Live data from Hacker News

DNS results now being manipulated in Turkey

news.ycombinator.com

51–60 of 73 posts

Re: DNS results now being manipulated in Turkey

#51
post #13

Earlier quoted context omitted.

You're right. Maybe if they turned on and required SSL for everyone visiting www.youtube.com and added www.youtube.com to Chrome's preloaded HSTS list and somehow got everyone to use Chrome. Sadly, this probably won't happen, but DNSSEC adoption probably won't happen either. Even with DNSSEC, they could still do deep packet inspection on HTTP traffic going to YouTube IPs and initiate MITM attacks that way.

Why not ditch the current DNS system and use Namecoin? If you have to force some piece of software into users computers, let's do it right at least...

[deleted]

Re: DNS results now being manipulated in Turkey

#52
post #25

DNSSEC wouldn't stop this... unless the resolver knew to require DNSSEC and ignored unsigned responses (which is unlikely). DNSCrypt could help here... but chances are their middleware would just barf on it. You need something more evasive.

It wouldn't prevent getting the wrong answer, sure. But a smart resolver would see DS records at the parent and recognize it as an unsigned, thereby invalid, response.

Re: DNS results now being manipulated in Turkey

#53
post #14

Too bad DNSSEC isn't widely used; signing the records would prevent this from working. The government could still block the DNS requests, though.

As I pointed out above, DNSSEC doesn't stop this.

I am not just a DNSSEC hater, but the level of misunderstanding on DNSSEC is quite large.

When victim issues a query for youtube.com, I can intercept that query and hand back whatever response I want. Unless the victim KNOWS IN ADVANCE (which DNSSEC doesn't offer) that the response should be DNSSEC signed, they will accept my forged response.

DNSSEC solves problems we don't really have, and ignores the ones we do.

Re: DNS results now being manipulated in Turkey

#55
It's about time Turkey took a step towards US in controlling the flow of information. I mean, how long has this been going on here, undetected? The obvious solution, Turkey, is to target specific individuals after digging into their background, confirming that they are not computer experts before attacking them via their computer.

Re: DNS results now being manipulated in Turkey

#56
post #37

Earlier quoted context omitted.

So every voter in Turkey essentially knows what Erdogan is doing. So nobody who understands democracy should vote for Erdogan. If however not enough people understand democracy ...

Erdogan claims that there is a "global conspiracy to stop the rise of Turkey" and people who believe him don't care much about the unlawful things he is doing because you know, Turkey is under attack and extraordinary measures should be taken to protect the country. Polls show that %77 of the population believe the corruption case against the government is real. However the situation is really complicated. Without go…

Yes, it's really nasty. Three groups with different agendas and none of them interested in democracy or the rule of law.

Re: DNS results now being manipulated in Turkey

#57
post #23
post #16

Earlier quoted context omitted.

By default using a SOCKS proxy (which, using ssh -D is probably the easiest and most common way to do this) in most browsers doesn't solve this problem as DNS resolving is still done locally. As they're messing with DNS, you'll still be connecting to their evil version of YouTube through your SSH tunnel. In Firefox this behaviour can be changed by toggling network.proxy.socks_remote_dns in about:config. Of course, se…

Why isn't it default behavior to route dns through socks?

There are decent reasons for either way, the real question is why isn't there a visible option for it.

Re: DNS results now being manipulated in Turkey

#58
post #12

Earlier quoted context omitted.

> another solution would be for YouTube to require SSL for all connections coming from Turkish IPs. What? NO! They are messing with the DNS results from 8.8.4.4 (Google DNS) Too early for TLS to do anything. Maybe with HSTS, but I still doubt that HSTS is any effective against state level MITM.

Are you suggesting the government compromised a trusted SSL CA? Or are you just saying they blocked HTTPS?

Huh? The government of Turkey itself is a trusted CA http://www.mozilla.org/en-US/about/governance/policies/secur... Ctrl+F "Government of Turkey"

Re: DNS results now being manipulated in Turkey

#59
post #52
post #25

DNSSEC wouldn't stop this... unless the resolver knew to require DNSSEC and ignored unsigned responses (which is unlikely). DNSCrypt could help here... but chances are their middleware would just barf on it. You need something more evasive.

It wouldn't prevent getting the wrong answer, sure. But a smart resolver would see DS records at the parent and recognize it as an unsigned, thereby invalid, response.

Thus, DNSSEC doesn't protect against censorship.

It's hilarious that people are saying DNSSEC can be used in Turkey (or anywhere else) to defend against censorship. Either they don't know what they're talking about or don't care about having an honest discussion. Or both.

Re: DNS results now being manipulated in Turkey

#60
post #32

Earlier quoted context omitted.

The best democracy money can buy!

Actually, whereas I don't think Turkey is that far "gone" on the antidemocratic spectrum, but it has one thing in common with more severe cases of "border-line" democracy, like Russia: It's not the money that rigs the government, it's the government that rigs the money. In some sense, the US with their absurdly high campaign spending, avoid this kind of corruption either way just by competition. Even if a single inte…

The US elections are equally rigged - you vote for which faction of the mil-ind complex you like, and whether planned parenthood is funded - but not anything like wars, which simple continue as scheduled.
Post reply on HN