7 ms·
On the modern web, ISPs are one of your threats (2015)
- jakasto 10y agoCan anyone think of other industries where this is the case? Imagine for a moment if grocery stores injected small amounts of lead into the food, or if gas stations injected water into the fuel (for bulking). I know this kind of thing happens in China (think about toxic products added to baby milk, for example, to cheat protein tests). But that's at the "website" level, not the "ISP" level. I suppose healthcare (at least in the US) is the most likely industry to see attacker behavior.
- cm2187 10y agoA closer analogy would be if grocery stores were giving you reward/savings cards that you have to scan on every purchase. It is advertised as providing you a small discount after a certain number of purchases but really it is meant to track you over time.
- grogenaut 10y agoofftopic: how many people don't put fake info on them? Also why not just track via the CC name? I guess cash / check users?
- scrollaway 10y agoDevice resellers will inject a ton of crapware/adware into whatever they're reselling (Laptops, Android phones etc). TV networks inject a ridiculous amount of ads in and around their content (even natively into the content sometimes), even for content you pay for.
- qwename 10y agoOne could say that non-cash (debit/credit) transactions are recorded by the devices that enable them, and thus recorded and tied to an identity. The information could then be used by matching your card number when you use it online or elsewhere.
- ThrustVectoring 10y agoThis is at least complicated somewhat by PCI compliance. Are you allowed to store irrecoverable hashes of card numbers?
- qwename 10y agoI am not familiar with the PCI compliance stuff, but I found this after a quick search: "How Companies Learn Your Secrets" http://www.nytimes.com/2012/02/19/magazine/shopping-habits.html http://www.nytimes.com/2012/02/19/magazine/shopping-habits.h...
- mcpherrinm 10y agoYes, you can store tokens representing a credit card number (whether an hmac, database identifier, etc) outside of PCI scope. https://www.pcicomplianceguide.org/how-you-can-use-tokenization-to-reduce-pci-scope/ https://www.pcicomplianceguide.org/how-you-can-use-tokenizat...
- tracker1 10y agoYou don't need the card number, the name + zip (+ store location) is enough to correlate enough of the time.
- drvdevd 10y agoIt's interesting to think of it this way. Clearly, the attackers (being ISPs in this case) don't see it this way or don't want to see this sort of MITM this way. Following one of the links in the article [1], you get some great quotes: > Comcast injects ads into unencrypted traffic, because "it's a courtesy, and it helps address some concerns that people might not be absolutely sure they're on a hotspot from Comcast". So maybe someone out there actually feels this way when they find content has been directly injected in their unencrypted browsing session. I sure don't. [1] https://konklone.com/post/were-deprecating-http-and-its-going-to-be-okay https://konklone.com/post/were-deprecating-http-and-its-goin...
- mtgx 10y agoAnything can be spun to look more positive, or more negative. But that's BS. There are other ways for Comcast to inform their customers that it's a Comcast Wi-Fi. And even if there weren't, are they even working with the Wi-Fi Alliance to create a "perfect protocol" to do this in a secure way?
- wolfgke 10y agoLet's assume Comcast really thinks it is a feature that many people will like (I personally rather think it is a feeble excuse, but don't want to completely exclude this possibility). But why doesn't Comcast enable people to opt out of this "feature" then?
- literallycancer 10y agoI'd expect the PR/marketing people to laugh at "the plebs" as they make up press releases like that :) Maybe I'm just cynical, but I can't imagine anyone believing that ads are a "courtesy".
- jwatte 10y agoYes, because a fake Comcast hotspot surely wouldn't display Comcast ads to make the fake complete? Comcast understands that politics works on money and connections, not facts, and had learned to play that game to great profit for themselves.
- deleted 10y ago
- tedunangst 10y agoImagine instead if they injected ethanol into your gasoline to reduce fuel efficiency.
- jwatte 10y agoActually, the reason they inject ethanol (by law) is to reduce asthma and cancer. So I'm okay with that.
- grzm 10y agoIs this in the States? I've always been under the impression that this has more to do with the corn lobby than anything else, with a nod towards the environment in that it's a biofuel so it's renewable. That's offset by using a potential food source for fuel. Here's a quote from Wikipedia that indicates ethanol (E85) actually worsens pollution: A study by atmospheric scientists at Stanford University found that E85 fuel would increase the risk of air pollution deaths relative to gasoline by 9% in Los Angeles, US: a very large, urban, car-based metropolis that is a worst-case scenario. Ozone levels are significantly increased, thereby increasing photochemical smog and aggravating medical problems such as asthma. https://en.wikipedia.org/wiki/Ethanol_fuel#Air_pollution https://en.wikipedia.org/wiki/Ethanol_fuel#Air_pollution
- TeMPOraL 10y ago> or if gas stations injected water into the fuel (for bulking) Does this not happen in the US? It may be an urban legend, but in Poland, I did hear from drivers that some gas stations do that (usually non-franchise ones).
- jabl 10y agoWhen I was visiting India roughly a decade ago, I was told that it was very common for gas stations to bulk gasoline with kerosine. Apparently kerosine is heavily subsidized by the state as it's used for cooking by poor people, so it's a lot cheaper than gasoline. The problem with this is that it reduces the octane rating of the fuel, and as a result cars in India are apparently commonly detuned in order to avoid knocking when running on low octane gas. That being said, bulking up gasoline with kerosine sounds like a less bad idea than using water, as I'd guess the water phase separates from the gasoline.
- qwename 10y agoCommunicating over the Internet is like relaying letters with the destination and return address at the top. Anyone in the chain can choose to look at the content, tamper with it, or refuse to pass it on. A giant web that relies on trust. Is there a system where trust is not necessary, but can still get things done? Although I can't think of a use-case for this.
- kuschku 10y agoPostcards. That describes what you mean.
- myowncrapulence 10y agoIs there a system where trust is not necessary, but can still get things done? Yes. Check out cjdns (https://en.wikipedia.org/wiki/Cjdns https://en.wikipedia.org/wiki/Cjdns) and Hyperboria (https://hyperboria.net https://hyperboria.net) An entirely encrypted network of relays where ip addresses themselves are encrypted so no one can snoop traffic.
- qwename 10y agoIt seems like users are not anonymous, but this lead me to the concepts of overlay networks[1], darknet[2], and mesh networks[3]. Thanks for that. [1] https://en.wikipedia.org/wiki/Overlay_network https://en.wikipedia.org/wiki/Overlay_network [2] https://en.wikipedia.org/wiki/Darknet https://en.wikipedia.org/wiki/Darknet [3] https://en.wikipedia.org/wiki/Mesh_networking https://en.wikipedia.org/wiki/Mesh_networking
- egh5oon 10y agoNo mention of Tor and its Onion Services?
- revelation 10y agoThe thin paper wafer around your mail hardly makes it tamperproof. Laws are a good start.
- coldcode 10y agoWill get worse next year in the US when ISPs can do as they please.
- drvdevd 10y agoWhat new rule(s) are coming into effect in 2017?
- perhonen 10y agoDonald Trump has stated his opposition to net neutrality [1], although it is unclear to what extent he intends to pursue this issue. Trump's picks for his FCC transition team are both supportive of permitting differential pricing models [2]. [1] https://twitter.com/realdonaldtrump/status/532608358508167168 https://twitter.com/realdonaldtrump/status/53260835850816716... [2] https://www.aei.org/wp-content/uploads/2012/10/-broadband-competition-in-the-internet-ecosystem_164734199280.pdf https://www.aei.org/wp-content/uploads/2012/10/-broadband-co...
- xenadu02 10y agoATT/Comcast: Sure is a nice startup you got there... be a shame if anything happened to your packets.
- petrikapu 10y agoI was working for many years for major ISP in nordics and they implemented wiretaps when requested by the officials.
- JumpCrisscross 10y agoAre any of the Nordic countries better than the others when it comes to this?
