Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

291–300 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#291
post #172

Earlier quoted context omitted.

It is rather stupid to equate the degree of media manipulation in the West vs. China and Russia.

Is it? Check out the CNN international edition and US edition on their website after a terrorist attack, and you'll see how blatant it can get (CNN is interesting in that respect since both versions are readily available from a selector at the top of their page). They don't even need to hide it - it's "sold as a feature" because most people are not interested in seeking out alternative viewpoints. You see it even wit…

Personally, I think...

(Well, I suppose that's an odd start, since half the problem with politics is people trusting their personal thoughts overmuch rather than gathering evidence. Then again, those who do gather evidence in politics, the softest science, rarely seem to find any that upsets their preconceived notions. Anyway-)

...that this would happen with or without any overt government interference. I'm sure that the soft pressure described by Mr. Chomsky plays a part, and that most government officials in democracies are happy that it exists.

But just look at smaller scales: say, at the umpteen "camp A vs. camp B" divisions that come up in one capacity or another on this site. JavaScript is a horrible language that's killing the web, or it's a cool language with some flaws. Go is a language firmly stuck in the 1980s with the goal of treating its programmers like disposable pawns[0], or it's a fluid pragmatic language with an emphasis on maintainability. Apple has a track record of producing shiny overpriced crap, or perhaps innovative products that usually beat the competitors'. Google is an advertising company and absolutely everything it does has some direct connection to invading its users' privacy, or it's a geeky paradise, tech culture's truest representative among large corporations. The NSA is a villainous organization through and through that's killing everything important about American freedom (common opinion on this site, not as pervasive elsewhere) or it's just doing its job and has little, if anything, to answer for. Feminism... well, I think that word is enough.

These are just some of the biggest examples; there are countless others, and obviously you can get far more examples by broadening the scope from tech. In each case, people tend to divide themselves based on their opinions into one of (usually) two opposing groups. Each group is self-reinforced by memes spreading through its echo chamber, each is very confident it's right, and importantly, eventually members of the two completely fail to understand each other, speaking with different terminology about different principles and both almost certainly far from objective neutrality. Some of the camps have some potential equivalent to Chomsky's cited explicit manipulation - c.f. the recent Fear of Apple post. Most don't. People self-manipulate, and they're rewarded with positive emotions generated from discussions with other people that share their views.

In politics, the camps form within political parties, geographical areas, and often entire countries. It would be interesting and powerful to think of ways to reduce this; on the other hand, I don't think it's fair to blame Western governments for what's basically human nature. My suspicion is that people look at the distortion of reality in democratic country X's politics, compare it to censored country Y's, find the proportion too large, and blame the government of X... but miss that a large portion of each side's distortion is natural, and if you subtract that from each side, the proportion gets far smaller. YMMV.

[0] opinions on Go aren't usually that strong, I think, but I've heard exactly that claim from one firebrand on Twitter.

Re: China's Man-On-the-Side Attack on GitHub

#292

If Baidu served everything over https, would that effectively make this attack impossible unless the China GFW mitm'd the connections? I suppose that might add a significant server load to Baidu, but I wonder if we should just start accepting SSL as a cost of doing business on the internet. Of course, that would require Baidu's cooperation, and I suppose they might now want to raise the ire of the Chinese government.…

> that would require Baidu's cooperation

Don't count on that. Baidu is part of the Chinese government gang. It is notorious for censoring/altering search results both for political and commercial reasons. I wouldn't be surprised if they were notified about this beforehand.

Re: China's Man-On-the-Side Attack on GitHub

#293
post #181

Earlier quoted context omitted.

You are right. The degree and sophistication of media manipulation is profoundly greater in the west. While the Chinese block a lot of media, the manipulation is minimal. Most Chinese are very cynical and know exactly what is going on. The west, or at least the US, traps people in a matrix of sorts where they don't even see the manipulation. The narrative is exquisitely framed and guided to leave people with a sense…

If you want to publish your own newspaper, you can. Nobody will stop you. Start your own online video news service, weblog or nes site - nobody will stop you. Post whatever you like to Reddit, or any other discussion platform. In China and Russia you cannot do these things. Published mdeia are strictly monitored and censored. The state employs thousands of astroturfers to flood social media with pro-government messag…

I won't argue with you that China is far more repressive and less free than the US, because you are correct in that assertion. I only state that the US is far more _manipulative_.

