The provider has access to the host, they can just inspect the job from the outside and you won’t be able to tell
The Hetzner one is a physical server. You would need to stage a "power outage" and backdoor it, which is probably not that easy - e.g. planting a kernel module which survives kernel upgrades and is pretty advanced at hiding itself (the article talks about analyzing raw memory dump).
Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
61–70 of 150 posts
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#62Earlier quoted context omitted.
> Both Hetzner and Linode network appear to be reconfigured specifically for this kind of attack for the XMPP service IP addresses This suggests a compromise of Hetzner and Linode network management.
More likely the carrier upstream of them.
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#63Who are the end users of xmpp.ru and jabber.ru? Are they hoping to pick up traffic between Russian soldiers? Spies? I hate mass surveillance as much as the next guy but why target Russian domains specifically?
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#64A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#65Earlier quoted context omitted.
extremely difficult to get physical access in a datacenter
I would suggest that if you are the police, you can break into a datacenter with a flash of a badge. I can't imagine many would attempt to stop you.
You would be 99% wrong. Even if law enforcment presented proper paperwork, every colo I have ever used would call and verify the paperwork. They might not call me, but they sure as hell would call their own lawyers. Once law enforcement is on the other side of the cage, important customers who pay real money could get compromised.
There is a massive difference between getting physical access to your server in a data center and coughing up everything about your server by simply emailing a minion in a cloud provider.
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#66Earlier quoted context omitted.
How would you do certificate pinning if you don't control the clients? My understanding is that certificate pinning is only possible if you control the clients, in which case you can embed which certificates are allowed directly in the client and bypass the whole web PKI. In a situation with general-purpose clients connecting, how would they know which certificates are meant to be allowed? That's what the web PKI is…
TLS client certificates. Use them. Stop using domains. Stop.
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#67A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…
They asked me to email them a copy of my ID card for verification. They refused to have me as a customer even after I provided it. I guess they didn't like the look of my face? They refused to tell me how I could still proceed, and I would've happily paid a year in advance or something. Heck, I could've probably visited their office in person.
I did try to register from a Protonmail account because I self-host my email and don't want to run into a chicken-and-egg problem (need to mail them because my server is down, can't mail them because my server is down...), so perhaps that was the issue.
Because Hetzner refused my business I was forced to look for another provider, and I've been using OVH without any issue for a few years now. Quite a shame though, because Hetzner definitely seems to provide a superior service - provided you can get them to take your business!
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#68A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…
They had the option to send it encrypted with PGP. But yes, this reminds me of communist countries where you had to leave your ID at the hotel upon check in. The Stasi mentality lingers on and accomplishes nothing.
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#69Great callout: > Don't use Cloudflare or similar services. See my article here for an explanation on why. If you use a service like this, you're basically already MitMing yourself. I wish more people would realize that when arguing on the internet about CAA, DNSSEC, NSA, etc. that none of it really matters. We willingly allow a government aligned entity to unwrap 20% of all TLS connections on the internet and peak in…
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#70Earlier quoted context omitted.
I would hope they at least: * Require a copy of the badge number, and verify that this officer is assigned and expected to be at this business right now. * Require them to sign into and out of the site. * Annotate which systems / compromises are in place. - That all of the above MIGHT be sealed under a court order; I would hope any such order has an automatic 'sunset' date, and possibly renewal upon review by a diffe…
A business can request visiting law enforcement to do all those things, and hopefully law enforcement complies. However, if they refuse to comply, realistically you just have to let them in anyway. Document their non-compliance and provide it to your lawyers, who can decide what action to take (lodge a formal complaint to the law enforcement agency, apply to a judge for an injunction to compel their compliance, etc)…