Earlier quoted context omitted.
Or they just dont want to be put in the position of having to give out keys. I think the real paranoid people use cloudHSM.
Both KMS and CloudHSM are FIPS 140-2 Level 3 and AWS claims they cannot read private keys from KMS. The main difference is KMS uses IAM and the AWS REST API while CloudHMS uses PKCS #11/JCE and a separate permissions system.
Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
171–180 of 195 posts
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#172Earlier quoted context omitted.
That's literally what VPNs are for. If you aren't aware: a Virtual Private Network creates a fully encrypted link between you and a remote node. So long as your encryption keys are secure, there's no way for anyone (even a global superpower) to listen to or intrude on that connection. There is no possible way to break into this connection, even with the entire planet's computing resources. From the outside, all you c…
Thanks for the reply. In order to connect to the VPN, your first call must be over https, from China, to the VPN. How does that circumvent the phenomenon in the article, where a nation state was injecting TCP to cause your connection to hang up, thus no VPN connection?
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#173Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#174Earlier quoted context omitted.
Both KMS and CloudHSM are FIPS 140-2 Level 3 and AWS claims they cannot read private keys from KMS. The main difference is KMS uses IAM and the AWS REST API while CloudHMS uses PKCS #11/JCE and a separate permissions system.
The docs say both use HSM. Under "Secure" in the accordion menu https://aws.amazon.com/kms/features/#topic-0
https://www.marvell.com/products/security-solutions/liquidse...
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#175Shouldn’t the rest of the world be blocking connections from China.
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#176Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#177Earlier quoted context omitted.
They have a minor capability to do intra-constellation routing now but if they want to operate in China the authorities are going to demand all data be downlinked through Chinese downlink stations so they can do their monitoring.
I wasn't aware that China does this. I know India does too though, for this reason only Inmarsat is allowed there because they cooperate with the authorities (and I believe even that is subject to local licensing). Though India doesn't have a great firewall so it's much less of an issue for foreigners visiting there.
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#178Earlier quoted context omitted.
But America isn't a place. There's the America s , as in plural, referring to the continents of North America and South America. So America is unassigned, hence why we assigned it to the USA colloquially.
Just for the sake of it I checked Wikipedia. > The Americas, sometimes collectively called America, are a landmass comprising the totality of North America and South America. When viewed as a single continent, the Americas are the 2nd largest continent by area after Asia, and is the 3rd largest continent by population. The Americas make up most of the land in Earth's Western Hemisphere and constitute the New World. Y…
It’s a silly side discussion in which nothing new is being said. Complaining that America generally refers to the country is a hobby for some folks, and that’s fine, but it’s only entertaining for them.
If someone needs the America you’re talking about specified, i.e. they can’t figure it out from context, the discussion is sort of moot. (Same way one can use the word Europe despite it being incredibly ambiguous. Overspecificity comes at the cost of conciseness.)
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#179Earlier quoted context omitted.
That's literally what VPNs are for. If you aren't aware: a Virtual Private Network creates a fully encrypted link between you and a remote node. So long as your encryption keys are secure, there's no way for anyone (even a global superpower) to listen to or intrude on that connection. There is no possible way to break into this connection, even with the entire planet's computing resources. From the outside, all you c…
Thanks for the reply. In order to connect to the VPN, your first call must be over https, from China, to the VPN. How does that circumvent the phenomenon in the article, where a nation state was injecting TCP to cause your connection to hang up, thus no VPN connection?
Besides that, when negotiating a secure connection through unencrypted channels you typically use Diffe-Hillman to establish the encryption keys. As far as I'm aware, this method cannot be broken. Both nodes compute their own private encryption key and do math to create unencrypted data that must be verified by the other node's key. Even if you had full control of the data stream, you can't determine those private keys and cannot break into the encrypted connection that follows.
Also VPNs are typically UDP, but there's no hard requirement as far as I know.
Re: Analysis of the GFW's Unconditional Port 443 Block on August 20, 2025
#180Think of how many people who have remote jobs with American companies couldn't connect to their meetings while they "work from home" while secretly being in China! Normally they have to fight VPN issues anyway, but having a sovereign state inject your packets is certainly a fun new one.
How common can this really be? And what kind of companies? I’m finding it really hard to imagine this to be widespread.
I'll just say Microsoft is not the only company doing that, and there are also Chinese-owned SAASes which American companies pay for.