Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

381–390 of 470 posts

Re: The Great Cannon has been deployed again

#381

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

I posted a top-level comment[1], but basically HTTPS-only, aside from throwing old sites under the bus, would not have helped.

[1] https://news.ycombinator.com/item?id=21726617

> and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?

Probably something like this, but I'm afraid of where that would lead.

Re: The Great Cannon has been deployed again

#382
post #174

The web needs to start moving towards a strong same-origin policy for all embedded content-- require sites to proxy requests if they want third party content. The first step could be sending CORS preflight, then requiring it, then just not allowing cross origin to different domains (but allow sub-/sibling- domains).

Can't the CORS preflight, by itself, be a DoS?

Re: The Great Cannon has been deployed again

#383

So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.

Google has had a lot of success blacklisting domains that spam. Getting blacklisted and losing 30-90 days worth of traffic because you wanted to bump your pagerank a bit is a bit silly.

We could potentially have sanctions that require Google to block commercial sites in China. That would definitely get their attention without massive financial implications on the economy.

This type of behavior CAN NOT be allowed to continue.

Re: The Great Cannon has been deployed again

#384

Earlier quoted context omitted.

> There’s a limit to how much leverage any one side has on a sovereign countries policies (and how much they actually enforce them when they agree). I’m not advocating for anyone controlling sovereign Chinese policies. They can continue their awful anti-humanitarian policies, fraud, IP theft, etc. I just don’t want my country aiding and abetting it. At very least I want my fellow citizens to be able to make informed…

The UK kept trade with the US when slavery there was rampant. Any country will have hiccups throughout its development. It's convenient but counterproductive to categorize every argument against yours as "whatabouttism".

> The UK kept trade with the US when slavery there was rampant.

And we’re I a citizen of the UK in this tortured analogy (with my contemporary morals and all that), I wouldn’t want my money supporting that.

> Any country will have hiccups throughout its development.

Right, but we don’t have to support those “hiccups”. Anyway, China had 60 million hiccups in the last century. They’re all out of hiccup passes.

> It's convenient but counterproductive to categorize every argument against yours as "whatabouttism".

Not every argument, only the ones that start with suggest I can’t criticize China until are completely without blame. Such as yours.

Re: The Great Cannon has been deployed again

#385

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

> Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net.

But that is literally what web users want.

Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users.

EDIT: That said, browsers have features for users such as yourself to disable JavaScript, and there are third party extensions for finer-grained control. Again, adding these limitations is unpopular among web users.

Re: The Great Cannon has been deployed again

#386

Earlier quoted context omitted.

It only works if you somehow remove entire China from the Internet.

That would be the kind of signal that would be hard for the Chinese to spin in such a way that it would make them look good, and the economic effect would be pretty much instantaneous. There is plenty of historical precedent for this: spammers' IP ranges would be blackholed to send a message to their ISPs that such behavior wasn't tolerated. That the Chinese authorities decide to play this game at the nation state le…

The spin would be "US cuts off global internet in a petty attempt to interfere with China's management of its own network". Justified by a technical backstory that approximately nobody understands, I don't think it would play well even outside of China.

Re: The Great Cannon has been deployed again

#387

Earlier quoted context omitted.

It's not that nobody cares, it's that nobody can do anything about it.

Well, with the rise of anti DDoS services meaning the targeted websites are staying online, rendering the “Great Cannon” more like a pathetic peashooter, that’s doing one thing. Calling China out whenever they do this is another. Unmask the Chinazis for what they are.

I don't think that last line is helpful. If you believe that the Chinese government is akin to the Nazi party, better to make the argument explicitly than to use a term like "Chinazis", which could be interpreted as overly broad and highly insulting in the best case.

Re: The Great Cannon has been deployed again

#388

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

It's called hyperlink and doesnt require any code or javascript to run. Maybe excessive requests to same IP could be throttled by a user agent.

An outbound browser firewall could helps also.

Re: The Great Cannon has been deployed again

#389
post #388

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

It's called hyperlink and doesnt require any code or javascript to run. Maybe excessive requests to same IP could be throttled by a user agent. An outbound browser firewall could helps also.

> It's called hyperlink and doesnt require any code or javascript to run.

Hyperlinks generally don't open themselves. There is an obvious exception -- img tags[1] -- and I think it's worth considering whether they should be allowed to have the behavior they do. As far as I see, img tags load themselves so that, if you're editing HTML by hand, you don't have to deal with binary image data in the middle of what was supposed to be a clean text file. That may not be the right tradeoff.

[1] The img model got extended to other external resource loads, like script and css. But both of those frequently do appear as part of the same HTML that uses them. Image data can, but usually doesn't.

Also, external script loads are such an obvious problem that we got the Content-Security-Policy just to deal with it.

Re: The Great Cannon has been deployed again

#390

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

I recently (4 or 5 months ago) joined an online community of aircraft owners and pilots that is primarily focused around a single brand of aircraft (although it's not an official site of, property of, that brand nor is it endorsed by that brand). When I signed up, they emailed me to welcome me to the site (they actually require manual authorization of users by an admin, which is... refreshing, but uncommon). The emai…

"How secure do you need your browsing to be?"

Perhaps explain to them that many people (unwisely) reuse passwords for many sites... possibly including their banking.

Post reply on HN