Live data from Hacker News

Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

devever.net

141–150 of 150 posts

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#141

Earlier quoted context omitted.

Cloudflare exists out of necessity for the most part. The alternatives to shield from large scale DDoS are all US American too.

> Cloudflare exists out of necessity for the most part. I agree with this, there don't seem to be that much self-hosted software that someone could (easily) setup for the use cases that Cloudflare serves. > The alternatives to shield from large scale DDoS are all US American too. Not only that, but the WAF functionality is also pretty useful. To be honest, the same applies to something like wanting to have CAPTCHAs o…

As a hobbyist, dealing with load consists of upgrading your $5 VPS to a $10 VPS or even a $50 dedicated server from Hetzner(!) - note that *no* other provider has dedicated servers at this price point.

WAFs are heuristics at best. If what you're running on your server is actually secure, you don't need a WAF. If it's not secure, the WAF is guaranteed to let through at least one attack.

CAPTCHAs are difficult. Try to avoid depending on them, but it's fair to use a third-party service if you need one. hCaptcha is pretty easy to integrate right now.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#142

Earlier quoted context omitted.

A business can request visiting law enforcement to do all those things, and hopefully law enforcement complies. However, if they refuse to comply, realistically you just have to let them in anyway. Document their non-compliance and provide it to your lawyers, who can decide what action to take (lodge a formal complaint to the law enforcement agency, apply to a judge for an injunction to compel their compliance, etc)…

> realistically you just have to let them in anyway No, you don't. If they have a warrant then you need to let them in for the purposes specified in the warrant. Otherwise you're free to tell them to piss off. Unfortunately you're also free to acquiesce to any of their demands. This kind of passive, default-compliant attitude from service providers, while understandable from a "path of least resistance" standpoint, i…

Non-compliance with a law enforcement order is a good way to get shot (in America) or arrested (in most countries) even if there is no legal basis for the order.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#143

Earlier quoted context omitted.

> realistically you just have to let them in anyway No, you don't. If they have a warrant then you need to let them in for the purposes specified in the warrant. Otherwise you're free to tell them to piss off. Unfortunately you're also free to acquiesce to any of their demands. This kind of passive, default-compliant attitude from service providers, while understandable from a "path of least resistance" standpoint, i…

> No, you don't. If they have a warrant then you need to let them in for the purposes specified in the warrant. Otherwise you're free to tell them to piss off. Any lawyer will tell you - if law enforcement attempts a warrant-less search, you tell them you do not consent to it, but you do not attempt to physically stop them from performing it. Tell them they are unwelcome and to come back with a warrant, but if they i…

"Letting them in" is another way of saying you consent. Don't "let" them in... just don't physically stop them coming in.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#144

Earlier quoted context omitted.

> Cloudflare exists out of necessity for the most part. I agree with this, there don't seem to be that much self-hosted software that someone could (easily) setup for the use cases that Cloudflare serves. > The alternatives to shield from large scale DDoS are all US American too. Not only that, but the WAF functionality is also pretty useful. To be honest, the same applies to something like wanting to have CAPTCHAs o…

As a hobbyist, dealing with load consists of upgrading your $5 VPS to a $10 VPS or even a $50 dedicated server from Hetzner(!) - note that *no* other provider has dedicated servers at this price point. WAFs are heuristics at best. If what you're running on your server is actually secure, you don't need a WAF. If it's not secure, the WAF is guaranteed to let through at least one attack. CAPTCHAs are difficult. Try to…

If someone tries to send you more traffic than your link supports, your only way to survive it is if your provider can filter it. Cloudflare will actually do a decent job of that even on the free plans.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#145
post #144

Earlier quoted context omitted.

As a hobbyist, dealing with load consists of upgrading your $5 VPS to a $10 VPS or even a $50 dedicated server from Hetzner(!) - note that *no* other provider has dedicated servers at this price point. WAFs are heuristics at best. If what you're running on your server is actually secure, you don't need a WAF. If it's not secure, the WAF is guaranteed to let through at least one attack. CAPTCHAs are difficult. Try to…

If someone tries to send you more traffic than your link supports, your only way to survive it is if your provider can filter it. Cloudflare will actually do a decent job of that even on the free plans.

