Hacker News new | past | comments | ask | show | jobs | submit login

> vpn provider can easy break your crypto if they need to, mitm you and get cleartext 'records' from live data.

Could you elaborate on that? I'm going to China soon and don't know if I should trust commercial VPN providers. I was under the impression that if I use SSL/TLS it's impossible to MITM my connection.




If an entity can mint certificates that are signed and appear legit then MITM is possible. We so many certificate authorities now it is possible that are certificate trust is failing us or can fail us.

https://arstechnica.com/information-technology/2017/03/googl...

Google chrome can detect a google cert that is not legitimate because it has embedded the certificate fingerprints in the browser for its public certs. We don't have that benefit elsewhere.

Might some state actors have cert signing ability. You be the judge.


Hey,

It's not that simple - it depends on the implementation, otherwise if your browser trusts root cert which was issued by chinese gov, what's to stop them doing the mitm? I mean, they issued the cert.

However to mitigate this, VPN providers (some of them) implement checks to make sure they only trust particular root certs, which makes doing mitm much harder.

Re your trip to China I would not be worried about that though - 30 % of Internet users in China are using VPN's daily so it's not like you will be flagged and get locked for using a VPN. Pick one of the reputable ones (NordVPN?) and you should be good.


If someone has the private key to a trusted root certificate, they can forge the certificates for any TLS connections you make.

The countermeasure is certificate pinning, but that is typically implemented only for a handful of sites; e.g. Google with Chrome.


It may be impossible to MITM your connection. However, it is entirely possible for the authorities to just prevent the connection from working in the first place.


Didn't China just recently ban VPNs?


They "ban" them for the last 20 years, but it's like baning encryption. Cat is already out of the bag.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: