Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

401–410 of 470 posts

Re: The Great Cannon has been deployed again

#401

Earlier quoted context omitted.

> Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. But that is literally what web users want . Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users. EDIT: That said, browsers have features for users such as yourself to…

No, that is not what web users want. No one asked them and they probably don't even have an opinion on that. It's what web developers and browser makers want.

It's certainly not what browser makers want, since the browser makers dropped native extensions and Flash and Java, and it's not what many web developers want, given the popularity of Content-Security-Policy.

Re: The Great Cannon has been deployed again

#402

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

Tls sadly won't make a difference.

Re: The Great Cannon has been deployed again

#403
post #396

Earlier quoted context omitted.

> Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. But that is literally what web users want . Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users. EDIT: That said, browsers have features for users such as yourself to…

I think you'll need some evidence for that. Silence is not consent, and it's certainly not enthusiastic consent. And even if you do want to take silence for consent, the fact that the vast majority of millions of millions of web users do not install an extension to route around Google AMP indicates that they do not want the operators of the web page to do whatever they want, they want to run a restricted subset of wh…

> they want to run a restricted subset of what the web designer might imagine

For the kinds of places that AMP is used, I would suspect so.

> Also, users did vote with their feet against downloading EXEs from the internet

So....this CAN happen???

> users would gladly accept even more restrictions on the execution platform.

The recent popularity of clipboard permissions, geolocation permissions, notification permissions, etc. would suggest otherwise.

What makes you so sure that web users care so much about the uptime of lihkg.com ?

Re: The Great Cannon has been deployed again

#405
post #396

Earlier quoted context omitted.

I think you'll need some evidence for that. Silence is not consent, and it's certainly not enthusiastic consent. And even if you do want to take silence for consent, the fact that the vast majority of millions of millions of web users do not install an extension to route around Google AMP indicates that they do not want the operators of the web page to do whatever they want, they want to run a restricted subset of wh…

> they want to run a restricted subset of what the web designer might imagine For the kinds of places that AMP is used, I would suspect so. > Also, users did vote with their feet against downloading EXEs from the internet So....this CAN happen??? > users would gladly accept even more restrictions on the execution platform. The recent popularity of clipboard permissions, geolocation permissions, notification permissio…

> The recent popularity of clipboard permissions, geolocation permissions, notification permissions, etc. would suggest otherwise.

What popularity? Do you have data that users tend to click "yes" on such permission prompts?

> What makes you so sure that web users care so much about the uptime of lihkg.com ?

I'm not sure I understand what you're asking or what you're responding to.

Re: The Great Cannon has been deployed again

#406
post #366

Earlier quoted context omitted.

What is "GA"?

General Aviation; the same people that lobby to keep using leaded fuels.

That's a bit too harsh. The GA people are lobbying to continue to be able to fly their aircraft. The FAA has been sitting on the problem of non-leaded avgas for something like 30 years now. The GA people don't like being exposed to lead any more than anyone else.

Re: The Great Cannon has been deployed again

#407

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

> Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. But that is literally what web users want . Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users. EDIT: That said, browsers have features for users such as yourself to…

> But that is literally what web users want.

No it absolutely does not.

Just because a user doesn't understand what Javascript is or how to diagnose why their computer is slow (is it an app, website, update, virus etc) does not imply consent.

Pretty sure that most people just want to be able to visit a website without it causing problems to their computer or to others.

Re: The Great Cannon has been deployed again

#408
post #205

So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.

that's what they want. a bifurcation of the internet.

I doubt that's what they want at least in the short term. The economic effects would be disastrous.

Re: The Great Cannon has been deployed again

#409

Earlier quoted context omitted.

It only works if you somehow remove entire China from the Internet.

It is possible: De-peer AS4134 (China Telecom) and reject all of their routes. They are the only international ISP that lands into mainland China. They are extensively peered around the world.

It's not just them. AS4837 (China Unicom) and a few others who have intl permission to route in and out of China. That said, you're going to hurt a lot of non-china multinationals who operate there.

Re: The Great Cannon has been deployed again

#410
“a web site Lihkg.com” is really an understatement as its title indicated. Given the “be water” and no leader, lihkg is really the only way to try to have some sort of info among possible noise (which popo is likely also post their confused Messages). There were discussion to cut off access by hksarg and a rush to install vpn is promoted. Guess they cannot firewall hk given its financial centre status.

The evil empire and culture will try and try to harm liberty and human rights. If it is not so important you would not see many of hkers like me instead of posting in here and other places, but in concentration camp as northern Turks up north.

Post reply on HN