Live data from Hacker News

Tech giants are hijacking the internet

dw.com

111–120 of 143 posts

Re: Tech giants are hijacking the internet

#111

Earlier quoted context omitted.

That's because it is unsafe. Without HTTPS, an attacker can inject arbitrary malicious javascript into the page. The only context in which plain HTTP is ok on today's internet is when you a loading a page from your own server on the same LAN, behind a firewall, when you are reasonably sure that nobody else is in you network.

> That's because it is unsafe. Without HTTPS, an attacker can inject arbitrary malicious javascript into the page. No they can't. If they can inject malicious content then you should fix the exploits on your platform. HTTPS isn't going to save you. If exploitable under HTTP hey can do the same under HTTPS. So, How is a static webpage of "hello world" unsafe? hello world sigh Replace hello world with whatever informat…

No, you don't get it:

There is no such thing as a "static" web page in the context of a MITM attack. The MITM can change the page to ANYTHING he wants it to be. The HTML you receive can be a completely different page than the one sitting on your server.

HTTPS protects you from that. It ensures that the HTML you receive is the same HTML from the server. That's why I sad: The only way unencrypted HTTP is reasonable is when you are fairly sure that there isn't a MITM. Like on your local LAN--anything that goes across the public internet is suspect.

> If they can inject malicious content then you should fix the exploits on your platform.

This is not reasonable. Literally every browser out there has multiple 0-days show up every year. Chrome, Firefox, Brave, Safari, Edge, you name it.

Re: Tech giants are hijacking the internet

#112

Earlier quoted context omitted.

Now try connecting to public wifi with that. Doing a MiTM and replacing anything with anything else is super easy. Just put a router with some Linux distro acting as extender (or mobile connection AP) with the same name and you can change traffic on any non-HTTPS website. Or not even a public wifi. Someone can put a device somewhere between your home and ISP and MiTM attack you the same way as above. Oh, and I will j…

Yes, however the website is still inherently secure outside of those scenarios. If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL. The scenarios you listed can even make HTTPS insecure. The users laptop is infected with a virus, their antivirus software has been exploited with a bogus root cert.

> The scenarios you listed can even make HTTPS insecure.

You don't understand what HTTPS does, then.

HTTPS is specifically designed to counter MITM attacks, so it is, in fact, not insecure in the scenarios listed by the parent comment.

> If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL.

That is really only relevant when you and your sever are on the same LAN, behind a firewall, and you are reasonably sure that you don't have an intruder (like I mentioned upthread).

When you are browsing a server across the public internet, you should assume you are being MITM'd. With HTTP (not S), the MITM attacker does not need to be between you and the server. If they can guess the TCP sequence number and when you are browsing, the MITM can inject (or replace) arbitrary content into the pages you load.

Re: Tech giants are hijacking the internet

#113

Earlier quoted context omitted.

How will anyone find your site in order for it to become popular, if Internet giants gatekeep the only methods that people use to find or access things? Internet giants control your browser, your smartphone, your search engine, your digital assistant, your DNS, most of the traffic going through CDNs, advertising, online shopping, app purchases, news, etc. Most of the internet is only accessible through the giants. Mo…

Internet giants don't gatekeep the methods that people use to find and access things. The simplist way is to do a bunch of advertising for your site.

How do you advertise for your site if not through internet giants' advertising platforms? Billboards?

Re: Tech giants are hijacking the internet

#114

Well DW could do something about it by at least adding the fediverse on their abominable "follow us on X, Y, Z". DW does not even have an RSS feed for chris sake. The press is complicit in the hijacking of the internet. They made a Faustian pact. Now they are crying foul.

This type of internet forum reply is so commmon there is a name for it and even a Wikipedia page. https://en.wikipedia.org/wiki/Whataboutism The "whatabout" type replies would seem to require that the only websites that can report on the ills of the internet are ones that have no ads, no tracking, no telemetry, no data collection, and so on. Everything must be perfect. That's a bit silly. Shooting the messenger. Argu…

"Whataboutism or whataboutery (as in "what about...?") denotes in a pejorative sense a procedure in which a critical question or argument is not answered or discussed, but retorted with a critical counter-question which expresses a counter-accusation."

Critical question or argument: Tech giants are hijacking the internet

Counter-question or counter-accusations: 1. Why doesn't DW have a link to a fediverse. 2. DW does not have an RSS feed. 3. The press is complicit in hijacking the internet.

The critical question or argument is neither answered or discussed.

Re: Tech giants are hijacking the internet

#115

Earlier quoted context omitted.

Yes, however the website is still inherently secure outside of those scenarios. If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL. The scenarios you listed can even make HTTPS insecure. The users laptop is infected with a virus, their antivirus software has been exploited with a bogus root cert.

> The scenarios you listed can even make HTTPS insecure. You don't understand what HTTPS does, then. HTTPS is specifically designed to counter MITM attacks, so it is, in fact, not insecure in the scenarios listed by the parent comment. > If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL. That is really only relevant when you and your sever are on t…

Yes, and with those scenarios if your root certificate has been maliciously modified https isn't going to save you either

Re: Tech giants are hijacking the internet

#116

Earlier quoted context omitted.

