cross-posted from: https://lemmy.bestiver.se/post/770637
Nitter link: https://xcancel.com/hkashfi/status/1995109785679573167
So how do I see the boobs
Send bob and vagene
You put on your robe and wizard hat
Goddamn old people.
Wait. I get that reference. Does that mean I’m an old people?
Old men are the future!
My original guess was that they’re intercepting DNS, but since boobs is in the path, it wouldn’t be sent. How does this work?
Right? If it were an unencrypted HTTP GET request, then every router on the way would see the plaintext string
boobsin the URL and therefore intercept it.If I had to guess, Iran has so few landline connections that they man-in-the-middle every TLS connection they can by either forcing every server to hand over their private key files (difficult) or by forcing a certificate authority trusted by default Web browsers (there’s a lot of them) to issue certificates for every top level domain they see in SNI data attached to encrypted packet headers; the latter method need not even require participation by Iranian servers, so long as the traffic is bottlenecked for man-in-the-middle attacks and outsiders don’t question unusual certificate authorities being used.
Don’t know if this is entirely accurate, but Wikipedia has article about it.
They are giving response codes like 403 so it’s not a failure to resolve and I agree it’s not DNS… It’s behaving differently based on different sub pages so it’s something underneath the https encryption. Maybe an intermediary WAF that decrypts? Maybe some weird server side tooling that has govt provided?
I would guess WAF but I’d love to hear from someone who actually knows.

Why with Iran?
Presumably because instead of responding to the request for boobs.jpg with with an HTTP 404 error (meaning, “not found”), Iran’s censorship tech returns a 403 error (meaning basically "you are forbidden from accessing this resource).
The “boobs” are “forbidden” you see; the tech mirrors the ruling party’s moral stance, probably coincidentally. Trying the same
curlcommand in Russia and China will likely just get you a 404 error, so the joke really only works with Iranian servers. The 404 version is slightly less funny: “We couldn’t find the boobs!”Hey, at least they’re using HTTP codes correctly.
They should change it to 80085 error.







