Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

191–200 of 470 posts

Re: The Great Cannon has been deployed again

#191
post #96

So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.

I would rather see more rigorous trade policy. Frankly fewer low-quality or fraudulent Chinese imports will probably be a net positive and even if it is more expensive, I would rather our trade dollars support countries with less corrupt governments and better ethics with respect to intellectual property, fraud, environmental protection, etc. I’m sure this will garner plenty of whataboutism regarding how the west is…

The west is constantly pushing for stuff like this in every trade policy with China and others...

There’s a limit to how much leverage any one side has on a sovereign countries policies (and how much they actually enforce them when they agree).

There’s also the question of the benefits of having China at all in these deals, some concessions and a growing dependence on western markets from initial deals is better than no deals.

Plus a wealthier China is good for the world and the billion people coming out of poverty, getting educated, and slowly becoming an advanced economy.

Re: The Great Cannon has been deployed again

#192
post #142

Earlier quoted context omitted.

War seems to progress as follows: 0 - Peace 1 - Trade War 2 - Financial War 3 - Electronic War 4 - Shooting War Note that 1 & 2 are different types of Economic war, and could be grouped together. The steps occur in order, but steps can be skipped. From a US-centric point of view, North Korea and Iran seem to be at #3. China & Russia are at a limited version of #2. Chinese/HK seem to be at #3 with each other.Given how…

I don't know who to attribute this to but I've heard a saying: "Countries that trade with each other don't make war with each other." As we isolate countries and disrupt trade we definitely are increasing the risk of conflict.

Yes, who cares about the forced labor camps and suicide nets around factories. I want my cheap plastic consumer devices!!

Re: The Great Cannon has been deployed again

#193
post #170

Earlier quoted context omitted.

HTTPS makes a MiTM attack much harder, because you need to have a valid cert for the host you are spoofing.

Doesn't the Great Firewall mandate (or at least strongly suggest) that those Chinese-controlled root certs are installed for devices behind it?

If this were a root cert, OSes and browsers could ban that CA. If you want this to work with SSL, giving the Great Firewall a domain cert would be enough.

Re: The Great Cannon has been deployed again

#194
post #179
post #97

Earlier quoted context omitted.

The first paragraph of the article mentions > operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack the users’ connections to make multiple requests against the targeted site. These requests consume all the resources of the targeted site, making it unavailable:

So basically browser vendors need to add all Chinese hosting sites to their safebrowsing blacklist?

It’s coming from a Baidu domain which is one of the biggest sites in the world. That might be a bit difficult...

Re: The Great Cannon has been deployed again

#195
> It is unlikely these sites will be seriously impacted. Partly due to LIHKG sitting behind an anti-DDoS service, and partly due to some bugs in the malicious Javascript code that we won’t discuss here.

If I get the attack scenario right, valid user IPs from behind the great firewall are driving traffic to the webservers, and so what are some examples of anti-DDoS mitigations that are effective in filtering out the adversarial traffic?

Re: The Great Cannon has been deployed again

#196
post #82
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

Bullets have been obsolete for decades. Wars are currently fought by selling shitty financial instruments en masse to your opponents while you sit and watch them implode from afar.

The ensuing civil strife that can occur if this is successful will make a literal, on the ground, bombs in the air, guns shoot war all the easier to attain for hawks that are good at stirring up the masses.

Need I remind you that China has a male surplus, and sadly, military enlistment will become a stronger appeal for single men if they do not have a family nor hope of starting one in the traditional sense.

More and more, war is looking like the nail to China's hammer of surplus men.

Re: The Great Cannon has been deployed again

#197
post #51
post #10

I've wondered about this, in the years since. Does anyone else have a sense of what (if any) pragmatic technical steps could effectively deter or neuter this tactic? If the network can't demonstrate the ability to at least pump the brakes on this, it's hard to imagine other states or even the owners of large safe-monopoly ISPs won't get a little jealous of the tool.

Block all traffic from China?

Collateral damage aside, that doesn't really solve the issue. The attack goes something like this:

1. non-chinese user visits a chinese site

2. the traffic goes through the gfw, which inserts malicious javascript

3. the user executes the malicious javascript and starts ddosing the victim site

Blocking chinese users won't help, since non-chinese visitors will still ddos your site.

Re: The Great Cannon has been deployed again

#198

It's bad that there are enough plain http connections for this to be possible.

Although Baidu does still default to HTTP, the Chinese government has the root certificates for every Chinese certificate authority. It can MITM traffic for anybody in China, even over HTTPS, so that wouldn't solve the problem.

Do browsers and OSes trust Chinese CAs?

Re: The Great Cannon has been deployed again

#200
post #179
post #97

Earlier quoted context omitted.

The first paragraph of the article mentions > operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack the users’ connections to make multiple requests against the targeted site. These requests consume all the resources of the targeted site, making it unavailable:

So basically browser vendors need to add all Chinese hosting sites to their safebrowsing blacklist?

[deleted]
Post reply on HN