Imagine a couple of years from now, you're working on some stuff for a client. Client sends you a link, but you can't open the link with your non-chromium browser of choice - it's been built on tech provided by google, and google says: You can only use chrome to view this site. You try to download chrome, but since you once used some ad-block plugin, you've been banned from using all alphabet products. Google has als…

I think we can all think of potential futures. I don't see why this one is particularly likely. Google has open sourced the guts of its browser so others can make non-Google controlled browsers, and they fund one of the two only real competitors to their browser.

People can fork Google Chrome, yet none has done this so far. Not counting pretty GUI or some integrated extensions as a fork really. Google Chromium is genius marketing idea, hats off to the people who invented it, they convinced even programmers that there is some mythical "independent" Chromium project and anyone can fork it. Well, theoretically it is possible, but practically - not so much. The strategy is so successful that not even anti-monopoly departments aren't that interested in it.

Re: Tech giants are hijacking the internet

#117

Earlier quoted context omitted.

Imagine a couple of years from now, you're working on some stuff for a client. Client sends you a link, but you can't open the link with your non-chromium browser of choice - it's been built on tech provided by google, and google says: You can only use chrome to view this site. You try to download chrome, but since you once used some ad-block plugin, you've been banned from using all alphabet products. Google has als…

I send them instructions how to SFTP files to me if it's important enough they will do it . I've managed to get lawyers to use SFTP albeit with a GUI [0a]. If anyone wants to test it out, put "ohblog.net" in the host field, then something like mysql [0b] in the username, leave the password blank and upload silly things into the /pub in the directory. AdminHands is a decent SFTP app for cell phones. If that isn't an o…

If it's important enough they will do it

Notably, this also requires that you are important enough. To some people, like the hypothetical client, you are not.

Re: Tech giants are hijacking the internet

#118

Earlier quoted context omitted.

I send them instructions how to SFTP files to me if it's important enough they will do it . I've managed to get lawyers to use SFTP albeit with a GUI [0a]. If anyone wants to test it out, put "ohblog.net" in the host field, then something like mysql [0b] in the username, leave the password blank and upload silly things into the /pub in the directory. AdminHands is a decent SFTP app for cell phones. If that isn't an o…

If it's important enough they will do it Notably, this also requires that you are important enough. To some people, like the hypothetical client, you are not.

I agree. For me personally that is a signal to cut ties with a business or organization. It's a red flag when orgs use crappy web portals that demand illogical or ill conceived compliance. I find those "turn key" solutions or platforms like Facebook to be full of dystopian and incompetent practices that are best to distance ones self from. Some may not find that an option but I can only hope that more people push back aggressively on malevolent patterns.

Re: Tech giants are hijacking the internet

#119

Earlier quoted context omitted.

No, the problem is no one is willing to pay for any of these services. How many people are paying for their news? For something like YouTube? That stuff costs mega $$$ Back in the day, you were forced to pay for things. You wanted news? You had to put in some coins for a newspaper. Now you sign on and you get news and YouTube seemingly for free… open standards or not, someone has to pay for it one way or another.

Even if this were true, this is a talking point from the beginning of the internet when there were way less people hooked to it, why does it follow that that makes anything okay? If people won’t pay for a service it’s because they really want or need it. You’re simply making the case that these services that no one believes useful enough to pay for are controlling everything because they’re frontends for marketing ag…

I use plenty of services that I do really want but as long as I don’t actually have to pay for it, I won’t pay. Do I watch Disney+ or HBO or Netflix a lot sometimes? Yes. Have I ever paid for any streaming service? God no, because I always got some friend I can bum off of. And as long as I can bum, I will continue to bum.

The only things I willingly and voluntarily pay for are news and music subscriptions and that’s because I value them the most and consider them important to society but I definitely don’t necessarily use them the most.

Anyway my only point is that it has nothing with open standards. People want free and will take advertising if it means it’s free.

Re: Tech giants are hijacking the internet

#120
post #62

Earlier quoted context omitted.

No, the problem is no one is willing to pay for any of these services. How many people are paying for their news? For something like YouTube? That stuff costs mega $$$ Back in the day, you were forced to pay for things. You wanted news? You had to put in some coins for a newspaper. Now you sign on and you get news and YouTube seemingly for free… open standards or not, someone has to pay for it one way or another.

There are definitely people who will and still do pay for these things, Apple News+ or whatever is an example of news...also WSJ, NYT, Economist subscriptions...Instagram verified checkmarks. The question is how do these companies capture both the paying and non paying users...and that is through advertising. If you pay any attention, the amount of ads you watch is your payment to these companies for "free" services.

I am one of those people but this is a far cry from the days where you had to use a newspaper vending machine or walk into a video rental store. Free wasn’t really even an option.

Anyway my point is that the problem is not the lack of open standards. The problem is that we discovered how to do “free” and a lot of people prefer this way whether they want to think about it or not.

Post reply on HN