11 ms·
Indian ISPs: We already give govt full access to web traffic
- bheadmaster 4y agoGNU Net [0] seems more relevant than ever: "The Internet is broken." "The conventional Internet is currently like a system of roads with deep potholes and highwaymen all over the place. Even if you still can use the roads (e.g. send emails, or browse websites) your vehicle might get hijacked, damaged, or long arms might reach into its back and steal your items (data) to use it against you and sell it to others - while you can't even notice the thievery nor accuse and hold the scroungers accountable. The Internet was not designed with security in mind: protecting against address forgery, routers learning metadata, or choosing trustworthy third parties is nontrivial and sometimes impossible." [0] https://www.gnunet.org/en/ https://www.gnunet.org/en/
- thr83away 4y agoHow does it differ from tor browser?
- eternalban 4y agoThanks. Great bib! https://bib.gnunet.org/ https://bib.gnunet.org/
- naring2 4y agothis is just a bad analogy. the internet is not transporting anything like a road would. the whole system works by copying “your data” every step along the way. they are not thieving your precious bits, they are copying them as they are transmitting them. this s also why you cannot even notice the “thievery”. furthermore, this analogy is mangling together data legitimacy, security, and property rights all into one big ball of “be worried, the internet is stealing you because it wasn’t designed with safety in mind”
- npteljes 4y agoSending postcards could be a more apt analogy. Even if a bit outdated, still a widely familiar activity, and postcards can be copied. And they are just as open to people in between as HTTP packets are.
- pessimizer 4y ago> the internet is not transporting anything like a road would. Comparing the internet to a highway system is a common and useful thing to do. Your objections are strange. > they are not thieving your precious bits, If I look over your shoulder at the ATM and learn your PIN, is it not clear what I mean when I say that "I've stolen your PIN?" > mangling together data legitimacy, security, and property rights all into one big ball Is entirely intentional, because these are things to be worried about on the internet.
- bheadmaster 4y agoIf you happen to come up with a better analogy, I'm sure the GNU Net development team will appreciate your input: gnunet-developers@gnu.org GNU Project is community-driven, after all.
- deleted 4y ago[deleted]
- mdp2021 4y agoAn important point is whether legislation exists which allows such "monitoring". Edit: I would also like to add, one of the latest news was about malicious access of administrative data in Australia - which surely has in general more funds to invest in security than others. I would be concerned about personal data being copied in more repositories (multiplying chances of malicious access).
- mathieuh 4y agoIsn't that why countries passed non-specific laws? E.g. in the UK we have the Snoopers' Charter: https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016 https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016, I believe in the US the Patriot Act did something similar.
- pessimizer 4y agoThat's an important thing to note, so you can recognize it where you live i.e. under what obscure interpretation, of what strangely written law, passed under what conditions, enabled unlimited network surveillance in the countries that have it? Who in your country supports similar legislation?
- nisegami 4y ago>An important point is whether legislation exists which allows such "monitoring". One thing that people from the "global north" need to remember is that in most of the world, laws are just loose guidelines.
- hulitu 4y agoIt is the same in the "global north". See Assange Swedish cases.
- jphsnsir 4y agoDon't all ISPs do this? They can be stubborn and lose connecting with the rest of the net.
- azalemeth 4y agoMany, if not most, nations have similar provisions to this. I think it's wrong and just over the top. However, encrypting everything and using multi-hop routing wherever possible at least will add noise to this sort of dragnet surveillance. Personally, I've taken steps to obsfucate my traffic since similar legislation was introduced in the UK.
- kurmouk 4y agoCould you possibly share the tools you use to obfuscate your traffic?
- _trampeltier 4y agoI did start with Yacy. First I would bould something thet search a list on Google or so and the just follow links forever. Finally I just found Yacy a P2P search. I did run it for a couple of years. https://yacy.net/ https://yacy.net/
- danuker 4y agoI would guess Tor, I2P, Freenet, GNUNet. But also configuring or avoiding certain other software: https://spyware.neocities.org/articles/index.html https://spyware.neocities.org/articles/index.html
- roenxi 4y agoSnowden released his trove back in 2013. At that point it became obvious that anyone with power to surveil would use it. I suppose the news here is that the response was so relaxed that governments started doing it publicly and explaining the tech.
