But their latest methods are scarily effective.
They now do a man in the middle attack to decrypt ssl, and store all of it, if you use openvpn as a proxy without accounting for this they own you.
They also have the ability to send fake a close packet (I think its a corrupt packet and most ssl / ssh will just drop the connection) to stop you tunnelling out and around their censorship.
The average citizen could not possibly hope to overcome this censorship and I find my own abilities more and more challenged to stay ahead of them, they have a whole army of people that understand the internet better than me, eventually they will exceed my abilities, its only a matter of time.
Have there been any evidence of HTTPS and/or VPNs being MITM'd by UK ISPs?
Unless the UK government has cracked all the ciphers used by HTTPS + VPNs and have backdoored every CA, I think we'd already know about widespread systematic MITM attacks in UK users. If they have done all of that, then you can bet others have too then the whole world is screwed
Please cite your sources of actual evidence. Talking about mysterious black boxes doesn't count - they could be pollution sensors for all we know.
[1] There is evidence GCHQ are doing attacks on HTTPS via UK ISPs pre-snowden, post-snowden what does it matter? There is no evidence they have stopped. [2] The Investigatory Powers Act legalizes the governments use of this technology. If you are going to argue that they no longer have this capability or Snowden made it all up Im gonna need some sources.
> Unless the UK government has cracked all the ciphers used by HTTPS + VPNs and have backdoored every CA
You don't need to hack all the things you just need to hack like 95% of the things and [1] is evidence GCHQ have that. I mean I guess you can say "yea but im in that 5% the system works!" while GCHQ work to close the gap.
I mean just read some of the stuff GCHQ do:
https://theintercept.com/2015/09/25/gchq-radio-porn-spies-tr...
[1] https://www.theguardian.com/world/2013/sep/05/nsa-gchq-encry... [2] https://www.libertyhumanrights.org.uk/human-rights/privacy/s...
Is there any evidence of this?
They have never claimed they send fake ssl packets to drop the stream but they have done it to me and the uk governments stance is kind of against modern tls greater than 1.2 which fixes the drop stream packet bug [4].
There is plenty more detail about what they are doing out there, search snoopers charter and GCHQ snowden to see what they have been doing and are now trying to make legal.
[1] https://www.zdnet.com/article/u-k-spy-agencies-plan-to-insta... [2] https://www.theguardian.com/world/2013/sep/05/nsa-gchq-encry... [3] https://www.libertyhumanrights.org.uk/human-rights/privacy/s... [4] https://www.ncsc.gov.uk/blog-post/tls-13-better-individuals-...
I was told they have intermediate keys for certificate authorities(probably done legally with the ca permission), generate a new key signed with the real intermediate. This would be detectable as the cert fingerprint would be different from the legit legit one, while SSH checks for this by default SSL does not.
I have tried to detect the above and as far as I can tell they are not doing it, but I believe the people I heard more than I believe my ability to detect it.