TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
91–100 of 102 posts
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#92Earlier quoted context omitted.
For bricks and mortar businesses Stripe won’t help much, still need a chip and PIN reader on premise. Square on the other hand does let you outsource the entire problem of physical card payments to them, at the cost of much higher fees, as they are the merchant of record so you don’t need to be PCI compliant at all. Which is a real worry as that doesn’t give me much confidence when buying from a square “seller”. Thei…
Can you link the PCI requirement that means anyone who simply accepts physical payments needs to TLS-intercept all network traffic?
Only services necessary for the business should be allowed in/out. If the service can’t be firewalled by simple IP:port then you are left with having to use a proxy to enforce the access control.
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#93Earlier quoted context omitted.
I agree. I see this all the time when otherwise reasonable people spout "oh well, Google/FB/Twitter are private companies so free speech argument does not apply to them and that racists/nazis etc aren't owed anything by social media platforms."
Step 1 is to normalize censorship for racists. Step 2 is to redefine racism until it captures most of your political opponents, up to and including "supports free speech" as a racist viewpoint.
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#94Earlier quoted context omitted.
I'm not following the connection between how IPv6 would accelerate in the absence of SNI. Could you elaborate?
Without SNI the only way for a client to talk to this.example rather than that.example over TLS and thus HTTPS is to give this.example and that.example different IP addresses. There aren't enough addresses to plausibly do this in IPv4, but in IPv6 there are plenty (except in some unusual corner cases)
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#95Earlier quoted context omitted.
> Where does speech go then? Federated / p2p systems like Mastodon? Non-Web-proper sites based on Dat and IPFS? /* If I were an adviser to the conspiracy theorists' insidious world government, I would suggest that pressure on non-consenting opinions be put carefully, to securely remove them form the normal mass Web, but not too strong as to push the normal users away from the (controlled) Web, to harder-to-control me…
Dat/IPFS are peer to peer protocols. There is nothing that makes them DDoS resistant, you can just locate each peer rehosting content and blast each one off the net. But more to the point, being forced onto Dat or IPFS is equivalent to being erased, given that nobody would know how to find or access the new location (Google doesn't index such net spaces).
> being forced onto Dat or IPFS is equivalent to being erased
Yes, for now it is! It's a wild frontier without amenities for a normal netizen, such as a decent search engine. So the point of censorship is to force every important non-consenter to that wilderness without having enough other people to go there and civilize it, as they civilized the web, the online music access, etc.
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#96Earlier quoted context omitted.
I agree that whitelisting only "known good" IP addresses (supposing for a moment that there are such things) achieves your goal of preventing bad guys from non-good IP addresses communicating. I observe this has nothing whatsoever to do with TLS. I'll base my response on your description of how you think this device would work rather than your confusing term "MITM (non-decrypting) proxy". A1. Alice sends a TCP SYN to…
Re commentary #1, it is due to websites being hosted on ever changing IPs such as with AWS and GCP allowing them to fire up additional resources easily, or using a fronting load balancer, or even a DDOS protection tool like CloudFront. In these cases only the domain name is known in advance by the intercepting firewall. It can’t get this info via reverse lookup on the requested destination IP (nor should it; reverse…
TLS SNI does NOT tell you where the client was trying to reach, you've made a classic security mistake of assuming bad guys are honest. Honest people will truthfully write good.example and be allowed past, bad guys will dishonestly write good.example, and thereby connect to bad.example on the same IP address and laugh at your ridiculous "security".
Caching all DNS answers for some indeterminate amount of time makes your security story worse, but even if you do this the worst case stands, ClientHello isn't required to work if you do this. It may work today, in fact it probably does, but it may break with no notice, and it'll be your fault.
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#97Earlier quoted context omitted.
>And no matter what I think about the things they said I still hold that they ought to be allowed to say them among themselves. And they are. No one is stopping them from talking to each other. They however are telling people to stop talking to each other in the office building Microsoft owns and rents out. Perhaps that's the best analogy? Providing (P|I|S)AAS is a business transaction. Its like renting out commercia…
> But when the space is virtual, it magically changes from a landlord to a speech thing. I think it because whenever there is piracy or unauthorized access to entertainment or information resource from cable/media companies comes up, apart from company whose property get stolen, all seem to have sympathy towards culprit . The standard arguments are couched in user freedom rather than taking someone's property without…
It's not surprising that people don't treat something that lacks one of the key aspects of property as property. Especially when the desired enforcement regime for this concept always seems to necessitate encroachment on their actual property!
Copyright applied to individuals is even less enforceable than drug persecution. And we see how well that's working out.
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#98Earlier quoted context omitted.
Re commentary #1, it is due to websites being hosted on ever changing IPs such as with AWS and GCP allowing them to fire up additional resources easily, or using a fronting load balancer, or even a DDOS protection tool like CloudFront. In these cases only the domain name is known in advance by the intercepting firewall. It can’t get this info via reverse lookup on the requested destination IP (nor should it; reverse…
If you're whitelisting names that point into arbitrary cloud stuff then you're screwed, the bad guys just get themselves co-located so that you'll happily connect to them because hey, this name was whitelisted and so the IP address must be OK. TLS SNI does NOT tell you where the client was trying to reach, you've made a classic security mistake of assuming bad guys are honest. Honest people will truthfully write good…
For other services that use dedicated IPs but spin up/down machines based on load etc it is still much more useful and secure than running a proxy with a CA that generates fake certificates, especially when you can’t update the trust root of the client device (often the case with embedded devices and those that are managed by the third party service provider)
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#99Earlier quoted context omitted.
I love how you can say "free speech is an ideal" while simultaneous arguing to limit the free speech of platform holders. The reason free speech only lawfully bounds the government is because the ability to kick bad actors out of your business is an essential free speech to the populous. MS is free to moderate their platform in anyway that doesn't violate US law; that's their exercise of free speech. Groups that disa…
You're pretty much proving my point when it comes to confusing the law with what is right. Ignore the law, it's completely orthogonal to the discussion. Free speech isn't prescriptive. Holding it as an ideal doesn't mean you want zero restrictions any more than holding liberty as an ideal means you want anarchy. Your 'system' is simply unrestricted speech to the powerful and your 'solution' is just a suggestion that…
Microsoft should be under no more obligation to enable the spread of hate by hosting it online than a business hosting it in physical space.
Re: TLS 1.3 Is an Opportunity for Amazon, Google and Microsoft to End Censorship
#100Earlier quoted context omitted.
I agree. I see this all the time when otherwise reasonable people spout "oh well, Google/FB/Twitter are private companies so free speech argument does not apply to them and that racists/nazis etc aren't owed anything by social media platforms."
This is based on a slippery slope argument: if the major platforms can ban speech inciting violence against Jews and African-Americans, then what's to stop them from doing it for other classes of speech? The answer is that the public outcry for kicking off other kinds of users is likely to be more pronounced and more justified. I'm not shedding any tears for the Daily Stormer or Gab, and I don't view them as canaries…
Moreover how do you measure "public outcry"? The very point of censorship is to stop public outcry. If the media aren't writing stories and anyone who expresses concern is deemed to be supporting hate speech and banned, then it will look a lot like nobody cares even if many people do.