Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

451–460 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#451

Earlier quoted context omitted.

In theory, in some case, it could be like that. In this case it's just like being in a city. They're not trying to take advantage of any particularly sensitive institution.

> They're not trying to take advantage of any particularly sensitive institution. They are. Amazon. And previously, Google. The worst-case consequence is not people losing access to Amazon store, but losing access to anything that's powered by Amazon cloud. People operating all kinds of services hosted on Amazon servers are the patients and hospital staff from my example.

Amazon servers are an entire city. There is a vast gulf between the equivalent of "being in a city that has a hospital" and the equivalent of "locating a base inside a hospital".

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#452
post #435

Earlier quoted context omitted.

Yes. It's called war. What's confusing here? If a citizen of a nation thinks that another nation is not behaving as they would like (whichever country or whatever behavior that is), the proper channels to enact change are through government action, either diplomatic or militarized. Asking a private corporation to be international police is not good for anyone, as well intentioned as it may seem.

You're being very nonchalant about going to war to make things easier for Amazon. I find that chilling.

I find it surprising how these threads get so lost in a just a few posts.

What I said is that if someone has an issue with another country (oppressive or otherwise) then they should use political means to influence change through their (and foreign) governments. As the commenter specifically stated the military, war is how that change is done in that case.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#453

Earlier quoted context omitted.

That would mean that Amazon was supplying Signals content as authentic Souq traffic, something that I doubt was happening.

Amazon was supplying Signal's content as souq.com but with the request making it clear it was for Signal. How might this be noticeable? Like so: - (irrelevant) the SNI and certificate presented by the server don't match the request -- only the hoster can see this, so what might they care? - (serious) metering: if the hoster uses SNI for metering... then Signal would be stealing the fronter's bandwidth - (mild) DNS me…

The metering isn't based o he SNI header, so the second point doesn't apply. And since the frontier's domains are presumably using the CDN's DNS servers anyway, it's not an issue either.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#454

Couldn't Signal use popular domains to host IP addresses as a rudimentary DNS server of sorts? For example, host a text file containing Signal server IPs on Google App engine (using the app.google.com address), Azure Blob Storage (using blob.azure.com endpoint), GitHub (raw.githubusercontent.com), S3 (s3.amazonaws.com), etc. There are hundreds of possibilities on some really popular hosting services. Then, when the a…

And then the censors can very conveniently block all those IPs too, can't they?

That's the point, it'd be a never ending game of cat and mouse, resulting in them blocking thousands of Amazon IPs. You don't have to plaintext the text files either, you could require some kind of shared secret from the app or user login to prevent the censors from just pulling the file in plaintext.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#456

Earlier quoted context omitted.

> They're not trying to take advantage of any particularly sensitive institution. They are. Amazon. And previously, Google. The worst-case consequence is not people losing access to Amazon store, but losing access to anything that's powered by Amazon cloud. People operating all kinds of services hosted on Amazon servers are the patients and hospital staff from my example.

Amazon servers are an entire city. There is a vast gulf between the equivalent of "being in a city that has a hospital" and the equivalent of "locating a base inside a hospital".

Then it's even worse, because the picture you're trying to paint implies that it's either leave guerillas alone, or nuke the entire city.

A ban of a cloud service affects everything else that depends on it. The more popular a service, the more damage. That's the point of "collateral freedom".

(Note the name of the term. It's no accident. It comes from "collateral damage".)

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#457

Earlier quoted context omitted.

Saying "we can't stop you from blockading, but we won't help you build regime-monitored passages through the blockade" is not sacrificing anyone.

To quote from the comment I replied to: > We simply need to shift the incentives by making it financially expensive to censor. This is known as "collateral freedom" In this context, "making it financially expensive" means "banning us would also mean banning lots of other unrelated services, which will have negative impact on both economy and morale of the population". In the same way, in warfare, using civilians as h…

The adversary is going to shoot down all packets that don't have certain labels on them.

Refusing to put those labels on packets is not putting anyone in harm's way. It's a refusal to help them treat certain classes above others.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#458

Earlier quoted context omitted.

Amazon servers are an entire city. There is a vast gulf between the equivalent of "being in a city that has a hospital" and the equivalent of "locating a base inside a hospital".

Then it's even worse, because the picture you're trying to paint implies that it's either leave guerillas alone, or nuke the entire city . A ban of a cloud service affects everything else that depends on it. The more popular a service, the more damage. That's the point of "collateral freedom". (Note the name of the term. It's no accident. It comes from "collateral damage".)

Block the road, not nuke the city.

But if they were going to nuke the city? Fuck them, don't negotiate, it is absolutely not the fault of any group that is merely located somewhere inside the city.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#459

Earlier quoted context omitted.

To quote from the comment I replied to: > We simply need to shift the incentives by making it financially expensive to censor. This is known as "collateral freedom" In this context, "making it financially expensive" means "banning us would also mean banning lots of other unrelated services, which will have negative impact on both economy and morale of the population". In the same way, in warfare, using civilians as h…

The adversary is going to shoot down all packets that don't have certain labels on them. Refusing to put those labels on packets is not putting anyone in harm's way. It's a refusal to help them treat certain classes above others.

In your strategy you only have three choices - put your own label, put someone else's label, or just give up. The labels are necessary for routing. If you put someone else's label on your packets, you're turning them into a potential target.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#460

It's a strange choice to use Souq.com as the target here. They could have used any AWS customer but chose to use one owned by Amazon. It probably is genuinely one of the biggest Middle East customers on AWS but going this way would really have forced Amazon's hand.

It needs to be big enough so you can try and rationalise the morality of the DNS call cost (even being a few dollars, you're still being a bad actor in this scenario), a site known and well classified by traffic monitors that they won't get blocked on their own.

I guess also that hitting an Amazon domain means the logical recourse is to get AWS restrictions (such as we have here), rather than having an aggressive this party company outright trying to sue.

Post reply on HN