Live data from Hacker News

TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

privateinternetaccess.com

81–90 of 102 posts

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#81

Earlier quoted context omitted.

Thanks for the heads up. I've made some proxy software that routes on SNI. If TLS1.3 drops SNI then I feel like that will accelerate ipv6 adoption because we're going to need a shitload more IP addresses.

I'm not following the connection between how IPv6 would accelerate in the absence of SNI. Could you elaborate?

Sure. If you are a CDN right now you can host multiple customers on one ip. If you are using TLS there are 2 ways to do this:

1. Have a big SAN cert with lots of names.

2. Use SNI to select the correct certificate for that client and route to the correct customer config (and therefore correct origin)

If SNI didn't exist we'd be back to the bad old days of every TLS site requiring a dedicated IP. As ipv4 exhaustion has gotten worse this has gotten more expensive. However if we're using ipv6 then hosting N listeners for N ip addresses, each with their own dedicated cert, is much more scalable.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#82
post #67

Earlier quoted context omitted.

I love how you can say "free speech is an ideal" while simultaneous arguing to limit the free speech of platform holders. The reason free speech only lawfully bounds the government is because the ability to kick bad actors out of your business is an essential free speech to the populous. MS is free to moderate their platform in anyway that doesn't violate US law; that's their exercise of free speech. Groups that disa…

You're pretty much proving my point when it comes to confusing the law with what is right. Ignore the law, it's completely orthogonal to the discussion. Free speech isn't prescriptive. Holding it as an ideal doesn't mean you want zero restrictions any more than holding liberty as an ideal means you want anarchy. Your 'system' is simply unrestricted speech to the powerful and your 'solution' is just a suggestion that…

If we lived in a fantasy dystopia inwhich computers were outlawed to all but the silicon valley elite and the rest of the populace had to rent from them or be left in the cold, maybe your argument would have some weight.

In the world we do live in, speech for your small niche community is literally a 30 dollar raspberry pi and an internet connection away. No one has any moral (or legal authority for that matter) to shut down the nazi chat rooms of others (under your views at least); just like Microsoft and others have no moral obligation to host content that breaks their terms of service and will drive others off of their platform.

Arguing what is "right" in a law abiding society is nonsense. If the laws are flawed you argue against the laws, if they aren't pretending that people or groups of people should conform to your ideals is ultimately a waste of time.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#83
post #51

That assumes they want to end censorship. Google, for instance, outright participates in political censorship, especially on Youtube - I've seen many right and alt-right youtubers disappear or get strikes for something unimportant that the left does without any repercussions. They also fired Damore for quite mild comments about sex/gender.

If Chinese government was only censoring racists / misogynists / homophobes, I'm sure less people wouldn't have a problem with that.

But that's not what Google is doing either.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#84

Earlier quoted context omitted.

How so? If I as the MITM (non-decrypting) proxy intercept the request, look at the SNI to ensure it’s on my whitelist, and then do my own DNS lookup and open my own TCP connection to that IP and relay the traffic between the two, what’s the attack vector?

Attackers can break into legitimate, low security, websites and use them as attack vectors. It's often easier that attacking the target directly and it's been done for decades. Also, botnets uses legitimate services to rely C&C traffic. Forums, pastebins, github gits, IRC and email gateways, VMs on AWS and other cloud services...

In my original comment I referred to the need to only allow access to necessary services. No forums, email gateways, IRC, etc. Just whitelisted domains and IPs:ports (if dedicated hosting) of the services required to handle the payments aspect of a business. An attacker would have to break into the sites I whitelisted— in which case the liability falls on the site for not maintaining adequate security. It doesn’t alleviate the need for the merchant to have good security themselves.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#86

Earlier quoted context omitted.

How so? If I as the MITM (non-decrypting) proxy intercept the request, look at the SNI to ensure it’s on my whitelist, and then do my own DNS lookup and open my own TCP connection to that IP and relay the traffic between the two, what’s the attack vector?

I agree that whitelisting only "known good" IP addresses (supposing for a moment that there are such things) achieves your goal of preventing bad guys from non-good IP addresses communicating. I observe this has nothing whatsoever to do with TLS. I'll base my response on your description of how you think this device would work rather than your confusing term "MITM (non-decrypting) proxy". A1. Alice sends a TCP SYN to…

Re commentary #1, it is due to websites being hosted on ever changing IPs such as with AWS and GCP allowing them to fire up additional resources easily, or using a fronting load balancer, or even a DDOS protection tool like CloudFront. In these cases only the domain name is known in advance by the intercepting firewall. It can’t get this info via reverse lookup on the requested destination IP (nor should it; reverse dns doesn’t always work and performance doing this for every connection would be bad).

I’ve also looked at other options, like dns based firewall rules that are populated by the firewall also being the local dns server and so is able to see the resolved IP(s), but if those IPs are to CloudFront etc then it would be granting access to everything else also hosted by CloudFront etc.