"Survive" is hyperbolic. If someone DDoSes your $5 website and it is down for a day until you sign up for Cloudflare, you do not literally die. You do not need to sell everyone's 24/7 browsing history to Cloudflare to keep your heart beating.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#146

Earlier quoted context omitted.

> No, you don't. If they have a warrant then you need to let them in for the purposes specified in the warrant. Otherwise you're free to tell them to piss off. Any lawyer will tell you - if law enforcement attempts a warrant-less search, you tell them you do not consent to it, but you do not attempt to physically stop them from performing it. Tell them they are unwelcome and to come back with a warrant, but if they i…

"Letting them in" is another way of saying you consent. Don't "let" them in... just don't physically stop them coming in.

If you unlock a door for someone but simultaneously say “I don’t consent to you passing through it”, the first act does not cancel out the second. Whereas, if you don’t unlock it, if they really want to go in they’ll knock it down, causing damage in the process. Unlocking it for them is about avoiding damage to property, it is not a form of consent if accompanied by a clear verbal refusal of consent

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#147
post #105

Earlier quoted context omitted.

That is how American tech monopolies like to paint what the EU does. Lol

dumb question: why do I have the option to downvote your comment, but not many other comments in this thread?

Downvoting is only available for comments that are less than 24h old and not replies to you.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#148
post #41

The summary of the attack from https://notes.valdikss.org.ru/jabber.ru-mitm/ is very interesting: * The attacker managed to issue multiple SSL/TLS certificates via Let’s Encrypt for jabber.ru and xmpp.ru domains since 18 Apr 2023 * The Man-in-the-Middle attack for jabber.ru/xmpp.ru client XMPP traffic decryption confirmed to be in place since at least 21 July 2023 for up to 19 Oct 2023, possibly (not confirmed) since…

> * The attacker failed to reissue TLS certificate and MiTM proxy started to serve expired certificate on port 5222 for jabber.ru domain (Hetzner) This is gold.

Someone was forced to do it, but they didn’t personally agree with it so they eventually made a “mistake” to tip off the target?

There is the plain incompetence explanation: the hosting provider gave control of the operation to the government entity. The underpaid and indifferent government employee did the best they could with their level motivation and skill level.

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#149

Earlier quoted context omitted.

> Cloudflare exists out of necessity for the most part. I agree with this, there don't seem to be that much self-hosted software that someone could (easily) setup for the use cases that Cloudflare serves. > The alternatives to shield from large scale DDoS are all US American too. Not only that, but the WAF functionality is also pretty useful. To be honest, the same applies to something like wanting to have CAPTCHAs o…

As a hobbyist, dealing with load consists of upgrading your $5 VPS to a $10 VPS or even a $50 dedicated server from Hetzner(!) - note that *no* other provider has dedicated servers at this price point. WAFs are heuristics at best. If what you're running on your server is actually secure, you don't need a WAF. If it's not secure, the WAF is guaranteed to let through at least one attack. CAPTCHAs are difficult. Try to…

OVH absolutely does have dedicated servers at this price point, and below - check out their Eco range (previously SoYouStart) or even Kimsufi. Leaseweb often does as well, although they have not been as good a deal recently from my perspective (and can cost more for transfer).

Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident

#150

Earlier quoted context omitted.

Latter is not correct. It's well known difference in Russia between companies that willingly cooperate with government agencies informally, and those who just provide information upon formal request according to law.

How do you know for sure the people who “just provide information upon formal request according to law” aren’t covertly engaging in informal cooperation? If one morning the CEO gets an unexpected visit at home from a group of FSB agents asking for some favours, is the CEO going to say “no”? And if the CEO says “yes”, are you going to hear about it, or are they going to let the CEO continue that pretence? Western CEOs…

Actually, that's happen to some people that I know.

Roem.ru site (small but ifluential at time) recieved official, but illegal request from high level FSB agent to disclose commentators identities. They send formal complaint to a FSB own security and to public prosecutor office. Former officially warned FSB to stoppes illegal actions.

Funny thing: 7 years later FSB agent was convicted for being CIA asset.

Post reply on HN