- altcognito 4y agoIt was obvious before Snowden. https://en.m.wikipedia.org/wiki/Room_641A https://en.m.wikipedia.org/wiki/Room_641A
- 4y ago
- Neil44 4y agoBut how... I mean presumably they don't install a root cert on every client device?
- stevewatson301 4y agoThey can intercept the unencrypted section of encrypted connections, such as TLS ServerName, and the source and destination of every IP datagram which already provides a lot of information to profile individual citizens. QUIC moves to a model where everything except the Connection ID is encrypted[1], but it is also apparently being blocked in India[2]. The mandated transition to IPv6 in India[3] would also take away the need to track 5-tuples to identify individual customers, easing the scaling of monitoring. [1] https://datatracker.ietf.org/doc/html/rfc8999 https://datatracker.ietf.org/doc/html/rfc8999 [2] https://github.com/kelmenhorst/quic-censorship/issues/2 https://github.com/kelmenhorst/quic-censorship/issues/2 [3] https://dot.gov.in/ipv6-transition https://dot.gov.in/ipv6-transition
- lakomen 4y agoHow would ipv6 "take away the need to track 5-tuples" and what does that even mean? That sentence doesn't make sense
- stevewatson301 4y agoNATing IPv4 traffic requires maintaining a 5-tuple of connection state[1], which means the ISP must log these 5-tuples to be able to track citizens individually. Further, if there's another layer of NAT (such as a free WiFi service in an airport or a WiFi router in a citizen's home), cooperation is needed at that NAT layer too. IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space. Each citizen can then be assigned an unique IP address which makes it easier to distinguish traffic without the cooperation of each NATing layer. [1] https://support.huawei.com/enterprise/en/doc/EDOC1100055044/a9c9d8ca/nat-address-pool-and-its-conversion-basis https://support.huawei.com/enterprise/en/doc/EDOC1100055044/...
- 4y ago
- petya0812 4y ago
- mritun 4y agoYes they do, mainly because it’s the law. That it’s a misguided law is open for debate, but I don’t believe there is any state in the world that doesn’t monitor and control tele-communications (internet is regulated as tele-communications WW).
- mdp2021 4y agoIt is the details of the law that count here. "Rights of investigation" and "capillary monitoring" are poles.
- quietbritishjim 4y agoThe level of surprise does seem overblown. This bit stuck out to me: > ... access to this data is so accessible remotely that physically visiting an internet provider’s premises is no longer required for government agencies. They were expecting government agents to have to physically visit the ISP's offices? Were they perhaps going to get their data on a floppy disk?
- Lealen 4y agoThey weren't asking for floppy disks, they were sending their people to connect directly to infrastructure. One of examples: https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A
- quietbritishjim 4y agoAh ok that does make a bit more sense.
- yardstick 4y agoJust because data can be made accessible remotely doesn’t mean it should be. Airgapped systems are also still a thing. On-site access would also make it harder to abuse the data at scale. I’m not surprised that the data is accessed remotely. But I can also understand scenarios where it makes sense to require physical access, and not because of long gone floppy disk drives or other ancient hardware.
- 2Gkashmiri 4y ago5 days ago i wrote about UK govt doing scans of all websites hosted in UK for "security" reasons and i was downvoted for " Stop lying and not relevant, you clearly came here with an agenda"... i guess we really do have an agenda when the government has access to full internet web traffic and they can pick and choose their targets with impunity https://news.ycombinator.com/item?id=33470079#33470409 https://news.ycombinator.com/item?id=33470079#33470409
- mdp2021 4y agoAnd in some countries we are starting to see "Adopt electronic payment: simple and safe" - which implies, "create tracks" -, as generic anonymous advertisement... Even on the electronic billboards of motorways!!!
