6 ms·
GoGo does not need to run “Man in the Middle Attacks” on YouTube
- barnaby 12y agoThis post assumes that GoGo are doing a MITM simply to block YouTube in order to prevent their network from being congested. My assumptions would be that 1) GoGo are blocking youtube in favor of their in-flight paid media services not just for badwidth 2) GoGo's MITM attack has little to do with media content but rather more about being able to read all the communications of passengers for "national security" purposes. If they are decrypting and logging your traffic (including passwords) and communications, then I assume their scheme can be defeated by a VPN. If you want to send intimate messages to your lover, or discuss a political protest while in flight, without some nosy GoGo employee reading it, then probably using OTR (like Cryptocat or pidgin/adium), PGP (like mailvelope, enigmail), and ZRTP (Redphone/Signal) are a pretty good idea.
- HackinOut 12y ago1) They are not blocking (completely) Youtube. But still plausible. 2) Then why would they be doing it only on video streaming websites? [1] Also, if they are so obvious about their methods from now on, one nice thing is that we won't need whistleblowers anymore. [1] https://news.ycombinator.com/item?id=8839733 https://news.ycombinator.com/item?id=8839733
- ubernostrum 12y agoAs a frequent user of in-flight internet, I can tell you their login page has a big reminder saying that streaming video is not supported and giving examples like Netflix and HBO Go. The technical reason -- which is sound -- is that there's not enough bandwidth between plane/ground.
- HackinOut 12y agoI would expect that even if it wasn't mentioned, I mean it's a freaking internet access in a fast moving object 30,000 feet above ground! I don't like what Gogo just did, but kudos for undertaking this challenge. barnaby mentioned they have in-flight paid media services, of what sort/diversity/quality? I suppose it's a selection of movies stored on a server in the plane.
- ubernostrum 12y agoYes, in-flight streaming services tend to have a bunch of stuff on a little server on-board, and the in-cabin routers can more than handle that. It's the plane<->ground link that's the chokepoint; on a lot of planes that bandwidth isn't much better (and sometimes worse) than a 4G cellular link, but shared among everyone on board.
- barnaby 12y agoExactly, those media servers are in the plane.
- wtallis 12y agoStrictly speaking, GoGo's service isn't capable of handling streaming, but it's not clear to what extent bandwidth is the limiting factor. Really bad bufferbloat does horrible things to goodput. With proper QoS, it's likely that they could sustain at least one or two low-resolution YouTube streams, just not a whole plane full. Terrestrial ISP's can't handle everyone watching video at the same time, either. Jim Gettys reported on the CeroWrt-devel list that he tried to benchmark the in-flight Internet connection on a United flight to Hawaii last November, and it apparently crashed the connection. The routers and accompanying software being used for these systems are probably of exceedingly low quality.
- xnull1guest 12y ago2.) Makes a lot of sense. I think it is the most likely explanation for the MitM. 1.) GoGo doesn't need MitM on video streaming to aid in law enforcement, but it's an opportune time to mention that video streaming has been a target of the intelligence apparatus as recruiting videos and indictments of US imperialist activity is condemned there (for example Al-Awlaki's videos were censored from youtube for being seditious; to give context here Al-Awlaki was a US citizen assassinated without a trial and is one of four American citizens killed by drone strikes - while never engaging in violent actions himself he was given the moniker 'The Osama Bin Laden of the Internet' for his recruiting efforts). Another relationship video streaming services have with intelligence efforts is that logins and cookies (associated with Google Accounts in the case of Google) are good identifiers. In this case a MAC address could be associated with online accounts (I'm not saying this is done).
