Earlier quoted context omitted.
Why would they assume local connect would work when AWS times out or notices it was never able to fetch a page? I think it will only be available via a buried setting that most users will never touch. Fire seems to discourage any kind of advanced user, it's the king of "no" Bluetooth? No HDMI? No Camera? No Microphone? No micro/SD slot? No GPS? No 3G? No Android Market? No (only amazon's market) It also brings yet an…
Why wouldn't they assume that? Amazon surely knows that some people block AWS servers (AWS customers sure know!). You also have to realize that Amazon gets the advantage of crowd sourcing--in short order they should know who's blocking what and not even have to make the original requests to be blocked.
Silk, Fire and Another Loss For Privacy
21–30 of 33 posts
Re: Silk, Fire and Another Loss For Privacy
#22Earlier quoted context omitted.
"Amazon Silk will facilitate a direct connection between your device and that site. Any security provided by these particular sites to their users would still exist." Between your device and that site doesn't sound like terminating at AWS. Also, the SPDY connection to AWS is secure which gets you a leg up on sites that aren't using SSL.
read the sentence right above that: " We will establish a secure connection from the cloud to the site owner on your behalf for page requests of sites using SSL (e.g. https://example.com )." that means that the SSL is terminated at amazon's servers, they see it in plaintext, then they send it via SPDY (re-encrypted) to your device. so it is always secure over the wire, but is plaintext readable by amazon. if you are…
[1] I'm making the assumption here that re-encryption is actually occurring. It could be the case that its not and the phrasing was simply poor.
Re: Silk, Fire and Another Loss For Privacy
#23There is no such thing as privacy on the internet. Only the illusion of privacy exists.
Re: Silk, Fire and Another Loss For Privacy
#24http://www.amazon.com/gp/search/ref=sr_kk_1?rh=i%3Amobile-ap...
That doesn't fix the problem for unaware users, but at least the option to use other browsers still exists.
Re: Silk, Fire and Another Loss For Privacy
#25Earlier quoted context omitted.
read the sentence right above that: " We will establish a secure connection from the cloud to the site owner on your behalf for page requests of sites using SSL (e.g. https://example.com )." that means that the SSL is terminated at amazon's servers, they see it in plaintext, then they send it via SPDY (re-encrypted) to your device. so it is always secure over the wire, but is plaintext readable by amazon. if you are…
Let's not forget that this decryption and re-encryption[1] is going on in the AWS cloud, which is ostensibly shared infrastructure. Its not just what Amazon can see, but what other people who happen to be running on the boxes doing this re-encryption can see (through security vulnerabilities). [1] I'm making the assumption here that re-encryption is actually occurring. It could be the case that its not and the phrasi…
And I don't see how it's possible for them to proxy SSL content without being MITM and re-encrypting. They could stay entirely out of the way for HTTPS requests, but if that's how they were doing it, I think their FAQ answer would just say so. If, on the other hand, they're inline enough to do the Silk acceleration thing at all, they have to be able to decrypt the traffic.
Re: Silk, Fire and Another Loss For Privacy
#26When intercepting a regular HTTP session Silk is no more of a MITM attack than any ISP out there. I trust Amazon more than I trust AT&T or Verizon. What disturbs me is that Amazon Silk will terminate SSL on their end by default. * This is the break from the past that's worrisome. * Source: http://www.amazon.com/gp/help/customer/display.html/ref=hp_l...
"Amazon Silk will facilitate a direct connection between your device and that site. Any security provided by these particular sites to their users would still exist." Between your device and that site doesn't sound like terminating at AWS. Also, the SPDY connection to AWS is secure which gets you a leg up on sites that aren't using SSL.
Also, unless they stop doing the Silk combining thing entirely, I don't see how it's possible not to peer inside the requests. They can either pass along the traffic without knowing what it is (meaning they can't cache, or combine, requests or responses, because they don't know what's in those requests and responses), or they have to see inside.
This, to me, means they're taking liberties with the meaning of "direct connection" in the snippet you quoted, and, if I'm being pedantic, I don't see how the final sentence ("Any security provided ... would still exist") is literally true at all. Seems to me that being end to end, encrypted by a key only you and the other end, know, is a form of security that does not still exist in this architecture.
(Somewhat off topic, but when using earlier-generation Kindles with whispernet 3G, over 3G, all traffic is proxied through Amazon's datacenters, even for SSL, and I have no idea if it's secured end-to-end all the way to the device, or decrypted in Amazon's datacenter, and possibly re-encrypted to send OTA to the device. There's no way to tell.)
Re: Silk, Fire and Another Loss For Privacy
#27According to Ars Technica's article on Silk, it is possible to turn off the split browsing mode and use Silk as a regular web browser, so people who have privacy issues with this can turn it off.
Re: Silk, Fire and Another Loss For Privacy
#28It's worse than that for webservers. I block all Amazon AWS/EC2 on my servers because it's never humans and I've yet to see a useful bot from there - they just suck bandwidth and cpu time. Since they have free, unlimited inbound, there's a bunch of nonsense going on. Now I suspect silk is going to use the same IP range as amazon aws, so if you block aws, you block silk? So no more using iptables to stop the traffic -…
Re: Silk, Fire and Another Loss For Privacy
#29There is no such thing as privacy on the internet. Only the illusion of privacy exists.
I don't think this is quite accurate; it's actually somewhat similar to say that there is no privacy in the real world because you have to travel through public property to get anywhere. Anyone could follow you to any store, keep ultimate tabs on where you go and who you meet. Except that isn't a problem, it doesn't happen. And it's not that people don't see you go places; it's very unlikely that you can make it from…
Now imagine that the guy is willing to share that information with others due to court order or a nominal fee.
Your analogy works if you imagine the privacy issue is other internet users seeing what you are doing while they are going about doing whatever it is they are doing.
Unless you have a direct connection to the Internet that does not go through a third party everything you do on the Internet is open to the possibility of being tracked. You use a gateway to get to the Internet and you are not the gatekeeper.
Re: Silk, Fire and Another Loss For Privacy
#30There is no such thing as privacy on the internet. Only the illusion of privacy exists.
Privacy in the sense of 'what websites do I visit' or 'what am I posting on Facebook' is one thing; privacy in the sense of 'how much money does online banking say I have?' is another issue entirely.
Depends on how trustworthy we think security certificates are in the long run.