that seems to be a great idea, google could also do Germans a favor by hosting "this video is not available in your country" mirrors, right?
Google Can Bring an End to Censorship in 10 Days
61–70 of 75 posts
Re: Google Can Bring an End to Censorship in 10 Days
#62>>“Google! Do it! If they don't block you, freedom wins. If they do block you, there will be much more opposition to censorship inside China and the system will be forced to change, thus freedom wins too!”
>Win-win.
I don't think the author realizes what a "win" means to corporations. Helping the cause of freedom doesn't turn losing a billion potential customers into a win, it's just the silver lining on a very dark cloud.
Re: Google Can Bring an End to Censorship in 10 Days
#63Re: Google Can Bring an End to Censorship in 10 Days
#64Re: Google Can Bring an End to Censorship in 10 Days
#65Earlier quoted context omitted.
How many legitimate websites use that CA? Especially ones Chinese users will visit often? If the browser blocks the CA, those will all break. Perhaps the browser could do something subtler, but it's not straightforward. Or we could make the https cert protocol more flexible, but changing protocols is hard.
Sourceforge and friends are known for injecting badware into binary installers for open-source software. It will be interesting to see if the Chinese government makes their own alterations to the Firefox binary installers that pass through their network that add the CA back in. Nobody checks their installers' GPG keys anyways
Wait... what???
Re: Google Can Bring an End to Censorship in 10 Days
#66I feel like this article is extremely short-sighted. If Google did the things that the author suggests, China would simply block all of Google instead. It has done this in the past, and would not hesitate to do so again.
Re: Google Can Bring an End to Censorship in 10 Days
#67> The code-sharing site Github uses encrypted-only access and, perhaps not intentionally, broke the pattern of Internet control in China. Encrypted-only access is not a solution, it's a patch. Here is how China could break it if they wanted to: 1. Choose domains that you want to monitor in this way. E.g. github.com. 2. Requests to any IP for that domain on port 443 will return a certificate that the Chinese governmen…
The entire CA approach requires me to trust entities that I am not certain are truly trustworthy. After all they all fall under varied jurisdictions and at the end of they day they are owned and operated by individuals that can be bribed or coerced. Furthermore, we don't know what kind of practices each CA has in place to mitigate tampering and prevent subversion of the CA system.
With that in mind, is it possible to make a CA that is distributed (via a DHT) and publicly verifiable. The process to get a certificate from such a distributed CA could be a long, intense process, but at least it would be trustworthy to a degree no other CA could be.
Is Namecoin a viable alternative? Are there others?
Re: Google Can Bring an End to Censorship in 10 Days
#68Earlier quoted context omitted.
How many legitimate websites use that CA? Especially ones Chinese users will visit often? If the browser blocks the CA, those will all break. Perhaps the browser could do something subtler, but it's not straightforward. Or we could make the https cert protocol more flexible, but changing protocols is hard.
Sourceforge and friends are known for injecting badware into binary installers for open-source software. It will be interesting to see if the Chinese government makes their own alterations to the Firefox binary installers that pass through their network that add the CA back in. Nobody checks their installers' GPG keys anyways
Re: Google Can Bring an End to Censorship in 10 Days
#69Earlier quoted context omitted.
Sourceforge and friends are known for injecting badware into binary installers for open-source software. It will be interesting to see if the Chinese government makes their own alterations to the Firefox binary installers that pass through their network that add the CA back in. Nobody checks their installers' GPG keys anyways
> Sourceforge and friends are known for injecting badware into binary installers for open-source software. Wait... what???
http://www.gluster.org/2013/08/how-far-the-once-mighty-sourc...
Re: Google Can Bring an End to Censorship in 10 Days
#70Earlier quoted context omitted.
> Sourceforge and friends are known for injecting badware into binary installers for open-source software. Wait... what???
GIMP no longer distributes binaries on sourceforge because sourceforge's installer "bundles third-party offers with Free Software packages. We do not want to support this kind of behavior, and have thus decided to abandon SourceForge." http://www.gimp.org/ http://www.gluster.org/2013/08/how-far-the-once-mighty-sourc...
For as long as I can remember Sourceforge's usability has sucked. That's reason enough to avoid it (but omg! free file hosting!) but the installer thing maybe isn't quite as deceptive and malwareish as your first message let on. It's just another facet of their lameness.
Kudos to Gimp for dumping them. Why does anyone stay with them at this point?