- PhantomGremlin 12y agoI think its (probably) wrong to kill US citizens without trial. I won't use the word "assassinate" since it perhaps dignifies the action too much. Also I highly respect John McCain's position against torture, aka "enhanced interrogation". However, the US isn't fighting against opponents who are playing by Marquess of Queensberry Rules. And the average American is willing to descend a little way down a "slippery slope". To quote a White House official:[1] "If Anwar al-Awlaki is your poster boy for why we shouldn't do drone strikes, good fucking luck." Yeah, sometimes right and wrong isn't completely black and white. There are shades of gray. There is a dark side that tries to seduce everyone. [1] http://www.rollingstone.com/politics/news/the-rise-of-the-killer-drones-how-america-goes-to-war-in-secret-20120416 http://www.rollingstone.com/politics/news/the-rise-of-the-ki...
- xnull1guest 12y agoInteresting quote and a good article by Michael Hastings (before his mysterious death) for those interested in the controversial subject of drone strikes. Thanks for the link! Given the use of the quote in the article to cast the CIA as dismissive of Constitutionality and of fundamental human rights would you say that you diverge from Hastings in your understanding (i.e. the CIA are 'right'?). I might be: I'm much more upset at the death of 76 children and 29 adult bystanders accidentally (?) killed while trying to target Ayman al Zawahiri (who is still reportedly at large) or in general the estimated 28:1 ratio of untargetted causualties to successful targets (themselves suspect in international law). Then again, even while Anwar al-Awlaki was no cupcake if his case were applied as a standard of justice in America any true sense or illusion of justice in the legal system we have would be lost.
- declan 12y agoBut there's no evidence that either of your assumptions is true. Gogo has said publicly[1] that they're trying to "shape bandwidth" to YouTube and other streaming sites. Let's not spread conspiracy theories about "national security" on HN when the truth about the NSA's domestic surveillance hijinks is disturbing enough. I say this even though I've criticized Gogo[2] and suggested ways in which they may be legally liable as a result of their fake *.google.com cert. For those who may not be familiar with his work, David Reed, the author of the linked post, helped with the early development of what would become the modern Internet. That includes UDP and IP signaling, which is one reason (I believe) he won an ACM hall of fame award. [1] http://concourse.gogoair.com/technology/statement-gogo-regarding-streaming-video-policy http://concourse.gogoair.com/technology/statement-gogo-regar... [2] https://twitter.com/declanm/status/552365531798716417 https://twitter.com/declanm/status/552365531798716417
- barnaby 12y agoFair point. It's most likely nothing nefarious, but who knows, maybe they log everything and will one day face a data breach like Sony? Maybe they data mine it? IRL if somebody intercepted all of your mail, opened the envelope and then put your private letters and bank statements in their own envelope to re-send it, then told you they were doing this to shape postage traffic because they physically cannot handle certain kinds of packages to your location, then you can both A) Believe them that they cannot handle such packages and B) worry about what goes on during the process of opening and repackaging your mail. You don't know the employees doing the repackaging and what if one of them moonlights as a thief. The post was about A, my response was about B. Sorry if it's off topic but you can and should take steps to protect yourself without interfering with their bandwidth shaping.
- sdenton4 12y agoThe Snowden documents explicitly point to heavy effort going into monitoring internet use by passengers on airplanes, including using information about connecting flights to connect passengers to MAC addresses. It wouldn't surprise me in the least if they were doing a bit of work to make sure that the actual content is readable. It's barely a conspiracy theory.
- 12y ago
- whyleyc 12y agoWhy are they even pulling this MITM trick in the first place ? Can't GoGo just "blacklist" streaming sites at a DNS level and deal with the problem before a connection is even made to a high-bandwith destination ?
- GauntletWizard 12y agoBecause you probably have youtube.com cached, for one.
- whyleyc 12y agoThe TTL on the A record for youtube.com is 5 mins though, so a "well-behaved" client would likely need to re-query the DNS. You could just edit your local hosts file to circumvent that but you'd have to then have entries for the myriad of streaming servers that YouTube uses to deliver videos.
