Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

431–440 of 470 posts

Re: The Great Cannon has been deployed again

#431
post #420

Earlier quoted context omitted.

That's a bit too harsh. The GA people are lobbying to continue to be able to fly their aircraft. The FAA has been sitting on the problem of non-leaded avgas for something like 30 years now. The GA people don't like being exposed to lead any more than anyone else.

Yes, harsh on people literally choosing to spray a neurotoxic heavy metal compound over populated areas for their fun. Their advocacy is the roadblock to the adoption of safer fuels.

I think we'd all rather burn cheaper / more prevalent gas than a leaded fuel that is the output of specialty refining. We're not allowed to by regulation, though, and furthermore present solutions would also endanger safety in a big slice of aircraft. The fleet of general aviation aircraft is really old, after all.

Re: The Great Cannon has been deployed again

#432

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

> This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). We're talking about China, so that's probably not going to work: Chinese users are using Chinese browsers [1] to access Chinese web…

The concern here is people using Chinese websites abroad. The Great Cannon rewrites javascript for a subset of remote users visiting Chinese sites, causing the users' browsers to participate in a DDoS against a target.

Re: The Great Cannon has been deployed again

#433

Earlier quoted context omitted.

The Chinese government can do this for systems sold within China. They don't have the authority to do it for computers globally. If I'm understanding other comments correctly, browser vendors installing HTTPSEverywhere cuts down the potential for this Great Cannon attack from 7.7 billion users to 1.4 billion. An 80% reduction seems significant.

I was under the impression that the other commenters were referring to HTTPS as a solution for those in China to protect themselves from their own government. Perhaps I was wrong.

No. It's to protect users outside China visiting Chinese sites from being coopted to participate in DDoS.

Re: The Great Cannon has been deployed again

#434
post #400
post #263

Earlier quoted context omitted.

> Unfortunately there's a giant category of devices that can't serve TLS. Like pretty much every consumer router in existence that you connect to through a webpage. Come on now. Of course those devices can use TLS - they just can't do so in the capricious constraints imposed by the system of "certificate authorities". It's not a fundamental limitation of the technology. If we were using something like noise protocol,…

Why do they have to use self-signed certs? Ship the device with a valid cert for $last_three_octets_of_mac_address.$vendor.com to the device, and print it clearly on the setup instructions. Typing in something like d63d15.ui.com isn't onerous. The CA/Browser Forum allows certs up to 27 months - do routers sit on store shelves for 27 months before being configured? Do they even sit for 12 months? (Once they're online,…

No need for even that. TLS should have an extension which says "I don't know how to verify my identity, but send this data to vendor.com and then they'll verify my identity".

Vendor.com can then look at the opaque blob forwarded from their hardware and decide if they want to deligate trust to it.

Re: The Great Cannon has been deployed again

#435

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

Sites embedding said JS "analytics" files could have implemented HSTS and CSP with SRI, and this attack wouldn't exist.

Re: The Great Cannon has been deployed again

#436
post #163
post #30

Earlier quoted context omitted.

It's 2019, what excuse does Baidu have to not support https for these scripts?

As far as I can tell many CDNs will gladly serve their scripts over HTTP if requested: http://cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.mi... I don't know if what's the reasoning behind that.

When visited over HTTP that CDN sets "Alt-Svc: h3-23=":443"; ma=86400", telling the browser that (encrypted) HTTP3/QUIC is available.

If you ever manage to load that CDN over HTTPS/QUIC it sets a HSTS header so all further pageloads will go over HTTPS.

Re: The Great Cannon has been deployed again

#437

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

TLS should be required, but it seems likely to me that the Chinese government can issue TLS certificates for MITM purposes that their browsers will trust. As for the DoS aspect, maybe it's time to do a CORS preflight on ALL cross-origin requests, including images. (Webfonts, for whatever reason, already require a CORS preflight. Probably because Adobe is on the W3C and they sell a service where certain origins can le…

> But with evidence of the CA issuing fake certificates to DoS websites, browsers would probably stop trusting that CA entirely.

"Hey Tim Apple/Microsoft/Google, if you want to do business in China you have to put our CA on your devices/software...".

At least Firefox would still be free from that. And Apple already has China-specific iOS, so they'd just activate the bad CA on Chinese devices...

Re: The Great Cannon has been deployed again

#438

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

Users should be able to restrain communication and duration of computation..

Re: The Great Cannon has been deployed again

#439
post #420

Earlier quoted context omitted.

That's a bit too harsh. The GA people are lobbying to continue to be able to fly their aircraft. The FAA has been sitting on the problem of non-leaded avgas for something like 30 years now. The GA people don't like being exposed to lead any more than anyone else.

Yes, harsh on people literally choosing to spray a neurotoxic heavy metal compound over populated areas for their fun. Their advocacy is the roadblock to the adoption of safer fuels.

It doesn't actually accumulate in any particular area. There was a study done at at an airport that showed no particular accumulation at the airport. Leaded gas ends up poisoning the whole world a bit.

This "dilution is the solution to pollution" argument is the excuse the FAA uses for forcing everyone to use leaded avgas. This should be more of a scandal. The FAA is basically helping maintain a harmful oil company monopoly at the expense of the world.

This is not just about recreational aircraft. For example, 45% of the Canadian commercial fleet is piston engine based. Incidentally, Canada was involved in a test program with the FAA for leaded fuel replacements. The FAA recently dropped out of that program.

Re: The Great Cannon has been deployed again

#440

Earlier quoted context omitted.

JavaScript was a mistake

This is just another kneejerk. They could have just injected an tag with randomized src="" directly.

That would not consitute such a problem. The script is what provides the amplification factor here.
Post reply on HN