Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

201–210 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#201

I really appreciate how they're doing this. The Chinese built up an amazing infrastructure for the Great Firewall; the Kazakhs just say "install our cert!" The Chinese spend billions and have to stay ahead of all of their citizens' clever new ideas at all times; the Kazakhs spend a few hundred and just need to point guns at their citizens until they install a cert. Sure, it's going to be difficult to enforce, but it…

Chinese govt is also capable of doing this. Best part? We even have our trusted* root certificate! Could this get any "better"? Sure! We can even MITM all the OUTGOING https traffic if we want! #GitHubDDoS * Recently un-trusted by Apple and Mozilla. https://support.apple.com/en-us/HT204938

I really don't understand how that sort of behaviour doesn't constitute an act of war.

Imagine if China sent saboteurs in-country to physically destroy infrastructure being used by American businesses. That would Not Be Taken Lightly.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#202

Earlier quoted context omitted.

There was no public uprising after Snowden in the US either ... Some will now say you can't compare this. They are right because what Kazakhstan is doing there looks amateurish.

For a while, I've been in the camp that the Snowden leaks were intentional and that he still works for the US. A rich work from home government contractor, with a smoking hot girlfriend, takes off with secrets and hides in Russia. His hot girlfriend is even allowed to join him. I think it's more likely the Snowden leaks were to show just how little Americans care. They're using that spy network to track reactions.

what does the attractiveness of his girlfriend have to do with it?

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#203
My first thought, any tech company to setup offices in this country are probably out the window. However, more importantly, they just made it really easy for other governments to spy on them. In their zeal to protect national security, they have done just the opposite.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#204
post #84

Earlier quoted context omitted.

Steganography needs vast quantities of cover data. You're increasing the bandwidth costs dramatically when you recommend steganography for everything.

Steganography needs vast quantities of cover data. Porn? Perhaps the world's smut peddlers will become beacons of freedom and civil disobedience? (Sounds like a Neal Stephenson book.)

That's a terrible TX/RX ratio. Unless you encode data in each request and receive small pictures only, it would take ages to send any real information. Good for receiving though.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#205

I wish somebody could tell me what this means half technically. My mind is wavering between this is a good thing because everyone's connection is becoming secure to not a good thing for reasons unknown.

It seems like you've got it backward. Kazakhstan is not making the internet more secure. They're requiring citizens to install something (their own root security certificate) that compromises the security of https. The result is that their government can eavesdrop on all traffic, encrypted or unencrypted. That's the story anyway.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#206
post #72

Google, Facebook, Yahoo, Microsoft, Salesforce, Box, Dropbox, Twitter, etc. could have a very strong influence on changing this if they banded together to respond to this in some way. The government might be doing what they think is right, but public backlash can change policy almost overnight. We saw this in the US recently with SOPA/PIPA. The "Internet" response was unprecedented. The people of Kazakhstan can achie…

Well they could make using client certificates mandatory from Kazakhstanian ip addresses. Now the gov server can't connect and so can't MITM anything.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#207
post #83

Woah, it can't be stressed how bad this is. If this succeeds, other countries will definitely follow! If it can be shown to work, it will be demanded that this be implemented by pretty much everyone for difficult to deny political reasons (terrorists, children, crime, etc) This feels like the first bullet in a new war that will occur in every parliament world wide.

It is already par for the course in the enterprise world (both public and private sector), for difficult to deny political/economic reasons.

Which is quite another thing, after all you are using somebody else network, just as you have every right to hear Adeles new album in your home, but not in mine.

Besides these days you can use your own phone and mobile data, at which point you should be safe.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#209

wait till private keys for the cert are leaked by some disgruntled telecom company employee.. Puts the whole country internet at risk.

Unfortunately that might be the most effective way to fight this type of thing. Massive incident that would show the foolishness of the move.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#210
post #199

Earlier quoted context omitted.

They can just block everything by default and only enable what they can decrypt. Maybe you could try tunelling encrypted data over HTTP, but heuristics could probably pick that up too.

Well, in that case I'm just going to invent a TCP-over-cat-pictures VPN. Encode all the TCP packets in the subtle details of the fur and package everything up as innocent-looking HTTP GET requests. This realistically shouldn't be too hard to do with obfsproxy's already-built framework.

Pretty easy really. Without knowing the key for the steganographic algorithm, it's really hard to get the data out unless you can compare it to the original. So if you're sourcing the pictures from somewhere, you'll need to manipulate false bits that aren't called for from the data itself to keep it from being breakable in such a manner.
Post reply on HN