Live data from Hacker News

Indian ISPs: We already give govt full access to web traffic

entrackr.com

91–100 of 113 posts

Re: Indian ISPs: We already give govt full access to web traffic

#91
post #76
post #59

People really underestimate the full scale of this, specially today with so many sites using cloudflare without strict ssl reverse proxy connection, Cloudflare Endpoints in India are INSIDE ISP networks [1], what this means is the ISP (and therefore by extension the government) sees EVERYTHING going out of cloudflare servers over http in plaintext. Worse ISP will also modify that content so you get the "This site has…

Do you honestly believe the US government doesn't have the same access to cloudflare data within the states?

No where in the parent's comment did they mention the US. What's the point of your comment?

It's like if we were discussing a serial killer and you were like "don't you think other people have killed?"

The second reply to this post and someone is already redirecting the conversation to a country not mention in the story. Are you upset because you think India is being singled out? No where on the article or the comment does it imply that.

On HN there are a massive amount of discussion about US government spying already, it's not something that people aren't aware of.

Re: Indian ISPs: We already give govt full access to web traffic

#92
post #59

People really underestimate the full scale of this, specially today with so many sites using cloudflare without strict ssl reverse proxy connection, Cloudflare Endpoints in India are INSIDE ISP networks [1], what this means is the ISP (and therefore by extension the government) sees EVERYTHING going out of cloudflare servers over http in plaintext. Worse ISP will also modify that content so you get the "This site has…

If I'm understanding you correctly, you are saying that the origin servers only listen on HTTP and that is where the ISP intercepts. Is it not common practice for the origin servers to also being using HTTPS? Afaik there's no simple way for the end user to know this though.

Re: Indian ISPs: We already give govt full access to web traffic

#93
post #76

Earlier quoted context omitted.

Do you honestly believe the US government doesn't have the same access to cloudflare data within the states?

No where in the parent's comment did they mention the US. What's the point of your comment? It's like if we were discussing a serial killer and you were like "don't you think other people have killed?" The second reply to this post and someone is already redirecting the conversation to a country not mention in the story. Are you upset because you think India is being singled out? No where on the article or the commen…

The parent comment is valid. The GP comment specially highlighted the Indian networks as different so that factoid being challenged (in efficacy rather than implementation) is a pretty valid stance.

Re: Indian ISPs: We already give govt full access to web traffic

#94
post #59

People really underestimate the full scale of this, specially today with so many sites using cloudflare without strict ssl reverse proxy connection, Cloudflare Endpoints in India are INSIDE ISP networks [1], what this means is the ISP (and therefore by extension the government) sees EVERYTHING going out of cloudflare servers over http in plaintext. Worse ISP will also modify that content so you get the "This site has…

pfft it's India. Ppl with access to sensitive data get paid peanuts. So you too can see "everything" by giving the right person a bag of nice mangoes.

Re: Indian ISPs: We already give govt full access to web traffic

#95

Earlier quoted context omitted.

> the US government doesn't have the same access to cloudflare data within the states? Yes. There is almost certainly access. But it’s partial and adversarial, not automatic as in India.

PRISM [1] didn't end when the media stopped reporting on it. If anything it's likely only become more emboldened given people's tepid response. This [2] is one of my favorite documents that was leaked. It's a user manual, "User's Guide For PRISM Skype Collection", for NSA agents spying on Skype "peer to peer" connections in real time. It even includes a helpful FAQ like agents wondering why they might receive copies…

PRISM is a good example of the difference between America and India. One, there's vocal and empowered opposition, opposition granted relief by the courts from time to time. Two, there was opposition–MUSCULAR involved hacking Google and Yahoo's clouds. Three, there is a warrant process. It's broken. It needs reform. But it exists.

Re: Indian ISPs: We already give govt full access to web traffic

#96
post #76
post #59

People really underestimate the full scale of this, specially today with so many sites using cloudflare without strict ssl reverse proxy connection, Cloudflare Endpoints in India are INSIDE ISP networks [1], what this means is the ISP (and therefore by extension the government) sees EVERYTHING going out of cloudflare servers over http in plaintext. Worse ISP will also modify that content so you get the "This site has…

Do you honestly believe the US government doesn't have the same access to cloudflare data within the states?

Do you see a green lock with message saying "your access is restricted" in the US?

Do you see any TLS connection resets based on SNI? If not, most(all?) indian ISPs already visibly do far more than average American ISP.

Re: Indian ISPs: We already give govt full access to web traffic

#97
post #59

People really underestimate the full scale of this, specially today with so many sites using cloudflare without strict ssl reverse proxy connection, Cloudflare Endpoints in India are INSIDE ISP networks [1], what this means is the ISP (and therefore by extension the government) sees EVERYTHING going out of cloudflare servers over http in plaintext. Worse ISP will also modify that content so you get the "This site has…

Does cloudflare mention this anywhere?

Re: Indian ISPs: We already give govt full access to web traffic

#98

The real canary in the coalmine was actually a movie from 1999 called "Enemy of the State." The plot for the movie was actually based on an account from an NSA employee who tipped one of the producers or director (I forget which) of the mass surveillance the agency was involved in. To me this movie is iconic just because it predicted events so vividly almost a quarter of a century ago.

Predicted or inspired... Imagine a young, going to be politician, kind of person watched it and thought "Hmm, this is not a bad idea at all!" and then climbing the political ladder lobbying for these kind of measures.

Re: Indian ISPs: We already give govt full access to web traffic

#99
post #85

Earlier quoted context omitted.

the use case most commonly cited by government(s) is national security. for example, the government might suspect a citizen to be an agent of the CCP. Would you defend that individuals right to privacy, vs the nations right to security?

So rather than blanket surveillance, wouldn't it make more sense for the government to build a case against a suspect, and then issue a warrant to track their behaviour etc? Unless the assumption is that all citizens of a country are potentially enemies of the state and we are all highly trained spies operating under deep cover for years...

the question would be 'building a case' - how would do you this if you didn't conduct some sort of profiling? The entire purpose of national security apparatus is to identify enemies of the state before they are able to act. Do you think this is always unjustified? Genuine question, don't know the answer myself!
Post reply on HN