MITM on HTTPS traffic in Kazakhstan
51–60 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#52Earlier quoted context omitted.
No, as the certificates are user installed. The Bugzilla and other threads are about distrusting that user certificate.
VPN with endpoint on affected ISP + Installing the cert (which is linked in the issue on Bugzilla) should be the same as just using the affect ISP directly, shouldn't it?
Re: MITM on HTTPS traffic in Kazakhstan
#53I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…
This is why I'm always advocating for political engagement for fighting these kind of issues. It's not exactly hard for a government to ban or forbid circumventing their monitoring. It does take time, but they're about to catch up.
This is also terrible for foreign investment and attracting business. It also makes foreign intelligence’s job easier.
Re: MITM on HTTPS traffic in Kazakhstan
#54I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…
We need new measures to not allow these certificates to be installed unless they're verified, or at least the OS shows a massive giant warning "DO NOT DO THIS unless you accept this cert gives $identity access to all your data". Seems a very solvable problem.
Re: MITM on HTTPS traffic in Kazakhstan
#55Question to local readers: Is Kazakhstan also blocking VPNs and SSH?
ZaTelecom Telegram channel (https://t.me/zatelecom) claims that that not all ISPs have rolled out the MITM attack. For now, a good solution would be to switch to a different ISP (it's not like in the US, each home has access to 2-5 different ISPs).
Also, users ask everyone to use a VPN. So, I think that they have access to VPNs.
Re: MITM on HTTPS traffic in Kazakhstan
#56hmm, certificate pinning will not allow this gov-ca to work for a lot of high profile web sites. i wonder if these sites with cert pins are whitelisted by the kz gov? -- somehow i missed that HPKP is dead and will be removed from chromium and all the derivative browsers. now google is focusing on Expect-CT
Re: MITM on HTTPS traffic in Kazakhstan
#57Re: MITM on HTTPS traffic in Kazakhstan
#58I find the social aspect of this interesting. Us "smart tech people" have been pushing https everywhere for a few years now as a way of protecting internet privacy "for the masses". And now the government found a very simple non-technical workaround. Send a message to everyone requiring a government root CA with an easy install, or their internet won't work. Now "us techies" have to find a new technical solution to a…
But we are in a better place than before. Without HTTPS everywhere and governments needing to ask people to install new root certs, we would not have learned about this Kazakhstan MITM issue.
Re: MITM on HTTPS traffic in Kazakhstan
#59Earlier quoted context omitted.
We need new measures to not allow these certificates to be installed unless they're verified, or at least the OS shows a massive giant warning "DO NOT DO THIS unless you accept this cert gives $identity access to all your data". Seems a very solvable problem.
Corporations also do this so they can scan traffic for data exfil.
Re: MITM on HTTPS traffic in Kazakhstan
#60Earlier quoted context omitted.
That would help people who already know what a root cert is, but it's well known that most people ignore any indicator in a URL bar. Even "smart people" ignore them. Do you actually check the lock status of every site you visit?
Most browsers have made the lack of a "lock" quite evident to end users.
If HN didn't have the lock in the url bar (no https), it would have zero impact on my behavior. I had to look just now to even know if there was one.