Live data from Hacker News

TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

privateinternetaccess.com

71–80 of 102 posts

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#71

Earlier quoted context omitted.

Absolutely not. Full MITM proxies are required to inspect traffic. Inspecting SNI is ineffective against the majority of threats including blocking botnet traffic.

How so? If I as the MITM (non-decrypting) proxy intercept the request, look at the SNI to ensure it’s on my whitelist, and then do my own DNS lookup and open my own TCP connection to that IP and relay the traffic between the two, what’s the attack vector?

Attackers can break into legitimate, low security, websites and use them as attack vectors. It's often easier that attacking the target directly and it's been done for decades.

Also, botnets uses legitimate services to rely C&C traffic. Forums, pastebins, github gits, IRC and email gateways, VMs on AWS and other cloud services...

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#72
post #55

The author does not consider that a filter can block TLS 1.3 and force apps to continue using TLS 1.2.

The downgrade protection in 1.3 is supposedly much better than 1.2, https://tools.ietf.org/html/rfc8446#section-4.1.3

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#73

Earlier quoted context omitted.

Thanks for the heads up. I've made some proxy software that routes on SNI. If TLS1.3 drops SNI then I feel like that will accelerate ipv6 adoption because we're going to need a shitload more IP addresses.

I'm not following the connection between how IPv6 would accelerate in the absence of SNI. Could you elaborate?

Without SNI the only way for a client to talk to this.example rather than that.example over TLS and thus HTTPS is to give this.example and that.example different IP addresses. There aren't enough addresses to plausibly do this in IPv4, but in IPv6 there are plenty (except in some unusual corner cases)

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#74
post #58
post #48

Earlier quoted context omitted.

It's actually worse than there being only a couple of big providers. The problem is that the same sort of people who are trying to shut down sites through legal pressure tactics against Amazon, Google etc are absolutely happy to use illegal tactics too. In particular once sites are booted off large providers onto smaller ones or self hosted sites, that's when the DDoS attacks start. Infowars already saw one, for inst…

> Where does speech go then? Federated / p2p systems like Mastodon? Non-Web-proper sites based on Dat and IPFS? /* If I were an adviser to the conspiracy theorists' insidious world government, I would suggest that pressure on non-consenting opinions be put carefully, to securely remove them form the normal mass Web, but not too strong as to push the normal users away from the (controlled) Web, to harder-to-control me…

Dat/IPFS are peer to peer protocols. There is nothing that makes them DDoS resistant, you can just locate each peer rehosting content and blast each one off the net.

But more to the point, being forced onto Dat or IPFS is equivalent to being erased, given that nobody would know how to find or access the new location (Google doesn't index such net spaces).

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#75

In fact, google cloud already be blocked by GFW. Many of AWS server's ip have been blocked by GFW. Only Azure can be used in China.

Yeah the article writes “They can either block gigantic swaths of the Internet (and face enormous backlash) or allow SNI to work” but I think China shows that depressingly the enormous backlash is a myth.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#76

I have a few thoughts that come to mind. One mistake we make frequently as tech people is trying to solve human relationship problems with a technology fixes. Censorship has existed for 10,000+ years; encrypted s night isn't going to magically fix it. There isn't an easy answer, just the hard path educate everyone. Requiring encrypted sni will only mean the little influence thought leaders have in censored countries…

Yeah, I think the recent death of domain fronting and the collateral damage from Russia blocking Telegram are pretty indicative.

Regimes are completely willing to block large chunks of the internet if they can't do targeted blocks. And cloud providers aren't particularly interested in using their customers as collateral.

I expect surveillance prone regimes to just block anything with encrypted SNI.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#77
post #70
post #48

Earlier quoted context omitted.

It's actually worse than there being only a couple of big providers. The problem is that the same sort of people who are trying to shut down sites through legal pressure tactics against Amazon, Google etc are absolutely happy to use illegal tactics too. In particular once sites are booted off large providers onto smaller ones or self hosted sites, that's when the DDoS attacks start. Infowars already saw one, for inst…

I agree. I see this all the time when otherwise reasonable people spout "oh well, Google/FB/Twitter are private companies so free speech argument does not apply to them and that racists/nazis etc aren't owed anything by social media platforms."

This is based on a slippery slope argument: if the major platforms can ban speech inciting violence against Jews and African-Americans, then what's to stop them from doing it for other classes of speech? The answer is that the public outcry for kicking off other kinds of users is likely to be more pronounced and more justified. I'm not shedding any tears for the Daily Stormer or Gab, and I don't view them as canaries in the coal mine.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#78
post #70
post #48

Earlier quoted context omitted.

It's actually worse than there being only a couple of big providers. The problem is that the same sort of people who are trying to shut down sites through legal pressure tactics against Amazon, Google etc are absolutely happy to use illegal tactics too. In particular once sites are booted off large providers onto smaller ones or self hosted sites, that's when the DDoS attacks start. Infowars already saw one, for inst…

I agree. I see this all the time when otherwise reasonable people spout "oh well, Google/FB/Twitter are private companies so free speech argument does not apply to them and that racists/nazis etc aren't owed anything by social media platforms."

Step 1 is to normalize censorship for racists. Step 2 is to redefine racism until it captures most of your political opponents, up to and including "supports free speech" as a racist viewpoint.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#79
post #77
post #70

Earlier quoted context omitted.

I agree. I see this all the time when otherwise reasonable people spout "oh well, Google/FB/Twitter are private companies so free speech argument does not apply to them and that racists/nazis etc aren't owed anything by social media platforms."

This is based on a slippery slope argument: if the major platforms can ban speech inciting violence against Jews and African-Americans, then what's to stop them from doing it for other classes of speech? The answer is that the public outcry for kicking off other kinds of users is likely to be more pronounced and more justified. I'm not shedding any tears for the Daily Stormer or Gab, and I don't view them as canaries…

Relying on public outcry to defend free speech is by definition guaranteed not to work, because the only speech that needs protecting is unpopular speech.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#80
post #14

Earlier quoted context omitted.

Aren't businesses that are serious about meeting their legal/regulatory obligations for controlling internet access already using full MITM TLS interception with their own CAs? Given a malicious actor can register any old domain and get a cert for it very easily, I'm not sure what particular threat blocking TLS connections based just on the SNI is actually protecting you from.

Think of all the small 1-2 employee businesses / mom & pop businesses etc that take credit cards. They have no dedicated IT person. They’d be lucky to have a dedicated LAN for payments (a PCI DSS requirement). Increasing the barriers to compliance for these people is not a good thing. In practice they will just close their eyes and pretend nothing is wrong, or they will just pay the fine charges by the banks for non…

1-2 person businesses are likely outsourcing the entire problem of payment processing (and thus, the majority of the PCI controls) to a 3rd party like Stripe. The only PCI compliance needed then is an annual self-attestation which basically asks "Did you change your router's default password?" and "do you apply patches?" [1]

There may be some mildly masochistic tiny businesses that choose to process / store payment details on their own networks and try to manage all the controls needed for that, but in the presence of so many options for outsourcing the problem, this doesn't seem like a particularly rational decision.

> You can’t tell all these small businesses they can’t take card payments, and you can’t make an already tough job harder, more complex and more expensive without an associated drop in compliance.

This is only true if there are no sane alternatives.

[1] https://www.pcisecuritystandards.org/documents/PCI-DSS-v3_2_...

Post reply on HN