Solved SSL hijacking


Exactly this,
Any servers based in the US, Germany, Canada and I'm sure even other states influenced by the US cannot be trusted.

This isn't only about DNS but also any kind of server which users frequently use such as email providers are also affected,
According to this site Privacy-Conscious Email Services



And according to this site: PRISM Break


But this is perhaps nothing new except when we face it on our own skin as it is the case now proving that Edward Snowden was correct about all that he said and is still saying.

If a government can tell cloudflare to hijack DNS then they can also tell Microsoft or any other firm or entity what to do if they want.

Both scenarios present differing levels of complexity, practicality, and potential repercussions.

It's conceivable that DNS servers, particularly those operated by Western entities, are receiving systematic orders to interfere with the security certificates of rt.com, and potentially other news websites, whose narratives are seen as discordant.

1. Compelling a DNS server to tamper with DNS queries:

From a technical perspective, this is less complex than compromising an operating system like Windows. A DNS server could, for example, be compelled to redirect traffic from one domain to another or return inaccurate IP addresses. This would be considered a form of DNS spoofing or poisoning.

From a practicality standpoint, this might be easier to achieve on a small scale, but managing this on a larger scale could be challenging due to the distributed nature of DNS, the number of DNS servers globally, and the fact that users can easily change their DNS servers.

In terms of repercussions, this could lead to significant breaches of trust and potential legal issues, especially if the DNS servers are run by reputable companies. It might also encourage more users to use encrypted DNS or DNS over HTTPS (DoH), making it harder for such tampering to occur in the future.

2. Compelling Microsoft to compromise its software:

Technically, this is more complex. Compromising an operating system without it being detected by security researchers would require sophisticated techniques. Moreover, any updates issued by Microsoft would need to maintain this compromise, adding another layer of complexity.

Practically, if a government could compel Microsoft to introduce a backdoor or similar compromise into Windows, it would potentially give them access to a large number of devices globally. However, the logistics and legality of compelling such action on a major corporation would be significantly challenging.

Repercussions would be severe. If discovered, the damage to Microsoft's reputation would be substantial, and the legal implications could be enormous. It would also likely lead to a significant shift in the tech industry, with users and companies looking for more secure alternatives.

In both cases, the feasibility would depend heavily on jurisdiction and the legal frameworks in place to protect companies and individuals from such government demands.
 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro
It seems that updating certificates is as easy as running the task, I ran both system/user tasks and it was fixed in a sec.

capture_07162023_165227.jpg
 

My Computer My Computer

At a glance

Home26H2CanAMD Ryzen 5 8600G (07/24)2x32GB Kingston FURY DDR5 5600 MHz CL36 @5200...ASROCK Radeon RX 6600 Challenger D 8G @48FPS ...
OS
Home26H2Can
Computer type
PC/Desktop
CPU
AMD Ryzen 5 8600G (07/24)
Motherboard
ASROCK B650M-HDV/M.2 (07/24) BIOS 4.21 AGESA ComboAM5 1.3.0.1 (04/26)
Memory
2x32GB Kingston FURY DDR5 5600 MHz CL36 @5200 CL36 (07/24)
Graphics Card(s)
ASROCK Radeon RX 6600 Challenger D 8G @48FPS (08/24)
Sound Card
Creative Sound BlasterX AE-5 Plus (05/24)
Monitor(s) Displays
24" Philips 24M1N3200ZS/00 (05/24)
Screen Resolution
1920×1080@165Hz via DP1.4
Hard Drives
Kingston KC3000 NVMe 2TB (05/24)
ADATA XPG GAMMIX S11 Pro 512GB (07/19)
PSU
Seasonic Core GM 550 Gold (04/24)
Case
Fractal Design Define 7 Mini with 3x Noctua NF-P14s/12@555rpm (04/24)
Cooling
Noctua NH-U12S with Noctua NF-P12 (04/24)
Keyboard
HP Pavilion Wired Keyboard 300 (07/24) + Rabalux 76017 Parker (01/24)
Mouse
Logitech M330 Silent Plus (01/26)
Internet Speed
500/100 Mbps via RouterOS (05/21) & TCP Optimizer
Browser
Edge, Brave for YouTube, LibreWolf for FB
Antivirus
NextDNS blocking 1/3 Traffic
Other Info
Phone: Motorola Moto G86 (02/26)
Backup: Hasleo Backup Suite (PreOS)
Headphones: Sennheiser RS170 (09/10)
Chair: Huzaro Force 4.4 Grey Mesh (05/24)
Notifier: Xiaomi Mi Band 9 Milanese (10/24)
FlexCore USB-C 3.2 Gen 1 (M) to LAN (F) (08/25)
Both scenarios present differing levels of complexity, practicality, and potential repercussions.

1. Compelling a DNS server to tamper with DNS queries:

<snip>

2. Compelling Microsoft to compromise its software:

<snip>

I like your diplomatic and technical answer, and I agree that doing such things on Windows would be more challenging and more serious and damaging for reputation on Microsoft.

