11 ms·
One important implication is that collateral freedom techniques [1] using Amazon S3 will no longer work. To put it simply, right now I could put some stuff not
by samat 7y ago
One important implication is that collateral freedom techniques [1] using Amazon S3 will no longer work.
To put it simply, right now I could put some stuff not liked by Russian or Chinese government (maybe entire website) and give a direct s3 link to https:// https:// s3 .amazonaws.com/mywebsite/index.html. Because it's https — there is no way man in the middle knows what people read on s3.amazonaws.com. With this change — dictators see my domain name and block requests to it right away.
I don't know if they did it on purpose or just forgot about those who are less fortunate in regards to access to information, but this is a sad development.
This censorship circumvention technique is actively used in the wild and loosing Amazon is no good.
1 https://en.wikipedia.org/wiki/Collateral_freedom https://en.wikipedia.org/wiki/Collateral_freedom
- samat 7y agoIf there is anyone from Amazon caring about freedom of speech and censorship — please contact me at s@samat.me, I'd love to give you more perspective on this.
- cle 7y agoHow about asking someone from Amazon to give you more perspective on this, too? You only seem interested in immediately accusing Amazon of not caring about freedom of speech and schooling them about it, without considering if there are legitimate technical reasons that might justify the tradeoff. I can think of many such reasons off the top of my head.
- sieabahlpark 7y agoWhatever gets the clicks amirite?
- ironmagma 7y agoWith Amazon being the ones making the change, this situation is asymmetric. It’s on the affected to convince the “affectors,” if you will, that what they are doing is a bad idea. Whether they convince us or not is irrelevant.
- bartread 7y ago> I can think of many such reasons off the top of my head. What are they, please?
- stickfigure 7y agoThe parent implied nothing about the merits of the change. He/she drew attention to one of the downsides, in a non-accusatory tone. I personally hadn't considered that aspect; maybe folks at Amazon didn't either. Whether or not it affects Amazon's decision, it's a constructive message, and you're mistaken to dismiss it.
- hkai 7y agoHey Samat, I am pretty sure that AWS knows exactly what they're doing. They don't want to lose money by hosting objectionable content, and then lose customers to Aliyun or Russian cloud providers.
- adamfisk 7y agoDoes Aliyun support path-based file storage? That could be handy!
- hkai 7y agoNot sure but what I heard their API is the exact copy or the S3 API, so you can switch from one to other without any effort.
- PhilippGille 7y agoI tested that when writing the S3 implementation of a Go key-value wrapper [1] and back then "Alibaba Cloud Object Storage Service (OSS)" did not support path-style addressing. If you're looking for a similarly robust and scalable alternative, Google Cloud Storage is accessible via S3 API when enabling that in the bucket's configuration and it supports path-style access (at least back when I tested the different S3-compatible services). [1] https://github.com/philippgille/gokv https://github.com/philippgille/gokv
- lightgreen 7y agoThey did it not to make blocking in Russia and China easier, but to make their deployment cheaper and faster. Basically with v2 protocol your TCP packets go straight to the server where data is stored without going through one giant proxy. In another words, they do IP routing now instead of HTTP proxying.
- KeenFox 7y agoGoogle Reader served a similar purpose. People used its social features for communication since (the thinking went) governments weren't going to block Google.
- saint_fiasco 7y agoTeenagers use Google Docs to chat in environments where popular IM applications are blocked, such as schools and libraries. It's not really the same threat model as people living under dictatorships, but it might just work.
- mLuby 7y agoNow that you mention it… [√] absolute dependence on authorities for food, shelter, clothing, transportation, money. [√] curfews often in effect for you and your social circle, especially if suspected of deviance. [√] 24/7 electronic or in-person monitoring is possible and largely accepted. [√] social circle often molded by authorities. [√] not allowed to vote or generally exercise political agency (and when allowed it's dismissed). [√] not allowed to leave your workplace or home without permission from authorities. [√] possible to flee and seek asylum but it means leaving everything behind for an uncertain future. [√] indoctrination is so effective you're extremely likely to continue the system when allowed to be an authority. Good thing it's a benevolent regime.
