The UK’s Secretive Web Surveillance Program Is Ramping Up
wired.com
wired.com
I think lesson to be learned here is that centralized systems such as the internet, due to CAs (including Cloudflare) and ISPs, are unsuitable for private communications.
It is so sad that so many people won't experience late 1980s and early 1990s era of the internet, which was devoid of extensive surveillance and censorship.
Hopefully, humanity will somehow figure out a superior, decentralized communications platform to ensure privacy. However, the current internet offers no such guarantees.
My recommendation at this stage is to assume that government and supranational organizations control the entirety of the internet and act accordingly as if internet had no privacy.
Certificate Transparency ensures that having control over a Certificate Authority's private keys doesn't allow for undetectable MITM attacks since both Chrome [1] and Apple (Safari) [2] will not trust certificates that have not been submitted to CT logs and stamped as such. If a government attempts to issue a trusted certificate using a CA they control, it will be logged. You can't passively decrypt TLS connections with just access to a CA's private keys since those aren't the keys involved in communication, or even the server's private key due to forward secrecy (assuming modern TLS configs).
[1]: https://groups.google.com/a/chromium.org/g/ct-policy/c/wHILi...
FTL:
>Firefox does not currently check or require the use of CT logs for sites that users visit.
Uggh... Anyone know why? Seems sensible to check.
[0]: https://developer.mozilla.org/en-US/docs/Web/Security/Certif...
1. Embedded in the certificate itself - no communication with a third-party
2. Distributed via TLS extension - no communication with a third-party
3. OCSP stapling - the server is the party that initiates a connection with the CA, the client doesn't touch the CA
You only need the complete set of CT logs if you want to verify the logs have not been tampered with.
I should get around to making an "Evil-CA" software that explicitly maintains those two logs.
A government agency using a root key, and getting spotted, would be disastrous for everyone, themselves included. So, if they do have them, and I think you are probably right to assume they do, they would only use them as a last resort in incredibly extreme cases. It would not surprise me if they have have them but have never used them.
Because the parent you're replying to seems to be talking about any/all governments rather than just the UK, and I'm guessing your statement here was 'scoped' to the UK only - I think it's important to point out that this absolutely HAS happened on multiple occasions outside of the UK.
https://en.greatfire.org/blog/2013/jan/china-github-and-man-...
https://www.eff.org/deeplinks/2011/05/syrian-man-middle-agai...
https://www.eff.org/deeplinks/2011/08/iranian-man-middle-att...
Twelve years ago is a different era, no Blessed Methods, no Certificate Transparency, pinning was new, which is why they got caught.
Note that even if you have the private key for a specific certificate, you still cannot perform a passive MitM attack against servers that use modern TLS using perfect forward secrecy, and active MitM attacks can sometimes be detected by the web server itself. There are different techniques that have cropped up; here's an old doc page about Caddy v1, mainly because it's the one that I remembered first:
https://caddy.its-em.ma/v1/docs/mitm-detection
That said, as others have mentioned, CT logs basically foil direct man-in-the-middle attacks abusing CA certificates. The attack will work, assuming it isn't foiled by HSTS, but it will be detected. For a government surveillance program, this would obviously be a very bad outcome.
The CA system definitely gets some deserved flak for being flawed, however I've personally found myself impressed with how much practical security against attackers the web ecosystem has managed to build up. It also was probably good to get more of it done ahead of time before governments could try to abuse gaps in the system; as it stands now, if we had DoH and ESNI (edit: or, now, ECH, I suppose) deployed widely across the internet, it would probably render this entire government surveillance operation useless.
For the NSA that's unacceptable, because the Americans specifically don't like people to know who did it, that's even the point of some big known NSA programmes, like that thing where they hack two Cisco routers so that all the stolen data goes from A to B, but via C, and the NSA steal the data again at C, so when A figure out what's happening they blame B...
But for e.g. the Russians it's totally fine. When you send assassins as "tourists" with a patently bogus reason for travel that's not because you're too stupid to do better, it's because that's all you needed for the mission and you don't care who knows it.
