A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
MITM on HTTPS traffic in Kazakhstan
371–380 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#372Earlier quoted context omitted.
Your statement only applies to the subset of countries where there is judicial independence.
Which is true in case of India
And their defense claims US has SSN which is equivalent of Aadhaar why anyone can see ludicrous
And still Aadhar requirement is not removed for filing income tax return (which results in massive penalities)
Re: MITM on HTTPS traffic in Kazakhstan
#373What is interesting is that some local internet providers in Kazakhstan used to inject their own ads into http websites their users visit. I wonder if they will start doing the same with https now. I noticed this behaviour last February with Kazakhtelecom (telecom.kz) internet provider. When I opened an http website in my browser and started clicking randomly on the parts of the page which are usually not clickable,…
Comcast used to do this to me about 6 or 7 years ago to tell me, or someone, about torrent use on the connection and something or other about copyright infringement. They'd inject their messages into the html of websites and you'd have to dismiss them to continue to use the site. Not their site. All sites.
Re: MITM on HTTPS traffic in Kazakhstan
#374This will immediately block their services in the country and will raise awareness at scale.
Re: MITM on HTTPS traffic in Kazakhstan
#375Earlier quoted context omitted.
Not only that but they can happily MITM HTTPS as well. Not all the HTTPS sites use certificate pinning or HSTS.
It's a tough problem because certificate pinning kills a lot of legitimate use patterns; it's not something I'd like to see being the default everywhere.
Re: MITM on HTTPS traffic in Kazakhstan
#376A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
Re: MITM on HTTPS traffic in Kazakhstan
#377Earlier quoted context omitted.
Not only that but they can happily MITM HTTPS as well. Not all the HTTPS sites use certificate pinning or HSTS.
What root cert would they us for that?
Re: MITM on HTTPS traffic in Kazakhstan
#378A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
What is the extent of the MITM attack that you can do with this certificate? Can you intercept all https traffic?
Re: MITM on HTTPS traffic in Kazakhstan
#379A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
What is the extent of the MITM attack that you can do with this certificate? Can you intercept all https traffic?
Re: MITM on HTTPS traffic in Kazakhstan
#380Earlier quoted context omitted.
The government of my country has at least one certificate that's trusted by Mozilla (and I guess Chrome and Windows too) by default.
It won't stay trusted if it is actively used for MITM attacks. At least that's the idea.