Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

281–290 of 470 posts

Re: The Great Cannon has been deployed again

#281
post #245

Earlier quoted context omitted.

> "Countries that trade with each other don't make war with each other." I'm pretty sure this was the prevailing thinking prior to World War 1. A large scale conflict would be so damaging on a human and economic level that most assumed the people in power would find away to stop a massive war from breaking out. Well, they were right about the first assumption, but very wrong about the second.

It's also why the EU was founded, and in that instance it worked great. European powers used to be constantly at war with each other, but in the last 70 years there was no large-scale war within Europe (except for Ukraine/Russia, both not in the EU), and war between EU states has become unthinkable.

This is surely a contributing factor, but being first-class citizens of Pax Americana US hegemony has been a larger one IMO (doubly so during the Cold War, when a common enemy on Western Europe's borders united them).

There's plenty of good things from a moral perspective about power being diffused away from a hyperpower hegemon, but stability and peace have never been among the side effects.

Re: The Great Cannon has been deployed again

#282
post #134
post #122

Earlier quoted context omitted.

I'm not defending China at all, they have tons of shitty policies. I'm just saying it is nothing like the holocaust and it is pretty absurd when people do those kind of comparisons. It reminds me of just before the Iraq invasion when the propaganda was at it's highest (Freedom fries and Dixie Chicks). If I again compare with the US as an example even if people don't like that. You have had many hundred if not thousan…

The problem is you have two types of people, you have the guy that sees his kid get blown up and is like F'it I am going to detonate myself. I get it, I could be that guy under the right circumstances. The problem is the world is just as full of people ready and willing to exploit that guy and that is what happens. The situation is a lot more complicated than the American imperialist kills babies meme. The problem is…

The thing is when you write:

>The problem is you have two types of people, you have the guy that sees his kid get blown up and is like F'it I am going to detonate myself. I get it, I could be that guy under the right circumstances. The problem is the world is just as full of people ready and willing to exploit that guy and that is what happens. The situation is a lot more complicated than the American imperialist kills babies meme. The problem is though when you go after the other guys, who need going after, some good people get killed and it creates a newly exploitable class based on that anger and resentment.

That is also the exact motivation that China uses for its re-education camps. It is because of terrorism that they need to go after.

Re: The Great Cannon has been deployed again

#283
post #205

Earlier quoted context omitted.

that's what they want. a bifurcation of the internet.

No they don't. They want to use it as a weapon against targets of their choosing and co-opt the rest of the net in doing so. The economic importance of the internet to China can not be overstated.

I think what parent is saying is that (unrelated to TFA) China wants a separate information sphere, where only party-approved sites and services are available to their citizens. They have largely accomplished this.

Re: The Great Cannon has been deployed again

#284

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

just for good measure: sudo echo -e "\n\n# Null route the Great Cannon:\n0.0.0.0 baidu.com\n0.0.0.0 qihucdn.com\n" | tee /etc/hosts ... but I know I'm only fooling myself.

(I strongly recommend tee -a :) as well as putting the sudo before the tee).

Re: The Great Cannon has been deployed again

#285

Earlier quoted context omitted.

just for good measure: sudo echo -e "\n\n# Null route the Great Cannon:\n0.0.0.0 baidu.com\n0.0.0.0 qihucdn.com\n" | tee /etc/hosts ... but I know I'm only fooling myself.

(I strongly recommend tee -a :) as well as putting the sudo before the tee).

:)

thanks (I admit didn't test it because I use `python3 ./updateHostsFile.py` to take care of /etc/hosts)

Re: The Great Cannon has been deployed again

#286
post #89

Can/shouldn't the rest of the world create a Greater firewall to block the traffic from China? Let China enjoy it's solitude and we'll enjoy our openness.

Yeah except we will effectively be cutting off _all_ outside information from the Cinese citizens, who already have to face incredible amounts of censorship. Cut them off completely, and we will never find out about all the human rights violations taking place in their country, and their government will be able to brainwash its citizens even more easily.

I'm OK with that.

Today we're just finding about them, not able to do anything, so that won't be much different from the status quo but the benefits would be immense.

Re: The Great Cannon has been deployed again

#287

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

I don't quite understand the mechanism after reading the article. Is the attacker (presumably the PRC) MITM'ing these CDN resources at the infrastructure level? If they had exploits in place within these CDNs (presumably within the PRC's capabilities) HTTPS wouldn't help, no?

More than likely they placed a phone call to Baidu and told them exactly what to do. I doubt it's a technological MITM probably just a social one. A totalitarian state can do that.

Re: The Great Cannon has been deployed again

#288
post #37

Earlier quoted context omitted.

Serve content related ads and don't track. I'd be fine with that.

Shameless plug: this is what we are trying to do at https://contextcue.com . Ads that are targeted to the website you’re on, instead of the person viewing the ad. We’d love any feedback about what we are trying to accomplish!

That's great! I wish you well.

Re: The Great Cannon has been deployed again

#289

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

> Visiting a HTTP site should come with a scary warning

Browsers are already moving to explicitly label HTTP sites as "not secure"

Re: The Great Cannon has been deployed again

#290

Earlier quoted context omitted.

I don't quite understand the mechanism after reading the article. Is the attacker (presumably the PRC) MITM'ing these CDN resources at the infrastructure level? If they had exploits in place within these CDNs (presumably within the PRC's capabilities) HTTPS wouldn't help, no?

More than likely they placed a phone call to Baidu and told them exactly what to do. I doubt it's a technological MITM probably just a social one. A totalitarian state can do that.

that's why probably null routing at ISP level is more likely. the time it takes to adapt to new defenses is much less than what it takes to come to an agreement in cabforum. When things escalate nobody will push vendors to agree on new security features when a blunt instrument like legislation is cheaper. If things escalate they'll just sinkhole all traffic going in and out of China.
Post reply on HN