- wtallis 12y agoIt's commonplace for savvy users to never trust the DHCP-provided DNS servers, and DNSSEC is available to detect when responses from your trusted DNS server are being hijacked and replaced with lies.
- Panino 12y agoDNSSEC offers no protection against censorship because it's not encrypted. All GoGo would have to do is drop the query or return SERVFAIL.
- wtallis 12y agoDNSSEC protects against the hard to detect forms of DNS fraud. A SERVFAIL or ignored query already makes it completely obvious that your DNS server isn't behaving, and if you're trying to use an otherwise-reliable DNS server, it's a major red flag that the network is working against you. What DNSSEC protects against is a DNS server returning information that it wants you to think is valid; a SERVFAIL is never going to look like the right response. There's a lot more than just censorship that can be accomplished by messing with DNS responses, and censorship done solely through DNS is actually pretty half-assed censorship.
- sandstrom 12y agoCertificate Transparency[1], a public log that makes maliciously issued certificates easier to detect, will roll out in Chrome [for EVs to begin with] this spring. FF will probably follow. It doesn't solve all CA problems, but it does soothe some. [1] http://www.certificate-transparency.org/ http://www.certificate-transparency.org/
- tptacek 12y agoYou don't need CT to detect this; Gogo was using self-signed certificates, which browsers reject all by themselves.
- Animats 12y agoWhat we need is not "HTTPS Everywhere" (which I sometimes call "Security Theater Everywhere") for static content. We need content signing without encryption for bulky content. The W3C proposal for this is called "Subresource integrity" (http://www.w3.org/TR/SRI/ http://www.w3.org/TR/SRI/). The "integrity" attribute is applied to links, like this: <a href="https://example.com/file.zip" integrity="ni:///sha256skjdsfkafinqfb...ihja_gqg?ct=application/octet-stream" download>Download!</a> This also applies to IMG, EMBED, LINK, etc - any content. This is a huge win for caching systems. Any cache in the path from browser to server, seeing that, can use a cached version of the content. Because cache content validity is defined by the sha256 hash, there's no cache expiration time issue. You can load JQuery once and use it all week. Caching systems can even index their cache by hash, and deliver data loaded from a different site. What a cache cannot do is change even one bit of the content. Such data tampering will be caught by the browser. (W3C is trying to figure out what to do about streaming data.) As for "bufferbloat", that's usually mis-identifying the problem. The real problem is usually bad queue ordering at a choke-point router. FIFO queuing at a choke point will not work well. At a router where there's significantly less outgoing bandwidth than incoming bandwidth, you need some kind of fair queuing, so that big flows don't starve out little ones. Most Cisco routers support that. On the other hand, there's nothing wrong with buffering up lots of content for a single flow if you have the space. If you're loading a big image or a video stream, temporarily stashing a full TCP window of it in the router is just fine. It will be delivered and will play out eventually. Ideally, you'd like full fair queuing, but it's somewhat computationally expensive. There are approximations to fair queuing that work reasonably well, and are being designed into DOCSIS cable routers. See (http://people.cs.clemson.edu/~jmarty/AQM/AQM-DOCSIS.pdf http://people.cs.clemson.edu/~jmarty/AQM/AQM-DOCSIS.pdf) If you're using expensive bandwidth like a satellite channel to an aircraft, you definitely need something smarter than FIFO. (I used to work on network congestion, a long time ago. See RFC 970, 1985. https://tools.ietf.org/html/rfc970 https://tools.ietf.org/html/rfc970)
- dtaht5 12y agoDocsis 3.1 is not using FQ, but the pie AQM. And it hasn't shipped yet. In the interim, fq_codel (which combines fq and aqm) now dominates the field of 3rd party firmware and home routers. It turns out that FQ nor AQM are computationally intense anymore, but software rate limiting, is.
- cornewut 12y agoThe problem is not that they are doing this, but that they can. This is a technology problem and it will not be fixed by shaming offenders (GoGo probably didn't have any evil intentions at all).