Live data from Hacker News

Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

devever.net

131–140 of 150 posts

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#131
post #45

Earlier quoted context omitted.

The Hetzner one is a physical server. You would need to stage a "power outage" and backdoor it, which is probably not that easy - e.g. planting a kernel module which survives kernel upgrades and is pretty advanced at hiding itself (the article talks about analyzing raw memory dump).

It only takes access to a DMA-enabled bus (e.g. PCIe) though, to siphon memory contents.

And I bet PCIe is a whole lot more hotpluggable than you're officially told.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#132
post #37

Earlier quoted context omitted.

Secure boot on a cloud machine is pretty useless, there's nothing stopping the hypervisor from injecting code into the running machine. Theoretically virtual machine memory is encrypted, but you'll just have to trust the hypervisor's word for it. You can try to verify the boot chain all the way to the hardware keys, but if the hypervisor just replaces your `JNE` with a `NOP` you'll have a hard time automating your pr…

That is not the case for the latest CPU extensions for encrypted VMs, AMD SEV-SNP and Intel TDX, which are designed to allow remote attestation based on a key hidden in the CPU that the hypervisor does not get access to. The hypervisor only ever sees the VM’s memory in encrypted form, and it’s integrity-checked by the CPU to prevent replay attacks.

SGX has been bypassed with hypervisor access. I'm sure the new extensions are different, but have similar fundamental flaws.

Besides, a nation-state actor can compel Intel to disclose your CPU's key.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#133
post #49

A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…

Fax is an accepted GDPR-compliant form of "secure" communication. Yes, many service providers need to ascertain your identity. In my experience, passport photo verification is normal at Hetzner, Hetzner is very aware that not everyone wants to meet the requirements for their service, and they will happily refund you if you decide not to proceed.

This passport verification is required in Germany for any Internet connection. You need to do the same if you sign up for a cellphone plan in Germany. It's a surveillance state.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#134

Earlier quoted context omitted.

Cloudflare is horrible for privacy. It is also a bit of a sovereignty issue for European countries to have all their citizens web habits to be MITM by a forging power (no matter how friendly they seam). Edit: not even going in to the sovereignty issue of having an American private company effectively decide your internet regulations.

Cloudflare exists out of necessity for the most part. The alternatives to shield from large scale DDoS are all US American too.

Most sites don't get DDoSed. https://immibis.com/ has been running without DDoS protection for a long time now. It's as simple as nobody caring to do so. Why would they? What's in it for them?

And if someone does knock it offline, I still don't care. I can wait until they get bored. The site isn't important to me, either.

And if I really do care, Cloudflare encourages people to sign up whilw they are actively under attack. Of course, it costs money, because you aren't paying with your access logs all the times you aren't under attack.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#135

Earlier quoted context omitted.

Cloudflare exists out of necessity for the most part. The alternatives to shield from large scale DDoS are all US American too.

DDoS protection is standard among hosting providers now, including budget ones like OVH. The fact that Cloudflare is allowed to continue hosting websites which are obviously illegal, some notorious, is deeply strange. As I wrote in my article on the subject, it makes no sense when you consider the way the US responds even just to copyright infringement; see how they nuked Megaupload's business without trial because t…

In this aspect, Cloudflare should be viewed similarly to an ISP. Why are ISPs allowed to host illegal sites? Well, they aren't supposed to pay much attention to what they're hosting - it's not their job. But they aren't supposed to protect what they're hosting, either. If they get a court order asking for the details of the subscriber hosting some website, they turn those details over. If they get a court order asking to turn off the service, they will. Governments are fine with this, because they can easily get the details upon request.

Cloudflare should be viewed the same way - they shield you from DDoS, not from the government. They allow everything to be hosted until proven otherwise. Cloudflare doesn't have to police what's hosted through it, because the police can do it easily enough.

There are lots of pirate websites, explicitly designed for piracy, but saying the opposite on their terms and conditions page to create a little plausible deniability. I can't tell you if Megaupload was one of those and I don't know what evidence the government had.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#136
post #64

Earlier quoted context omitted.

They had the option to send it encrypted with PGP. But yes, this reminds me of communist countries where you had to leave your ID at the hotel upon check in. The Stasi mentality lingers on and accomplishes nothing.

I think it is less Stasi and more so 30 euro dedicated servers with unmetered gigabit lines are ripe for bad clients. You've got the general issue of abuse and fraud that all providers face. But I think there are two issues that make it worse for companies like Hetzner, OVH, and other low-cost providers: 1. Chargebacks are a big deal, both in terms of being cut off from payment networks but also the fees imposed, whi…

BuyVM comes off as one of those sites that's explicitly set up to host illegal content, but with plausible deniability. I don't understand how they're still allowed to remain operating. Governments usually err on the side of arresting innocent people.

P.S. Hetzner gigabit is not actually unmetered, but the limits are vague, but high (>100TB/month)

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#137
post #16

Great callout: > Don't use Cloudflare or similar services. See my article here for an explanation on why. If you use a service like this, you're basically already MitMing yourself. I wish more people would realize that when arguing on the internet about CAA, DNSSEC, NSA, etc. that none of it really matters. We willingly allow a government aligned entity to unwrap 20% of all TLS connections on the internet and peak in…

There are lots of reasons to not use Cloudflare, but many of those given in the article don't hold up. For example, Cloudflare does not set a cookie for all connections, discrimination against Tor users, CAPTCHAs and WAFs are all configurable.

Cloudflare encourages all these bad things by making them simple checkboxes and insinuating that if you care about security you'll check the checkbox.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#138
post #105
post #29

Earlier quoted context omitted.

The EU regularly de-facto tries to decide regulations for other countries. All is fair in a globally connected world.

That is how American tech monopolies like to paint what the EU does. Lol

dumb question: why do I have the option to downvote your comment, but not many other comments in this thread?

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#139

Who are the end users of xmpp.ru and jabber.ru? Are they hoping to pick up traffic between Russian soldiers? Spies? I hate mass surveillance as much as the next guy but why target Russian domains specifically?

I can't imagine it is war-related, or at least not in any direct sense, like literally trying to intercept soldiers or spies. I think the more likely scenario is that someone was to catch carders/botnet operators, since Jabber/XMPP is still very popular amongst people in that scene in Russia; you'll see often see screenshots or logs containing @exploit.in, @jabber.ru, and various other servers pretty much in any Kreb…

> I can't imagine it is war-related, or at least not in any direct sense, like literally trying to intercept soldiers or spies.

Perhaps a majority of war between technologically developed countries these days occurs on the internet - just because no soldiers or spies are involved in something, that doesn't mean it isn't direct war. Example: propaganda around Russia/Ukraine last year and Israel/Palestine this year

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#140

Earlier quoted context omitted.

I can't imagine it is war-related, or at least not in any direct sense, like literally trying to intercept soldiers or spies. I think the more likely scenario is that someone was to catch carders/botnet operators, since Jabber/XMPP is still very popular amongst people in that scene in Russia; you'll see often see screenshots or logs containing @exploit.in, @jabber.ru, and various other servers pretty much in any Kreb…

> I can't imagine it is war-related, or at least not in any direct sense, like literally trying to intercept soldiers or spies. The Ukrainian military has been using Discord, so it's not totally unimaginable. Are these domains administered by Russians? IMO it would be pretty naive for Russians to be hosting comm servers in NATO datacenters right now. Perhaps related: I interviewed for a job recently where the hiring…

> Do people not understand the severity of the situation or is this behavior of acting like it is business as usual a coping mechanism?

Why not both? See also: climate change.

Post reply on HN