Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

21–30 of 470 posts

Re: The Great Cannon has been deployed again

#21
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

The question is, you know I'm using it. Besides some words, what the heck are you going to do?

Re: The Great Cannon has been deployed again

#22
post #6

I didn’t see this anywhere in the article (maybe I missed it), but because this utilizes the Great Firewall, it’s undoubtedly done by the Chinese government, right?

So, what happens if the endpoints start returning data that triggers the GF?

Re: The Great Cannon has been deployed again

#23

Earlier quoted context omitted.

But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.

> But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. This folk has an answer: display ads the ol' fashioned way, with a pair of and tags.

Ad blockers still remove them. They have tried not to and the users intentionally moved to ad blockers that still did.

https://en.wikipedia.org/wiki/Adblock_Plus#Controversy_over_...

Re: The Great Cannon has been deployed again

#24
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

[flagged]

Re: The Great Cannon has been deployed again

#25
post #2

This is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.

But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.

I think the primary argument line is something along:

1. Online ads today are so bad they must be blocked

2. But blocking ads blocks revenue for sites we like

3. So we should pay for them more directly

4. But I'm not about to set up 100 different monthly subscriptions. These corporations are not trustworthy and I cannot monitor this many bills.

5. We need a solution to simplify money -> content -> creator transfer

6. There's been many attempts at that, but there's too many players who want the power and control that comes with wedging themselves in between consumers and creators.

7. So we're stuck.

Re: The Great Cannon has been deployed again

#26
post #6

I didn’t see this anywhere in the article (maybe I missed it), but because this utilizes the Great Firewall, it’s undoubtedly done by the Chinese government, right?

No. "Behind the Great Firewall" is another way of saying "served from China". Perhaps -- or even most likely -- it is the government. But this is hardly a smoking gun. There are plenty of people on the mainland that hate what's going on in HK, and who are not the government.

Re: The Great Cannon has been deployed again

#27
post #2

This is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.

Or "Why should I care about security, I have nothing of value" folks. You do have something of value: Bandwidth.

It always bothers me when I hear people say this, it's everyone's responsibility that their devices don't become part of a botnet or worse used to take part in an attack against infrastructure that we're increasingly dependent upon that either makes for an unpleasant time for people or threatens lives.

Re: The Great Cannon has been deployed again

#28

Earlier quoted context omitted.

But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.

On the contrary, people pay for Netflix. People also pay for the ad-free upgrade to Hulu. Speaking to text websites, people are also using Brave, though I don't know how that experiment will work out in the end.

I think Brave is on the right track, but I am skeptical the kind of users that are aggressively anti-ad are going to like seeing ads straight in their notifications.

I'd prefer to just pay Brave e.g. $10/month and have it give out that money to sites I visit.

Re: The Great Cannon has been deployed again

#29
post #11

If baidu.com is distributing the script, why is baidu.com not being flagged as malware by the various mechanisms used to block this kind of nastiness? Are the vendors just cowards?

baidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.

Re: The Great Cannon has been deployed again

#30
post #11

If baidu.com is distributing the script, why is baidu.com not being flagged as malware by the various mechanisms used to block this kind of nastiness? Are the vendors just cowards?

baidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.

It's 2019, what excuse does Baidu have to not support https for these scripts?
Post reply on HN