Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

411–420 of 470 posts

Re: The Great Cannon has been deployed again

#411
post #7

So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?

What's wild is how at times the GFW will be abused to profit the operators of the GFW itself. Redirecting people to sites owned by friends to drive traffic/sales, etc. Due to the nature of the GFW, there isn't a lot of auditing or transparency there. Only the Chinese carriers can generally engage them and it usually involves a visit to a specific building in Beijing (no foreigners allowed).

Re: The Great Cannon has been deployed again

#412

Earlier quoted context omitted.

> Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. But that is literally what web users want . Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users. EDIT: That said, browsers have features for users such as yourself to…

> But that is literally what web users want. No it absolutely does not. Just because a user doesn't understand what Javascript is or how to diagnose why their computer is slow (is it an app, website, update, virus etc) does not imply consent. Pretty sure that most people just want to be able to visit a website without it causing problems to their computer or to others.

But a “website” isn’t an HTML page any more. It’s a network-deployed application. Most people want to run these applications.

Re: The Great Cannon has been deployed again

#413

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

Can there be a list that come up so user who want control can see what pages the link they have selected to link implicitly. Just on the side perhaps. They can explicitly block or AI learn etc. It may have to a feature as deny or enable all is too rough to be useful.

For china need some way to handle that whole commerical-military-party all one entity.

Re: The Great Cannon has been deployed again

#414
post #380

So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.

I agree that such bad behavior should be punished, but why just couple of days? This would be similar to UN trade sanctions that are imposed on bad state actors. I think we generally overestimate the hurt on the outside and underestimate the hurt on the inside considering the massive trade imbalance that China enjoys with the rest of the world. Personally I have already pi-holed entire .cn and other domains.

> This would be similar to UN trade sanctions that are imposed on bad state actors.

UN sanctions are not imposed on bad state actors. They are imposed on weak state actors. UN sanctions have never been imposed on the US, China, Russia, Britain and France easily the worst state actors globally - the biggest weapons sellers and the cause of instability all over the world. They also are the 5 permanent security council members with veto power.

> I think we generally overestimate the hurt on the outside and underestimate the hurt on the inside considering the massive trade imbalance that China enjoys with the rest of the world.

China doesn't enjoy a trade imbalance with the "rest of the world". The enjoy it with the US primarily. They are net importers of Japan, South Korea, Saudi Arabia, Brazil, etc.

Germany, Japan, South Korea, etc also enjoy trade imbalance with the "rest of the world". Do you support sanctioning them?

> Personally I have already pi-holed entire .cn and other domains.

That doesn't do much if you really think about it. It's not like chinese individual, company or government are barred from owning everything from coms to orgs.

Re: The Great Cannon has been deployed again

#415
post #228
post #192

Earlier quoted context omitted.

Yes, who cares about the forced labor camps and suicide nets around factories. I want my cheap plastic consumer devices!!

> Yes, who cares about the forced labor camps and suicide nets around factories. Nobody really cares, except for those directly involved. Sad but true, nobody will ever go to war for that, for foreign citizens. > I want my cheap plastic consumer devices!! People do actually want that. And their cheap shoes and clothes and...

Speak for yourself, and let others speak for themselves.

Re: The Great Cannon has been deployed again

#416
post #305

Earlier quoted context omitted.

You do know you’re suggesting that sites not be able to load assets from other sites right?

They are specifically suggesting that HTTP-only sites not be able to load from third party sites, which is quite a bit different than your interpretation of generally preventing any site from loading any external content. HTTPS ought to be the default and browsers can, and should, move towards that. But to answer your question more directly, yes they clearly know what they are suggesting.

> But to answer your question more directly, yes they clearly know what they are suggesting.

Highly unlikely, or else the suggestion would be to just ban http all-together. Http without the ability to load resources from other domains would break the majority of sites.

Re: The Great Cannon has been deployed again

#417

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

This sounds like a knee-jerk reaction that doesn't take into consideration the ramifactions of the suggested policy. It won't stop DDoS attacks, because those exist _because the internet exists_ and unless you dismantle the very concept of interconnected "everyone can reach everyone" networking, all you're doing is locking down access to more and more people until only technical experts or the people with enough mone…

I have NoScript installed on FireFox, and when I visit sites, I individually grant temporary permission to anywhere from one to more than twenty javascript sources. I suspect that I am among the 1% of those willing to make that effort.

I haven't noticed NoScript distinguish between http and https sources for javascript, but perhaps I don't visit sites that pull in javascript via http.

Re: The Great Cannon has been deployed again

#418

Earlier quoted context omitted.

Well, with the rise of anti DDoS services meaning the targeted websites are staying online, rendering the “Great Cannon” more like a pathetic peashooter, that’s doing one thing. Calling China out whenever they do this is another. Unmask the Chinazis for what they are.

I don't think that last line is helpful. If you believe that the Chinese government is akin to the Nazi party, better to make the argument explicitly than to use a term like "Chinazis", which could be interpreted as overly broad and highly insulting in the best case.

Oh, and saying "nobody can do anything" is helpful? Fuck what "could be interpreted" in a way or another: if you interpret it that way, if you consider it "overly broad and highly insulting in the best case", better to make the argument explicitly. Good luck.

Re: The Great Cannon has been deployed again

#419
post #305

Earlier quoted context omitted.

They are specifically suggesting that HTTP-only sites not be able to load from third party sites, which is quite a bit different than your interpretation of generally preventing any site from loading any external content. HTTPS ought to be the default and browsers can, and should, move towards that. But to answer your question more directly, yes they clearly know what they are suggesting.

I note this language in the writeup: > These attacks would not be successful if the following resources were served over HTTPS instead of HTTP: > http://push.zhanzhang.baidu.com/push.js ; or > http://js.passport.qihucdn.com/11.0.1.js This seems overly generous. I personally would not assume that the government of China couldn't persuade Baidu or qihucdn.com to serve government-provided JavaScript. It also assumes tha…

I'll speculate that there are sufficient locations failing to use https that they haven't felt a need to use https. I further speculate that China is sufficiently entangled with the international internet that they would prefer not to have their certificate authorities de-listed by the major browser vendors.

Re: The Great Cannon has been deployed again

#420
post #366

Earlier quoted context omitted.

General Aviation; the same people that lobby to keep using leaded fuels.

That's a bit too harsh. The GA people are lobbying to continue to be able to fly their aircraft. The FAA has been sitting on the problem of non-leaded avgas for something like 30 years now. The GA people don't like being exposed to lead any more than anyone else.

Yes, harsh on people literally choosing to spray a neurotoxic heavy metal compound over populated areas for their fun. Their advocacy is the roadblock to the adoption of safer fuels.
Post reply on HN