists and is spreading.
Does DNS over HTTPS allow the dns provider to see beyond the domain name?
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#39Earlier quoted context omitted.
Hence the desire to backdoor all encryption to see the full juicy details. Also the reason DNS over HTTPS exists and is spreading.
Does DNS over HTTPS allow the dns provider to see beyond the domain name?
In the way DoH is being used in practice, it alllows third parties to collect histories of DNS lookups for myriad users, separated by individual program. In other words, the third party can tell which program was used by a given user to initiate any given DNS lookup. The program often reveals identifying information about the device on which it is installed. Other parties collect user data pertaining to IP address and device.
Device fingerprinting, i.e., associating a given user with a given device, is in widespread use purportedly "as a security measure" by "tech" companies like Facebook. Can we be sure the data collected is also not being used for other purposes.1
Combine the DNS program+IP fingerprint with, e.g., a web browser+IP fingerprint and now we can potentially identify a user from DNS lookups.
Now consider that Facebook prefixes all external URLs posted to Facebook pages (including external URLs posted in messages) so that any clicks on these URLs are captured, and the HTTP requests to non-Facebook sites are redirected via Facebook servers, again as a purported "security measure". Can we be sure the data collected is not also being used for other purposes.1 Thus Facebook has a history for each user of the URLs in Facebook pages/messages that the user clicks/follows.
The problem with DoH in practice is that it is being used almost exclusivelt to provide third party DNS. When we use third party DNS we give anyone (e.g., a "tech" company, a government, etc.) the potential opportunity to obtain from the third party (e.g., through subpoena, acquiring assets through merger, undisclosed data breach, etc.) complete DNS lookup histories for users' individual programs. There is no need to do this because there is no technical need to use third party DNS. And, of course, DoH does not have to be used only by third party DNS providers, so DoH itself is not the problem.
1. If I recall correctly, Facebook in the past has been caught lying about collecting telephone numbers "only" as a security measure.
Re: The UK Is Trying to Stop Facebook's End-to-End Encryption
#40Is there any co-ordinated political response to this in the UK? Where do I sign up?
Vote libertarian. Governments will do what they can to make their jobs easier, to show off success. I know left leaning people are going to dislike that, but it's a double edged sword - if you want eg a national health system, you're going to end up with the government telling you to eat your five vegetables each day.