‹ BackHN Continuity

Thread

Court agrees with EFF: Utah's VPN law demands a technical impossibility

802 points · 405 comments · hn_acker

  1. usernomdeguerre · · focus · HN ↗
    >As we’ve said time and time again: the internet will always route around censorship.

    Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.

    Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.

    Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.

    1. tialaramex · · focus · HN ↗
      The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.

      Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.

      The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"

      1. nazcan · · focus · HN ↗
        My guess is if you are in China they can MITM you with their own root certs.
        1. JoshTriplett · · focus · HN ↗
          Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
          1. someonebaggy · · focus · HN ↗
            Useless. You still don't get the connection unless you trust the MITM. You either disable CT, or you don't get a connection.
            1. JoshTriplett · · focus · HN ↗
              That&#x27;s a different case where they&#x27;re not trying to be surreptitious. For that case, see <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49937347">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49937347 and my response.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.