Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

471–480 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#471

Earlier quoted context omitted.

Boatload of VMs with constantly migrating IP addresses.

Which then has the problem of how do users find them (if by DNS, you can block the DNS record).

Service discovery is an actual interesting problem to solve when you don't outsource it to k8s, huh?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#472

Earlier quoted context omitted.

It takes longer to inspect applications that it takes to deploy into yet another VM provider and do push notifications or discovery. If censors had enough skills to handle it those countries would have been producing innovations leaving US and Western companies in the dust.

Push notifications? How do these work, when the app can't rely on access to any particular domain or IP? Your posts in this thread seem to include a great deal of hand-waving.

Here's a simplest push notification ever: email

It was used by Akamai to do automated billing from the edges in the nineties when it was the first network that billed per byte delivered at the edges with multiple tiers.

It is very easy to kill an annoying mosquito in a room if it can hide in 3 places. It is much more difficult if it can hide in thousands.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#473
post #188
post #180

Earlier quoted context omitted.

They're arguably impersonating Amazon on the server side by hosting their service behind Amazon's proxies and using a trick to pretend that they're talking to some Amazon service instead of their own.

The beauty of this is they are not doing anything on the server side to impersonate or spoof Amazon.

You're right of course, my comment was too short and factually wrong. What I meant was that what they're doing is effectively renting office space in Amazon's building and then exploiting a loophole in the way mail is distributed to receive packages even though the outside envelope says "c/o amazon.com" (or c/o souq.com in this case).

So while they don't do anything fishy on the server side they still took care to put their servers there for a reason. And since they also write the client code it's not difficult to show that the intent is to impersonate Amazon to 3rd parties.

Interestingly it seems that amazon couldn't really complain if the people writing the client were independent from those maintaining the servers since the spoofing code is entirely in the client. Although in the end I'm sure if it turned out to be a problem for they they'd just enforce that the domains match the HTTPS query and remove the technical possibility of fronting altogether.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#474
post #437

Earlier quoted context omitted.

You say "proper" but what you're describing (at least the military option) is a war of aggression. This is not only illegal (both internationally, and, for example, in US Law), but described as "the supreme international crime."

It's an option, and if it comes to war then the legality of whether it should've been declared is usually not a priority. Also in the context of oppressive regimes, the "aggression" in this case wouldn't be unwarranted, nor is it unprecedented. Regardless, what actually isn't proper is expecting major corporations to do police duty. That never ends well.

A war of aggression has nothing to do with whether or not it was declared (in fact, declaring such a war is, by itself, considered a war of aggression and is illegal and is a war crime).

Are you sure you still feel that committing a war crime and doing what philosophers and statesmen and lawyers consider the "supreme" crime is really worse than "expecting major corporations to do police duty" ?

I think part of your argument is reasonable to a point that two people could, in good conscious and respectfully, disagree. Maybe governments are better suited to handle this (via what is known as soft power).

But as long as you take such an extreme position that cannot be defended (it's better to wage of war of aggression than to have amazon stand up for Signal), you're just commenting for yourself. No one is going to engage you in meaningful discussion, because even when it gets pointed out that you're advocating for a war crime, you can't even say "well ya, maybe that was a bit extreme."

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#476

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…

Isn't the first problem that mr Marlinspike has been holding off federation of the Signal protocol? If anyone could run a server and join the Signal network (like Riot/Matrix, who got it right), the problem of circumventing censorship would be a lot easier.

Any one of these federated servers could use whatever tricks they like to circumvent censorship, and yes they'd risk getting banned themselves if their circumvention measures are violating TOS of where they're hosted, but they wouldn't have to demand special treatment in the light of that, like Moxie Marlinspike did, because it doesn't happen to block the entire Signal network at once.

Their lack of federation is their censorship weak spot. I haven't heard a single reason for holding off federation from Moxie (and the "best" reason I currently can come up with is that he has issues letting go of "his baby", other reasons being more nefarious). There's a lot of strongly principled wording about why Signal should or should not do certain things, because Signal doesn't want to rely on anything but the protocol itself to guarantee its security, privacy and censorship resistance.