Hijacking sites such as rt is not really an issue because nobody was hacked and I was not redirected to malicious site, and my data was not stolen, it's also not issue because I had a chance to close the tab to rt and nothing bad happens to me.

However issue is knowing that if a governments wants to abuse some company to do contrary to it's claims it can do it.
Issue is that those companies which claim to respect user's privacy and to deliver good service are being forced to violate their own claims.
I was trusting cloudflare but after this incident I don't think I'll ever use cloudlfare again and that's what's the issue.

Therefore the issue is that a government forced a reputable service to become no longer trusted and this is not only cloudflares problem but a problem for any service in the US or any other state whose services can be influenced.

@TairikuOkami
Thank you for suggestion, I was sure it's my ISP but it turns out it's cloudflare, but I've added this link to my bookmarks because it's good to know for troubleshooting if needed.

I didn't test if resetting cert store resolves the problem since changing DNS fixed it, but I'll test it out of interest again with cloudflare.
 

My Computer My Computer

At a glance

Windows 11 Pro 23H2Intel i3 8100 @3.6Ghz1 x 16GB DDR4 @2400 MHzNvidia GeForce GT 1030 2GB SDDR4
OS
Windows 11 Pro 23H2
Computer type
PC/Desktop
Manufacturer/Model
MSI / MS-7B29
CPU
Intel i3 8100 @3.6Ghz
Motherboard
H310M PRO-VDH (MS-7B29)
Memory
1 x 16GB DDR4 @2400 MHz
Graphics Card(s)
Nvidia GeForce GT 1030 2GB SDDR4
Sound Card
Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
Monitor(s) Displays
Acer V226HQL
Screen Resolution
1920 x 1080
Hard Drives
SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
PSU
ATX, details unknown
Case
Everest 551B
Cooling
details unknown
Keyboard
Mechanical Gaming Hydra R7 - Rampage
Mouse
Logitech G703
Internet Speed
Down: 28Mbps / Up: 19Mbps
Browser
Microsoft Edge
Antivirus
Microsoft Defender Antivirus
Other Info
Bluetooth: TP Link 5.0 Nano USB adapter UB500
WLAN: D-Link 150 Pico USB adapter, N standard
Web camera: Logitech C270 HD 720p @30fps
Microphone: Trust MICO, model 23790
@TairikuOkami
I don't know why, but now I set DNS back to cloudflare, cleared the DNS cache and it's working normally o_O
It's odd because @windoc was also able to repro the issue.
 

My Computer My Computer

At a glance

Windows 11 Pro 23H2Intel i3 8100 @3.6Ghz1 x 16GB DDR4 @2400 MHzNvidia GeForce GT 1030 2GB SDDR4
OS
Windows 11 Pro 23H2
Computer type
PC/Desktop
Manufacturer/Model
MSI / MS-7B29
CPU
Intel i3 8100 @3.6Ghz
Motherboard
H310M PRO-VDH (MS-7B29)
Memory
1 x 16GB DDR4 @2400 MHz
Graphics Card(s)
Nvidia GeForce GT 1030 2GB SDDR4
Sound Card
Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
Monitor(s) Displays
Acer V226HQL
Screen Resolution
1920 x 1080
Hard Drives
SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
PSU
ATX, details unknown
Case
Everest 551B
Cooling
details unknown
Keyboard
Mechanical Gaming Hydra R7 - Rampage
Mouse
Logitech G703
Internet Speed
Down: 28Mbps / Up: 19Mbps
Browser
Microsoft Edge
Antivirus
Microsoft Defender Antivirus
Other Info
Bluetooth: TP Link 5.0 Nano USB adapter UB500
WLAN: D-Link 150 Pico USB adapter, N standard
Web camera: Logitech C270 HD 720p @30fps
Microphone: Trust MICO, model 23790
@windoc
btw. I would like to know which is the DNS software that you're using to create rules?

For security reasons, I prefer not to disclose specific details about my personal network setup, including the DNS software I'm using. However, I'm happy to discuss general topics related to DNS software and its functionality
 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro
No problem, it's not bad to keep security setup private.
Thank you all for useful replies!
 

My Computer My Computer

At a glance

Windows 11 Pro 23H2Intel i3 8100 @3.6Ghz1 x 16GB DDR4 @2400 MHzNvidia GeForce GT 1030 2GB SDDR4
OS
Windows 11 Pro 23H2
Computer type
PC/Desktop
Manufacturer/Model
MSI / MS-7B29
CPU
Intel i3 8100 @3.6Ghz
Motherboard
H310M PRO-VDH (MS-7B29)
Memory
1 x 16GB DDR4 @2400 MHz
Graphics Card(s)
Nvidia GeForce GT 1030 2GB SDDR4
Sound Card
Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
Monitor(s) Displays
Acer V226HQL
Screen Resolution
1920 x 1080
Hard Drives
SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
PSU
ATX, details unknown
Case
Everest 551B
Cooling
details unknown
Keyboard
Mechanical Gaming Hydra R7 - Rampage
Mouse
Logitech G703
Internet Speed
Down: 28Mbps / Up: 19Mbps
Browser
Microsoft Edge
Antivirus
Microsoft Defender Antivirus
Other Info
Bluetooth: TP Link 5.0 Nano USB adapter UB500
WLAN: D-Link 150 Pico USB adapter, N standard
Web camera: Logitech C270 HD 720p @30fps
Microphone: Trust MICO, model 23790
@TairikuOkami
I don't know why, but now I set DNS back to cloudflare, cleared the DNS cache and it's working normally o_O
It's odd because @windoc was also able to repro the issue.

