Live data from Hacker News

Identifying Airtel middleboxes that censor HTTPS traffic

iamkush.me

101–110 of 130 posts

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#101
post #81

Earlier quoted context omitted.

I also get redirected to the HTTPS site. I think different ISPs block inconsistently.

Airtel is so big they use roaming for their customers. If you have a SIM from Bengaluru and go to Delhi you'll see the little R indicator. That suggests the Airtel business in each state manages at least parts of their network independently. And so the MitMs could be deployed non-uniformly.

India used to be and still is split into several telecom regions with different spectrum leasing, operations and governance.

Until around 2009-10, when you are traveling out of state, you had to pay roaming charges. Worse used to be metro cities within their own states as they used to be different telecom circles. I used to pay roaming charges when going to Chennai from rest of Tamil Nadu. Even the operators were different sometimes. E.g. there was no Hutch (now Vodafone) originally in rest of Tamil Nadu and they operated only in Chennai. Similarly RPG (later Aircel which went bankrupt couple of years back) had 2 networks - RPG in Chennai and Aircel in rest of Tamil Nadu. It used to be a mess.

No operator had pan-India operation as every small operator had their own fiefdoms and the big operators like Airtel used to pay roaming charges to those operators for their subscribers to get signal.

This all slowly went away only early this decade.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#102

Earlier quoted context omitted.

At some level, everywhere has some form of censorship. For any country you could name, there are, or could easily be, content in any kind of media - books, audio, video, games, whatever, that is so abhorrent that it would either not be published, or would be shut down as soon as possible. So if you say censorship is binary, it's already here, and has been here for ever. But I would guess that few believe that censors…

Censorship is fine if it's opt in. I don't use facebook and censor myself from it. I opt in to use a pihole and adblocker. It filters many things I otherwise would see. You can't often choose your ISP so this makes it extra important for censorship of any kind of to be opt in rather than forced.

My kids will not opt-in to censoring "Thomas the Train" videos when they should be doing their school work.

I think I just got everyone to take a step down the slippery slope.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#103
post #98

Earlier quoted context omitted.

Client Evil Middlebox Real Web Server Client establishes a tcpcrypt session with what it thinks is Real Web Server but is actually Evil Middlebox replaying the request to the server and the response back to the client.

Oh so A and B are describing the same scenario, okay.

Yeah, I'm not sure what the parent was getting at separating them out since from the clients perspective they're the same. I guess they mean that getting a tcpcrypt connection on your server isn't a guarantee that there isn't a middlebox either.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#104
post #34

Earlier quoted context omitted.

Yes, ISPs are blocking DDG. Airtel(ISP) is blocking DDG but HTTPS version is accessible. https://imgur.com/a/y7wnOjD

What reason could they have for blocking DDG? Is it easier to find pirated content there than on Google or something? That's my best guess. I can't imagine they'd block on behalf of a competitor or something.

Is it possible the big guys will provide (sell?) query surveillance feeds to random governments while DDG can't/won't?

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#105

On a meta level, this is one of the reasons why I tell every junior/entry level person I encounter in the ISP business the following: Ethics is important in network engineering. You can and should refuse to do things that cause measurable harm to the Internet. You should understand why certain things are bad, and should make a conscious choice not to aid and abet them. It is regretful that organizations like NANOG, R…

All well and good, but are these kind of 'middleboxes' unequivocally unethical? For example, some ISPs might want to block highly illegal content - let's use the typical examples, e.g. child porn sites, malware domains, and so on. It's not inherently unethical (or, at least, there are plenty of reasonable people who would say it is ethical) to install a middlebox that will make it more difficult for users to access t…

How do you propose to determine that a new, never-seen-before URL hosts child porn? In the US, viewing child porn is a strict-liability offense, meaning you are guilty of a serious felony just by looking at a page with the image(s) on it.

There are also civil and criminal liability concerns at the corporate level by assuming the responsibility for constructing and/or maintaining these filters.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#107
post #34

Earlier quoted context omitted.

Yes, ISPs are blocking DDG. Airtel(ISP) is blocking DDG but HTTPS version is accessible. https://imgur.com/a/y7wnOjD

What reason could they have for blocking DDG? Is it easier to find pirated content there than on Google or something? That's my best guess. I can't imagine they'd block on behalf of a competitor or something.

Ducks are considered sacred in India, or so I have heard. I could be wrong though.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#108
Theoretically, lets say am in India, using a tor browser, or an opera browser wit inbuilt VPN, would I see different results? my point is to see whether a VPN of sort can circumvent, in that case, what if all those browsers decides to create inbuilt vpn (for connection origins)..

does that makes sense?

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#109

Theoretically, lets say am in India, using a tor browser, or an opera browser wit inbuilt VPN, would I see different results? my point is to see whether a VPN of sort can circumvent, in that case, what if all those browsers decides to create inbuilt vpn (for connection origins).. does that makes sense?

A VPN would prevent SNI snooping since traffic over it is encrypted. Of course, the ISP could block the TLS handshake between you and the VPN server if that's how your VPN functions.

Tor would similarly work.

Re: Identifying Airtel middleboxes that censor HTTPS traffic

#110

This is completely off-topic but the strike-through on links had me confused for a good few minutes. I was not clicking on those because I thought the link were not valid today and hence it has strike-through.

What strike-through?

All links have a thin red line through them: https://pasteimg.com/images/2020/09/29/strika.png
Post reply on HN