Thai government to MITM all internet communications
bangkokpost.com
bangkokpost.com
It's quite possible. An MITM attack has a basic quality that makes it detectable - each end is seeing different crypto bits for the same plaintext. All they have to do is compare notes.
There are out-of-band ways to do this, such as certificate pinning and certificate repositories. But these haven't achieved much traction.
Doing it in-band is difficult, but possible. An early system, for one of the Secure Telephone Units (STU), displayed a 2-digit number to the user at each end, based on the crypto bits. The users were supposed to compare these numbers by voice, and if they matched, they were probably not having a MITM attack. An MITM attacker would need to fake the voices of the participants to break that.
This is the insight that makes MITM detection possible. You can force the MITM to have to tell a lie to convince the endpoints. More than that, if you work at it, you can force the MITM to have to tell an arbitrarily complex lie. You can even force the MITM to have to tell a lie about the future traffic on the connection. That means they have to take over the entire conversation and fake the other end.
As an example, suppose a server sending a page sends, at the beginning of the page, a hash value which is based on the contents of the page about to be sent, and also based on the first 64 bytes of the crypto bits of the connection. The browser checks this. The MITM attacker now has a problem. If they don't know about this, the MITM attack immediately sounds an alarm at the browser. If the attacker does know about this, they can compute their own hash. But they haven't seen the content the hash covers, because the page hasn't been transmitted yet.
So the attacker either has to buffer up the entire page before they can send any of it, or fake the page based on some source like a cache. Buffering up the entire page adds delay. The server can add to that delay by deliberately stalling for some seconds before sending the last few bytes of the page. If the MITM attack adds 10 seconds before every page begins to load, it's obvious what's happening. The browser could even check this; if the first byte of the page doesn't appear within N seconds, don't display it.
Faking the page is a lot of work, especially if it's customized. A cache won't be enough. Users will notice if they get a generic page instead of their personal social network page.
This would be a good feature to add to HTTP2, because it has one persistent connection which, once validated, is good for many pages.
Nobody seems to be doing enough with in-band MITM detection. There's [1], but that requires "previously established user authentication credentials." Facebook has a scheme which relies on MITM attackers not knowing how to MITM Flash content.[2] That's a form of security through obscurity, but it does detect most attacks at the proxy and hostile WiFi level.
[1] http://www.cc.gatech.edu/~traynor/papers/dacosta-esorics12.p... [2] http://www.scmagazine.com/researchers-detect-ssl-mitm-attack...
The government will still be left with two options: Severely cripple themselves by blocking entire services or remain unable to decrypt traffic. Unlike China, Thailand is in no position to create their own search engines, social media and messaging systems.
My guess is that they will attempt to do what is being talked about. If it breaks the internet in Thailand they don't care. The junta and their masters don't really understand and don't use it. It's just a toy to them and a place that is used to spread speech they don't like. The royalist elites that the junta are focused on protecting have their private bankers and underlings to take care of things so they don't care if internet banking is broken or if social media breaks. All that matters to the junta is protecting their core interest group of royalists.
Though I don't see how they will manage that for mobile browsers.
Android dominates in Thailand. I wonder if Google's licensing allows vendors to make such modifications for carriers? The leaked agreement between Google and Samsung explicitly forbids tampering with any of Google's software.
Well, "fortunately", Blue Coat Systems, leading manufacturer of intercept devices for authoritarian regimes, now has an intermediate cert courtesy of Symantec CA, so they're fully capable of issuing and installing MITM certs for use on their clients' devices.
They would have to give their private key to their clients to achieve a MITM attack, right?
Others have suggested they could provide a cloud-type service to achieve the same result.
[0]: https://blog.cloudflare.com/keyless-ssl-the-nitty-gritty-tec...
Yeah it's just a tool and yeah your workplace or school might need one to "keep the children safe", and yeah they're not responsible for what their customers do with their products. But when they knowingly sell[1] to repressive governments where bad things happen to dissenters, what does that make them? And please spare us the "terrorist" and "criminal" barf, we've heard it in the West.
Any Blue Coat care to comment?
1. https://www.eff.org/deeplinks/2011/10/blue-coat-acknowledges...
Thats literally the one thing you aren't allowed to do as a CA.
Because they (and the companies they own, like Verisign), are the root of about 30-40% of all active, web-visible ssl certs at the moment.
No browser maker, even Google is going to break that much of the web over one shady intermediate cert. The consequences for users are too high and too many people are willing to excuse it because it's "only" a pathlen=0 and it would be noticed if used en masse so it's "only" useful for targeted attacks by state-actor clients.
And like one bazillion apps that unlike browsers will not have any UI to ask the user to confirm if falling back to unencrypted channels is okay.
I really don't see this working without Thai people revolting...
Because they are for-profit businesses who would want an economic edge over competitors in the Thai market and aren't vanguards for classical/social liberal ideals?
As someone from /r/Thailand put it, "I'm hoping incompetence and indifference would save the day once again, as it has many times in the past." They can't withdraw it now without losing face, but they can let it just wither and become forgotten over a few years.
firstname dot lastname at gmail
The only difference is that the Thai government is being honest about what it wants to do. The "democracies" in the five eyes implemented mass surveillance in complete secrecy.
We begin therefore where they are determined not to end, with the question whether any form of democratic self-government, anywhere, is consistent with the kind of massive, pervasive, surveillance into which the Unites States government has led not only us but the world.
This should not actually be a complicated inquiry.
https://archive.org/details/EbenMoglen-WhyFreedomOfThoughtRe...
Surveillance is not an end toward totalitarianism, it is totalitarianism itself.
https://www.washingtonpost.com/world/national-security/nsa-i...
https://thainetizen.org/2016/05/single-gateway-back-ssl-cens...
Maybe it is what it takes to move forward from a dictatorship to a (fake) democracy these days.
the https everywhere movement was a pain-in-the-ass when I was in China, because many websites would redirect me from http to blocked https.
I switched from Gmail while I was there (and back) and just watched youku instead of youtube, so I mostly didn't bother paying for a VPN.
It may be that I would be even less comfortable with it if I knew the details.