> These attacks would not be successful if the following resources were served over HTTPS instead of HTTP: Can someone explain how using HTTPS would mitigate this attack?
The Great Cannon has been deployed again
151–160 of 470 posts
Re: The Great Cannon has been deployed again
#152Earlier quoted context omitted.
Yes, absolutely. The economic clout gives them the confidence and means. That needs to be dealt with. Declaw!
Like how the world dealt with the US after Snowden's reveals?
Americans must regain the courage and dignity of differing from the hundred lame, neoliberal, tacit fascist-enabling bugman regimes that litter the world.
It's often good not to be like them.
Re: The Great Cannon has been deployed again
#153This is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.
But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.
Re: The Great Cannon has been deployed again
#154Earlier quoted context omitted.
Baidu will serve the script over HTTPS (though firefox complained about a bad certificate), the issue is that it will also serve it over HTTP, and some 3rd party pages request the HTTP version.
No browser will load the script from within a tag because of the bad certificate, serving the script with a bad certificate achieves nothing.
Re: The Great Cannon has been deployed again
#155Earlier quoted context omitted.
This doesn’t work. The DDoS requests actually come from outside China when oversea visitors are hit by the malicious js while browsing Chinese websites.
So it does work. It doesn't really matter where you break the chain as long as it gets broken.
Re: The Great Cannon has been deployed again
#156It's bad that there are enough plain http connections for this to be possible.
Although Baidu does still default to HTTP, the Chinese government has the root certificates for every Chinese certificate authority. It can MITM traffic for anybody in China, even over HTTPS, so that wouldn't solve the problem.
Re: The Great Cannon has been deployed again
#157Re: The Great Cannon has been deployed again
#158Earlier quoted context omitted.
For one, we should all be making sure our websites use https all the time. If all you have is a personal website serving up mostly static content then it might not seem like you need to bother with a certificate but things like the Great Cannon are a great argument that you do. It's not unlike a public health argument for why everybody should be vaccinated.
HTTPS will help your users not getting infected by code that a 3rd party injected on your site. But it will probably not help against the cannon, because the Chinese probably have some china controlled certificate installed.
Re: The Great Cannon has been deployed again
#159So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?
War seems to progress as follows: 0 - Peace 1 - Trade War 2 - Financial War 3 - Electronic War 4 - Shooting War Note that 1 & 2 are different types of Economic war, and could be grouped together. The steps occur in order, but steps can be skipped. From a US-centric point of view, North Korea and Iran seem to be at #3. China & Russia are at a limited version of #2. Chinese/HK seem to be at #3 with each other.Given how…
Re: The Great Cannon has been deployed again
#160So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.
This doesn’t work. The DDoS requests actually come from outside China when oversea visitors are hit by the malicious js while browsing Chinese websites.