Live data from Hacker News

Kazakhstan to MitM all HTTPS traffic starting Jan 1

telecom.kz

361–370 of 378 posts

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#361
post #323

Earlier quoted context omitted.

Certificate pinning is absolutely targeted at stopping the use of rogue root CA's installed in devices. OWASP does a pretty good job of covering the topic. https://www.owasp.org/index.php/Certificate_and_Public_Key_P...

You just linked to 20 screenfuls of text that explain pinning in general, without a single mention of "rogue". The fact is that pinning as implemented in Chrome exempts installed CA's from pinning checks because they want to allow administrator-mandated MITM - apparently "market requirement" because it's a common practice in schools and workplaces in some countries that lack reasonable communications privacy legislat…

Of course a system misbehaves if you use an (intentionally) broken application. That's a Google Chrome issue and not an issue with pinning.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#363
post #145

Correct me if I'm wrong, but doesn't android display a rather ennerving "someone might be spying on you" warning when custom root certs are installed? I'm looking forward to the reactions when every (android-using) citizen of the country student gets that warning.

I installed some custom roots onto 4.4.2 the other night to MiTM some apps. I saw no obvious warnings at all.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#364
While I applaud the privacy advocates, we knew this was coming when HTTP/2 (RFC 4750-4751) because an official standard in May 2015. The only way a country with limited bandwidth can operate a transparent proxy is to stick a new certificate in the root chain so that it can decode, cache and re-encode the traffic.

I don't like it anymore than anyone else, but I see a non-malicious purpose here.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#365

Earlier quoted context omitted.

Whereas I'd say the problem was forced nationalisation.

A foreign coup is a valid response to nationalisation?

I'm not sure. But nationalisation is certainly a violation of rights.

Of course, I'd be interested to see how those assets were set up in the first place - my bet would be during a non-rights-respecting period of colonialism.

How far back do you go? (Serious question).

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#366

Earlier quoted context omitted.

> most people wouldn't understand the full implication So attack that. Tell a story. What does this allow the government to do? Could a jealous ex-lover who works for the government read their ex's messages? Could the local mayor find out if you've got a medical problem? Get an illustrator to draw these up as little comics. Make images that people can understand. This is a great example: http://www.wordstream.com/ima…

Keep the government out of our dick picks! John Oliver: Government Surveillance https://youtu.be/XEVlyP4_11M?t=1518

Ha! This is great. Might consider putting together something similar. Thanks.

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#367
post #283
post #274

Earlier quoted context omitted.

Thanks. That's a solid idea.

I created the above image. Just to give you an idea of how important it is to make sure that the message is easy to absorb, a few years ago this made it into the WCIT leaks: http://files.wcitleaks.org/public/WCIT12%20-%20ITRs%20and%20... Check out the fifth to last page, which is basically identical to what I created, if presented a bit worse. Did anyone give a shit? Nope. Is that a genuine logo of the fucking ITU, t…

Thanks so much for your offer to help - as soon as I figure out the best course of action I might contact you. The fact that they took the page down gives some hope - maybe they're not as reckless and understand that the public won't be happy about this. We'll see what happens next.

>In all honesty, make investors and bankers afraid and any government will shut up. This is a great idea in general, but it requires a strong corporate/investor establishment that is independent from the government. Unfortunately and unsurprisingly, 90% of the Kazakh Forbes list are either 1) straight up politicians, 2) politicians' close relatives (offspring and in-laws), 3) those, whose involvement with government is "open secret" (e.g. someone rumored as being a president's personal banker), or 4) those doing in oil and gas, heavily regulated industries where government's cooperation is required to make it work. :(

Anyways, thanks for all the insight!

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#368
post #302

Earlier quoted context omitted.

Beaten into submission? Maybe they tried that, but eventually what worked was that they were legislated into submission. They found some technicality for why they couldn't legally occupy that space, and everything went downhill fast after that. (I could be wrong. I wasn't paying much attention at the time.)

We can rest assured there were plenty of beatings and tasings involved - that's a big part of why some "people" become police officers in the first place. But the point is that the same thing happens everywhere. Not that long ago, Hong Kong's people protested against China appointing their rulers. They were beaten and maced etc. Brazilians protested against a massive waste of their money on The World Cup (or some suc…

I'd like to point out one difference: as far as I know, in the US police are never given orders to hurt protesters. In theory, they can even get in trouble for doing so. In the other countries you listed, this was official policy.

In any case, my point was that in the Occupy Wall Street case, these things occurred, but they are not what caused the final blow. The final blow was a court ruling that said they have to clear out. (The wording was a bit more subtle, but that's what Wikipedia is for.)

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#369
post #323

Earlier quoted context omitted.

You just linked to 20 screenfuls of text that explain pinning in general, without a single mention of "rogue". The fact is that pinning as implemented in Chrome exempts installed CA's from pinning checks because they want to allow administrator-mandated MITM - apparently "market requirement" because it's a common practice in schools and workplaces in some countries that lack reasonable communications privacy legislat…

Of course a system misbehaves if you use an (intentionally) broken application. That's a Google Chrome issue and not an issue with pinning.

You might have a point if Chrome hadn't been the first browser to implement pinning, therefore defining the concept in web context to a large extent.

You may argue that this is is broken behaviour, but that's what pinning currently is in browsers. Seems it's this way in Firefox too ("pinning not enforced if the trust anchor is a user inserted CA, default" - https://wiki.mozilla.org/SecurityEngineering/Public_Key_Pinn...)

Re: Kazakhstan to MitM all HTTPS traffic starting Jan 1

#370
post #286

I don't agree with all the comments here. A sovereign state decided to ensure all outgoing traffic is protected by a secure signature that is not possessed by foreign intelligence agencies or hackers (well, that's the idea). It is a very cheap and effective way to achieve this. Spying on the population is not prevented by GeoTrust and Cie's loosy certificates, a lot of literature and real life examples already show t…

It doesn't protect from a foreign intelligence agencies or hackers because connection is only encrypted by Kazakhstan's certificate to the point where MitM is performed by the government of Kazakhstan from that point connection to the website is encrypted with a valid certificate.

Even if what you said is true and western countries have private encryption keys of all websites I think that citizens of Kazakhstan would rather be spied by foreign governments than by their own government.

Post reply on HN