Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…
What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impac…
Kazakhstan to MitM all HTTPS traffic starting Jan 1
291–300 of 378 posts
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#292Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#293Earlier quoted context omitted.
I've been thinking about this lately, and it seems that you could use something like a book code. Client and server use existing internet accessible images as the book and then your communication simply references bytes in those images: client requests a URL that encodes the bytes it wants to send, server returns HTML containing the urls of images containing the bytes it wants to send in response (and any extra conte…
Just pass a DVD with white noise when you meet in person. That should keep you in one time pads as long as you want to communicate with someone. All you need is XOR and a bookmark. Of course you need to meet once , if that's not feasible you're going to get more technical.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#294Earlier quoted context omitted.
What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impac…
Certificate pinning does not work with certificates that are installed in the devices trusted certificate store.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#295Earlier quoted context omitted.
How would the telco get their Private Trust Anchor into the certificate store ? More social engineering, i suppose. At the app level though, a chain resolution like what you describe is not required.
I'll give you a hint: they run customs.
Also we are talking about apps implementing certificate pinning. Not reading from the OS store etc., and therefore, I don't see Kazakhstan reverse engineering and patching executables.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#296Earlier quoted context omitted.
Was that trusted root cert ever misused? IIRC, it was un-trusted because they did not do their due diligence on how an issued sub-cert was being used by an Egyptian company. What does the GitHub DDOS have to do with MITM attacks on https?
the ddos was achieved by altering the contents of one of the script on a large chinese site (was it baidu? google it). Once every user on that site loaded the tampered script, it made sure to send many requests to github.
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#297> The national security certificate will secure protection of Kazakhstan users when using coded access protocols to foreign Internet resources. How is this protecting users? They are outright lying here, if I understand correctly. Also why are they asking for my location? http://i.imgur.com/fYKHRK1.png
But obviously the security as a whole has to consider the increased risk due to the centralized cert, disregarding entirely the fact that you're trusting a totalitarian government with all of your secrets...
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#298Earlier quoted context omitted.
What do you do? You immediately reach out to Apple, Google, Facebook, Twitter, Box, Dropbox, Tumblr, and any other popular platform which has mobile apps. You ask, or down-right demand they implement certificate pinning in their apps so they will fail when middled with the government provided certificate. This will in turn break access to those platforms via mobile apps which will result in very real and direct impac…
Down-right demand? With what authority? It sounds like you're confusing these corporations for governments, as if they had to enforce your human rights..
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#299This is lame news. But what I'm curious about is: What are they going to do (if anything) to validate the upstream certificates? - What will their upstream root certificate policy be? - If they MITM any old upstream certificate, how will they mitigate the huge target they are painting on Kazakh Internet users?
Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1
#300Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…
>Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? Revolution or leaving the country are your only choices. There is no democracy so there is probably no way to resolve this grievance, and I doubt it would be anywhere near the top of list for most citizens. You can speak english and probably have computer skills, so I hope it would be possible for you to get out.
Just for the record, look to the US for a good example of how well democracy works for "resolving grievances".
Occupy Wall Street protesters aired some grievances, and were beaten and tased into submission. The same happens anywhere, every time the citizenry actually demands something.
It's kind of amazing how people still hold democracy as some sort of 'value' to strive for, when in reality it's just a PR-facade.