China collecting Apple iCloud data
en.greatfire.org
en.greatfire.org
When the artist Ai Weiwei had his email account compromised by the state, they simply logged into his email webmail UI and forwarded a copy of his emails to a 3rd party email address. They didn't even bother intercepting his email at the network or service provider level.
Edit: > "Apple increased the encryption aspects on the phone allegedly to prevent snooping from the NSA. However, this increased encryption would also prevent the Chinese authorities from snooping on Apple user data."
It's a shame articles keep confusing Apple's harddisk encryption with network data encryption. :\
I'm a little shocked - they've surely got the ability to do a proper MITM. CNNIC is a root CA for plenty of browsers. Saving it up for when they really need it, maybe?
It said in the article: the most popular Chinese browser Qihoop 360 browser doesn't even giving a warning for the bad SSL cert. "Qihoo’s popular Chinese 360 secure browser is anything but and will load the MITMed page directly."
* The popularity of that browser is way over reported - they tend to report "installed" statistics rather than "used".
* If you read the article you'll see self signed certificates were used for the MitM. From my own research, 360 secure browser just doesn't validate certificates in many circumstances. No CA required.
https://developer.apple.com/library/mac/documentation/Securi...
edit: but only in so much as you trust Apple, as they provide and verify the keys. But... assuming you're using an iphone, this isn't really a new threat vector.
So they just get the gullible.
It might also be other 3rd parties who is doing the MITM.
Anyone can setup a fake free wifi, reroute the DNS system. Some percentage of those "free" service users will press "OK" to let other sniff their "secure" connections.
In China, it's very common for websites to ask people to trust their self-issued certificates. If you want to buy train tickets in China, you end up with this page (https://kyfw.12306.cn/otn) which asks you to trust its own cert.
TL;DR, This is what a train station looks like before Chinese New Year [1].
Let's start from Hukou policy: Every Chinese is required to register their information to the government and has to provide a permanent address. This looks similar to most other country. But it goes quite far beyond a simple registration. Your Hukou is associated with a permanent address and in many cases, you are only allowed to do many critical things within the city of your permanent address. For example, your child cannot go to the local schools outside their Hukou address. Changing your address on Hukou is very hard and usually happens in some cases: When you go to university, you are allowed to temporarily change your Hukou under the university's city; 2. If you found a job in another city and your employer is willing to help you to relocate your Hukou address. 3. You married with a local person for several years. Basically, you can understand Hukou as a domestic visa. There are two types of Hukou: Farmer Hukou and City Hukou. Basically, they have different benefits/restrictions. Similar to F1 visa, H1B visa, etc.
Well, why I mention this? Here is some history. 30 years ago, major amount of the Chinese population were farmers. To build cities, you have to let those farmers live in the city and do lots of construction works. Due to the Hukou policy, people are not allowed to permanently migrate, esp. changing their Hukou status from Farmer to City. But there's more opportunities in cities and people could make more money. So gradually, there emerges a large group of people whose Hukou address is out of city but work in the cities. Their family has to in their home town, otherwise their children cannot go to school in the cities.
Every year, people works outside their home town will try to go back during Chinese New Year. Since the fact I mentioned above, there's a huge amount of people. They have to take trains (which is cheaper than flight.) Such yearly migration is quite large, ~3.3B tickets in 2014 [0].
Oh, and here is the answer to your question: Go to the train station is really not an option. It's like black Friday, but in a much larger scale. People have to wait outside for even weeks to get a ticket. To some extend, online ticket system helps. However, because of the throughput of the train system is limited, it's still hard to get a ticket.
0. http://en.wikipedia.org/wiki/Chunyun 1. https://www.google.com/search?q=%E6%98%A5%E8%BF%90&espv=2&so...
Not that buying property may be easy for a migrant worker, but for most cities an 80 square meter property should be enough. Outside of Beijing/Shanghai/Shenzhen that's about a million Yuan.
Just wanted to add some clarification / quantification for a casual reader.
This AM electrician comes over, guy in his early 30's (not an old timer) has a new iphone doesn't know how to sync and get the old stuff to the new iphone. Doesn't even know that Apple can help him with that. For computer things relies on his brother in law "the computer guy". Thinks Dell makes great "computers". "Don't they?" he says to me. Doesn't even really understand the difference between Mac OS and Windows. [1]
Point being there are tons of people out there that you could get to do practically anything. And they don't know the difference between one warning dialog box and another. It's just all a mashup to them.