- dspillett 4y agoLooking at that, I'd suggest the downvotes are from being technically wrong (the “Scanning for vulnerabilities won't help you find critics. If you wanted to look for critics, you would scan for critics.” argument – there are better/easier ways to achieve what you are talking about a government trying to achieve so why would they go to that effort?). Maybe some considered the comment concerning India on a thread about the UK was pulling things off-topic, though as not all voters replied with clarifying comments we'll never know. The lying/agenda thing seems to just be one comment. Try not to assume that one angry reply represents a larger chunk of HN's readership. The Internet is full of bus-stop boxers, it is best to not let them wind you up overly.
- 2Gkashmiri 4y agooh no, not that. >Try not to assume that one angry reply represents a larger chunk of HN's readership. you get to have a thick skin when you are on an anonymous public platform. i accept that.... i live in a place where i have to actually assume malice on part of the government because the government "is" hostile against me. Again, this isn't some tin-foil conspiracy but as you might've guessed from my handle, its yeah... So that comment earlier and the current article about ISPs tracking users, this is primarily to catch critics and dissenters.
- lakomen 4y agoOk so how is it different from what the USA does?
- Sakos 4y agoProbably not at all. Still worth reporting and talking about. It's not okay if the US or India or any other country does it. I'm not happy that most comments here are so resigned, "well, yeah, everybody does it".
- ozim 4y agoWorth talking because there are still people who argue that TLS and HTTPS is hassle that is not needed.
- hulitu 4y agoYou do realize that they are talking about "https" and "tls" trafic , do you ? The only use i see for those protocols is to identify you.
- sremani 4y agoIndia is neither a 'Nation of creed' like US or a National-Security state like Russia or Pakistan. It is a nation of insurgencies though, so look elsewhere if Privacy to holy to you, cause it ain't going to be India's forte.
- Ptchd 4y agoIt's probably not as bad as what the USA is doing today...
- balaji1 4y agoAs many have mentioned, this is probably very common in every country. But there is always the next target(s) to go after, to keep in check, in a pop culture sense. So one way is to see this (article and this HN post) as a hit piece.
- hunglee2 4y agoI think we must all agree that national governments have a duty of care towards their citizens. From the Indian govt perspective, the dominance of the Internet by foreign owned businesses means that the country is vulnerable to malfeasance should those foreign governments mean India harm or come to decide - over the head of the government - what the Indian people want or need. This is about national sovereignty and national security. We have seen how those values trump privacy concerns for individuals in any country, including the US, so must accord the same understanding for other nations also.
- instagraham 4y agoThis government's police agencies have used Israeli spyware to plant incriminating evidence on journalists and activists. "National security" has come to mean "anything critical of the government". Loose terms like "national security" are like good times that breed weak leaders. I think we must all agree that citizens have a right against persecution. What track record does this government have that suggests they will do no wrong with their internet history logs?
- hunglee2 4y ago"National security" has come to mean "anything critical of the government". Yes this is true! Hence government needs to invest in indoctrination in order to better convince the people of the justness of their actions. Singing the national anthem, waving the flag, inventing enemies without and within - it's pretty easy to build the 'cognitive infrastructure' required to carry the day
- raxxorraxor 4y agoI agree that most western democratic nations are a very bad example when it comes to defending their own values. But government should simply not have the ability to monitor citizen communication. It was a problem in the past and it should not be a problem in the future.
- hunglee2 4y ago
- praveen9920 4y agoThis came as a surprise to me considering when the Indian court orders to take down particular content of particular site, ISPs still uses dns blocking instead of more granular blocking which resulted in blanket site blockings of popular sites
- rand0mx1 4y agoMost Indian ISPs employ Deep-packet Inspection to block websites
- praveen9920 4y agoNot all of them have the capabilities of course
- m33k44 4y agoThis happens because the Indian government does not yet have the infrastructure of NSA and or GCHQ :) They have to demand for the information instead :)
- deleted 4y ago[deleted]
- LatteLazy 4y agoAnd US and UK and Australian and basically all countries at this point.
- mtgx 4y ago
- neets 4y agoWhat is India turning into China lite?