I've just conducted another test with Cloudflare, and it appears to be functioning properly for me now.

If recent modifications were made to rt's SSL certificate or DNS records, it might initiate a process known as DNS propagation. This is a period during which servers across the globe update their cached internet location records to reflect these changes. During DNS propagation, some users could experience discrepancies, including certificate errors, which get resolved once the propagation is complete and the new information has been fully updated across all servers.
 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro
If recent modifications were made to the rt's SSL certificate or DNS records, it might initiate a process known as DNS propagation. This is a period during which servers across the globe update their cached internet location records to reflect these changes. During DNS propagation, some users could experience discrepancies, including certificate errors, which get resolved once the propagation is complete and the new information has been fully updated across all servers.
This is very likely the case because certificate that was reported as invalid said it expires as of today's date.

A new certificate shows that rt is renewing certs likely twice a year:
CJZCa3X.png


You're really expert when it comes to DNS, I've learned so much from you, thank you so much for your insights!
 

My Computer My Computer

At a glance

Windows 11 Pro 23H2Intel i3 8100 @3.6Ghz1 x 16GB DDR4 @2400 MHzNvidia GeForce GT 1030 2GB SDDR4
OS
Windows 11 Pro 23H2
Computer type
PC/Desktop
Manufacturer/Model
MSI / MS-7B29
CPU
Intel i3 8100 @3.6Ghz
Motherboard
H310M PRO-VDH (MS-7B29)
Memory
1 x 16GB DDR4 @2400 MHz
Graphics Card(s)
Nvidia GeForce GT 1030 2GB SDDR4
Sound Card
Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
Monitor(s) Displays
Acer V226HQL
Screen Resolution
1920 x 1080
Hard Drives
SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
PSU
ATX, details unknown
Case
Everest 551B
Cooling
details unknown
Keyboard
Mechanical Gaming Hydra R7 - Rampage
Mouse
Logitech G703
Internet Speed
Down: 28Mbps / Up: 19Mbps
Browser
Microsoft Edge
Antivirus
Microsoft Defender Antivirus
Other Info
Bluetooth: TP Link 5.0 Nano USB adapter UB500
WLAN: D-Link 150 Pico USB adapter, N standard
Web camera: Logitech C270 HD 720p @30fps
Microphone: Trust MICO, model 23790
This is very likely the case because certificate that was reported as invalid said it expires as of today's date.

A new certificate shows that rt is renewing certs likely twice a year:
CJZCa3X.png


You're really expert when it comes to DNS, I've learned so much from you, thank you so much for your insights!


Thank you, but I consider myself an enthusiast, rather than an expert in DNS. I've picked up some knowledge along the way and I'm always eager to learn more. I'm glad if I've been able to provide useful information, and I appreciate our discussion as it also helps me understand and explore these topics better.
 

My Computer My Computer

At a glance

Windows 11 Pro
OS
Windows 11 Pro
It seems that updating certificates is as easy as running the task, I ran both system/user tasks and it was fixed in a sec.
Given the insight by windoc of cert propagation, your solution might prove very useful in the future to force renewal of certs.

Again thank you guys for helpful replies!
 

My Computer My Computer

At a glance

Windows 11 Pro 23H2Intel i3 8100 @3.6Ghz1 x 16GB DDR4 @2400 MHzNvidia GeForce GT 1030 2GB SDDR4
OS
Windows 11 Pro 23H2
Computer type
PC/Desktop
Manufacturer/Model
MSI / MS-7B29
CPU
Intel i3 8100 @3.6Ghz
Motherboard
H310M PRO-VDH (MS-7B29)
Memory
1 x 16GB DDR4 @2400 MHz
Graphics Card(s)
Nvidia GeForce GT 1030 2GB SDDR4
Sound Card
Realtek VEN_10EC&DEV_0887 / NVIDIA VEN_10DE&DEV_0081
Monitor(s) Displays
Acer V226HQL
Screen Resolution
1920 x 1080
Hard Drives
SSD 500 GB Crucial MX500 / HDD 1 TB TOSHIBA DT01ACA100
PSU
ATX, details unknown
Case
Everest 551B
Cooling
details unknown
Keyboard
Mechanical Gaming Hydra R7 - Rampage
Mouse
Logitech G703
Internet Speed
Down: 28Mbps / Up: 19Mbps
Browser
Microsoft Edge
Antivirus
Microsoft Defender Antivirus
Other Info
Bluetooth: TP Link 5.0 Nano USB adapter UB500
WLAN: D-Link 150 Pico USB adapter, N standard
Web camera: Logitech C270 HD 720p @30fps
Microphone: Trust MICO, model 23790

Latest Support Threads

Back
Top Bottom