Live data from Hacker News

Signs of a Creepy Government Conspiracy at Standing Rock

cracked.com

1–10 of 88 posts

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#4

Invalid SSL cert on the site. > There were even reports of people's Gmail accounts being hacked. This sounds suspiciously false - even if they are phones were forced to downgrade to A5/1 this should have no effect on TLS.

Do you have an extension that is trying to redirect you to https? It's an http link but I can see that https doesn't work on cracked.com.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#5
post #4

Invalid SSL cert on the site. > There were even reports of people's Gmail accounts being hacked. This sounds suspiciously false - even if they are phones were forced to downgrade to A5/1 this should have no effect on TLS.

Do you have an extension that is trying to redirect you to https? It's an http link but I can see that https doesn't work on cracked.com.

Traveling and the ISP here hi-jacks DNS requests for http sites to it's currently broken proxy..

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#6

Invalid SSL cert on the site. > There were even reports of people's Gmail accounts being hacked. This sounds suspiciously false - even if they are phones were forced to downgrade to A5/1 this should have no effect on TLS.

Without HSTS and cert pinning they don't even get as far as TLS.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#8
post #4

Earlier quoted context omitted.

Do you have an extension that is trying to redirect you to https? It's an http link but I can see that https doesn't work on cracked.com.

Traveling and the ISP here hi-jacks DNS requests for http sites to it's currently broken proxy..

That's the real crime here.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#9
post #6

Invalid SSL cert on the site. > There were even reports of people's Gmail accounts being hacked. This sounds suspiciously false - even if they are phones were forced to downgrade to A5/1 this should have no effect on TLS.

Without HSTS and cert pinning they don't even get as far as TLS.

If they've connected to Gmail before they would have received HSTS headers. So I'm not sure what you are suggesting? Could you elaborate on how you think GSM cipher downgrades lead to stolen Gmail credentials?

edit: Furthermore Chrome/Firefox implement HSTS preload lists on which gmail.com is included. [0][1]

[0] https://cs.chromium.org/chromium/src/net/http/transport_secu...

[1] https://blog.mozilla.org/security/2012/11/01/preloading-hsts...

Post reply on HN