Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

311–320 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#312
post #221
post #213

Kazakh here. Fuck, what do we do? Any suggestions other than trying to raise awareness? To give some context, the reason why they are getting away with such brute methods is that the most people wouldn't understand the full implication. I would be surprised if this would prove difficult to enforce - the first thing an ordinary person would do when, say, Facebook wouldn't load is to call up the Kazakhtelecom's support…

Raise awareness, spread the word about Tor. If they start running attacks against Tor, start an uproar. And pitch Tor as an elementary security measure; say "do this to make your communications more secure." It isn't perfect, but maybe it's better than nothing?

Kazakhstan already blocks Tor website and its bootstrap nodes. Also I heard that it has DPI hardware and made an attempts to block Tor traffic (but last time Tor worked for me with my private bridge). No uproars here :) Most citizens are not educated to understand what Tor is and will trust government, who'll tell them that Tor is for criminals and must be forbidden.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#313
post #281

Earlier quoted context omitted.

the ddos was achieved by altering the contents of one of the script on a large chinese site (was it baidu? google it). Once every user on that site loaded the tampered script, it made sure to send many requests to github.

Was the large Chinese site serving traffic over HTTPS?

Sadly, they (Baidu) are not, which is why the script content was easily modified.

To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#314
post #84

Earlier quoted context omitted.

Steganography needs vast quantities of cover data. You're increasing the bandwidth costs dramatically when you recommend steganography for everything.

Steganography needs vast quantities of cover data. Porn? Perhaps the world's smut peddlers will become beacons of freedom and civil disobedience? (Sounds like a Neal Stephenson book.)

Every huge porn site is banned in Kazakhstan. I believe that porn is forbidden here.

The worst thing — they just ban sites without any explanation. Site just stopped to work and you don't know why. Even w3.org was banned for some time (probably because its validator could be used as web proxy).

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#315

wait till private keys for the cert are leaked by some disgruntled telecom company employee.. Puts the whole country internet at risk.

I'm 100% sure that keys are in hardware device and couldn't be leaked. Kazakhstan has certificate infrastructure for years to issue digital certificates for their citizens. Nothing was leaked yet.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#316

Earlier quoted context omitted.

Was the large Chinese site serving traffic over HTTPS?

Sadly, they (Baidu) are not, which is why the script content was easily modified. To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.

Experiment? This isn't science. They can ask any engineer what MITM with a non-trusted cert would do, and that's nothing.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#317

Earlier quoted context omitted.

Down-right demand? With what authority? It sounds like you're confusing these corporations for governments, as if they had to enforce your human rights..

The authority of the free market. Did web PKI develop because of governments? No. In fact, quite the contrary. Similarly, if consumers are educated and aware of the weaknesses of current cryptography controls in light of new threats such as governments requiring the installation of their own root CA so they can middle the connection, maybe they'll drive demand for better controls, controls which already exist.

Consumers want their kitten videos. They would only view the dialog as an error message, something to get rid of.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#318

Earlier quoted context omitted.

Was the large Chinese site serving traffic over HTTPS?

Sadly, they (Baidu) are not, which is why the script content was easily modified. To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.

@andreyf: More like a social experiment. See whether people would notice (we did) and what's their reaction.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#319
post #278
post #267

Earlier quoted context omitted.

Sorry, no: Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. -- https://www.chromium.org/Home/chromium-security/security-faq...

How would the telco get their Private Trust Anchor into the certificate store ? More social engineering, i suppose. At the app level though, a chain resolution like what you describe is not required.

They will be telling citizens to install a "national security certificate". After they implement this, you won't be able to access the internet without it.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#320

I really appreciate how they're doing this. The Chinese built up an amazing infrastructure for the Great Firewall; the Kazakhs just say "install our cert!" The Chinese spend billions and have to stay ahead of all of their citizens' clever new ideas at all times; the Kazakhs spend a few hundred and just need to point guns at their citizens until they install a cert. Sure, it's going to be difficult to enforce, but it…

It's not even difficult to enforce. If you don't install their cert, you don't have access to the internet. Or you just have to force Chrome to ignore all SSL errors, which is the same thing.
Post reply on HN