But really, what are these principles worth if Signal is in fact reliant on a third party (Amazon) closing their eyes to violation of their own TOS? They shouldn't be, and federation allows for that property.

And to add one more reason, it's not entirely fair to Amazon. By using the load balancing trick, the only thing that Signal risks is getting banned from Amazon, they can rent another server from someone else and set up shop there. However, by allowing Signal to continue to use their load balancing service in this manner, Amazon is risking having their entire service banned by an oppressive regime. It's not really cool of Signal/Moxie to ask Amazon to take this risk for them.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#477

Earlier quoted context omitted.

> "They're spoofing identity" That's the entire point. By making it impossible for censors to distinguish Signal traffic from other web traffic going to AWS, domain fronting forces the government censors to either 1) stop censoring, or 2) censor many important websites that people rely upon. The associated economic cost has the tendency to discourage censors, and as shown by Signal, is actually quite an effective det…

My first thought is "How is it in the interest of Amazon's stockholders to prevent censorship in countries ruled by dictatorial regimes?" and secondly, "How does consenting to being a front for services that are strictly forbidden in certain countries benefit our company?"

This an abhorrent chain of logic. By this rationale everything should be permissible if it’s profitable and legal in the country it’s done in. Ethics be damned.

Slavery?[1] Fine. Assisting with genocide?[2] Ok. Human trafficking. Sure, as long as we’re making money. Now consider the likes of Facebook or Google. If Iran wanted to purge an ethnic minority from their country and offered a government contract to Facebook to help identify said minority, how is it in the interests of Facebook stockholders to prevent genocide in countries ruled by dictatorial regimes?

Finally, if what you say is correct - that in the current system the wealth of the shareholders is what matters most - I think the broader question becomes: “Why should western democracies continue to permit Laisser-faire capitalism if it refuses to impose any ethical or moral boundaries on itself?”

[1] https://www.quora.com/To-what-degree-has-Dubai-been-built-by...

[2] https://en.m.wikipedia.org/wiki/IBM_and_the_Holocaust

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#478

Earlier quoted context omitted.

Capitulating to foreign censors for business reasons has something to do with censorship.

Amazon has a ton of customers, at least a few of which like https://preemptivelove.org/ are also doing good things in these countries. It's not just Amazon that suffers, but Amazon's customers and everyone else downstream.

Signal was hiding behind Souq.com which is owned by Amazon.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#479

Earlier quoted context omitted.

> simply using a domain name you dont own in the SNI header just because it is terminated at the same service as you want to use is something you cannot do Why not out of curiosity? I'm not disputing Amazon's right to disallow this (it's their service after all), but before that I don't see any objective reason why this is something they they "cannot" or even "should not" do. Also, unless Amazon put in a technical ba…

> Why not out of curiosity? Because you are lying about what domain you want to access. This is against the TOS, and simply something you should not do. I know it helps signal to get around censorship and blocks, and it's technically working, but one should not do that.

I'm not lying about anything. This entire system is designed so that the user can get what they're looking for, and the user is using it to get what they're looking for.

Whether doing this as AWS's customer breaks their TOS is up for debate, but it's a fairly moot one as Amazon could easily change their TOS.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#480
post #309

Earlier quoted context omitted.

I realize now, that it's possible to even dynamically deliver a bytecode of a domain generating algorithm itself or pretty much any circumvention logic by embedding a tiny interpreter into the app.

You don't need to deliver bytecode, just a new seed for the algorithm. Even 64 bits is more than sufficient to ensure that they can't enumerate all possible seeds.

Seeds don't impose human costs of reverse engineering though. Which could be important in some cases, since we are up against state actors.

But yeah, having seeds sharded per id/phone_number same way I proposed above could make it pretty much unblockable.

Post reply on HN