Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

131–140 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#131

This is nothing to do with censorship. AWS has many clients and does not want its network to be blocked because of a single customer. Tough for Signal but that's how it is when dealing with businesses (especially one that so many others rely on). The same thing just happened with Telegram in Russia which explains the preemptive messages: https://arstechnica.com/information-technology/2018/04/in-ef...

The loss of domain fronting as a viable strategy means that it will be possible to censor Signal in areas where the service was previously working.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#132
post #66

It seems centralized solutions (Telegram, Signal) are under fire recently. I wonder what would happen if federated protocols (Matrix, XMPP, etc.) were more popular and, thus, also in spotlight.

They say it doesn't solve the problem - "Would adding federation to Signal help with users behind country-wide blocks? Seems like a distributed service would be harder to censor than a centralized one." - "It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. Only the users of that software wo…

It sounds like a hard thing, but in case of XMPP "rebuilding your social graph again" is very easy - it's just a matter of importing your roster and sending authorization requests where needed. Could be, and probably already is, easily automated with some user friendly tool.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#133

Wouldn't it make more sense to build TOR or something like it into signal for these use cases?

Tor was actually using the same trick to avoid censorship: https://blog.torproject.org/how-use-meek-pluggable-transport

meek-amazon makes it look like you are talking to an Amazon Web Services server (when you are actually talking to a Tor bridge), and meek-google makes it look like you are talking to the Google search page (when you are actually talking to a Tor bridge).

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#134

Earlier quoted context omitted.

Capitulating to foreign censors for business reasons has something to do with censorship.

No, it doesn't. This is Amazon saying they don't wish to be a part of this dispute, which is entirely their right. It is not Signal's right to drag Amazon into the dispute against their will.

Amazon stepping away is literally the result of censorship working.

It's entirely their right of course.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#137

Earlier quoted context omitted.

Capitulating to foreign censors for business reasons has something to do with censorship.

No, it doesn't. This is Amazon saying they don't wish to be a part of this dispute, which is entirely their right. It is not Signal's right to drag Amazon into the dispute against their will.

> they don't wish to be a part of this dispute,

Right, because of the risk of being blocked.

It is their right, but to say it's not motivated by a risk of censorship is pretty disingenuous.

(I have no horse in this race. I'm merely contextualizing the debate)

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#138
post #76
post #11

I still don't understand why would Google or Amazon care about this, and why it's against their ToS. Do they think that some of those states may block all kind of access to their IP blocks just because of some people using Signal?

I can imagine why someone cares if someone else pretend being that someone....

No, the trick works the other way around; they pretend they want to talk to someone, but then talk to someone else. They never pretend to be someone else.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#139
post #118
post #89

Earlier quoted context omitted.

I think it may depend on how well distributed would a service be: having several big servers would not help but if every family and company had their own mini server, located in a non-censoring country then the censors would be unable to do anything easily. These servers, in turn, would be able to easily connect to the broader network. Of course that wouldn't be as easy to setup as a simple installation of the Signal…

An aspiring censor could also "easily connect to the broader network" and masquerade as a federated server in order to discover others. This process could even be automated. Federated services also require an identifier, and this identifier usually indicates where the user's account is located and how to connect with them (e.g. user@domain.com). As people share these identifiers, the aspiring censor can just keep add…

At least in case of XMPP, the client doesn't need to be able to connect to other domains, so as long as you can connect to your own server outside of the censorship's reach (which could be accessible for c2s connections in a completely different way than for s2s), you should be fine.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#140
post #95
post #59

I'm thinking of a legislative, not technological solution to this, which seems to be pretty straightforward: make it unlawful for US companies to refuse service simply for Domain fronting. That way, none of the big companies could lawfully refuse service to Signal; neither could they be faulted by these other regimes for "letting Signal use their domain".

Good, go ahead and pass those laws and I'll use Cloudfront to impersonate Amazon.com and steal credit card info, and Amazon will be legally unable to stop me.

You've misunderstood how the trick works. Nobody is impersonating anybody.

To make an analogy, they're like a guy who tells the building security guard that they're going to apartment 5 (the Souq servers), but when they're in they actually go to apartment 8 (Signal's servers).

Except the censors can only see the conversation with the guard, but they can't see where he actually goes, so they can't distinguish him from a real Souq visitor.

Post reply on HN