Live data from Hacker News

Amazon threatens to suspend Signal's AWS account over censorship circumvention

signal.org

71–80 of 519 posts

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#71
post #6

So they're basically asking for forgiveness instead of permission, fronting other sites until they are told to stop?

You can’t really stop someone from domain fronting on any CDN. This is like “maybe you should have not talked about this on HN”. :)

Exactly, bragging about this hack made them do something about it.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#72

Sorry, I'm not on board with using an Amazon owned domain for this. That's got the potential to get Amazon itself blacklisted in some places, so they're absolutely not going to be okay with it.

Or it forces oppressive regimes to realize that they are being an oppressive regime. Want to censor the internet, fine, send your citizens back to the dark ages; see how long it is until they protest or move.

I'm guessing you haven't spent much time looking into how oppressive regimes work.

They aren't going "to realize that they are being an oppressive regime" and have an epiphany where they realize, "Hey maybe I'm an evil dictator?"

If you are up for reading, I highly recommend Michael Malice's book, Dear Reader: The Unauthorized Autobiography of Kim Jong Il . After reading that you will completely understand why "see how long it is until they protest or move" is a silly thing to say.

[1] https://smile.amazon.com/Dear-Reader-Unauthorized-Autobiogra...

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#73
post #59

I'm thinking of a legislative, not technological solution to this, which seems to be pretty straightforward: make it unlawful for US companies to refuse service simply for Domain fronting. That way, none of the big companies could lawfully refuse service to Signal; neither could they be faulted by these other regimes for "letting Signal use their domain".

No, the solution is to solve the technical problem of leaking metadata during the TLS handshake.

Should it also be unlawful to refuse service to someone who pretends to be you when they resell your widgets to the mob because they fear retaliation if the mob isn't happy with the goods?

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#74
Based on the story Amazon has no problem with you circumventing censorship, it is not the subject of the topic at all, do not lie please because you only hurt your own reputation and trustfulness - which in a highly sensitive area that you are working in is paramount!

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#76
post #11

I still don't understand why would Google or Amazon care about this, and why it's against their ToS. Do they think that some of those states may block all kind of access to their IP blocks just because of some people using Signal?

I can imagine why someone cares if someone else pretend being that someone....

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#77
post #67

Earlier quoted context omitted.

Or it forces oppressive regimes to realize that they are being an oppressive regime. Want to censor the internet, fine, send your citizens back to the dark ages; see how long it is until they protest or move.

Amazon isn't in the business of forcing oppressive regimes to realize they are oppressive regimes, they are in the business of selling goods and services regardless of the oppressiveness of the regime governing the region where the currency comes from. If you want Amazon to stop doing business with oppressive regimes, contact your politicians about sanctions.

[deleted]

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#78

They're spoofing identity of non-consenting parties. The cause is noble, but it isn't what the headline would imply. Amazon isn't saying "You can't host encrypted services on our platform", they are saying "You can't use TLS and load balancing hacks to pretend to be us in oppresive countries". And >The idea behind domain fronting was that to block a single site, you’d have to block the rest of the internet as well. I…

Am I missing something, or is anyone using a CDN domain fronting?

An HTTPS connection sends the domain it wants to connect to in two layers: first unencrypted in the TLS headers, then encrypted in the HTTP header.

In a regular connection (even using a CDN), those two will match. Using domain fronting, you put a popular domain in the unencrypted part, and the real domain in a encrypted HTTP header.

Due to how they're implemented, the load balancers at Google and Amazon will ignore the first (unencrypted) layer, and will send the traffic to the correct server based only on the encrypted HTTP header.

Regular browsers always send the same domain in both layers, only a custom app like Signal can perform domain fronting.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#79

Sorry, I'm not on board with using an Amazon owned domain for this. That's got the potential to get Amazon itself blacklisted in some places, so they're absolutely not going to be okay with it.

Or it forces oppressive regimes to realize that they are being an oppressive regime. Want to censor the internet, fine, send your citizens back to the dark ages; see how long it is until they protest or move.

You think oppressive regimes don't already realize what they are?

They simply don't care.

Re: Amazon threatens to suspend Signal's AWS account over censorship circumvention

#80
post #74

Based on the story Amazon has no problem with you circumventing censorship, it is not the subject of the topic at all, do not lie please because you only hurt your own reputation and trustfulness - which in a highly sensitive area that you are working in is paramount!

The technique that Signal was using to circumvent censorship (domain fronting) will no longer be possible on Amazon:

https://aws.amazon.com/blogs/security/enhanced-domain-protec...

Post reply on HN