- dredmorbius 7y agoYou're neglecting a key point: primary and secondary education are the province of legal minors. Full legal rights of majors do not apply. Not that there aren't problems with both P/S education and higher education or public discoure and media generally, though your analysis misses a few key salient aspects and presents numerous red herrings. J.S. Mill affords a longer view you may appreciate: https://old.reddit.com/r/dredmorbius/comments/6x7u6a/on_the_role_of_universities_and_primary_education/ https://old.reddit.com/r/dredmorbius/comments/6x7u6a/on_the_...
- xiaq 7y agoYou cannot solve a political problem with a technical solution.
- samat 7y agoIt's better to approach issues from all sides.
- filoleg 7y agoYou are correct, but you forget that a technological solution like this one can help bringing around the actual social change you are looking for. It is kinda difficult to bring a social change when your major communication and information distribution methods are gutted.
- jmull 7y agoThat's true, but technology can be part of a political solution. In particular, a political solution requires that people be able to communicate (in order to work together), and technology can be a component of that.
- geofft 7y agoSure you can. Weapons research is a very common counterexample; people have been solving political problems with technical solutions ranging from sharpening spear-heads to achieving nuclear chain reactions. (Of course "who is politically right" and "who has the most technical expertise on their side" are at best tenuously related, but that's a different and longstanding problem. If you believe you're politically right and you have technical expertise on your side, use it.)
- thereare5lights 7y agoAre there any non-violent technical solutions? I think we all know that's what that person really meant.
- prepend 7y agoRadio Free Europe is a technical, non-violent solution to a political problem. Viagra solved tiger poaching political problem.
- Someone1234 7y agoUse DNS over HTTP. Firefox is very easily configurable (network.trr.bootstrapAddress, network.trr.mode, etc) so that if you pick the right bootstrap provider and DNS over HTTP provider you'll never send an unencrypted DNS query (including no SNIs) and it will fail completely rather than reverting to your OS's DNS Client if it cannot be resolved via the DNS over HTTP channel you define. Because the S3 buckets are virtual-hosted they share IPs so there is deniability if you can hide the DNS/SNI.
- aaomidi 7y agoYes but https SNI still exists.
- simcop2387 7y agoTLS v1.3 finally addresses this, https://blog.cloudflare.com/encrypted-sni/ https://blog.cloudflare.com/encrypted-sni/
- yardstick 7y agoI expect this will only work until the government in question is sufficiently angered that they just outright block the entire AWS infrastructure. Or whoever else supports ESNI.
- Spivak 7y agoBut the only reason domain fronting works in the first place is because people think that large web hosting providers are too large to block. If a hypothetical tyrantical government was willing to block all of Amazon S3 this change doesn't affect anything.
- yardstick 7y agoIf it impacted Amazon’s (or whoever is targeted) bottom line then I would expect they would be open to dropping domain fronting support. But I admit I don’t know this for sure - time will tell. China has blocked GitHub and Akamai before. https://www.latimes.com/business/technology/la-fi-tn-great-firewall-china-censorship-20141126-story.html https://www.latimes.com/business/technology/la-fi-tn-great-f...
- supergirl 7y agoDoes the same technique work to serve something not liked by the US gov?
- yjftsjthsd-h 7y agoBit of a moot point, since the US has passable safeguards such that you can host your content openly.
- djsumdog 7y agoThis is similar to domain fronting, which many providers are no longer allowing either.
- Thaxll 7y agoUse Cloudflare or any free CDN service? Edit: Why am I getting downvoted, it's a legit answer, CDN hides your origin.
- jetzzz 7y agoCloudflare is just a disaster for bypassing government censorship. If some website is blocked in my country and I try to access it with Tor or VPN then I better hope it is not behind Cloudflare, because Cloudflare just gives me endless Google captcha instead of the desired website.
- ec109685 7y agoThat assumes the website actually wants to block abusive traffic. A freedom site won’t.
- lugg 7y agoIt's captchas from cloudflare because their country is routinely used for malicious activity.
- ec109685 7y agoThey do have a Captchas Effectively Off setting, but you are right that it still could trigger: https://support.cloudflare.com/hc/en-us/articles/200170096-How-do-I-turn-off-the-Cloudflare-Captcha-challenge-page- https://support.cloudflare.com/hc/en-us/articles/200170096-H...
- kevin_nisbet 7y agoThis is an interesting perspective. Just as a counter argument, one of the things we tried to do at a previous employer was data exfiltration protection. This meant using outbound proxies from our networks to reach pre-approved urls and we don't want to mitm the TLS connections. This leaves a bit of a problem, because we don't want to whitelist all of s3, the defeats the purpose, so we had to mandate using the bucket.s3 uri style, which is a bit of a pain for clients that use the direct s3 link style, but then we could whitelist buckets we control. I don't want to say this use case is more important, but I can see the merits of standardizing on the subdomain style, and that this might be a common ask of amazon.
- arcbyte 7y agoExfiltration protection is pointless. It's a great way to waste money and annoy your employees.
- stevenpetryk 7y agoThis is not a helpful comment. Could you provide some examples of why it's a waste of money?
- outside1234 7y agoWhen there is a will, there is a way.
- Scoundreller 7y agoAny output device is an output device. A VGA interface. An HDMI interface. A Scroll lock keyboard light. A hard drive interface. A speaker. All you need to do is send the signal down one wire and you could tap into that wire and copy all the data to another system. Copying files from one folder into another could do the job.
- Darkphibre 7y ago
- paulddraper 7y agoIMO the even bigger problem is that this literally breaks HTTPS. AWS S3 will only provide SSL validation if your bucket name happens to not contain "." Which is a practice encouraged by AWS. [1] So anyone that has www.example.com as the bucket name can no longer use HTTPS. [1] https://docs.aws.amazon.com/AmazonS3/latest/dev/website-hosting-custom-domain-walkthrough.html https://docs.aws.amazon.com/AmazonS3/latest/dev/website-host...
- giovannibajo1 7y agoWe have exactly this problem. I would appreciate if somebody explained how we should fix this. We need HTTPS and we have buckets with dots in their names
- taormina 7y agoA simple answer might be "time to move to another static hosting solution".
- PetahNZ 7y agoIf static hosting is the purpose, just put cloud front in front if it.
- thayne 7y agos3 isn't just used for static hosting. And if you have terabytes of data in a bucket that happens to have a dot in it (that may have been created a long time ago). Your options appear to be not using https, or spending a _lot_ of time and money moving to a new bucket or a different storage system. It seems to me that if Amazon is going to do this, they should at least provide a way to rename buckets without having to copy all of the objects.
- runamok 7y agoIt obviously depends on how many files we are talking about but copying files to a new bucket in the same region will not cost that much. You could definitely make the case to AWS that you don't want to pay since they are removing a feature and you might get a concession. $0.005 / 1,000 copy requests... ref: https://blog.cloudability.com/aws-s3-understanding-cloud-storage-costs-to-save/ https://blog.cloudability.com/aws-s3-understanding-cloud-sto... Also you will likely want to use some sort of parallel operation. I used this eons ago: https://github.com/mishudark/s3-parallel-put https://github.com/mishudark/s3-parallel-put
- randomguy9839 7y ago"right now I could put some stuff not liked by Russian or Chinese government (maybe entire website) and give a direct s3 link to https:// https:// s3 .amazonaws.com/mywebsite/index.html. Because it's https — there is no way man in the middle knows what people read on s3.amazonaws.com." Chinese government will just ban the whole s3.amazonaws.com domain. Same as facebook.com, youtube.com, google.com, gmail.com, wikipedia... However letting them banning sub-domains will actually make S3 a useable service in China. It's a huge step forward.
- andromeduck 7y agoYou could say the same about Dragonfly.
