‹ BackHN Continuity

Thread

Court agrees with EFF: Utah's VPN law demands a technical impossibility

802 points · 405 comments · hn_acker

  1. usernomdeguerre · · focus · HN ↗
    >As we’ve said time and time again: the internet will always route around censorship.

    Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.

    Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.

    Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.

    1. tialaramex · · focus · HN ↗
      The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.

      Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.

      The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"

      1. nazcan · · focus · HN ↗
        My guess is if you are in China they can MITM you with their own root certs.
        1. JoshTriplett · · focus · HN ↗
          Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
          1. ndriscoll · · focus · HN ↗
            If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

              1. Make it illegal to distribute a browser that distrusts their CA
            
              2. Make it illegal to run a browser that distrusts their CA
            
              3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
            1. mrzimmerman · · focus · HN ↗
              “Make it illegal to…” that has never in human history prevented anything from happening. Cannot increase the risk? Of course, but laws do not stop humans from humaning.

              Furthermore, doing any of the things you listed would isolate all legitimate network traffic as well as any undesirable traffic, fully shuttering all Chinese manufacturing businesses from global requests via the web. This hat would happen then? Phone calls, emails, and even physical mail would become the new norm and most of the Chinese economy would collapse under the weight of not being able to hop on a Zoom with a client that wants tooling made for its aluminum manufacturing molds.

              So besides my point of the black market your hypothesis of total control misses all the other pressures that exist that make what you’re proposing infeasible on its face. Only a place like North Korea that is willing to be a pariah state is old be willing to take the economic and social costs associated with your proposal, and they’ve only been able to do that because their abominable regime was in place before the internet existed and they pre-built controls very late in the game.

              Tl;dr simply because a country _could_ do something doesn’t mean it’s realistic for reasons outside of basic networking concepts.

              1. [deleted] · · focus · HN ↗

                [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.