8 ms·
Here is what is happening: Cloudflare Indian datacentres are hosted on Airtel's networks. Airtel by default blocks and replaces(with a notice) Piratebay traff
by spikengineer 10y ago
Here is what is happening:
Cloudflare Indian datacentres are hosted on Airtel's networks.
Airtel by default blocks and replaces(with a notice) Piratebay traffic all across it's network due to multiple court orders.
Cloudflare India servers call the piratebay origin servers and ask for a master copy and Airtel instead gives the substitute page on all the http traffic from piratebay to cloudflare servers.
Cloudflare servers display the malformed page they received from Airtel to all clients(all ISP's) asking for piratebay in India.
- ComodoHacker 10y ago>Airtel blocks the http traffic to piratebay No, Airtel substitutes Piratebay's response to CloudFlare.
- spikengineer 10y agoYeah, What you said is correct. I was not clear and edited the comment.
- pilif 10y agoAnd this is why we want HTTPS everywhere. Yes. It would probably mean that the site is completely not reachable, but I prefer that to an altered response.
- apeace 10y agoUnless I'm mistaken, the site could be made reachable if only TPB would enable SSL between Cloudflare and their origin. Currently, Airtel is blocking based on the Host header. If they can't see the Host header, they'd have to instead know TPB's origin IP, which they wouldn't.
- mikecb 10y agoTLS transmits the host in cleartext.
- theandrewbailey 10y agoCompletely beside the point. Airtel is obviously looking at the HTTP host header.
- mikecb 10y agoParent suggested deploying TLS from origin to Cloudflare would resolve this. Simply pointing out that it will not.
- aptwebapps 10y agoThe post said that Cloudfare communicates with TPB via its IP address, not its host name, and that Airtel must be sniffing the hostname out of the header. So if they went full TLS Airtel would have to block the relevant IPs, which can be a little harder to find out, instead of the host.
- astrange 10y agoCloudflare does use SNI to talk to origin servers.
- captn3m0 10y agoonly if the origin server uses HTTPS and SNI.
- scurvy 10y agoMost layer 7 blocking mechanisms look for the SNI header in a TLS datagram or the host header. It's not complicated and trivial to do. Only looking at the host header would be quite amateurish. I'm not a security expert, and even I know this. CF could use some sort of IPSec or SSL tunnel back to another datacenter to make the origin request. It would add a lot of latency, but it would ensure that local authorities don't mess with the traffic. This was a popular way for CDN's to get around China for a while. I believe one CDN provider billed it as "Secure origin routing." I doubt that they still offer it, as everyone wants to play ball and make money in the end.
- mschuster91 10y agoIt is still possible, it needs three things to work: 1) SNI indicators on the HTTPS handshake deliver the hostname to the DPI processor, be it on the connection Consumer => CF or CF => TPB. 2) Most likely the provider has a trusted CA... and CF => TPB connection does not support pinning. 3) Provider redirects to interceptor, which serves a "blocked" notice page, with a trusted HTTPS cert. Alternative to 2 & 3 in case provider doesn't want to risk his CA: simply drop the connection by injecting a FIN packet once TPB is seen in the SNI headers.
- 0xmohit 10y agoFunny that this comes from a company that talks of "building a truly transparent network", and says "... And we have nothing to hide." https://www.airtel.in/opennetwork/ https://www.airtel.in/opennetwork/
- ukyrgf 10y agoWell, they are being transparent. Courts ordered them to block Pirate Bay, so they complied and put up a notice saying so.
- beachstartup 10y agoin my opinion transparency is something of a red herring, or buzzword. usually you can tell what's going on inside of an organization just by observing what they do. conversely, if you can't observe it, how would you know they're not being transparent (despite their claims)?
- rajaganesh87 10y agocourt usually asks to block URLs, not to sniff data between PirateBay and CloudFlare.
- vinay_ys 10y agoAnd how would you block url without sniffing packets?