- morpheuskafka 7y agoWould encrypted SNI fix this? [1] https://blog.cloudflare.com/encrypted-sni/ https://blog.cloudflare.com/encrypted-sni/
- ec109685 7y agoYes, nothing man in the middle can do to detect the final domain being connected to.
- MichaelMoser123 7y agohttps://en.wikipedia.org/wiki/Domain_fronting#Disabling https://en.wikipedia.org/wiki/Domain_fronting#Disabling Interestingly a different although related trick (that of domain fronting) has been blocked last year "by both Google and Amazon.... in part due to pressure from the Russian government over Telegram domain fronting activity using both of the cloud providers' services."
- eecc 7y agoFollow the money :/
- consumer451 7y agoThe Russian market is tiny, so that logic leads me to the country south-east of Russia. The one with all the new consumers.
- andrewxhill 7y agoDefinitely worth checking out https://ipfs.io/ https://ipfs.io/. Even for those who don't or can't run IPFS peers on their own devices, IPFS gateways can fill much of the same purpose you listed above. Additionally, the same content should be viewable through _any_ gateway. Meaning if a Gateway provider ever amazoned you, you simply make the requests through a new gateway.
- MichaelMoser123 7y agoYes, but restrictive governments will have no problem with blocking access to the ipfs.io domain via DNS and by blocking its IP addresses, whereas using the same method for blocking all access to AWS or google cloud is too costly as it will result in collateral damage at home. (Well China can block access to AWS located outside of China because there are AWS Regions in China)
- zanny 7y agoWith ipfs anyone can operate an http relay to access the network from any arbitrary IP and/or distribute endpoint IPs to populate the daemons dht if run locally.
- netheril96 7y agoCollateral freedom doesn't work in China. China has already blocked or throttled (hard to tell which, since GFW doesn't announce it) connections to AWS S3 for years.
- adamfisk 7y agoS3 is hardly the only example of collateral freedom in China. There are many other cases where the concept works.
- deleted 7y ago[deleted]
- ignoramous 7y agoHi Adam! Thanks for the effort you put in for https://getlantern.org https://getlantern.org Since you're here, can I request that lantern start being more privacy friendly too, apart from helping with censorship? May be there's two versions of lantern network that you could run? Frankly, clauses in lantern's privacy document are appalling: https://s3.amazonaws.com/lantern/LanternPrivacyPolicy.pdf https://s3.amazonaws.com/lantern/LanternPrivacyPolicy.pdf > Personalize and improve the Services, including to provide or recommend features, content, social connections, referrals, and advertisements. > (We may share information...) With vendors, consultants, marketing partners, and other service providers who need access to such information to carry out work on our behalf > When you use our Services, we collect information sent to us by your computer, mobile phone or other access device. The information sent to us includes, but is not limited to, the following: data about the pages you access, computer IP address, device ID or unique identifier, device type, geo-location information, computer and connection information, mobile network information, statistics on page views, traffic to and from the sites, referral URL, ad data, and standard web log data and other information. We also collect information through our use of cookies and web beacons. > Device Information: We may collect information about your mobile device, including, for example, the hardware model, operating system and version, software and file names and versions, preferred language, unique device identifier, advertising identifiers, serial number, device motion information, and mobile network information. > Log Information: When you interact with the Services, we collect server logs, which may include information like device IP address, access dates and times, app features or pages viewed, app crashes and other system activity, type of browser, and the third-party site or service you were using before interacting with our Services. ...which you might share with the US government (even if we ignore the fact that you're also funded by them, the privacy policy leaves a lot to be desired). > We may transfer the information described in this Statement to, and process and store it in, the United States and other countries, some of which may have less protective data protection laws than the region in which you reside
- _pmf_ 7y agoI think this is exactly what happened.
- est 7y ago"collateral freedom" is a failed concept. Many years ago people use Gmail to communicate, and they argue that Chinese government won't dare to block such important and neutral service. There are like <1% websites in China relies on S3 to deliver static files. Blocking AWS as a whole has happened before. There is simply no freedom was "collateral". Freedom has to be fought hard and eared.