Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

111–120 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#111
post #25

What was it that convinced Google and Amazon to no longer allow this particular censorship evasion?

Russia made it clear that they would block AWS and Google Cloud if domain fronting was allowed to continue. https://arstechnica.com/information-technology/2018/04/in-ef... As moxie says in the blog post >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. In the end, the rest of the internet didn’t like that plan.

I have looked into the Russia/Telegram war thoroughly due to personal interest, and to my knowledge that situation hasn't involved domain fronting. Rather, Russia is blocking by IP and Telegram is hopping to IPs all over the cloud.

Russia is on record as wishing to go a different path than the Great Firewall of China. From statements I read including Putin, they're saying they want to avoid a deep packet inspection regime à la NSA or China except when they've got a court order to go after someone in particular.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#112
post #102

Earlier quoted context omitted.

I agree. The intent is noble, but this headline makes Amazon look like the bad guy for disapproving unauthorized use of one of their domains, which is quite reasonable.

Hardly reasonable. Domains are (in reality, if not in legislative fantasy) property of ICANN and merely rented by everyone else.

So? If we qualify it to preventing unauthorized use of one of their rented domains does that make it any less reasonable?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#113

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

So AWS finally lost enough money to the Russian blockade that they caved. Sad.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#114
post #16

Earlier quoted context omitted.

The part you're missing is: ... to third parties. They aren't spoofing the domain, they are just making sure that outside parties to an SSL connection will have a difficult time determining where that SSL connection is going. The two parties creating the SSL connection are not lying to each other, though.

But the result may be Amazon getting blocked in those countries, which could cause Amazon financial and logistical harm. I'm all for Signal helping people bypass state censorship, but they're attempting to bring third parties into the fold and use them as fodder for the cause.

That's the whole point of this, by blocking Amazon, these countries would be taking down a large part of the Internet inside their borders. We're not talking Amazon your one stop shop for dildos and bobble heads, but AWS, which powers a lot of other websites. The countries listed, like Egypt, know that you can get away with torture, but don't touch the people's memes.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#115

Sorry, I'm not on board with using an Amazon owned domain for this. That's got the potential to get Amazon itself blacklisted in some places, so they're absolutely not going to be okay with it.

Or it forces oppressive regimes to realize that they are being an oppressive regime. Want to censor the internet, fine, send your citizens back to the dark ages; see how long it is until they protest or move.

Sure, but the point being is that Amazon is not consenting to being a bargaining chip in this manner. If you're in control of a site, and you want to say, "If you block them, my site will be blocked too, in solidarity," that's just fine. But it would be pretty awful for you to involve me in that, as well, if I don't wish to be part of it.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#116

Couldn't they ask people to donate their AWS instances or a portion of their webserver (or domain) resources to running a small outward facing webserver as a dummy, making the domain look like its a real website (eCommerce etc) and then passing Signal data through a Shadowsocks (or something similar) proxy? Couldn't they develop an AMI that they hold the keys to that people could deploy with ease?

Those who wish to suppress Signal would just play whack-a-mole. They'd login to Signal, find what domains it was connecting to and then block those. To update Signal with new addresses constantly, you'd need a server hosting those updates- which would in turn be blocked immediately.

The idea of using Souq.com or Google.com as the domain name in the TLS header was that even oppressive regimes won't block Google or Souq for their entire country.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#117

Earlier quoted context omitted.

If they were self-hosted, it would be even easier for Iran to block them.

If they hosted on VMs they would simply hop from one place to the other. The problem is that all of this stuff is "difficult" and no one would be writing stories about how great signal is if it could switch between thousands of companies that provide VMs to masses. We do not have these thousands of companies because AWS/GCS/Azure are the go to. Well, guess what? That means that objectively there are three kings of th…

> If they hosted on VMs they would simply hop from one place to the other.

No, that isn't a good enough solution. Signal needs to be reliable, or it's not worth having at all. The fundamental problem is node discovery: allowing the users to discover the IP address of the mothership (or, if you prefer, other members of the P2P network, but Signal is a centralized network) without the oppressive regime finding those IP addresses. Domain fronting was supposed to be a "cut the knot" solution, but CDN providers are shutting it down.

Tor's approach has been to use a La Resistance approach, where Dave in the US runs an obfsproxy node for Yasim and his twelve trusted friends, that's how node discovery works, and as long as Dave is a good sysadmin and nobody squeals it's reliable. Personally, I think that's the only sustainable solution, but it's not very user-friendly, because you need to have trusted confidants on the other side of the firewall that your government doesn't know about. Signal can't be that trusted confidant, though I imagine Signal works over Tor just fine if you set it up.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#118
post #89
post #66

Earlier quoted context omitted.

They say it doesn't solve the problem - "Would adding federation to Signal help with users behind country-wide blocks? Seems like a distributed service would be harder to censor than a centralized one." - "It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. Only the users of that software wo…

I think it may depend on how well distributed would a service be: having several big servers would not help but if every family and company had their own mini server, located in a non-censoring country then the censors would be unable to do anything easily. These servers, in turn, would be able to easily connect to the broader network. Of course that wouldn't be as easy to setup as a simple installation of the Signal…

An aspiring censor could also "easily connect to the broader network" and masquerade as a federated server in order to discover others. This process could even be automated.

Federated services also require an identifier, and this identifier usually indicates where the user's account is located and how to connect with them (e.g. user@domain.com). As people share these identifiers, the aspiring censor can just keep adding new entries to the blacklist.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#119
post #16
post #4

Misleading headline? > Signal plans to make its traffic look like traffic from another site, (popularly known as “domain fronting”) by using a domain owned by Amazon -- Souq.com

The part you're missing is: ... to third parties. They aren't spoofing the domain, they are just making sure that outside parties to an SSL connection will have a difficult time determining where that SSL connection is going. The two parties creating the SSL connection are not lying to each other, though.

But in order to do that, they're dragging an unrelated third (fourth?) party into it, without their consent.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#120
post #69

It seems centralized solutions (Telegram, Signal) are under fire recently. I wonder what would happen if federated protocols (Matrix, XMPP, etc.) were more popular and, thus, also in spotlight.

Unfortunately, federation is not an effective tactic against censorship: https://news.ycombinator.com/item?id=16871352

Peer-to-peer, on the other hand, is.
Post reply on HN