[1] Add: By that I mean isn't aware that there is even a difference more than Coke vs. Pepsi is different.
[1] Add: By that, I mean he isn't aware of the things he isn't aware of.
Ease up on the geek rhetoric until you walk in his shoes.
Unless I trust each CA, their processes and every employee who could circumvent them, the current CA infrastructure is inherently unsafe. Self-signed certificates are only marginally less trustworthy (rather than having to compromise a CA, a bad actor would simply have to generate a new certificate and hope that I don't check the fingerprint - and I wouldn't check it).
I too remember something like that, but was under the impression that CAs are still ok.
But of course, judging by the massive downvoting you've gotten, I suppose you're incorrect. I wish those downvoters would explain their viewpoint rather than downvoting...
Root CAs are not really trustworthy. Manually trusting a self-signed cert is, probably, more secure in the long term. You take control of trust, rather than delegating it out to some faceless corporation who can be corrupted or hacked.
That said, I'd be more inclined to trust a self-signed cert of a CA signed one. I don't even know half the CAs that my device trusts, and some I recognise (government ones) I explicitly wouldn't trust.
Assuming the majority of people desire not to be tortured or killed far more then they desire freedom. It's probably more effective to simply pretend that you're performing surveillance as an intimidation tactic, than to actually perform surveillance unnoticed. It's also far more socially acceptable on an international level than violence.
Re this:
Even a government will only have the capabibilty to
perform meaningful surveillance on a limited number of
people not to mention act on it.
That claim is currently true, but if you understand Bayes' Theorem and Moore's Law, you know that it's just a matter of time.But re this:
It's probably more effective to simply pretend that
you're performing surveillance as an intimidation
tactic, than to actually perform surveillance unnoticed.
iirc, former East German Stasi or KGB have said essentially the same thing.Honesty is a traditional value. Privacy and sovereignty based on the consent of the governed? Not so much.
It is hard to tell whether it always is. If they are smart they use a deterrent, which must be visible to work, to decrease the number of potential targets to track, and something well hidden to follow the remaining real/potential troublemakers.
Is this a known fact? If I wanted to spy on a prominent dissident [1], I would use a variety of methods. Some would be intentionally crude, so that the target feels safer after noticing and defeating them, making the more sophisticated approaches that much more effective.
[1] I recommend visiting the current Ai Weiwei exhibit in San Francisco. It's quite good.
I get that America means 'USA' in this context. How exactly do US government officials hide the fact that they keep data of everything possible that happens online outside the United States (and doesn't give a damn about what anyone else thinks about it)?
Given the statements of many US senators, after both Cablegate and Snowden I don't think the US tries to hide anything at all.
It's also not as popular as frequently reported. It is widely installed because many orgs are required to have the security software that bundles it, but when I was researching it the consensus I got from several Chinese people was that few people actually used it - "only old people who don't know computers use it".
I wonder if 2FA is really that safe in a country like that, they have all the means to intercept the second channel, it just requires knowledge about the account owner or some not to complex synchronization to detect auth codes sent via text messages.
A good 2FA doesn't require anything else than the local time to generate the current password.
The risk here is someone could intercept and set/reset that password, but the end user would immediately know that as they would be unable to set a password or login.
Even in cases where that token is intercepted, it's a one-time use token, so you know if it's been intercepted.
(MTM is not only the "man in the middle" but also "the machine in the middle" -- a computer which would react in real time.)
MTM your internet connection means whatever the service is you have to replicate exactly, which is not feasible at any scale.
They're two entirely different vectors. If you wanted to hijack a token as part of a 2FA, that serves the purposes of initializing an account. In this case, the second MTM (intercepting communications) will not work, because the user will be unable to log in (as you initialized their account and therefor had to set a password).
Further, in the traditional MTM attack, there's no need to steal that 2FA token in the first place - not only because it prevents an active, working account, but because you can already get the information you want through data interception.
OK, once again: both SMS and internet are MTMed. Now why can't the machine doing the internet MTM use the user's password? Why do you think it has to do that before the user inputs it?
In this case, we're talking about a MTM on SMS and Internet. When a token is sent via SMS, we intercept that and use it to initialize an account (this is totally superfluous since we already have the MTM on the Internet, but for the sake of this argument, let's go with it).
Now when a user logs in, we know our generated password, so we need to eschew user input and supplant it with the password we generated by intercepting the 2FA, then return the response as expected.
