Live data from Hacker News

China systematically hijacks internet traffic: researchers

itnews.com.au

21–30 of 54 posts

Re: China systematically hijacks internet traffic: researchers

#21
post #13
post #12

Earlier quoted context omitted.

If you have something that you genuinely need to keep from the Chinese, don't connect to the internet full-stop. Even SSL can be decrypted by their great firewall if they are suspicious enough. Even VPNs have no guarantee that someone with the right resources hasn't terminated the VPN themselves on the quiet!

[citation needed] Like whoa, are you even aware of what you are suggesting? This is completely false.

I know that SSL and TLS tend to be thrown around interchangeably, but SSL is actually deprecated and unrecommended for being unsecure[0]

[0] https://en.wikipedia.org/wiki/Transport_Layer_Security#SSL_2...

Re: China systematically hijacks internet traffic: researchers

#22
post #6

And the US and the rest of the 5-eyes don't? that doesn't make it right, just more wrong, if you're angry that China is doing this then you should be equally because the US and 'friends' are doing it to you too

At least in theory FVEY nations are democratically accountable for the behavior.

Being spied upon by a non-democratic nation is the same as being spied upon by a democratic nation if you're not a citizen - you don't hold any influence over either and neither is accountable to you.

So from an outside perspective the US and China are pretty much the same thing in that regard.

To top it off, the five eyes nations are spying on each other - so even if you're a citizen of one you're tolerating being spied upon by four other surveillance apparati that aren't accountable to you.

Re: China systematically hijacks internet traffic: researchers

#23
post #20

Traffic heading to China gets intercepted-- you don't say?

This is not what the article says happened. Rather, the researchers found that China was able to reroute traffic going to other countries to instead go to China, presumably to analyze or decrypt it, before sending it on to its original destination later.

Please read the article before commenting.

Re: China systematically hijacks internet traffic: researchers

#24
post #6

And the US and the rest of the 5-eyes don't? that doesn't make it right, just more wrong, if you're angry that China is doing this then you should be equally because the US and 'friends' are doing it to you too

“And you are lynching negroes”

https://en.wikipedia.org/wiki/And_you_are_lynching_Negroes

Or if you prefer, the contemporary form:

https://en.wikipedia.org/wiki/Whataboutism

——

This varient is particularly useful against anybody with a social justice argument. Let’s say I complain about Google and what appears to be systemic support for sexual coercion by male managers. You can trot out, “But it’s far worse at Uber, did you complain then? No? Have you taken an Uber since then? You have? You have no right to complain now.”

Or maybe I say that migrant children have been separated from their families. “You’re a Canadian. Did you speak out against Residentual Schools? No? Then shut up about migrant families.”

It’s endlessly applicable.

Re: China systematically hijacks internet traffic: researchers

#26
post #13

Earlier quoted context omitted.

[citation needed] Like whoa, are you even aware of what you are suggesting? This is completely false.

I know that SSL and TLS tend to be thrown around interchangeably, but SSL is actually deprecated and unrecommended for being unsecure[0] [0] https://en.wikipedia.org/wiki/Transport_Layer_Security#SSL_2...

I would still like to see them decrypt the traffic on demand. There are heaps of other attack vectors that are much easier to deploy. Also, looking at Qualys SSL Labs[0] it seems like most of the web does a good job at supporting secure and modern protocols. And it feels safe to assume that parent meant TLS, like most people do.

[0] https://www.ssllabs.com/ssl-pulse/

Re: China systematically hijacks internet traffic: researchers

#27

As someone with a trip to Beijing on the horizon, aside from using a VPN, are there any other best practices to keep data secure while traveling there?

(I live in China) I would advise against VPN entirely. I am unsure about the state ability to decrypt the content of the connection (heavily depends on how the VPN is configured really — weak and legacy ciphers, etc.). But they will detect it and eventually you'll start dropping packets like crazy.

A simple way to evade all of this is to use shadowsocks with a strong cipher and strong password between your computer in China and your server outside of it. Don't use any free server and don't use any commercial shadowsocks offerings. Set it up yourself, it's pretty easy.

On the mobile phone side of things. I wouldn't trust anything. Especially Apple that has been very complaisant with local authorities.

China plays a tactical game: they pretend (or we suspect, and they want us to) that they can do a lot of things. But nobody knows the extent of what they are actually capable of.

Re: China systematically hijacks internet traffic: researchers

#28
Could someone explain how out-of-ordinary these hijacks are? I thought network traffic is similar to connecting flights: it's not uncommon to fly from NY to Seoul with a transit stop in China. Network traffic may follow a non-optimal path for various reasons, such as complicated deal/rebate structures among AS, third party ASN spoofing, technical failures within AS and state-sponsored hacks. The paper seemed to cherry-pick some examples of "hijacks" involving China. But it would be more convincing to show whether they are happening all over the world or are specific to China.

In addition, network traffic at ISP level are never intended to be secure. That's why we have/need end-to-end encryption.

Re: China systematically hijacks internet traffic: researchers

#29

As someone with a trip to Beijing on the horizon, aside from using a VPN, are there any other best practices to keep data secure while traveling there?

(I live in China) I would advise against VPN entirely. I am unsure about the state ability to decrypt the content of the connection (heavily depends on how the VPN is configured really — weak and legacy ciphers, etc.). But they will detect it and eventually you'll start dropping packets like crazy. A simple way to evade all of this is to use shadowsocks with a strong cipher and strong password between your computer i…

But shadowsocks is a VPN. What makes it better than other offerings?

Re: China systematically hijacks internet traffic: researchers

#30
post #7
post #5

"then an appropriate defence policy in response could state that no traffic to or from the US or ally is allowed to enter a China Telecom PoP in the US or in the ally's networks" The fact that this is possible today seems incredible to me when i think of the number of times i've heard cybersecurity and cyberespionage was a priority of the US security agencies during the last decade.

On the contrary, I think as phrased that's a "break the internet" policy, especially if more than one country does it - what if China asks for a reciprocal version?

the article in fact points out that china does exactly that
Post reply on HN