TLS SNI is the only way of knowing where the client is trying to reach — short of the expensive and difficult to deploy explicit/non-transparent HTTPS proxy.

Re commentary #2, since all the TLS traffic is going through the proxy, the original request and any subsequent requests would go to the same IP each time.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#87
post #26

Why would anybody think that Amazon, Google, or Microsoft are against censorship? Recent events have demonstrated that they love them some censorship, when they do it. Witness the case of gab.ai - Google was happy to pull their app from the Play store. Microsoft didn't mind at all threatening to shut down their Azure account unless they censored a post. The Azure case is particularly amazing. I can't believe the tech…

I'm a supporter of extremely strong free speech protection, but this doesn't seem entirely black and white to me.

AWS is a private hosting company, and they may be exposed to legal or authority action based on what their clients host. It seems a lot like the Facebook arguments to me.

If you want to obligate them to support free speech, I think they need to be regulated as carriers otherwise it's not a reasonable standard to hold a private entity to. At least there is more competition in the hosting space than there is for Facebook.

Maybe this is an argument for regulation, but I don't think it's an argument for finger wagging. Either there is some sort of enforcement, or we acknowledge there are alternatives.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#88
post #53

Earlier quoted context omitted.

I really hate this meme; Randall did the world a great disservice by missing the point and putting it in a format which spread like wildfire for smug people to quote until the end of time. Free speech is a principal which extends farther than a very limited right in US law -- it's not a rule, it's not prescriptive, it's not afforded by any law -- it's an ideal. I don't in any way deny that you can find people who con…

>And no matter what I think about the things they said I still hold that they ought to be allowed to say them among themselves. And they are. No one is stopping them from talking to each other. They however are telling people to stop talking to each other in the office building Microsoft owns and rents out. Perhaps that's the best analogy? Providing (P|I|S)AAS is a business transaction. Its like renting out commercia…

> But when the space is virtual, it magically changes from a landlord to a speech thing.

I think it because whenever there is piracy or unauthorized access to entertainment or information resource from cable/media companies comes up, apart from company whose property get stolen, all seem to have sympathy towards culprit . The standard arguments are couched in user freedom rather than taking someone's property without consent. All this is because resource is digital so my access does not deprive other.

So blocking is claimed to harmful, immoral, greed by media or cable companies for things some people want to have. And now non-blocking is considered harmful by social media companies for things some people do not want.

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#89
post #80

Earlier quoted context omitted.

Think of all the small 1-2 employee businesses / mom & pop businesses etc that take credit cards. They have no dedicated IT person. They’d be lucky to have a dedicated LAN for payments (a PCI DSS requirement). Increasing the barriers to compliance for these people is not a good thing. In practice they will just close their eyes and pretend nothing is wrong, or they will just pay the fine charges by the banks for non…

1-2 person businesses are likely outsourcing the entire problem of payment processing (and thus, the majority of the PCI controls) to a 3rd party like Stripe. The only PCI compliance needed then is an annual self-attestation which basically asks "Did you change your router's default password?" and "do you apply patches?" [1] There may be some mildly masochistic tiny businesses that choose to process / store payment d…

For bricks and mortar businesses Stripe won’t help much, still need a chip and PIN reader on premise.

Square on the other hand does let you outsource the entire problem of physical card payments to them, at the cost of much higher fees, as they are the merchant of record so you don’t need to be PCI compliant at all. Which is a real worry as that doesn’t give me much confidence when buying from a square “seller”.

Their card reader originally didn’t encrypt data, and at least one model that did encrypt could be bypassed via tampering https://www.zdnet.com/article/square-reader-to-card-skimmer-... and while their current hardware may or may not have issues, they display a distinct lack of concern for local device security. Defense in depth is the way to go, but with Square you can put your Android/iOS device onto any WiFi network and without any security on who else is on it. Likewise you can download any random app that may look innocent enough but is full of exploits (eg an app that claims to help you manage a customer mailing list so you can grab signups on the same device as you take payments, or an app that claims to help with inventory levels, etc).

Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship

#90
post #80

Earlier quoted context omitted.

1-2 person businesses are likely outsourcing the entire problem of payment processing (and thus, the majority of the PCI controls) to a 3rd party like Stripe. The only PCI compliance needed then is an annual self-attestation which basically asks "Did you change your router's default password?" and "do you apply patches?" [1] There may be some mildly masochistic tiny businesses that choose to process / store payment d…

For bricks and mortar businesses Stripe won’t help much, still need a chip and PIN reader on premise. Square on the other hand does let you outsource the entire problem of physical card payments to them, at the cost of much higher fees, as they are the merchant of record so you don’t need to be PCI compliant at all. Which is a real worry as that doesn’t give me much confidence when buying from a square “seller”. Thei…

Can you link the PCI requirement that means anyone who simply accepts physical payments needs to TLS-intercept all network traffic?
Post reply on HN