Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, I agree. If the global internet community is developing software to deal with threat models that deal with a worst case scenario (the government of Uzbekistan ordering ISPs to randomly block things), the Chinese great firewall, and so forth, we absolutely need technology like encrypted SNI in TLS1.3 and similar.

If we develop software with end-to-end crypto to deal with repressive-regime threat models, its crypto should also be inherently sufficient to deal with more normal traffic interception and modification attempts.

A lot of non democratic regimes in places outside of North America take a very blunt approach, of having government agencies order all of their domestic ISPs to simply null route huge chunks of the Internet (like, entire ipv6 /16s belonging to Azure and AWS) in order to ban politically objectionable sites. Or to order all ISPs to be singlehomed to, and downstream of the government state run telecom. There is one ASN in Iran which is allowed to have international IP transit connectivity to other non-Iranian ASes, for instance.

https://bgp.he.net/AS12880



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: