5 ms·
Does this really "move the needle" in terms of security? TLS should be sufficient to allow your traffic to enter and exit hostile territory.
by dev_dull 8y ago
Does this really "move the needle" in terms of security? TLS should be sufficient to allow your traffic to enter and exit hostile territory.
- marzell 8y agoMay be somewhat of a philosophical argument if you are limiting it to viewing the content of packets. However, there is still a ton of data that can be leaked that could be considered sensitive - volume of transactions, where they are routing from/to, the frequency distribution of that volume. Also, there is also the possibility for manipulation of transmissions - blocking/dropping them altogether causing service outages/censorship, delay/deprioritization that could affect markets, etc. At the nation-state level, this provides a lot of useful opportunities for bad actors.
- smokeyj 8y agoIf you could avoid certain pipes it could only help security. Even with the security of TLS, that doesn't prevent state-level actors from observing meta data with the advantage of internet-wide timing data, which could be useful for say, analyzing TOR traffic. Not a crypto expert but doesn't trusting TLS imply trusting root certs on your PC? Regardless, the Snowden leaks showed that internet traffic can be modified to contain harmful payloads for targeted individuals. Even if only susceptible over non-TLS it still represents a non-zero percentage of internet traffic.
- dev_dull 8y agoWho will you even "avoid"? It's in the interest of every major country to do surveillance.
- TaylorAlexander 8y agoIt may seem equally compelling to all countries, but in practice some countries put huge resources in to gathering everything, and some don’t. Avoiding the ones that in practice collect everything in favor of ones that in practice don’t would increase security. Separately, we should stay mindful of who is doing this collection, and simultaneously take additional measures to secure our communications.
- semi-extrinsic 8y agoI'm trying to come up with a list of countries that don't collect basically all data, and I'm coming up short. Do you have any suggestions?
- r1ch 8y agoTrusting root certs is a lot less worrying with the advent of certificate transparency. It's now very noisy if a CA issues a cert for something like google.com, and smaller sites can get notifications about cert issuances for their domains from various free alerting services.
- quickthrower2 8y agoWhat if TLS traffic is recorded. Future technology may be able to decrypt it. Your secrets may be out later.
- deepsun 8y agoThere are a lot of information in requests metadata. For example, even without accessing any encrypted data you can identify: 1. Client (user IP). 2. Service (server IP). 3. Amount of traffic. 4. Direction of traffic. 4. Just watching timestamps, you can identify patterns that will give you information on what type of content user is accessing (e.g. if you are oppression nation state, and want to know who watched or reshared a certain video on youtube, you can get that purely from requests patterns, mainly timestamps). By correlating those timestamps with others, you can identify user's friends/collaborators, or other identities they use.
- aatharuv 8y agoTLS isn't sufficient. There was at least one country, Kazakhstan, which had a plan to force all of its citizens to install their own CA to MITM all SSL traffic. (I'm not sure if the plan ever got implemented because the original government press release now 404's). https://www.eff.org/deeplinks/2015/12/kazakhstan-considers-plan-snoop-all-internet-traffic https://www.eff.org/deeplinks/2015/12/kazakhstan-considers-p...
- jccooper 8y agoThat's a case of traffic originating in an unsafe country. Circumventing local laws is a completely different issue. This is about transiting "unsafe" countries while routing to/from a (reasonably?) "safe" country. (Are you really certain Brazil isn't logging local traffic? I wouldn't be.) Anyway, TLS does leak a lot of metadata, which perhaps you'd rather publish a bit less widely. It's an improvement in casual security, which is nice, but not gonna save your bacon on anything specific.