No Istanbul Convention in Croatia Referendum

However, this page is only about technical side of it.

The comparison is with the huge surveillor-grade (and possibly worse) other referendum form for volonteers at: ../cap-180505-schmoog-referendum

Of course, this webteam should have gone HTTPS, not opened everybody to the huge internet (for casual non-advanced readers, anybody can follow you if you browse in plain HTTP, and this volonteer form page is in poor old HTTP). But it's still less damage than selling you to the Schmoog, in my opinion.

But only in case there wasn't anybody MiTM-ing and sending my data to /dev/null. Which is not unfeasible and esp. the censoring shadows with huge resources unconstitutionally and unlawfully at their whim in serving the traitorous regime could do it in a blink and laugh at you... I hope my data got through... But haven't received any confirmation on any channel I offered, yet.

Another drawback of plain, cleartext-for-any-onlooker HTTP, is HTTP (it's hard stuff, it's way complex for someone small, I'm not saying I could do it, I couldn't, not even in a theoretical few years dedicated work, I don't think so... but...) but HTTP can be faked. Not so HTTPS... Not the conversations locked with the Perfect Forward Privacy keys of this day. It's simply the nature of encryption.

What I mean, if they didn't get my submission but the UDBA ate it, not even these detailed traces and logs and all would consitute proofs beyond doubt in case of (let's imagine it for a moment) contestation... HTTPS and the SSL-keys, that's way different and way more solid evidence...

Otherwise, it's the same workflow as far as my programs presented in that other page, so I'm not going to repeat about those.

---

By uncenz:

dump_180504_1639_gdO.pcap

---

WARNING: Familiarity with and use of some Unix-like OS such as GNU/Linux or BSD, (or being able to use Cygwin on Windows but I haven't tested that yet) is required to be able to follow.

Most of the original files of this section are produced with my (primitive) set of scripts:

uncenz.

Notice there are different scripts there, some I use for minimal anonymization of the dumps (dump_perl_repl.sh). Ah, and another could be useful for downloading, instead of of click-downloading each file in a list (dump_dLo.sh). If not downloading uncenz, you can get it directly: https://raw.githubusercontent.com/miroR/uncenz/master/dump_dLo.sh or later version if that looks too old.

For analysis/stream extraction I often use my modest and lacking in good programming practices, but doing what I created them for, scripts:

tshark-hosts-conv

and:

tshark-streams.

as well as:

workPCAPs which can run tshark-streams and tshark-hosts-conv
( and from May 2018 also stream-cont.pl from program

stream-cont )

on (a lot) of PCAP(s) (usually) non-interactively.

Readers are advised to try and analyze the traffic dumps for themselves, with the above programs (I also try to offer some educational usefulness to them). There would anyway be too little point posting all the streams and the listings that those would produce. I usually post just the ones among that produce which are crucial for the discussion in question.

And just another one thing: I post lots of command lines and snippets of scripts. Be aware that some of those are in HTML, so before using them, check that they correspond to what the page shows, and of course, report (find miro.rovis or such at the front page of www.croatiafidelie.hr) back to me the typoes and errors if you find any.

The files necessary for this study are listed in:

ls-1

dump_180504_1639_gdO.pcap
Screen_180504_1639_gdO.webm
dump_180504_1639_gdO_SSLKEYLOGFILE.txt

and verify to: ls-1.sum signed by: ls-1.sum.asc

The above is all you need to be able follow the tutorial on the other page. See there for more details, and in case you can't figure out how to use my programs, here's their results:

ls-1Rest

It's a lot to download. But it should be much easier with my dump_dLo.sh indicated above. Pls. also make sure you got the short list above downloaded too. And place all in one same dir then. (The maybe three or so symlinks that you'll also be downloading, is just extra work, but no harm.)

dump_180504_1639_gdO_SSLKEYLOGFILE.txt
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_151.21.208.64-frame-http-request-full_uri.txt
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO-frame-http-request-full_uri.txt
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO.POST
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_69.195.158.196-frame-http-request-full_uri.txt
dump_180504_1639_gdO_tHostsConv/.tshark-hosts-conv_non-interactive
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_93.136.116.73.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO.hosts
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO.hosts-worked-ls-1
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_224.0.0.1.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_151.21.208.64.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_104.31.78.223.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_69.195.158.196.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_SSLKEYLOGFILE.txt
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_94.177.171.127.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_93.136.116.73-frame-http-request-full_uri.txt
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO.conv-ip
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_104.19.198.151.pcap
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_104.31.78.223-frame-http-request-full_uri.txt
dump_180504_1639_gdO_tHostsConv/dump_180504_1639_gdO_104.19.198.151-frame-http-request-full_uri.txt
dump_180504_1639_gdO_tHostsConv.log
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s002-ssl.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s001.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003-ssl.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s001.part_02.data
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000-ssl.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004.part_01.empty
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003-ssl.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_streams.ls-1
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s002.part_02.xml
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s002.part_01.empty
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s001-ssl.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000-ssl.part_01.empty
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004-ssl.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004-ssl.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004-ssl.part_02.data
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO.pcap
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000-ssl.part_02.data
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s002-ssl.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000-ssl.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_01.empty
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000.part_01.empty
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004-ssl.part_01.empty
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_SSLKEYLOGFILE.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s001.part_01.data
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s004.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s001-ssl.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s002.txt
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_03
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_05.gz
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s002.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_02
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_04.html
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_05
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_02.gz
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.part_03.gz
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s001.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s000.bin
dump_180504_1639_gdO_tStreams/dump_180504_1639_gdO_s003.bin

and verify to: ls-1Rest.sum signed by: ls-1Rest.sum.asc