Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

311–320 of 470 posts

Re: The Great Cannon has been deployed again

#311

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

> This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons).

We're talking about China, so that's probably not going to work: Chinese users are using Chinese browsers [1] to access Chinese websites. I don't think Chinese browser-makers and website operators are going to take action against their government like that.

[1] https://www.fastcompany.com/3058432/the-top-3-web-browsers-i...

Re: The Great Cannon has been deployed again

#312

> These attacks would not be successful if the following resources were served over HTTPS instead of HTTP: Can someone explain how using HTTPS would mitigate this attack?

Https is not hackable “yet” so you can’t intercept the traffic in the middle. They intercepted http traffic and swapped the malicious js file in http traffic.

Can't China just issue its own certificates to make the browser see a secure connection to the target server when it talks to a Chinese firewall server instead. I mean they have access to valid root certificates, right?

Re: The Great Cannon has been deployed again

#313

This should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other sol…

I recently (4 or 5 months ago) joined an online community of aircraft owners and pilots that is primarily focused around a single brand of aircraft (although it's not an official site of, property of, that brand nor is it endorsed by that brand).

When I signed up, they emailed me to welcome me to the site (they actually require manual authorization of users by an admin, which is... refreshing, but uncommon). The email ended by stating that if I lost my password, they could "recover it" and send it back to me.

I raised a thread about it in one of their off-topic sections, and got harassed - "How secure do you need your browsing to be?" (And hey, I mean, I was asking them to do more work)

But it stands out that most of the public doesn't know, and doesn't care to know. Even a site that's populated by people with net worths and/or incomes that average in the six-to-seven figure range, that they probably signed up for with the same email address and password that they use for their bank and brokerage accounts.

HTTP should come with a warning. Furthermore, it would be fan-fucking-tastic if there was some generalizable way to (automatically) audit a website's security practice. Like, a crawler that just runs standard OWASP-style attack-vector checks, and sends an email to the site's owners when one succeeds. And then put that data into a database and warn users (with a browser plugin) when they are creating credentials for sites with bad security.

Re: The Great Cannon has been deployed again

#314
post #142

Earlier quoted context omitted.

War seems to progress as follows: 0 - Peace 1 - Trade War 2 - Financial War 3 - Electronic War 4 - Shooting War Note that 1 & 2 are different types of Economic war, and could be grouped together. The steps occur in order, but steps can be skipped. From a US-centric point of view, North Korea and Iran seem to be at #3. China & Russia are at a limited version of #2. Chinese/HK seem to be at #3 with each other.Given how…

I don't know who to attribute this to but I've heard a saying: "Countries that trade with each other don't make war with each other." As we isolate countries and disrupt trade we definitely are increasing the risk of conflict.

Sometimes known as the “Golden Arches Theory of Diplomacy”

Re: The Great Cannon has been deployed again

#315

Earlier quoted context omitted.

No. "Behind the Great Firewall" is another way of saying "served from China". Perhaps -- or even most likely -- it is the government. But this is hardly a smoking gun. There are plenty of people on the mainland that hate what's going on in HK, and who are not the government.

Also the Great Firewall isn't one box admin'd by a single actor. It's a set of network firewalls managed by different network entities to fulfill legal obligations. It could be one of them acting alone. Then there's the question of how separate the operating company is from the Party..

Acting alone? Yeah right. Do that in the PRC, and you'll probably be in a "reeducation camp" by the end of the week.

Re: The Great Cannon has been deployed again

#316

Earlier quoted context omitted.

That would be the kind of signal that would be hard for the Chinese to spin in such a way that it would make them look good, and the economic effect would be pretty much instantaneous. There is plenty of historical precedent for this: spammers' IP ranges would be blackholed to send a message to their ISPs that such behavior wasn't tolerated. That the Chinese authorities decide to play this game at the nation state le…

I'm not sure 'We have the technology to censor the internet, and it's okay to deploy it' is the message you want to give the CCP.

That's not censorship.

https://en.wikipedia.org/wiki/Censorship

The criminal co-opting of networks and nodes on those networks is not speech by any definition.

Re: The Great Cannon has been deployed again

#317

Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…

This sounds like a knee-jerk reaction that doesn't take into consideration the ramifactions of the suggested policy. It won't stop DDoS attacks, because those exist _because the internet exists_ and unless you dismantle the very concept of interconnected "everyone can reach everyone" networking, all you're doing is locking down access to more and more people until only technical experts or the people with enough mone…

[deleted]

Re: The Great Cannon has been deployed again

#318

Earlier quoted context omitted.

It only works if you somehow remove entire China from the Internet.

Who cares? China is a net negative on the Internet, they can stay over in their intranet as far as I am concerned, nothing of value would be lost.

Ohh no! Human to human connections are far too important to maintain in today's glocalized world.

Re: The Great Cannon has been deployed again

#319

Earlier quoted context omitted.

If you can’t distinguish between the Vietnamese War and the Axis Concentration Camps on a scale of atrocity, I’m doubtful there’s any intellectual exercise that’s going to clarify that for you.

[flagged]

Calling the interning of over 1 million people an attempt at unification is blatant astroturfing and is wildly and viciously wrong.

Re: The Great Cannon has been deployed again

#320
post #154

Earlier quoted context omitted.

The whole point is that the pages being modified are served over HTTP, there's no certificate there, good or bad.

The whole point is that you couldn’t use the script over HTTPS even if you really wanted to.

Oh okay I see what you mean now, sorry for the misunderstanding.
Post reply on HN