- user_7832 4y agoWell if you look at the Snowden/Five Eyes/9 Eyes etc by that logic USA/Aus/France etc are already "turning" into China (except, of course that this has been going on forever and no one really paid too much attention to Snowden). Not blaming you as mainstream media also often paints Snowden negatively but something to be aware of.
- Anunayj 4y agoPeople really underestimate the full scale of this, specially today with so many sites using cloudflare without strict ssl reverse proxy connection, Cloudflare Endpoints in India are INSIDE ISP networks [1], what this means is the ISP (and therefore by extension the government) sees EVERYTHING going out of cloudflare servers over http in plaintext. Worse ISP will also modify that content so you get the "This site has been blocked in India under diretions from [...]" over https! cause that's what cloudflare saw when it did it's (insecure) http request 1. https://github.com/captn3m0/hello-cloudflare https://github.com/captn3m0/hello-cloudflare
- roody15 4y agoDo you honestly believe the US government doesn't have the same access to cloudflare data within the states?
- JumpCrisscross 4y ago> the US government doesn't have the same access to cloudflare data within the states? Yes. There is almost certainly access. But it’s partial and adversarial, not automatic as in India.
- somenameforme 4y agoPRISM [1] didn't end when the media stopped reporting on it. If anything it's likely only become more emboldened given people's tepid response. This [2] is one of my favorite documents that was leaked. It's a user manual, "User's Guide For PRISM Skype Collection", for NSA agents spying on Skype "peer to peer" connections in real time. It even includes a helpful FAQ like agents wondering why they might receive copies of the same message multiple times. What happens there is when somebody they're spying on logs in via another device, their resync process involves everything being sent right on over directly, automatically, and in real time to the NSA again. They can even spy on video/audio in real time, with some promises to agents frustrated about audio falling out of sync with video - that they were working on a technical solution. The companies at the time participating in PRISM were Apple, Google, Microsoft, Facebook, and others. That's undoubtedly been long since expanded. [1] - https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM [2] - https://www.aclu.org/sites/default/files/field_document/Guide%20for%20Analysts%20on%20How%20to%20Use%20the%20PRISM%20Skype%20Collection.pdf https://www.aclu.org/sites/default/files/field_document/Guid...
- UltraViolence 4y agoThe real canary in the coalmine was actually a movie from 1999 called "Enemy of the State." The plot for the movie was actually based on an account from an NSA employee who tipped one of the producers or director (I forget which) of the mass surveillance the agency was involved in. To me this movie is iconic just because it predicted events so vividly almost a quarter of a century ago.
- 0x445442 4y agoEven before that, Sneakers “predicted” the NSA spying on its own citizens. I use quotes because it happens too often to be happen stance IMHO.
- i_am_jl 4y agoI remember watching Enemy of the State in theaters with my dad. I remember thinking it was a cool movie, but sort of unrealistic and over-the-top, like James Bond. Now I think it's unrealistic because Will Smith and Gene Hackman survived the first 25 minutes of the film.
- a4isms 4y agoDigression: If you like "Enemy of the State," you absolutely must watch "The Conversation"[1] if you haven't already. You may decide, as many have before you, that it exists in the same universe as "Enemy of the State," and that Gene Hackman's character in "Enemy of the State" is an older, even more cynical Harry Caul from "The Conversation." [1]: https://en.wikipedia.org/wiki/The_Conversation https://en.wikipedia.org/wiki/The_Conversation
- varispeed 4y agoPredicted or inspired... Imagine a young, going to be politician, kind of person watched it and thought "Hmm, this is not a bad idea at all!" and then climbing the political ladder lobbying for these kind of measures.
- syntaxing 4y agoCurious how this works technically, does the Indian government have control over ca certs and every ISP uses them to MiTM it?
- evnix 4y agowe need a decentralized list for holding key pair signatures. it could something like adblocker list, No more central CA.
- sidcool 4y agoUse VPNs. Most are quire expensive from Indian standards.
- openasocket 4y agoI'm confused, are they actually getting the plaintext content of HTTPS traffic, or are they just harvesting connection metadata? Not that bulk metadata collection isn't bad, but getting access to unencrypted data would be much worse.