You can sort of understand what I'm saying here. If you have MTM on the network side, you don't need to bother on the SMS side, it provides no advantage. Meanwhile, if you have MTM solely on the SMS side, there's no way to do this without alerting a user, because they will be unable to log in anyway.
http://en.wikipedia.org/wiki/Man-in-the-middle_attack
"The man-in-the-middle attack (often abbreviated MITM, MitM, MIM, MiM, MITMA) in cryptography and computer security is a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all messages going between the two victims and inject new ones, which is straightforward in many circumstances."
At the moment we write this on the fist page of HN there is an article about the MTM currently used by Chinese:
https://news.ycombinator.com/item?id=8482119
Where they don't even bother to remain undetected. I didn't think it would be much more complicated for the government which already does MTM to do the real-time query through the victim's SMS. The queries of the SMS would happen very rarely and need much less resources compared to the internet traffic.
Reading the conversation before I joined the discussion, I've also believed that worklogin also worried about the MTM as he wrote, many messages before: "With SMS-based 2FA, the token is sent via insecure channels to the user BEFORE auth, which is an opportunity for state actors and telecom to intercept it before use." I believed he wouldn't need to discuss when the token is sent otherwise and that his "intercept" was in the MTM-implied meaning "to take, seize, or halt (someone or something on the way from one place to another); cut off from an intended destination: to intercept a messenger."
So, per your discussion, the existence of 2FA is irrelevant as soon as the internet is MTM-ed, that is, as soon as somebody plugs in your TLS session? I honestly have never considered how irrelevant it is then. Thanks. I still have some other view of the 2FA ultimate goals.
Like, there is this: https://news.ycombinator.com/item?id=8487115 on the first page now where Google exactly tries to avoid the SMS channel. I can imagine that you'd consider that more than 2FA which you discuss, it's also OK.
As a mitigation tactic for full MTM, 2FA is basically without teeth. Same applies for the new item Google is trumpeting.
I'm not saying someone couldn't do a MTM with both SMS and full network, I'm saying it's overkill and redundant. There's no advantage. If you're already funneling the data, you have what you want.
What I believe is that a mechanism can definitely be made where without having the second authentication item of the 2FA the MTM on the internet channel would be automatically deactivated (or the user would recognize the existence of the MTM since it would reject the connection). Namely, the MTMI (internet) point from my scenario wouldn't be able to keep the connection to the server active since it doesn't have the key which is needed to even have the (encrypted) communication: the key given from the entity with the server to the user, but not using the internet, and therefore impossible to be used by the MTM interceptor. I believe such a mechanism can be made as soon as we assume the existence of such a key. That some simpler forms are currently still more popular doesn't mean we should dismiss the properly implemented mechanism as "without teeth." Maybe you'd say that such a mechanism isn't 2FA at all. How would you call it?
- user created, 2FA token created, user not active - user gets 2FA token via 2nd channel - user enters token, gets to create a password for account - user active, token invalidated
this isn't airtight - nothing is - but it means either you got the token or you can't log in to your account, which should raise a red flag.
Hmm, maybe websites should allow people to select an "encryption" format for the SMS. Something not too complicated, like a ROT13'ish type of thing:
"We'll txt you the code, but every 3 char should be ignored... or every 4th number should be multipled by 3"
That said, hardly any user would be willing to take on such complexity without very strong reason.
Does anyone know if iOS uses certificate pinning when connecting to iCloud services, and if so if that is sufficient to prevent against this type of attack?
I'm not an iOS dev, but I do not think that the iOS SDK would allow for invalid certificates. Then Apple could just go ahead and not use any encryption at all.
The 'hack' in the article works, because users ignore security warnings or even use a browser that is clearly made to easily snoop on people.
It's not a shocking news, however. Apple has already moved [1] some of its storage servers to Beijing. The attack could just be the authorities making sure that Chinese users' iCloud data is actually stored in China.
[1] http://techcrunch.com/2014/08/15/apple-taps-china-telecom-as...
I realize this isn't the real reason why China told Apple to build a datacenter there, but that's the one they used publicly, and as long as the company itself can get access to that data, then the argument is a pretty plausible one, even from China. Apple, Google and others could weaken this argument by adopting end-to-end encryption for their services.
Unfortunately, it seems the companies decided to keep the data as is, but build the data centers in Russia, China and wherever else they might ask them to do it.
