4 ms·
Approx. 30% of Russian internet providers will block Wikipedia.org entirely, because Wikipedia.org use HTTPS (and Deep Package Inspection is too damn costly).
by marinintim 11y ago
Approx. 30% of Russian internet providers will block Wikipedia.org entirely, because Wikipedia.org use HTTPS (and Deep Package Inspection is too damn costly).
Runet, as usual, is full of tragedy jokes: [lang=ru] https://tjournal.ru/p/rkn-wikipedia-block-bloggers https://tjournal.ru/p/rkn-wikipedia-block-bloggers
- guard-of-terra 11y agoDeep Packet Inspection won't help you versus HTTPS (unless you're CIA and have crypto backdoors).
- deleted 11y ago[deleted]
- socceroos 11y agoOr the private keys to a tonne of Certs from the cert authorities. The massive elephant in the room is the cert authorities..
- QUFB 11y agoNot for long, the Wikimedia Foundation intends to implement HPKP: https://phabricator.wikimedia.org/T92002 https://phabricator.wikimedia.org/T92002
- drdaeman 11y agoCA private key won't help classic (passive) DPI systems. You have to perform active MITM attack. And if anyone's aware of any ISP anywhere in the world, doing a MITM with a certificate that passes validation, they should really shout about this as loud as they can (or at least whisper to someone who can shout), because it concerns virtually everyone on the Internet.
- schoen 11y agoThis is apparently an order from the Russian government to individual ISPs. Do you think the individual ISPs have the ability (and desire) to issue fake certs from compromised root CAs to MITM Wikipedia connections? The question in this case is not whether some CA is compromised or malicious, but whether the entities involved have access to such a CA and are willing to use that access. Also, a very wide-scale HTTPS MITM is more likely every month to be detected because there are more and more people looking for it. That may not be true of small-scale MITMs for some time, but it's probably true, for example, for a large-country-wide attack against a major site -- especially a site used by lots of technically sophisticated people who've been given prior warning that something sketchy is going to happen on a particular date!
- drdaeman 11y agoThe use of "DPI" is frequently has a buzzword-like nature, which could mean literally anything from real DPI to transparent and semi-transparent HTTP proxies and sometimes even DNS spoofing techniques. The bad thing is that some ISPs MITM (with obviously invalid self-signed certificate, not even matching CN/DN of the domain being proxied) instead of completely dropping all tcp/443 traffic. Not that it's bad intent to try to provide access to the non-blacklisted pages, but it's an absolutely harmful practice of teaching users to click the knobs "aw, ignore those errors, I want to read the site".