Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

71–80 of 470 posts

Re: The Great Cannon has been deployed again

#72
post #9

Earlier quoted context omitted.

And yet here you are. I'm interested how you would perceive something that might supercede the internet by being better (than a boiling toilet fueled by greed), ignoring network effects?

Something similar to the web in the late 90s / early 2000s?

Exactly what I'm thinking. Not everything is awful but the insistence of turning the browser into a vm and loading random javascript is pure insane. I'm not advocating for stoneage html and frames but let's take a step back and realize that not every website has to be an interactive webpage some designer dreamed up. I want information, not entertainment or an experience. The experience is what I take away from the information, not the clown paint smeared all over it for show.

Re: The Great Cannon has been deployed again

#73

Earlier quoted context omitted.

> But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. This folk has an answer: display ads the ol' fashioned way, with a pair of and tags.

Ad blockers still remove them. They have tried not to and the users intentionally moved to ad blockers that still did. https://en.wikipedia.org/wiki/Adblock_Plus#Controversy_over_...

Yes, because Adblock Plus did it in the shadiest possible way imaginable. From the Wikipedia page:

> * In February 2013, an anonymous source accused Adblock Plus developer Wladimir Palant of offering to add his site's advertisements to the whitelist in return for one-third of the advertisement revenue.[68] In June 2013, blogger Sascha Pallenberg accused the developers of Adblock Plus of maintaining business connections to "strategic partners in the advertising industry", and called ABP a "mafia-like advertising network".[69] He alleged that Adblock Plus whitelisted all ads coming from "friendly" sites and subsidiaries, and promoted their product using fake reviews and pornography.[70] Faida responded to Pallenberg's accusations, stating that "a large part of the information concerning the collaboration with our partners is correct", but that the company did not see these industry connections as a conflict of interest.*

"We'll whitelist acceptable ads. Btw, acceptable means 'willing to pay us a kickback'".

The move on Adblock Plus did nothing to make me safer, so of course I ditched them for a more secure solution. Of course, it's Adblock Plus's goal and right to try to make a revenue, but I don't owe them the continued use of their product.

And I absolutely reject the premise that I owe every website that's willing to send a 200 OK response the right to run arbitrary javascript in my browser. If you don't want me 'mooching' your content, fine - put up a paywall.

Re: The Great Cannon has been deployed again

#74

Earlier quoted context omitted.

But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.

On the contrary, people pay for Netflix. People also pay for the ad-free upgrade to Hulu. Speaking to text websites, people are also using Brave, though I don't know how that experiment will work out in the end.

I think we need a solution for websites that aren't as unanimously popular as Netflix and Hulu. It's no surprise to me that the biggest entertainment services online can attract a subscription. But it would be a damn shame if those are the only services that can make much money. Just more and more centralization of content.

People often respond to this with "well, hobbyists make plenty of content for free," but the thing is that we benefit when our favorite hobbyists can make money from the craft and produce more work for us to enjoy instead of waiting around for their charity.

Though the growth of Patreon is a good step in the right direction, culturally. It shows a growing willingness to indeed pay content producers directly with small recurring transactions.

Re: The Great Cannon has been deployed again

#76
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

Why should they care, what's anyone going to do about it?

[deleted]

Re: The Great Cannon has been deployed again

#77
post #61
post #18

Earlier quoted context omitted.

That's the implication but as with most cyber attacks it's impossible to really prove the source.

This is one of the cyber attacks where the source is proven.

We all know who the attacker is here, but it's not literally "proven" to the standard of evidence that would be required in a US court. The attacker still has plausible deniability.

Re: The Great Cannon has been deployed again

#78
post #30

Earlier quoted context omitted.

baidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.

It's 2019, what excuse does Baidu have to not support https for these scripts?

Baidu will serve the script over HTTPS (though firefox complained about a bad certificate), the issue is that it will also serve it over HTTP, and some 3rd party pages request the HTTP version.

Re: The Great Cannon has been deployed again

#79
post #30

Earlier quoted context omitted.

baidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.

It's 2019, what excuse does Baidu have to not support https for these scripts?

Remember that all internet related companies that operate in China have mandatory stewardship from the CCP.

One reason may be that http makes it easier for surveillance or injection.

Post reply on HN