Re: China's Man-On-the-Side Attack on GitHub

#294

If Baidu served everything over https, would that effectively make this attack impossible unless the China GFW mitm'd the connections? I suppose that might add a significant server load to Baidu, but I wonder if we should just start accepting SSL as a cost of doing business on the internet. Of course, that would require Baidu's cooperation, and I suppose they might now want to raise the ire of the Chinese government.…

I don't think they would be able to MITM the connections because your browser would detect that they don't own the certificate for the site.

Unless of course, the CA is also compromised.

I'm no expert so please do correct me if I'm wrong =]

Re: China's Man-On-the-Side Attack on GitHub

#296
post #250

Earlier quoted context omitted.

> So what's the rule then? Block all packets coming out of countries with governments that do MITM attacks? Block packets from any company that does not take reasonable steps to stop its network from being used to attack others. This has been networking rule for a long time. - We block open mail relays - we block hacked Windows XP machines - we should block a company who's in a hacked data center where their upstream…

I assumed you were talking about our governments when you said we. Who's stopping you from blocking whatever you want? Or from creating a public block list for that matter. You have to convince me to install it on my machines though. :P

I think they are addressing their fellow network admins with that comment

Re: China's Man-On-the-Side Attack on GitHub

#297

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

Wouldn't it be awesome if GitHub somehow exposed issues / pull requests / etc as actual git repos for each project, like they do for wikis? Seems like that would mitigate much of the risk associated with centralized issue tracking. And yes, I'm aware that all the data is already accessible via their API, but that's not quite as easy to deal with as a simple "git clone". For now, perhaps something like https://backhub…

I've thought about this as well. Should be possible to store the data in the repo itself. Later we can add a gui to make things easy. I believe that we can let their existing api schema determine the format. I'd like to do it in node because of its portability and ubiquity. Pm me if you are interested in helping.

Big decision is whether to store the issues and other metadata in a seperate branch or not.

Re: China's Man-On-the-Side Attack on GitHub

#299
post #283
post #274

Earlier quoted context omitted.

I like to grab old books at yard sales, and found this an interesting read (Arms Control Disarmament And National Security, 1961, https://archive.org/details/armscontroldisar013124mbp ). It's a collection of essays by various authors on a variety of arms control subjects. Everyone sees nuclear / Cold War negotiations in hindsight, but in 1961 (and probably also ~1950) the logic is much more interesting, given that th…

In this case, the problem with any kind of technical workaround on the server side is that Baidu is under the jurisdiction of the government implementing the DDoS and is thus unlikely to be able to actively work to defeat it. If another country tried to do the same... well, that's what HTTPS is for.

HTTPS is not secure when we talk about China it is false sense of security! Last case 7days ago: http://www.theregister.co.uk/2015/03/24/google_ssl_cnnic/

Re: China's Man-On-the-Side Attack on GitHub

#300

Earlier quoted context omitted.

The actual detail/technology, more or less. There's nothing China did this last couple of weeks that the Five Eyes' QUANTUM setups aren't already tooled to do: QUANTUMINSERT can be used to inject the JavaScript, just change the selectors and the payload. Indeed, I believe this capability has already been privately trialled by GCHQ. (QUANTUMSLAMMER, was it?) It is not advanced technology: TCP just has no protection he…

I believe this is precisely the method GCHQ used to compromise Belgacom, for the purposes of spying on the EU. They used QUANTUMINSERT to inject an exploit payload into connections from belgacom employees to LinkedIn and slashdot.

Although in those, they targeted using pretty close selectors and the payload was browser exploits with a very advanced dropper from what is essentially a big, supported modern malware construction kit. GCHQ used the same technique, but leveraged it to do a very different - and actually far more intrusive and destructive - thing.

This, by contrast, is a widely-targeted, fairly dumb DoS payload - but of course, not every DDoS has to be smart! Scale does all the work, and dropping malware, albeit relatively benign malware, en masse like this yields a lot of scale. This is particularly bad when there are potentially more personnel adapting it to evade defenses than there are personnel trying to defend against it: bravo to the GitHub security team!

Post reply on HN