- paulmd 10y agoWith the creation of Let's Encrypt, there is really no longer any justifiable reason to bitch about the costs of a certificate. We all know the threat model now and if you are going to be interacting with the general public you should absolutely be held to minimum standards to ensure that nobody is tampering or sniffing your traffic along the way. If you are just doing DIY stuff then you probably don't need the advanced features that are getting moved to HTTPS-only. If you do need those features, you are advanced enough to take the five minutes and generate your own CA certificate and install it onto your machines. Boom, now you can sign your own HTTPS cert. Problem solved and you don't need to destroy the internet for everyone else nor participate in even the minimum of public interaction. DIY to your heart's content.
- nothrabannosir 10y agoIf you are just doing DIY stuff then you probably don't need the advanced features that are getting moved to HTTPS-only. Like getusermedia, or service workers, or webrtc? Speak. For. Your. Self. Precisely personal projects use these technologies. That's why they're personal projects; because I'm trying out new stuff. Testing this from a phone emulator the other day i had to resort to inordinate hacks to access a web push test page on the host. How to https://10.0.2.2 https://10.0.2.2? It's not straightforward. Im happy for it, it's worth it. but don't discount the effort it now takes. Ps: "bitch about the costs of a certificate." --- I prefer to call it a valid complaint about an extortion racket, but I guess opinions differ.
- Spivak 10y ago> It's not straightforward. But it's no less straightforward than being your own CA in your dev environment and issuing a cert to any other name. There's no need to go through the hassle of getting a public cert for this use case.
- drvdevd 10y agoInteresting to note how important this is for developers to consider now. If we're going to move to an HTTPS only web, we need to both: 1) understand how CAs work (including how to be your own local CA) and 2) make this an easy or seamless process in terms of workflow. Granted, it's really not that difficult, but baking this into existing development environments will become a task many projects will need to repeat.
- cj 10y agoI look forward to a HTTPS-only world some day to prevent MITM issues like the original article, but we have a ways to go. I run a service that involves adding Javascript to a site (like you would with Google Analytics). At one point we were serving 100% of scripts / APIs via SSL, but ended up moving to matching the origin host's protocol because customers were complaining of older version of IE that actually block HTTPS requests that originate from HTTP pages. So now we serve API calls matching the protocol of the domain the script is loaded on. It's been on our mind to go back and figure out exactly which browsers this affects, implement browser detection logic, and then serve SSL APIs for everyone else. Although it's a bit tricky when supporting customers who have users (still) accessing them with obscure / old browsers. More broadly, Let's Encrypt has been a great initiative. AWS WAF is also great for generating certs easily (although only inside AWS unfortunately with specific AWS services). Initiatives encouraging people using legacy browsers upgrade to upgrade will also help companies like ours (and others) trying to support 100+ browser versions on various OS's. For us, China has also been a slight issue. The firewall tends to add extra (unpredictable) latency for SSL requests, even when engaging with firms for $xx,000 specializing in overcoming China networking related obstacles.
- matt_wulfeck 10y agoCan you explain more? Does China capture ssl traffic or something similar?
- flopto 10y agoChina throttles lots of foreign websites that it doesn't block. It wouldn't be surprising if they target all foreign ssl traffic for throttling too.
- derwiki 10y agoIn Beijing currently. I set up a SOCKS proxy through an EC2 instance and it seems to be throttled after 10 minutes of use -- to the point that Edge on my smartphone is faster. Unrelatedly: I was very surprised that the GFW lets through Amazon web traffic.
- jwatte 10y agoIf TLS/HTTPS was easy to use from userspace C, HTTP could probably phase out very soon. Node, Go, Python, and other web tech actually makes this easier, because I don't have to call OpenSSL myself. So, even though I really love C, it's not in the best place for the modern network.
- hobarrera 10y agoVery few applications actually add the TLS layer themselves. Most apps webapps are behind a forwarder that does the security part. I believe the only places where you'd use C is web servers themselves.
- aaronmdjones 10y agoARM MbedTLS makes using TLS from C easy. Like, really easy. Really, really easy. As an aside, the last CVE (publicly known, logged vulnerability) for MbedTLS that affected server-side code was from January 2015.
- Demcox 10y agoGood short writeup.
- tracker1 10y agoI've just a few days ago started using a seedbox/vps service to avoid any possible incursions on comcast/xfinity's 6-strikes policy.