Ultimately there's only so far you can go against the wishes of the Chinese government when your factories are there, or against the US government when your HQ is there.
http://www.reuters.com/article/2014/08/06/us-china-apple-idU...
HSTS is mainly to prevent SSL-stripping. But I think part of HSTS could also note that the certificate was trusted, and then having an HSTS header could entirely prevent any later connection with the self-signed certificate, without clearing the HSTS history.
You may not need to even store the extra bit, it's enough to say if you have HSTS then by default the connection must not just be encrypted, but it must be trusted.
Do current browsers entirely prevent a connection to untrusted certs when HSTS is set? Or is it just the same error you get when connecting to any self-signed cert?
It seems like you are hinting towards certificate pinning (https://en.wikipedia.org/wiki/Transport_Layer_Security#Certi...). Pinning would prevent rouge CA's from signing bad certificates, but pinning is hard to do on the web. It is mainly used with mobile applications from what I have seen.
Edit: Here is a list of pinned sites in Chrome, if you are curious. (https://src.chromium.org/viewvc/chrome/trunk/src/net/http/tr...)
And what prevents the government from doing that? Certificate pinning will address MITM no matter what - if the certificate the browser receives is not the one it pinned, it will refuse to connect even if the cert was signed by another trusted authority.
Although it's unclear from the article as to what really is happening - is it that Apple trusts whatever Chinese CA is used to forge the certificate for iCloud.com but others like Mozilla and Google don't? In any case I don't see how pinning won't help here.
If China were to misuse the root I believe their academics dept has, it would be instantly banned. There was a bugzilla bug about removing it @ Mozilla and a LOT of people supported it, but it won't be removed unless there is abuse.
Regular link: https://proxy.sh
Affiliate link: https://proxy.sh/panel/aff.php?aff=477
The problem is that Apple is using the industry standard for encryption here (SSL). China cracks that security by giving their folks a browser that allows them to easily swap the certificate out and send all the data to them before sending it to Apple. This is called a MITM (Man In The Middle Attack).
Personally, I'm a big fan of privacy - also I'm the CTO of a web-company, so I'm concerned with security for webapps, too.
When users are ignore warnings of their browsers (what Firefox would do in such an event) or even install a "trojan browser" by a mean government - well, then there is little you can do as a company.
Just wanted to give a short TL;DR on the article to prevent an icloud shitstorm on HN, because the article is really on how mean China is. Not saying or implying at all that other governments are better.
Also not saying that Apple is perfect in terms of security. Btw, as developer and sysadmin I'm using Debian stable - my Mac is for convenience and productivity. Just saying that to disqualify myself as the regular fanboy(;
Seriously "they've gotta do something" sounds good but I'm not sure what options they actually have. If the user clicks through a clear SSL warning, that's Apple's fault?
Your response is like saying when Facebook was privacy zuckering (http://darkpatterns.org/library/privacy_zuckering/), the user clicks right through the settings that should have sounded an alarm.
What can Apple do? They could make a better browser (I like how Chrome and Firefox do things - you have to go out of your way to reach a page with bad SSL -- compare Safari's rather passive and enabling error message: http://blog.serverdensity.com/wp-content/uploads/2009/05/ssl... vs. chrome's: http://i.imgur.com/ttmmDJ8.png -- you have to REALLY see and think how to access the site despite the warning, it's that good). They could be more vigilant in alerting users of where and how this can happen.
If we were talking about any other young startup, your apology might fly -- not so with Apple, they're sitting on billions, they have the resources to think of a solution and implement it.
> Your response is like saying when Facebook was privacy zuckering, the user clicks right through the settings that should have sounded an alarm.
This is a bit odd, though. On one hand we have a company directly attempting to trick users; on the other, we have a company whose product is being attacked by a hostile government. Drawing an equivalence between the two is a bit ridiculous, no?
I think the two are quite comparable. In both cases, the software developer should be responsible for guiding the user to make the right decision.
"It’s hard to blame users for not being interested in SSL and certificates when (as far as we can determine) 100% of all certificate errors seen by users are false positives."*
* http://msdn.microsoft.com/en-us/magazine/hh288087.aspx"It’s hard to blame users for not being interested in SSL and certificates when (as far as we can determine) 100% of all certificate errors seen by users are false positives."
Yes. But they don't own their own iCloud. Or their own iPhones. Or their own Apple.
It's Apple's choice to concede.