You can then intercept everything through the ISP gateway. It would be theoretically possible to fragment the entire internet this way via coordinating with the ISPs.
This has been the standard for a pretty long time, and it of course still works this way with ACME certificate issuance as well. Very neat imo.
Or it would require compromising the server [0]
[0] https://www.csoonline.com/article/3137065/shadow-brokers-lea...
Frankly though, I am going to say it; I think the idea that compromising a ton of web servers to be able to build a better profile of a user's web history is part of this UK government surveillance initiative is simply absurd. Compromising servers is a pretty nasty cat and mouse game, especially if you're up against orgs like Cloudflare, Amazon and Google. In practice, there's just no chance this is their strategy.
(And the game certainly isn't going to get any easier. You can, for example, use a TPM to generate your private keys, and have encryption occur on a TPM device, such that extracting them would require much more challenging exploits than just pwning some servers, meaning you'd need to actively have control over the servers to do anything interesting. It's not purely theory, either, though I do not know who is currently using this approach.)
https://www.asset-intertech.com/resources/blog/2017/12/micro...
Major ISP's definitely I feel like would do this. And most people are leaving DNS as default to their ISP (especially on mobile)
Its litterally the law, they will comply with the law.
Was it though?
We need a one way system such as satellite data broadcasting, which has more than enough bandwidth for a Web 1.0 experience. I had an entire Usenet feed by satellite many many years ago, and it was totally anonymous because it's receive only. We now only have https://blocksat.info/ but hardly anybody uses it.
So obviously it's just DNS records they look at, unless they look at other metadata? I know that DoH encrypts your DNS queries, but still leaks the site you're visiting via the TLS handshake.
There are further developments in this space which mitigate this weakspot, namely ECH[0] and Oblivious DoH[1]. Combine a VPN that you trust with these and you've essentially gone dark to this sort of surveillance apparatus.
The tyranny possible today is far worse than the tyranny of a few hundred years ago
Just wait till they introduce a law that allows them to imprison people for using a VPN to get around some bs accusation and they don't believe your defense.
IME, younger people have given up on protecting themselves.
It's part of VPN that most users these days don't even understand, as VPN providers are heavily advertised on the claim of improving privacy.
When in reality the VPN only shifts the party you have to trust from one to another, but the problem still remains the same.
[0]: https://status.torproject.org/issues/2022-06-09-network-ddos...
[0]: https://gitlab.torproject.org/tpo/core/torspec/-/blob/main/p...
https://www.vice.com/en/article/jg84yy/data-brokers-netflow-...
As one of the original posters mentioned, the Internet itself, being so centralized, is the problem. We need a new network.
> Haidar of Privacy International says that creating powers to collect more of people’s data doesn’t result in “more security” for people. “Building the data retention capabilities of companies and a vast range of government agencies doesn't mean that intelligence operations will be enhanced,” Haidar says. “In fact, we argue that it makes us less secure as this data becomes vulnerable to being misused or abused.”
What's most important is what they don't say, and that they don't say it: It's a threat to the minority's freedom and safety, their right to hold unpopular views, dissent, and protest. That is the definition of freedom. Saying something 'acceptable' is allowed with or without free speech. As Isaac Asimov (supposedly) said: "Politically popular speech has always been protected: even the Jews were free to say ‘Heil Hitler.’"
But they've given up on that argument, which means they implicitly communicate that they don't believe it, and support the notion that the majority is all that matters.
The only way to defeat these authoritarian, anti-free movements is to stop accommodating them (and thus signaling acceptance of their rule) and to talk assertively and confidently and knowledgeably about universal freedom.
no actually, explain h0w that works
i dont know a single person these days who thinks that the police need to monitor chat and shit online, yet the police keep adding more and more of this around the world. is it just like in software where one autist is given power over a project and masturbates adding new features to it every day at the cost of anyone who needs to verify the code, because he has nothing else to do? like in governments do legislators just hire some kid with no idea what hes doing out of school and he just creates shit law for the rest of his life and thats the sole way this shit works?