5 ms·
Why are they even pulling this MITM trick in the first place ? Can't GoGo just "blacklist" streaming sites at a DNS level and deal with the problem before a co
by whyleyc 12y ago
Why are they even pulling this MITM trick in the first place ?
Can't GoGo just "blacklist" streaming sites at a DNS level and deal with the problem before a connection is even made to a high-bandwith destination ?
- GauntletWizard 12y agoBecause you probably have youtube.com cached, for one.
- whyleyc 12y agoThe TTL on the A record for youtube.com is 5 mins though, so a "well-behaved" client would likely need to re-query the DNS. You could just edit your local hosts file to circumvent that but you'd have to then have entries for the myriad of streaming servers that YouTube uses to deliver videos.
- wtallis 12y agoIt's commonplace for savvy users to never trust the DHCP-provided DNS servers, and DNSSEC is available to detect when responses from your trusted DNS server are being hijacked and replaced with lies.
- Panino 12y agoDNSSEC offers no protection against censorship because it's not encrypted. All GoGo would have to do is drop the query or return SERVFAIL.
- wtallis 12y agoDNSSEC protects against the hard to detect forms of DNS fraud. A SERVFAIL or ignored query already makes it completely obvious that your DNS server isn't behaving, and if you're trying to use an otherwise-reliable DNS server, it's a major red flag that the network is working against you. What DNSSEC protects against is a DNS server returning information that it wants you to think is valid; a SERVFAIL is never going to look like the right response. There's a lot more than just censorship that can be accomplished by messing with DNS responses, and censorship done solely through DNS is actually pretty half-assed censorship.
- Panino 12y agoRight, but the comment that prompted this sub-thread was: > Can't GoGo just "blacklist" streaming sites at a DNS level and deal with the problem before a connection is even made to a high-bandwith destination ? Clearly the word here is "censorship." Or if you prefer, "blocking," which doesn't have a politial connotation. DNSSEC was then proposed as a countermeasure to this blocking, and I showed why it's not a countermeasure. DNSCrypt would be more effective here because it's encrypted.
- wtallis 12y agoDNSCrypt on its own accomplishes nothing. What you're really saying is to use DNSCrypt and configure it to masquerade its traffic by not using port 53 so that it's less likely to be blocked. Without using a non-standard port, the results for DNSCrypt will be the same as from DNSSEC: an error in trying to look up the domain, which is identifiable as being different from an error trying to access the server pointed to by the DNS record. You don't need DNSCrypt to be able to do DNS lookups on a non-standard port. DNSCrypt just happens to offer a list of a few servers that respond (using their protocol) on non-standard ports. The list is short enough (16 IPs to block!) that it could easily be included in the malicious gateway's firewall rules, rendering DNSCrypt useless for working around the blocking and still less useful than DNSSEC for deducing the nature of the interference.
- Panino 12y agoI think you've misunderstood what whyleyc wrote above. OP asked why GoGo doesn't just "blacklist" ie censor the mentioned sites via DNS, explicitly excluding a MITM attack: > Why are they even pulling this MITM trick in the first place ? > Can't GoGo just "blacklist" streaming sites at a DNS level and deal with the problem before a connection is even made to a high-bandwith destination ? So no MITM, just GFW of China style blocking. Which is trivial for unencrypted packets like DNSSEC. Observe, by the way, that China supports DNSSEC -- it's not a problem for them! http://dnsviz.net/d/cn/dnssec/ http://dnsviz.net/d/cn/dnssec/ And it wouldn't be a problem for GoGo, either, because DNSSEC is not encrypted and blacklisted sites can be dropped on the floor. Or GoGo could trivially return SERVFAIL. But the whole thing is moot anyway because youtube.com doesn't support DNSSEC and probably never will.