news.volyx.in

Encrypted traffic interception on Hetzner and Linode targeting Jabber service (notes.valdikss.org.ru)

731 points by f311a · 1038 days ago · 306 comments on HN

Article summary

A Man-in-the-Middle (MitM) attack was discovered on the XMPP messaging service jabber.ru, targeting its encrypted traffic on Hetzner and Linode hosting providers. The attack involved issuing fake TLS certificates using Let's Encrypt, allowing the interception of encrypted communications. The attack is believed to have lasted for up to 6 months and may have been a lawful interception. The service's administrators detected the attack due to an expired certificate and have taken steps to mitigate it.

Main themes

  • MitM attack
  • XMPP security
  • Certificate transparency
  • DNSSEC and CAA
  • Lawful interception
  • End-to-end encryption

What commenters say

  • The use of certificate transparency logs and active monitoring of TLS changes can help detect such attacks.
  • DNSSEC and CAA records can prevent MitM certificates from being issued, but are not foolproof.
  • Law enforcement can compel domain registrars and hosting providers to cooperate with surveillance efforts, making it difficult to prevent such attacks.
  • The attack highlights the importance of end-to-end encryption and secure key exchange in messaging services.
  • Let's Encrypt's transparency reports and CAA record support can help prevent similar attacks in the future.
  • The possibility of NSLs and gag orders can limit the effectiveness of transparency reports and canary pages.
  • The use of quantum-resistant encryption methods will become increasingly important as quantum computing capabilities improve.