8 ms·
Airtel is sniffing and censoring CloudFlare’s traffic in India
- puranjay 10y agoNot just "an Indian ISP". It's the largest ISP in the country, and one with an increasingly larger footprint in Africa. It had revenues of close to $15B last year
- ishansharma 10y agoI know I'm being a bit cynical here but do we know that Cloudflare doesn't know about it? It's entirely possible that they know about it. Considering their recent datacenter opening in India (again, not clear on laws but maybe they need to follow the blocking as ordered by DoT/courts?) They just started operations in China and partnered with an ISP there, so unless they say that they are not involved, I'm sceptical about this.
- fahrradflucht 10y agoSeems like it's not just airtel: https://medium.com/@sushubh/when-you-said-they-do-not-even-know-it-i-thought-you-meant-airtel-was-quite-confusing-9954b7afc8ac https://medium.com/@sushubh/when-you-said-they-do-not-even-k...
- vinothgopi 10y agoYes, the OP mentions in his post itself that all ISP customers get the same message from Airtel.
- fahrradflucht 10y agoAh so the traffic between piratebay and CloudFlare gets routed through Airtel. Thanks for pointing that out.
- spikengineer 10y agoIt's only airtel blocking the connection between Cloudflare India's servers and the Origin server's for piratebay because Cloudflare uses Airtel as it's ISP for it's datacentres.
- yoo1I 10y agoAll I'm hearing is that Cloudflare allows their customers to configure client facing TLS without enforcing it upstream over the internet, providing a false sense of security. Thanks Cloudflare! ... and I'm pretty sure that their response will be "We are just a proxy, we are not responsible for anything".
- iamjason89 10y agoYeah, it's intrinsic of how the flexible ssl option works: https://support.cloudflare.com/hc/en-us/articles/200170416-What-do-the-SSL-options-mean- https://support.cloudflare.com/hc/en-us/articles/200170416-W...
- jgrahamc 10y agoWe give all our customers free certificates for their origin servers. http://blog.cloudflare.com/cloudflare-ca-encryption-origin/ http://blog.cloudflare.com/cloudflare-ca-encryption-origin/
- r1ch 10y agoWhy provide the option to use unencrypted origin connections then? If a customer wants SSL, make them do it right.
- michaelt 10y agoPresumably because some people have backends that don't support SSL (e.g. anything hosted on S3) and CloudFlare thought "eh, some encryption is better than nothing, and they're going to let us MITM their encrypted connection anyway so they're obviously not a bank or something really important"
- nileshtrivedi 10y agoGood example where "false sense of security" can trump "something is better than nothing".
- hitr 10y agoIn the article,testing the host header with different IP is done over http and not https.so i so it does not prove that Airtel is sniffing https traffic,isn't it ? >curl -H "Host: thepiratebay.org" http://192.30.253.112/ http://192.30.253.112/ May be I missed something. Technically it is possible block the traffic by looking at SNI[1] or simply block the ipaddress if it belongs to the blocked site.I always thought that every ISPs had to follow this because all ISPS are asked to block a list of such sites by the Supreme Court . []1 https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- Manishearth 10y agoIt can't sniff https traffic, except for basic metadata. The point is that many sites using cloudflare talk to cloudflare over HTTP (while users get HTTPS), and airtel is sniffing that.
- kekub 10y agoIt is possible for them to block the access to such a site using SNI, however they will not be able to do a man-in-the-middle attack (as it would be possible in this scenario) unless they could obtain a valid certificate for the site.
- userbinator 10y agoI wonder if there's any proposals/extensions for moving SNI into the encrypted part of the communication. The initial certificate would have to be keyed to the IP address of the server, or maybe something from DNS, and probably there are other complications too, but it'd at least reduce the amount of plaintext information transmitted with each connection.
- deleted 10y ago[deleted]
- NetStrikeForce 10y ago> moving SNI into the encrypted part of the communication. That's called host header :-)
- snowy 10y agoSo is it reasonable to say?: piratebays fault for not enforcing SSL between their origin servers and cloud flare?
- sneak 10y agoSort of, but the real fault lies with people actively censoring free speech. TPB could and should mitigate this attack with Origin TLS, yes.
- spikengineer 10y agoHere is what is happening: Cloudflare Indian datacentres are hosted on Airtel's networks. Airtel by default blocks and replaces(with a notice) Piratebay traffic all across it's network due to multiple court orders. Cloudflare India servers call the piratebay origin servers and ask for a master copy and Airtel instead gives the substitute page on all the http traffic from piratebay to cloudflare servers. Cloudflare servers display the malformed page they received from Airtel to all clients(all ISP's) asking for piratebay in India.
- ComodoHacker 10y ago>Airtel blocks the http traffic to piratebay No, Airtel substitutes Piratebay's response to CloudFlare.
- spikengineer 10y agoYeah, What you said is correct. I was not clear and edited the comment.
- pilif 10y agoAnd this is why we want HTTPS everywhere. Yes. It would probably mean that the site is completely not reachable, but I prefer that to an altered response.
- apeace 10y agoUnless I'm mistaken, the site could be made reachable if only TPB would enable SSL between Cloudflare and their origin. Currently, Airtel is blocking based on the Host header. If they can't see the Host header, they'd have to instead know TPB's origin IP, which they wouldn't.
- mikecb 10y agoTLS transmits the host in cleartext.
- kekub 10y agoIs there any way for cloudflare to detect wether or not their connection has been modified by a third party besides certificates? I could only think of loading the site from more than one location and comparing the responses. However that might not be a trivial task, as most websites will not be static enough.
- jakozaur 10y agoI see a lot of people bashing CloudFlare, but to be fair: 1. Thanks to them many sites got SSL and sniffing your local network/ISP is source of majority of the problems. 2. Some SSL is better than no SSL, though it can also create illusion of full security. 3. You can configure encryption between CloudFlare and your origin. You probably should do that. 4. CloudFlare this year (May 2016) announce better tooling to encrypt between origin and their own CDN servers: https://blog.cloudflare.com/cloudflare-ca-encryption-origin/ https://blog.cloudflare.com/cloudflare-ca-encryption-origin/
- hueving 10y agoOr you could get a let's encrypt certificate and have actual security for free.
- lmm 10y ago> 2. Some SSL is better than no SSL, though it can also create illusion of full security. In this scenario the illusion is a much bigger problem than the benefits. If I make a request over https I do not expect my traffic to be sent unencrypted over the open internet.
- deleted 10y ago[deleted]
- karthikb351 10y agoHi, OP here. There are basically two important points from this story. > CF can't tell if it's the actual website or the notice from Airtel, and neither can the user. > Airtel is implementing this block by looking at the Host: headers of ALL HTTP requests going out of CF, and since everyone in India will hit CF, they are now looking at the headers of all users in India, across ISPs.
- runesoerensen 10y agoI've never understood CloudFlare's position on this issue/feature. They generally do a great job at improving, caring and fighting for internet security, yet continue to offer a product (Flexible SSL) that they know is insecure: This option is not recommended if you have any sensitive information on your website. It should only be used as a last resort if you are not able to setup SSL on your own web server, but it is less secure than any other option (even “Off”) [1] So by CF's own admission this is less secure than having SSL disabled. That's of course technically incorrect assuming the visitor is aware that SSL is terminated at CloudFlare, and insecure from there to the origin server. If the visitor is aware of this distinction (and know what it means, which includes knowing where the CF edge and origins are located) then it does add some security (the coffeeshop's Wi-Fi etc). However it's probably fair to assume that most visitors of CloudFlare-protected sites are not aware of this distinction. They're probably just aware that Green Lock + HTTPS = secure. So instead this product primarily gives a visitor a false sense of security, which in my opinion is much worse and potentially dangerous. I guess CloudFlare agrees with that; why else would they say it's less secure than no SSL? In the end, CloudFlare should clarify why they continue to offer a seemingly secure encryption product that they themselves consider less secure than no encryption. They say it should only be used "as a last resort", but when is choosing "Flexible SSL" really the last resort? I mean, you can just disable SSL entirely or do it properly (and even get a free certificate from CF), both of which are more secure. I don't know, but here's an idea: It might be a good product for CloudFlare customers, such as TBP, who don't care enough to actually secure their visitors' traffic, but still want to give the appearance thereof. Which is exactly what the more prominent product page lists as the advantages of "Flexible SSL"[2]: - You do not need an SSL certificate on your server. - Visitors will see the SSL lock icon in their browser. I might be missing something and I'd honestly appreciate if someone can shed some light on this. I respect CloudFlare a lot and appreciate their efforts to improve internet security. It's just difficult to maintain a brand as a company on the forefront of the internet security battle, while also enabling customers to somewhat deceitfully give the appearance of security at the expense of their visitors' security and safety. It seems pretty clear that CF needs to discontinue this product before it hurt their brand as well as unassuming visitors. [1] https://support.cloudflare.com/hc/en-us/articles/200170416-What-do-the-SSL-options-mean- https://support.cloudflare.com/hc/en-us/articles/200170416-W... [2] https://www.cloudflare.com/ssl/ https://www.cloudflare.com/ssl/
- cvs268 10y agoDear Airtel, sniff this... https://pbs.twimg.com/media/CnUlDy0UEAAvTz4.png https://pbs.twimg.com/media/CnUlDy0UEAAvTz4.png
- uber1geek 10y agoAirtel is known for doing notorious things in the past. From injecting iframes to serving compressed images via their own cdn.
- cesarb 10y agoIn cases like this, where the upstream of some of Cloudflare's servers is known to be non-transparent (dropping or modifying data going through it), couldn't they tunnel everything to Cloudflare servers with a working upstream, and connect to the origin servers from there? They would still benefit from caching near the users, while avoiding the broken upstream.
- gnurag 10y agoThe lesson learnt from this fiasco is that CF can't trust its upstream ISPs, so tunneling traffic over to another ISP in a different geo adds additional overhead without actually solving the problem. The right approach to fix upstream MITM is to drop http+https mix and match mode.
- deleted 10y ago[deleted]