Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

91–100 of 470 posts

Re: The Great Cannon has been deployed again

#91
post #85
post #2

This is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.

This is not a good counterexample: the attacker is only able to do this because the analytics scripts are being served over HTTP. If you include the analytics on your site over HTTPS this sort of attack is not relevant.

I imagine China has quite a bit of infrastructure to push their own CA's onto devices in china, enough to do any MITM'ing they want.

Re: The Great Cannon has been deployed again

#93
post #30

Earlier quoted context omitted.

It's 2019, what excuse does Baidu have to not support https for these scripts?

Baidu will serve the script over HTTPS (though firefox complained about a bad certificate), the issue is that it will also serve it over HTTP, and some 3rd party pages request the HTTP version.

No browser will load the script from within a tag because of the bad certificate, serving the script with a bad certificate achieves nothing.

Re: The Great Cannon has been deployed again

#94
post #64
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

[flagged]

[flagged]

Re: The Great Cannon has been deployed again

#95
post #85
post #2

This is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.

This is not a good counterexample: the attacker is only able to do this because the analytics scripts are being served over HTTP. If you include the analytics on your site over HTTPS this sort of attack is not relevant.

The Chinese government has the root certificates for every Chinese certificate authority. It can MITM traffic for any citizen, even over HTTPS.

Re: The Great Cannon has been deployed again

#96

So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.

I would rather see more rigorous trade policy. Frankly fewer low-quality or fraudulent Chinese imports will probably be a net positive and even if it is more expensive, I would rather our trade dollars support countries with less corrupt governments and better ethics with respect to intellectual property, fraud, environmental protection, etc.

I’m sure this will garner plenty of whataboutism regarding how the west is imperfect (never minding that I didn’t say “the west”)...

Re: The Great Cannon has been deployed again

#97
post #6

I didn’t see this anywhere in the article (maybe I missed it), but because this utilizes the Great Firewall, it’s undoubtedly done by the Chinese government, right?

The first paragraph of the article mentions

> operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack the users’ connections to make multiple requests against the targeted site. These requests consume all the resources of the targeted site, making it unavailable:

Re: The Great Cannon has been deployed again

#98

It's bad that there are enough plain http connections for this to be possible.

Although Baidu does still default to HTTP, the Chinese government has the root certificates for every Chinese certificate authority. It can MITM traffic for anybody in China, even over HTTPS, so that wouldn't solve the problem.

Re: The Great Cannon has been deployed again

#99
post #33
post #27

Earlier quoted context omitted.

It always bothers me when I hear people say this, it's everyone's responsibility that their devices don't become part of a botnet or worse used to take part in an attack against infrastructure that we're increasingly dependent upon that either makes for an unpleasant time for people or threatens lives.

A responsibility is meaningless if most people have no practical means to exercise that responsibility.

One step in the right direction is to drop the marketing bullshit of "unlimited internet" (which doesn't exist) and always meter it, but make it completely transparent.

If your smart toaster is saturating your bandwidth, it should show up as an expensive line-item on your bill. You should see that "SmartToast9000" used $80 of bandwidth, "baidu.com" used $17 because it used your bandwidth to ddos. And, of course, the tooling to catch these things before they escalate would likely become part of our computing devices.

Right now, everything is completely opaque to the end-user and we all suffer except for bad actors. It's a problem when we can't even estimate how much bandwidth we used in a month off the top of our head. Instead it should be informing our decisions from the IoTrash we buy to which websites we use.

Example: the internet was regularly awful at my girlfriend's house. We couldn't figure it out despite calling the ISP. On a suspicion, I helped my gf install a bandwidth monitor on her laptop. We found that a recipes website she often had open would get stuck in some sort of ad-loading retry loop due to her adblocker and would saturate her download bandwidth as long as she had it open.

It's completely ridiculous to me that there's no feedback built in to the browser when I think it should be a first-class UI component. I think transparent + metered bandwidth (at a fair price of course) would start the ball rolling on this kind of tooling. Until then, it's like everything acts like bandwidth is unlimited.

Re: The Great Cannon has been deployed again

#100
post #64
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

[flagged]

[flagged]
Post reply on HN