What is India turning into China lite?
Indian ISPs: We already give govt full access to web traffic
61–70 of 113 posts
Re: Indian ISPs: We already give govt full access to web traffic
#62But how... I mean presumably they don't install a root cert on every client device?
They can intercept the unencrypted section of encrypted connections, such as TLS ServerName, and the source and destination of every IP datagram which already provides a lot of information to profile individual citizens. QUIC moves to a model where everything except the Connection ID is encrypted[1], but it is also apparently being blocked in India[2]. The mandated transition to IPv6 in India[3] would also take away…
This page [1] shows I am using HTTP/3 which unless I am mistaken requires QUIC to work.
Re: Indian ISPs: We already give govt full access to web traffic
#63I think we must all agree that national governments have a duty of care towards their citizens. From the Indian govt perspective, the dominance of the Internet by foreign owned businesses means that the country is vulnerable to malfeasance should those foreign governments mean India harm or come to decide - over the head of the government - what the Indian people want or need. This is about national sovereignty and n…
Re: Indian ISPs: We already give govt full access to web traffic
#64Earlier quoted context omitted.
How would ipv6 "take away the need to track 5-tuples" and what does that even mean? That sentence doesn't make sense
NATing IPv4 traffic requires maintaining a 5-tuple of connection state[1], which means the ISP must log these 5-tuples to be able to track citizens individually. Further, if there's another layer of NAT (such as a free WiFi service in an airport or a WiFi router in a citizen's home), cooperation is needed at that NAT layer too. IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space.…
Re: Indian ISPs: We already give govt full access to web traffic
#65Earlier quoted context omitted.
Looking at that, I'd suggest the downvotes are from being technically wrong (the “Scanning for vulnerabilities won't help you find critics. If you wanted to look for critics, you would scan for critics.” argument – there are better/easier ways to achieve what you are talking about a government trying to achieve so why would they go to that effort?). Maybe some considered the comment concerning India on a thread about…
oh no, not that. >Try not to assume that one angry reply represents a larger chunk of HN's readership. you get to have a thick skin when you are on an anonymous public platform. i accept that.... i live in a place where i have to actually assume malice on part of the government because the government "is" hostile against me. Again, this isn't some tin-foil conspiracy but as you might've guessed from my handle, its ye…
I was suggesting that the downvotes there, complained about above, where people disagreeing with this possibility, on the basis that it would not offer a practical amount of extra information (considering the effort involved) than already being gleaned with other methods they are already using. Not generally how downvotes should be used IMO, but it happens.
Re: Indian ISPs: We already give govt full access to web traffic
#66Earlier quoted context omitted.
How would ipv6 "take away the need to track 5-tuples" and what does that even mean? That sentence doesn't make sense
NATing IPv4 traffic requires maintaining a 5-tuple of connection state[1], which means the ISP must log these 5-tuples to be able to track citizens individually. Further, if there's another layer of NAT (such as a free WiFi service in an airport or a WiFi router in a citizen's home), cooperation is needed at that NAT layer too. IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space.…
You don't understand how IPv6 works.
Re: Indian ISPs: We already give govt full access to web traffic
#67Earlier quoted context omitted.
NATing IPv4 traffic requires maintaining a 5-tuple of connection state[1], which means the ISP must log these 5-tuples to be able to track citizens individually. Further, if there's another layer of NAT (such as a free WiFi service in an airport or a WiFi router in a citizen's home), cooperation is needed at that NAT layer too. IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space.…
Wouldn't people just continue using consumer-grade routers which operate their own nat anyway? Even with ipv6, the traffic generated by all hosts behind a single isp subscription would appear to originate from a single ipv6 host, no?
Re: Indian ISPs: We already give govt full access to web traffic
#68The real canary in the coalmine was actually a movie from 1999 called "Enemy of the State." The plot for the movie was actually based on an account from an NSA employee who tipped one of the producers or director (I forget which) of the mass surveillance the agency was involved in. To me this movie is iconic just because it predicted events so vividly almost a quarter of a century ago.
Re: Indian ISPs: We already give govt full access to web traffic
#69I think we must all agree that national governments have a duty of care towards their citizens. From the Indian govt perspective, the dominance of the Internet by foreign owned businesses means that the country is vulnerable to malfeasance should those foreign governments mean India harm or come to decide - over the head of the government - what the Indian people want or need. This is about national sovereignty and n…
How is violating someone's privacy caring for them? "Forfeit your rights so your rights can be protected"
for example, the government might suspect a citizen to be an agent of the CCP. Would you defend that individuals right to privacy, vs the nations right to security?
Re: Indian ISPs: We already give govt full access to web traffic
#70Ok so how is it different from what the USA does?
But there is always the next target(s) to go after, to keep in check, in a pop culture sense. So one way is to see this (article and this HN post) as a hit piece.